Thagor99 | 14.08.2013 10:13 | Liste der Anhänge anzeigen (Anzahl: 1) Hallo Cosinus,
das nenne ich mal eine hervorragende Response-Zeit!!!!!!
1. FRST-Scan durchgeführt. Txt-Dateien sind angefügt.
2. Ich habe keine anderen Virenscanner
3. Ich habe die AVG-Logs gefunden. Es gibt nur ein TXT-Log von gestern und eine Reihe von heute morgen. Der Rest sind andere Formate (1-Datei etc.). ICh poste erstmal nur die Datei von gestern, da die von heute morgen z.T. sehr groß sind. Die Übersicht Poste ich als Jpeg.
LG
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-08-2013
Ran by Admin (administrator) on 14-08-2013 10:10:24
Running from C:\Users\Admin\Desktop
Windows 8 Pro (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
() C:\Users\Admin\AppData\Local\Temp\OCS\Downloads\0674e23d6502b36621d489f1b4fbd22a\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(REINER SCT) C:\WINDOWS\SysWOW64\cjpcsc.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\svchost.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
() C:\WINDOWS\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Dropbox, Inc.) C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\sysWow64\SearchProtocolHost.exe
(Microsoft Corporation) C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16613_none_6273bd8950d6cae2\TiWorker.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [362032 2009-10-31] (Acronis)
HKLM\...\Run: [HP Color LaserJet CM1312 MFP Series Fax] - C:\Program Files (x86)\HP\HP Color LaserJet CM1312 MFP Series\hppfaxprintersrv.exe [3700736 2009-09-22] (Hewlett-Packard Company)
HKCU\...\Run: [GoogleChromeAutoLaunch_A5B343D047FD8BD2F268B0EA0F8DBD7C] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [846288 2013-07-25] (Google Inc.)
MountPoints2: {2ec902a0-b878-11e2-bef3-0025223bca07} - "F:\Install.exe"
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AppleSyncNotifier] - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [724536 2012-04-22] (Sony Corporation)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [SMB50StarMoneyRunEntry] - C:\Program Files (x86)\StarMoney Business 5.0\app\oflagent.exe [56528 2012-10-11] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5140952 2009-10-31] (Acronis)
HKLM-x32\...\Run: [HPPQVideo] - "C:\Program Files (x86)\HP\ScheduledLaunch\HP Color LaserJet CM1312 MFP Series\bin\hppschlnch.exe" -r SOFTWARE\Hewlett-Packard\ScheduledLaunch\CLJ_CM1312_MFP_Series -f PQOptimizerVideo.xml -o remindLater [x]
HKLM-x32\...\Run: [ToolBoxFX] - C:\Program Files (x86)\HP\ToolBoxFX\bin\HPTLBXFX.exe [53248 2009-10-22] (HP)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411440 2013-07-01] (AVG Technologies CZ, s.r.o.)
HKU\Marie\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2012-07-26] (Microsoft Corporation)
HKU\UpdatusUser\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2012-07-26] (Microsoft Corporation)
AppInit_DLLs: ,C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL [516096 2012-07-26] ()
AppInit_DLLs-x32: C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll [516096 2012-07-26] ()
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050&SSPV=IEAUTOTB
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://www.searchqu.com/web?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://www.searchqu.com/web?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = hxxp://de.search.yahoo.com/search/?p={searchTerms}&fr=vc_trans_de_8197&type=ds2se&d
SearchScopes: HKLM-x32 - {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = hxxp://de.search.yahoo.com/search/?p={searchTerms}&fr=vc_trans_de_8197&type=ds2se&d
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://www.searchqu.com/web?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms}
SearchScopes: HKCU - DefaultScope {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = hxxp://de.search.yahoo.com/search/?p={searchTerms}&fr=vc_trans_de_8197&type=ds2se&d
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=10588&tt=110911_startpage
SearchScopes: HKCU - {356CB213-4C0E-4557-A09A-F8551E8F7565} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=302398&p={searchTerms}
SearchScopes: HKCU - {520B27EC-C90F-4274-9A9C-6CBBE4DE4E47} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = hxxp://de.search.yahoo.com/search/?p={searchTerms}&fr=vc_trans_de_8197&type=ds2se&d
SearchScopes: HKCU - {80772991-8ABF-42BD-BC74-A78D926820BE} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=IEAUTOBR
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://www.searchqu.com/web?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
Toolbar: HKLM - No Name - !{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
Toolbar: HKLM - No Name - !{25A3A431-30BB-47C8-AD6A-E1063801134F} - No File
Toolbar: HKLM - No Name - !{872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - No Name - !{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
Toolbar: HKLM-x32 - No Name - !{25A3A431-30BB-47C8-AD6A-E1063801134F} - No File
Toolbar: HKLM-x32 - No Name - !{872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: HKLM-x32 {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.2.cab
DPF: HKLM-x32 {A8F2B9BD-A6A0-486A-9744-18920D898429} hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Handler: msdaipp - No CLSID Value -
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Hosts: 192.168.2.154 NPI88A38F
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml
FF Extension: No Name - C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor
Chrome:
=======
CHR RestoreOnStartup: "urls_to_restore_on_startup": null
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.139\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\McChPlg.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (ActiveTouch General Plugin Container) - C:\Users\Admin\AppData\Roaming\Mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U39) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.313\npMcAfeeMss.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Unity Player) - C:\Users\Admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.390.4) - C:\WINDOWS\SysWOW64\npdeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (SiteAdvisor) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.2.1341_0
