Hello,
I get pop ups with the ib.adnxs.com url when I open for example youtube songs in firefox (not with ie).
Thank you for your help!
DDS:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 19:45:36 on 2012-08-14
Microsoft Windows 7 Professional 6.1.7601.1.1252.43.1031.18.8086.5926 [GMT 2:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\viakaraokesrv.exe
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\mobsync.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: {BA0454C5-FD30-428E-8DB9-3FF87A612F64} - No File
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/s ... wflash.cab
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{07787C27-73E5-44CD-82D0-9B2E8F3B7994} : DhcpNameServer = 10.0.0.138
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}
{53707962-6F74-2D53-2644-206D7942484F}
BHO-X64: {BA0454C5-FD30-428E-8DB9-3FF87A612F64} - No File
mRun-x64: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun-x64: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\qx56zo0x.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://ixquick.com/
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll
.
---- FIREFOX POLICIES ----
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys --> C:\Windows\system32\DRIVERS\avgidsha.sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;C:\Windows\system32\DRIVERS\iusb3hcs.sys --> C:\Windows\system32\DRIVERS\iusb3hcs.sys [?]
R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys --> C:\Windows\system32\DRIVERS\AppleCharger.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-7-4 5160568]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-8 607456]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-7-26 161560]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2012-7-27 1153368]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-7-26 363800]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\Windows\system32\viakaraokesrv.exe --> C:\Windows\system32\viakaraokesrv.exe [?]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys --> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys --> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\system32\Drivers\EtronHub3.sys --> C:\Windows\system32\Drivers\EtronHub3.sys [?]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\system32\Drivers\EtronXHCI.sys --> C:\Windows\system32\Drivers\EtronXHCI.sys [?]
R3 IntcDAud;Intel(R) Display-Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;C:\Windows\system32\DRIVERS\iusb3hub.sys --> C:\Windows\system32\DRIVERS\iusb3hub.sys [?]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;C:\Windows\system32\DRIVERS\iusb3xhc.sys --> C:\Windows\system32\DRIVERS\iusb3xhc.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\system32\drivers\viahduaa.sys --> C:\Windows\system32\drivers\viahduaa.sys [?]
S2 gupdate;Google Update-Dienst (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-29 116648]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-7-29 250056]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 cphs;Intel(R) Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-7-26 274200]
S3 cpuz135;cpuz135;C:\Program Files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys [2012-7-27 23816]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 gupdatem;Google Update-Dienst (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-29 116648]
S3 StorSvc;Speicherdienst;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S3 WatAdminSvc;Windows-Aktivierungstechnologieservice;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-08-14 16:31:06 -------- d-----w- C:\Users\Peter\AppData\Roaming\Malwarebytes
2012-08-14 16:30:52 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-08-14 16:30:52 -------- d-----w- C:\ProgramData\Malwarebytes
2012-08-14 16:30:52 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-07 08:23:55 -------- d-----w- C:\Program Files (x86)\GTASA-Ultimate Editor
2012-08-07 08:23:41 249856 ------w- C:\Windows\Setup1.exe
2012-08-07 08:23:40 73216 ----a-w- C:\Windows\ST6UNST.EXE
2012-08-06 17:41:49 99840 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\HPZPPLHN.DLL
