![]() |
Plagegeister aller Art und deren Bekämpfung: Ist mein PC sauber`?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #1 |
| ![]() Ist mein PC sauber`? Hallo und Guten Tag Seit Heute kann mein Computer nach dem Start nichts mehr machen, dies für ca. 2 Minuten. Nach den 2 Minuten folgt ein Error Ton und anschließend läuft alles. Ich weiß nicht was das zu bedeuten hat und warum es aufeinmal auftretet früher lief alles ganz normal. Also nach dem Start kann ich dann gar keine Programme etc. öffnen überall steht keine Rückmeldung und alles hängt für eine lange Zeit. Ich weiß nicht was ich machen soll... EDIT: Und einmal hat mir Avira diese Meldung gezeigt: In der Datei 'C:\Program Files (x86)\Skype\Phone\Skype.exe' wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan] gefunden. ganz plötzlich. Weiß nicht ob das jetzt eine Fehlmeldung ist oder etwas richtiges. Ab und zu hängt mein PC ich kann nicht normal musik hören alles hängt etc und dies war vorher nicht so |
![]() | #2 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Ist mein PC sauber`? Hi,
__________________Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
__________________ |
![]() | #3 |
| ![]() Ist mein PC sauber`? Hi, Danke für die schnelle Antwort hier die Logs
__________________Log Nummer 1 Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-06-2013 01 Ran by Oguzhan (administrator) on 06-06-2013 20:25:40 Running from C:\Users\Oguzhan\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe () C:\Program Files (x86)\PHotkey\ASLDRSrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe (brother Industries Ltd) C:\Windows\SysWOW64\brsvc01a.exe (UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe (brother Industries Ltd) C:\Windows\SysWOW64\brss01a.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe () C:\Program Files (x86)\PHotkey\PHotkey.exe () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Memeo) C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe () C:\Program Files (x86)\watchmi\TvdService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe () C:\Program Files (x86)\PHotkey\PVDesktop.exe () C:\Program Files (x86)\PHotkey\PVDAgent.exe () C:\Program Files (x86)\PHotkey\POSD.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (TeamSpeak Systems GmbH) C:\Users\Oguzhan\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe () C:\Program Files (x86)\Rockstar Games\Grand Theft Auto San Andreas\samp.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11817576 2011-04-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 [2209896 2011-04-18] (Realtek Semiconductor) HKLM\...\Run: [PSQLLauncher] "C:\Program Files\Protector Suite\launcher.exe" /startup [84816 2010-12-10] (UPEK Inc.) HKLM\...\Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray [1935120 2011-05-02] (Intel(R) Corporation) HKLM\...\Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [10361616 2011-02-11] (Intel Corporation) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2028328 2010-01-22] (Synaptics Incorporated) HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4123 2012-05-30] () Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.) HKCU\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation) HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation) HKLM-x32\...\Run: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart [506712 2011-02-03] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2011-04-14] (Renesas Electronics Corporation) HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG) AppInit_DLLs: C:\Windows\system32\nvinitx.dll [239720 2011-06-12] (NVIDIA Corporation) Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: No Name - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No File BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Oguzhan\AppData\Roaming\Mozilla\Firefox\Profiles\8idmpker.default FF Homepage: hxxp://forum.life-of-german.org/index.php?page=Home FF NetworkProxy: "ftp", "" FF NetworkProxy: "ftp_port", 20319 FF NetworkProxy: "http", "" FF NetworkProxy: "http_port", 20319 FF NetworkProxy: "socks", "" FF NetworkProxy: "socks_port", 20319 FF NetworkProxy: "ssl", "" FF NetworkProxy: "ssl_port", 20319 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: No Name - C:\Users\Oguzhan\AppData\Roaming\Mozilla\Firefox\Profiles\8idmpker.