TheKidBilly | 08.12.2013 19:07 | Hallo Schrauber, vielen Dank für die prompte Hilfe und die genaue Ansage. Es hat trotzdem ein bissle gedauert, musste erst einen anderen Rechner organisieren. Ich hoffe, es ist so richtig und bin gespannt, was Du darin lesen kannst. Ich blick gar nichts.
lg Billy - hier die gewünschten log-Dateien erst first dann Addition:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-12-2013 02
Ran by Sibylle (administrator) on SIBYLLE-PC on 08-12-2013 18:51:22
Running from G:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Safe Mode (with Networking)
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2294568 2010-09-03] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12661352 2011-08-01] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2264168 2011-07-13] (Realtek Semiconductor)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1511792 2013-03-28] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe [578560 2013-07-18] (Samsung Electronics)
HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1106288 2013-03-28] (Samsung)
HKCU\...\Run: [AshSnap] - C:\Program Files (x86)\Medion MediaPack 2\Ashampoo Snap\ashsnap.exe [1721344 2011-04-14] (ashampoo GmbH & Co. KG)
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1106288 2013-03-28] (Samsung)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1098072 2013-03-27] (Garmin Ltd or its subsidiaries)
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKCU\...409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-422236853-3680715244-3807727618-1001\$3ff37d061ee5a5056ea75a5e6172b6ce\n. ATTENTION! ====> ZeroAccess?
HKLM-x32\...\Run: [HotkeyApp] - C:\Program Files (x86)\Launch Manager\HotkeyApp.exe [207400 2011-08-06] (Wistron)
HKLM-x32\...\Run: [LMgrVolOSD] - C:\Program Files (x86)\Launch Manager\OSD.exe [348960 2011-08-06] (Wistron Corp.)
HKLM-x32\...\Run: [LMgrOSD] - "C:\Program Files (x86)\Launch Manager\OSDCtrl.exe"
HKLM-x32\...\Run: [Wbutton] - C:\Program Files (x86)\Launch Manager\WButton.exe [447016 2011-08-13] (Wistron Corp.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-03] (CyberLink)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] - C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310640 2013-03-28] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-25] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-06-07] (Apple Inc.)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1707472 2013-11-06] (APN)
HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-22] ()
HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-22] ()
HKU\UpdatusUser\...\Run: [Power2GoExpress] - NA
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [226920 2011-07-25] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [193128 2011-07-25] (NVIDIA Corporation)
Startup: C:\Users\Sibylle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Sibylle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Versandhelfer.lnk
ShortcutTarget: Versandhelfer.lnk -> C:\Program Files (x86)\Versandhelfer\Versandhelfer.exe (No File)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Welcome to ALDI
URLSearchHook: HKLM-x32 - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
URLSearchHook: HKCU - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {B37A1F7F-970F-4A84-BB87-A4D07CD241FD} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848
SearchScopes: HKCU - {F1A730E2-D36C-4727-9559-B79FF089FDC0} URL = hxxp://www.search.ask.com/web?tpid=CME-V7&o=APN11289&pf=&p2=%5EB7J%5EYYYYYY%5EYY%5EDE&gct=&itbv=12.7.0.2278&apn_uid=874B38C6-2B27-4814-8558-F2C1E9C66E9D&apn_ptnrs=%5EB7J&apn_dtid=%5EYYYYYY%5EYY%5EDE&apn_dbr=iexplore.exe_6_10.0.9200.16736&doi=2013-11-16&trgb=IE&q={searchTerms}&psv=barid%253D60454864036993237682981627786531877576%2526cargo%253DCME%252DV7%2526spr%253Da%2526did%253D10714%2526ppd%253D
BHO: Ask Toolbar - {434D452D-5637-006A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport_x64.dll (APN LLC.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
BHO-x32: DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
BHO-x32: Ask Toolbar - {434D452D-5637-006A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport.dll (APN LLC.)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
Toolbar: HKLM - Ask Toolbar - {434D452D-5637-006A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - Ask Toolbar - {434D452D-5637-006A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport.dll (APN LLC.)
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - No File
Toolbar: HKCU - Ask Toolbar - {434D452D-5637-006A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport_x64.dll (APN LLC.)
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} https://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [jainjonnknhmbbkibcbmhihbopigapdm] - C:\Program Files (x86)\Lizardlink\jainjonnknhmbbkibcbmhihbopigapdm.crx
==================== Services (Whitelisted) =================
S2 AAV UpdateService; C:\Program Files (x86)\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG)
S2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-11-06] (APN LLC.)
