Schmidbauer | 12.11.2013 15:32 | FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-11-2013 01
Ran by Schmidbauer (administrator) on SCHMIDBAUER-PC on 12-11-2013 13:50:29
Running from C:\Users\Schmidbauer\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
() C:\Windows\system32\PSIService.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Nico Mak Computing) C:\Program Files\WinZip Malware Protector\WinZipMalwareProtector.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Learnpulse) C:\Users\Schmidbauer\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe
(Dropbox, Inc.) C:\Users\Schmidbauer\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.2.241.0\SeaPort.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM\...\Run: [CLMLServer] - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-06-03] (CyberLink)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7703072 2009-08-04] (Realtek Semiconductor)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-02] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE [1983816 2009-07-27] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files\Canon\SolutionMenu\CNSLMAIN.EXE [767312 2009-03-18] (CANON INC.)
HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [3830224 2013-05-16] (Safer-Networking Ltd.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKCU\...\Run: [Screenpresso] - C:\Users\Schmidbauer\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe [10880016 2013-09-29] (Learnpulse)
HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.)
MountPoints2: {90547b4e-c51c-11e2-bd50-806e6f6e6963} - E:\autostart.exe
HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] ()
HKU\Default\...\RunOnce: [MEDION] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [ 2009-10-23] ()
Startup: C:\Users\Schmidbauer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Schmidbauer\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
ProxyServer: localhost:21320
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Freiwillige Feuerwehr Ebersegg
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Welcome to ALDI
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Certified-Toolbar Search
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Certified-Toolbar Search
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = Certified-Toolbar Search
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1382047200000.000007&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&q={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1382047200000.000007&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&q={searchTerms}
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1382078115023&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&q={searchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {097FB4BD-5B76-449B-9BA6-3AC448025950} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
SearchScopes: HKCU - {575414CF-2DF7-47E6-B377-1F5F58BB8DD1} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10263&src=crm&q={searchTerms}&locale=de_AT&apn_ptnrs=^AGU&apn_dtid=^YYYYYY^YY^AT&apn_uid=2332769e-b89b-4b8c-8a1d-ac946215b4ba&apn_sauid=E82B4122-D4A9-4996-8D05-6B17C67CCB4E
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
BHO: Plus-HD-3.8 - {11111111-1111-1111-1111-110311901130} - C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-bho.dll (Plus HD)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Web Optimizer - {bbb1d54d-cf70-4a80-bf2f-3bafca0225ce} - C:\Program Files\Web Optimizer\weboptimizer.dll (Web Optimizer)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - No Name - {a25e7121-3dd8-41b3-855b-756c5bc45449} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Schmidbauer\AppData\Roaming\Mozilla\Firefox\Profiles\7uvpei24.default
FF NewTab: about:home
FF DefaultSearchEngine: Web Search
FF SearchEngineOrder.1: Web Search
FF SelectedSearchEngine: Web Search
FF Homepage: about:home
FF Keyword.URL: hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.4&ts=1382047200000.000007&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&st=chrome&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.4 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Schmidbauer\AppData\Roaming\Mozilla\Firefox\Profiles\7uvpei24.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Plus-HD-3.8 - C:\Users\Schmidbauer\AppData\Roaming\Mozilla\Firefox\Profiles\7uvpei24.default\Extensions\c17236e8-fd66-44bc-aeef-1e00981cbb64@0a4ee0fe-5356-4fd3-b37c-5cd5671a315c.com
FF Extension: vis - C:\Users\Schmidbauer\AppData\Roaming\Mozilla\Firefox\Profiles\7uvpei24.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
FF Extension: HomeTab - C:\Users\Schmidbauer\AppData\Roaming\Mozilla\Firefox\Profiles\7uvpei24.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947}
FF HKLM\...\Firefox\Extensions: [{ff0f24dd-184a-42ca-9ce8-8ca6184fd0ac}] - C:\Program Files\Web Optimizer\weboptimizer.xpi
FF Extension: No Name - C:\Program Files\Web Optimizer\weboptimizer.xpi
Chrome:
=======
CHR HomePage: hxxp://www.google.at/
CHR RestoreOnStartup: "hxxp://ff-ebersegg.at/", "hxxp://theater-kleinraming.at/", "hxxp://www.google.at/"
CHR Extension: (Web Optimizer) - C:\Users\SCHMID~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\afjadpgpmmloiaibmijliigmaokkejnk\0.1_1
CHR Extension: (Google Wallet) - C:\Users\SCHMID~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Plus-HD-3.8) - C:\Users\SCHMID~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjgnhihlklpobkaloamkankaaoclfjh\1.23.19_0
CHR HKLM\...\Chrome\Extension: [afjadpgpmmloiaibmijliigmaokkejnk] - C:\Program Files\Web Optimizer\weboptimizer.crx
CHR HKLM\...\Chrome\Extension: [bddpogknpjlgfpbboediomaiiaecfajn] - C:\Program Files\HomeTab\chrome\HomeTab.crx
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1155072 2009-02-03] (MAGIX AG)
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®)
R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
S4 Hbnbe0vnuslo;
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-02] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-05-25] (Avira Operations GmbH & Co. KG)
S3 silabenm; C:\Windows\System32\DRIVERS\silabenm.sys [47176 2011-10-14] (Silicon Laboratories)
S3 silabser; C:\Windows\System32\DRIVERS\silabser.sys [61312 2011-10-14] (Silicon Laboratories)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-05-25] (Avira GmbH)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-12 13:50 - 2013-11-12 13:50 - 00000000 ____D C:\FRST
2013-11-12 13:49 - 2013-11-12 13:49 - 01090275 _____ (Farbar) C:\Users\Schmidbauer\Desktop\FRST.exe
2013-11-12 13:41 - 2013-11-12 13:41 - 103891779 _____ C:\Windows\system32\ᒲᷣJ
2013-11-11 10:38 - 2013-11-11 10:38 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Local\Adobe
2013-11-10 17:43 - 2013-11-10 17:43 - 00006511 _____ C:\Users\Schmidbauer\Documents\log.xml
2013-11-10 17:42 - 2013-11-10 17:42 - 00000000 ____D C:\Users\Schmidbauer\Documents\Neuer Ordner (2)
2013-11-10 16:53 - 2013-11-10 16:53 - 04892480 _____ (WinZip International LLC ) C:\Users\Schmidbauer\Downloads\wzmp_8.exe
2013-11-10 16:53 - 2013-11-10 16:53 - 00001151 _____ C:\Users\Public\Desktop\WinZip Malware Protector.lnk
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Nico Mak Computing
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\ProgramData\Nico Mak Computing
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\Program Files\WinZip Malware Protector
2013-11-10 16:53 - 2013-03-15 17:01 - 00016384 _____ C:\Windows\system32\wsusnative32.exe
2013-11-10 14:04 - 2013-11-10 14:04 - 103467942 _____ C:\Windows\system32\쇓讟g
2013-11-07 20:05 - 2013-11-07 20:05 - 00006144 _____ C:\Users\Schmidbauer\Downloads\Doodle.xls
2013-11-04 20:08 - 2013-11-04 20:08 - 00032734 _____ C:\Users\Schmidbauer\Downloads\mitgliederliste (2).csv
2013-11-01 09:45 - 2013-11-01 09:59 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0
2013-10-27 11:41 - 2013-10-27 11:41 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Roaming\Mozilla
