hgzeidler | 18.10.2013 08:59 | ok
hier die posts:
1) Systemlook Code:
SystemLook 30.07.11 by jpshortstuff
Log created at 09:58 on 16/10/2013 by Fortshof Autengrün
Administrator - Elevation successful
========== filefind ==========
Searching for "*snap.do*"
No files found.
========== folderfind ==========
Searching for "*snap.do*"
No folders found.
========== regfind ==========
Searching for "snap.do"
[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\7BEB351B42FE32345848F39E65AA7E1D]
"ProductName"="Snap.Do"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{b6488265-5f45-4b40-9359-7977c13f70e8}]
"DisplayName"="Snap.Do Engine"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-364686899-3215564061-3121816915-1000\Products\7BEB351B42FE32345848F39E65AA7E1D\InstallProperties]
"HelpLink"="hxxp://snap.do"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-364686899-3215564061-3121816915-1000\Products\7BEB351B42FE32345848F39E65AA7E1D\InstallProperties]
"URLInfoAbout"="hxxp://snap.do"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-364686899-3215564061-3121816915-1000\Products\7BEB351B42FE32345848F39E65AA7E1D\InstallProperties]
"DisplayName"="Snap.Do"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B153BEB7-EF24-4323-8584-3FE956AAE7D1}]
"HelpLink"="hxxp://snap.do"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B153BEB7-EF24-4323-8584-3FE956AAE7D1}]
"URLInfoAbout"="hxxp://snap.do"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B153BEB7-EF24-4323-8584-3FE956AAE7D1}]
"DisplayName"="Snap.Do"
[HKEY_USERS\S-1-5-21-364686899-3215564061-3121816915-1000\Software\Microsoft\Installer\Products\7BEB351B42FE32345848F39E65AA7E1D]
"ProductName"="Snap.Do"
[HKEY_USERS\S-1-5-21-364686899-3215564061-3121816915-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\{b6488265-5f45-4b40-9359-7977c13f70e8}]
"DisplayName"="Snap.Do Engine"
-= EOF =- 2) JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.7 (10.15.2013:3)
OS: Windows 7 Home Premium x86
Ran by Fortshof Autengrn on 16.10.2013 at 13:21:40,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Fortshof Autengrn\AppData\Roaming\mozilla\firefox\profiles\wc6blcle.default\minidumps [98 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.10.2013 at 13:25:07,33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
3)
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013
Ran by Fortshof Autengrün (administrator) on FORSTHOF on 09-10-2013 22:55:00
Running from C:\Users\Fortshof Autengrün\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
(X10) C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
(CANON INC.) C:\Windows\system32\CNAB4RPK.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Wistron) C:\Program Files\Launch Manager\HotkeyApp.exe
(Wistron Corp.) C:\Program Files\Launch Manager\OSD.exe
(Wistron Corp.) C:\Program Files\Launch Manager\WButton.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Wistron Corp.) C:\Program Files\Launch Manager\WisLMSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [HotkeyApp] - C:\Program Files\Launch Manager\HotkeyApp.exe [200704 2009-12-14] (Wistron)
HKLM\...\Run: [LMgrVolOSD] - C:\Program Files\Launch Manager\OSD.exe [348960 2009-12-11] (Wistron Corp.)
HKLM\...\Run: [Wbutton] - C:\Program Files\Launch Manager\Wbutton.exe [436264 2010-06-21] (Wistron Corp.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [fspuip] - C:\Program Files\FSP\fspuip.exe [745472 2009-05-07] (Sentelic Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1594664 2009-12-10] (Synaptics Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN)
HKCU\...\Run: [Driver Detective] - C:\Program Files\PC Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.exe /applicationMode:systemTray /showWelcome:false
HKCU\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000
HKU\Fritzi\...\Run: [Sony Ericsson PC Suite] - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [ 2009-11-20] (Sony Ericsson Mobile Communications AB)
AppInit_DLLs: C:\Windows\system32\nvinit.dll [ 2012-10-24] (NVIDIA Corporation)
Startup: C:\Users\Fortshof Autengrün\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk
ShortcutTarget: FastStone Capture.lnk -> C:\Program Files\FastStone Capture\FSCapture.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD5C4C43E4177CB01
SearchScopes: HKLM - DefaultScope value is missing.
BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {E4CF4E86-D0DC-4864-8F0E-4F6EA2526334} https://img.ui-portal.de/webde/smartdrive/activex/gmxnet_osupload_2002.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Fortshof Autengrün\AppData\Roaming\Mozilla\Firefox\Profiles\wc6blcle.default
FF NewTab: about:blank
FF SearchEngineOrder.1: Ask.com
FF Homepage: hxxp://www.google.de/
FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=DE&userid=8eb980bc-3e96-1450-b8cf-2960a5035eb2&searchtype=ds&installDate=05/10/2013&q=
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: toolbar_AVIRA-V7 - C:\Users\Fortshof Autengrün\AppData\Roaming\Mozilla\Firefox\Profiles\wc6blcle.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
FF Extension: No Name - C:\Users\Fortshof Autengrün\AppData\Roaming\Mozilla\Firefox\Profiles\wc6blcle.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: No Name - C:\Users\Fortshof Autengrün\AppData\Roaming\Mozilla\Firefox\Profiles\wc6blcle.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: No Name - C:\Users\Fortshof Autengrün\AppData\Roaming\Mozilla\Firefox\Profiles\wc6blcle.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
CHR HKLM\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\FORTSH~1\AppData\Local\Temp\tbch.crx
========================== Services (Whitelisted) =================
S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2010-11-12] ()
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [90112 2009-04-30] ()
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
S2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118560 2009-10-22] (Wistron Corp.)
R2 x10nets; C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe [20480 2009-11-07] (X10)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-08-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-08-17] (Avira Operations GmbH & Co. KG)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 mod7700; C:\Windows\System32\DRIVERS\mod7700.sys [786400 2009-08-13] (DiBcom SA)
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [64904 2010-04-27] (Renesas Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [146568 2010-04-27] (Renesas Electronics Corporation)
R0 nvpciflt; C:\Windows\System32\DRIVERS\nvpciflt.sys [24936 2012-10-24] (NVIDIA Corporation)
S3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [104744 2009-03-25] (MCCI Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-17] (Avira GmbH)
R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13720 2009-05-13] (X10 Wireless Technology, Inc.)
S3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27160 2009-05-13] (X10 Wireless Technology, Inc.)
S3 nmwcd; system32\drivers\ccdcmb.sys [x]
S3 nmwcdc; system32\drivers\ccdcmbo.sys [x]
S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [x]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [x]
U3 Viapxtncvs4.0; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-09 22:31 - 2013-10-09 22:34 - 00000000 ____D C:\AdwCleaner
2013-10-09 22:31 - 2013-10-09 22:31 - 01048960 _____ C:\Users\Fortshof Autengrün\Desktop\adwcleaner.exe
2013-10-09 22:10 - 2013-10-09 22:10 - 00001071 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-09 22:10 - 2013-10-09 22:10 - 00000000 ____D C:\Users\Fortshof Autengrün\AppData\Roaming\Malwarebytes
2013-10-09 22:10 - 2013-10-09 22:10 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-09 22:10 - 2013-10-09 22:10 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-09 22:10 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-09 22:09 - 2013-10-09 22:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Fortshof Autengrün\Desktop\mbam-setup-1.75.0.1300.exe
2013-10-09 22:05 - 2013-10-09 22:06 - 00020168 _____ C:\Users\Fortshof Autengrün\Desktop\Addition.txt
2013-10-09 22:04 - 2013-10-09 22:04 - 00000000 ____D C:\FRST
2013-10-09 22:01 - 2013-10-09 22:01 - 01087213 _____ (Farbar) C:\Users\Fortshof Autengrün\Desktop\FRST.exe
