| elisadaphne |  10.01.2015 18:54 |        Hallo Schrauber, danke dir. Habe alles nach deiner Anleitung durchgeführt.  
Hier die Ergebnisse.  
Mbam:    Code:  
 Malwarebytes Anti-Malware 
www.malwarebytes.org   
Suchlauf Datum: 10.01.2015 
Suchlauf-Zeit: 16:48:15 
Logdatei: mbam.txt 
Administrator: Ja   
Version: 2.00.4.1028 
Malware Datenbank: v2015.01.10.13 
Rootkit Datenbank: v2015.01.07.01 
Lizenz: Testversion 
Malware Schutz: Aktiviert 
Bösartiger Webseiten Schutz: Aktiviert 
Selbstschutz: Deaktiviert   
Betriebssystem: Windows 8.1 
CPU: x64 
Dateisystem: NTFS 
Benutzer: Elisa   
Suchlauf-Art: Bedrohungs-Suchlauf 
Ergebnis: Abgeschlossen 
Durchsuchte Objekte: 363528 
Verstrichene Zeit: 47 Min, 35 Sek   
Speicher: Aktiviert 
Autostart: Aktiviert 
Dateisystem: Aktiviert 
Archive: Aktiviert 
Rootkits: Deaktiviert 
Heuristik: Aktiviert 
PUP: Aktiviert 
PUM: Aktiviert   
Prozesse: 0 
(Keine schädliche Elemente erkannt)   
Module: 0 
(Keine schädliche Elemente erkannt)   
Registrierungsschlüssel: 0 
(Keine schädliche Elemente erkannt)   
Registrierungswerte: 0 
(Keine schädliche Elemente erkannt)   
Registrierungsdaten: 0 
(Keine schädliche Elemente erkannt)   
Ordner: 0 
(Keine schädliche Elemente erkannt)   
Dateien: 0 
(Keine schädliche Elemente erkannt)   
Physische Sektoren: 0 
(Keine schädliche Elemente erkannt)     
(end)   adw   Code:  
 # AdwCleaner v4.107 - Bericht erstellt am 10/01/2015 um 17:59:05 
# Aktualisiert 07/01/2015 von Xplode 
# Database : 2015-01-03.1 [Live] 
# Betriebssystem : Windows 8.1  (64 bits) 
# Benutzername : Elisa - MASCHINE 
# Gestartet von : C:\Users\Elisa\AppData\Local\Microsoft\Windows\INetCache\IE\C9IMR004\AdwCleaner_4.107.exe 
# Option : Löschen   
***** [ Dienste ] *****   
Dienst Gelöscht : APNMCP   
***** [ Dateien / Ordner ] *****   
Ordner Gelöscht : C:\ProgramData\apn 
Ordner Gelöscht : C:\ProgramData\AskPartnerNetwork 
Ordner Gelöscht : C:\Program Files (x86)\AskPartnerNetwork 
Ordner Gelöscht : C:\Users\Elisa\AppData\Local\Temp\apn 
Ordner Gelöscht : C:\Users\Elisa\AppData\Local\AskPartnerNetwork 
Datei Gelöscht : C:\Users\Elisa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk 
Datei Gelöscht : C:\Users\Elisa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster.lnk 
Datei Gelöscht : C:\Users\Elisa\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk   
***** [ Tasks ] *****     
***** [ Verknüpfungen ] *****   
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Start Now Technology.lnk   
***** [ Registrierungsdatenbank ] *****   
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon] 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D} 
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4} 
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3870947B-97B1-45EC-A23B-CA37E25D38AC} 
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3870947B-97B1-45EC-A23B-CA37E25D38AC} 
Schlüssel Gelöscht : HKCU\Software\AskPartnerNetwork 
Schlüssel Gelöscht : HKLM\SOFTWARE\AskPartnerNetwork 
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\AskPartnerNetwork   
***** [ Browser ] *****   
-\\ Internet Explorer v11.0.9600.17416     
-\\ Mozilla Firefox v   
[c63dxojs.default\prefs.js] - Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.startfenster.de"); 
[c63dxojs.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"147eeac56576-092cce44ba378f8-42504336-0-147eeac56581\""); 
[c63dxojs.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.SAUTH_expires_at", "1413199967"); 
[c63dxojs.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.SAUTH_rndsnr", "\"026fe100a32f41b35d65fb0916be073457e3029f\""); 
[c63dxojs.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.SAUTH_userid", "4312333019"); 
[c63dxojs.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.SAUTH_utoken", "\"614ae79d3602cb0c993b429d89c68a64a4e19413\""); 
[c63dxojs.default\prefs.js] - Zeile gelöscht : user_pref("extensions.safesearch.install", "1408458577519");   
*************************   
AdwCleaner[R0].txt - [4172 octets] - [10/01/2015 17:52:57] 
AdwCleaner[S0].txt - [4068 octets] - [10/01/2015 17:59:05]   
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4128 octets] ##########   JRT:   Code:  
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Junkware Removal Tool (JRT) by Thisisu 
Version: 6.4.1 (12.28.2014:1) 
OS: Windows 8.1 x64 
Ran by Elisa on 10.01.2015 at 18:20:24,63 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~         
~~~ Services       
~~~ Registry Values       
~~~ Registry Keys       
~~~ Files       
~~~ Folders       
~~~ Event Viewer Logs were cleared           
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Scan was completed on 10.01.2015 at 18:29:10,75 
End of JRT log 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~   FRST Editor:  
FRST Logfile:  
FRST Logfile:   Code:  
 Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-01-2015 
Ran by Elisa (administrator) on MASCHINE on 10-01-2015 18:39:05 
Running from C:\Users\Elisa\Downloads 
Loaded Profile: Elisa (Available profiles: Elisa) 
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) 
Internet Explorer Version 11 (Default browser: IE) 
Boot Mode: Normal 
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/   
==================== Processes (Whitelisted) =================   
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)   
(AMD) C:\Windows\System32\atiesrxx.exe 
(AMD) C:\Windows\System32\atieclxx.exe 
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe 
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE 
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 
() C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe 
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe 
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe 
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe 
(Microsoft Corporation) C:\Windows\System32\dasHost.exe 
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe 
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe 
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe 
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe 
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe 
