Hallo Schrauber,
hier die anderen Logfiles: Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 14:48 on 03/07/2014 (Moritz)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-07-2014
Ran by Moritz (administrator) on MO on 03-07-2014 14:50:01
Running from C:\Users\Moritz\Desktop
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(Systweak) C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(COMPANYVERS_NAME) C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65barsvc.exe
(Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Program Files (x86)\NewPlayer\NewPlayerUpdaterService.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Program Files\004\rqpbhevlkc64.exe
() C:\Program Files (x86)\Bizzybolt\updateBizzybolt.exe
() C:\Program Files (x86)\Bizzybolt\bin\utilBizzybolt.exe
() C:\Users\Moritz\AppData\Roaming\VOPackage\VOsrv.exe
(Wajam) C:\Program Files (x86)\Wajam\Updater\WajamUpdaterV3.exe
() C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
() C:\Users\Moritz\AppData\Local\fst_de_70\upfst_de_70.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
( ) C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\AppIntegrator64.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(VER_COMPANY_NAME) C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65brmon.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(VER_COMPANY_NAME) C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65brmon64.exe
() C:\Program Files (x86)\Bench\BService\bservice.exe
() C:\Program Files (x86)\Bench\Wd\wd.exe
() C:\Program Files (x86)\Bench\Proxy\pwdg.exe
() C:\Program Files (x86)\Bench\Proxy\proc.exe
() C:\Program Files (x86)\fst_de_70\fst_de_70.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-09-11] (ASUS)
HKLM\...\Run: [FromDocToPDF Home Page Guard 64 bit] => C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\AppIntegrator64.exe [485448 2014-01-11] ( )
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [3417984 2012-08-28] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [Search Protection] => C:\ProgramData\Search Protection\SearchProtection.exe [944224 2013-06-26] (Visicom Media Inc.)
HKLM-x32\...\Run: [FromDocToPDF EPM Support] => C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65medint.exe [12872 2014-01-11] (Mindspark Interactive Network, Inc.)
HKLM-x32\...\Run: [FromDocToPDF Search Scope Monitor] => C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65SrchMn.exe [55368 2014-01-11] (Mindspark)
HKLM-x32\...\Run: [FromDocToPDF_65 Browser Plugin Loader] => C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65brmon.exe [61512 2014-01-11] (VER_COMPANY_NAME)
HKLM-x32\...\Run: [FromDocToPDF_65 Browser Plugin Loader 64] => C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65brmon64.exe [71752 2014-01-11] (VER_COMPANY_NAME)
HKLM-x32\...\Run: [BService] => C:\Program Files (x86)\Bench\BService\bservice.exe [49664 2014-02-26] ()
HKLM-x32\...\Run: [Wd] => C:\Program Files (x86)\Bench\Wd\wd.exe [60416 2014-02-26] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Bench Communicator Watcher] => C:\Program Files (x86)\Bench\Proxy\pwdg.exe [111616 2014-05-29] ()
HKLM-x32\...\Run: [Bench Settings Cleaner] => C:\Program Files (x86)\Bench\Proxy\cl.exe [55296 2014-05-29] ()
HKLM-x32\...\Run: [fst_de_70] => C:\Program Files (x86)\fst_de_70\fst_de_70.exe [3980280 2014-06-27] ()
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-06-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Runonce: [Coupon Server-repairJob] - wscript.exe "C:\Users\Moritz\AppData\Local\Coupon Server\repair.js" "Coupon Server-repairJob" [X]
HKLM-x32\...\RunOnce: [upfst_de_70.exe] - C:\Users\Moritz\AppData\Local\fst_de_70\upfst_de_70.exe -runonce [3353592 2014-06-27] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2881450208-3143922396-676551458-1002\...\Run: [Google+ Auto Backup] => "C:\Users\Moritz\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart
HKU\S-1-5-21-2881450208-3143922396-676551458-1002\...\MountPoints2: {c9e90845-9f1d-11e3-bec3-0009dd505b2a} - "F:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-2881450208-3143922396-676551458-1002\...\MountPoints2: {c9e9099b-9f1d-11e3-bec3-0009dd505b2a} - "G:\HTC_Sync_Manager_PC.exe"
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found
AppInit_DLLs-x32: c:\progra~2\suptab\search~1.dll => "c:\progra~2\suptab\search~1.dll" File Not Found
Startup: C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3mq3gif.lnk
ShortcutTarget: 3mq3gif.lnk -> C:\PROGRA~3\299219~1\fig3qm3.cpp (No File)
Startup: C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\9170.lnk
ShortcutTarget: 9170.lnk -> 0719.dll,work (No File)
Startup: C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers-x32: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:3128
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1404320361&from=slbnew&uid=HGSTXHTS541075A9E680_J8410076HPUXBDHPUXBDX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1404320361&from=slbnew&uid=HGSTXHTS541075A9E680_J8410076HPUXBDHPUXBDX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1404320361&from=slbnew&uid=HGSTXHTS541075A9E680_J8410076HPUXBDHPUXBDX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1404320361&from=slbnew&uid=HGSTXHTS541075A9E680_J8410076HPUXBDHPUXBDX&q={searchTerms}
URLSearchHook: HKCU - UsProvider Class - {539F76FD-084E-4858-86D5-62F02F54AE86} - C:\Program Files (x86)\Minibar\Minibar.dll (KangoExtensions)
URLSearchHook: HKCU - (No Name) - {4c60e5ab-5c68-4c59-abaa-885010b24b32} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65SrcAs.dll (Mindspark)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1385763946&from=tugs&uid=HGSTXHTS541075A9E680_J8410076HPUXBDHPUXBDX
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - {5a15c091-f3c2-4c8f-8964-e3434a2a4a95} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^ZJ^xpt251^YYA^de&si=begin-download&ptb=34149539-A81E-4B12-A08C-C8B162B52ABD&ind=2013112917&n=77fdaa55&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://www.mystart.com/results.php?gen=ms&pr=vmn&id=mystarttb&v=5_3&ent=ch_4981&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://www.mystart.com/results.php?gen=ms&pr=vmn&id=mystarttb&v=5_3&ent=ch_4981&q={searchTerms}
SearchScopes: HKCU - {5a15c091-f3c2-4c8f-8964-e3434a2a4a95} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^ZJ^xpt251^YYA^de&si=begin-download&ptb=34149539-A81E-4B12-A08C-C8B162B52ABD&ind=2013112917&n=77fdaa55&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p23_serp_ie_de_display?ie=UTF8&tagbase=bds-p23&tag=bds-p23-serp-de-ie-21&tbrId=v1_abb-channel-23_5d24f9ef7d13467fb5df6a45bbe3b118_39_1006_20131119_DE_ie_ds_&query={searchTerms}
BHO: Feven 1.5 - {11111111-1111-1111-1111-110311851132} - C:\Program Files (x86)\Feven 1.5\Feven 1.5-bho64.dll (Feven)
BHO: Plus-HD-4.8 - {11111111-1111-1111-1111-110411591114} - C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-bho64.dll (Plus HD)
BHO: TrustMediaViewerV1alpha4018 - {1e76fe1b-6e01-4eb6-a705-11bcdfc56b57} - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha4018\ie\TrustMediaViewerV1alpha4018x64.dll ()
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Coupon Server BHO - {F791D8AE-47E8-40A5-A913-EB2D2AF29602} - C:\Program Files (x86)\Coupon Server\FrameworkBHO64.dll ()
BHO-x32: CouponDownloader - {10AD2C61-0898-4348-8600-14A342F22AC3} - C:\Program Files (x86)\Coupon Downloader\Coupon Downloader.dll ()