2012-08-03 09:51:39 -------- d-----w- C:\Users\Peter\AppData\Roaming\pdfforge
2012-08-03 09:51:38 95744 ----a-w- C:\Windows\System32\pdfcmon.dll
2012-08-03 09:51:38 662288 ----a-w- C:\Windows\SysWow64\MSCOMCT2.OCX
2012-08-03 09:51:38 137000 ----a-w- C:\Windows\SysWow64\MSMAPI32.OCX
2012-08-03 09:51:38 1071088 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX
2012-08-03 09:51:37 64512 ----a-w- C:\Windows\SysWow64\MSCC2DE.DLL
2012-08-03 09:51:37 23552 ----a-w- C:\Windows\SysWow64\MSMPIDE.DLL
2012-08-03 09:51:37 158208 ----a-w- C:\Windows\SysWow64\MSCMCDE.DLL
2012-08-03 09:51:37 125712 ----a-w- C:\Windows\SysWow64\VB6DE.DLL
2012-08-03 09:51:37 -------- d-----w- C:\Program Files (x86)\PDFCreator
2012-08-02 14:00:03 -------- d-----w- C:\Users\Peter\AppData\Roaming\SchreibTrainer4
2012-08-02 14:00:00 -------- d-----w- C:\Program Files (x86)\AB-Tools.com
2012-08-01 12:02:49 749568 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2012-08-01 12:02:49 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2012-08-01 12:02:49 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2012-08-01 12:02:49 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2012-08-01 12:02:49 180224 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2012-08-01 12:02:40 323716 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2012-08-01 12:02:40 192644 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2012-08-01 08:18:18 -------- d-----w- C:\Program Files (x86)\VideoLAN
2012-08-01 07:51:07 -------- d-----w- C:\Program Files (x86)\tmx5
2012-08-01 05:36:17 -------- d-----w- C:\Program Files (x86)\uTorrent
2012-08-01 05:31:23 -------- d-----w- C:\Users\Peter\AppData\Roaming\uTorrent
2012-07-31 11:06:00 -------- d-----w- C:\Users\Peter\AppData\Local\Diagnostics
2012-07-31 10:50:43 -------- d-----w- C:\Users\Peter\AppData\Local\ElevatedDiagnostics
2012-07-30 13:35:19 -------- d-----w- C:\Users\Peter\AppData\Roaming\7-PDFWebsiteConverter
2012-07-30 13:35:19 -------- d-----w- C:\Program Files (x86)\7-PDF
2012-07-29 17:19:43 -------- d-----w- C:\Users\Peter\AppData\Roaming\WikidPad
2012-07-29 15:56:54 -------- d-----w- C:\Users\Peter\AppData\Local\Macromedia
2012-07-29 15:56:27 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-29 15:56:27 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-29 15:46:55 -------- d-----w- C:\Users\Peter\AppData\Roaming\LibreOffice
2012-07-29 15:33:37 -------- d-----w- C:\Users\Peter\AppData\Local\Google
2012-07-29 15:25:44 -------- d-----w- C:\Users\Peter\AppData\Local\Thunderbird
2012-07-29 14:58:54 -------- d-----w- C:\Program Files (x86)\MozBackup
2012-07-29 07:05:16 -------- d-----w- C:\Program Files (x86)\WikidPad
2012-07-29 06:55:35 -------- d-----w- C:\Program Files (x86)\GIMP 2
2012-07-29 06:21:36 -------- d-----w- C:\Users\Peter\AppData\Local\Adobe
2012-07-29 06:21:04 -------- d-----w- C:\Program Files (x86)\LibreOffice 3.5
2012-07-27 14:59:42 -------- d-----w- C:\Program Files (x86)\Microsoft WSE
2012-07-27 14:59:36 3977496 ----a-w- C:\Windows\System32\d3dx9_31.dll
2012-07-27 14:59:36 2414360 ----a-w- C:\Windows\SysWow64\d3dx9_31.dll
2012-07-27 14:34:56 -------- d-----r- C:\Program Files (x86)\Skype
2012-07-27 11:46:12 -------- d-----w- C:\Program Files (x86)\SpeedFan
2012-07-27 11:38:05 -------- d-----w- C:\Program Files (x86)\Motherboard Monitor 5
2012-07-27 06:45:34 -------- d-----w- C:\Program Files (x86)\Rockstar Games
2012-07-27 06:42:46 -------- d-----w- C:\Program Files (x86)\OpenApp
2012-07-27 06:42:27 -------- d-----w- C:\Program Files (x86)\smartdl
2012-07-27 06:40:12 -------- d-----w- C:\Windows\SysWow64\wbem\en-US
2012-07-27 06:40:11 -------- d-----w- C:\Windows\System32\wbem\en-US
2012-07-27 06:40:10 -------- d-----w- C:\Windows\SysWow64\Wat
2012-07-27 06:40:10 -------- d-----w- C:\Windows\System32\Wat