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 
(Secure Banking) C:\Program Files (x86)\Secure Banking\SecureBanking.exe 
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe 
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe 
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE 
() C:\Program Files (x86)\Secure Banking\sbservice.exe 
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe 
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe 
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe 
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe 
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe 
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe 
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe 
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe 
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe 
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe 
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\core-static\MOM.exe 
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\core-static\CCC.exe 
(Microsoft Corporation) C:\Windows\System32\dllhost.exe 
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe     
==================== Registry (Whitelisted) ==================   
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)   
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188040 2013-05-11] (Realtek Semiconductor) 
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2780400 2014-01-16] (Synaptics Incorporated) 
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642816 2013-06-20] (Advanced Micro Devices, Inc.) 
HKLM-x32\...\Run: [HP CoolSense] => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1343904 2012-11-05] (Hewlett-Packard Development Company, L.P.) 
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-17] (Avira Operations GmbH & Co. KG) 
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.) 
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [475448 2014-03-26] (Hewlett-Packard Development Company, L.P.) 
HKLM-x32\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020192 2014-06-25] (Wondershare) 
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020192 2014-06-25] (Wondershare) 
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.) 
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [126240 2014-04-01] (Hewlett-Packard Company) 
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) 
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-12-16] (Hewlett-Packard) 
HKU\S-1-5-21-413923388-1701970662-873926003-1002\...\Run: [SkyDrive] => C:\Users\Elisa\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [277672 2014-09-25] (Microsoft Corporation) 
HKU\S-1-5-21-413923388-1701970662-873926003-1002\...\Run: [SecureBanking] => C:\Program Files (x86)\Secure Banking\SecureBanking.exe [507904 2013-06-30] (Secure Banking) 
HKU\S-1-5-21-413923388-1701970662-873926003-1002\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020192 2014-06-25] (Wondershare) 
HKU\S-1-5-21-413923388-1701970662-873926003-1002\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [468192 2014-10-15] (Sony) 
HKU\S-1-5-21-413923388-1701970662-873926003-1002\...\MountPoints2: {90ea1c52-08f0-11e4-be97-2c44fdbb0f5a} - "E:\Startme.exe"  
HKU\S-1-5-21-413923388-1701970662-873926003-1002\...\MountPoints2: {a945960c-7c86-11e4-bea4-2c44fdbb0f5a} - "E:\LaunchU3.exe" -a 
HKU\S-1-5-21-413923388-1701970662-873926003-1002\...\MountPoints2: {d4940e31-8539-11e4-bea6-2c44fdbb0f5a} - "E:\LaunchU3.exe" -a 
Startup: C:\Users\Elisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk 
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) 
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File 
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File 
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File 
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File 
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File 
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File   
==================== Internet (Whitelisted) ====================   
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)   
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 
HKU\S-1-5-21-413923388-1701970662-873926003-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ 
HKU\S-1-5-21-413923388-1701970662-873926003-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 
SearchScopes: HKLM -> {742F5B54-2814-4148-98A2-519FD76D0944} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} 
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} 
SearchScopes: HKLM-x32 -> {742F5B54-2814-4148-98A2-519FD76D0944} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} 
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =  
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =  
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =  
SearchScopes: HKU\S-1-5-21-413923388-1701970662-873926003-1002 -> {742F5B54-2814-4148-98A2-519FD76D0944} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} 
SearchScopes: HKU\S-1-5-21-413923388-1701970662-873926003-1002 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} 
BHO: Avira SearchFree Toolbar -> {41564952-412D-5637-4300-7A786E7484D7} -> "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll" No File 
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) 
BHO-x32: Avira SearchFree Toolbar -> {41564952-412D-5637-4300-7A786E7484D7} -> "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll" No File 
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) 
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll" No File 
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll" No File 
Toolbar: HKU\S-1-5-21-413923388-1701970662-873926003-1002 -> Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll" No File 
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1   
FireFox: 
======== 
FF ProfilePath: C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\c63dxojs.default 
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll () 
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) 
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll () 
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.) 
