MacGyver76 | 29.10.2013 20:25 | hoffe jetzt passt es... Andreas Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-10-2013
Ran by Andreas at 2013-10-29 20:12:27
Running from C:\Users\Andreas\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: AntiVir Desktop (Enabled - Out of date) {090F9C29-64CE-6C6F-379C-5901B49A85B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AntiVir Desktop (Enabled - Out of date) {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
==================== Installed Programs ======================
Update for Microsoft Office 2007 (KB2508958) (x32)
Acrobat.com (x32 Version: 1.6.65)
ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.2)
Adobe AIR (x32 Version: 2.6.0.19140)
Adobe Community Help (x32 Version: 3.4.980)
Adobe Download Assistant (x32 Version: 1.0.6)
Adobe Flash Player 10 ActiveX (x32 Version: 10.1.102.64)
Adobe Flash Player 11 Plugin (x32 Version: 11.6.602.180)
Adobe Photoshop 7.0 (x32 Version: 7.0)
Adobe Reader 9.4.5 MUI (x32 Version: 9.4.5)
Adobe Shockwave Player (x32 Version: 11.5.1.601)
Adobe Story (x32 Version: 1.0.571)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.82)
AMD USB Filter Driver (x32 Version: 1.0.15.94)
Analogy Screen Saver (x32)
Apple Application Support (x32 Version: 2.1.5)
Apple Software Update (x32 Version: 2.1.3.127)
Ask Toolbar (x32 Version: 1.15.1.0)
Atheros Driver Installation Program (x32 Version: 5.0)
ATI Catalyst Install Manager (Version: 3.0.765.0)
Avira Free Antivirus (x32 Version: 13.0.0.4052)
Avira SearchFree Toolbar plus Web Protection Updater (HKCU Version: 1.2.1.22229)
BearShare (x32 Version: 9.0.0.94309)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.82)
Belkin Home Base Control Center (Version: 1.0.0)
Blasterball 3 (x32 Version: 2.2.0.82)
Bus Driver (x32 Version: 2.2.0.82)
Canon MP550 series Benutzerregistrierung (x32)
Canon MP550 series MP Drivers
Canon Utilities My Printer (x32)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Core Implementation (x32 Version: 2010.0416.541.8279)
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0416.541.8279)
Catalyst Control Center Graphics Full New (x32 Version: 2010.0416.541.8279)
Catalyst Control Center Graphics Light (x32 Version: 2010.0416.541.8279)
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0416.541.8279)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0416.541.8279)
Catalyst Control Center InstallProxy (x32 Version: 2010.0416.541.8279)
Catalyst Control Center Localization All (x32 Version: 2010.0416.541.8279)
CCC Help Chinese Standard (x32 Version: 2010.0416.0540.8279)
CCC Help Chinese Traditional (x32 Version: 2010.0416.0540.8279)
CCC Help Czech (x32 Version: 2010.0416.0540.8279)
CCC Help Danish (x32 Version: 2010.0416.0540.8279)
CCC Help Dutch (x32 Version: 2010.0416.0540.8279)
CCC Help English (x32 Version: 2010.0416.0540.8279)
CCC Help Finnish (x32 Version: 2010.0416.0540.8279)
CCC Help French (x32 Version: 2010.0416.0540.8279)
CCC Help German (x32 Version: 2010.0416.0540.8279)
CCC Help Greek (x32 Version: 2010.0416.0540.8279)
CCC Help Hungarian (x32 Version: 2010.0416.0540.8279)
CCC Help Italian (x32 Version: 2010.0416.0540.8279)
CCC Help Japanese (x32 Version: 2010.0416.0540.8279)
CCC Help Korean (x32 Version: 2010.0416.0540.8279)
CCC Help Norwegian (x32 Version: 2010.0416.0540.8279)
CCC Help Polish (x32 Version: 2010.0416.0540.8279)
CCC Help Portuguese (x32 Version: 2010.0416.0540.8279)
CCC Help Russian (x32 Version: 2010.0416.0540.8279)
CCC Help Spanish (x32 Version: 2010.0416.0540.8279)
CCC Help Swedish (x32 Version: 2010.0416.0540.8279)
CCC Help Thai (x32 Version: 2010.0416.0540.8279)
CCC Help Turkish (x32 Version: 2010.0416.0540.8279)
ccc-core-static (x32 Version: 2010.0416.541.8279)
ccc-utility64 (Version: 2010.0416.541.8279)
CDBurnerXP (x32 Version: 4.4.0.3018)
Chuzzle Deluxe (x32 Version: 2.2.0.82)
Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000)
CVE-2012-4969
CyberLink DVD Suite (x32 Version: 7.0.2527)
Designer 2.0 (x32 Version: 7.8.3)
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.82)
DivX-Setup (x32 Version: 2.6.1.3)
Dream Chronicles (x32 Version: 2.2.0.82)
DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.0.3715)
ESU for Microsoft Windows 7 (x32 Version: 1.0.0)
FATE (x32 Version: 2.2.0.82)
Fences (Version: 1.0)
Fences (x32)
Fliqlo Screen Saver (x32)
Free FLV Converter V 7.4.0 (x32 Version: 7.4.0.0)
FreeFileSync v4.2 (x32 Version: 4.2)
Gem Shop (x32 Version: 2.2.0.82)
HP 3D DriveGuard (Version: 4.0.3.1)
HP Customer Experience Enhancements (x32 Version: 6.0.1.4)
HP DVB-T TV Tuner 8.0.64.43 (x32 Version: 8.0.64.43)
HP Game Console (x32)
HP Games (x32 Version: 1.0.0.80)
HP MediaSmart Internet TV (x32 Version: 3.2.2513)
HP MediaSmart Music (x32 Version: 4.0.3903)
HP MediaSmart Photo (x32 Version: 4.0.3911)
HP MediaSmart SmartMenu (Version: 3.1.1.12)
HP MediaSmart Video (x32 Version: 4.0.3911)
HP MediaSmart Webcam (x32 Version: 4.0.2511)
HP Power Plan Utility (x32 Version: 1.0.6)
HP Quick Launch (Version: 1.0.18)
HP QuickWeb Installer (x32 Version: 1.2.12.0)
HP Setup (x32 Version: 1.2.3988.3281)
HP SimplePass Identity Protection (Version: 5.00.140)
HP Software Framework (x32 Version: 4.0.112.1)
HP Support Assistant (x32 Version: 4.3.1.2)
HP Tone Control (Version: 2.0.2)
HP Update (x32 Version: 5.001.000.014)
HP User Guides 0193 (x32 Version: 1.01.0001)
