Instant Savings im Browser (bei FB, ebay ...)

Hallo zusammen,

seit ein paar Tagen nervt mich dieses "Instant Savings" auf Facebook, Ebay usw... Überall tauchen die Werbeflächen auf, sogar im Text. Wie kann ich diesen Mist wieder los werden? Finde weder bei den AddOns etwas, noch bei "Programme deinstallieren".

Schon mal vielen Dank für Eure Hilfe!


Hier noch die Inhalte
der FRST.txt

FRST Logfile:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-07-2013
Ran by Dominik (administrator) on 20-07-2013 00:10:38
Running from C:\Users\USERXXX\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Windows\SysWOW64\XSrvSetup.exe
(Microsoft Corporation) c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Akamai Technologies, Inc.) C:\Users\USERXXX\AppData\Local\Akamai\netsession_win.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Spotify Ltd) C:\Users\USERXXX\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Akamai Technologies, Inc.) C:\Users\USERXXX\AppData\Local\Akamai\netsession_win.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2000-01-01] (Microsoft Corporation)
HKLM\...\Run: [itype] - C:\Program Files\Microsoft IntelliType Pro\itype.exe [1873256 2000-01-01] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12879976 2000-01-01] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-03] (NVIDIA Corporation)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\USERXXX\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\USERXXX\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-10] (Spotify Ltd)
MountPoints2: {17452ba4-0498-11e0-b381-bc054301286b} - E:\Autorun.exe
MountPoints2: {3bbc047a-fb02-11df-9f79-806e6f6e6963} - D:\autorun.exe
MountPoints2: {6e59b409-531f-11e2-bd6a-00241d74b654} - E:\AutoRun.exe
MountPoints2: {6e59b41b-531f-11e2-bd6a-00241d74b654} - E:\AutoRun.exe
MountPoints2: {d4e4449f-fb02-11df-a917-00241d74b654} - E:\pushinst.exe
HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [] -  [x]
HKLM-x32\...\Run: [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-06-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

ProxyServer: :0
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.zona-de-galgos.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
URLSearchHook: (No Name) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} -  No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Plus-HD-2.3 - {11111111-1111-1111-1111-110311341126} - C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-bho.dll (Plus HD)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
DPF: HKLM-x32 {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} file:///D:/components/hidinputmonitorx.ocx
DPF: HKLM-x32 {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} file:///D:/components/A9.ocx
DPF: HKLM-x32 {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} file:///D:/components/wmvhdrating.ocx
DPF: HKLM-x32 {B07F54E6-0806-47DB-B5D8-398F240776F2} file:///D:/viewer/ORDcmViewCD.ocx
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\USERXXX\AppData\Roaming\Mozilla\Firefox\Profiles\v4fwmwdp.default
FF user.js: detected! => C:\Users\USERXXX\AppData\Roaming\Mozilla\Firefox\Profiles\v4fwmwdp.default\user.js
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=3 - C:\Program Files (x86)\DealPlyLive\Update\\npGoogleUpdate3.dll (DealPly Technologies Ltd)
FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=9 - C:\Program Files (x86)\DealPlyLive\Update\\npGoogleUpdate3.dll (DealPly Technologies Ltd)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\USERXXX\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\USERXXX\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101714.dll (Amazon.com, Inc.)
FF Extension: No Name - C:\Users\USERXXX\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com
FF Extension: No Name - C:\Users\USERXXX\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
FF Extension: No Name - C:\Users\USERXXX\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: No Name - C:\Users\USERXXX\AppData\Roaming\Mozilla\Firefox\Profiles\v4fwmwdp.default\Extensions\7125a285-7e68-47aa-9d72-e81874f4d47e@d3fcdb92-135d-4a8a-8cf6-11e3b57c5fda.com
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\

CHR HomePage: hxxp://www.mediterrane-landschildkroeten.de/
CHR RestoreOnStartup: "hxxp://www.mediterrane-landschildkroeten.de/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\USERXXX\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\USERXXX\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\USERXXX\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101714.dll (Amazon.com, Inc.)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (PlayStation(R)Network Downloader Check Plug-in) - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll No File
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll No File
CHR Plugin: (Windows Activation Technologies) - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (YouTube) - C:\Users\USERXXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\USERXXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\
CHR Extension: (Plus-HD-2.3) - C:\Users\USERXXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.23.17_0
CHR Extension: (Gmail) - C:\Users\USERXXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [hphibigbodkkohoglgfkddblldpfohjl] - C:\Program Files (x86)\TorrentHandler\TorrentHandler.crx
CHR HKLM-x32\...\Chrome\Extension: [jbpkiefagocgkmemidfngdkamloieekf] - C:\Program Files (x86)\TornTV.com\torn10.crx
CHR HKLM-x32\...\Chrome\Extension: [pmlghpafmmnmmkjdhacccolfgnkiboco] - C:\Program Files (x86)\1ClickDownload\oneclickdownloader12.crx

