steffen56123 | 17.10.2013 15:23 | Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-10-2013
Ran by USER at 2013-10-17 16:11:10
Running from C:\Users\USER\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Microsoft Security Essentials (Enabled - Up to date) {3F839487-C7A2-C958-E30C-E2825BA31FB5}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {84E27563-E198-C6D6-D9BC-D9F020245508}
==================== Installed Programs ======================
32 Bit HP CIO Components Installer (Version: 7.1.8)
8500A909_eDocs (Version: 1.00.0000)
8500A909_Help (Version: 1.00.0000)
8500A909g (Version: 50.0.165.000)
Acronis*True*Image*Home 2011 (Version: 14.0.5105)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8)
ALLMESS Datenschieber V2.0
AMD Drag and Drop Transcoding (Version: 2.00.0000)
Application Profiles (Version: 2.0.3904.33816)
ATI AVIVO Codecs (Version: 11.6.0.50825)
ATI Catalyst Install Manager (Version: 3.0.790.0)
Attachmate EXTRA! X-treme 8 (Version: 8.0.0.0000)
BPD_DSWizards (Version: 1.00.0000)
bpd_scan (Version: 3.00.0000)
BPDSoftware (Version: 50.0.165.000)
BPDSoftware_Ini (Version: 1.00.0000)
BufferChm (Version: 130.0.331.000)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (Version: 2010.0825.2146.37182)
Catalyst Control Center Graphics Previews Vista (Version: 2010.0825.2146.37182)
Catalyst Control Center InstallProxy (Version: 2010.0825.2146.37182)
Catalyst Control Center Localization All (Version: 2010.0825.2146.37182)
CCC Help Chinese Standard (Version: 2010.0825.2145.37182)
CCC Help Chinese Traditional (Version: 2010.0825.2145.37182)
CCC Help Czech (Version: 2010.0825.2145.37182)
CCC Help Danish (Version: 2010.0825.2145.37182)
CCC Help Dutch (Version: 2010.0825.2145.37182)
CCC Help English (Version: 2010.0825.2145.37182)
CCC Help Finnish (Version: 2010.0825.2145.37182)
CCC Help French (Version: 2010.0825.2145.37182)
CCC Help German (Version: 2010.0825.2145.37182)
CCC Help Greek (Version: 2010.0825.2145.37182)
CCC Help Hungarian (Version: 2010.0825.2145.37182)
CCC Help Italian (Version: 2010.0825.2145.37182)
CCC Help Japanese (Version: 2010.0825.2145.37182)
CCC Help Korean (Version: 2010.0825.2145.37182)
CCC Help Norwegian (Version: 2010.0825.2145.37182)
CCC Help Polish (Version: 2010.0825.2145.37182)
CCC Help Portuguese (Version: 2010.0825.2145.37182)
CCC Help Russian (Version: 2010.0825.2145.37182)
CCC Help Spanish (Version: 2010.0825.2145.37182)
CCC Help Swedish (Version: 2010.0825.2145.37182)
CCC Help Thai (Version: 2010.0825.2145.37182)
CCC Help Turkish (Version: 2010.0825.2145.37182)
ccc-core-static (Version: 2010.0825.2146.37182)
ccc-utility (Version: 2010.0825.2146.37182)
Cisco Systems VPN Client 5.0.00.0340 (Version: 5.0.0)
d.velop d3client
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Destinations (Version: 130.0.0.0)
DeviceDiscovery (Version: 130.0.465.000)
DocMgr (Version: 130.0.000.000)
DocProc (Version: 13.0.0.0)
ElsterFormular (Version: 12.4.0.7094u)
ElsterFormular (Version: 13.0.0.8086u)
Fax (Version: 130.0.418.000)
FoxTab PDF Creator
Google Chrome (HKCU Version: 30.0.1599.101)
Google Earth (Version: 6.0.1.2032)
GPBaseService2 (Version: 130.0.371.000)
GPL Ghostscript 9.01
HP Customer Participation Program 13.0 (Version: 13.0)
HP Document Manager 2.0 (Version: 2.0)
HP Imaging Device Functions 13.0 (Version: 13.0)
HP Officejet Pro 8500 A910 - Grundlegende Software für das Gerät (Version: 22.50.231.0)
HP Officejet Pro 8500 A910 Hilfe (Version: 140.0.2.2)
HP Smart Web Printing 4.51 (Version: 4.51)
HP Solution Center 13.0 (Version: 13.0)
HP Update (Version: 5.003.001.001)
HPDiagnosticAlert (Version: 1.00.0000)
HPDiagnosticCoreDll (Version: 1.0.3.0)
HPProductAssistant (Version: 130.0.371.000)
HPSSupply (Version: 130.0.371.000)
HydraVision (Version: 4.2.180.0)
I.R.I.S. OCR (Version: 12.3.4.0)
Intel(R) Management Engine Components (Version: 6.0.0.1179)
IrfanView (remove only) (Version: 4.28)
Java Auto Updater (Version: 2.0.7.1)
Java(TM) 6 Update 31 (Version: 6.0.310)
K-Lite Codec Pack 6.9.0 (Full) (Version: 6.9.0)
MarketResearch (Version: 130.0.374.000)
Marketsplash Schnellzugriffe (Version: 1.0.1.7)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft IntelliPoint 8.0 (Version: 8.01.249.0)
