Lord Sokar | 03.06.2014 17:30 | ....Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-06-2014 01
Ran by Jens at 2014-06-02 17:28:30
Running from C:\Users\Jens\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
ACER ICONIA TAB Driver Installation (HKLM-x32\...\InstallShield_{E3D98871-36D1-492B-95B4-AB8BC64E1E4C}) (Version: 1.06.1500 - acer)
ACER ICONIA TAB Driver Installation (x32 Version: 1.06.1500 - acer) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19120 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 2.6.0.19120 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Photoshop Elements (HKLM-x32\...\Adobe Photoshop Elements 1.0) (Version: 1.0 - Adobe Systems, Inc.)
Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Adobe SVG Viewer 3.0 (HKLM-x32\...\Adobe SVG Viewer) (Version: 3.0 - Adobe Systems, Inc.)
Anvi Smart Defender 2.2 (HKLM-x32\...\Anvi Smart Defender) (Version: 2.2 - Anvisoft)
ArcSoft PhotoStudio 5.5 (HKLM-x32\...\{85309D89-7BE9-4094-BB17-24999C6118FC}) (Version: - ArcSoft)
Ashampoo Burning Studio 12 v.12.0.5 (HKLM-x32\...\{91B33C97-93EB-244C-F687-71D85E45A206}_is1) (Version: 12.0.5 - Ashampoo GmbH & Co. KG)
Avira (HKLM-x32\...\{c13d72f9-bcdd-4c16-a942-7373a528171e}) (Version: 1.0.5218.31571 - Avira Operations GmbH & Co. KG)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira)
Avira System Speedup (HKLM-x32\...\AviraSpeedup) (Version: 1.3.1.9930 - Avira System Speedup)
AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - )
AVM FRITZ!Box Druckeranschluss (HKLM-x32\...\AVMFBoxPrinter) (Version: - AVM Berlin)
Canon MP Navigator EX 2.0 (HKLM-x32\...\MP Navigator EX 2.0) (Version: - )
Canon Utilities CameraWindow DC 8 (HKLM-x32\...\CameraWindowDC) (Version: 8.7.0.11 - Canon Inc.)
Canon Utilities ImageBrowser EX (HKLM-x32\...\ImageBrowser EX) (Version: 1.2.1.13 - Canon Inc.)
Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.)
CanoScan 5600F Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4808) (Version: - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DDBAC (HKLM-x32\...\{8E1246B9-9F66-4303-BF11-212EC2672BBE}) (Version: 5.3.13 - DataDesign)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{349F73CA-653A-43A6-AE77-970B07D6EDA0}) (Version: - Microsoft)
devolo dLAN Cockpit (HKLM-x32\...\dlancockpit) (Version: 3.2.0.0 - devolo AG)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC)
dLAN Cockpit (x32 Version: 3.2.28 - devolo AG) Hidden
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
EaseUS Partition Master 9.2.1 Home Edition (HKLM-x32\...\EaseUS Partition Master Home Edition_is1) (Version: - EaseUS)
Free Studio version 2013 (HKLM-x32\...\Free Studio_is1) (Version: 6.1.11.827 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.11.32.918 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.32.918 - DVDVideoSoft Ltd.)
GenealogyJ 6755 (HKLM-x32\...\GenealogyJ 6755) (Version: 6755 - )
GNU Backgammon (MAIN branch, 20081113 code) (HKLM-x32\...\GNU Backgammon_is1) (Version: - Free Software Foundation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.)
Google Drive (HKLM-x32\...\{418BAAD1-754D-48B4-B078-46EF4F25AF42}) (Version: 1.15.6556.8063 - Google, Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
Green Line 1 Sprachtrainer (HKLM-x32\...\{BC1ECCD7-EE86-4231-AF1B-6E52B49A4532}) (Version: 1.00.000 - Klett)
Handset WinDriver 1.02.03.00 (HKLM-x32\...\Handset WinDriver) (Version: 1.02.03.00 - Huawei technologies Co., Ltd.)
Hardcopy (HKLM-x32\...\Hardcopy) (Version: 2013.02.18 - www.hardcopy.de)
Inkjet Printer/Scanner Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - )
Java 7 Update 13 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417013FF}) (Version: 7.0.130 - Oracle)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) SE Runtime Environment 6 (HKLM-x32\...\{3248F0A8-6813-11D6-A77B-00B0D0160000}) (Version: 1.6.0.0 - Sun Microsystems, Inc.)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Juniper Citrix Services Client (HKCU\...\Juniper_Citrix_Services) (Version: 7.1.12.21827 - Juniper Networks)
Juniper Networks Setup Client Activex Control (HKLM-x32\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks)
Juniper Networks, Inc. Setup Client (HKCU\...\Juniper_Setup_Client) (Version: 7.1.10.21853 - Juniper Networks, Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
K-Lite Mega Codec Pack 9.6.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.6.5 - )
Logitech Harmony Remote Software 7 (HKLM-x32\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech)
Logitech Harmony Remote Software 7 (x32 Version: 7.3.0.15 - Logitech) Hidden
Logitech Vid (HKLM-x32\...\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}) (Version: 1.10.1009 - Logitech Inc.)