2012-07-27 06:36:56 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-27 06:29:34 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-07-27 06:29:34 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-07-27 06:29:34 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-07-27 06:29:34 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-07-27 06:29:34 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-07-27 06:29:34 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-07-27 06:29:34 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-07-27 06:10:34 114176 ----a-w- C:\Windows\SysWow64\PCWizard.cpl
2012-07-27 06:10:34 -------- d-----w- C:\Program Files (x86)\CPUID
2012-07-27 06:04:29 -------- d-----w- C:\Users\Peter\AppData\Local\Mozilla
2012-07-27 05:58:14 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2012-07-27 05:58:14 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2012-07-27 05:46:08 -------- d-----w- C:\Users\Peter\AppData\Roaming\AVG2012
2012-07-27 05:44:53 -------- d-----w- C:\Windows\SysWow64\drivers\AVG
2012-07-27 05:44:51 -------- d--h--w- C:\$AVG
2012-07-27 05:44:51 -------- d-----w- C:\Windows\System32\drivers\AVG
2012-07-27 05:44:51 -------- d-----w- C:\ProgramData\AVG2012
2012-07-27 05:44:43 -------- d-----w- C:\Program Files (x86)\AVG
2012-07-27 05:37:49 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-07-27 05:36:53 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2012-07-27 05:35:22 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-07-27 05:35:21 9133488 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E40F3BDC-4576-4124-8CFA-E54372177044}\mpengine.dll
2012-07-26 20:58:37 -------- d-----w- C:\Windows\Panther
2012-07-26 20:25:38 -------- d-----w- C:\Program Files (x86)\Etron Technology
2012-07-26 20:24:57 104560 ----a-w- C:\Windows\System32\drivers\L1C62x64.sys
2012-07-26 20:24:53 16152 ----a-w- C:\Windows\System32\drivers\iusb3hcs.sys
2012-07-26 20:24:44 356120 ----a-w- C:\Windows\System32\drivers\iusb3hub.sys
2012-07-26 20:24:42 787736 ----a-w- C:\Windows\System32\drivers\iusb3xhc.sys
2012-07-26 20:24:42 -------- d-----w- C:\Windows\SysWow64\Atheros_L1e
2012-07-26 20:22:32 -------- d-----w- C:\Program Files\Common Files\Intel
2012-07-26 20:21:08 15128 ----a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll
2012-07-26 20:20:51 53248 ----a-r- C:\Windows\SysWow64\CSVer.dll
2012-07-26 20:20:50 -------- d-sh--w- C:\Windows\Installer
2012-07-26 20:20:46 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
2012-07-26 20:20:39 -------- d-----w- C:\Intel
2012-07-26 20:20:37 60184 ----a-w- C:\Windows\System32\drivers\HECIx64.sys
2012-07-26 20:09:27 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-07-26 20:09:27 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-07-26 20:09:27 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-07-26 20:06:42 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-07-26 20:06:41 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-07-26 20:06:40 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-07-26 20:06:40 186752 ----a-w- C:\Windows\System32\wuwebv.dll
.
==================== Find3M ====================
.
2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-05-31 10:25:12 279656 ------w- C:\Windows\System32\MpSigStub.exe
.
============= FINISH: 19:45:48,10 ===============
Attach:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 26.07.2012 22:05:25
System Uptime: 14.08.2012 19:16:49 (0 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. | | Z77-D3H
Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz | Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz | 3801/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 141 GiB total, 88,043 GiB free.
D: is FIXED (NTFS) - 932 GiB total, 903,235 GiB free.
E: is CDROM (UDF)
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft Virtual WiFi Miniport Adapter
Device ID: {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP\5&2D559611&0&01
Manufacturer: Microsoft
Name: Microsoft Virtual WiFi Miniport Adapter
PNP Device ID: {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP\5&2D559611&0&01
Service: vwifimp
.
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: Microsoft PS/2-Maus
Device ID: ACPI\PNP0F03\4&FA2F13B&0
Manufacturer: Microsoft
Name: Microsoft PS/2-Maus
PNP Device ID: ACPI\PNP0F03\4&FA2F13B&0
Service: i8042prt
.