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Oguzhan\AppData\Local\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Oguzhan\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Oguzhan\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Oguzhan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Extension: (Google Docs) - C:\Users\Oguzhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Oguzhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Oguzhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Oguzhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (Gmail) - C:\Users\Oguzhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-02] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-02] (Avira Operations GmbH & Co. KG) R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2009-12-19] () R2 Brother XP spl Service; C:\Windows\SysWOW64\brsvc01a.exe [57344 2004-06-14] (brother Industries Ltd) R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-07] () S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] () S3 npggsvc; C:\Windows\SysWow64\GameMon.des [3889424 2011-08-01] (INCA Internet Co., Ltd.) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2012-10-08] () R2 PnkBstrB; C:\Windows\SysWow64\PnkBstrB.exe [189248 2012-10-08] () R2 watchmi; C:\Program Files (x86)\watchmi\TvdService.exe [70144 2011-10-07] () ==================== Drivers (Whitelisted) ==================== R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-08-23] (DT Soft Ltd) S3 NPPTNT2; C:\Windows\SysWow64\npptNT2.sys [4682 2005-01-01] (INCA Internet Co., Ltd.) R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON) S3 ssudobex; C:\Windows\System32\DRIVERS\ssudobex.sys [203672 2013-04-03] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.) S3 ALSysIO; \??\C:\Users\Oguzhan\AppData\Local\Temp\ALSysIO64.sys [x] R2 avgntflt; system32\DRIVERS\avgntflt.sys [x] R1 avipbb; system32\DRIVERS\avipbb.sys [x] R1 avkmgr; system32\DRIVERS\avkmgr.sys [x] S3 dump_wmimmc; \??\C:\AeriaGames\Wolfteam-DE\GameGuard\dump_wmimmc.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S1 StarOpen; No ImagePath S3 wolf; \??\C:\Program Files (x86)\Joygame\WolfTeamTS\avital\wolf64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-06 20:25 - 2013-06-06 20:25 - 00000000 ____D C:\FRST 2013-06-06 20:23 - 2013-06-06 20:23 - 01917710 ____A (Farbar) C:\Users\Oguzhan\Downloads\FRST64.exe 2013-06-06 18:05 - 2013-06-06 18:05 - 00000056 ____A C:\Windows\setupact.log 2013-06-06 18:05 - 2013-06-06 18:05 - 00000000 ____A C:\Windows\setuperr.log 2013-06-06 16:53 - 2013-06-06 16:53 - 00120060 ____A C:\Users\Oguzhan\Downloads\Extras.Txt 2013-06-06 16:52 - 2013-06-06 16:52 - 00102306 ____A C:\Users\Oguzhan\Downloads\OTL.Txt 2013-06-06 16:43 - 2013-06-06 16:43 - 00602112 ____A (OldTimer Tools) C:\Users\Oguzhan\Downloads\OTL.exe 2013-06-06 07:16 - 2013-06-06 07:16 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{77054857-D401-404E-B8A8-7B5A096F8558} 2013-06-05 13:13 - 2013-06-05 13:14 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{85A618E7-73B8-4131-9B72-7384152F35E7} 2013-06-04 18:16 - 2013-06-04 18:25 - 00000465 ____A C:\Windows\SysWOW64\DetectiveBinder.ini 2013-06-04 18:16 - 2013-06-04 18:16 - 00165888 ___AH C:\Windows\SysWOW64\API.dll 2013-06-04 18:16 - 2013-06-04 18:16 - 00023982 ___AH C:\Windows\SysWOW64\API.ahk 2013-06-04 18:16 - 2013-06-04 18:16 - 00013452 ___AH C:\Windows\SysWOW64\GebäudeKomplexe.ini 2013-06-04 18:16 - 2013-06-04 18:16 - 00000037 ___AH C:\Windows\SysWOW64\API.ini 2013-06-04 13:16 - 2013-06-04 13:17 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{3B92FBFB-0D90-41A1-87AD-6627010A9142} 2013-06-03 21:11 - 2013-06-03 21:11 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{43DC9934-94B4-460E-A096-028FF9AF41C2} 