fornoville | 29.11.2013 08:33 | alles klar, hier noch mal die log files eingebedded im thread! Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 19:10 on 28/11/2013 (Tim)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-11-2013
Ran by Tim (administrator) on TIM-PC on 28-11-2013 20:13:07
Running from C:\Users\Tim\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(Adobe Systems Incorporated) C:\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
(Microsoft Corporation) C:\Program Files\Windows Home Server\esClient.exe
(STRATO) C:\Program Files (x86)\STRATO AG\STRATO HiDrive\STRATO HiDrive Service.exe
(GlavSoft LLC.) C:\Program Files\TightVNC\tvnserver.exe
(VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Windows Home Server\Microsoft.HomeServer.Archive.TransferService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Microsoft Corporation) C:\Program Files\Windows Home Server\WHSConnector.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(GlavSoft LLC.) C:\Program Files\TightVNC\tvnserver.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraMD.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
() C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIIVE.EXE
(Microsoft Corporation) C:\Program Files\Windows Home Server\WHSTrayApp.exe
() C:\Program Files (x86)\teraterm\Collector\Collector.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\hqtray.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Power Software Ltd) C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Adobe Sytems Incorporated) C:\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\FRITZWLANMini.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(STRATO) C:\Program Files (x86)\STRATO AG\STRATO HiDrive\STRATO HiDrive.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraMD64.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(Farbar) C:\Users\Tim\Desktop\FRST64(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [tvncontrol] - C:\Program Files\TightVNC\tvnserver.exe [1633296 2012-04-26] (GlavSoft LLC.)
HKCU\...\Run: [HydraVisionMDEngine] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraMD.exe [569344 2010-05-04] (AMD)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [960440 2012-08-07] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-08-07] ()
HKCU\...\Run: [LogMeTT.exe] - C:\Program Files (x86)\LogMeTT\LogMeTT.exe [371712 2011-09-30] (LogMeTT.com)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)
HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_YATIIVE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION)
HKCU\...\Run: [Comrade.exe] - C:\Program Files (x86)\GameSpy\Comrade\Comrade.exe
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_117_Plugin.exe -update plugin [829832 2013-10-10] (Adobe Systems Incorporated)
HKCU\...\Policies\system: [LogonHoursAction] 2
HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
MountPoints2: {7d8bdafb-9a3f-11e1-9d17-97848db2fd69} - E:\pushinst.exe
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2441840 2010-06-25] (VIA)
HKLM-x32\...\Run: [VMware hqtray] - C:\Program Files (x86)\VMware\VMware Player\hqtray.exe [64112 2010-11-11] (VMware, Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-08-07] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [PWRISOVM.EXE] - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [336992 2012-08-24] (Power Software Ltd)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [Adobe Version Cue CS2] - C:\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe [856064 2005-04-06] (Adobe Sytems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\FRITZWLANMini.exe [933888 2012-08-24] (AVM Berlin)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\Spielen\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_YATIIVE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION)
HKU\Spielen\...\Policies\system: [LogonHoursAction] 2
HKU\Spielen\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
AppInit_DLLs: [ ] ()
Startup: C:\Users\Spielen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Collector.lnk
ShortcutTarget: Collector.lnk -> C:\Program Files (x86)\teraterm\Collector\Collector.exe ()
Startup: C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\start WampServer.lnk
ShortcutTarget: start WampServer.lnk -> C:\wamp\wampmanager.exe (Aestan Software)
Startup: C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\STRATO HiDrive.lnk
ShortcutTarget: STRATO HiDrive.lnk -> C:\Program Files (x86)\STRATO AG\STRATO HiDrive\STRATO HiDrive.exe (STRATO)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9CA5222CAD60CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - DefaultScope {934BDC85-8477-49DC-9C1A-045BF2109EC1} URL = hxxp://search.ividi.org/?q={searchTerms}&src=tbsp&id=9c6c1797000000000000bc05430be6ca&affilt=3&r=483
SearchScopes: HKCU - {934BDC85-8477-49DC-9C1A-045BF2109EC1} URL = hxxp://search.ividi.org/?q={searchTerms}&src=tbsp&id=9c6c1797000000000000bc05430be6ca&affilt=3&r=483
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: BrowserHelper Class - {9A065C65-4EE7-4DDD-9918-F129089A894A} - C:\Program Files\Windows Home Server\WHSDeskBands.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Home Server Banner - {D73E76A3-F902-45BD-8FC8-95AE8E014671} - C:\Program Files\Windows Home Server\WHSDeskBands.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog9 11 C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll [346736] (VMware, Inc.)
Winsock: Catalog9 12 C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll [346736] (VMware, Inc.)
Winsock: Catalog9-x64 11 C:\Program Files (x86)\VMware\VMware Player\x64\vsocklib.dll [446576] (VMware, Inc.)