Logitech Webcam Software (HKLM\...\{987FE247-4E69-4A2E-A961-D14F901FDBF6}) (Version: 12.10.1113 - Logitech Inc.)
MediaPortal (HKLM-x32\...\MediaPortal) (Version: 1.2.3 - Team MediaPortal)
MediaPortal TV Server / Client (HKLM-x32\...\MediaPortal TV Server) (Version: 1.2.3 - Team MediaPortal)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Money 2006 (HKLM-x32\...\Money2006b) (Version: 15 - Microsoft)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\...\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
mkv2vob (HKLM-x32\...\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}) (Version: 2.4.9 - 3r1c)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mp3tag v2.56 (HKLM-x32\...\Mp3tag) (Version: v2.56 - Florian Heidenreich)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
NAVIGON Fresh 3.5.1 (HKLM-x32\...\NAVIGON Fresh) (Version: 3.5.1 - NAVIGON)
NVIDIA 3D Vision Treiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA Grafiktreiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.108.688 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 311.06 (Version: 311.06 - NVIDIA Corporation) Hidden
NVIDIA Update 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.11.3 - NVIDIA Corporation) Hidden
OnlineFotoservice (HKLM-x32\...\OnlineFotoservice) (Version: 5.1.3 - CEWE Stiftung u Co. KGaA)
OpenStage ConnectionService V2 R2.2.0 (HKLM-x32\...\{9B4AA6F3-FF97-4B3E-BCBF-3B618C0F90C1}) (Version: V2 R2.2.0 - Siemens Enterprise Communications GmbH & Co. KG)
OpenStage Manager V2 R2.2.0 (HKLM-x32\...\{B244059F-384C-4F46-A070-43FC0F3AB130}) (Version: V2 R2.2.0 - Siemens Enterprise Communications GmbH & Co. KG)
Personal Ancestral File 5 (HKLM-x32\...\{D94A8E22-DF2B-4107-9E51-608A60A7671D}) (Version: - )
PS3 Media Server (HKLM-x32\...\PS3 Media Server) (Version: 1.90.1 - PS3 Media Server)
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6196 - Realtek Semiconductor Corp.)
Remote Control USB Driver (HKLM-x32\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - )
Scratch (HKLM-x32\...\Scratch) (Version: 1.4.0.0 - MIT Media Lab Lifelong Kindergarten Group)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden
Skype Click to Call (HKLM-x32\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.2.15747.10003 - Microsoft Corporation)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sprachtrainer Fonts (HKLM-x32\...\{FBCF2ED3-AFB5-475E-BF9A-30BEAD366FBC}) (Version: 1.00.01 - Ernst Klett Verlag GmbH)
Stammbaum Profi 2.4.3 (HKLM-x32\...\Stammbaum Profi_is1) (Version: - Open Source Factory)
t@x 2011 (HKCU\...\{B0414A3B-3AE3-47B8-8FC0-2129781FF425}) (Version: 18.05.7041 - Buhl Data Service GmbH)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.28223 - TeamViewer)
TI Connect 1.6 (HKLM-x32\...\{A8B94669-8654-4126-BD28-D0D2412CDED6}) (Version: 1.6 - Texas Instruments Incorporated)
Uninstall 1.0.0.1 (HKLM-x32\...\Uninstall_is1) (Version: - )
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUS_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUS_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUS_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft)
URL Snooper v2.33.01 (HKLM-x32\...\URLSnooper 2_is1) (Version: - DonationCoder.com)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Windows Driver Package - Texas Instruments Inc. (SilvrLnk) USB (06/11/2009 1.0.0.0) (HKLM\...\EC3E466026556D3EB760B01C4772277614354E11) (Version: 06/11/2009 1.0.0.0 - Texas Instruments Inc.)
