FSRT:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-08-2013
Ran by ***** (administrator) on 23-08-2013 11:22:20
Running from K:\Antivirenzeugs
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
() C:\Program Files (x86)\Tor\tor.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Alienware) C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe
(Dropbox, Inc.) C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
(PowerISO Computing, Inc.) C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Alienware) C:\Program Files\Alienware\Command Center\ThermalController.exe
(Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
() C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\avcenter.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6419560 2011-11-21] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-21] (Realtek Semiconductor)
HKLM\...\Run: [Launch Keyboard CI] - C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe [3439928 2012-07-11] (Alienware)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [Command Center Controllers] - C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [12656 2012-07-25] (Alienware)
HKCU\...\Run: [EA Core] - "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent [x]
HKCU\...\Run: [HP Photosmart 5510 series (NET)] - C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [2676584 2011-09-16] (Hewlett-Packard Co.)
MountPoints2: J - J:\Autorun.exe
MountPoints2: M - M:\Autorun.exe
MountPoints2: {8844ef79-9ea4-11e2-a07c-d4bed9fd526c} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL K:\index.html
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [RUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PWRISOVM.EXE] - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [180224 2009-07-27] (PowerISO Computing, Inc.)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
AppInit_DLLs-x32: c:\progra~3\browse~1\261519~1.190\{c16c1~1\browse~1.dll [97280 2009-07-14] ()
Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: msdaipp - No CLSID Value -
Handler-x32: msdaipp - No CLSID Value -
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default
FF NetworkProxy: "backup.ftp", ""
FF NetworkProxy: "backup.ftp_port", 0
FF NetworkProxy: "backup.socks", ""
FF NetworkProxy: "backup.socks_port", 0
FF NetworkProxy: "backup.ssl", ""
FF NetworkProxy: "backup.ssl_port", 0
FF NetworkProxy: "ftp", "112.115.5.37:$"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "112.115.5.37:$"
FF NetworkProxy: "ssl", "112.115.5.37:$"
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\icq-search.xml
FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{4EA20D6D-D7F6-4C7D-A61F-EA5ECBA9A302}.xml
FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{BCAFAC8D-52F8-440B-B859-12339354365D}.xml
FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{D8DE6131-5A57-473B-B1CC-3198470737B2}.xml
FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{F117ECFC-ECBC-4B1D-997F-D7C69D90110F}.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
FF Extension: LavaFox V2-Blue - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\Extensions\djziggy@gmail.com
FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-23] ()
R2 Windows Internet Name Service; C:\Windows\SysWow64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe [2735616 2013-08-23] ()
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-08-20] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-05] (Avira Operations GmbH & Co. KG)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [26072 2012-08-08] (Intel Corporation)
R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [114568 2013-02-08] (Renesas Electronics Corporation)
R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [216064 2011-09-15] (Renesas Electronics Corporation)
S3 BTMCOM; System32\Drivers\btmcom.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-23 11:04 - 2013-08-23 11:05 - 00000000 ____D C:\AdwCleaner
2013-08-23 10:56 - 2013-08-23 10:56 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-23 10:56 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-23 10:56 - 2013-08-23 10:56 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-23 10:56 - 2013-08-23 10:56 - 00000000 ____D C:\ProgramData\Sun
2013-08-23 10:56 - 2013-08-23 10:55 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-08-23 10:56 - 2013-08-23 10:55 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-08-23 10:56 - 2013-08-23 10:55 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-23 10:55 - 2013-08-23 10:55 - 00000000 ____D C:\Program Files (x86)\Java
2013-08-23 10:54 - 2013-08-23 10:54 - 00903080 _____ (Oracle Corporation) C:\Users\*****\Downloads\JavaSetup7u25.exe
2013-08-23 10:17 - 2013-08-23 10:17 - 00000000 ____D C:\Program Files (x86)\Tor
2013-08-22 21:59 - 2013-08-22 21:59 - 99814594 _____ C:\Windows\SysWOW64\থऽ赤™
