coniglio | 06.09.2015 10:35 | Hallo Schrauber,
danke für deine erste Antwort. Hier nun nochmal die Dateien. Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x86) Version:04-09-2015
durchgeführt von ****** (2015-09-06 01:29:37)
Gestartet von C:\Users\******\Desktop
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-270361425-1554236732-2519145148-500 - Administrator - Enabled) => C:\Users\Administrator
Gast (S-1-5-21-270361425-1554236732-2519145148-501 - Limited - Disabled)
****** (S-1-5-21-270361425-1554236732-2519145148-1000 - Administrator - Enabled) => C:\Users\******
UpdatusUser (S-1-5-21-270361425-1554236732-2519145148-1001 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
1X-Ripper (HKLM\...\1X-Ripper_is1) (Version: Aktuelle Version - IN MEDIA KG)
7-PDF Split & Merge Version 2.2.0 (Build 145) (HKLM\...\7-PDF Split & Merge_is1) (Version: 7-PDF Split & Merge - Version 2.2.0 (Build 145) - 7-PDF, Germany - Thorsten Hodes)
7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader X (10.1.4) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.4 - Adobe Systems Incorporated)
Adolix Split and Merge PDF v2.1 (HKLM\...\Adolix Split and Merge PDF_is1) (Version: - Adolix Software)
Altova XMLSpy 2015 rel. 4 sp1 Enterprise Edition (HKLM\...\{C154F8BC-7508-4795-B16A-4F18B33180DE}) (Version: 2015.04.01 - Altova)
Altova XMLSpy® 2010 rel. 3 sp 1 Enterprise Edition (HKLM\...\{78238A2B-F513-4605-A160-24ADF4096041}) (Version: 2010.03.01 - Altova)
Amazon MP3-Downloader 1.0.17 (HKLM\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC)
Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Arbeitszeugnisse (HKLM\...\{8A409F0E-9F75-4315-B64A-21A1E8C1206D}) (Version: 6.0.0.0 - Haufe-Lexware GmbH & Co. KG)
ArcSoft PhotoStudio 6 (HKLM\...\{ED8EF3C2-FA5B-4A1E-950D-5A0227161F97}) (Version: 6.0.1.148 - ArcSoft)
Audacity 2.0.5 (HKLM\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
AudibleManager (HKLM\...\AudibleManager) (Version: 6426938.-2.1996910774.1996909788 - Audible, Inc.)
Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.12.420 - Avira Operations GmbH & Co. KG)
Avira SearchFree Toolbar (HKLM\...\{41564952-412D-5637-00A7-A758B70C1D00}) (Version: 12.29.0.1507 - APN, LLC)
Belkin USB Wireless Adaptor (HKLM\...\InstallShield_{549CE1BD-88E4-4C5E-BF75-B155624714CC}) (Version: 1.0.0.10 - Belkin)
Belkin USB Wireless Adaptor (Version: 1.0.0.10 - Belkin) Hidden
Benutzerhandbuch anzeigen (HKLM\...\View User Guide) (Version: 3.60.43.0 - )
Bing Bar (HKLM\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CADEMIA 4.0 (HKLM\...\CADEMIA 4.0) (Version: 4.0 - CADEMIA-Consult GmbH)
Canon MP Navigator EX 2.0 (HKLM\...\MP Navigator EX 2.0) (Version: - )
Canon Utilities Solution Menu (HKLM\...\CanonSolutionMenu) (Version: - )
CanoScan 5600F Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4808) (Version: - )
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4478 - CDBurnerXP)
Common Desktop Agent (Version: 1.62.0 - OEM) Hidden
Cosmo Player 2.1.1 (HKLM\...\CosmoPlayer) (Version: - )
DemoVersion ELSA-Suite (HKLM\...\{3C580AC6-CC3E-44C4-B72A-E1A2DD622241}) (Version: 8.0 - IBYKUS Software GmbH & Co. KG)
DesignPro 5 (HKLM\...\InstallShield_{F82C6574-AD88-4B40-A432-970BC77F1BD2}) (Version: 5.5.708 - Avery)
DesignPro 5 (Version: 5.5.708 - Avery) Hidden
DJ Java Decompiler v.3.12.12.100 (HKLM\...\{2BEFBE4A-6905-4F2C-8DDB-C84A74FEF443}) (Version: 3.12.12.100 - Atanas Neshkov 2009)
DVD Flick 1.3.0.7 (HKLM\...\DVD Flick_is1) (Version: 1.3.0.7 - Dennis Meuwissen)
File Type Advisor 1.6 (HKLM\...\File Type Advisor_is1) (Version: - )
Firebird SQL Server - MAGIX Edition (HKLM\...\{6C5F8503-55D2-4398-858C-362B7A7AF51C}) (Version: 2.1.31.0 - MAGIX AG)
Free Mp3 Wma Converter V 1.91 (HKLM\...\Free Mp3 Wma Converter_is1) (Version: 1.91.0.0 - Koyote Soft)
Free Video Converter V 2.9 (HKLM\...\Free Video Converter_is1) (Version: 2.9.0.0 - Koyote Soft)
Freemake Video Converter Version 4.1.5 (HKLM\...\Freemake Video Converter_is1) (Version: 4.1.5 - Ellora Assets Corporation)
FreePDF (Remove only) (HKLM\...\FreePDF_XP) (Version: - )
Google Chrome (HKLM\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Update Helper (Version: 1.3.28.13 - Google Inc.) Hidden
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.04) (Version: 9.04 - Artifex Software Inc.)
Haufe Formular-Manager (HKLM\...\{CE7F2CA3-ADA3-4907-9013-8B61C370B6E4}) (Version: 11.01.03.0001 - Haufe-Lexware GmbH & Co. KG)
ImTOO Video Editor (HKLM\...\ImTOO Video Editor) (Version: 1.0.34.1231 - ImTOO)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.37 - Irfan Skiljan)
iTunes (HKLM\...\{C197BC08-3D82-4651-8886-E68C21578A38}) (Version: 11.1.3.8 - Apple Inc.)
Java 7 Update 60 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217060FF}) (Version: 7.0.600 - Oracle)
K-Lite Mega Codec Pack 9.9.0 (HKLM\...\KLiteCodecPack_is1) (Version: 9.9.0 - )
L.ASSISTENT Version 2.12 (HKLM\...\{053D08A3-FD86-4286-B481-A9437A56CB57}_is1) (Version: 2.12 - Chris Müller)
LinuxLive USB Creator (HKLM\...\LinuxLive USB Creator) (Version: 2.8 - Thibaut Lauziere)
MAGIX Audio Cleaning Lab MX (HKLM\...\MAGIX_MSI_mclab_mx) (Version: 18.0.0.9 - MAGIX AG)
MAGIX Audio Cleaning Lab MX (Version: 18.0.0.9 - MAGIX AG) Hidden
MAGIX Screenshare (HKLM\...\MAGIX_{BA4782C0-4124-4FA1-B15C-15333744444E}) (Version: 4.3.6.1987 - MAGIX AG)
MAGIX Screenshare (Version: 4.3.6.1987 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM\...\MAGIX_{A93134FC-5812-4B37-BC58-7E9FF2FDF72F}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX USB-Videowandler 2 (HKLM\...\{383F89BE-C8C9-4C58-978E-1178620DA80B}) (Version: 1.03.0000 - Ihr Firmenname)
MAGIX Video easy Retten Sie Ihre Videokassetten 6 (HKLM\...\MAGIX_{4F394EC0-28F2-44D1-BAB9-42C65CA2371E}) (Version: 4.0.0.82 - MAGIX AG)
MAGIX Video easy Retten Sie Ihre Videokassetten 6 (Version: 4.0.0.82 - MAGIX AG) Hidden
MessageViewer Pro 3.1.5 (HKU\S-1-5-21-270361425-1554236732-2519145148-1000\...\MessageViewer Pro) (Version: 3.1.5 - Encryptomatic, LLC)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
MOST Tutorial (HKLM\...\{A7E31869-1412-4183-9672-C4F6ABCF56A4}) (Version: - )
Motorola Device Manager (HKLM\...\{28DB8373-C1BB-444F-A427-A55585A12ED7}) (Version: 2.3.9 - Motorola Mobility)
Motorola Device Software Update (Version: 13.02.1402 - Motorola Mobility) Hidden
Motorola Mobile Drivers Installation 6.0.0 (Version: 6.0.0 - Motorola Inc.) Hidden
Mozilla Firefox 39.0 (x86 de) (HKLM\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Firefox 40.0.3 (x86 de) (HKU\S-1-5-21-270361425-1554236732-2519145148-1000\...\Mozilla Firefox 40.0.3 (x86 de)) (Version: 40.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 39.0 - Mozilla)
Mozilla Thunderbird 17.0 (x86 de) (HKLM\...\Mozilla Thunderbird 17.0 (x86 de)) (Version: 17.0 - Mozilla)
Mozilla Thunderbird 17.0.8 (x86 de) (HKU\S-1-5-21-270361425-1554236732-2519145148-1000\...\Mozilla Thunderbird 17.0.8 (x86 de)) (Version: 17.0.8 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
NVIDIA 3D Vision Treiber 306.97 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 306.97 - NVIDIA Corporation)
NVIDIA Grafiktreiber 306.97 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.97 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.12.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0604 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
Paint Shop Pro 7 Evaluation (HKLM\...\{D6DE02C7-1F47-11D4-9515-00105AE4B89A}) (Version: 7.0.0.0000 - Jasc Software Inc)
PC Connectivity Solution (HKLM\...\{6094AB91-4CC8-498E-9DFF-134CC0B159DE}) (Version: 6.43.14.0 - Nokia)
Peter's XML Editor (HKLM\...\{5E770B51-820C-402E-8569-E02D12C212D2}) (Version: 2.00.0000 - Peter Reynolds)
Philips Songbird (HKLM\...\Philips Songbird) (Version: 6.1.2265 (2265) - Koninklijke Philips Electronics N.V.)
Prism Videodatei-Konverter (HKLM\...\Prism) (Version: 2.02 - NCH Software)
PSPad editor (HKLM\...\PSPad editor_is1) (Version: 4.5.7.2450 - Jan Fiala)
QUIZPro V4.53 (HKLM\...\QUIZPro_is1) (Version: QUIZPro V.4.53 - Litschi)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5605 - Realtek Semiconductor Corp.)