HP Wireless Assistant (Version: 4.0.4.2)
HPAsset component for HP Active Support Library (x32 Version: 3.0.2.2)
IDT Audio (x32 Version: 1.0.6269.0)
Insaniquarium Deluxe (x32 Version: 2.2.0.82)
IrfanView (remove only) (x32 Version: 4.28)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Java(TM) 6 Update 17 (64-bit) (Version: 6.0.170)
Jewel Quest II (x32 Version: 2.2.0.82)
Jewel Quest Solitaire (x32 Version: 2.2.0.82)
Junk Mail filter update (x32 Version: 14.0.8117.416)
LabelPrint (x32 Version: 2.5.2515)
lameGen 1.1.3 (x32)
LightScribe System Software (x32 Version: 1.18.11.1)
Magic Desktop (x32)
Mahjongg Artifacts (x32 Version: 2.2.0.82)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Choice Guard (x32 Version: 2.0.48.0)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053)
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000)
Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.0.3715)
Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
MSVCRT (x32 Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MyPhoneExplorer (x32 Version: 1.8.4)
Mystery P.I. - The Vegas Heist (x32 Version: 2.2.0.82)
NewFreeScreensaver nfsClock17 (x32)
NewFreeScreensaver nfsGermanyFlagClock (x32)
NewFreeScreensaver nfsRadar (x32)
Orbit Downloader (x32)
Penguins! (x32 Version: 2.2.0.82)
PhotoNow! (x32 Version: 1.1.6904)
Pinnacle Video Treiber (Version: 12.1.0.030)
PokerStars.net (x32)
Polar Bowler (x32 Version: 2.2.0.82)
Power2Go (x32 Version: 6.1.3715)
PowerDirector (x32 Version: 8.0.2514)
QuickTime (x32 Version: 7.71.80.42)
Realtek Ethernet Controller Driver For Windows 7 (x32 Version: 7.11.1127.2009)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30113)
Recovery Manager (x32 Version: 5.5.2512)
Slingo Deluxe (x32 Version: 2.2.0.82)
Sony USB Driver (x32)
Synaptics Pointing Device Driver (Version: 15.1.6.64)
TMPGEnc DVD Author 1.6 (x32 Version: 1.6.34)
TMPGEnc Plus 2.5 (x32 Version: 2.524.63.181)
TV Jukebox 3.1 (x32 Version: 3.10.000)
UltraVnc (Version: 1.1.8)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Validity Sensors DDK (Version: 4.1.129.0)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Virtual Villagers - The Secret City (x32 Version: 2.2.0.82)
VLC media player 1.1.5 (x32 Version: 1.1.5)
WEB.DE MailCheck für Mozilla Firefox (x32 Version: 2.1.4.1300)
WEB.DE Softwareaktualisierung (x32 Version: 3.0.0.55)
WEB.DE Toolbar für Internet Explorer (x32 Version: 1.7.0.0)
WEB.DE Toolbar MSVC100 CRT x64 (Version: 1.0.0)
WEB.DE Toolbar MSVC100 CRT x86 (x32 Version: 1.0.0)
Wedding Dash (x32 Version: 2.2.0.82)
Winamp (x32 Version: 5.601 )
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1)
Windows Live Call (x32 Version: 14.0.8117.0416)
Windows Live Communications Platform (x32 Version: 14.0.8117.416)
Windows Live Essentials (x32 Version: 14.0.8117.0416)
Windows Live Essentials (x32 Version: 14.0.8117.416)
Windows Live Fotogalerie (x32 Version: 14.0.8117.416)
Windows Live ID Sign-in Assistant (Version: 6.500.3165.0)
Windows Live Mail (x32 Version: 14.0.8117.0416)
Windows Live Messenger (x32 Version: 14.0.8117.0416)
Windows Live Sync (x32 Version: 14.0.8117.416)
Windows Live Writer (x32 Version: 14.0.8117.0416)
Windows Live-Uploadtool (x32 Version: 14.0.8014.1029)
Windows Searchqu Toolbar (x32 Version: 4.1.0.3114)
WinZip (x32)
WISO Steuer-Sparbuch 2011 (x32 Version: 18.00.6928)
Zuma Deluxe (x32 Version: 2.2.0.82)
==================== Restore Points =========================
==================== Hosts content: ==========================
2013-10-27 19:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {004F5DD8-7251-4F62-843D-7E38C2511EBD} - System32\Tasks\HPCeeScheduleForAndreas => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard)
Task: {007477E2-80F0-418D-85E7-EB6108430E48} - System32\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A} => C:\Users\Andreas\AppData\Local\Temp\Bx2.exe
Task: {2CA870FD-6386-493C-A052-4315497F5EAD} - System32\Tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C} => C:\Windows\Bbuxea.exe
Task: {33EA4202-D9F4-4695-B4B0-619BD92D7792} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {3F08B708-020A-4A1B-9BA1-00F013F27D59} - System32\Tasks\Hewlett-Packard\HP Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2009-11-10] (Hewlett-Packard)
Task: {70D3CB70-190B-44F4-805C-EC2C4B676B66} - System32\Tasks\Registration 1und1 Task => C:\Program Files (x86)\1und1Softwareaktualisierung\cdsupdclient.exe [2013-06-18] (1&1 Mail & Media GmbH)
Task: {8591EB05-7F2A-400E-9089-A01795E66141} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-01-26] ()
Task: {B9688D77-CD14-4FC6-B35F-6DF716DDC31A} - System32\Tasks\Owpmzevaq => Rundll32.exe "C:\Windows\SysWOW64\azroles4.dll",wavg
Task: {CAC8FA6C-87AA-4BBC-A4F6-35B7C14E535E} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-01-26] ()
Task: {CBC66806-541C-4C36-A7F3-BE8939FDDA74} - System32\Tasks\CLMLSvc => c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Music\Kernel\CLML\CLMLSvc.exe
Task: {CCE93F33-FAB6-4ABF-8D65-67CBEC97265B} - System32\Tasks\AdobeAAMUpdater-1.0-Andreas-PC-Andreas => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-03-15] (Adobe Systems Incorporated)
Task: {CF15F4E1-DAB3-4F83-803B-5BA6B1C943F6} - System32\Tasks\Hewlett-Packard\HP Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2009-11-10] (Hewlett-Packard)