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_0
CHR Extension: (YouTube Unblocker) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl\0.4.4_0
CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonChrome.crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx
==================== Services (Whitelisted) =================
R2 AddonsHelper; C:\Users\Admin\AppData\Local\Temp\OCS\Downloads\0674e23d6502b36621d489f1b4fbd22a\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe [896512 2013-02-13] ()
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)
R2 cjpcsc; C:\WINDOWS\SysWOW64\cjpcsc.exe [514128 2012-03-19] (REINER SCT)
S3 LoB.IT Service; C:\Program Files (x86)\LoB.IT 2.0\ServerService\ServerService.exe [6566912 2013-08-12] (kommSolutions GmbH)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [120592 2013-05-22] (McAfee, Inc.)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [474168 2012-04-22] (Sony Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-01-24] ()
S2 StarMoney Business 5.0 OnlineUpdate; C:\Program Files (x86)\StarMoney Business 5.0\ouservice\StarMoneyOnlineUpdate.exe [692432 2012-06-28] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [245760 2011-02-18] ()
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20912 2012-10-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206648 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-07-10] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [30568 2012-11-09] (AVG Technologies)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [248632 2013-07-09] (AVG Technologies CZ, s.r.o.)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [27800 2012-09-24] (Avira Operations GmbH & Co. KG)
R3 cjusb; C:\Windows\system32\DRIVERS\cjusb.sys [34672 2011-03-29] (REINER SCT)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 ncplelhp; C:\Windows\system32\DRIVERS\ncplelhp.sys [102832 2012-04-12] (NCP Engineering GmbH)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2010-04-09] ()
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2010-04-09] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2010-04-09] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2010-04-09] ()
R0 tdrpman258; C:\Windows\System32\DRIVERS\tdrpm258.sys [1477728 2010-08-01] (Acronis)
U3 idsvc;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-14 10:09 - 2013-08-14 10:09 - 00000000 ____D C:\FRST
2013-08-14 10:08 - 2013-08-14 10:08 - 01575544 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2013-08-14 00:09 - 2013-08-14 00:09 - 00093602 _____ C:\Users\Admin\Desktop\Extras.Txt
2013-08-14 00:07 - 2013-08-14 00:07 - 00127790 _____ C:\Users\Admin\Desktop\OTL.Txt
2013-08-13 23:25 - 2013-08-13 23:25 - 00602112 _____ (OldTimer Tools) C:\Users\Admin\Desktop\OTL.exe
2013-08-13 22:12 - 2013-08-13 22:15 - 244975430 _____ C:\Users\Admin\Downloads\Mirja Boes liest Kerstin Gier -Die Mütter-Mafia-.wma
2013-08-13 20:43 - 2013-08-13 20:43 - 00001499 _____ C:\Users\Admin\Downloads\URLLink.acsm
2013-08-12 12:50 - 2013-08-12 12:50 - 00000000 ____D C:\Program Files (x86)\TypoTextCP
2013-08-09 15:24 - 2013-08-09 15:24 - 00000332 _____ C:\Users\Admin\Downloads\BK_ADKO_000866DE_LC_128_44100_ste_kai@litschen.net.adh
2013-08-09 15:05 - 2013-08-09 15:05 - 00000299 _____ C:\Users\Admin\Downloads\BK_ADKO_000867DE_LC_128_44100_ste_kai@litschen.net.adh
2013-08-09 14:59 - 2013-08-09 14:59 - 00255352 _____ (Audible, Inc.) C:\WINDOWS\SysWOW64\awrdscdc.ax
2013-08-09 14:59 - 2013-08-09 14:59 - 00002001 _____ C:\Users\Uta Handy\Desktop\Audible Manager.lnk
2013-08-09 14:59 - 2013-08-09 14:59 - 00002001 _____ C:\Users\UpdatusUser\Desktop\Audible Manager.lnk
2013-08-09 14:59 - 2013-08-09 14:59 - 00002001 _____ C:\Users\Marie\Desktop\Audible Manager.lnk
2013-08-09 14:59 - 2013-08-09 14:59 - 00002001 _____ C:\Users\Admin\Desktop\Audible Manager.lnk
2013-08-09 14:59 - 2013-08-09 14:59 - 00000299 _____ C:\Users\Admin\Downloads\BK_ADKO_000864DE_LC_128_44100_ste_kai@litschen.net.adh
2013-08-09 14:59 - 2001-08-17 22:43 - 00024576 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3a.dll
2013-08-09 14:58 - 2013-08-09 14:58 - 01730272 _____ (Audible Inc.) C:\Users\Admin\Downloads\ActiveSetupN.exe
2013-08-09 14:57 - 2013-08-09 14:57 - 00000332 _____ C:\Users\Admin\Downloads\admhelper (7).adh
2013-08-09 14:57 - 2013-08-09 14:57 - 00000299 _____ C:\Users\Admin\Downloads\admhelper (9).adh
2013-08-09 14:57 - 2013-08-09 14:57 - 00000299 _____ C:\Users\Admin\Downloads\admhelper (8).adh
2013-08-09 14:57 - 2013-08-09 14:57 - 00000299 _____ C:\Users\Admin\Downloads\admhelper (6).adh
2013-08-09 14:55 - 2013-08-09 14:55 - 00000334 _____ C:\Users\Admin\Downloads\admhelper (4).adh
2013-08-09 14:55 - 2013-08-09 14:55 - 00000299 _____ C:\Users\Admin\Downloads\admhelper (5).adh
2013-08-09 14:54 - 2013-08-09 14:54 - 00000299 _____ C:\Users\Admin\Downloads\admhelper (3).adh
2013-08-09 14:12 - 2013-08-09 14:14 - 136217996 _____ C:\Users\Admin\Downloads\Wer war Robin Hood- (2).wma
2013-08-09 14:09 - 2013-08-09 14:09 - 73848689 _____ C:\Users\Admin\Downloads\Das Geheimnis der 100 Pforten_04 (1).wma
2013-08-09 13:57 - 2013-08-09 13:58 - 73848689 _____ C:\Users\Admin\Downloads\Das Geheimnis der 100 Pforten_04.wma
2013-08-09 13:49 - 2013-08-09 13:49 - 67298993 _____ C:\Users\Admin\Downloads\Das Geheimnis der 100 Pforten_03.wma
2013-08-09 13:23 - 2013-08-09 13:24 - 74864609 _____ C:\Users\Admin\Downloads\Das Geheimnis der 100 Pforten_01.wma
2013-08-09 13:16 - 2013-08-09 13:19 - 205487985 _____ C:\Users\Admin\Downloads\Das Geheimnis des alten Bahnhofs.wma
2013-08-07 12:11 - 2013-08-14 10:01 - 00000000 ____D C:\Users\Admin\AppData\Roaming\PamFax Office Integrations
2013-08-07 12:03 - 2013-08-07 12:03 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Scendix Software
2013-08-07 12:03 - 2013-08-07 12:03 - 00000000 ____D C:\Users\Admin\AppData\Local\Scendix Software
2013-08-07 12:00 - 2013-08-07 12:00 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Softland
2013-08-07 12:00 - 2013-05-09 10:53 - 00033088 _____ (Softland) C:\WINDOWS\system32\novamnv7.dll
2013-08-07 12:00 - 2013-05-09 10:53 - 00022336 _____ (Softland) C:\WINDOWS\system32\novamiv7.dll