Microsoft IntelliType Pro 8.0 (Version: 8.0.225.0)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Home and Business 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Security Client (Version: 4.3.0219.0)
Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0)
Microsoft Security Essentials (Version: 4.3.219.0)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
Mozilla Firefox 24.0 (x86 de) (Version: 24.0)
Mozilla Maintenance Service (Version: 24.0)
MPM (Version: 1.00.0000)
MSVC80_x86_v2 (Version: 1.0.3.0)
MSVC90_x86 (Version: 1.0.1.2)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Network (Version: 130.0.579.000)
Nokia Connectivity Cable Driver (Version: 7.1.41.0)
Nokia Ovi Suite (Version: 3.1.0.91)
Nokia Ovi Suite Software Updater (Version: 02.07.004.45780)
Nokia PC Suite (Version: 7.1.60.0)
OCR Software by I.R.I.S. 13.0 (Version: 13.0)
Officejet Pro 8500 A909 Series (Version: 13.0)
Ovi Desktop Sync Engine (Version: 1.5.257.0)
OviMPlatform (Version: 2.7.66.0)
PandaPDFConverter
PC Connectivity Solution (Version: 11.4.16.0)
PDF Architect (Version: 1.1.83.9982)
PDFCreator (Version: 1.7.1)
ProductContext (Version: 50.0.165.000)
Realtek 8136 8168 8169 Ethernet Driver (Version: 1.00.0005)
Realtek High Definition Audio Driver (Version: 6.0.1.6037)
RedMon - Redirection Port Monitor
SAMSUNG USB Driver for Mobile Phones (Version: 1.2.1050.0)
Scan (Version: 13.0.0.0)
Shop for HP Supplies (Version: 13.0)
SmartWebPrinting (Version: 130.0.457.000)
SolutionCenter (Version: 130.0.373.000)
Status (Version: 130.0.469.000)
Studie zur Verbesserung von HP Officejet Pro 8500 A910 Produkten (Version: 22.50.231.0)
TeamViewer 6 (Version: 6.0.10194)
Toolbox (Version: 130.0.648.000)
TrayApp (Version: 130.0.422.000)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition
Updater Service (Version: 14,1,1,3)
VideoPerformer
VLC media player 1.1.7 (Version: 1.1.7)
wc3270 3.3.9ga12
WebReg (Version: 130.0.132.017)
Windows Mobile Device Updater Component (Version: 04.08.2345.00)
Windows Phone Intro Video (DEU) (Version: 04.07.0975.00)
Windows-Treiberpaket - Nokia Modem (06/09/2010 7.01.0.8) (Version: 06/09/2010 7.01.0.8)
Windows-Treiberpaket - Nokia Modem (10/07/2010 4.6) (Version: 10/07/2010 4.6)
Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) (Version: 08/22/2008 7.0.0.0)
WinRAR
Zune (Version: 04.08.2345.00)
Zune Language Pack (CHS) (Version: 04.08.2345.00)
Zune Language Pack (CHT) (Version: 04.08.2345.00)
Zune Language Pack (CSY) (Version: 04.08.2345.00)
Zune Language Pack (DAN) (Version: 04.08.2345.00)
Zune Language Pack (DEU) (Version: 04.08.2345.00)
Zune Language Pack (ELL) (Version: 04.08.2345.00)
Zune Language Pack (ESP) (Version: 04.08.2345.00)
Zune Language Pack (FIN) (Version: 04.08.2345.00)
Zune Language Pack (FRA) (Version: 04.08.2345.00)
Zune Language Pack (HUN) (Version: 04.08.2345.00)
Zune Language Pack (IND) (Version: 04.08.2345.00)
Zune Language Pack (ITA) (Version: 04.08.2345.00)
Zune Language Pack (JPN) (Version: 04.08.2345.00)
Zune Language Pack (KOR) (Version: 04.08.2345.00)
Zune Language Pack (MSL) (Version: 04.08.2345.00)
Zune Language Pack (NLD) (Version: 04.08.2345.00)
Zune Language Pack (NOR) (Version: 04.08.2345.00)
Zune Language Pack (PLK) (Version: 04.08.2345.00)
Zune Language Pack (PTB) (Version: 04.08.2345.00)
Zune Language Pack (PTG) (Version: 04.08.2345.00)
Zune Language Pack (RUS) (Version: 04.08.2345.00)
Zune Language Pack (SVE) (Version: 04.08.2345.00)
==================== Restore Points =========================
26-09-2013 10:02:29 Windows Update
30-09-2013 05:35:12 Windows Update
04-10-2013 05:57:57 Windows Update
07-10-2013 06:09:10 Windows Update
09-10-2013 08:46:23 Removed Iminent Toolbar For Internet Explorer
09-10-2013 08:49:20 TuneUp Utilities 2013 wird entfernt
09-10-2013 08:50:07 TuneUp Utilities Language Pack (de-DE) wird entfernt
09-10-2013 08:51:18 Removed Update Manager for SweetPacks 1.1
09-10-2013 08:51:38 Removed Internet Explorer Toolbar 4.6 by SweetPacks
10-10-2013 07:08:31 Windows Update
10-10-2013 11:27:48 Windows Update
14-10-2013 05:32:05 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {2CDB7326-A693-4F5B-A25A-EBA5C4878D95} - System32\Tasks\{255ECFDD-36B4-41D6-A9DB-E6AF83605435} => C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe [2007-04-03] (Cisco Systems, Inc.)