2013-10-27 11:41 - 2013-10-27 11:41 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Local\Mozilla
2013-10-26 07:12 - 2013-10-26 07:12 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Roaming\Macromedia
2013-10-26 07:12 - 2013-10-26 07:12 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Local\Macromedia
2013-10-26 07:11 - 2013-11-09 18:43 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Local\Mozilla
2013-10-26 07:11 - 2013-10-26 07:11 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Roaming\Mozilla
2013-10-25 17:33 - 2013-10-25 17:33 - 00000939 _____ C:\Users\Schmidbauer\Downloads\CalendarService.ics
2013-10-22 18:47 - 2013-10-22 18:47 - 00000000 ____D C:\ProgramData\Licenses
2013-10-21 13:06 - 2013-10-21 13:06 - 00032313 _____ C:\Users\Schmidbauer\Downloads\mitgliederliste (1).csv
2013-10-20 17:13 - 2013-10-20 17:13 - 00001095 _____ C:\Users\Public\Desktop\Formatwandler 5.lnk
2013-10-20 17:13 - 2013-10-20 17:13 - 00000000 ____D C:\ProgramData\Engelmann Media
2013-10-20 17:13 - 2013-10-20 17:13 - 00000000 ____D C:\Program Files\Common Files\Ogg+WebM
2013-10-20 17:08 - 2013-10-20 17:12 - 84171136 _____ (S.A.D.) C:\Users\Schmidbauer\Downloads\formatconverter5.exe
2013-10-20 17:07 - 2013-10-20 17:07 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Engelmann Media
2013-10-20 17:03 - 2013-10-20 17:03 - 00000000 ____D C:\Program Files\S.A.D
2013-10-20 17:03 - 2013-10-20 17:03 - 00000000 ____D C:\Program Files\Common Files\HDX4
2013-10-19 18:53 - 2013-10-19 18:53 - 00000000 ____D C:\Users\Schmidbauer\Documents\Kulturring
2013-10-18 08:13 - 2013-10-18 08:13 - 00000000 ____D C:\Users\Schmidbauer\AppData\Local\Macromedia
2013-10-18 08:12 - 2013-10-18 08:12 - 07912440 _____ (Adobe Systems Inc.) C:\Users\Schmidbauer\Downloads\Shockwave_Installer_Slim.exe
2013-10-18 08:10 - 2013-10-18 08:10 - 00000000 ____D C:\ProgramData\McAfee
2013-10-18 08:05 - 2013-10-18 08:05 - 00001211 _____ C:\Windows\wininit.ini
2013-10-18 07:47 - 2013-10-18 07:47 - 00000000 ____D C:\SoloApp
2013-10-18 07:37 - 2013-11-12 08:37 - 00001290 _____ C:\Windows\Tasks\Plus-HD-3.8-updater.job
2013-10-18 07:37 - 2013-10-18 07:37 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Windows Net Data
2013-10-18 07:36 - 2013-11-12 08:36 - 00001892 _____ C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job
2013-10-18 07:36 - 2013-11-12 08:36 - 00001816 _____ C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job
2013-10-18 07:36 - 2013-11-12 08:36 - 00001196 _____ C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job
2013-10-18 07:36 - 2013-11-12 08:36 - 00001094 _____ C:\Windows\Tasks\Plus-HD-3.8-enabler.job
2013-10-18 07:36 - 2013-11-01 13:47 - 00000000 ____D C:\Program Files\Plus-HD-3.8
2013-10-18 07:36 - 2013-10-18 07:36 - 00000000 ____D C:\Program Files\Web Optimizer
2013-10-18 07:36 - 2013-08-13 07:38 - 00032328 _____ C:\Windows\Launcher.exe
2013-10-18 07:34 - 2013-10-18 07:34 - 00465224 _____ C:\Users\Schmidbauer\Downloads\geotag-0087-Downloader.exe
2013-10-17 17:33 - 2013-10-17 17:33 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Roaming\Macromedia
==================== One Month Modified Files and Folders =======
2013-11-12 13:50 - 2013-11-12 13:50 - 00000000 ____D C:\FRST
2013-11-12 13:49 - 2013-11-12 13:49 - 01090275 _____ (Farbar) C:\Users\Schmidbauer\Desktop\FRST.exe
2013-11-12 13:45 - 2013-05-25 13:50 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-12 13:41 - 2013-11-12 13:41 - 103891779 _____ C:\Windows\system32\ᒲᷣJ
2013-11-12 13:41 - 2013-07-23 06:28 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-12 13:41 - 2013-05-25 10:29 - 01839792 _____ C:\Windows\WindowsUpdate.log
2013-11-12 08:37 - 2013-10-18 07:37 - 00001290 _____ C:\Windows\Tasks\Plus-HD-3.8-updater.job
2013-11-12 08:36 - 2013-10-18 07:36 - 00001892 _____ C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job
2013-11-12 08:36 - 2013-10-18 07:36 - 00001816 _____ C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job
2013-11-12 08:36 - 2013-10-18 07:36 - 00001196 _____ C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job
2013-11-12 08:36 - 2013-10-18 07:36 - 00001094 _____ C:\Windows\Tasks\Plus-HD-3.8-enabler.job
2013-11-12 08:28 - 2012-05-31 16:20 - 00000000 ____D C:\Users\Schmidbauer\Documents\Windowsprobleme
2013-11-12 07:48 - 2009-07-14 05:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-12 07:48 - 2009-07-14 05:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-12 07:46 - 2009-11-16 10:59 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-12 07:41 - 2013-05-27 16:52 - 00000000 ___RD C:\Users\Schmidbauer\Dropbox
2013-11-12 07:41 - 2013-05-27 16:50 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Dropbox
2013-11-12 07:41 - 2013-05-25 13:50 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-12 07:40 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-12 07:40 - 2009-07-14 05:39 - 00087180 _____ C:\Windows\setupact.log
2013-11-11 16:39 - 2013-05-27 12:57 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\FileZilla
2013-11-11 16:38 - 2011-01-05 16:35 - 00000000 ____D C:\Users\Schmidbauer\Documents\Feuerwehr HP
2013-11-11 10:38 - 2013-11-11 10:38 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Local\Adobe
2013-11-11 10:38 - 2013-08-20 07:35 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Roaming\Adobe
2013-11-10 17:43 - 2013-11-10 17:43 - 00006511 _____ C:\Users\Schmidbauer\Documents\log.xml
2013-11-10 17:42 - 2013-11-10 17:42 - 00000000 ____D C:\Users\Schmidbauer\Documents\Neuer Ordner (2)
2013-11-10 16:53 - 2013-11-10 16:53 - 04892480 _____ (WinZip International LLC ) C:\Users\Schmidbauer\Downloads\wzmp_8.exe
2013-11-10 16:53 - 2013-11-10 16:53 - 00001151 _____ C:\Users\Public\Desktop\WinZip Malware Protector.lnk
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Nico Mak Computing
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\ProgramData\Nico Mak Computing
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\Program Files\WinZip Malware Protector
2013-11-10 14:04 - 2013-11-10 14:04 - 103467942 _____ C:\Windows\system32\쇓讟g
2013-11-10 08:40 - 2010-03-03 13:17 - 00000000 ____D C:\Users\Schmidbauer\Documents\EDV
2013-11-09 18:43 - 2013-10-26 07:11 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Local\Mozilla
2013-11-08 07:22 - 2013-05-25 10:47 - 00000000 ____D C:\Users\Schmidbauer\AppData\Local\Microsoft Help
2013-11-07 20:05 - 2013-11-07 20:05 - 00006144 _____ C:\Users\Schmidbauer\Downloads\Doodle.xls
2013-11-04 20:08 - 2013-11-04 20:08 - 00032734 _____ C:\Users\Schmidbauer\Downloads\mitgliederliste (2).csv
2013-11-03 15:28 - 2013-05-29 09:27 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\Documents\Kochbuch
2013-11-01 13:47 - 2013-10-18 07:36 - 00000000 ____D C:\Program Files\Plus-HD-3.8
2013-11-01 09:59 - 2013-11-01 09:45 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0
2013-10-27 11:41 - 2013-10-27 11:41 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Roaming\Mozilla
2013-10-27 11:41 - 2013-10-27 11:41 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Local\Mozilla
2013-10-27 07:53 - 2010-12-10 10:52 - 00000000 ____D C:\Users\Schmidbauer\Documents\Privat
2013-10-26 07:12 - 2013-10-26 07:12 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Roaming\Macromedia
2013-10-26 07:12 - 2013-10-26 07:12 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Local\Macromedia
2013-10-26 07:11 - 2013-10-26 07:11 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Roaming\Mozilla
2013-10-25 17:33 - 2013-10-25 17:33 - 00000939 _____ C:\Users\Schmidbauer\Downloads\CalendarService.ics
2013-10-24 07:35 - 2010-02-28 15:56 - 00000000 ____D C:\Users\Schmidbauer\Documents\Theater
2013-10-24 06:51 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2013-10-22 18:47 - 2013-10-22 18:47 - 00000000 ____D C:\ProgramData\Licenses
2013-10-21 13:06 - 2013-10-21 13:06 - 00032313 _____ C:\Users\Schmidbauer\Downloads\mitgliederliste (1).csv
2013-10-21 06:27 - 2009-11-16 12:39 - 00397464 _____ C:\Windows\PFRO.log