BHO-x32: Feven 1.5 - {11111111-1111-1111-1111-110311851132} - C:\Program Files (x86)\Feven 1.5\Feven 1.5-bho.dll (Feven)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Toolbar BHO - {a235e1e3-6296-4710-af39-104a7faa6c7c} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65bar.dll (Mindspark)
BHO-x32: Wajam - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll (Wajam)
BHO-x32: MinibarBHO - {AA74D58F-ACD0-450D-A85E-6C04B171C044} - C:\Program Files (x86)\Minibar\Minibar.dll (KangoExtensions)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Search Assistant BHO - {f236ca79-3123-4afb-9f74-e98117ad5625} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65SrcAs.dll (Mindspark)
BHO-x32: Coupon Server BHO - {F791D8AE-47E8-40A5-A913-EB2D2AF29602} - C:\Program Files (x86)\Coupon Server\FrameworkBHO.dll ()
Toolbar: HKLM-x32 - FromDocToPDF - {c66a678d-5e6c-4af9-8f57-c6192f42cf74} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65bar.dll (Mindspark)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\z06u780h.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @FromDocToPDF_65.com/Plugin - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\NP65Stub.dll (Mindspark)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Ghostery - C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\z06u780h.default\Extensions\firefox@ghostery.com.xpi [2014-07-02]
FF Extension: Adblock Plus - C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\z06u780h.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-02]
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha290.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha290\ff
FF Extension: Media Player - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha290\ff [2014-01-29]
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewerV1alpha2899.net] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha2899\ff
FF Extension: Media Viewer - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha2899\ff [2014-02-26]
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1852.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1852\ff
FF Extension: Media View - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1852\ff [2014-02-28]
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home163.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home163\ff
FF Extension: Media Watch - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home163\ff [2014-03-23]
FF HKLM-x32\...\Firefox\Extensions: [ext@TrustMediaViewerV1alpha4018.net] - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha4018\ff
FF Extension: Trust Media Viewer - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha4018\ff [2014-06-29]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Plus-HD-4.8) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlnnachibjmjahfpoemhledlpakoicg [2013-12-03]
CHR HKLM-x32\...\Chrome\Extension: [eaddmcgmiegiegohilhikidpjlnlcmjd] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha2899\ch\MediaViewerV1alpha2899.crx [2014-02-23]
CHR HKLM-x32\...\Chrome\Extension: [kimcboogmdekmpejkalfnjgjokhflgkj] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1852\ch\MediaViewV1alpha1852.crx [2014-02-26]
CHR HKLM-x32\...\Chrome\Extension: [kpomaebjdghlefchfleaoibdfabdlkdd] - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha4018\ch\TrustMediaViewerV1alpha4018.crx [2014-06-26]
CHR HKLM-x32\...\Chrome\Extension: [ppekllhafhodajijbbpffgiholmlobjp] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home163\ch\MediaWatchV1home163.crx [2014-03-20]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-24] (Avira Operations GmbH & Co. KG)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2013-11-19] (BitRaider, LLC)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2279608 2014-05-21] (Microsoft Corporation)
R2 FromDocToPDF_65Service; C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65barsvc.exe [88648 2014-01-11] (COMPANYVERS_NAME)
R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-11-10] (Nero AG)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed]
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 NewPlayerUpdaterService; C:\Program Files (x86)\NewPlayer\NewPlayerUpdaterService.exe [11776 2014-04-16] () [File not signed]
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
R2 rqpbhevlkc64; C:\Program Files\004\rqpbhevlkc64.exe [709120 2014-05-30] () [File not signed]
R2 Update Bizzybolt; C:\Program Files (x86)\Bizzybolt\updateBizzybolt.exe [318752 2014-07-02] ()
R2 Util Bizzybolt; C:\Program Files (x86)\Bizzybolt\bin\utilBizzybolt.exe [318752 2014-07-02] ()
R2 vosr; C:\Users\Moritz\AppData\Roaming\VOPackage\VOsrv.exe [55808 2014-05-28] () [File not signed]
R2 WajamUpdaterV3; C:\Program Files (x86)\Wajam\Updater\WajamUpdaterV3.exe [114176 2013-11-11] (Wajam) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S2 Winmgmt; C:\ProgramData\2992199F9A\9170.faa [332532 2014-04-24] (Microsoft Corporation) [File not signed]
S2 64af91bf; "C:\Windows\system32\rundll32.exe" "c:\progra~3\fastan~1\FastAndSafeSvc.dll",service
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [X]
==================== Drivers (Whitelisted) ====================
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-24] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-06-24] (Avira Operations GmbH & Co. KG)
S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2013-11-19] (BitRaider)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
S3 BTHprint; C:\Windows\system32\DRIVERS\bthprint.sys [61952 2012-07-26] (Microsoft Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R1 nethfdrv; C:\Windows\system32\drivers\nethfdrv.sys [46160 2014-06-20] (nethfdrv)
R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61120 2014-03-23] (StdLib)
U0 msahci;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-03 14:50 - 2014-07-03 14:50 - 00026996 _____ () C:\Users\Moritz\Desktop\FRST.txt
2014-07-03 14:48 - 2014-07-03 14:48 - 00000474 _____ () C:\Users\Moritz\Desktop\defogger_disable.log
2014-07-03 01:45 - 2014-07-03 01:45 - 00007235 _____ () C:\Users\Moritz\Desktop\Gmer.txt
2014-07-03 01:04 - 2014-07-03 01:04 - 00380416 _____ () C:\Users\Moritz\Desktop\Gmer-19357.exe
2014-07-03 00:59 - 2014-07-03 00:59 - 00003072 _____ () C:\Windows\System32\Tasks\{CF41D0D1-DF62-4E47-AADA-0C345C908F4C}
2014-07-03 00:44 - 2014-07-03 03:02 - 00001088 _____ () C:\Users\Moritz\Desktop\Continue VuuPC Installation.lnk
2014-07-03 00:11 - 2014-07-03 14:50 - 00000000 ____D () C:\FRST
2014-07-03 00:10 - 2014-07-03 00:10 - 02083840 _____ (Farbar) C:\Users\Moritz\Desktop\FRST64.exe
2014-07-03 00:05 - 2014-07-03 00:05 - 00000000 _____ () C:\Users\Moritz\defogger_reenable
2014-07-03 00:04 - 2014-07-03 00:04 - 00050477 _____ () C:\Users\Moritz\Desktop\Defogger.exe
2014-07-02 23:52 - 2014-07-03 14:33 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-02 23:52 - 2014-07-02 23:52 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-02 23:52 - 2014-07-02 23:52 - 00000000 ____D () C:\Users\Moritz\AppData\Local\Macromedia
2014-07-02 23:03 - 2014-07-02 23:03 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\Avira
2014-07-02 22:58 - 2014-07-02 22:58 - 00002068 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-07-02 22:58 - 2014-07-02 22:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-07-02 22:58 - 2014-07-02 22:58 - 00000000 ____D () C:\ProgramData\Avira
2014-07-02 22:58 - 2014-07-02 22:58 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-07-02 22:58 - 2014-06-24 20:39 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-07-02 22:58 - 2014-06-24 20:39 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-07-02 22:58 - 2014-06-24 20:39 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-07-02 22:57 - 2014-07-02 22:57 - 00000000 ____D () C:\Users\Moritz\Downloads\avira_free_antivirus45_de
