sofisticata | 05.11.2013 16:19 | trojandownloader win32/adload.da Hallo zusammen,
seit einigen Tagen bekomme ich die Meldung, dass Windows den Virus trojandownloader win32/adload.da erkannt hat.
Mit meinem Antivirusprogramm wurde nichts gefunden, auch nicht mit dem Microsoft Safety Scan. Ich habe soeben den Systemscan mit FRST und den Scan mit GMER durchgeführt.
Was nun? :balla:
Außerdem ist mein Laptop viel zu langsam, braucht sehr lange um hochzufahren und hängt sich des Öfteren auf. Liegt das auch an dem Virus? Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013
Ran by Sofia (administrator) on SOFIA-PC on 05-11-2013 15:02:03
Running from C:\Users\Sofia\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
(pdfforge GbR) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files\PDF Architect\ConversionService.exe
(Microsoft Corporation) C:\windows\System32\IgrsSvcs.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Lenovo) C:\Program Files\Lenovo\VeriFace\PManage.exe
(Conexant Systems, Inc) C:\Program Files\Conexant\SAII\SmartAudio.exe
(Lenovo(beijing) Limited) C:\Program Files\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files\Lenovo\Energy Management\Energy Management.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] ()
HKLM\...\Run: [VeriFaceManager] - C:\Program Files\Lenovo\VeriFace\PManage.exe [3122440 2010-06-27] (Lenovo)
HKLM\...\Run: [UpdateP2GShortCut] - C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM\...\Run: [EnergyUtility] - C:\Program Files\Lenovo\Energy Management\utility.exe [4114288 2009-09-29] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] - C:\Program Files\Lenovo\Energy Management\Energy Management.exe [5064560 2009-09-29] (Lenovo (Beijing) Limited)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [47904 2010-10-08] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-15] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-10] (Avira Operations GmbH & Co. KG)
HKCU\...\Run: [msnmsgr] - C:\Program Files\Windows Live\Messenger\msnmsgr.exe [4283256 2011-05-13] (Microsoft Corporation)
HKCU\...\Run: [Facebook Update] - "C:\Users\Sofia\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20684656 2013-07-25] (Skype Technologies S.A.)
HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1564016 2013-07-15] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-07-15] (Samsung)
HKU\Default\...\RunOnce: [WLStart] - C:\Program Files\Windows Live\Installer\wlstart.exe [ 2009-07-26] (Microsoft Corporation)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://lenovo.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKCU - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = hxxp://www.crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=60341
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = hxxp://www.daemon-search.com/search/web?q={searchTerms}
BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GbR)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.11.1
FireFox:
========
FF ProfilePath: C:\Users\Sofia\AppData\Roaming\Mozilla\Firefox\Profiles\a0jdxmqp.default
FF user.js: detected! => C:\Users\Sofia\AppData\Roaming\Mozilla\Firefox\Profiles\a0jdxmqp.default\user.js
FF Homepage: hxxp://neueswort.de/|hxxp://www.faz.net/
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Sofia\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
FF SearchPlugin: C:\Users\Sofia\AppData\Roaming\Mozilla\Firefox\Profiles\a0jdxmqp.default\searchplugins\daemon-search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Sofia\AppData\Roaming\Mozilla\Firefox\Profiles\a0jdxmqp.default\Extensions\nostmp
FF Extension: Yahoo! Toolbar - C:\Users\Sofia\AppData\Roaming\Mozilla\Firefox\Profiles\a0jdxmqp.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF Extension: DivXWebPlayer - C:\Users\Sofia\AppData\Roaming\Mozilla\Firefox\Profiles\a0jdxmqp.default\Extensions\DivXWebPlayer@divx.com.xpi
FF Extension: noscript - C:\Users\Sofia\AppData\Roaming\Mozilla\Firefox\Profiles\a0jdxmqp.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: No Name - C:\Users\Sofia\AppData\Roaming\Mozilla\Firefox\Profiles\a0jdxmqp.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: Adblock Plus - C:\Users\Sofia\AppData\Roaming\Mozilla\Firefox\Profiles\a0jdxmqp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Sofia\AppData\Roaming\Mozilla\Firefox\Profiles\a0jdxmqp.default\Extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\SOFIAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\SOFIAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\SOFIAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\SOFIAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\SOFIAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\SOFIAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [fnjbmmemklcjgepojigaapkoodmkgbae] - C:\Program Files\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\google_chrome\html5video\html5video.crx
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-10] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1164360 2013-10-10] (Avira Operations GmbH & Co. KG)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [582944 2009-08-11] (Broadcom Corporation.)