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () 
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) 
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) 
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF SearchPlugin: C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\c63dxojs.default\searchplugins\avira-safesearch.xml 
FF SearchPlugin: C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\c63dxojs.default\searchplugins\suchmaschine.xml 
FF Extension: Avira Browser Safety - C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\c63dxojs.default\Extensions\abs@avira.com [2014-12-12] 
FF Extension: NoScript - C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\c63dxojs.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-04] 
FF Extension: Adblock Plus - C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\c63dxojs.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-04] 
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]   
Chrome:  
======= 
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path   
==================== Services (Whitelisted) =================   
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)   
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [103424 2013-06-20] () [File not signed] 
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-06-20] (Advanced Micro Devices, Inc.) [File not signed] 
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-17] (Avira Operations GmbH & Co. KG) 
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-17] (Avira Operations GmbH & Co. KG) 
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584 2014-12-17] (Avira Operations GmbH & Co. KG) 
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) 
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] 
R2 HPWMISVC; c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [469304 2014-03-26] (Hewlett-Packard Development Company, L.P.) 
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) 
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) 
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [224840 2013-05-10] (Realtek Semiconductor) 
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-12-28] (Microsoft Corporation) 
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) 
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)   
==================== Drivers (Whitelisted) ====================   
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)   
R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17504 2013-02-08] (Advanced Micro Devices, INC.) 
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98744 2013-04-24] (Advanced Micro Devices) 
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-09] (Avira Operations GmbH & Co. KG) 
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-09] (Avira Operations GmbH & Co. KG) 
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG) 
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43064 2014-10-09] (Avira Operations GmbH & Co. KG) 
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) 
S3 BTHUSB; C:\Windows\System32\Drivers\BTHUSB.sys [81920 2013-12-28] (Microsoft Corporation) [File not signed] 
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) 
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-10] (Malwarebytes Corporation) 
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation) 
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [290520 2013-12-28] (Realtek Semiconductor Corp.) 
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204424 2013-12-02] (Ralink Technology, Corp.) 
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [29424 2013-04-24] (Synaptics Incorporated) 
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [33008 2013-04-24] (Synaptics Incorporated) 
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed] 
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) 
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.) 
R3 WUDFWpdComp; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation) 
S3 BtAudioBusSrv; \SystemRoot\System32\Drivers\BtAudioBus.sys [X] 
S3 BthL2caScoIfSrv; \SystemRoot\System32\Drivers\BtL2caScoIf.sys [X] 
S3 btUrbFilterDrv; \SystemRoot\System32\Drivers\IvtUrbBtFlt.sys [X]   
==================== NetSvcs (Whitelisted) ===================   
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)     
==================== One Month Created Files and Folders ========   
(If an entry is included in the fixlist, the file\folder will be moved.)   