2013-06-03 11:14 - 2013-06-03 11:14 - 00000000 ____D C:\Users\Oguzhan\Downloads\DetectiveBinder 2013-06-03 11:13 - 2013-06-03 11:13 - 00430275 ____A C:\Users\Oguzhan\Downloads\DetectiveBinder.rar 2013-06-03 08:59 - 2013-06-03 09:01 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{089128BC-AC5B-4F8A-A458-462629954430} 2013-06-02 16:02 - 2013-06-02 16:03 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{CF306D13-027C-462E-82A7-59A9FF72DEC4} 2013-06-01 23:19 - 2013-06-01 23:20 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{E3F96E72-B6EB-4BBC-9C78-9FA9D04C2CC3} 2013-05-31 23:28 - 2013-05-31 23:28 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{B80881EE-C2E8-4A1D-9E48-A39ADB35D1D8} 2013-05-31 13:11 - 2013-05-31 13:11 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-05-31 11:27 - 2013-05-31 11:27 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{5D5A4895-87A2-4840-B99E-82589C4D6358} 2013-05-30 22:23 - 2013-05-30 22:24 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{9A86FD61-1CAA-4029-8AD4-353DB6883E1A} 2013-05-30 10:01 - 2013-05-30 10:02 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{D38661A9-836B-4FE9-929A-3D567E421C11} 2013-05-29 16:46 - 2013-05-29 16:47 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{CC560BC9-F1AF-4ACF-8BBC-5D57975B9077} 2013-05-28 07:32 - 2013-05-28 07:33 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{B0CA6609-A34D-42BC-B9CD-8B0B62B75982} 2013-05-27 16:49 - 2013-05-27 16:49 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{F45A65C5-CDF0-4C7E-B5A4-CB050FF67F71} 2013-05-26 15:18 - 2013-05-26 15:19 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{CA1C8C1E-0CB6-472E-A02D-3892FFC17013} 2013-05-25 23:12 - 2013-05-25 23:12 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{4228BF68-7B19-46F1-8281-F40D7B8D8CB3} 2013-05-25 08:23 - 2013-05-25 08:23 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{F8D34A8E-E4DA-4265-B224-B29793C2A7C9} 2013-05-24 18:10 - 2013-05-24 18:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-05-24 12:25 - 2013-05-24 12:25 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{4D176431-7274-4EF0-BF15-C0CBB4155525} 2013-05-23 22:16 - 2013-05-23 22:18 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{F768AC61-3D23-416C-A8E5-819C1D52EDD6} 2013-05-23 19:37 - 2013-05-23 19:37 - 00000000 ____D C:\Users\Oguzhan\AppData\Roaming\Screaming Bee 2013-05-23 07:22 - 2013-05-23 07:22 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{546BDAFF-0AA8-4F8B-988C-FAB34F73A9E1} 2013-05-22 07:28 - 2013-05-22 07:29 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{4ED6DA97-94BE-4654-A7EB-3B6961A09CEA} 2013-05-21 13:04 - 2013-05-21 13:04 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{0739DAE7-445B-41AA-97DC-7293B73671F1} 2013-05-20 15:54 - 2013-05-20 15:55 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{12060DA5-2398-4706-9ABE-969E3565F15F} 2013-05-20 14:20 - 2013-05-20 14:20 - 00890880 ____A C:\Users\Oguzhan\Downloads\trollv4skill 5.exe 2013-05-20 11:30 - 2013-05-20 11:30 - 00951808 ____A C:\Users\Oguzhan\Downloads\bugatti.exe 2013-05-19 22:08 - 2013-05-19 22:10 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{FC957FD8-36B9-4E2B-B898-46973412FF64} 2013-05-18 22:54 - 2013-05-18 22:55 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{B1366123-9843-46AB-840D-63ABF84683EE} 2013-05-18 10:20 - 2013-05-18 10:20 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{506FD84E-B4A4-48CC-860C-352A1E6CF319} 2013-05-18 08:31 - 2013-05-18 08:31 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{B6D2B370-9B8E-4CFA-86FC-C6B5D8F7FB90} 2013-05-17 15:58 - 2013-05-17 15:58 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{F1F78A2A-4437-467E-993B-21C35122DEB6} 2013-05-17 12:42 - 2013-05-17 12:42 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{A16354B5-1F59-4508-B6FB-9B44E77C0837} 2013-05-16 13:32 - 2013-05-16 13:33 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{D32C5C13-4909-45EF-8352-7D1744EC348A} 2013-05-15 21:44 - 2013-04-05 08:52 