Task: {FC35F48C-81EF-4770-BB71-27ED2207C7D1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe [2013-10-29] ()
Task: C:\Windows\Tasks\HPCeeScheduleForAndreas.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\Windows\Tasks\Owpmzevaq.job => ?
Task: C:\Windows\Tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job => C:\Windows\Bbuxea.exe
Task: C:\Windows\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job => C:\Users\Andreas\AppData\Local\Temp\Bx2.exe
==================== Loaded Modules (whitelisted) =============
2011-07-30 10:23 - 2009-06-22 06:46 - 00136704 ____N () C:\Program Files\Belkin\Home Base Control Center\OSAL.dll
2011-07-30 10:23 - 2009-06-22 06:46 - 00100352 ____N () C:\Program Files\Belkin\Home Base Control Center\BkLocalBackup.dll
2010-03-09 13:34 - 2010-03-09 13:34 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2010-05-17 00:44 - 2010-05-17 00:44 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2010-01-27 13:01 - 2010-01-27 13:01 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll
2010-01-27 13:01 - 2010-01-27 13:01 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll
2010-01-27 13:01 - 2010-01-27 13:01 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll
2013-10-02 18:32 - 2013-10-02 18:30 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2010-01-22 09:29 - 2010-01-22 09:29 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
2010-01-22 09:30 - 2010-01-22 09:30 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
2010-01-22 09:29 - 2010-01-22 09:29 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2011-01-23 10:59 - 2011-01-23 10:59 - 00039088 _____ () C:\ProgramData\Screentime\Fliqlo\saver1.dll
2011-07-29 00:09 - 2011-07-29 00:09 - 00096112 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Andreas\Lokale Einstellungen:K7OVjAFwPVwsATTfrtllOJ9TSw2
AlternateDataStreams: C:\Users\Andreas\AppData\Local:K7OVjAFwPVwsATTfrtllOJ9TSw2
AlternateDataStreams: C:\Users\Andreas\AppData\Local\Anwendungsdaten:K7OVjAFwPVwsATTfrtllOJ9TSw2
AlternateDataStreams: C:\Users\Andreas\AppData\Local\Temporary Internet Files:DWIg6CJaOPcj3pXFs7k5kdz
AlternateDataStreams: C:\Users\Andreas\AppData\Local\Temporary Internet Files:jIhugGoJvObF6lcKPTEzAnUoTAP
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (10/29/2013 07:53:02 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: taskeng.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce79d2c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000986ea
ID des fehlerhaften Prozesses: 0x12bc
Startzeit der fehlerhaften Anwendung: 0xtaskeng.exe0
Pfad der fehlerhaften Anwendung: taskeng.exe1
Pfad des fehlerhaften Moduls: taskeng.exe2
Berichtskennung: taskeng.exe3
Error: (10/29/2013 07:09:40 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: unzip.exe, Version: 1.0.1.0, Zeitstempel: 0x487e6471
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000986ea
ID des fehlerhaften Prozesses: 0xcdc
Startzeit der fehlerhaften Anwendung: 0xunzip.exe0
Pfad der fehlerhaften Anwendung: unzip.exe1
Pfad des fehlerhaften Moduls: unzip.exe2
Berichtskennung: unzip.exe3
Error: (10/29/2013 06:54:13 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0x10c0
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (10/27/2013 07:30:49 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: WinVNC.exe, Version: 1.1.8.0, Zeitstempel: 0x50afe01f
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000986ea
ID des fehlerhaften Prozesses: 0x1624
Startzeit der fehlerhaften Anwendung: 0xWinVNC.exe0
Pfad der fehlerhaften Anwendung: WinVNC.exe1
Pfad des fehlerhaften Moduls: WinVNC.exe2
Berichtskennung: WinVNC.exe3
Error: (10/24/2013 07:10:03 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: WLIDSvcM.exe, Version: 6.500.3165.0, Zeitstempel: 0x4a8b055b
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000986ea
ID des fehlerhaften Prozesses: 0xeec
Startzeit der fehlerhaften Anwendung: 0xWLIDSvcM.exe0
Pfad der fehlerhaften Anwendung: WLIDSvcM.exe1
Pfad des fehlerhaften Moduls: WLIDSvcM.exe2
Berichtskennung: WLIDSvcM.exe3
Error: (10/23/2013 09:01:39 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: DllHost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bca54
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000986ea
ID des fehlerhaften Prozesses: 0x155c
Startzeit der fehlerhaften Anwendung: 0xDllHost.exe0
Pfad der fehlerhaften Anwendung: DllHost.exe1
Pfad des fehlerhaften Moduls: DllHost.exe2
Berichtskennung: DllHost.exe3
Error: (10/23/2013 08:23:03 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: SearchProtocolHost.exe, Version: 7.0.7600.16385, Zeitstempel: 0x4a5bd1b4
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000986ea
ID des fehlerhaften Prozesses: 0x1018
Startzeit der fehlerhaften Anwendung: 0xSearchProtocolHost.exe0
Pfad der fehlerhaften Anwendung: SearchProtocolHost.exe1
Pfad des fehlerhaften Moduls: SearchProtocolHost.exe2
Berichtskennung: SearchProtocolHost.exe3
Error: (10/23/2013 06:17:42 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0x106c
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (10/22/2013 06:00:00 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0x136c
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (10/20/2013 07:42:05 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: rundll32.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc637