2015-01-10 18:36 - 2015-01-10 18:36 - 00000614 _____ () C:\Users\Elisa\Desktop\Jwrmt.txt 
2015-01-10 18:29 - 2015-01-10 18:29 - 00000614 _____ () C:\Users\Elisa\Desktop\JRT.txt 
2015-01-10 18:20 - 2015-01-10 18:20 - 00000000 ____D () C:\WINDOWS\ERUNT 
2015-01-10 18:13 - 2015-01-10 18:13 - 00004224 _____ () C:\Users\Elisa\Desktop\AdwCleaner[S0].txt 
2015-01-10 17:52 - 2015-01-10 18:00 - 00000000 ____D () C:\AdwCleaner 
2015-01-10 17:49 - 2015-01-10 17:49 - 00001188 _____ () C:\Users\Elisa\Desktop\mbam.txt 
2015-01-10 16:45 - 2015-01-10 18:11 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 
2015-01-10 16:44 - 2015-01-10 16:44 - 00001121 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 
2015-01-10 16:44 - 2015-01-10 16:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 
2015-01-10 16:44 - 2015-01-10 16:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 
2015-01-10 16:44 - 2015-01-10 16:44 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 
2015-01-10 16:44 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 
2015-01-10 16:44 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 
2015-01-10 16:44 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 
2015-01-08 18:45 - 2015-01-09 17:54 - 00025295 _____ () C:\Users\Elisa\Downloads\Addition.txt 
2015-01-08 18:42 - 2015-01-10 18:40 - 00018767 _____ () C:\Users\Elisa\Downloads\FRST.txt 
2015-01-08 18:39 - 2015-01-10 18:39 - 00000000 ____D () C:\FRST 
2015-01-08 18:39 - 2015-01-08 18:39 - 02124288 _____ (Farbar) C:\Users\Elisa\Downloads\FRST64.exe 
2015-01-07 17:27 - 2015-01-07 17:27 - 00000000 ____D () C:\Users\Elisa\AppData\Roaming\dvdcss 
2015-01-07 17:25 - 2015-01-07 18:48 - 00000000 ____D () C:\Users\Elisa\AppData\Roaming\vlc 
2015-01-07 17:24 - 2015-01-08 18:44 - 00000000 ____D () C:\Program Files (x86)\VideoLAN 
2015-01-07 17:22 - 2015-01-07 17:23 - 24954112 _____ () C:\Users\Elisa\Downloads\vlc-2.1.5-win32.exe 
2015-01-04 16:03 - 2015-01-04 16:03 - 01054912 _____ (Adobe) C:\Users\Elisa\Downloads\install_flashplayer16x32au_mssd_aaa_aih.exe 
2014-12-19 14:53 - 2014-12-19 14:53 - 00600202 _____ () C:\Users\Elisa\Desktop\~PI6082.tmp 
2014-12-19 11:55 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 
2014-12-19 11:55 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 
2014-12-15 15:39 - 2014-12-15 15:39 - 00002673 _____ () C:\Users\Elisa\Documents\Mein Film2.wlmp 
2014-12-15 15:29 - 2014-12-22 15:06 - 00032256 ___SH () C:\Users\Elisa\Desktop\Thumbs.db 
2014-12-15 12:55 - 2014-12-15 12:55 - 00002668 _____ () C:\Users\Elisa\Documents\Mein Film.wlmp 
2014-12-15 09:53 - 2015-01-05 10:57 - 00000000 ____D () C:\Users\Elisa\Desktop\Videos Komprimiert 
2014-12-13 13:49 - 2014-11-26 22:10 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 
2014-12-13 13:49 - 2014-11-26 22:10 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 
2014-12-13 13:44 - 2014-12-13 13:44 - 00000000 ____D () C:\WINDOWS\system32\appraiser 
2014-12-12 17:04 - 2014-11-10 03:29 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupStatusProvider.dll 
2014-12-12 17:04 - 2014-11-10 02:51 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceSetupStatusProvider.dll 
2014-12-12 17:04 - 2014-10-31 00:39 - 01970432 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 
2014-12-12 17:04 - 2014-10-31 00:38 - 01612992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 
2014-12-12 17:03 - 2014-12-04 00:37 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 
2014-12-12 17:03 - 2014-12-04 00:09 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 
2014-12-12 17:03 - 2014-12-03 00:09 - 01083392 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 
2014-12-12 17:03 - 2014-12-03 00:09 - 00740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 
2014-12-12 17:03 - 2014-12-03 00:09 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 
2014-12-12 17:03 - 2014-12-03 00:09 - 00396288 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 
2014-12-12 17:03 - 2014-12-03 00:09 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 
2014-12-12 17:03 - 2014-11-07 05:16 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 
2014-12-12 17:03 - 2014-11-07 04:26 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 
2014-12-12 17:02 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 
2014-12-12 17:02 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 
2014-12-12 17:02 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 
2014-12-12 17:02 - 2014-11-22 03:49 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec 
2014-12-12 17:02 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 
2014-12-12 17:02 - 2014-11-22 03:35 - 00812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 
2014-12-12 17:02 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 
2014-12-12 17:02 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 
2014-12-12 17:02 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 
2014-12-12 17:02 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 