Task: {34AA2591-82D8-4E05-A880-CD97100A3C69} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => C:\Program Files\Microsoft IntelliType Pro\IType.exe [2010-07-21] (Microsoft Corporation)
Task: {424D2EC8-99E3-494C-A0B9-5AD1B04F5F29} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-145834025-3833221412-4044396105-1000Core => C:\Users\USER\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-28] (Google Inc.)
Task: {45094B04-6B55-48B7-B6A6-9C693D34E107} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2011-05-10] (Hewlett-Packard)
Task: {58F8EC73-E379-4C76-96CD-C3D2D47665CE} - System32\Tasks\{46CBB05C-4E3F-4C12-9C1C-16707AC72524} => C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE [2013-07-18] (Microsoft Corporation)
Task: {62526F9F-D75B-4A5C-9602-997904D96A13} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {73DE71E4-B8D5-4F63-9840-78E85AF79B59} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {81A9AFD5-1B32-444D-801F-112326D6F9BA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-145834025-3833221412-4044396105-1000UA => C:\Users\USER\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-28] (Google Inc.)
Task: {C9F82DAB-C68B-4AB0-96D7-DF1598C31744} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {CA48C66E-0697-4BAB-9860-6A391C4C9CA3} - System32\Tasks\HPCustParticipation HP Officejet Pro 8500 A910 => C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.)
Task: {DA02DDF5-E11D-4DAD-9A54-26C4FAA39DCE} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation)
Task: {F40433A8-1D75-46FB-BF27-CAE579905536} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-01-07] (Microsoft Corporation)
Task: {FA37B234-C174-4397-A326-1F45B747350C} - System32\Tasks\Google Updater and Installer => C:\Users\USER\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-28] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-145834025-3833221412-4044396105-1000Core.job => C:\Users\USER\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-145834025-3833221412-4044396105-1000UA.job => C:\Users\USER\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2011-02-28 14:15 - 2010-03-15 12:28 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll
2010-08-04 16:58 - 2010-08-04 16:58 - 00016384 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
2010-08-25 22:44 - 2010-08-25 22:44 - 00270336 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2007-08-08 11:37 - 2007-08-08 11:37 - 00056320 _____ () C:\Program Files\d.velop\d3client\isock32.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 08166912 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtGui4.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 02282496 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtCore4.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 00913920 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtNetwork4.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 00026624 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\imageformats\qgif4.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 00196608 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\imageformats\qjpeg4.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 00340480 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtXml4.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 02246656 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtDeclarative4.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 01288192 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtScript4.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 00190464 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtSql4.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 02551296 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtXmlPatterns4.dll
2011-05-20 16:29 - 2011-05-20 16:29 - 00924672 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\Maps Service API.dll
2005-07-20 11:48 - 2005-07-20 11:48 - 00059904 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\zlib1.dll
2011-05-20 16:29 - 2011-05-20 16:29 - 00422800 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\ssoengine.dll
2011-05-20 16:29 - 2011-05-20 16:29 - 00060816 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\securestorage.dll
2011-05-20 16:29 - 2011-05-20 16:29 - 00387976 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\OviShareLib.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 00266752 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\phonon4.dll
2011-05-20 16:30 - 2011-05-20 16:30 - 00508416 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtMultimediaKit1.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 00676864 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtOpenGL4.dll
2011-05-20 16:28 - 2011-05-20 16:28 - 00687616 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\CommonUpdateChecker.dll
2011-05-20 16:54 - 2011-05-20 16:54 - 10837504 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\QtWebKit4.dll
2011-05-20 16:30 - 2011-05-20 16:30 - 00109568 _____ () C:\Program Files\Nokia\Nokia Ovi Suite\mediaservice\dsengine.dll
2011-02-28 17:22 - 1996-12-03 00:00 - 03661072 _____ () C:\Windows\system32\mso97rt.dll
2011-03-03 12:00 - 2013-10-09 16:45 - 09489408 _____ () C:\Users\USER\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_rdlang32.deu
2013-09-03 15:53 - 2013-09-03 15:53 - 00305520 _____ () C:\Program Files\Adobe\Reader 10.0\Reader\sqlite.dll