2013-08-21 17:52 - 2013-08-21 17:52 - 15899557 _____ C:\Users\*****\Desktop\bauantragsformulare.zip
2013-08-21 12:46 - 2013-08-21 12:47 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Grundstücksart
2013-08-21 11:03 - 2013-08-21 11:03 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Nachbarschaft
2013-08-19 21:58 - 2013-08-19 23:01 - 00000000 ____D C:\Users\*****\Desktop\2013-08-19 Worlds
2013-08-19 20:08 - 2013-08-18 10:56 - 77797091 _____ C:\Users\*****\Desktop\2013-08-18_Objekte.Sims3Pack
2013-08-17 23:45 - 2013-08-17 23:45 - 00000000 ____D C:\Users\*****\Desktop\2013-08-17 Worlds
2013-08-16 21:34 - 2013-08-17 00:01 - 00000000 ____D C:\Users\*****\Desktop\2013-08-16 Worlds
2013-08-15 14:03 - 2013-08-15 14:03 - 00000000 ____D C:\Users\*****\Desktop\Neuer Ordner
2013-08-15 14:00 - 2013-08-15 14:02 - 00000000 ____D C:\Program Files\s3pe
2013-08-15 14:00 - 2013-08-15 14:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Peter L Jones
2013-08-15 13:55 - 2013-08-15 13:56 - 00000000 ____D C:\Users\*****\Desktop\2013-08-15 Worlds
2013-08-14 18:23 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 18:23 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 18:23 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 18:23 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 18:23 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 18:23 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 18:23 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 18:23 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 18:23 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 18:23 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 18:23 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 18:23 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 18:23 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 18:23 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 18:23 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 18:23 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 18:23 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 18:23 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 18:23 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 18:23 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 18:23 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 18:23 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 18:23 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 18:23 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-14 18:23 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-14 18:23 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 18:23 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 18:23 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-14 18:23 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 18:23 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 18:23 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 18:19 - 2013-08-14 18:20 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 17:56 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 17:56 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 17:56 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 17:56 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 17:56 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 17:56 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 17:56 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 17:56 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 17:55 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 17:55 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 17:55 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 17:55 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 17:55 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 17:55 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 17:55 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 17:55 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 17:55 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 17:55 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 17:55 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 17:55 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 17:55 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 17:55 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 17:55 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 17:55 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 17:55 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 17:55 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 17:55 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-14 12:13 - 2013-08-23 11:07 - 00000000 ___RD C:\Users\*****\Dropbox
2013-08-14 12:13 - 2013-08-14 12:13 - 00001041 _____ C:\Users\*****\Desktop\Dropbox.lnk