S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [185688 2013-03-27] (Garmin Ltd or its subsidiaries)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
S2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-12-14] ()
S2 watchmi; C:\Program Files (x86)\watchmi\TvdService.exe [62464 2010-12-06] ()
S3 WisLMSvc; C:\Program Files (x86)\Launch Manager\WisLMSvc.exe [118560 2011-08-06] (Wistron Corp.)
S2 x10nets; C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10)
U2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{3ff37d06-1ee5-a505-6ea7-5a5e6172b6ce}\ \...\???\{3ff37d06-1ee5-a505-6ea7-5a5e6172b6ce}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
==================== Drivers (Whitelisted) ====================
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106904 2013-11-25] (Avira Operations GmbH & Co. KG)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-25] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2011-08-10] (ITE )
S3 mod7764; C:\Windows\System32\DRIVERS\mod77-64.sys [1077416 2010-09-16] (DiBcom SA)
R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [15896 2009-05-13] (X10 Wireless Technology, Inc.)
S3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [32792 2009-05-13] (X10 Wireless Technology, Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-08 18:51 - 2013-12-08 18:51 - 00000000 ____D C:\FRST
2013-12-08 18:49 - 2013-12-08 18:44 - 01927772 _____ (Farbar) C:\Users\Sibylle\Desktop\FRST64.exe
2013-12-08 11:32 - 2013-12-08 11:32 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{3D37D3CF-EE9C-4C9B-A7A4-BDD9236D3D9F}
2013-12-07 21:54 - 2013-12-07 21:54 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{98A67535-EE47-4DDC-8AC1-38542E1CD42D}
2013-12-07 04:05 - 2013-12-07 04:05 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{57D992AE-7EB8-41B7-9EB1-09AF90C3710B}
2013-12-06 15:57 - 2013-12-06 15:57 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{C615A725-2DAF-4686-BF05-7FBB2EAAF7EE}
2013-12-05 17:22 - 2013-12-05 17:22 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{7A82DFFE-CB89-4A13-832F-1DB3C742A0C1}
2013-12-04 18:58 - 2013-12-04 18:59 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{2D281722-5B69-4433-960A-48426FF0C557}
2013-12-03 08:20 - 2013-12-03 08:20 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{747AE50A-52FD-4835-AB58-08951D25A76D}
2013-11-30 20:59 - 2013-11-30 20:59 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{DB64F622-2501-4C3E-B665-C9A261F3861B}
2013-11-29 23:25 - 2013-11-30 09:56 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Baly
2013-11-29 23:25 - 2013-11-30 09:53 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Itakuf
2013-11-29 23:25 - 2013-11-29 23:25 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Main
2013-11-29 20:04 - 2013-11-29 20:05 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{36A46081-52E5-42B0-9E28-2F4578F84529}
2013-11-28 20:14 - 2013-11-28 22:11 - 00001585 _____ C:\Windows\comsetup.log
2013-11-28 15:51 - 2013-11-28 15:51 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{5656480D-F811-4344-9005-07C8519B9DF6}
2013-11-27 22:00 - 2013-11-30 09:56 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Ixus
2013-11-27 22:00 - 2013-11-29 23:41 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Ystis
2013-11-27 22:00 - 2013-11-27 22:00 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Diwy
2013-11-27 21:49 - 2013-11-27 21:49 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{415B3126-EE02-4979-B749-F0609AFF8DDD}
2013-11-26 21:11 - 2013-11-26 21:11 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{B328043B-0A79-4ABB-AE81-2974884C3DCE}
2013-11-25 18:38 - 2013-11-25 18:38 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{A5697B04-AA8B-4076-A134-B02D9F3DA9BF}
2013-11-24 20:02 - 2013-11-24 20:02 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{0F9DE336-8D0B-42F5-B375-82BA47E6465D}
2013-11-23 20:49 - 2013-11-23 20:49 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{44376442-D67A-4158-9174-9132B00E88C3}
2013-11-22 15:22 - 2013-11-22 15:22 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{B384BA83-1B35-4544-90E2-7FFAE6C7A257}
2013-11-21 19:51 - 2013-11-21 19:52 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{DE59F5BB-B2FC-49D2-A68F-8210B3863442}
2013-11-20 19:15 - 2013-11-20 19:15 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{0169A7EC-F780-41D7-9D57-472ECA10D0BA}