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-15 21:44 - 2013-04-05 08:52 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-15 21:44 - 2013-04-05 08:52 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-05-15 21:44 - 2013-04-05 08:50 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-15 21:44 - 2013-04-05 08:50 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-15 21:44 - 2013-04-05 08:50 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-15 21:44 - 2013-04-05 08:50 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-15 21:44 - 2013-04-05 08:50 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-15 21:44 - 2013-04-05 08:50 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-15 21:44 - 2013-04-05 08:50 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-05-15 21:44 - 2013-04-05 08:50 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-05-15 21:44 - 2013-04-05 08:50 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-05-15 21:44 - 2013-04-05 08:50 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-05-15 21:44 - 2013-04-05 08:50 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-05-15 21:44 - 2013-04-05 07:28 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-05-15 21:44 - 2013-04-05 07:28 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-05-15 21:44 - 2013-04-05 07:26 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-05-15 21:44 - 2013-04-05 06:43 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-05-15 21:44 - 2013-04-05 06:29 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-05-15 21:44 - 2013-04-05 05:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-05-15 21:44 - 2013-04-05 05:38 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-05-15 18:29 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-05-15 18:29 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys 2013-05-15 18:29 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-05-15 18:29 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll 2013-05-15 18:29 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll 2013-05-15 18:29 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-05-15 18:29 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-05-15 18:29 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-05-15 18:29 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-05-15 18:29 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-05-15 18:29 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-05-15 18:29 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-05-15 18:29 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-05-15 18:29 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll 2013-05-15 13:17 - 2013-05-15 13:18 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{2A91F6BE-4449-429F-B070-63E10D2131EE} 2013-05-14 13:18 - 2013-05-14 13:18 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{60BB2D71-2DA1-445F-B3B1-E236A81F466C} 2013-05-13 19:13 - 2013-05-13 19:14 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{B8FBDBB0-B99C-41C9-AB0F-254F84130740} 2013-05-13 14:35 - 2013-05-13 14:35 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Virtual Desktop Manager 2013-05-13 14:32 - 2013-05-13 14:32 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Avira 2013-05-13 14:27 - 2013-05-13 14:27 - 00000000 ____D C:\Users\Gast\Documents\GTA San Andreas User Files 2013-05-13 14:24 - 2013-05-13 14:24 - 00191856 ____A C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2013-05-13 14:24 - 2013-05-13 14:24 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Protector Suite 2013-05-13 14:24 - 2013-05-13 14:24 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Intel Corporation 2013-05-13 14:24 - 2013-05-13 14:24 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Apple Computer 2013-05-13 14:24 - 2013-05-13 14:24 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Adobe 2013-05-13 14:23 - 2013-05-13 14:24 - 00000000 ____D C:\users\Gast 2013-05-13 14:23 - 2013-05-13 14:23 - 00000020 __ASH C:\Users\Gast\ntuser.ini 