Windows Driver Package - Texas Instruments Inc. (TIEHDUSB) USB (09/02/2009 1.0.0.1) (HKLM\...\7511B29C86C398B4D11A0B0E4176CAD68D1B7057) (Version: 09/02/2009 1.0.0.1 - Texas Instruments Inc.)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 4.00 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH)
WISO Steuer-Sparbuch 2012 (HKLM-x32\...\{0CC1DAFB-40C8-4903-953D-471E541477C7}) (Version: 19.00.7303 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2013 (HKLM-x32\...\{D6CC2FAF-F827-4091-96A1-D32CC9B69C79}) (Version: 20.00.8137 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2014 (HKLM-x32\...\{F8F7C07A-FB19-46C6-8860-DC2A44E37AB9}) (Version: 21.02.8520 - Buhl Data Service GmbH)
Yahoo! Detect (HKLM-x32\...\YTdetect) (Version: - )
==================== Restore Points =========================
28-04-2014 05:58:56 Geplanter Prüfpunkt
30-04-2014 15:15:30 Windows Update
03-05-2014 16:59:26 Windows Update
06-05-2014 17:11:54 Windows Update
15-05-2014 15:47:56 Windows Update
24-05-2014 08:15:09 Geplanter Prüfpunkt
01-06-2014 09:15:44 Geplanter Prüfpunkt
01-06-2014 10:29:04 Gerätetreiber-Paketinstallation: Anvisoft Netzwerkdienst
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0206AC8B-9F2F-4078-BFCE-28344D8205F2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-27] (Google Inc.)
Task: {42F9A995-F5A5-47C3-B543-735C0EE40B97} - System32\Tasks\hcdll2_ex_Win32 => C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe [2012-11-08] ()
Task: {629E48A2-96AE-4502-96A2-FA39899211B7} - System32\Tasks\hcdll2_ex_x64 => C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe [2012-11-08] ()
Task: {65434F14-8260-43E6-AFAF-0923670D0868} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-16] (Adobe Systems Incorporated)
Task: {782B9367-18AD-46AB-8E66-A4A277AFA202} - System32\Tasks\AviraSpeedup => C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe [2014-03-27] (Avira)
Task: {A9B1BE1E-755C-4AF6-9979-CE4B103A8766} - System32\Tasks\ASD_Main => C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2.exe [2014-05-28] (Anvisoft)
Task: {AA7EFA5B-F971-46EF-A008-19A47B1927A9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-27] (Google Inc.)
Task: {AC4A1273-92DC-4EFB-A269-092EC2545E33} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {EF32EB44-D2DC-4642-86E4-6A5292A9C3FF} - System32\Tasks\DivX-Online-Aktualisierungsprogramm => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2014-01-10] ()
Task: {F6632857-7291-40FA-A921-8269BB7AC0BC} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2012-11-18 14:02 - 2013-01-18 17:00 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2011-03-09 18:08 - 2011-03-02 13:40 - 00164864 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
2013-03-10 20:23 - 2012-11-08 08:39 - 00037440 _____ () C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe
2013-03-10 20:23 - 2012-11-08 08:38 - 00044608 _____ () C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe
2012-09-23 12:42 - 2013-01-29 19:56 - 00069120 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
2009-10-14 14:36 - 2009-10-14 14:36 - 02793304 _____ () C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
2014-01-10 07:26 - 2014-01-10 07:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2009-10-14 14:34 - 2009-10-14 14:34 - 00560472 _____ () C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
2014-06-02 17:21 - 2014-06-02 17:21 - 00050477 _____ () C:\Users\Jens\Desktop\Defogger.exe
2013-03-10 20:23 - 2012-07-05 15:56 - 00052800 _____ () C:\Program Files (x86)\Hardcopy\hardcopy_05.dll
2009-07-16 16:34 - 2009-07-16 16:34 - 02140944 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtCore4.dll
2009-07-16 16:34 - 2009-07-16 16:34 - 07704336 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtGui4.dll
2009-07-16 16:34 - 2009-07-16 16:34 - 00968976 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtNetwork4.dll
2009-07-16 16:34 - 2009-07-16 16:34 - 00475408 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtOpenGL4.dll
2009-07-16 16:35 - 2009-07-16 16:35 - 00363792 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtXml4.dll
2009-07-16 16:34 - 2009-07-16 16:34 - 00199952 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtSql4.dll
2009-07-16 16:35 - 2009-07-16 16:35 - 00027408 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\SDL.dll
2009-07-16 16:35 - 2009-07-16 16:35 - 11311888 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtWebKit4.dll
2009-07-16 16:34 - 2009-07-16 16:34 - 00291600 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\phonon4.dll
2009-07-16 16:36 - 2009-07-16 16:36 - 00028944 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qgif4.dll
2009-07-16 16:36 - 2009-07-16 16:36 - 00035088 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qico4.dll
2009-07-16 16:36 - 2009-07-16 16:36 - 00138000 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qjpeg4.dll
2012-09-23 12:42 - 2013-01-29 19:45 - 00112128 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFMFileSystemWatcher.dll
2014-01-10 07:28 - 2014-01-10 07:28 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2014-06-01 09:19 - 2014-06-01 09:19 - 00098816 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32api.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00110080 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\pywintypes27.dll
2014-06-01 09:19 - 2014-06-01 09:19 - 00364544 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\pythoncom27.dll
