Goldengirl | 16.11.2013 13:03 | okay. hier sind die beiden dateien.
FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-11-2013
Ran by Michaela (administrator) on MICHAELA-PC on 16-11-2013 12:57:32
Running from C:\Users\Michaela\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\Users\Michaela\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Akamai Technologies, Inc.) C:\Users\Michaela\AppData\Local\Akamai\netsession_win.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Akamai Technologies, Inc.) C:\Users\Michaela\AppData\Local\Akamai\netsession_win.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Opera Software) C:\Program Files\Opera\17.0.1241.53_0\opera.exe
() C:\Program Files\Opera\17.0.1241.53_0\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera\17.0.1241.53_0\opera.exe
(Opera Software) C:\Program Files\Opera\17.0.1241.53_0\opera.exe
(Opera Software) C:\Program Files\Opera\17.0.1241.53_0\opera.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6111232 2008-04-17] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-10-26] (Synaptics, Inc.)
HKLM\...\Run: [Ocs_SM] - C:\Users\Michaela\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [106496 2012-06-06] (OCS)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-05] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Michaela\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
MountPoints2: {8a09b030-f4b6-11df-8406-806e6f6e6963} - D:\AutoRun.exe
MountPoints2: {a5e9558f-1f72-11e0-b7e4-806e6f6e6963} - D:\AUTORUN.EXE
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
AppInit_DLLs: [ ] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=6050a44f-03a3-4e73-84ea-085c14bdb3ce&searchtype=ds&q={searchTerms}&installDate=24/02/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=6050a44f-03a3-4e73-84ea-085c14bdb3ce&searchtype=ds&q={searchTerms}&installDate=24/02/2013
SearchScopes: HKLM - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=6050a44f-03a3-4e73-84ea-085c14bdb3ce&searchtype=ds&q={searchTerms}&installDate=24/02/2013
SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=6050a44f-03a3-4e73-84ea-085c14bdb3ce&searchtype=ds&q={searchTerms}&installDate=24/02/2013
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=6050a44f-03a3-4e73-84ea-085c14bdb3ce&searchtype=ds&q={searchTerms}&installDate=24/02/2013
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=6050a44f-03a3-4e73-84ea-085c14bdb3ce&searchtype=ds&q={searchTerms}&installDate=24/02/2013
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E6C6976652E636F6D2F726573756C74732E617370783F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826466F726D3D494538535243&st={searchTerms}&clid=b01dd3b0-bce2-4ba8-acd4-dbf98c89f673&pid=murb&k=0
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Plus-HD-2.6 - {11111111-1111-1111-1111-110311341140} - C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-bho.dll (Plus HD)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: WebEnhance - {814664b0-d93b-4da6-9216-722c56179397} - C:\Program Files\WebEnhance\webenhance.dll (WebEnhance)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKCU - No Name - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No File
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\brpuueol.default
FF user.js: detected! => C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\brpuueol.default\user.js
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Plus-HD-2.6 - C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\brpuueol.default\Extensions\7f404ccc-b0a9-4faf-b3c0-89ceea949aea@a6724a05-9380-4ebe-be02-e67e35a3402c.com
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [webbooster@iminent.com] - C:\Program Files\Iminent\webbooster@iminent.com
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKLM\...\Firefox\Extensions: [{38e9e285-5266-4fe2-b5b5-c14c29b0cd45}] - C:\Program Files\WebEnhance\webenhance.xpi
FF HKCU\...\Firefox\Extensions: [firejump@firejump.net] - C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\ujvxghf0.default\extensions\firejump@firejump.net
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [mbegnhpbhfjiaelealfpieodkembdgbj] - C:\Program Files\WebEnhance\webenhance.crx
========================== Services (Whitelisted) =================
R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-02] (Akamai Technologies, Inc.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 SearchAnonymizer; C:\Users\Michaela\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2012-06-06] ()
S2 SystemStoreService; C:\Program Files\SoftwareUpdater\SystemStore.exe [296448 2013-10-19] ()
S3 UPnPService; C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-08-05] (Avira Operations GmbH & Co. KG)
S3 RTL2832UBDA; C:\Windows\System32\drivers\RTL2832UBDA.sys [189184 2011-07-25] (REALTEK SEMICONDUCTOR Corp.)