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Vorlagen 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Startmenü 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Netzwerkumgebung 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Lokale Einstellungen 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Eigene Dateien 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Druckumgebung 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Documents\Eigene Musik 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Documents\Eigene Bilder 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\AppData\Local\Verlauf 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\AppData\Local\Anwendungsdaten 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Anwendungsdaten 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Intel 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 ____D C:\Users\Gast\AppData\Local\VirtualStore 2013-05-13 14:23 - 2012-08-25 07:29 - 00000000 ____D C:\Users\Gast\AppData\Local\Microsoft Help 2013-05-13 14:23 - 2011-08-10 21:09 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Macromedia 2013-05-13 14:09 - 2013-05-13 14:09 - 00000292 ____A C:\Users\Oguzhan\Downloads\z0pfed berechtigungsschlüssel.txt 2013-05-13 06:48 - 2013-05-13 06:48 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{6C5B8987-B0F7-4AD5-8AF9-EEFCE62BAEC5} 2013-05-12 07:59 - 2013-05-12 07:59 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{034D0575-6308-4A2B-B485-88BCDBA042FF} 2013-05-11 13:11 - 2013-06-03 20:12 - 00000600 ____A C:\Users\Oguzhan\AppData\Local\PUTTY.RND 2013-05-11 13:02 - 2013-05-11 13:02 - 00483328 ____A (Simon Tatham) C:\Users\Oguzhan\Downloads\putty062.exe 2013-05-11 11:28 - 2013-05-11 12:40 - 00000000 ____D C:\Users\Oguzhan\Desktop\mathe blau gelb 2013-05-11 09:57 - 2013-05-11 11:27 - 00000000 ____D C:\Users\Oguzhan\Desktop\blau mathe u 2013-05-11 06:55 - 2013-05-11 06:55 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{6DA835BE-F53D-4245-B0D0-C099C5874B62} 2013-05-10 21:09 - 2013-05-11 09:58 - 00000000 ____D C:\Users\Oguzhan\Desktop\leerformate 2013-05-10 21:05 - 2013-05-10 21:06 - 00000000 ____D C:\Users\Oguzhan\Desktop\Projekt 3 U und Ankreuz 2013-05-10 21:02 - 2013-05-10 21:04 - 00000000 ____D C:\Users\Oguzhan\Desktop\Projekt 1 - 1.2 2013-05-10 17:51 - 2013-05-20 15:17 - 00000000 ____D C:\Users\Oguzhan\AppData\Roaming\TIPP10 2013-05-10 17:51 - 2013-05-10 17:51 - 00000000 ____D C:\Program Files (x86)\Tipp10 2013-05-10 17:50 - 2013-05-10 17:50 - 04441861 ____A ((c) 2006-2011, Tom Thielicke IT Solutions ) C:\Users\Oguzhan\Downloads\tipp10_win_v2-1-0.exe 2013-05-10 07:54 - 2013-05-10 07:54 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{AEA7AA68-E931-4447-BC3C-C3572ACD7D74} 2013-05-09 20:11 - 2013-05-09 20:11 - 00575354 ____A C:\Users\Oguzhan\Downloads\Settings allround.rar 2013-05-09 07:21 - 2013-05-09 07:22 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{F6318BD2-3015-4D49-A765-394782345AEE} 2013-05-08 21:02 - 2013-05-08 21:02 - 00002708 ____A C:\Users\Oguzhan\AppData\Local\recently-used.xbel 2013-05-08 11:58 - 2013-05-08 11:58 - 00501248 ____A (Facebook Inc.) C:\Users\Oguzhan\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe 2013-05-08 11:58 - 2013-05-08 11:58 - 00501248 ____A (Facebook Inc.) C:\Users\Oguzhan\Downloads\FacebookVideoCallSetup_v1.2.205.0 (1).exe 2013-05-08 06:34 - 2013-05-08 06:34 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{11CBCCE2-D04F-4398-A784-659690175F04} 2013-05-07 14:55 - 2013-05-07 14:55 - 00001300 ____A C:\Users\Oguzhan\Desktop\samp - Verknüpfung.lnk 2013-05-07 06:41 - 2013-05-07 06:41 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{AD03949B-FBFF-4D45-A418-5EA71821D269} ==================== One Month Modified Files and Folders ======= 2013-06-06 20:25 - 2013-06-06 20:25 - 00000000 ____D C:\FRST 2013-06-06 20:23 - 2013-06-06 20:23 - 01917710 ____A (Farbar) C:\Users\Oguzhan\Downloads\FRST64.exe 2013-06-06 19:54 - 2013-02-11 17:33 - 00001128 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-384833181-4078317062-3792428673-1002UA.job 