Winsock: Catalog9-x64 12 C:\Program Files (x86)\VMware\VMware Player\x64\vsocklib.dll [446576] (VMware, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.123.2
FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6fa9ufrw.default
FF SearchEngineOrder.1: Search
FF Homepage: hxxp://www.google.de/
FF Keyword.URL: hxxp://search.ividi.org/?src=tbsp&id=9c6c1797000000000000bc05430be6ca&affilt=3&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=1.1.11 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6fa9ufrw.default\searchplugins\ividi.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Wörterbuch Deutsch (de-DE), Hunspell-unterstützt - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6fa9ufrw.default\Extensions\de_DE@dicts.j3e.de
FF Extension: iVIDI - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6fa9ufrw.default\Extensions\ffxtlbr@ividi.com
FF Extension: EPUBReader - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6fa9ufrw.default\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
FF Extension: firefox - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6fa9ufrw.default\Extensions\firefox@bomlabio.biz.xpi
FF Extension: Adblock Plus - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6fa9ufrw.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Microsoft Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Foxit Reader Plugin for Mozilla) - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (VLC Multimedia Plug-in) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.70.10) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (Google Drive) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Gangnam Style Game) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdbdhcafljkcahgefanhpdahdnpfkaok\1.0.0_0
CHR Extension: (Apple Shooter) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbcjjgkapdombcilbfbjapkbpnocbkcf\2.0.0_0
CHR Extension: (3D Bowling ) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gemohgpikgjbgmdfbfjdailocichgbjm\2.0_0
CHR Extension: (Cut the Rope) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkddaofiamhgfjmaccfcfpfolpgbeomj\15_0
CHR Extension: (iVidi Chrome Toolbar) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef\1.0_1
CHR Extension: (Temple Run 2 Online ) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\mminkcbambeahjkfpfngeffkdepojjnb\1.1_0
CHR Extension: (3D Parking) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\npgjnhabcgahcfdembgboapbefikbmld\1.0_0
CHR Extension: (Gmail) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [kpdhgpkkloealnjnmepfhanpcleldbef] - C:\Program Files (x86)\Unitech LLC\ividi\1.8.23.0\ividi.crx
CHR HKLM-x32\...\Chrome\Extension: [ljidjdddaoiogpbmniipclcppkoembao] - C:\Program Files (x86)\bomlabio\ljidjdddaoiogpbmniipclcppkoembao.crx
==================== Services (Whitelisted) =================
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-10] (Adobe Systems)
R2 Adobe Version Cue CS2; c:\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe [163840 2005-04-06] (Adobe Systems Incorporated)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 arXfrSvc; C:\Program Files\Windows Home Server\Microsoft.HomeServer.Archive.TransferService.exe [231280 2011-01-10] (Microsoft Corporation)
R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [224256 2011-03-02] ()
S2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 esClient; C:\Program Files\Windows Home Server\esClient.exe [109936 2011-01-10] (Microsoft Corporation)
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [36352 2010-11-08] ()
R2 STRATO HiDrive Service; C:\Program Files (x86)\STRATO AG\STRATO HiDrive\STRATO HiDrive Service.exe [32768 2011-11-15] (STRATO)
R2 tvnserver; C:\Program Files\TightVNC\tvnserver.exe [1633296 2012-04-26] (GlavSoft LLC.)
S3 ufad-ws60; C:\Program Files (x86)\VMware\VMware Player\vmware-ufad.exe [191024 2010-08-19] (VMware, Inc.)
S3 wampapache; c:\wamp\bin\apache\apache2.2.21\bin\httpd.exe [18432 2011-09-26] (Apache Software Foundation)
S3 wampmysqld; c:\wamp\bin\mysql\mysql5.5.16\bin\mysqld.exe [8158720 2011-09-26] ()
R2 WHSConnector; C:\Program Files\Windows Home Server\WHSConnector.exe [489840 2011-01-10] (Microsoft Corporation)
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]
==================== Drivers (Whitelisted) ====================
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106904 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-04] (AVM Berlin)
R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-04] (AVM GmbH)
S3 jlink; C:\Windows\System32\Drivers\jlinkx64.sys [24448 2007-07-11] (SEGGER Microcontroller Systeme GmbH)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] ()
S3 tap0801; C:\Windows\System32\DRIVERS\tap0801.sys [30720 2005-04-13] (The OpenVPN Project)
R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [30832 2010-11-11] (VMware, Inc.)
R2 vstor2-ws60; C:\Program Files (x86)\VMware\VMware Player\vstor2-ws60.sys [32816 2010-08-19] (VMware, Inc.)
S3 ALSysIO; \??\C:\Users\Tim\AppData\Local\Temp\ALSysIO64.sys [x]
R3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\WNt500x64\Sandra.sys [x]
U3 uwldipow; \??\C:\Users\Tim\AppData\Local\Temp\uwldipow.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-28 20:10 - 2013-11-28 20:10 - 00001153 _____ C:\Users\Tim\Desktop\gmer.txt
2013-11-28 19:18 - 2013-11-28 19:18 - 00377856 _____ C:\Users\Tim\Desktop\6m9r7gc7.exe
2013-11-28 19:12 - 2013-11-28 20:14 - 00021753 _____ C:\Users\Tim\Desktop\FRST.txt
2013-11-28 19:11 - 2013-11-28 19:11 - 01959024 _____ (Farbar) C:\Users\Tim\Desktop\FRST64(1).exe