R2 IGRS; C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [579400 2009-09-22] (Lenovo Group Limited)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
S3 PS_MDP; C:\Program Files\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
R2 ReadyComm.DirectRouter; C:\Program Files\Lenovo\ReadyComm\common\router.dll [103688 2009-07-14] (Lenovo Group Limited)
==================== Drivers (Whitelisted) ====================
R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [21520 2009-05-19] (Lenovo Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-10] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [67680 2013-10-10] (Avira Operations GmbH & Co. KG)
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [63240 2009-07-28] (Lenovo)
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
S4 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.)
R1 funfrm; C:\Windows\System32\Drivers\funfrm.sys [54800 2010-06-27] ()
S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [86824 2008-10-21] (MCCI Corporation)
S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [15016 2008-10-21] (MCCI Corporation)
S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [114600 2008-10-21] (MCCI Corporation)
S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [108328 2008-10-21] (MCCI Corporation)
S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [26024 2008-10-21] (MCCI Corporation)
S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [104616 2008-10-21] (MCCI Corporation)
S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [109736 2008-10-21] (MCCI Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-10-18] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-10-10] (Avira GmbH)
R3 usbsmi; C:\Windows\System32\DRIVERS\SMIksdrv.sys [171776 2009-10-16] (SMI)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider)
S3 wsvd; C:\Windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink)
S3 HTCAND32; System32\Drivers\ANDROIDUSB.sys [x]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x]
S3 WinRing0_1_2_0; \??\D:\test\ECECECEC\WinRing0.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-05 15:01 - 2013-11-05 14:59 - 01089445 _____ (Farbar) C:\Users\Sofia\Desktop\FRST.exe
2013-11-05 15:00 - 2013-11-05 15:00 - 00000000 ____D C:\FRST
2013-11-04 21:40 - 2013-11-04 21:40 - 00000000 ____D C:\Users\Sofia\AppData\Roaming\Avira
2013-11-04 21:33 - 2013-11-04 21:33 - 00002016 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-11-04 21:33 - 2013-10-10 19:14 - 00028520 _____ (Avira GmbH) C:\windows\system32\Drivers\ssmdrv.sys
2013-11-04 21:31 - 2013-11-04 21:31 - 00000000 ____D C:\ProgramData\Avira
2013-11-04 21:31 - 2013-11-04 21:31 - 00000000 ____D C:\Program Files\Avira
2013-11-04 21:31 - 2013-10-10 19:14 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2013-11-04 21:31 - 2013-10-10 19:14 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2013-11-04 21:31 - 2013-10-10 19:14 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2013-11-04 21:31 - 2013-10-10 19:14 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2013-11-04 14:50 - 2013-11-04 14:50 - 00135216 _____ C:\windows\Minidump\110413-26676-01.dmp
2013-10-14 20:09 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-10-14 20:09 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-10-14 20:09 - 2013-09-23 00:28 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-10-14 20:09 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-10-14 20:09 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-10-14 20:09 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-10-14 20:09 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-10-14 20:09 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-10-14 20:09 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-10-14 20:09 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-10-14 20:09 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-10-14 20:09 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-10-14 20:09 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-10-14 20:09 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-10-14 20:09 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-10-14 20:09 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-10-14 08:10 - 2013-09-14 01:48 - 00338944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2013-10-14 08:10 - 2013-09-08 03:07 - 01294272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-10-14 08:10 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2013-10-14 08:10 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2013-10-14 08:10 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2013-10-14 08:10 - 2013-07-03 05:02 - 00036352 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbscan.sys
