elbereth116 | 12.09.2013 15:10 | Avira findet ADWARE/bProtect.D Hallo,
Avira hat heute Alarm geschlagen wegen ADWARE/bProtect.D.
Habe schon ein bisschen gelesen, was anderen bei diesem Problem geraten wurde und deswegen schon FRST 32-Bit scannen lassen. Ich wäre wirklich froh, wenn ihr mir weiterhelfen könntet! Schon mal danke :)
Hier die FRST.txt Datei: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-09-2013 02
Ran by Carina_2 (ATTENTION: The logged in user is not administrator) on CARINA-PC on 12-09-2013 15:40:15
Running from C:\Users\Carina_2\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Inc.) C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
(Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
(Acer Incorporated) C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
() C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor Corp.) C:\Users\Carina_2\AppData\Local\Temp\RtkBtMnt.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(CyberLink Corp.) C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
(CyberLink) C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
() C:\Program Files\Winamp\winampa.exe
(sonix) C:\Windows\PLFSetL.exe
() C:\Windows\PLFSetI.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\ICQ.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Mozilla Corporation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\program files\avira\antivir desktop\avcenter.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6111232 2008-04-28] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1033512 2008-01-18] (Synaptics, Inc.)
HKLM\...\Run: [ePower_DMC] - C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [397312 2008-04-23] (Acer Inc.)
HKLM\...\Run: [eDataSecurity Loader] - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [526896 2008-03-04] (Egis Incorporated)
HKLM\...\Run: [eAudio] - C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe [544768 2008-03-07] (Acer Incorporated)
HKLM\...\Run: [BkupTray] - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [34040 2008-04-06] ()
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [182808 2008-07-20] (Intel Corporation)
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [LManager] - C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE [821768 2008-07-02] (Dritek System Inc.)
HKLM\...\Run: [Google Desktop Search] - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-18] (Google)
HKLM\...\Run: [ArcadeDeluxeAgent] - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [147456 2008-05-12] (CyberLink Corp.)
HKLM\...\Run: [CLMLServer] - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [167936 2008-05-12] (CyberLink)
HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [36352 2008-08-04] ()
HKLM\...\Run: [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [80896 2007-08-22] (Hewlett-Packard)
HKLM\...\Run: [PLFSetL] - C:\Windows\PLFSetL.exe [94208 2007-07-05] (sonix)
HKLM\...\Run: [PLFSetI] - C:\Windows\PLFSetI.exe [200704 2007-10-23] ()
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-12] (Avira Operations GmbH & Co. KG)
HKLM\...\Runonce: [awat7zip55018] - [x]
HKLM\...\RunOnce: [EBURUN0] - C:\PROGRA~1\MICROS~1\AGEOFM~1\msxmlger.msi /Q [1144320 2002-10-15] ()
HKLM\...\Runonce: [EBUSetup] - C:\Windows\system32\cmd.exe /C C:\Users\Carina\AppData\Local\Temp\DelUS.bat
Winlogon\Notify\AWinNotifyVitaKey MC3000:
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2009-01-09] (Google Inc.)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [ICQ] - C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\ICQ.exe [124480 2011-08-01] (ICQ, LLC.)
HKCU\...\Runonce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_Plugin.exe -update plugin
MountPoints2: H - H:\AutoRun.exe
MountPoints2: {a4fbc0a0-e0a3-11dd-882f-00238b31440c} - H:\LaunchU3.exe -a
MountPoints2: {bbf9b21a-dae3-11de-916c-00238b31440c} - G:\autorun.exe
Startup: C:\Users\Carina_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=TJ&userid=92ecf892-2805-4f3e-8291-8a1b4f19607f&searchtype=ds&q={searchTerms}&installDate=13/08/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=TJ&userid=92ecf892-2805-4f3e-8291-8a1b4f19607f&searchtype=hp&installDate=13/08/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0c07&s=2&o=vp32&d=1108&m=aspire_7730g
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=TJ&userid=92ecf892-2805-4f3e-8291-8a1b4f19607f&searchtype=ds&q={searchTerms}&installDate=13/08/2013
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=HitachiXHTS543232L9A300_081008FB2400LECDWJNAX&ts=1376383631
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=HitachiXHTS543232L9A300_081008FB2400LECDWJNAX&ts=1376383631
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=HitachiXHTS543232L9A300_081008FB2400LECDWJNAX&ts=1376383631
SearchScopes: HKLM - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=TJ&userid=92ecf892-2805-4f3e-8291-8a1b4f19607f&searchtype=ds&q={searchTerms}&installDate=13/08/2013
SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=TJ&userid=92ecf892-2805-4f3e-8291-8a1b4f19607f&searchtype=ds&q={searchTerms}&installDate=13/08/2013
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=HitachiXHTS543232L9A300_081008FB2400LECDWJNAX&ts=1376383631
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2319825
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=TJ&userid=92ecf892-2805-4f3e-8291-8a1b4f19607f&searchtype=ds&q={searchTerms}&installDate=13/08/2013
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
SearchScopes: HKCU - {70D46D94-BF1E-45ED-B567-48701376298E} URL = hxxp://127.0.0.1:4664/search&s=9yYUHqZDKnWxPt84cY4eAHj6gnk?q={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: Winload Toolbar - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\prxtbWinl.dll (Conduit Ltd.)
BHO: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM - loadtbs - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - loadtbs\toolbar.dll No File
Toolbar: HKLM - Winload Toolbar - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\prxtbWinl.dll (Conduit Ltd.)
Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -Winload Toolbar - {40C3CC16-7269-4B32-9531-17F2950FB06F} - C:\Program Files\Winload\prxtbWinl.dll (Conduit Ltd.)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 140.78.2.62 140.78.3.62
FireFox:
========
FF ProfilePath: C:\Users\Carina_2\AppData\Roaming\Mozilla\Firefox\Profiles\x4ag9lv2.default
FF NewTab: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=TJ&userid=92ecf892-2805-4f3e-8291-8a1b4f19607f&searchtype=nt&installDate=13/08/2013&q=
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Homepage: https://www.google.at/
FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=TJ&userid=92ecf892-2805-4f3e-8291-8a1b4f19607f&searchtype=ds&installDate=13/08/2013&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @cambridgesoft.com/Chem3D,version=12.0 - C:\Program Files\CambridgeSoft\ChemOffice2010\Chem3D\npChem3DPlugin.dll (CambridgeSoft Corp.)
FF Plugin: @cambridgesoft.com/ChemDraw,version=12.0 - C:\Program Files\CambridgeSoft\ChemOffice2010\ChemDraw\npcdp32.dll (CambridgeSoft Corp.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - E:\Programme\PDF X Change Viewer\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nosltd.com/getPlus+(R),version=1.6.2.91 - C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @wolfram.com/Mathematica - C:\Program Files\Common Files\Wolfram Research\Browser\9.0.0.3824406\npmathplugin.dll (Wolfram Research, Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\Carina_2\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
FF SearchPlugin: C:\Users\Carina_2\AppData\Roaming\Mozilla\Firefox\Profiles\x4ag9lv2.default\searchplugins\BrowserDefender.xml
FF SearchPlugin: C:\Users\Carina_2\AppData\Roaming\Mozilla\Firefox\Profiles\x4ag9lv2.default\searchplugins\icqplugin-1.xml
FF SearchPlugin: C:\Users\Carina_2\AppData\Roaming\Mozilla\Firefox\Profiles\x4ag9lv2.default\searchplugins\icqplugin.xml
FF SearchPlugin: C:\Users\Carina_2\AppData\Roaming\Mozilla\Firefox\Profiles\x4ag9lv2.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Users\Carina_2\AppData\Roaming\Mozilla\Firefox\Profiles\x4ag9lv2.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\googledesktop.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\qvo6.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Carina_2\AppData\Roaming\Mozilla\Firefox\Profiles\x4ag9lv2.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: No Name - C:\Users\Carina_2\AppData\Roaming\Mozilla\Firefox\Profiles\x4ag9lv2.default\Extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF Extension: toolbar - C:\Users\Carina_2\AppData\Roaming\Mozilla\Firefox\Profiles\x4ag9lv2.default\Extensions\toolbar@gmx.net.xpi
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF HKLM\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=HitachiXHTS543232L9A300_081008FB2400LECDWJNAX&ts=1376383631
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchURL: (Google) - {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\17.0.963.46\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\17.0.963.46\pdf.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\17.0.963.46\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
CHR Plugin: (QuickTime Plug-in 7.6.6) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.6) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.6) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.6) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.6) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.6) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.6) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (getPlusPlus for Adobe 16291) - C:\Program Files\Mozilla Firefox\plugins\np_gp.dll (NOS Microsystems Ltd.)
CHR Plugin: (Bio3D) - C:\Program Files\CambridgeSoft\ChemOffice2010\Chem3D\npChem3DPlugin.dll (CambridgeSoft Corp.)
CHR Plugin: (ChemDraw) - C:\Program Files\CambridgeSoft\ChemOffice2010\ChemDraw\npcdp32.dll (CambridgeSoft Corp.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll No File
CHR Plugin: (Move Media Player 7) - C:\Users\Carina_2\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (YouTube) - C:\Users\Carina_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0
CHR Extension: (Google Search) - C:\Users\Carina_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Carina_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0
CHR Extension: (Gmail) - C:\Users\Carina_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-12] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-12] (Avira Operations GmbH & Co. KG)
R2 BrowserDefendert; C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [2847696 2013-07-26] ()
R2 CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [81504 2008-01-16] ()
R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2008-03-21] ()
S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-18] (Google)
R2 iphlpsvc; C:\Windows\System32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-12-06] ()
R2 NlaSvc; C:\Windows\System32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [131072 2008-04-04] ()
R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [272024 2007-01-09] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [1528672 2012-05-29] (TuneUp Software)
R2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [891456 2013-08-13] (Wsys Co., Ltd.)
==================== Drivers (Whitelisted) ====================
S3 A310; C:\Windows\System32\DRIVERS\AVerA310USB.sys [25856 2008-04-15] (AVerMedia TECHNOLOGIES, Inc.)
R3 ATSWPDRV; C:\Windows\System32\DRIVERS\ATSwpDrv.sys [146688 2008-04-25] (AuthenTec, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-12] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-12] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-26] (Avira Operations GmbH & Co. KG)
S3 BDASwCap; C:\Windows\System32\drivers\AVerA310Cap.sys [42880 2008-04-15] (AVerMedia TECHNOLOGIES, Inc.)
R0 CLFS; C:\Windows\System32\CLFS.sys [247352 2008-01-21] (Microsoft Corporation)
R2 int15; C:\Windows\system32\drivers\int15.sys [69632 2007-01-26] ()
R2 NTIPPKernel; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [122368 2008-01-16] (Cyberlink Corp.)
