FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-11-2013
Ran by *** (ATTENTION: The logged in user is not administrator) on *** on 20-11-2013 12:17:50
Running from C:\Users\***\AppData\Local\Opera\Opera\temporary_downloads
Microsoft Windows 8 Pro (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynToshiba.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Opera Software) C:\Users\***\AppData\Local\Programs\Opera\opera.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1348904 2008-08-14] (Synaptics, Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-10-02] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM\...\Runonce: [ASYNCMAC] - rundll32.exe streamci,StreamingDeviceSetup {eeab7790-c514-11d1-b42b-00805fc1270e},asyncmac,{ad498944-762f-11d0-8dcb-00c04fc3358c},C:\WINDOWS\INF\netrasa.inf,Ndis-Mp-AsyncMac
HKLM\...\Runonce: [MSPCLOCK] - rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000}
HKLM\...\Runonce: [MSPQM] - rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196}
HKLM\...\Runonce: [MSKSSRV] - rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196}
HKLM\...\Runonce: [MSTEE.CxTransform] - rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\WINDOWS\inf\ksfilter.inf,MSTEE.Interface.Install
HKLM\...\Runonce: [MSTEE.Splitter] - rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\WINDOWS\inf\ksfilter.inf,MSTEE.Interface.Install
HKLM\...\Runonce: [WDM_DRMKAUD] - rundll32.exe streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\WINDOWS\inf\WDMAUDIO.inf,WDM_DRMKAUD.Interface.Install
HKLM\...\RunOnce: [BrowserChoice] - C:\WINDOWS\BrowserChoice\browserchoice.exe [84064 2012-08-15] (Microsoft Corporation)
HKLM\...\RunOnce: [*Restore] - C:\WINDOWS\System32\rstrui.exe /runonce [244224 2012-07-26] (Microsoft Corporation)
Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://google.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x94D8FDB36DDCCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-10-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-10-02] (Avira Operations GmbH & Co. KG)
R2 lmhosts; C:\Windows\system32\svchost.exe [23040 2012-09-20] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [23040 2012-09-20] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [23040 2012-09-20] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14480 2013-07-01] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 athr; C:\Windows\system32\DRIVERS\athr.sys [2273280 2012-06-02] (Qualcomm Atheros Communications, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-10-02] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [136672 2013-10-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [37352 2013-06-17] (Avira Operations GmbH & Co. KG)
R1 BasicRender; C:\Windows\System32\drivers\BasicRender.sys [24576 2012-07-26] (Microsoft Corporation)
R1 ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [28520 2013-06-17] (Avira GmbH)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-20 12:19 - 2013-11-20 12:19 - 00000090 ____H C:\Users\***\Desktop\.~lock.Mappe1.xlsx#
2013-11-20 12:16 - 2013-11-20 12:16 - 00000000 ____D C:\FRST
2013-11-20 10:45 - 2013-11-20 10:45 - 105319036 _____ C:\WINDOWS\system32\夐避L™
2013-11-18 21:55 - 2013-11-18 21:55 - 00440952 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-18 18:03 - 2013-11-18 18:03 - 104931504 _____ C:\WINDOWS\system32\衣؛LZ
2013-11-18 09:03 - 2013-11-05 23:58 - 00694232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-11-18 09:03 - 2013-11-05 23:58 - 00078296 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-11-15 20:36 - 2013-09-13 23:36 - 02600448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2013-11-15 20:36 - 2013-09-13 23:36 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2013-11-15 20:36 - 2013-09-13 23:36 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2013-11-15 20:36 - 2013-09-13 23:36 - 00247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2013-11-15 20:36 - 2013-08-30 01:44 - 00054104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2013-11-15 20:36 - 2013-08-30 00:48 - 00914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2013-11-15 20:36 - 2013-08-21 05:28 - 00407384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2013-11-15 20:36 - 2013-08-10 06:24 - 00123224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2013-11-15 20:36 - 2013-07-25 00:10 - 