2013-11-19 22:57 - 2013-11-19 22:57 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{A7671F08-A274-4A79-89A4-52CBDECC2A97}
2013-11-18 18:24 - 2013-11-18 18:25 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{413D5641-36D5-456F-9A9D-ACD46C367E58}
2013-11-17 13:46 - 2013-11-17 13:46 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{D2ABE5A5-0FB0-43EB-B6DC-EEE50C4940BA}
2013-11-16 15:24 - 2013-11-16 15:24 - 00000000 ____D C:\Users\Sibylle\AppData\Local\AskPartnerNetwork
2013-11-16 15:23 - 2012-04-09 00:39 - 00048128 _____ C:\Windows\SysWOW64\ff_acm.acm
2013-11-16 15:20 - 2013-11-16 15:23 - 00000000 ____D C:\Program Files (x86)\ffdshow
2013-11-16 15:20 - 2013-11-16 15:20 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-11-16 15:20 - 2013-11-16 15:20 - 00000000 ____D C:\ProgramData\APN
2013-11-16 15:20 - 2013-11-16 15:20 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2013-11-16 15:20 - 2012-04-09 00:40 - 00079360 _____ C:\Windows\SysWOW64\ff_vfw.dll
2013-11-15 16:45 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-15 16:45 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-15 16:45 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-15 16:45 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-15 16:45 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-15 16:45 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-15 16:45 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-15 16:45 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-15 16:45 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-15 16:45 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-15 16:45 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-15 16:45 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-15 16:45 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-15 16:45 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-15 16:45 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-15 16:45 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-15 16:45 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-15 16:45 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-15 16:45 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-15 16:45 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-15 16:45 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-15 16:34 - 2013-11-15 16:34 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{84E83F97-649F-4BB1-BB79-0F004DE3395C}
2013-11-14 18:11 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 18:11 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-14 18:10 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-14 18:10 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-14 18:10 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-14 18:10 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-14 18:10 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-14 18:10 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-14 18:10 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-14 18:10 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 18:10 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 18:10 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 18:10 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 18:10 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 18:10 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 18:10 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 18:10 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 18:10 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-14 18:10 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-14 18:10 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-14 18:10 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-14 18:10 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 18:10 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-14 18:09 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 18:09 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 18:09 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 18:09 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-14 18:09 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-14 18:09 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 18:09 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-14 06:45 - 2013-11-14 06:45 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{703F0DD2-D583-4ACF-ACB9-2F0092A14EE2}