Class GUID: {4d36e96b-e325-11ce-bfc1-08002be10318}
Description: Standardtastatur (PS/2)
Device ID: ACPI\PNP0303\4&FA2F13B&0
Manufacturer: (Standardtastaturen)
Name: Standardtastatur (PS/2)
PNP Device ID: ACPI\PNP0303\4&FA2F13B&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP20: 01.08.2012 09:51:03 - *tmx spanisch wird installiert
RP21: 01.08.2012 09:53:04 - *tmx englisch wird installiert
RP22: 01.08.2012 14:04:29 - Installed GTA San Andreas
RP23: 01.08.2012 17:01:34 - Gerätetreiber-Paketinstallation: Microsoft Netzwerkadapter
RP24: 06.08.2012 17:59:12 - Windows Update
RP25: 14.08.2012 15:16:22 - Geplanter Prüfpunkt
.
==== Installed Programs ======================
.
*tmx englisch
*tmx spanisch
7-PDF Website Converter Version 1.0.6 (Build 164)
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3) - Deutsch
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
µTorrent
Die Sims™ 3
Die Sims™ 3 Einfach tierisch
Die Sims™ 3 Luxus-Accessoires
Etron USB3.0 Host Controller
Google Earth Plug-in
Google Update Helper
GTA San Andreas
GTASA-Ultimate Editor
Intel(R) Management Engine Components
Intel(R) OpenCL CPU Runtime
Intel(R) Processor Graphics
Intel(R) USB 3.0 eXtensible Host Controller Driver
LibreOffice 3.5
Malwarebytes Anti-Malware Version 1.62.0.1300
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft WSE 3.0 Runtime
MozBackup 1.5.1
Mozilla Firefox 14.0.1 (x86 de)
Mozilla Thunderbird 14.0 (x86 de)
ON_OFF Charge B11.1102.1
PC Wizard 2012.2.1
PDFCreator
Platform
Schreib-Trainer 4.1.3
Skype™ 5.10
SpeedFan (remove only)
Spybot - Search & Destroy
VIA Plattform-Geräte-Manager
VideoFileDownload
Visual Studio 2008 x64 Redistributables
VLC media player 2.0.3
WikidPad 2.1
.
==== End Of File ===========================
I get pop ups with the ib.adnxs.com url when I open for example youtube songs in firefox (not with ie).
Thank you for your help!
DDS:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 19:45:36 on 2012-08-14
Microsoft Windows 7 Professional 6.1.7601.1.1252.43.1031.18.8086.5926 [GMT 2:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\viakaraokesrv.exe
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\mobsync.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: {BA0454C5-FD30-428E-8DB9-3FF87A612F64} - No File
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/s ... wflash.cab
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{07787C27-73E5-44CD-82D0-9B2E8F3B7994} : DhcpNameServer = 10.0.0.138
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}
{53707962-6F74-2D53-2644-206D7942484F}
BHO-X64: {BA0454C5-FD30-428E-8DB9-3FF87A612F64} - No File
mRun-x64: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun-x64: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\qx56zo0x.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://ixquick.com/
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll
.
---- FIREFOX POLICIES ----
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys --> C:\Windows\system32\DRIVERS\avgidsha.sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;C:\Windows\system32\DRIVERS\iusb3hcs.sys --> C:\Windows\system32\DRIVERS\iusb3hcs.sys [?]
R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys --> C:\Windows\system32\DRIVERS\AppleCharger.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-7-4 5160568]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-8 607456]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-7-26 161560]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2012-7-27 1153368]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-7-26 363800]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\Windows\system32\viakaraokesrv.exe --> C:\Windows\system32\viakaraokesrv.exe [?]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys --> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys --> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\system32\Drivers\EtronHub3.sys --> C:\Windows\system32\Drivers\EtronHub3.sys [?]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\system32\Drivers\EtronXHCI.sys --> C:\Windows\system32\Drivers\EtronXHCI.sys [?]
R3 IntcDAud;Intel(R) Display-Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;C:\Windows\system32\DRIVERS\iusb3hub.sys --> C:\Windows\system32\DRIVERS\iusb3hub.sys [?]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;C:\Windows\system32\DRIVERS\iusb3xhc.sys --> C:\Windows\system32\DRIVERS\iusb3xhc.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\system32\drivers\viahduaa.sys --> C:\Windows\system32\drivers\viahduaa.sys [?]