S3 RTL2832UUSB; C:\Windows\System32\Drivers\RTL2832UUSB.sys [33536 2011-07-25] (REALTEK SEMICONDUCTOR Corp.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH)
R3 VMC302; C:\Windows\System32\Drivers\VMC302.sys [242560 2008-04-05] (Vimicro Corporation)
S3 X86BDA; C:\Windows\System32\DRIVERS\OEMDrv.sys [195712 2011-06-08] ( )
S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [x]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 XDva379; \??\C:\Windows\system32\XDva379.sys [x]
S3 XDva383; \??\C:\Windows\system32\XDva383.sys [x]
S3 XDva385; \??\C:\Windows\system32\XDva385.sys [x]
S3 XDva386; \??\C:\Windows\system32\XDva386.sys [x]
S3 XDva387; \??\C:\Windows\system32\XDva387.sys [x]
S3 XDva391; \??\C:\Windows\system32\XDva391.sys [x]
S3 XDva394; \??\C:\Windows\system32\XDva394.sys [x]
S3 XDva396; \??\C:\Windows\system32\XDva396.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-16 12:57 - 2013-11-16 12:57 - 01090529 _____ (Farbar) C:\Users\Michaela\Desktop\FRST.exe
2013-11-16 12:57 - 2013-11-16 12:57 - 00013501 _____ C:\Users\Michaela\Desktop\FRST.txt
2013-11-16 12:57 - 2013-11-16 12:57 - 00000104 _____ C:\Users\Michaela\Desktop\Internet - Verknüpfung.lnk
2013-11-16 12:51 - 2013-11-16 12:51 - 00000348 _____ C:\Windows\PFRO.log
2013-11-16 08:47 - 2013-11-16 08:49 - 00026887 _____ C:\Users\Michaela\Downloads\Addition.txt
2013-11-16 08:44 - 2013-11-16 08:49 - 00028517 _____ C:\Users\Michaela\Downloads\FRST.txt
2013-11-16 08:43 - 2013-11-16 08:43 - 00000000 ____D C:\FRST
2013-11-14 20:00 - 2013-11-14 20:00 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Opera Software
2013-11-14 20:00 - 2013-11-14 20:00 - 00000000 ____D C:\Users\Michaela\AppData\Local\Opera Software
2013-11-14 19:59 - 2013-11-16 12:45 - 00000000 ____D C:\Program Files\Opera
2013-11-10 17:11 - 2013-11-10 17:11 - 00550354 _____ C:\Users\Michaela\Downloads\Clay Thomsen.sim
2013-11-05 21:54 - 2013-11-05 21:54 - 00000000 ____D C:\Program Files\CDBurnerXP
2013-11-01 22:27 - 2013-11-01 22:27 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Grandy Games
2013-11-01 22:26 - 2013-11-01 22:26 - 00000000 ____D C:\Program Files\Unterwegs in Düsterburg v1.21
2013-10-27 14:44 - 2013-10-27 14:44 - 00000000 ____D C:\Program Files\Electronic Arts
2013-10-20 12:49 - 2013-10-20 12:49 - 102034533 _____ C:\Windows\system32\皱ಋᴼ
2013-10-19 16:48 - 2013-10-19 16:48 - 00000000 ____D C:\Users\Michaela\AppData\Local\Freemium
2013-10-19 16:45 - 2013-11-16 10:59 - 00000000 ____D C:\ProgramData\FreeSystemUtilities
2013-10-19 16:45 - 2013-11-16 10:59 - 00000000 ____D C:\Program Files\SoftwareUpdater
2013-10-19 16:45 - 2013-10-19 16:45 - 00000000 ____D C:\Program Files\Covus Freemium
2013-10-19 16:44 - 2013-11-16 10:59 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-19 16:44 - 2013-11-16 10:59 - 00000000 ____D C:\Program Files\WebEnhance
2013-10-19 16:39 - 2013-11-16 10:59 - 00000000 ____D C:\Users\Michaela\AppData\Local\DownloadGuide
2013-10-19 16:39 - 2013-10-19 16:39 - 00444408 _____ C:\Users\Michaela\Downloads\free-system-utilities-DE(1).exe
2013-10-18 12:37 - 2013-11-16 10:59 - 00000000 ____D C:\ProgramData\Apple Computer
2013-10-18 12:35 - 2013-11-16 10:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-10-18 12:34 - 2013-11-16 10:59 - 00000000 ____D C:\ProgramData\Apple
2013-10-18 12:34 - 2013-11-16 10:59 - 00000000 ____D C:\Program Files\Apple Software Update
2013-10-18 12:33 - 2013-10-18 12:33 - 41404760 _____ (Apple Inc.) C:\Users\Michaela\Downloads\QuickTimeInstaller(1).exe
2013-10-18 12:26 - 2013-10-18 12:26 - 07912440 _____ (Adobe Systems Inc.) C:\Users\Michaela\Downloads\Shockwave_Installer_Slim(1).exe
2013-10-18 12:05 - 2013-10-18 12:05 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\PPNetDE
2013-10-18 12:05 - 2013-10-18 12:05 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\cef-cache
2013-10-18 12:03 - 2013-10-18 12:07 - 00000000 ____D C:\Program Files\PartyGaming.Net
2013-10-18 12:02 - 2013-10-18 12:02 - 00851888 _____ C:\Users\Michaela\Downloads\PartyPokerNetDESetup.exe
==================== One Month Modified Files and Folders =======
2013-11-16 12:58 - 2013-11-16 12:57 - 00013501 _____ C:\Users\Michaela\Desktop\FRST.txt