2013-11-28 19:10 - 2013-11-28 19:10 - 00000468 _____ C:\Users\Tim\Desktop\defogger_disable.log
2013-11-28 19:10 - 2013-11-28 19:10 - 00000000 _____ C:\Users\Tim\defogger_reenable
2013-11-28 19:09 - 2013-11-28 19:09 - 00050477 _____ C:\Users\Tim\Desktop\Defogger.exe
2013-11-28 17:36 - 2013-11-28 17:36 - 00000000 _____ C:\autoexec.bat
2013-11-28 17:34 - 2013-11-28 17:34 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-11-28 17:33 - 2013-11-28 19:03 - 00000000 ____D C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-11-28 17:31 - 2013-11-28 17:31 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Tim\Downloads\SpyHunter-Installer.exe
2013-11-24 12:29 - 2013-11-24 12:29 - 00000000 ____D C:\Users\Tim\AppData\Local\Foxit Reader
2013-11-20 16:29 - 2013-11-20 16:29 - 00000891 _____ C:\Users\Spielen\Desktop\SERVER - Verknüpfung.lnk
2013-11-20 16:23 - 2013-11-20 16:24 - 08266114 _____ C:\Users\Spielen\Downloads\Deine Mutter Song Lyrics.avi
2013-11-19 17:44 - 2013-11-19 17:44 - 00000021 _____ C:\Windows\S.dirmngr
2013-11-19 12:31 - 2013-11-19 12:31 - 00002054 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2013-11-17 03:08 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-17 03:08 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-17 03:08 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-17 03:08 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-17 03:08 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-17 03:08 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-17 03:08 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-17 03:08 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-17 03:08 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-17 03:08 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-17 03:08 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-17 03:08 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-17 03:08 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-17 03:08 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-17 03:08 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-17 03:08 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-17 03:08 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-17 03:08 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-17 03:08 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-17 03:08 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-17 03:08 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-16 04:14 - 2013-11-16 04:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-15 10:38 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-15 10:38 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-15 10:38 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-15 10:38 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-15 10:38 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-15 10:38 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-15 10:38 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-15 10:38 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-15 10:38 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-15 10:38 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-15 10:38 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-15 10:38 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-15 10:38 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-15 10:38 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-15 10:38 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-15 10:38 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-15 10:38 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-15 10:38 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-15 10:38 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-15 10:38 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-15 10:38 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-15 10:38 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-15 10:38 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-15 10:38 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-15 10:38 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-15 10:38 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-15 10:38 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-15 10:38 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-15 10:38 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-15 10:38 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-12 15:32 - 2013-11-12 15:32 - 00000000 ____D C:\Users\Spielen\Downloads\Moderne Stadt
2013-11-12 15:31 - 2013-11-12 15:32 - 10560375 _____ C:\Users\Spielen\Downloads\Moderne Stadt.zip
2013-11-11 16:04 - 2013-11-11 16:04 - 02300919 _____ () C:\Users\Spielen\Downloads\TechnicLauncher (1).exe
2013-11-06 12:33 - 2013-11-06 12:33 - 00000000 ____D C:\Users\Spielen\AppData\Roaming\Malwarebytes
2013-11-05 16:13 - 2013-11-05 16:13 - 00018605 _____ C:\Users\Spielen\Downloads\Script Film 7A.odt
2013-11-05 14:00 - 2013-11-05 14:00 - 00001112 _____ C:\Users\Tim\Desktop\JRT.txt
2013-11-05 13:55 - 2013-11-05 13:55 - 00000000 ____D C:\Windows\ERUNT
2013-11-05 13:43 - 2013-11-05 13:46 - 00000000 ____D C:\AdwCleaner
2013-11-05 13:25 - 2013-11-05 13:25 - 00052703 _____ C:\Users\Tim\Downloads\FRST.txt
2013-11-05 13:24 - 2013-11-05 13:25 - 00030443 _____ C:\Users\Tim\Downloads\Addition.txt
2013-11-05 13:24 - 2013-11-05 13:24 - 01073258 _____ C:\Users\Tim\Downloads\adwcleaner.exe
2013-11-05 13:24 - 2013-11-05 13:24 - 01033335 _____ (Thisisu) C:\Users\Tim\Downloads\JRT.exe
2013-11-05 13:23 - 2013-11-05 13:23 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tim\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-05 13:21 - 2013-11-05 13:21 - 01957098 _____ (Farbar) C:\Users\Tim\Downloads\FRST64.exe