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0038dc10
ID des fehlerhaften Prozesses: 0x614
Startzeit der fehlerhaften Anwendung: 0xrundll32.exe0
Pfad der fehlerhaften Anwendung: rundll32.exe1
Pfad des fehlerhaften Moduls: rundll32.exe2
Berichtskennung: rundll32.exe3
System errors:
=============
Error: (10/29/2013 06:54:25 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (10/29/2013 06:54:25 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Browser-Schutz" ist vom Dienst "Avira Echtzeit-Scanner" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (10/29/2013 06:54:25 PM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (10/29/2013 06:54:24 PM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (10/27/2013 07:33:59 PM) (Source: Microsoft-Windows-DNS-Client) (User: NT-AUTORITÄT)
Description: Fehler beim Lesen der Datei für lokale Hosts.
Error: (10/27/2013 06:20:02 PM) (Source: Service Control Manager) (User: )
Description: Dienst "Belkin Local Backup Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (10/27/2013 04:37:44 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (10/27/2013 04:37:44 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Browser-Schutz" ist vom Dienst "Avira Echtzeit-Scanner" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1070
Error: (10/27/2013 04:37:44 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Echtzeit-Scanner" wurde nicht richtig gestartet.
Error: (10/27/2013 04:37:34 PM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Microsoft Office Sessions:
=========================
Error: (01/19/2013 09:50:04 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 921 seconds with 900 seconds of active time. This session ended with a crash.
Error: (08/29/2011 09:42:54 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 5202 seconds with 4320 seconds of active time. This session ended with a crash.
Error: (08/09/2011 08:04:25 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1653 seconds with 1080 seconds of active time. This session ended with a crash.
Error: (04/29/2011 07:37:02 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2768 seconds with 840 seconds of active time. This session ended with a crash.
Error: (03/19/2011 10:47:43 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 37 seconds with 0 seconds of active time. This session ended with a crash.
Error: (03/19/2011 10:46:50 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 144 seconds with 120 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Percentage of memory in use: 36%
Total physical RAM: 3834.9 MB
Available physical RAM: 2445 MB
Total Pagefile: 7667.98 MB
Available Pagefile: 5691.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (HAUPTPLATTE) (Fixed) (Total:195.31 GB) (Free:21.35 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:21.33 GB) (Free:3.11 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
Drive h: () (Removable) (Total:0.95 GB) (Free:0.8 GB) FAT
Drive i: (Intenso) (Removable) (Total:7.38 GB) (Free:5.11 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 298 GB) (Disk ID: DE17C439)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=195 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=21 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=103 MB) - (Type=0C)
========================================================
Disk: 1 (Size: 969 MB) (Disk ID: 00000000)
Partition 1: (Not Active) - (Size=969 MB) - (Type=06)
========================================================
Disk: 2 (Size: 7 GB) (Disk ID: 2BD54882)
Partition 1: (Not Active) - (Size=7 GB) - (Type=0C)
==================== End Of Log ============================
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-10-2013
Ran by Andreas (administrator) on ANDREAS-PC on 29-10-2013 20:10:07
Running from C:\Users\Andreas\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_471277d5d45019ea\STacSV64.exe
(Hewlett-Packard) C:\Windows\system32\Hpservice.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Validity Sensors, Inc.) C:\Windows\system32\vcsFPService.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_471277d5d45019ea\AESTSr64.exe
() C:\Program Files\Belkin\Home Base Control Center\Hbapcs.exe
() C:\Program Files\Belkin\Home Base Control Center\BkBackupScheduler.exe
(DeviceVM, Inc.) C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
() C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(UltraVNC) C:\Program Files\uvnc bvba\UltraVNC\WinVNC.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard ) C:\Program Files\Hewlett-Packard\HPToneControl\HPToneCtl.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Belkin International, Inc.) C:\Program Files\Belkin\Home Base Control Center\Connect.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(Belkin International, Inc.) C:\Program Files\Belkin\Home Base Control Center\Hbhelper.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
() C:\Program Files (x86)\MMEDIA\TV Jukebox 3.1\tvjbMonitor.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(UltraVNC) C:\Program Files\uvnc bvba\UltraVNC\WinVNC.exe
(Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe
(Bandoo Media, inc) C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DPAgent.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2281256 2010-09-13] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-02-01] (IDT, Inc.)