2014-07-02 22:52 - 2014-07-02 22:52 - 00887896 _____ (Microsoft Corporation) C:\Users\Moritz\Downloads\dotNetFx40_Client_setup.exe
2014-07-02 21:34 - 2014-07-02 21:36 - 141865920 _____ () C:\Users\Moritz\Downloads\avira_free_antivirus45_de.exe
2014-07-02 21:15 - 2014-07-02 21:15 - 00001161 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-07-02 21:15 - 2014-07-02 21:15 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-07-02 21:15 - 2014-07-02 21:15 - 00000000 ____D () C:\Users\Moritz\AppData\Local\Mozilla
2014-07-02 21:15 - 2014-07-02 21:15 - 00000000 ____D () C:\ProgramData\Mozilla
2014-07-02 21:15 - 2014-07-02 21:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-02 21:13 - 2014-07-02 21:13 - 29677544 _____ (Mozilla) C:\Users\Moritz\Downloads\Firefox_Setup_de30.0.exe
2014-07-02 20:12 - 2014-07-02 20:12 - 00000000 ____D () C:\Program Files (x86)\SemuaRtCoMMppAurE
2014-07-02 19:03 - 2014-07-02 20:18 - 00000000 ____D () C:\ProgramData\SemuaRtCoMMppAurE
2014-07-02 18:59 - 2014-07-02 23:06 - 00000000 ____D () C:\Program Files\003
2014-07-02 18:59 - 2014-07-02 20:13 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-07-02 18:59 - 2014-07-02 19:22 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-07-02 18:59 - 2014-07-02 19:00 - 102323272 _____ () C:\Users\Moritz\Desktop\avira.exe
2014-07-02 18:59 - 2014-07-02 19:00 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-07-02 18:53 - 2014-07-02 18:53 - 00421280 _____ (Setup Process) C:\Users\Moritz\Downloads\AviraAntiVirus.exe
2014-07-02 18:39 - 2014-07-02 18:39 - 00000099 _____ () C:\Windows\Reimage.ini
2014-07-02 18:28 - 2014-07-02 18:28 - 00533642 _____ () C:\Users\Moritz\Desktop\DAS MEERSCHWEINCHEN.pptx
2014-07-02 18:27 - 2014-07-02 18:27 - 01114682 _____ () C:\Users\Moritz\Desktop\DER HOMERISMUS.pptx
2014-07-02 18:26 - 2014-07-02 23:06 - 00000000 ____D () C:\ProgramData\Fast And Safe
2014-07-02 18:25 - 2014-07-02 20:26 - 00000000 ____D () C:\ProgramData\374311380
2014-06-30 21:03 - 2014-06-30 21:03 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\Der Planer 4
2014-06-30 21:01 - 2014-06-30 21:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Der Planer 4
2014-06-29 21:31 - 2014-06-30 21:00 - 00000000 ____D () C:\Program Files (x86)\Der Planer 4
2014-06-29 20:49 - 2014-06-29 20:49 - 00000000 ____D () C:\Program Files (x86)\TrustMediaViewerV1
2014-06-27 21:12 - 2014-06-29 21:29 - 00000000 ____D () C:\Program Files\CouponDownloader
2014-06-27 19:28 - 2014-07-03 12:06 - 00000000 ____D () C:\Users\Moritz\AppData\Local\fst_de_70
2014-06-27 19:28 - 2014-07-02 18:38 - 00000000 ____D () C:\Program Files (x86)\fst_de_70
2014-06-27 19:28 - 2014-06-27 19:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FREE_SOFTTODAY
2014-06-24 20:52 - 2014-06-24 20:52 - 00000000 ____D () C:\Users\Moritz\AppData\Local\SWTOR
2014-06-23 20:56 - 2014-06-23 20:56 - 00000000 ____D () C:\Users\Moritz\Documents\OneNote-Notizbücher
2014-06-23 20:49 - 2014-07-02 19:03 - 00000000 ____D () C:\ProgramData\bf0432fc5b56746a
2014-06-23 20:36 - 2014-06-23 20:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-06-20 14:21 - 2014-06-20 14:21 - 00180224 _____ () C:\Windows\SysWOW64\nethtsrv.exe
2014-06-20 14:21 - 2014-06-20 14:21 - 00161792 _____ () C:\Windows\SysWOW64\netupdsrv.exe
2014-06-20 14:21 - 2014-06-20 14:21 - 00111104 _____ () C:\Windows\SysWOW64\installd.exe
2014-06-20 14:21 - 2014-06-20 14:21 - 00046160 _____ (nethfdrv) C:\Windows\system32\Drivers\nethfdrv.sys
2014-06-20 14:20 - 2014-06-20 14:20 - 00249856 _____ () C:\Windows\SysWOW64\hfpapi.dll
2014-06-15 15:42 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-15 15:42 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-06-15 15:42 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-15 15:42 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-06-15 15:42 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-06-15 15:42 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-15 15:42 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml
2014-06-15 15:42 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-06-15 15:42 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-06-15 15:41 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-15 15:41 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-15 15:41 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-15 15:41 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-06-15 15:41 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-15 15:41 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-15 15:41 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-15 15:41 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-15 15:41 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-15 15:41 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-15 15:41 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-15 15:41 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-15 15:41 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-15 15:41 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-15 15:41 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-15 15:41 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-06-15 15:41 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-15 15:41 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-15 15:41 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-15 15:41 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-15 15:41 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-15 15:41 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-15 15:41 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-15 15:41 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-15 15:41 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-15 15:41 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-15 15:41 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-15 15:41 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-15 15:41 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-15 15:41 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-06-15 15:41 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-15 15:41 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-15 15:41 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-14 16:33 - 2014-06-24 08:47 - 00387199 _____ () C:\Users\Moritz\Desktop\Christoph Kolumbus.pptx
2014-06-14 14:40 - 2014-06-15 16:15 - 00000000 ____D () C:\Users\Moritz\Desktop\Bilder für Kolumbus Referat
2014-06-11 14:34 - 2014-06-11 14:34 - 00003026 _____ () C:\Windows\System32\Tasks\{C02985F3-088A-43E5-B974-FB0C416F0891}
2014-06-11 13:54 - 2014-06-11 13:54 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\Opera Software
2014-06-11 13:54 - 2014-06-11 13:54 - 00000000 ____D () C:\Users\Moritz\AppData\Local\Opera Software
2014-06-11 13:50 - 2014-07-02 18:41 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-11 13:50 - 2014-06-25 15:28 - 00003838 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1402487439
2014-06-11 13:50 - 2014-06-11 13:50 - 00001137 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk.1404319265.old
2014-06-11 13:01 - 2014-06-11 13:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2014-06-11 12:58 - 2014-06-11 12:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
==================== One Month Modified Files and Folders =======