2013-11-05 13:21 - 2013-11-05 13:21 - 00000000 ____D C:\FRST
2013-11-03 11:45 - 2013-11-03 11:45 - 00275544 _____ C:\Windows\Minidump\110313-28111-01.dmp
2013-10-31 11:56 - 2013-10-31 11:57 - 00000000 ____D C:\Program Files (x86)\Minecraft
2013-10-31 11:56 - 2013-10-31 11:56 - 00001988 _____ C:\Users\Tim\Desktop\Minecraft.lnk
2013-10-31 11:56 - 2013-10-31 11:56 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2013-10-31 11:48 - 2013-10-31 11:48 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Unitech LLC
2013-10-31 11:48 - 2013-10-31 11:48 - 00000000 ____D C:\Program Files (x86)\Unitech LLC
2013-10-31 11:48 - 2013-10-31 11:48 - 00000000 ____D C:\Program Files (x86)\iVIDI.org plugin
==================== One Month Modified Files and Folders =======
2013-11-28 20:14 - 2013-11-28 19:12 - 00021753 _____ C:\Users\Tim\Desktop\FRST.txt
2013-11-28 20:10 - 2013-11-28 20:10 - 00001153 _____ C:\Users\Tim\Desktop\gmer.txt
2013-11-28 20:08 - 2011-02-16 12:40 - 01257925 _____ C:\Windows\WindowsUpdate.log
2013-11-28 19:37 - 2012-12-14 18:04 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-28 19:19 - 2012-04-08 11:57 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-28 19:18 - 2013-11-28 19:18 - 00377856 _____ C:\Users\Tim\Desktop\6m9r7gc7.exe
2013-11-28 19:11 - 2013-11-28 19:11 - 01959024 _____ (Farbar) C:\Users\Tim\Desktop\FRST64(1).exe
2013-11-28 19:10 - 2013-11-28 19:10 - 00000468 _____ C:\Users\Tim\Desktop\defogger_disable.log
2013-11-28 19:10 - 2013-11-28 19:10 - 00000000 _____ C:\Users\Tim\defogger_reenable
2013-11-28 19:10 - 2011-02-16 12:56 - 00000000 ____D C:\Users\Tim
2013-11-28 19:09 - 2013-11-28 19:09 - 00050477 _____ C:\Users\Tim\Desktop\Defogger.exe
2013-11-28 19:03 - 2013-11-28 17:33 - 00000000 ____D C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-11-28 17:57 - 2013-08-16 19:13 - 00002985 _____ C:\Users\Spielen\Desktop\IrfanView Thumbnails.lnk
2013-11-28 17:36 - 2013-11-28 17:36 - 00000000 _____ C:\autoexec.bat
2013-11-28 17:34 - 2013-11-28 17:34 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-11-28 17:31 - 2013-11-28 17:31 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Tim\Downloads\SpyHunter-Installer.exe
2013-11-28 17:27 - 2012-05-04 12:56 - 00000000 ____D C:\Users\Tim\AppData\Roaming\FileZilla
2013-11-28 16:51 - 2011-02-16 20:55 - 00000000 ____D C:\eclipse
2013-11-28 16:42 - 2013-03-09 11:57 - 00000000 ____D C:\Users\Spielen\AppData\Local\TSVNCache
2013-11-28 16:06 - 2013-09-17 16:24 - 00000000 ____D C:\Users\Spielen\AppData\Roaming\.minecraft
2013-11-28 15:53 - 2012-12-14 18:04 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-28 15:47 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-11-24 12:29 - 2013-11-24 12:29 - 00000000 ____D C:\Users\Tim\AppData\Local\Foxit Reader
2013-11-23 11:34 - 2009-07-14 05:45 - 00014640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-23 11:34 - 2009-07-14 05:45 - 00014640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-21 10:39 - 2013-03-16 12:49 - 00000000 ____D C:\Program Files (x86)\Steam
2013-11-21 10:39 - 2011-02-23 20:55 - 00000000 ____D C:\Users\Tim\AppData\Local\TSVNCache
2013-11-20 16:29 - 2013-11-20 16:29 - 00000891 _____ C:\Users\Spielen\Desktop\SERVER - Verknüpfung.lnk
2013-11-20 16:24 - 2013-11-20 16:23 - 08266114 _____ C:\Users\Spielen\Downloads\Deine Mutter Song Lyrics.avi
2013-11-20 16:24 - 2009-07-14 18:58 - 00665294 _____ C:\Windows\system32\perfh007.dat
2013-11-20 16:24 - 2009-07-14 18:58 - 00135156 _____ C:\Windows\system32\perfc007.dat
2013-11-20 16:24 - 2009-07-14 06:13 - 01530332 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-20 16:21 - 2009-07-14 05:51 - 00065274 _____ C:\Windows\setupact.log
2013-11-19 17:45 - 2011-02-25 17:19 - 00000000 ____D C:\ProgramData\VMware
2013-11-19 17:44 - 2013-11-19 17:44 - 00000021 _____ C:\Windows\S.dirmngr
2013-11-19 17:44 - 2012-05-03 17:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-19 17:44 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-19 16:04 - 2013-10-10 15:29 - 00000000 ____D C:\Users\Spielen\AppData\Roaming\Foxit Software
2013-11-19 15:04 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-11-19 12:32 - 2013-05-06 12:56 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-11-19 12:32 - 2013-04-02 09:20 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-19 12:32 - 2013-04-02 09:20 - 00106904 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-11-19 12:32 - 2013-04-02 09:20 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-11-19 12:32 - 2011-09-06 14:44 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Foxit Software
2013-11-19 12:31 - 2013-11-19 12:31 - 00002054 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2013-11-17 04:07 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-17 03:16 - 2012-02-26 08:34 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Skype
2013-11-17 03:07 - 2013-07-31 02:05 - 00000000 ____D C:\Windows\system32\MRT
2013-11-17 03:04 - 2011-02-16 16:04 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-16 10:33 - 2012-12-14 18:06 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-16 04:16 - 2013-11-16 04:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-15 11:08 - 2013-04-12 17:10 - 00000000 ____D C:\Users\Spielen\Documents\OPENOFFICE Dokumente
2013-11-13 20:25 - 2013-02-25 10:40 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-11-13 20:25 - 2012-02-26 08:34 - 00000000 ____D C:\ProgramData\Skype
2013-11-12 15:32 - 2013-11-12 15:32 - 00000000 ____D C:\Users\Spielen\Downloads\Moderne Stadt