S2 gupdate;Google Update-Dienst (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-29 116648]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-7-29 250056]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 cphs;Intel(R) Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-7-26 274200]
S3 cpuz135;cpuz135;C:\Program Files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys [2012-7-27 23816]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 gupdatem;Google Update-Dienst (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-29 116648]
S3 StorSvc;Speicherdienst;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S3 WatAdminSvc;Windows-Aktivierungstechnologieservice;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-08-14 16:31:06 -------- d-----w- C:\Users\Peter\AppData\Roaming\Malwarebytes
2012-08-14 16:30:52 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-08-14 16:30:52 -------- d-----w- C:\ProgramData\Malwarebytes
2012-08-14 16:30:52 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-07 08:23:55 -------- d-----w- C:\Program Files (x86)\GTASA-Ultimate Editor
2012-08-07 08:23:41 249856 ------w- C:\Windows\Setup1.exe
2012-08-07 08:23:40 73216 ----a-w- C:\Windows\ST6UNST.EXE
2012-08-06 17:41:49 99840 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\HPZPPLHN.DLL
2012-08-03 09:51:39 -------- d-----w- C:\Users\Peter\AppData\Roaming\pdfforge
2012-08-03 09:51:38 95744 ----a-w- C:\Windows\System32\pdfcmon.dll
2012-08-03 09:51:38 662288 ----a-w- C:\Windows\SysWow64\MSCOMCT2.OCX
2012-08-03 09:51:38 137000 ----a-w- C:\Windows\SysWow64\MSMAPI32.OCX
2012-08-03 09:51:38 1071088 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX
2012-08-03 09:51:37 64512 ----a-w- C:\Windows\SysWow64\MSCC2DE.DLL
2012-08-03 09:51:37 23552 ----a-w- C:\Windows\SysWow64\MSMPIDE.DLL
2012-08-03 09:51:37 158208 ----a-w- C:\Windows\SysWow64\MSCMCDE.DLL
2012-08-03 09:51:37 125712 ----a-w- C:\Windows\SysWow64\VB6DE.DLL
2012-08-03 09:51:37 -------- d-----w- C:\Program Files (x86)\PDFCreator
2012-08-02 14:00:03 -------- d-----w- C:\Users\Peter\AppData\Roaming\SchreibTrainer4
2012-08-02 14:00:00 -------- d-----w- C:\Program Files (x86)\AB-Tools.com
2012-08-01 12:02:49 749568 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2012-08-01 12:02:49 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2012-08-01 12:02:49 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2012-08-01 12:02:49 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2012-08-01 12:02:49 180224 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2012-08-01 12:02:40 323716 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2012-08-01 12:02:40 192644 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2012-08-01 08:18:18 -------- d-----w- C:\Program Files (x86)\VideoLAN
2012-08-01 07:51:07 -------- d-----w- C:\Program Files (x86)\tmx5
2012-08-01 05:36:17 -------- d-----w- C:\Program Files (x86)\uTorrent
2012-08-01 05:31:23 -------- d-----w- C:\Users\Peter\AppData\Roaming\uTorrent
2012-07-31 11:06:00 -------- d-----w- C:\Users\Peter\AppData\Local\Diagnostics
2012-07-31 10:50:43 -------- d-----w- C:\Users\Peter\AppData\Local\ElevatedDiagnostics
2012-07-30 13:35:19 -------- d-----w- C:\Users\Peter\AppData\Roaming\7-PDFWebsiteConverter
2012-07-30 13:35:19 -------- d-----w- C:\Program Files (x86)\7-PDF
2012-07-29 17:19:43 -------- d-----w- C:\Users\Peter\AppData\Roaming\WikidPad
2012-07-29 15:56:54 -------- d-----w- C:\Users\Peter\AppData\Local\Macromedia
2012-07-29 15:56:27 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-29 15:56:27 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-29 15:46:55 -------- d-----w- C:\Users\Peter\AppData\Roaming\LibreOffice
2012-07-29 15:33:37 -------- d-----w- C:\Users\Peter\AppData\Local\Google
2012-07-29 15:25:44 -------- d-----w- C:\Users\Peter\AppData\Local\Thunderbird
2012-07-29 14:58:54 -------- d-----w- C:\Program Files (x86)\MozBackup
2012-07-29 07:05:16 -------- d-----w- C:\Program Files (x86)\WikidPad
2012-07-29 06:55:35 -------- d-----w- C:\Program Files (x86)\GIMP 2
2012-07-29 06:21:36 -------- d-----w- C:\Users\Peter\AppData\Local\Adobe