==================== Services (Whitelisted) =================

R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-02] (Akamai Technologies, Inc.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-24] (Avira Operations GmbH & Co. KG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin)
S2 dealplylive; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-07-17] (DealPly Technologies Ltd)
S3 dealplylivem; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-07-17] (DealPly Technologies Ltd)
R2 JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [72280 2000-01-01] ()
R2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2011-11-27] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-29] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-29] (Avira Operations GmbH & Co. KG)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2009-03-20] (AVM Berlin)
R3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [552704 2009-03-20] (AVM GmbH)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2011-11-27] ()
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [508472 2011-10-05] (Duplex Secure Ltd.)
S2 SSPORT; C:\Windows\SysWow64\Drivers\SSPORT.sys [11576 2009-09-10] (Samsung Electronics)
S3 V0540Dev; C:\Windows\System32\DRIVERS\V0540Vid.sys [321376 2009-06-15] (Creative Technology Ltd.)
S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [x]
S2 SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-07-20 00:10 - 2013-07-20 00:10 - 00000000 ____D C:\FRST
2013-07-20 00:09 - 2013-07-20 00:10 - 01779345 _____ (Farbar) C:\Users\USERXXX\Desktop\FRST64.exe
2013-07-20 00:00 - 2013-07-20 00:00 - 00602112 _____ (OldTimer Tools) C:\Users\USERXXX\Desktop\OTL.exe
2013-07-20 00:00 - 2013-07-20 00:00 - 00000586 _____ C:\Users\USERXXX\Desktop\defogger_disable.log
2013-07-20 00:00 - 2013-07-20 00:00 - 00000020 _____ C:\Users\USERXXX\defogger_reenable
2013-07-19 23:59 - 2013-07-19 23:59 - 00050477 _____ C:\Users\USERXXX\Desktop\Defogger.exe
2013-07-19 23:22 - 2013-07-20 00:01 - 00000112 _____ C:\Windows\setupact.log
2013-07-19 23:22 - 2013-07-19 23:22 - 00002306 _____ C:\Windows\PFRO.log
2013-07-19 23:22 - 2013-07-19 23:22 - 00000000 _____ C:\Windows\setuperr.log
2013-07-19 23:21 - 2013-07-19 23:21 - 00000085 _____ C:\Windows\wininit.ini
2013-07-19 21:06 - 2013-07-19 21:06 - 00009216 _____ C:\Users\USERXXX\Desktop\cc_20130719_210610.reg
2013-07-19 21:05 - 2013-07-19 21:05 - 00000333 _____ C:\AdwCleaner[S1].txt
2013-07-19 21:03 - 2013-07-19 21:05 - 00014005 _____ C:\AdwCleaner[R1].txt
2013-07-19 21:02 - 2013-07-19 21:03 - 00666633 _____ C:\Users\USERXXX\Desktop\adwcleaner.exe
2013-07-19 20:16 - 2013-07-19 20:38 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-07-19 20:16 - 2013-07-19 20:16 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-07-19 20:10 - 2013-07-19 20:15 - 36271144 _____ (Safer-Networking Ltd.                                       ) C:\Users\USERXXX\Desktop\spybot-2.1.exe
2013-07-19 14:52 - 2013-07-19 15:25 - 00000000 ____D C:\Users\USERXXX\AppData\Local\S2
2013-07-19 14:52 - 2013-07-19 14:52 - 00000000 __RHD C:\Users\USERXXX\AppData\Roaming\SecuROM
2013-07-19 14:52 - 2013-07-19 14:52 - 00000000 ____D C:\Users\USERXXX\Documents\S2
2013-07-19 12:48 - 2013-07-19 12:48 - 00002548 _____ C:\Users\UpdatusUser\Desktop\Die Siedler II - Die nächste Generation - Karteneditor.lnk
2013-07-19 12:48 - 2013-07-19 12:48 - 00002548 _____ C:\Users\USERXXX\Desktop\Die Siedler II - Die nächste Generation - Karteneditor.lnk
2013-07-19 12:48 - 2013-07-19 12:48 - 00002502 _____ C:\Users\UpdatusUser\Desktop\Die Siedler II - Die nächste Generation.lnk
2013-07-19 12:48 - 2013-07-19 12:48 - 00002502 _____ C:\Users\USERXXX\Desktop\Die Siedler II - Die nächste Generation.lnk
2013-07-19 12:48 - 2013-07-19 12:48 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-07-19 12:47 - 2013-07-19 12:47 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-07-19 10:17 - 2013-07-19 10:17 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-07-19 10:17 - 2013-07-19 10:17 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-07-19 10:17 - 2013-07-19 10:17 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-07-19 10:17 - 2013-07-19 10:17 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-07-19 10:17 - 2013-07-19 10:17 - 00000000 ____D C:\Program Files\Java
2013-07-19 10:16 - 2013-07-19 10:16 - 00000000 ____D C:\ProgramData\Apple Computer
2013-07-19 10:15 - 2013-07-19 10:15 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-07-18 09:56 - 2013-07-18 09:56 - 00001724 _____ C:\Users\Public\Desktop\Defraggler.lnk
2013-07-18 09:55 - 2013-07-18 09:55 - 03839648 _____ (Piriform Ltd) C:\Users\USERXXX\Downloads\dfsetup214.exe
2013-07-17 15:46 - 2013-07-17 15:46 - 00011492 _____ C:\Users\USERXXX\Desktop\cc_20130717_154623.reg
2013-07-17 15:32 - 2013-07-17 15:32 - 04396440 _____ (Piriform Ltd) C:\Users\USERXXX\Downloads\ccsetup403.exe
2013-07-17 15:23 - 2013-07-20 00:02 - 00001198 _____ C:\Windows\Tasks\Plus-HD-2.3-updater.job
2013-07-17 15:23 - 2013-07-20 00:01 - 00001910 _____ C:\Windows\Tasks\Plus-HD-2.3-chromeinstaller.job
2013-07-17 15:23 - 2013-07-20 00:01 - 00001834 _____ C:\Windows\Tasks\Plus-HD-2.3-firefoxinstaller.job
2013-07-17 15:23 - 2013-07-20 00:01 - 00001202 _____ C:\Windows\Tasks\Plus-HD-2.3-codedownloader.job
2013-07-17 15:23 - 2013-07-20 00:01 - 00001102 _____ C:\Windows\Tasks\Plus-HD-2.3-enabler.job
2013-07-17 15:23 - 2013-07-17 15:23 - 17273952 _____ C:\Users\USERXXX\Downloads\SETUP_A1-Faktura.exe
2013-07-17 15:23 - 2013-07-17 15:23 - 00004232 _____ C:\Windows\System32\Tasks\Plus-HD-2.3-codedownloader
2013-07-17 15:23 - 2013-07-17 15:23 - 00004228 _____ C:\Windows\System32\Tasks\Plus-HD-2.3-updater
2013-07-17 15:23 - 2013-07-17 15:23 - 00004132 _____ C:\Windows\System32\Tasks\Plus-HD-2.3-enabler
2013-07-17 15:23 - 2013-07-17 15:23 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.3
2013-07-17 15:22 - 2013-07-20 00:01 - 00000904 _____ C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job
2013-07-17 15:22 - 2013-07-19 23:27 - 00000908 _____ C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job
2013-07-17 15:22 - 2013-07-17 15:22 - 00003904 _____ C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineUA
2013-07-17 15:22 - 2013-07-17 15:22 - 00003652 _____ C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineCore
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\Dealply
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\Users\USERXXX\AppData\Local\DealPlyLive
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\ProgramData\DealPlyLive
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\Program Files (x86)\DealPlyLive
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\Program Files (x86)\DealPly
2013-07-17 15:21 - 2013-07-17 15:21 - 00620096 _____ C:\Users\USERXXX\Downloads\SETUP_A1-Faktura-Downloader.exe
2013-07-17 15:01 - 2013-07-17 15:01 - 00000000 ____D C:\Users\USERXXX\Desktop\herpedia
2013-07-17 15:00 - 2013-07-17 15:00 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\IT-Service Christian Hau (www.a-bit-more.de)
2013-07-17 14:58 - 2013-07-17 14:58 - 00001055 _____ C:\Users\UpdatusUser\Desktop\Zeiterfassung.lnk
2013-07-17 14:57 - 2013-07-17 14:58 - 06734957 _____ C:\Users\USERXXX\Downloads\Setup.Faktura.curr.zip
2013-07-13 10:27 - 2013-07-13 11:10 - 00000000 ____D C:\Users\USERXXX\Desktop\Schulunterricht
2013-07-10 17:54 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-10 17:54 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-10 17:54 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-10 17:54 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-10 17:54 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-10 17:54 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-10 17:54 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-10 17:54 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-10 17:54 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-10 17:54 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-10 17:54 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-10 17:54 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-10 17:54 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-10 17:54 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-10 17:54 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-10 17:54 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-10 17:54 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-10 17:54 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-10 17:54 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-10 17:54 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-10 17:54 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-10 17:54 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-10 17:54 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-10 17:54 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-10 17:54 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-10 17:54 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-10 17:54 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-10 17:54 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-10 17:54 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-10 17:54 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-10 17:54 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-10 10:53 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-10 10:53 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-10 10:53 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-10 10:53 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-10 10:53 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-10 10:53 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-10 10:53 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-03 13:00 - 2013-07-03 13:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 17:31 - 2013-07-02 17:31 - 04815135 _____ (FileZilla Project) C:\Users\USERXXX\Downloads\FileZilla_3.7.1_win32-setup.exe
2013-07-02 15:50 - 2013-07-02 15:50 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-07-02 15:48 - 2013-06-21 14:06 - 27781920 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 21102368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 15144928 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 13411896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 11235104 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-07-02 15:48 - 2013-06-21 14:06 - 09239344 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 07687592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 07641832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 06324360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 02953504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 02777888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 02363680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 02002720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432049.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432049.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 00572704 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 00570656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 00467232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-07-02 15:48 - 2013-06-21 14:06 - 00465184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-07-02 14:56 - 2013-07-02 14:56 - 00000000 ____D C:\Users\USERXXX\AppData\Local\NVIDIA
2013-06-27 13:44 - 2013-06-27 15:43 - 00000000 ____D C:\Users\USERXXX\Desktop\Werbung
2013-06-26 14:26 - 2013-06-26 15:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-21 05:16 - 2013-06-21 05:16 - 00566048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe

==================== One Month Modified Files and Folders =======

2013-07-20 00:10 - 2013-07-20 00:10 - 00000000 ____D C:\FRST
2013-07-20 00:10 - 2013-07-20 00:09 - 01779345 _____ (Farbar) C:\Users\USERXXX\Desktop\FRST64.exe
2013-07-20 00:09 - 2009-07-14 06:45 - 00014832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-20 00:09 - 2009-07-14 06:45 - 00014832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-20 00:08 - 2011-04-23 10:05 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3958744611-970375325-1774594619-1000UA.job
2013-07-20 00:02 - 2013-07-17 15:23 - 00001198 _____ C:\Windows\Tasks\Plus-HD-2.3-updater.job
2013-07-20 00:01 - 2013-07-19 23:22 - 00000112 _____ C:\Windows\setupact.log
2013-07-20 00:01 - 2013-07-17 15:23 - 00001910 _____ C:\Windows\Tasks\Plus-HD-2.3-chromeinstaller.job
2013-07-20 00:01 - 2013-07-17 15:23 - 00001834 _____ C:\Windows\Tasks\Plus-HD-2.3-firefoxinstaller.job
2013-07-20 00:01 - 2013-07-17 15:23 - 00001202 _____ C:\Windows\Tasks\Plus-HD-2.3-codedownloader.job
2013-07-20 00:01 - 2013-07-17 15:23 - 00001102 _____ C:\Windows\Tasks\Plus-HD-2.3-enabler.job
2013-07-20 00:01 - 2013-07-17 15:22 - 00000904 _____ C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job
2013-07-20 00:01 - 2010-11-28 21:31 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-20 00:01 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-20 00:00 - 2013-07-20 00:00 - 00602112 _____ (OldTimer Tools) C:\Users\USERXXX\Desktop\OTL.exe
2013-07-20 00:00 - 2013-07-20 00:00 - 00000586 _____ C:\Users\USERXXX\Desktop\defogger_disable.log
2013-07-20 00:00 - 2013-07-20 00:00 - 00000020 _____ C:\Users\USERXXX\defogger_reenable
2013-07-20 00:00 - 2012-09-06 21:08 - 01412770 _____ C:\Windows\WindowsUpdate.log
2013-07-20 00:00 - 2010-11-28 17:24 - 00000000 ____D C:\Users\USERXXX
2013-07-19 23:59 - 2013-07-19 23:59 - 00050477 _____ C:\Users\USERXXX\Desktop\Defogger.exe
2013-07-19 23:27 - 2013-07-17 15:22 - 00000908 _____ C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job
2013-07-19 23:27 - 2012-10-14 15:28 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-19 23:22 - 2013-07-19 23:22 - 00002306 _____ C:\Windows\PFRO.log
2013-07-19 23:22 - 2013-07-19 23:22 - 00000000 _____ C:\Windows\setuperr.log
2013-07-19 23:21 - 2013-07-19 23:21 - 00000085 _____ C:\Windows\wininit.ini
2013-07-19 21:16 - 2013-03-18 14:43 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\Spotify
2013-07-19 21:06 - 2013-07-19 21:06 - 00009216 _____ C:\Users\USERXXX\Desktop\cc_20130719_210610.reg
2013-07-19 21:05 - 2013-07-19 21:05 - 00000333 _____ C:\AdwCleaner[S1].txt
2013-07-19 21:05 - 2013-07-19 21:03 - 00014005 _____ C:\AdwCleaner[R1].txt
2013-07-19 21:03 - 2013-07-19 21:02 - 00666633 _____ C:\Users\USERXXX\Desktop\adwcleaner.exe
2013-07-19 20:38 - 2013-07-19 20:16 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-07-19 20:16 - 2013-07-19 20:16 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-07-19 20:15 - 2013-07-19 20:10 - 36271144 _____ (Safer-Networking Ltd.                                       ) C:\Users\USERXXX\Desktop\spybot-2.1.exe
2013-07-19 15:25 - 2013-07-19 14:52 - 00000000 ____D C:\Users\USERXXX\AppData\Local\S2
2013-07-19 14:52 - 2013-07-19 14:52 - 00000000 __RHD C:\Users\USERXXX\AppData\Roaming\SecuROM
2013-07-19 14:52 - 2013-07-19 14:52 - 00000000 ____D C:\Users\USERXXX\Documents\S2
2013-07-19 12:48 - 2013-07-19 12:48 - 00002548 _____ C:\Users\UpdatusUser\Desktop\Die Siedler II - Die nächste Generation - Karteneditor.lnk
2013-07-19 12:48 - 2013-07-19 12:48 - 00002548 _____ C:\Users\USERXXX\Desktop\Die Siedler II - Die nächste Generation - Karteneditor.lnk
2013-07-19 12:48 - 2013-07-19 12:48 - 00002502 _____ C:\Users\UpdatusUser\Desktop\Die Siedler II - Die nächste Generation.lnk
2013-07-19 12:48 - 2013-07-19 12:48 - 00002502 _____ C:\Users\USERXXX\Desktop\Die Siedler II - Die nächste Generation.lnk
2013-07-19 12:48 - 2013-07-19 12:48 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-07-19 12:47 - 2013-07-19 12:47 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-07-19 10:50 - 2012-02-11 16:49 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\SoftGrid Client
2013-07-19 10:29 - 2010-11-28 21:22 - 00000000 ____D C:\Users\USERXXX\AppData\Local\Adobe
2013-07-19 10:28 - 2012-10-14 15:28 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-19 10:28 - 2012-04-06 16:26 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-19 10:28 - 2011-05-16 10:43 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-19 10:17 - 2013-07-19 10:17 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-07-19 10:17 - 2013-07-19 10:17 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-07-19 10:17 - 2013-07-19 10:17 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-07-19 10:17 - 2013-07-19 10:17 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-07-19 10:17 - 2013-07-19 10:17 - 00000000 ____D C:\Program Files\Java
2013-07-19 10:17 - 2012-11-16 21:12 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-07-19 10:17 - 2012-11-16 21:12 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-07-19 10:16 - 2013-07-19 10:16 - 00000000 ____D C:\ProgramData\Apple Computer
2013-07-19 10:16 - 2011-07-02 14:35 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-07-19 10:15 - 2013-07-19 10:15 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-07-18 10:37 - 2011-08-24 06:56 - 00000000 ____D C:\Users\USERXXX\Desktop\Buchhaltung
2013-07-18 09:56 - 2013-07-18 09:56 - 00001724 _____ C:\Users\Public\Desktop\Defraggler.lnk
2013-07-18 09:56 - 2012-11-08 01:50 - 00000000 ____D C:\Program Files\Defraggler
2013-07-18 09:55 - 2013-07-18 09:55 - 03839648 _____ (Piriform Ltd) C:\Users\USERXXX\Downloads\dfsetup214.exe
2013-07-17 15:46 - 2013-07-17 15:46 - 00011492 _____ C:\Users\USERXXX\Desktop\cc_20130717_154623.reg
2013-07-17 15:45 - 2010-11-28 17:14 - 00000000 ____D C:\Windows\Panther
2013-07-17 15:33 - 2011-12-31 12:17 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-07-17 15:33 - 2011-12-31 12:17 - 00000000 ____D C:\Program Files\CCleaner
2013-07-17 15:32 - 2013-07-17 15:32 - 04396440 _____ (Piriform Ltd) C:\Users\USERXXX\Downloads\ccsetup403.exe
2013-07-17 15:23 - 2013-07-17 15:23 - 17273952 _____ C:\Users\USERXXX\Downloads\SETUP_A1-Faktura.exe
2013-07-17 15:23 - 2013-07-17 15:23 - 00004232 _____ C:\Windows\System32\Tasks\Plus-HD-2.3-codedownloader
2013-07-17 15:23 - 2013-07-17 15:23 - 00004228 _____ C:\Windows\System32\Tasks\Plus-HD-2.3-updater
2013-07-17 15:23 - 2013-07-17 15:23 - 00004132 _____ C:\Windows\System32\Tasks\Plus-HD-2.3-enabler
2013-07-17 15:23 - 2013-07-17 15:23 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.3
2013-07-17 15:22 - 2013-07-17 15:22 - 00003904 _____ C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineUA
2013-07-17 15:22 - 2013-07-17 15:22 - 00003652 _____ C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineCore
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\Dealply
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\Users\USERXXX\AppData\Local\DealPlyLive
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\ProgramData\DealPlyLive