2014-07-03 14:50 - 2014-07-03 14:50 - 00026996 _____ () C:\Users\Moritz\Desktop\FRST.txt
2014-07-03 14:50 - 2014-07-03 00:11 - 00000000 ____D () C:\FRST
2014-07-03 14:48 - 2014-07-03 14:48 - 00000474 _____ () C:\Users\Moritz\Desktop\defogger_disable.log
2014-07-03 14:33 - 2014-07-02 23:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-03 14:31 - 2013-11-19 23:40 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\Systweak
2014-07-03 14:28 - 2014-01-13 00:39 - 00000352 _____ () C:\Windows\Tasks\bench-S-1-5-21-2881450208-3143922396-676551458-1002.job
2014-07-03 14:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-07-03 12:06 - 2014-06-27 19:28 - 00000000 ____D () C:\Users\Moritz\AppData\Local\fst_de_70
2014-07-03 11:35 - 2014-01-13 00:39 - 00000352 _____ () C:\Windows\Tasks\bench-sys.job
2014-07-03 11:26 - 2013-11-30 00:26 - 00001292 _____ () C:\Windows\Tasks\Feven 1.5-updater.job
2014-07-03 11:26 - 2013-11-30 00:26 - 00001194 _____ () C:\Windows\Tasks\Feven 1.5-codedownloader.job
2014-07-03 11:26 - 2013-11-30 00:26 - 00001094 _____ () C:\Windows\Tasks\Feven 1.5-enabler.job
2014-07-03 11:21 - 2012-12-29 00:00 - 01081994 _____ () C:\Windows\WindowsUpdate.log
2014-07-03 11:19 - 2013-11-30 00:19 - 00001304 _____ () C:\Windows\Tasks\Plus-HD-4.8-updater.job
2014-07-03 11:19 - 2013-11-30 00:19 - 00001206 _____ () C:\Windows\Tasks\Plus-HD-4.8-codedownloader.job
2014-07-03 11:19 - 2013-11-30 00:19 - 00001106 _____ () C:\Windows\Tasks\Plus-HD-4.8-enabler.job
2014-07-03 11:18 - 2013-11-30 00:18 - 00001912 _____ () C:\Windows\Tasks\Plus-HD-4.8-chromeinstaller.job
2014-07-03 03:46 - 2013-11-30 00:25 - 00000000 ____D () C:\Program Files (x86)\Feven 1.5
2014-07-03 03:46 - 2013-11-30 00:18 - 00000000 ____D () C:\Program Files (x86)\Plus-HD-4.8
2014-07-03 03:02 - 2014-07-03 00:44 - 00001088 _____ () C:\Users\Moritz\Desktop\Continue VuuPC Installation.lnk
2014-07-03 02:32 - 2013-02-08 11:49 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2881450208-3143922396-676551458-1002
2014-07-03 02:08 - 2013-11-19 23:44 - 00003120 _____ () C:\Windows\System32\Tasks\Advanced System Protector_startup
2014-07-03 02:07 - 2014-05-30 14:33 - 00000003 _____ () C:\Users\Moritz\AppData\Local\proxy.log
2014-07-03 02:07 - 2013-02-07 18:48 - 00000408 _____ () C:\Users\Moritz\AppData\Roaming\sp_data.sys
2014-07-03 02:06 - 2014-03-23 14:12 - 00000000 ____D () C:\Users\Moritz\AppData\Local\HTC MediaHub
2014-07-03 02:06 - 2014-01-09 11:57 - 00000360 _____ () C:\Windows\Tasks\AmiUpdXp.job
2014-07-03 02:06 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-03 01:45 - 2014-07-03 01:45 - 00007235 _____ () C:\Users\Moritz\Desktop\Gmer.txt
2014-07-03 01:10 - 2012-08-02 15:24 - 00035846 _____ () C:\Windows\PFRO.log
2014-07-03 01:04 - 2014-07-03 01:04 - 00380416 _____ () C:\Users\Moritz\Desktop\Gmer-19357.exe
2014-07-03 00:59 - 2014-07-03 00:59 - 00003072 _____ () C:\Windows\System32\Tasks\{CF41D0D1-DF62-4E47-AADA-0C345C908F4C}
2014-07-03 00:10 - 2014-07-03 00:10 - 02083840 _____ (Farbar) C:\Users\Moritz\Desktop\FRST64.exe
2014-07-03 00:05 - 2014-07-03 00:05 - 00000000 _____ () C:\Users\Moritz\defogger_reenable
2014-07-03 00:05 - 2013-02-07 18:44 - 00000000 ____D () C:\Users\Moritz
2014-07-03 00:04 - 2014-07-03 00:04 - 00050477 _____ () C:\Users\Moritz\Desktop\Defogger.exe
2014-07-02 23:52 - 2014-07-02 23:52 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-02 23:52 - 2014-07-02 23:52 - 00000000 ____D () C:\Users\Moritz\AppData\Local\Macromedia
2014-07-02 23:06 - 2014-07-02 18:59 - 00000000 ____D () C:\Program Files\003
2014-07-02 23:06 - 2014-07-02 18:26 - 00000000 ____D () C:\ProgramData\Fast And Safe
2014-07-02 23:06 - 2014-04-24 13:13 - 00000000 ____D () C:\ProgramData\2992199F9A
2014-07-02 23:03 - 2014-07-02 23:03 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\Avira
2014-07-02 22:58 - 2014-07-02 22:58 - 00002068 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-07-02 22:58 - 2014-07-02 22:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-07-02 22:58 - 2014-07-02 22:58 - 00000000 ____D () C:\ProgramData\Avira
2014-07-02 22:58 - 2014-07-02 22:58 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-07-02 22:57 - 2014-07-02 22:57 - 00000000 ____D () C:\Users\Moritz\Downloads\avira_free_antivirus45_de
2014-07-02 22:52 - 2014-07-02 22:52 - 00887896 _____ (Microsoft Corporation) C:\Users\Moritz\Downloads\dotNetFx40_Client_setup.exe
2014-07-02 22:00 - 2013-07-06 14:55 - 00117248 ___SH () C:\Users\Moritz\Desktop\Thumbs.db
2014-07-02 21:36 - 2014-07-02 21:34 - 141865920 _____ () C:\Users\Moritz\Downloads\avira_free_antivirus45_de.exe
2014-07-02 21:15 - 2014-07-02 21:15 - 00001161 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-07-02 21:15 - 2014-07-02 21:15 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-07-02 21:15 - 2014-07-02 21:15 - 00000000 ____D () C:\Users\Moritz\AppData\Local\Mozilla
2014-07-02 21:15 - 2014-07-02 21:15 - 00000000 ____D () C:\ProgramData\Mozilla
2014-07-02 21:15 - 2014-07-02 21:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-02 21:15 - 2014-05-30 15:18 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\Mozilla
2014-07-02 21:14 - 2013-11-30 00:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-02 21:13 - 2014-07-02 21:13 - 29677544 _____ (Mozilla) C:\Users\Moritz\Downloads\Firefox_Setup_de30.0.exe
2014-07-02 20:26 - 2014-07-02 18:25 - 00000000 ____D () C:\ProgramData\374311380
2014-07-02 20:21 - 2014-01-29 17:04 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-07-02 20:18 - 2014-07-02 19:03 - 00000000 ____D () C:\ProgramData\SemuaRtCoMMppAurE
2014-07-02 20:13 - 2014-07-02 18:59 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-07-02 20:12 - 2014-07-02 20:12 - 00000000 ____D () C:\Program Files (x86)\SemuaRtCoMMppAurE
2014-07-02 19:22 - 2014-07-02 18:59 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-07-02 19:22 - 2013-02-07 18:46 - 00001440 _____ () C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-02 19:10 - 2012-12-28 23:58 - 00000000 ____D () C:\ProgramData\Temp
2014-07-02 19:03 - 2014-06-23 20:49 - 00000000 ____D () C:\ProgramData\bf0432fc5b56746a
2014-07-02 19:00 - 2014-07-02 18:59 - 102323272 _____ () C:\Users\Moritz\Desktop\avira.exe
2014-07-02 19:00 - 2014-07-02 18:59 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-07-02 18:53 - 2014-07-02 18:53 - 00421280 _____ (Setup Process) C:\Users\Moritz\Downloads\AviraAntiVirus.exe
2014-07-02 18:41 - 2014-06-11 13:50 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-07-02 18:39 - 2014-07-02 18:39 - 00000099 _____ () C:\Windows\Reimage.ini
2014-07-02 18:38 - 2014-06-27 19:28 - 00000000 ____D () C:\Program Files (x86)\fst_de_70
2014-07-02 18:33 - 2014-01-30 18:20 - 00000000 ____D () C:\Users\Moritz\Desktop\BILDER
2014-07-02 18:31 - 2014-04-24 14:44 - 00000000 ____D () C:\Users\Moritz\Desktop\Schule
2014-07-02 18:28 - 2014-07-02 18:28 - 00533642 _____ () C:\Users\Moritz\Desktop\DAS MEERSCHWEINCHEN.pptx
2014-07-02 18:27 - 2014-07-02 18:27 - 01114682 _____ () C:\Users\Moritz\Desktop\DER HOMERISMUS.pptx
2014-07-02 18:25 - 2014-05-30 15:17 - 00000000 ____D () C:\Program Files (x86)\PC Speed Maximizer
2014-07-02 18:21 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-07-02 18:15 - 2014-01-30 18:21 - 00000000 ____D () C:\Users\Moritz\Desktop\Spiele
2014-06-30 21:03 - 2014-06-30 21:03 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\Der Planer 4
2014-06-30 21:01 - 2014-06-30 21:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Der Planer 4
2014-06-30 21:00 - 2014-06-29 21:31 - 00000000 ____D () C:\Program Files (x86)\Der Planer 4