2013-06-06 18:13 - 2009-07-14 06:45 - 00016944 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-06 18:13 - 2009-07-14 06:45 - 00016944 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-06 18:06 - 2012-07-14 23:21 - 00017408 ____A C:\Windows\System32\rpcnetp.exe 2013-06-06 18:05 - 2013-06-06 18:05 - 00000056 ____A C:\Windows\setupact.log 2013-06-06 18:05 - 2013-06-06 18:05 - 00000000 ____A C:\Windows\setuperr.log 2013-06-06 18:05 - 2012-07-15 09:48 - 00000000 ____D C:\Users\Oguzhan\Tracing 2013-06-06 18:05 - 2012-07-14 23:22 - 00017408 ____A C:\Windows\SysWOW64\rpcnetp.dll 2013-06-06 18:05 - 2012-07-14 17:23 - 00069792 ____A (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.dll 2013-06-06 18:05 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-06 18:04 - 2013-01-02 00:22 - 02023627 ____A C:\Windows\WindowsUpdate.log 2013-06-06 18:04 - 2012-07-14 23:21 - 00017408 ____A C:\Windows\SysWOW64\rpcnetp.exe 2013-06-06 16:53 - 2013-06-06 16:53 - 00120060 ____A C:\Users\Oguzhan\Downloads\Extras.Txt 2013-06-06 16:52 - 2013-06-06 16:52 - 00102306 ____A C:\Users\Oguzhan\Downloads\OTL.Txt 2013-06-06 16:43 - 2013-06-06 16:43 - 00602112 ____A (OldTimer Tools) C:\Users\Oguzhan\Downloads\OTL.exe 2013-06-06 15:15 - 2012-12-17 15:31 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-06-06 15:08 - 2012-07-14 20:10 - 00000000 ____D C:\Users\Oguzhan\AppData\Roaming\Skype 2013-06-06 14:48 - 2012-08-30 18:17 - 01613340 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-06 14:48 - 2011-05-16 16:04 - 00697082 ____A C:\Windows\System32\perfh007.dat 2013-06-06 14:48 - 2011-05-16 16:04 - 00148346 ____A C:\Windows\System32\perfc007.dat 2013-06-06 07:16 - 2013-06-06 07:16 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{77054857-D401-404E-B8A8-7B5A096F8558} 2013-06-05 23:47 - 2013-02-07 21:33 - 00000000 ____D C:\Users\Oguzhan\AppData\Roaming\Winamp 2013-06-05 23:47 - 2012-08-01 15:57 - 00000000 ____D C:\Program Files (x86)\Steam 2013-06-05 21:48 - 2013-03-26 09:18 - 00000000 ____D C:\Program Files (x86)\Rockstar Games 2013-06-05 15:57 - 2013-02-11 17:35 - 00002380 ____A C:\Users\Oguzhan\Desktop\Google Chrome.lnk 2013-06-05 13:14 - 2013-06-05 13:13 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{85A618E7-73B8-4131-9B72-7384152F35E7} 2013-06-04 21:54 - 2013-03-29 14:39 - 00000000 ____D C:\Users\Oguzhan\Documents\Bandicam 2013-06-04 18:25 - 2013-06-04 18:16 - 00000465 ____A C:\Windows\SysWOW64\DetectiveBinder.ini 2013-06-04 18:16 - 2013-06-04 18:16 - 00165888 ___AH C:\Windows\SysWOW64\API.dll 2013-06-04 18:16 - 2013-06-04 18:16 - 00023982 ___AH C:\Windows\SysWOW64\API.ahk 2013-06-04 18:16 - 2013-06-04 18:16 - 00013452 ___AH C:\Windows\SysWOW64\GebäudeKomplexe.ini 2013-06-04 18:16 - 2013-06-04 18:16 - 00000037 ___AH C:\Windows\SysWOW64\API.ini 2013-06-04 13:17 - 2013-06-04 13:16 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{3B92FBFB-0D90-41A1-87AD-6627010A9142} 2013-06-03 21:11 - 2013-06-03 21:11 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{43DC9934-94B4-460E-A096-028FF9AF41C2} 2013-06-03 20:12 - 2013-05-11 13:11 - 00000600 ____A C:\Users\Oguzhan\AppData\Local\PUTTY.RND 2013-06-03 15:35 - 2013-05-06 17:30 - 00165888 ____A C:\Users\Oguzhan\Downloads\API2.dll 2013-06-03 11:14 - 2013-06-03 11:14 - 00000000 ____D C:\Users\Oguzhan\Downloads\DetectiveBinder 2013-06-03 11:13 - 2013-06-03 11:13 - 00430275 ____A C:\Users\Oguzhan\Downloads\DetectiveBinder.rar 2013-06-03 09:01 - 2013-06-03 08:59 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{089128BC-AC5B-4F8A-A458-462629954430} 2013-06-02 16:03 - 2013-06-02 16:02 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{CF306D13-027C-462E-82A7-59A9FF72DEC4} 2013-06-01 23:20 - 2013-06-01 23:19 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{E3F96E72-B6EB-4BBC-9C78-9FA9D04C2CC3} 2013-05-31 23:28 - 2013-05-31 23:28 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{B80881EE-C2E8-4A1D-9E48-A39ADB35D1D8} 2013-05-31 13:11 - 2013-05-31 13:11 