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\Program Files (x86)\DealPlyLive
2013-07-17 15:22 - 2013-07-17 15:22 - 00000000 ____D C:\Program Files (x86)\DealPly
2013-07-17 15:21 - 2013-07-17 15:21 - 00620096 _____ C:\Users\USERXXX\Downloads\SETUP_A1-Faktura-Downloader.exe
2013-07-17 15:01 - 2013-07-17 15:01 - 00000000 ____D C:\Users\USERXXX\Desktop\herpedia
2013-07-17 15:00 - 2013-07-17 15:00 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\IT-Service Christian Hau (www.a-bit-more.de)
2013-07-17 14:58 - 2013-07-17 14:58 - 00001055 _____ C:\Users\UpdatusUser\Desktop\Zeiterfassung.lnk
2013-07-17 14:58 - 2013-07-17 14:57 - 06734957 _____ C:\Users\USERXXX\Downloads\Setup.Faktura.curr.zip
2013-07-13 15:32 - 2010-11-28 18:15 - 00124008 _____ C:\Users\USERXXX\AppData\Local\GDIPFONTCACHEV1.DAT
2013-07-13 15:11 - 2012-01-02 23:15 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-13 15:11 - 2012-01-02 23:15 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-13 11:10 - 2013-07-13 10:27 - 00000000 ____D C:\Users\USERXXX\Desktop\Schulunterricht
2013-07-13 08:23 - 2011-04-28 10:31 - 00000000 ____D C:\Users\USERXXX\Desktop\VORLAGEN
2013-07-13 07:08 - 2011-04-23 10:05 - 00001076 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3958744611-970375325-1774594619-1000Core.job
2013-07-13 07:03 - 2011-04-23 10:05 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3958744611-970375325-1774594619-1000UA
2013-07-13 07:03 - 2011-04-23 10:05 - 00003706 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3958744611-970375325-1774594619-1000Core
2013-07-13 07:00 - 2012-01-02 23:15 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-13 07:00 - 2012-01-02 23:15 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-10 19:52 - 2009-07-14 06:45 - 05086896 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-10 19:50 - 2009-07-14 20:18 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-10 19:50 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-10 19:50 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-10 18:01 - 2009-07-14 19:58 - 00756778 _____ C:\Windows\system32\perfh007.dat
2013-07-10 18:01 - 2009-07-14 19:58 - 00173252 _____ C:\Windows\system32\perfc007.dat
2013-07-10 18:01 - 2009-07-14 07:13 - 01789904 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-10 17:55 - 2010-11-29 09:16 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-07-10 10:16 - 2010-12-23 09:11 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\FileZilla
2013-07-10 10:11 - 2013-02-11 15:19 - 00000000 ____D C:\Users\USERXXX\Desktop\Fasching 2013
2013-07-10 09:09 - 2013-03-18 14:45 - 00000000 ____D C:\Users\USERXXX\AppData\Local\Spotify
2013-07-06 10:56 - 2013-01-31 20:50 - 00000000 ____D C:\Users\USERXXX\Desktop\Müller gg. FFF
2013-07-06 10:46 - 2010-12-05 19:08 - 00000000 ____D C:\Users\USERXXX\Desktop\Webseite2010
2013-07-03 19:56 - 2012-04-28 18:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-03 13:00 - 2013-07-03 13:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 17:48 - 2013-06-12 16:15 - 00010919 _____ C:\Users\USERXXX\Desktop\Gotthold.xlsx
2013-07-02 17:32 - 2013-05-13 10:14 - 00001960 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2013-07-02 17:32 - 2010-11-28 19:06 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2013-07-02 17:31 - 2013-07-02 17:31 - 04815135 _____ (FileZilla Project) C:\Users\USERXXX\Downloads\FileZilla_3.7.1_win32-setup.exe
2013-07-02 17:31 - 2012-11-04 15:51 - 00000000 ____D C:\Users\USERXXX\Desktop\schildkroetenforum.net_phpbb3
2013-07-02 15:50 - 2013-07-02 15:50 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-07-02 15:50 - 2010-11-28 21:31 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-07-02 14:56 - 2013-07-02 14:56 - 00000000 ____D C:\Users\USERXXX\AppData\Local\NVIDIA
2013-07-02 14:56 - 2010-11-28 21:30 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-06-30 10:57 - 2013-05-30 11:36 - 00000000 ____D C:\Users\USERXXX\Desktop\Webdesign
2013-06-30 10:56 - 2010-12-05 21:08 - 00000000 ____D C:\Users\USERXXX\Desktop\Bilder
2013-06-29 12:45 - 2011-11-10 11:27 - 00000000 ____D C:\Users\USERXXX\AppData\Local\Akamai
2013-06-27 15:43 - 2013-06-27 13:44 - 00000000 ____D C:\Users\USERXXX\Desktop\Werbung
2013-06-27 14:08 - 2012-02-16 16:39 - 00000099 _____ C:\Users\Public\LMDebug.log
2013-06-26 15:55 - 2011-03-10 18:32 - 00000000 ____D C:\Users\USERXXX\AppData\Roaming\Vocup
2013-06-26 15:29 - 2011-03-10 18:32 - 00000000 ____D C:\Users\USERXXX\Documents\Vokabelhefte
2013-06-26 15:22 - 2013-06-26 14:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-24 11:06 - 2013-05-07 12:18 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-06-21 14:06 - 2013-07-02 15:48 - 27781920 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 21102368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 15144928 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 13411896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 11235104 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-06-21 14:06 - 2013-07-02 15:48 - 09239344 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 07687592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 07641832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 06324360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 02953504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 02777888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 02363680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 02002720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432049.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432049.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 00572704 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 00570656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 00467232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-06-21 14:06 - 2013-07-02 15:48 - 00465184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-06-21 14:06 - 2013-05-25 01:27 - 12427240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-06-21 14:06 - 2013-05-25 01:27 - 02597856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-06-21 14:06 - 2013-02-26 00:32 - 15920536 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-06-21 14:06 - 2013-02-26 00:32 - 02936208 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-06-21 14:06 - 2010-11-28 21:30 - 00021578 _____ C:\Windows\system32\nvinfo.pb
2013-06-21 12:23 - 2010-10-16 14:13 - 06496544 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-06-21 12:23 - 2010-10-16 14:13 - 03514656 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-06-21 12:23 - 2010-10-16 14:13 - 02555680 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2013-06-21 12:23 - 2010-10-16 14:13 - 00884512 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-06-21 12:23 - 2010-10-16 14:13 - 00237856 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-06-21 12:23 - 2010-10-16 14:13 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-06-21 05:16 - 2013-06-21 05:16 - 00566048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-06-20 21:40 - 2012-11-27 21:41 - 00000000 ____D C:\Users\USERXXX\Desktop\medication