2013-11-16 12:58 - 2008-01-21 08:16 - 01560840 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-16 12:57 - 2013-11-16 12:57 - 01090529 _____ (Farbar) C:\Users\Michaela\Desktop\FRST.exe
2013-11-16 12:57 - 2013-11-16 12:57 - 00000104 _____ C:\Users\Michaela\Desktop\Internet - Verknüpfung.lnk
2013-11-16 12:52 - 2010-12-24 17:55 - 00000000 ____D C:\Program Files\Common Files\Akamai
2013-11-16 12:52 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-16 12:52 - 2006-11-02 13:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-16 12:51 - 2013-11-16 12:51 - 00000348 _____ C:\Windows\PFRO.log
2013-11-16 12:51 - 2013-09-30 17:28 - 00001284 _____ C:\Windows\Tasks\Plus-HD-2.6-updater.job
2013-11-16 12:51 - 2013-09-30 17:28 - 00001188 _____ C:\Windows\Tasks\Plus-HD-2.6-codedownloader.job
2013-11-16 12:51 - 2013-09-30 17:28 - 00001088 _____ C:\Windows\Tasks\Plus-HD-2.6-enabler.job
2013-11-16 12:51 - 2013-09-30 17:27 - 00001808 _____ C:\Windows\Tasks\Plus-HD-2.6-firefoxinstaller.job
2013-11-16 12:51 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-16 12:50 - 2013-04-01 10:27 - 02049472 _____ C:\Windows\WindowsUpdate.log
2013-11-16 12:50 - 2006-11-02 14:01 - 00032560 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-16 12:47 - 2013-03-23 17:22 - 00000000 ____D C:\Users\Michaela\AppData\Local\CrashDumps
2013-11-16 12:45 - 2013-11-14 19:59 - 00000000 ____D C:\Program Files\Opera
2013-11-16 12:33 - 2012-04-10 20:30 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-16 11:00 - 2006-11-02 11:22 - 44040192 _____ C:\Windows\system32\config\software_previous
2013-11-16 11:00 - 2006-11-02 11:22 - 39321600 _____ C:\Windows\system32\config\components_previous
2013-11-16 11:00 - 2006-11-02 11:22 - 28049408 _____ C:\Windows\system32\config\system_previous
2013-11-16 11:00 - 2006-11-02 11:22 - 00524288 _____ C:\Windows\system32\config\default_previous
2013-11-16 11:00 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2013-11-16 11:00 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2013-11-16 10:59 - 2013-10-19 16:45 - 00000000 ____D C:\ProgramData\FreeSystemUtilities
2013-11-16 10:59 - 2013-10-19 16:45 - 00000000 ____D C:\Program Files\SoftwareUpdater
2013-11-16 10:59 - 2013-10-19 16:44 - 00000000 ____D C:\ProgramData\Package Cache
2013-11-16 10:59 - 2013-10-19 16:44 - 00000000 ____D C:\Program Files\WebEnhance
2013-11-16 10:59 - 2013-10-19 16:39 - 00000000 ____D C:\Users\Michaela\AppData\Local\DownloadGuide
2013-11-16 10:59 - 2013-10-18 12:37 - 00000000 ____D C:\ProgramData\Apple Computer
2013-11-16 10:59 - 2013-10-18 12:35 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-11-16 10:59 - 2013-10-18 12:34 - 00000000 ____D C:\ProgramData\Apple
2013-11-16 10:59 - 2013-10-18 12:34 - 00000000 ____D C:\Program Files\Apple Software Update
2013-11-16 10:59 - 2013-10-01 20:02 - 00000000 ____D C:\Program Files\MPC-HC
2013-11-16 10:59 - 2013-10-01 18:06 - 00000000 ____D C:\Program Files\MSI Afterburner
2013-11-16 10:59 - 2013-10-01 17:34 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Ulead Systems
2013-11-16 10:59 - 2013-09-20 08:24 - 00000000 ____D C:\Users\Michaela\Downloads\abrViewer.NET
2013-11-16 10:59 - 2013-09-20 08:14 - 00000000 ____D C:\Users\Michaela\Downloads\Smoke_Brush_Promo_abr
2013-11-16 10:59 - 2013-09-20 08:14 - 00000000 ____D C:\Users\Michaela\Downloads\__MACOSX
2013-11-16 10:59 - 2013-09-01 08:00 - 00000000 ____D C:\Users\Michaela\AppData\Local\gtk-2.0
2013-11-16 10:59 - 2013-05-18 07:50 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2013-11-16 10:59 - 2013-04-18 06:10 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
2013-11-16 10:59 - 2013-03-23 16:18 - 00000000 ____D C:\Program Files\Common Files\TechSmith Shared
2013-11-16 10:59 - 2013-03-23 16:17 - 00000000 ____D C:\ProgramData\TechSmith
2013-11-16 10:59 - 2013-03-23 16:17 - 00000000 ____D C:\Program Files\TechSmith
2013-11-16 10:59 - 2013-03-18 06:45 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\FreeScreenToVideo
2013-11-16 10:59 - 2013-03-18 06:34 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Audacity
2013-11-16 10:59 - 2013-03-15 16:33 - 00000000 ____D C:\Program Files\Audacity