2014-12-12 17:02 - 2014-11-22 03:06 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec 
2014-12-12 17:02 - 2014-11-22 03:06 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 
2014-12-12 17:02 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 
2014-12-12 17:02 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 
2014-12-12 17:02 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 
2014-12-12 17:02 - 2014-11-22 02:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 
2014-12-12 17:02 - 2014-11-22 02:55 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 
2014-12-12 17:02 - 2014-11-22 02:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 
2014-12-12 17:02 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 
2014-12-12 17:02 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 
2014-12-12 17:02 - 2014-11-22 02:49 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 
2014-12-12 17:02 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 
2014-12-12 17:02 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 
2014-12-12 17:02 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 
2014-12-12 17:02 - 2014-11-22 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 
2014-12-12 17:02 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 
2014-12-12 17:02 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 
2014-12-12 17:02 - 2014-11-22 02:29 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 
2014-12-12 17:02 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 
2014-12-12 17:02 - 2014-11-22 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 
2014-12-12 17:02 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 
2014-12-12 17:02 - 2014-11-22 02:23 - 00326656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 
2014-12-12 17:02 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 
2014-12-12 17:02 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 
2014-12-12 17:02 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 
2014-12-12 17:02 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 
2014-12-12 17:02 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 
2014-12-12 17:02 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 
2014-12-12 17:02 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 
2014-12-12 17:02 - 2014-11-01 00:57 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 
2014-12-12 17:02 - 2014-11-01 00:47 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 
2014-12-12 17:02 - 2014-10-13 03:43 - 00238912 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 
2014-12-12 17:02 - 2014-10-13 03:43 - 00153920 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 
2014-12-12 17:02 - 2014-10-13 03:43 - 00086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 
2014-12-12 17:02 - 2014-10-13 03:43 - 00039744 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 
2014-12-12 10:13 - 2014-12-12 10:13 - 00000000 __SHD () C:\Users\Elisa\AppData\Local\EmieBrowserModeList   
==================== One Month Modified Files and Folders =======   
(If an entry is included in the fixlist, the file\folder will be moved.)   
2015-01-10 18:29 - 2013-12-25 13:50 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-413923388-1701970662-873926003-1002 
2015-01-10 18:28 - 2013-12-28 09:01 - 01988486 _____ () C:\WINDOWS\WindowsUpdate.log 
2015-01-10 18:17 - 2014-11-11 13:56 - 00003164 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleForElisa 
2015-01-10 18:17 - 2014-11-11 13:56 - 00000350 _____ () C:\WINDOWS\Tasks\HPCeeScheduleForElisa.job 
2015-01-10 18:16 - 2013-12-28 08:37 - 00000000 ____D () C:\Users\Elisa 
2015-01-10 18:16 - 2013-12-25 14:44 - 00000000 ___DO () C:\Users\Elisa\SkyDrive 
2015-01-10 18:16 - 2013-11-14 08:27 - 01980934 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 
2015-01-10 18:16 - 2013-11-14 08:11 - 00842568 _____ () C:\WINDOWS\system32\perfh007.dat 
2015-01-10 18:16 - 2013-11-14 08:11 - 00191764 _____ () C:\WINDOWS\system32\perfc007.dat 
2015-01-10 18:09 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 
2015-01-10 18:08 - 2013-11-13 23:18 - 00039124 _____ () C:\WINDOWS\PFRO.log 
2015-01-10 18:01 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI 
2015-01-10 18:00 - 2013-09-11 11:58 - 00001347 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Start Now Technology.lnk 
2015-01-10 18:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru 
2015-01-10 17:55 - 2013-12-28 13:13 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 
2015-01-10 16:39 - 2014-02-13 12:39 - 00003930 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7043888F-C57E-4759-828D-DD7AB42BF569} 
2015-01-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 
2015-01-08 19:16 - 2014-06-22 00:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 
2015-01-08 18:33 - 2013-12-28 12:56 - 00001469 _____ () C:\Users\Elisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 
2015-01-08 18:29 - 2013-12-28 14:21 - 00000052 _____ () C:\WINDOWS\SysWOW64\DOErrors.log 