2014-06-01 09:19 - 2014-06-01 09:19 - 00045568 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_socket.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 01159680 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_ssl.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00320512 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32com.shell.shell.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00713216 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_hashlib.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 01175040 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._core_.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00805888 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._gdi_.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00811008 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._windows_.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 01062400 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._controls_.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00735232 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._misc_.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00128512 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_elementtree.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00127488 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\pyexpat.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00557056 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\pysqlite2._sqlite.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00087552 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_ctypes.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00119808 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32file.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00108544 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32security.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00018432 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32event.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00038912 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32inet.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00070656 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._html2.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00167936 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32gui.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00011264 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32crypt.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00027136 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_multiprocessing.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00122368 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._wizard.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00010240 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\select.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00024064 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32pipe.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00686080 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\unicodedata.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00025600 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32pdh.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00525640 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\windows._lib_cacheinvalidation.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00035840 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32process.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00017408 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32profile.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00022528 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32ts.pyd
2014-06-01 09:19 - 2014-06-01 09:19 - 00078336 _____ () C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._animate.pyd
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-02-14 16:46 - 2013-02-14 16:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2014-05-11 18:55 - 2014-05-11 18:55 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2002-04-25 06:42 - 2002-04-25 06:42 - 00053248 _____ () C:\Program Files (x86)\Hardcopy\hcdll2_9.dll
2014-05-27 09:02 - 2014-05-27 09:02 - 00500968 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\http_hook.dll
2002-11-17 18:12 - 2002-11-17 18:12 - 00221184 _____ () C:\Program Files (x86)\Hardcopy\HcDllS.dll
1999-06-03 07:46 - 1999-06-03 07:46 - 00032768 _____ () C:\Program Files (x86)\Hardcopy\hardcopy.dll
2014-06-01 12:30 - 2014-06-01 12:30 - 00043008 _____ () c:\users\jens\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpil738f.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Jens\AppData\Roaming\Dropbox\bin\libcef.dll
2014-04-30 04:04 - 2014-04-30 04:04 - 00088080 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\libglog.dll
2014-05-27 09:02 - 2014-05-27 09:02 - 01039080 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2Engine.dll
2014-04-30 04:04 - 2014-04-30 04:04 - 00038928 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\fuzzy.dll
2014-04-30 04:04 - 2014-04-30 04:04 - 00093712 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\zlibwapi.dll
2014-05-27 09:02 - 2014-05-27 09:02 - 00135400 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ExtractImpl.dll
2014-05-27 09:02 - 2014-05-27 09:02 - 00437480 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\InnoExtractDll.dll
2014-05-27 09:02 - 2014-05-27 09:02 - 00030440 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\UnpackImpl.dll
2014-05-27 09:02 - 2014-05-27 09:02 - 00259816 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\pyunpacker.dll