2013-11-16 10:59 - 2013-03-01 17:54 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-11-16 10:59 - 2013-03-01 17:35 - 00000000 ____D C:\Users\Michaela\Documents\ProcessExplorer
2013-11-16 10:59 - 2013-02-20 06:58 - 00000000 ____D C:\Users\Michaela\AppData\Local\WeGame
2013-11-16 10:59 - 2012-11-19 20:24 - 00000000 ____D C:\Program Files\QuickTime
2013-11-16 10:59 - 2012-06-19 20:58 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\ICQ Search
2013-11-16 10:59 - 2011-11-17 13:25 - 00000000 ____D C:\Program Files\Xvid
2013-11-16 10:59 - 2011-11-10 07:15 - 00000000 ____D C:\Users\Michaela\AppData\Local\Akamai
2013-11-16 10:59 - 2011-10-12 20:12 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\DesktopIconForAmazon
2013-11-16 10:59 - 2011-08-14 12:58 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-16 10:59 - 2011-01-14 01:08 - 00000000 ____D C:\Windows\VMC302
2013-11-16 10:59 - 2011-01-04 13:01 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\DVDVideoSoft
2013-11-16 10:59 - 2010-12-31 14:51 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\gtk-2.0
2013-11-16 10:59 - 2010-12-06 22:25 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Skype
2013-11-16 10:59 - 2010-12-06 20:29 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\vlc
2013-11-16 10:59 - 2010-12-05 20:45 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
2013-11-16 10:59 - 2010-12-05 20:44 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Winamp
2013-11-16 10:59 - 2010-11-20 20:47 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Thunderbird
2013-11-16 10:59 - 2010-11-20 17:25 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-11-16 10:59 - 2010-11-20 16:06 - 00000000 ___RD C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-16 10:59 - 2010-11-20 16:06 - 00000000 ___RD C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-16 10:59 - 2006-11-02 13:37 - 00000000 ____D C:\Windows\twain_32
2013-11-16 10:59 - 2006-11-02 12:18 - 00000000 __RSD C:\Windows\Media
2013-11-16 10:59 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\spool
2013-11-16 10:59 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-16 10:59 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\registration
2013-11-16 10:01 - 2010-11-20 16:06 - 00000000 ____D C:\Users\Michaela
2013-11-16 10:01 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\Msdtc
2013-11-16 08:49 - 2013-11-16 08:47 - 00026887 _____ C:\Users\Michaela\Downloads\Addition.txt
2013-11-16 08:49 - 2013-11-16 08:44 - 00028517 _____ C:\Users\Michaela\Downloads\FRST.txt
2013-11-16 08:43 - 2013-11-16 08:43 - 00000000 ____D C:\FRST
2013-11-14 20:24 - 2013-09-19 22:20 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 20:00 - 2013-11-14 20:00 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Opera Software
2013-11-14 20:00 - 2013-11-14 20:00 - 00000000 ____D C:\Users\Michaela\AppData\Local\Opera Software
2013-11-10 17:11 - 2013-11-10 17:11 - 00550354 _____ C:\Users\Michaela\Downloads\Clay Thomsen.sim
2013-11-05 21:54 - 2013-11-05 21:54 - 00000000 ____D C:\Program Files\CDBurnerXP
2013-11-01 22:27 - 2013-11-01 22:27 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Grandy Games
2013-11-01 22:26 - 2013-11-01 22:26 - 00000000 ____D C:\Program Files\Unterwegs in Düsterburg v1.21
2013-10-27 14:44 - 2013-10-27 14:44 - 00000000 ____D C:\Program Files\Electronic Arts
2013-10-25 17:02 - 2013-03-05 19:21 - 00000000 ____D C:\Users\Michaela\AppData\Local\gctmp
2013-10-25 17:02 - 2011-11-15 13:32 - 00000000 ____D C:\Users\Michaela\AppData\Local\Ashampoo Movie Shrink & Burn 3
2013-10-25 17:02 - 2011-04-02 09:44 - 00000000 ____D C:\Users\Michaela\AppData\Local\{5E55945C-5DC5-4496-B44A-4036C9A1C7E8}
2013-10-25 17:02 - 2011-01-11 18:04 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\Plane9
2013-10-25 17:02 - 2010-11-20 15:57 - 00000000 ____D C:\Windows\Panther
2013-10-20 12:49 - 2013-10-20 12:49 - 102034533 _____ C:\Windows\system32\皱ಋᴼ
2013-10-19 16:48 - 2013-10-19 16:48 - 00000000 ____D C:\Users\Michaela\AppData\Local\Freemium
2013-10-19 16:45 - 2013-10-19 16:45 - 00000000 ____D C:\Program Files\Covus Freemium
2013-10-19 16:39 - 2013-10-19 16:39 - 00444408 _____ C:\Users\Michaela\Downloads\free-system-utilities-DE(1).exe