2015-01-08 18:29 - 2013-12-28 14:21 - 00000000 _____ () C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 
2015-01-08 18:25 - 2014-11-16 20:17 - 00001160 _____ () C:\Users\Public\Desktop\Avira.lnk 
2015-01-08 18:25 - 2013-12-26 22:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 
2015-01-08 18:25 - 2013-12-26 22:15 - 00000000 ____D () C:\Program Files (x86)\Avira 
2015-01-08 18:25 - 2013-09-11 12:13 - 00000000 ____D () C:\ProgramData\Package Cache 
2015-01-07 17:26 - 2014-11-11 22:49 - 00000000 ____D () C:\Users\Elisa\Desktop\HIOB 
2015-01-04 01:54 - 2013-09-11 12:15 - 00000000 ____D () C:\WINDOWS\Hewlett-Packard 
2015-01-04 01:54 - 2012-08-04 01:02 - 00000000 ____D () C:\SWSetup 
2015-01-04 01:53 - 2013-07-18 16:14 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard 
2014-12-24 19:19 - 2013-12-25 00:32 - 00000000 ____D () C:\Users\Elisa\AppData\Local\Packages 
2014-12-22 12:45 - 2013-08-22 15:46 - 00314643 _____ () C:\WINDOWS\setupact.log 
2014-12-19 13:13 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 
2014-12-16 16:42 - 2014-11-02 15:49 - 00000000 ____D () C:\Users\Elisa\Desktop\MusikUniWeltkrieg 
2014-12-15 12:49 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache 
2014-12-13 13:44 - 2014-07-11 02:04 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 
2014-12-13 13:44 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-RS 
2014-12-13 13:44 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-CS 
2014-12-13 13:44 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions 
2014-12-12 19:04 - 2013-12-25 14:11 - 00000000 ____D () C:\ProgramData\Microsoft Help 
2014-12-12 19:03 - 2013-12-28 02:13 - 00000000 ____D () C:\WINDOWS\system32\MRT 
2014-12-12 18:58 - 2013-12-28 02:13 - 112710672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 
2014-12-11 14:55 - 2013-12-28 13:13 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater   
Some content of TEMP: 
==================== 
C:\Users\Elisa\AppData\Local\Temp\avgnt.exe 
C:\Users\Elisa\AppData\Local\Temp\Extract.exe 
C:\Users\Elisa\AppData\Local\Temp\Quarantine.exe 
C:\Users\Elisa\AppData\Local\Temp\SP63401.exe 
C:\Users\Elisa\AppData\Local\Temp\SP63402.exe 
C:\Users\Elisa\AppData\Local\Temp\SP63534.exe 
C:\Users\Elisa\AppData\Local\Temp\SP63752.exe 
C:\Users\Elisa\AppData\Local\Temp\SP63786.exe 
C:\Users\Elisa\AppData\Local\Temp\sp64126.exe 
C:\Users\Elisa\AppData\Local\Temp\SP64569.exe 
C:\Users\Elisa\AppData\Local\Temp\SP64823.exe 
C:\Users\Elisa\AppData\Local\Temp\SP64825.exe 
C:\Users\Elisa\AppData\Local\Temp\SP64949.exe 
C:\Users\Elisa\AppData\Local\Temp\SP65755.exe 
C:\Users\Elisa\AppData\Local\Temp\SP66078.exe 
C:\Users\Elisa\AppData\Local\Temp\SP66088.exe 
C:\Users\Elisa\AppData\Local\Temp\SP66604.exe 
C:\Users\Elisa\AppData\Local\Temp\SP66764.exe 
C:\Users\Elisa\AppData\Local\Temp\SP67280.exe 
C:\Users\Elisa\AppData\Local\Temp\SP69821.exe 
C:\Users\Elisa\AppData\Local\Temp\sqlite3.dll 
C:\Users\Elisa\AppData\Local\Temp\UninstallHPSA.exe     
==================== Bamital & volsnap Check =================   
(There is no automatic fix for files that do not pass verification.)   
C:\Windows\System32\winlogon.exe => File is digitally signed 
C:\Windows\System32\wininit.exe => File is digitally signed 
C:\Windows\explorer.exe => File is digitally signed 
C:\Windows\SysWOW64\explorer.exe => File is digitally signed 
C:\Windows\System32\svchost.exe => File is digitally signed 
C:\Windows\SysWOW64\svchost.exe => File is digitally signed 
C:\Windows\System32\services.exe => File is digitally signed 
C:\Windows\System32\User32.dll => File is digitally signed 
C:\Windows\SysWOW64\User32.dll => File is digitally signed 
C:\Windows\System32\userinit.exe => File is digitally signed 
C:\Windows\SysWOW64\userinit.exe => File is digitally signed 
C:\Windows\System32\rpcss.dll => File is digitally signed 
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed     
LastRegBack: 2015-01-04 16:13   
==================== End Of Log ============================   --- --- ---  
--- --- ---   
und FRST Addition:   Code:  
 Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-01-2015 
Ran by Elisa at 2015-01-10 18:42:03 
Running from C:\Users\Elisa\Downloads 
Boot Mode: Normal 
==========================================================     
==================== Security Center ========================   
(If an entry is included in the fixlist, it will be removed.)   
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} 
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}   
==================== Installed Programs ======================   
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)   
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) 
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.246 - Adobe Systems Incorporated) 
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.) 
AMD Catalyst Install Manager (HKLM\...\{399CF2C5-569E-98B2-8823-073041A3F9F5}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.) 
