ok, läuft schon besser, Google Chrom lässt sich zwar draufspielen funktioniert aber nicht
lg Scuby
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-07-2013
Ran by Reiner (administrator) on 22-07-2013 21:49:39
Running from C:\Users\Reiner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C0I8TQVH
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\Teco.exe
(TOSHIBA Corporation.) C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\TOPI.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files\TOSHIBA\FlashCards\Hotkey\TcrdKBB.exe
(TOSHIBA Corporation) C:\Windows\system32\ThpSrv.exe
(TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(TOSHIBA Corporation.) C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\ipmGui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Toshiba TEMPRO] - C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1050072 2010-10-26] (Toshiba Europe GmbH)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [505696 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [910136 2009-11-10] (TOSHIBA Corporation)
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-07-16] ()
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [508472 2009-10-09] (Conexant Systems, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1881384 2009-10-23] (Synaptics Incorporated)
HKLM\...\Run: [ThpSrv] - C:\Windows\system32\thpsrv /logon [x]
HKLM\...\Run: [SmartFaceVWatcher] - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] - C:\Program Files\TOSHIBA\TECO\Teco.exe [1482592 2009-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [HDMICtrlMan] - C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe [1032536 2009-10-23] (TOSHIBA Corporation.)
HKLM\...\Run: [TosNC] - C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [595816 2009-11-30] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [34648 2009-12-01] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKCU\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe [6203296 2009-08-12] (TOSHIBA)
HKCU\...\Run: [Facebook Update] - C:\Users\Reiner\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.)
HKCU\...\Run: [MobileDocuments] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [x]
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1476104 2012-12-20] (Samsung)
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung)
HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-12-13] (Google Inc.)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup [x]
MountPoints2: F - F:\AutoRun.exe
MountPoints2: {021b7e0f-3759-11e0-8dfa-00269ee33272} - F:\AutoRun.exe
MountPoints2: {021b7e15-3759-11e0-8dfa-00269ee33272} - F:\AutoRun.exe
MountPoints2: {04dce64a-cf05-11df-9326-00269ee33272} - G:\AutoRun.exe
MountPoints2: {04dce6b5-cf05-11df-9326-00269ee33272} - G:\AutoRun.exe
MountPoints2: {04dce6c3-cf05-11df-9326-00269ee33272} - F:\AutoRun.exe
MountPoints2: {04dce6c7-cf05-11df-9326-00269ee33272} - F:\AutoRun.exe
MountPoints2: {1589bb30-c439-11df-b9fe-00269ee33272} - F:\setup.exe
MountPoints2: {1589bb38-c439-11df-b9fe-00269ee33272} - G:\setup.exe
MountPoints2: {1589bb5a-c439-11df-b9fe-00269ee33272} - F:\AutoRun.exe
MountPoints2: {1589bb5c-c439-11df-b9fe-00269ee33272} - F:\AutoRun.exe
MountPoints2: {298a79cb-3793-11e0-b6bd-00269ee33272} - F:\AutoRun.exe
MountPoints2: {45324351-d7e6-11df-a407-00269ee33272} - F:\AutoRun.exe
MountPoints2: {4532435d-d7e6-11df-a407-00269ee33272} - F:\AutoRun.exe
MountPoints2: {4532437d-d7e6-11df-a407-001e101fa1f5} - F:\AutoRun.exe
MountPoints2: {45324385-d7e6-11df-a407-001e101fa1f5} - G:\AutoRun.exe
MountPoints2: {88832f2f-c559-11df-b3d4-00269ee33272} - F:\setup.exe
MountPoints2: {8f891fff-37a9-11e0-8cae-00269ee33272} - F:\AutoRun.exe
MountPoints2: {8f892005-37a9-11e0-8cae-00269ee33272} - F:\AutoRun.exe
MountPoints2: {c5c7ad31-8d80-11df-8172-00269ee33272} - F:\LaunchU3.exe -a
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM-x32\...\Run: [ITSecMng] - %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START [83336 2009-07-22] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [TUSBSleepChargeSrv] - %ProgramFiles(x86)%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe [x]
HKLM-x32\...\Run: [ToshibaServiceStation] - "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 [1295736 2011-02-11] (TOSHIBA Corporation)
HKLM-x32\...\Run: [TRCMan] - C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe [701752 2009-07-21] (TOSHIBA Corporation)
HKLM-x32\...\Run: [TWebCamera] - "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun [2454840 2009-11-24] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [NPSStartup] - [x]
HKLM-x32\...\Run: [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-07-15] (Avira Operations GmbH & Co. KG)
HKU\Default\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe [6203296 2009-08-12] (TOSHIBA)
HKU\Default User\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe [6203296 2009-08-12] (TOSHIBA)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Reiner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Super Lyrics - {B9020890-9E08-446B-87B0-0C5CD0436D86} - C:\Program Files (x86)\Super_Lyrics\116.dll No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - No File
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @facebook.com/FBPlugin,version=1.0.3 - C:\Users\Reiner\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Reiner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Reiner\AppData\Local\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
Chrome:
=======
CHR DefaultSearchURL: (Hola Search) - hxxp://www.holasearch.com/?q={searchTerms}&affID=121962&tt=gc_&babsrc=SP_ss&mntrId=3213701A04C355D4
CHR DefaultSuggestURL: (Hola Search) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
==================== Services (Whitelisted) =================
R2 AntiVirFirewallService; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [654392 2013-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [371768 2013-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-15] (Avira Operations GmbH & Co. KG)
R2 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [124368 2010-10-26] (Toshiba Europe GmbH)
==================== Drivers (Whitelisted) ====================
R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [114608 2013-07-15] (Avira GmbH)
R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [141376 2013-07-15] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-07-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-07-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-07-15] (Avira Operations GmbH & Co. KG)
R3 hidshim; C:\Windows\System32\DRIVERS\hidshim.sys [6656 2009-08-31] (Windows (R) Win 7 DDK provider)
R3 nuvotoncir; C:\Windows\System32\DRIVERS\nuvotoncir.sys [48128 2009-08-31] (Nuvoton Technology Corporation)
R3 nuvotonhidcir; C:\Windows\System32\DRIVERS\nuvotonhidcir.sys [26624 2009-08-31] (Nuvoton Technology Corporation)
R3 O2SDGRDR; C:\Windows\System32\DRIVERS\o2sdgx64.sys [49568 2009-08-18] (O2Micro )
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-22 21:49 - 2013-07-22 21:49 - 00000000 ____D C:\FRST