2014-05-27 09:02 - 2014-05-27 09:02 - 00041704 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\fsmlib.dll
2014-04-30 03:27 - 2014-04-30 03:27 - 00649744 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\sqlite3.dll
2014-05-16 13:31 - 2014-05-16 13:31 - 16361136 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== Disabled items from MSCONFIG ==============
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^OpenStage Connection Service.lnk => C:\Windows\pss\OpenStage Connection Service.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Jens^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^t@x aktuell.lnk => C:\Windows\pss\t@x aktuell.lnk.Startup
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (05/25/2014 08:01:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: gnubg.exe, Version: 0.0.0.0, Zeitstempel: 0x491c05cc
Name des fehlerhaften Moduls: gnubg.exe, Version: 0.0.0.0, Zeitstempel: 0x491c05cc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00074f47
ID des fehlerhaften Prozesses: 0x1308
Startzeit der fehlerhaften Anwendung: 0xgnubg.exe0
Pfad der fehlerhaften Anwendung: gnubg.exe1
Pfad des fehlerhaften Moduls: gnubg.exe2
Berichtskennung: gnubg.exe3
Error: (05/10/2014 07:47:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: PictureViewer.exe, Version: 7.74.80.86, Zeitstempel: 0x5180f08e
Name des fehlerhaften Moduls: QuickTime.qts_unloaded, Version: 0.0.0.0, Zeitstempel: 0x5180f322
Ausnahmecode: 0xc0000005
Fehleroffset: 0x62ddcc49
ID des fehlerhaften Prozesses: 0x66c
Startzeit der fehlerhaften Anwendung: 0xPictureViewer.exe0
Pfad der fehlerhaften Anwendung: PictureViewer.exe1
Pfad des fehlerhaften Moduls: PictureViewer.exe2
Berichtskennung: PictureViewer.exe3
Error: (05/08/2014 08:11:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: gnubg.exe, Version: 0.0.0.0, Zeitstempel: 0x491c05cc
Name des fehlerhaften Moduls: gnubg.exe, Version: 0.0.0.0, Zeitstempel: 0x491c05cc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00074f47
ID des fehlerhaften Prozesses: 0x1164
Startzeit der fehlerhaften Anwendung: 0xgnubg.exe0
Pfad der fehlerhaften Anwendung: gnubg.exe1
Pfad des fehlerhaften Moduls: gnubg.exe2
Berichtskennung: gnubg.exe3
Error: (04/28/2014 07:26:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Avira.OE.ServiceHost.exe, Version: 1.0.5218.31571, Zeitstempel: 0x534d5f16
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0x848
Startzeit der fehlerhaften Anwendung: 0xAvira.OE.ServiceHost.exe0
Pfad der fehlerhaften Anwendung: Avira.OE.ServiceHost.exe1
Pfad des fehlerhaften Moduls: Avira.OE.ServiceHost.exe2
Berichtskennung: Avira.OE.ServiceHost.exe3
Error: (04/28/2014 07:26:15 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: Avira.OE.ServiceHost.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.AccessViolationException
Stack:
at Avira.OE.AvConnector.Interface.ILicensePlugin.GetLicenseType()
at Avira.OE.AvConnector.AvStatusReporter.GetLicenseType()
at Avira.OE.ServiceHost.ComputerAndServicesInfo.CreateMessagePayload()
at Avira.OE.ServiceHost.UpdateAvailabilityChecker.CheckForUpdate()
at Avira.OE.ServiceHost.UpdateAvailabilityChecker.OnRecurrentUpdateCheck(System.Object)
at System.Threading.TimerQueueTimer.CallCallbackInContext(System.Object)
at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
at System.Threading.TimerQueueTimer.CallCallback()
at System.Threading.TimerQueueTimer.Fire()
at System.Threading.TimerQueue.FireQueuedTimerCompletion(System.Object)
at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
at System.Threading.ThreadPoolWorkQueue.Dispatch()
at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()
Error: (04/12/2014 05:55:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: burningstudio12.exe, Version: 12.0.5.12, Zeitstempel: 0x51010dbc
Name des fehlerhaften Moduls: brtcdau.dll, Version: 11.0.3.0, Zeitstempel: 0x51010d6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x008000a4
ID des fehlerhaften Prozesses: 0x10e8
Startzeit der fehlerhaften Anwendung: 0xburningstudio12.exe0
Pfad der fehlerhaften Anwendung: burningstudio12.exe1
Pfad des fehlerhaften Moduls: burningstudio12.exe2
Berichtskennung: burningstudio12.exe3
Error: (04/12/2014 02:13:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: gnubg.exe, Version: 0.0.0.0, Zeitstempel: 0x491c05cc
Name des fehlerhaften Moduls: gnubg.exe, Version: 0.0.0.0, Zeitstempel: 0x491c05cc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00074f47
ID des fehlerhaften Prozesses: 0x36c
Startzeit der fehlerhaften Anwendung: 0xgnubg.exe0
Pfad der fehlerhaften Anwendung: gnubg.exe1
Pfad des fehlerhaften Moduls: gnubg.exe2
Berichtskennung: gnubg.exe3
Error: (04/10/2014 07:38:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: gnubg.exe, Version: 0.0.0.0, Zeitstempel: 0x491c05cc
Name des fehlerhaften Moduls: gnubg.exe, Version: 0.0.0.0, Zeitstempel: 0x491c05cc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00074f47
ID des fehlerhaften Prozesses: 0x768
Startzeit der fehlerhaften Anwendung: 0xgnubg.exe0
Pfad der fehlerhaften Anwendung: gnubg.exe1
Pfad des fehlerhaften Moduls: gnubg.exe2
Berichtskennung: gnubg.exe3
Error: (04/07/2014 06:31:56 PM) (Source: Avira Service Host) (EventID: 0) (User: )
Description: Service cannot be started. Der Dienstprozess konnte keine Verbindung mit dem Dienstcontroller herstellen
Error: (04/05/2014 03:21:13 PM) (Source: MsiInstaller) (EventID: 11925) (User: Jens-PC)
Description: Product: Adobe AIR -- Error 1925. You do not have sufficient privileges to complete this installation for all users of the machine. Log on as administrator and then retry this installation.
