Plagegeister aller Art und deren Bekämpfung: Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an
![]() | ![]() Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Hallo, Ich habe das Problem das ich in Firefox keine weiterführende Links (zum öffnen von Bildern oder z.Bsp. Kleinanzeigen) anklicken kann. Außerdem öffnet er plötzlich popups zu AdFly obwol ein Adblocker instaliert ist. Auch die Avira Toolbar ist jedesmal beim Neustart des rechners deaktiviert. Ein Bekannter riet mir Malwarebytes zu instalieren und auszuführen. Das habe ich auch getan. Es hat 6 Funde gefunden und gelöscht (Logfile weiter unten). als dann das Problem mit Firefox weiter bestand wurde ir geraten Windows zu reparieren mittels Instalations DVD. Auch das habe ich getan nur leider ist das Problem dadurch nicht weg. Nun habe ich das Forum hier gefunden und glaube das meine Aktionen vieleicht nicht so klug waren. Das Problem besteht übrigen nur in Frefox. Ich wollte über Firefox hier meine Problem schreiben jedoch geht das nicht weil immer die Meldunbg kommt das nicht genug Wörter (min 3) im Komentarfeld stehen müssen. Es sind ja aber offensichtlich mehr. Vileicht hängt das ja auch damit zusammen. Ich habe folgende Programme instaliert: Win 7 Professional sp1 Avira Antivir Suite (bezahl Version) Spyboot Malwarebytes Testversion Hier die Logfile von dem Fund: Zitat:
Auch Antivir zeigt nichts an. Ich wäre euch echt dankbar wenn Ihr mir helfen könnt. Gruß Patrick |
Hallo und
Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!

Zudem bitte auch ein Log mit Farbars Tool machen:

Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
![]() | ![]() Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Danke für die schnelle Antwort. In Ativir ist kein Fund aufgelistet und es gab auch keine Meldung. Und Malwarebyte hatte nur einmal einen Fund den dan Löschen lies. Danach kam nix mehr. Ander Virenprogramme habe ich nicht instaliert.
Spyboot hat noch Logfiles. Ich weis nicht welche du brauchst. Älter als 3 Tage habe ich weggelassen.
Code: RootAlyzer Quick Scan Results
[Sample entries showing hidden files found]
ATTFilter Search results from Spybot - Search & Destroy 25.01.2014 12:21:19 Scan took 00:13:50. 23 items found. Babylon.Toolbar: [SBI $DEB52F26] Program directory (Directory, nothing done) C:\ProgramData\Babylon\ Babylon.Toolbar: [SBI $DEB52F26] Program directory (Directory, nothing done) C:\Users\Patrick Polzyn\AppData\Roaming\Babylon\ Directory.subfile=C:\Users\Patrick Polzyn\AppData\Roaming\Babylon\log_file.txt Directory.subfile.size=3051 Directory.subfile.md5=91E363FA6C22F0C0AA174C1DBAD01FA8 Directory.subfile.filedate=1380293971 Directory.subfile.filedatetext=2013-09-27 15:59:31 Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent MS Direct3D: [SBI $7FB7B83F] Most recent application (Registry Change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done) HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication\Name MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Direct3D\MostRecentApplication\Name MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done) HKEY_USERS\S-1-5-18\Software\Microsoft\Direct3D\MostRecentApplication\Name MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry Change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name Windows.OpenWith: [SBI $286A25C6] Open with list - .ACE extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ACE\OpenWithList Windows.OpenWith: [SBI $59A5380C] Open with list - .ACF extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ACF\OpenWithList Windows.OpenWith: [SBI $F7204896] Open with list - .AVI extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AVI\OpenWithList Windows.OpenWith: [SBI $691C1B44] Open with list - .BIN extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BIN\OpenWithList Windows.OpenWith: [SBI $A1C94E79] Open with list - .BMP extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\OpenWithList Windows Explorer: [SBI $AA0766B5] Stream history (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry Change, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows Media\WMSDK\General\ComputerName Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry Change, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows Media\WMSDK\General\UniqueID Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry Value, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber WinRAR: [SBI $0B56E92B] Recent file list (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\WinRAR\ArcHistory WinRAR: [SBI $B510882E] Extraction directory history (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\WinRAR\DialogEditHistory\ExtrPath Verlauf: [SBI $49804B54] Browser: History (4) (Browser: History, nothing done) Cookie: [SBI $49804B54] Browser: Cookie (63) (Browser: Cookie, nothing done) --- Spybot - Code: [Spybot version and scan summary - 23 items found]
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01 Ran by Patrick Polzyn (administrator) on PATRICKPOLZYN on 29-01-2014 14:08:49 Running from C:\Users\Patrick Polzyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYPJZKPN Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Realtek) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe (Realtek) C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\RtlService.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Microsoft Corporation) C:\Windows\System32\LogonUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe (Autodesk, Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ServiceLocator.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Toolbar.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Farbar) C:\Users\Patrick Polzyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYPJZKPN\FRST64[1].exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor) HKLM-x32\...\Run: [ADSK DLMSession] - C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1641368 2013-02-01] (Autodesk, Inc.) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1778640 2013-12-20] (APN) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1815976 2014-01-27] (Valve Corporation) HKU\Administrator\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2010-11-21] (Microsoft Corporation) HKU\UpdatusUser\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKU\UpdatusUser\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1815976 2014-01-27] (Valve Corporation) HKU\UpdatusUser\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2010-11-21] (Microsoft Corporation) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-10-27] (NVIDIA Corporation) AppInit_DLLs: C:\PROGRA~1\LUCIDL~1\VIRTU\APPINI~1.DLL => C:\Program Files\Lucidlogix Technologies\VIRTU\appinit_dll.dll [188704 2011-08-08] (Lucidlogix Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=647ABC5FF40E1A85&affID=119357&tt=250913_nocpn&tsp=5018 SearchScopes: HKCU - {5296BDA4-2B7E-4BA6-967A-DEDF0C5EF2FE} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=7779cf80-3995-4fa9-88b1-c1c49f097328&apn_sauid=9188E539-ADAA-4997-8E35-E120D657C537 BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GbR) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default FF user.js: detected! => C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\user.js FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\searchplugins\askcom.