2013-10-20 17:17 - 2013-05-25 16:08 - 00000000 ____D C:\Users\Schmidbauer\AppData\Local\Adobe
2013-10-20 17:13 - 2013-10-20 17:13 - 00001095 _____ C:\Users\Public\Desktop\Formatwandler 5.lnk
2013-10-20 17:13 - 2013-10-20 17:13 - 00000000 ____D C:\ProgramData\Engelmann Media
2013-10-20 17:13 - 2013-10-20 17:13 - 00000000 ____D C:\Program Files\Common Files\Ogg+WebM
2013-10-20 17:12 - 2013-10-20 17:08 - 84171136 _____ (S.A.D.) C:\Users\Schmidbauer\Downloads\formatconverter5.exe
2013-10-20 17:07 - 2013-10-20 17:07 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Engelmann Media
2013-10-20 17:03 - 2013-10-20 17:03 - 00000000 ____D C:\Program Files\S.A.D
2013-10-20 17:03 - 2013-10-20 17:03 - 00000000 ____D C:\Program Files\Common Files\HDX4
2013-10-19 18:53 - 2013-10-19 18:53 - 00000000 ____D C:\Users\Schmidbauer\Documents\Kulturring
2013-10-18 08:13 - 2013-10-18 08:13 - 00000000 ____D C:\Users\Schmidbauer\AppData\Local\Macromedia
2013-10-18 08:12 - 2013-10-18 08:12 - 07912440 _____ (Adobe Systems Inc.) C:\Users\Schmidbauer\Downloads\Shockwave_Installer_Slim.exe
2013-10-18 08:12 - 2009-11-16 12:15 - 00000000 ____D C:\Windows\system32\Adobe
2013-10-18 08:10 - 2013-10-18 08:10 - 00000000 ____D C:\ProgramData\McAfee
2013-10-18 08:10 - 2013-07-23 06:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-18 08:10 - 2013-07-23 06:28 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-18 08:05 - 2013-10-18 08:05 - 00001211 _____ C:\Windows\wininit.ini
2013-10-18 07:50 - 2013-05-25 13:52 - 00002133 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-18 07:47 - 2013-10-18 07:47 - 00000000 ____D C:\SoloApp
2013-10-18 07:37 - 2013-10-18 07:37 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Windows Net Data
2013-10-18 07:36 - 2013-10-18 07:36 - 00000000 ____D C:\Program Files\Web Optimizer
2013-10-18 07:35 - 2013-10-11 13:40 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-18 07:35 - 2009-11-20 13:01 - 00001745 _____ C:\Users\Public\Desktop\eBay.lnk
2013-10-18 07:34 - 2013-10-18 07:34 - 00465224 _____ C:\Users\Schmidbauer\Downloads\geotag-0087-Downloader.exe
2013-10-17 17:50 - 2013-05-29 09:27 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\Documents\Rezepte
2013-10-17 17:33 - 2013-10-17 17:33 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Roaming\Macromedia
2013-10-14 11:44 - 2009-07-14 05:53 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-13 12:34 - 2013-10-11 09:38 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-13 07:05 - 2013-10-11 09:38 - 00000000 ____D C:\Users\Schmidbauer\AppData\Local\Mozilla
Some content of TEMP:
====================
C:\Users\Gast.Schmidbauer-PC\AppData\Local\Temp\FileSystemView.dll
C:\Users\Schmidbauer\AppData\Local\Temp\ose00000.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-10 12:33
==================== End Of Log ============================ --- --- ---
--- --- ---
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 10-11-2013 01
Ran by Schmidbauer at 2013-11-12 13:51:33
Running from C:\Users\Schmidbauer\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
==================== Installed Programs ======================
Activation Assistant for the 2007 Microsoft Office suites
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Photoshop 7.0 (Version: 7.0)
Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05)
Adobe Shockwave Player 12.0 (Version: 12.0.4.144)
Ashampoo Home Designer Pro v.1.0.1 (Version: 1.0.1)
Avira Free Antivirus (Version: 13.0.0.4052)
Bing Bar (Version: 7.2.241.0)
Canon MP Navigator EX 3.0
Canon MP250 series Benutzerregistrierung
Canon MP250 series MP Drivers
Canon Utilities Easy-PhotoPrint EX
Canon Utilities My Printer
Canon Utilities Solution Menu
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
Corel MediaOne (Version: 2.100.0000)
CorelDRAW Essential Edition 3
CorelDRAW Essential Edition 3 (Version: 3.0)
CyberLink LabelPrint (Version: 2.5.1916)
CyberLink Power2Go (Version: 6.1.3213)
CyberLink PowerDVD Copy (Version: 1.0.6720)
DE (Version: 3.0)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
DirectX for Managed Code Update (Summer 2004) (Version: 9.02.2904)
Dropbox (HKCU Version: 2.0.22)
ELBA5 (C:\Program Files\ELBA5) (Version: 5.0.0.0)
FileZilla Client 3.7.3 (Version: 3.7.3)
Firebird SQL Server - MAGIX Edition (Version: 2.1.23.0)
Formatwandler 5 (Version: 5.0.13.429)
Google Chrome (Version: 30.0.1599.101)
Google Update Helper (Version: 1.3.21.165)
GPS Master 2.0.14 (Version: 1.0)
Hofer Foto Manager Free (Version: 6.0.1.491)
Hofer Foto Service (Version: 4.5.9.142)
Hofer Fotodruck Service 4.5 (Version: 4.5)
Hofer Online Druck Service (Version: 4.5.1.1)
HomeTab 4.8 (Version: 4.8)
Intel(R) Rapid Storage Technology (Version: 9.5.0.1037)
Java Auto Updater (Version: 2.0.1.2)
Java(TM) 6 Update 18 (Version: 6.0.180)
Junk Mail filter update (Version: 14.0.8089.726)
Macromedia Dreamweaver 8 (Version: 8.0.0.2751)
Macromedia Extension Manager (Version: 1.7.240)
Macromedia Extension Manager (Version: 1.7.270)
MEDION Fotos auf CD & DVD SE Hofer (Version: 8.0.3.4)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.4 (Version: 2.0.3008.0)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000)
Microsoft Office Professional 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [DEU] (Version: 3.1.0000)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0)
Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Works (Version: 9.7.0621)
Mozilla Firefox 24.0 (x86 de) (Version: 24.0)
Mozilla Maintenance Service (Version: 24.0)
MSVCRT (Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
NVIDIA Display Control Panel (Version: 1.6)
NVIDIA Drivers (Version: 1.10)
NVIDIA PhysX (Version: 9.09.1112)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0)
Plus-HD-3.8 (Version: 1.27.153.11)
Realtek High Definition Audio Driver (Version: 6.0.1.5910)
Screenpresso (HKCU Version: 1.4.1.6)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal)
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
Spybot - Search & Destroy (Version: 2.1.19)
swMSM (Version: 12.0.0.1)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2827325) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition
Update für Microsoft Office Excel 2007 Help (KB963678)
Update für Microsoft Office Outlook 2007 Help (KB963677)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)
Update für Microsoft Office Word 2007 Help (KB963665)
Update Manager (Version: 4.60)
VIS
Web Optimizer
Windows Live Call (Version: 14.0.8064.0206)
Windows Live Communications Platform (Version: 14.0.8064.206)
Windows Live Essentials (Version: 14.0.8089.0726)
Windows Live Essentials (Version: 14.0.8089.726)
Windows Live Fotogalerie (Version: 14.0.8081.709)
Windows Live ID-Anmelde-Assistent (Version: 6.500.3146.0)
Windows Live Mail (Version: 14.0.8089.0726)
Windows Live Messenger (Version: 14.0.8089.0726)
Windows Live Movie Maker (Version: 14.0.8091.0730)
Windows Live Sync (Version: 14.0.8089.726)
Windows Live Writer (Version: 14.0.8089.0726)
Windows Live-Uploadtool (Version: 14.0.8014.1029)
WinZip Malware Protector (Version: 2.1.1000.10798)
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {13E5E58C-3C9D-43AD-AEA2-278B877BEAAE} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
Task: {15824438-B2F2-45CA-86D6-89EDD54831CD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-18] (Adobe Systems Incorporated)
Task: {34DF7326-6CD6-42A5-AEE4-BF3E182F8E77} - System32\Tasks\Plus-HD-3.8-chromeinstaller => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-chromeinstaller.exe [2013-10-18] (Plus HD)
Task: {37CE32FB-1340-42A1-97A3-CB574873D3BC} - System32\Tasks\Plus-HD-3.8-codedownloader => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-codedownloader.exe [2013-10-18] (Plus HD)
Task: {54CC87BF-78CA-451A-A4D7-E5BB691F01D6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {56A6164D-D19C-4F65-8868-3DAA8C507FF7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-05-25] (Google Inc.)