2013-11-13 14:45 - 2013-11-13 14:45 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{AA64027A-7D78-4BDB-83C3-98E7E86F5B18}
2013-11-13 14:33 - 2013-11-13 14:33 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{B8F73ABA-333C-4801-9834-E920957F3C24}
2013-11-11 20:03 - 2013-11-11 20:03 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{48687B54-9763-4FF3-8B6F-9F5BCD557D3B}
2013-11-10 20:06 - 2013-11-10 20:07 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{B094F5C9-6588-4C75-9B01-E3F124211854}
2013-11-09 11:51 - 2013-11-09 11:51 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{52A5E51A-D9CB-4FEB-AE9A-DC9808A8B172}
2013-11-08 21:18 - 2013-11-08 21:18 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{FADE328A-C594-4035-9E77-324CC19C7D02}
==================== One Month Modified Files and Folders =======
2013-12-08 18:51 - 2013-12-08 18:51 - 00000000 ____D C:\FRST
2013-12-08 18:48 - 2011-08-10 00:07 - 00654602 _____ C:\Windows\system32\perfh007.dat
2013-12-08 18:48 - 2011-08-10 00:07 - 00130216 _____ C:\Windows\system32\perfc007.dat
2013-12-08 18:48 - 2009-07-14 06:13 - 01500104 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-08 18:44 - 2013-12-08 18:49 - 01927772 _____ (Farbar) C:\Users\Sibylle\Desktop\FRST64.exe
2013-12-08 15:59 - 2012-07-09 21:32 - 00000000 ____D C:\Program Files (x86)\PDF24
2013-12-08 15:59 - 2011-12-05 18:22 - 00000000 ____D C:\Users\Sibylle
2013-12-08 15:58 - 2012-12-14 17:14 - 00000000 ____D C:\Windows\system32\Macromed
2013-12-08 15:58 - 2012-01-01 15:21 - 00000000 ____D C:\Windows\SysWOW64\Adobe
2013-12-08 15:58 - 2011-08-10 20:00 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-12-08 15:57 - 2013-03-01 16:33 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-08 15:57 - 2011-08-10 20:14 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-08 15:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-08 15:54 - 2011-12-06 20:41 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Skype
2013-12-08 15:53 - 2011-12-06 20:41 - 00000000 ____D C:\ProgramData\Skype
2013-12-08 11:32 - 2013-12-08 11:32 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{3D37D3CF-EE9C-4C9B-A7A4-BDD9236D3D9F}
2013-12-07 23:29 - 2011-12-16 11:23 - 00000000 ____D C:\Users\Sibylle\Documents\privat
2013-12-07 21:54 - 2013-12-07 21:54 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{98A67535-EE47-4DDC-8AC1-38542E1CD42D}
2013-12-07 09:16 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-07 09:16 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-07 04:05 - 2013-12-07 04:05 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{57D992AE-7EB8-41B7-9EB1-09AF90C3710B}
2013-12-06 15:57 - 2013-12-06 15:57 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{C615A725-2DAF-4686-BF05-7FBB2EAAF7EE}
2013-12-05 17:22 - 2013-12-05 17:22 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{7A82DFFE-CB89-4A13-832F-1DB3C742A0C1}
2013-12-04 23:48 - 2011-12-06 16:15 - 00000000 ____D C:\Users\Sibylle\Documents\Lyrics of Favourite Songs
2013-12-04 18:59 - 2013-12-04 18:58 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{2D281722-5B69-4433-960A-48426FF0C557}
2013-12-03 08:20 - 2013-12-03 08:20 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{747AE50A-52FD-4835-AB58-08951D25A76D}
2013-12-01 23:53 - 2013-10-29 00:29 - 00000000 ____D C:\Users\Sibylle\Documents\Weihnachten 2013
2013-12-01 22:55 - 2011-12-06 20:45 - 00000000 ____D C:\Users\Sibylle\Documents\Youcam
2013-12-01 20:16 - 2011-12-05 18:14 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-01 15:18 - 2011-12-05 18:14 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-30 22:05 - 2009-07-14 05:51 - 00112784 _____ C:\Windows\setupact.log
2013-11-30 20:59 - 2013-11-30 20:59 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{DB64F622-2501-4C3E-B665-C9A261F3861B}
2013-11-30 20:20 - 2011-12-06 03:09 - 01113955 _____ C:\Windows\WindowsUpdate.log
2013-11-30 20:14 - 2010-11-21 04:47 - 00236780 _____ C:\Windows\PFRO.log
2013-11-30 20:14 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-30 09:56 - 2013-11-29 23:25 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Baly
2013-11-30 09:56 - 2013-11-27 22:00 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Ixus
2013-11-30 09:53 - 2013-11-29 23:25 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Itakuf