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-05-31 12:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-05-31 11:27 - 2013-05-31 11:27 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{5D5A4895-87A2-4840-B99E-82589C4D6358} 2013-05-30 22:24 - 2013-05-30 22:23 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{9A86FD61-1CAA-4029-8AD4-353DB6883E1A} 2013-05-30 10:02 - 2013-05-30 10:01 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{D38661A9-836B-4FE9-929A-3D567E421C11} 2013-05-29 16:47 - 2013-05-29 16:46 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{CC560BC9-F1AF-4ACF-8BBC-5D57975B9077} 2013-05-28 18:00 - 2011-07-18 23:06 - 00000000 ____D C:\ProgramData\Adobe 2013-05-28 17:59 - 2012-07-14 18:00 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-05-28 17:59 - 2011-08-10 21:09 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-05-28 13:17 - 2009-07-14 07:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-05-28 07:33 - 2013-05-28 07:32 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{B0CA6609-A34D-42BC-B9CD-8B0B62B75982} 2013-05-27 16:49 - 2013-05-27 16:49 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{F45A65C5-CDF0-4C7E-B5A4-CB050FF67F71} 2013-05-26 15:34 - 2013-05-06 17:30 - 00000038 ____A C:\Users\Oguzhan\Downloads\API.ini 2013-05-26 15:34 - 2013-04-30 17:09 - 00226816 ____A C:\Users\Oguzhan\Downloads\API.dll 2013-05-26 15:34 - 2013-04-30 14:24 - 02427904 ____A C:\Users\Oguzhan\Downloads\Keybinder.exe 2013-05-26 15:19 - 2013-05-26 15:18 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{CA1C8C1E-0CB6-472E-A02D-3892FFC17013} 2013-05-26 12:53 - 2012-08-11 22:51 - 00000000 ____D C:\Users\Oguzhan\Desktop\Mein Ordner 2013-05-26 08:54 - 2013-02-11 17:33 - 00001076 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-384833181-4078317062-3792428673-1002Core.job 2013-05-25 23:12 - 2013-05-25 23:12 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{4228BF68-7B19-46F1-8281-F40D7B8D8CB3} 2013-05-25 08:23 - 2013-05-25 08:23 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{F8D34A8E-E4DA-4265-B224-B29793C2A7C9} 2013-05-24 22:47 - 2012-07-14 17:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-05-24 18:10 - 2013-05-24 18:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-05-24 12:25 - 2013-05-24 12:25 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{4D176431-7274-4EF0-BF15-C0CBB4155525} 2013-05-23 22:18 - 2013-05-23 22:16 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{F768AC61-3D23-416C-A8E5-819C1D52EDD6} 2013-05-23 19:37 - 2013-05-23 19:37 - 00000000 ____D C:\Users\Oguzhan\AppData\Roaming\Screaming Bee 2013-05-23 07:22 - 2013-05-23 07:22 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{546BDAFF-0AA8-4F8B-988C-FAB34F73A9E1} 2013-05-22 07:29 - 2013-05-22 07:28 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{4ED6DA97-94BE-4654-A7EB-3B6961A09CEA} 2013-05-21 13:04 - 2013-05-21 13:04 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{0739DAE7-445B-41AA-97DC-7293B73671F1} 2013-05-21 12:19 - 2012-10-19 20:58 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\PMB Files 2013-05-21 12:19 - 2012-10-19 20:58 - 00000000 ____D C:\ProgramData\PMB Files 2013-05-20 15:55 - 2013-05-20 15:54 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{12060DA5-2398-4706-9ABE-969E3565F15F} 2013-05-20 15:17 - 2013-05-10 17:51 - 00000000 ____D C:\Users\Oguzhan\AppData\Roaming\TIPP10 2013-05-20 14:20 - 2013-05-20 14:20 - 00890880 ____A C:\Users\Oguzhan\Downloads\trollv4skill 5.exe 2013-05-20 14:20 - 2013-04-28 08:42 - 00075277 ____A C:\Users\Oguzhan\Downloads\trollv4skill 5.ahk 2013-05-20 11:30 - 2013-05-20 11:30 - 00951808 ____A C:\Users\Oguzhan\Downloads\bugatti.exe 2013-05-19 22:10 - 2013-05-19 22:08 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{FC957FD8-36B9-4E2B-B898-46973412FF64} 2013-05-18 22:55 - 2013-05-18 22:54 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{B1366123-9843-46AB-840D-63ABF84683EE} 2013-05-18 10:20 - 2013-05-18 10:20 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{506FD84E-B4A4-48CC-860C-352A1E6CF319} 