HKLM\...\Run: [SmartMenu] - C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [611896 2010-01-20] ()
HKLM\...\Run: [HP Quick Launch] - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [451072 2010-01-18] (Hewlett-Packard Company)
HKLM\...\Run: [HPToneControl] - C:\Program Files\Hewlett-Packard\HPToneControl\HPToneCtl.exe [107832 2009-08-19] (Hewlett-Packard )
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [172032 2010-05-07] (Sun Microsystems, Inc.)
HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-01-27] (Hewlett-Packard)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE [2184520 2009-07-27] (CANON INC.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe,
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKCU\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-01-22] (Hewlett-Packard Company)
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKCU\...\Policies\system: [DisableChangePassword] 0
MountPoints2: {ff7faec0-05e6-11e1-86e9-f0e9fd8e750d} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\Start.hta
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-04-16] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-30] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2011-06-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2010-01-25] (EasyBits Software AS)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2010-12-06] (Nullsoft, Inc.)
HKLM-x32\...\Run: [tvjbmonitor] - C:\Program Files (x86)\MMEDIA\TV Jukebox 3.1\tvjbMonitor.exe [53248 2006-12-26] ()
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] ()
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1557160 2012-04-18] (Ask)
HKLM-x32\...\Run: [DATAMNGR] - C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe [1890744 2012-09-02] (Bandoo Media, inc)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-10-02] (Avira Operations GmbH & Co. KG)
HKU\Default\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
AppInit_DLLs: C:\PROGRA~2\WIA6EB~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\WIA6EB~1\Datamngr\x64\IEBHO.dll [1528760 2012-09-02] (Bandoo Media, inc)
AppInit_DLLs-x32: C:\PROGRA~2\WIA6EB~1\Datamngr\datamngr.dll C:\PROGRA~2\WIA6EB~1\Datamngr\IEBHO.dll [1185208 2012-09-02] (Bandoo Media, inc)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Belkin Home Base Control Center.lnk
ShortcutTarget: Belkin Home Base Control Center.lnk -> C:\Program Files\Belkin\Home Base Control Center\Connect.exe (Belkin International, Inc.)
Startup: C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=e211d489-3a29-4de7-ac16-7f3e15c24d91&searchtype=ds&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1293043730&rver=6.1.6206.0&wp=MBI&wreply=http:%2F%2Fmail.live.com%2Fdefault.aspx&lc=1031&id=64855&mkt=de-de&cbcxt=mai&snsc=1
https://webmail.zf.com/exchweb/bin/auth/owalogon.asp?url=https://webmail.zf.com/exchange/&reason=0
hxxp://www.chip.de/
hxxp://www.ebay.de/
hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=e211d489-3a29-4de7-ac16-7f3e15c24d91&searchtype=ds&q={searchTerms}
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=e211d489-3a29-4de7-ac16-7f3e15c24d91&searchtype=ds&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=e211d489-3a29-4de7-ac16-7f3e15c24d91&searchtype=ds&q={searchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=e211d489-3a29-4de7-ac16-7f3e15c24d91&searchtype=ds&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=e211d489-3a29-4de7-ac16-7f3e15c24d91&searchtype=ds&q={searchTerms}
SearchScopes: HKCU - {1134328D-D56C-40D7-80B8-0884EB79307A} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {17BE333C-8E2A-4EF1-9441-9C11B61B7662} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {5E969295-A8AC-44EB-BF42-554BA49EBE4F} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie
SearchScopes: HKCU - {8AC971A3-B7C6-4090-8EBC-0E3C10F93937} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms}
BHO: HP SimplePass Identity Protection Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\x64\BrowserConnection.dll (Bandoo Media, inc)
BHO: WEB.DE Toolbar BHO - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: HP SimplePass Identity Protection Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
BHO-x32: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
BHO-x32: WEB.DE Toolbar BHO - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - WEB.DE Toolbar - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - WEB.DE Toolbar - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
Toolbar: HKLM-x32 - Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM-x32 - Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKCU - WEB.DE Toolbar - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
Toolbar: HKCU - No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Handler: webde - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: webde - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL [52920 2010-05-07] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default
FF DefaultSearchEngine: Web Search
FF SearchEngineOrder.1: Search Results
FF SelectedSearchEngine: Web Search
FF Homepage: hxxp://www.google.de/
FF Keyword.URL: hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=413&sr=0&q=
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\searchplugins\11-suche.xml
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\searchplugins\Search_Results.xml
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Searchqu Toolbar - C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\Extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
FF Extension: toolbar - C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\Extensions\toolbar@web.de.xpi
FF Extension: No Name - C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
FF Extension: No Name - C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\y8k8bsow.default\Extensions\{35379F86-8CCB-4724-AE33-4278DE266C70}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
==================== Services (Whitelisted) =================
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_471277d5d45019ea\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-10-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-10-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-10-02] (Avira Operations GmbH & Co. KG)
R2 Belkin Home Base Control Center Service; C:\Program Files\Belkin\Home Base Control Center\Hbapcs.exe [48128 2009-01-15] ()
R2 Belkin Local Backup Service; C:\Program Files\Belkin\Home Base Control Center\BkBackupScheduler.exe [103424 2009-06-22] ()
R2 DvmMDES; C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe [338168 2010-03-05] (DeviceVM, Inc.)