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) 
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.) 
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) 
Avira (HKLM-x32\...\{e7c7c227-b742-4878-9425-f09bbf9951db}) (Version: 1.1.27.25527 - Avira Operations & Co. KG) 
Avira (x32 Version: 1.1.27.25527 - Avira Operations & Co. KG) Hidden 
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) 
Avira SearchFree Toolbar (HKLM-x32\...\{41564952-412D-5637-4300-A758B70C1300}) (Version: 12.19.0.3556 - APN, LLC) 
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) 
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden 
Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company) 
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden 
HP 3D DriveGuard (HKLM-x32\...\{13133E99-B0D5-4143-B832-AAD55C62A41C}) (Version: 6.0.19.1 - Hewlett-Packard Company) 
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: 1.0 - Meridian Audio Ltd) 
HP Connected Music (Meridian - player) (HKU\S-1-5-21-413923388-1701970662-873926003-1002\...\HPConnectedMusic) (Version: 1.1 (build 126) hp - Meridian Audio Ltd) 
HP CoolSense (HKLM-x32\...\{11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F}) (Version: 2.10.51 - Hewlett-Packard Company) 
HP Documentation (HKLM-x32\...\{F86C62DC-1600-426B-981C-F398EF7CCB24}) (Version: 1.1.0.0 - Hewlett-Packard) 
HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.6317.4309 - Hewlett-Packard) 
HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) 
HP System Event Utility (HKLM-x32\...\{DEF23826-DB71-4654-BC00-D5D6C20802EA}) (Version: 1.1.4 - Hewlett-Packard Company) 
HP Utility Center (HKLM\...\{2AFEFC93-F0C7-4390-BB51-F914EC546B30}) (Version: 2.1.6 - Hewlett-Packard Company) 
HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company) 
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.) 
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) 
Mediatek Bluetooth (HKLM\...\{66D292E3-6228-3AF1-EDED-6D53C63DBCB7}) (Version: 11.0.748.2 - Mediatek) 
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) 
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft) 
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) 
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) 
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) 
Microsoft OneDrive (HKU\S-1-5-21-413923388-1701970662-873926003-1002\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation) 
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) 
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) 
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) 
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) 
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) 
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) 
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 
OEM Application Profile (HKLM-x32\...\{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}) (Version: 1.00.0000 - Ihr Firmenname) 
Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.45.0 - Mediatek) 
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.29069 - Realtek Semiconductor Corp.) 
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.13.314.2013 - Realtek) 
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6914 - Realtek Semiconductor Corp.) 
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) 
Secure Banking Version 1.5.2 (HKLM-x32\...\{0BEE0AF9-79F3-4C4F-B374-90C0A16BF294}_is1) (Version: 1.5.2 - Hopfgartner Niklas) 
Sony PC Companion 2.10.236 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.236 - Sony) 
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden 
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.13.1 - Synaptics Incorporated) 
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft) 
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft) 
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft) 
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft) 
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)   
==================== Custom CLSID (selected items): ==========================   
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)   
CustomCLSID: HKU\S-1-5-21-413923388-1701970662-873926003-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Elisa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)   
==================== Restore Points  =========================   
19-12-2014 13:08:50 Windows Update 
04-01-2015 01:48:12 HPSF Applying updates   
==================== Hosts content: ==========================   
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)   
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts   
==================== Scheduled Tasks (whitelisted) =============   
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)   
Task: {2927BA42-C7B3-4072-AF60-B5368D9CEC9D} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-11] (Adobe Systems Incorporated) 
Task: {5A794A6E-F3D3-4680-8ABC-AC2AF3EE0ED6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) 
Task: {73EC20AE-722F-4C96-8A3B-68CF131635D6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-10-21] (Hewlett-Packard) 
Task: {99A8722B-4A52-4DA3-987E-6E9F97CB6821} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-12-12] (Microsoft Corporation) 
Task: {9C0EFB4E-FA09-4611-8248-EBD301F20F63} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-10-21] (Hewlett-Packard) 
Task: {AC02DBE8-89E3-4F5E-8920-22DA2B50A18F} - System32\Tasks\HPCeeScheduleForElisa => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13] (Hewlett-Packard) 
Task: {BC088823-9B9A-4BA7-946B-A43C9298358D} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-413923388-1701970662-873926003-1002 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe 