2013-11-12 15:32 - 2013-11-12 15:31 - 10560375 _____ C:\Users\Spielen\Downloads\Moderne Stadt.zip
2013-11-11 16:09 - 2013-09-25 15:30 - 00000000 ____D C:\Users\Spielen\AppData\Roaming\.technic
2013-11-11 16:04 - 2013-11-11 16:04 - 02300919 _____ () C:\Users\Spielen\Downloads\TechnicLauncher (1).exe
2013-11-10 13:50 - 2012-04-22 05:33 - 00000000 ____D C:\ProgramData\Sonos,_Inc
2013-11-09 11:32 - 2011-02-16 13:57 - 00213876 _____ C:\Windows\PFRO.log
2013-11-06 12:33 - 2013-11-06 12:33 - 00000000 ____D C:\Users\Spielen\AppData\Roaming\Malwarebytes
2013-11-05 16:13 - 2013-11-05 16:13 - 00018605 _____ C:\Users\Spielen\Downloads\Script Film 7A.odt
2013-11-05 14:00 - 2013-11-05 14:00 - 00001112 _____ C:\Users\Tim\Desktop\JRT.txt
2013-11-05 13:55 - 2013-11-05 13:55 - 00000000 ____D C:\Windows\ERUNT
2013-11-05 13:46 - 2013-11-05 13:43 - 00000000 ____D C:\AdwCleaner
2013-11-05 13:45 - 2011-02-16 13:34 - 00001053 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-11-05 13:45 - 2011-02-16 12:56 - 00000991 _____ C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-05 13:25 - 2013-11-05 13:25 - 00052703 _____ C:\Users\Tim\Downloads\FRST.txt
2013-11-05 13:25 - 2013-11-05 13:24 - 00030443 _____ C:\Users\Tim\Downloads\Addition.txt
2013-11-05 13:24 - 2013-11-05 13:24 - 01073258 _____ C:\Users\Tim\Downloads\adwcleaner.exe
2013-11-05 13:24 - 2013-11-05 13:24 - 01033335 _____ (Thisisu) C:\Users\Tim\Downloads\JRT.exe
2013-11-05 13:23 - 2013-11-05 13:23 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tim\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-05 13:21 - 2013-11-05 13:21 - 01957098 _____ (Farbar) C:\Users\Tim\Downloads\FRST64.exe
2013-11-05 13:21 - 2013-11-05 13:21 - 00000000 ____D C:\FRST
2013-11-05 13:15 - 2011-02-16 12:56 - 00000000 ___RD C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-04 17:32 - 2013-07-27 06:01 - 00000115 _____ C:\Users\Spielen\AppData\Roaming\WB.CFG
2013-11-04 17:32 - 2013-07-26 13:21 - 00000006 _____ C:\Users\Spielen\AppData\Roaming\WBPU-TTL.DAT
2013-11-03 11:45 - 2013-11-03 11:45 - 00275544 _____ C:\Windows\Minidump\110313-28111-01.dmp
2013-11-03 11:45 - 2012-04-26 14:22 - 290852180 _____ C:\Windows\MEMORY.DMP
2013-11-03 11:45 - 2012-04-26 14:22 - 00000000 ____D C:\Windows\Minidump
2013-10-31 11:57 - 2013-10-31 11:56 - 00000000 ____D C:\Program Files (x86)\Minecraft
2013-10-31 11:57 - 2013-04-12 17:40 - 00000000 ____D C:\Users\Tim\AppData\Roaming\.minecraft
2013-10-31 11:56 - 2013-10-31 11:56 - 00001988 _____ C:\Users\Tim\Desktop\Minecraft.lnk
2013-10-31 11:56 - 2013-10-31 11:56 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2013-10-31 11:48 - 2013-10-31 11:48 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Unitech LLC
2013-10-31 11:48 - 2013-10-31 11:48 - 00000000 ____D C:\Program Files (x86)\Unitech LLC
2013-10-31 11:48 - 2013-10-31 11:48 - 00000000 ____D C:\Program Files (x86)\iVIDI.org plugin
Some content of TEMP:
====================
C:\Users\Spielen\AppData\Local\Temp\avgnt.exe
C:\Users\Spielen\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Spielen\AppData\Local\Temp\i4jdel0.exe
C:\Users\Spielen\AppData\Local\Temp\i4jdel1.exe
C:\Users\Tim\AppData\Local\Temp\18lu7dnm.dll
C:\Users\Tim\AppData\Local\Temp\4mkmy43k.dll
C:\Users\Tim\AppData\Local\Temp\9t9hpmeo.dll
C:\Users\Tim\AppData\Local\Temp\air5DE.exe
C:\Users\Tim\AppData\Local\Temp\airCE77.exe
C:\Users\Tim\AppData\Local\Temp\airEEE1.exe
C:\Users\Tim\AppData\Local\Temp\AskSLib.dll
C:\Users\Tim\AppData\Local\Temp\AVG.exe
C:\Users\Tim\AppData\Local\Temp\avgnt.exe
C:\Users\Tim\AppData\Local\Temp\BackupSetup.exe
C:\Users\Tim\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Tim\AppData\Local\Temp\E4A3_minecraftsetup.exe
C:\Users\Tim\AppData\Local\Temp\FileSystemView.dll
C:\Users\Tim\AppData\Local\Temp\h2svptqe.dll
C:\Users\Tim\AppData\Local\Temp\i4jdel0.exe
C:\Users\Tim\AppData\Local\Temp\installhelper.dll
C:\Users\Tim\AppData\Local\Temp\install_flashplayer11x32au_mssd_aih.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\pdf24-creator-update.exe
C:\Users\Tim\AppData\Local\Temp\Quarantine.exe
C:\Users\Tim\AppData\Local\Temp\RdpUtils.dll
C:\Users\Tim\AppData\Local\Temp\SHSetup.exe
C:\Users\Tim\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Tim\AppData\Local\Temp\SRAssetsHelper.dll
C:\Users\Tim\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Tim\AppData\Local\Temp\t2ve1nuk.dll
C:\Users\Tim\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Tim\AppData\Local\Temp\vwhki0fk.dll
C:\Users\Tim\AppData\Local\Temp\_is5BE5.exe
C:\Users\Tim\AppData\Local\Temp\_is9AD7.exe
C:\Users\Tim\AppData\Local\Temp\_isA0A3.exe
C:\Users\Tim\AppData\Local\Temp\_isB461.exe
C:\Users\Tim\AppData\Local\Temp\_isE0E9.exe
C:\Users\Tim\AppData\Local\Temp\_isE481.exe
C:\Users\Tim\AppData\Local\Temp\_isFAF2.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-20 17:01
==================== End Of Log ============================ --- --- ---
[/CODE] Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-11-2013
Ran by Tim at 2013-11-28 20:14:58
Running from C:\Users\Tim\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
64 Bit HP CIO Components Installer (Version: 7.2.8)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe AIR (x32 Version: 3.2.0.2070)
Adobe Bridge 1.0 (x32 Version: 001.000.001)
Adobe Common File Installer (x32 Version: 1.00.001)
Adobe Creative Suite 2 (x32)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Help Center 1.0 (x32 Version: 1.0.1)
Adobe Illustrator CS2 (x32 Version: 12.000.000)
Adobe InDesign CS2 (x32 Version: 004.000.000)
Adobe Photoshop CS2 (x32 Version: 9.0)