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2013-07-13 16:11

==================== End Of Log ============================
--- --- ---

--- --- ---

und der addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-07-2013
Ran by Dominik at 2013-07-20 00:11:17
Running from C:\Users\USERXXX\Desktop
Boot Mode: Normal

==================== Installed Programs =======================

64 Bit HP CIO Components Installer (Version: 7.2.8)
Adobe AIR (x32 Version:
Adobe Digital Editions (x32)
Adobe Download Assistant (x32 Version: 1.2.5)
Adobe Dreamweaver CS5 (x32 Version: 11.0)
Adobe Fireworks CS5 (x32 Version: 11.0)
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Help Manager (x32 Version: 4.0.244)
Adobe Media Player (x32 Version: 1.8)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
Adobe Shockwave Player 12.0 (x32 Version:
AIO_Scan (x32 Version: 130.0.365.000)
Akamai NetSession Interface (HKCU)
Akamai NetSession Interface Service (x32)
Amazon MP3-Downloader 1.0.17 (x32 Version: 1.0.17)
Apple Application Support (x32 Version: 2.3.4)
Apple Software Update (x32 Version:
Arclab Web Form Builder (x32)
Avira Free Antivirus (x32 Version:
Biologie heute CD (x32 Version: 1.0)
BufferChm (x32 Version: 130.0.331.000)
C7200 (x32 Version: 130.0.365.000)
C7200_Help (x32 Version:
CCleaner (Version: 4.03)
Chemie heute SII interaktiv (x32 Version: 27754)
Chinese Simplified Fonts Support For Adobe Reader X (x32 Version: 10.0.0)
Copy (x32 Version: 130.0.428.000)
Creative Live! Cam Video IM/Video Chat (VF0540) (
D3DX10 (x32 Version: 15.4.2368.0902)
Defraggler (Version: 2.14)
Destinations (x32 Version:
Deutsche Post E-Porto (x32 Version: 2.3.0)
DeviceDiscovery (x32 Version: 130.0.465.000)
Diablo III (x32 Version:
Die Siedler II - Die nächste Generation (x32)
Divinity II - Ego Draconis (x32)
DocProc (x32 Version:
Dropbox (HKCU Version: 2.0.22)
EAR 17 (x32 Version: 17.1)
ElsterFormular (x32 Version: 14.1.11318)
Fax (x32 Version: 130.0.418.000)
FileZilla Client 3.7.1 (x32 Version: 3.7.1)
Free YouTube to MP3 Converter version (x32 Version:
Gigabyte Raid Configurer (x32 Version:
Google Chrome (HKCU Version: 28.0.1500.72)
Google Update Helper (x32 Version:
GPBaseService2 (x32 Version: 130.0.371.000)
GSiteCrawler (x32 Version: v1.23)
HP Customer Participation Program 13.0 (Version: 13.0)
HP Imaging Device Functions 13.0 (Version: 13.0)
HP Photosmart All-In-One Driver Software 13.0 Rel. 2 (Version: 13.0)
HP Photosmart Essential 3.5 (Version: 3.5)
HP Smart Web Printing 4.51 (Version: 4.51)
HP Solution Center 13.0 (Version: 13.0)
HPDiagnosticAlert (x32 Version: 1.00.0000)
HPPhotoGadget (x32 Version:
HPPhotoSmartDiscLabel_PaperLabel (x32 Version: 2.04.0000)
HPPhotoSmartDiscLabel_PrintOnDisc (x32 Version: 2.04.0000)
HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000)
hpphotosmartdisclabelplugin (x32 Version: 2.04.0000)
HPPhotosmartEssential (x32 Version: 2.04.0000)
HPProductAssistant (x32 Version: 130.0.371.000)
HPSSupply (x32 Version: 130.0.371.000)
Image Resizer Powertoy Clone for Windows (64 bit) (Version: 2.1.1)
Inkscape (x32 Version:
Java 7 Update 21 (x32 Version: 7.0.210)
Java 7 Update 25 (64-bit) (Version: 7.0.250)
Java Auto Updater (x32 Version:
Java(TM) 6 Update 22 (x32 Version: 6.0.220)
Java(TM) 6 Update 29 (x32 Version: 6.0.290)
Litora in fenestris (x32 Version: 1.1.0)
MarketResearch (x32 Version: 130.0.374.000)
Mathcad PDSi viewable support (x32 Version: 9.0.0)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft IntelliPoint 8.2 (Version: 8.20.468.0)
Microsoft IntelliType Pro 8.2 (Version: 8.20.469.0)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Home and Student 2010 - Deutsch (x32 Version: 14.0.6114.5002)
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft SQL Server 2005 (x32)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) (x32 Version: 9.4.5000.00)
Microsoft SQL Server Native Client (Version: 9.00.5000.00)
Microsoft SQL Server VSS Writer (Version: 9.00.5000.00)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual J# 2.0 Redistributable Package (x32 Version: 2.0.50727)
Microsoft Visual J# 2.0 Redistributable Package (x32)
Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86 (x32 Version: 1.00.0000)
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000)
Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0)
Mozilla Maintenance Service (x32 Version: 22.0)
Mozilla Thunderbird 17.0.7 (x86 de) (x32 Version: 17.0.7)
MSVCRT (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Multiple Image Resizer .NET 4 (x32 Version:
Network64 (Version: 130.0.572.000)
Network64 (Version:
NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49)
NVIDIA 3D Vision Treiber 320.49 (Version: 320.49)
NVIDIA GeForce Experience 1.5.1 (Version: 1.5.1)
NVIDIA Grafiktreiber 320.49 (Version: 320.49)
NVIDIA Install Application (Version: 2.1002.125.816)
NVIDIA PhysX (x32 Version: 9.13.0604)
NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604)
NVIDIA Stereoscopic 3D Driver (x32 Version:
NVIDIA Systemsteuerung 320.49 (Version: 320.49)
NVIDIA Update 6.4.23 (Version: 6.4.23)
NVIDIA Update Components (Version: 6.4.23)
OCR Software by I.R.I.S. 13.0 (Version: 13.0)
on LBP3010/LBP3018/LBP3050
PDF/X-3 Inspector (Freeware) (x32)
Picasa 3 (x32 Version: 3.9)
Plus-HD-2.3 (x32 Version:
PS_AIO_02_ProductContext (x32 Version: 130.0.365.000)
PS_AIO_02_Software (x32 Version: 130.0.365.000)
PS_AIO_02_Software_Min (x32 Version: 130.0.365.000)
QuickTime (x32 Version:
Realtek Ethernet Controller Driver (x32 Version: 7.46.531.2011)
Realtek High Definition Audio Driver (x32 Version:
Risen (x32 Version: 1.00.0000)
Risen 2 - Dark Waters (x32)
Samsung Kies (x32 Version:
SAMSUNG USB Driver for Mobile Phones (Version:
Scan (x32 Version:
Shop for HP Supplies (Version: 13.0)
Skype™ 6.2 (x32 Version: 6.2.106)
SlimDrivers (x32 Version: 2.2.17058)
SmartWebPrinting (x32 Version: 130.0.457.000)
Softwarenetz Rechnung4 (x32)
SolutionCenter (x32 Version: 130.0.373.000)
Source SDK Base 2007 (x32)
Spotify (HKCU Version:
StarCraft II (x32 Version:
Status (x32 Version: 130.0.469.000)
Steam (x32 Version:
swMSM (x32 Version:
TeamViewer 8 (x32 Version: 8.0.16642)
The Elder Scrolls V: Skyrim (x32)
TomTom HOME (x32 Version:
TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2)
Toolbox (x32 Version: 130.0.648.000)
Tools für Microsoft SQL Server 2005 Express Edition (x32 Version: 9.4.5000.00)
TrayApp (x32 Version: 130.0.422.000)
tulox (x32)
UnloadSupport (x32 Version: 11.0.0)
Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (x32 Version: 9.00.5000.00)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Vocup 1.4.3 (x32 Version: 1.4.3)
Wartung Samsung CLP-320 Series (x32)
WebReg (x32 Version:
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)

==================== Restore Points  =========================

18-07-2013 14:25:15 Geplanter Prüfpunkt
19-07-2013 07:40:41 Windows Update
19-07-2013 08:15:46 Installed QuickTime
19-07-2013 08:17:12 Installed Java 7 Update 25 (64-bit)
19-07-2013 10:47:52 DirectX wurde installiert

==================== Hosts content: ==========================

2009-07-14 04:34 - 2010-12-09 07:50 - 00001254 ____A C:\Windows\system32\Drivers\etc\hosts localhost hl2rcv.adobe.com adobeereg.com activate.adobe.com practivate.adobe.com ereg.adobe.com activate.wip3.adobe.com ereg.wip3.adobe.com wip3.adobe.com activate-sea.adobe.com wwis-dubc1-vip60.adobe.com activate-sjc0.adobe.com 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com adobe-dns-5.adobe.com hh-software.com H+H Software GmbH activate.adobe.de practivate.adobe.de ereg.adobe.de activate.wip3.adobe.de

There are 11 more lines.