2014-06-29 21:29 - 2014-06-27 21:12 - 00000000 ____D () C:\Program Files\CouponDownloader
2014-06-29 20:49 - 2014-06-29 20:49 - 00000000 ____D () C:\Program Files (x86)\TrustMediaViewerV1
2014-06-29 20:49 - 2014-01-29 17:05 - 00000393 _____ () C:\extensions.ini
2014-06-27 20:46 - 2012-07-26 09:21 - 00060049 _____ () C:\Windows\setupact.log
2014-06-27 19:28 - 2014-06-27 19:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FREE_SOFTTODAY
2014-06-25 15:34 - 2014-05-28 19:51 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
2014-06-25 15:28 - 2014-06-11 13:50 - 00003838 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1402487439
2014-06-24 21:40 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-06-24 20:52 - 2014-06-24 20:52 - 00000000 ____D () C:\Users\Moritz\AppData\Local\SWTOR
2014-06-24 20:39 - 2014-07-02 22:58 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-24 20:39 - 2014-07-02 22:58 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-24 20:39 - 2014-07-02 22:58 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-06-24 20:20 - 2013-11-19 22:22 - 00000000 ____D () C:\ProgramData\BitRaider
2014-06-24 08:47 - 2014-06-14 16:33 - 00387199 _____ () C:\Users\Moritz\Desktop\Christoph Kolumbus.pptx
2014-06-23 20:56 - 2014-06-23 20:56 - 00000000 ____D () C:\Users\Moritz\Documents\OneNote-Notizbücher
2014-06-23 20:53 - 2014-02-01 20:10 - 00003769 _____ () C:\Users\Moritz\Desktop\HOTEL.ods
2014-06-23 20:36 - 2014-06-23 20:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-06-23 20:36 - 2013-12-19 22:24 - 00000000 _____ () C:\END
2014-06-23 20:36 - 2013-11-19 22:12 - 00014213 _____ () C:\Users\Moritz\Documents\Install STAR WARS The Old Republic.log
2014-06-21 14:19 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-06-20 17:01 - 2013-08-20 17:49 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-20 14:21 - 2014-06-20 14:21 - 00180224 _____ () C:\Windows\SysWOW64\nethtsrv.exe
2014-06-20 14:21 - 2014-06-20 14:21 - 00161792 _____ () C:\Windows\SysWOW64\netupdsrv.exe
2014-06-20 14:21 - 2014-06-20 14:21 - 00111104 _____ () C:\Windows\SysWOW64\installd.exe
2014-06-20 14:21 - 2014-06-20 14:21 - 00046160 _____ (nethfdrv) C:\Windows\system32\Drivers\nethfdrv.sys
2014-06-20 14:21 - 2013-03-16 15:19 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-20 14:20 - 2014-06-20 14:20 - 00249856 _____ () C:\Windows\SysWOW64\hfpapi.dll
2014-06-15 17:38 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-15 16:15 - 2014-06-14 14:40 - 00000000 ____D () C:\Users\Moritz\Desktop\Bilder für Kolumbus Referat
2014-06-15 13:57 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-06-15 13:57 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-15 13:57 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-15 13:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-06-15 13:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-06-15 13:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-06-14 16:08 - 2013-02-07 18:44 - 00000000 ____D () C:\Users\Moritz\AppData\Local\Packages
2014-06-12 12:58 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-06-11 15:24 - 2013-11-19 23:43 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2014-06-11 14:34 - 2014-06-11 14:34 - 00003026 _____ () C:\Windows\System32\Tasks\{C02985F3-088A-43E5-B974-FB0C416F0891}
2014-06-11 14:30 - 2013-02-08 12:10 - 00000000 ____D () C:\Users\Moritz\Documents\My Games
2014-06-11 13:54 - 2014-06-11 13:54 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\Opera Software
2014-06-11 13:54 - 2014-06-11 13:54 - 00000000 ____D () C:\Users\Moritz\AppData\Local\Opera Software
2014-06-11 13:50 - 2014-06-11 13:50 - 00001137 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk.1404319265.old
2014-06-11 13:08 - 2013-10-28 15:21 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-06-11 13:01 - 2014-06-11 13:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2014-06-11 12:58 - 2014-06-11 12:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\Users\Public\AlexaNSISPlugin.796.dll
Some content of TEMP:
====================
C:\Users\Moritz\AppData\Local\Temp\adgwsukbgauoppf.exe
C:\Users\Moritz\AppData\Local\Temp\AutoRun.exe
C:\Users\Moritz\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Moritz\AppData\Local\Temp\avgnt.exe
C:\Users\Moritz\AppData\Local\Temp\BackupSetup.exe
C:\Users\Moritz\AppData\Local\Temp\COMAP.EXE
C:\Users\Moritz\AppData\Local\Temp\dlLogic.exe
C:\Users\Moritz\AppData\Local\Temp\drm_dyndata_7270006.dll
C:\Users\Moritz\AppData\Local\Temp\drm_dyndata_7400006.dll
C:\Users\Moritz\AppData\Local\Temp\drm_dyndata_7400008.dll
C:\Users\Moritz\AppData\Local\Temp\EBUFA0C.exe
C:\Users\Moritz\AppData\Local\Temp\EBUFB64.DLL
C:\Users\Moritz\AppData\Local\Temp\EnableExtDll.dll
C:\Users\Moritz\AppData\Local\Temp\f.exe
C:\Users\Moritz\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Moritz\AppData\Local\Temp\instract.exe
C:\Users\Moritz\AppData\Local\Temp\NewPlayerUpdater.exe
C:\Users\Moritz\AppData\Local\Temp\nsf6B1B.tmp.exe
C:\Users\Moritz\AppData\Local\Temp\OfficeSetup.exe
C:\Users\Moritz\AppData\Local\Temp\optprosetup.exe
C:\Users\Moritz\AppData\Local\Temp\rnsetup0.exe
C:\Users\Moritz\AppData\Local\Temp\sblomktupjpbv.exe
C:\Users\Moritz\AppData\Local\Temp\setupproplusretail.x86.de-de_act_1_.exe
C:\Users\Moritz\AppData\Local\Temp\speedupmypc.exe
C:\Users\Moritz\AppData\Local\Temp\sqlite3.exe
C:\Users\Moritz\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Moritz\AppData\Local\Temp\VP6Install.exe
C:\Users\Moritz\AppData\Local\Temp\VP6VFW.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-03 11:18
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-07-2014
Ran by Moritz at 2014-07-03 14:50:38
Running from C:\Users\Moritz\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
==================== Installed Programs ======================
18 WoS Across America (HKLM-x32\...\InstallShield_{BF9BA346-27AA-4EE0-8333-FEA5400D2AA0}) (Version: 0.2.0000 - ValuSoft)
18 WoS Across America (x32 Version: 0.2.0000 - ValuSoft) Hidden
18 WoS: Voll aufs Gas (HKLM-x32\...\{39286675-3166-9420-2336-779493021964}) (Version: 1.0 - rondomedia)
Abschleppwagen-Simulator 2010 Version 1.3 (HKLM-x32\...\Abschleppwagen-Simulator 2010_is1) (Version: 1.3 - astragon Software GmbH)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.125 - Adobe Systems Incorporated)
Adobe Reader X (10.1.1) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.1 - Adobe Systems Incorporated)
Advanced System Protector (HKLM-x32\...\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1) (Version: 2.1.1000.12150 - Systweak Software) <==== ATTENTION
Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.8 - ASUS)
ASUS InstantOn (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 3.0.4 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.9 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.9 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 2.0.4 - ASUS)
ASUS Product Demo Movie (HKLM-x32\...\{DC06C90B-C5BE-42F6-B74D-A9503170998C}) (Version: 1.0.3 - ASUS )
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 1.0.35 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0005 - ASUS)
ASUS Tutor (HKLM-x32\...\{58172D66-2F69-4215-9AEC-ED8196023736}) (Version: 1.0.7 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.5 - ASUS)
ASUS WebStorage Sync Agent (HKLM-x32\...\ASUS WebStorage) (Version: 1.1.9.120 - ASUS Cloud Corporation)
ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4126.52 - CyberLink Corp.)