System errors:
=============
Error: (06/01/2014 09:19:06 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (06/01/2014 09:19:06 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1330
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (05/30/2014 05:57:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (05/30/2014 05:57:31 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1330
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (05/30/2014 09:59:06 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (05/30/2014 09:59:06 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1330
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (05/30/2014 09:42:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (05/30/2014 09:42:51 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1330
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (05/29/2014 00:47:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (05/29/2014 00:47:00 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1330
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Microsoft Office Sessions:
=========================
Error: (05/25/2014 08:01:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: gnubg.exe0.0.0.0491c05ccgnubg.exe0.0.0.0491c05ccc000000500074f47130801cf7841f06f0a10C:\Program Files (x86)\gnubg\gnubg.exeC:\Program Files (x86)\gnubg\gnubg.exea22111d0-e436-11e3-b317-001e8cc4ce8d
Error: (05/10/2014 07:47:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: PictureViewer.exe7.74.80.865180f08eQuickTime.qts_unloaded0.0.0.05180f322c000000562ddcc4966c01cf6c77f4aca950C:\Program Files (x86)\QuickTime\PictureViewer.exeQuickTime.qts355dd140-d86b-11e3-9f7a-001e8cc4ce8d
Error: (05/08/2014 08:11:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: gnubg.exe0.0.0.0491c05ccgnubg.exe0.0.0.0491c05ccc000000500074f47116401cf6ae7e0a65320C:\Program Files (x86)\gnubg\gnubg.exeC:\Program Files (x86)\gnubg\gnubg.exe3d5b7540-d6dc-11e3-925d-001e8cc4ce8d
Error: (04/28/2014 07:26:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Avira.OE.ServiceHost.exe1.0.5218.31571534d5f16unknown0.0.0.000000000c00000050000000084801cf62a1a90cf0c0C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exeunknown9f119f20-ce95-11e3-9f6e-001e8cc4ce8d
Error: (04/28/2014 07:26:15 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: Avira.OE.ServiceHost.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.AccessViolationException
Stack:
at Avira.OE.AvConnector.Interface.ILicensePlugin.GetLicenseType()
at Avira.OE.AvConnector.AvStatusReporter.GetLicenseType()
at Avira.OE.ServiceHost.ComputerAndServicesInfo.CreateMessagePayload()
at Avira.OE.ServiceHost.UpdateAvailabilityChecker.CheckForUpdate()
at Avira.OE.ServiceHost.UpdateAvailabilityChecker.OnRecurrentUpdateCheck(System.Object)
at System.Threading.TimerQueueTimer.CallCallbackInContext(System.Object)
at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
at System.Threading.TimerQueueTimer.CallCallback()
at System.Threading.TimerQueueTimer.Fire()
at System.Threading.TimerQueue.FireQueuedTimerCompletion(System.Object)
at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
at System.Threading.ThreadPoolWorkQueue.Dispatch()
at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()
Error: (04/12/2014 05:55:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: burningstudio12.exe12.0.5.1251010dbcbrtcdau.dll11.0.3.051010d6ec0000005008000a410e801cf56670ee07120C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 12\burningstudio12.exeC:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 12\brtcdau.dlld7816710-c25a-11e3-a242-001e8cc4ce8d
Error: (04/12/2014 02:13:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: gnubg.exe0.0.0.0491c05ccgnubg.exe0.0.0.0491c05ccc000000500074f4736c01cf56469ee551d0C:\Program Files (x86)\gnubg\gnubg.exeC:\Program Files (x86)\gnubg\gnubg.exed89aaf90-c23b-11e3-9c66-001e8cc4ce8d
Error: (04/10/2014 07:38:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: gnubg.exe0.0.0.0491c05ccgnubg.exe0.0.0.0491c05ccc000000500074f4776801cf54e2a43320f0C:\Program Files (x86)\gnubg\gnubg.exeC:\Program Files (x86)\gnubg\gnubg.exee6dd8b60-c0d6-11e3-b8bd-001e8cc4ce8d
Error: (04/07/2014 06:31:56 PM) (Source: Avira Service Host) (EventID: 0) (User: )
Description: Service cannot be started. Der Dienstprozess konnte keine Verbindung mit dem Dienstcontroller herstellen
Error: (04/05/2014 03:21:13 PM) (Source: MsiInstaller) (EventID: 11925) (User: Jens-PC)
Description: Product: Adobe AIR -- Error 1925. You do not have sufficient privileges to complete this installation for all users of the machine. Log on as administrator and then retry this installation.(NULL)(NULL)(NULL)(NULL)(NULL)
==================== Memory info ===========================
Percentage of memory in use: 66%
Total physical RAM: 4094.49 MB
Available physical RAM: 1355.32 MB
Total Pagefile: 8187.16 MB
Available Pagefile: 3661.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:455.57 GB) (Free:292.01 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Bibliothek) (Fixed) (Total:465.76 GB) (Free:50.1 GB) NTFS
Drive e: (Windows Vista) (Fixed) (Total:10.19 GB) (Free:1.4 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive g: (MyDrive) (Fixed) (Total:931.51 GB) (Free:453.51 GB) NTFS
Drive m: (Daten_Gamma) (Fixed) (Total:298.09 GB) (Free:6.53 GB) NTFS