2013-07-22 21:48 - 2013-07-22 21:48 - 01779197 _____ (Farbar) C:\Users\Reiner\Desktop\FRST64.exe
2013-07-22 21:29 - 2013-07-22 21:29 - 00002222 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-22 21:26 - 2013-07-22 21:26 - 00005163 _____ C:\Users\Reiner\Documents\AdwCleaner[S1].txt
2013-07-22 21:24 - 2013-07-22 21:24 - 00005163 _____ C:\AdwCleaner[S1].txt
2013-07-22 21:23 - 2013-07-22 21:23 - 00005225 _____ C:\AdwCleaner[R4].txt
2013-07-22 20:15 - 2013-07-22 20:15 - 00005404 _____ C:\AdwCleaner[R3].txt
2013-07-22 19:44 - 2013-07-22 19:44 - 00005344 _____ C:\AdwCleaner[R2].txt
2013-07-22 19:40 - 2013-07-22 19:40 - 00005284 _____ C:\Users\Reiner\Documents\AdwCleaner[R1].txt
2013-07-22 19:40 - 2013-07-22 19:40 - 00005284 _____ C:\AdwCleaner[R1].txt
2013-07-22 19:39 - 2013-07-22 19:39 - 00666633 _____ C:\Users\Reiner\Desktop\adwcleaner.exe
2013-07-22 19:19 - 2013-07-22 20:33 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\Zip Opener Packages
2013-07-22 19:19 - 2013-07-22 19:19 - 00000000 ____D C:\Program Files (x86)\Super_Lyrics
2013-07-20 02:40 - 2013-07-20 02:42 - 00000000 ____D C:\Windows\system32\MRT
2013-07-20 02:29 - 2013-07-20 02:29 - 00793536 _____ C:\Users\Reiner\Downloads\ZipOpenerSetup (1).exe
2013-07-19 23:10 - 2013-07-20 11:44 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-07-19 23:06 - 2013-07-19 23:08 - 13399154 _____ C:\Users\Reiner\Downloads\mbar-1.06.0.1004.zip
2013-07-19 22:53 - 2013-07-19 22:53 - 00793536 _____ C:\Users\Reiner\Downloads\ZipOpenerSetup.exe
2013-07-19 22:49 - 2013-07-19 22:37 - 00000462 _____ C:\zoek-results19.07.2013-2237.log
2013-07-19 22:37 - 2013-07-19 22:37 - 00003124 _____ C:\Windows\System32\Tasks\{1FF0053F-70CF-4CDD-9ACB-42E6B4025455}
2013-07-19 22:36 - 2013-07-19 22:36 - 01274974 _____ C:\Users\Reiner\Downloads\zoek.exe
2013-07-19 22:36 - 2013-07-19 22:04 - 00000859 _____ C:\zoek-results19.07.2013-2204.log
2013-07-19 22:21 - 2013-07-20 02:29 - 00000306 __RSH C:\Users\Reiner\ntuser.pol
2013-07-19 22:20 - 2013-07-22 19:19 - 00003398 _____ C:\Windows\System32\Tasks\EPUpdater
2013-07-19 22:18 - 2013-07-22 19:19 - 00003238 _____ C:\Windows\System32\Tasks\DSite
2013-07-19 22:06 - 2013-07-19 22:06 - 00000859 _____ C:\Users\Reiner\Documents\zoek-results2.txt
2013-07-19 22:03 - 2013-07-19 20:59 - 00050377 _____ C:\zoek-results19.07.2013-2059.log
2013-07-19 21:56 - 2013-07-19 21:56 - 00129080 _____ C:\Users\Reiner\Documents\OTL.Txt
2013-07-19 21:56 - 2013-07-19 21:56 - 00080908 _____ C:\Users\Reiner\Documents\Extras.Txt
2013-07-19 21:03 - 2013-07-19 21:03 - 00050377 _____ C:\Users\Reiner\Documents\zoek-results.log
2013-07-19 20:56 - 2013-07-19 20:56 - 00003432 _____ C:\Windows\System32\Tasks\BrowserProtect
2013-07-19 20:46 - 2013-07-19 22:49 - 00000508 _____ C:\zoek-results.log
2013-07-18 21:40 - 2013-07-18 21:40 - 00001076 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-18 20:24 - 2013-07-18 20:24 - 00002982 _____ C:\Windows\System32\Tasks\{88254E50-0171-4044-B06C-FA3ED768A3F0}
2013-07-18 20:24 - 2013-07-18 20:24 - 00002982 _____ C:\Windows\System32\Tasks\{7A531A76-29F0-4B9F-A778-40A5983ECBB8}
2013-07-15 18:28 - 2013-07-15 18:28 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-07-15 18:28 - 2013-07-15 18:28 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\Avira
2013-07-15 18:27 - 2013-07-15 18:27 - 00001961 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-07-15 18:27 - 2013-07-15 18:27 - 00000000 ____D C:\Program Files (x86)\Avira
2013-07-15 18:27 - 2013-07-15 18:17 - 00141376 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwot.sys
2013-07-15 18:27 - 2013-07-15 18:17 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-07-15 18:27 - 2013-07-15 18:17 - 00114608 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwim.sys
2013-07-15 18:27 - 2013-07-15 18:17 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-07-15 18:27 - 2013-07-15 18:17 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-15 18:21 - 2013-07-15 18:21 - 00009847 _____ C:\Users\Reiner\Documents\Avira 2013.odt
2013-07-15 18:15 - 2013-07-15 18:15 - 02092776 _____ C:\Users\Reiner\Downloads\avira_internet_security(1).exe
2013-07-10 21:24 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-10 21:24 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-10 21:24 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-10 21:24 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-10 21:24 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-10 21:24 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-10 21:24 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-10 21:24 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-10 21:24 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-10 20:16 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-10 20:16 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-10 20:16 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-10 20:16 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-10 20:16 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-10 20:15 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-10 20:15 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-07 23:22 - 2013-07-22 18:59 - 00000005 _____ C:\Users\Reiner\AppData\Roaming\WBPU-TTL.DAT
2013-07-07 22:22 - 2013-07-22 19:23 - 00000000 ____D C:\ProgramData\Norton
2013-07-07 22:22 - 2013-07-07 22:22 - 00000000 ____D C:\ProgramData\Symantec
2013-07-07 22:21 - 2013-07-07 22:21 - 00794680 _____ C:\Users\Reiner\Downloads\ZipExtractorSetup.exe
2013-07-07 22:20 - 2013-07-07 22:20 - 06464840 _____ C:\Users\Reiner\Downloads\Default with Voice Name.rar
2013-07-07 22:20 - 2013-07-07 22:20 - 06464840 _____ C:\Users\Reiner\Downloads\Default with Voice Name (1).rar
2013-07-06 19:42 - 2013-07-06 19:42 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-06-27 15:42 - 2013-06-27 15:42 - 00014358 _____ C:\Users\Reiner\Downloads\Neue Termin Gastico Juli 2013.xlsx
==================== One Month Modified Files and Folders =======
2013-07-22 21:49 - 2013-07-22 21:49 - 00000000 ____D C:\FRST
2013-07-22 21:48 - 2013-07-22 21:48 - 01779197 _____ (Farbar) C:\Users\Reiner\Desktop\FRST64.exe
2013-07-22 21:45 - 2009-07-14 06:45 - 00016304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-22 21:45 - 2009-07-14 06:45 - 00016304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-22 21:37 - 2010-03-17 18:20 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-22 21:37 - 2009-12-13 23:32 - 00865640 _____ C:\Windows\PFRO.log
2013-07-22 21:37 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-22 21:37 - 2009-07-14 06:51 - 00247675 _____ C:\Windows\setupact.log
2013-07-22 21:36 - 2010-01-26 15:28 - 02050182 _____ C:\Windows\WindowsUpdate.log
2013-07-22 21:29 - 2013-07-22 21:29 - 00002222 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-22 21:29 - 2009-12-13 23:33 - 00000000 ____D C:\Program Files (x86)\Google
2013-07-22 21:26 - 2013-07-22 21:26 - 00005163 _____ C:\Users\Reiner\Documents\AdwCleaner[S1].txt
2013-07-22 21:24 - 2013-07-22 21:24 - 00005163 _____ C:\AdwCleaner[S1].txt
2013-07-22 21:23 - 2013-07-22 21:23 - 00005225 _____ C:\AdwCleaner[R4].txt