Task: {5C99E0A3-C5D6-445D-AD1B-BE21F53038BF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-05-25] (Google Inc.)
Task: {659CA911-9E96-4083-ACF1-E9F12F8B102A} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {815369C0-79CC-4103-8556-E93DB6BD0265} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {B6940020-EDF3-4C2A-9292-DACA8AED75EC} - System32\Tasks\Plus-HD-3.8-enabler => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-enabler.exe
Task: {B747277B-5DA8-4FDA-91BF-830642F99C5B} - System32\Tasks\Browser Updater\Browser Updater => Rundll32.exe "C:\Program Files\HomeTab\TBUpdater.dll",TBCheckForUpdate
Task: {D2B459E1-09EA-4465-83CE-6A20B5754F15} - System32\Tasks\Plus-HD-3.8-updater => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-updater.exe [2013-10-18] (Plus HD)
Task: {D5C7700F-3839-4185-9FBD-095DC85A5054} - System32\Tasks\Plus-HD-3.8-firefoxinstaller => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-firefoxinstaller.exe [2013-10-18] (Plus HD)
Task: {DAB7EC83-A7DC-41AD-9EEF-8DBB04D70DAD} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files\WinZip Malware Protector\WinZipMalwareProtector.exe [2013-07-15] (Nico Mak Computing)
Task: {F2820E51-DA7B-4F2D-A777-E148DB467B2C} - System32\Tasks\ProtectedSearch\Protected Search => C:\Program Files\HomeTab\ProtectedSearch.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-chromeinstaller.exe
Task: C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-codedownloader.exe
Task: C:\Windows\Tasks\Plus-HD-3.8-enabler.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-enabler.exe
Task: C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-firefoxinstaller.exe
Task: C:\Windows\Tasks\Plus-HD-3.8-updater.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-updater.exe
==================== Loaded Modules (whitelisted) =============
2013-11-10 16:53 - 2013-02-28 16:53 - 00886272 _____ () C:\Program Files\WinZip Malware Protector\System.Data.SQLite.dll
2013-11-10 16:53 - 2013-07-15 16:53 - 01717936 _____ () C:\Program Files\WinZip Malware Protector\aspsys.dll
2013-11-10 16:53 - 2013-02-28 16:53 - 00168448 _____ () C:\Program Files\WinZip Malware Protector\UNRAR.DLL
2013-08-07 20:25 - 2013-08-07 20:25 - 00093696 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2009-06-03 20:59 - 2009-06-03 20:59 - 00619816 ____N () C:\Program Files\CyberLink\Power2Go\CLMediaLibrary.dll
2009-06-03 20:59 - 2009-06-03 20:59 - 00013096 ____N () C:\Program Files\CyberLink\Power2Go\CLMLSvcPS.dll
2013-05-27 17:30 - 2013-05-16 09:55 - 00113496 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-05-27 17:30 - 2013-05-16 09:55 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
2013-05-27 17:30 - 2013-05-16 09:55 - 00161112 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Schmidbauer\AppData\Roaming\Dropbox\bin\libcef.dll
2011-03-16 23:11 - 2011-03-16 23:11 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf
2010-12-21 00:15 - 2010-12-21 00:15 - 01041248 _____ () C:\Program Files\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (11/11/2013 05:44:10 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/10/2013 04:18:10 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: SDTray.exe, Version: 2.1.18.127, Zeitstempel: 0x51949fd1
Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0004866a
ID des fehlerhaften Prozesses: 0xfc4
Startzeit der fehlerhaften Anwendung: 0xSDTray.exe0
Pfad der fehlerhaften Anwendung: SDTray.exe1
Pfad des fehlerhaften Moduls: SDTray.exe2
Berichtskennung: SDTray.exe3
Error: (11/10/2013 00:35:09 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/08/2013 07:18:18 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/07/2013 04:40:21 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/07/2013 10:05:45 AM) (Source: Application Hang) (User: )
Description: Programm OUTLOOK.EXE, Version 14.0.7105.5000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: a94
Startzeit: 01cedb9874ac7caf
Endzeit: 15
Anwendungspfad: C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
Berichts-ID: c0d808db-478b-11e3-a0ba-406186905b94
Error: (11/06/2013 07:37:01 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/06/2013 02:19:03 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc015000f
Fehleroffset: 0x00083fd3
ID des fehlerhaften Prozesses: 0x12fc
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3
Error: (11/06/2013 02:18:59 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7
Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1d731
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0004b1e8
ID des fehlerhaften Prozesses: 0x12fc
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3
Error: (11/06/2013 02:18:38 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc015000f
Fehleroffset: 0x00083fd3
ID des fehlerhaften Prozesses: 0x9cc
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
System errors:
=============
Error: (11/12/2013 08:16:53 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:16:53 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:16:53 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:16:53 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:16:32 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:15:59 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:15:59 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:15:59 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:15:59 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:15:17 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 35%
Total physical RAM: 3063.11 MB
Available physical RAM: 1988.26 MB
Total Pagefile: 6124.52 MB
Available Pagefile: 4271.33 MB
Total Virtual: 2047.88 MB
Available Virtual: 1895.86 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:910.41 GB) (Free:830.07 GB) NTFS
Drive d: (Recover) (Fixed) (Total:20 GB) (Free:11.58 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 499C4133)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=910 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
==================== End Of Log ============================ --- --- ---
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-11-2013 01
Ran by Schmidbauer (administrator) on SCHMIDBAUER-PC on 12-11-2013 13:50:29
Running from C:\Users\Schmidbauer\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
() C:\Windows\system32\PSIService.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Nico Mak Computing) C:\Program Files\WinZip Malware Protector\WinZipMalwareProtector.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Learnpulse) C:\Users\Schmidbauer\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe
(Dropbox, Inc.) C:\Users\Schmidbauer\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.2.241.0\SeaPort.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM\...\Run: [CLMLServer] - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-06-03] (CyberLink)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7703072 2009-08-04] (Realtek Semiconductor)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-02] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE [1983816 2009-07-27] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files\Canon\SolutionMenu\CNSLMAIN.EXE [767312 2009-03-18] (CANON INC.)
HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [3830224 2013-05-16] (Safer-Networking Ltd.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKCU\...\Run: [Screenpresso] - C:\Users\Schmidbauer\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe [10880016 2013-09-29] (Learnpulse)
HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.)
MountPoints2: {90547b4e-c51c-11e2-bd50-806e6f6e6963} - E:\autostart.exe
HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] ()
HKU\Default\...\RunOnce: [MEDION] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [ 2009-10-23] ()
Startup: C:\Users\Schmidbauer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Schmidbauer\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
ProxyServer: localhost:21320
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ff-ebersegg.at/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://google.at/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.4&ts=1382047200000.000007&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&st=chrome&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.4&ts=1382047200000.000007&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&st=chrome&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.4&ts=1382047200000.000007&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&st=chrome&q=
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1382047200000.000007&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&q={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1382047200000.000007&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&q={searchTerms}
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1382078115023&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&q={searchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {097FB4BD-5B76-449B-9BA6-3AC448025950} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
SearchScopes: HKCU - {575414CF-2DF7-47E6-B377-1F5F58BB8DD1} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10263&src=crm&q={searchTerms}&locale=de_AT&apn_ptnrs=^AGU&apn_dtid=^YYYYYY^YY^AT&apn_uid=2332769e-b89b-4b8c-8a1d-ac946215b4ba&apn_sauid=E82B4122-D4A9-4996-8D05-6B17C67CCB4E
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
BHO: Plus-HD-3.8 - {11111111-1111-1111-1111-110311901130} - C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-bho.dll (Plus HD)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Web Optimizer - {bbb1d54d-cf70-4a80-bf2f-3bafca0225ce} - C:\Program Files\Web Optimizer\weboptimizer.dll (Web Optimizer)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - No Name - {a25e7121-3dd8-41b3-855b-756c5bc45449} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Schmidbauer\AppData\Roaming\Mozilla\Firefox\Profiles\7uvpei24.default
FF NewTab: about:home
FF DefaultSearchEngine: Web Search
FF SearchEngineOrder.1: Web Search
FF SelectedSearchEngine: Web Search
FF Homepage: about:home
FF Keyword.URL: hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.4&ts=1382047200000.000007&tguid=66920-6787-1382078115023-D5F77859C56D7BB825D24169503DB739&st=chrome&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.4 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Schmidbauer\AppData\Roaming\Mozilla\Firefox\Profiles\7uvpei24.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Plus-HD-3.8 - C:\Users\Schmidbauer\AppData\Roaming\Mozilla\Firefox\Profiles\7uvpei24.default\Extensions\c17236e8-fd66-44bc-aeef-1e00981cbb64@0a4ee0fe-5356-4fd3-b37c-5cd5671a315c.com
FF Extension: vis - C:\Users\Schmidbauer\AppData\Roaming\Mozilla\Firefox\Profiles\7uvpei24.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
FF Extension: HomeTab - C:\Users\Schmidbauer\AppData\Roaming\Mozilla\Firefox\Profiles\7uvpei24.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947}
FF HKLM\...\Firefox\Extensions: [{ff0f24dd-184a-42ca-9ce8-8ca6184fd0ac}] - C:\Program Files\Web Optimizer\weboptimizer.xpi
FF Extension: No Name - C:\Program Files\Web Optimizer\weboptimizer.xpi
Chrome:
=======
CHR HomePage: hxxp://www.google.at/
CHR RestoreOnStartup: "hxxp://ff-ebersegg.at/", "hxxp://theater-kleinraming.at/", "hxxp://www.google.at/"
CHR Extension: (Web Optimizer) - C:\Users\SCHMID~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\afjadpgpmmloiaibmijliigmaokkejnk\0.1_1
CHR Extension: (Google Wallet) - C:\Users\SCHMID~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Plus-HD-3.8) - C:\Users\SCHMID~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjgnhihlklpobkaloamkankaaoclfjh\1.23.19_0
CHR HKLM\...\Chrome\Extension: [afjadpgpmmloiaibmijliigmaokkejnk] - C:\Program Files\Web Optimizer\weboptimizer.crx
CHR HKLM\...\Chrome\Extension: [bddpogknpjlgfpbboediomaiiaecfajn] - C:\Program Files\HomeTab\chrome\HomeTab.crx
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1155072 2009-02-03] (MAGIX AG)
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®)
R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
S4 Hbnbe0vnuslo;
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-02] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-05-25] (Avira Operations GmbH & Co. KG)
S3 silabenm; C:\Windows\System32\DRIVERS\silabenm.sys [47176 2011-10-14] (Silicon Laboratories)
S3 silabser; C:\Windows\System32\DRIVERS\silabser.sys [61312 2011-10-14] (Silicon Laboratories)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-05-25] (Avira GmbH)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-12 13:50 - 2013-11-12 13:50 - 00000000 ____D C:\FRST
2013-11-12 13:49 - 2013-11-12 13:49 - 01090275 _____ (Farbar) C:\Users\Schmidbauer\Desktop\FRST.exe
2013-11-12 13:41 - 2013-11-12 13:41 - 103891779 _____ C:\Windows\system32\ᒲᷣJ
2013-11-11 10:38 - 2013-11-11 10:38 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Local\Adobe
2013-11-10 17:43 - 2013-11-10 17:43 - 00006511 _____ C:\Users\Schmidbauer\Documents\log.xml
2013-11-10 17:42 - 2013-11-10 17:42 - 00000000 ____D C:\Users\Schmidbauer\Documents\Neuer Ordner (2)
2013-11-10 16:53 - 2013-11-10 16:53 - 04892480 _____ (WinZip International LLC ) C:\Users\Schmidbauer\Downloads\wzmp_8.exe
2013-11-10 16:53 - 2013-11-10 16:53 - 00001151 _____ C:\Users\Public\Desktop\WinZip Malware Protector.lnk
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Nico Mak Computing
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\ProgramData\Nico Mak Computing
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\Program Files\WinZip Malware Protector
2013-11-10 16:53 - 2013-03-15 17:01 - 00016384 _____ C:\Windows\system32\wsusnative32.exe
2013-11-10 14:04 - 2013-11-10 14:04 - 103467942 _____ C:\Windows\system32\쇓讟g
2013-11-07 20:05 - 2013-11-07 20:05 - 00006144 _____ C:\Users\Schmidbauer\Downloads\Doodle.xls
2013-11-04 20:08 - 2013-11-04 20:08 - 00032734 _____ C:\Users\Schmidbauer\Downloads\mitgliederliste (2).csv
2013-11-01 09:45 - 2013-11-01 09:59 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0
2013-10-27 11:41 - 2013-10-27 11:41 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Roaming\Mozilla
2013-10-27 11:41 - 2013-10-27 11:41 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Local\Mozilla
2013-10-26 07:12 - 2013-10-26 07:12 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Roaming\Macromedia