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Garmin Communicator - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013-11-19] FF Extension: WOT - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26] FF Extension: DownloadHelper - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013-08-27] FF Extension: Easy YouTube MP3 Downloader - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\5@thumbpro.net.xpi [2013-06-26] FF Extension: Adblock Plus Pop-up Addon - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\adblockpopups@jessehakanen.net.xpi [2012-10-29] FF Extension: MP3 Download! - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\anthonyytmp3download@gmail.com.xpi [2013-06-26] FF Extension: InvisibleHand - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\canitbecheaper@trafficbroker.co.uk.xpi [2012-10-18] FF Extension: YouTube to MP3 - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\info@sharkcube.com.xpi [2013-06-26] FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\toolbar_AVIRA-V7C@apn.ask.com.xpi [2013-12-20] FF Extension: NoScript - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-25] FF Extension: Adblock Plus - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-10-30] FF Extension: DownThemAll! - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2012-10-30] FF Extension: QuickJava - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi [2012-10-18] FF Extension: JavaScript Debugger - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi [2012-10-18] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-01-06] ==================== Services (Whitelisted) ================= S4 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-22] (Adobe Systems) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [908856 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-12] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-17] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.) S4 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [393032 2013-06-19] (BlueStack Systems, Inc.) S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384840 2013-06-19] (BlueStack Systems, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 mi-raysat_3dsmax2014_64; C:\Program Files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe [86016 2011-09-15] () S4 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR) S4 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR) R2 Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [45056 2010-01-21] (Realtek) R2 RealtekPCIE; C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\RtlService.exe [45056 2010-01-21] (Realtek) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-17] (Avira Operations GmbH & Co. KG) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [70984 2013-06-19] (BlueStack Systems) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-01-18] (FNet Co., Ltd.) S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 rtl819xpn64; C:\Windows\System32\DRIVERS\rtl819xp.sys [622624 2010-02-01] (Realtek Semiconductor Corporation ) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S4 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [68608 2005-08-10] (Protection Technology) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-29 14:06 - 2014-01-29 14:08 - 00000000 ____D C:\FRST 2014-01-29 11:24 - 2014-01-29 11:27 - 00009302 _____ C:\Windows\IE10_main.log 2014-01-29 10:54 - 2014-01-29 10:54 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\AskPartnerNetwork 2014-01-29 10:46 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2014-01-29 10:46 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2014-01-29 10:41 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2014-01-29 10:25 - 2011-11-19 15:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-01-29 10:25 - 2011-11-19 15:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-01-29 04:21 - 2014-01-28 21:06 - 00000000 ____D C:\Windows\Panther 2014-01-29 04:18 - 2014-01-29 04:18 - 00262144 _____ C:\Windows\system32\config\userdiff 2014-01-29 04:18 - 2011-02-16 03:16 - 00000029 ___RH C:\Windows\version 2014-01-29 04:18 - 2011-02-16 03:16 - 00000013 ____R C:\Windows\csup.txt 2014-01-29 04:17 - 2014-01-29 13:20 - 00696132 _____ C:\Windows\system32\perfh007.dat 2014-01-29 04:17 - 2014-01-29 13:20 - 00147428 _____ C:\Windows\system32\perfc007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00295922 _____ C:\Windows\system32\perfi007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00038104 _____ C:\Windows\system32\perfd007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\0407 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\0407 2014-01-29 04:09 - 2014-01-28 20:35 - 00000000 ___HD C:\$WINDOWS.~Q 2014-01-29 03:51 - 2014-01-29 03:58 - 00000000 ___HD C:\$INPLACE.~TR 2014-01-28 21:13 - 2014-01-29 11:05 - 01588294 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-28 21:10 - 2014-01-28 21:10 - 00001443 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-28 21:10 - 2014-01-28 21:10 - 00001409 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-01-28 21:06 - 2014-01-28 21:06 - 00000020 ___SH C:\Users\Patrick Polzyn\ntuser.ini 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Favoriten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Dokumente 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2014-01-28 20:55 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2014-01-28 20:55 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2014-01-28 20:55 - 2012-02-17 05:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-01-28 20:55 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2014-01-28 20:47 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-01-28 20:47 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-01-28 20:47 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-01-28 20:47 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-01-28 20:47 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-01-28 20:47 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-01-28 20:47 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-01-28 20:46 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-01-28 20:46 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-01-28 19:27 - 2014-01-28 21:06 - 00000000 ____D C:\Users\Patrick Polzyn 2014-01-28 19:27 - 2014-01-28 20:18 - 00000000 ____D C:\Users\Administrator 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten 2014-01-28 19:27 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 19:27 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 19:27 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 19:27 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 19:27 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 19:27 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 19:26 - 2014-01-28 19:59 - 00000000 ____D C:\ProgramData\EPSON 2014-01-28 19:26 - 2014-01-28 19:37 - 00000000 ____D C:\Program Files\Common Files\EPSON 2014-01-28 19:26 - 2014-01-28 19:26 - 00001355 _____ C:\Windows\TSSysprep.log 2014-01-28 19:25 - 2014-01-29 13:27 - 01184019 _____ C:\Windows\WindowsUpdate.log 2014-01-28 19:25 - 2014-01-29 13:13 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-28 19:25 - 2014-01-28 19:59 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2014-01-28 19:25 - 2014-01-28 19:40 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-28 19:25 - 2014-01-28 19:37 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files\Realtek 2014-01-28 19:25 - 2013-10-23 09:20 - 06669600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 03489568 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 03426956 _____ C:\Windows\system32\nvcoproc.bin 2014-01-28 19:25 - 2013-10-23 09:20 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-01-28 19:25 - 2013-10-23 09:20 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-01-28 19:24 - 2014-01-28 19:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-01-28 18:22 - 2014-01-28 20:35 - 00006773 _____ C:\Windows\comsetup.log 2014-01-27 18:55 - 2014-01-28 20:20 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Malwarebytes 2014-01-27 18:55 - 2014-01-28 19:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-27 18:55 - 2014-01-28 19:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-27 18:55 - 2014-01-27 18:56 - 00000000 ____D C:\AdwCleaner 2014-01-27 18:55 - 2014-01-27 18:55 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-27 18:55 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-27 18:35 - 2014-01-28 19:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-27 18:35 - 2014-01-27 18:35 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-27 13:54 - 2014-01-28 19:58 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2014-01-27 