Task: {D61D39E1-EB91-41BB-B12D-4C75F9242E25} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) 
Task: {D71AE830-7714-4921-8212-56EFBFC366F3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) 
Task: {EA7022C5-4F1B-4B78-B186-1C2DB4FA84CF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 
Task: C:\WINDOWS\Tasks\HPCeeScheduleForElisa.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe 
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe   
==================== Loaded Modules (whitelisted) =============   
2014-09-18 10:06 - 2014-09-18 10:06 - 00034304 _____ () C:\WINDOWS\System32\ssm1mlm.dll 
2013-06-20 02:53 - 2013-06-20 02:53 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe 
2013-06-20 02:53 - 2013-06-20 02:53 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 
2013-12-28 06:45 - 2012-09-07 16:30 - 00002560 _____ () C:\Program Files (x86)\Secure Banking\sbservice.exe 
2014-07-28 23:01 - 2014-06-23 08:07 - 00113376 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe 
2013-06-20 02:53 - 2013-06-20 02:53 - 00016896 _____ () C:\Program Files\ATI Technologies\ATI.ACE\a4\AS4.NativeProxy.dll 
2013-06-20 02:53 - 2013-06-20 02:53 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 
2014-07-28 19:31 - 2014-06-25 09:13 - 01457664 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll 
2014-07-28 19:31 - 2014-05-19 16:19 - 00137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll 
2014-07-28 23:01 - 2012-04-30 10:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll 
2014-07-28 23:01 - 2013-09-13 10:02 - 00208896 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll 
2011-07-07 13:54 - 2011-07-07 13:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll 
2014-07-28 23:01 - 2013-05-20 11:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll 
2014-07-28 23:01 - 2010-01-11 15:44 - 00053248 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll 
2013-12-28 06:45 - 2013-06-30 16:01 - 00017920 _____ () C:\Program Files (x86)\Secure Banking\SecureBanking.dll 
2013-12-28 06:45 - 2013-05-26 12:13 - 00008704 _____ () C:\Program Files (x86)\Secure Banking\funcs.dll   
==================== Alternate Data Streams (whitelisted) =========   
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)   
AlternateDataStreams: C:\Users\Elisa\SkyDrive:ms-properties   
==================== Safe Mode (whitelisted) ===================   
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)     
==================== EXE Association (whitelisted) =============   
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)     
==================== MSCONFIG/TASK MANAGER disabled items =========   
(Currently there is no automatic fix for this section.)     
========================= Accounts: ==========================   
Administrator (S-1-5-21-413923388-1701970662-873926003-500 - Administrator - Disabled) 
Elisa (S-1-5-21-413923388-1701970662-873926003-1002 - Administrator - Enabled) => C:\Users\Elisa 
Gast (S-1-5-21-413923388-1701970662-873926003-501 - Limited - Disabled) 
HomeGroupUser$ (S-1-5-21-413923388-1701970662-873926003-1014 - Limited - Enabled)   
==================== Faulty Device Manager Devices =============   
Name:  
Description:  
Class Guid:  
Manufacturer:  
Service:  
Problem: : The drivers for this device are not installed. (Code 28) 
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.     
==================== Event log errors: =========================   
Application errors: 
================== 
Error: (01/10/2015 06:29:18 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MASCHINE) 
Description: Bei der Aktivierung der App „Microsoft.Reader_8wekyb3d8bbwe!Microsoft.Reader“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.     
System errors: 
=============   
Microsoft Office Sessions: 
=========================   
CodeIntegrity Errors: 
=================================== 
  Date: 2014-01-29 17:36:31.802 
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\BtL2caScoIf.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.   
  Date: 2014-01-16 14:50:55.414 
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\BtL2caScoIf.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.   
  Date: 2014-01-09 18:12:54.518 
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\BtL2caScoIf.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.   
  Date: 2014-01-09 12:00:51.315 
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\BtL2caScoIf.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.   
  Date: 2014-01-03 03:37:38.931 
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\BtL2caScoIf.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.     
==================== Memory info ===========================    
Processor: AMD A4-1250 APU with Radeon(TM) HD Graphics  
Percentage of memory in use: 35% 
Total physical RAM: 3798.26 MB 
Available physical RAM: 2457.9 MB 
Total Pagefile: 4438.26 MB 
Available Pagefile: 2573.97 MB 
Total Virtual: 131072 MB 
Available Virtual: 131071.85 MB   
==================== Drives ================================   
Drive c: (Windows) (Fixed) (Total:446.81 GB) (Free:380.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] 
Drive d: (RECOVERY) (Fixed) (Total:17.83 GB) (Free:1.76 GB) NTFS ==>[System with boot components (obtained from reading drive)]   
==================== MBR & Partition Table ==================   
======================================================== 
Disk: 0 (Size: 465.8 GB) (Disk ID: B4D436BA)   
Partition: GPT Partition Type.   
==================== End Of Log =========================   
Danke und viele Grüße!    |