2013-07-22 21:03 - 2012-06-30 19:09 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-22 20:53 - 2010-03-17 18:20 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-22 20:33 - 2013-07-22 19:19 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\Zip Opener Packages
2013-07-22 20:15 - 2013-07-22 20:15 - 00005404 _____ C:\AdwCleaner[R3].txt
2013-07-22 19:47 - 2011-09-02 22:36 - 00001142 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-87162310-1213645192-2319634588-1001UA.job
2013-07-22 19:44 - 2013-07-22 19:44 - 00005344 _____ C:\AdwCleaner[R2].txt
2013-07-22 19:40 - 2013-07-22 19:40 - 00005284 _____ C:\Users\Reiner\Documents\AdwCleaner[R1].txt
2013-07-22 19:40 - 2013-07-22 19:40 - 00005284 _____ C:\AdwCleaner[R1].txt
2013-07-22 19:39 - 2013-07-22 19:39 - 00666633 _____ C:\Users\Reiner\Desktop\adwcleaner.exe
2013-07-22 19:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-22 19:23 - 2013-07-07 22:22 - 00000000 ____D C:\ProgramData\Norton
2013-07-22 19:19 - 2013-07-22 19:19 - 00000000 ____D C:\Program Files (x86)\Super_Lyrics
2013-07-22 19:19 - 2013-07-19 22:20 - 00003398 _____ C:\Windows\System32\Tasks\EPUpdater
2013-07-22 19:19 - 2013-07-19 22:18 - 00003238 _____ C:\Windows\System32\Tasks\DSite
2013-07-22 18:59 - 2013-07-07 23:22 - 00000005 _____ C:\Users\Reiner\AppData\Roaming\WBPU-TTL.DAT
2013-07-20 11:44 - 2013-07-19 23:10 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-07-20 02:42 - 2013-07-20 02:40 - 00000000 ____D C:\Windows\system32\MRT
2013-07-20 02:39 - 2009-07-14 19:58 - 00654400 _____ C:\Windows\system32\perfh007.dat
2013-07-20 02:39 - 2009-07-14 19:58 - 00130240 _____ C:\Windows\system32\perfc007.dat
2013-07-20 02:39 - 2009-07-14 07:13 - 01520734 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-20 02:29 - 2013-07-20 02:29 - 00793536 _____ C:\Users\Reiner\Downloads\ZipOpenerSetup (1).exe
2013-07-20 02:29 - 2013-07-19 22:21 - 00000306 __RSH C:\Users\Reiner\ntuser.pol
2013-07-20 02:29 - 2010-03-17 17:57 - 00000000 ____D C:\Users\Reiner
2013-07-20 01:47 - 2011-09-02 22:36 - 00001120 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-87162310-1213645192-2319634588-1001Core.job
2013-07-19 23:08 - 2013-07-19 23:06 - 13399154 _____ C:\Users\Reiner\Downloads\mbar-1.06.0.1004.zip
2013-07-19 22:53 - 2013-07-19 22:53 - 00793536 _____ C:\Users\Reiner\Downloads\ZipOpenerSetup.exe
2013-07-19 22:49 - 2013-07-19 20:46 - 00000508 _____ C:\zoek-results.log
2013-07-19 22:37 - 2013-07-19 22:49 - 00000462 _____ C:\zoek-results19.07.2013-2237.log
2013-07-19 22:37 - 2013-07-19 22:37 - 00003124 _____ C:\Windows\System32\Tasks\{1FF0053F-70CF-4CDD-9ACB-42E6B4025455}
2013-07-19 22:36 - 2013-07-19 22:36 - 01274974 _____ C:\Users\Reiner\Downloads\zoek.exe
2013-07-19 22:21 - 2009-07-14 05:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-07-19 22:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2013-07-19 22:20 - 2013-04-12 16:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-19 22:06 - 2013-07-19 22:06 - 00000859 _____ C:\Users\Reiner\Documents\zoek-results2.txt
2013-07-19 22:04 - 2013-07-19 22:36 - 00000859 _____ C:\zoek-results19.07.2013-2204.log
2013-07-19 21:56 - 2013-07-19 21:56 - 00129080 _____ C:\Users\Reiner\Documents\OTL.Txt
2013-07-19 21:56 - 2013-07-19 21:56 - 00080908 _____ C:\Users\Reiner\Documents\Extras.Txt
2013-07-19 21:03 - 2013-07-19 21:03 - 00050377 _____ C:\Users\Reiner\Documents\zoek-results.log
2013-07-19 20:59 - 2013-07-19 22:03 - 00050377 _____ C:\zoek-results19.07.2013-2059.log
2013-07-19 20:56 - 2013-07-19 20:56 - 00003432 _____ C:\Windows\System32\Tasks\BrowserProtect
2013-07-18 21:40 - 2013-07-18 21:40 - 00001076 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-18 21:40 - 2011-01-06 23:42 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-18 21:30 - 2010-03-17 18:17 - 00000000 ____D C:\Users\Reiner\AppData\Local\Google
2013-07-18 21:02 - 2010-05-31 09:45 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\Mozilla
2013-07-18 20:55 - 2012-07-02 13:42 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\TS3Client
2013-07-18 20:24 - 2013-07-18 20:24 - 00002982 _____ C:\Windows\System32\Tasks\{88254E50-0171-4044-B06C-FA3ED768A3F0}
2013-07-18 20:24 - 2013-07-18 20:24 - 00002982 _____ C:\Windows\System32\Tasks\{7A531A76-29F0-4B9F-A778-40A5983ECBB8}
2013-07-15 18:28 - 2013-07-15 18:28 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-07-15 18:28 - 2013-07-15 18:28 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\Avira
2013-07-15 18:27 - 2013-07-15 18:27 - 00001961 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-07-15 18:27 - 2013-07-15 18:27 - 00000000 ____D C:\Program Files (x86)\Avira
2013-07-15 18:27 - 2010-03-17 18:55 - 00000000 ____D C:\ProgramData\Avira
2013-07-15 18:21 - 2013-07-15 18:21 - 00009847 _____ C:\Users\Reiner\Documents\Avira 2013.odt
2013-07-15 18:17 - 2013-07-15 18:27 - 00141376 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwot.sys
2013-07-15 18:17 - 2013-07-15 18:27 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-07-15 18:17 - 2013-07-15 18:27 - 00114608 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwim.sys
2013-07-15 18:17 - 2013-07-15 18:27 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-07-15 18:17 - 2013-07-15 18:27 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-15 18:15 - 2013-07-15 18:15 - 02092776 _____ C:\Users\Reiner\Downloads\avira_internet_security(1).exe
2013-07-15 17:57 - 2009-12-13 23:31 - 00000000 ____D C:\Program Files (x86)\eBay
2013-07-15 17:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-07-15 17:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-07-15 17:48 - 2010-03-17 18:20 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-15 17:48 - 2010-03-17 18:20 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-11 17:52 - 2009-07-14 06:45 - 00390752 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-11 17:50 - 2013-03-13 23:30 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-11 17:50 - 2013-03-13 23:30 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-11 17:50 - 2009-07-14 20:18 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-11 17:50 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-11 17:50 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-07 22:22 - 2013-07-07 22:22 - 00000000 ____D C:\ProgramData\Symantec
2013-07-07 22:21 - 2013-07-07 22:21 - 00794680 _____ C:\Users\Reiner\Downloads\ZipExtractorSetup.exe
2013-07-07 22:20 - 2013-07-07 22:20 - 06464840 _____ C:\Users\Reiner\Downloads\Default with Voice Name.rar
2013-07-07 22:20 - 2013-07-07 22:20 - 06464840 _____ C:\Users\Reiner\Downloads\Default with Voice Name (1).rar
2013-07-06 19:42 - 2013-07-06 19:42 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-07-06 19:42 - 2013-02-07 23:26 - 00000000 ____D C:\Users\Reiner\Documents\SelfMV
2013-06-27 15:42 - 2013-06-27 15:42 - 00014358 _____ C:\Users\Reiner\Downloads\Neue Termin Gastico Juli 2013.xlsx
2013-06-24 00:57 - 2010-03-29 12:58 - 78277128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-15 08:57
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-07-2013
Ran by Reiner at 2013-07-22 21:50:56
Running from C:\Users\Reiner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C0I8TQVH
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Adobe AIR (x32 Version: 1.5.2.8870)
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
Adobe Reader X (10.1.7) - Deutsch (x32 Version: 10.1.7)
Apple Application Support (x32 Version: 2.3.3)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.0.17)
Avira Internet Security (x32 Version: 13.0.0.3737)
Bing Bar (x32 Version: 7.0.609.0)
Bluetooth Stack for Windows by Toshiba (Version: v7.10.01(T))
Bonjour (Version: 3.0.0.10)
Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000)
Conexant HD Audio (Version: 4.98.16.61)
D3DX10 (x32 Version: 15.4.2368.0902)
Direct DiscRecorder (x32 Version: 1.00.0000)
dows-Treiberpaket - Nokia pccsmcfd (10/12/2007 6.85.4.0) (Version: 10/12/2007 6.85.4.0)
DVD MovieFactory for TOSHIBA (x32 Version: 7.0.0)
eBay (x32 Version: 1.0.5)
Facebook Plug-In (HKCU)
Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287)
Google Chrome (x32 Version: 28.0.1500.72)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Google Update Helper (x32 Version: 1.3.21.153)
HDMI Control Manager (Version: 2.0)
HDMI Control Manager (x32 Version: 2.0)
iCloud (Version: 2.1.2.8)
Intel(R) Control Center (x32 Version: 1.2.0.1006)
Intel(R) Management Engine Components (x32 Version: 6.0.0.1179)
Intel(R) Rapid Storage Technology (x32 Version: 9.5.0.1037)
Intel(R) Turbo Boost Technology Driver (x32 Version: 01.00.01.1002)
InterVideo WinDVD BD for TOSHIBA (x32 Version: 8.0-B20.185)
iTunes (Version: 11.0.2.26)
Java 7 Update 17 (x32 Version: 7.0.170)
Java Auto Updater (x32 Version: 2.1.9.0)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
LoudMo Contextual Ad Assistant (x32)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office PowerPoint Viewer 2007 (German) (x32 Version: 12.0.6612.1000)
Microsoft Office Suite Activation Assistant (x32 Version: 2.9)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Works (x32 Version: 9.7.0621)
MobileMe Control Panel (Version: 3.1.8.0)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MyFreeCodec (HKCU)
Nuvoton CIR Device Drivers (x32 Version: 8.60.2002)
NVIDIA 3D Vision Controller Driver (x32 Version: 275.33)
NVIDIA 3D Vision Controller-Treiber 296.10 (Version: 296.10)
NVIDIA Display Control Panel (Version: 6.14.12.5912)
NVIDIA Grafiktreiber 296.10 (Version: 296.10)
NVIDIA HD-Audiotreiber 1.3.12.0 (Version: 1.3.12.0)
NVIDIA Install Application (Version: 2.1002.62.312)
NVIDIA PhysX (x32 Version: 9.12.0213)
NVIDIA PhysX-Systemsoftware 9.12.0213 (Version: 9.12.0213)
NVIDIA Systemsteuerung 296.10 (Version: 296.10)
O2Micro Flash Memory Card Windows Driver (Version: 2.0.24.D)
O2Micro Flash Memory Card Windows Driver (x32 Version: 2.0.24.D)
OpenOffice.org 3.2 (x32 Version: 3.2.9483)
PC Connectivity Solution (x32 Version: 8.15.0.0)
Photo Service - powered by myphotobook (x32 Version: 1.0.5)
Photo Service - powered by myphotobook (x32 Version: 1.0.5-124)
PlayReady PC Runtime amd64 (Version: 1.3.0)
QuickTime (x32 Version: 7.72.80.56)
Realtek WLAN Driver (x32 Version: 2.00.0006)
Regi (Version: 1.00.0000)
Safari (x32 Version: 5.34.57.2)
Samsung Kies (x32 Version: 2.5.1.12123_2)
Samsung Mobile phone USB driver Drive Software
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.16.0)
Synaptics Pointing Device Driver (Version: 14.0.12.0)
TeamSpeak 3 Client (Version: 3.0.10.1)
Toshiba Assist (x32 Version: 3.00.10)
TOSHIBA Bulletin Board (Version: 1.5.06.64)
TOSHIBA Bulletin Board (x32 Version: 1.5.06.64)
TOSHIBA ConfigFree (x32 Version: 8.0.25)
TOSHIBA Disc Creator (Version: 2.1.0.2 for x64)
TOSHIBA DVD PLAYER (x32 Version: 3.01.1.07-A)
TOSHIBA eco Utility (Version: 1.1.12.64)
TOSHIBA eco Utility (x32 Version: 1.1.12.64)
TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00)
TOSHIBA Extended Tiles for Windows Mobility Center (x32 Version: )
TOSHIBA Face Recognition (Version: 3.1.3.64)
TOSHIBA Face Recognition (x32 Version: 3.1.3.64)
TOSHIBA Hardware Setup (Version: 4.02.01.00)
TOSHIBA Hardware Setup (x32 Version: 4.02.01.00)
TOSHIBA HDD Protection (Version: 2.2.0.3)
TOSHIBA HDD/SSD Alert (Version: 3.1.64.6)
TOSHIBA HDD/SSD Alert (x32 Version: 3.1.64.6)
Toshiba Manuals (x32 Version: 10.00)
Toshiba Online Product Information (x32 Version: 2.08.0001)
TOSHIBA Recovery Media Creator (Version: 2.1.0.4 x64)
TOSHIBA Recovery Media Creator Reminder (x32 Version: 1.00.0019)
TOSHIBA ReelTime (Version: 1.5.08.64)
TOSHIBA ReelTime (x32 Version: 1.5.08.64)
TOSHIBA Remote Control Manager (x32 Version: 3.0.1.0)
TOSHIBA Service Station (x32 Version: 2.2.9)
TOSHIBA Supervisor Password (Version: 4.02.01.00)
TOSHIBA Supervisor Password (x32 Version: 4.02.01.00)
TOSHIBA TEMPRO (x32 Version: 3.34)
TOSHIBA USB Sleep and Charge Utility (x32 Version: 1.3.2.0)
TOSHIBA Value Added Package (Version: 1.2.34.64)
TOSHIBA Value Added Package (x32 Version: 1.2.34.64)
TOSHIBA Web Camera Application (x32 Version: 1.1.1.10)
TRORMCLauncher (Version: 1.0.0.9)
TRORMCLauncher (x32 Version: )
Unity Web Player (HKCU Version: )
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
VoiceOver Kit (x32 Version: 1.42.128.0)
WildTangent-Spiele (x32 Version: 1.0.0.71)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3538.0513)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3538.0513)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Sync (x32 Version: 14.0.8089.726)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
==================== Restore Points =========================
14-07-2013 18:33:10 Removed eBay
18-07-2013 19:11:15 PC Performer Do, Jul 18, 13 21:11
19-07-2013 18:46:51 zoek.exe restore point
19-07-2013 23:47:48 Removed eBay
19-07-2013 23:54:14 Removed eBay
20-07-2013 00:35:35 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {2B998473-F4CD-41E9-BFA5-E43D3BC01787} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-17] (Google Inc.)
Task: {2C1A3883-A8CE-4754-87ED-BA35EADA0C71} - System32\Tasks\{B0898463-A185-4BAC-BF36-D6612A02F050} => C:\Program Files (x86)\Samsung\Kies\Kies.exe [2012-12-20] (Samsung)
Task: {3EEC8A03-990B-45C3-B86A-DF2EFA3709FF} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation)
Task: {459EEC1A-22A9-4D98-9C22-A4C8EB3EC3FC} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {4B576DA5-373C-4C1C-9CD2-467C44797A88} - System32\Tasks\EPUpdater => C:\Users\Reiner\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe No File
Task: {58DE164A-41E3-4816-8D6C-72CCE4DD04DE} - System32\Tasks\ConfigFree Startup Programs => C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [2009-10-28] (TOSHIBA CORPORATION)
Task: {6FF985F2-7222-42AA-A115-13220D2BB0D5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated)
Task: {76237254-E56D-4933-B1E8-370D1D412DB6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A4799860-835C-4CEB-8D48-CD7793A9DF6E} - System32\Tasks\DSite => C:\Users\Reiner\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File
Task: {ABF280ED-6161-4D76-869F-DC9900D928DB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-17] (Google Inc.)
Task: {BE90B33F-5512-4ECD-8EFD-FF4BC6EA1E92} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-87162310-1213645192-2319634588-1001UA => C:\Users\Reiner\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {BEBF4FB8-F68F-401B-85F7-057CBB7BEE6D} - System32\Tasks\AdobeFlashPlayerUpdate => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated)
Task: {C312DA33-CD24-402A-AE1B-01F74FBE88C7} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated)
Task: {C34F0069-5B1E-457F-8D19-68EB98CE17ED} - System32\Tasks\{88254E50-0171-4044-B06C-FA3ED768A3F0} => C:\Users\Reiner\Desktop\UnityWebPlayer_4-0-1-62181.exe [2013-05-08] (Unity Technologies ApS)
Task: {C5E36429-F835-4B40-89D0-9D18DF94F971} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-87162310-1213645192-2319634588-1001Core => C:\Users\Reiner\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {E4BF4D00-76DF-4908-8969-D02A056EF821} - System32\Tasks\{7A531A76-29F0-4B9F-A778-40A5983ECBB8} => C:\Users\Reiner\Desktop\UnityWebPlayer_4-0-1-62181.exe [2013-05-08] (Unity Technologies ApS)
Task: {E85324AB-036E-48DE-90AF-3A85D9018354} - System32\Tasks\BrowserProtect => C:\Windows\system32\sc.exe [2009-07-14] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-87162310-1213645192-2319634588-1001Core.job => C:\Users\Reiner\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-87162310-1213645192-2319634588-1001UA.job => C:\Users\Reiner\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/22/2013 09:03:01 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e243
ID des fehlerhaften Prozesses: 0xfb4
Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0
Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1
Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2
Berichtskennung: FlashPlayerUpdateService.exe3
Error: (07/22/2013 08:03:02 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e243
ID des fehlerhaften Prozesses: 0x1b70
Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0
Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1
Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2
Berichtskennung: FlashPlayerUpdateService.exe3
Error: (07/22/2013 07:31:31 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15584
Error: (07/22/2013 07:31:31 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15584
Error: (07/22/2013 07:31:31 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (07/22/2013 07:09:50 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error: (07/22/2013 07:03:01 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e243
ID des fehlerhaften Prozesses: 0x83c
Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0
Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1
Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2
Berichtskennung: FlashPlayerUpdateService.exe3
Error: (07/20/2013 11:03:01 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e243
ID des fehlerhaften Prozesses: 0x18f0
Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0
Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1
Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2
Berichtskennung: FlashPlayerUpdateService.exe3
Error: (07/20/2013 10:03:01 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e243
ID des fehlerhaften Prozesses: 0x1668
Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0
Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1
Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2
Berichtskennung: FlashPlayerUpdateService.exe3
Error: (07/20/2013 09:03:03 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e243
ID des fehlerhaften Prozesses: 0x1700
Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0
Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1
Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2
Berichtskennung: FlashPlayerUpdateService.exe3
System errors:
=============
Error: (07/22/2013 09:26:47 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Notebook Performance Tuning Service (TEMPRO) erreicht.
Error: (07/22/2013 08:47:24 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Notebook Performance Tuning Service (TEMPRO) erreicht.
Error: (07/20/2013 09:37:13 AM) (Source: NetBT) (User: )
Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers,
der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an
der Eingabeaufforderung, um den doppelten Namen zu bestimmen.
Error: (07/20/2013 09:37:11 AM) (Source: NetBT) (User: )
Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers,
der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an
der Eingabeaufforderung, um den doppelten Namen zu bestimmen.
Error: (07/20/2013 09:37:11 AM) (Source: NetBT) (User: )
Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers,
der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an
der Eingabeaufforderung, um den doppelten Namen zu bestimmen.
Error: (07/20/2013 09:37:10 AM) (Source: NetBT) (User: )
Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers,
der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an
der Eingabeaufforderung, um den doppelten Namen zu bestimmen.
Error: (07/20/2013 02:31:40 AM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "TANJA-PC",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{BB598D80-B5EA-4F06-9341-2145D3431E42}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (07/20/2013 02:31:39 AM) (Source: NetBT) (User: )
Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers,
der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an
der Eingabeaufforderung, um den doppelten Namen zu bestimmen.
Error: (07/20/2013 02:31:38 AM) (Source: NetBT) (User: )
Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers,
der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an
der Eingabeaufforderung, um den doppelten Namen zu bestimmen.
Error: (07/20/2013 02:31:36 AM) (Source: NetBT) (User: )
Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers,
der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an
der Eingabeaufforderung, um den doppelten Namen zu bestimmen.
Microsoft Office Sessions:
=========================
Error: (07/22/2013 09:03:01 PM) (Source: Application Error)(User: )
Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.177254ec49b8fc00000050002e243fb401ce870e157d03bcC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dll543428bb-f301-11e2-84f4-00269ee33272
Error: (07/22/2013 08:03:02 PM) (Source: Application Error)(User: )
Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.177254ec49b8fc00000050002e2431b7001ce8705b3ba9cf4C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dllf2bdedfc-f2f8-11e2-8492-00269ee33272
Error: (07/22/2013 07:31:31 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15584
Error: (07/22/2013 07:31:31 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15584
Error: (07/22/2013 07:31:31 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (07/22/2013 07:09:50 PM) (Source: SideBySide)(User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3
Error: (07/22/2013 07:03:01 PM) (Source: Application Error)(User: )
Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.177254ec49b8fc00000050002e24383c01ce86fd51f78312C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dll9092178d-f2f0-11e2-8128-00269ee33272
Error: (07/20/2013 11:03:01 AM) (Source: Application Error)(User: )
Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.177254ec49b8fc00000050002e24318f001ce8527ef162d75C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dll2dae6090-f11b-11e2-bb9e-00269ee33272
Error: (07/20/2013 10:03:01 AM) (Source: Application Error)(User: )
Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.177254ec49b8fc00000050002e243166801ce851f8d3947b8C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dllcbd89ef4-f112-11e2-bb9e-00269ee33272
Error: (07/20/2013 09:03:03 AM) (Source: Application Error)(User: )
Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.177254ec49b8fc00000050002e243170001ce85172b866778C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dll6b6e3c9a-f10a-11e2-bb9e-00269ee33272
==================== Memory info ===========================
Percentage of memory in use: 44%
Total physical RAM: 3956.47 MB
Available physical RAM: 2179.79 MB
Total Pagefile: 7911.13 MB
Available Pagefile: 5814.64 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (WINDOWS) (Fixed) (Total:232.94 GB) (Free:159.62 GB) NTFS (Disk=0 Partition=2)
Drive d: (Data) (Fixed) (Total:232.43 GB) (Free:215.67 GB) NTFS (Disk=0 Partition=3)
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 4442DD8E)
Partition 1: (Active) - (Size=400 MB) - (Type=27)
Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=232 GB) - (Type=07 NTFS)
==================== End Of Log ============================
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-07-2013
Ran by Reiner (administrator) on 22-07-2013 22:11:22
Running from C:\Users\Reiner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C0I8TQVH
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\Teco.exe
(TOSHIBA Corporation.) C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\TOPI.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files\TOSHIBA\FlashCards\Hotkey\TcrdKBB.exe
(TOSHIBA Corporation) C:\Windows\system32\ThpSrv.exe
(TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(TOSHIBA Corporation.) C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\ipmGui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Toshiba TEMPRO] - C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1050072 2010-10-26] (Toshiba Europe GmbH)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [505696 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [910136 2009-11-10] (TOSHIBA Corporation)
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-07-16] ()
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [508472 2009-10-09] (Conexant Systems, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1881384 2009-10-23] (Synaptics Incorporated)
HKLM\...\Run: [ThpSrv] - C:\Windows\system32\thpsrv /logon [x]
HKLM\...\Run: [SmartFaceVWatcher] - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] - C:\Program Files\TOSHIBA\TECO\Teco.exe [1482592 2009-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [HDMICtrlMan] - C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe [1032536 2009-10-23] (TOSHIBA Corporation.)
HKLM\...\Run: [TosNC] - C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [595816 2009-11-30] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [34648 2009-12-01] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKCU\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe [6203296 2009-08-12] (TOSHIBA)
HKCU\...\Run: [Facebook Update] - C:\Users\Reiner\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.)
HKCU\...\Run: [MobileDocuments] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [x]
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1476104 2012-12-20] (Samsung)
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung)
HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-12-13] (Google Inc.)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup [x]
MountPoints2: F - F:\AutoRun.exe
MountPoints2: {021b7e0f-3759-11e0-8dfa-00269ee33272} - F:\AutoRun.exe
MountPoints2: {021b7e15-3759-11e0-8dfa-00269ee33272} - F:\AutoRun.exe
MountPoints2: {04dce64a-cf05-11df-9326-00269ee33272} - G:\AutoRun.exe
MountPoints2: {04dce6b5-cf05-11df-9326-00269ee33272} - G:\AutoRun.exe
MountPoints2: {04dce6c3-cf05-11df-9326-00269ee33272} - F:\AutoRun.exe
MountPoints2: {04dce6c7-cf05-11df-9326-00269ee33272} - F:\AutoRun.exe
MountPoints2: {1589bb30-c439-11df-b9fe-00269ee33272} - F:\setup.exe
MountPoints2: {1589bb38-c439-11df-b9fe-00269ee33272} - G:\setup.exe
MountPoints2: {1589bb5a-c439-11df-b9fe-00269ee33272} - F:\AutoRun.exe
MountPoints2: {1589bb5c-c439-11df-b9fe-00269ee33272} - F:\AutoRun.exe
MountPoints2: {298a79cb-3793-11e0-b6bd-00269ee33272} - F:\AutoRun.exe
MountPoints2: {45324351-d7e6-11df-a407-00269ee33272} - F:\AutoRun.exe
MountPoints2: {4532435d-d7e6-11df-a407-00269ee33272} - F:\AutoRun.exe
MountPoints2: {4532437d-d7e6-11df-a407-001e101fa1f5} - F:\AutoRun.exe
MountPoints2: {45324385-d7e6-11df-a407-001e101fa1f5} - G:\AutoRun.exe
MountPoints2: {88832f2f-c559-11df-b3d4-00269ee33272} - F:\setup.exe
MountPoints2: {8f891fff-37a9-11e0-8cae-00269ee33272} - F:\AutoRun.exe
MountPoints2: {8f892005-37a9-11e0-8cae-00269ee33272} - F:\AutoRun.exe
MountPoints2: {c5c7ad31-8d80-11df-8172-00269ee33272} - F:\LaunchU3.exe -a
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM-x32\...\Run: [ITSecMng] - %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START [83336 2009-07-22] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [TUSBSleepChargeSrv] - %ProgramFiles(x86)%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe [x]
HKLM-x32\...\Run: [ToshibaServiceStation] - "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 [1295736 2011-02-11] (TOSHIBA Corporation)
HKLM-x32\...\Run: [TRCMan] - C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe [701752 2009-07-21] (TOSHIBA Corporation)
HKLM-x32\...\Run: [TWebCamera] - "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun [2454840 2009-11-24] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [NPSStartup] - [x]
HKLM-x32\...\Run: [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-07-15] (Avira Operations GmbH & Co. KG)
HKU\Default\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe [6203296 2009-08-12] (TOSHIBA)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Reiner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Super Lyrics - {B9020890-9E08-446B-87B0-0C5CD0436D86} - C:\Program Files (x86)\Super_Lyrics\116.dll No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - No File
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @facebook.com/FBPlugin,version=1.0.3 - C:\Users\Reiner\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Reiner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Reiner\AppData\Local\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
Chrome:
=======
CHR DefaultSearchURL: (Hola Search) - hxxp://www.holasearch.com/?q={searchTerms}&affID=121962&tt=gc_&babsrc=SP_ss&mntrId=3213701A04C355D4
CHR DefaultSuggestURL: (Hola Search) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
==================== Services (Whitelisted) =================
R2 AntiVirFirewallService; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [654392 2013-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [371768 2013-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-15] (Avira Operations GmbH & Co. KG)
R2 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [124368 2010-10-26] (Toshiba Europe GmbH)
==================== Drivers (Whitelisted) ====================
R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [114608 2013-07-15] (Avira GmbH)
R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [141376 2013-07-15] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-07-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-07-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-07-15] (Avira Operations GmbH & Co. KG)
R3 hidshim; C:\Windows\System32\DRIVERS\hidshim.sys [6656 2009-08-31] (Windows (R) Win 7 DDK provider)
R3 nuvotoncir; C:\Windows\System32\DRIVERS\nuvotoncir.sys [48128 2009-08-31] (Nuvoton Technology Corporation)
R3 nuvotonhidcir; C:\Windows\System32\DRIVERS\nuvotonhidcir.sys [26624 2009-08-31] (Nuvoton Technology Corporation)
R3 O2SDGRDR; C:\Windows\System32\DRIVERS\o2sdgx64.sys [49568 2009-08-18] (O2Micro )
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-22 21:58 - 2013-07-22 21:58 - 00038016 _____ C:\Users\Reiner\Documents\FRST.txt
2013-07-22 21:58 - 2013-07-22 21:58 - 00024465 _____ C:\Users\Reiner\Documents\Addition FRST.txt
2013-07-22 21:49 - 2013-07-22 21:49 - 00000000 ____D C:\FRST
2013-07-22 21:48 - 2013-07-22 21:48 - 01779197 _____ (Farbar) C:\Users\Reiner\Desktop\FRST64.exe
2013-07-22 21:29 - 2013-07-22 21:29 - 00002222 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-22 21:26 - 2013-07-22 21:26 - 00005163 _____ C:\Users\Reiner\Documents\AdwCleaner[S1].txt
2013-07-22 21:24 - 2013-07-22 21:24 - 00005163 _____ C:\AdwCleaner[S1].txt
2013-07-22 21:23 - 2013-07-22 21:23 - 00005225 _____ C:\AdwCleaner[R4].txt
2013-07-22 20:15 - 2013-07-22 20:15 - 00005404 _____ C:\AdwCleaner[R3].txt
2013-07-22 19:44 - 2013-07-22 19:44 - 00005344 _____ C:\AdwCleaner[R2].txt
2013-07-22 19:40 - 2013-07-22 19:40 - 00005284 _____ C:\Users\Reiner\Documents\AdwCleaner[R1].txt
2013-07-22 19:40 - 2013-07-22 19:40 - 00005284 _____ C:\AdwCleaner[R1].txt
2013-07-22 19:39 - 2013-07-22 19:39 - 00666633 _____ C:\Users\Reiner\Desktop\adwcleaner.exe
2013-07-22 19:19 - 2013-07-22 20:33 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\Zip Opener Packages
2013-07-22 19:19 - 2013-07-22 19:19 - 00000000 ____D C:\Program Files (x86)\Super_Lyrics
2013-07-20 02:40 - 2013-07-20 02:42 - 00000000 ____D C:\Windows\system32\MRT
2013-07-20 02:29 - 2013-07-20 02:29 - 00793536 _____ C:\Users\Reiner\Downloads\ZipOpenerSetup (1).exe
2013-07-19 23:10 - 2013-07-20 11:44 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-07-19 23:06 - 2013-07-19 23:08 - 13399154 _____ C:\Users\Reiner\Downloads\mbar-1.06.0.1004.zip
2013-07-19 22:53 - 2013-07-19 22:53 - 00793536 _____ C:\Users\Reiner\Downloads\ZipOpenerSetup.exe
2013-07-19 22:49 - 2013-07-19 22:37 - 00000462 _____ C:\zoek-results19.07.2013-2237.log
2013-07-19 22:37 - 2013-07-19 22:37 - 00003124 _____ C:\Windows\System32\Tasks\{1FF0053F-70CF-4CDD-9ACB-42E6B4025455}
2013-07-19 22:36 - 2013-07-19 22:36 - 01274974 _____ C:\Users\Reiner\Downloads\zoek.exe
2013-07-19 22:36 - 2013-07-19 22:04 - 00000859 _____ C:\zoek-results19.07.2013-2204.log
2013-07-19 22:21 - 2013-07-20 02:29 - 00000306 __RSH C:\Users\Reiner\ntuser.pol
2013-07-19 22:20 - 2013-07-22 19:19 - 00003398 _____ C:\Windows\System32\Tasks\EPUpdater
2013-07-19 22:18 - 2013-07-22 19:19 - 00003238 _____ C:\Windows\System32\Tasks\DSite
2013-07-19 22:06 - 2013-07-19 22:06 - 00000859 _____ C:\Users\Reiner\Documents\zoek-results2.txt
2013-07-19 22:03 - 2013-07-19 20:59 - 00050377 _____ C:\zoek-results19.07.2013-2059.log
2013-07-19 21:56 - 2013-07-19 21:56 - 00129080 _____ C:\Users\Reiner\Documents\OTL.Txt
2013-07-19 21:56 - 2013-07-19 21:56 - 00080908 _____ C:\Users\Reiner\Documents\Extras.Txt
2013-07-19 21:03 - 2013-07-19 21:03 - 00050377 _____ C:\Users\Reiner\Documents\zoek-results.log
2013-07-19 20:56 - 2013-07-19 20:56 - 00003432 _____ C:\Windows\System32\Tasks\BrowserProtect
2013-07-19 20:46 - 2013-07-19 22:49 - 00000508 _____ C:\zoek-results.log
2013-07-18 21:40 - 2013-07-18 21:40 - 00001076 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-18 20:24 - 2013-07-18 20:24 - 00002982 _____ C:\Windows\System32\Tasks\{88254E50-0171-4044-B06C-FA3ED768A3F0}
2013-07-18 20:24 - 2013-07-18 20:24 - 00002982 _____ C:\Windows\System32\Tasks\{7A531A76-29F0-4B9F-A778-40A5983ECBB8}
2013-07-15 18:28 - 2013-07-15 18:28 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-07-15 18:28 - 2013-07-15 18:28 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\Avira
2013-07-15 18:27 - 2013-07-15 18:27 - 00001961 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-07-15 18:27 - 2013-07-15 18:27 - 00000000 ____D C:\Program Files (x86)\Avira
2013-07-15 18:27 - 2013-07-15 18:17 - 00141376 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwot.sys
2013-07-15 18:27 - 2013-07-15 18:17 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-07-15 18:27 - 2013-07-15 18:17 - 00114608 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwim.sys
2013-07-15 18:27 - 2013-07-15 18:17 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-07-15 18:27 - 2013-07-15 18:17 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-15 18:21 - 2013-07-15 18:21 - 00009847 _____ C:\Users\Reiner\Documents\Avira 2013.odt
2013-07-15 18:15 - 2013-07-15 18:15 - 02092776 _____ C:\Users\Reiner\Downloads\avira_internet_security(1).exe
2013-07-10 21:24 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-10 21:24 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-10 21:24 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-10 21:24 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-10 21:24 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-10 21:24 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-10 21:24 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-10 21:24 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-10 21:24 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-10 21:24 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-10 21:24 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-10 21:24 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-10 20:16 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-10 20:16 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-10 20:16 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-10 20:16 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-10 20:16 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-10 20:15 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-10 20:15 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-07 23:22 - 2013-07-22 18:59 - 00000005 _____ C:\Users\Reiner\AppData\Roaming\WBPU-TTL.DAT
2013-07-07 22:22 - 2013-07-22 19:23 - 00000000 ____D C:\ProgramData\Norton
2013-07-07 22:22 - 2013-07-07 22:22 - 00000000 ____D C:\ProgramData\Symantec
2013-07-07 22:21 - 2013-07-07 22:21 - 00794680 _____ C:\Users\Reiner\Downloads\ZipExtractorSetup.exe
2013-07-07 22:20 - 2013-07-07 22:20 - 06464840 _____ C:\Users\Reiner\Downloads\Default with Voice Name.rar
2013-07-07 22:20 - 2013-07-07 22:20 - 06464840 _____ C:\Users\Reiner\Downloads\Default with Voice Name (1).rar
2013-07-06 19:42 - 2013-07-06 19:42 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-06-27 15:42 - 2013-06-27 15:42 - 00014358 _____ C:\Users\Reiner\Downloads\Neue Termin Gastico Juli 2013.xlsx
==================== One Month Modified Files and Folders =======
2013-07-22 22:03 - 2012-06-30 19:09 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-22 21:58 - 2013-07-22 21:58 - 00038016 _____ C:\Users\Reiner\Documents\FRST.txt
2013-07-22 21:58 - 2013-07-22 21:58 - 00024465 _____ C:\Users\Reiner\Documents\Addition FRST.txt
2013-07-22 21:53 - 2010-03-17 18:20 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-22 21:49 - 2013-07-22 21:49 - 00000000 ____D C:\FRST
2013-07-22 21:48 - 2013-07-22 21:48 - 01779197 _____ (Farbar) C:\Users\Reiner\Desktop\FRST64.exe
2013-07-22 21:45 - 2009-07-14 06:45 - 00016304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-22 21:45 - 2009-07-14 06:45 - 00016304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-22 21:42 - 2010-01-26 15:28 - 02050182 _____ C:\Windows\WindowsUpdate.log
2013-07-22 21:37 - 2010-03-17 18:20 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-22 21:37 - 2009-12-13 23:32 - 00865640 _____ C:\Windows\PFRO.log
2013-07-22 21:37 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-22 21:37 - 2009-07-14 06:51 - 00247675 _____ C:\Windows\setupact.log
2013-07-22 21:29 - 2013-07-22 21:29 - 00002222 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-22 21:29 - 2009-12-13 23:33 - 00000000 ____D C:\Program Files (x86)\Google
2013-07-22 21:26 - 2013-07-22 21:26 - 00005163 _____ C:\Users\Reiner\Documents\AdwCleaner[S1].txt
2013-07-22 21:24 - 2013-07-22 21:24 - 00005163 _____ C:\AdwCleaner[S1].txt
2013-07-22 21:23 - 2013-07-22 21:23 - 00005225 _____ C:\AdwCleaner[R4].txt
2013-07-22 20:33 - 2013-07-22 19:19 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\Zip Opener Packages
2013-07-22 20:15 - 2013-07-22 20:15 - 00005404 _____ C:\AdwCleaner[R3].txt
2013-07-22 19:47 - 2011-09-02 22:36 - 00001142 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-87162310-1213645192-2319634588-1001UA.job
2013-07-22 19:44 - 2013-07-22 19:44 - 00005344 _____ C:\AdwCleaner[R2].txt
2013-07-22 19:40 - 2013-07-22 19:40 - 00005284 _____ C:\Users\Reiner\Documents\AdwCleaner[R1].txt
2013-07-22 19:40 - 2013-07-22 19:40 - 00005284 _____ C:\AdwCleaner[R1].txt
2013-07-22 19:39 - 2013-07-22 19:39 - 00666633 _____ C:\Users\Reiner\Desktop\adwcleaner.exe
2013-07-22 19:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-22 19:23 - 2013-07-07 22:22 - 00000000 ____D C:\ProgramData\Norton
2013-07-22 19:19 - 2013-07-22 19:19 - 00000000 ____D C:\Program Files (x86)\Super_Lyrics
2013-07-22 19:19 - 2013-07-19 22:20 - 00003398 _____ C:\Windows\System32\Tasks\EPUpdater
2013-07-22 19:19 - 2013-07-19 22:18 - 00003238 _____ C:\Windows\System32\Tasks\DSite
2013-07-22 18:59 - 2013-07-07 23:22 - 00000005 _____ C:\Users\Reiner\AppData\Roaming\WBPU-TTL.DAT
2013-07-20 11:44 - 2013-07-19 23:10 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-07-20 02:42 - 2013-07-20 02:40 - 00000000 ____D C:\Windows\system32\MRT
2013-07-20 02:39 - 2009-07-14 19:58 - 00654400 _____ C:\Windows\system32\perfh007.dat
2013-07-20 02:39 - 2009-07-14 19:58 - 00130240 _____ C:\Windows\system32\perfc007.dat
2013-07-20 02:39 - 2009-07-14 07:13 - 01520734 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-20 02:29 - 2013-07-20 02:29 - 00793536 _____ C:\Users\Reiner\Downloads\ZipOpenerSetup (1).exe
2013-07-20 02:29 - 2013-07-19 22:21 - 00000306 __RSH C:\Users\Reiner\ntuser.pol
2013-07-20 02:29 - 2010-03-17 17:57 - 00000000 ____D C:\Users\Reiner
2013-07-20 01:47 - 2011-09-02 22:36 - 00001120 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-87162310-1213645192-2319634588-1001Core.job
2013-07-19 23:08 - 2013-07-19 23:06 - 13399154 _____ C:\Users\Reiner\Downloads\mbar-1.06.0.1004.zip
2013-07-19 22:53 - 2013-07-19 22:53 - 00793536 _____ C:\Users\Reiner\Downloads\ZipOpenerSetup.exe
2013-07-19 22:49 - 2013-07-19 20:46 - 00000508 _____ C:\zoek-results.log
2013-07-19 22:37 - 2013-07-19 22:49 - 00000462 _____ C:\zoek-results19.07.2013-2237.log
2013-07-19 22:37 - 2013-07-19 22:37 - 00003124 _____ C:\Windows\System32\Tasks\{1FF0053F-70CF-4CDD-9ACB-42E6B4025455}
2013-07-19 22:36 - 2013-07-19 22:36 - 01274974 _____ C:\Users\Reiner\Downloads\zoek.exe
2013-07-19 22:21 - 2009-07-14 05:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-07-19 22:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2013-07-19 22:20 - 2013-04-12 16:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-19 22:06 - 2013-07-19 22:06 - 00000859 _____ C:\Users\Reiner\Documents\zoek-results2.txt
2013-07-19 22:04 - 2013-07-19 22:36 - 00000859 _____ C:\zoek-results19.07.2013-2204.log
2013-07-19 21:56 - 2013-07-19 21:56 - 00129080 _____ C:\Users\Reiner\Documents\OTL.Txt
2013-07-19 21:56 - 2013-07-19 21:56 - 00080908 _____ C:\Users\Reiner\Documents\Extras.Txt
2013-07-19 21:03 - 2013-07-19 21:03 - 00050377 _____ C:\Users\Reiner\Documents\zoek-results.log
2013-07-19 20:59 - 2013-07-19 22:03 - 00050377 _____ C:\zoek-results19.07.2013-2059.log
2013-07-19 20:56 - 2013-07-19 20:56 - 00003432 _____ C:\Windows\System32\Tasks\BrowserProtect
2013-07-18 21:40 - 2013-07-18 21:40 - 00001076 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-18 21:40 - 2011-01-06 23:42 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-18 21:30 - 2010-03-17 18:17 - 00000000 ____D C:\Users\Reiner\AppData\Local\Google
2013-07-18 21:02 - 2010-05-31 09:45 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\Mozilla
2013-07-18 20:55 - 2012-07-02 13:42 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\TS3Client
2013-07-18 20:24 - 2013-07-18 20:24 - 00002982 _____ C:\Windows\System32\Tasks\{88254E50-0171-4044-B06C-FA3ED768A3F0}
2013-07-18 20:24 - 2013-07-18 20:24 - 00002982 _____ C:\Windows\System32\Tasks\{7A531A76-29F0-4B9F-A778-40A5983ECBB8}
2013-07-15 18:28 - 2013-07-15 18:28 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-07-15 18:28 - 2013-07-15 18:28 - 00000000 ____D C:\Users\Reiner\AppData\Roaming\Avira
2013-07-15 18:27 - 2013-07-15 18:27 - 00001961 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-07-15 18:27 - 2013-07-15 18:27 - 00000000 ____D C:\Program Files (x86)\Avira
2013-07-15 18:27 - 2010-03-17 18:55 - 00000000 ____D C:\ProgramData\Avira
2013-07-15 18:21 - 2013-07-15 18:21 - 00009847 _____ C:\Users\Reiner\Documents\Avira 2013.odt
2013-07-15 18:17 - 2013-07-15 18:27 - 00141376 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwot.sys
2013-07-15 18:17 - 2013-07-15 18:27 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-07-15 18:17 - 2013-07-15 18:27 - 00114608 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwim.sys
2013-07-15 18:17 - 2013-07-15 18:27 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-07-15 18:17 - 2013-07-15 18:27 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-15 18:15 - 2013-07-15 18:15 - 02092776 _____ C:\Users\Reiner\Downloads\avira_internet_security(1).exe
2013-07-15 17:57 - 2009-12-13 23:31 - 00000000 ____D C:\Program Files (x86)\eBay
2013-07-15 17:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-07-15 17:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-07-15 17:48 - 2010-03-17 18:20 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-15 17:48 - 2010-03-17 18:20 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-11 17:52 - 2009-07-14 06:45 - 00390752 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-11 17:50 - 2013-03-13 23:30 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-11 17:50 - 2013-03-13 23:30 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-11 17:50 - 2009-07-14 20:18 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-11 17:50 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-11 17:50 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-07 22:22 - 2013-07-07 22:22 - 00000000 ____D C:\ProgramData\Symantec
2013-07-07 22:21 - 2013-07-07 22:21 - 00794680 _____ C:\Users\Reiner\Downloads\ZipExtractorSetup.exe
2013-07-07 22:20 - 2013-07-07 22:20 - 06464840 _____ C:\Users\Reiner\Downloads\Default with Voice Name.rar
2013-07-07 22:20 - 2013-07-07 22:20 - 06464840 _____ C:\Users\Reiner\Downloads\Default with Voice Name (1).rar
2013-07-06 19:42 - 2013-07-06 19:42 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-07-06 19:42 - 2013-02-07 23:26 - 00000000 ____D C:\Users\Reiner\Documents\SelfMV
2013-06-27 15:42 - 2013-06-27 15:42 - 00014358 _____ C:\Users\Reiner\Downloads\Neue Termin Gastico Juli 2013.xlsx
2013-06-24 00:57 - 2010-03-29 12:58 - 78277128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-15 08:57
==================== End Of Log ============================ --- --- ---
--- --- --- |