Drive n: (Movies) (Fixed) (Total:74.52 GB) (Free:4.58 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=456 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=10 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 466 GB) (Disk ID: 260DE4C2)
Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (Size: 932 GB) (Disk ID: 14F5C759)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)
========================================================
Disk: 3 (MBR Code: Windows XP) (Size: 75 GB) (Disk ID: 49D3D9F7)
Partition 1: (Not Active) - (Size=75 GB) - (Type=07 NTFS)
========================================================
Disk: 4 (Size: 298 GB) (Disk ID: 0A01E9E4)
Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS)
==================== End Of Log ============================ und last not least Gmer.txt Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-06-02 17:55:24
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000067 Hitachi_ rev.V56O 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Jens\AppData\Local\Temp\kxldypoc.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800033f0000 64 bytes [00, 00, 1C, 02, 41, 66, 64, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 594 fffff800033f0042 4 bytes [00, 00, 00, 00]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[3328] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000075e78791 5 bytes JMP 00000001663c7e6f
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5752] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000768a1465 2 bytes [8A, 76]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5752] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768a14bb 2 bytes [8A, 76]
.text ... * 2
.text C:\Users\Jens\AppData\Roaming\Dropbox\bin\Dropbox.exe[6372] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 00000000768a1465 2 bytes [8A, 76]
.text C:\Users\Jens\AppData\Roaming\Dropbox\bin\Dropbox.exe[6372] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 00000000768a14bb 2 bytes [8A, 76]
.text ... * 2
.text C:\Users\Jens\Desktop\Defogger.exe[5560] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000768a1465 2 bytes [8A, 76]
.text C:\Users\Jens\Desktop\Defogger.exe[5560] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768a14bb 2 bytes [8A, 76]
.text ... * 2
---- Processes - GMER 2.1 ----
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\python27.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156] (Python Core/Python Software Foundation)(2014-06-01 07:19:33) 000000001e000000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32api.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:28) 000000001e8c0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\pywintypes27.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:32) 000000001e7a0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\pythoncom27.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:27) 0000000000370000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_socket.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:28) 0000000000240000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_ssl.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:32) 0000000010000000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32com.shell.shell.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:27) 000000001e800000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_hashlib.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:31) 0000000002030000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._core_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:27) 0000000002f50000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wxbase294u_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156] (wxWidgets for MSW/wxWidgets development team)(2014-06-01 07:19:33) 0000000003080000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wxbase294u_net_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156] (wxWidgets for MSW/wxWidgets development team)(2014-06-01 07:19:34) 0000000000290000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wxmsw294u_core_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156] (wxWidgets for MSW/wxWidgets development team)(2014-06-01 07:19:34) 0000000003270000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wxmsw294u_adv_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156] (wxWidgets for MSW/wxWidgets development team)(2014-06-01 07:19:34) 0000000003710000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._gdi_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:32) 0000000003950000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._windows_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:31) 00000000042c0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wxmsw294u_html_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156] (wxWidgets for MSW/wxWidgets development team)(2014-06-01 07:19:35) 0000000002790000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._controls_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:30) 0000000004520000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._misc_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:27) 0000000004630000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_elementtree.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:28) 000000001d100000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\pyexpat.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:30) 0000000001ee0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\pysqlite2._sqlite.