2013-10-14 08:10 - 2013-07-03 04:36 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2013-10-14 08:10 - 2013-07-03 04:36 - 00025728 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2013-10-14 08:09 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-10-14 08:09 - 2013-08-29 02:50 - 01289096 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-10-14 08:09 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2013-10-14 08:09 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2013-10-14 08:09 - 2013-08-28 02:04 - 02348544 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-10-14 08:09 - 2013-08-28 01:57 - 00434688 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2013-10-14 08:09 - 2013-08-01 12:03 - 00729024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2013-10-14 08:09 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-14 08:09 - 2013-06-06 05:52 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2013-10-14 08:09 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2013-10-14 08:09 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2013-10-14 08:09 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2013-10-14 08:09 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2013-10-14 08:08 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2013-10-14 08:08 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2013-10-14 08:08 - 2013-07-04 10:48 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2013-10-14 08:07 - 2013-07-12 11:08 - 00146816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2013-10-14 08:07 - 2013-07-12 11:07 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2013-10-14 08:07 - 2013-06-25 23:56 - 00527064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2013-10-07 19:46 - 2013-11-04 14:50 - 00000000 ____D C:\windows\Minidump
2013-10-07 19:46 - 2013-11-04 14:49 - 117439708 _____ C:\windows\MEMORY.DMP
2013-10-07 19:46 - 2013-10-07 19:46 - 00135272 _____ C:\windows\Minidump\100713-28470-01.dmp
==================== One Month Modified Files and Folders =======
2013-11-05 15:08 - 2011-07-04 07:50 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-05 15:03 - 2009-07-14 05:34 - 00015568 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-05 15:03 - 2009-07-14 05:34 - 00015568 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-05 15:00 - 2013-11-05 15:00 - 00000000 ____D C:\FRST
2013-11-05 14:59 - 2013-11-05 15:01 - 01089445 _____ (Farbar) C:\Users\Sofia\Desktop\FRST.exe
2013-11-05 14:56 - 2012-04-20 17:54 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-11-05 14:54 - 2010-06-27 21:06 - 01968612 _____ C:\windows\WindowsUpdate.log
2013-11-05 14:52 - 2010-06-27 21:20 - 12777529 _____ C:\FaceProv.log
2013-11-05 14:22 - 2010-05-01 06:13 - 01507342 _____ C:\windows\system32\PerfStringBackup.INI
2013-11-05 14:15 - 2011-07-04 07:50 - 00001102 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-05 14:15 - 2010-10-24 22:44 - 00000000 ____D C:\Users\Sofia\Tracing
2013-11-05 14:15 - 2010-06-27 21:18 - 00000000 ____D C:\ProgramData\VeriFace
2013-11-05 14:14 - 2010-05-01 06:24 - 00950684 _____ C:\windows\PFRO.log
2013-11-05 14:14 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-11-05 14:14 - 2009-07-14 05:39 - 00135944 _____ C:\windows\setupact.log
2013-11-04 22:10 - 2012-01-04 16:46 - 00001158 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3574326216-3019278211-3624931514-1001UA.job
2013-11-04 21:40 - 2013-11-04 21:40 - 00000000 ____D C:\Users\Sofia\AppData\Roaming\Avira
2013-11-04 21:33 - 2013-11-04 21:33 - 00002016 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-11-04 21:31 - 2013-11-04 21:31 - 00000000 ____D C:\ProgramData\Avira
2013-11-04 21:31 - 2013-11-04 21:31 - 00000000 ____D C:\Program Files\Avira
2013-11-04 14:50 - 2013-11-04 14:50 - 00135216 _____ C:\windows\Minidump\110413-26676-01.dmp
2013-11-04 14:50 - 2013-10-07 19:46 - 00000000 ____D C:\windows\Minidump
2013-11-04 14:49 - 2013-10-07 19:46 - 117439708 _____ C:\windows\MEMORY.DMP
2013-11-04 13:18 - 2012-01-04 16:46 - 00001136 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3574326216-3019278211-3624931514-1001Core.job
2013-11-04 13:17 - 2010-10-18 11:13 - 00000000 ____D C:\Users\Sofia\AppData\Roaming\Skype
2013-10-15 12:58 - 2009-07-14 03:37 - 00000000 ____D C:\windows\rescache
2013-10-15 12:14 - 2009-07-14 03:37 - 00000000 ____D C:\windows\Microsoft.NET
2013-10-15 08:08 - 2009-07-14 05:33 - 00431504 _____ C:\windows\system32\FNTCACHE.DAT
2013-10-15 07:52 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\de-DE
2013-10-15 07:42 - 2010-05-01 06:33 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-14 20:27 - 2010-10-18 11:19 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-14 20:25 - 2013-08-17 10:50 - 00000000 ____D C:\windows\system32\MRT
