Hallo,
alles gemacht wie gesagt. Hier die Logs. Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
Ran by xxx & xxx at 2014-04-11 16:29:12
Running from C:\Users\xxx & xxx\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Norton Internet Security (Disabled - Out of date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Disabled - Out of date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Disabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
==================== Installed Programs ======================
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader X MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.0.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.5 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.5.9.620 - Adobe Systems, Inc.)
Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden
Age of Empires Online (HKLM-x32\...\Steam App 105430) (Version: - Microsoft)
Ashampoo Home Designer Pro v.1.0.1 (HKLM-x32\...\{4D1A0101-17A2-4fca-9119-4734EDBDA12D}_is1) (Version: 1.0.1 - Creative Amadeo GmbH)
ATI Catalyst Install Manager (HKLM\...\{9A11B072-9CE7-ABB9-2F65-EC971A7B839D}) (Version: 3.0.816.0 - ATI Technologies, Inc.)
AudibleManager (HKLM-x32\...\AudibleManager) (Version: 2010463470.48.56.3018098 - Audible, Inc.)
AuthenTec TrueAPI (Version: 1.2.1.33 - AuthenTec, Inc.) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
Avira SearchFree Toolbar (HKLM-x32\...\{41564952-412D-5637-00A7-A758B70C0A03}) (Version: 12.10.3.4487 - APN, LLC)
Bauskript Software 2013-11 Standard (HKLM-x32\...\Bauskript Software 2013-11 Standard) (Version: 2013-11 Standard - Bauskript Software)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Big Rig Europe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Blasterball 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bounce Symphony (x32 Version: 2.2.0.95 - WildTangent) Hidden
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.48.61 - Broadcom Corporation)
Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cake Mania Main Street (HKLM-x32\...\510001653) (Version: - Oberon Media)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center (x32 Version: 2011.0508.224.2391 - Ihr Firmenname) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0508.224.2391 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2011.0508.224.2391 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2011.0508.224.2391 - ATI) Hidden
Catalyst Control Center Profiles Mobile (x32 Version: 2011.0508.224.2391 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Czech (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Danish (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Dutch (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help English (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Finnish (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help French (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help German (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Greek (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Italian (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Japanese (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Korean (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Polish (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Russian (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Spanish (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Swedish (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Thai (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
CCC Help Turkish (x32 Version: 2011.0508.0223.2391 - ATI) Hidden
ccc-utility64 (Version: 2011.0508.224.2391 - ATI) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Crazy Chicken Kart 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.1.3922 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.5.1.3922 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)
Evernote v. 4.2.2 (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 4.2.2.3979 - Evernote Corp.)
Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden
FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden
Fishdom (x32 Version: 2.2.0.95 - WildTangent) Hidden
Free Video Converter V 3.2 (HKLM-x32\...\Free Video Converter_is1) (Version: 3.2.0.0 - Koyote Soft)
GIMP 2.8.0 (HKLM\...\GIMP-2_is1) (Version: 2.8.0 - The GIMP Team)
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\...\{7B4DEBE1-E3E3-45BD-88E6-6C3CA9EEED36}) (Version: 4.1.16.1 - Hewlett-Packard Company)
HP Auto (Version: 1.0.12935.3667 - Hewlett-Packard Company) Hidden
HP Client Services (Version: 1.1.12938.3539 - Hewlett-Packard) Hidden
HP Connection Manager (HKLM-x32\...\{5E63C0AB-19B0-47D4-842E-6B324EB0614B}) (Version: 4.1.23.1 - Hewlett-Packard Company)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden
HP Documentation (HKLM-x32\...\{3C5AB11A-2DDB-49E6-9FC0-CFD88A7DDFE4}) (Version: 1.1.0.0 - Hewlett-Packard)
HP DVB-T TV Tuner 8.0.64.43 (HKLM-x32\...\HP DVB-T TV Tuner) (Version: 8.0.64.43 - )
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.4 - WildTangent)
HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company)
HP Power Manager (HKLM-x32\...\{872B1C80-38EC-4A31-A25C-980820593900}) (Version: 1.2.3 - Hewlett-Packard Company)
HP Quick Launch (HKLM-x32\...\{53B17A98-5BF0-40BC-AAFF-850A357975AC}) (Version: 2.7.2 - Hewlett-Packard Company)
HP Setup (HKLM-x32\...\{210A03F5-B2ED-4947-B27E-516F50CBB292}) (Version: 8.6.4530.3651 - Hewlett-Packard Company)
HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13253.3682 - Hewlett-Packard Company)
HP SimplePass 2011 (HKLM-x32\...\{BCFAA37D-A6DB-43BF-A351-43F183E52D07}) (Version: 5.1.0.495 - Hewlett-Packard)
HP Software Framework (HKLM-x32\...\{483539DB-FA71-4C45-8438-55D3DCFDECC8}) (Version: 4.5.10.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6381.0 - IDT)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3074 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.6.0.1002 - Intel Corporation)
Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217021FF}) (Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 24 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416024FF}) (Version: 6.0.240 - Oracle)
Java(TM) 6 Update 24 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216024FF}) (Version: 6.0.240 - Oracle)
Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: 3.0 - EasyBits Software AS)
Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Mein Heim 3D V3 Professional (HKLM-x32\...\Mein Heim 3D V3 Professional) (Version: - )
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