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - )
Samsung CLP-360 Series (HKLM\...\Samsung CLP-360 Series) (Version: 1.14 (14.04.2014) - Samsung Electronics Co., Ltd.)
Samsung Drucker-Diagnose (HKLM\...\Samsung Printer Diagnostics) (Version: 1.0.0.16 - Samsung Electronics Co., Ltd.)
Samsung Easy Printer Manager (HKLM\...\Samsung Easy Printer Manager) (Version: 1.05.32.00(01.04.2014) - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
SiSoftware Sandra Lite 2013a (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1) (Version: 19.19.2013.1 - SiSoftware)
Skype™ 7.8 (HKLM\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM\...\SpeedFan) (Version: - )
Suissl version 1.0 (HKLM\...\Suissl_is1) (Version: 1.0 - Suissl AG)
Switch Audiodatei-Konverter (HKLM\...\Switch) (Version: 4.53 - NCH Software)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.0.12.0 - Synaptics)
TomTom HOME (HKLM\...\{9017CEAF-BE5A-4F73-8A0E-C87E26971E55}) (Version: 2.9.3 - Ihr Firmenname)
TomTom HOME Visual Studio Merge Modules (HKLM\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 8.01 - Ghisler Software GmbH)
VideoPad Video Editor (HKLM\...\VideoPad) (Version: - NCH Software)
Viscosity 1.3.7 (1143) (HKLM\...\{CC85567E-DC83-4BB5-AD77-D84514C0D059}_is1) (Version: 1.3.7 - SparkLabs)
WavePad Audio-Editor (HKLM\...\WavePad) (Version: 5.58 - NCH Software)
WebTemp 3.37 (kostenlose Version) (HKLM\...\WebTemp_is1) (Version: - hxxp://www.webtemp.org)
WIDCOMM Bluetooth Software (HKLM\...\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.3400 - Broadcom Corporation)
Winamp (HKLM\...\Winamp) (Version: 5.63 - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKU\S-1-5-21-270361425-1554236732-2519145148-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
WinPcap 4.1.3 (HKLM\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
Wireshark 1.10.5 (32-bit) (HKLM\...\Wireshark) (Version: 1.10.5 - The Wireshark developer community, hxxp://www.wireshark.org)
XAMPP 1.7.4 (HKLM\...\xampp) (Version: - )
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1000_Classes\CLSID\{16d51579-a30b-4c8b-a276-0ff4dc41e755}\InprocServer32 -> kein Dateipfad
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1000_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.)
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1000_Classes\CLSID\{4955DD33-B159-11D0-8FCF-00AA006BCC59}\InprocServer32 -> kein Dateipfad
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1000_Classes\CLSID\{989D1DC0-B162-11D1-B6EC-D27DDCF9A923}\InprocServer32 -> kein Dateipfad
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1000_Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32 -> kein Dateipfad
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1000_Classes\CLSID\{B54F3743-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32 -> kein Dateipfad
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1000_Classes\CLSID\{cc5bbec3-db4a-4bed-828d-08d78ee3e1ed}\InprocServer32 -> kein Dateipfad
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1000_Classes\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\InprocServer32 -> kein Dateipfad
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1000_Classes\CLSID\{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32 -> kein Dateipfad
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1000_Classes\CLSID\{f414c262-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32 -> kein Dateipfad
CustomCLSID: HKU\S-1-5-21-270361425-1554236732-2519145148-1001_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.)
==================== Wiederherstellungspunkte =========================
02-08-2015 20:09:10 Geplanter Prüfpunkt
13-08-2015 03:14:59 Windows Update
20-08-2015 10:37:26 Windows Update
31-08-2015 12:31:03 Geplanter Prüfpunkt
01-09-2015 05:02:49 Installed DJ Java Decompiler v.3.12.12.100
05-09-2015 22:37:24 Altova XMLSpy® 2010 rel. 3 sp 1 Enterprise Edition wird installiert
05-09-2015 23:17:07 Altova XMLSpy 2015 rel. 4 sp1 Enterprise Edition wird installiert
05-09-2015 23:19:59 Altova XMLSpy 2015 rel. 4 sp1 Enterprise Edition wird installiert
==================== Hosts Inhalt: ==========================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0149A86B-981C-4B1B-933E-417C4E815F60} - System32\Tasks\Motorola Device Manager Engine => C:\Program Files\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-03-25] ()
Task: {24C4DA88-C262-4EA4-8393-307EEE94D02D} - System32\Tasks\Motorola Device Manager Initial Update => C:\Program Files\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-03-25] ()
Task: {52B68296-08A7-4EC8-86E7-8E94371DC8AE} - System32\Tasks\FileAdvisorCheck => C:\Program Files\File Type Advisor\file-type-advisor.exe [2014-02-24] ( )
Task: {66D0D1C3-15DE-4768-BCD9-32FABDC34F6E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated)
Task: {7A963812-E865-4416-8734-0B51ADFEBC8F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {7F540ED9-C547-4897-90E5-E75DA2C2180C} - System32\Tasks\FileAdvisorUpdate => C:\Program Files\File Type Advisor\fileadvisor.exe [2014-02-24] (File Type Advisor)
Task: {87D00D5A-F115-40C7-BD37-7762D34863B7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {ADABC001-5C64-4505-A873-9A17C194AC04} - System32\Tasks\Motorola Device Manager Update => C:\Program Files\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-03-25] ()
Task: {D3B00619-9F2D-4D5E-9E11-619E291D0CD0} - System32\Tasks\{08408198-3E5E-45C6-A904-6A5ACDEADD5D} => Firefox.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/abandoninstall?page=tsProgressBar
Task: {E8602D97-039A-47EA-B22D-819F872BF62B} - System32\Tasks\NCH Software\videopadShakeIcon => C:\Program Files\NCH Software\VideoPad\VideoPad.exe [2012-12-25] (NCH Software)
Task: {ECA134A8-69BA-4B36-889F-62593C0D0723} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - ****** => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2012-12-22 15:53 - 2010-06-17 22:56 - 00116224 _____ () C:\Windows\System32\redmonnt.dll
2015-07-05 21:02 - 2012-01-09 13:41 - 00024064 _____ () C:\Windows\System32\sst6clm.dll
2015-07-05 21:02 - 2014-03-20 09:26 - 00896512 _____ () C:\Windows\system32\spool\DRIVERS\W32X86\3\sst6cdu.dll
2013-09-13 20:51 - 2013-09-13 20:51 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-09-13 20:51 - 2013-09-13 20:51 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-03-20 20:55 - 2009-11-16 21:31 - 00069632 _____ () C:\Program Files\PSPad editor\PSPadShell.dll
2013-03-25 21:44 - 2013-03-25 21:44 - 00172032 _____ () C:\Program Files\Motorola Mobility\Motorola Device Manager\css_core.dll
2012-03-19 12:23 - 2012-03-19 12:23 - 00380416 _____ () C:\Program Files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe
2012-03-09 09:58 - 2012-03-09 09:58 - 00350072 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
2012-03-09 09:58 - 2012-03-09 09:58 - 00056696 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll
2015-09-05 22:55 - 2015-09-05 22:55 - 01457664 _____ () C:\Users\******\AppData\Local\Temp\mdi064.dll
2015-08-12 09:51 - 2015-08-12 09:51 - 17482952 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-270361425-1554236732-2519145148-1000\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-21-270361425-1554236732-2519145148-1001\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: )
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
==================== FirewallRules (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{88021D0B-E8CF-4534-B774-414857E0A78F}] => (Allow) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{3F698CAA-2C2F-4A15-8D22-7A98C753EDB3}] => (Allow) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{5292D3A6-EABC-43FB-843D-DC058E42437B}] => (Allow) D:\SiSoftware_Sandra_ Lite_2013a\RpcAgentSrv.exe
FirewallRules: [{46FF1310-2F9B-4DD3-8BA8-A62464AC5444}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{7498CB3C-A7A4-410D-83A5-5750E5B7F2C0}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{E02C19B4-F567-4C47-9054-B17CCF328DF3}] => (Allow) LPort=80
FirewallRules: [{E735BB8A-7F15-4124-8491-2D98ED1AC857}] => (Allow) LPort=80
FirewallRules: [{5532A55F-829F-44ED-A22B-BEDEEBA24A4C}] => (Allow) LPort=80
FirewallRules: [{FDA0C123-4DD1-4481-83ED-C782BA1BF9C8}] => (Allow) I:\Setup.exe
FirewallRules: [{A0F59CAD-034A-49BF-9B3E-92E6F2404820}] => (Allow) C:\Windows\twain_32\Samsung\SCX3400\SCNSearch\USDAgent.exe
FirewallRules: [{0AD9A298-D7BF-4DA0-8C7D-615390790AE9}] => (Allow) C:\Windows\twain_32\Samsung\SCX3400\SCNSearch\USDAgent.exe
FirewallRules: [{D88B98EC-B360-4AC1-9F0F-362168C7F67E}] => (Allow) C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{D8446EF6-36CD-41D1-8693-383288C5CC1E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B19071E9-817E-4CA4-B79E-35B646863A4E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6086D609-E3D2-404D-ADB9-7D54E3A5CE6F}] => (Allow) D:\i_tunes\iTunes.exe
FirewallRules: [{148BD769-233B-4D89-87E5-36528F430D95}] => (Allow) D:\SiSoftware_Sandra_ Lite_2013a\WNt500x86\RpcSandraSrv.exe
FirewallRules: [TCP Query User{9281634E-214C-49FE-AA36-354016E1FE73}C:\program files\winamp\winamp.exe] => (Block) C:\program files\winamp\winamp.exe
FirewallRules: [UDP Query User{1ABAAF6B-70A2-424F-983E-F06C5FA420FC}C:\program files\winamp\winamp.exe] => (Block) C:\program files\winamp\winamp.exe
FirewallRules: [TCP Query User{9263C399-A6F0-4D09-9A23-5D4CA003E834}D:\mozillafirefox\firefox.exe] => (Allow) D:\mozillafirefox\firefox.exe
FirewallRules: [UDP Query User{F14E1FF5-08A7-43F5-8C9D-EFD3573304BD}D:\mozillafirefox\firefox.exe] => (Allow) D:\mozillafirefox\firefox.exe
FirewallRules: [TCP Query User{D68D3568-2163-420B-953C-584CD7EE8ED6}D:\mozillafirefox\firefox.exe] => (Allow) D:\mozillafirefox\firefox.exe
FirewallRules: [UDP Query User{37CA6AB4-3306-49CB-AB01-3FF43B45B03B}D:\mozillafirefox\firefox.exe] => (Allow) D:\mozillafirefox\firefox.exe
FirewallRules: [{E4FA2E22-066A-4212-882E-9E3563CDDAC4}] => (Allow) D:\MozillaFirefox\firefox.exe
FirewallRules: [{596DD870-C611-4832-A077-E31AE928B814}] => (Allow) D:\MozillaFirefox\firefox.exe