10799104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2013-11-15 20:35 - 2013-10-10 10:29 - 00683520 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2013-11-15 20:35 - 2013-10-03 00:41 - 01075712 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2013-11-15 20:35 - 2013-10-02 00:37 - 02035712 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2013-11-15 20:35 - 2013-10-02 00:37 - 01569280 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2013-11-15 20:35 - 2013-09-23 23:30 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2013-11-15 20:35 - 2013-09-13 23:58 - 00052656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2013-11-15 20:35 - 2013-09-13 23:36 - 00216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2013-11-15 20:35 - 2013-09-13 23:36 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2013-11-15 20:35 - 2013-09-13 23:36 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2013-11-15 20:35 - 2013-09-13 23:36 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2013-11-15 20:35 - 2013-09-13 23:36 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2013-11-15 20:35 - 2013-08-23 02:44 - 01711616 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-11-15 20:35 - 2013-08-10 04:58 - 00656896 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2013-11-15 20:35 - 2013-07-12 02:30 - 00485376 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2013-11-15 20:34 - 2013-10-12 08:04 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-15 20:34 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-15 20:34 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-15 20:34 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-15 20:34 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-15 20:34 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-15 20:34 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-15 20:34 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2013-11-15 20:34 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2013-11-15 20:34 - 2013-10-10 11:07 - 00038744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2013-11-15 20:34 - 2013-10-10 10:28 - 00473600 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2013-11-15 20:19 - 2013-11-15 20:19 - 00000000 ____D C:\Users\***\.thumbnails
2013-11-15 20:15 - 2013-11-15 20:15 - 104496569 _____ C:\WINDOWS\system32\탡❶Lġ
2013-11-14 15:24 - 2013-11-14 15:24 - 104225154 _____ C:\WINDOWS\system32\ቿგLŢ
2013-11-13 20:36 - 2013-11-14 08:22 - 104179408 _____ C:\WINDOWS\system32\赻䉩LÄ
2013-11-13 14:38 - 2013-11-13 14:38 - 104010312 _____ C:\WINDOWS\system32\X눵Lĺ
2013-11-13 08:35 - 2013-11-13 08:35 - 104004073 _____ C:\WINDOWS\system32\䥕筇Lª
2013-11-12 13:39 - 2013-11-12 13:39 - 103891779 _____ C:\WINDOWS\system32\疌㊼L½
2013-11-09 10:04 - 2013-11-09 10:04 - 103347145 _____ C:\WINDOWS\system32\驄Lë
2013-11-08 10:50 - 2013-11-08 10:50 - 103075526 _____ C:\WINDOWS\system32\崡鳤Lġ
2013-11-07 23:34 - 2013-11-07 23:34 - 00008816 _____ C:\Users\***\Desktop\Mappe1.xlsx
2013-11-07 23:06 - 2013-11-07 23:06 - 00000000 ____D C:\Users\***\AppData\Local\Microsoft Help
2013-11-07 21:00 - 2013-11-07 21:00 - 103000967 _____ C:\WINDOWS\system32\㾆Lij
2013-11-05 20:54 - 2013-11-05 20:54 - 105085299 _____ C:\WINDOWS\system32\摣愍LĢ
2013-11-05 06:20 - 2013-11-05 06:20 - 105017276 _____ C:\WINDOWS\system32\ἕ熞L„
2013-11-04 17:11 - 2013-11-04 17:11 - 104894933 _____ C:\WINDOWS\system32\ü㾕睱
2013-11-04 07:53 - 2013-11-04 07:53 - 104845822 _____ C:\WINDOWS\system32\娘䝡L§
2013-11-03 21:18 - 2013-11-07 14:38 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-11-03 21:09 - 2013-11-07 14:39 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-03 21:07 - 2013-11-07 14:31 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-11-03 21:07 - 2013-11-03 21:07 - 00000000 ____D C:\WINDOWS\PCHEALTH
2013-11-03 21:03 - 2013-11-07 14:27 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2013-11-03 21:02 - 2013-11-03 21:02 - 00000000 ____D C:\Users\***\AppData\Local\Microsoft Help
2013-11-03 21:01 - 2013-11-07 15:17 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-03 21:01 - 2013-11-07 14:27 - 00000000 ____D C:\Program Files\Microsoft Office
2013-11-03 20:58 - 2013-11-07 14:25 - 00000000 __RHD C:\MSOCache
2013-11-03 16:23 - 2013-11-03 16:23 - 104760586 _____ C:\WINDOWS\system32\皮总LŃ
2013-10-30 16:45 - 2013-11-07 14:27 - 00000000 ____D C:\Program Files\LibreOffice 4