2013-11-29 23:41 - 2013-11-27 22:00 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Ystis
2013-11-29 23:33 - 2011-12-05 18:14 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-29 23:32 - 2011-12-05 19:17 - 00000000 ____D C:\Users\Sibylle\AppData\Local\Google
2013-11-29 23:25 - 2013-11-29 23:25 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Main
2013-11-29 20:05 - 2013-11-29 20:04 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{36A46081-52E5-42B0-9E28-2F4578F84529}
2013-11-29 17:34 - 2011-12-05 21:54 - 00000000 ____D C:\Users\Sibylle\AppData\Local\Ashampoo Photo Optimizer Medion
2013-11-28 23:23 - 2011-12-05 22:41 - 00000000 ___DC C:\Users\Sibylle\AppData\Local\MigWiz
2013-11-28 22:11 - 2013-11-28 20:14 - 00001585 _____ C:\Windows\comsetup.log
2013-11-28 15:51 - 2013-11-28 15:51 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{5656480D-F811-4344-9005-07C8519B9DF6}
2013-11-27 22:00 - 2013-11-27 22:00 - 00000000 ____D C:\Users\Sibylle\AppData\Roaming\Diwy
2013-11-27 21:49 - 2013-11-27 21:49 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{415B3126-EE02-4979-B749-F0609AFF8DDD}
2013-11-26 21:11 - 2013-11-26 21:11 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{B328043B-0A79-4ABB-AE81-2974884C3DCE}
2013-11-25 18:38 - 2013-11-25 18:38 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{A5697B04-AA8B-4076-A134-B02D9F3DA9BF}
2013-11-25 18:34 - 2013-04-02 22:17 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-25 18:34 - 2013-04-02 22:17 - 00106904 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-11-24 20:02 - 2013-11-24 20:02 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{0F9DE336-8D0B-42F5-B375-82BA47E6465D}
2013-11-23 20:49 - 2013-11-23 20:49 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{44376442-D67A-4158-9174-9132B00E88C3}
2013-11-23 17:31 - 2013-07-27 15:44 - 00000000 ____D C:\Users\Sibylle\Documents\Dublin 2013
2013-11-22 22:41 - 2011-12-06 16:40 - 00000000 ____D C:\Users\Sibylle\Documents\Angel
2013-11-22 15:22 - 2013-11-22 15:22 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{B384BA83-1B35-4544-90E2-7FFAE6C7A257}
2013-11-21 19:52 - 2013-11-21 19:51 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{DE59F5BB-B2FC-49D2-A68F-8210B3863442}
2013-11-20 19:15 - 2013-11-20 19:15 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{0169A7EC-F780-41D7-9D57-472ECA10D0BA}
2013-11-19 22:57 - 2013-11-19 22:57 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{A7671F08-A274-4A79-89A4-52CBDECC2A97}
2013-11-18 18:25 - 2013-11-18 18:24 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{413D5641-36D5-456F-9A9D-ACD46C367E58}
2013-11-17 14:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-11-17 13:46 - 2013-11-17 13:46 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{D2ABE5A5-0FB0-43EB-B6DC-EEE50C4940BA}
2013-11-16 15:24 - 2013-11-16 15:24 - 00000000 ____D C:\Users\Sibylle\AppData\Local\AskPartnerNetwork
2013-11-16 15:23 - 2013-11-16 15:20 - 00000000 ____D C:\Program Files (x86)\ffdshow
2013-11-16 15:20 - 2013-11-16 15:20 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-11-16 15:20 - 2013-11-16 15:20 - 00000000 ____D C:\ProgramData\APN
2013-11-16 15:20 - 2013-11-16 15:20 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2013-11-15 16:47 - 2012-01-04 14:34 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-15 16:42 - 2013-08-13 16:16 - 00000000 ____D C:\Windows\system32\MRT
2013-11-15 16:37 - 2011-08-10 16:28 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-15 16:34 - 2013-11-15 16:34 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{84E83F97-649F-4BB1-BB79-0F004DE3395C}
2013-11-14 06:45 - 2013-11-14 06:45 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{703F0DD2-D583-4ACF-ACB9-2F0092A14EE2}
2013-11-13 14:45 - 2013-11-13 14:45 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{AA64027A-7D78-4BDB-83C3-98E7E86F5B18}
2013-11-13 14:33 - 2013-11-13 14:33 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{B8F73ABA-333C-4801-9834-E920957F3C24}
2013-11-11 20:03 - 2013-11-11 20:03 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{48687B54-9763-4FF3-8B6F-9F5BCD557D3B}
2013-11-11 00:31 - 2011-12-06 16:15 - 00000000 ____D C:\Users\Sibylle\Documents\Gina
2013-11-10 20:07 - 2013-11-10 20:06 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{B094F5C9-6588-4C75-9B01-E3F124211854}