13:54 - 2014-01-28 19:38 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork 2014-01-27 12:41 - 2014-01-27 12:41 - 02278856 _____ C:\Users\Patrick Polzyn\Downloads\avira_pc_cleaner_de.exe 2014-01-27 12:41 - 2014-01-27 12:41 - 00002049 _____ C:\Users\Patrick Polzyn\Desktop\Entfernen des Avira PC Cleaners.lnk 2014-01-27 12:41 - 2014-01-27 12:41 - 00001993 _____ C:\Users\Patrick Polzyn\Desktop\Avira PC Cleaner.lnk 2014-01-27 08:39 - 2014-01-27 08:39 - 00000262 _____ C:\Users\Patrick Polzyn\Desktop\Run.lnk 2014-01-26 16:28 - 2014-01-28 19:58 - 00000000 ____D C:\ProgramData\APN 2014-01-26 10:06 - 2014-01-26 10:06 - 23867560 _____ (Mozilla) C:\Users\Patrick Polzyn\Downloads\Firefox Setup 26.0.exe 2014-01-25 14:02 - 2014-01-25 14:02 - 00004540 _____ C:\Users\Patrick Polzyn\Documents\cc_20140125_140224.reg 2014-01-25 12:10 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\LicenseCrawler 2014-01-24 18:27 - 2014-01-24 18:27 - 00316109 _____ C:\Users\Patrick Polzyn\Desktop\Grenzsteine_DE-PL.rwp 2014-01-24 16:33 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\PR_PKP_infra_02 2014-01-24 16:30 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\ZestawSieciTrakcyjnejPKP 2014-01-13 16:45 - 2014-01-13 16:45 - 00001566 _____ C:\Users\Patrick Polzyn\Desktop\railworks - Verknüpfung.lnk 2014-01-11 19:27 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Developer Docs 2014-01-08 20:18 - 2012-09-10 20:42 - 00275899 _____ C:\Users\Patrick Polzyn\Desktop\DR-So2_und_So7-Tafeln.rwp 2014-01-05 10:14 - 2014-01-05 10:14 - 00115592 _____ C:\Users\Patrick Polzyn\Documents\cc_20140105_101436.reg ==================== One Month Modified Files and Folders ======= 2014-01-29 14:08 - 2014-01-29 14:06 - 00000000 ____D C:\FRST 2014-01-29 14:07 - 2013-02-19 15:30 - 00001126 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-29 13:59 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2014-01-29 13:58 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\WCN 2014-01-29 13:58 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2014-01-29 13:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\MUI 2014-01-29 13:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism 2014-01-29 13:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\com 2014-01-29 13:50 - 2012-12-28 16:57 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-29 13:27 - 2014-01-28 19:25 - 01184019 _____ C:\Windows\WindowsUpdate.log 2014-01-29 13:21 - 2009-07-14 05:45 - 00025680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-29 13:21 - 2009-07-14 05:45 - 00025680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-29 13:20 - 2014-01-29 04:17 - 00696132 _____ C:\Windows\system32\perfh007.dat 2014-01-29 13:20 - 2014-01-29 04:17 - 00147428 _____ C:\Windows\system32\perfc007.dat 2014-01-29 13:20 - 2009-07-14 06:13 - 01611160 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-29 13:15 - 2013-02-19 15:30 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-29 13:15 - 2012-10-17 16:30 - 00000000 ____D C:\Program Files (x86)\Steam 2014-01-29 13:14 - 2013-06-21 17:35 - 00000441 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2014-01-29 13:13 - 2014-01-28 19:25 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-29 13:13 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-29 13:13 - 2009-07-14 05:51 - 01260976 _____ C:\Windows\setupact.log 2014-01-29 13:13 - 2009-07-14 05:45 - 00367024 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-29 12:56 - 2010-11-21 08:17 - 00000000 ____D C:\Program Files\Windows Journal 2014-01-29 12:56 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2014-01-29 12:56 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2014-01-29 12:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2014-01-29 12:56 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System 2014-01-29 11:27 - 2014-01-29 11:24 - 00009302 _____ C:\Windows\IE10_main.log 2014-01-29 11:05 - 2014-01-28 21:13 - 01588294 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-29 10:54 - 2014-01-29 10:54 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\AskPartnerNetwork 2014-01-29 10:13 - 2010-11-21 04:47 - 00012266 _____ C:\Windows\PFRO.log 2014-01-29 04:21 - 2009-07-14 06:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2014-01-29 04:21 - 2009-07-14 06:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2014-01-29 04:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\oobe 2014-01-29 04:18 - 2014-01-29 04:18 - 00262144 _____ C:\Windows\system32\config\userdiff 2014-01-29 04:18 - 2009-07-14 05:45 - 00000000 ____D C:\Windows\Setup 2014-01-29 04:17 - 2014-01-29 04:17 - 00295922 _____ C:\Windows\system32\perfi007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00038104 _____ C:\Windows\system32\perfd007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\0407 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\0407 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\winrm 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\WCN 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\sysprep 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\slmgr 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\winrm 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\slmgr 2014-01-29 04:17 - 2009-07-14 06:37 - 00000000 ____D C:\Windows\DigitalLocker 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Setup 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\oobe 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\MUI 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\com 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Setup 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\migwiz 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\servicing 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME 2014-01-29 03:58 - 2014-01-29 03:51 - 00000000 ___HD C:\$INPLACE.~TR 2014-01-28 21:39 - 2012-12-17 08:18 - 00002070 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2014-01-28 21:10 - 2014-01-28 21:10 - 00001443 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-28 21:10 - 2014-01-28 21:10 - 00001409 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-01-28 21:10 - 2012-10-16 20:34 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-28 21:10 - 2012-10-16 20:34 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-28 21:06 - 2014-01-29 04:21 - 00000000 ____D C:\Windows\Panther 2014-01-28 21:06 - 2014-01-28 21:06 - 00000020 ___SH C:\Users\Patrick Polzyn\ntuser.ini 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Favoriten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Dokumente 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2014-01-28 21:06 - 2014-01-28 19:27 - 00000000 ____D C:\Users\Patrick Polzyn 2014-01-28 21:06 - 2012-04-13 19:07 - 00000000 __SHD C:\Recovery 2014-01-28 21:06 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-28 21:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Recovery 2014-01-28 21:06 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT 2014-01-28 20:46 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\restore 2014-01-28 20:46 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration 2014-01-28 20:35 - 2014-01-29 04:09 - 00000000 ___HD C:\$WINDOWS.