2013-10-14 20:12 - 2010-10-26 14:00 - 78106760 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-10-14 08:56 - 2012-04-20 17:54 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2013-10-14 08:56 - 2011-05-19 00:23 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-14 08:13 - 2013-09-01 11:37 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-10 19:14 - 2013-11-04 21:33 - 00028520 _____ (Avira GmbH) C:\windows\system32\Drivers\ssmdrv.sys
2013-10-10 19:14 - 2013-11-04 21:31 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2013-10-10 19:14 - 2013-11-04 21:31 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2013-10-10 19:14 - 2013-11-04 21:31 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2013-10-10 19:14 - 2013-11-04 21:31 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2013-10-08 04:57 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\LogFiles
2013-10-07 19:46 - 2013-10-07 19:46 - 00135272 _____ C:\windows\Minidump\100713-28470-01.dmp
Some content of TEMP:
====================
C:\Users\Gast\AppData\Local\Temp\AskSLib.dll
C:\Users\Sofia\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-04 23:48
==================== End Of Log ============================ Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 31-10-2013
Ran by Sofia at 2013-11-05 15:10:56
Running from C:\Users\Sofia \Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Update for Microsoft Office 2007 (KB2508958)
7-Zip 9.20
Adobe AIR (Version: 3.2.0.2070)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05)
ALPS Touch Pad Driver
Avanquest update (Version: 1.29)
Avira Free Antivirus (Version: 14.0.0.411)
Broadcom Gigabit Integrated Controller (Version: 12.24.02)
Conexant HD Audio (Version: 4.119.0.60)
D3DX10 (Version: 15.4.2368.0902)
EasyBits GO
EasyCapture (Version: V4.0.09.1015)
Energy Management (Version: 4.3.1.5)
Facebook Video Calling 1.2.0.287 (Version: 1.2.287)
Free YouTube to MP3 Converter version 3.11.35.1031 (Version: 3.11.35.1031)
GMX SMS-Manager
Google Chrome (Version: 30.0.1599.69)
Google Update Helper (Version: 1.3.21.165)
Intel® Matrix Storage Manager
Java Auto Updater (Version: 2.0.3.1)
Java(TM) 6 Update 24 (Version: 6.0.240)
Junk Mail filter update (Version: 15.4.3502.0922)
Lenovo Bluetooth with Enhanced Data Rate Software (Version: 6.2.1.100)
Lenovo EasyCamera (Version: 5.8.0.12)
Lenovo OneKey Recovery (Version: 7.0.0723)
Lenovo ReadyComm 5 (Version: 5.1.1.20)
Lenovo ReadyComm 5.0 Service (Version: 5.0.0.1)
Mesh Runtime (Version: 15.4.5722.2)
Messenger Companion (Version: 15.4.3502.0922)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
MobileMe Control Panel (Version: 3.1.5.0)
Mozilla Firefox 24.0 (x86 de) (Version: 24.0)
Mozilla Maintenance Service (Version: 24.0)
MSVCRT (Version: 15.4.2862.0708)
MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
NVIDIA Drivers (Version: 1.10.57.35)
PC-Doctor für Windows (Version: 6.0.5426.03)
PDF Architect (Version: 1.0.52.8917)
PDFCreator (Version: 1.6.2)
PhotoScape
Power2Go (Version: 5.6.0.4809d4)
Project64 1.6 (Version: 1.6)
Realtek USB 2.0 Card Reader (Version: 6.1.7600.30101)
Samsung Kies (Version: 2.6.0.13064_2)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0)
Skype Click to Call (Version: 5.9.9216)
Skype™ 6.1 (Version: 6.1.129)
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
Uninstall 1.0.0.1
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update für Microsoft Office Excel 2007 Help (KB963678)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)
Update für Microsoft Office Word 2007 Help (KB963665)
VeriFace (Version: 3.6.0.0921)
VLC media player 1.1.8 (Version: 1.1.8)
Windows Driver Package - Broadcom Bluetooth (06/15/2009 6.2.0.9000) (Version: 06/15/2009 6.2.0.9000)
Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405) (Version: 07/30/2009 6.2.0.9405)
Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (Version: 07/28/2009 6.2.0.9800)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3538.0513)
Windows Live Family Safety (Version: 15.4.3538.0513)
Windows Live Fotogalerie (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live Sync (Version: 14.0.8089.726)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
WinZip 17.5 (Version: 17.5.10480)
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {22A43DB9-4816-4AF4-ACAA-C3FC9E6A20CD} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3574326216-3019278211-3624931514-1001UA => C:\Users\Sofia\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {22A4D017-D8A6-4D4B-9736-97F9882FAAE7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-07-04] (Google Inc.)