ASUSDVD (x32 Version: 10.0.4126.52 - CyberLink Corp.) Hidden
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0025 - ASUS)
Austrian Truck Simulator 1.31 (HKLM-x32\...\German Truck Simulator) (Version: 1.31 - SCS Software)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.5.450 - Avira)
BitRaider Web Client (HKLM-x32\...\BitRaider Web Client) (Version: 1.1.9.9 - BitRaider, LLC)
Bizzybolt (HKLM\...\Bizzybolt) (Version: 2013.11.20.184610 - Bizzybolt) <==== ATTENTION
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Coupon Server (HKLM-x32\...\35852_Coupon Server) (Version: 1.1 - Exciting Apps) <==== ATTENTION
Der Planer 4 Version 1.3 (HKLM-x32\...\{BA9E9ED5-FFF3-4E0D-95B9-62527672268B}_is1) (Version: - rondomedia Marketing & Vertriebs GmbH)
Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version: - )
Die Sims 2: Wilde Campus-Jahre (HKLM-x32\...\{01521746-02A6-4A72-00BD-A285DF6B80C6}) (Version: - )
Die Sims™ 2 (HKLM-x32\...\{2C82E097-694E-44ea-A947-2750679469CF}) (Version: - Electronic Arts)
Die Sims™ 2 Haustiere (HKLM-x32\...\{4817189D-1785-4627-A33C-39FD90919300}) (Version: - )
Fast And Safe (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{64af91bf}) (Version: - GTgroup) <==== ATTENTION
Feven 1.5 (HKLM-x32\...\Feven 1.5) (Version: 1.31.153.0 - Feven) <==== ATTENTION
FilesFrog Update Checker (HKLM-x32\...\FilesFrog Update Checker) (Version: - ) <==== ATTENTION
FromDocToPDF Internet Explorer Toolbar (HKLM-x32\...\FromDocToPDF_65bar Uninstall Internet Explorer) (Version: - Mindspark Interactive Network) <==== ATTENTION
fst_de_70 (HKLM-x32\...\fst_de_70_is1) (Version: - FREE_SOFTTODAY) <==== ATTENTION
Geländewagen-Simulator 2012 (Nur entfernen) (HKLM-x32\...\{50747054-5F94-4BBC-B189-4D3F4D22C094}_is1) (Version: 1.1.1.0 - Rondomedia Marketing & Vertriebs GmbH)
HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.10.0.001 - HTC Corporation)
HTC Sync Manager (HKLM-x32\...\{368E4EF8-E840-40EE-A224-50B8D1DC2B12}) (Version: 2.4.36.0 - HTC)
Installer (HKLM-x32\...\VOPackage) (Version: 1.0.0.0 - ) <==== ATTENTION
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2828 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.8 - HTC)
Java 7 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.5 - Sun Microsystems, Inc.) Hidden
Landwirtschafts Simulator 2011 (HKLM-x32\...\FarmingSimulator2011DE_is1) (Version: 1.0 - GIANTS Software)
LEGO® Star Wars™: Die Komplette Saga (HKLM-x32\...\InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}) (Version: 1.00.0000 - LucasArts)
LEGO® Star Wars™: The Complete Saga (x32 Version: 1.00.0000 - LucasArts) Hidden
Mathica (HKLM-x32\...\{511C626A-66BB-4E4D-8A23-5E8D52B8FA32}) (Version: 1.00.0000 - BrainGame Publishing GmbH)
Media Player (HKLM-x32\...\MediaPlayerV1alpha290) (Version: 1.1 - Media Player) <==== ATTENTION
Media View (HKLM-x32\...\MediaViewV1alpha1852) (Version: 1.1 - Media View) <==== ATTENTION
Media Viewer (HKLM-x32\...\MediaViewerV1alpha2899) (Version: 1.1 - Media Viewer) <==== ATTENTION
Media Watch (HKLM-x32\...\MediaWatchV1home163) (Version: 1.1 - Media Watch) <==== ATTENTION
Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 15.0.4623.1003 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Zoo Tycoon (HKLM-x32\...\Zoo Tycoon 1.0) (Version: - )
Minecraft PC Gamer Demo version 1.5 (HKLM-x32\...\{55D65D27-C0CD-4375-9021-F3D3D024ED90}_is1) (Version: 1.5 - Mojang)
Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
Network System Driver (HKLM-x32\...\inethnfd) (Version: 1.0.0.3001 - ) <==== ATTENTION
NewPlayer (HKLM-x32\...\NewPlayer) (Version: v2.1.1.7 - ) <==== ATTENTION
NVIDIA Grafiktreiber 306.97 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.97 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.85.551 - NVIDIA Corporation) Hidden
NVIDIA Optimus 1.10.8 (Version: 1.10.8 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.12.0613 - NVIDIA Corporation) Hidden
NVIDIA PhysX System Software 9.12.0613 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0613 - NVIDIA Corporation)
NVIDIA Systemsteuerung 306.97 (Version: 306.97 - NVIDIA Corporation) Hidden
NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.10.8 - NVIDIA Corporation) Hidden
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4623.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4623.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4623.1003 - Microsoft Corporation) Hidden
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Plus-HD-4.8 (HKLM-x32\...\Plus-HD-4.8) (Version: 1.30.153.0 - Plus HD) <==== ATTENTION
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6685 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.27024 - Realtek Semiconductor Corp.)
RS2 (HKLM-x32\...\RS2) (Version: - )
Schiff-Simulator 2008 (HKLM-x32\...\Shipsim2008) (Version: - )
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Software Version Updater (HKLM-x32\...\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}) (Version: 1.1.3.8 - ) <==== ATTENTION
Spezialfahrzeuge-Simulator Version 1.45 (HKLM-x32\...\Spezialfahrzeuge-Simulator_is1) (Version: 1.45 - astragon Software GmbH)
Star Wars Battlefront II (HKLM-x32\...\{3D374523-CFDE-461A-827E-2A102E2AB365}) (Version: 1.0 - LucasArts)
Star Wars Empire at War (HKLM-x32\...\{99AE7207-8612-4DBA-A8F8-BAE5C633390D}) (Version: 1.0 - LucasArts)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: 7.0.0.45 - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Trust Media Viewer (HKLM-x32\...\TrustMediaViewerV1alpha4018) (Version: 1.1 - Trust Media Viewer) <==== ATTENTION
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
UK Truck Simulator 1.11 (HKLM-x32\...\UK Truck Simulator) (Version: 1.11 - )
VirtualRides - Der Fahrgeschäftsimulator Version 1.0 (HKLM-x32\...\{A29906AD-C03C-4A1A-9D88-1B77EA561B25}_is1) (Version: 1.0 - VirtualRides Developement Team)
VuuPC Packages (HKCU\...\VuuPC Packages) (Version: - ) <==== ATTENTION
Wajam (HKLM-x32\...\Wajam) (Version: 2.05 - Wajam) <==== ATTENTION
Werksfeuerwehr-Simulator Version 1.0 (HKLM-x32\...\{AB244A3D-59DF-4D43-8497-D33644A0486C}_is1) (Version: - rondomedia Marketing & Vertriebs GmbH)
Windows Driver Package - ASUS (ATP) Mouse (10/29/2012 1.0.0.148) (HKLM\...\C01F56FBD9B141017E63E2A1A141E59934D4DC67) (Version: 10/29/2012 1.0.0.148 - ASUS)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.1 - ASUS)
WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net)
==================== Restore Points =========================
Could not list Restore Points. Check "winmgmt" service or repair WMI.
==================== Hosts content: ==========================
2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {1DD193D8-5F8C-44D5-8F38-08359E27EF9A} - System32\Tasks\Plus-HD-4.8-chromeinstaller => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-chromeinstaller.exe <==== ATTENTION
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {25E8735C-1890-40A1-80D5-01FA8D4BC81B} - System32\Tasks\Plus-HD-4.8-updater => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-updater.exe [2013-11-30] (Plus HD) <==== ATTENTION
Task: {2751D5A3-B943-4ACB-843C-8206348915AF} - System32\Tasks\Plus-HD-4.8-codedownloader => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-codedownloader.exe <==== ATTENTION
Task: {29543673-F749-4038-A689-95585AC52075} - System32\Tasks\Opera scheduled Autoupdate 1402487439 => C:\Program Files (x86)\Opera\launcher.exe [2014-06-16] (Opera Software)
Task: {2EFB3F47-4982-4B75-BBF9-552F8D408943} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.)