~Q 2014-01-28 20:35 - 2014-01-28 18:22 - 00006773 _____ C:\Windows\comsetup.log 2014-01-28 20:31 - 2012-11-17 11:29 - 00023056 _____ C:\Windows\system32\emptyregdb.dat 2014-01-28 20:30 - 2013-01-16 09:56 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2014-01-28 20:25 - 2013-09-26 08:08 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-01-28 20:25 - 2009-07-14 05:46 - 00005157 _____ C:\Windows\DtcInstall.log 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 20:22 - 2013-06-12 17:36 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\TomTom 2014-01-28 20:22 - 2013-05-26 12:12 - 00000000 ___RD C:\Users\Patrick Polzyn\Dropbox 2014-01-28 20:22 - 2013-01-26 12:04 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\SimCity 2014-01-28 20:22 - 2012-12-10 19:33 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\SelfMV 2014-01-28 20:22 - 2012-10-17 16:11 - 00000000 ____D C:\Users\Patrick Polzyn\Lucidlogix 2014-01-28 20:22 - 2012-10-17 16:11 - 00000000 ____D C:\Users\Patrick Polzyn\dwhelper 2014-01-28 20:21 - 2014-01-25 12:10 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\LicenseCrawler 2014-01-28 20:21 - 2014-01-24 16:33 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\PR_PKP_infra_02 2014-01-28 20:21 - 2014-01-24 16:30 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\ZestawSieciTrakcyjnejPKP 2014-01-28 20:21 - 2014-01-11 19:27 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Developer Docs 2014-01-28 20:21 - 2013-12-12 18:30 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Camera 2014-01-28 20:21 - 2013-11-23 19:18 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\daten von justin usb 2014-01-28 20:21 - 2013-11-23 18:23 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\eRightSoft 2014-01-28 20:21 - 2013-11-23 14:34 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Dateien für Streckenprojekt 2014-01-28 20:21 - 2013-11-13 17:45 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Dokumente Viktor 2014-01-28 20:21 - 2013-11-10 18:15 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\usb stick christoph 2014-01-28 20:21 - 2013-11-04 17:47 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Inventor Server x64 3dsMax 2014-01-28 20:21 - 2013-09-27 16:04 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\PC Speed Maximizer 2014-01-28 20:21 - 2013-07-08 16:19 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Bilder Verkauf 2014-01-28 20:21 - 2013-06-12 18:57 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Bandicam 2014-01-28 20:21 - 2013-06-12 17:36 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\TomTom 2014-01-28 20:21 - 2013-03-14 15:56 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\WinRAR 2014-01-28 20:21 - 2013-02-26 15:34 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3DCrafter 9.2 2014-01-28 20:21 - 2013-01-26 11:48 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Origin 2014-01-28 20:21 - 2013-01-22 10:59 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\AdobeStockPhotos 2014-01-28 20:21 - 2013-01-18 13:24 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3dsMaxDesign 2014-01-28 20:21 - 2013-01-06 19:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\PDF Architect 2014-01-28 20:21 - 2013-01-06 19:22 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\pdfforge 2014-01-28 20:21 - 2012-12-09 12:06 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\samsung 2014-01-28 20:21 - 2012-12-09 12:06 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Samsung 2014-01-28 20:21 - 2012-10-18 18:39 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\OpenOffice.org 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Inventor 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\4A Games 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3dsMax 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3DCrafter 9.1 2014-01-28 20:20 - 2014-01-27 18:55 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Malwarebytes 2014-01-28 20:20 - 2013-11-15 18:28 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RW_Tools 2014-01-28 20:20 - 2013-09-28 06:50 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FAKEFACTORY CM2013 2014-01-28 20:20 - 2013-06-26 12:43 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\DVDVideoSoft 2014-01-28 20:20 - 2013-06-21 17:49 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Azureus 2014-01-28 20:20 - 2013-06-12 18:58 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\BANDISOFT 2014-01-28 20:20 - 2013-06-09 16:44 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Garmin 2014-01-28 20:20 - 2013-05-26 12:11 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-28 20:20 - 2013-05-26 12:08 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Dropbox 2014-01-28 20:20 - 2013-05-15 19:08 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\3DTrains 2014-01-28 20:20 - 2013-03-14 15:56 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-01-28 20:20 - 2013-02-17 14:17 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rail Simulator Packager Manager 2014-01-28 20:20 - 2013-01-27 19:27 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Apple Computer 2014-01-28 20:20 - 2013-01-06 19:22 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\APP_NAME_NON_STRING 2014-01-28 20:20 - 2013-01-06 14:43 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\#Startup# 2014-01-28 20:20 - 2012-12-17 08:23 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Avira 2014-01-28 20:20 - 2012-12-11 14:30 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\InstallShield 2014-01-28 20:20 - 2012-12-06 11:07 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\EPSON 2014-01-28 20:20 - 2012-11-29 14:28 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Autodesk 2014-01-28 20:20 - 2012-11-18 19:39 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Need for Speed World 2014-01-28 20:20 - 2012-11-13 18:23 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Foxit Software 2014-01-28 20:20 - 2012-10-17 18:59 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\NVIDIA 2014-01-28 20:20 - 2012-10-17 16:44 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-01-28 20:20 - 2012-10-16 21:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Macromedia 2014-01-28 20:20 - 2012-10-16 21:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Adobe 2014-01-28 20:20 - 2012-10-16 20:37 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla 2014-01-28 20:19 - 2013-10-20 14:22 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\RailSimulator.com 2014-01-28 20:19 - 2013-06-13 15:40 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Windows Live 2014-01-28 20:19 - 2013-06-12 17:36 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\TomTom 2014-01-28 20:19 - 2013-02-19 15:30 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Google 2014-01-28 20:19 - 2013-02-13 11:55 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Autodesk, Inc 2014-01-28 20:19 - 2013-01-26 11:47 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Origin 2014-01-28 20:19 - 2013-01-22 11:28 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\gegl-0.2 2014-01-28 20:19 - 2013-01-18 13:37 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\backburner 2014-01-28 20:19 - 2013-01-18 11:38 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\cFos 2014-01-28 20:19 - 2012-12-09 12:07 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Samsung 2014-01-28 20:19 - 2012-12-09 12:03 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\NVIDIA 2014-01-28 20:19 - 2012-12-09 12:00 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Downloaded Installations 2014-01-28 20:19 - 2012-11-29 14:45 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Autodesk 2014-01-28 20:19 - 2012-11-18 18:06 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Electronic_Arts_Inc 2014-01-28 20:19 - 2012-10-18 10:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Nexway 2014-01-28 20:19 - 2012-10-16 21:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Macromedia 2014-01-28 20:19 - 2012-10-16 20:37 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Mozilla 2014-01-28 20:19 - 2012-10-16 20:34 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\VirtualStore 2014-01-28 20:18 - 2014-01-28 19:27 - 00000000 ____D C:\Users\Administrator 2014-01-28 20:18 - 2013-12-01 19:19 - 00000000 ____D C:\Users\Administrator\AppData\Local\Autodesk 2014-01-28 20:18 - 2013-09-09 16:05 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\APP_NAME_NON_STRING 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Local\Macromedia 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Local\DoNotTrackPlus 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Local\AskToolbar 2014-01-28 20:18 - 2013-09-09 16:02 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Mozilla 2014-01-28 20:18 - 