2013-10-19 15:30 - 2011-02-26 17:45 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\FileZilla
2013-10-19 15:29 - 2011-05-07 19:34 - 00000000 ____D C:\Windows\Minidump
2013-10-18 12:33 - 2013-10-18 12:33 - 41404760 _____ (Apple Inc.) C:\Users\Michaela\Downloads\QuickTimeInstaller(1).exe
2013-10-18 12:26 - 2013-10-18 12:26 - 07912440 _____ (Adobe Systems Inc.) C:\Users\Michaela\Downloads\Shockwave_Installer_Slim(1).exe
2013-10-18 12:26 - 2010-12-29 22:14 - 00000000 ____D C:\Windows\system32\Adobe
2013-10-18 12:07 - 2013-10-18 12:03 - 00000000 ____D C:\Program Files\PartyGaming.Net
2013-10-18 12:05 - 2013-10-18 12:05 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\PPNetDE
2013-10-18 12:05 - 2013-10-18 12:05 - 00000000 ____D C:\Users\Michaela\AppData\Roaming\cef-cache
2013-10-18 12:02 - 2013-10-18 12:02 - 00851888 _____ C:\Users\Michaela\Downloads\PartyPokerNetDESetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-16 12:57
==================== End Of Log ============================ --- --- ---
addition Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 14-11-2013
Ran by Michaela at 2013-11-16 12:59:46
Running from C:\Users\Michaela\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
VIDEO DVR (Version: 2012.04.17)
32 Bit HP CIO Components Installer (Version: 6.1.1)
Access 97rt PAN EURO G
Adobe AIR (Version: 2.7.1.19610)
Adobe Community Help (Version: 3.4.980)
Adobe Download Assistant (Version: 1.0.3)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Reader X (10.1.4) - Deutsch (Version: 10.1.4)
Adobe Shockwave Player 12.0 (Version: 12.0.4.144)
Akamai NetSession Interface
Apple Application Support (Version: 2.3.4)
Apple Software Update (Version: 2.1.3.127)
Atheros WLAN Client (Version: 1.00.000)
Audacity 2.0.3 (Version: 2.0.3)
Avira Free Antivirus (Version: 13.0.0.4052)
BufferChm (Version: 130.0.331.000)
Camtasia Studio 8 (Version: 8.0.4.1060)
CCleaner (Version: 3.09)
Copy (Version: 130.0.366.000)
D3DX10 (Version: 15.4.2368.0902)
Destinations (Version: 130.0.0.0)
DeviceDiscovery (Version: 130.0.372.000)
DJ_AIO_06_F4500_SW_MIN (Version: 130.0.406.000)
ElsterFormular (Version: 14.0.0.10960)
F4500 (Version: 130.0.406.000)
FileZilla Client 3.2.7.1 (HKCU Version: 3.2.7.1)
FireJump (Version: 1.0.2.5)
Free System Utilities (Version: 1.1.3.0)
Free SystemUtilities (Version: 1.1.3.0)
Game Booster 3 (Version: 3.4)
Google Update Helper (Version: 1.3.23.0)
GPBaseService2 (Version: 130.0.371.000)
HP Customer Participation Program 13.0 (Version: 13.0)
HP Deskjet F4500 Printer Driver Software 13.0 Rel .6 (Version: 13.0)
HP Imaging Device Functions 13.0 (Version: 13.0)
HP Print Projects 1.0 (Version: 1.0)
HP Smart Web Printing 4.5 (Version: 4.5)
HP Solution Center 13.0 (Version: 13.0)
HP Update (Version: 5.002.007.004)
HPPhotoGadget (Version: 130.0.282.000)
hpPrintProjects (Version: 130.0.303.000)
HPProductAssistant (Version: 130.0.371.000)
HPSSupply (Version: 130.0.371.000)
hpWLPGInstaller (Version: 130.0.303.000)
Intel® Matrix Storage Manager
MarketResearch (Version: 130.0.374.000)
Mesh Runtime (Version: 15.4.5722.2)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office Click-to-Run 2010 (Version: 14.0.6122.5000)
Microsoft Office Starter 2010 - English (Version: 14.0.6137.5001)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft SQL Server Compact 3.5 SP2 ENU (Version: 3.5.8080.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0)
Microsoft_VC80_ATL_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053)
Microsoft_VC90_ATL_x86 (Version: 1.00.0000)
Microsoft_VC90_CRT_x86 (Version: 1.00.0000)
Microsoft_VC90_MFC_x86 (Version: 1.00.0000)
Microsoft_VC90_MFCLOC_x86 (Version: 1.00.0000)
Mozilla Firefox 24.0 (x86 de) (Version: 24.0)
Mozilla Maintenance Service (Version: 24.0)
MPC-HC 1.7.0 (Version: 1.7.0.7858)
MSVCRT (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Network (Version: 130.0.572.000)
NVIDIA Grafiktreiber 260.99 (Version: 260.99)
NVIDIA HD-Audiotreiber 1.1.9.0 (Version: 1.1.9.0)
NVIDIA Install Application (Version: 2.0.12.0)
NVIDIA PhysX (Version: 9.10.0514)
NVIDIA PhysX-Systemsoftware 260.99 (Version: 260.99)
NVIDIA Systemsteuerung 260.99 (Version: 260.99)
Opera Stable 17.0.1241.53 (Version: 17.0.1241.53)