==================== Scheduled Tasks (whitelisted) =============

Task: {0A1FAA1C-D234-4A3B-B3CF-3358D2E1373A} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => C:\Program Files\Microsoft IntelliType Pro\IType.exe [2000-01-01] (Microsoft Corporation)
Task: {0C42DD15-9464-47F8-8473-B4E961C09844} - System32\Tasks\Plus-HD-2.3-firefoxinstaller => C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-firefoxinstaller.exe [2013-07-17] (Plus HD)
Task: {0FA8912E-2D66-4B19-BF6E-CC19DA4ED42A} - System32\Tasks\{5594E46A-6669-4724-B7B8-0B3964C7CF93} => D:\eFilmLt.exe No File
Task: {13BE7C1B-1E53-45EE-B1EB-E3D842E159DC} - System32\Tasks\Plus-HD-2.3-codedownloader => C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-codedownloader.exe [2013-07-17] (Plus HD)
Task: {1A433075-D9AF-43D7-8B93-CFA2AA3EC4F8} - System32\Tasks\{B16F6FDA-D79F-4992-89A6-602117CFDBB0} => D:\eFilmLt.exe No File
Task: {1FD9F13B-B328-492E-B8EF-B5F74BC09525} - System32\Tasks\{F304EA15-BFB2-4929-973C-6734B2D51A01} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-06-26] (Mozilla Corporation)
Task: {209A37E2-AAB0-43AA-A6EB-C869E7649030} - System32\Tasks\DealPlyLiveUpdateTaskMachineCore => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-07-17] (DealPly Technologies Ltd)
Task: {285211F7-E679-4817-B9AA-7782F1B22ACE} - System32\Tasks\Plus-HD-2.3-enabler => C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-enabler.exe [2013-07-17] (Plus HD)
Task: {2888FF4E-6889-4971-B97D-B1406289CFF4} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-19] (Adobe Systems Incorporated)
Task: {3BA8F337-33EA-4CD4-B71E-1D7D465B280F} - System32\Tasks\{499A8193-2055-43A8-9A8F-3202D46E533E} => C:\Users\USERXXX\Downloads\falzass.exe No File
Task: {430919BF-A382-4E77-A84C-BC2D874FFF0C} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {60A342AF-9AD8-47ED-A1DC-39111D92845C} - System32\Tasks\{95471265-75C3-468E-B578-AEC471E02A53} => C:\Programme\Schroedel\Chemie heute SII\bin\Release\LearnWeb.exe No File
Task: {6E4D937B-F87B-4EE4-A39F-5B07A703CEBA} - System32\Tasks\{04AE94F7-62EB-427C-BDE9-D5EDD0FE68A5} => D:\eFilmLt.exe No File
Task: {70058DEA-A7AD-4670-9220-C2518014EE03} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3958744611-970375325-1774594619-1000Core => C:\Users\USERXXX\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-23] (Google Inc.)
Task: {723EAC2D-298E-473F-8714-00BA755DD031} - System32\Tasks\Plus-HD-2.3-chromeinstaller => C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-chromeinstaller.exe [2013-07-17] (Plus HD)
Task: {73DFCA14-ADD4-4779-844A-84009FABFCBD} - System32\Tasks\{B6DCA215-F5B9-493E-BFD1-3111B1C65E43} => D:\eFilmLt.exe No File
Task: {7EA95E01-2867-4F1A-9099-6ECA9F8A88E4} - System32\Tasks\{A8E76163-FFAE-4EF8-BDBD-FAF9BCC747E7} => D:\eFilmLt.exe No File
Task: {80EEDB1B-664E-4529-B4C7-436A4FB66F7C} - System32\Tasks\{71634EA8-FC7F-4457-B79E-A0A7E5C581C4} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-02-07] (Skype Technologies S.A.)
Task: {8414D22F-995A-4A8E-B4E4-12ED33F6C817} - System32\Tasks\DealPlyLiveUpdateTaskMachineUA => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-07-17] (DealPly Technologies Ltd)
Task: {84FB056C-BB9F-41BC-BCE4-C37272961973} - System32\Tasks\Plus-HD-2.3-updater => C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-updater.exe [2013-07-17] (Plus HD)
Task: {8993978B-C7AB-4461-B334-AEBDCD6AF1C2} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {8C2CE0E3-C229-4123-975C-4595C5A2C0C7} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3958744611-970375325-1774594619-1000UA => C:\Users\USERXXX\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-23] (Google Inc.)
Task: {90C5EB26-693F-4CFF-B9DD-588A2D64C7A5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-02] (Google Inc.)
Task: {9122BB62-AAA3-4A51-B966-BCA2833FDE25} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\IPoint.exe [2000-01-01] (Microsoft Corporation)
Task: {A8A35AFE-E6A7-44A9-A548-6BD0942F2DEB} - System32\Tasks\{B4107D40-FD9F-4858-902E-A6CDBC9A35C8} => D:\eFilmLt.exe No File
Task: {B5C3EBD2-C926-4FE7-B493-F1C69A7483FA} - System32\Tasks\{83B7F3DE-AC76-46CD-8B75-1310E3CE9E6D} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-06-26] (Mozilla Corporation)
Task: {C3009187-638D-44D4-BF34-EEA2B0D1A2AD} - System32\Tasks\{9D6125B0-6D08-4580-855A-219B09623C33} => D:\eFilmLt.exe No File
Task: {C476B9BD-F684-4C4B-B854-9451B1B611A2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-02] (Google Inc.)
Task: {C7C36EB4-E38C-48CB-98A9-25EBF5AFE49C} - System32\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A} => C:\Users\USERXXX\AppData\Local\Temp\Ery.exe No File
Task: {D3B2E2A5-429D-4EA2-ABE7-A66DA564784E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
Task: {E89E98D8-27AC-42E9-87C8-B9CF28604C86} - System32\Tasks\{9939550A-9450-4F50-82B9-238B9BC637F0} => C:\Users\USERXXX\Virtual Machines\DKII_German\German\Setup\SETUP.EXE [1999-02-16] (InstallShield Software Corporation)
Task: {F8E497D4-8EF3-44EC-8406-B90B937B308B} - System32\Tasks\YourFile Update => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe No File
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe
Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3958744611-970375325-1774594619-1000Core.job => C:\Users\USERXXX\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3958744611-970375325-1774594619-1000UA.job => C:\Users\USERXXX\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Plus-HD-2.3-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-chromeinstaller.exe
Task: C:\Windows\Tasks\Plus-HD-2.3-codedownloader.job => C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-codedownloader.exe
Task: C:\Windows\Tasks\Plus-HD-2.3-enabler.job => C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-enabler.exe
Task: C:\Windows\Tasks\Plus-HD-2.3-firefoxinstaller.job => C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-firefoxinstaller.exe
Task: C:\Windows\Tasks\Plus-HD-2.3-updater.job => C:\Program Files (x86)\Plus-HD-2.3\Plus-HD-2.3-updater.exe

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (07/20/2013 00:09:04 AM) (Source: Application Hang) (User: )
Description: Programm OTL.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 16f4

Startzeit: 01ce84cbe23c233b

Endzeit: 0

Anwendungspfad: C:\Users\USERXXX\Desktop\OTL.exe

Berichts-ID: bb1bbc90-f0bf-11e2-bd2d-bc054301286b

Error: (07/17/2013 03:22:51 PM) (Source: MsiInstaller) (User: Pandorum)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\DealPlyLive\Update\\GoogleUpdateHelper.msi

Error: (07/17/2013 02:34:05 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version:, Zeitstempel: 0x51c06b1b
Name des fehlerhaften Moduls: xul.dll, Version:, Zeitstempel: 0x51c06a5b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00173668
ID des fehlerhaften Prozesses: 0x13e0
Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0
Pfad der fehlerhaften Anwendung: firefox.exe1
Pfad des fehlerhaften Moduls: firefox.exe2
Berichtskennung: firefox.exe3

Error: (07/13/2013 03:48:56 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Fireworks.exe, Version:, Zeitstempel: 0x4bb074c9
Name des fehlerhaften Moduls: QuickTime.qts_unloaded, Version:, Zeitstempel: 0x50890e53
Ausnahmecode: 0xc0000005
Fehleroffset: 0x5450cce9
ID des fehlerhaften Prozesses: 0x102c
Startzeit der fehlerhaften Anwendung: 0xFireworks.exe0
Pfad der fehlerhaften Anwendung: Fireworks.exe1
Pfad des fehlerhaften Moduls: Fireworks.exe2
Berichtskennung: Fireworks.exe3

Error: (07/10/2013 05:37:08 PM) (Source: Windows Search Service) (User: )
Description: Der Index kann nicht initialisiert werden.

	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/10/2013 05:37:08 PM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung

	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/10/2013 05:37:08 PM) (Source: Windows Search Service) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog

	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/10/2013 05:37:08 PM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog

	Element nicht gefunden.  (HRESULT : 0x80070490) (0x80070490)

Error: (07/10/2013 05:37:07 PM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog

	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/10/2013 05:37:07 PM) (Source: Windows Search Service) (User: )
Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden.