2013-10-09 21:57 - 2013-10-09 21:57 - 02828552 _____ (AVAST Software) C:\Users\Fortshof Autengrün\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-10-07 18:59 - 2013-10-07 18:59 - 00001122 _____ C:\Users\Fortshof Autengrün\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-10-05 23:13 - 2013-10-05 23:13 - 00000000 ____D C:\Users\Fortshof Autengrün\AppData\Roaming\MyPhoneExplorer
2013-10-05 23:13 - 2013-10-05 23:13 - 00000000 ____D C:\Program Files\MyPhoneExplorer
2013-10-05 22:51 - 2013-10-05 22:51 - 00148736 _____ (Avanquest Software) C:\ProgramData\hpe16EC.dll
2013-10-05 22:51 - 2013-10-05 22:51 - 00000000 ____D C:\Program Files\Sony Ericsson
2013-10-05 22:47 - 2013-10-05 22:47 - 00000000 ____D C:\Program Files\Sony Media Go Install
2013-10-05 22:39 - 2013-10-05 22:39 - 19159080 _____ (Sony Ericsson ) C:\Users\Fortshof Autengrün\Downloads\Sony_Ericsson_PC_Suite_6.011.00_Web_DEU.exe
2013-10-04 15:57 - 2013-10-05 22:52 - 00701174 _____ C:\Windows\DPINST.LOG
2013-10-01 08:45 - 2013-10-01 08:45 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-18 15:28 - 2013-09-18 15:28 - 12844032 _____ C:\Users\Fortshof Autengrün\Downloads\LBP2900_R112_V302_Win_x32_EN_7(1).exe
2013-09-14 20:27 - 2013-09-14 20:28 - 00410512 _____ C:\Windows\Minidump\091413-22339-01.dmp
2013-09-14 08:28 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-14 08:28 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-14 08:28 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-14 08:28 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-14 08:28 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-14 08:28 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-14 08:28 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-14 08:28 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-14 08:28 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-14 08:28 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-14 08:28 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-14 08:28 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-14 08:28 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-14 08:28 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-14 08:28 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-14 08:27 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-13 15:43 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-13 15:43 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-13 15:43 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-13 15:43 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-13 15:43 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-13 15:43 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-13 15:43 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-13 15:43 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-13 15:43 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
==================== One Month Modified Files and Folders =======
2013-10-09 22:45 - 2013-01-14 21:46 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-09 22:45 - 2009-07-14 06:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-09 22:45 - 2009-07-14 06:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-09 22:42 - 2010-10-29 09:36 - 01146553 _____ C:\Windows\WindowsUpdate.log
2013-10-09 22:36 - 2013-06-20 10:03 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-09 22:36 - 2012-07-29 15:17 - 00024986 _____ C:\Windows\setupact.log
2013-10-09 22:36 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-09 22:34 - 2013-10-09 22:31 - 00000000 ____D C:\AdwCleaner
2013-10-09 22:31 - 2013-10-09 22:31 - 01048960 _____ C:\Users\Fortshof Autengrün\Desktop\adwcleaner.exe
2013-10-09 22:26 - 2012-07-29 15:17 - 00017546 _____ C:\Windows\PFRO.log
2013-10-09 22:26 - 2010-11-01 20:59 - 00000000 ____D C:\Windows\PCHEALTH
2013-10-09 22:10 - 2013-10-09 22:10 - 00001071 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-09 22:10 - 2013-10-09 22:10 - 00000000 ____D C:\Users\Fortshof Autengrün\AppData\Roaming\Malwarebytes
2013-10-09 22:10 - 2013-10-09 22:10 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-09 22:10 - 2013-10-09 22:10 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-09 22:09 - 2013-10-09 22:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Fortshof Autengrün\Desktop\mbam-setup-1.75.0.1300.exe