==================== One Month Modified Files and Folders =======
2013-11-20 12:19 - 2013-11-20 12:19 - 00000090 ____H C:\Users\***\Desktop\.~lock.Mappe1.xlsx#
2013-11-20 12:16 - 2013-11-20 12:16 - 00000000 ____D C:\FRST
2013-11-20 12:00 - 2012-07-26 07:53 - 00000000 ____D C:\WINDOWS\system32\sru
2013-11-20 10:45 - 2013-11-20 10:45 - 105319036 _____ C:\WINDOWS\system32\夐避L™
2013-11-20 09:00 - 2012-07-26 07:53 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-11-19 22:50 - 2013-06-17 16:24 - 02031310 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-18 21:55 - 2013-11-18 21:55 - 00440952 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-18 21:55 - 2012-07-26 07:04 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-18 18:03 - 2013-11-18 18:03 - 104931504 _____ C:\WINDOWS\system32\衣؛LZ
2013-11-18 12:19 - 2012-07-26 07:53 - 00000000 ____D C:\WINDOWS\rescache
2013-11-18 08:58 - 2012-07-26 07:53 - 00000000 ____D C:\WINDOWS\WinStore
2013-11-18 08:58 - 2012-07-26 07:53 - 00000000 ____D C:\WINDOWS\system32\de-DE
2013-11-18 08:57 - 2012-07-26 07:53 - 00000000 ___RD C:\WINDOWS\ToastData
2013-11-17 21:11 - 2013-08-14 08:18 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-17 21:06 - 2013-06-18 17:49 - 80340640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-15 20:19 - 2013-11-15 20:19 - 00000000 ____D C:\Users\***\.thumbnails
2013-11-15 20:19 - 2013-06-17 16:21 - 00000000 ____D C:\Users\***
2013-11-15 20:15 - 2013-11-15 20:15 - 104496569 _____ C:\WINDOWS\system32\탡❶Lġ
2013-11-14 15:24 - 2013-11-14 15:24 - 104225154 _____ C:\WINDOWS\system32\ቿგLŢ
2013-11-14 08:22 - 2013-11-13 20:36 - 104179408 _____ C:\WINDOWS\system32\赻䉩LÄ
2013-11-13 14:38 - 2013-11-13 14:38 - 104010312 _____ C:\WINDOWS\system32\X눵Lĺ
2013-11-13 08:35 - 2013-11-13 08:35 - 104004073 _____ C:\WINDOWS\system32\䥕筇Lª
2013-11-12 13:39 - 2013-11-12 13:39 - 103891779 _____ C:\WINDOWS\system32\疌㊼L½
2013-11-09 10:04 - 2013-11-09 10:04 - 103347145 _____ C:\WINDOWS\system32\驄Lë
2013-11-08 10:50 - 2013-11-08 10:50 - 103075526 _____ C:\WINDOWS\system32\崡鳤Lġ
2013-11-07 23:34 - 2013-11-07 23:34 - 00008816 _____ C:\Users\***\Desktop\Mappe1.xlsx
2013-11-07 23:06 - 2013-11-07 23:06 - 00000000 ____D C:\Users\***\AppData\Local\Microsoft Help
2013-11-07 21:00 - 2013-11-07 21:00 - 103000967 _____ C:\WINDOWS\system32\㾆Lij
2013-11-07 15:44 - 2013-06-17 16:29 - 01654648 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-11-07 15:17 - 2013-11-03 21:01 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-07 14:42 - 2012-07-26 09:45 - 00000000 ____D C:\WINDOWS\ShellNew
2013-11-07 14:39 - 2013-11-03 21:09 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-07 14:38 - 2013-11-03 21:18 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-11-07 14:35 - 2012-07-26 07:53 - 00000000 ____D C:\WINDOWS\registration
2013-11-07 14:31 - 2013-11-03 21:07 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-11-07 14:31 - 2012-07-26 07:53 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-11-07 14:27 - 2013-11-03 21:03 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2013-11-07 14:27 - 2013-11-03 21:01 - 00000000 ____D C:\Program Files\Microsoft Office
2013-11-07 14:27 - 2013-10-30 16:45 - 00000000 ____D C:\Program Files\LibreOffice 4
2013-11-07 14:27 - 2012-07-26 07:53 - 00000000 ____D C:\Program Files\Common Files\System
2013-11-07 14:27 - 2012-07-26 07:53 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-07 14:25 - 2013-11-03 20:58 - 00000000 __RHD C:\MSOCache
2013-11-07 10:31 - 2012-07-26 07:53 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-11-05 23:58 - 2013-11-18 09:03 - 00694232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-11-05 23:58 - 2013-11-18 09:03 - 00078296 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-11-05 20:54 - 2013-11-05 20:54 - 105085299 _____ C:\WINDOWS\system32\摣愍LĢ
2013-11-05 06:20 - 2013-11-05 06:20 - 105017276 _____ C:\WINDOWS\system32\ἕ熞L„
2013-11-04 17:11 - 2013-11-04 17:11 - 104894933 _____ C:\WINDOWS\system32\ü㾕睱
2013-11-04 07:53 - 2013-11-04 07:53 - 104845822 _____ C:\WINDOWS\system32\娘䝡L§
2013-11-04 07:49 - 2013-06-17 16:16 - 00008842 _____ C:\WINDOWS\PFRO.log
2013-11-03 21:07 - 2013-11-03 21:07 - 00000000 ____D C:\WINDOWS\PCHEALTH
2013-11-03 21:04 - 2012-07-26 05:17 - 00000167 _____ C:\WINDOWS\win.ini
2013-11-03 21:02 - 2013-11-03 21:02 - 00000000 ____D C:\Users\***\AppData\Local\Microsoft Help