Task: {3270D3D8-3236-47C2-94DA-82F13A0326B3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-06-11] (Microsoft Corporation)
Task: {3513C992-3A9B-4616-B72F-32B9C7036D88} - System32\Tasks\Feven 1.5-enabler => C:\Program Files (x86)\Feven 1.5\Feven 1.5-enabler.exe <==== ATTENTION
Task: {39BA4E32-F32E-445C-A003-5B1F55412736} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe [2013-10-04] (Systweak) <==== ATTENTION
Task: {3DADC4F8-30E7-4C67-B7C7-DB653BA99BB3} - System32\Tasks\ASUS InstantOn Config => C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [2012-09-24] (ASUS)
Task: {402E38C8-13D4-48E7-B0DF-DC1E9322751D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-02] (Adobe Systems Incorporated)
Task: {56ED2B7B-AC4D-4F83-8EEE-1B623575DC5C} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-05-13] (Microsoft Corporation)
Task: {680BF8FD-6D95-4074-BCE1-6119C458AA89} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\updater.exe [2014-01-10] () <==== ATTENTION
Task: {6F89F713-A676-4942-A5CA-2885E38F9ED5} - System32\Tasks\Plus-HD-4.8-enabler => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-enabler.exe [2013-11-30] (Plus HD) <==== ATTENTION
Task: {878BD489-99B1-4B2E-8BFF-6F3A9CBABD62} - System32\Tasks\Feven 1.5-codedownloader => C:\Program Files (x86)\Feven 1.5\Feven 1.5-codedownloader.exe [2013-11-30] (Feven) <==== ATTENTION
Task: {A44DFBB5-9770-47D8-8736-98C5A2C5B273} - System32\Tasks\Feven 1.5-updater => C:\Program Files (x86)\Feven 1.5\Feven 1.5-updater.exe <==== ATTENTION
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {BFE36E1C-30E4-4DEC-BE68-19BD84947529} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-24] (ASUS)
Task: {C42D28D7-DDB3-497C-9DF1-B8F1ECA5BB86} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-06-20] (Microsoft Corporation)
Task: {C4901444-395E-409B-8C89-B5ABF3F39BE2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-06-11] (Microsoft Corporation)
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {CF28F8B8-69CC-4122-9CB4-CC117C3E5E99} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2012-10-31] (AsusTek)
Task: {E3E5A673-8003-4C24-8A79-C5D3654B0BAC} - System32\Tasks\bench-S-1-5-21-2881450208-3143922396-676551458-1002 => C:\Program Files (x86)\Bench\Updater\updater.exe [2014-01-10] () <==== ATTENTION
Task: {E4220533-6493-42DE-87BE-0D4E8C4E8281} - System32\Tasks\AmiUpdXp => C:\Users\Moritz\AppData\Local\SwvUpdater\Updater.exe [2014-01-09] (Amonetizé Ltd) <==== ATTENTION
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {F87B98A0-5F91-445B-A93C-82108D50858B} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-08-22] (ASUSTeK Computer Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AmiUpdXp.job => C:\Users\Moritz\AppData\Local\SwvUpdater\Updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-S-1-5-21-2881450208-3143922396-676551458-1002.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.5-codedownloader.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.5-enabler.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.5-updater.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-4.8-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-4.8-codedownloader.job => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-4.8-enabler.job => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-4.8-updater.job => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-updater.exe <==== ATTENTION
==================== Loaded Modules (whitelisted) =============
2012-08-24 19:26 - 2012-08-24 19:26 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2014-04-05 21:43 - 2013-10-31 18:13 - 00102568 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2014-04-16 17:14 - 2014-04-16 17:14 - 00011776 _____ () C:\Program Files (x86)\NewPlayer\NewPlayerUpdaterService.exe
2012-12-07 19:27 - 2012-12-07 19:27 - 00167424 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2014-05-30 15:18 - 2014-05-30 15:18 - 00709120 _____ () C:\Program Files\004\rqpbhevlkc64.exe
2013-11-20 20:46 - 2014-07-02 18:53 - 00318752 _____ () C:\Program Files (x86)\Bizzybolt\updateBizzybolt.exe
2014-02-14 20:44 - 2014-07-02 18:32 - 00318752 _____ () C:\Program Files (x86)\Bizzybolt\bin\utilBizzybolt.exe
2014-05-28 19:08 - 2014-05-28 19:08 - 00055808 _____ () C:\Users\Moritz\AppData\Roaming\VOPackage\VOsrv.exe
2014-01-26 12:55 - 2014-01-26 12:55 - 00821600 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
2014-06-27 19:28 - 2014-06-27 15:13 - 03353592 _____ () C:\Users\Moritz\AppData\Local\fst_de_70\upfst_de_70.exe
2012-11-09 09:31 - 2012-08-15 19:52 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
2014-02-26 19:05 - 2014-02-26 19:05 - 00049664 _____ () C:\Program Files (x86)\Bench\BService\bservice.exe
2014-02-26 19:05 - 2014-02-26 19:05 - 00060416 _____ () C:\Program Files (x86)\Bench\Wd\wd.exe
2014-05-29 20:35 - 2014-05-29 20:35 - 00111616 _____ () C:\Program Files (x86)\Bench\Proxy\pwdg.exe
2014-05-29 20:35 - 2014-05-29 20:35 - 00410624 _____ () C:\Program Files (x86)\Bench\Proxy\proc.exe
2014-06-27 19:28 - 2014-06-27 15:13 - 03980280 _____ () C:\Program Files (x86)\fst_de_70\fst_de_70.exe
2013-11-19 23:44 - 2012-07-25 13:03 - 00886272 _____ () C:\Program Files (x86)\Advanced System Protector\System.Data.SQLite.dll
2013-11-19 23:43 - 2013-10-04 19:20 - 01730928 _____ () C:\Program Files (x86)\Advanced System Protector\aspsys.dll
2013-11-19 23:44 - 2012-07-25 13:03 - 00168448 _____ () C:\Program Files (x86)\Advanced System Protector\UNRAR.DLL
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-01-26 12:54 - 2014-01-26 12:54 - 00031080 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DbAccess.dll
2014-01-26 12:54 - 2014-01-26 12:54 - 00607376 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\sqlite3.dll
2014-01-26 12:54 - 2014-01-26 12:54 - 00044392 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NAdvLog.dll
2014-01-26 12:54 - 2014-01-26 12:54 - 00036216 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NFileCacheDBAccess.dll
2014-01-26 12:54 - 2014-01-26 12:54 - 00080248 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\ninstallerhelper.dll
2014-01-26 12:55 - 2014-01-26 12:55 - 00129376 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\zlib1.dll
2014-01-26 12:57 - 2014-01-26 12:57 - 00223592 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DevConnMon.dll
2014-07-02 21:14 - 2014-06-06 06:38 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-02-26 19:05 - 2014-02-26 19:05 - 00049664 _____ () C:\Program Files (x86)\Bench\BService\bhelper.dll
2012-09-11 16:01 - 2012-09-11 16:01 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2014-06-11 13:03 - 2014-06-11 13:03 - 00316584 _____ () C:\Program Files\Microsoft Office 15\root\office15\AppVIsvStream32.dll
2012-12-28 23:43 - 2012-06-25 12:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\Temp:373E1720
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
==================== Faulty Device Manager Devices =============
Could not list Devices. Check "winmgmt" service or repair WMI.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/03/2014 01:55:44 AM) (Source: Windows Search Service) (EventID: 3079) (User: )
Description: Benachrichtigungen für Volume C:\ sind nicht aktiv.
Kontext: Windows Anwendung
Details:
Nicht genügend Quoten, um den angeforderten Dienst auszuführen. (HRESULT : 0x800705ad) (0x800705ad)
Error: (07/03/2014 00:35:04 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 1.6.2014.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 17f0
Startzeit: 01cf964296d7ee75
Endzeit: 4294967295
Anwendungspfad: C:\Users\Moritz\Desktop\FRST64.exe
Berichts-ID: 1a585e2f-0239-11e4-bee6-08606e17ad0d
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/03/2014 00:35:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 1.6.2014.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: d5c
Startzeit: 01cf9645148b8fbb
Endzeit: 4294967295
Anwendungspfad: C:\Users\Moritz\Desktop\FRST64.exe
Berichts-ID: 18090eb7-0239-11e4-bee6-08606e17ad0d
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/02/2014 11:41:55 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm setup.exe, Version 14.0.5.448 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 11e8
Startzeit: 01cf963e240e8c68
Endzeit: 4294967295
Anwendungspfad: C:\Users\Moritz\Downloads\avira_free_antivirus45_de\setup.exe
Berichts-ID: af1d472d-0231-11e4-bee4-08606e17ad0d
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/02/2014 11:38:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm setup.exe, Version 14.0.5.448 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 96c
Startzeit: 01cf963da52922df
Endzeit: 4294967295
Anwendungspfad: C:\Users\Moritz\Downloads\avira_free_antivirus45_de\setup.exe
Berichts-ID: 40ace292-0231-11e4-bee4-08606e17ad0d
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/02/2014 11:35:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm setup.exe, Version 14.0.5.448 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 123c
Startzeit: 01cf963ce67a8aeb
Endzeit: 4294967295
Anwendungspfad: C:\Users\Moritz\Downloads\avira_free_antivirus45_de\setup.exe
Berichts-ID: d5412231-0230-11e4-bee4-08606e17ad0d
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/02/2014 11:24:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm setup.exe, Version 14.0.5.448 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: df8
Startzeit: 01cf963b132115aa
Endzeit: 4294967295
Anwendungspfad: C:\Users\Moritz\Downloads\avira_free_antivirus45_de\setup.exe
Berichts-ID: 41e03235-022f-11e4-bee3-08606e17ad0d
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/02/2014 11:13:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm setup.exe, Version 14.0.5.448 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 78c
Startzeit: 01cf9638484ac7e9
Endzeit: 4294967295
Anwendungspfad: C:\Users\Moritz\Downloads\avira_free_antivirus45_de\setup.exe
Berichts-ID: b51efc44-022d-11e4-bee2-08606e17ad0d
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/02/2014 11:05:54 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddWin32ServiceFiles: Unable to back up image of service xmkysecqun64 since QueryServiceConfig API failed
System Error:
Das System kann die angegebene Datei nicht finden.