2013-08-07 12:00 - 2011-11-22 18:05 - 00007549 _____ C:\WINDOWS\system32\novav7.ctm
2013-08-07 11:58 - 2013-08-07 12:03 - 00000000 ____D C:\Program Files (x86)\PamFax
2013-08-07 11:58 - 2013-08-07 11:58 - 00001890 _____ C:\Users\Public\Desktop\PamFax Portal.lnk
2013-08-07 11:58 - 2013-08-07 11:58 - 00001884 _____ C:\Users\Public\Desktop\PamFax senden.lnk
2013-08-07 11:57 - 2013-08-07 11:57 - 00809688 _____ (Scendix Software GmbH ) C:\Users\Admin\Downloads\PamFaxInstaller.exe
2013-08-07 11:57 - 2013-08-07 11:57 - 00809688 _____ (Scendix Software GmbH ) C:\Users\Admin\Downloads\PamFaxInstaller (2).exe
2013-08-07 11:57 - 2013-08-07 11:57 - 00809688 _____ (Scendix Software GmbH ) C:\Users\Admin\Downloads\PamFaxInstaller (1).exe
2013-08-06 18:36 - 2013-08-06 18:36 - 00262144 ____N C:\WINDOWS\Minidump\080613-49375-01.dmp
2013-08-05 21:45 - 2013-08-05 21:46 - 55878646 _____ C:\Users\Admin\Downloads\Ali Baba und die vierzig Räuber.wma
2013-08-05 21:37 - 2013-08-05 21:38 - 63199633 _____ C:\Users\Admin\Downloads\Spanisch lernen mit The Grooves- Groovy Basics_2.wma
2013-08-05 21:30 - 2013-08-05 21:37 - 519301099 _____ C:\Users\Admin\Downloads\Oliver Twist.wma
2013-08-05 21:25 - 2013-08-05 21:30 - 379937508 _____ C:\Users\Admin\Downloads\Andrea Sawatzki liest Flavia de Luce, Mord ist kein Kinderspiel.wma
2013-08-05 21:18 - 2013-08-05 21:20 - 88320654 _____ C:\Users\Admin\Downloads\Goethe.wma
2013-08-05 21:03 - 2013-08-05 21:04 - 30048083 _____ C:\Users\Admin\Downloads\Der Beste- Loriot.wma
2013-08-05 20:59 - 2013-08-05 21:02 - 180488264 _____ C:\Users\Admin\Downloads\Christoph Maria Herbst liest -BGB-.wma
2013-08-05 20:53 - 2013-08-05 20:57 - 303623912 _____ C:\Users\Admin\Downloads\Oliver Kalkofe liest Roger Schmelzer -Die besten zehn Sekunden meines Lebens.wma
2013-07-26 13:52 - 2013-07-26 13:52 - 00113390 _____ C:\Users\Admin\Downloads\romeiko.zip
2013-07-25 14:14 - 2013-07-25 14:14 - 00001350 _____ C:\Users\Admin\Desktop\Ruhe.lnk
2013-07-20 01:51 - 2013-07-20 01:51 - 00311608 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgloga.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00246072 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00206648 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgldx64.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00071480 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsha.sys
2013-07-19 16:12 - 2013-07-19 16:12 - 34887288 _____ (Google Inc.) C:\Users\Admin\Downloads\Chrome28StandaloneSetup.exe
2013-07-19 16:08 - 2013-07-19 16:10 - 140002992 _____ (AVG Technologies) C:\Users\Admin\Downloads\avg_free_x86_all_2013_3349a6461.exe
2013-07-19 16:07 - 2013-07-19 16:07 - 04411440 _____ (AVG Technologies) C:\Users\Admin\Downloads\avg_avct_stb_all_2013_2667_cm10.exe
2013-07-17 13:03 - 2013-07-19 16:13 - 00602624 ___SH C:\Users\Admin\Downloads\Thumbs.db
2013-07-17 12:03 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2013-07-17 12:03 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2013-07-17 12:03 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2013-07-17 12:03 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2013-07-17 12:03 - 2013-06-01 13:33 - 02233600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2013-07-17 12:03 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-07-17 12:03 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UCX01000.SYS
2013-07-17 12:03 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-07-17 12:03 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2013-07-17 12:03 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2013-07-17 12:03 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2013-07-17 12:03 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2013-07-17 12:03 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2013-07-17 12:03 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2013-07-17 12:03 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2013-07-17 12:03 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-07-17 12:03 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2013-07-17 12:03 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2013-07-17 12:03 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2013-07-17 12:03 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsutil.dll
2013-07-17 12:03 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2013-07-17 12:03 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2013-07-17 12:03 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2013-07-17 12:03 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-07-17 12:03 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2013-07-17 12:03 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2013-07-17 12:03 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2013-07-17 12:03 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2013-07-17 12:03 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2013-07-17 12:03 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthAvrcpTg.sys
2013-07-17 12:03 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2013-07-17 12:03 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2013-07-17 12:03 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2013-07-17 12:03 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2013-07-17 12:03 - 2013-05-20 02:08 - 00386642 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-07-16 21:10 - 2013-07-16 21:10 - 00530384 _____ C:\Users\Admin\Downloads\Player_Setup.exe
==================== One Month Modified Files and Folders =======
2013-08-14 10:09 - 2013-08-14 10:09 - 00000000 ____D C:\FRST
2013-08-14 10:08 - 2013-08-14 10:08 - 01575544 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2013-08-14 10:02 - 2012-11-09 15:21 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1950117156-4129327238-117919278-1001
2013-08-14 10:01 - 2013-08-07 12:11 - 00000000 ____D C:\Users\Admin\AppData\Roaming\PamFax Office Integrations
2013-08-14 10:01 - 2012-03-29 20:53 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-08-14 10:01 - 2012-01-20 19:52 - 00000000 ____D C:\Users\Admin\Documents\Backups
2013-08-14 10:01 - 2009-07-14 04:34 - 00000556 _____ C:\WINDOWS\win.ini
2013-08-14 10:00 - 2013-06-21 15:43 - 00000000 ____D C:\ProgramData\MFAData