2012-07-27 22:51 - 2012-07-27 22:51 - 06549432 _____ () C:\Program Files\Adobe\Reader 10.0\Reader\authplay.dll
2011-03-03 14:16 - 2013-10-09 16:45 - 03065856 _____ () C:\Users\USER\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_Annots.DEU
2011-04-20 06:55 - 2013-10-09 16:45 - 00023040 _____ () C:\Users\USER\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_SendMail.DEU
2011-03-17 00:11 - 2011-03-17 00:11 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf
2011-03-03 14:51 - 2013-10-09 17:32 - 00014336 _____ () C:\Users\USER\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_Updater.DEU
2010-12-21 02:15 - 2010-12-21 02:15 - 01041248 _____ () C:\Program Files\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:B801D4E2
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Cisco Systems VPN Adapter
Description: Cisco Systems VPN Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: OCT Inc. USB Serial Converter
Description: OCT Inc. USB Serial Converter
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/17/2013 02:50:33 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: aswMBR.exe, Version: 0.9.9.1771, Zeitstempel: 0x5147644e
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00052d37
ID des fehlerhaften Prozesses: 0x1cc0
Startzeit der fehlerhaften Anwendung: 0xaswMBR.exe0
Pfad der fehlerhaften Anwendung: aswMBR.exe1
Pfad des fehlerhaften Moduls: aswMBR.exe2
Berichtskennung: aswMBR.exe3
Error: (10/17/2013 02:46:12 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: aswMBR.exe, Version: 0.9.9.1771, Zeitstempel: 0x5147644e
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00052d94
ID des fehlerhaften Prozesses: 0x1ed8
Startzeit der fehlerhaften Anwendung: 0xaswMBR.exe0
Pfad der fehlerhaften Anwendung: aswMBR.exe1
Pfad des fehlerhaften Moduls: aswMBR.exe2
Berichtskennung: aswMBR.exe3
Error: (10/17/2013 08:10:57 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: MSACCESS.EXE, Version: 8.0.0.3512, Zeitstempel: 0x328951b3
Name des fehlerhaften Moduls: MSACCESS.EXE, Version: 8.0.0.3512, Zeitstempel: 0x328951b3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00023293
ID des fehlerhaften Prozesses: 0xc10
Startzeit der fehlerhaften Anwendung: 0xMSACCESS.EXE0
Pfad der fehlerhaften Anwendung: MSACCESS.EXE1
Pfad des fehlerhaften Moduls: MSACCESS.EXE2
Berichtskennung: MSACCESS.EXE3
Error: (10/17/2013 07:50:23 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 24.0.0.5001, Zeitstempel: 0x518e80fd
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0005d032
ID des fehlerhaften Prozesses: 0x1074
Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0
Pfad der fehlerhaften Anwendung: firefox.exe1
Pfad des fehlerhaften Moduls: firefox.exe2
Berichtskennung: firefox.exe3
Error: (10/16/2013 04:17:46 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: MSACCESS.EXE, Version: 8.0.0.3512, Zeitstempel: 0x328951b3
Name des fehlerhaften Moduls: MSACCESS.EXE, Version: 8.0.0.3512, Zeitstempel: 0x328951b3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00023293
ID des fehlerhaften Prozesses: 0x11dc
Startzeit der fehlerhaften Anwendung: 0xMSACCESS.EXE0
Pfad der fehlerhaften Anwendung: MSACCESS.EXE1
Pfad des fehlerhaften Moduls: MSACCESS.EXE2
Berichtskennung: MSACCESS.EXE3
Error: (10/16/2013 03:28:07 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 24.0.0.5001, Zeitstempel: 0x518e80fd
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0005d032
ID des fehlerhaften Prozesses: 0xf6c
Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0
Pfad der fehlerhaften Anwendung: firefox.exe1
Pfad des fehlerhaften Moduls: firefox.exe2
Berichtskennung: firefox.exe3
Error: (10/15/2013 06:10:32 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: MSACCESS.EXE, Version: 8.0.0.3512, Zeitstempel: 0x328951b3
Name des fehlerhaften Moduls: MSACCESS.EXE, Version: 8.0.0.3512, Zeitstempel: 0x328951b3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00023293
ID des fehlerhaften Prozesses: 0x13b8
Startzeit der fehlerhaften Anwendung: 0xMSACCESS.EXE0
Pfad der fehlerhaften Anwendung: MSACCESS.EXE1
Pfad des fehlerhaften Moduls: MSACCESS.EXE2
Berichtskennung: MSACCESS.EXE3
Error: (10/15/2013 03:39:58 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (10/15/2013 03:39:58 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (10/15/2013 03:39:57 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
System errors:
=============
Error: (10/16/2013 03:28:40 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005
Error: (10/15/2013 06:54:15 AM) (Source: DCOM) (User: )
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (10/14/2013 04:18:50 PM) (Source: DCOM) (User: )
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (10/14/2013 09:23:09 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
Error: (10/10/2013 08:07:33 AM) (Source: Microsoft Antimalware) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt.
Neue Signaturversion:
Vorherige Signaturversion: 1.159.1589.0
Aktualisierungsquelle: %NT-AUTORITÄT59
Aktualisierungsphase: 4.2.0223.00
Quellpfad: 4.2.0223.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\SYSTEM
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (10/09/2013 05:42:26 PM) (Source: DCOM) (User: )
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (10/09/2013 04:52:15 PM) (Source: Microsoft Antimalware) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt.