miCoach Manager (HKLM-x32\...\adidas miCoach Manager_is1) (Version: 5.3.10 - adidas)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.5128.5002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}) (Version: 08.05.0822 - Microsoft Corporation)
Movies Toolbar for Firefox (Dist. by Koyote-Lab, Inc.) (HKLM-x32\...\koyotesoftmoviestoolbarhaFF) (Version: 1.6.2.0 - APN LLC) <==== ATTENTION
Movies Toolbar for Internet Explorer (Dist. by Koyote-Lab, Inc.) (HKLM-x32\...\koyotesoftmoviestoolbarhaIE) (Version: 1.6.2.0 - APN LLC) <==== ATTENTION
Mozilla Firefox 13.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 13.0.1 (x86 de)) (Version: 13.0.1 - Mozilla)
Mozilla Firefox 28.0 (x86 de) (HKCU\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 13.0.1 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Mystery P.I. - The London Caper (x32 Version: 2.2.0.95 - WildTangent) Hidden
Namco All-Stars PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden
Norton Internet Security (HKLM-x32\...\NIS) (Version: 18.7.2.3 - Symantec Corporation)
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.41.216.2011 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.83 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 2.0.0 - Hewlett-Packard) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.19.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.1.19.0 - Renesas Electronics Corporation) Hidden
SketchUp 2013 (HKLM-x32\...\{2C0777B8-E91F-45AA-976B-7EB6B40E5400}) (Version: 13.0.4812 - Trimble Navigation Limited)
Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
SweetPacks bundle uninstaller (HKLM-x32\...\{953AA732-9AFB-49C9-84A4-7F96CA0A08DA}) (Version: 1.0.0001 - SweetIM Technologies Ltd.) <==== ATTENTION
Synaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.11.0 - Synaptics Incorporated)
Torch (HKCU\...\Torch) (Version: 29.0.0.6292 - Torch) <==== ATTENTION
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Validity WBF DDK (HKLM\...\{79174AF2-6CB1-42F5-981E-66DCA49391D0}) (Version: 4.3.205.0 - Validity Sensors, Inc.)
Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden
Web Assistant 2.0.0.478 (HKLM\...\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1) (Version: 2.0.0.478 - IncrediBar) <==== ATTENTION
Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden
WildTangent Games App (HP Games) (x32 Version: 4.0.10.5 - WildTangent) Hidden
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
==================== Restore Points =========================
02-03-2014 07:02:46 Windows Update
09-03-2014 17:13:01 Geplanter Prüfpunkt
14-03-2014 05:46:29 Windows Update
22-03-2014 14:29:28 Geplanter Prüfpunkt
31-03-2014 19:23:46 Geplanter Prüfpunkt
08-04-2014 04:45:24 Geplanter Prüfpunkt
11-04-2014 14:23:15 Windows Modules Installer
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {03BAB28F-6188-4DDD-9629-1CB3AD7043F5} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2011-01-31] ()
Task: {0FE8AF0E-9B64-4DE0-9A06-A9C1FE81A0AB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-03-21] (Hewlett-Packard)
Task: {104ED743-3574-4819-B40D-C79C82C6FACA} - System32\Tasks\Symantec\Norton Error Processor 18.7.2.3 => C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\SymErr.exe [2012-06-08] (Symantec Corporation)
Task: {1D2E4F41-DE22-4CE9-A9A6-B311D47541AF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-13] (Adobe Systems Incorporated)
Task: {2B71CC95-AC30-479D-B5E6-2266BD2EC471} - System32\Tasks\HPCeeScheduleForxxx & xxx => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13] (Hewlett-Packard)
Task: {4865D30A-DC9B-4919-9A84-BDDC9D911BE7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {84F98E4C-8325-469A-AD4C-931EC6860C7F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-03-21] (Hewlett-Packard)
Task: {88925BFC-1A3F-4D2D-9A6A-4ED462880270} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {90459382-2CD4-40F6-A003-A7F4EB909951} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company)
Task: {93F74D0A-950C-45EB-8240-06013606ADE0} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-03-22] (CyberLink)
Task: {98AD0139-3BAB-4E9C-B1B9-00200C85CF54} - System32\Tasks\Symantec\Norton Error Analyzer 18.7.2.3 => C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\SymErr.exe [2012-06-08] (Symantec Corporation)
Task: {CC059ABF-AC0B-42FB-AE46-CAC20672A218} - \CreateChoiceProcessTask No Task File
Task: {D4EAA428-1722-47AF-85F7-E40E009A80E8} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2011-01-31] ()
Task: {D4F8DD08-54DD-4CDD-AA80-E95FC8F7E65A} - System32\Tasks\Hewlett-Packard\HP Assistant\HPSA Upgrade => C:\ProgramData\Hewlett-Packard\HPSAUpgrade3\HpSAUpgrade.exe [2011-09-26] (Hewlett-Packard)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\HPCeeScheduleForxxx & xxx.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Loaded Modules (whitelisted) =============
2014-04-08 20:43 - 2014-04-07 10:57 - 00665096 _____ () C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll
2011-12-10 02:16 - 2011-04-15 05:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-05-12 15:13 - 2011-05-12 15:13 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2011-05-08 03:23 - 2011-05-08 03:23 - 00243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-04-27 17:05 - 2011-04-27 17:05 - 01102336 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\System.Data.SQLite.dll
2014-04-08 20:43 - 2014-04-07 10:57 - 00490504 _____ () C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll
2013-07-05 20:46 - 2013-06-20 14:48 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-04-08 20:43 - 2014-04-07 10:57 - 00020488 _____ () C:\Program Files (x86)\Movies Toolbar\Datamngr\mgrldr.dll
2014-02-15 16:26 - 2014-02-15 16:26 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\367540c92c2004ff2c6695778fed5dd6\IsdiInterop.ni.dll
2011-12-10 02:15 - 2011-05-20 10:05 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2011-04-27 17:05 - 2011-04-27 17:05 - 00514570 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\sqlite3.dll
2014-03-19 20:51 - 2014-03-19 20:51 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-03-13 18:58 - 2014-03-13 18:58 - 16276872 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\Temp:3612C9BE
AlternateDataStreams: C:\ProgramData\Temp:80B291A7
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
Name: Unknown Device
Description: Unknown Device
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard-USB-Hostcontroller)
Service:
Problem: : This device is disabled because the firmware of the device did not give it the required resources. (Code 29)
Resolution: Enable the device in the BIOS of the device.