2012-07-29 06:21:04 -------- d-----w- C:\Program Files (x86)\LibreOffice 3.5
2012-07-27 14:59:42 -------- d-----w- C:\Program Files (x86)\Microsoft WSE
2012-07-27 14:59:36 3977496 ----a-w- C:\Windows\System32\d3dx9_31.dll
2012-07-27 14:59:36 2414360 ----a-w- C:\Windows\SysWow64\d3dx9_31.dll
2012-07-27 14:34:56 -------- d-----r- C:\Program Files (x86)\Skype
2012-07-27 11:46:12 -------- d-----w- C:\Program Files (x86)\SpeedFan
2012-07-27 11:38:05 -------- d-----w- C:\Program Files (x86)\Motherboard Monitor 5
2012-07-27 06:45:34 -------- d-----w- C:\Program Files (x86)\Rockstar Games
2012-07-27 06:42:46 -------- d-----w- C:\Program Files (x86)\OpenApp
2012-07-27 06:42:27 -------- d-----w- C:\Program Files (x86)\smartdl
2012-07-27 06:40:12 -------- d-----w- C:\Windows\SysWow64\wbem\en-US
2012-07-27 06:40:11 -------- d-----w- C:\Windows\System32\wbem\en-US
2012-07-27 06:40:10 -------- d-----w- C:\Windows\SysWow64\Wat
2012-07-27 06:40:10 -------- d-----w- C:\Windows\System32\Wat
2012-07-27 06:36:56 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-27 06:29:34 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-07-27 06:29:34 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-07-27 06:29:34 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-07-27 06:29:34 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-07-27 06:29:34 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-07-27 06:29:34 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-07-27 06:29:34 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-07-27 06:10:34 114176 ----a-w- C:\Windows\SysWow64\PCWizard.cpl
2012-07-27 06:10:34 -------- d-----w- C:\Program Files (x86)\CPUID
2012-07-27 06:04:29 -------- d-----w- C:\Users\Peter\AppData\Local\Mozilla
2012-07-27 05:58:14 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2012-07-27 05:58:14 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2012-07-27 05:46:08 -------- d-----w- C:\Users\Peter\AppData\Roaming\AVG2012
2012-07-27 05:44:53 -------- d-----w- C:\Windows\SysWow64\drivers\AVG
2012-07-27 05:44:51 -------- d--h--w- C:\$AVG
2012-07-27 05:44:51 -------- d-----w- C:\Windows\System32\drivers\AVG
2012-07-27 05:44:51 -------- d-----w- C:\ProgramData\AVG2012
2012-07-27 05:44:43 -------- d-----w- C:\Program Files (x86)\AVG
2012-07-27 05:37:49 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-07-27 05:36:53 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2012-07-27 05:35:22 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-07-27 05:35:21 9133488 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E40F3BDC-4576-4124-8CFA-E54372177044}\mpengine.dll
2012-07-26 20:58:37 -------- d-----w- C:\Windows\Panther
2012-07-26 20:25:38 -------- d-----w- C:\Program Files (x86)\Etron Technology
2012-07-26 20:24:57 104560 ----a-w- C:\Windows\System32\drivers\L1C62x64.sys
2012-07-26 20:24:53 16152 ----a-w- C:\Windows\System32\drivers\iusb3hcs.sys
2012-07-26 20:24:44 356120 ----a-w- C:\Windows\System32\drivers\iusb3hub.sys
2012-07-26 20:24:42 787736 ----a-w- C:\Windows\System32\drivers\iusb3xhc.sys
2012-07-26 20:24:42 -------- d-----w- C:\Windows\SysWow64\Atheros_L1e
2012-07-26 20:22:32 -------- d-----w- C:\Program Files\Common Files\Intel
2012-07-26 20:21:08 15128 ----a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll
2012-07-26 20:20:51 53248 ----a-r- C:\Windows\SysWow64\CSVer.dll
2012-07-26 20:20:50 -------- d-sh--w- C:\Windows\Installer
2012-07-26 20:20:46 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
2012-07-26 20:20:39 -------- d-----w- C:\Intel
2012-07-26 20:20:37 60184 ----a-w- C:\Windows\System32\drivers\HECIx64.sys
2012-07-26 20:09:27 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-07-26 20:09:27 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-07-26 20:09:27 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-07-26 20:06:42 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-07-26 20:06:41 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-07-26 20:06:40 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-07-26 20:06:40 186752 ----a-w- C:\Windows\System32\wuwebv.dll
.