2013-08-14 10:00 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\sru
2013-08-14 09:57 - 2012-07-18 00:05 - 00000000 ___RD C:\Users\Admin\Dropbox
2013-08-14 09:57 - 2012-07-18 00:03 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Dropbox
2013-08-14 09:56 - 2013-01-12 12:04 - 00001122 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-14 09:54 - 2013-06-22 17:49 - 00818269 _____ C:\WINDOWS\setupact.log
2013-08-14 09:54 - 2012-07-26 09:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-14 09:54 - 2010-07-22 15:44 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-14 00:26 - 2010-08-01 17:36 - 00000000 ____D C:\Users\Admin\Documents\Outlook-Dateien
2013-08-14 00:09 - 2013-08-14 00:09 - 00093602 _____ C:\Users\Admin\Desktop\Extras.Txt
2013-08-14 00:07 - 2013-08-14 00:07 - 00127790 _____ C:\Users\Admin\Desktop\OTL.Txt
2013-08-13 23:54 - 2013-06-21 22:12 - 01844173 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-13 23:31 - 2013-01-12 12:04 - 00001126 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-13 23:25 - 2013-08-13 23:25 - 00602112 _____ (OldTimer Tools) C:\Users\Admin\Desktop\OTL.exe
2013-08-13 23:20 - 2011-07-07 16:21 - 00000000 ____D C:\Users\Admin\Desktop\Zwischenspeicher
2013-08-13 22:15 - 2013-08-13 22:12 - 244975430 _____ C:\Users\Admin\Downloads\Mirja Boes liest Kerstin Gier -Die Mütter-Mafia-.wma
2013-08-13 20:43 - 2013-08-13 20:43 - 00001499 _____ C:\Users\Admin\Downloads\URLLink.acsm
2013-08-13 19:36 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2013-08-13 12:31 - 2012-07-18 00:05 - 00001017 _____ C:\Users\Admin\Desktop\Dropbox.lnk
2013-08-13 12:31 - 2012-07-18 00:04 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-08-13 12:31 - 2010-07-22 14:35 - 00000000 ___RD C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-12 12:50 - 2013-08-12 12:50 - 00000000 ____D C:\Program Files (x86)\TypoTextCP
2013-08-12 12:50 - 2013-04-12 16:22 - 00001778 _____ C:\Users\Public\Desktop\HJR Autorenportal.lnk
2013-08-12 12:50 - 2012-06-11 09:27 - 00000000 ____D C:\Users\Admin\AppData\Roaming\TypoScript
2013-08-12 12:50 - 2010-11-19 16:50 - 00208384 ___SH C:\Users\Admin\Desktop\Thumbs.db
2013-08-12 10:18 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\NDF
2013-08-09 15:33 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2013-08-09 15:24 - 2013-08-09 15:24 - 00000332 _____ C:\Users\Admin\Downloads\BK_ADKO_000866DE_LC_128_44100_ste_kai@litschen.net.adh
2013-08-09 15:05 - 2013-08-09 15:05 - 00000299 _____ C:\Users\Admin\Downloads\BK_ADKO_000867DE_LC_128_44100_ste_kai@litschen.net.adh
2013-08-09 14:59 - 2013-08-09 14:59 - 00255352 _____ (Audible, Inc.) C:\WINDOWS\SysWOW64\awrdscdc.ax
2013-08-09 14:59 - 2013-08-09 14:59 - 00002001 _____ C:\Users\Uta Handy\Desktop\Audible Manager.lnk
2013-08-09 14:59 - 2013-08-09 14:59 - 00002001 _____ C:\Users\UpdatusUser\Desktop\Audible Manager.lnk
2013-08-09 14:59 - 2013-08-09 14:59 - 00002001 _____ C:\Users\Marie\Desktop\Audible Manager.lnk
2013-08-09 14:59 - 2013-08-09 14:59 - 00002001 _____ C:\Users\Admin\Desktop\Audible Manager.lnk
2013-08-09 14:59 - 2013-08-09 14:59 - 00000299 _____ C:\Users\Admin\Downloads\BK_ADKO_000864DE_LC_128_44100_ste_kai@litschen.net.adh
2013-08-09 14:59 - 2013-06-15 22:21 - 00000000 ____D C:\Users\Admin\AppData\Local\Audible
2013-08-09 14:59 - 2013-06-15 22:17 - 00000000 ____D C:\Program Files (x86)\Audible
2013-08-09 14:58 - 2013-08-09 14:58 - 01730272 _____ (Audible Inc.) C:\Users\Admin\Downloads\ActiveSetupN.exe
2013-08-09 14:57 - 2013-08-09 14:57 - 00000332 _____ C:\Users\Admin\Downloads\admhelper (7).adh
2013-08-09 14:57 - 2013-08-09 14:57 - 00000299 _____ C:\Users\Admin\Downloads\admhelper (9).adh
2013-08-09 14:57 - 2013-08-09 14:57 - 00000299 _____ C:\Users\Admin\Downloads\admhelper (8).adh
2013-08-09 14:57 - 2013-08-09 14:57 - 00000299 _____ C:\Users\Admin\Downloads\admhelper (6).adh
2013-08-09 14:55 - 2013-08-09 14:55 - 00000334 _____ C:\Users\Admin\Downloads\admhelper (4).adh
2013-08-09 14:55 - 2013-08-09 14:55 - 00000299 _____ C:\Users\Admin\Downloads\admhelper (5).adh
2013-08-09 14:54 - 2013-08-09 14:54 - 00000299 _____ C:\Users\Admin\Downloads\admhelper (3).adh
2013-08-09 14:51 - 2012-07-26 12:27 - 00755402 _____ C:\WINDOWS\system32\perfh007.dat
2013-08-09 14:51 - 2012-07-26 12:27 - 00156630 _____ C:\WINDOWS\system32\perfc007.dat
2013-08-09 14:51 - 2012-07-26 09:28 - 01754016 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-08-09 14:14 - 2013-08-09 14:12 - 136217996 _____ C:\Users\Admin\Downloads\Wer war Robin Hood- (2).wma
2013-08-09 14:09 - 2013-08-09 14:09 - 73848689 _____ C:\Users\Admin\Downloads\Das Geheimnis der 100 Pforten_04 (1).wma
2013-08-09 13:58 - 2013-08-09 13:57 - 73848689 _____ C:\Users\Admin\Downloads\Das Geheimnis der 100 Pforten_04.wma
2013-08-09 13:49 - 2013-08-09 13:49 - 67298993 _____ C:\Users\Admin\Downloads\Das Geheimnis der 100 Pforten_03.wma
2013-08-09 13:24 - 2013-08-09 13:23 - 74864609 _____ C:\Users\Admin\Downloads\Das Geheimnis der 100 Pforten_01.wma
2013-08-09 13:19 - 2013-08-09 13:16 - 205487985 _____ C:\Users\Admin\Downloads\Das Geheimnis des alten Bahnhofs.wma
2013-08-07 22:35 - 2012-06-25 15:16 - 00002123 _____ C:\Users\Public\Desktop\StarMoney Business 5.0.lnk
2013-08-07 12:03 - 2013-08-07 12:03 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Scendix Software
2013-08-07 12:03 - 2013-08-07 12:03 - 00000000 ____D C:\Users\Admin\AppData\Local\Scendix Software
2013-08-07 12:03 - 2013-08-07 11:58 - 00000000 ____D C:\Program Files (x86)\PamFax
2013-08-07 12:00 - 2013-08-07 12:00 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Softland
2013-08-07 11:58 - 2013-08-07 11:58 - 00001890 _____ C:\Users\Public\Desktop\PamFax Portal.lnk
2013-08-07 11:58 - 2013-08-07 11:58 - 00001884 _____ C:\Users\Public\Desktop\PamFax senden.lnk
2013-08-07 11:57 - 2013-08-07 11:57 - 00809688 _____ (Scendix Software GmbH ) C:\Users\Admin\Downloads\PamFaxInstaller.exe
2013-08-07 11:57 - 2013-08-07 11:57 - 00809688 _____ (Scendix Software GmbH ) C:\Users\Admin\Downloads\PamFaxInstaller (2).exe
2013-08-07 11:57 - 2013-08-07 11:57 - 00809688 _____ (Scendix Software GmbH ) C:\Users\Admin\Downloads\PamFaxInstaller (1).exe