Name: NO_NAME
Description: PCIE Card Reader
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Realtek
Service: WUDFRd
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
==================== Event log errors: =========================
Application errors:
==================
Error: (04/11/2014 04:23:10 PM) (Source: System Restore) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x81000101).
Error: (04/10/2014 08:20:44 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: AcroRd32.exe, Version: 10.0.0.396, Zeitstempel: 0x4cc5e97b
Name des fehlerhaften Moduls: AcroRd32.exe, Version: 10.0.0.396, Zeitstempel: 0x4cc5e97b
Ausnahmecode: 0x40000015
Fehleroffset: 0x0007df03
ID des fehlerhaften Prozesses: 0x18a0
Startzeit der fehlerhaften Anwendung: 0xAcroRd32.exe0
Pfad der fehlerhaften Anwendung: AcroRd32.exe1
Pfad des fehlerhaften Moduls: AcroRd32.exe2
Berichtskennung: AcroRd32.exe3
Error: (04/10/2014 08:20:19 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: AcroRd32.exe, Version: 10.0.0.396, Zeitstempel: 0x4cc5e97b
Name des fehlerhaften Moduls: AcroRd32.exe, Version: 10.0.0.396, Zeitstempel: 0x4cc5e97b
Ausnahmecode: 0x40000015
Fehleroffset: 0x0007df03
ID des fehlerhaften Prozesses: 0x1ac4
Startzeit der fehlerhaften Anwendung: 0xAcroRd32.exe0
Pfad der fehlerhaften Anwendung: AcroRd32.exe1
Pfad des fehlerhaften Moduls: AcroRd32.exe2
Berichtskennung: AcroRd32.exe3
Error: (04/10/2014 08:16:22 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU failed to post message to CCC
System errors:
=============
Error: (04/10/2014 08:16:17 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Torch Crash Handler" wurde aufgrund folgenden Fehlers nicht gestartet:
%%193
Error: (04/09/2014 07:31:46 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Torch Crash Handler" wurde aufgrund folgenden Fehlers nicht gestartet:
%%193
Error: (04/09/2014 07:31:25 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 09.04.2014 um 15:46:19 unerwartet heruntergefahren.
Error: (04/08/2014 08:47:42 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Torch Crash Handler" wurde aufgrund folgenden Fehlers nicht gestartet:
%%193
Error: (04/08/2014 08:47:42 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Torch Crash Handler" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (04/08/2014 08:44:19 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Datamngr Coordinator" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (04/07/2014 04:30:48 PM) (Source: DCOM) (User: )
Description: {FE9617F6-E606-42AA-BECC-0E9CDA246D63}
Error: (03/31/2014 06:04:22 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR11 gefunden.
Error: (03/31/2014 06:04:21 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR11 gefunden.
Error: (03/31/2014 06:04:20 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR11 gefunden.
Microsoft Office Sessions:
=========================
Error: (04/11/2014 04:23:10 PM) (Source: System Restore)(User: )
Description: C:\Windows\system32\svchost.exe -k netsvcsWindows Update0x81000101
Error: (04/10/2014 08:20:44 PM) (Source: Application Error)(User: )
Description: AcroRd32.exe10.0.0.3964cc5e97bAcroRd32.exe10.0.0.3964cc5e97b400000150007df0318a001cf54e995227f5dC:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exeC:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exed45e070e-c0dc-11e3-b8d6-082e5f818a79
Error: (04/10/2014 08:20:19 PM) (Source: Application Error)(User: )
Description: AcroRd32.exe10.0.0.3964cc5e97bAcroRd32.exe10.0.0.3964cc5e97b400000150007df031ac401cf54e982cbc97fC:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exeC:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exec517fc8a-c0dc-11e3-b8d6-082e5f818a79
Error: (04/10/2014 08:16:22 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord)(User: )
Description:
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord)(User: )
Description:
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord)(User: )
Description:
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord)(User: )
Description:
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord)(User: )
Description:
Error: (04/10/2014 08:14:29 PM) (Source: ATIeRecord)(User: )
Description:
==================== Memory info ===========================
Percentage of memory in use: 43%
Total physical RAM: 6091.86 MB
Available physical RAM: 3455.2 MB
Total Pagefile: 12181.9 MB
Available Pagefile: 9045.85 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:447.59 GB) (Free:365.8 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:17.87 GB) (Free:1.92 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive g: (NO_NAME) (Removable) (Total:3.68 GB) (Free:3.27 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: FA5300E9)
Partition: GPT Partition Type.