R3 ROCKEYNT; C:\Windows\System32\DRIVERS\Rockey4.sys [22528 2011-11-15] (Feitian Technologies Co., Ltd.)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1769984 2007-10-01] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2009-11-27] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-26] (Avira GmbH)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [10064 2012-05-08] (TuneUp Software)
R3 winbondcir; C:\Windows\System32\DRIVERS\winbondcir.sys [43008 2007-03-28] (Winbond Electronics Corporation)
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [61424 2008-05-09] (Cyberlink Corp.)
U3 a07r7pxr; C:\Windows\System32\Drivers\a07r7pxr.sys [0 ] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-12 15:38 - 2013-09-12 15:38 - 01082587 _____ (Farbar) C:\Users\Carina_2\Desktop\FRST.exe
2013-08-20 17:55 - 2013-08-28 19:29 - 00000000 ____D C:\Users\Carina_2\AppData\Local\Mozilla Firefox
2013-08-20 14:55 - 2013-08-20 14:55 - 00001917 _____ C:\Users\Public\Desktop\Age of Mythology.lnk
2013-08-13 11:00 - 2013-08-13 11:00 - 00000000 ____D C:\Users\Carina\AppData\Local\Macromedia
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\Users\Carina\AppData\Roaming\Babylon
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\Users\Carina\AppData\Roaming\BabSolution
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\ProgramData\BrowserDefender
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\ProgramData\Babylon
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\Program Files\BabylonToolbar
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\Program Files\7-Zip
2013-08-13 10:51 - 2013-08-13 10:51 - 00000000 ____D C:\Users\Carina\AppData\Roaming\Swiss Academic Software
2013-08-13 10:50 - 2013-08-13 10:51 - 00000000 ____D C:\Users\Carina\AppData\Local\Smartbar
2013-08-13 10:50 - 2013-08-13 10:50 - 00000000 ____D C:\Users\Carina_2\AppData\Roaming\7-PDFMaker
2013-08-13 10:49 - 2013-08-13 10:49 - 00000900 _____ C:\Users\Public\Desktop\7-PDF Maker.lnk
2013-08-13 10:49 - 2013-08-13 10:49 - 00000000 ____D C:\Users\Carina\AppData\Roaming\7-PDFMaker
2013-08-13 10:49 - 2013-08-13 10:49 - 00000000 ____D C:\Program Files\Common Files\7-PDF
2013-08-13 10:49 - 2013-08-13 10:49 - 00000000 ____D C:\Program Files\7-PDF
2013-08-13 10:48 - 2013-08-13 10:48 - 55633177 _____ (7-PDF, Germany ) C:\Users\Carina_2\Downloads\7p141.exe
2013-08-13 10:47 - 2013-09-12 14:28 - 00000000 ____D C:\ProgramData\eSafe
2013-08-13 10:47 - 2013-08-13 10:47 - 00000000 ____D C:\Users\Carina\AppData\Roaming\eIntaller
==================== One Month Modified Files and Folders =======
2013-09-12 15:39 - 2013-09-12 15:39 - 00000000 ____D C:\FRST
2013-09-12 15:38 - 2013-09-12 15:38 - 01082587 _____ (Farbar) C:\Users\Carina_2\Desktop\FRST.exe
2013-09-12 15:37 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-12 15:37 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-12 15:32 - 2012-09-15 08:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-12 15:32 - 2012-09-15 08:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-12 15:32 - 2012-09-15 08:38 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-12 15:12 - 2013-07-26 18:13 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-09-12 15:12 - 2013-07-26 18:13 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-09-12 14:50 - 2011-10-24 23:44 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-12 14:28 - 2013-08-13 10:47 - 00000000 ____D C:\ProgramData\eSafe
2013-09-12 14:27 - 2008-11-13 18:19 - 01807246 _____ C:\Windows\WindowsUpdate.log
2013-09-12 14:23 - 2009-01-10 00:47 - 00069944 _____ C:\ProgramData\nvModes.001
2013-09-12 09:50 - 2011-10-24 23:44 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-12 09:19 - 2008-01-21 09:16 - 01432888 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-12 09:06 - 2008-11-13 19:21 - 00000000 _____ C:\Windows\system32\LogConfigTemp.xml
2013-09-12 09:04 - 2008-04-18 11:49 - 00000147 _____ C:\Windows\system32\agent.log
2013-09-12 09:03 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-12 09:02 - 2008-01-21 04:47 - 06991486 _____ C:\Windows\PFRO.log
2013-09-05 17:57 - 2009-01-10 14:52 - 00000012 _____ C:\Windows\bthservsdp.dat
2013-09-05 17:57 - 2006-11-02 15:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-05 16:37 - 2010-08-23 20:08 - 00000000 ____D C:\Users\Carina_2\AppData\Local\Paint.NET
2013-09-05 13:05 - 2009-01-12 17:06 - 00000000 ____D C:\Users\Carina_2\AppData\Local\Google
2013-09-05 10:37 - 2009-01-12 17:29 - 00002633 _____ C:\Users\Carina_2\Desktop\Microsoft Office Excel 2007.lnk
2013-09-04 09:11 - 2009-03-10 15:39 - 00000000 ____D C:\Users\Carina_2\AppData\Roaming\dvdcss
2013-09-03 18:13 - 2009-04-29 00:20 - 00000584 _____ C:\Users\Carina_2\Documents\grstyles.stl
2013-09-02 16:38 - 2008-04-18 11:18 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-28 19:29 - 2013-08-20 17:55 - 00000000 ____D C:\Users\Carina_2\AppData\Local\Mozilla Firefox
2013-08-28 19:23 - 2008-04-18 11:44 - 00001024 ___RH C:\Users\Public\Documents\NTIMP3.dll
2013-08-28 19:20 - 2006-11-02 14:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-08-20 16:15 - 2009-01-10 00:39 - 00069944 _____ C:\ProgramData\nvModes.dat
2013-08-20 14:58 - 2009-01-12 17:06 - 00099376 _____ C:\Users\Carina_2\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-20 14:57 - 2006-11-02 14:47 - 00366776 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-20 14:55 - 2013-08-20 14:55 - 00001917 _____ C:\Users\Public\Desktop\Age of Mythology.lnk
2013-08-20 14:46 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Microsoft Games
2013-08-13 20:18 - 2009-01-12 17:22 - 00219136 _____ C:\Users\Carina_2\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-08-13 11:00 - 2013-08-13 11:00 - 00000000 ____D C:\Users\Carina\AppData\Local\Macromedia
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\Users\Carina\AppData\Roaming\Babylon
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\Users\Carina\AppData\Roaming\BabSolution
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\ProgramData\BrowserDefender
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\ProgramData\Babylon
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\Program Files\BabylonToolbar
2013-08-13 10:59 - 2013-08-13 10:59 - 00000000 ____D C:\Program Files\7-Zip
2013-08-13 10:59 - 2009-12-22 00:21 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-13 10:59 - 2009-01-09 21:44 - 00000000 ____D C:\Users\Carina
2013-08-13 10:51 - 2013-08-13 10:51 - 00000000 ____D C:\Users\Carina\AppData\Roaming\Swiss Academic Software
2013-08-13 10:51 - 2013-08-13 10:50 - 00000000 ____D C:\Users\Carina\AppData\Local\Smartbar
2013-08-13 10:51 - 2009-01-11 21:42 - 00098992 _____ C:\Users\Carina\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-13 10:51 - 2009-01-09 21:47 - 00000000 ____D C:\Users\Carina\AppData\Local\Google
2013-08-13 10:50 - 2013-08-13 10:50 - 00000000 ____D C:\Users\Carina_2\AppData\Roaming\7-PDFMaker
2013-08-13 10:49 - 2013-08-13 10:49 - 00000900 _____ C:\Users\Public\Desktop\7-PDF Maker.lnk
2013-08-13 10:49 - 2013-08-13 10:49 - 00000000 ____D C:\Users\Carina\AppData\Roaming\7-PDFMaker
2013-08-13 10:49 - 2013-08-13 10:49 - 00000000 ____D C:\Program Files\Common Files\7-PDF
2013-08-13 10:49 - 2013-08-13 10:49 - 00000000 ____D C:\Program Files\7-PDF
2013-08-13 10:49 - 2012-08-18 13:35 - 00000000 ____D C:\Users\Carina\AppData\Roaming\OpenCandy
2013-08-13 10:48 - 2013-08-13 10:48 - 55633177 _____ (7-PDF, Germany ) C:\Users\Carina_2\Downloads\7p141.exe
2013-08-13 10:47 - 2013-08-13 10:47 - 00000000 ____D C:\Users\Carina\AppData\Roaming\eIntaller
Files to move or delete:
====================
C:\Users\Carina\AppData\Local\Temp\7z920.exe
C:\Users\Carina\AppData\Local\Temp\AskSLib.dll
C:\Users\Carina\AppData\Local\Temp\AutoRun.exe
C:\Users\Carina\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Carina\AppData\Local\Temp\BabylonTB.exe
C:\Users\Carina\AppData\Local\Temp\conduitinstaller.exe
C:\Users\Carina\AppData\Local\Temp\converter.exe
C:\Users\Carina\AppData\Local\Temp\EAInstall.dll
C:\Users\Carina\AppData\Local\Temp\EBU1BF8.DLL
C:\Users\Carina\AppData\Local\Temp\EBUF3C.exe
C:\Users\Carina\AppData\Local\Temp\ose00001.exe
C:\Users\Carina\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\Carina\AppData\Local\Temp\_is40BC.exe
C:\Users\Carina\AppData\Local\Temp\_is7010.exe
C:\Users\Carina\AppData\Local\Temp\_isDA22.exe
C:\Users\Carina\AppData\Local\Temp\_isFA18.exe
C:\Users\Carina_2\AppData\Local\Temp\AMPing.exe
C:\Users\Carina_2\AppData\Local\Temp\AskSLib.dll
C:\Users\Carina_2\AppData\Local\Temp\DWPUpgradeInstaller.exe
C:\Users\Carina_2\AppData\Local\Temp\firefoxjre_exe.exe
C:\Users\Carina_2\AppData\Local\Temp\InstallManager_BAB_BAB.exe
C:\Users\Carina_2\AppData\Local\Temp\Paint.NET.3.5.6.Install.exe
C:\Users\Carina_2\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\Carina_2\AppData\Local\Temp\SearchWithGoogleUpdate.exe
C:\Users\Carina_2\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Carina_2\AppData\Local\Temp\_is30F3.exe
C:\Users\Carina_2\AppData\Local\Temp\_is72A8.exe
C:\Users\Carina_2\AppData\Local\Temp\_isB973.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================
Und hier die Addition.txt Datei: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 09-09-2013 02
Ran by Carina_2 at 2013-09-12 15:41:18
Running from C:\Users\Carina_2\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Update for Microsoft Office 2007 (KB2508958)
32 Bit HP CIO Components Installer (Version: 2.1.5)
7-PDF Maker Version 1.4.1 (Build 128) (Version: 7-PDF Maker - Version 1.4.1 (Build 128))
7-Zip 9.20
ACD/Labs Software in C:\Program Files\ACDFREE12\ (Version: v12.00, FREE)
Acer Arcade Deluxe (Version: 2.0.5315)
Acer Crystal Eye webcam (Version: 1.0.10)
Acer Crystal Eye Webcam 2.0.7 (Version: 2.0.7)
Acer Crystal Eye Webcam Video Class Camera (Version: 5.8.33.501-1.0)
Acer eAudio Management (Version: 3.0.3007)
Acer eDataSecurity Management (Version: 3.0.3060)
Acer Empowering Technology (Version: 3.0.3006)
Acer ePower Management (Version: 3.0.3008)
Acer eRecovery Management (Version: 3.0.3013)
Acer eSettings Management (Version: 3.0.3007)
Acer GameZone Console 2.0.1.1
Acer GridVista (Version: 2.72.317)
Acer Mobility Center Plug-In (Version: 3.0.3000)
Acer ScreenSaver (Version: 1.12.0506)
Activation Assistant for the 2007 Microsoft Office suites
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0)
Adobe Download Manager (Version: 1.6.2.91)
Adobe Flash Player 11 ActiveX (Version: 11.8.800.168)
Adobe Flash Player 11 Plugin (Version: 11.8.800.168)
Adobe Reader X (10.1.4) - Deutsch (Version: 10.1.4)
Adobe Shockwave Player 11.5 (Version: 11.5.6.606)
Agatha Christie Death on the Nile
Age of Mythology
Agere Systems HDA Modem
Alice Greenfingers
Amazon Kindle
Amazon MP3-Downloader 1.0.17 (Version: 1.0.17)
ANNO 1503 GOLD (Version: 1.05.00)
aonUpdate
aonUpdate (Version: 1.0)
Apple Application Support (Version: 1.2.1)
Apple Software Update (Version: 2.1.1.116)
Audacity 1.3.11 (Unicode)
Aufstieg des Hexenkönigs™
AuthenTec Fingerprint Sensor Minimum Install (Version: 7.10.0.1129)
AVerMedia A310 (MiniCard, DVB-T) 1.1.0.27 (Version: 1.1.0.27)
Avira Free Antivirus (Version: 13.0.0.4052)
Azada
Babylon toolbar (Version: 1.8.23.1)
Backspin Billiards
Big Kahuna Reef
Bricks of Egypt
Broadcom Gigabit Integrated Controller (Version: 11.11.03)
BrowserDefender
BufferChm (Version: 100.0.170.000)
Bundled software uninstaller
Cake Mania
CambridgeSoft Activation Client (Version: 12.0)
CambridgeSoft ChemDraw Ultra 12.0 (Version: 12.0)
Chicken Invaders 3
Chuzzle
Citavi (Version: 3.3.0.0)
Controller
Controller (Version: 2.7)
Copy (Version: 100.0.170.000)
CustomerResearchQFolder (Version: 1.00.0000)
CutePDF Writer 2.7
DAEMON Tools Toolbar (Version: 1.1.0.0283)
Debut Video Capture Software
Destination Component (Version: 100.0.0.0)
DeviceDiscovery (Version: 100.0.190.000)
DeviceManagementQFolder (Version: 1.00.0000)
Die Schlacht um Mittelerde™ II
Diner Dash Flo on the Go
DivX Converter (Version: 7.1.0)
DivX Plus DirectShow Filters
DivX-Setup (Version: 2.6.1.5)
DJ_AIO_03_F2200_ProductContext (Version: 100.0.215.000)
DJ_AIO_03_F2200_Software (Version: 100.0.206.000)
DJ_AIO_03_F2200_Software_Min (Version: 100.0.239.000)
Driver Detective (Version: 8.0.1)
eSobi v2 (Version: 2.0.3.000189)
eSupportQFolder (Version: 1.00.0000)
F2200 (Version: 100.0.206.000)
F2200_Help (Version: 100.0.206.000)
Free Video to MP3 Converter version 5.0.15.706 (Version: 5.0.15.706)
Free YouTube to MP3 Converter version 3.11.34.1015 (Version: 3.11.34.1015)
Google Desktop (Version: 5.9.1005.12335)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4413.1752)
Google Update Helper (Version: 1.3.21.153)
GPBaseService (Version: 100.0.187.000)
HotPotatoes v 6.3.0.5
HP Customer Participation Program 10.0 (Version: 10.0)
HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3 (Version: 10.0)
HP Imaging Device Functions 10.0 (Version: 10.0)
HP Photosmart Essential 2.5 (Version: 1.02.0000)
HP Photosmart Essential 2.5 (Version: 2.5)
HP Smart Web Printing (Version: 3.5)
HP Solution Center 10.0 (Version: 10.0)
HP Update (Version: 4.000.007.003)
HPProductAssistant (Version: 100.0.170.000)
HPSSupply (Version: 100.0.170.000)
ICQ7.5 (HKCU Version: 7.5)
Intel® Matrix Storage Manager
Java 7 Update 9 (Version: 7.0.90)
Java Auto Updater (Version: 2.1.9.0)
Jewel Quest Solitaire
JMicron JMB38X Flash Media Controller (Version: 1.00.10.04)
Kick N Rush
LAME v3.98.2 for Audacity
Launch Manager
LightScribe 1.4.142.1 (Version: 1.4.142.1)
LyX 2.0.4 (Version: 2.0.4)
Mahjong Escape Ancient China
Mahjongg Artifacts
MarketResearch (Version: 100.0.170.000)
Massenspektrograph 2.0
Mathematica 5.2 for Students (Version: 5.2.0.530454)
Mathematica Extras 9.0 (3824406) (Version: 9.0.0)
MestReNova LITE 5.2.5-5780 (Version: 5.2.5-5780)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Works (Version: 08.05.0822)
MiKTeX 2.9 (HKCU Version: 2.9)
MiraScan V4.03
MODEM Mobiler Anschluss (Version: 1.0.0.1)
Move Media Player
Mozilla Firefox (3.5.6) (Version: 3.5.6 (de))
Mozilla Firefox 23.0.1 (x86 de) (HKCU Version: 23.0.1)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Mystery Case Files - Huntsville
Mystery Solitaire - Secret Island
NTI Backup Now 5 (Version: 5.1.2.503)
NTI Backup Now Standard (Version: 5.1.2.503)
NTI Media Maker 8 (Version: 8.0.2.6322)
NVIDIA Drivers
Origin85 (Version: 8.50.000)
OriginPro 8.5G (Version: 8.5)
Paint.NET v3.5.6 (Version: 3.56.0)
PDF-Viewer (Version: 2.5.201.0)
PhotoNow! (Version: 1.1.4619)
PowerDirector (Version: 6.5.2713)
Preispilot (Version: 1.3.678)
PSSWCORE (Version: 2.02.0000)
QuickTime (Version: 7.66.71.0)
rayman2
Realtek High Definition Audio Driver (Version: 6.0.1.5612)
Recuva (remove only)
SA32xx Device Manager (Version: 01.01.01.1027)
SA32xx Media Converter (Version: 1.0.6.1013)
SAI ZView (Version: 3.2b)
Scan (Version: 10.1.0.0)
Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) (Version: 1.0.0)
Shop for HP Supplies (Version: 10.0)
Skype™ 5.10 (Version: 5.10.116)
SmartWebPrintingOC (Version: 100.0.189.000)
Snap.Do (Version: 1.47.1.11067)
SolutionCenter (Version: 100.0.175.000)
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
Status (Version: 100.0.175.000)
Synaptics Pointing Device Driver (Version: 10.2.4.0)
Texmaker
Toolbox (Version: 100.0.170.000)
TrayApp (Version: 100.0.170.000)
TuneUp Utilities 2012 (Version: 12.0.3600.73)
TuneUp Utilities Language Pack (de-DE) (Version: 12.0.3600.73)
Turbo Pizza
UnloadSupport (Version: 10.0.0)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update für Microsoft Office Excel 2007 Help (KB963678)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)
Update für Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
VideoToolkit01 (Version: 100.0.128.000)
VLC media player 0.9.8a (Version: 0.9.8a)
Watchtower Library 2008 - Deutsch (Version: 10.0)
Watchtower Library 2009 - Deutsch (Version: 11.0)
Watchtower Library 2010 - Deutsch (Version: 12.0)
WebReg (Version: 100.0.170.000)
WIDCOMM Bluetooth Software 6.0.1.6300 (Version: 6.0.1.6300)
Winamp (Version: 5.541 )
Winbond CIR Device Drivers (Version: 7.60.1012)
Winload Toolbar (Version: 6.8.5.1)
WinRAR
Wolfram Mathematica 9 (M-WIN-L 9.0.0 3868239) (Version: 9.0.0)
Wsys Control 1.0.0.2598 (Version: 1.0.0.2598)
Zuma Deluxe
==================== Restore Points =========================
Could not list Restore Points.
==================== Hosts content: ==========================
2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ?
==================== Loaded Modules (whitelisted) =============
2013-08-13 10:59 - 2013-07-26 12:10 - 02691536 ____N () C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll
2008-04-21 05:14 - 2008-08-07 09:05 - 05885952 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll
2008-04-18 10:56 - 2008-04-23 15:58 - 00204800 _____ () C:\Windows\System32\SysHook.dll
2008-02-12 14:19 - 2008-02-12 14:19 - 00208896 _____ (Broadcom Corporation.) C:\Windows\system32\btmmhook.dll
2008-03-04 23:38 - 2008-03-04 23:38 - 00121392 _____ (Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
2008-03-04 23:38 - 2008-03-04 23:38 - 00240176 _____ (Egis Incorporated.) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
2008-02-12 13:36 - 2008-02-12 13:36 - 00184320 _____ (Broadcom Corporation.) C:\Windows\system32\btncopy.dll
2008-02-12 14:36 - 2008-02-12 14:36 - 00647168 _____ (Broadcom Corporation.) C:\Windows\system32\BtwNamespaceExt.dll
2008-02-12 14:17 - 2008-02-12 14:17 - 00368640 _____ (Broadcom Corporation.) C:\Windows\system32\BtwNeLib.dll
2008-02-12 13:31 - 2008-02-12 13:31 - 00602112 _____ (Broadcom Corporation.) C:\Windows\system32\btwapi.dll
2008-02-12 13:46 - 2008-02-12 13:46 - 00233472 _____ (Broadcom Corporation.) C:\Windows\system32\btosif.dll
2008-02-12 13:48 - 2008-02-12 13:48 - 00180224 _____ (Broadcom Corporation.) C:\Windows\system32\btwpimif.dll
2008-02-12 14:12 - 2008-02-12 14:12 - 00126976 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2010-10-24 19:19 - 2010-03-15 11:28 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll
2008-04-21 05:13 - 2008-08-07 09:05 - 00458752 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll
2008-04-18 20:25 - 2008-01-18 04:51 - 00163840 _____ (Synaptics, Inc.) C:\Windows\system32\SynCOM.dll
2008-04-18 20:25 - 2008-01-18 05:03 - 00147456 _____ (Synaptics, Inc.) C:\Windows\system32\SynTPAPI.dll
2008-04-18 10:52 - 2008-04-18 10:52 - 00036864 _____ () C:\Windows\assembly\GAC_MSIL\Framework.Utility\3.0.3006.0__4df5dcab8860d239\Framework.Utility.dll
2008-04-18 10:52 - 2008-04-18 10:52 - 00061440 _____ () C:\Windows\assembly\GAC_MSIL\Framework.Library\3.0.3006.0__3036420f80dd6947\Framework.Library.dll
2008-04-18 10:52 - 2008-04-18 10:52 - 00020480 _____ () C:\Windows\assembly\GAC_MSIL\Framework.Model.ControllerInterface\3.0.3006.0__d842b71b4d6ed079\Framework.Model.ControllerInterface.dll
2008-03-04 23:37 - 2008-03-04 23:37 - 00254000 _____ (Egis Incorporated.) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ADMIN_CLASS_LIB.dll
2008-03-04 23:38 - 2008-03-04 23:38 - 00272944 _____ (Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\keyManager.dll
2008-03-04 23:37 - 2008-03-04 23:37 - 00551472 _____ (Egis inc.) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\CryptoAPI.dll
2008-03-04 23:38 - 2008-03-04 23:38 - 00199216 _____ (Egis Incorporated.) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDUtil.dll
2008-03-04 23:38 - 2008-03-04 23:38 - 00227888 _____ () C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ShowErrMsg.dll
2008-03-04 23:37 - 2008-03-04 23:37 - 00102448 _____ (Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSop.dll
2008-03-04 23:37 - 2008-03-04 23:37 - 04966960 _____ (Egis Incorporated.) C:\Program Files\Acer\Empowering Technology\eDataSecurity\EDS.Windows.Forms.dll
2008-04-18 10:59 - 2008-02-20 16:31 - 00162336 _____ (Realtek Semiconductor) C:\Program Files\Acer\Empowering Technology\eAudio\AcrRtAud.dll
2008-04-04 03:00 - 2008-04-04 03:00 - 00003072 _____ () C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTrayLOC.dll
2008-09-05 11:31 - 2008-08-07 09:05 - 00092704 _____ (NVIDIA Corporation) C:\Windows\system32\NvMcTray.dll
2008-04-21 05:13 - 2008-08-07 09:05 - 00458752 _____ (NVIDIA Corporation) C:\Windows\System32\nvapi.dll
2008-05-12 23:11 - 2008-05-12 23:11 - 00753664 ____N () C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMediaLibrary.dll
2008-05-12 23:11 - 2008-05-12 23:11 - 00007680 ____N () C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvcPS.dll
2006-11-02 14:35 - 2006-11-02 14:35 - 00116736 _____ (Microsoft Corporation) C:\Windows\eHome\ehProxy.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 00607232 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MUtils.dll
2011-06-05 15:01 - 2011-06-05 15:01 - 00221696 _____ (AOL Inc.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\xprt6.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 00247296 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MKernel.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 00763392 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MDb.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 00104448 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MCoreLib.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 02392576 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MUIUtils.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 00785920 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MUICoreLib.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 00199168 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MBContainer.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 01432576 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MCore.dll
2011-06-05 15:01 - 2011-06-05 15:01 - 00747008 _____ (AOL Inc.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\coolcore59.dll
2011-06-05 15:01 - 2011-06-05 15:01 - 00761344 _____ (AOL Inc.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\acccore.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 00859648 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MISB.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 02581504 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MUICore.dll
2011-06-05 15:01 - 2011-08-01 10:28 - 00091136 _____ (ICQ, LLC.) C:\Users\Carina_2\AppData\Roaming\ICQ\Application\ICQ7.5\MReport.dll
2008-02-12 13:58 - 2008-02-12 13:58 - 00393216 _____ (Broadcom Corporation.) C:\Windows\system32\btwhidcs.DLL
2008-02-12 13:26 - 2008-02-12 13:26 - 05271552 _____ (Broadcom Corporation.) C:\Windows\system32\btrez.dll
2008-07-18 14:13 - 2008-07-18 14:13 - 00033792 _____ (Hewlett-Packard) C:\Windows\system32\hpzipr12.dll
2008-07-18 14:13 - 2008-07-18 14:13 - 00049152 _____ (Hewlett-Packard) C:\Windows\system32\hpzidr12.dll
2013-08-20 17:56 - 2012-09-01 14:12 - 00770384 _____ (Microsoft Corporation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\MSVCR100.dll
2013-08-20 17:56 - 2012-09-01 14:12 - 00421200 _____ (Microsoft Corporation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\MSVCP100.dll
2013-08-20 17:56 - 2013-08-20 17:56 - 00158104 _____ (Mozilla Foundation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\mozglue.dll
2013-08-20 17:56 - 2013-08-20 17:56 - 01914264 _____ (Mozilla Foundation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\nss3.dll
2013-08-20 17:56 - 2013-08-20 17:56 - 03551640 _____ () C:\Users\Carina_2\AppData\Local\Mozilla Firefox\mozjs.dll
2013-08-20 17:56 - 2013-08-20 17:56 - 00016280 _____ (Mozilla Foundation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\mozalloc.dll
2013-08-20 17:56 - 2013-08-20 17:56 - 03429784 _____ (Mozilla Foundation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\gkmedias.dll
2013-08-20 17:56 - 2013-08-20 17:56 - 20616088 _____ (Mozilla Foundation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\xul.dll
2013-08-20 17:55 - 2013-08-20 17:56 - 00262552 _____ (Mozilla Foundation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\browser\components\browsercomps.dll
2013-08-20 17:56 - 2013-08-20 17:56 - 00152984 _____ (Mozilla Foundation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\softokn3.dll
2013-08-20 17:56 - 2013-08-20 17:56 - 00091544 _____ (Mozilla Foundation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\nssdbm3.dll
2013-08-20 17:56 - 2013-08-20 17:56 - 00301976 _____ (Mozilla Foundation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\freebl3.dll
2013-08-20 17:56 - 2013-08-20 17:56 - 00392600 _____ (Mozilla Foundation) C:\Users\Carina_2\AppData\Local\Mozilla Firefox\nssckbi.dll
2012-10-26 12:11 - 2012-10-26 12:11 - 00122880 _____ () C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox\components\CitaviPickerCommunication.dll
2013-08-28 23:32 - 2013-08-28 23:32 - 16166280 ____N () C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll
==================== Alternate Data Streams (whitelisted) ==========
AlternateDataStreams: C:\ProgramData\TEMP:8AB6C1D7
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/12/2013 03:18:44 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy18,0xc0000000,0x00000003,...)". hr = 0x80070005.
Error: (09/12/2013 03:16:25 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy18,0xc0000000,0x00000003,...)". hr = 0x80070005.
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (09/12/2013 03:16:24 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy18,0x80000000,0x00000003,...)". hr = 0x80070005.
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (09/12/2013 09:04:47 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/05/2013 08:20:15 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/04/2013 09:09:06 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/03/2013 06:00:01 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
Error: (09/03/2013 09:23:56 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/02/2013 07:57:48 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\CARINA_2\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\X4AG9LV2.DEFAULT\SAFEBROWSING> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
Error: (09/02/2013 07:57:48 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\CARINA_2\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\X4AG9LV2.DEFAULT\SAFEBROWSING> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
System errors:
=============
Error: (09/12/2013 09:06:15 AM) (Source: Service Control Manager) (User: )
Description: HP CUE DeviceDiscovery Service
Error: (09/12/2013 09:04:47 AM) (Source: Service Control Manager) (User: )
Description: Wsys Service
Error: (09/12/2013 09:04:36 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (09/05/2013 08:21:44 AM) (Source: Service Control Manager) (User: )
Description: HP CUE DeviceDiscovery Service
Error: (09/05/2013 08:20:15 AM) (Source: Service Control Manager) (User: )
Description: Wsys Service
Error: (09/05/2013 08:20:09 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (09/04/2013 09:10:36 AM) (Source: Service Control Manager) (User: )
Description: HP CUE DeviceDiscovery Service
Error: (09/04/2013 09:09:06 AM) (Source: Service Control Manager) (User: )
Description: Wsys Service
Error: (09/04/2013 09:08:58 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (09/03/2013 09:34:22 AM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 10.0.0.148 für die Netzwerkkarte mit der Netzwerkadresse 00215D59CD4E wurde durch den DHCP-Server 140.78.168.1 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).
Microsoft Office Sessions:
=========================
Error: (04/04/2012 01:36:52 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 39530 seconds with 6900 seconds of active time. This session ended with a crash.
Error: (12/15/2009 04:53:56 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 15 seconds with 0 seconds of active time. This session ended with a crash.
Error: (12/15/2009 04:52:55 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 134 seconds with 120 seconds of active time. This session ended with a crash.
Error: (12/15/2009 04:50:31 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 116 seconds with 60 seconds of active time. This session ended with a crash.
Error: (12/15/2009 04:48:14 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 34 seconds with 0 seconds of active time. This session ended with a crash.
Error: (12/15/2009 04:47:29 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 122 seconds with 120 seconds of active time. This session ended with a crash.
Error: (12/15/2009 04:45:04 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1497 seconds with 540 seconds of active time. This session ended with a crash.
Error: (11/08/2009 05:05:18 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6504.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 1236 seconds with 1080 seconds of active time. This session ended with a crash.
CodeIntegrity Errors:
===================================
Date: 2013-09-12 15:40:59.305
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-09-12 15:40:59.183
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-09-12 15:40:59.058
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-09-12 15:40:58.933
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-09-12 15:40:58.792
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-09-12 15:40:58.666
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-09-12 15:40:58.538
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-09-12 15:40:58.369
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 62%
Total physical RAM: 3065.94 MB
Available physical RAM: 1150.4 MB
Total Pagefile: 6336.89 MB
Available Pagefile: 4080.75 MB
Total Virtual: 2047.88 MB
Available Virtual: 1900.23 MB
==================== Drives ================================
Drive c: (ACER) (Fixed) (Total:144.04 GB) (Free:49.18 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (DATA) (Fixed) (Total:144.04 GB) (Free:38.47 GB) NTFS
Drive f: (DATA) (Fixed) (Total:298.09 GB) (Free:216.62 GB) NTFS
==================== MBR & Partition Table ==================
==================== End Of Log ============================ |