Task: {46A89D9A-3BAE-4B84-9491-6FBB910306DE} - System32\Tasks\{7034CB95-0146-4D7D-9F62-C81D173D992A} => C:\Program Files\Skype\\Phone\Skype.exe [2013-07-25] (Skype Technologies S.A.)
Task: {683DA3F7-643C-4530-BD3C-5EF6A61EA501} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3574326216-3019278211-3624931514-1001Core => C:\Users\Sofia\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {71C9A08D-B9AB-4559-9984-689793EF6A9B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-07-04] (Google Inc.)
Task: {8FED5079-C4F1-4D12-A2E0-6F9651A97173} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {B0FD917F-7FD4-49EE-B881-EFA5677531E2} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: {CA1A389C-C8D3-49E9-A490-30AC647700F6} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
Task: {EACBCBEE-F47C-46B8-A51C-27C5CB1C215C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-14] (Adobe Systems Incorporated)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3574326216-3019278211-3624931514-1001Core.job => C:\Users\Sofia\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3574326216-3019278211-3624931514-1001UA.job => C:\Users\Sofia\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2010-06-27 21:18 - 2010-06-27 21:18 - 01410312 _____ () C:\windows\system32\IcnOvrly.dll
2010-06-27 21:18 - 2010-06-27 21:18 - 00492808 _____ () C:\Program Files\Lenovo\VeriFace\ChooseLang.dll
2010-06-27 21:19 - 2008-12-20 04:20 - 00063304 _____ () C:\Program Files\Lenovo\Energy Management\kbdhook.dll
2010-06-27 21:19 - 2008-12-20 04:20 - 00051016 _____ () C:\Program Files\Lenovo\Energy Management\HookLib.dll
2010-06-27 21:17 - 2009-06-05 17:36 - 00217088 _____ () C:\windows\system32\370prop.ax
2013-08-17 11:38 - 2013-08-17 11:38 - 01895936 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\8e923d3ad06fd5f042d8bf66c432a0e2\Kies.UI.ni.dll
2013-08-17 11:38 - 2013-08-17 11:38 - 00079360 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\8160bb2b834c56f38342d119cb276cb8\Kies.MVVM.ni.dll
2013-08-17 11:38 - 2013-08-17 11:38 - 00188416 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\3ee49e4ecf5b649fddeb15e8ed69e71c\Kies.Common.DeviceServiceLib.Interface.ni.dll
2013-08-17 11:39 - 2013-08-17 11:39 - 00361984 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\DevicePhoto\ad607c611b411a59ddd357685c224eb2\DevicePhoto.ni.dll
2013-08-17 11:39 - 2013-08-17 11:39 - 00295936 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\DeviceVideo\7bec0c9678a83c4d0c9a1d9f54c41b2b\DeviceVideo.ni.dll
2013-08-17 11:39 - 2013-08-17 11:39 - 00612352 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\DevicePodcast\5da3433009e8c14e4ff1fd233b89f340\DevicePodcast.ni.dll
2013-08-17 11:39 - 2013-08-17 11:39 - 00307200 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\DummyStorePlugin\d33dd7ce4386cbc558e02327ef82a8f3\DummyStorePlugin.ni.dll
2013-08-17 11:39 - 2013-08-17 11:39 - 17281024 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\151393cf59146e4909888dd1f3d7002c\Kies.Theme.ni.dll
2013-08-17 11:39 - 2013-08-17 11:39 - 00582144 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\82ae0031f6ca5ac17aaed462ce7fd45e\Kies.Common.DeviceServiceLib.FileService.ni.dll
2013-07-20 18:48 - 2013-07-20 18:48 - 00046592 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\9011c20bd063214159d84d624c0687de\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.ni.dll
2013-08-17 11:39 - 2013-08-17 11:39 - 00998912 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\DeviceCommonLib\2fcfc8b9d4bca4635c9b71eb325c810a\DeviceCommonLib.ni.dll
2013-08-17 11:39 - 2013-08-17 11:39 - 00232960 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\6c2268d21092027249488bb1b5b0b75f\ASF_cSharpAPI.ni.dll
2009-08-11 17:10 - 2009-08-11 17:10 - 00132384 _____ () C:\Program Files\Lenovo\Bluetooth Software\btkeyind.dll
2013-10-01 19:17 - 2013-10-01 19:17 - 03279768 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Faulty Device Manager Devices =============
Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/05/2013 03:08:42 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.2.183.21, Zeitstempel: 0x4b95e661
Name des fehlerhaften Moduls: goopdate.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x5238b7bc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x733c3feb
ID des fehlerhaften Prozesses: 0x13d8
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3
Error: (11/05/2013 02:52:57 PM) (Source: Application Hang) (User: )
Description: Programm msert(1).exe, Version 1.161.1458.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: ba8
Startzeit: 01ceda2afa16225d
Endzeit: 20
Anwendungspfad: D:\Downloads\msert(1).exe
Berichts-ID:
Error: (11/05/2013 02:22:23 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
Error: (11/05/2013 02:15:24 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.2.183.21, Zeitstempel: 0x4b95e661
Name des fehlerhaften Moduls: goopdate.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x5238b7bc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x70a33feb
ID des fehlerhaften Prozesses: 0xb0c
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3
Error: (11/04/2013 10:09:43 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.2.183.21, Zeitstempel: 0x4b95e661
Name des fehlerhaften Moduls: goopdate.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x5238b7bc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x6d543feb
ID des fehlerhaften Prozesses: 0xd28
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3
Error: (11/04/2013 09:04:20 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.2.183.21, Zeitstempel: 0x4b95e661
Name des fehlerhaften Moduls: goopdate.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x5238b7bc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x726a3feb
ID des fehlerhaften Prozesses: 0x149c
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3
Error: (11/04/2013 08:04:21 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.2.183.21, Zeitstempel: 0x4b95e661
Name des fehlerhaften Moduls: goopdate.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x5238b7bc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x67523feb
ID des fehlerhaften Prozesses: 0x1488
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3
Error: (11/04/2013 07:34:23 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/04/2013 07:31:42 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (11/04/2013 07:04:41 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.2.183.21, Zeitstempel: 0x4b95e661
Name des fehlerhaften Moduls: goopdate.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x5238b7bc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x6ed73feb
ID des fehlerhaften Prozesses: 0x1410
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3
System errors:
=============
Error: (11/05/2013 02:19:46 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst eventlog erreicht.
Error: (11/05/2013 02:19:15 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (11/05/2013 02:19:15 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Player-Netzwerkfreigabedienst erreicht.
Error: (11/05/2013 02:18:42 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (11/05/2013 02:18:42 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Google Update-Dienst (gupdate) erreicht.
Error: (11/05/2013 02:17:18 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden aufgrund eines E/A-Fehlers auf Volume "C:" abgebrochen.
Error: (11/05/2013 02:16:52 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: Fehler bei der CBS-Clientinitialisierung. Letzter Fehler: 0x8007041d
Error: (11/05/2013 02:16:51 PM) (Source: DCOM) (User: )
Description: 1053TrustedInstaller{752073A1-23F2-4396-85F0-8FDB879ED0ED}
Error: (11/05/2013 02:16:51 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Modules Installer" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (11/05/2013 02:16:51 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Modules Installer erreicht.