========================================================
Disk: 1 (Size: 4 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End Of Log ============================
und hier FRST.txt
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 29 days old and could be outdated)
Ran by xxx & xxx (administrator) on xxx-xxx-HP on 11-04-2014 16:28:23
Running from C:\Users\xxx & xxx\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Koyote-Lab Inc) C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe
(Koyote-Lab Inc) C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe
(Koyote-Lab Inc) C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
(Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\ipmGui.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2013-05-29] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2013-05-30] (IDT, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-05-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2013-05-29] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-03-16] (EasyBits Software AS)
HKLM-x32\...\Run: [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [103992 2011-06-14] (Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [HPOSD] - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-13] (APN)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Download Protect] - C:\ProgramData\dlprotect.exe
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-08] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-4205555943-3136606563-2108145796-1000\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1602984 2013-02-25] (Valve Corporation)
HKU\S-1-5-21-4205555943-3136606563-2108145796-1000\...\Run: [Exetender_148] - "C:\Program Files (x86)\FreeRide Games\GPlayer.exe" /schedule 300000
HKU\S-1-5-21-4205555943-3136606563-2108145796-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-4205555943-3136606563-2108145796-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-4205555943-3136606563-2108145796-1000\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll [490504 2014-04-07] () <===== ATTENTION
HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll [665096 2014-04-07] () <===== ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.search.ask.com/?o=APN10649A&gct=hp&d=414-135&v=n12281-311&t=4
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4
URLSearchHook: HKLM-x32 - RadioTotal1 Toolbar - {422f7661-9403-4da4-b4ef-cc3e268817b5} - C:\Program Files (x86)\RadioTotal1\prxtbRadi.dll No File
URLSearchHook: HKCU - RadioTotal1 Toolbar - {422f7661-9403-4da4-b4ef-cc3e268817b5} - C:\Program Files (x86)\RadioTotal1\prxtbRadi.dll No File
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2414} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=135&systemid=414&v=n12281-311&apn_uid=7132217142364078&apn_dtid=BND414&o=APN10649&apn_ptnrs=AGA&q={searchTerms}
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM - {C0B93072-C5B9-4412-9A37-4012A29AE9D3} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2414} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=135&systemid=414&v=n12281-311&apn_uid=7132217142364078&apn_dtid=BND414&o=APN10649&apn_ptnrs=AGA&q={searchTerms}
SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM-x32 - {C0B93072-C5B9-4412-9A37-4012A29AE9D3} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2414} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=135&systemid=414&v=n12281-311&apn_uid=7132217142364078&apn_dtid=BND414&o=APN10649&apn_ptnrs=AGA&q={searchTerms}
SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKCU - {C0B93072-C5B9-4412-9A37-4012A29AE9D3} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/?a=6OyLVUbk3a&loc=skw&search={searchTerms}
SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
BHO: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll No File
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll No File
BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO-x32: RadioTotal1 Toolbar - {422f7661-9403-4da4-b4ef-cc3e268817b5} - C:\Program Files (x86)\RadioTotal1\prxtbRadi.dll No File
BHO-x32: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll (Symantec Corporation)
BHO-x32: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Movies Toolbar (Dist. by Koyote-Lab, Inc.) - {e5d4f4fd-a039-4670-8354-633c30a5f54e} - C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\searchresultsDx.dll ()
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKLM-x32 - RadioTotal1 Toolbar - {422f7661-9403-4da4-b4ef-cc3e268817b5} - C:\Program Files (x86)\RadioTotal1\prxtbRadi.dll No File
Toolbar: HKLM-x32 - Movies Toolbar (Dist. by Koyote-Lab, Inc.) - {e5d4f4fd-a039-4670-8354-633c30a5f54e} - C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\searchresultsDx.dll ()
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095}
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-09-02] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default
FF user.js: detected! => C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\user.js
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.search.ask.com/?o=APN10649A&gct=hp&d=414-135&v=n12281-311&t=4
FF Keyword.URL: hxxp://www.google.de/search?hl=de&gl=de&lr=&ie=UTF-8&oe=UTF-8&meta=lr=lang_de&q=
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @oberon-media.com/ONCAdapter - C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll (Oberon-Media )
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\6\NP_wtapp.dll ()
FF Plugin-x32: TorchVLC - C:\Users\xxx & xxx\AppData\Local\Torch\Plugins\Video\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\searchplugins\ask-web-search.xml
FF SearchPlugin: C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\searchplugins\Ask.xml
FF SearchPlugin: C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\searchplugins\MyStart Search.xml
FF SearchPlugin: C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\searchplugins\sweetim.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\Extensions\ich@maltegoetz.de [2013-12-11]
FF Extension: Ask New Tabs - C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\Extensions\{B08F8994-AC71-AB07-5E09-CB39FD50DF38} [2014-04-08]
FF Extension: Movies Toolbar (Dist. by Koyote-Lab, Inc.) - C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\Extensions\{e5d4f4fd-a039-4670-8354-633c30a5f54e} [2014-04-08]
FF Extension: Lightbeam - C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2012-09-11]
FF Extension: PrivacyChoice TrackerBlock - C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\Extensions\trackerblock@privacychoice.org.xpi [2012-09-11]
FF Extension: Updated Ad Blocker for Firefox 11+ - C:\Users\xxx & xxx\AppData\Roaming\Mozilla\Firefox\Profiles\g142o9nu.default\Extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi [2012-12-31]
FF Extension: TrueSuite Website Logon - C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com [2014-03-19]
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\IPSFFPlgn\
FF Extension: Symantec Intrusion Prevention - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\IPSFFPlgn\ []
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\coFFPlgn_2011_7_13_2
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\coFFPlgn_2011_7_13_2 [2014-04-10]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (No Name) - C:\Users\xxx & xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab [2014-01-05]
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [2014-01-05]
CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [2014-02-21]
CHR HKLM-x32\...\Chrome\Extension: [aepeildmfnnehghlknddebgjghlompfe] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-02-11]
CHR HKLM-x32\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [2011-02-11]
CHR HKLM-x32\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\xxx & xxx\AppData\Local\Wajam\Chrome\wajam.crx [2011-02-11]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.)