Neue Signaturversion:
Vorherige Signaturversion: 1.159.1589.0
Aktualisierungsquelle: %NT-AUTORITÄT59
Aktualisierungsphase: 4.2.0223.00
Quellpfad: 4.2.0223.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\SYSTEM
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (10/09/2013 00:22:08 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Server" wurde mit folgendem Fehler beendet:
%%13
Error: (10/09/2013 00:22:08 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" wurde mit folgendem Fehler beendet:
%%1115
Error: (10/09/2013 00:20:42 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Microsoft Office Sessions:
=========================
Error: (10/17/2013 02:50:33 PM) (Source: Application Error)(User: )
Description: aswMBR.exe0.9.9.17715147644entdll.dll6.1.7601.18247521ea91cc000000500052d371cc001cecb36ec3fb1c9C:\Users\USER\Desktop\aswMBR.exeC:\Windows\SYSTEM32\ntdll.dllb5a7b139-372a-11e3-967c-20cf30e64d7a
Error: (10/17/2013 02:46:12 PM) (Source: Application Error)(User: )
Description: aswMBR.exe0.9.9.17715147644entdll.dll6.1.7601.18247521ea91cc000000500052d941ed801cecb353727573cC:\Users\USER\Desktop\aswMBR.exeC:\Windows\SYSTEM32\ntdll.dll19ba668e-372a-11e3-967c-20cf30e64d7a
Error: (10/17/2013 08:10:57 AM) (Source: Application Error)(User: )
Description: MSACCESS.EXE8.0.0.3512328951b3MSACCESS.EXE8.0.0.3512328951b3c000000500023293c1001cecafd15ec4217C:\RKES\OFFICE\MSACCESS.EXEC:\RKES\OFFICE\MSACCESS.EXEe2e3aa64-36f2-11e3-967c-20cf30e64d7a
Error: (10/17/2013 07:50:23 AM) (Source: Application Error)(User: )
Description: firefox.exe24.0.0.5001518e80fdntdll.dll6.1.7601.18247521ea91cc00000050005d032107401cecafcc43b4c52C:\Program Files\Mozilla Firefox\firefox.exeC:\Windows\SYSTEM32\ntdll.dll030f01d4-36f0-11e3-967c-20cf30e64d7a
Error: (10/16/2013 04:17:46 PM) (Source: Application Error)(User: )
Description: MSACCESS.EXE8.0.0.3512328951b3MSACCESS.EXE8.0.0.3512328951b3c00000050002329311dc01ceca74c82c5406C:\RKES\OFFICE\MSACCESS.EXEC:\RKES\OFFICE\MSACCESS.EXEba071a37-366d-11e3-9c3b-20cf30e64d7a
Error: (10/16/2013 03:28:07 PM) (Source: Application Error)(User: )
Description: firefox.exe24.0.0.5001518e80fdntdll.dll6.1.7601.18247521ea91cc00000050005d032f6c01ceca738327511fC:\Program Files\Mozilla Firefox\firefox.exeC:\Windows\SYSTEM32\ntdll.dllca55e271-3666-11e3-9c3b-20cf30e64d7a
Error: (10/15/2013 06:10:32 PM) (Source: Application Error)(User: )
Description: MSACCESS.EXE8.0.0.3512328951b3MSACCESS.EXE8.0.0.3512328951b3c00000050002329313b801cec9a731a69150C:\RKES\OFFICE\MSACCESS.EXEC:\RKES\OFFICE\MSACCESS.EXE50ec3f19-35b4-11e3-961a-20cf30e64d7a
Error: (10/15/2013 03:39:58 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\ati technologies\hydravision\HydraMD64.exe
Error: (10/15/2013 03:39:58 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\ati technologies\hydravision\HydraDM64.exe
Error: (10/15/2013 03:39:57 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\ati technologies\hydravision\Grid64.exe
==================== Memory info ===========================
Percentage of memory in use: 48%
Total physical RAM: 3550.05 MB
Available physical RAM: 1812.86 MB
Total Pagefile: 7098.4 MB
Available Pagefile: 5199.9 MB
Total Virtual: 2047.88 MB
Available Virtual: 1884.32 MB
==================== Drives ================================
Drive c: (system) (Fixed) (Total:195.21 GB) (Free:89.72 GB) NTFS
Drive d: (Archiv & Sicherungen) (Fixed) (Total:195.31 GB) (Free:194.92 GB) NTFS
Drive f: (Daten) (Fixed) (Total:540.89 GB) (Free:539.91 GB) NTFS
Drive i: (HDDRIVE2GO) (Fixed) (Total:335.27 GB) (Free:248.21 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 2635F9C6)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=195 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=195 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=541 GB) - (Type=OF Extended)
========================================================
Disk: 1 (Size: 335 GB) (Disk ID: BC1B019C)
Partition 1: (Not Active) - (Size=335 GB) - (Type=0C)
==================== End Of Log ============================ FRST.txt
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013
Ran by USER (administrator) on USER-PC on 17-10-2013 16:06:48
Running from C:\Users\USER\Desktop
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
() C:\ProgramData\IBUpdaterService\ibsvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe
(Acronis) C:\Program Files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Acronis) C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
(Nokia) C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
(Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(d.velop) C:\Program Files\d.velop\d3client\d3login.exe
(Nokia) C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Zune\ZuneNss.exe
(Microsoft Corporation) C:\RKES\OFFICE\MSACCESS.EXE
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
(d.velop) C:\Program Files\d.velop\d3client\dwatch.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
(TeamViewer GmbH) C:\Users\USER\AppData\Local\Temp\TeamViewer\Version7\TeamViewer.exe
(TeamViewer GmbH) C:\Users\USER\AppData\Local\Temp\TeamViewer\Version7\tv_w32.exe
(TeamViewer GmbH) c:\users\user\appdata\local\temp\teamviewer\version7\TeamViewer_Desktop.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8493600 2010-01-29] (Realtek Semiconductor)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-25] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [itype] - C:\Program Files\Microsoft IntelliType Pro\itype.exe [1778064 2010-07-21] (Microsoft Corporation)
HKLM\...\Run: [SAOB Monitor] - C:\Program Files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe [2536752 2010-08-20] (Acronis)
HKLM\...\Run: [TrueImageMonitor.exe] - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [5459136 2010-08-21] (Acronis)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [390712 2010-08-21] (Acronis)
HKLM\...\Run: [NokiaMServer] - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [159456 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-08-12] (Microsoft Corporation)
HKLM\...\Run: [logonf] - C:\Program Files\Windows NT\logonf.lnk [650 2013-10-01] ()
HKLM\...\Run: [packvusrv] - C:\Program Files\Windows NT\packvusrv.lnk [664 2013-10-07] ()
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Policies\Explorer\Run: [20845] - c:\progra~2\dxmjpgk.exe No File
HKCU\...\Run: [D3LOGIN] - C:\Program Files\d.velop\d3client\d3login.exe [351744 2007-08-08] (d.velop)
HKCU\...\Run: [NokiaOviSuite2] - C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [724536 2011-05-20] (Nokia)
HKCU\...\Run: [] - [x]
HKCU\...\Run: [Google Update] - C:\Users\USER\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-02-28] (Google Inc.)