2013-10-26 07:12 - 2013-10-26 07:12 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Local\Macromedia
2013-10-26 07:11 - 2013-11-09 18:43 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Local\Mozilla
2013-10-26 07:11 - 2013-10-26 07:11 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Roaming\Mozilla
2013-10-25 17:33 - 2013-10-25 17:33 - 00000939 _____ C:\Users\Schmidbauer\Downloads\CalendarService.ics
2013-10-22 18:47 - 2013-10-22 18:47 - 00000000 ____D C:\ProgramData\Licenses
2013-10-21 13:06 - 2013-10-21 13:06 - 00032313 _____ C:\Users\Schmidbauer\Downloads\mitgliederliste (1).csv
2013-10-20 17:13 - 2013-10-20 17:13 - 00001095 _____ C:\Users\Public\Desktop\Formatwandler 5.lnk
2013-10-20 17:13 - 2013-10-20 17:13 - 00000000 ____D C:\ProgramData\Engelmann Media
2013-10-20 17:13 - 2013-10-20 17:13 - 00000000 ____D C:\Program Files\Common Files\Ogg+WebM
2013-10-20 17:08 - 2013-10-20 17:12 - 84171136 _____ (S.A.D.) C:\Users\Schmidbauer\Downloads\formatconverter5.exe
2013-10-20 17:07 - 2013-10-20 17:07 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Engelmann Media
2013-10-20 17:03 - 2013-10-20 17:03 - 00000000 ____D C:\Program Files\S.A.D
2013-10-20 17:03 - 2013-10-20 17:03 - 00000000 ____D C:\Program Files\Common Files\HDX4
2013-10-19 18:53 - 2013-10-19 18:53 - 00000000 ____D C:\Users\Schmidbauer\Documents\Kulturring
2013-10-18 08:13 - 2013-10-18 08:13 - 00000000 ____D C:\Users\Schmidbauer\AppData\Local\Macromedia
2013-10-18 08:12 - 2013-10-18 08:12 - 07912440 _____ (Adobe Systems Inc.) C:\Users\Schmidbauer\Downloads\Shockwave_Installer_Slim.exe
2013-10-18 08:10 - 2013-10-18 08:10 - 00000000 ____D C:\ProgramData\McAfee
2013-10-18 08:05 - 2013-10-18 08:05 - 00001211 _____ C:\Windows\wininit.ini
2013-10-18 07:47 - 2013-10-18 07:47 - 00000000 ____D C:\SoloApp
2013-10-18 07:37 - 2013-11-12 08:37 - 00001290 _____ C:\Windows\Tasks\Plus-HD-3.8-updater.job
2013-10-18 07:37 - 2013-10-18 07:37 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Windows Net Data
2013-10-18 07:36 - 2013-11-12 08:36 - 00001892 _____ C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job
2013-10-18 07:36 - 2013-11-12 08:36 - 00001816 _____ C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job
2013-10-18 07:36 - 2013-11-12 08:36 - 00001196 _____ C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job
2013-10-18 07:36 - 2013-11-12 08:36 - 00001094 _____ C:\Windows\Tasks\Plus-HD-3.8-enabler.job
2013-10-18 07:36 - 2013-11-01 13:47 - 00000000 ____D C:\Program Files\Plus-HD-3.8
2013-10-18 07:36 - 2013-10-18 07:36 - 00000000 ____D C:\Program Files\Web Optimizer
2013-10-18 07:36 - 2013-08-13 07:38 - 00032328 _____ C:\Windows\Launcher.exe
2013-10-18 07:34 - 2013-10-18 07:34 - 00465224 _____ C:\Users\Schmidbauer\Downloads\geotag-0087-Downloader.exe
2013-10-17 17:33 - 2013-10-17 17:33 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Roaming\Macromedia
==================== One Month Modified Files and Folders =======
2013-11-12 13:50 - 2013-11-12 13:50 - 00000000 ____D C:\FRST
2013-11-12 13:49 - 2013-11-12 13:49 - 01090275 _____ (Farbar) C:\Users\Schmidbauer\Desktop\FRST.exe
2013-11-12 13:45 - 2013-05-25 13:50 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-12 13:41 - 2013-11-12 13:41 - 103891779 _____ C:\Windows\system32\ᒲᷣJ
2013-11-12 13:41 - 2013-07-23 06:28 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-12 13:41 - 2013-05-25 10:29 - 01839792 _____ C:\Windows\WindowsUpdate.log
2013-11-12 08:37 - 2013-10-18 07:37 - 00001290 _____ C:\Windows\Tasks\Plus-HD-3.8-updater.job
2013-11-12 08:36 - 2013-10-18 07:36 - 00001892 _____ C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job
2013-11-12 08:36 - 2013-10-18 07:36 - 00001816 _____ C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job
2013-11-12 08:36 - 2013-10-18 07:36 - 00001196 _____ C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job
2013-11-12 08:36 - 2013-10-18 07:36 - 00001094 _____ C:\Windows\Tasks\Plus-HD-3.8-enabler.job
2013-11-12 08:28 - 2012-05-31 16:20 - 00000000 ____D C:\Users\Schmidbauer\Documents\Windowsprobleme
2013-11-12 07:48 - 2009-07-14 05:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-12 07:48 - 2009-07-14 05:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-12 07:46 - 2009-11-16 10:59 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-12 07:41 - 2013-05-27 16:52 - 00000000 ___RD C:\Users\Schmidbauer\Dropbox
2013-11-12 07:41 - 2013-05-27 16:50 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Dropbox
2013-11-12 07:41 - 2013-05-25 13:50 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-12 07:40 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-12 07:40 - 2009-07-14 05:39 - 00087180 _____ C:\Windows\setupact.log
2013-11-11 16:39 - 2013-05-27 12:57 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\FileZilla
2013-11-11 16:38 - 2011-01-05 16:35 - 00000000 ____D C:\Users\Schmidbauer\Documents\Feuerwehr HP
2013-11-11 10:38 - 2013-11-11 10:38 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Local\Adobe
2013-11-11 10:38 - 2013-08-20 07:35 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Roaming\Adobe
2013-11-10 17:43 - 2013-11-10 17:43 - 00006511 _____ C:\Users\Schmidbauer\Documents\log.xml
2013-11-10 17:42 - 2013-11-10 17:42 - 00000000 ____D C:\Users\Schmidbauer\Documents\Neuer Ordner (2)
2013-11-10 16:53 - 2013-11-10 16:53 - 04892480 _____ (WinZip International LLC ) C:\Users\Schmidbauer\Downloads\wzmp_8.exe
2013-11-10 16:53 - 2013-11-10 16:53 - 00001151 _____ C:\Users\Public\Desktop\WinZip Malware Protector.lnk
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Nico Mak Computing
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\ProgramData\Nico Mak Computing
2013-11-10 16:53 - 2013-11-10 16:53 - 00000000 ____D C:\Program Files\WinZip Malware Protector
2013-11-10 14:04 - 2013-11-10 14:04 - 103467942 _____ C:\Windows\system32\쇓讟g
2013-11-10 08:40 - 2010-03-03 13:17 - 00000000 ____D C:\Users\Schmidbauer\Documents\EDV
2013-11-09 18:43 - 2013-10-26 07:11 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Local\Mozilla
2013-11-08 07:22 - 2013-05-25 10:47 - 00000000 ____D C:\Users\Schmidbauer\AppData\Local\Microsoft Help
2013-11-07 20:05 - 2013-11-07 20:05 - 00006144 _____ C:\Users\Schmidbauer\Downloads\Doodle.xls
2013-11-04 20:08 - 2013-11-04 20:08 - 00032734 _____ C:\Users\Schmidbauer\Downloads\mitgliederliste (2).csv
2013-11-03 15:28 - 2013-05-29 09:27 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\Documents\Kochbuch
2013-11-01 13:47 - 2013-10-18 07:36 - 00000000 ____D C:\Program Files\Plus-HD-3.8
2013-11-01 09:59 - 2013-11-01 09:45 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0
2013-10-27 11:41 - 2013-10-27 11:41 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Roaming\Mozilla
2013-10-27 11:41 - 2013-10-27 11:41 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Local\Mozilla
2013-10-27 07:53 - 2010-12-10 10:52 - 00000000 ____D C:\Users\Schmidbauer\Documents\Privat
2013-10-26 07:12 - 2013-10-26 07:12 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Roaming\Macromedia
2013-10-26 07:12 - 2013-10-26 07:12 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Local\Macromedia
2013-10-26 07:11 - 2013-10-26 07:11 - 00000000 ____D C:\Users\Gast.Schmidbauer-PC\AppData\Roaming\Mozilla