R2 DatamngrCoordinator; C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe [3544072 2014-04-07] (Koyote-Lab Inc)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation)
S2 TorchCrashHandler; C:\Users\xxx & xxx\AppData\Local\Torch\Update\TorchCrashHandler.exe [1216520 2014-03-27] (TorchMedia Inc.)
S2 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20130702.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-08-10] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-08-10] (Symantec Corporation)
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622; C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\setmgrc1.cfg [36232 2014-04-07] (Koyote-Lab Inc)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20130702.001\IDSvia64.sys [513184 2012-09-01] (Symantec Corporation)
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [44480 2011-05-17] (hxxp://libusb-win32.sourceforge.net)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20130703.002\ENG64.SYS [126040 2013-05-22] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20130703.002\EX64.SYS [2098776 2013-05-22] (Symantec Corporation)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1207020.003\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1207020.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1207020.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1207020.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2012-07-03] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS [171128 2011-01-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-11 16:28 - 2014-04-11 16:28 - 00029242 _____ () C:\Users\xxx & xxx\Downloads\FRST.txt
2014-04-11 16:25 - 2014-04-11 16:28 - 00000000 ____D () C:\FRST
2014-04-11 16:24 - 2014-04-11 16:25 - 02157056 _____ (Farbar) C:\Users\xxx & xxx\Downloads\FRST64.exe
2014-04-10 15:29 - 2014-04-10 15:29 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{333D8FE3-AAA0-4738-9CEF-A176FBA4EC54}
2014-04-09 19:35 - 2014-04-09 19:35 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{B89098AD-E138-42EC-BEDA-F9BDD37C07BA}
2014-04-09 15:46 - 2014-04-09 15:46 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{1915E95D-0886-4180-83C3-5565837DAEB7}
2014-04-08 20:47 - 2014-04-08 20:47 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch
2014-04-08 20:47 - 2014-04-08 20:47 - 00000000 ____D () C:\ProgramData\TorchCrashHandler
2014-04-08 20:46 - 2014-04-08 20:55 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\Torch
2014-04-08 20:46 - 2014-04-08 20:47 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Roaming\FreeVideoConverter
2014-04-08 20:46 - 2014-04-08 20:46 - 00001203 _____ () C:\Users\xxx & xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Video Converter.lnk
2014-04-08 20:43 - 2014-04-11 16:27 - 00000000 ____D () C:\ProgramData\Datamngr
2014-04-08 20:43 - 2014-04-08 20:46 - 00000000 ____D () C:\Program Files (x86)\Free Video Converter
2014-04-08 20:43 - 2014-04-08 20:43 - 00000000 ____D () C:\Program Files (x86)\Movies Toolbar
2014-04-08 20:42 - 2014-04-08 20:43 - 01226344 _____ (Koyote-Lab Inc) C:\Users\xxx & xxx\Downloads\FreeVideoConverterSetup-r135-n-bf.exe
2014-04-08 18:21 - 2014-04-08 18:21 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{77C3BAFE-23BC-4F66-81BE-973FFA90405F}
2014-04-07 18:51 - 2014-04-07 18:51 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{CFE70962-0377-4EA8-9DDE-920316C241E4}
2014-04-06 20:27 - 2014-04-06 20:27 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{25D8F602-F74E-4D51-90D6-AB8335ABD577}
2014-04-06 08:18 - 2014-04-06 08:18 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{DA3EC4E6-30E1-4D3F-94D5-843F2B26A319}
2014-04-05 14:23 - 2014-04-05 14:23 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{00CA81FC-8DDD-4CE3-90B3-98593F6704D6}
2014-04-03 17:25 - 2014-04-03 17:26 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{7CB0C6E5-9987-4ACC-AA5A-30C7F3C75318}
2014-04-02 17:09 - 2014-04-02 17:11 - 104871190 _____ () C:\Users\xxx & xxx\Downloads\Lily Allen - Hard Out Here -- John Newman - CheatingM56895028.zip
2014-04-02 16:44 - 2014-04-02 16:44 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{44CA6229-4537-4ADC-89CE-5317173C2C02}
2014-04-01 19:07 - 2014-04-01 19:08 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{FA9AE02A-129F-49D2-9EFB-FB9CFD169290}
2014-03-31 17:48 - 2014-03-31 18:27 - 104957015 _____ () C:\Users\xxx & xxx\Downloads\Lily Allen - Hard Out Here -- Placebo - Loud Like LoveM56895028.zip
2014-03-31 17:38 - 2014-03-31 17:38 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{1A0450D9-94A7-4CB2-A5D1-094D4C4C5F69}
2014-03-31 11:33 - 2014-03-31 11:33 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{FCACF1C9-3BF6-4235-B2F7-F1A6E8C935F4}
2014-03-30 15:00 - 2014-03-30 15:00 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{DEE6F2EA-7821-4A41-8D37-D67AEB226E7B}
2014-03-29 19:37 - 2014-03-29 19:37 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{540EEB4C-4C48-4723-8A3B-20A66CCBAA7D}
2014-03-29 06:11 - 2014-03-29 06:11 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{897BCAF8-EF9C-47CA-9869-8D65283A61F4}
2014-03-28 14:25 - 2014-03-28 14:25 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{73A04EE1-EAFD-43BC-9E0A-8902B7213E75}
2014-03-27 21:30 - 2014-03-27 21:31 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{956AE24B-4D1A-4246-BFD7-176682FAC42F}
2014-03-27 20:58 - 2014-03-28 14:27 - 00024380 _____ () C:\Users\xxx & xxx\Documents\Bericht xxx Roggen.odt
2014-03-27 09:31 - 2014-03-27 09:31 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{381E0914-00DE-4BFB-B859-40CF0086D8FA}
2014-03-26 09:47 - 2014-03-26 09:47 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{CF4EB0CC-A28F-4FEE-8F1C-CE85350583C6}