2013-11-03 16:23 - 2013-11-03 16:23 - 104760586 _____ C:\WINDOWS\system32\皮总LŃ
Some content of TEMP:
====================
C:\Users\***\AppData\Local\Temp\mpam-57c1b46e.exe
C:\Users\***\AppData\Local\Temp\AskSLib.dll
C:\Users\***\AppData\Local\Temp\lowproc.exe
C:\Users\***\AppData\Local\Temp\ose00000.exe
C:\Users\***\AppData\Local\Temp\stubhelper.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 18-11-2013
Ran by *** at 2013-11-20 12:20:19
Running from C:\Users\***\AppData\Local\Opera\Opera\temporary_downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 11 Plugin (Version: 11.8.800.94)
Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05)
Apple Application Support (Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (Version: 2.1.3.127)
Avira Free Antivirus (Version: 13.0.0.4052)
Bonjour (Version: 3.0.0.10)
GIMP 2.8.4 (Version: 2.8.4)
iTunes (Version: 11.0.5.5)
LibreOffice 4.1 Help Pack (German) (Version: 4.1.2.3)
Microsoft Access MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft DCF MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft Excel MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft Groove MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft Lync MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4420.1017)
Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft Office Professional Plus 2013 (Version: 15.0.4420.1017)
Microsoft Office Proofing (German) 2013 (Version: 15.0.4420.1017)
Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4420.1017)
Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4420.1017)
Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft OneNote MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft Outlook MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft Publisher MUI (German) 2013 (Version: 15.0.4420.1017)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Word MUI (German) 2013 (Version: 15.0.4420.1017)
OpenOffice.org 3.4.1 (Version: 3.41.9593)
Opera 12.16 (HKCU Version: 12.16.1860)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4420.1017)
Synaptics Pointing Device Driver (Version: 11.2.4.0)
Texas Instruments PCIxx21/x515/xx12 drivers. (Version: 1.23.0000)
TIPCI (Version: 1.23.0000)
==================== Restore Points =========================
Could not list Restore Points. Check WMI.
==================== Hosts content: ==========================
2012-07-26 05:17 - 2012-07-26 05:17 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
==================== Loaded Modules (whitelisted) =============
2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00835584 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\gstreamer.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00093696 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstaudioconvert.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00094208 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstaudioresample.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00057344 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstautodetect.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00096256 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstcoreplugins.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00062976 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstdecodebin2.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00067072 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstdirectsound.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00158208 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstffmpegcolorspace.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00312832 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstoggdec.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00038912 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstwaveform.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00073728 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstwavparse.dll
2013-06-17 16:43 - 2013-07-19 07:20 - 00101888 _____ () C:\Users\***\AppData\Local\Programs\Opera\gstreamer\plugins\gstwebmdec.dll
2013-08-06 07:03 - 2013-08-06 07:03 - 16166280 _____ () C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/19/2013 07:26:53 AM) (Source: Desktop Window Manager) (User: )
Description: Der Desktopfenster-Manager hat einen schwerwiegenden Fehler (0x8898008d) festgestellt.