R2 HPWMISVC; C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [20480 2010-01-18] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_471277d5d45019ea\STacSV64.exe [244736 2010-02-01] (IDT, Inc.)
R2 uvnc_service; C:\Program Files\uvnc bvba\UltraVNC\WinVNC.exe [2190584 2012-11-23] (UltraVNC)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-10-02] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-10-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-02] (Avira Operations GmbH & Co. KG)
R1 DVMIO; C:\Windows\System32\DRIVERS\dvmio.sys [20056 2009-11-11] (DeviceVM, Inc.)
R2 sxuptp; C:\Windows\System32\DRIVERS\sxuptp.sys [291352 2009-06-22] (silex technology, Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-29 20:05 - 2013-10-29 20:05 - 01956538 _____ (Farbar) C:\Users\Andreas\Desktop\FRST64.exe
2013-10-29 20:03 - 2013-10-29 20:03 - 00752096 _____ C:\Users\Andreas\Downloads\ZipExtractorSetup.exe
2013-10-27 09:06 - 2013-10-27 09:06 - 00001192 _____ C:\Users\Andreas\Desktop\Ereignisse.txt
2013-10-26 20:58 - 2013-10-26 20:58 - 00005952 _____ C:\Users\Andreas\Desktop\Gmer.txt
2013-10-26 20:43 - 2013-10-26 20:44 - 00030651 _____ C:\Users\Andreas\Desktop\Addition1.txt
2013-10-26 20:39 - 2013-10-26 20:39 - 00000000 ____D C:\FRST
2013-10-26 20:09 - 2013-10-21 13:26 - 00000000 _____ C:\Users\Andreas\Desktop\trojaner-board_de_1234qwer.txt
2013-10-26 20:08 - 2013-10-21 13:24 - 00377856 _____ C:\Users\Andreas\Desktop\gmer_2.1.19163.exe
2013-10-26 20:08 - 2013-10-21 13:20 - 00752296 _____ C:\Users\Andreas\Desktop\ZipExtractorSetup64.exe
2013-10-26 17:53 - 2013-10-26 18:08 - 00000000 ____D C:\Users\Andreas\Desktop\MiaAndMe13
2013-10-26 17:36 - 2013-10-26 17:51 - 00000000 ____D C:\Users\Andreas\Desktop\MiaAndMe12
2013-10-26 17:16 - 2013-10-26 17:31 - 00000000 ____D C:\Users\Andreas\Desktop\MiaAndMe11
2013-10-24 19:08 - 2013-10-24 19:08 - 00274512 _____ C:\Windows\Minidump\102413-16146-01.dmp
2013-10-19 07:17 - 2013-10-19 07:17 - 00000000 ____D C:\ProgramData\UUdb
2013-10-13 09:55 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-13 09:55 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-13 09:55 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-13 09:55 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-13 09:55 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-13 09:55 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-13 09:55 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-13 09:55 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-13 09:55 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-13 09:55 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-13 09:55 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-13 09:55 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-13 09:55 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-13 09:55 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-13 09:55 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-13 09:55 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-13 09:55 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-13 09:55 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-13 09:55 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-13 09:55 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-13 09:55 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-13 08:02 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-13 08:02 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-13 08:02 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-13 08:02 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-13 08:02 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-13 08:02 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-13 08:02 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-13 08:02 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-13 08:02 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-13 08:02 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-13 08:02 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-13 08:02 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-13 08:02 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-13 08:02 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2013-10-13 08:02 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2013-10-13 08:02 - 2012-11-28 23:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2013-10-13 08:01 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-13 08:01 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-13 08:01 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-13 08:01 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-13 08:01 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-13 08:01 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-13 08:01 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-13 08:01 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-13 08:01 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-04 14:39 - 2013-10-24 19:08 - 259989773 _____ C:\Windows\MEMORY.DMP