2014-03-25 20:11 - 2014-03-25 20:11 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{8EC20861-F24A-4BA0-BC3F-C713B760ACD6}
2014-03-25 11:48 - 2014-03-26 18:54 - 00022839 _____ () C:\Users\xxx & xxx\Documents\Bericht xxx Mais.odt
2014-03-24 18:24 - 2014-03-24 18:24 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{2D0C7E63-BC47-439B-A861-76BC2C9664BA}
2014-03-23 19:36 - 2014-03-28 14:35 - 00025065 _____ () C:\Users\xxx & xxx\Documents\Bericht xxx Maisernte.odt
2014-03-23 19:28 - 2014-03-23 19:28 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{EC2B8F7F-28BC-4005-9EF4-6D484E905665}
2014-03-23 07:27 - 2014-03-23 07:28 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{D74E6010-C1AB-401B-982A-1870C9BD6E59}
2014-03-22 16:29 - 2014-03-22 16:29 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{1F19C754-066E-43DE-B968-DBABB168E174}
2014-03-21 14:11 - 2014-03-21 14:11 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{34F9F651-DB4F-4A65-8E9A-A3090EBFDA1B}
2014-03-20 17:34 - 2014-03-20 17:48 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{0CEBF870-4AD5-46FD-A4CC-F83579C69A4A}
2014-03-19 20:51 - 2014-03-19 20:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-19 17:35 - 2014-03-19 17:35 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{72864900-82CD-47BD-9D87-6782DCA5A66D}
2014-03-18 16:47 - 2014-03-18 16:47 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{14ED5C9E-03C8-4CA2-84CC-282CED83F7BE}
2014-03-17 12:08 - 2014-03-17 12:08 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{247DF94F-9B88-46EB-8253-731352236185}
2014-03-16 12:16 - 2014-03-16 12:17 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{A40D2FCF-7CE1-4619-B3C6-CBC84678D908}
2014-03-15 23:43 - 2014-03-15 23:43 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{EF2D3DA8-FF5B-47FF-90E3-C5CF55FB5813}
2014-03-15 11:42 - 2014-03-15 11:42 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{614118F0-5CE9-4E19-8CE3-8B9457C3F3E8}
2014-03-14 14:12 - 2014-03-11 19:03 - 00023278 _____ () C:\Users\xxx & xxx\Documents\Themenvorschläge%20f%20EB%20-2012Änd.docx_0.odt
2014-03-14 07:46 - 2014-03-14 07:46 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{A9D49696-004A-470E-8ADC-F5E736D4075D}
2014-03-13 19:25 - 2014-03-13 19:25 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{C48857D5-466B-45F0-82D8-52DE13AA014B}
2014-03-13 19:13 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 19:13 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 19:13 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 19:13 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 19:13 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 19:13 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 19:13 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 19:13 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 19:13 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 19:13 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 19:13 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 19:13 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 19:13 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-13 19:13 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 19:13 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 19:13 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-13 19:13 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 19:13 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 19:13 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-13 19:13 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-13 19:13 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-13 19:13 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-13 19:13 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-13 19:13 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 19:13 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-13 19:13 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-13 19:13 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-13 19:13 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 19:13 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 19:13 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-13 19:13 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-13 19:13 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 19:13 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-13 19:13 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-13 19:13 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-13 19:13 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 19:13 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-13 19:13 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-13 19:13 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 19:13 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-13 19:13 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 19:13 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 19:13 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-13 19:13 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-13 19:12 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-13 19:12 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 19:12 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-13 19:12 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-13 18:58 - 2014-03-13 18:58 - 05777288 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
==================== One Month Modified Files and Folders =======
2014-04-11 16:28 - 2014-04-11 16:28 - 00029242 _____ () C:\Users\xxx & xxx\Downloads\FRST.txt
2014-04-11 16:28 - 2014-04-11 16:25 - 00000000 ____D () C:\FRST