FirewallRules: [{F46E653A-8EE2-4E29-89F9-9B3E3EA9799F}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDS.Application.exe
FirewallRules: [{D4794388-BEA5-4231-963A-482F103E94BD}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDS.Application.exe
FirewallRules: [{1E9A6A61-6E13-4610-82D3-C432F8AFB725}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\OrderSupplies.exe
FirewallRules: [{E8F5CA87-EC8A-4839-B5EF-0AC8D7EAF545}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\OrderSupplies.exe
FirewallRules: [{700D4E81-DD83-455B-9271-F48409F72A53}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDSAlert.exe
FirewallRules: [{D10F0839-A180-4439-B54D-10CEE9D1B172}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDSAlert.exe
FirewallRules: [{932692D4-0524-4105-9CB3-C114200A4D03}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\uninstall.exe
FirewallRules: [{362E653D-1477-4BF5-9260-598D50824605}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\uninstall.exe
FirewallRules: [{D31EE568-610C-475D-B3AA-E8DDEA786788}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe
FirewallRules: [{00B61E7B-7647-41F0-AD56-FAC04A4AFF83}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe
FirewallRules: [{B29054A0-03BB-4CF1-9C8B-7F5756B47DA2}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\CDAS2PC\ScanProcess.exe
FirewallRules: [{5EB016AD-87A7-4A4C-A9AC-8A2FC6D4D810}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\CDAS2PC\ScanProcess.exe
FirewallRules: [{756F3679-0725-480A-943B-574EAD0DCE8A}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\CDAS2PC\Scan2PCNotify.exe
FirewallRules: [{DD175A06-54D3-4ECE-B419-29F1211D9831}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\CDAS2PC\Scan2PCNotify.exe
FirewallRules: [{356F74BC-39F9-41D1-B252-CE2B3CDCDEB6}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
FirewallRules: [{CDAF5EEE-1C76-4D12-85D2-35E00A508090}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
FirewallRules: [{9CB1554A-C0A2-407D-9529-6DB09A1369DA}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{BCDB0BF4-EA87-4BF6-A610-339051D7676F}] => (Allow) LPort=2799
FirewallRules: [{86795320-6CBE-4FA7-AA04-BBF6EBA6911F}] => (Allow) LPort=2799
==================== Fehlerhafte Geräte im Gerätemanager =============
Name: Viscosity Virtual Adapter V9.1
Description: Viscosity Virtual Adapter V9.1
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Sparklabs
Service: visctap0901
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Nokia N95
Description: Nokia N95
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (09/06/2015 12:48:52 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\******\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\S1D0EO99.DEFAULT-1404836466344\SAFEBROWSING> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
Error: (09/06/2015 12:48:51 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\******\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\S1D0EO99.DEFAULT-1404836466344\SAFEBROWSING> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
Error: (09/05/2015 11:17:56 PM) (Source: MsiInstaller) (EventID: 11327) (User: WINDOWS-69RC4WU)
Description: Produkt: Altova XMLSpy 2015 rel. 4 sp1 Enterprise Edition -- Fehler 1327. Ungültiges Laufwerk: J:\
Error: (09/05/2015 10:55:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung key.exe, Version 0.0.0.0, Zeitstempel 0x55e41a24, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x021426a0,
Prozess-ID 0x1188, Anwendungsstartzeit key.exe0.
Error: (09/05/2015 10:47:17 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\******\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\S1D0EO99.DEFAULT-1404836466344\SAFEBROWSING-BACKUP> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
Error: (08/31/2015 10:45:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sst6csm.exe, Version 1.4.0.35, Zeitstempel 0x5322fff8, fehlerhaftes Modul sst6csm.exe, Version 1.4.0.35, Zeitstempel 0x5322fff8, Ausnahmecode 0xc0000409, Fehleroffset 0x000c0f27,
Prozess-ID 0x11c8, Anwendungsstartzeit sst6csm.exe0.
Error: (08/31/2015 08:45:47 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c
Error: (08/30/2015 08:51:35 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\******\APPDATA\LOCAL\SKYPE\APPS\LOGIN\CSS\INDEX.CSS> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
Error: (08/30/2015 08:51:35 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\******\APPDATA\LOCAL\SKYPE\APPS\LOGIN\CSS\INDEX.CSS> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
Error: (08/29/2015 10:02:20 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\******\APPDATA\LOCAL\SKYPE\APPS\LOGIN\FONTS\SEGOE-UI-LIGHT-CYRILLIC.WOFF> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
Systemfehler:
=============
Error: (09/06/2015 12:41:44 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Windows-Dienst für Schriftartencache%%1053
Error: (09/06/2015 12:41:44 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Windows-Dienst für Schriftartencache
Error: (09/06/2015 12:41:14 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: iPod-Dienst%%1053
Error: (09/06/2015 12:41:14 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000iPod-Dienst
Error: (09/06/2015 12:41:14 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1053iPod Service{063D34A4-BF84-4B8D-B699-E8CA06504DDE}
Error: (09/06/2015 12:40:21 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
Error: (09/06/2015 12:36:50 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: 1Neustart des DienstsWindows Search%%1056
Error: (09/06/2015 12:36:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Office Software Protection Platform1
Error: (09/06/2015 12:36:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: BBUpdate1
Error: (09/06/2015 12:36:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: NVIDIA Update Service Daemon1
Microsoft Office:
=========================
Error: (09/06/2015 12:48:52 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
C:\USERS\******\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\S1D0EO99.DEFAULT-1404836466344\SAFEBROWSING
Error: (09/06/2015 12:48:51 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
C:\USERS\******\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\S1D0EO99.DEFAULT-1404836466344\SAFEBROWSING
Error: (09/05/2015 11:17:56 PM) (Source: MsiInstaller) (EventID: 11327) (User: WINDOWS-69RC4WU)
Description: Produkt: Altova XMLSpy 2015 rel. 4 sp1 Enterprise Edition -- Fehler 1327. Ungültiges Laufwerk: J:\(NULL)(NULL)(NULL)(NULL)
Error: (09/05/2015 10:55:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: key.exe0.0.0.055e41a24unknown0.0.0.000000000c0000005021426a0118801d0e81d23ff2e95
Error: (09/05/2015 10:47:17 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
C:\USERS\******\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\S1D0EO99.DEFAULT-1404836466344\SAFEBROWSING-BACKUP
Error: (08/31/2015 10:45:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: sst6csm.exe1.4.0.355322fff8sst6csm.exe1.4.0.355322fff8c0000409000c0f2711c801d0e42da1eef991
Error: (08/31/2015 08:45:47 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c
Error: (08/30/2015 08:51:35 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
C:\USERS\******\APPDATA\LOCAL\SKYPE\APPS\LOGIN\CSS\INDEX.CSS
Error: (08/30/2015 08:51:35 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
C:\USERS\******\APPDATA\LOCAL\SKYPE\APPS\LOGIN\CSS\INDEX.CSS
Error: (08/29/2015 10:02:20 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
C:\USERS\******\APPDATA\LOCAL\SKYPE\APPS\LOGIN\FONTS\SEGOE-UI-LIGHT-CYRILLIC.WOFF
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) Dual CPU T2390 @ 1.86GHz
Prozentuale Nutzung des RAM: 46%
Installierter physikalischer RAM: 3068.27 MB
Verfügbarer physikalischer RAM: 1636.23 MB
Summe virtueller Speicher: 6382.8 MB
Verfügbarer virtueller Speicher: 4309.68 MB
==================== Laufwerke ================================
Drive c: (OS) (Fixed) (Total:120.01 GB) (Free:17.17 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)]
Drive d: (Programme) (Fixed) (Total:50.01 GB) (Free:27.39 GB) NTFS
Drive e: (DATEN) (Fixed) (Total:40 GB) (Free:14.54 GB) NTFS
Drive f: (Install) (Fixed) (Total:25 GB) (Free:15.92 GB) NTFS
Drive g: () (Fixed) (Total:11.99 GB) (Free:2.35 GB) FAT32
Drive h: (Sicherung) (Fixed) (Total:51.06 GB) (Free:5 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: 55E0B14E)
Partition 1: (Active) - (Size=120 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=178.1 GB) - (Type=05)
==================== Ende vom Addition.txt ============================ Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x86) Version:04-09-2015
durchgeführt von ****** (Administrator) auf WINDOWS-69RC4WU (06-09-2015 01:27:41)
Gestartet von C:\Users\******\Desktop
Geladene Profile: ****** & UpdatusUser (Verfügbare Profile: ****** & UpdatusUser & Administrator)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Sprache: Deutsch (Deutschland)
Internet Explorer Version 9 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Motorola Mobility LLC) C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
(Motorola) C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe
(Motorola Mobility LLC) C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
(TomTom) D:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
(SparkLabs) D:\Program Files\Suissl\Viscosity\ViscosityService.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
() C:\Program Files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(TomTom) D:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Mozilla Corporation) D:\MozillaFirefox\firefox.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Mozilla Corporation) D:\MozillaFirefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_18_0_0_232.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_18_0_0_232.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6111232 2008-04-17] (Realtek Semiconductor)
HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-08-17] (Synaptics, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [689488 2008-03-11] (CANON INC.)