2013-08-14 12:12 - 2013-08-14 12:12 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-08-14 12:01 - 2013-08-23 11:07 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox
2013-08-12 10:20 - 2013-08-21 23:36 - 00000000 ____D C:\Users\*****\Desktop\DLs
2013-08-06 18:28 - 2013-08-06 21:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-08-04 20:38 - 2013-08-04 20:38 - 00001458 _____ C:\Users\*****\AppData\Local\recently-used.xbel
2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\Extensions
==================== One Month Modified Files and Folders =======
2013-08-23 11:14 - 2009-07-14 06:45 - 00025648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-23 11:14 - 2009-07-14 06:45 - 00025648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-23 11:12 - 2013-04-06 07:26 - 00653928 _____ C:\Windows\system32\perfh007.dat
2013-08-23 11:12 - 2013-04-06 07:26 - 00129800 _____ C:\Windows\system32\perfc007.dat
2013-08-23 11:12 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-23 11:07 - 2013-08-14 12:13 - 00000000 ___RD C:\Users\*****\Dropbox
2013-08-23 11:07 - 2013-08-14 12:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox
2013-08-23 11:06 - 2013-04-05 22:00 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-23 11:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-23 11:06 - 2009-07-14 06:51 - 00043565 _____ C:\Windows\setupact.log
2013-08-23 11:05 - 2013-08-23 11:04 - 00000000 ____D C:\AdwCleaner
2013-08-23 11:05 - 2013-04-05 21:32 - 01641107 _____ C:\Windows\WindowsUpdate.log
2013-08-23 11:01 - 2013-04-28 11:53 - 00000254 _____ C:\Windows\Tasks\HP Photo Creations Messager.job
2013-08-23 10:56 - 2013-08-23 10:56 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-23 10:56 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-23 10:56 - 2013-08-23 10:56 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-23 10:56 - 2013-08-23 10:56 - 00000000 ____D C:\ProgramData\Sun
2013-08-23 10:55 - 2013-08-23 10:56 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-08-23 10:55 - 2013-08-23 10:56 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-08-23 10:55 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-23 10:55 - 2013-08-23 10:55 - 00000000 ____D C:\Program Files (x86)\Java
2013-08-23 10:54 - 2013-08-23 10:54 - 00903080 _____ (Oracle Corporation) C:\Users\*****\Downloads\JavaSetup7u25.exe
2013-08-23 10:17 - 2013-08-23 10:17 - 00000000 ____D C:\Program Files (x86)\Tor
2013-08-22 21:59 - 2013-08-22 21:59 - 99814594 _____ C:\Windows\SysWOW64\থऽ赤™
2013-08-22 16:22 - 2013-04-06 14:00 - 00000000 ____D C:\Users\*****\AppData\Local\Paint.NET
2013-08-21 23:36 - 2013-08-12 10:20 - 00000000 ____D C:\Users\*****\Desktop\DLs
2013-08-21 19:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-21 17:52 - 2013-08-21 17:52 - 15899557 _____ C:\Users\*****\Desktop\bauantragsformulare.zip
2013-08-21 12:47 - 2013-08-21 12:46 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Grundstücksart
2013-08-21 11:03 - 2013-08-21 11:03 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Nachbarschaft
2013-08-20 10:45 - 2013-05-07 18:57 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-20 10:45 - 2013-04-05 22:37 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-20 10:45 - 2013-04-05 22:37 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-19 23:01 - 2013-08-19 21:58 - 00000000 ____D C:\Users\*****\Desktop\2013-08-19 Worlds
2013-08-19 14:14 - 2013-04-06 14:00 - 00000000 ____D C:\Program Files\Paint.NET
2013-08-18 10:56 - 2013-08-19 20:08 - 77797091 _____ C:\Users\*****\Desktop\2013-08-18_Objekte.Sims3Pack
2013-08-17 23:45 - 2013-08-17 23:45 - 00000000 ____D C:\Users\*****\Desktop\2013-08-17 Worlds
2013-08-17 19:56 - 2013-04-06 12:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-17 18:24 - 2013-04-06 12:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-17 00:01 - 2013-08-16 21:34 - 00000000 ____D C:\Users\*****\Desktop\2013-08-16 Worlds
2013-08-15 14:03 - 2013-08-15 14:03 - 00000000 ____D C:\Users\*****\Desktop\Neuer Ordner
2013-08-15 14:02 - 2013-08-15 14:00 - 00000000 ____D C:\Program Files\s3pe
2013-08-15 14:00 - 2013-08-15 14:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Peter L Jones
2013-08-15 13:56 - 2013-08-15 13:55 - 00000000 ____D C:\Users\*****\Desktop\2013-08-15 Worlds
2013-08-14 18:20 - 2013-08-14 18:19 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 18:19 - 2013-04-05 23:56 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-14 12:18 - 2010-11-21 05:47 - 00020356 _____ C:\Windows\PFRO.log
2013-08-14 12:13 - 2013-08-14 12:13 - 00001041 _____ C:\Users\*****\Desktop\Dropbox.lnk
2013-08-14 12:13 - 2013-04-05 21:53 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-14 12:13 - 2013-04-05 21:52 - 00000000 ____D C:\Users\*****