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:28) 0000000003a20000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_ctypes.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:28) 000000001d1a0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32file.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:29) 000000001ea10000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32security.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:29) 000000001ec80000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32event.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:30) 000000001e9b0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32inet.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:30) 000000001eaa0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._html2.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:31) 00000000046f0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wxmsw294u_webview_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156] (wxWidgets for MSW/wxWidgets development team)(2014-06-01 07:19:34) 0000000004710000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32gui.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:28) 000000001ea40000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32crypt.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:27) 000000001e980000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\_multiprocessing.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:32) 0000000002830000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._wizard.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:26) 0000000005700000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\select.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:30) 0000000005df0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32pipe.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:31) 000000001eb90000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\unicodedata.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:30) 0000000005fc0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32pdh.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:31) 000000001eb60000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32process.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:31) 000000001ebf0000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32profile.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:29) 000000001ec20000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\win32ts.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:27) 000000001ed40000
Library C:\Users\Jens_2\AppData\Local\Temp\_MEI22602\wx._animate.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4156](2014-06-01 07:19:27) 0000000005e00000
Library C:\Users\Jens\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll (*** suspicious ***) @ C:\Users\Jens\AppData\Roaming\Dropbox\bin\Dropbox.exe [6372](2014-01-03 01:09:26) 0000000004180000
Library c:\users\jens\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpil738f.dll (*** suspicious ***) @ C:\Users\Jens\AppData\Roaming\Dropbox\bin\Dropbox.exe [6372](2014-06-01 10:30:09) 0000000003ee0000
Library C:\Users\Jens\AppData\Roaming\Dropbox\bin\libcef.dll (*** suspicious ***) @ C:\Users\Jens\AppData\Roaming\Dropbox\bin\Dropbox.exe [6372](2013-08-23 19:01:44) 00000000535a0000
Library C:\Users\Jens\AppData\Roaming\Dropbox\bin\icudt.dll (*** suspicious ***) @ C:\Users\Jens\AppData\Roaming\Dropbox\bin\Dropbox.exe [6372] (ICU Data DLL/The ICU Project)(2013-08-23 19:01:42) 0000000052c10000
---- EOF - GMER 2.1 ---- ...danke fürs Lesen :daumenhoc
Ich habe ncohmal ein Quickscan mit Anvi SmartDefender gemacht - der kam nur auf 6 Security Threats:
1. PUP.OptionaLinstallCoreA - Pfad: HKCU\Software\InstallCore|tb
2. PUPOptionaLBabylon.A - Pfad: HKCU\Software\BabSolution\Updater
3. PUP.OptionaLSearchProtoect - Pfad: HKCU\Software\Microsoft\Interne...aa-5d3f-42ee-b79c-185a7020515b}
4. PUP.OptionLinstallCoreA - Pfad: HKCU\Software\InstallCore\1I1T1Q1S
5. Security.Hijack - Pfad: HKLM\SOFTWARE\Microsoft\Wondow...ile Execution Options\dw20.exe
6. PUP.OptionaLStartPage - Pfad: HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page
Des Weiteren:
7. W32/Ramnit.E - Pfad: C:\Program Files (x86)\Canon\PhotoStitch\fkodak.dll
8. PUP.OptionaLAmazGame - Pfad C:\Program Files (x86)\Mobogenie\mgusb.exe
9. Trojan.Agent - Pfad: C:\Program Files (x86)\WISO\Steuersoftware 2012\buhlqs_de.exe
10. Trojan.Agent - Pfad: C:\Program Files (x86)\WISO\Steuersoftware 2013\buhlqs_de.exe
11. Trojan.Agent - Pfad: C:\Program Files (x86)\WISO\Steuersoftware 2014\buhlqs_de.exe
12. PUP.OptionaLConduit - Pfad: C:\Users\Christoph\AppData\LocalLow\TVersitybar\ldrtbTVe2.dll
13. PUP.OptionaLConduit - Pfad: C:\Users\Christoph\AppData\LocalLow\TVersitybar\tbTVe2.dll
14. PUP.OptionaLBabylon - Pfad: C:\Users\Jens\AppData\Local\Temp\uninst1.exe
15. PUP.OptionaLBabylon - Pfad: C:\Users\Jens\AppData\Roaming...A9424329F36B64B7C\DeltaTB.exe
16. PUP.OptionaLBabylon - Pfad: C:\Users\Jens\AppData\Roaming...0BE71DA385DFE580E\DeltaTB.exe
Das sind bisher alle...Scanning Process 43% complete
Kann ich das Problem nochmal nach oben heben?
Ich hab noch zwei:
18.TrojanGeneric.KD - Pfad: C:\Windows\winsxs\wow64_microso...e_c0db7c4ff1842c59\csccompui.dll
19. PSW.OnLineGames - Pfad: E:\hp\Drv\APP00581\src\LS_HSI.m...A88_1298_4139_BC51_C215F726A6C7
:twak::twak::twak: |