2013-09-09 16:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\Mozilla 2014-01-28 20:18 - 2013-09-09 15:25 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Avira 2014-01-28 20:18 - 2013-09-09 15:21 - 00000000 ____D C:\Users\Administrator\Documents\4a games 2014-01-28 20:18 - 2013-06-21 17:31 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-28 20:18 - 2013-06-21 17:31 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-28 20:18 - 2013-06-21 17:31 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe 2014-01-28 20:18 - 2013-02-13 11:44 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Akamai 2014-01-28 20:18 - 2013-01-27 13:41 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Apple 2014-01-28 20:18 - 2013-01-22 11:36 - 00000000 ____D C:\Users\Patrick Polzyn\.thumbnails 2014-01-28 20:18 - 2013-01-22 11:28 - 00000000 ____D C:\Users\Patrick Polzyn\.gimp-2.8 2014-01-28 20:18 - 2013-01-22 10:47 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Adobe 2014-01-28 20:18 - 2013-01-06 11:20 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\AskToolbar 2014-01-28 20:18 - 2012-12-25 15:12 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\4A Games 2014-01-28 20:18 - 2012-10-17 16:09 - 00000000 ____D C:\Users\Patrick Polzyn\.swt 2014-01-28 20:00 - 2013-07-16 17:58 - 00000000 ____D C:\Windows\Uninstall 2014-01-28 20:00 - 2013-01-18 12:01 - 00000000 ____D C:\Windows\system32\appmgmt 2014-01-28 20:00 - 2012-12-14 21:02 - 00000000 ____D C:\Windows\pss 2014-01-28 20:00 - 2012-10-16 21:15 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2014-01-28 20:00 - 2012-10-16 21:15 - 00000000 ____D C:\Windows\system32\Macromed 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2014-01-28 19:59 - 2014-01-28 19:26 - 00000000 ____D C:\ProgramData\EPSON 2014-01-28 19:59 - 2014-01-28 19:25 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2014-01-28 19:59 - 2014-01-27 18:55 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-28 19:59 - 2013-06-13 15:43 - 00000000 ____D C:\Windows\de 2014-01-28 19:59 - 2013-06-12 17:38 - 00000000 ____D C:\ProgramData\TomTom 2014-01-28 19:59 - 2013-05-30 08:09 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-28 19:59 - 2013-05-15 19:08 - 00000000 ____D C:\Windows\3DTrains 2014-01-28 19:59 - 2013-01-26 11:47 - 00000000 ____D C:\ProgramData\Origin 2014-01-28 19:59 - 2013-01-22 10:46 - 00000000 ____D C:\Users\Public\Documents\Adobe PDF 2014-01-28 19:59 - 2013-01-18 11:59 - 00000000 _RSHD C:\ProgramData\Key-Base 2014-01-28 19:59 - 2013-01-18 11:38 - 00000000 ____D C:\ProgramData\FNET 2014-01-28 19:59 - 2013-01-16 09:56 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2014-01-28 19:59 - 2012-12-17 08:10 - 00000000 ____D C:\Windows\erdnt 2014-01-28 19:59 - 2012-12-09 12:05 - 00000000 ____D C:\ProgramData\Samsung 2014-01-28 19:59 - 2012-11-29 14:45 - 00000000 ____D C:\ProgramData\FLEXnet 2014-01-28 19:59 - 2012-10-17 18:52 - 00000000 ____D C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP 2014-01-28 19:59 - 2012-10-16 21:37 - 00000000 ____D C:\Users\Public\Documents\S.T.A.L.K.E.R. - Call of Pripyat 2014-01-28 19:59 - 2012-10-16 21:06 - 00000000 ____D C:\ProgramData\Sun 2014-01-28 19:59 - 2012-10-16 20:37 - 00000000 ____D C:\ProgramData\Mozilla 2014-01-28 19:59 - 2010-11-21 08:16 - 00000000 ___RD C:\Users\Public\Recorded TV 2014-01-28 19:59 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2014-01-28 19:59 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports 2014-01-28 19:58 - 2014-01-27 13:54 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2014-01-28 19:58 - 2014-01-26 16:28 - 00000000 ____D C:\ProgramData\APN 2014-01-28 19:58 - 2013-11-04 15:25 - 00000000 ____D C:\ProgramData\Applications 2014-01-28 19:58 - 2013-06-26 17:22 - 00000000 ____D C:\ProgramData\BlueStacksSetup 2014-01-28 19:58 - 2013-06-26 17:22 - 00000000 ____D C:\ProgramData\BlueStacks 2014-01-28 19:58 - 2013-06-13 15:42 - 00000000 ____D C:\Program Files (x86)\Windows Live 2014-01-28 19:58 - 2013-01-27 13:41 - 00000000 ____D C:\ProgramData\Apple Computer 2014-01-28 19:58 - 2013-01-27 13:40 - 00000000 ____D C:\ProgramData\Apple 2014-01-28 19:58 - 2013-01-18 11:38 - 00000000 ____D C:\ProgramData\cFos 2014-01-28 19:58 - 2012-11-29 14:28 - 00000000 ____D C:\ProgramData\Autodesk 2014-01-28 19:58 - 2012-11-18 18:04 - 00000000 ____D C:\ProgramData\Electronic Arts 2014-01-28 19:58 - 2012-10-16 21:48 - 00000000 ____D C:\ProgramData\Avira 2014-01-28 19:58 - 2012-10-16 21:15 - 00000000 ____D C:\ProgramData\Adobe 2014-01-28 19:58 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\XFastUsb 2014-01-28 19:58 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\Vuze 2014-01-28 19:40 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-28 19:40 - 2014-01-27 18:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-28 19:40 - 2014-01-27 18:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-28 19:40 - 2013-12-21 16:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-28 19:40 - 2013-12-12 19:39 - 00000000 ____D C:\Program Files (x86)\MyFree Codec 2014-01-28 19:40 - 2013-06-13 15:43 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2014-01-28 19:40 - 2013-03-13 22:09 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2014-01-28 19:40 - 2013-02-20 20:21 - 00000000 ____D C:\Program Files (x86)\Foxit Software 2014-01-28 19:40 - 2013-02-20 18:40 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 2014-01-28 19:40 - 2013-02-19 15:30 - 00000000 ____D C:\Program Files (x86)\Google 2014-01-28 19:40 - 2013-01-27 13:41 - 00000000 ____D C:\Program Files (x86)\QuickTime 2014-01-28 19:40 - 2013-01-26 11:47 - 00000000 ____D C:\Program Files (x86)\Origin 2014-01-28 19:40 - 2013-01-23 12:02 - 00000000 ____D C:\Program Files (x86)\Magical Jelly Bean 2014-01-28 19:40 - 2013-01-22 10:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2014-01-28 19:40 - 2013-01-22 10:58 - 00000000 ____D C:\Program Files (x86)\MSECache 2014-01-28 19:40 - 2013-01-16 09:55 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-01-28 19:40 - 2013-01-06 19:22 - 00000000 ____D C:\Program Files (x86)\PDFCreator 2014-01-28 19:40 - 2013-01-06 19:22 - 00000000 ____D C:\Program Files (x86)\PDF Architect 2014-01-28 19:40 - 2012-12-09 12:07 - 00000000 ____D C:\Program Files (x86)\MarkAny 2014-01-28 19:40 - 2012-12-09 12:05 - 00000000 ____D C:\Program Files (x86)\Samsung 2014-01-28 19:40 - 2012-11-30 17:24 - 00000000 ____D C:\Program Files (x86)\Rail Simulator 2014-01-28 19:40 - 2012-10-18 11:18 - 00000000 ____D C:\Program Files (x86)\Fire Department 3 2014-01-28 19:40 - 2012-10-16 21:06 - 00000000 ____D C:\Program Files (x86)\Java 2014-01-28 19:40 - 2012-10-16 21:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2014-01-28 19:40 - 2012-10-16 21:00 - 00000000 ____D C:\Program Files (x86)\REALTEK 2014-01-28 19:40 - 2012-10-16 20:44 - 00000000 ____D C:\Program Files (x86)\Intel 2014-01-28 19:39 - 2013-11-07 18:38 - 00000000 ____D C:\Program Files (x86)\Convar 2014-01-28 19:39 - 2013-06-26 12:43 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2014-01-28 19:39 - 2013-01-18 11:34 - 00000000 ____D C:\Program Files (x86)\Etron Technology 2014-01-28 19:39 - 2012-11-18 18:04 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2014-01-28 19:39 - 2012-10-18 11:22 - 00000000 ____D C:\Program Files (x86)\Fire Department 2 2014-01-28 19:39 - 2012-10-16 21:16 - 00000000 ____D C:\Program Files (x86)\epson 2014-01-28 19:39 - 2012-10-16 20:45 - 00000000 ____D C:\Program Files (x86)\CyberLink 2014-01-28 19:39 - 2012-10-16 20:45 - 00000000 ____D C:\Program Files (x86)\Creative 2014-01-28 19:38 - 2014-01-27 13:54 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork 2014-01-28 19:38 - 2013-11-23 18:24 - 00000000 ____D C:\Program Files (x86)\AviSynth 2.5 2014-01-28 19:38 - 2013-06-26 17:23 - 00000000 ____D C:\Program Files (x86)\BlueStacks 2014-01-28 19:38 - 2013-06-12 18:57 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1 2014-01-28 19:38 - 2013-06-12 18:57 - 00000000 ____D C:\Program Files (x86)\Bandicam 2014-01-28 19:38 - 2013-02-26 15:33 - 00000000 ____D C:\Program Files (x86)\3DCrafter 92 2014-01-28 19:38 - 2013-02-24 15:53 - 00000000 ____D C:\Program Files (x86)\7-Zip 2014-01-28 19:38 - 2013-01-27 13:40 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2014-01-28 19:38 - 2013-01-18 13:07 - 00000000 ____D C:\Program Files (x86)\Autodesk 2014-01-28 19:38 - 2012-12-17 08:17 - 00000000 ____D C:\Program Files (x86)\Avira 2014-01-28 19:38 - 2012-10-16 20:45 - 00000000 ____D C:\Program Files (x86)\Cisco 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\bitComposer Games 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\ASRock Utility 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\Adobe 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\3DCrafter 9 2014-01-28 19:37 - 2014-01-28 19:26 - 00000000 ____D C:\Program Files\Common Files\EPSON 2014-01-28 19:37 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2014-01-28 19:37 - 2013-11-07 18:31 - 00000000 ____D C:\Program Files\Recuva 2014-01-28 19:37 - 2013-03-14 15:55 - 00000000 ____D C:\Program Files\WinRAR 2014-01-28 19:37 - 2013-03-13 22:09 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2014-01-28 19:37 - 2013-02-13 11:25 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared 2014-01-28 19:37 - 2013-01-22 11:16 - 00000000 ____D C:\Program Files\GIMP 2 2014-01-28 19:37 - 2013-01-18 11:35 - 00000000 ____D C:\Program Files\Lucidlogix Technologies 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Steam 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\postureAgent 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Java 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Intel 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\InstallShield 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Etron Technology 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Epson Software 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\epson 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared 2014-01-28 19:37 - 2012-10-17 16:09 - 00000000 ____D C:\Program Files\CyberLink 2014-01-28 19:37 - 2012-10-17 16:09 - 00000000 ____D C:\Program Files\Creative 2014-01-28 19:37 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\EXPERTool 2014-01-28 19:37 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2014-01-28 19:36 - 2013-02-24 16:03 - 00000000 ____D C:\Program Files\CCleaner 2014-01-28 19:36 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR 2014-01-28 19:36 - 2012-10-17 16:09 - 00000000 ____D C:\Program Files\Cisco 2014-01-28 19:36 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\bitComposer Games 2014-01-28 19:34 - 2013-02-13 11:24 - 00000000 ____D C:\Program Files\Autodesk 2014-01-28 19:29 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\ASRock Utility 2014-01-28 19:29 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\Adobe 2014-01-28 19:29 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\3DCrafter 9 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten 2014-01-28 19:26 - 2014-01-28 19:26 - 00001355 _____ C:\Windows\TSSysprep.log 2014-01-28 19:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files\Realtek 2014-01-28 19:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Help 2014-01-28 19:24 - 2014-01-28 19:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-01-28 19:23 - 2010-11-21 08:17 - 00000000 ____D C:\Windows\CSC 2014-01-28 18:47 - 2013-01-23 13:15 - 00700540 _____ C:\Windows\WindowsUpdate (1).log 2014-01-28 18:08 - 2012-11-17 10:13 - 00001890 _____ C:\Windows\diagwrn.xml 2014-01-28 18:08 - 2012-11-17 10:13 - 00001890 _____ C:\Windows\diagerr.xml 2014-01-27 19:01 - 2013-09-27 15:59 - 00000000 ____D C:\ProgramData\DSearchLink 2014-01-27 18:56 - 2014-01-27 18:55 - 00000000 ____D C:\AdwCleaner 2014-01-27 18:55 - 2014-01-27 18:55 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-27 18:35 - 2014-01-27 18:35 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-27 12:41 - 2014-01-27 12:41 - 02278856 _____ C:\Users\Patrick Polzyn\Downloads\avira_pc_cleaner_de.exe 2014-01-27 12:41 - 2014-01-27 12:41 - 00002049 _____ C:\Users\Patrick Polzyn\Desktop\Entfernen des Avira PC Cleaners.lnk 2014-01-27 12:41 - 2014-01-27 12:41 - 00001993 _____ C:\Users\Patrick Polzyn\Desktop\Avira PC Cleaner.lnk 2014-01-27 08:39 - 2014-01-27 08:39 - 00000262 _____ C:\Users\Patrick Polzyn\Desktop\Run.lnk 2014-01-26 11:28 - 2013-01-11 09:36 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Debugmode 2014-01-26 11:28 - 2013-01-11 09:36 - 00000000 ____D C:\Program Files (x86)\DebugMode 2014-01-26 11:22 - 2013-11-23 18:23 - 00000000 ____D C:\Program Files (x86)\eRightSoft 2014-01-26 10:06 - 2014-01-26 10:06 - 23867560 _____ (Mozilla) C:\Users\Patrick Polzyn\Downloads\Firefox Setup 26.0.exe 2014-01-25 14:02 - 2014-01-25 14:02 - 00004540 _____ C:\Users\Patrick Polzyn\Documents\cc_20140125_140224.reg 2014-01-24 18:27 - 2014-01-24 18:27 - 00316109 _____ C:\Users\Patrick Polzyn\Desktop\Grenzsteine_DE-PL.rwp 2014-01-16 08:36 - 2013-08-14 19:12 - 00000000 ____D C:\Windows\system32\MRT 2014-01-13 16:45 - 2014-01-13 16:45 - 00001566 _____ C:\Users\Patrick Polzyn\Desktop\railworks - Verknüpfung.lnk 2014-01-05 10:14 - 2014-01-05 10:14 - 00115592 _____ C:\Users\Patrick Polzyn\Documents\cc_20140105_101436.reg Some content of TEMP: ==================== C:\Users\Patrick Polzyn\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-29 13:48 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-01-2014 01 Ran by Patrick Polzyn at 2014-01-29 14:10:59 Running from C:\Users\Patrick Polzyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYPJZKPN Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== 3DCrafter (x32 Version: - Amabilis Software) 7-Zip 9.20 (x32 Version: - ) Adobe AIR (x32 Version: 1.0.4990 - Adobe Systems Inc.) Adobe AIR (x32 Version: - Adobe Systems Inc.) Hidden Adobe Bridge 1.0 (x32 Version: 001.000.001 - Adobe Systems) Hidden Adobe Common File Installer (x32 Version: 1.00.001 - Adobe System Incorporated) Hidden Adobe Creative Suite 2 (x32 Version: - ) Adobe Flash Player 11 ActiveX (x32 Version: 11.6.602.180 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Help Center 1.0 (x32 Version: 1.0.1 - Adobe Systems) Hidden Adobe Photoshop CS2 (x32 Version: 9.0 - Adobe Systems, Inc.) Hidden Adobe Reader XI (11.0.02) - Deutsch (x32 Version: 11.0.02 - Adobe Systems Incorporated) Adobe Stock Photos 1.0 (x32 Version: 1.0.1 - Adobe Systems) Hidden Akamai NetSession Interface (HKCU Version: - Akamai Technologies, Inc) Akamai NetSession Interface Service (x32 Version: - Akamai Technologies, Inc) Apple Software Update (x32 Version: - Apple Inc.) ASRock App Charger v1.0.4 (Version: - ASRock Inc.) ASRock InstantBoot v1.29 (x32 Version: - ) AutoCAD 2011 - Deutsch (Version: - Autodesk) AutoCAD 2011 - Deutsch (Version: - Autodesk) Hidden AutoCAD 2011 Language Pack - Deutsch (Version: - Autodesk) Hidden Autodesk 3ds Max 2014 (Version: 16.2.475.0 - Autodesk) Autodesk 3ds Max 2014 (Version: 16.2.475.0 - Autodesk) Hidden Autodesk 3ds Max 2014 64-bit Populate Data (Version: - Autodesk) Autodesk 3ds Max 2014 SP2 (Version: 16.2.475.0 - Autodesk) Autodesk Backburner 2014 (x32 Version: - Autodesk, Inc.) Autodesk Composite 2014 (Version: - Autodesk) Autodesk Composite 2014 (Version: - Autodesk) Hidden Autodesk Design Review 2013 (x32 Version: - Autodesk, Inc.) Autodesk Design Review 2013 (x32 Version: - Autodesk, Inc.) Hidden Autodesk DirectConnect 2014 64-bit (Version: - Autodesk) Autodesk DirectConnect 2014 64-bit (Version: - Autodesk) Hidden Autodesk Download Manager (x32 Version: - Autodesk, Inc.) Autodesk Essential Skills Movies for 3ds Max 2014 64-bit (Version: - Autodesk) Autodesk FBX Plugin 2009.4 - 3ds Max Design 2010 (x32 Version: - Autodesk) Autodesk Inventor Server Engine for 3ds Max 2014 64-bit (Version: 16.0 - Autodesk) Autodesk Material Library 2011 Base Image library (x32 Version: - Autodesk) Autodesk Material Library 2011 Medium Image library (x32 Version: - Autodesk) Autodesk Material Library 2014 (x32 Version: - Autodesk) Autodesk