Kontext: Windows Anwendung, SystemIndex Katalog

	Die Inhaltsindexdatenbank ist fehlerhaft.  (HRESULT : 0xc0041800) (0xc0041800)

System errors:
Error: (07/20/2013 00:02:15 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (07/20/2013 00:01:48 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (07/19/2013 11:22:21 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (07/19/2013 11:22:14 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (07/19/2013 11:21:10 PM) (Source: DCOM) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

Error: (07/19/2013 08:27:30 PM) (Source: DCOM) (User: )
Description: {F48FC5B2-094A-44C7-B48C-289738C9582D}

Error: (07/19/2013 07:53:09 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (07/19/2013 07:53:06 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (07/19/2013 02:51:18 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (07/19/2013 02:51:15 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: 

Microsoft Office Sessions:
Error: (07/20/2013 00:09:04 AM) (Source: Application Hang)(User: )
Description: OTL.exe3.2.69.016f401ce84cbe23c233b0C:\Users\USERXXX\Desktop\OTL.exebb1bbc90-f0bf-11e2-bd2d-bc054301286b

Error: (07/17/2013 03:22:51 PM) (Source: MsiInstaller)(User: Pandorum)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\DealPlyLive\Update\\GoogleUpdateHelper.msi(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (07/17/2013 02:34:05 PM) (Source: Application Error)(User: )
Description: firefox.exe22.0.0.491751c06b1bxul.dll22.0.0.491751c06a5bc00000050017366813e001ce82e80528b916C:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dll2a9cffe7-eedd-11e2-8685-bc054301286b

Error: (07/13/2013 03:48:56 PM) (Source: Application Error)(User: )
Description: Fireworks.exe11.0.0.4844bb074c9QuickTime.qts_unloaded0.0.0.050890e53c00000055450cce9102c01ce7fcd58fe187dC:\Program Files (x86)\Adobe\Adobe Fireworks CS5\Fireworks.exeQuickTime.qtsf5faced0-ebc2-11e2-95c8-bc054301286b

Error: (07/10/2013 05:37:08 PM) (Source: Windows Search Service)(User: )
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/10/2013 05:37:08 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung

	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/10/2013 05:37:08 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog

	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/10/2013 05:37:08 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog

	Element nicht gefunden.  (HRESULT : 0x80070490) (0x80070490)

Error: (07/10/2013 05:37:07 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog

	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/10/2013 05:37:07 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog

	Die Inhaltsindexdatenbank ist fehlerhaft.  (HRESULT : 0xc0041800) (0xc0041800)

==================== Memory info =========================== 

Percentage of memory in use: 41%
Total physical RAM: 4093.49 MB
Available physical RAM: 2413.43 MB
Total Pagefile: 8185.17 MB
Available Pagefile: 6286.55 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:698.63 GB) (Free:495.97 GB) NTFS (Disk=0 Partition=1) ==>[Drive with boot components (obtained from BCD)]
Drive d: (SII_10TH_A) (CDROM) (Total:0.6 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 18ED4C26)
Partition 1: (Active) - (Size=699 GB) - (Type=07 NTFS)

==================== End Of Log ============================

/// Winkelfunktion
/// TB-Süch-Tiger™
Instant Savings im Browser (bei FB, ebay ...)

Hallo und

Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Warum hast du eine Ultimate-Edition von Windows, brauchst du das als Heimanwender?
Oder ist das rein zufällig ein Büro-/Firmen-PC bzw. ein Uni-Rechner?

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die jemals fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs posten!

Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.


Alt 21.07.2013, 19:42   #3
Instant Savings im Browser (bei FB, ebay ...) - Standard

Instant Savings im Browser (bei FB, ebay ...)

Der Rechner wird sowohl beruflich als auch privat genutzt...

Andere Logs hab ich leider nicht. Als Anti-Viren-Programm nutz ich "Avira Antivirus". Funde gab es bisher nie.

Was soll ich am besten als nächstes tun?

/// Winkelfunktion
/// TB-Süch-Tiger™
Instant Savings im Browser (bei FB, ebay ...)

Der Rechner wird sowohl beruflich als auch privat genutzt...
Bitte lesen => http://www.trojaner-board.de/108422-...-anfragen.html

Bedenkt jedoch, dass Logfiles viele heikle Informationen enthalten können ( Kundendaten, Bankdaten, etc ) sowie das Malware die Möglichkeit besitzt, diese auszuspähen und zu missbrauchen. Hier legen wir euch ein Formatieren und Neuaufsetzen nahe.

3. Grundsätzlich bereinigen wir keine gewerblich genutzten Rechner. Dafür ist die IT Abteilung eurer Firma zuständig.

Bei Kleinunternehmen, welche keinen IT Support haben, machen wir da eine Ausnahme und helfen gerne ( kleine Spende hilft auch uns ).
Voraussetzung: Ihr teilt uns dies in eurer ersten Antwort mit.
Gelesen und verstanden?
Logfiles bitte immer in CODE-Tags posten

Instant Savings im Browser (bei FB, ebay ...) - Standard

Instant Savings im Browser (bei FB, ebay ...)

Da ich Kleinunternehmer bin und auch nur ich allein an dem PC arbeite, hab ich leider auch keine IT Abteilung

Alt 22.07.2013, 23:01   #6
/// Winkelfunktion
/// TB-Süch-Tiger™
Instant Savings im Browser (bei FB, ebay ...)

Du hast den extra farblich hervorgehobenen Teil gelesen und verstanden?
--> Instant Savings im Browser (bei FB, ebay ...)

Alt 23.07.2013, 09:08   #7
Instant Savings im Browser (bei FB, ebay ...) - Standard

Instant Savings im Browser (bei FB, ebay ...)

Ja, habe ich. Sensible Daten/Kundendaten befinden sich nicht auf meinem Rechner, ich wäre daher froh, wenn ich um das Formatieren rum kommen würde.

Alt 24.07.2013, 00:19   #8
/// Winkelfunktion
/// TB-Süch-Tiger™
Instant Savings im Browser (bei FB, ebay ...) - Standard

Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
  • Lies dir meine Anleitungen, die ich im Laufe dieses Strangs hier posten werde, aufmerksam durch. Frag umgehend nach, wenn dir irgendetwas unklar sein sollte, bevor du anfängst meine Anleitungen umzusetzen.

  • Solltest du bei einem Schritt Probleme haben, stoppe dort und beschreib mir das Problem so gut du kannst. Manchmal erfordert ein Schritt den vorhergehenden.

  • Bitte nur Scans durchführen zu denen du von einem Helfer aufgefordert wurdest! Installiere / Deinstalliere keine Software ohne Aufforderung!

  • Poste die Logfiles direkt in deinen Thread (bitte in CODE-Tags) und nicht als Anhang, ausser du wurdest dazu aufgefordert. Logs in Anhängen erschweren mir das Auswerten!

  • Die Logs der aufgegebenen Tools wie zB Malwarebytes sind immer zu posten - egal ob ein Fund dabei war oder nicht!

  • Beachte bitte auch => Löschen von Logfiles und andere Anfragen

Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread.
Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards.

Rootkitscan mit GMER

Bitte lade dir GMER Rootkit Scanner GMER herunter: (Dateiname zufällig)
  • Schließe alle anderen Programme, deaktiviere deinen Virenscanner und trenne den Rechner vom Internet bevor du GMER startest.
  • Sollte sich nach dem Start ein Fenster mit folgender Warnung öffnen:
    WARNING !!!
    GMER has found system modification, which might have been caused by ROOTKIT activity.
    Do you want to fully scan your system ?
    Unbedingt auf "No" klicken.
  • Entferne rechts den Haken bei: IAT/EAT und Show All
  • Setze den Haken bei Quickscan und entferne ihn bei allen anderen Laufwerken.
  • Starte den Scan mit "Scan".
  • Mache nichts am Computer während der Scan läuft.
  • Wenn der Scan fertig ist klicke auf Save und speichere die Logfile unter Gmer.txt auf deinem Desktop. Mit "Ok" wird GMER beendet.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor Du ins Netz gehst!

Tauchen Probleme auf?
  • Probiere alternativ den abgesicherten Modus.
  • Erhältst du einen Bluescreen, dann entferne den Haken vor Devices.

Anschließend bitte MBAR ausführen:

Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
Logfiles bitte immer in CODE-Tags posten

Instant Savings im Browser (bei FB, ebay ...) - Standard

Instant Savings im Browser (bei FB, ebay ...)

Hallo und vielen Dank schon mal für die Hilfestellung.

Hier die gewünschten Logs:

GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-07-24 09:19:14
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Scsi\JRAID1Port0Path0Target0Lun0 SAMSUNG_ rev.9035 698,64GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Dominik\AppData\Local\Temp\uflcapob.sys

---- User code sections - GMER 2.1 ----

.text   C:\Windows\SysWOW64\svchost.exe[1692] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                          0000000076281465 2 bytes [28, 76]
.text   C:\Windows\SysWOW64\svchost.exe[1692] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                         00000000762814bb 2 bytes [28, 76]
.text   ...                                                                                                                                                    * 2
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                 0000000076281465 2 bytes [28, 76]
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                00000000762814bb 2 bytes [28, 76]
.text   ...                                                                                                                                                    * 2
.text   c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2352] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69                     0000000076281465 2 bytes [28, 76]
.text   c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2352] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155                    00000000762814bb 2 bytes [28, 76]
.text   ...                                                                                                                                                    * 2
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3232] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000076281465 2 bytes [28, 76]
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3232] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  00000000762814bb 2 bytes [28, 76]
.text   ...                                                                                                                                                    * 2
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[3204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                  0000000076281465 2 bytes [28, 76]
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[3204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                 00000000762814bb 2 bytes [28, 76]
.text   ...                                                                                                                                                    * 2
.text   C:\Users\Dominik\AppData\Local\Akamai\netsession_win.exe[3168] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                 0000000076281465 2 bytes [28, 76]
.text   C:\Users\Dominik\AppData\Local\Akamai\netsession_win.exe[3168] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                00000000762814bb 2 bytes [28, 76]
.text   ...                                                                                                                                                    * 2
.text   C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[1276] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint                             0000000076f5000c 1 byte [C3]
.text   C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[1276] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin                        0000000076fdf85a 5 bytes JMP 0000000176f8d571
.text   C:\Users\Dominik\AppData\Local\Akamai\netsession_win.exe[764] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                  0000000076281465 2 bytes [28, 76]
.text   C:\Users\Dominik\AppData\Local\Akamai\netsession_win.exe[764] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                 00000000762814bb 2 bytes [28, 76]
.text   ...                                                                                                                                                    * 2

---- Threads - GMER 2.1 ----

Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:1908]                                                                0000000076f93e45
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:1940]                                                                0000000076f92e25
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:1976]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:1980]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:1984]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:1996]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2000]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2024]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2028]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2032]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2036]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:1100]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:1844]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:1800]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:1948]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2296]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2300]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2304]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2316]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2320]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2324]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2328]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2396]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2432]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2440]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2516]                                                                0000000076f93e45
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2596]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2600]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2604]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2608]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2612]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2704]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:2740]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:3324]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:3328]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:3332]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:3308]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:3304]                                                                00000000719129e1
Thread  c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1856:3312]                                                                00000000719129e1

---- Registry - GMER 2.1 ----

Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                       
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                    0x4E 0x5F 0x00 0x00 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                    0
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                 0x1D 0xEC 0xEA 0x36 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                                                   
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                        0x4E 0x5F 0x00 0x00 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                        0
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                     0x1D 0xEC 0xEA 0x36 ...

---- EOF - GMER 2.1 ----
Malwarebytes Anti-Rootkit BETA

Database version: v2013.07.24.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
Dominik :: PANDORUM [administrator]

24.07.2013 09:34:29
mbar-log-2013-07-24 (09-34-29).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: PUP
Objects scanned: 328175
Time elapsed: 1 hour(s), 6 minute(s), 40 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)


/// Winkelfunktion
/// TB-Süch-Tiger™
Instant Savings im Browser (bei FB, ebay ...)


JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

Im Anschluss:

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Danach eine Kontrolle mit OTL bitte:
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles in CODE-Tags hier in den Thread.
Logfiles bitte immer in CODE-Tags posten

Instant Savings im Browser (bei FB, ebay ...) - Standard

Instant Savings im Browser (bei FB, ebay ...)

Hier schon mal die JRT.txt

Junkware Removal Tool (JRT) by Thisisu
Version: 5.2.2 (07.22.2013:2)
OS: Windows 7 Ultimate x64
Ran by Dominik on 24.07.2013 at 16:40:03,24

~~~ Services

Successfully stopped: [Service] dealplylive 
Successfully deleted: [Service] dealplylive 
Successfully stopped: [Service] dealplylivem 
Successfully deleted: [Service] dealplylivem 

~~~ Registry Values

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\dealplylive.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\secman.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{4d076ab4-7562-427a-b5d2-bd96e19dee56}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{80fabb17-63af-4655-9f07-b6509ee37af2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{bdb69379-802f-4eaf-b541-f8de92dd98db}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{ea28b360-05e0-4f93-8150-02891f1d8d3c}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{f48fc5b2-094a-44c7-b48c-289738c9582d}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{0d89de71-3d99-4288-84dc-f18f1047a7d8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{1e0c9b2a-6447-452c-b012-2314a0c29412}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{34a8ceb6-89bb-49f1-b5e4-0d0d6c21f3b1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{3a4dbd3a-98cc-41ce-ad21-352d42b6f754}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{4f8a50f6-69de-4be3-a33a-a1079b9ac0db}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{501cb57a-d4e2-4855-96ad-edb0a9083395}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{66eef543-a9ac-4a9d-aa3c-1ed148ac8eee}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{6ff2c4dd-77a4-4bb5-ba4c-b42defbf9137}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{7f1796b2-bec6-427b-b734-f9c75ed94a80}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{80fabb17-63af-4655-9f07-b6509ee37af2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{826d7151-8d99-434b-8540-082b8c2ae556}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{83aba270-8390-4ca6-ae48-fc089f55629e}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{8b218a5f-1a3d-4347-94ef-a79575eb8094}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{8c338ddb-19fc-4c1f-b74d-6931ee55f7a1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{9bdb5e09-4bba-4422-8c2b-529b281c32b8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{ae48ed75-5a56-4c5f-bbce-6f1ac3875f66}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{c536f080-57b7-46d6-8894-c647553f2889}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{ca5d945f-e738-4d0b-a0b5-25ac51c64659}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{f48fc5b2-094a-44c7-b48c-289738c9582d}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{f7698761-4aba-45c2-a5bb-d2163922c725}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{ffcc53e6-2655-47fc-a89b-54e8d7f305d1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplylive.oneclickctrl.9
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplylive.oneclickprocesslaunchermachine
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplylive.oneclickprocesslaunchermachine.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplylive.update3webcontrol.3
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.cocreateasync
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.cocreateasync.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.coreclass
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.coreclass.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.coremachineclass
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.coremachineclass.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.credentialdialogmachine
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.credentialdialogmachine.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.ondemandcomclassmachine
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.ondemandcomclassmachine.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.ondemandcomclassmachinefallback
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.ondemandcomclassmachinefallback.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.ondemandcomclasssvc
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.ondemandcomclasssvc.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.processlauncher
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.processlauncher.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.update3comclassservice
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.update3comclassservice.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.update3webmachine
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.update3webmachine.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.update3webmachinefallback
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.update3webmachinefallback.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.update3websvc
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\dealplyliveupdate.update3websvc.1.0
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\interface\{66eef543-a9ac-4a9d-aa3c-1ed148ac8eee}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\mime\database\content type\application/x-vnd.dpliveupdate.oneclickctrl.9
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\mime\database\content type\application/x-vnd.dpliveupdate.update3webcontrol.3
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\typelib\{11549fe4-7c5a-4c17-9fc3-56fc5162a994}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dealply
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dealply
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dealplylive
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dealplylive
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\iminent
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\iminent
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installcore
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\startsearch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\yourfiledownloader
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\applications\ilividsetup.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\oneclick
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\oneclickmg
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\internet explorer\low rights\elevationpolicy\{7f1796b2-bec6-427b-b734-f9c75ed94a80}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\internet explorer\low rights\elevationpolicy\{8c338ddb-19fc-4c1f-b74d-6931ee55f7a1}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\askpartnercobrandingtool_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\askpartnercobrandingtool_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilivid_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilivid_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilividsetup_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilividsetup_rasmancs
OTL logfile created on: 24.07.2013 16:54:31 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\Dominik\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,33 Gb Available Physical Memory | 58,37% Memory free
7,99 Gb Paging File | 6,30 Gb Available in Paging File | 78,83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 698,63 Gb Total Space | 494,50 Gb Free Space | 70,78% Space Free | Partition Type: NTFS
Drive D: | 612,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: PANDORUM | User Name: Dominik | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