HKCU\...\Run: [{1B07821F-E2B1-CA33-4DA2-9104C64BD5CE}] - C:\Users\USER\AppData\Roaming\Keas\mahesy.exe [181973 2011-12-18] ()
HKCU\...\Policies\Explorer: [HideSCAHealth] 1
MountPoints2: {f755a338-b53b-11e1-9234-20cf30e64d7a} - H:\LaunchU3.exe -a
AppInit_DLLs: [ ] ()
Startup: C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Outlook 2010.lnk
ShortcutTarget: Microsoft Outlook 2010.lnk -> C:\Windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\outicon.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3E44D156D8FDCB01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=331128&systemid=426&sr=0&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://www.searchqu.com/web?src=ieb&appid=175&systemid=406&sr=0&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=331128&systemid=426&sr=0&q={searchTerms}
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=331128&systemid=426&sr=0&q={searchTerms}
SearchScopes: HKCU - {0D7562AE-8EF6-416d-A838-AB665251703A} URL = hxxp://start.facemoods.com/?a=gppc&s={searchTerms}&f=4
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&AF=100482&babsrc=SP_ss&mntrId=5a60516d00000000000020cf30e64d7a
SearchScopes: HKCU - {6D127035-96CD-4429-A754-10E49E69E54D} URL = hxxp://search.softonic.com/MON00016/tb_v1?q={searchTerms}&SearchSource=4&cc=
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://www.searchqu.com/web?src=ieb&appid=175&systemid=406&sr=0&q={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=331128&systemid=426&sr=0&q={searchTerms}
SearchScopes: HKCU - {BC91B570-6A28-40AD-9D58-39713D19E700} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=827316&p={searchTerms}
SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredimail.com/mb68/?search={searchTerms}&loc=search_box&u=92541545952027901
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - !{8dcb7100-df86-4384-8842-8fa844297b3f} - No File
Toolbar: HKLM - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\86zrn2w3.default
FF Homepage: hxxp://www.msn.com/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Google.com/GoogleEarthPlugin - C:\Users\USER\AppData\Local\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\USER\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\USER\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\86zrn2w3.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF HKLM\...\Firefox\Extensions: [{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}] - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\
FF Extension: Firefox Synchronisation Extension - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF HKLM\...\Thunderbird\Extensions: [{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}] - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\
FF Extension: Thunderbird Address Book Synchronisation Extension - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR RestoreOnStartup: "hxxp://start.iminent.com/?appId=26743BF3-DB62-4643-B7F2-168542EA3BDE"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\USER\AppData\Local\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\USER\AppData\Local\Google\Chrome\Application\30.0.1599.69\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\USER\AppData\Local\Google\Chrome\Application\30.0.1599.69\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Users\USER\AppData\Local\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Users\USER\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Extension: (FileConverter 1.3) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\engeblojhfeingnjnfpiceofljnjpldp\10.20.1.508_0
CHR Extension: (SweetIM for Facebook) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (SweetPacks Chrome Extension) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.2_0
CHR HKLM\...\Chrome\Extension: [engeblojhfeingnjnfpiceofljnjpldp] - C:\Users\USER\AppData\Local\CRE\engeblojhfeingnjnfpiceofljnjpldp.crx
CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx
CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx
CHR StartMenuInternet: Google Chrome - C:\Users\USER\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [779944 2010-08-21] (Acronis)
R2 afcdpsrv; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [3975088 2011-03-03] (Acronis)
R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1516584 2007-04-03] (Cisco Systems, Inc.)
R2 IBUpdaterService; C:\ProgramData\IBUpdaterService\ibsvc.exe [396216 2012-05-18] ()
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-08-12] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-08-12] (Microsoft Corporation)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
==================== Drivers (Whitelisted) ====================
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW73.sys [101904 2010-07-15] (ATI Technologies, Inc.)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306295 2007-04-03] (Cisco Systems, Inc.)