2013-10-25 17:33 - 2013-10-25 17:33 - 00000939 _____ C:\Users\Schmidbauer\Downloads\CalendarService.ics
2013-10-24 07:35 - 2010-02-28 15:56 - 00000000 ____D C:\Users\Schmidbauer\Documents\Theater
2013-10-24 06:51 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2013-10-22 18:47 - 2013-10-22 18:47 - 00000000 ____D C:\ProgramData\Licenses
2013-10-21 13:06 - 2013-10-21 13:06 - 00032313 _____ C:\Users\Schmidbauer\Downloads\mitgliederliste (1).csv
2013-10-21 06:27 - 2009-11-16 12:39 - 00397464 _____ C:\Windows\PFRO.log
2013-10-20 17:17 - 2013-05-25 16:08 - 00000000 ____D C:\Users\Schmidbauer\AppData\Local\Adobe
2013-10-20 17:13 - 2013-10-20 17:13 - 00001095 _____ C:\Users\Public\Desktop\Formatwandler 5.lnk
2013-10-20 17:13 - 2013-10-20 17:13 - 00000000 ____D C:\ProgramData\Engelmann Media
2013-10-20 17:13 - 2013-10-20 17:13 - 00000000 ____D C:\Program Files\Common Files\Ogg+WebM
2013-10-20 17:12 - 2013-10-20 17:08 - 84171136 _____ (S.A.D.) C:\Users\Schmidbauer\Downloads\formatconverter5.exe
2013-10-20 17:07 - 2013-10-20 17:07 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Engelmann Media
2013-10-20 17:03 - 2013-10-20 17:03 - 00000000 ____D C:\Program Files\S.A.D
2013-10-20 17:03 - 2013-10-20 17:03 - 00000000 ____D C:\Program Files\Common Files\HDX4
2013-10-19 18:53 - 2013-10-19 18:53 - 00000000 ____D C:\Users\Schmidbauer\Documents\Kulturring
2013-10-18 08:13 - 2013-10-18 08:13 - 00000000 ____D C:\Users\Schmidbauer\AppData\Local\Macromedia
2013-10-18 08:12 - 2013-10-18 08:12 - 07912440 _____ (Adobe Systems Inc.) C:\Users\Schmidbauer\Downloads\Shockwave_Installer_Slim.exe
2013-10-18 08:12 - 2009-11-16 12:15 - 00000000 ____D C:\Windows\system32\Adobe
2013-10-18 08:10 - 2013-10-18 08:10 - 00000000 ____D C:\ProgramData\McAfee
2013-10-18 08:10 - 2013-07-23 06:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-18 08:10 - 2013-07-23 06:28 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-18 08:05 - 2013-10-18 08:05 - 00001211 _____ C:\Windows\wininit.ini
2013-10-18 07:50 - 2013-05-25 13:52 - 00002133 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-18 07:47 - 2013-10-18 07:47 - 00000000 ____D C:\SoloApp
2013-10-18 07:37 - 2013-10-18 07:37 - 00000000 ____D C:\Users\Schmidbauer\AppData\Roaming\Windows Net Data
2013-10-18 07:36 - 2013-10-18 07:36 - 00000000 ____D C:\Program Files\Web Optimizer
2013-10-18 07:35 - 2013-10-11 13:40 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-18 07:35 - 2009-11-20 13:01 - 00001745 _____ C:\Users\Public\Desktop\eBay.lnk
2013-10-18 07:34 - 2013-10-18 07:34 - 00465224 _____ C:\Users\Schmidbauer\Downloads\geotag-0087-Downloader.exe
2013-10-17 17:50 - 2013-05-29 09:27 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\Documents\Rezepte
2013-10-17 17:33 - 2013-10-17 17:33 - 00000000 ____D C:\Users\Hildegard.Schmidbauer-PC\AppData\Roaming\Macromedia
2013-10-14 11:44 - 2009-07-14 05:53 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-13 12:34 - 2013-10-11 09:38 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-13 07:05 - 2013-10-11 09:38 - 00000000 ____D C:\Users\Schmidbauer\AppData\Local\Mozilla
Some content of TEMP:
====================
C:\Users\Gast.Schmidbauer-PC\AppData\Local\Temp\FileSystemView.dll
C:\Users\Schmidbauer\AppData\Local\Temp\ose00000.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-10 12:33
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 10-11-2013 01
Ran by Schmidbauer at 2013-11-12 13:51:33
Running from C:\Users\Schmidbauer\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
==================== Installed Programs ======================
Activation Assistant for the 2007 Microsoft Office suites
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Photoshop 7.0 (Version: 7.0)
Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05)
Adobe Shockwave Player 12.0 (Version: 12.0.4.144)
Ashampoo Home Designer Pro v.1.0.1 (Version: 1.0.1)
Avira Free Antivirus (Version: 13.0.0.4052)
Bing Bar (Version: 7.2.241.0)
Canon MP Navigator EX 3.0
Canon MP250 series Benutzerregistrierung
Canon MP250 series MP Drivers
Canon Utilities Easy-PhotoPrint EX
Canon Utilities My Printer
Canon Utilities Solution Menu
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
Corel MediaOne (Version: 2.100.0000)
CorelDRAW Essential Edition 3
CorelDRAW Essential Edition 3 (Version: 3.0)
CyberLink LabelPrint (Version: 2.5.1916)
CyberLink Power2Go (Version: 6.1.3213)
CyberLink PowerDVD Copy (Version: 1.0.6720)
DE (Version: 3.0)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
DirectX for Managed Code Update (Summer 2004) (Version: 9.02.2904)
Dropbox (HKCU Version: 2.0.22)
ELBA5 (C:\Program Files\ELBA5) (Version: 5.0.0.0)
FileZilla Client 3.7.3 (Version: 3.7.3)
Firebird SQL Server - MAGIX Edition (Version: 2.1.23.0)
Formatwandler 5 (Version: 5.0.13.429)
Google Chrome (Version: 30.0.1599.101)
Google Update Helper (Version: 1.3.21.165)
GPS Master 2.0.14 (Version: 1.0)
Hofer Foto Manager Free (Version: 6.0.1.491)
Hofer Foto Service (Version: 4.5.9.142)
Hofer Fotodruck Service 4.5 (Version: 4.5)
Hofer Online Druck Service (Version: 4.5.1.1)
HomeTab 4.8 (Version: 4.8)
Intel(R) Rapid Storage Technology (Version: 9.5.0.1037)
Java Auto Updater (Version: 2.0.1.2)
Java(TM) 6 Update 18 (Version: 6.0.180)
Junk Mail filter update (Version: 14.0.8089.726)
Macromedia Dreamweaver 8 (Version: 8.0.0.2751)
Macromedia Extension Manager (Version: 1.7.240)
Macromedia Extension Manager (Version: 1.7.270)
MEDION Fotos auf CD & DVD SE Hofer (Version: 8.0.3.4)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.4 (Version: 2.0.3008.0)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000)
Microsoft Office Professional 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [DEU] (Version: 3.1.0000)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0)
Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Works (Version: 9.7.0621)
Mozilla Firefox 24.0 (x86 de) (Version: 24.0)
Mozilla Maintenance Service (Version: 24.0)
MSVCRT (Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
NVIDIA Display Control Panel (Version: 1.6)
NVIDIA Drivers (Version: 1.10)
NVIDIA PhysX (Version: 9.09.1112)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0)
Plus-HD-3.8 (Version: 1.27.153.11)
Realtek High Definition Audio Driver (Version: 6.0.1.5910)
Screenpresso (HKCU Version: 1.4.1.6)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal)
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
Spybot - Search & Destroy (Version: 2.1.19)
swMSM (Version: 12.0.0.1)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2827325) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition
Update für Microsoft Office Excel 2007 Help (KB963678)
Update für Microsoft Office Outlook 2007 Help (KB963677)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)
Update für Microsoft Office Word 2007 Help (KB963665)
Update Manager (Version: 4.60)
VIS
Web Optimizer
Windows Live Call (Version: 14.0.8064.0206)
Windows Live Communications Platform (Version: 14.0.8064.206)
Windows Live Essentials (Version: 14.0.8089.0726)
Windows Live Essentials (Version: 14.0.8089.726)
Windows Live Fotogalerie (Version: 14.0.8081.709)
Windows Live ID-Anmelde-Assistent (Version: 6.500.3146.0)
Windows Live Mail (Version: 14.0.8089.0726)