Material Library Base Resolution Image Library 2014 (x32 Version: - Autodesk) Autodesk Material Library Medium Resolution Image Library 2014 (x32 Version: - Autodesk) Autodesk Revit Interoperability for 3ds Max 2014 (Version: 13.02.15161 - Autodesk) Autodesk Revit Interoperability for 3ds Max 2014 (Version: 13.02.15161 - Autodesk) Hidden Avira Antivirus Suite (x32 Version: - Avira) Avira SearchFree Toolbar (x32 Version: - APN, LLC) Avira Update Manager (x32 Version: - Avira Operations GmbH & Co. KG) Bandicam (x32 Version: - Bandisoft.com) Bandisoft MPEG-1 Decoder (x32 Version: - Bandisoft.com) BlueStacks App Player (x32 Version: - BlueStack Systems, Inc.) BlueStacks Notification Center (x32 Version: - BlueStack Systems, Inc.) CCleaner (Version: 3.27 - Piriform) Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.) Counter-Strike: Source (x32 Version: - Valve) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKCU Version: 2.0.22 - Dropbox, Inc.) EPSON BX305 Plus Series Printer Uninstall (Version: - SEIKO EPSON Corporation) EPSON Scan (x32 Version: - Seiko Epson Corporation) Etron USB3.0 Host Controller (x32 Version: 0.104 - Etron Technology) Hidden FAKEFACTORY Cinematic Mod 2013 (x32 Version: alpha1 - FAKEFACTORY) Fire Department 2 (x32 Version: - Nexway) Fire Department 3 (x32 Version: - Nexway) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Foxit Reader (x32 Version: - Foxit Corporation) Fraps (x32 Version: - ) Free YouTube to MP3 Converter version (x32 Version: - DVDVideoSoft Ltd.) GIMP 2.8.2 (Version: 2.8.2 - The GIMP Team) Google Earth (x32 Version: - Google) Google Update Helper (x32 Version: - Google Inc.) Hidden Half-Life 2 (x32 Version: - Valve) Half-Life 2: Deathmatch (x32 Version: - Valve) Half-Life 2: Episode One (x32 Version: - Valve) Half-Life 2: Episode Two (x32 Version: - Valve) Half-Life 2: Lost Coast (x32 Version: - Valve) Intel(R) Management Engine Components (x32 Version: - Intel Corporation) Intel(R) Processor Graphics (x32 Version: - Intel Corporation) Java 7 Update 25 (x32 Version: 7.0.250 - Oracle) Java Auto Updater (x32 Version: - Sun Microsystems, Inc.) Hidden Left 4 Dead 2 (x32 Version: - Valve) Magical Jelly Bean KeyFinder (x32 Version: - Magical Jelly Bean) Malwarebytes Anti-Malware Version (x32 Version: - Malwarebytes Corporation) Metro: Last Light (x32 Version: - 4A Games) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: - ) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Word Viewer 2003 (x32 Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MyFreeCodec (HKCU Version: - ) Need For Speed™ World (x32 Version: - Electronic Arts) NVIDIA 3D Vision Controller-Treiber 310.90 (Version: 310.90 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 331.65 (Version: 331.65 - NVIDIA Corporation) NVIDIA GeForce Experience 1.0 (BETA) (Version: 1.0 (BETA) - NVIDIA Corporation) NVIDIA Grafiktreiber 331.65 (Version: 331.65 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.12.1031 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden NVIDIA Update 2.47.55 (Version: 2.47.55 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 2.47.55 - NVIDIA Corporation) Hidden OpenOffice.org 3.4.1 (x32 Version: 3.41.9593 - Apache Software Foundation) Origin (x32 Version: - Electronic Arts, Inc.) PC Inspector smart recovery (x32 Version: 4.50 - ) PDF Architect (x32 Version: - pdfforge) PDFCreator (x32 Version: 1.6.1 - pdfforge) Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden QuickTime (x32 Version: - Apple Inc.) Realtek Ethernet Controller Driver (x32 Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (x32 Version: - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver and Utility (x32 Version: 1.00.0148 - REALTEK Semiconductor Corp.) REALTEK Wireless LAN Driver and Utility (x32 Version: 1.00.0149 - REALTEK Semiconductor Corp.) Recuva (Version: 1.48 - Piriform) RW_Tools V4 (HKCU Version: - ) RW_Tools V5 (HKCU Version: - ) Samsung Kies (x32 Version: - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (Version: - SAMSUNG Electronics Co., Ltd.) Source SDK (x32 Version: - Valve) Source SDK Base 2006 (x32 Version: - Valve) Source SDK Base 2007 (x32 Version: - Valve) Source SDK Base 2013 Multiplayer (x32 Version: - ) Source SDK Base 2013 Singleplayer (x32 Version: - ) Spybot - Search & Destroy (x32 Version: 2.0.12 - Safer-Networking Ltd.) Steam (x32 Version: - Valve Corporation) Suite Specific (x32 Version: 2.0.0 - Adobe Systems, Incorporated) Hidden Train Simulator 2013 (x32 Version: - RailSimulator.com) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation) VIRTU 1.2.106 (Version: 1.2.106 - Lucfidlogix Technologies LTD) Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden WinRAR 4.20 (64-Bit) (Version: 4.20.0 - win.rar GmbH) World Landscapes (x32 Version: - Freeware Edition - 3DTrains) XFastUsb (x32 Version: - ) ==================== Restore Points ========================= 28-01-2014 20:07:07 Windows Update 28-01-2014 20:11:27 Windows Update 29-01-2014 09:55:52 Windows Update 29-01-2014 12:55:05 Sprachpaketdeinstallation ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {141D7D2D-F5DD-42AA-9478-03E012705B4C} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {1E51A613-D59D-4205-BF8F-51554967374E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-19] (Google Inc.) Task: {29DF561B-38D6-48B7-AFA3-C595D37393EF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {51209254-6434-406A-811F-8996321AF8B6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-15] (Adobe Systems Incorporated) Task: {7864BE98-96CC-4B56-8402-B3C7AF2CF0C1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {8B54751B-3428-4E3D-A76C-BDA48081BD6F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-19] (Google Inc.) Task: {EBC9CD4D-AEB8-4257-BCCE-EDD08C172F22} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {EDAA0A35-A9BD-416F-8B03-143F7C405A0D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-28 19:25 - 2013-10-23 09:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2012-11-19 08:33 - 2012-11-19 08:33 - 00070264 _____ () C:\Windows\system32\bdmpega64.acm 2013-11-07 01:52 - 2013-11-07 01:52 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-12-17 08:17 - 2014-01-27 18:36 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2013-01-16 09:55 - 2012-11-13 14:06 - 00108960 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-01-16 09:55 - 2012-11-13 14:06 - 00416160 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-01-16 09:55 - 2012-11-13 14:06 - 00158624 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-01-16 09:55 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-01-16 09:55 - 2012-11-13 14:06 - 00528288 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl 2012-10-16 21:00 - 2009-12-09 20:20 - 00126976 _____ () C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\EnumDevLib.dll 2012-10-18 10:55 - 2009-12-09 20:20 - 00126976 _____ () C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\EnumDevLib.dll 2013-01-16 09:55 - 2012-11-13 14:06 - 00554400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Realtek RTL8190 802.11n Wireless LAN (Mini-)PCI NIC Description: Realtek RTL8190 802.11n Wireless LAN (Mini-)PCI NIC Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Semiconductor Corp. Service: rtl819xpn64 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/29/2014 01:56:03 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName1". Die Einstellung "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName" ist nicht registriert. Error: (01/29/2014 01:52:47 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/29/2014 01:51:08 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "FARO.LS,processorArchitecture="x86",publicKeyToken="1d23f5635ba800ab",type="win32",version="1.1.406.58"1". Die abhängige Assemblierung "FARO.LS,processorArchitecture="x86",publicKeyToken="1d23f5635ba800ab",type="win32",version="1.1.406.58"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/29/2014 01:14:02 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/29/2014 