2013-08-14 12:12 - 2013-08-14 12:12 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-08-13 18:24 - 2013-04-28 11:52 - 00000000 ____D C:\Users\*****\AppData\Roaming\HpUpdate
2013-08-13 12:13 - 2013-04-06 18:25 - 00000000 ___RD C:\Users\*****\Desktop\*****
2013-08-06 21:01 - 2013-08-06 18:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-08-04 20:39 - 2013-07-10 19:11 - 00000000 ____D C:\Users\*****\.gimp-2.8
2013-08-04 20:38 - 2013-08-04 20:38 - 00001458 _____ C:\Users\*****\AppData\Local\recently-used.xbel
2013-08-03 10:43 - 2010-11-21 09:16 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-07-28 16:53 - 2013-04-06 18:47 - 00000000 ____D C:\Users\*****\Documents\Electronic Arts
2013-07-28 16:52 - 2013-04-06 18:32 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-07-28 16:52 - 2013-04-05 22:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-26 07:13 - 2013-08-14 18:23 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-26 07:13 - 2013-08-14 18:23 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-26 07:13 - 2013-08-14 18:23 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-26 07:12 - 2013-08-14 18:23 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-26 07:12 - 2013-08-14 18:23 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-26 07:12 - 2013-08-14 18:23 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-26 07:12 - 2013-08-14 18:23 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-26 07:12 - 2013-08-14 18:23 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-26 07:12 - 2013-08-14 18:23 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-26 07:12 - 2013-08-14 18:23 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-26 07:12 - 2013-08-14 18:23 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-26 07:12 - 2013-08-14 18:23 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-26 07:12 - 2013-08-14 18:23 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-26 07:12 - 2013-08-14 18:23 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-26 05:35 - 2013-08-14 18:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-26 05:13 - 2013-08-14 18:23 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-26 05:13 - 2013-08-14 18:23 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-26 05:12 - 2013-08-14 18:23 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-26 05:12 - 2013-08-14 18:23 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-26 05:12 - 2013-08-14 18:23 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-26 05:12 - 2013-08-14 18:23 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-26 05:12 - 2013-08-14 18:23 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-26 05:12 - 2013-08-14 18:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-26 05:12 - 2013-08-14 18:23 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-26 05:12 - 2013-08-14 18:23 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-26 05:12 - 2013-08-14 18:23 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-26 05:11 - 2013-08-14 18:23 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-26 05:11 - 2013-08-14 18:23 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-26 04:49 - 2013-08-14 18:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-26 04:39 - 2013-08-14 18:23 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-26 03:59 - 2013-08-14 18:23 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-25 11:25 - 2013-08-14 17:55 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-25 10:57 - 2013-08-14 17:55 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-07-24 18:43 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-18 22:39
==================== End Of Log ============================ --- --- ---
--- --- --- Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-08-2013
Ran by ***** at 2013-08-23 11:22:46
Running from K:\Antivirenzeugs
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Flash Player ActiveX (x32 Version: 9.0.124.0)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
Alienware Command Center (Version: 2.8.11.0)
Alienware Command Center (x32 Version: 2.8.11.0)
Alienware TactX Keyboard CI 1.10.102 (Version: 1.10.102)
Avira Free Antivirus (x32 Version: 13.0.0.4045)
Cisco EAP-FAST Module (x32 Version: 2.2.14)
Cisco LEAP Module (x32 Version: 1.0.19)
Cisco PEAP Module (x32 Version: 1.1.6)
Die Sims™ 3 "Erstelle eine Welt"-Tool - Beta (x32 Version: 1.18.46)
Die Sims™ 3 (x32 Version: 1.55.4)
Die Sims™ 3 70er, 80er & 90er Accessoires (x32 Version: 17.0.77)
Die Sims™ 3 Design-Garten-Accessoires (x32 Version: 7.3.2)
Die Sims™ 3 Diesel Accessoires (x32 Version: 14.0.48)
Die Sims™ 3 Einfach tierisch (x32 Version: 10.0.96)
Die Sims™ 3 Gib Gas-Accessoires (x32 Version: 5.8.1)
Die Sims™ 3 Inselparadies (x32 Version: 19.0.101)
Die Sims™ 3 Jahreszeiten (x32 Version: 16.0.136)
Die Sims™ 3 Katy Perry Süße Welt (x32 Version: 13.0.62)
Die Sims™ 3 Late Night (x32 Version: 6.5.1)