2013-10-09 22:06 - 2013-10-09 22:05 - 00020168 _____ C:\Users\Fortshof Autengrün\Desktop\Addition.txt
2013-10-09 22:04 - 2013-10-09 22:04 - 00000000 ____D C:\FRST
2013-10-09 22:04 - 2013-06-20 10:03 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-09 22:01 - 2013-10-09 22:01 - 01087213 _____ (Farbar) C:\Users\Fortshof Autengrün\Desktop\FRST.exe
2013-10-09 21:57 - 2013-10-09 21:57 - 02828552 _____ (AVAST Software) C:\Users\Fortshof Autengrün\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-10-09 14:45 - 2012-05-24 21:18 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-09 14:45 - 2011-05-24 22:21 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-07 18:59 - 2013-10-07 18:59 - 00001122 _____ C:\Users\Fortshof Autengrün\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-10-05 23:13 - 2013-10-05 23:13 - 00000000 ____D C:\Users\Fortshof Autengrün\AppData\Roaming\MyPhoneExplorer
2013-10-05 23:13 - 2013-10-05 23:13 - 00000000 ____D C:\Program Files\MyPhoneExplorer
2013-10-05 22:52 - 2013-10-04 15:57 - 00701174 _____ C:\Windows\DPINST.LOG
2013-10-05 22:51 - 2013-10-05 22:51 - 00148736 _____ (Avanquest Software) C:\ProgramData\hpe16EC.dll
2013-10-05 22:51 - 2013-10-05 22:51 - 00000000 ____D C:\Program Files\Sony Ericsson
2013-10-05 22:50 - 2010-10-31 13:05 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-10-05 22:47 - 2013-10-05 22:47 - 00000000 ____D C:\Program Files\Sony Media Go Install
2013-10-05 22:41 - 2011-04-11 20:48 - 00000000 ____D C:\Program Files\Avanquest update
2013-10-05 22:39 - 2013-10-05 22:39 - 19159080 _____ (Sony Ericsson ) C:\Users\Fortshof Autengrün\Downloads\Sony_Ericsson_PC_Suite_6.011.00_Web_DEU.exe
2013-10-05 22:36 - 2010-12-05 21:55 - 00000000 ____D C:\Users\Fortshof Autengrün\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony Ericsson
2013-10-05 22:33 - 2010-11-13 23:35 - 00000000 ____D C:\Program Files\Nokia
2013-10-05 22:30 - 2010-12-05 21:08 - 00000000 ____D C:\ProgramData\Sony Ericsson
2013-10-04 20:36 - 2013-02-27 20:45 - 00346112 ___SH C:\Users\Fritzi\Desktop\Thumbs.db
2013-10-04 15:51 - 2012-05-01 22:14 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-04 15:47 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-10-04 15:36 - 2010-11-01 10:04 - 00000000 ____D C:\Users\Fritzi\AppData\Roaming\Adobe
2013-10-04 15:36 - 2010-11-01 10:02 - 00000000 ____D C:\ProgramData\Adobe
2013-10-04 10:26 - 2010-10-29 10:10 - 00000000 ____D C:\Users\Fortshof Autengrün\AppData\Local\Mozilla
2013-10-01 08:52 - 2013-08-20 10:55 - 00000000 ____D C:\Program Files\Mozilla Firefox.bak
2013-10-01 08:52 - 2010-10-30 13:08 - 00000000 ____D C:\Users\Fritzi\AppData\Local\Mozilla
2013-10-01 08:45 - 2013-10-01 08:45 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-18 15:31 - 2013-04-20 00:03 - 00000000 ____D C:\Program Files\Canon
2013-09-18 15:28 - 2013-09-18 15:28 - 12844032 _____ C:\Users\Fortshof Autengrün\Downloads\LBP2900_R112_V302_Win_x32_EN_7(1).exe
2013-09-15 11:06 - 2010-10-29 09:51 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-14 20:28 - 2013-09-14 20:27 - 00410512 _____ C:\Windows\Minidump\091413-22339-01.dmp
2013-09-14 20:27 - 2012-12-06 21:22 - 370894661 _____ C:\Windows\MEMORY.DMP
2013-09-14 20:27 - 2010-12-11 22:17 - 00000000 ____D C:\Windows\Minidump
2013-09-14 09:28 - 2010-10-29 09:47 - 00000000 ____D C:\Users\Fortshof Autengrün
2013-09-14 09:27 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-09-14 08:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-09-14 08:50 - 2009-07-14 06:33 - 00409432 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-14 08:48 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-09-14 08:32 - 2010-11-01 20:57 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-14 08:25 - 2013-08-14 07:39 - 00000000 ____D C:\Windows\system32\MRT
2013-09-14 08:22 - 2010-10-29 23:50 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-12 08:21 - 2010-11-05 20:45 - 00000000 ____D C:\Users\Fortshof Autengrün\AppData\Roaming\Adobe
Files to move or delete:
====================
C:\ProgramData\hpe16EC.dll