Origin (Version: 9.3.10.4710)
Paint.NET v3.5.11 (Version: 3.61.0)
partypoker.net
Plus-HD-2.6 (Version: 1.28.153.1)
QuickTime (Version: 7.74.80.86)
Realtek High Definition Audio Driver (Version: 6.0.1.5605)
Scan (Version: 13.0.0.0)
SearchAnonymizer (Version: 1.0.1 (de))
Segoe UI (Version: 15.4.2271.0615)
Shop for HP Supplies (Version: 13.0)
Skype™ 6.2 (Version: 6.2.106)
SmartSound Common Data (Version: 1.1.0)
SmartSound Quicktracks 5 (Version: 5.1.6)
SmartSound Quicktracks Plugin (Version: 3.0.2.7)
SmartWebPrinting (Version: 130.0.373.000)
SolutionCenter (Version: 130.0.373.000)
Status (Version: 130.0.373.000)
swMSM (Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 10.1.2.0)
Toolbox (Version: 130.0.648.000)
TrayApp (Version: 130.0.376.000)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (Version: 3)
USB2.0 Capture Device (Version: 1.0.3.0)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
Vimicro UVC Camera (Version: 1.00.0000)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
VLC media player 1.1.5 (Version: 1.1.5)
WebEnhance
WebReg (Version: 130.0.132.017)
Winamp (Version: 5.601 )
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalerie (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series (Version: 9.00.3374)
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
WinRAR 4.20 (32-Bit) (Version: 4.20.0)
Xvid Video Codec (Version: 1.3.2)
==================== Restore Points =========================
25-10-2013 15:51:24 Removed Avira SearchFree Toolbar plus Web Protection
25-10-2013 15:57:18 Windows Update
27-10-2013 13:44:31 Installiert The Sims 3
27-10-2013 14:49:24 Installiert The Sims 3
29-10-2013 18:13:43 Windows Update
31-10-2013 17:53:42 Geplanter Prüfpunkt
01-11-2013 19:43:53 Geplanter Prüfpunkt
03-11-2013 12:23:03 Geplanter Prüfpunkt
05-11-2013 16:39:14 Windows Update
08-11-2013 22:25:32 Windows Update
10-11-2013 16:04:49 Geplanter Prüfpunkt
14-11-2013 05:06:59 Windows Update
14-11-2013 18:53:36 Removed Avira SearchFree Toolbar
14-11-2013 18:54:51 Free System Utilities
14-11-2013 19:21:22 Windows Update
15-11-2013 05:40:12 Camtasia Studio 8 wird entfernt
15-11-2013 05:41:04 Removed Apple Application Support
15-11-2013 05:43:01 Removed Apple Software Update
16-11-2013 07:29:53 Removed QuickTime
16-11-2013 07:31:23 Removed QuickTime
16-11-2013 08:06:52 Removed Avira SearchFree Toolbar
16-11-2013 08:36:09 Camtasia Studio 8 wird entfernt
16-11-2013 09:48:33 Wiederherstellungsvorgang
16-11-2013 10:14:35 Windows Update
16-11-2013 11:49:06 Removed Avira SearchFree Toolbar plus Web Protection
==================== Hosts content: ==========================
2006-11-02 11:23 - 2011-04-06 22:32 - 00000937 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 im.adtech.de
127.0.0.1 adserver.adtech.de
127.0.0.1 adtech.de
127.0.0.1 atwola.com
127.0.0.1 adserver.71i.de
127.0.0.1 adicqserver.71i.de
127.0.0.1 71i.de
==================== Scheduled Tasks (whitelisted) =============
Task: {1587E0F8-599A-41B6-9906-A164FE12C0F4} - System32\Tasks\Plus-HD-2.6-enabler => C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-enabler.exe [2013-09-30] (Plus HD)
Task: {174FFD01-C128-46A3-818E-B926F3EDF2FE} - System32\Tasks\Plus-HD-2.6-updater => C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-updater.exe [2013-09-30] (Plus HD)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2B0B8DAE-A8A0-44F7-B828-EF0247899FEB} - System32\Tasks\Software Updater => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe [2013-11-16] ()
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {3D5AD314-1395-4C6A-B37B-35D7D4935F69} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {4A29D740-92D0-4BF3-BC17-6C0532BD5698} - System32\Tasks\Plus-HD-2.6-codedownloader => C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-codedownloader.exe [2013-09-30] (Plus HD)
Task: {53B46C38-3CCE-44A8-BD45-5C36B467A6B5} - System32\Tasks\{7C93DEC2-834A-4C75-BF0F-8ABFC322CEA2} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.158/de/abandoninstall?page=tsProgressBar