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [782008 2015-08-26] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [FreePDF Assistant] => C:\Program Files\FreePDF_XP\fpassist.exe [381440 2009-08-06] (shbox.de)
HKLM\...\Run: [Philips Device Listener] => C:\Program Files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe [380416 2012-03-19] ()
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] => D:\i_tunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [350072 2012-03-09] ()
HKU\S-1-5-21-270361425-1554236732-2519145148-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-270361425-1554236732-2519145148-1000\...\Run: [TomTomHOME.exe] => D:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [247768 2012-12-05] (TomTom)
HKU\S-1-5-21-270361425-1554236732-2519145148-1000\...\Run: [TextbausteinverwaltungDeluxe] => C:\Program Files\TBDeluxe\TBDeluxe.exe
HKU\S-1-5-21-270361425-1554236732-2519145148-1000\...\Run: [tsiVideo] => rundll32.exe C:\Users\******\AppData\Local\Temp\\mdi064.dll,dalmat <===== ACHTUNG
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-04-30]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{3EDA2618-BC5F-478C-9888-599244C2C3D3}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{81BE255A-F019-4A63-AF97-AEA992813647}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{D83092F8-7706-4683-9EAB-4A507F7588FC}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
HKU\S-1-5-21-270361425-1554236732-2519145148-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-270361425-1554236732-2519145148-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-05-30] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-05-30] (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\s1d0eo99.default-1404836466344
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> D:\i_tunes\Mozilla Plugins\npitunes.dll [2013-10-01] ()
FF Plugin: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-05-30] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-05-30] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-10-02] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-10-02] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-29] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-29] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-07-27] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-270361425-1554236732-2519145148-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll [2012-12-07] (Amazon.com, Inc.)
FF Extension: ProductivityBoss - C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\s1d0eo99.default-1404836466344\Extensions\e5ffxtbr@www.productivityboss.com [2015-09-06]
FF Extension: Kein Name - C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\s1d0eo99.default-1404836466344\Extensions\trash [2015-09-06]
FF Extension: Bitdefender QuickScan - C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\s1d0eo99.default-1404836466344\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2015-08-31]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-12-23]
StartMenuInternet: FIREFOX.EXE - D:\MozillaFirefox\firefox.exe
Chrome:
=======
CHR Plugin: (Google
"new_tab_url": "{google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding}",
"prepopulate_id": "1",
"search_terms_replacement_key": "espv",
"search_url": "{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}",
"search_url_post_params": "",
"suggest_url": "{google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}",
"suggest_url_post_params": ""
},
"distribution": {
"make_chrome_default_for_user": true
},
"download": {
"directory_upgrade": true,
"extensions_to_open": "adh"
},
"extensions": {
"alerts": {
"initialized": true
},
"autoupdate": {
"last_check": "13030296089960096",
"next_check": "13030881118139910"
},
"blacklistupdate": {
"lastpingday": "13029408213072911",
"version": "0.0.0.149"
},
"chrome_url_overrides": {
"bookmarks": [ "chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html" ]
},
"known_disabled": [ "aaaaacalgebmfelllfiaoknifldpngjh" ],
"last_chrome_version": "31.0.1650.63",
"settings": {
"aaaaacalgebmfelllfiaoknifldpngjh": {
"ack_external": true,
"active_permissions": {
"api": [ "bookmarks", "contentSettings", "contextMenus", "cookies", "geolocation", "history", "idle", "management", "notifications", "plugin", "tabs", "unlimitedStorage", "webRequest", "webRequestBlocking", "webRequestInternal" ],
"explicit_host": [ "chrome://favicon/*", "hxxp://*/*", "https://*/*" ],
"scriptable_host": [ "*://*.ask.com/", "*://*.bagsbuy.com/*", "*://*.childrenschorus.org/*", "*://*.csaa.com/*", "*://*.facebook.com/*", "*://*.google.com/*", "*://*.google.com/imgres*", "*://*.mercurynews.com/*", "*://*.usnews.com/*", "*://*.wikipedia.org/*", "*://*/*", "*://codesearch.google.com/*", "*://images.google.com/*" ]
},
"creation_flags": 1,
"disable_reasons": 1,
"external_first_run": true,
"from_bookmark": false,
"from_webstore": false,
"initial_keybindings_set": true,
"install_time": "13027963270078932",
"location": 3,
"manifest": {
"background": {
"page": "background/background.html"
},
"browser_action": {
"default_icon": "config/skin/images/logo/logo_19x.png",
"default_popup": "config/skin/chrome-options.html",
"default_title": "Control the Avira SearchFree Toolbar"
},
"chrome_url_overrides": {
"newtab": "config/skin/new-tab-page.html"
},
"content_scripts": [ {
"all_frames": true,
"js": [ "lib/constant.js", "lib/default-config.js", "config/tb-config.js", "lib/protocol.js", "lib/tb-message.js", "lib/widget-messaging.js", "content_script/inline-html.js" ],
"matches": [ "*://*/*" ],
"run_at": "document_end"
}, {
"js": [ "lib/jquery.js", "lib/constant.js", "lib/default-config.js", "config/tb-config.js", "config/widget-config.js", "lib/protocol.js", "lib/tb-message.js", "lib/state-machine.js", "lib/window-position.js", "content_script/positioning.js", "content_script/toolbar.js", "content_script/widget.js", "content_script/injector.js" ],
"matches": [ "*://*/*" ],
"run_at": "document_start"
}, {
"css": [ "content_script/hack/facebook.css" ],
"matches": [ "*://*.facebook.com/*" ]
}, {
"css": [ "content_script/hack/relative.css" ],
"matches": [ "*://*.google.com/*", "*://*.ask.com/", "*://*.bagsbuy.com/*", "*://*.csaa.com/*", "*://*.childrenschorus.org/*", "*://*.wikipedia.org/*", "*://*.mercurynews.com/*", "*://*.usnews.com/*" ],
"run_at": "document_start"
}, {
"css": [ "content_script/hack/static.css" ],
"matches": [ "*://*.google.com/imgres*", "*://images.google.com/*", "*://codesearch.google.com/*" ],
"run_at": "document_start"
} ],
"description": "Convenient tools and links to make your browsing more enjoyable",
"icons": {
"128": "config/skin/images/logo/logo_128x.png",
"24": "config/skin/images/logo/logo_24x.png",
"32": "config/skin/images/logo/logo_32x.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbM5MplJHhMMjoBDXypb8IzKcuYt+sISdqFzUsvqHBoB5d3/JMn4RmGiueAkoVFtHyDQ1H5VPKL6Ryt+SabpX/dpx9MaKkqXuiYYsComQYGQ4/tRFD4D9hNRk2RupgJu15UsWXU35gc6LGhW50cjQ9yfH5gih2Pd7RKDyAd+hLiwIDAQAB",
"manifest_version": 2,
Avira SearchFree Toolbar plus Web Protection
"permissions": [ "bookmarks", "contextMenus", "contentSettings", "cookies", "geolocation", "history", "idle", "management", "notifications", "tabs", "unlimitedStorage", "webRequest", "webRequestBlocking", "hxxp://*/*", "https://*/*", "chrome://favicon/*", "bookmarks", "contextMenus", "contentSettings", "cookies", "geolocation", "history", "idle", "management", "notifications", "tabs", "unlimitedStorage", "hxxp://*/*", "https://*/*", "chrome://favicon/*", "webRequest", "webRequestBlocking" ],
"plugins": [ {
"path": "background/ChromeUtilPlugin.dll",
"public": false
} ],
"update_url": "hxxp://apnmedia.ask.com/media/toolbar/everest/partners/AVIRA-V7/YY/update.xml",
"version": "25.62088",
"web_accessible_resources": [ "config/skin/css/containers.css", "config/skin/toolbar.html", "widgets/search-suggestion/search-suggestion.html", "widgets/options/options.html", "widgets/templates/feed.html", "widgets/templates/menu.html", "config/skin/widgets/com.avira.dnt/widget/background.html", "config/skin/widgets/com.avira.dnt/widget/button.html", "config/skin/widgets/com.avira.dnt/widget/window.html", "config/skin/widgets/com.avira.dnt/widget/blank.html", "config/skin/widgets/com.avira.dnt/widget/blank.gif", "config/skin/widgets/toolbar-options/options.html" ]
},
"path": "aaaaacalgebmfelllfiaoknifldpngjh\\25.62088_0",
"state": 0,
"was_installed_by_default": false
},
"ahfgeienlihckogmohjhadlkjgocpleb": {
"active_permissions": {
"api": [ "management", "webstorePrivate" ]
},
"app_launcher_ordinal": "n",
"creation_flags": 1,
"from_bookmark": false,
"from_webstore": false,
"install_time": "13021028681513658",
"location": 5,
"manifest": {
"app": {
"launch": {
"web_url": "https://chrome.google.com/webstore"
},
"urls": [ "https://chrome.google.com/webstore" ]
},
"description": "Chrome Web Store",
"icons": {
"128": "webstore_icon_128.png",
"16": "webstore_icon_16.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB",
Store
"permissions": [ "webstorePrivate", "management" ],
"version": "0.2"
},
"page_ordinal": "n",
"path": "C:\\Program Files\\Google\\Chrome\\Application\\28.0.1500.95\\resources\\web_store") - "name": "Google",
"new_tab_url": "{google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding}",
"prepopulate_id": "1",
"search_terms_replacement_key": "espv",
"search_url": "{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}",
"search_url_post_params": "",
"suggest_url": "{google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}",
"suggest_url_post_params": ""
},
"distribution": {
"make_chrome_default_for_user": true
},
"download": {
"directory_upgrade": true,
"extensions_to_open": "adh"
},
"extensions": {
"alerts": {
"initialized": true
},
"autoupdate": {
"last_check": "13030296089960096",
"next_check": "13030881118139910"
},
"blacklistupdate": {