.
Error: (07/02/2014 10:55:55 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
System errors:
=============
Error: (07/03/2014 03:43:26 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet:
%%127
Error: (07/03/2014 03:43:26 PM) (Source: DCOM) (EventID: 10010) (User: Mo)
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error: (07/03/2014 03:41:26 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet:
%%127
Error: (07/03/2014 03:41:26 PM) (Source: DCOM) (EventID: 10010) (User: Mo)
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error: (07/03/2014 03:39:26 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet:
%%127
Error: (07/03/2014 03:39:26 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error: (07/03/2014 03:37:26 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet:
%%127
Error: (07/03/2014 03:37:26 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error: (07/03/2014 03:35:26 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem Fehler beendet:
%%127
Error: (07/03/2014 03:35:26 PM) (Source: DCOM) (EventID: 10010) (User: Mo)
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Microsoft Office Sessions:
=========================
Error: (07/03/2014 01:55:44 AM) (Source: Windows Search Service) (EventID: 3079) (User: )
Description: Kontext: Windows Anwendung
Details:
Nicht genügend Quoten, um den angeforderten Dienst auszuführen. (HRESULT : 0x800705ad) (0x800705ad)
C:\
Error: (07/03/2014 00:35:04 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe1.6.2014.017f001cf964296d7ee754294967295C:\Users\Moritz\Desktop\FRST64.exe1a585e2f-0239-11e4-bee6-08606e17ad0d
Error: (07/03/2014 00:35:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe1.6.2014.0d5c01cf9645148b8fbb4294967295C:\Users\Moritz\Desktop\FRST64.exe18090eb7-0239-11e4-bee6-08606e17ad0d
Error: (07/02/2014 11:41:55 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: setup.exe14.0.5.44811e801cf963e240e8c684294967295C:\Users\Moritz\Downloads\avira_free_antivirus45_de\setup.exeaf1d472d-0231-11e4-bee4-08606e17ad0d
Error: (07/02/2014 11:38:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: setup.exe14.0.5.44896c01cf963da52922df4294967295C:\Users\Moritz\Downloads\avira_free_antivirus45_de\setup.exe40ace292-0231-11e4-bee4-08606e17ad0d
Error: (07/02/2014 11:35:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: setup.exe14.0.5.448123c01cf963ce67a8aeb4294967295C:\Users\Moritz\Downloads\avira_free_antivirus45_de\setup.exed5412231-0230-11e4-bee4-08606e17ad0d
Error: (07/02/2014 11:24:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: setup.exe14.0.5.448df801cf963b132115aa4294967295C:\Users\Moritz\Downloads\avira_free_antivirus45_de\setup.exe41e03235-022f-11e4-bee3-08606e17ad0d
Error: (07/02/2014 11:13:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: setup.exe14.0.5.44878c01cf9638484ac7e94294967295C:\Users\Moritz\Downloads\avira_free_antivirus45_de\setup.exeb51efc44-022d-11e4-bee2-08606e17ad0d
Error: (07/02/2014 11:05:54 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service xmkysecqun64 since QueryServiceConfig API failed
System Error:
Das System kann die angegebene Datei nicht finden.
Error: (07/02/2014 10:55:55 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Users\Moritz\Downloads\vcredist_arm.exe
==================== Memory info ===========================
Percentage of memory in use: 28%
Total physical RAM: 8077.48 MB
Available physical RAM: 5753.63 MB
Total Pagefile: 13197.48 MB
Available Pagefile: 7696.76 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:279.45 GB) (Free:133.42 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:397.87 GB) (Free:390.07 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 699 GB) (Disk ID: A3362226)
Partition: GPT Partition Type.
==================== End Of Log ============================
Beim Durchlauf von GMER kommt folgende Meldung:
C:\windows\system32\config\system
Der Prozeß kann nicht auf die Datei zugreifen da sie von einem anderen Prozeß verwendet wird. Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-07-03 22:40:16
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000036 HGST_HTS541075A9E680 rev.JA2OA560 698,64GB
Running: Gmer-19357.exe; Driver: C:\Users\Moritz\AppData\Local\Temp\fxloypow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\system32\ntoskrnl.exe!KiCpuId + 988 fffff8015f2de3dc 1 byte [31]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[696] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fa83d91532 4 bytes [D9, 83, FA, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[696] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fa83d9153a 4 bytes [D9, 83, FA, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[696] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fa83d9165a 4 bytes [D9, 83, FA, 07]
.text C:\Windows\system32\nvvsvc.exe[836] C:\Windows\system32\MSIMG32.dll!GradientFill + 690 000007fa83d91532 4 bytes [D9, 83, FA, 07]
.text C:\Windows\system32\nvvsvc.exe[836] C:\Windows\system32\MSIMG32.dll!GradientFill + 698 000007fa83d9153a 4 bytes [D9, 83, FA, 07]
.text C:\Windows\system32\nvvsvc.exe[836] C:\Windows\system32\MSIMG32.dll!TransparentBlt + 246 000007fa83d9165a 4 bytes [D9, 83, FA, 07]
.text C:\Windows\system32\nvvsvc.exe[836] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fa8898177a 4 bytes [98, 88, FA, 07]
.text C:\Windows\system32\nvvsvc.exe[836] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fa88981782 4 bytes [98, 88, FA, 07]
.text C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe[2656] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fa8898177a 4 bytes [98, 88, FA, 07]
.text C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe[2656] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fa88981782 4 bytes [98, 88, FA, 07]
.text C:\Program Files\004\rqpbhevlkc64.exe[3044] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fa8898177a 4 bytes [98, 88, FA, 07]
.text C:\Program Files\004\rqpbhevlkc64.exe[3044] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fa88981782 4 bytes [98, 88, FA, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3424] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fa83d91532 4 bytes [D9, 83, FA, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3424] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fa83d9153a 4 bytes [D9, 83, FA, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3424] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fa83d9165a 4 bytes [D9, 83, FA, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4436] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fa83d91532 4 bytes [D9, 83, FA, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4436] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fa83d9153a 4 bytes [D9, 83, FA, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4436] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fa83d9165a 4 bytes [D9, 83, FA, 07]
.text C:\Windows\system32\igfxpers.exe[4564] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fa8898177a 4 bytes [98, 88, FA, 07]
.text C:\Windows\system32\igfxpers.exe[4564] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fa88981782 4 bytes [98, 88, FA, 07]
.text C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[3928] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fa83d91532 4 bytes [D9, 83, FA, 07]
.text C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[3928] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fa83d9153a 4 bytes [D9, 83, FA, 07]
.text C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[3928] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fa83d9165a 4 bytes [D9, 83, FA, 07]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [556:580] fffff960008de5e8
Thread [1612:1676] 0000000077dc50a7
Thread [1612:1684] 0000000075a48064
Thread [1612:1708] 0000000074f2bfb4
Thread [1612:1876] 0000000074f2bfb4
Thread [1612:1880] 0000000074f2bfb4
Thread [1612:1884] 0000000074f2bfb4
Thread [1612:1908] 0000000074e7304c
---- Processes - GMER 2.1 ----
Library c:\progra~3\2992199f9a\9170.faa (*** suspicious ***) @ C:\Windows\system32\svchost.exe [940] (Non-COM WMI Event Provision APIs/Microsoft Corporation)(2014-04-24 11:19:0 0000000063e40000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Frage: Wenn ich diese Seite öffne erscheint immer eine Umfrage in einem neuen Fenster. Ist Euch das bekannt?
VG Gerald |