R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [127376 2007-01-31] (Deterministic Networks, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
R1 MpKslf90b867f; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F19F7838-67E9-47D4-B628-B748A49A020B}\MpKslf90b867f.sys [40392 2013-10-17] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2009-07-16] ()
S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-11-03] (Microsoft Corporation)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [34016 2013-01-10] (The OpenVPN Project)
S4 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
U3 aswMBR; \??\C:\Users\USER\AppData\Local\Temp\aswMBR.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-17 16:06 - 2013-10-17 16:06 - 00000000 ____D C:\FRST
2013-10-17 16:05 - 2013-10-17 16:05 - 01087213 _____ (Farbar) C:\Users\USER\Desktop\FRST.exe
2013-10-10 09:14 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-10 09:14 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-10 09:14 - 2013-09-23 01:28 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-10 09:14 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-10 09:14 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-10 09:14 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-10 09:14 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-10 09:14 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-10 09:14 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-10 09:14 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-10 09:14 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-10 09:14 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-10 09:14 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-10 09:14 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-10 09:14 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-10 09:14 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-10 09:03 - 2013-09-14 02:48 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-10 09:03 - 2013-09-08 04:07 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-10 09:03 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-10 09:03 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-10-10 09:03 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-10 09:03 - 2013-08-29 03:50 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-10 09:03 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-10 09:03 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-10 09:03 - 2013-08-29 03:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys
2013-10-10 09:03 - 2013-08-28 03:04 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 09:03 - 2013-08-28 02:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-10 09:03 - 2013-08-01 13:03 - 00729024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 09:03 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 09:03 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-10 09:03 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-10 09:03 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 09:03 - 2013-07-04 11:48 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-10 09:03 - 2013-07-03 06:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-10 09:03 - 2013-07-03 05:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-10 09:03 - 2013-07-03 05:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 09:03 - 2013-06-06 06:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-10 09:03 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-10 09:03 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-10 09:03 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 09:03 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 09:02 - 2013-07-12 12:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-10 09:02 - 2013-06-26 00:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-09 11:20 - 2013-10-09 11:21 - 00000000 ____D C:\Users\USER\AppData\Roaming\Mozilla
2013-10-09 11:20 - 2013-10-09 11:20 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-10-09 11:20 - 2013-10-09 11:20 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-09 11:00 - 2013-10-09 11:00 - 00000000 ____D C:\Users\USER\Downloads\backups
2013-10-09 10:57 - 2013-10-09 10:58 - 00388608 _____ (Trend Micro Inc.) C:\Users\USER\Downloads\hijackthis.exe
2013-10-09 10:21 - 2013-10-09 10:24 - 00000000 ____D C:\Users\USER\AppData\Roaming\Ykto
2013-10-09 10:21 - 2013-10-09 10:21 - 00000000 ____D C:\Users\USER\AppData\Roaming\Keas
2013-09-23 08:15 - 2013-09-23 08:15 - 00000168 _____ C:\Users\USER\Downloads\html-2.3 (1).html
2013-09-23 08:14 - 2013-09-23 08:14 - 00009137 _____ C:\Users\USER\Downloads\html-2.3.html
2013-09-23 08:13 - 2013-09-23 08:13 - 00000168 _____ C:\Users\USER\Downloads\html-2.5.html
==================== One Month Modified Files and Folders =======
2013-10-17 16:06 - 2013-10-17 16:06 - 00000000 ____D C:\FRST
2013-10-17 16:05 - 2013-10-17 16:05 - 01087213 _____ (Farbar) C:\Users\USER\Desktop\FRST.exe
2013-10-17 16:04 - 2012-06-26 09:50 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-17 15:31 - 2011-02-28 16:25 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-145834025-3833221412-4044396105-1000UA.job
2013-10-17 15:30 - 2011-02-28 20:48 - 01077150 _____ C:\Windows\WindowsUpdate.log
2013-10-17 14:31 - 2011-02-28 16:25 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-145834025-3833221412-4044396105-1000Core.job
2013-10-17 09:51 - 2012-06-04 11:06 - 00413184 ___SH C:\Users\USER\Documents\Thumbs.db
2013-10-17 08:10 - 2011-02-28 17:22 - 00000000 ____D C:\RKES
2013-10-17 07:57 - 2009-07-14 06:34 - 00014816 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-17 07:57 - 2009-07-14 06:34 - 00014816 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-17 07:50 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Windows NT