2013-10-04 14:39 - 2013-10-04 14:40 - 00274512 _____ C:\Windows\Minidump\100413-13057-01.dmp
2013-10-03 18:38 - 2013-10-03 18:38 - 00036792 _____ C:\Users\Andreas\Desktop\Details deiner Bestellung bei IKEA.htm
2013-10-03 18:38 - 2013-10-03 18:38 - 00000000 ____D C:\Users\Andreas\Desktop\Details deiner Bestellung bei IKEA-Dateien
2013-10-03 16:33 - 2013-10-03 16:33 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-10-02 18:37 - 2013-10-02 18:37 - 00000000 ____D C:\Users\Andreas\AppData\Roaming\Avira
2013-10-02 18:32 - 2013-10-02 18:32 - 00000000 ____D C:\Program Files (x86)\Avira
2013-10-02 18:32 - 2013-10-02 18:31 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-02 18:32 - 2013-10-02 18:31 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-02 18:32 - 2013-10-02 18:31 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-10-02 17:56 - 2013-10-02 17:56 - 02296952 _____ C:\Users\Andreas\Downloads\avira_free_antivirus.exe
2013-10-01 18:06 - 2013-10-01 18:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-29 07:19 - 2013-09-29 07:20 - 00000000 ____D C:\Users\Andreas\Desktop\Handy
2013-09-29 07:00 - 2013-09-29 07:00 - 00000000 ____D C:\Users\Andreas\Documents\Mia
==================== One Month Modified Files and Folders =======
2013-10-29 20:10 - 2011-05-17 19:30 - 00000250 ____H C:\Windows\Tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job
2013-10-29 20:05 - 2013-10-29 20:05 - 01956538 _____ (Farbar) C:\Users\Andreas\Desktop\FRST64.exe
2013-10-29 20:03 - 2013-10-29 20:03 - 00752096 _____ C:\Users\Andreas\Downloads\ZipExtractorSetup.exe
2013-10-29 19:54 - 2011-05-17 19:30 - 00000294 ____H C:\Windows\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
2013-10-29 19:21 - 2012-08-29 18:45 - 00003198 _____ C:\Windows\System32\Tasks\HPCeeScheduleForAndreas
2013-10-29 19:21 - 2012-08-29 18:45 - 00000340 _____ C:\Windows\Tasks\HPCeeScheduleForAndreas.job
2013-10-29 19:09 - 2011-05-03 20:37 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log
2013-10-29 19:01 - 2009-07-14 05:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-29 19:01 - 2009-07-14 05:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-29 18:59 - 2010-05-08 04:03 - 00697082 _____ C:\Windows\system32\perfh007.dat
2013-10-29 18:59 - 2010-05-08 04:03 - 00148346 _____ C:\Windows\system32\perfc007.dat
2013-10-29 18:59 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-29 18:58 - 2010-05-17 00:45 - 01729694 _____ C:\Windows\WindowsUpdate.log
2013-10-29 18:53 - 2011-05-17 19:30 - 00000306 ___SH C:\Windows\Tasks\Owpmzevaq.job
2013-10-29 18:53 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-29 18:53 - 2009-07-14 05:51 - 00167315 _____ C:\Windows\setupact.log
2013-10-27 19:27 - 2013-01-02 22:16 - 00000000 ____D C:\Users\Andreas\Desktop\Sicherung
2013-10-27 09:06 - 2013-10-27 09:06 - 00001192 _____ C:\Users\Andreas\Desktop\Ereignisse.txt
2013-10-26 20:58 - 2013-10-26 20:58 - 00005952 _____ C:\Users\Andreas\Desktop\Gmer.txt
2013-10-26 20:44 - 2013-10-26 20:43 - 00030651 _____ C:\Users\Andreas\Desktop\Addition1.txt
2013-10-26 20:39 - 2013-10-26 20:39 - 00000000 ____D C:\FRST
2013-10-26 18:08 - 2013-10-26 17:53 - 00000000 ____D C:\Users\Andreas\Desktop\MiaAndMe13
2013-10-26 17:51 - 2013-10-26 17:36 - 00000000 ____D C:\Users\Andreas\Desktop\MiaAndMe12
2013-10-26 17:31 - 2013-10-26 17:16 - 00000000 ____D C:\Users\Andreas\Desktop\MiaAndMe11
2013-10-24 19:08 - 2013-10-24 19:08 - 00274512 _____ C:\Windows\Minidump\102413-16146-01.dmp
2013-10-24 19:08 - 2013-10-04 14:39 - 259989773 _____ C:\Windows\MEMORY.DMP
2013-10-24 19:08 - 2012-12-01 11:06 - 00000000 ____D C:\Windows\Minidump
2013-10-23 18:24 - 2010-12-22 19:37 - 00000000 ____D C:\Users\Andreas\AppData\Roaming\Winamp
2013-10-21 13:26 - 2013-10-26 20:09 - 00000000 _____ C:\Users\Andreas\Desktop\trojaner-board_de_1234qwer.txt
2013-10-21 13:24 - 2013-10-26 20:08 - 00377856 _____ C:\Users\Andreas\Desktop\gmer_2.1.19163.exe
2013-10-21 13:20 - 2013-10-26 20:08 - 00752296 _____ C:\Users\Andreas\Desktop\ZipExtractorSetup64.exe
2013-10-20 15:35 - 2012-08-16 20:23 - 00000000 ____D C:\Users\Andreas\AppData\Roaming\MyPhoneExplorer
2013-10-19 07:17 - 2013-10-19 07:17 - 00000000 ____D C:\ProgramData\UUdb
2013-10-19 07:17 - 2011-12-30 20:34 - 00003880 _____ C:\Windows\System32\Tasks\Registration 1und1 Task
2013-10-19 07:17 - 2011-12-30 20:34 - 00000000 ____D C:\Program Files (x86)\1und1Softwareaktualisierung
2013-10-19 07:09 - 2012-05-14 12:14 - 00065024 ___SH C:\Users\Andreas\Thumbs.db