Adobe Stock Photos 1.0 (x32 Version: 1.0.1)
Adobe SVG Viewer 3.0 (x32 Version: 3.0)
Adobe Version Cue CS2 (x32 Version: 2.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
Android SDK Tools (x32 Version: 0.6)
Apple Software Update (x32 Version: 2.1.3.127)
AT91-ISP v1.10 --- ATMEL AT91 ISP Solution (x32)
ATI AVIVO64 Codecs (Version: 11.1.0.50504)
ATI Catalyst Install Manager (Version: 3.0.774.0)
Avira Free Antivirus (x32 Version: 14.0.1.749)
AVM FRITZ!WLAN (x32 Version: 1.2.0.0)
Battle for Wesnoth 1.11.1 (x32 Version: 1.11.1)
Blender (Version: 2.63-release)
bomlabio 1.0.0 (Version: 1.0.0)
Bonjour (Version: 3.0.0.10)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Core Implementation (x32 Version: 2010.0504.2152.37420)
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0504.2152.37420)
Catalyst Control Center Graphics Full New (x32 Version: 2010.0504.2152.37420)
Catalyst Control Center Graphics Light (x32 Version: 2010.0504.2152.37420)
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0504.2152.37420)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0504.2152.37420)
Catalyst Control Center HydraVision Full (x32 Version: 2010.0504.2152.37420)
Catalyst Control Center InstallProxy (x32 Version: 2010.0504.2152.37420)
Catalyst Control Center Localization All (x32 Version: 2010.0504.2152.37420)
CCC Help Chinese Standard (x32 Version: 2010.0504.2151.37420)
CCC Help Chinese Traditional (x32 Version: 2010.0504.2151.37420)
CCC Help Czech (x32 Version: 2010.0504.2151.37420)
CCC Help Danish (x32 Version: 2010.0504.2151.37420)
CCC Help Dutch (x32 Version: 2010.0504.2151.37420)
CCC Help English (x32 Version: 2010.0504.2151.37420)
CCC Help Finnish (x32 Version: 2010.0504.2151.37420)
CCC Help French (x32 Version: 2010.0504.2151.37420)
CCC Help German (x32 Version: 2010.0504.2151.37420)
CCC Help Greek (x32 Version: 2010.0504.2151.37420)
CCC Help Hungarian (x32 Version: 2010.0504.2151.37420)
CCC Help Italian (x32 Version: 2010.0504.2151.37420)
CCC Help Japanese (x32 Version: 2010.0504.2151.37420)
CCC Help Korean (x32 Version: 2010.0504.2151.37420)
CCC Help Norwegian (x32 Version: 2010.0504.2151.37420)
CCC Help Polish (x32 Version: 2010.0504.2151.37420)
CCC Help Portuguese (x32 Version: 2010.0504.2151.37420)
CCC Help Russian (x32 Version: 2010.0504.2151.37420)
CCC Help Spanish (x32 Version: 2010.0504.2151.37420)
CCC Help Swedish (x32 Version: 2010.0504.2151.37420)
CCC Help Thai (x32 Version: 2010.0504.2151.37420)
CCC Help Turkish (x32 Version: 2010.0504.2151.37420)
ccc-core-static (x32 Version: 2010.0504.2152.37420)
ccc-utility64 (Version: 2010.0504.2152.37420)
CDBurnerXP (x32 Version: 4.4.2.3442)
Clonk Rage (x32)
CloudReading (x32 Version: 1.0.31.1111)
Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000)
Core Temp 1.0 RC3 (Version: 1.0)
D3DX10 (x32 Version: 15.4.2368.0902)
Download Navigator (x32 Version: 3.4.1)
Druckerdeinstallation für EPSON WF-2530 Series
Electronic Arts Product Registration (x32 Version: 1.01.0000)
Epson Connect Printer Setup (x32 Version: 1.1.1)
Epson E-Web Print (x32 Version: 1.17.0000)
EPSON Printer Finder (x32 Version: 1.0.0)
EPSON Scan (x32)
EpsonNet Print (x32 Version: 2.5.00)
EPU-4 Engine (x32 Version: 1.02.01)
FaJo - TimeTool (x32)
FileMaker Pro 12 Advanced (x32 Version: 12.0.1.0)
FileZilla Client 3.7.0.1 (HKCU Version: 3.7.0.1)
Foxit Reader (x32 Version: 6.1.1.1031)
Free Mp3 Wma Converter V 2.2 (x32 Version: 2.2.0.0)
GIMP 2.8.2 (Version: 2.8.2)
Google Chrome (x32 Version: 31.0.1650.57)
Google Earth (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
Gpg4win (2.1.0) (x32 Version: 2.1.0)
Grand Ages Rome 1.11 (x32 Version: 1.11)
HandBrake 0.9.8 (x32 Version: 0.9.8)
Harry Potter II (x32)
HP Update (x32 Version: 5.003.001.001)
HydraVision (x32 Version: 4.2.162.0)
Imperium Romanum 1.04 Gold Edition (x32 Version: 1.04)
iVIDI Plugin 1.3 (x32 Version: 1.3)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Java(TM) 6 Update 24 (64-bit) (Version: 6.0.240)
Java(TM) 6 Update 31 (x32 Version: 6.0.310)
Java(TM) SE Development Kit 6 Update 24 (64-bit) (Version: 1.6.0.240)
J-Link ARM V3.74d (x32 Version: V3.74d)
LogMeTT 2.9.9 (x32)
MagicDisc 2.7.106 (x32)
metaio Creator Demo 2.5.1 (x32 Version: 2.5.1)
metaio SDK 4.0 (x32 Version: 4.0)
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office Word Viewer 2003 (x32 Version: 11.0.8173.0)
Microsoft PowerPoint Viewer (x32 Version: 14.0.6029.1000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1)
Mozilla Maintenance Service (x32 Version: 25.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Napster 5.0 Beta (x32 Version: 1.0.29)
NirSoft SmartSniff (x32)
Notepad++ (x32 Version: 5.8.7)
OpenOffice.org 3.3 (x32 Version: 3.3.9567)
OpenVPN 2.1.4 (x32 Version: 2.1.4)
Pando Media Booster (x32 Version: 2.6.0.7)
PDF24 Creator 5.2.0 (x32)
Pflanzen gegen Zombies (x32)
Platform (x32 Version: 1.34)
PowerISO (x32 Version: 5.4)
Realtek Ethernet Controller Driver For Windows 7 (x32 Version: 7.23.623.2010)
Safari (x32 Version: 5.34.54.16)
Samsung Kies (x32 Version: 2.3.2.12074_13)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.6.0)
Sid Meier's Civilization 4 Complete (x32 Version: 1.74)
Sid Meier's Civilization V (x32)
Skype™ 6.9 (x32 Version: 6.9.106)
Sonos Controller (x32 Version: 22.0.64240)
SPORE™ (x32 Version: 1.00.0000)
Steam (x32 Version: 1.0.0.0)
STRATO HiDrive (remove only) (x32)
Suite Specific (x32 Version: 2.0.0)
TA-Designer 1.03 (x32)
TAPPS 1.29 DE (x32 Version: 1.29)
TeamSpeak 3 Client (HKCU)
Tera Term 4.75 (x32)
TightVNC (Version: 2.5.1.0)
TightVNC 2.0.2 (x32 Version: 2.0.2)
tools-linux (x32 Version: 8.4.5.14951)
tools-windows (x32 Version: 8.4.5.14951)