2013-08-06 18:36 - 2013-08-06 18:36 - 00262144 ____N C:\WINDOWS\Minidump\080613-49375-01.dmp
2013-08-06 18:36 - 2012-11-09 22:10 - 00000000 ____D C:\WINDOWS\Minidump
2013-08-06 10:56 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-08-05 21:46 - 2013-08-05 21:45 - 55878646 _____ C:\Users\Admin\Downloads\Ali Baba und die vierzig Räuber.wma
2013-08-05 21:38 - 2013-08-05 21:37 - 63199633 _____ C:\Users\Admin\Downloads\Spanisch lernen mit The Grooves- Groovy Basics_2.wma
2013-08-05 21:37 - 2013-08-05 21:30 - 519301099 _____ C:\Users\Admin\Downloads\Oliver Twist.wma
2013-08-05 21:30 - 2013-08-05 21:25 - 379937508 _____ C:\Users\Admin\Downloads\Andrea Sawatzki liest Flavia de Luce, Mord ist kein Kinderspiel.wma
2013-08-05 21:20 - 2013-08-05 21:18 - 88320654 _____ C:\Users\Admin\Downloads\Goethe.wma
2013-08-05 21:04 - 2013-08-05 21:03 - 30048083 _____ C:\Users\Admin\Downloads\Der Beste- Loriot.wma
2013-08-05 21:02 - 2013-08-05 20:59 - 180488264 _____ C:\Users\Admin\Downloads\Christoph Maria Herbst liest -BGB-.wma
2013-08-05 20:57 - 2013-08-05 20:53 - 303623912 _____ C:\Users\Admin\Downloads\Oliver Kalkofe liest Roger Schmelzer -Die besten zehn Sekunden meines Lebens.wma
2013-08-01 20:40 - 2010-08-01 16:46 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype
2013-07-31 23:33 - 2013-01-12 12:05 - 00002219 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-31 11:01 - 2013-06-21 18:17 - 00001017 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-07-26 13:52 - 2013-07-26 13:52 - 00113390 _____ C:\Users\Admin\Downloads\romeiko.zip
2013-07-25 14:14 - 2013-07-25 14:14 - 00001350 _____ C:\Users\Admin\Desktop\Ruhe.lnk
2013-07-25 09:40 - 2012-03-29 20:53 - 00003796 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2013-07-25 09:40 - 2010-08-01 16:37 - 00000000 ____D C:\Users\Admin\AppData\Local\Adobe
2013-07-24 21:55 - 2010-08-01 16:49 - 00017408 _____ C:\Users\Admin\AppData\Local\WebpageIcons.db
2013-07-20 01:51 - 2013-07-20 01:51 - 00311608 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgloga.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00246072 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00206648 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgldx64.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00071480 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsha.sys
2013-07-19 16:13 - 2013-07-17 13:03 - 00602624 ___SH C:\Users\Admin\Downloads\Thumbs.db
2013-07-19 16:12 - 2013-07-19 16:12 - 34887288 _____ (Google Inc.) C:\Users\Admin\Downloads\Chrome28StandaloneSetup.exe
2013-07-19 16:10 - 2013-07-19 16:08 - 140002992 _____ (AVG Technologies) C:\Users\Admin\Downloads\avg_free_x86_all_2013_3349a6461.exe
2013-07-19 16:07 - 2013-07-19 16:07 - 04411440 _____ (AVG Technologies) C:\Users\Admin\Downloads\avg_avct_stb_all_2013_2667_cm10.exe
2013-07-18 12:42 - 2012-11-08 10:48 - 00000000 ____D C:\Users\Admin\Desktop\Haufe 2013
2013-07-16 21:10 - 2013-07-16 21:10 - 00530384 _____ C:\Users\Admin\Downloads\Player_Setup.exe
2013-07-16 09:49 - 2011-05-19 10:54 - 00000000 ____D C:\Users\Admin\AppData\Roaming\webex
2013-07-15 01:17 - 2012-11-09 14:55 - 00000000 ____D C:\Users\Admin
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-13 12:45
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-08-2013
Ran by Admin at 2013-08-14 10:12:08
Running from C:\Users\Admin\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
2013 (Version: 2013.0.3392)
3DMark06 (x32 Version: 1.1.0)
64 Bit HP CIO Components Installer (Version: 4.2.1)
7-Zip 4.65 (x32)
Acronis*True*Image*Home (x32 Version: 13.0.6029)
Adobe AIR (x32 Version: 3.7.0.1860)
Adobe Connect Add-in (HKCU)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Reader X (10.1.7) - Deutsch (x32 Version: 10.1.7)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
Assassin's Creed(R) III v1.02 (x32 Version: 1.02)
Audacity 2.0.3 (x32 Version: 2.0.3)
AudibleManager (x32 Version: 18414980.4759644.48.1998993224)
Audiograbber 1.83 SE (x32 Version: 1.83 SE )
AVG 2013 (Version: 13.0.3211)
AVG 2013 (Version: 13.0.3392)
Biet-O-Matic v2.14.3 (x32 Version: Biet-O-Matic v2.14.3)
Bonjour (Version: 3.0.0.10)
BufferChm (x32 Version: 100.0.170.000)
CCleaner (Version: 4.02)
CDBurnerXP (x32 Version: 4.4.1.3341)
Cisco WebEx Meetings (HKCU)
cyberJack Base Components (x32 Version: 6.10.0)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
DeviceDiscovery (x32 Version: 100.0.190.000)
DeviceManagementQFolder (x32 Version: 1.00.0000)
DrayTek Smart VPN Client (x32)
Dropbox (HKCU Version: 2.0.22)
EASEUS Partition Master 9.1.0 Home Edition (x32)
ElsterFormular (x32 Version: 14.1.11318)
FFmpeg v0.6.2 for Audacity (x32)
Free Studio version 2013 (x32 Version: 6.0.0.128)
Free Video Flip and Rotate version 2.0.5.508 (x32 Version: 2.0.5.508)
Free Video to MP3 Converter version 5.0.15.706 (x32 Version: 5.0.15.706)
Google Chrome (x32 Version: 28.0.1500.95)
Google Update Helper (x32 Version: 1.3.21.153)
HD Writer AE 3.0 (x32 Version: 3.00.019.1031)
HJR Autorenportal (x32 Version: 3.3)
HP Color LaserJet CM1312 MFP Series 5.1 (Version: 5.1)
HP Update (x32 Version: 4.000.007.003)
hppCLJCM1312 (x32 Version: 005.001.00142)
hppFaxDrvCM1312 (x32 Version: 005.000.00001)
hppFaxUtilityCM1312 (x32 Version: 005.001.00137)
hppFonts (x32 Version: 001.001.00061)
hppLaserJetService (x32 Version: 001.001.0.0)
hppManualsCM1312 (x32 Version: 005.001.00145)
hppPQVideoCM1312 (x32 Version: 005.001.00142)
hppQFolderCM1312 (x32 Version: 1.00.0000)
hppScanToCM1312 (x32 Version: 005.001.00140)
hppSendFaxCM1312 (x32 Version: 005.000.00001)
hppTLBXFXCM1312 (x32 Version: 001.017.00050)
hpzTLBXFX (x32 Version: 005.003.00171)
iCloud (Version: 2.1.0.39)
iTunes (Version: 11.0.4.4)
Java 7 Update 21 (x32 Version: 7.0.210)
Java Auto Updater (x32 Version: 2.1.9.5)
Java(TM) 6 Update 39 (x32 Version: 6.0.390)
Java(TM) SE Runtime Environment 6 (x32 Version: 1.6.0.0)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
LoB.IT (x32 Version: 2.1.64.0)
McAfee Security Scan Plus (x32 Version: 3.0.318.3)
McAfee SiteAdvisor (x32 Version: 3.6.168)
Mesh Runtime (x32 Version: 15.4.5722.2)