2014-04-11 16:28 - 2012-07-12 18:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-11 16:28 - 2011-12-10 02:19 - 01838584 _____ () C:\Windows\WindowsUpdate.log
2014-04-11 16:27 - 2014-04-08 20:43 - 00000000 ____D () C:\ProgramData\Datamngr
2014-04-11 16:25 - 2014-04-11 16:24 - 02157056 _____ (Farbar) C:\Users\xxx & xxx\Downloads\FRST64.exe
2014-04-10 20:48 - 2013-11-16 20:13 - 00004002 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{8764855C-9FF7-4BB2-9271-CC7AAF962017}
2014-04-10 20:24 - 2012-10-06 13:02 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-04-10 20:24 - 2009-07-14 06:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-10 20:24 - 2009-07-14 06:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-10 20:23 - 2011-09-02 10:43 - 00700126 _____ () C:\Windows\system32\perfh007.dat
2014-04-10 20:23 - 2011-09-02 10:43 - 00149976 _____ () C:\Windows\system32\perfc007.dat
2014-04-10 20:23 - 2009-07-14 07:13 - 01622196 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-10 20:20 - 2012-07-11 07:07 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\CrashDumps
2014-04-10 20:16 - 2013-01-09 18:24 - 00000364 _____ () C:\Windows\Tasks\HPCeeScheduleForxxx & xxx.job
2014-04-10 20:16 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-10 20:15 - 2009-07-14 06:51 - 00068987 _____ () C:\Windows\setupact.log
2014-04-10 15:29 - 2014-04-10 15:29 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{333D8FE3-AAA0-4738-9CEF-A176FBA4EC54}
2014-04-09 19:43 - 2013-01-09 18:24 - 00003258 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForxxx & xxx
2014-04-09 19:43 - 2012-07-04 20:09 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-04-09 19:42 - 2012-07-18 17:28 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-04-09 19:35 - 2014-04-09 19:35 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{B89098AD-E138-42EC-BEDA-F9BDD37C07BA}
2014-04-09 19:31 - 2010-11-21 05:47 - 00174980 _____ () C:\Windows\PFRO.log
2014-04-09 15:46 - 2014-04-09 15:46 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{1915E95D-0886-4180-83C3-5565837DAEB7}
2014-04-08 20:55 - 2014-04-08 20:46 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\Torch
2014-04-08 20:47 - 2014-04-08 20:47 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch
2014-04-08 20:47 - 2014-04-08 20:47 - 00000000 ____D () C:\ProgramData\TorchCrashHandler
2014-04-08 20:47 - 2014-04-08 20:46 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Roaming\FreeVideoConverter
2014-04-08 20:46 - 2014-04-08 20:46 - 00001203 _____ () C:\Users\xxx & xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Video Converter.lnk
2014-04-08 20:46 - 2014-04-08 20:43 - 00000000 ____D () C:\Program Files (x86)\Free Video Converter
2014-04-08 20:46 - 2009-07-14 04:34 - 00000561 _____ () C:\Windows\win.ini
2014-04-08 20:43 - 2014-04-08 20:43 - 00000000 ____D () C:\Program Files (x86)\Movies Toolbar
2014-04-08 20:43 - 2014-04-08 20:42 - 01226344 _____ (Koyote-Lab Inc) C:\Users\xxx & xxx\Downloads\FreeVideoConverterSetup-r135-n-bf.exe
2014-04-08 18:21 - 2014-04-08 18:21 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{77C3BAFE-23BC-4F66-81BE-973FFA90405F}
2014-04-07 18:51 - 2014-04-07 18:51 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{CFE70962-0377-4EA8-9DDE-920316C241E4}
2014-04-06 20:27 - 2014-04-06 20:27 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{25D8F602-F74E-4D51-90D6-AB8335ABD577}
2014-04-06 08:18 - 2014-04-06 08:18 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{DA3EC4E6-30E1-4D3F-94D5-843F2B26A319}
2014-04-05 14:23 - 2014-04-05 14:23 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{00CA81FC-8DDD-4CE3-90B3-98593F6704D6}
2014-04-03 17:26 - 2014-04-03 17:25 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{7CB0C6E5-9987-4ACC-AA5A-30C7F3C75318}
2014-04-02 17:11 - 2014-04-02 17:09 - 104871190 _____ () C:\Users\xxx & xxx\Downloads\Lily Allen - Hard Out Here -- John Newman - CheatingM56895028.zip
2014-04-02 16:44 - 2014-04-02 16:44 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{44CA6229-4537-4ADC-89CE-5317173C2C02}
2014-04-01 19:08 - 2014-04-01 19:07 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{FA9AE02A-129F-49D2-9EFB-FB9CFD169290}
2014-03-31 18:27 - 2014-03-31 17:48 - 104957015 _____ () C:\Users\xxx & xxx\Downloads\Lily Allen - Hard Out Here -- Placebo - Loud Like LoveM56895028.zip
2014-03-31 17:38 - 2014-03-31 17:38 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{1A0450D9-94A7-4CB2-A5D1-094D4C4C5F69}
2014-03-31 11:33 - 2014-03-31 11:33 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{FCACF1C9-3BF6-4235-B2F7-F1A6E8C935F4}
2014-03-30 15:00 - 2014-03-30 15:00 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{DEE6F2EA-7821-4A41-8D37-D67AEB226E7B}
2014-03-29 19:37 - 2014-03-29 19:37 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{540EEB4C-4C48-4723-8A3B-20A66CCBAA7D}
2014-03-29 06:11 - 2014-03-29 06:11 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{897BCAF8-EF9C-47CA-9869-8D65283A61F4}
2014-03-28 14:35 - 2014-03-23 19:36 - 00025065 _____ () C:\Users\xxx & xxx\Documents\Bericht xxx Maisernte.odt
2014-03-28 14:31 - 2014-02-23 14:03 - 00025887 _____ () C:\Users\xxx & xxx\Documents\Erfahrungsbericht 1 Kuhstall.odt
2014-03-28 14:27 - 2014-03-27 20:58 - 00024380 _____ () C:\Users\xxx & xxx\Documents\Bericht xxx Roggen.odt
2014-03-28 14:25 - 2014-03-28 14:25 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{73A04EE1-EAFD-43BC-9E0A-8902B7213E75}
2014-03-28 14:22 - 2014-02-25 20:11 - 00023446 _____ () C:\Users\xxx & xxx\Documents\Berichte xxx Mais.odt
2014-03-28 14:19 - 2014-03-06 19:58 - 00023223 _____ () C:\Users\xxx & xxx\Documents\Berichte xxx Getriede´´.odt