01:14:02 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName1". Die Einstellung "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName" ist nicht registriert. Error: (01/29/2014 01:13:54 PM) (Source: RaySat_3dsmax2014_64 Server) (User: ) Description: (1507) getservbyname: Der angeforderte Name ist gültig, es wurden jedoch keine Daten des angeforderten Typs gefunden. (0x2afc) Error: (01/29/2014 00:58:49 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/29/2014 00:58:47 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName1". Die Einstellung "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName" ist nicht registriert. Error: (01/29/2014 00:58:34 PM) (Source: RaySat_3dsmax2014_64 Server) (User: ) Description: (1507) getservbyname: Der angeforderte Name ist gültig, es wurden jedoch keine Daten des angeforderten Typs gefunden. (0x2afc) Error: (01/29/2014 00:51:03 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2862152) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 3.5.1 unter Windows 7 und Windows Server 2008 R2 SP1 für x64-basierte Systeme (KB2736422) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-Systeme (KB2698365) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2834886) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 3.5.1 unter Windows 7 und Windows Server 2008 R2 für x64-basierte Systeme (KB2832414) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Update für Microsoft .NET Framework 3.5.1 unter Windows 7 und Windows Server 2008 R2 SP1 für x64-basierte Systeme (KB2836943) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2876284) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2619339) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2564958) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2511455) Microsoft Office Sessions: ========================= Error: (01/29/2014 01:56:03 PM) (Source: SideBySide)(User: ) Description: hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayNamec:\program files (x86)\spybot - search & destroy 2\SDWSCSvc.exe Error: (01/29/2014 01:52:47 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Autodesk\Composite2014\python\lib\distutils\command\wininst-8_d.exe Error: (01/29/2014 01:51:08 PM) (Source: SideBySide)(User: ) Description: FARO.LS,processorArchitecture="x86",publicKeyToken="1d23f5635ba800ab",type="win32",version="1.1.406.58"C:\Program Files\Autodesk\AutoCAD 2011\FaroImporter.exe Error: (01/29/2014 01:14:02 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/29/2014 01:14:02 PM) (Source: SideBySide)(User: ) Description: hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayNameC:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe Error: (01/29/2014 01:13:54 PM) (Source: RaySat_3dsmax2014_64 Server)(User: ) Description: (1507) getservbyname: Der angeforderte Name ist gültig, es wurden jedoch keine Daten des angeforderten Typs gefunden. (0x2afc) Error: (01/29/2014 00:58:49 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/29/2014 00:58:47 PM) (Source: SideBySide)(User: ) Description: hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayNameC:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe Error: (01/29/2014 00:58:34 PM) (Source: RaySat_3dsmax2014_64 Server)(User: ) Description: (1507) getservbyname: Der angeforderte Name ist gültig, es wurden jedoch keine Daten des angeforderten Typs gefunden. (0x2afc) Error: (01/29/2014 00:51:03 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2013-03-24 09:31:23.563 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:23.547 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:21.252 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:21.236 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:18.702 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:18.683 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:15.223 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:15.205 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:12.456 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:12.440 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 32% Total physical RAM: 8104.67 MB Available physical RAM: 5457.57 MB Total Pagefile: 16207.54 MB Available Pagefile: 13105.45 MB Total Virtual: 8192 MB Available Virtual: 8191.78 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:938.54 GB) (Free:565.53 GB) NTFS Drive f: (Volume) (Fixed) (Total:924.37 GB) (Free:783.57 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 861EACED) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=939 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=924 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Gruß |
![]() | #4 | |
Spybot ist Müll, deinstallieren, das Tool bringt niix
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #5 |
![]() | ![]() Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Das Programm habe ich weil ich in der Ausbildung bin kostenlos. Ist ein Privater rechner. Das Programm ist aber auf meinen Namen und Adresse regestriert. Ist das Programm ein Problem? |
![]() | #6 |
Wieso glauben alle immer gleich an ein Problem, diese Software ist kein Problem, aber nicht gerade so eine die Lieschen Müller vorinstalliert auf ihrem Home-Rechner findet. Deswegen kann man hier gewerbliche Nutzung vermuten und deswegen frage ich immer nach.

Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ --> Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an |
![]() | #7 |
Ich habe das Tool instaliert und den Scan laufen lassen. Jetzt ist er fertig hat aber nichts gefunden.
Code: Malwarebytes Anti-Rootkit scan completed - 0 malicious items detected
![]() | #8 |
Adware/Junkware/Toolbars entfernen

1. Schritt: adwCleaner
2. Schritt: JRT - Junkware Removal Tool
3. Schritt: Frisches Log mit FRST
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #9 |
So hier nun die Log Files der drei Programme:

JRT Code: [JRT scan results showing deleted registry keys and folders]

FRST Logfile: [Beginning of FRST scan]
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Professional x64 Ran by Patrick Polzyn on 29.01.2014 at 19:10:14,50 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5296BDA4-2B7E-4BA6-967A-DEDF0C5EF2FE} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" ~~~ FireFox Successfully deleted the following from C:\Users\Patrick Polzyn\AppData\Roaming\mozilla\firefox\profiles\ryyx8uo6.default\prefs.js user_pref("extensions.AVIRA-V7C.com.avira.dnt.rules", "\"{\\\"Version\\\":39,\\\"Companies\\\":[{\\\"company\\\":\\\"Google Inc\\\",\\\"rules\\\":[{\\\"name\\\":\\\"Google Ana user_pref("extensions.AVIRA-V7C.domain", "\"avira.search.ask.com\""); Emptied folder: C:\Users\Patrick Polzyn\AppData\Roaming\mozilla\firefox\profiles\ryyx8uo6.default\minidumps [106 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 29.01.2014 at 19:15:00,09 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01 Ran by Patrick Polzyn (administrator) on PATRICKPOLZYN on 29-01-2014 19:19:26 Running from C:\Users\Patrick Polzyn\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Realtek) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
(Realtek) C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\RtlService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Toolbar.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1815976 2014-01-27] (Valve Corporation) HKU\Administrator\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2010-11-21] (Microsoft Corporation) HKU\UpdatusUser\...\Run: [Spybot-S&D Cleaning] - "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean HKU\UpdatusUser\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1815976 2014-01-27] (Valve Corporation) HKU\UpdatusUser\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2010-11-21] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.) Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) ==================== Services (Whitelisted) ===================

R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [908856 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. 