Die Sims™ 3 Lebensfreude (x32 Version: 8.0.152)
Die Sims™ 3 Luxus-Accessoires (x32 Version: 3.13.1)
Die Sims™ 3 Reiseabenteuer (x32 Version: 2.17.2)
Die Sims™ 3 Showtime (x32 Version: 12.0.273)
Die Sims™ 3 Stadt-Accessoires (x32 Version: 9.0.73)
Die Sims™ 3 Supernatural (x32 Version: 15.0.135)
Die Sims™ 3 Traumkarrieren (x32 Version: 4.10.1)
Die Sims™ 3 Traumsuite-Accessoires (x32 Version: 11.0.84)
Die Sims™ 3 Wildes Studentenleben (x32 Version: 18.0.126)
Dropbox (HKCU Version: 2.0.26)
General Runtime Files for Nemetschek Allplan 2008 (x32 Version: 1.5.0.0)
HP FWUpdateEDO2 (x32 Version: 1.2.0.0)
HP Photo Creations (x32 Version: 1.0.0.5192)
HP Photosmart 5510 series - Grundlegende Software für das Gerät (Version: 25.0.621.0)
HP Photosmart 5510 series Hilfe (x32 Version: 140.0.2.2)
HP Update (x32 Version: 5.003.000.004)
HPDiagnosticAlert (x32 Version: 1.00.0000)
Intel(R) Management Engine Components (x32 Version: 7.1.21.1134)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Office Professional Edition 2003 (x32 Version: 11.0.5614.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0)
MozBackup 1.5.1 (x32)
Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1)
Mozilla Maintenance Service (x32 Version: 23.0.1)
Mozilla Thunderbird 17.0.8 (x86 de) (x32 Version: 17.0.8)
Nemetschek Allplan 2008 (x32 Version: 2008.0)
Nemetschek SoftLock 2006 (x32 Version: 1.00.0000)
NVIDIA 3D Vision Controller-Treiber 301.42 (Version: 301.42)
NVIDIA 3D Vision Treiber 301.42 (Version: 301.42)
NVIDIA Grafiktreiber 301.42 (Version: 301.42)
NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0)
NVIDIA Install Application (Version: 2.1002.109.718)
NVIDIA Optimus 1.8.15 (Version: 1.8.15)
NVIDIA PhysX (x32 Version: 9.12.0213)
NVIDIA PhysX-Systemsoftware 9.12.0213 (Version: 9.12.0213)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.0142)
NVIDIA Systemsteuerung 301.42 (Version: 301.42)
NVIDIA Update Components (Version: 1.8.15)
OpenOffice.org 3.4.1 (x32 Version: 3.41.9593)
Origin (x32 Version: 9.1.15.109)
Paint.NET v3.5.11 (Version: 3.61.0)
PDF Architect (x32 Version: 1.0.52.8917)
PDFCreator (x32 Version: 1.6.2)
PowerISO (x32)
Ralink RT2870 Wireless LAN Card (x32 Version: 1.5.9.0)
Realtek Ethernet Controller Driver (x32 Version: 7.46.610.2011)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6505)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 3.0.8.0)
rosoft .NET Framework 4 Client Profile (Version: 4.0.30319)
s3pe - Sims3 Package Editor (x32 Version: 13-0316-1933)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
==================== Restore Points =========================
19-08-2013 12:13:52 Paint.NET v3.5.11
22-08-2013 11:33:18 Windows Update
23-08-2013 08:55:40 Installed Java 7 Update 25
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {090DBEF1-32E4-4834-8A4C-7EF1AC381BFF} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {496DD7E7-7A6E-4C34-BECB-1488E4CE30EC} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation)
Task: {4BDB74F3-10EF-439A-BAA8-6760DD4F8A40} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {719B49BD-96EC-4C8B-9950-3A5196316DBB} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated)
Task: {8C2D951C-763C-48F9-9C4A-5CD4325896BD} - System32\Tasks\AdobeFlashPlayerUpdate => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated)
Task: {C3DA8E0C-07A3-4AE3-A655-29FF4A093B3D} - \BrowserProtect No Task File
Task: {DED33DCB-3F08-4B6D-806A-6D87935A8255} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] ()
Task: {FE5B4966-6B30-4C9E-87DC-BDD7AAA034E7} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/23/2013 11:07:30 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/23/2013 11:00:44 AM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
Error: (08/23/2013 10:17:57 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/23/2013 10:17:51 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00011380
ID des fehlerhaften Prozesses: 0x1010
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (08/22/2013 11:23:03 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/22/2013 09:58:56 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00011380
ID des fehlerhaften Prozesses: 0x2868
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (08/22/2013 03:59:00 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00011380
ID des fehlerhaften Prozesses: 0xcbc
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (08/22/2013 03:23:55 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/22/2013 02:14:14 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
Error: (08/22/2013 01:23:13 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
System errors:
=============
Error: (08/22/2013 11:21:23 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 22.08.2013 um 23:19:46 unerwartet heruntergefahren.