TortoiseSVN 1.6.12.20536 (64 bit) (Version: 1.6.20536)
TTLEditor 1.4 (x32)
Unitech LLC toolbar (x32 Version: 1.8.23.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
VIA Plattform-Geräte-Manager (x32 Version: 1.34)
VLC media player 1.1.11 (x32 Version: 1.1.11)
VMware Player (x32 Version: 3.1.3.14951)
vuforia-sdk-android-1-5-9 (Version: 1.5.9.0)
WampServer 2.2 (x32)
Windows Home Server-Connector (Version: 6.0.3436.0)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912)
Windows Live Essentials (x32 Version: 16.4.3505.0912)
Windows Live Family Safety (Version: 16.4.3505.0912)
Windows Live Family Safety (x32 Version: 16.4.3505.0912)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (x32 Version: 16.4.3505.0912)
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912)
Windows Live SOXE (x32 Version: 16.4.3505.0912)
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912)
Windows Live UX Platform (x32 Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912)
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8)
Windows XP Mode (Version: 1.3.7600.16422)
XviD4PSP 5.10.271.0 (x32)
YAGARTO 4.2.2 (x32)
==================== Restore Points =========================
28-10-2013 15:10:46 Geplanter Prüfpunkt
05-11-2013 14:15:12 Geplanter Prüfpunkt
12-11-2013 17:00:45 Geplanter Prüfpunkt
17-11-2013 02:01:25 Windows Update
24-11-2013 14:12:47 Geplanter Prüfpunkt
28-11-2013 16:34:02 Installed SpyHunter
28-11-2013 17:55:54 Removed SpyHunter
28-11-2013 18:03:11 Removed SpyHunter
==================== Hosts content: ==========================
2009-07-14 03:34 - 2012-04-15 05:54 - 00000850 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {1E71FC46-B0B3-491A-BA19-D2AADD054A04} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {651F456A-22F6-4547-A647-DE53F00224B5} - System32\Tasks\{2DB4C9A0-E020-43F8-934C-FACBCD8AD3A0} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.156/de/privacy?source=lightinstaller
Task: {6D349EA4-51BC-4CF6-B71E-ED873DA725A2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-14] (Google Inc.)
Task: {7A53E9B0-E0AF-4082-86EC-DA3BC19E0676} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-14] (Google Inc.)
Task: {883094B7-88A6-411E-86A0-220504BB686B} - System32\Tasks\ASUS\ASUS SIX Engine => C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe [2010-02-03] (ASUSTeK Computer Inc.)
Task: {CCAA7837-64EC-4647-8B9C-573DC0839B4B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10] (Adobe Systems Incorporated)
Task: {E2B53719-8C93-406E-AA09-606ECD4DAA90} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {F12F4571-601A-4BAE-BD5C-E561D266604C} - \DSite No Task File
Task: {F41314E9-74E4-4D91-B4C6-C3FC11F51A93} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [2011-05-10] (Hewlett-Packard)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2005-04-06 16:52 - 2005-04-06 16:52 - 00028791 _____ () c:\Adobe\Adobe Version Cue CS2\jre\bin\hpi.dll
2005-04-06 16:53 - 2005-04-06 16:53 - 00057453 _____ () c:\Adobe\Adobe Version Cue CS2\jre\bin\verify.dll
2005-04-06 16:53 - 2005-04-06 16:53 - 00102515 _____ () c:\Adobe\Adobe Version Cue CS2\jre\bin\java.dll
2005-04-06 16:53 - 2005-04-06 16:53 - 00053364 _____ () c:\Adobe\Adobe Version Cue CS2\jre\bin\zip.dll
2005-04-06 16:53 - 2005-04-06 16:53 - 00057455 _____ () C:\Adobe\Adobe Version Cue CS2\jre\bin\net.dll
2005-04-06 16:53 - 2005-04-06 16:53 - 00032880 _____ () C:\Adobe\Adobe Version Cue CS2\jre\bin\nio.dll
2005-04-06 16:53 - 2005-04-06 16:53 - 00434255 _____ () c:\Adobe\Adobe Version Cue CS2\bin\ps-rw-vc-v8_58.dll
2005-04-06 16:53 - 2005-04-06 16:53 - 01019904 _____ () c:\Adobe\Adobe Version Cue CS2\bin\ps-vc-v8_58.dll
2011-03-02 16:16 - 2011-03-02 16:16 - 00208384 _____ () C:\Program Files (x86)\GNU\GnuPG\libksba-8.dll
2011-03-02 16:13 - 2011-03-02 16:13 - 00048640 _____ () C:\Program Files (x86)\GNU\GnuPG\libgpg-error-0.dll
2011-03-02 16:11 - 2011-03-02 16:11 - 00038400 _____ () C:\Program Files (x86)\GNU\GnuPG\libw32pth-0.dll
2011-03-02 16:16 - 2011-03-02 16:16 - 00073216 _____ () C:\Program Files (x86)\GNU\GnuPG\libassuan-0.dll
2011-03-02 16:17 - 2011-03-02 16:17 - 00603136 _____ () C:\Program Files (x86)\GNU\GnuPG\libgcrypt-11.dll
2010-11-11 13:31 - 2010-11-11 13:31 - 00970352 _____ () C:\Program Files (x86)\VMware\VMware Player\libxml2.dll
2010-11-11 13:31 - 2010-11-11 13:31 - 00068720 _____ () C:\Program Files (x86)\VMware\VMware Player\zlib1.dll
2012-11-19 10:57 - 2012-08-31 17:09 - 00008192 _____ () C:\Program Files (x86)\teraterm\Collector\hthook.dll
2012-08-20 14:47 - 2012-08-20 14:47 - 00115137 _____ () C:\Users\Tim\AppData\Local\Temp\d6ebea43-a7f6-428d-ab33-ddb1ea1983ec\CliSecureRT.dll
2013-05-10 19:56 - 2013-05-10 19:56 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2011-01-17 16:19 - 2011-03-26 10:02 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
2013-03-07 11:17 - 2013-03-07 11:02 - 00397704 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2013-11-16 04:16 - 2013-11-16 04:16 - 03363952 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-10-10 02:03 - 2013-10-10 02:03 - 16233864 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:D346F792
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: VMware Virtual Ethernet Adapter for VMnet1
Description: VMware Virtual Ethernet Adapter for VMnet1
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: VMware, Inc.
Service: VMnetAdapter
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: VMware Virtual Ethernet Adapter for VMnet8
Description: VMware Virtual Ethernet Adapter for VMnet8
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: VMware, Inc.