2013-10-17 07:49 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-17 07:49 - 2009-07-14 06:39 - 00117786 _____ C:\Windows\setupact.log
2013-10-10 13:28 - 2011-03-03 09:32 - 00001912 _____ C:\Windows\epplauncher.mif
2013-10-10 13:28 - 2011-03-03 09:31 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-10-10 12:50 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-10-10 10:20 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-10-10 09:32 - 2011-02-28 13:57 - 01507342 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-10 09:27 - 2012-06-01 13:50 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 09:27 - 2009-07-14 06:33 - 00374040 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-10 09:25 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-10-10 09:23 - 2011-02-28 14:37 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-10 09:21 - 2013-08-19 10:51 - 00000000 ____D C:\Windows\system32\MRT
2013-10-10 09:16 - 2011-03-03 09:23 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-09 17:05 - 2012-06-26 09:49 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-09 17:05 - 2011-06-14 12:19 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-09 12:18 - 2011-02-28 16:14 - 00041084 _____ C:\Windows\PFRO.log
2013-10-09 11:21 - 2013-10-09 11:20 - 00000000 ____D C:\Users\USER\AppData\Roaming\Mozilla
2013-10-09 11:20 - 2013-10-09 11:20 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-10-09 11:20 - 2013-10-09 11:20 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-09 11:20 - 2011-02-28 14:14 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-09 11:13 - 2011-02-28 14:20 - 00000000 ____D C:\Users\USER\AppData\Local\Mozilla
2013-10-09 11:00 - 2013-10-09 11:00 - 00000000 ____D C:\Users\USER\Downloads\backups
2013-10-09 10:58 - 2013-10-09 10:57 - 00388608 _____ (Trend Micro Inc.) C:\Users\USER\Downloads\hijackthis.exe
2013-10-09 10:48 - 2013-02-01 15:45 - 00001721 _____ C:\Windows\system32\InstallUtil.InstallLog
2013-10-09 10:47 - 2013-07-31 14:39 - 00000000 ____D C:\Program Files\Amazon
2013-10-09 10:24 - 2013-10-09 10:21 - 00000000 ____D C:\Users\USER\AppData\Roaming\Ykto
2013-10-09 10:21 - 2013-10-09 10:21 - 00000000 ____D C:\Users\USER\AppData\Roaming\Keas
2013-09-26 07:59 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-23 08:15 - 2013-09-23 08:15 - 00000168 _____ C:\Users\USER\Downloads\html-2.3 (1).html
2013-09-23 08:14 - 2013-09-23 08:14 - 00009137 _____ C:\Users\USER\Downloads\html-2.3.html
2013-09-23 08:13 - 2013-09-23 08:13 - 00000168 _____ C:\Users\USER\Downloads\html-2.5.html
2013-09-23 01:28 - 2013-10-10 09:14 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-23 01:28 - 2013-10-10 09:14 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-23 01:28 - 2013-10-10 09:14 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-23 01:27 - 2013-10-10 09:14 - 14335488 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-23 01:27 - 2013-10-10 09:14 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-23 01:27 - 2013-10-10 09:14 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-23 01:27 - 2013-10-10 09:14 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-23 01:27 - 2013-10-10 09:14 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-23 01:27 - 2013-10-10 09:14 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-23 01:27 - 2013-10-10 09:14 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-23 01:27 - 2013-10-10 09:14 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-23 01:27 - 2013-10-10 09:14 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-23 01:27 - 2013-10-10 09:14 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-23 01:27 - 2013-10-10 09:14 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-21 05:30 - 2013-10-10 09:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-21 04:39 - 2013-10-10 09:14 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.6808.dll
C:\Users\Public\AlexaNSISPlugin.7552.dll
Some content of TEMP:
====================
C:\Users\USER\AppData\Local\Temp\1354784909.exe
C:\Users\USER\AppData\Local\Temp\1354838409.exe
C:\Users\USER\AppData\Local\Temp\1354842228.exe
C:\Users\USER\AppData\Local\Temp\1354850896.exe
C:\Users\USER\AppData\Local\Temp\1354958673.exe
C:\Users\USER\AppData\Local\Temp\1354983839.exe
C:\Users\USER\AppData\Local\Temp\1355943288.exe
C:\Users\USER\AppData\Local\Temp\1355976717.exe
C:\Users\USER\AppData\Local\Temp\1356079972.exe
C:\Users\USER\AppData\Local\Temp\1356138072.exe
C:\Users\USER\AppData\Local\Temp\1356147250.exe
C:\Users\USER\AppData\Local\Temp\1356157837.exe
C:\Users\USER\AppData\Local\Temp\1356238655.exe
C:\Users\USER\AppData\Local\Temp\1356239115.exe
C:\Users\USER\AppData\Local\Temp\1356268725.exe
C:\Users\USER\AppData\Local\Temp\1356277393.exe
C:\Users\USER\AppData\Local\Temp\1356311750.exe
C:\Users\USER\AppData\Local\Temp\1356759082.exe
C:\Users\USER\AppData\Local\Temp\1356773818.exe
C:\Users\USER\AppData\Local\Temp\1357417363.exe
C:\Users\USER\AppData\Local\Temp\1357440809.exe
C:\Users\USER\AppData\Local\Temp\1357517013.exe
C:\Users\USER\AppData\Local\Temp\1357525309.exe
C:\Users\USER\AppData\Local\Temp\1357548581.exe
C:\Users\USER\AppData\Local\Temp\1357579786.exe
C:\Users\USER\AppData\Local\Temp\1357587023.exe
C:\Users\USER\AppData\Local\Temp\1357614692.exe
C:\Users\USER\AppData\Local\Temp\1357622871.exe
C:\Users\USER\AppData\Local\Temp\1357682991.exe
C:\Users\USER\AppData\Local\Temp\1357741728.exe
C:\Users\USER\AppData\Local\Temp\1357755734.exe
C:\Users\USER\AppData\Local\Temp\1357763247.exe
C:\Users\USER\AppData\Local\Temp\1357771833.exe
C:\Users\USER\AppData\Local\Temp\jna4052414465679408263.dll
C:\Users\USER\AppData\Local\Temp\NEventMessages.dll
C:\Users\USER\AppData\Local\Temp\NOSEventMessages.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-14 15:08
==================== End Of Log ============================ --- --- ---
--- --- --- |