Microsoft Office Sessions:
=========================
Error: (03/16/2012 10:58:12 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 45924 seconds with 1380 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Percentage of memory in use: 39%
Total physical RAM: 3036.6 MB
Available physical RAM: 1848.01 MB
Total Pagefile: 6071.49 MB
Available Pagefile: 4503.16 MB
Total Virtual: 2047.88 MB
Available Virtual: 1905.22 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:252.89 GB) (Free:155.99 GB) NTFS
Drive d: (Lenovo) (Fixed) (Total:30.25 GB) (Free:16.57 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 4E841145)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=253 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=30 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=15 GB) - (Type=12)
==================== End Of Log ============================ Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-11-05 15:51:44
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST932032 rev.0010 298,09GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\SOFIAT~1\AppData\Local\Temp\ugtoruod.sys
---- System - GMER 2.1 ----
SSDT 90F01076 ZwCreateSection
SSDT 90F01080 ZwRequestWaitReplyPort
SSDT 90F0107B ZwSetContextThread
SSDT 90F01085 ZwSetSecurityObject
SSDT 90F0108A ZwSystemDebugControl
SSDT 90F01017 ZwTerminateProcess
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 83441A15 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8347B212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 8348258C 4 Bytes [76, 10, F0, 90] {JBE 0x12; NOP }
.text ntkrnlpa.exe!KeRemoveQueueEx + 1553 834828E8 4 Bytes [80, 10, F0, 90] {ADC BYTE [EAX], 0xf0; NOP }
.text ntkrnlpa.exe!KeRemoveQueueEx + 1597 8348292C 4 Bytes [7B, 10, F0, 90] {JNP 0x12; NOP }
.text ntkrnlpa.exe!KeRemoveQueueEx + 1613 834829A8 4 Bytes [85, 10, F0, 90] {TEST [EAX], EDX; NOP }
.text ntkrnlpa.exe!KeRemoveQueueEx + 1667 834829FC 4 Bytes [8A, 10, F0, 90] {MOV DL, [EAX]; NOP }
.text ...
? System32\Drivers\spjg.sys Das System kann den angegebenen Pfad nicht finden. !
---- Devices - GMER 2.1 ----
Device \FileSystem\Ntfs \Ntfs 86A181F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{B4AF099B-1A43-49EF-B0CC-DFFA615CE58D} 878991F8
Device \Driver\volmgr \Device\VolMgrControl 85D471F8
---- Trace I/O - GMER 2.1 ----
Trace ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spjg.sys halmacpi.dll >>UNKNOWN [0x85d1e938]<< 85d1e938
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8751e5b8] 8751e5b8
Trace 3 CLASSPNP.SYS[8bfac59e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x86a74028] 86a74028
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269ec2d88
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f07bcbdc471f
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f07bcbdc471f@0c6076e059f0 0x92 0xDB 0x30 0x3F ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f07bcbdc471f@0023f1a43494 0x5A 0x16 0x87 0x2B ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f07bcbdc471f@0023f1a3de6f 0x53 0x9B 0xEE 0x5B ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f07bcbdc471f@d8b377612c63 0xBF 0xA8 0x42 0x1C ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f07bcbdc471f@001963ebb95a 0xAA 0xFC 0x8A 0x59 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x17 0x48 0x93 0xAF ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002269ec2d88 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f07bcbdc471f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f07bcbdc471f@0c6076e059f0 0x92 0xDB 0x30 0x3F ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f07bcbdc471f@0023f1a43494 0x5A 0x16 0x87 0x2B ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f07bcbdc471f@0023f1a3de6f 0x53 0x9B 0xEE 0x5B ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f07bcbdc471f@d8b377612c63 0xBF 0xA8 0x42 0x1C ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f07bcbdc471f@001963ebb95a 0xAA 0xFC 0x8A 0x59 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x17 0x48 0x93 0xAF ...
---- EOF - GMER 2.1 ----
Danke schonmal;) |