"lastpingday": "13029408213072911",
"version": "0.0.0.149"
},
"chrome_url_overrides": {
"bookmarks": [ "chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html" ]
},
"known_disabled": [ "aaaaacalgebmfelllfiaoknifldpngjh" ],
"last_chrome_version": "31.0.1650.63",
"settings": {
"aaaaacalgebmfelllfiaoknifldpngjh": {
"ack_external": true,
"active_permissions": {
"api": [ "bookmarks", "contentSettings", "contextMenus", "cookies", "geolocation", "history", "idle", "management", "notifications", "plugin", "tabs", "unlimitedStorage", "webRequest", "webRequestBlocking", "webRequestInternal" ],
"explicit_host": [ "chrome://favicon/*", "hxxp://*/*", "https://*/*" ],
"scriptable_host": [ "*://*.ask.com/", "*://*.bagsbuy.com/*", "*://*.childrenschorus.org/*", "*://*.csaa.com/*", "*://*.facebook.com/*", "*://*.google.com/*", "*://*.google.com/imgres*", "*://*.mercurynews.com/*", "*://*.usnews.com/*", "*://*.wikipedia.org/*", "*://*/*", "*://codesearch.google.com/*", "*://images.google.com/*" ]
},
"creation_flags": 1,
"disable_reasons": 1,
"external_first_run": true,
"from_bookmark": false,
"from_webstore": false,
"initial_keybindings_set": true,
"install_time": "13027963270078932",
"location": 3,
"manifest": {
"background": {
"page": "background/background.html"
},
"browser_action": {
"default_icon": "config/skin/images/logo/logo_19x.png",
"default_popup": "config/skin/chrome-options.html",
"default_title": "Control the Avira SearchFree Toolbar"
},
"chrome_url_overrides": {
"newtab": "config/skin/new-tab-page.html"
},
"content_scripts": [ {
"all_frames": true,
"js": [ "lib/constant.js", "lib/default-config.js", "config/tb-config.js", "lib/protocol.js", "lib/tb-message.js", "lib/widget-messaging.js", "content_script/inline-html.js" ],
"matches": [ "*://*/*" ],
"run_at": "document_end"
}, {
"js": [ "lib/jquery.js", "lib/constant.js", "lib/default-config.js", "config/tb-config.js", "config/widget-config.js", "lib/protocol.js", "lib/tb-message.js", "lib/state-machine.js", "lib/window-position.js", "content_script/positioning.js", "content_script/toolbar.js", "content_script/widget.js", "content_script/injector.js" ],
"matches": [ "*://*/*" ],
"run_at": "document_start"
}, {
"css": [ "content_script/hack/facebook.css" ],
"matches": [ "*://*.facebook.com/*" ]
}, {
"css": [ "content_script/hack/relative.css" ],
"matches": [ "*://*.google.com/*", "*://*.ask.com/", "*://*.bagsbuy.com/*", "*://*.csaa.com/*", "*://*.childrenschorus.org/*", "*://*.wikipedia.org/*", "*://*.mercurynews.com/*", "*://*.usnews.com/*" ],
"run_at": "document_start"
}, {
"css": [ "content_script/hack/static.css" ],
"matches": [ "*://*.google.com/imgres*", "*://images.google.com/*", "*://codesearch.google.com/*" ],
"run_at": "document_start"
} ],
"description": "Convenient tools and links to make your browsing more enjoyable",
"icons": {
"128": "config/skin/images/logo/logo_128x.png",
"24": "config/skin/images/logo/logo_24x.png",
"32": "config/skin/images/logo/logo_32x.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbM5MplJHhMMjoBDXypb8IzKcuYt+sISdqFzUsvqHBoB5d3/JMn4RmGiueAkoVFtHyDQ1H5VPKL6Ryt+SabpX/dpx9MaKkqXuiYYsComQYGQ4/tRFD4D9hNRk2RupgJu15UsWXU35gc6LGhW50cjQ9yfH5gih2Pd7RKDyAd+hLiwIDAQAB",
"manifest_version": 2,
"name": "Avira SearchFree Toolbar plus Web Protection",
"permissions": [ "bookmarks", "contextMenus", "contentSettings", "cookies", "geolocation", "history", "idle", "management", "notifications", "tabs", "unlimitedStorage", "webRequest", "webRequestBlocking", "hxxp://*/*", "https://*/*", "chrome://favicon/*", "bookmarks", "contextMenus", "contentSettings", "cookies", "geolocation", "history", "idle", "management", "notifications", "tabs", "unlimitedStorage", "hxxp://*/*", "https://*/*", "chrome://favicon/*", "webRequest", "webRequestBlocking" ],
"plugins": [ {
background/ChromeUtilPlugin.dll,
"public": false
} ],
"update_url": "hxxp://apnmedia.ask.com/media/toolbar/everest/partners/AVIRA-V7/YY/update.xml",
"version": "25.62088",
"web_accessible_resources": [ "config/skin/css/containers.css", "config/skin/toolbar.html", "widgets/search-suggestion/search-suggestion.html", "widgets/options/options.html", "widgets/templates/feed.html", "widgets/templates/menu.html", "config/skin/widgets/com.avira.dnt/widget/background.html", "config/skin/widgets/com.avira.dnt/widget/button.html", "config/skin/widgets/com.avira.dnt/widget/window.html", "config/skin/widgets/com.avira.dnt/widget/blank.html", "config/skin/widgets/com.avira.dnt/widget/blank.gif", "config/skin/widgets/toolbar-options/options.html" ]
},
aaaaacalgebmfelllfiaoknifldpngjh\25.62088_0,
"state": 0,
"was_installed_by_default": false
},
"ahfgeienlihckogmohjhadlkjgocpleb": {
"active_permissions": {
"api": [ "management", "webstorePrivate" ]
},
"app_launcher_ordinal": "n",
"creation_flags": 1,
"from_bookmark": false,
"from_webstore": false,
"install_time": "13021028681513658",
"location": 5,
"manifest": {
"app": {
"launch": {
"web_url": "https://chrome.google.com/webstore"
},
"urls": [ "https://chrome.google.com/webstore" ]
},
"description": "Chrome Web Store",
"icons": {
"128": "webstore_icon_128.png",
"16": "webstore_icon_16.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB",
"name": "Store",
"permissions": [ "webstorePrivate", "management" ],
"version": "0.2"
},
"page_ordinal": "n",
C:\Program Files\Google\Chrome\Application\28.0.1500.95\resources\web_store Keine Datei
CHR Plugin: (Google Docs
"offline_enabled": true,
"update_url": "hxxp://clients2.google.com/service/update2/crx",
"version": "0.5"
},
"page_ordinal": "n",
"path": "aohghmighlieiainnegkcijnfilokake\\0.5_0") - "name": "Google Docs",
"offline_enabled": true,
"update_url": "hxxp://clients2.google.com/service/update2/crx",
"version": "0.5"
},
"page_ordinal": "n",
aohghmighlieiainnegkcijnfilokake\0.5_0 Keine Datei
CHR Plugin: (Google Drive
"offline_enabled": true,
"options_page": "https://drive.google.com/settings",
"permissions": [ "background", "clipboardRead", "clipboardWrite", "notifications", "unlimitedStorage" ],
"update_url": "hxxp://clients2.google.com/service/update2/crx",
"version": "6.3"
},
"page_ordinal": "n",
"path": "apdfllckaahabafndbhieahigkjlhalf\\6.3_0") - "name": "Google Drive",
"offline_enabled": true,
"options_page": "https://drive.google.com/settings",
"permissions": [ "background", "clipboardRead", "clipboardWrite", "notifications", "unlimitedStorage" ],
"update_url": "hxxp://clients2.google.com/service/update2/crx",
"version": "6.3"
},
"page_ordinal": "n",
apdfllckaahabafndbhieahigkjlhalf\6.3_0 Keine Datei
CHR Plugin: (YouTube
"permissions": [ "appNotifications" ],
"update_url": "hxxp://clients2.google.com/service/update2/crx",
"version": "4.2.6"
},
"page_ordinal": "n",
"path": "blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0") - "name": "YouTube",
"permissions": [ "appNotifications" ],
"update_url": "hxxp://clients2.google.com/service/update2/crx",
"version": "4.2.6"
},
"page_ordinal": "n",
blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 Keine Datei
CHR Plugin: (Google-Suche
"update_url": "hxxp://clients2.google.com/service/update2/crx",
"version": "0.0.0.20"
},
"page_ordinal": "n",
"path": "coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0") - "name": "Google-Suche",
"update_url": "hxxp://clients2.google.com/service/update2/crx",
"version": "0.0.0.20"
},
"page_ordinal": "n",
coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 Keine Datei
CHR Plugin: (Bookmark Manager
"permissions": [ "bookmarks", "bookmarkManagerPrivate", "metricsPrivate", "systemPrivate", "tabs", "chrome://favicon/", "chrome://resources/" ],
"version": "0.1"
},
"path": "C:\\Program Files\\Google\\Chrome\\Application\\28.0.1500.95\\resources\\bookmark_manager",
"was_installed_by_default": false
},
"ennkphjdgehloodpbhlhldgbnhmacadg": {
"active_permissions": {
"api": [ "app.currentWindowInternal", "app.runtime", "app.window" ],
"explicit_host": [ "chrome://settings-frame/*" ]
},
"creation_flags": 1,
"events": [ "app.runtime.onLaunched" ],
"from_bookmark": false,
"from_webstore": false,
"install_time": "13021028681513658",
"location": 5,
"manifest": {
"app": {
"background": {
"scripts": [ "settings_app.js" ]
}
},
"description": "Settings",
"display_in_launcher": false,
"icons": {
"128": "settings_app_icon_128.png",
"16": "settings_app_icon_16.png",
"32": "settings_app_icon_32.png",
"48": "settings_app_icon_48.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB",
"manifest_version": 2,
Settings
"permissions": [ "chrome://settings-frame/" ],
"version": "0.2"
},
"path": "C:\\Program Files\\Google\\Chrome\\Application\\28.0.1500.95\\resources\\settings_app",
"running": false,
"was_installed_by_default": false
},
"gfdkimpbcpahaombhbimeihdjnejgicl": {
"active_permissions": {
"api": [ "app.currentWindowInternal", "app.runtime", "app.window", "feedbackPrivate" ],
"explicit_host": [ "chrome://resources/*" ]
},
"creation_flags": 1,
"events": [ "feedbackPrivate.onFeedbackRequested" ],
"from_bookmark": false,
"from_webstore": false,
"initial_keybindings_set": true,
"install_time": "13029438503225686",
"location": 5,
"manifest": {
"app": {
"background": {
"scripts": [ "js/event_handler.js" ]
},
"content_security_policy": "default-src 'none'; script-src 'self' chrome://resources; style-src 'unsafe-inline' *; img-src *; media-src 'self'"
},
"description": "User feedback extension",
"display_in_launcher": false,
"display_in_new_tab_page": false,
"icons": {
"32": "images/icon32.png",
"64": "images/icon64.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMZElzFX2J1g1nRQ/8S3rg/1CjFyDltWOxQg+9M8aVgNVxbutEWFQz+oQzIP9BB67mJifULgiv12ToFKsae4NpEUR8sPZjiKDIHumc6pUdixOm8SJ5Rs16SMR6+VYxFUjlVW+5CA3IILptmNBxgpfyqoK0qRpBDIhGk1KDEZ4zqQIDAQAB",
"manifest_version": 2,
Feedback
"permissions": [ "feedbackPrivate", "chrome://resources/" ],
"version": "1.0"
},