Service: VMnetAdapter
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/28/2013 05:33:25 PM) (Source: Application Hang) (User: )
Description: Programm firefox.exe, Version 25.0.1.5064 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1248
Startzeit: 01cee69dc5ee99d2
Endzeit: 360
Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Berichts-ID: c5f8d6ca-584a-11e3-b59d-bc05430be6ca
Error: (11/27/2013 04:30:05 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9937
Error: (11/27/2013 04:30:05 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9937
Error: (11/26/2013 06:32:56 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/25/2013 04:24:29 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9999
Error: (11/25/2013 04:24:29 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9999
Error: (11/25/2013 04:24:28 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/24/2013 05:07:56 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9999
Error: (11/24/2013 05:07:56 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9999
Error: (11/24/2013 05:07:56 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (11/28/2013 03:47:33 PM) (Source: cdrom) (User: )
Description: Das Gerät \Device\CdRom0 ist für den Zugriff noch nicht bereit.
Error: (11/23/2013 00:26:36 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR4 gefunden.
Error: (11/23/2013 00:26:35 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR4 gefunden.
Error: (11/23/2013 00:26:35 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR4 gefunden.
Error: (11/23/2013 00:26:34 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR4 gefunden.
Error: (11/23/2013 00:19:06 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
Error: (11/23/2013 00:19:05 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
Error: (11/23/2013 00:19:05 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
Error: (11/23/2013 00:19:04 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
Error: (11/22/2013 03:15:30 PM) (Source: DCOM) (User: )
Description: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
Microsoft Office Sessions:
=========================
Error: (11/28/2013 05:33:25 PM) (Source: Application Hang)(User: )
Description: firefox.exe25.0.1.5064124801cee69dc5ee99d2360C:\Program Files (x86)\Mozilla Firefox\firefox.exec5f8d6ca-584a-11e3-b59d-bc05430be6ca
Error: (11/27/2013 04:30:05 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9937
Error: (11/27/2013 04:30:05 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9937
Error: (11/26/2013 06:32:56 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/25/2013 04:24:29 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9999
Error: (11/25/2013 04:24:29 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9999
Error: (11/25/2013 04:24:28 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/24/2013 05:07:56 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9999
Error: (11/24/2013 05:07:56 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9999
Error: (11/24/2013 05:07:56 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
CodeIntegrity Errors:
===================================
Date: 2011-02-16 14:15:11.030
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tap0801.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-02-16 14:15:11.030
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tap0801.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-02-16 14:14:31.047
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tap0801.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-02-16 14:14:31.031
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tap0801.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-02-16 14:11:24.745
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tap0801.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-02-16 14:11:24.745
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tap0801.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-02-16 14:09:46.086
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tap0801.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-02-16 14:09:46.070
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tap0801.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-02-16 14:08:37.293
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tap0801.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-02-16 14:08:37.278
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tap0801.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 53%
Total physical RAM: 3838.05 MB
Available physical RAM: 1795.99 MB
Total Pagefile: 7674.29 MB
Available Pagefile: 4622.73 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:465.66 GB) (Free:272.82 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 3C130C6B)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)
==================== End Of Log ============================ [CODE]
GMER Logfile: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-11-28 20:10:04
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3500312CS rev.SC13 465,76GB
Running: 6m9r7gc7.exe; Driver: C:\Users\Tim\AppData\Local\Temp\uwldipow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002dbe000 63 bytes [43, 4D, 33, 31, 05, 00, 00, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 593 fffff80002dbe041 12 bytes [90, F5, 09, A0, F8, FF, FF, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[5100] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin 000000007797f8ea 1 byte [C3]
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [452:2848] 000007fefb702a7c
---- EOF - GMER 2.1 ---- --- --- --- |