2013-11-09 11:51 - 2013-11-09 11:51 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{52A5E51A-D9CB-4FEB-AE9A-DC9808A8B172}
2013-11-08 21:18 - 2013-11-08 21:18 - 00000000 ____D C:\Users\Sibylle\AppData\Local\{FADE328A-C594-4035-9E77-324CC19C7D02}
ZeroAccess:
C:\Users\Sibylle\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files (x86)\Google\Desktop\Install
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-422236853-3680715244-3807727618-1001\$3ff37d061ee5a5056ea75a5e6172b6ce
Files to move or delete:
====================
C:\ProgramData\4560508.pad
C:\ProgramData\87_fg.pad
C:\ProgramData\ism_0_llatsni.pad
C:\ProgramData\jNCB1FMc.dat
C:\ProgramData\otebof.bat
C:\ProgramData\otebof.reg
Some content of TEMP:
====================
C:\Users\Sibylle\AppData\Local\Temp\2SKKKKKKK.exe
C:\Users\Sibylle\AppData\Local\Temp\AskSLib.dll
C:\Users\Sibylle\AppData\Local\Temp\avgnt.exe
C:\Users\Sibylle\AppData\Local\Temp\COMAP.EXE
C:\Users\Sibylle\AppData\Local\Temp\DivXInstaller.exe
C:\Users\Sibylle\AppData\Local\Temp\InstallFlashPlayer.exe
C:\Users\Sibylle\AppData\Local\Temp\mtuul1ku.dll
C:\Users\Sibylle\AppData\Local\Temp\pdf24-creator-update.exe
C:\Users\Sibylle\AppData\Local\Temp\q4cs1kwf.dll
C:\Users\Sibylle\AppData\Local\Temp\Setup.exe
C:\Users\Sibylle\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Sibylle\AppData\Local\Temp\totalmediaextreme_1.0.22.1_2.0.36.1_update_all.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
LastRegBack: 2013-04-05 22:52
==================== End Of Log ============================ --- --- ---
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-12-2013 02
Ran by Sibylle at 2013-12-08 18:52:11
Running from G:\
Boot Mode: Safe Mode (with Networking)
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
AAVUpdateManager (x32 Version: 18.00.0000)
Adobe Flash Player 10 Plugin (x32 Version: 10.3.183.5)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Reader X (10.1.8) MUI (x32 Version: 10.1.8)
Adobe Shockwave Player 11.6 (x32 Version: 11.6.5.635)
ALDI Bestellsoftware 4.11.0 (x32 Version: 4.11.0)
ALDI SÜD Mah Jong (x32)
Amazon Kindle (HKCU)
AMI VR-pulse OS Switcher (Version: 1.2)
Apple Application Support (x32 Version: 2.1.9)
Apple Mobile Device Support (Version: 5.2.0.6)
Apple Software Update (x32 Version: 2.1.3.127)
ArcSoft TotalMedia Extreme (x32 Version: 2.0.36.1)
Ashampoo Burning Studio (x32 Version: 10.0.10)
Ashampoo Photo Commander (x32 Version: 9.2.0)
Ashampoo Photo Optimizer (x32 Version: 4.0.0)
Ashampoo Snap (x32 Version: 4.3.0)
Ask Toolbar (x32 Version: 12.7.0.2278)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.0.39)
Avira Free Antivirus (x32 Version: 14.0.1.749)
Bonjour (Version: 3.0.0.10)
Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2)
Corel Graphics - Windows Shell Extension (x32 Version: 15.2.0.686)
Corel Graphics - Windows Shell Extension (x32 Version: 15.2.686)
Corel Graphics - Windows Shell Extension 64 Bit (Version: 15.2.686)
CorelDRAW Essentials X5 - Common (x32 Version: 15.3)
CorelDRAW Essentials X5 - Connect (x32 Version: 15.3)
CorelDRAW Essentials X5 - Custom Data (x32 Version: 15.3)
CorelDRAW Essentials X5 - DE (x32 Version: 15.3)
CorelDRAW Essentials X5 - Draw (x32 Version: 15.3)
CorelDRAW Essentials X5 - EN (x32 Version: 15.3)
CorelDRAW Essentials X5 - ES (x32 Version: 15.3)
CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0)
CorelDRAW Essentials X5 - Extra Content (x32)
CorelDRAW Essentials X5 - Filters (x32 Version: 15.3)
CorelDRAW Essentials X5 - FR (x32 Version: 15.3)
CorelDRAW Essentials X5 - IPM (x32 Version: 15.3)
CorelDRAW Essentials X5 - IT (x32 Version: 15.3)
CorelDRAW Essentials X5 - PHOTO-PAINT (x32 Version: 15.3)
CorelDRAW Essentials X5 - Redist (x32 Version: 15.0)
CorelDRAW Essentials X5 - Setup Files (x32 Version: 15.3)
CorelDRAW Essentials X5 - WT (x32 Version: 15.3)
CorelDRAW Essentials X5 (x32 Version: 15.2.0.686)
CorelDRAW Essentials X5 (x32 Version: 15.3)
CyberLink LabelPrint (x32 Version: 2.5.3624)
CyberLink MediaEspresso (x32 Version: 6.5.1508_36229)
CyberLink MediaShow (x32 Version: 5.1.2414)
CyberLink PhotoNow (x32 Version: 1.1.0.6904)
CyberLink Power2Go (x32 Version: 7.0.0.1327)
CyberLink PowerDirector (x32 Version: 8.0.4020)
CyberLink PowerDVD 10 (x32 Version: 10.0.2930.52)
CyberLink PowerDVD Copy (x32 Version: 1.5.1306)
CyberLink PowerProducer (x32 Version: 5.0.2.3503)