==================== Find3M ====================
.
2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-05-31 10:25:12 279656 ------w- C:\Windows\System32\MpSigStub.exe
.
============= FINISH: 19:45:48,10 ===============
Attach:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 26.07.2012 22:05:25
System Uptime: 14.08.2012 19:16:49 (0 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. | | Z77-D3H
Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz | Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz | 3801/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 141 GiB total, 88,043 GiB free.
D: is FIXED (NTFS) - 932 GiB total, 903,235 GiB free.
E: is CDROM (UDF)
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft Virtual WiFi Miniport Adapter
Device ID: {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP\5&2D559611&0&01
Manufacturer: Microsoft
Name: Microsoft Virtual WiFi Miniport Adapter
PNP Device ID: {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP\5&2D559611&0&01
Service: vwifimp
.
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: Microsoft PS/2-Maus
Device ID: ACPI\PNP0F03\4&FA2F13B&0
Manufacturer: Microsoft
Name: Microsoft PS/2-Maus
PNP Device ID: ACPI\PNP0F03\4&FA2F13B&0
Service: i8042prt
.
Class GUID: {4d36e96b-e325-11ce-bfc1-08002be10318}
Description: Standardtastatur (PS/2)
Device ID: ACPI\PNP0303\4&FA2F13B&0
Manufacturer: (Standardtastaturen)
Name: Standardtastatur (PS/2)
PNP Device ID: ACPI\PNP0303\4&FA2F13B&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP20: 01.08.2012 09:51:03 - *tmx spanisch wird installiert
RP21: 01.08.2012 09:53:04 - *tmx englisch wird installiert
RP22: 01.08.2012 14:04:29 - Installed GTA San Andreas
RP23: 01.08.2012 17:01:34 - Gerätetreiber-Paketinstallation: Microsoft Netzwerkadapter
RP24: 06.08.2012 17:59:12 - Windows Update
RP25: 14.08.2012 15:16:22 - Geplanter Prüfpunkt
.
==== Installed Programs ======================
.
*tmx englisch
*tmx spanisch
7-PDF Website Converter Version 1.0.6 (Build 164)
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3) - Deutsch
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
µTorrent
Die Sims™ 3
Die Sims™ 3 Einfach tierisch
Die Sims™ 3 Luxus-Accessoires
Etron USB3.0 Host Controller
Google Earth Plug-in
Google Update Helper
GTA San Andreas
GTASA-Ultimate Editor
Intel(R) Management Engine Components
Intel(R) OpenCL CPU Runtime
Intel(R) Processor Graphics
Intel(R) USB 3.0 eXtensible Host Controller Driver
LibreOffice 3.5
Malwarebytes Anti-Malware Version 1.62.0.1300
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft WSE 3.0 Runtime
MozBackup 1.5.1
Mozilla Firefox 14.0.1 (x86 de)
Mozilla Thunderbird 14.0 (x86 de)
ON_OFF Charge B11.1102.1
PC Wizard 2012.2.1
PDFCreator
Platform
Schreib-Trainer 4.1.3
Skype™ 5.10
SpeedFan (remove only)
Spybot - Search & Destroy
VIA Plattform-Geräte-Manager
VideoFileDownload
Visual Studio 2008 x64 Redistributables
VLC media player 2.0.3
WikidPad 2.1
.
==== End Of File ===========================
text box. Do not include the word Code