Task: {5510B863-341F-43BD-A9AB-DDD12B03625D} - System32\Tasks\{445A468A-08F1-4A28-A047-1FD496AACFDB} => Firefox.exe hxxp://ui.skype.com/ui/0/5.5.0.124/en/abandoninstall?page=tsPlugin&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {55C5064A-FB3E-470E-8314-55F1941F54F4} - System32\Tasks\RunAsStdUser Task => C:\Users\Michaela\AppData\Local\ClickPotatoLiteSA\bin\12.0.15.0\ClickPotatoLiteSA.exe
Task: {583AF29E-5E49-4C79-A9CE-EBEAC7D8F73C} - System32\Tasks\Software Updater Ui => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe [2013-11-16] ()
Task: {83DB806C-6999-4703-98E5-C79882CC95B8} - System32\Tasks\Plus-HD-2.6-firefoxinstaller => C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-firefoxinstaller.exe [2013-09-30] (Plus HD)
Task: {8CCAC036-51B1-45B3-AC1D-6012D46EA300} - System32\Tasks\Freemium1ClickMaint => C:\Users\Michaela\Downloads\1Click.exe
Task: {A0C36932-18D8-4B41-A1D9-961D9C6D7A04} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03] (Adobe Systems Incorporated)
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\System32\pla.dll [2008-01-21] (Microsoft Corporation)
Task: {AEB55FE6-7AED-4CAC-AC7B-0250835617CC} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files\IObit\Game Booster 3\Autoupdate.exe [2013-06-20] ()
Task: {D32383F9-F6C1-45E5-A608-4DB6E80A25C4} - System32\Tasks\{422021F5-DBEA-4CAC-958E-04E939902A4A} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.156/en/abandoninstall?page=tsMain
Task: {D96DBE66-FA28-4CFE-8FC6-C3B057D86738} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Michaela => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {DCE197FE-E5F5-49D4-B5D2-1B37CC1C1D28} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe
Task: {DE20207D-568C-48C5-AA2C-78075D276BDC} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\hpwuschd2.exe [2011-01-12] (Hewlett-Packard)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {F6785A24-D2D1-43DB-A512-DA45163794C5} - System32\Tasks\{90447DA7-7261-44E7-A284-97D8E15853BD} => C:\Program Files\Skype\\Phone\Skype.exe [2013-02-07] (Skype Technologies S.A.)
Task: {FFD8ABA8-D97B-4629-8A20-1EC63E318BA3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-15] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Plus-HD-2.6-codedownloader.job => C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-codedownloader.exe
Task: C:\Windows\Tasks\Plus-HD-2.6-enabler.job => C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-enabler.exe
Task: C:\Windows\Tasks\Plus-HD-2.6-firefoxinstaller.job => C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-firefoxinstaller.exe
Task: C:\Windows\Tasks\Plus-HD-2.6-updater.job => C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-updater.exe
==================== Loaded Modules (whitelisted) =============
2013-08-13 16:07 - 2013-08-05 21:49 - 00394824 _____ () C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
2010-11-21 15:54 - 2009-08-23 18:58 - 00094208 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2013-11-16 12:45 - 2013-10-21 07:41 - 00868704 _____ () C:\Program Files\Opera\17.0.1241.53_0\ffmpegsumo.dll
2013-11-16 12:45 - 2013-10-21 07:41 - 00881504 _____ () C:\Program Files\Opera\17.0.1241.53_0\libglesv2.dll
2013-11-16 12:45 - 2013-10-21 07:41 - 00109408 _____ () C:\Program Files\Opera\17.0.1241.53_0\libegl.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:260575F1
AlternateDataStreams: C:\ProgramData\TEMP:BF640EE5
AlternateDataStreams: C:\ProgramData\TEMP:C22674B6
AlternateDataStreams: C:\ProgramData\TEMP:E9FAC3AB
AlternateDataStreams: C:\ProgramData\TEMP:FC70A22A
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: Marvell Yukon 88E8055 PCI-E Gigabit Ethernet Controller
Description: Marvell Yukon 88E8055 PCI-E Gigabit Ethernet Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Marvell
Service: yukonwlh
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Deskjet F4500 series
Description: Deskjet F4500 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/16/2013 00:52:50 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/16/2013 00:47:06 PM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung avnotify.exe, Version 13.6.20.2100, Zeitstempel 0x51e6b921, fehlerhaftes Modul avnotify.exe, Version 13.6.20.2100, Zeitstempel 0x51e6b921, Ausnahmecode 0xc0000005, Fehleroffset 0x00001487,
Prozess-ID 0x1280, Anwendungsstartzeit avnotify.exe0.