"path": "C:\\Program Files\\Google\\Chrome\\Application\\31.0.1650.57\\resources\\feedback",
"running": false,
"was_installed_by_default": false
},
"mfehgcgbbipciphmccgaenjidiccnmng": {
"active_permissions": {
"api": [ "cloudPrintPrivate" ]
},
"creation_flags": 1,
"from_bookmark": false,
"from_webstore": false,
"install_time": "13021028681513658",
"location": 5,
"manifest": {
"app": {
"launch": {
"web_url": "https://www.google.com/cloudprint"
},
"urls": [ "https://www.google.com/cloudprint/enable_chrome_connector" ]
},
"description": "Cloud Print",
"display_in_launcher": false,
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB",
Cloud Print
"permissions": [ "cloudPrintPrivate" ],
"version": "0.1"
},
"path": "C:\\Program Files\\Google\\Chrome\\Application\\28.0.1500.95\\resources\\cloud_print",
"was_installed_by_default": false
},
"mgndgikekgjfcpckkfioiadnlibdjbkf": {
"app_launcher_ordinal": "t",
"creation_flags": 1,
"from_bookmark": false,
"from_webstore": false,
"install_time": "13021028681513658",
"location": 5,
"manifest": {
"app": {
"launch": {
"web_url": "hxxp://THIS-WILL-BE-REPLACED"
}
},
"description": "Chrome as an app",
"display_in_launcher": true,
"display_in_new_tab_page": false,
"icons": {
"128": "product_logo_128.png",
"16": "product_logo_16.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNuYLEQ1QPMcc5HfWI/9jiEf6FdJWqEtgRmIeI7qtjPLBM5oje+Ny2E2mTAhou5qdJiO2CHWdU1DQXY2F7Zu2gZaKZgHLfK4WimHxUT5Xd9/aro/R9PCzjguM1BLusiWYc9xlj1IsZpyiN1hcjU7SCnBhv1feQlv2WSB5KRiXwhQIDAQAB",
Chrome
"version": "0.1"
},
"page_ordinal": "n",
"path": "C:\\Program Files\\Google\\Chrome\\Application\\28.0.1500.95\\resources\\chrome_app") - "name": "Bookmark Manager",
"permissions": [ "bookmarks", "bookmarkManagerPrivate", "metricsPrivate", "systemPrivate", "tabs", "chrome://favicon/", "chrome://resources/" ],
"version": "0.1"
},
C:\Program Files\Google\Chrome\Application\28.0.1500.95\resources\bookmark_manager,
"was_installed_by_default": false
},
"ennkphjdgehloodpbhlhldgbnhmacadg": {
"active_permissions": {
"api": [ "app.currentWindowInternal", "app.runtime", "app.window" ],
"explicit_host": [ "chrome://settings-frame/*" ]
},
"creation_flags": 1,
"events": [ "app.runtime.onLaunched" ],
"from_bookmark": false,
"from_webstore": false,
"install_time": "13021028681513658",
"location": 5,
"manifest": {
"app": {
"background": {
"scripts": [ "settings_app.js" ]
}
},
"description": "Settings",
"display_in_launcher": false,
"icons": {
"128": "settings_app_icon_128.png",
"16": "settings_app_icon_16.png",
"32": "settings_app_icon_32.png",
"48": "settings_app_icon_48.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB",
"manifest_version": 2,
"name": "Settings",
"permissions": [ "chrome://settings-frame/" ],
"version": "0.2"
},
C:\Program Files\Google\Chrome\Application\28.0.1500.95\resources\settings_app,
"running": false,
"was_installed_by_default": false
},
"gfdkimpbcpahaombhbimeihdjnejgicl": {
"active_permissions": {
"api": [ "app.currentWindowInternal", "app.runtime", "app.window", "feedbackPrivate" ],
"explicit_host": [ "chrome://resources/*" ]
},
"creation_flags": 1,
"events": [ "feedbackPrivate.onFeedbackRequested" ],
"from_bookmark": false,
"from_webstore": false,
"initial_keybindings_set": true,
"install_time": "13029438503225686",
"location": 5,
"manifest": {
"app": {
"background": {
"scripts": [ "js/event_handler.js" ]
},
"content_security_policy": "default-src 'none'; script-src 'self' chrome://resources; style-src 'unsafe-inline' *; img-src *; media-src 'self'"
},
"description": "User feedback extension",
"display_in_launcher": false,
"display_in_new_tab_page": false,
"icons": {
"32": "images/icon32.png",
"64": "images/icon64.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMZElzFX2J1g1nRQ/8S3rg/1CjFyDltWOxQg+9M8aVgNVxbutEWFQz+oQzIP9BB67mJifULgiv12ToFKsae4NpEUR8sPZjiKDIHumc6pUdixOm8SJ5Rs16SMR6+VYxFUjlVW+5CA3IILptmNBxgpfyqoK0qRpBDIhGk1KDEZ4zqQIDAQAB",
"manifest_version": 2,
"name": "Feedback",
"permissions": [ "feedbackPrivate", "chrome://resources/" ],
"version": "1.0"
},
C:\Program Files\Google\Chrome\Application\31.0.1650.57\resources\feedback,
"running": false,
"was_installed_by_default": false
},
"mfehgcgbbipciphmccgaenjidiccnmng": {
"active_permissions": {
"api": [ "cloudPrintPrivate" ]
},
"creation_flags": 1,
"from_bookmark": false,
"from_webstore": false,
"install_time": "13021028681513658",
"location": 5,
"manifest": {
"app": {
"launch": {
"web_url": "https://www.google.com/cloudprint"
},
"urls": [ "https://www.google.com/cloudprint/enable_chrome_connector" ]
},
"description": "Cloud Print",
"display_in_launcher": false,
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB",
"name": "Cloud Print",
"permissions": [ "cloudPrintPrivate" ],
"version": "0.1"
},
C:\Program Files\Google\Chrome\Application\28.0.1500.95\resources\cloud_print,
"was_installed_by_default": false
},
"mgndgikekgjfcpckkfioiadnlibdjbkf": {
"app_launcher_ordinal": "t",
"creation_flags": 1,
"from_bookmark": false,
"from_webstore": false,
"install_time": "13021028681513658",
"location": 5,
"manifest": {
"app": {
"launch": {
"web_url": "hxxp://THIS-WILL-BE-REPLACED"
}
},
"description": "Chrome as an app",
"display_in_launcher": true,
"display_in_new_tab_page": false,
"icons": {
"128": "product_logo_128.png",
"16": "product_logo_16.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNuYLEQ1QPMcc5HfWI/9jiEf6FdJWqEtgRmIeI7qtjPLBM5oje+Ny2E2mTAhou5qdJiO2CHWdU1DQXY2F7Zu2gZaKZgHLfK4WimHxUT5Xd9/aro/R9PCzjguM1BLusiWYc9xlj1IsZpyiN1hcjU7SCnBhv1feQlv2WSB5KRiXwhQIDAQAB",
"name": "Chrome",
"version": "0.1"
},
"page_ordinal": "n",
C:\Program Files\Google\Chrome\Application\28.0.1500.95\resources\chrome_app Keine Datei
CHR Plugin: (Google Wallet
"oauth2": {
"auto_approve": true,
"client_id": "203784468217.apps.googleusercontent.com",
"scopes": [ "https://www.googleapis.com/auth/sierra", "https://www.googleapis.com/auth/sierrasandbox" ]
},
"permissions": [ "identity", "webview", "https://checkout.google.com/", "https://sandbox.google.com/checkout/", "https://www.google.com/" ],
"update_url": "https://clients2.google.com/service/update2/crx",
"version": "0.0.5.0"
},
"path": "nmmhkkegccagdldgiimedpiccmgmieda\\0.0.5.0_0",
"running": false,
"state": 1,
"was_installed_by_default": false
},
"pjkljhegncpnkpknbcohdijeoejaedia": {
"ack_external": true,
"active_permissions": {
"api": [ "notifications" ]
},
"app_launcher_ordinal": "z",
"creation_flags": 137,
"from_bookmark": false,
"from_webstore": true,
"granted_permissions": {
"api": [ "notifications" ]
},
"install_time": "13021028701353303",
"lastpingday": "13030272000136096",
"location": 1,
"manifest": {
"app": {
"launch": {
"container": "tab",
"web_url": "https://mail.google.com/mail/ca"
},
"urls": [ "*://mail.google.com/mail/ca" ]
},
"current_locale": "de",
"default_locale": "en",
"description": "Schneller E-Mail-Dienst mit Suchfunktion und wenig Spam.",
"icons": {
"128": "128.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB",
Google Mail
"options_page": "https://mail.google.com/mail/ca/#settings",
"permissions": [ "notifications" ],
"update_url": "hxxp://clients2.google.com/service/update2/crx",
"version": "7"
},
"page_ordinal": "n",
"path": "pjkljhegncpnkpknbcohdijeoejaedia\\7_0") - "name": "Google Wallet",
"oauth2": {
"auto_approve": true,
"client_id": "203784468217.apps.googleusercontent.com",
"scopes": [ "https://www.googleapis.com/auth/sierra", "https://www.googleapis.com/auth/sierrasandbox" ]
},
"permissions": [ "identity", "webview", "https://checkout.google.com/", "https://sandbox.google.com/checkout/", "https://www.google.com/" ],
"update_url": "https://clients2.google.com/service/update2/crx",
"version": "0.0.5.0"
},
nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0,
"running": false,
"state": 1,
"was_installed_by_default": false
},
"pjkljhegncpnkpknbcohdijeoejaedia": {
"ack_external": true,
"active_permissions": {
"api": [ "notifications" ]
},
"app_launcher_ordinal": "z",
"creation_flags": 137,
"from_bookmark": false,
"from_webstore": true,
"granted_permissions": {
"api": [ "notifications" ]
},
"install_time": "13021028701353303",
"lastpingday": "13030272000136096",
"location": 1,
"manifest": {
"app": {
"launch": {
"container": "tab",
"web_url": "https://mail.google.com/mail/ca"
},
"urls": [ "*://mail.google.com/mail/ca" ]
},
"current_locale": "de",
"default_locale": "en",
"description": "Schneller E-Mail-Dienst mit Suchfunktion und wenig Spam.",
"icons": {
"128": "128.png"
},
"key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB",
"name": "Google Mail",
"options_page": "https://mail.google.com/mail/ca/#settings",
"permissions": [ "notifications" ],
"update_url": "hxxp://clients2.google.com/service/update2/crx",
"version": "7"
},
"page_ordinal": "n",
pjkljhegncpnkpknbcohdijeoejaedia\7_0 Keine Datei
CHR Plugin: (Shockwave Flash
"path": "C:\\Program Files\\Google\\Chrome\\Application\\31.0.1650.63\\PepperFlash\\pepflashplayer.dll") - "name": "Shockwave Flash",
C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll Keine Datei
CHR Plugin: (Chrome Remote Desktop Viewer
"path": "internal-remoting-viewer") - "name": "Chrome Remote Desktop Viewer",
internal-remoting-viewer
CHR Plugin: (Native Client
"path": "C:\\Program Files\\Google\\Chrome\\Application\\31.0.1650.63\\ppGoogleNaClPluginChrome.dll") - "name": "Native Client",
C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll Keine Datei
CHR Plugin: (Chrome PDF Viewer
"path": "C:\\Program Files\\Google\\Chrome\\Application\\31.0.1650.63\\pdf.dll") - "name": "Chrome PDF Viewer",
C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll Keine Datei
CHR Plugin: (Adobe Acrobat
"path": "C:\\Program Files\\Adobe\\Reader 10.0\\Reader\\Browser\\nppdf32.dll") - "name": "Adobe Acrobat",
C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll Keine Datei
CHR Plugin: (Cosmo Player 2.1.1 from PLATINUM technology, inc.