Error: (11/18/2013 11:31:08 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15741
Error: (11/18/2013 11:31:08 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15741
Error: (11/18/2013 11:31:08 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/18/2013 04:08:49 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8705
Error: (11/18/2013 04:08:49 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8705
Error: (11/18/2013 04:08:49 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/18/2013 04:08:27 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9485
Error: (11/18/2013 04:08:27 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9485
Error: (11/18/2013 04:08:24 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (11/20/2013 08:48:31 AM) (Source: bowser) (User: )
Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "***BOX" zum Namen "***" auf Transport "NetBT_Tcpip_{05ECDB8E-FDCC-45D2-82B6-B8E6". Das Datagramm steht in den Daten.
Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist.
Error: (11/19/2013 08:52:19 PM) (Source: bowser) (User: )
Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "***BOX" zum Namen "***" auf Transport "NetBT_Tcpip_{05ECDB8E-FDCC-45D2-82B6-B8E6". Das Datagramm steht in den Daten.
Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist.
Error: (11/19/2013 07:37:00 PM) (Source: bowser) (User: )
Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "***BOX" zum Namen "***" auf Transport "NetBT_Tcpip_{05ECDB8E-FDCC-45D2-82B6-B8E6". Das Datagramm steht in den Daten.
Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist.
Error: (11/19/2013 01:48:57 PM) (Source: bowser) (User: )
Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "***BOX" zum Namen "***" auf Transport "NetBT_Tcpip_{05ECDB8E-FDCC-45D2-82B6-B8E6". Das Datagramm steht in den Daten.
Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist.
Error: (11/19/2013 11:48:23 AM) (Source: bowser) (User: )
Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "***BOX" zum Namen "***" auf Transport "NetBT_Tcpip_{05ECDB8E-FDCC-45D2-82B6-B8E6". Das Datagramm steht in den Daten.
Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist.
Error: (11/19/2013 11:43:51 AM) (Source: bowser) (User: )
Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "***BOX" zum Namen "***" auf Transport "NetBT_Tcpip_{05ECDB8E-FDCC-45D2-82B6-B8E6". Das Datagramm steht in den Daten.
Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist.
Error: (11/19/2013 08:43:43 AM) (Source: Microsoft-Windows-HAL) (User: )
Description: Der Speicher wurde beim letzten Leistungsübergang des Systems von der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte Firmware verfügbar ist.
Error: (11/19/2013 07:26:58 AM) (Source: bowser) (User: )
Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "***BOX" zum Namen "***" auf Transport "NetBT_Tcpip_{05ECDB8E-FDCC-45D2-82B6-B8E6". Das Datagramm steht in den Daten.
Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist.
Error: (11/18/2013 09:56:48 PM) (Source: bowser) (User: )
Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "***BOX" zum Namen "***" auf Transport "NetBT_Tcpip_{05ECDB8E-FDCC-45D2-82B6-B8E6". Das Datagramm steht in den Daten.
Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist.
Error: (11/18/2013 09:55:57 PM) (Source: bowser) (User: )
Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "***BOX" zum Namen "***" auf Transport "NetBT_Tcpip_{05ECDB8E-FDCC-45D2-82B6-B8E6". Das Datagramm steht in den Daten.
Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist.
Microsoft Office Sessions:
=========================
Error: (11/19/2013 07:26:53 AM) (Source: Desktop Window Manager)(User: )
Description: 0x8898008d
Error: (11/18/2013 11:31:08 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15741
Error: (11/18/2013 11:31:08 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15741
Error: (11/18/2013 11:31:08 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/18/2013 04:08:49 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8705
Error: (11/18/2013 04:08:49 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8705
Error: (11/18/2013 04:08:49 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/18/2013 04:08:27 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9485
Error: (11/18/2013 04:08:27 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9485
Error: (11/18/2013 04:08:24 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
==================== Memory info ===========================
Percentage of memory in use: 88%
Total physical RAM: 1014.05 MB
Available physical RAM: 117.96 MB
Total Pagefile: 2294.05 MB
Available Pagefile: 891 MB
Total Virtual: 2047.88 MB
Available Virtual: 1844.4 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:74.22 GB) (Free:30.96 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: () (Fixed) (Total:73.36 GB) (Free:73.02 GB) NTFS
==================== MBR & Partition Table ==================
==================== End Of Log ============================ |