2013-10-14 19:00 - 2009-07-14 05:45 - 04994432 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-14 18:57 - 2013-03-16 10:26 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-14 18:57 - 2013-03-16 10:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-13 09:58 - 2010-05-07 19:41 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-13 09:51 - 2011-11-25 21:16 - 01591234 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-13 09:45 - 2013-08-20 21:17 - 00000000 ____D C:\Windows\system32\MRT
2013-10-13 09:45 - 2011-01-04 16:53 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-12 14:10 - 2011-01-01 13:11 - 00000000 ____D C:\Users\Andreas\AppData\Roaming\dvdcss
2013-10-08 19:42 - 2012-05-13 20:11 - 00000000 ____D C:\ProgramData\Avira
2013-10-08 19:32 - 2010-12-18 15:33 - 00000000 ____D C:\Users\Andreas
2013-10-04 14:40 - 2013-10-04 14:39 - 00274512 _____ C:\Windows\Minidump\100413-13057-01.dmp
2013-10-03 18:38 - 2013-10-03 18:38 - 00036792 _____ C:\Users\Andreas\Desktop\Details deiner Bestellung bei IKEA.htm
2013-10-03 18:38 - 2013-10-03 18:38 - 00000000 ____D C:\Users\Andreas\Desktop\Details deiner Bestellung bei IKEA-Dateien
2013-10-03 16:33 - 2013-10-03 16:33 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-10-03 16:32 - 2013-03-04 20:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-03 16:32 - 2010-05-17 00:51 - 00370212 _____ C:\Windows\PFRO.log
2013-10-02 18:37 - 2013-10-02 18:37 - 00000000 ____D C:\Users\Andreas\AppData\Roaming\Avira
2013-10-02 18:32 - 2013-10-02 18:32 - 00000000 ____D C:\Program Files (x86)\Avira
2013-10-02 18:31 - 2013-10-02 18:32 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-02 18:31 - 2013-10-02 18:32 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-02 18:31 - 2013-10-02 18:32 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-10-02 17:56 - 2013-10-02 17:56 - 02296952 _____ C:\Users\Andreas\Downloads\avira_free_antivirus.exe
2013-10-02 17:54 - 2011-11-04 20:28 - 00000000 ____D C:\Users\Andreas\AppData\Local\Mozilla
2013-10-01 18:06 - 2013-10-01 18:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-29 07:20 - 2013-09-29 07:19 - 00000000 ____D C:\Users\Andreas\Desktop\Handy
2013-09-29 07:02 - 2010-12-19 21:35 - 00000000 ____D C:\Users\Andreas\Documents\Feste
2013-09-29 07:00 - 2013-09-29 07:00 - 00000000 ____D C:\Users\Andreas\Documents\Mia
Files to move or delete:
====================
C:\Windows\Tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job
C:\Windows\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
Some content of TEMP:
====================
C:\Users\Andreas\AppData\Local\Temp\AskSLib.dll
C:\Users\Andreas\AppData\Local\Temp\autostitch.exe
C:\Users\Andreas\AppData\Local\Temp\BearShare_setup.exe
C:\Users\Andreas\AppData\Local\Temp\Extract.exe
C:\Users\Andreas\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Andreas\AppData\Local\Temp\FlashPlayerUpdate01.exe
C:\Users\Andreas\AppData\Local\Temp\HPQSi.exe
C:\Users\Andreas\AppData\Local\Temp\ijl11.dll
C:\Users\Andreas\AppData\Local\Temp\installhelper.dll
C:\Users\Andreas\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe
C:\Users\Andreas\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Users\Andreas\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\Andreas\AppData\Local\Temp\jre-6u30-windows-i586-iftw-rv.exe
C:\Users\Andreas\AppData\Local\Temp\jre-6u34-windows-i586-iftw.exe
C:\Users\Andreas\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
C:\Users\Andreas\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe
C:\Users\Andreas\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe
C:\Users\Andreas\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Andreas\AppData\Local\Temp\mediaget_installer.exe
C:\Users\Andreas\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Andreas\AppData\Local\Temp\msg52F3.exe
C:\Users\Andreas\AppData\Local\Temp\msg6A1B.exe
C:\Users\Andreas\AppData\Local\Temp\msg9467.exe
C:\Users\Andreas\AppData\Local\Temp\MSN7ABC.exe
C:\Users\Andreas\AppData\Local\Temp\ose00000.exe
C:\Users\Andreas\AppData\Local\Temp\pegavi.dll
C:\Users\Andreas\AppData\Local\Temp\pegcore.dll
C:\Users\Andreas\AppData\Local\Temp\SetupDataMngr_BearShare.exe
C:\Users\Andreas\AppData\Local\Temp\SetupDataMngr_Searchqu.exe
C:\Users\Andreas\AppData\Local\Temp\SP52615.exe
C:\Users\Andreas\AppData\Local\Temp\SRAssetsHelper.dll
C:\Users\Andreas\AppData\Local\Temp\WEB.DE_Sicherheitsupdate_Sep2012_Setup.exe
C:\Users\Andreas\AppData\Local\Temp\WEB.DE_Softwareaktualisierung_Setup.exe
C:\Users\Andreas\AppData\Local\Temp\WEB.DE_Toolbar_IE_Setup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-21 17:27
==================== End Of Log ============================ --- --- --- |