CyberLink YouCam (x32 Version: 3.1.4013)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
Dolby Advanced Audio v2 (x32 Version: 7.2.7000.4)
DVDVideoSoftTB DE Toolbar (x32 Version: 6.9.0.16)
Elevated Installer (x32 Version: 2.1.13)
ElsterFormular (x32 Version: 13.3.0.9066)
ffdshow v1.2.4422 [2012-04-09] (x32 Version: 1.2.4422.0)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (x32 Version: 15.4.5722.2)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922)
Free YouTube Download version 3.2.12.827 (x32 Version: 3.2.12.827)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922)
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922)
Garmin Express (x32 Version: 2.1.13)
Garmin Express Tray (x32 Version: 2.1.13)
Garmin Update Service (x32 Version: 2.1.13)
Google Chrome (x32 Version: 12.0.742.91)
Google Update Helper (x32 Version: 1.3.21.165)
Intel PROSet Wireless
Intel PROSet Wireless (x32)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2462)
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (Version: 1.1.0.0157)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 1.1.0.0537)
Intel(R) PROSet/Wireless WiFi Software (Version: 14.01.1000)
Intel(R) Rapid Storage Technology (x32 Version: 10.6.0.1002)
Intel(R) WiDi (x32 Version: 2.1.41.0)
Intel(R) Wireless Display
IT9130 Driver v11.4.26.1 (x32)
iTunes (Version: 10.6.3.25)
Java Auto Updater (x32 Version: 2.0.5.1)
Java(TM) 6 Update 26 (64-bit) (Version: 6.0.260)
Java(TM) 6 Update 26 (x32 Version: 6.0.260)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (x32 Version: 15.4.5722.2)
Launch Manager (x32 Version: 1.5.1.4)
Lizardlink 1.0.0 (Version: 1.0.0)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Medion Home Cinema (x32 Version: 8.0.2608)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Mathematics (64-Bit) (Version: 4.0)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Home and Student 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft PowerPoint Viewer (x32 Version: 14.0.7015.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MyFreeCodec (HKCU)
NVIDIA 3D Vision Driver 269.24 (Version: 269.24)
NVIDIA Control Panel 269.24 (Version: 269.24)
NVIDIA Graphics Driver 269.24 (Version: 269.24)
NVIDIA Install Application (Version: 2.265.42.0)
NVIDIA Optimus 1.0.23 (Version: 1.0.23)
NVIDIA PhysX (x32 Version: 9.10.0513)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6924)
NVIDIA Update Components (Version: 1.0.23)
PDF24 Creator 5.2.0 (x32)
PlayReady PC Runtime amd64 (Version: 1.3.0)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922)
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922)
Pošta Windows Live (x32 Version: 15.4.3502.0922)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6428)
Realtek USB 2.0 Reader Driver (x32 Version: 6.1.7600.10010)
Samsung Kies (x32 Version: 2.3.2.12074_13)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.22.0)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32)
Skype™ 6.6 (x32 Version: 6.6.106)
Spelling Dictionaries Support For Adobe Reader X (x32 Version: 10.0.0)
Steuer-Sparer 2011 (x32 Version: 16.16)
Steuer-Sparer 2012 (x32 Version: 17.13)
swMSM (x32 Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 15.1.12.0)
TI USB 3.0 Host Controller Driver (x32 Version: 1.12.14.0)
TI USB3 Host Driver (x32 Version: 1.12.14.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32)
Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32)
VR-pulse Installer (Version: 1.4.0)
watchmi (x32 Version: 2.5.0)
Windows Live (x32 Version: 15.4.3502.0922)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live Fotótár (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
X10 Hardware(TM) (x32)
==================== Restore Points =========================
20-10-2013 19:27:56 Windows-Sicherung
22-10-2013 01:00:38 Windows Update
27-10-2013 18:00:45 Windows-Sicherung
10-11-2013 19:03:13 Windows-Sicherung
15-11-2013 15:32:33 Windows Update
17-11-2013 22:46:38 Windows-Sicherung
24-11-2013 18:00:40 Windows-Sicherung
28-11-2013 15:30:30 Windows-Sicherung
01-12-2013 19:16:56 Windows-Sicherung
07-12-2013 23:22:03 Removed Adobe Reader X (10.1.8) MUI.
==================== Hosts content: ==========================
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {022C9C61-4E91-4E56-9C40-1B6F54C5BAA8} - System32\Tasks\{AFFB8AB8-ED6C-470D-8AE8-7F9E3F6821DA} => C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [2011-04-15] (CyberLink Corp.)