Messenger Companion (x32 Version: 15.4.3502.0922)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 Service Pack 1 (SP1) (x32)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Outlook Connector (x32 Version: 14.0.5118.5000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (x32 Version: 14.0.5120.5000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Software Update for Web Folders (German) 12 (x32 Version: 12.0.6612.1000)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft SQL Server Compact 3.5 SP2 ENU (x32 Version: 3.5.8080.0)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (Version: 3.5.8080.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ Run Time Lib Setup (x32 Version: 1.0.0)
Might & Magic Heroes VI (x32 Version: 1.8)
MobileMe Control Panel (Version: 3.1.8.0)
MozBackup 1.4.9 (x32)
Mp3tag v2.48 (x32 Version: v2.48)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Need for Speed(TM) Hot Pursuit (x32 Version: 1.0.0.0)
NVIDIA 3D Vision Controller-Treiber 296.10 (Version: 296.10)
NVIDIA 3D Vision Treiber 311.06 (Version: 311.06)
NVIDIA Display Control Panel (Version: 6.14.12.5896)
NVIDIA Grafiktreiber 311.06 (Version: 311.06)
NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0)
NVIDIA Install Application (Version: 2.1002.109.718)
NVIDIA PhysX (x32 Version: 9.12.0213)
NVIDIA PhysX-Systemsoftware 9.12.0213 (Version: 9.12.0213)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106)
NVIDIA Systemsteuerung 311.06 (Version: 311.06)
NVIDIA Update 1.11.3 (Version: 1.11.3)
NVIDIA Update Components (Version: 1.11.3)
Opera 12.02 (x32 Version: 12.02.1578)
Origin (x32 Version: 9.1.15.109)
PamFax (x32 Version: 3.5.0.14)
PamFax Office Integration (x32 Version: 1.0.4)
PDFCreator (x32 Version: 1.6.1)
PlayMemories Home (x32 Version: 6.3.00.04221)
Plus Pack für Acronis True Image Home 2010 (x32 Version: 13.0.6029)
PunkBuster Services (x32 Version: 0.991)
PVSonyDll (Version: 1.00.0001)
QuickTime (x32 Version: 7.73.80.64)
Risiko II (x32)
Sibelius Scorch (ActiveX Only) (x32 Version: 6.2.0)
Sibelius Scorch (Firefox, Opera, Netscape only) (x32 Version: 6.2.0)
simfy (x32 Version: 1.7.3)
Skype Click to Call (x32 Version: 5.9.9216)
Skype™ 6.3 (x32 Version: 6.3.107)
Sony PC Companion 2.10.065 (x32 Version: 2.10.065)
StarMoney (x32 Version: 2.0)
StarMoney (x32 Version: 3.0.3.19)
StarMoney Business 5.0 (x32 Version: 5.0)
sv.net (x32 Version: 12.1)
Synology Assistant (remove only) (x32)
TrayApp (x32 Version: 100.0.170.000)
TypoText (x32 Version: 3.1)
Ubisoft Game Launcher (x32 Version: 1.0.0.0)
Unity Web Player (HKCU Version: )
Update for Microsoft Office 2010 (KB2494150) (x32)
Update for Microsoft Office 2010 (KB2553065) (x32)
Update for Microsoft Office 2010 (KB2553092) (x32)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2566458) (x32)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32)
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition (x32)
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition (x32)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
VLC media player 1.1.11 (x32 Version: 1.1.11)
WebReg (x32 Version: 100.0.170.000)
WebSign Basiskomponeten (x32 Version: 3.2.2)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
XnView 1.98.2 (x32 Version: 1.98.2)
Zattoo4 4.0.5 (x32 Version: 4.0.5)
==================== Restore Points =========================
23-07-2013 08:34:07 Geplanter Prüfpunkt
30-07-2013 15:53:50 Geplanter Prüfpunkt
06-08-2013 16:54:52 Geplanter Prüfpunkt
12-08-2013 10:48:54 HJR Autorenportal wird installiert
==================== Hosts content: ==========================
2009-07-14 04:34 - 2010-08-02 09:56 - 00000849 ____A C:\WINDOWS\system32\Drivers\etc\hosts
192.168.2.154 NPI88A38F
==================== Scheduled Tasks (whitelisted) =============
Task: {0156CEE9-7DFB-4975-938F-2858A5428A41} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2012-07-26] (Microsoft Corporation)
Task: {0B092311-EB98-40DE-A12E-9B6DC0C3D9BB} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUSessionConnect
Task: {0E994E77-651D-405E-9A42-C4BAB0A1FC84} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe No File
Task: {10D85952-E3F6-47A1-96CF-5E1C2D874EA6} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe [2012-07-26] (Microsoft Corporation)
Task: {13A2AC02-B682-48CC-9155-2E2673580117} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
Task: {17644F17-DC4C-4AC8-9444-7AAA52EB5CDC} - System32\Tasks\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler
Task: {196E68BB-FB10-4D8E-A2F4-EBC0D2E7F7EB} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe No File
Task: {1A91CFE3-D589-4DA9-829B-E133CBC02392} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1950117156-4129327238-117919278-1001
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {1C015270-DB78-4D98-BE50-CFE2F989BB61} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1DB7C2F1-876C-4F24-AD17-8428211113F9} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
Task: {214B24F4-FEB4-4C59-AF1F-70136065199C} - System32\Tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance
Task: {23700E5C-0E77-499D-908A-415D5C6252F4} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {2AD2B6C7-7AE2-40BE-B1DE-B10885345045} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe No File
Task: {2C6B9EA8-7F5A-4ABA-BF96-8D352D02A743} - System32\Tasks\Microsoft\Windows\Device Setup\Metadata Refresh
Task: {2E030FA7-3D7C-4E1D-8CFE-56ADB26FD402} - System32\Tasks\Microsoft\Windows\PI\Sqm-Tasks
Task: {3054485A-F517-4E95-9977-4DD827B1E9B3} - System32\Tasks\Microsoft\Windows\WS\Badge Update
Task: {32F0C502-351F-4597-BBCF-0E15DB62DF50} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start => C:\WINDOWS\system32\sc.exe [2012-07-26] (Microsoft Corporation)
Task: {360AD61D-0DCC-48CC-A6C3-A1E9BB939CAF} - System32\Tasks\RunAsStdUser Task => C:\Program Files\NetDrive\netdrive.exe No File
Task: {378401BA-A703-444A-A79C-3C47AD2DC5B6} - System32\Tasks\Microsoft\Windows\TaskScheduler\Maintenance Configurator
Task: {3AE164E7-30CD-40BC-9422-3EC7A5618965} - System32\Tasks\Microsoft\Windows\WS\WSTask
Task: {3C490ABD-D849-41AF-9AC4-87DD759B0996} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
Task: {4032C8C0-A3B4-491A-B075-0443B326DC07} - System32\Tasks\{D4A4B1E0-1EAC-4542-AE4A-B0240A302377} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-04-19] (Skype Technologies S.A.)
Task: {4073C1B3-6E16-4AA8-B7F3-C6A6D35D5071} - System32\Tasks\Microsoft\Windows\TPM\Tpm-Maintenance
Task: {44B3F1B8-5943-4072-8D8C-A9484676AC44} - System32\Tasks\Microsoft\Windows\Live\Roaming\SynchronizeWithStorage
Task: {4620F4D7-ADCC-410A-89EB-E8B29F733BB6} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe No File
Task: {483A8F5C-5D26-44B5-B49E-AF6741D1BBEB} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\Windows\System32\MbaeParserTask.exe [2013-06-01] (Microsoft Corporation)
Task: {4B952129-9AE9-41A3-BE2B-8AD2E06F66B6} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
Task: {502B51D7-0100-4BE7-A486-18394A866934} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe No File
Task: {5755E746-D7ED-4C20-A472-66C11834CDE4} - System32\Tasks\Microsoft\Windows\TaskScheduler\Manual Maintenance
Task: {5C4EFB77-EFA6-45DF-A373-D795C0725BFF} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required
Task: {6134BE4B-BFF5-4B0C-A006-892102BE4FF7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe No File
Task: {627441F3-8526-4B62-BF9A-1A3EA414E71A} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask => C:\Windows\system32\SpaceAgent.exe [2012-07-26] (Microsoft Corporation)
Task: {64346B0E-BEC0-4E6E-8D63-22F283554872} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1950117156-4129327238-117919278-1005 => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {68D3CC7F-5383-4E06-8459-6C1AE93C969B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-12] (Google Inc.)
Task: {6E9DE125-5583-4031-B572-FEE48F25CFFF} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor => C:\Windows\System32\wpcmon.exe [2012-09-20] (Microsoft Corporation)
Task: {6FDDEA7C-6310-428D-AEB2-54FFC72811EF} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
Task: {71A143E0-6F68-408D-9EA6-3DC7F6F9B60C} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe No File
Task: {74096F94-B654-4DB0-96F5-3C3408B92FE3} - System32\Tasks\Microsoft\Windows\PI\Secure-Boot-Update
Task: {7A77816F-9283-4EDF-8A0D-49C3FE3C3FA6} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe No File
Task: {7D9A9A1C-499C-40A6-8F8A-5BCC4CC9A87C} - System32\Tasks\Microsoft\Windows\TaskScheduler\Regular Maintenance
Task: {7E2C2F6B-EF4B-4A4D-8AB6-FFA6CAF0B75B} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe No File
Task: {81C798F6-22D2-423F-9912-F0719ABB0D7A} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {836094F2-9BF3-4792-A3B8-7E51B9631A24} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe No File
Task: {845CB020-68B5-4C6B-9876-7BEC7B3E27AC} - System32\Tasks\Microsoft\Windows\TaskScheduler\Idle Maintenance
Task: {87354DAA-66DF-4B41-9346-15958D96E1D2} - System32\Tasks\Microsoft\Windows\FileHistory\File History (maintenance mode)
Task: {8AFCB42D-0196-4D70-B912-01F629053526} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe No File
Task: {8B996136-1E5A-4953-884C-0B46AC8D16B4} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe No File
Task: {8D24CD31-8382-42FD-9600-0CE56A65ECB3} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {921A1D4E-32FB-46D7-B6C0-6F467884074D} - System32\Tasks\Microsoft\Windows\WS\Sync Licenses
Task: {92A53E67-C998-4C24-BDD8-ECCD42ED5E94} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe No File
Task: {9479EF8E-11D4-41B3-9783-CC65070D592D} - System32\Tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
Task: {94DCF254-64FB-4C4E-8E12-5F4055C10C2A} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
Task: {989A7C6D-BE82-4C3C-AF96-6116039E336B} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
Task: {A4024E53-B88A-4873-8A6B-C5A2DA8C28CE} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe No File
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {A800277E-E202-4492-AD38-3312641CBC04} - System32\Tasks\Microsoft\Windows\Live\Roaming\MaintenanceTask
Task: {AB62FA47-2C99-44B1-A5D0-D4161423BE43} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefresh
Task: {AC6259DE-AC59-459E-849E-6ADFFD1ADE63} - System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask
Task: {AE8B55F1-3148-47BC-BA46-88DEF2CB33F7} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall
Task: {AEB0B5BD-B9E5-458A-898A-E559BD9EB51B} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask
Task: {AF549BD8-337C-4BF7-8681-36A182E30507} - System32\Tasks\Microsoft\Windows\Chkdsk\ProactiveScan
Task: {AFEC4378-8A44-4C7F-B301-2422DD07A7DF} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe No File
Task: {B2105480-B3C4-4608-AF49-9F196D1FF965} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUScheduledInstall
Task: {B3674A87-C925-4213-82C3-CBF03A42BC48} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe No File
Task: {B5B49976-C5BA-4745-99B2-6A3345D52F75} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe No File
Task: {B79064CA-994C-4379-AEB3-B9618FA13CC7} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2013-01-29] (Microsoft Corporation)
Task: {BC76AEF7-2CF0-4EB6-B65B-A8803E0B5E12} - System32\Tasks\Microsoft\Windows\AppID\SmartScreenSpecific
Task: {C1ACCD1E-4385-4FB2-B5E4-7F2A57A626A2} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
Task: {C463FD1E-31C7-4C20-AB65-08E514CA152D} - System32\Tasks\Microsoft\Windows\IME\SQM data sender
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {C725BE30-D9B9-4039-B401-BFDEFD296757} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup
Task: {C9A0CDCD-A8CC-4949-BF2C-92BDE8400798} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-12] (Google Inc.)
Task: {CA621AE8-60E2-4B15-A4D5-290E4FF68D45} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe No File
Task: {CD1054FF-8005-4904-8B9C-436EAB1E2021} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
Task: {D44510C7-A779-43BC-B7C7-B3988CD3BC84} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd)
Task: {D855C391-A3AE-468B-98A2-334649CED02E} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {DAB5F04E-A91F-4319-91E4-255E00256CA7} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe No File
Task: {DB559B72-B407-4035-B1A0-73820E5CA5E7} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe No File
Task: {DBCF6E1B-CE0A-441E-B7A5-219C8BE50C65} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
Task: {DECE5921-598D-454B-9A04-B2DE95EFC1B3} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
Task: {E0E82B76-8A12-4AA5-9499-FFD711442797} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe No File
Task: {E4DFE66F-E089-4CC3-A70F-957223D565F4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
Task: {E8DAA09B-DF2A-4951-9134-6FA9587793F9} - System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers => C:\Windows\System32\drvinst.exe [2012-09-20] (Microsoft Corporation)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {ED0C1F69-C3A2-41EA-B8C3-3F0D83A1F6C0} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM
Task: {F0E587C1-BC07-4E1A-AABB-81E413522473} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe No File
Task: {F8784F0C-BD32-4163-A463-C6E0C88E7EBF} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe No File
Task: {FFB11403-4D99-4B9F-B2C6-4BB8C9B99834} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-25] (Adobe Systems Incorporated)
Task: {FFE3FD50-646E-4A64-913B-23C4187E6025} - System32\Tasks\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (08/13/2013 05:59:44 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5828
Error: (08/13/2013 05:59:44 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5828
Error: (08/13/2013 05:59:44 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (08/13/2013 05:59:42 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3906
Error: (08/13/2013 05:59:42 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3906
Error: (08/13/2013 05:59:42 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (08/13/2013 05:59:40 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1953
Error: (08/13/2013 05:59:40 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1953
Error: (08/13/2013 05:59:40 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (08/13/2013 00:58:00 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5859
System errors:
=============
Error: (08/14/2013 09:58:13 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (08/14/2013 09:58:13 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1330
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (08/14/2013 09:56:12 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet.
Error: (08/14/2013 09:54:58 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst StarMoney Business 5.0 OnlineUpdate erreicht.
Error: (08/14/2013 00:26:59 AM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (08/13/2013 00:34:29 PM) (Source: DCOM) (User: Admin-PC)
Description: {ED1D0FDF-4414-470A-A56D-CFB68623FC58}
Error: (08/13/2013 08:39:33 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (08/13/2013 08:39:33 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1330
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (08/13/2013 08:37:42 AM) (Source: DCOM) (User: Admin-PC)
Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}Admin-PCAdminS-1-5-21-1950117156-4129327238-117919278-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (08/13/2013 08:37:42 AM) (Source: DCOM) (User: Admin-PC)
Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}Admin-PCAdminS-1-5-21-1950117156-4129327238-117919278-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Microsoft Office Sessions:
=========================
Error: (08/13/2013 05:59:44 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5828
Error: (08/13/2013 05:59:44 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5828
Error: (08/13/2013 05:59:44 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (08/13/2013 05:59:42 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3906
Error: (08/13/2013 05:59:42 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3906
Error: (08/13/2013 05:59:42 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (08/13/2013 05:59:40 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1953
Error: (08/13/2013 05:59:40 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1953
Error: (08/13/2013 05:59:40 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (08/13/2013 00:58:00 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5859
CodeIntegrity Errors:
===================================
Date: 2013-07-19 11:16:32.705
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll with signing level Unsigned while the system requires signing level Microsoft or better to load.
Date: 2013-07-19 11:16:32.529
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll with signing level Unsigned while the system requires signing level Microsoft or better to load.
Date: 2013-07-19 11:16:31.355
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll with signing level Unsigned while the system requires signing level Microsoft or better to load.
Date: 2013-07-19 11:16:31.092
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll with signing level Unsigned while the system requires signing level Microsoft or better to load.
Date: 2013-07-19 11:16:30.988
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll with signing level Unsigned while the system requires signing level Microsoft or better to load.
Date: 2013-07-19 11:16:30.853
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll with signing level Unsigned while the system requires signing level Microsoft or better to load.
Date: 2013-07-19 11:16:26.202
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll with signing level Unsigned while the system requires signing level Microsoft or better to load.
Date: 2013-07-19 11:16:23.048
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll with signing level Unsigned while the system requires signing level Microsoft or better to load.
Date: 2013-07-19 11:05:16.967
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll with signing level Unsigned while the system requires signing level Microsoft or better to load.
Date: 2013-07-19 11:05:16.345
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll with signing level Unsigned while the system requires signing level Microsoft or better to load.
==================== Memory info ===========================
Percentage of memory in use: 89%
Total physical RAM: 2046.08 MB
Available physical RAM: 223.04 MB
Total Pagefile: 4094.08 MB
Available Pagefile: 1764.71 MB
Total Virtual: 8192 MB
Available Virtual: 8191.76 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:207.04 GB) (Free:59.74 GB) NTFS (Disk=0 Partition=2)
Drive d: (Daten) (Fixed) (Total:258.62 GB) (Free:138.1 GB) NTFS (Disk=0 Partition=3)
Drive o: (Expansion Drive) (Fixed) (Total:931.51 GB) (Free:0.11 GB) NTFS (Disk=1 Partition=1)
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 3EFCFCC6)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=207 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=259 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 932 GB) (Disk ID: 005B7DD0)
Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Code:
2013-08-13 06:41:09,267 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 07:05:35,448 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 07:08:16,307 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 08:40:43,911 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 08:46:39,790 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 09:40:45,838 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 10:13:35,974 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 10:50:13,052 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 11:40:15,183 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 12:32:18,094 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 14:03:55,854 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 14:15:29,447 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 15:44:54,072 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 17:32:48,735 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 19:04:51,419 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 19:28:17,928 3382 MSG:<actionitem><actionid>2</actionid></actionitem>
2013-08-13 19:28:19,618 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 19:28:20,835 3382 MSG:<actionitem><actionid>1400</actionid><status>C:\Program Files (x86)\AVG\AVG2013\awacs\firewallicon\component\fwfree.html</status></actionitem>
2013-08-13 19:28:21,222 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 19:28:22,270 3382 MSG:<actionitem><actionid>1400</actionid><status>C:\Program Files (x86)\AVG\AVG2013\banners\free\ge.html</status></actionitem>
2013-08-13 19:28:27,532 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 20:05:34,396 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:06:27,944 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:06:27,944 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:06:35,285 3382 MSG:<actionitem><actionid>1200</actionid><status>1</status></actionitem>
2013-08-13 21:06:43,880 3382 MSG:<actionitem><actionid>1400</actionid><status>avg://open_report(033e6244-5e65-4f1a-a26d-6d1e09917d7d)/</status></actionitem>
2013-08-13 21:06:43,905 3382 MSG:<actionitem><actionid>1500</actionid></actionitem>
2013-08-13 21:08:00,246 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:08:51,184 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:14:08,663 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:20:24,034 3382 MSG:<actionitem><actionid>3</actionid></actionitem>
2013-08-13 21:21:49,252 3382 MSG:<actionitem><actionid>2</actionid></actionitem>
2013-08-13 21:21:50,567 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:21:51,311 3382 MSG:<actionitem><actionid>1400</actionid><status>C:\Program Files (x86)\AVG\AVG2013\awacs\firewallicon\component\fwfree.html</status></actionitem>
2013-08-13 21:21:51,788 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:21:51,986 3382 MSG:<actionitem><actionid>1400</actionid><status>C:\Program Files (x86)\AVG\AVG2013\banners\free\ge.html</status></actionitem>
2013-08-13 21:22:01,953 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:22:22,591 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:22:30,009 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 21:35:46,808 3382 MSG:<actionitem><actionid>1400</actionid><status>about:blank</status></actionitem>
2013-08-13 22:26:20,008 3382 MSG:<actionitem><actionid>3</actionid></actionitem> |