2014-03-27 21:31 - 2014-03-27 21:30 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{956AE24B-4D1A-4246-BFD7-176682FAC42F}
2014-03-27 09:31 - 2014-03-27 09:31 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{381E0914-00DE-4BFB-B859-40CF0086D8FA}
2014-03-26 18:54 - 2014-03-25 11:48 - 00022839 _____ () C:\Users\xxx & xxx\Documents\Bericht xxx Mais.odt
2014-03-26 09:47 - 2014-03-26 09:47 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{CF4EB0CC-A28F-4FEE-8F1C-CE85350583C6}
2014-03-25 20:11 - 2014-03-25 20:11 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{8EC20861-F24A-4BA0-BC3F-C713B760ACD6}
2014-03-25 11:52 - 2014-02-23 15:54 - 00028275 _____ () C:\Users\xxx & xxx\Documents\Berichte xxx.odt
2014-03-25 10:53 - 2014-03-04 21:14 - 00024234 _____ () C:\Users\xxx & xxx\Documents\Berichte xxx Weizen.odt
2014-03-25 10:51 - 2014-03-11 20:38 - 00025143 _____ () C:\Users\xxx & xxx\Documents\Berichte xxx Ernte Mais.odt
2014-03-24 18:24 - 2014-03-24 18:24 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{2D0C7E63-BC47-439B-A861-76BC2C9664BA}
2014-03-23 19:28 - 2014-03-23 19:28 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{EC2B8F7F-28BC-4005-9EF4-6D484E905665}
2014-03-23 07:28 - 2014-03-23 07:27 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{D74E6010-C1AB-401B-982A-1870C9BD6E59}
2014-03-22 16:29 - 2014-03-22 16:29 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{1F19C754-066E-43DE-B968-DBABB168E174}
2014-03-21 14:11 - 2014-03-21 14:11 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{34F9F651-DB4F-4A65-8E9A-A3090EBFDA1B}
2014-03-20 17:48 - 2014-03-20 17:34 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{0CEBF870-4AD5-46FD-A4CC-F83579C69A4A}
2014-03-19 20:51 - 2014-03-19 20:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-19 17:35 - 2014-03-19 17:35 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{72864900-82CD-47BD-9D87-6782DCA5A66D}
2014-03-18 16:47 - 2014-03-18 16:47 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{14ED5C9E-03C8-4CA2-84CC-282CED83F7BE}
2014-03-17 12:08 - 2014-03-17 12:08 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{247DF94F-9B88-46EB-8253-731352236185}
2014-03-16 12:17 - 2014-03-16 12:16 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{A40D2FCF-7CE1-4619-B3C6-CBC84678D908}
2014-03-15 23:43 - 2014-03-15 23:43 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{EF2D3DA8-FF5B-47FF-90E3-C5CF55FB5813}
2014-03-15 11:42 - 2014-03-15 11:42 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{614118F0-5CE9-4E19-8CE3-8B9457C3F3E8}
2014-03-14 14:11 - 2013-04-04 19:55 - 00000000 ___RD () C:\Users\xxx & xxx\Desktop\johannes
2014-03-14 08:07 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-14 08:07 - 2009-07-14 06:45 - 00346936 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-14 08:06 - 2013-03-14 08:20 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-14 08:06 - 2013-03-14 08:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-14 07:46 - 2014-03-14 07:46 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{A9D49696-004A-470E-8ADC-F5E736D4075D}
2014-03-13 19:25 - 2014-03-13 19:25 - 00000000 ____D () C:\Users\xxx & xxx\AppData\Local\{C48857D5-466B-45F0-82D8-52DE13AA014B}
2014-03-13 18:58 - 2014-03-13 18:58 - 05777288 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-03-13 18:58 - 2012-07-12 18:16 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-13 18:58 - 2012-07-12 18:16 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-13 18:58 - 2012-07-12 18:16 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
Files to move or delete:
====================
C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll
C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll
Some content of TEMP:
====================
C:\Users\xxx & xxx\AppData\Local\Temp\avgnt.exe
C:\Users\xxx & xxx\AppData\Local\Temp\Extract.exe
C:\Users\xxx & xxx\AppData\Local\Temp\FileSystemView.dll
C:\Users\xxx & xxx\AppData\Local\Temp\HPHelpUpdater.exe
C:\Users\xxx & xxx\AppData\Local\Temp\increBibar_install1003.exe
C:\Users\xxx & xxx\AppData\Local\Temp\install_reader11_de_mssa_aih.exe
C:\Users\xxx & xxx\AppData\Local\Temp\miCoach1_micoachmanagersetup.exe
C:\Users\xxx & xxx\AppData\Local\Temp\miCoach_miCoachManagerSetup.exe
C:\Users\xxx & xxx\AppData\Local\Temp\Resource.exe
C:\Users\xxx & xxx\AppData\Local\Temp\sdisrqo2.dll
C:\Users\xxx & xxx\AppData\Local\Temp\SIMEEI2Installer.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SIMEEIInstaller.exe
C:\Users\xxx & xxx\AppData\Local\Temp\sp54620.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP54630.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP54714.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP55101.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP55102.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP55104.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP55107.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP55109.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP55152.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP56878.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP56929.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP57232.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP57965.exe
C:\Users\xxx & xxx\AppData\Local\Temp\sp58915.exe
C:\Users\xxx & xxx\AppData\Local\Temp\SP59542.exe
C:\Users\xxx & xxx\AppData\Local\Temp\sp64126.exe
C:\Users\xxx & xxx\AppData\Local\Temp\UninstallHPSA.exe
C:\Users\xxx & xxx\AppData\Local\Temp\UninstallHPTCA.exe
C:\Users\xxx & xxx\AppData\Local\Temp\xmlUpdater.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-31 21:06
==================== End Of Log ============================ --- --- ---
--- --- --- |