Error: (11/16/2013 00:46:57 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
Error: (11/16/2013 00:46:15 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
Error: (11/16/2013 11:02:48 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/16/2013 11:02:44 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: -528
Error: (11/16/2013 11:02:44 AM) (Source: ESENT) (User: )
Description: Catalog Database (1704) Catalog Database: Fehler -1811 beim Öffnen von Protokolldatei C:\Windows\system32\CatRoot2\edb001C9.log.
Error: (11/16/2013 10:01:51 AM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
Error: (11/16/2013 09:25:42 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/16/2013 09:23:50 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (11/16/2013 00:52:51 PM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058
Error: (11/16/2013 00:43:05 PM) (Source: DCOM) (User: Michaela-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Michaela-PCMichaelaS-1-5-21-3086956417-774972897-2570352139-1000LocalHost (unter Verwendung von LRPC)
Error: (11/16/2013 11:09:17 AM) (Source: WinDefend) (User: )
Description: Beim Laden der Signaturen wurde von %%%82627 ein Fehler festgestellt. Es wird versucht, einen als gültig bekannten Signatursatz wiederherzustellen.
Versuchte Signaturen: %%%82625
Fehlercode: 0x8050a004
Fehlerbeschreibung: Das Programm kann keine Definitionsdateien finden, die dazu dienen, unerwünschte Software zu erkennen. Überprüfen Sie, ob aktualisierte Definitionsdateien vorhanden sind, und versuchen Sie es dann erneut. Weitere Informationen zum Installieren von Updates finden Sie unter "Hilfe und Support".
Ladende Signaturen: %%826
Ladene Signaturversion: 1.0.0.0
Ladende Modulversion: %%%826270
Error: (11/16/2013 11:08:38 AM) (Source: WinDefend) (User: )
Description: Beim Laden der Signaturen wurde von %%%82527 ein Fehler festgestellt. Es wird versucht, einen als gültig bekannten Signatursatz wiederherzustellen.
Versuchte Signaturen: %%%82524
Fehlercode: 0x8050a001
Fehlerbeschreibung: Das Programm kann keine Definitionsdateien finden, die dazu dienen, unerwünschte Software zu erkennen. Überprüfen Sie, ob aktualisierte Definitionsdateien vorhanden sind, und versuchen Sie es dann erneut. Weitere Informationen zum Installieren von Updates finden Sie unter "Hilfe und Support".
Ladende Signaturen: %%825
Ladene Signaturversion: 1.161.1906.0
Ladende Modulversion: %%%825270
Error: (11/16/2013 11:08:17 AM) (Source: Service Control Manager) (User: )
Description: Windows Update
Error: (11/16/2013 11:02:49 AM) (Source: Service Control Manager) (User: )
Description: Avira Browser-Schutz1 (0x1)
Error: (11/16/2013 11:02:49 AM) (Source: Service Control Manager) (User: )
Description: SearchAnonymizer%%1053
Error: (11/16/2013 11:02:49 AM) (Source: Service Control Manager) (User: )
Description: 30000SearchAnonymizer
Error: (11/16/2013 11:02:49 AM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058
Error: (11/16/2013 09:25:42 AM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058
Microsoft Office Sessions:
=========================
Error: (11/16/2013 00:52:50 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/16/2013 00:47:06 PM) (Source: Application Error)(User: )
Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500001487128001cee2c19347b230
Error: (11/16/2013 00:46:57 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x0
Error: (11/16/2013 00:46:15 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x0
Error: (11/16/2013 11:02:48 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/16/2013 11:02:44 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: -528
Error: (11/16/2013 11:02:44 AM) (Source: ESENT)(User: )
Description: Catalog Database1704Catalog Database: C:\Windows\system32\CatRoot2\edb001C9.log-1811
Error: (11/16/2013 10:01:51 AM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x0
Error: (11/16/2013 09:25:42 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/16/2013 09:23:50 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity Errors:
===================================
Date: 2011-03-26 11:35:59.875
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2011-03-26 11:35:59.682
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2011-03-26 11:35:59.421
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2011-03-26 11:35:59.171
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2010-12-08 22:02:49.735
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2010-12-08 22:02:49.635
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2010-12-08 22:02:49.557
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2010-12-08 22:02:49.505
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2010-12-08 22:02:49.442
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 40%
Total physical RAM: 3065.88 MB
Available physical RAM: 1822.04 MB
Total Pagefile: 6364.14 MB
Available Pagefile: 4865.34 MB
Total Virtual: 2047.88 MB
Available Virtual: 1896.21 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:288.09 GB) (Free:200.96 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: B6394A61)
Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
Partition 2: (Active) - (Size=288 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |