coolmann100 | 10.07.2014 18:32 |
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-07-2014
Ran by Lukas (administrator) on HP-ENVY-J105 on 10-07-2014 19:22:27
Running from C:\Users\Lukas\Downloads
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
(Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
(Avira GmbH) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira GmbH) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Validity Sensors, Inc.) C:\Windows\System32\valWBFPolicyService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\v08BlockAndSurf\BlockAndSurf.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe
(Avira GmbH) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9600.16384_x64__8wekyb3d8bbwe\glcnd.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-08-16] (IDT, Inc.)
HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2249104 2013-09-03] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [151608 2013-08-23] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [151608 2013-08-23] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-08-02] (Synaptics Incorporated)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [77088 2013-07-24] (Hewlett-Packard Company)
HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [267224 2013-08-01] (CyberLink Corp.)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-07-23] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft anti-malware\a2guard.exe [4841824 2014-07-09] (Emsisoft GmbH)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [209153 2009-03-02] (Avira GmbH)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\...\Run: [BlockAndSurf] => C:\Program Files (x86)\v08BlockAndSurf\BlockAndSurf.exe [131072 2014-07-09] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk
ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
ShellIconOverlayIdentifiers: ShareOverlay -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
ShellIconOverlayIdentifiers: StorageProviderError -> {0CA2640D-5B9C-4c59-A5FB-2DA61A7437CF} => C:\Windows\System32\shell32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: StorageProviderSyncing -> {0A30F902-8398-4ee8-86F7-4CFB589F04D1} => C:\Windows\System32\shell32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: ShareOverlay -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
ShellIconOverlayIdentifiers-x32: StorageProviderError -> {0CA2640D-5B9C-4c59-A5FB-2DA61A7437CF} => C:\Windows\SysWOW64\shell32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: StorageProviderSyncing -> {0A30F902-8398-4ee8-86F7-4CFB589F04D1} => C:\Windows\SysWOW64\shell32.dll (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {333F16B1-26A4-4EE6-86E4-CC4CDE08DA62} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\rfryvurn.default
FF NewTab: chrome://quick_start/content/index.html
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @videolan.org/vlc,version=2.1.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Yahoo Community Smartbar - C:\Users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\rfryvurn.default\Extensions\{4ca574c1-4cb9-1732-5830-6c3da0997330} [2014-07-09]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-11]
FF HKCU\...\Firefox\Extensions: [{CE3484DB-0318-6791-22A4-DBB2123B7E53}] - C:\Program Files (x86)\v08BlockAndSurf\174.xpi
FF Extension: No Name - C:\Program Files (x86)\v08BlockAndSurf\174.xpi [2014-07-09]
==================== Services (Whitelisted) =================
R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4741384 2014-07-09] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [108289 2009-05-13] (Avira GmbH) [File not signed]
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [185089 2009-07-21] (Avira GmbH) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-08-23] () [File not signed]
R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-08-12] (CyberLink)
R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-08-12] (CyberLink)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-08-29] (Hewlett-Packard Company) [File not signed]
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-07-23] (Hewlett-Packard Development Company, L.P.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-22] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-08-09] (Intel Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-12] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-09] (Intel Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-08-23] (Softex Inc.) [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [339456 2013-08-16] (IDT, Inc.) [File not signed]
R2 valWBFPolicyService; C:\Windows\system32\valWBFPolicyService.exe [32768 2013-08-01] (Validity Sensors, Inc.) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-08-26] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
S2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service [X]
==================== Drivers (Whitelisted) ====================
R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [73048 2009-04-06] (Avira GmbH)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-08] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-08] ()
R3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-08-07] ()
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-07] ()
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-09] (Intel Corporation)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204424 2013-12-02] (Ralink Technology, Corp.)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [429272 2013-08-22] (Realsil Semiconductor Corporation)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-08-02] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-02] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-10 19:22 - 2014-07-10 19:22 - 00017607 _____ () C:\Users\Lukas\Downloads\FRST.txt
2014-07-10 19:22 - 2014-07-10 19:22 - 00000000 ____D () C:\FRST
2014-07-10 19:21 - 2014-07-10 19:22 - 02084352 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64.exe
2014-07-10 13:29 - 2014-07-10 13:29 - 00001992 _____ () C:\Users\Lukas\Desktop\Skype.lnk
2014-07-10 00:36 - 2014-07-10 00:36 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-07-10 00:16 - 2014-07-10 00:16 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Macromedia
2014-07-09 23:52 - 2014-07-09 23:52 - 00002093 _____ () C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
2014-07-09 23:52 - 2014-07-09 23:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-07-09 23:52 - 2014-07-09 23:52 - 00000000 ____D () C:\ProgramData\Avira
2014-07-09 23:52 - 2014-07-09 23:52 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-07-09 23:52 - 2009-05-11 10:12 - 00028520 _____ (Avira GmbH) C:\Windows\SysWOW64\Drivers\ssmdrv.sys
2014-07-09 23:52 - 2009-04-06 10:51 - 00073048 _____ (Avira GmbH) C:\Windows\system32\Drivers\avgntflt.sys
2014-07-09 23:33 - 2014-07-10 14:12 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\vlc
2014-07-09 23:29 - 2014-07-09 23:29 - 00001114 _____ () C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2014-07-09 23:29 - 2014-07-09 23:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2014-07-09 23:28 - 2014-07-10 19:10 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2014-07-09 21:48 - 2014-07-09 22:56 - 00000000 ____D () C:\AdwCleaner
2014-07-09 21:46 - 2014-07-09 21:46 - 00002109 _____ () C:\Users\Lukas\Desktop\Mozilla Thunderbird.lnk
2014-07-09 21:46 - 2014-07-09 21:46 - 00001182 _____ () C:\Users\Lukas\Desktop\Mozilla Firefox.lnk
2014-07-09 21:44 - 2014-07-09 21:44 - 00000000 ____D () C:\Windows\ERUNT
2014-07-09 21:20 - 2014-07-09 21:20 - 00000894 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-07-09 21:20 - 2014-07-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-07-09 21:19 - 2014-07-09 21:19 - 00000000 ____D () C:\Program Files\VideoLAN
2014-07-09 21:18 - 2014-07-10 00:36 - 00000000 ____D () C:\Program Files (x86)\v08BlockAndSurf
2014-07-09 21:18 - 2014-07-09 21:18 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-07-09 21:18 - 2014-07-09 21:18 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf
2014-07-09 21:18 - 2014-07-09 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FrEeSoFtOdAy
2014-07-09 21:18 - 2014-06-26 07:24 - 00057528 _____ (Corsica) C:\Windows\system32\Drivers\webinstr.sys
2014-07-09 21:14 - 2014-07-09 21:14 - 00000000 ____D () C:\Users\Lukas\AppData\Local\CrashDumps
2014-07-09 21:12 - 2014-07-09 21:12 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\PDF Architect 2
2014-07-09 21:01 - 2014-07-09 21:50 - 00001123 _____ () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-09 20:59 - 2014-07-09 20:59 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-07-09 20:59 - 2014-07-09 20:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-07-09 20:58 - 2014-07-09 21:10 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-07-09 20:58 - 2014-07-09 20:58 - 00002121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-07-09 20:58 - 2014-07-09 20:58 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Thunderbird
2014-07-09 20:58 - 2014-07-09 20:58 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Thunderbird
2014-07-09 20:58 - 2014-07-09 20:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-07-09 20:58 - 2014-04-25 17:44 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-07-09 20:58 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-07-09 20:58 - 2014-04-25 17:44 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2014-07-09 20:58 - 2014-04-25 17:44 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-07-09 20:58 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-07-09 20:58 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6DE.DLL
2014-07-09 20:58 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCDE.DLL
2014-07-09 20:58 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCC2DE.DLL
2014-07-09 20:57 - 2014-07-09 20:57 - 00001559 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2014-07-09 20:57 - 2014-07-09 20:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-07-09 20:57 - 2014-07-09 20:57 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-07-09 20:54 - 2014-07-09 20:54 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Skype
2014-07-09 20:53 - 2014-07-10 13:31 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Skype
2014-07-09 20:53 - 2014-07-09 20:54 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-07-09 20:53 - 2014-07-09 20:53 - 00000000 ____D () C:\ProgramData\Skype
2014-07-09 20:53 - 2014-07-09 20:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-07-09 20:50 - 2014-07-09 20:58 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\DVDVideoSoft
2014-07-09 20:47 - 2014-07-09 20:47 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-07-09 20:47 - 2014-07-09 20:47 - 00000841 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-07-09 20:47 - 2014-07-09 20:47 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-09 20:46 - 2014-07-09 23:14 - 00000000 ____D () C:\Users\Lukas\Documents\PC alt
2014-07-09 20:23 - 2014-07-09 20:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2014-07-09 20:23 - 2014-07-09 20:23 - 00000000 ____D () C:\Program Files\Classic Shell
2014-07-09 20:20 - 2014-07-09 21:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-09 20:20 - 2014-07-09 20:21 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Mozilla
2014-07-09 20:20 - 2014-07-09 20:20 - 00001182 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-07-09 20:20 - 2014-07-09 20:20 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Mozilla
2014-07-09 20:20 - 2014-07-09 20:20 - 00000000 ____D () C:\ProgramData\Mozilla
2014-07-09 20:20 - 2014-07-09 20:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-09 16:40 - 2014-07-09 16:40 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Microsoft Corporation
2014-07-09 16:01 - 2014-07-10 19:19 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\ClassicShell
2014-07-09 16:01 - 2014-07-09 16:01 - 00000000 ____D () C:\ProgramData\ClassicShell
2014-07-09 15:59 - 2014-07-09 15:59 - 00000000 ____D () C:\Windows\LastGood.Tmp
2014-07-09 15:46 - 2014-07-09 15:46 - 00004032 _____ () C:\Windows\System32\Tasks\HPGenoobeReminder
2014-07-09 15:46 - 2014-07-09 15:46 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Macromedia
2014-07-09 14:13 - 2014-07-10 14:17 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3922937922-1857203726-1302306953-1002
2014-07-09 14:11 - 2014-07-09 15:46 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Hewlett-Packard
2014-07-09 14:11 - 2014-07-09 14:11 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\IDT
2014-07-09 14:10 - 2014-07-09 14:10 - 00000000 ____D () C:\Users\Lukas\Documents\Avatar
2014-07-09 14:10 - 2014-07-09 14:10 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\hpqlog
2014-07-09 14:09 - 2014-07-10 19:10 - 00000000 ____D () C:\Users\Lukas\Documents\Youcam
2014-07-09 14:09 - 2014-07-09 14:10 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Hewlett-Packard
2014-07-09 14:09 - 2014-07-09 14:09 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\CyberLink
2014-07-09 14:09 - 2014-07-09 14:09 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Power2Go8
2014-07-09 14:09 - 2014-07-09 14:09 - 00000000 ____D () C:\Users\Lukas\AppData\Local\CyberLink
2014-07-09 14:08 - 2014-07-09 14:08 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Synaptics
2014-07-09 14:07 - 2014-07-10 14:15 - 00273388 _____ () C:\Windows\WindowsUpdate.log
2014-07-09 14:07 - 2014-07-09 15:46 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Packages
2014-07-09 14:07 - 2014-07-09 14:07 - 00001461 _____ () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-09 14:07 - 2014-07-09 14:07 - 00000020 ___SH () C:\Users\Lukas\ntuser.ini
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Vorlagen
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Startmenü
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Netzwerkumgebung
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Lokale Einstellungen
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Eigene Dateien
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Druckumgebung
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Documents\Eigene Musik
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Documents\Eigene Bilder
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\AppData\Local\Verlauf
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\AppData\Local\Anwendungsdaten
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Anwendungsdaten
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Adobe
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 ____D () C:\Users\Lukas\AppData\Local\VirtualStore
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 ____D () C:\Users\Lukas
2014-07-09 14:07 - 2013-09-07 12:31 - 00000000 ___HD () C:\Users\Lukas\Documents\hp.system.package.metadata
2014-07-09 14:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-07-09 14:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-09 14:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-09 14:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Programme
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Dokumente und Einstellungen
==================== One Month Modified Files and Folders =======
2014-07-10 19:22 - 2014-07-10 19:22 - 00017607 _____ () C:\Users\Lukas\Downloads\FRST.txt
2014-07-10 19:22 - 2014-07-10 19:22 - 00000000 ____D () C:\FRST
2014-07-10 19:22 - 2014-07-10 19:21 - 02084352 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64.exe
2014-07-10 19:19 - 2014-07-09 16:01 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\ClassicShell
2014-07-10 19:10 - 2014-07-09 23:28 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2014-07-10 19:10 - 2014-07-09 14:09 - 00000000 ____D () C:\Users\Lukas\Documents\Youcam
2014-07-10 19:08 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-07-10 14:17 - 2014-07-09 14:13 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3922937922-1857203726-1302306953-1002
2014-07-10 14:15 - 2014-07-09 14:07 - 00273388 _____ () C:\Windows\WindowsUpdate.log
2014-07-10 14:12 - 2014-07-09 23:33 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\vlc
2014-07-10 13:57 - 2013-09-07 22:11 - 00801992 _____ () C:\Windows\system32\perfh007.dat
2014-07-10 13:57 - 2013-09-07 22:11 - 00174994 _____ () C:\Windows\system32\perfc007.dat
2014-07-10 13:57 - 2013-08-26 08:09 - 01924512 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-10 13:52 - 2014-02-19 10:37 - 00000000 ____D () C:\ProgramData\McAfee
2014-07-10 13:52 - 2014-02-19 10:37 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-07-10 13:52 - 2013-08-22 16:46 - 00023052 _____ () C:\Windows\setupact.log
2014-07-10 13:52 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-10 13:51 - 2013-08-26 08:01 - 00005866 _____ () C:\Windows\PFRO.log
2014-07-10 13:51 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-07-10 13:31 - 2014-07-09 20:53 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Skype
2014-07-10 13:29 - 2014-07-10 13:29 - 00001992 _____ () C:\Users\Lukas\Desktop\Skype.lnk
2014-07-10 13:24 - 2013-08-22 17:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-07-10 00:36 - 2014-07-10 00:36 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-07-10 00:36 - 2014-07-09 21:18 - 00000000 ____D () C:\Program Files (x86)\v08BlockAndSurf
2014-07-10 00:25 - 2014-02-19 10:33 - 00000000 ____D () C:\ProgramData\CyberLink
2014-07-10 00:16 - 2014-07-10 00:16 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Macromedia
2014-07-09 23:52 - 2014-07-09 23:52 - 00002093 _____ () C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
2014-07-09 23:52 - 2014-07-09 23:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-07-09 23:52 - 2014-07-09 23:52 - 00000000 ____D () C:\ProgramData\Avira
2014-07-09 23:52 - 2014-07-09 23:52 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-07-09 23:29 - 2014-07-09 23:29 - 00001114 _____ () C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2014-07-09 23:29 - 2014-07-09 23:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2014-07-09 23:14 - 2014-07-09 20:46 - 00000000 ____D () C:\Users\Lukas\Documents\PC alt
2014-07-09 22:56 - 2014-07-09 21:48 - 00000000 ____D () C:\AdwCleaner
2014-07-09 21:51 - 2014-07-09 20:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-09 21:50 - 2014-07-09 21:01 - 00001123 _____ () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-09 21:46 - 2014-07-09 21:46 - 00002109 _____ () C:\Users\Lukas\Desktop\Mozilla Thunderbird.lnk
2014-07-09 21:46 - 2014-07-09 21:46 - 00001182 _____ () C:\Users\Lukas\Desktop\Mozilla Firefox.lnk
2014-07-09 21:44 - 2014-07-09 21:44 - 00000000 ____D () C:\Windows\ERUNT
2014-07-09 21:20 - 2014-07-09 21:20 - 00000894 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-07-09 21:20 - 2014-07-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-07-09 21:19 - 2014-07-09 21:19 - 00000000 ____D () C:\Program Files\VideoLAN
2014-07-09 21:18 - 2014-07-09 21:18 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-07-09 21:18 - 2014-07-09 21:18 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf
2014-07-09 21:18 - 2014-07-09 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FrEeSoFtOdAy
2014-07-09 21:18 - 2013-08-22 17:36 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-07-09 21:18 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-07-09 21:14 - 2014-07-09 21:14 - 00000000 ____D () C:\Users\Lukas\AppData\Local\CrashDumps
2014-07-09 21:12 - 2014-07-09 21:12 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\PDF Architect 2
2014-07-09 21:10 - 2014-07-09 20:58 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-07-09 20:59 - 2014-07-09 20:59 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-07-09 20:59 - 2014-07-09 20:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-07-09 20:58 - 2014-07-09 20:58 - 00002121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-07-09 20:58 - 2014-07-09 20:58 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Thunderbird
2014-07-09 20:58 - 2014-07-09 20:58 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Thunderbird
2014-07-09 20:58 - 2014-07-09 20:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-07-09 20:58 - 2014-07-09 20:50 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\DVDVideoSoft
2014-07-09 20:57 - 2014-07-09 20:57 - 00001559 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2014-07-09 20:57 - 2014-07-09 20:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-07-09 20:57 - 2014-07-09 20:57 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-07-09 20:54 - 2014-07-09 20:54 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Skype
2014-07-09 20:54 - 2014-07-09 20:53 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-07-09 20:53 - 2014-07-09 20:53 - 00000000 ____D () C:\ProgramData\Skype
2014-07-09 20:53 - 2014-07-09 20:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-07-09 20:47 - 2014-07-09 20:47 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-07-09 20:47 - 2014-07-09 20:47 - 00000841 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-07-09 20:47 - 2014-07-09 20:47 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-09 20:23 - 2014-07-09 20:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2014-07-09 20:23 - 2014-07-09 20:23 - 00000000 ____D () C:\Program Files\Classic Shell
2014-07-09 20:21 - 2014-07-09 20:20 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Mozilla
2014-07-09 20:20 - 2014-07-09 20:20 - 00001182 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-07-09 20:20 - 2014-07-09 20:20 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Mozilla
2014-07-09 20:20 - 2014-07-09 20:20 - 00000000 ____D () C:\ProgramData\Mozilla
2014-07-09 20:20 - 2014-07-09 20:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-09 16:45 - 2013-09-07 12:34 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-07-09 16:40 - 2014-07-09 16:40 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Microsoft Corporation
2014-07-09 16:08 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-07-09 16:01 - 2014-07-09 16:01 - 00000000 ____D () C:\ProgramData\ClassicShell
2014-07-09 16:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\restore
2014-07-09 15:59 - 2014-07-09 15:59 - 00000000 ____D () C:\Windows\LastGood.Tmp
2014-07-09 15:59 - 2014-02-19 10:23 - 00002702 _____ () C:\Windows\system32\RaCoInst.log
2014-07-09 15:46 - 2014-07-09 15:46 - 00004032 _____ () C:\Windows\System32\Tasks\HPGenoobeReminder
2014-07-09 15:46 - 2014-07-09 15:46 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Macromedia
2014-07-09 15:46 - 2014-07-09 14:11 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Hewlett-Packard
2014-07-09 15:46 - 2014-07-09 14:07 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Packages
2014-07-09 14:15 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-07-09 14:11 - 2014-07-09 14:11 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\IDT
2014-07-09 14:10 - 2014-07-09 14:10 - 00000000 ____D () C:\Users\Lukas\Documents\Avatar
2014-07-09 14:10 - 2014-07-09 14:10 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\hpqlog
2014-07-09 14:10 - 2014-07-09 14:09 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Hewlett-Packard
2014-07-09 14:10 - 2013-09-07 21:56 - 00000000 ___HD () C:\HP
2014-07-09 14:10 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-07-09 14:09 - 2014-07-09 14:09 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\CyberLink
2014-07-09 14:09 - 2014-07-09 14:09 - 00000000 ____D () C:\Users\Lukas\AppData\Local\Power2Go8
2014-07-09 14:09 - 2014-07-09 14:09 - 00000000 ____D () C:\Users\Lukas\AppData\Local\CyberLink
2014-07-09 14:09 - 2014-02-19 10:36 - 00000000 ____D () C:\Users\Public\CyberLink
2014-07-09 14:08 - 2014-07-09 14:08 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Synaptics
2014-07-09 14:07 - 2014-07-09 14:07 - 00001461 _____ () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-09 14:07 - 2014-07-09 14:07 - 00000020 ___SH () C:\Users\Lukas\ntuser.ini
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Vorlagen
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Startmenü
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Netzwerkumgebung
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Lokale Einstellungen
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Eigene Dateien
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Druckumgebung
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Documents\Eigene Musik
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Documents\Eigene Bilder
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\AppData\Local\Verlauf
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\AppData\Local\Anwendungsdaten
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 _SHDL () C:\Users\Lukas\Anwendungsdaten
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Adobe
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 ____D () C:\Users\Lukas\AppData\Local\VirtualStore
2014-07-09 14:07 - 2014-07-09 14:07 - 00000000 ____D () C:\Users\Lukas
2014-07-09 14:07 - 2014-02-19 10:34 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
2014-07-09 14:07 - 2013-09-07 12:44 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2014-07-09 14:07 - 2013-09-07 12:41 - 00000000 ___RD () C:\Program Files\Online Services
2014-07-09 14:07 - 2013-09-07 12:41 - 00000000 ___RD () C:\Program Files (x86)\Online Services
2014-07-09 14:07 - 2013-09-07 12:34 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2014-07-09 14:07 - 2013-09-07 12:33 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2014-07-09 14:07 - 2013-09-01 04:03 - 00000000 ___HD () C:\SYSTEM.SAV
2014-07-09 14:03 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Programme
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-07-09 14:01 - 2014-07-09 14:01 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2014-07-09 14:01 - 2013-08-26 08:57 - 00000000 ____D () C:\Windows\Panther
2014-07-09 14:01 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows NT
2014-07-09 14:01 - 2013-08-22 15:36 - 00000000 __RHD () C:\Users\Default
2014-06-26 07:24 - 2014-07-09 21:18 - 00057528 _____ (Corsica) C:\Windows\system32\Drivers\webinstr.sys
Some content of TEMP:
====================
C:\Users\Lukas\AppData\Local\Temp\0007631404991346mcinst.exe
C:\Users\Lukas\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2013-08-26 08:01
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-07-2014
Ran by Lukas at 2014-07-10 19:23:03
Running from C:\Users\Lukas\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Emsisoft Anti-Malware (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
==================== Installed Programs ======================
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.3.133 - Adobe Systems, Inc.)
Avira AntiVir Personal - Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: - Avira GmbH)
BlockAndSurf (HKLM-x32\...\DF65F072-6737-C9C0-23A4-1C2C9D8F2BFA) (Version: - BlockAndSurf-software) <==== ATTENTION
CCleaner (HKLM\...\CCleaner) (Version: 4.15 - Piriform)
Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4.6515 - CyberLink Corp.)
CyberLink LabelPrint (x32 Version: 2.5.4.6515 - CyberLink Corp.) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.4.2928 - CyberLink Corp.)
CyberLink Media Suite 10 (x32 Version: 10.0.4.2928 - CyberLink Corp.) Hidden
Cyberlink PhotoDirector (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.2.4128 - CyberLink Corp.)
Cyberlink PhotoDirector (x32 Version: 3.0.2.4128 - CyberLink Corp.) Hidden
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.4.3130 - CyberLink Corp.)
CyberLink Power2Go 8 (x32 Version: 8.0.4.3130 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.4.3122 - CyberLink Corp.)
CyberLink PowerDirector 10 (x32 Version: 10.0.4.3122 - CyberLink Corp.) Hidden
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.1.3212 - CyberLink Corp.)
CyberLink PowerDVD 12 (x32 Version: 12.0.1.3212 - CyberLink Corp.) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.1.3202 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 5.0.1.3202 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Emsisoft Anti-Malware (HKLM-x32\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 9.0 - Emsisoft GmbH)
Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Free YouTube to MP3 Converter version 3.12.41.623 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.41.623 - DVDVideoSoft Ltd.)
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM-x32\...\{07F6DC37-0857-4B68-A675-4E35989E85E3}) (Version: 6.0.15.1 - Hewlett-Packard Company)
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: 1.0 - Meridian Audio Ltd)
HP Connected Music (Meridian - player) (HKCU\...\HPConnectedMusic) (Version: 1.1 (build 112) hp - Meridian Audio Ltd)
HP CoolSense (HKLM-x32\...\{59F8C5AA-91BD-423D-BF05-09A80F39898F}) (Version: 2.10.62 - Hewlett-Packard Company)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden
HP Documentation (HKLM-x32\...\{1154543C-D5D0-49BE-A004-82EE0A3746AE}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Postscript Converter (Version: 4.5.12202 - Hewlett-Packard) Hidden
HP Recovery Manager (x32 Version: 11.00 - Hewlett-Packard) Hidden
HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7045.4591 - Hewlett-Packard)
HP SimplePass (HKLM-x32\...\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.49 - Hewlett-Packard)
HP SimplePass (Version: 8.00.49 - Hewlett-Packard) Hidden
HP Support Assistant (HKLM-x32\...\{3AF15EEA-8EDF-4393-BB6C-CF8A9986486A}) (Version: 7.3.35.20 - Hewlett-Packard Company)
HP System Event Utility (HKLM-x32\...\{23EF407B-E7D0-4CB6-8916-43E5B9EEFDED}) (Version: 1.0.9 - Hewlett-Packard Company)
HP Utility Center (HKLM\...\{AED1C141-3AFC-47FE-AE90-C820AA60B103}) (Version: 2.2.5 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6491.0 - IDT)
Inst5675 (Version: 8.00.49 - Softex Inc.) Hidden
Inst5676 (Version: 8.00.49 - Softex Inc.) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3277 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.1.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (Version: 12.8.1.1000 - Intel Corporation) Hidden
Intel(R) Smart Connect Technology (HKLM\...\{26AA61D4-B04D-4E0D-8E20-94A8FF2EE64D}) (Version: 4.2.40.2439 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.6.0 - Mozilla)
Mozilla Thunderbird 24.6.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
NVIDIA Grafiktreiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 326.80 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden
NVIDIA Optimus 1.14.17 (Version: 1.14.17 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0604 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0604 - NVIDIA Corporation)
NVIDIA Systemsteuerung 326.80 (Version: 326.80 - NVIDIA Corporation) Hidden
NVIDIA Update 1.14.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.14.17 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.14.17 - NVIDIA Corporation) Hidden
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Ralink Bluetooth Stack64 (HKLM\...\{8A2E2A41-B814-407E-2F96-4E433C42AB78}) (Version: 11.0.739.0 - Mediatek)
Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.29.8105 - Mediatek)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.21239 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek)
Skype Click to Call (HKLM-x32\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.2.15747.10003 - Microsoft Corporation)
Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.105 - Skype Technologies S.A.)
sweet-page uninstall (HKLM-x32\...\sweet-page uninstall) (Version: - sweet-page) <==== ATTENTION
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.8.0 - Synaptics Incorporated)
Validity WBF DDK (HKLM\...\{21498212-1146-4540-8A81-6A1328BA19F2}) (Version: 4.5.228.0 - Validity Sensors, Inc.)
VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
WindowsMangerProtect20.0.0.502 (HKLM-x32\...\WindowsMangerProtect) (Version: 20.0.0.502 - WindowsProtect LIMITED)
Yahoo Community Smartbar (HKLM-x32\...\{3BC7022B-CDE0-4664-9AB6-E3EC25CE644A}) (Version: 11.63.66.17714 - Linkury Inc.) <==== ATTENTION
Yahoo Community Smartbar Engine (HKCU\...\{d4fb3539-cb3c-475a-b65a-6c8060268fa9}) (Version: 11.63.66.17714 - Linkury Inc.) <==== ATTENTION
==================== Restore Points =========================
09-07-2014 14:00:04 Installed Classic Shell
==================== Hosts content: ==========================
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {035792A1-D4EF-4A78-BF9A-AA9628C281A3} - System32\Tasks\Microsoft\Windows\Setup\SetupCleanupTask
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {13CB4529-7270-4C01-ABAB-FB8D54AD69D5} - \BlockAndSurf_wd No Task File <==== ATTENTION
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {48CB52FE-197C-47CE-B137-07B56C4F46AB} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-03-12] (CyberLink)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {506F12A5-FC1A-43A5-9A00-5AEEDE9A0A3F} - System32\Tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2013-06-07] (Hewlett-Packard Development Company, L.P.)
Task: {53FFC3DE-1F9A-4AEE-98D0-E181A6BA2389} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-08-09] (Hewlett-Packard)
Task: {68B3E432-B9A2-4856-8220-EE47C9505C74} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-08-09] (Hewlett-Packard)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DD34B78-8A15-4D50-813F-CB1BD9C2E3B6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-06-24] (Piriform Ltd)
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {85896823-057D-41AE-B758-2649AAFED8C1} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8A69FC0C-F62F-442A-A581-F4B34083D333} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-08-29] (Hewlett-Packard Company)
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {8F1E7921-8290-4CA9-BBD1-5BE82D327AF2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-29] (Hewlett-Packard Company)
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A9CA9951-C57F-4C5E-BBFC-8D2AC16D394E} - \BlockAndSurf Update No Task File <==== ATTENTION
Task: {A9DD1277-B12B-40DA-8648-DBC42EA0C277} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-08-29] (Hewlett-Packard Company)
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {ED542C28-2898-49CF-8CCF-6FECB506C917} - System32\Tasks\HPGenoobeReminder => C:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HP GenOOBE\HPGenOOBE.exe [2013-08-29] ()
==================== Loaded Modules (whitelisted) =============
2013-08-23 02:08 - 2013-08-23 02:08 - 00109568 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
2013-08-23 02:13 - 2013-08-23 02:13 - 00627200 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll
2013-08-23 02:09 - 2013-08-23 02:09 - 02508800 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2013-08-23 02:07 - 2013-08-23 02:07 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2013-08-23 02:07 - 2013-08-23 02:07 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2013-08-23 02:07 - 2013-08-23 02:07 - 00021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll
2013-08-23 02:20 - 2013-08-23 02:20 - 00304016 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll
2013-08-23 02:20 - 2013-08-23 02:20 - 01283472 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll
2013-08-12 20:06 - 2013-08-12 20:06 - 00198120 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2013-08-12 20:06 - 2013-08-12 20:06 - 00054760 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2013-08-12 20:06 - 2013-08-12 20:06 - 00034792 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll
2013-08-23 02:12 - 2013-08-23 02:12 - 00064000 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2014-07-09 21:18 - 2014-07-09 21:18 - 00131072 _____ () C:\Program Files (x86)\v08BlockAndSurf\BlockAndSurf.exe
2014-07-09 23:28 - 2014-06-18 15:50 - 00703800 _____ () C:\Program Files (x86)\Emsisoft Anti-Malware\fw32.dll
2014-07-09 23:52 - 2009-01-28 16:03 - 00326401 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-02-19 10:20 - 2013-08-09 14:25 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-02-19 10:36 - 2013-03-12 16:51 - 00626240 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2013-03-12 23:53 - 2013-03-12 23:53 - 00015424 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2014-07-09 20:20 - 2014-06-06 06:38 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/09/2014 09:13:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OPBHOBrokerDsktop.exe, Version: 8.0.0.49, Zeitstempel: 0x5216ff16
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000000000
ID des fehlerhaften Prozesses: 0xb50
Startzeit der fehlerhaften Anwendung: 0xOPBHOBrokerDsktop.exe0
Pfad der fehlerhaften Anwendung: OPBHOBrokerDsktop.exe1
Pfad des fehlerhaften Moduls: OPBHOBrokerDsktop.exe2
Berichtskennung: OPBHOBrokerDsktop.exe3
Vollständiger Name des fehlerhaften Pakets: OPBHOBrokerDsktop.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: OPBHOBrokerDsktop.exe5
Error: (07/09/2014 09:06:47 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm IEXPLORE.EXE, Version 11.0.9600.16384 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: f10
Startzeit: 01cf9ba89b046c3f
Endzeit: 11
Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Berichts-ID: 28ddadd0-079c-11e4-825d-54353061741e
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/09/2014 04:10:29 PM) (Source: Software Protection Platform Service) (EventID: 8208) (User: )
Description: Fehler bei der Erfassung des authentischen Tickets (hr=0x80072EE2) für die Vorlagen-ID {99d92734-d682-4d71-983e-d6ec3f16059f}.
Error: (07/09/2014 04:10:29 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Lizenzerwerb-Fehlerdetails.
hr=0x80072EE2
Error: (07/09/2014 04:08:09 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0xC004E028
Befehlszeilenargumente:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c7c00280-b24d-4e82-89ca-4f1288eb1d9e;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (07/09/2014 04:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0x80072EE7
Befehlszeilenargumente:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c7c00280-b24d-4e82-89ca-4f1288eb1d9e;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (07/09/2014 04:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8208) (User: )
Description: Fehler bei der Erfassung des authentischen Tickets (hr=0x80072EE7) für die Vorlagen-ID {99d92734-d682-4d71-983e-d6ec3f16059f}.
Error: (07/09/2014 04:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Lizenzerwerb-Fehlerdetails.
hr=0x80072EE7
Error: (07/09/2014 04:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8208) (User: )
Description: Fehler bei der Erfassung des authentischen Tickets (hr=0x80072EE7) für die Vorlagen-ID {99d92734-d682-4d71-983e-d6ec3f16059f}.
Error: (07/09/2014 04:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Lizenzerwerb-Fehlerdetails.
hr=0x80072EE7
System errors:
=============
Error: (07/10/2014 02:56:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "CyberLink PowerDVD 12 Media Server Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (07/10/2014 02:18:53 PM) (Source: DCOM) (EventID: 10010) (User: HP-ENVY-j105)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (07/10/2014 02:18:22 PM) (Source: DCOM) (EventID: 10010) (User: HP-ENVY-j105)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (07/10/2014 01:52:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WindowsMangerProtect Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (07/10/2014 01:24:01 PM) (Source: DCOM) (EventID: 10010) (User: HP-ENVY-j105)
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (07/10/2014 01:23:31 PM) (Source: DCOM) (EventID: 10010) (User: HP-ENVY-j105)
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (07/10/2014 08:07:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "CyberLink PowerDVD 12 Media Server Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (07/10/2014 08:06:21 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WindowsMangerProtect Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (07/10/2014 07:12:54 AM) (Source: DCOM) (EventID: 10010) (User: HP-ENVY-j105)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (07/10/2014 07:12:24 AM) (Source: DCOM) (EventID: 10010) (User: HP-ENVY-j105)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Microsoft Office Sessions:
=========================
Error: (07/09/2014 09:13:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: OPBHOBrokerDsktop.exe8.0.0.495216ff16unknown0.0.0.000000000c00000050000000000000000b5001cf9ba169a61531C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exeunknown2c13b880-079d-11e4-825d-54353061741e
Error: (07/09/2014 09:06:47 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.16384f1001cf9ba89b046c3f11C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE28ddadd0-079c-11e4-825d-54353061741e
Error: (07/09/2014 04:10:29 PM) (Source: Software Protection Platform Service) (EventID: 8208) (User: )
Description: hr=0x80072EE2{99d92734-d682-4d71-983e-d6ec3f16059f}
Error: (07/09/2014 04:10:29 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: hr=0x80072EE200010001(0x00000000, 16:08:04:897 - https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx)
00020001(0x00000000, 16:08:04:897)
00030001(0x00000000, 16:08:04:897 - https://validation-v2.sls.microsoft.com)
00030002(0x00000000, 16:08:04:897 - 0)
00040001(0x00000000, 16:08:04:897 - https://validation-v2.sls.microsoft.com)
00040002(0x00000000, 16:08:04:912 - 1, <NULL>, <NULL>, <NULL>)
00050002(0x80072F94, 16:08:05:053 - 0, 1)
00040006(0x00000001, 16:08:05:053 - 0, https://validation-v2.sls.microsoft.com, <N/A>, <N/A>)
00020005(0x00000000, 16:08:05:053 - 0)
00020008(0x80072EE2, 16:10:29:059 - SOAPAction: "hxxp://microsoft.com/SL/GenuineAdvantageService/IssueToken"
Content-Type: text/xml; charset=utf-8
, <soap:Envelope xmlns:soap="hxxp://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:soapenc="hxxp://schemas.xmlsoap.org/soap/encoding/"><soap:Body><RequestSecurityToken xmlns="hxxp://schemas.xmlsoap.org/ws/2004/04/security/trust"><TokenType>SLWGA</TokenType><RequestType>hxxp://schemas.xmlsoap.org/ws/2004/04/security/trust/Issue</RequestType><UseKey><Values xsi:nil="1"/></UseKey><Claims><Values xmlns:q1="hxxp://schemas.xmlsoap.org/ws/2004/04/security/trust" soapenc:arrayType="q1:TokenEntry[6]"><TokenEntry><Name>GenuineAdvantagePhase</Name><Value>GenuineAdvantagePhase1</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageVersion</Name><Value>1.0</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageTemplateId</Name><Value>{99d92734-d682-4d71-983e-d6ec3f16059f}</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageClientTransactionId</Name><Value>8d90703e-17d1-4050-a5d3-03447ad7f884</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageClientToken</Name><Value></Value></TokenEntry><TokenEntry><Name>GenuineAdvantageParameters</Name><Value>OSArch=9;OSVersion=6.3.9600.16402;ServiceVersion=6.3.9600.16402;AvailablePID2s=10005-40010-00024-AA527\2,00259-60600-00001-AA072\2,00259-30000-00001-AAOEM\2,00258-61080-00001-AAOEM\2,00258-61290-29984-AAOEM\3;TemplateId={99d92734-d682-4d71-983e-d6ec3f16059f};</Value></TokenEntry></Values></Claims></RequestSecurityToken></soap:Body></soap:Envelope>)
00010002(0x80072EE2, 16:10:29:059 - <NULL>)
00010003(0x80072EE2, 16:10:29:059)
Error: (07/09/2014 04:08:09 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0xC004E028RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c7c00280-b24d-4e82-89ca-4f1288eb1d9e;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (07/09/2014 04:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0x80072EE7RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c7c00280-b24d-4e82-89ca-4f1288eb1d9e;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (07/09/2014 04:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8208) (User: )
Description: hr=0x80072EE7{99d92734-d682-4d71-983e-d6ec3f16059f}
Error: (07/09/2014 04:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: hr=0x80072EE700010001(0x00000000, 16:06:51:490 - https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx)
00020001(0x00000000, 16:06:51:490)
00030001(0x00000000, 16:06:51:490 - https://validation-v2.sls.microsoft.com)
00030002(0x00000000, 16:06:51:490 - 0)
00040001(0x00000000, 16:06:51:490 - https://validation-v2.sls.microsoft.com)
00040002(0x00000000, 16:06:51:490 - 1, <NULL>, <NULL>, <NULL>)
00050002(0x80072F94, 16:06:51:490 - 0, 1)
00040006(0x00000001, 16:06:51:490 - 0, https://validation-v2.sls.microsoft.com, <N/A>, <N/A>)
00020005(0x00000000, 16:06:51:490 - 0)
00020008(0x80072EE7, 16:06:51:490 - SOAPAction: "hxxp://microsoft.com/SL/GenuineAdvantageService/IssueToken"
Content-Type: text/xml; charset=utf-8
, <soap:Envelope xmlns:soap="hxxp://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:soapenc="hxxp://schemas.xmlsoap.org/soap/encoding/"><soap:Body><RequestSecurityToken xmlns="hxxp://schemas.xmlsoap.org/ws/2004/04/security/trust"><TokenType>SLWGA</TokenType><RequestType>hxxp://schemas.xmlsoap.org/ws/2004/04/security/trust/Issue</RequestType><UseKey><Values xsi:nil="1"/></UseKey><Claims><Values xmlns:q1="hxxp://schemas.xmlsoap.org/ws/2004/04/security/trust" soapenc:arrayType="q1:TokenEntry[6]"><TokenEntry><Name>GenuineAdvantagePhase</Name><Value>GenuineAdvantagePhase1</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageVersion</Name><Value>1.0</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageTemplateId</Name><Value>{99d92734-d682-4d71-983e-d6ec3f16059f}</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageClientTransactionId</Name><Value>970f3fdf-67cf-4548-a7ad-98c635e52f5d</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageClientToken</Name><Value></Value></TokenEntry><TokenEntry><Name>GenuineAdvantageParameters</Name><Value>OSArch=9;OSVersion=6.3.9600.16402;ServiceVersion=6.3.9600.16402;AvailablePID2s=10005-40010-00024-AA527\2,00259-60600-00001-AA072\2,00259-30000-00001-AAOEM\2,00258-61080-00001-AAOEM\2,00258-61290-29984-AAOEM\3;TemplateId={99d92734-d682-4d71-983e-d6ec3f16059f};</Value></TokenEntry></Values></Claims></RequestSecurityToken></soap:Body></soap:Envelope>)
00010002(0x80072EE7, 16:06:51:490 - <NULL>)
00010003(0x80072EE7, 16:06:51:490)
Error: (07/09/2014 04:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8208) (User: )
Description: hr=0x80072EE7{99d92734-d682-4d71-983e-d6ec3f16059f}
Error: (07/09/2014 04:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: hr=0x80072EE700010001(0x00000000, 16:06:51:224 - https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx)
00020001(0x00000000, 16:06:51:224)
00030001(0x00000000, 16:06:51:224 - https://validation-v2.sls.microsoft.com)
00030002(0x00000000, 16:06:51:224 - 0)
00040001(0x00000000, 16:06:51:224 - https://validation-v2.sls.microsoft.com)
00040002(0x00000000, 16:06:51:240 - 1, <NULL>, <NULL>, <NULL>)
00050002(0x80072F94, 16:06:51:240 - 0, 1)
00040006(0x00000001, 16:06:51:240 - 0, https://validation-v2.sls.microsoft.com, <N/A>, <N/A>)
00020005(0x00000000, 16:06:51:240 - 0)
00020008(0x80072EE7, 16:06:51:240 - SOAPAction: "hxxp://microsoft.com/SL/GenuineAdvantageService/IssueToken"
Content-Type: text/xml; charset=utf-8
, <soap:Envelope xmlns:soap="hxxp://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:soapenc="hxxp://schemas.xmlsoap.org/soap/encoding/"><soap:Body><RequestSecurityToken xmlns="hxxp://schemas.xmlsoap.org/ws/2004/04/security/trust"><TokenType>SLWGA</TokenType><RequestType>hxxp://schemas.xmlsoap.org/ws/2004/04/security/trust/Issue</RequestType><UseKey><Values xsi:nil="1"/></UseKey><Claims><Values xmlns:q1="hxxp://schemas.xmlsoap.org/ws/2004/04/security/trust" soapenc:arrayType="q1:TokenEntry[6]"><TokenEntry><Name>GenuineAdvantagePhase</Name><Value>GenuineAdvantagePhase1</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageVersion</Name><Value>1.0</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageTemplateId</Name><Value>{99d92734-d682-4d71-983e-d6ec3f16059f}</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageClientTransactionId</Name><Value>af46b376-c27d-4ee8-996d-f22722c19fda</Value></TokenEntry><TokenEntry><Name>GenuineAdvantageClientToken</Name><Value></Value></TokenEntry><TokenEntry><Name>GenuineAdvantageParameters</Name><Value>OSArch=9;OSVersion=6.3.9600.16402;ServiceVersion=6.3.9600.16402;AvailablePID2s=10005-40010-00024-AA527\2,00259-60600-00001-AA072\2,00259-30000-00001-AAOEM\2,00258-61080-00001-AAOEM\2,00258-61290-29984-AAOEM\3;TemplateId={99d92734-d682-4d71-983e-d6ec3f16059f};</Value></TokenEntry></Values></Claims></RequestSecurityToken></soap:Body></soap:Envelope>)
00010002(0x80072EE7, 16:06:51:240 - <NULL>)
00010003(0x80072EE7, 16:06:51:240)
==================== Memory info ===========================
Percentage of memory in use: 19%
Total physical RAM: 12220.02 MB
Available physical RAM: 9857.72 MB
Total Pagefile: 14652.02 MB
Available Pagefile: 12186.56 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:681.17 GB) (Free:608.31 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:16.69 GB) (Free:1.69 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 699 GB) (Disk ID: 1E1F4777)
Partition: GPT Partition Type.
==================== End Of Log ============================
So hier die 2 Dateien ich bin auf Scan und danach hat er die ausgespuckt.
Ich hoffe das ist richtig so (das blöde Windows 8.1 bringt mich noch zum kotzen) |