Task: {98682812-182A-4B7F-A71A-98022B28E00D} - System32\Tasks\RunAsStdUser Task for VeohWebPlayer => C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
Task: {A5E42EAA-B83D-4EA4-9295-98F313899269} - System32\Tasks\{4C777C3B-5972-40AF-8D6C-34DF798E1955} => C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE [2013-07-23] (Microsoft Corporation)
Task: {B5EBA8D5-ECDE-4EE4-8388-D4AA0F901E54} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-05] (Google Inc.)
Task: {B6D99E2F-9D9F-4969-9B47-65031077E91C} - System32\Tasks\irMonitor => C:\Windows\System32 [2013-12-08] ()
Task: {C2980517-2080-4608-8A53-812F865138DD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-05] (Google Inc.)
Task: {E32EAA39-9FDD-412D-A6A4-77B768C51472} - System32\Tasks\{2657A17D-248B-468B-83B0-8FFA45B0895F} => C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE [2013-07-23] (Microsoft Corporation)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
==================== Faulty Device Manager Devices =============
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/08/2013 04:28:51 PM) (Source: SignInAssistant) (User: )
Description: StartService failed with hr = 0x8007043c
Error: (12/08/2013 02:17:26 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9984
Error: (12/08/2013 02:17:26 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9984
Error: (12/08/2013 00:01:05 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (12/08/2013 09:19:14 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9922
Error: (12/08/2013 09:19:14 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9922
Error: (12/08/2013 09:19:14 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (12/08/2013 09:19:13 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8814
Error: (12/08/2013 09:19:13 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8814
Error: (12/08/2013 09:19:13 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (12/08/2013 04:00:22 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (12/08/2013 04:00:22 PM) (Source: DCOM) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}
Error: (12/08/2013 04:00:20 PM) (Source: DCOM) (User: )
Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error: (12/08/2013 04:00:07 PM) (Source: DCOM) (User: )
Description: 1084EventSystem{1BE1F766-5536-11D1-B726-00C04FB926AF}
Error: (12/08/2013 04:00:01 PM) (Source: DCOM) (User: )
Description: 1084ShellHWDetection{DD522ACC-F821-461A-A407-50B198B896DC}
Error: (12/08/2013 03:59:48 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\System32\IWMSSvc.dll
Fehlercode: 21
Error: (12/08/2013 03:59:44 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
avipbb
avkmgr
discache
spldr
Wanarpv6
Error: (12/08/2013 03:59:28 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Client Virtualization Handler" ist vom Dienst "Application Virtualization Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (12/08/2013 03:59:28 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "IKE- und AuthIP IPsec-Schlüsselerstellungsmodule" ist von folgendem Dienst abhängig: BFE. Dieser Dienst ist eventuell nicht installiert.
Error: (12/08/2013 03:59:28 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Microsoft Office Sessions:
=========================
Error: (12/08/2013 04:28:51 PM) (Source: SignInAssistant)(User: )
Description: StartService failed with hr = 0x8007043c
Error: (12/08/2013 02:17:26 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9984
Error: (12/08/2013 02:17:26 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9984
Error: (12/08/2013 00:01:05 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (12/08/2013 09:19:14 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9922
Error: (12/08/2013 09:19:14 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9922
Error: (12/08/2013 09:19:14 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (12/08/2013 09:19:13 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8814
Error: (12/08/2013 09:19:13 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8814
Error: (12/08/2013 09:19:13 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
CodeIntegrity Errors:
===================================
Date: 2013-03-05 14:44:33.858
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-03-05 14:44:33.805
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-03-05 14:44:31.252
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-03-05 14:44:31.196
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-03-05 14:44:29.123
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-03-05 14:44:29.056
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-03-05 14:44:26.935
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-03-05 14:44:26.872
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-03-05 14:44:24.766
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-03-05 14:44:24.719
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 22%
Total physical RAM: 4001.87 MB
Available physical RAM: 3109.68 MB
Total Pagefile: 8001.92 MB
Available Pagefile: 7147.66 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:647.54 GB) (Free:535.27 GB) NTFS
Drive d: (Recover) (Fixed) (Total:48 GB) (Free:0 GB) NTFS
Drive g: () (Removable) (Total:0.94 GB) (Free:0.2 GB) FAT
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 699 GB) (Disk ID: 97BE5B6A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=648 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=50 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
========================================================
Disk: 1 (Size: 961 MB) (Disk ID: 6F20736B)
No partition Table on disk 1.
Disk 1 is a removable device.
==================== End Of Log ============================ --- --- --- |