C:\Users\Fritzi\GoogleEarthSetup.exe
C:\Users\Fritzi\Setup_BullzipPDFPrinter_9_8_0_1599_S.exe
Some content of TEMP:
====================
C:\Users\Fortshof Autengrün\AppData\Local\Temp\AskSLib.dll
C:\Users\Fortshof Autengrün\AppData\Local\Temp\Installer.exe
C:\Users\Fortshof Autengrün\AppData\Local\Temp\jre-7u11-windows-i586-iftw.exe
C:\Users\Fortshof Autengrün\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Fortshof Autengrün\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Fortshof Autengrün\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe
C:\Users\Fortshof Autengrün\AppData\Local\Temp\Quarantine.exe
C:\Users\Fortshof Autengrün\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Fritzi\AppData\Local\Temp\AskSLib.dll
C:\Users\Fritzi\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Fritzi\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-03 19:49
==================== End Of Log ============================ --- --- ---
--- --- ---
und Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-10-2013
Ran by Fortshof Autengrün at 2013-10-09 22:05:41
Running from C:\Users\Fortshof Autengrün\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.20
Adobe AIR (Version: 3.6.0.5970)
Adobe Flash Player 10 ActiveX (Version: 10.0.45.2)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Photoshop CS (Version: CS)
Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7)
Apple Application Support (Version: 2.1.7)
Apple Software Update (Version: 2.1.3.127)
Avanquest update (Version: 1.34)
Avira Free Antivirus (Version: 13.0.0.4052)
Avira SearchFree Toolbar plus Web Protection (Version: 12.2.2.663)
Bullzip PDF Printer 9.8.0.1599 (Version: 9.8.0.1599)
Canon iP4800 series Printer Driver
Canon LBP2900
CCleaner (Version: 3.21)
CDBurnerXP (Version: 4.4.1.3243)
CDex - Open Source Digital Audio CD Extractor (Version: 1.70.4.2009)
Citrix Presentation Server Client (Version: 10.00.52110)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
EPSON Scan
eRepair Excel 1.0
FastStone Capture 5.3 (Version: 5.3)
Finger-sensing Pad Driver (Version: 8.4.1.5)
Free YouTube to MP3 Converter version 3.11.35.1031 (Version: 3.11.35.1031)
Google Earth (Version: 7.1.1.1888)
Google Update Helper (Version: 1.3.21.165)
Internet-TV für Windows Media Center (Version: 4.2.2.0)
IrfanView (remove only) (Version: 4.27)
Java 7 Update 21 (Version: 7.0.210)
Java Auto Updater (Version: 2.1.9.5)
Java(TM) 6 Update 31 (Version: 6.0.310)
KE 2.0 (Version: 1.00.0004)
Launch Manager (Version: 1.5.1.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mozilla Firefox 24.0 (x86 de) (Version: 24.0)
Mozilla Maintenance Service (Version: 24.0)
MSVC80_x86_v2 (Version: 1.0.3.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyPhoneExplorer (Version: 1.8.5)
myphotobook.de (Version: 1.4.12)
NVIDIA Grafiktreiber 307.21 (Version: 307.21)
NVIDIA Install Application (Version: 2.1002.85.551)
NVIDIA Systemsteuerung 307.21 (Version: 307.21)
PCFriendly
PDF Architect (Version: 1.1.83.9982)
PDFCreator (Version: 1.7.0)
PlayReady PC Runtime x86 (Version: 1.3.0)
QuickTime (Version: 7.72.80.56)
Ravensburger tiptoi
Skype Click to Call (Version: 5.6.8442)
Skype™ 6.6 (Version: 6.6.106)
Sony Ericsson PC Suite 6.011.00 (Version: 6.011.00)
Synaptics Pointing Device Driver (Version: 14.0.19.0)
TeamViewer 7 (Version: 7.0.14563)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
VLC media player 1.1.4 (Version: 1.1.4)
Windows Media Center Add-in for Silverlight (Version: 4.7.3.0)
X10 Hardware(TM)
==================== Restore Points =========================
23-09-2013 07:15:37 Windows-Sicherung
24-09-2013 06:04:19 Windows Update
28-09-2013 08:43:24 Windows Update
04-10-2013 08:45:46 Windows Update
04-10-2013 13:59:40 Sony PC Companion
05-10-2013 20:32:07 Nokia Connectivity Cable Driver wird entfernt
05-10-2013 20:34:18 PC Connectivity Solution wird entfernt
05-10-2013 20:34:21 Installed Sony Ericsson Drivers
05-10-2013 20:35:10 Uninstalled Sony Ericsson Drivers
05-10-2013 20:42:20 Sony PC Companion
05-10-2013 20:43:42 Sony PC Companion
05-10-2013 20:49:19 Removed PlayStation(R)Store.
05-10-2013 20:50:08 Removed PlayStation(R)Network Downloader.
08-10-2013 08:19:16 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {B12EF78D-1A40-4D66-8C4C-5A39148629F0} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {B591A24B-ED03-41F4-88CD-90DDC9D98AC5} - System32\Tasks\{5D2295D1-47CB-43A8-9F0B-9284BAD7EEB4} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.)
Task: {BB4F123C-ED14-4D37-BCA2-B58C11A6C53E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-20] (Google Inc.)
Task: {D0BF230D-3104-4052-B647-6F769C32D9A2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-20] (Google Inc.)
Task: {DCCC5C30-78A4-459D-BF25-CC43CD2459DC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {F6E106C9-B016-4850-B731-1DBABD699523} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-07-24] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2011-03-17 01:11 - 2011-03-17 01:11 - 04297568 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-10-01 08:45 - 2013-10-01 08:45 - 03279768 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2011-03-17 01:11 - 2011-03-17 01:11 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf
2010-12-21 02:15 - 2010-12-21 02:15 - 01041248 _____ () C:\Program Files\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: Microsoft-Adapter für Miniports virtueller WiFis
Description: Microsoft-Adapter für Miniports virtueller WiFis
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/08/2013 10:46:09 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (10/08/2013 10:43:55 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig.
Error: (10/08/2013 10:20:40 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig.
Error: (10/07/2013 07:35:25 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (10/07/2013 07:32:19 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig.
Error: (10/06/2013 11:37:41 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "F:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)"
Error: (10/05/2013 10:50:51 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: setup.exe_Sony PC Companion, Version: 17.0.0.717, Zeitstempel: 0x4cab8cfa
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x6d412140
ID des fehlerhaften Prozesses: 0xec4
Startzeit der fehlerhaften Anwendung: 0xsetup.exe_Sony PC Companion0
Pfad der fehlerhaften Anwendung: setup.exe_Sony PC Companion1
Pfad des fehlerhaften Moduls: setup.exe_Sony PC Companion2
Berichtskennung: setup.exe_Sony PC Companion3
Error: (10/05/2013 10:37:21 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (10/05/2013 10:31:29 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: setup.exe_Sony PC Companion, Version: 17.0.0.717, Zeitstempel: 0x4cab8cfa
Name des fehlerhaften Moduls: MExplorer.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x5195ef82
Ausnahmecode: 0xc0000005
Fehleroffset: 0x6c092140
ID des fehlerhaften Prozesses: 0x1da0
Startzeit der fehlerhaften Anwendung: 0xsetup.exe_Sony PC Companion0
Pfad der fehlerhaften Anwendung: setup.exe_Sony PC Companion1
Pfad des fehlerhaften Moduls: setup.exe_Sony PC Companion2
Berichtskennung: setup.exe_Sony PC Companion3
Error: (10/05/2013 10:30:00 PM) (Source: MsiInstaller) (User: Forsthof)
Description: Produkt: Sony Ericsson PC Suite -- Fehler 2229. Database: . Could not load table 'LaunchCondition' in SQL query: SELECT `Condition`, `Description` FROM `LaunchCondition`.
System errors:
=============
Error: (10/09/2013 09:54:03 PM) (Source: DCOM) (User: )
Description: {B12468C9-5B13-40D9-B74B-1815B776F1FB}
Error: (10/09/2013 09:53:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PDF Architect Service" wurde mit folgendem Fehler beendet:
%%-2147467259
Error: (10/08/2013 09:09:03 AM) (Source: DCOM) (User: )
Description: {B12468C9-5B13-40D9-B74B-1815B776F1FB}
Error: (10/08/2013 09:08:33 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PDF Architect Service" wurde mit folgendem Fehler beendet:
%%-2147467259
Error: (10/07/2013 06:51:40 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PDF Architect Service" wurde mit folgendem Fehler beendet:
%%-2147467259
Error: (10/06/2013 03:14:09 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Browser-Schutz" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (10/06/2013 09:29:13 AM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Error: (10/06/2013 09:29:10 AM) (Source: DCOM) (User: )
Description: {C332C124-340D-4430-AA0D-C75602876FCC}
Error: (10/06/2013 00:11:09 AM) (Source: DCOM) (User: )
Description: {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C}
Error: (10/06/2013 00:11:09 AM) (Source: DCOM) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Microsoft Office Sessions:
=========================
Error: (10/08/2013 10:46:09 AM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\sony ericsson\sony ericsson pc suite\Drivers\DPInst64.exe
Error: (10/08/2013 10:43:55 AM) (Source: SideBySide)(User: )
Description: C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exeC:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe2
Error: (10/08/2013 10:20:40 AM) (Source: SideBySide)(User: )
Description: C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exeC:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe2
Error: (10/07/2013 07:35:25 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\sony ericsson\sony ericsson pc suite\Drivers\DPInst64.exe
Error: (10/07/2013 07:32:19 PM) (Source: SideBySide)(User: )
Description: C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exeC:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe2
Error: (10/06/2013 11:37:41 PM) (Source: Windows Backup)(User: )
Description: F:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)
Error: (10/05/2013 10:50:51 PM) (Source: Application Error)(User: )
Description: setup.exe_Sony PC Companion17.0.0.7174cab8cfaunknown0.0.0.000000000c00000056d412140ec401cec20c8405305fC:\Users\FORTSH~1\AppData\Local\Temp\{061D9BD8-D6DD-4CB9-A0F1-A9DBDCCD50D5}\setup.exeunknownd19cef14-2dff-11e3-83c0-00262dc1affd
Error: (10/05/2013 10:37:21 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Sony Ericsson USB\DPInst64.exe
Error: (10/05/2013 10:31:29 PM) (Source: Application Error)(User: )
Description: setup.exe_Sony PC Companion17.0.0.7174cab8cfaMExplorer.dll_unloaded0.0.0.05195ef82c00000056c0921401da001cec209beb9051fC:\Users\FORTSH~1\AppData\Local\Temp\{20409EA5-F093-4F4C-B03A-DD017873FF10}\setup.exeMExplorer.dll1d1f1468-2dfd-11e3-83c0-00262dc1affd
Error: (10/05/2013 10:30:00 PM) (Source: MsiInstaller)(User: Forsthof)
Description: Produkt: Sony Ericsson PC Suite -- Fehler 2229. Database: . Could not load table 'LaunchCondition' in SQL query: SELECT `Condition`, `Description` FROM `LaunchCondition`.(NULL)(NULL)(NULL)(NULL)(NULL)
==================== Memory info ===========================
Percentage of memory in use: 47%
Total physical RAM: 3253.42 MB
Available physical RAM: 1721.64 MB
Total Pagefile: 6505.13 MB
Available Pagefile: 4772.27 MB
Total Virtual: 2047.88 MB
Available Virtual: 1887.98 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:565.07 GB) (Free:318.3 GB) NTFS
Drive d: (Recover) (Fixed) (Total:30 GB) (Free:9.58 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=565 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=30 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
==================== End Of Log ============================ Und, hey! Vielen Dank, daß Ihr Euch mit meinem computer befaßt - echt toll!!! Danke Schrauber, daß Du Dich kümmerst!
Gruß HG |