Error: (08/18/2013 01:53:09 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005
Error: (08/15/2013 06:51:48 PM) (Source: NetBT) (User: )
Description: Der Name "*****-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.146
registriert werden. Der Computer mit IP-Adresse 192.168.0.192 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/15/2013 06:42:55 PM) (Source: NetBT) (User: )
Description: Der Name "*****-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.146
registriert werden. Der Computer mit IP-Adresse 192.168.0.192 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/15/2013 06:42:55 PM) (Source: Server) (User: )
Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{B9E9EE2E-3D49-446A-8418-C4C764F71209} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden.
Error: (08/15/2013 06:42:48 PM) (Source: NetBT) (User: )
Description: Der Name "*****-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.146
registriert werden. Der Computer mit IP-Adresse 192.168.0.192 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/14/2013 04:32:55 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005
Error: (08/14/2013 01:55:48 PM) (Source: NetBT) (User: )
Description: Der Name "*****-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.146
registriert werden. Der Computer mit IP-Adresse 192.168.0.192 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/14/2013 01:55:47 PM) (Source: NetBT) (User: )
Description: Der Name "*****-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.146
registriert werden. Der Computer mit IP-Adresse 192.168.0.192 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/14/2013 01:53:04 PM) (Source: NetBT) (User: )
Description: Der Name "*****-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.146
registriert werden. Der Computer mit IP-Adresse 192.168.0.192 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Microsoft Office Sessions:
=========================
Error: (08/23/2013 11:07:30 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/23/2013 11:00:44 AM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
Error: (08/23/2013 10:17:57 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/23/2013 10:17:51 AM) (Source: Application Error)(User: )
Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500011380101001ce9fd92c653530C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe807176ec-0bcc-11e3-ae9a-d4bed9fd526c
Error: (08/22/2013 11:23:03 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/22/2013 09:58:56 PM) (Source: Application Error)(User: )
Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500011380286801ce9f720696f6aeC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe46ae0a95-0b65-11e3-9626-d4bed9fd526c
Error: (08/22/2013 03:59:00 PM) (Source: Application Error)(User: )
Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500011380cbc01ce9f3fbbf018e2C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exefe68f377-0b32-11e3-9626-d4bed9fd526c
Error: (08/22/2013 03:23:55 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/22/2013 02:14:14 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
Error: (08/22/2013 01:23:13 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
==================== Memory info ===========================
Percentage of memory in use: 17%
Total physical RAM: 16300.23 MB
Available physical RAM: 13472.86 MB
Total Pagefile: 32598.64 MB
Available Pagefile: 29447.59 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:921.13 GB) (Free:501.62 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:9.73 GB) (Free:2.76 GB) NTFS
Drive k: (TRANSCEND) (Removable) (Total:3.73 GB) (Free:3.06 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 9CEB53D4)
Partition: GPT Partition Type
========================================================
Disk: 1 (Size: 4 GB) (Disk ID: 0FF16EAD)
Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)
==================== End Of Log ============================ |