Windows Live Messenger (Version: 14.0.8089.0726)
Windows Live Movie Maker (Version: 14.0.8091.0730)
Windows Live Sync (Version: 14.0.8089.726)
Windows Live Writer (Version: 14.0.8089.0726)
Windows Live-Uploadtool (Version: 14.0.8014.1029)
WinZip Malware Protector (Version: 2.1.1000.10798)
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {13E5E58C-3C9D-43AD-AEA2-278B877BEAAE} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
Task: {15824438-B2F2-45CA-86D6-89EDD54831CD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-18] (Adobe Systems Incorporated)
Task: {34DF7326-6CD6-42A5-AEE4-BF3E182F8E77} - System32\Tasks\Plus-HD-3.8-chromeinstaller => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-chromeinstaller.exe [2013-10-18] (Plus HD)
Task: {37CE32FB-1340-42A1-97A3-CB574873D3BC} - System32\Tasks\Plus-HD-3.8-codedownloader => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-codedownloader.exe [2013-10-18] (Plus HD)
Task: {54CC87BF-78CA-451A-A4D7-E5BB691F01D6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {56A6164D-D19C-4F65-8868-3DAA8C507FF7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-05-25] (Google Inc.)
Task: {5C99E0A3-C5D6-445D-AD1B-BE21F53038BF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-05-25] (Google Inc.)
Task: {659CA911-9E96-4083-ACF1-E9F12F8B102A} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {815369C0-79CC-4103-8556-E93DB6BD0265} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {B6940020-EDF3-4C2A-9292-DACA8AED75EC} - System32\Tasks\Plus-HD-3.8-enabler => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-enabler.exe
Task: {B747277B-5DA8-4FDA-91BF-830642F99C5B} - System32\Tasks\Browser Updater\Browser Updater => Rundll32.exe "C:\Program Files\HomeTab\TBUpdater.dll",TBCheckForUpdate
Task: {D2B459E1-09EA-4465-83CE-6A20B5754F15} - System32\Tasks\Plus-HD-3.8-updater => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-updater.exe [2013-10-18] (Plus HD)
Task: {D5C7700F-3839-4185-9FBD-095DC85A5054} - System32\Tasks\Plus-HD-3.8-firefoxinstaller => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-firefoxinstaller.exe [2013-10-18] (Plus HD)
Task: {DAB7EC83-A7DC-41AD-9EEF-8DBB04D70DAD} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files\WinZip Malware Protector\WinZipMalwareProtector.exe [2013-07-15] (Nico Mak Computing)
Task: {F2820E51-DA7B-4F2D-A777-E148DB467B2C} - System32\Tasks\ProtectedSearch\Protected Search => C:\Program Files\HomeTab\ProtectedSearch.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-chromeinstaller.exe
Task: C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-codedownloader.exe
Task: C:\Windows\Tasks\Plus-HD-3.8-enabler.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-enabler.exe
Task: C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-firefoxinstaller.exe
Task: C:\Windows\Tasks\Plus-HD-3.8-updater.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-updater.exe
==================== Loaded Modules (whitelisted) =============
2013-11-10 16:53 - 2013-02-28 16:53 - 00886272 _____ () C:\Program Files\WinZip Malware Protector\System.Data.SQLite.dll
2013-11-10 16:53 - 2013-07-15 16:53 - 01717936 _____ () C:\Program Files\WinZip Malware Protector\aspsys.dll
2013-11-10 16:53 - 2013-02-28 16:53 - 00168448 _____ () C:\Program Files\WinZip Malware Protector\UNRAR.DLL
2013-08-07 20:25 - 2013-08-07 20:25 - 00093696 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2009-06-03 20:59 - 2009-06-03 20:59 - 00619816 ____N () C:\Program Files\CyberLink\Power2Go\CLMediaLibrary.dll
2009-06-03 20:59 - 2009-06-03 20:59 - 00013096 ____N () C:\Program Files\CyberLink\Power2Go\CLMLSvcPS.dll
2013-05-27 17:30 - 2013-05-16 09:55 - 00113496 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-05-27 17:30 - 2013-05-16 09:55 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
2013-05-27 17:30 - 2013-05-16 09:55 - 00161112 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Schmidbauer\AppData\Roaming\Dropbox\bin\libcef.dll
2011-03-16 23:11 - 2011-03-16 23:11 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf
2010-12-21 00:15 - 2010-12-21 00:15 - 01041248 _____ () C:\Program Files\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (11/11/2013 05:44:10 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/10/2013 04:18:10 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: SDTray.exe, Version: 2.1.18.127, Zeitstempel: 0x51949fd1
Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0004866a
ID des fehlerhaften Prozesses: 0xfc4
Startzeit der fehlerhaften Anwendung: 0xSDTray.exe0
Pfad der fehlerhaften Anwendung: SDTray.exe1
Pfad des fehlerhaften Moduls: SDTray.exe2
Berichtskennung: SDTray.exe3
Error: (11/10/2013 00:35:09 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/08/2013 07:18:18 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/07/2013 04:40:21 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/07/2013 10:05:45 AM) (Source: Application Hang) (User: )
Description: Programm OUTLOOK.EXE, Version 14.0.7105.5000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: a94
Startzeit: 01cedb9874ac7caf
Endzeit: 15
Anwendungspfad: C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
Berichts-ID: c0d808db-478b-11e3-a0ba-406186905b94
Error: (11/06/2013 07:37:01 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/06/2013 02:19:03 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc015000f
Fehleroffset: 0x00083fd3
ID des fehlerhaften Prozesses: 0x12fc
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3
Error: (11/06/2013 02:18:59 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7
Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1d731
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0004b1e8
ID des fehlerhaften Prozesses: 0x12fc
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3
Error: (11/06/2013 02:18:38 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc015000f
Fehleroffset: 0x00083fd3
ID des fehlerhaften Prozesses: 0x9cc
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
System errors:
=============
Error: (11/12/2013 08:16:53 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:16:53 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:16:53 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:16:53 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:16:32 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:15:59 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:15:59 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:15:59 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:15:59 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Error: (11/12/2013 08:15:17 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 35%
Total physical RAM: 3063.11 MB
Available physical RAM: 1988.26 MB
Total Pagefile: 6124.52 MB
Available Pagefile: 4271.33 MB
Total Virtual: 2047.88 MB
Available Virtual: 1895.86 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:910.41 GB) (Free:830.07 GB) NTFS
Drive d: (Recover) (Fixed) (Total:20 GB) (Free:11.58 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 499C4133)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=910 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
==================== End Of Log ============================
|