"path": "D:\\MozillaFirefox\\plugins\\npcosmop211.dll") - "name": "Cosmo Player 2.1.1 from PLATINUM technology, inc.",
D:\MozillaFirefox\plugins\npcosmop211.dll Keine Datei
CHR Plugin: (Winamp Application Detector
"path": "D:\\MozillaFirefox\\plugins\\npwachk.dll") - "name": "Winamp Application Detector",
D:\MozillaFirefox\plugins\npwachk.dll Keine Datei
CHR Plugin: (Microsoft Office 2010
"path": "C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL") - "name": "Microsoft Office 2010",
C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL Keine Datei
CHR Plugin: (Microsoft Office 2010
"path": "C:\\PROGRA~1\\MICROS~3\\Office14\\NPSPWRAP.DLL") - "name": "Microsoft Office 2010",
C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL Keine Datei
CHR Plugin: (AmazonMP3DownloaderPlugin
"path": "C:\\Program Files\\Amazon\\MP3 Downloader\\npAmazonMP3DownloaderPlugin10174.dll") - "name": "AmazonMP3DownloaderPlugin",
C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll Keine Datei
CHR Plugin: (Google Update
"path": "C:\\Program Files\\Google\\Update\\1.3.21.153\\npGoogleUpdate3.dll") - "name": "Google Update",
C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll Keine Datei
CHR Plugin: (Java(TM) Platform SE 7 U10
"path": "C:\\Program Files\\Java\\jre7\\bin\\plugin2\\npjp2.dll") - "name": "Java(TM) Platform SE 7 U10",
C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll Keine Datei
CHR Plugin: (NVIDIA 3D Vision
"path": "C:\\Program Files\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll") - "name": "NVIDIA 3D Vision",
C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll Keine Datei
CHR Plugin: (NVIDIA 3D VISION
"path": "C:\\Program Files\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll") - "name": "NVIDIA 3D VISION",
C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll Keine Datei
CHR Plugin: (Shockwave Flash
"path": "C:\\Windows\\system32\\Macromed\\Flash\\NPSWF32_11_7_700_202.dll") - "name": "Shockwave Flash",
C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll Keine Datei
CHR Plugin: (Java Deployment Toolkit 7.0.100.18
"path": "C:\\Windows\\system32\\npDeployJava1.dll") - "name": "Java Deployment Toolkit 7.0.100.18",
C:\Windows\system32\npDeployJava1.dll Keine Datei
CHR Plugin: (Silverlight Plug-In
"path": "c:\\Program Files\\Microsoft Silverlight\\5.1.20513.0\\npctrl.dll") - "name": "Silverlight Plug-In",
c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll Keine Datei
CHR Plugin: (Windows Presentation Foundation
"path": "c:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Windows Presentation Foundation\\NPWPF.dll") - "name": "Windows Presentation Foundation",
c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll Keine Datei
CHR Profile: C:\Users\******\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [887128 2015-07-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [461672 2015-08-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [461672 2015-08-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1212048 2015-08-26] (Avira Operations GmbH & Co. KG)
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [Datei ist nicht signiert]
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [Datei ist nicht signiert]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [Datei ist nicht signiert]
R2 Motorola Device Manager; C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [121144 2013-03-25] (Motorola Mobility LLC)
R2 PST Service; C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) [Datei ist nicht signiert]
S3 SandraAgentSrv; D:\SiSoftware_Sandra_ Lite_2013a\RpcAgentSrv.exe [68760 2008-12-07] (SiSoftware) [Datei ist nicht signiert]
S3 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [212480 2007-02-08] (Nokia.) [Datei ist nicht signiert]
R2 TomTomHOMEService; D:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [92632 2012-12-05] (TomTom)
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
R2 ViscosityService; d:\Program Files\Suissl\Viscosity\ViscosityService.exe [26736 2012-04-26] (SparkLabs)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-07-25] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-07-25] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-07] (Avira Operations GmbH & Co. KG)
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [170552 2012-09-24] (Broadcom Corporation.)
S3 btwampfl; C:\Windows\system32\drivers\btwampfl.sys [507704 2012-07-03] (Broadcom Corporation.) [Datei ist nicht signiert]
R3 EMSCR; C:\Windows\System32\DRIVERS\EMS7SK.sys [67584 2007-04-10] (ENE Technology Inc.)
R3 ESDCR; C:\Windows\System32\DRIVERS\ESD7SK.sys [46592 2007-04-10] (ENE Technology Inc.)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [Datei ist nicht signiert]
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [350720 2010-03-31] (Realtek Semiconductor Corporation )
S3 SANDRA; D:\SiSoftware_Sandra_ Lite_2013a\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware)
R0 speedfan; C:\Windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-05-27] (Avira Operations GmbH & Co. KG)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2013-11-26] (Samsung Electronics) [Datei ist nicht signiert]
S3 USB28xxBGA; C:\Windows\System32\DRIVERS\emBDA.sys [654848 2012-06-20] (eMPIA Technology, Inc.)
S3 USB28xxOEM; C:\Windows\System32\DRIVERS\emOEM.sys [1090816 2012-06-20] (eMPIA Technology, Inc.)
S3 visctap0901; C:\Windows\System32\DRIVERS\visctap0901.sys [33760 2012-04-26] (The OpenVPN Project)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-09-06 01:27 - 2015-09-06 01:27 - 00059009 _____ C:\Users\******\Desktop\FRST.txt
2015-09-06 01:27 - 2015-09-06 01:27 - 00000000 ____D C:\FRST
2015-09-06 01:26 - 2015-09-06 01:25 - 01690624 _____ (Farbar) C:\Users\******\Desktop\FRST.exe
2015-09-06 01:26 - 2015-09-06 01:24 - 00000474 _____ C:\Users\******\Desktop\defogger_disable.log
2015-09-06 01:26 - 2015-09-06 01:22 - 00050477 _____ C:\Users\******\Desktop\Defogger.exe
2015-09-06 01:25 - 2015-09-06 01:25 - 01690624 _____ (Farbar) C:\Users\******\Downloads\FRST.exe
2015-09-06 01:23 - 2015-09-06 01:24 - 00000474 _____ C:\Users\******\Downloads\defogger_disable.log
2015-09-06 01:23 - 2015-09-06 01:23 - 00000000 _____ C:\Users\******\defogger_reenable
2015-09-06 01:22 - 2015-09-06 01:22 - 00050477 _____ C:\Users\******\Downloads\Defogger.exe
2015-09-06 01:08 - 2015-09-06 01:16 - 00000000 ____D C:\Users\******\Desktop\trojaner_board_anleitung
2015-09-06 00:32 - 2015-09-06 00:36 - 00000000 ____D C:\AdwCleaner
2015-09-05 23:47 - 2015-09-05 23:47 - 00000000 ____D C:\Users\******\Desktop\Neuer Ordner (2)
2015-09-05 23:24 - 2015-09-05 23:24 - 00002176 _____ C:\Users\Public\Desktop\Altova XMLSpy 2015.lnk
2015-09-05 23:24 - 2015-09-05 23:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Altova MissionKit 2015
2015-09-05 22:43 - 2015-09-05 22:50 - 100689984 _____ (Altova GmbH) C:\Users\******\Downloads\XMLSpyEnt2015_DE.exe
2015-09-05 22:40 - 2015-09-05 23:28 - 00000000 ____D C:\Users\******\Documents\Altova
2015-09-05 22:40 - 2015-09-05 22:40 - 00002378 _____ C:\Users\Public\Desktop\Altova XMLSpy.lnk
2015-09-05 22:40 - 2015-09-05 22:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Altova MissionKit 2010
2015-09-05 22:38 - 2015-09-05 23:23 - 00000000 ____D C:\Program Files\Common Files\Altova
2015-09-05 22:38 - 2015-09-05 23:20 - 00000000 ____D C:\Program Files\Altova
2015-09-05 22:19 - 2015-09-05 23:22 - 00000000 ____D C:\ProgramData\Altova
2015-09-01 05:04 - 2015-09-01 05:06 - 00000000 ____D C:\Users\******\AppData\Roaming\DJJava
2015-09-01 05:03 - 2015-09-01 05:03 - 00001527 _____ C:\Users\Public\Desktop\DJ Java Decompiler 3.12.lnk
2015-09-01 05:03 - 2015-09-01 05:03 - 00001527 _____ C:\ProgramData\Microsoft\Windows\Start Menu\DJ Java Decompiler 3.12.lnk
2015-09-01 05:03 - 2015-09-01 05:03 - 00000000 ____D C:\ProgramData\TEMP
2015-09-01 05:03 - 2015-09-01 05:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DJ Java Decompiler v.3.12.12.100
2015-09-01 05:00 - 2015-09-01 05:00 - 09262588 _____ C:\Users\******\Downloads\djdec312.zip
2015-09-01 00:06 - 2015-09-01 00:06 - 02954013 _____ C:\Users\******\Downloads\2015_08_31__SandroKoch__Bewerbungsunterlagen.zip
2015-08-31 21:12 - 2015-08-31 21:12 - 00000000 ____D C:\Users\******\AppData\Roaming\QuickScan
2015-08-31 21:10 - 2015-08-31 21:10 - 02870984 _____ (ESET) C:\Users\******\Downloads\esetsmartinstaller_deu.exe
2015-08-29 22:01 - 2015-08-29 22:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-29 22:01 - 2015-08-29 22:01 - 00000000 ____D C:\Program Files\Common Files\Skype
2015-08-26 11:02 - 2015-08-26 11:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-08-20 10:38 - 2015-08-15 01:03 - 12386816 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-20 10:38 - 2015-08-15 00:56 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-20 10:38 - 2015-08-15 00:55 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-17 04:14 - 2015-08-17 04:15 - 00491359 _____ C:\Users\******\Downloads\Geburtstag.zip
2015-08-17 03:57 - 2015-08-17 05:19 - 00009613 _____ C:\Users\******\Documents\Uebersicht_Geburtstag.xlsx
2015-08-13 22:30 - 2015-08-13 22:44 - 00000000 ____D C:\Users\******\Desktop\SE
2015-08-13 03:52 - 2015-07-21 22:55 - 01206192 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-13 03:52 - 2015-07-21 18:07 - 03605440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-08-13 03:52 - 2015-07-21 18:07 - 03553216 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-13 03:52 - 2015-07-21 18:07 - 00140224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys
2015-08-13 03:52 - 2015-07-21 18:07 - 00056256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-13 03:52 - 2015-07-21 18:03 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll
2015-08-13 03:52 - 2015-07-21 18:03 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-13 03:52 - 2015-07-21 18:03 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-13 03:51 - 2015-07-31 21:27 - 00103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 03:50 - 2015-07-09 16:20 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2015-08-13 03:49 - 2015-07-10 21:37 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-13 03:47 - 2015-07-11 17:56 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-13 03:24 - 2015-07-18 18:03 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-13 03:21 - 2015-07-10 21:37 - 01402368 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-13 03:21 - 2015-07-10 21:37 - 01253376 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-13 03:18 - 2015-08-01 00:08 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-13 03:18 - 2015-07-31 23:46 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-08-13 03:18 - 2015-07-31 23:46 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-08-13 03:18 - 2015-07-31 23:46 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-08-13 03:18 - 2015-07-31 23:46 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-08-13 03:18 - 2015-07-31 22:41 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-13 03:18 - 2015-07-31 22:40 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-08-13 03:18 - 2015-07-31 22:35 - 00682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-08-13 03:18 - 2015-07-31 22:33 - 02066944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-13 03:18 - 2015-07-31 22:33 - 01072640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-13 03:18 - 2015-07-31 22:33 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-13 03:18 - 2015-07-31 22:33 - 00297472 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-13 03:17 - 2015-07-09 16:25 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-13 03:17 - 2015-07-09 16:25 - 00151040 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-13 03:17 - 2015-07-01 17:57 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-12 10:17 - 2015-07-22 22:54 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-12 10:17 - 2015-07-22 22:51 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-12 10:17 - 2015-07-22 22:47 - 09751040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-12 10:17 - 2015-07-22 22:46 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-12 10:17 - 2015-07-22 22:46 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-12 10:17 - 2015-07-22 22:45 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-12 10:17 - 2015-07-22 22:45 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-08-12 10:17 - 2015-07-22 22:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-12 10:17 - 2015-07-22 22:44 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-12 10:17 - 2015-07-22 22:44 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-12 10:17 - 2015-07-22 22:44 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-12 10:17 - 2015-07-22 22:44 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-12 10:17 - 2015-07-22 22:43 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-12 10:17 - 2015-07-22 22:43 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-12 10:17 - 2015-07-22 22:43 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-12 10:17 - 2015-07-22 22:43 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-08-12 10:17 - 2015-07-22 22:43 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-08-12 10:17 - 2015-07-22 22:43 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-08-12 10:17 - 2015-07-22 22:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-08 08:48 - 2015-08-08 08:48 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Samsung
2015-08-08 08:48 - 2015-08-08 08:48 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Motorola Mobility
2015-08-08 08:48 - 2015-08-08 08:48 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Apple Computer
2015-08-08 08:48 - 2015-08-08 08:48 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-09-06 01:23 - 2012-12-16 18:13 - 00000000 ____D C:\Users\******
2015-09-06 01:15 - 2006-11-02 14:52 - 01884203 _____ C:\Windows\WindowsUpdate.log
2015-09-06 00:51 - 2015-07-04 11:07 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-06 00:44 - 2013-08-15 10:17 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-06 00:43 - 2015-04-07 10:32 - 00000000 ____D C:\Users\******\AppData\Roaming\FileAdvisor
2015-09-06 00:39 - 2013-08-15 10:16 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-06 00:39 - 2013-06-19 19:16 - 00000000 ____D C:\Temp
2015-09-06 00:39 - 2012-12-16 19:38 - 00000000 ____D C:\ProgramData\NVIDIA
2015-09-06 00:39 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-06 00:39 - 2006-11-02 14:47 - 00003664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-06 00:39 - 2006-11-02 14:47 - 00003664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-06 00:37 - 2013-03-24 11:53 - 00000012 _____ C:\Windows\bthservsdp.dat
2015-09-06 00:37 - 2006-11-02 15:01 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-09-05 23:41 - 2006-11-02 12:33 - 01614244 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-05 22:36 - 2014-01-09 03:14 - 00000000 ____D C:\Windows\Downloaded Installations
2015-09-04 06:41 - 2012-12-17 00:02 - 00000000 ____D C:\Users\******\AppData\Roaming\Mozilla
2015-09-02 08:55 - 2013-08-15 10:20 - 00001965 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-31 22:54 - 2013-08-20 20:50 - 00015000 _____ C:\fpRedmon.log
2015-08-31 22:54 - 2012-12-22 15:55 - 00000000 ____D C:\Users\******\AppData\Local\FreePDF_XP
2015-08-29 22:07 - 2012-12-23 00:27 - 00000000 ____D C:\Users\******\AppData\Roaming\Skype
2015-08-29 22:01 - 2014-03-16 09:43 - 00000000 ___RD C:\Program Files\Skype
2015-08-29 22:01 - 2012-12-23 00:27 - 00000000 ____D C:\ProgramData\Skype
2015-08-26 11:02 - 2015-05-07 21:13 - 00001861 _____ C:\Users\Public\Desktop\Avira Antivirus.lnk
2015-08-20 21:05 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2015-08-13 04:00 - 2006-11-02 14:47 - 00376096 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-13 03:57 - 2013-06-20 16:03 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-13 03:56 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2015-08-13 03:52 - 2013-06-20 16:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-13 03:50 - 2012-12-22 10:35 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 03:45 - 2013-08-15 04:59 - 00000000 ____D C:\Windows\system32\MRT
2015-08-13 03:26 - 2006-11-02 12:24 - 129304528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-08-12 10:39 - 2015-06-12 22:09 - 00000000 ____D C:\Users\******\Desktop\Neuer Ordner
2015-08-12 09:51 - 2012-12-26 05:27 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-08-12 09:51 - 2012-12-26 05:27 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-08-09 09:23 - 2012-12-16 18:14 - 00000946 _____ C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-08-08 08:48 - 2012-12-22 21:29 - 00008224 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-08 08:48 - 2012-12-22 21:28 - 00000946 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-08-08 08:48 - 2006-11-02 12:23 - 00000165 _____ C:\Windows\win.ini
2015-08-08 08:00 - 2015-04-07 08:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Type Advisor
2015-08-08 08:00 - 2015-04-07 08:00 - 00000000 ____D C:\Program Files\File Type Advisor
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2013-01-25 07:39 - 2014-03-16 12:32 - 0000312 _____ () C:\Users\******\AppData\Roaming\com.thesparklabs.ViscosityWin.plist
2012-12-17 00:49 - 2014-01-21 03:25 - 13115392 _____ () C:\Users\******\AppData\Roaming\Sandra.mdb
2013-01-23 06:49 - 2013-01-23 06:49 - 0000219 ____H () C:\Users\******\AppData\Local\CacheConfig.dat
2012-12-16 18:13 - 2014-06-28 07:36 - 0001356 _____ () C:\Users\******\AppData\Local\d3d9caps.dat
2012-12-24 14:56 - 2013-07-10 20:00 - 0008192 _____ () C:\Users\******\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-12-16 19:38 - 2012-12-16 20:09 - 0027934 _____ () C:\ProgramData\nvModes.001
2012-12-16 19:38 - 2012-12-16 20:09 - 0027934 _____ () C:\ProgramData\nvModes.dat
Einige Dateien in TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\******\AppData\Local\Temp\aacdec.exe
C:\Users\******\AppData\Local\Temp\amrdec.exe
C:\Users\******\AppData\Local\Temp\avgnt.exe
C:\Users\******\AppData\Local\Temp\BingBarSetup-Partner.exe
C:\Users\******\AppData\Local\Temp\cfcigjgz.dll
C:\Users\******\AppData\Local\Temp\FreemakeVideoConverterFull.exe
C:\Users\******\AppData\Local\Temp\InstallAsk.exe
C:\Users\******\AppData\Local\Temp\lj1018-HB-pd-win32-gep.exe
C:\Users\******\AppData\Local\Temp\mdi064.dll
C:\Users\******\AppData\Local\Temp\MotoCast_Installer_2.0309.exe
C:\Users\******\AppData\Local\Temp\mp3el.exe
C:\Users\******\AppData\Local\Temp\MSETUP4.EXE
C:\Users\******\AppData\Local\Temp\NEventMessages.dll
C:\Users\******\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\******\AppData\Local\Temp\nvStInst.exe
C:\Users\******\AppData\Local\Temp\ose00000.exe
C:\Users\******\AppData\Local\Temp\SetupDJ312RN7.exe
C:\Users\******\AppData\Local\Temp\sfamcc00001.dll
C:\Users\******\AppData\Local\Temp\sfamcc00002.dll
C:\Users\******\AppData\Local\Temp\sfextra.dll
C:\Users\******\AppData\Local\Temp\SkypeSetup.exe
C:\Users\******\AppData\Local\Temp\sp-downloader.exe
C:\Users\******\AppData\Local\Temp\sqlite3.dll
C:\Users\******\AppData\Local\Temp\wpsetup.exe
C:\Users\******\AppData\Local\Temp\_isED2B.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-09-06 00:48
==================== Ende vom FRST.txt ============================ |