2013-05-18 08:31 - 2013-05-18 08:31 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{B6D2B370-9B8E-4CFA-86FC-C6B5D8F7FB90} 2013-05-17 15:58 - 2013-05-17 15:58 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{F1F78A2A-4437-467E-993B-21C35122DEB6} 2013-05-17 12:42 - 2013-05-17 12:42 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{A16354B5-1F59-4508-B6FB-9B44E77C0837} 2013-05-16 16:42 - 2011-07-18 22:54 - 00000000 ____D C:\Windows\Panther 2013-05-16 13:33 - 2013-05-16 13:32 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{D32C5C13-4909-45EF-8352-7D1744EC348A} 2013-05-16 13:05 - 2009-07-14 06:45 - 00630728 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-15 21:51 - 2012-08-23 15:44 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-05-15 21:49 - 2011-07-18 22:31 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-05-15 13:18 - 2013-05-15 13:17 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{2A91F6BE-4449-429F-B070-63E10D2131EE} 2013-05-14 13:18 - 2013-05-14 13:18 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{60BB2D71-2DA1-445F-B3B1-E236A81F466C} 2013-05-14 13:16 - 2012-08-24 07:14 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-05-14 13:16 - 2012-08-24 07:14 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-05-13 19:14 - 2013-05-13 19:13 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{B8FBDBB0-B99C-41C9-AB0F-254F84130740} 2013-05-13 14:35 - 2013-05-13 14:35 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Virtual Desktop Manager 2013-05-13 14:34 - 2012-07-14 21:04 - 00001511 ____A C:\Users\Oguzhan\Desktop\TeamSpeak 3 Client.lnk 2013-05-13 14:32 - 2013-05-13 14:32 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Avira 2013-05-13 14:27 - 2013-05-13 14:27 - 00000000 ____D C:\Users\Gast\Documents\GTA San Andreas User Files 2013-05-13 14:24 - 2013-05-13 14:24 - 00191856 ____A C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2013-05-13 14:24 - 2013-05-13 14:24 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Protector Suite 2013-05-13 14:24 - 2013-05-13 14:24 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Intel Corporation 2013-05-13 14:24 - 2013-05-13 14:24 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Apple Computer 2013-05-13 14:24 - 2013-05-13 14:24 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Adobe 2013-05-13 14:24 - 2013-05-13 14:23 - 00000000 ____D C:\users\Gast 2013-05-13 14:23 - 2013-05-13 14:23 - 00000020 __ASH C:\Users\Gast\ntuser.ini 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Vorlagen 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Startmenü 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Netzwerkumgebung 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Lokale Einstellungen 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Eigene Dateien 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Druckumgebung 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Documents\Eigene Musik 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Documents\Eigene Bilder 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\AppData\Local\Verlauf 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\AppData\Local\Anwendungsdaten 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 __SHD C:\Users\Gast\Anwendungsdaten 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Intel 2013-05-13 14:23 - 2013-05-13 14:23 - 00000000 ____D C:\Users\Gast\AppData\Local\VirtualStore 2013-05-13 14:09 - 2013-05-13 14:09 - 00000292 ____A C:\Users\Oguzhan\Downloads\z0pfed berechtigungsschlüssel.txt 2013-05-13 07:25 - 2012-11-30 18:15 - 00000000 ____D C:\Users\Oguzhan\Desktop\Oguzhan Bewerbung komplett 2013-05-13 06:48 - 2013-05-13 06:48 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{6C5B8987-B0F7-4AD5-8AF9-EEFCE62BAEC5} 2013-05-12 19:58 - 2013-03-16 19:55 - 00000000 ____D C:\Users\Oguzhan\Downloads\SCREENFAKE 2013-05-12 07:59 - 2013-05-12 07:59 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{034D0575-6308-4A2B-B485-88BCDBA042FF} 2013-05-11 13:02 - 2013-05-11 13:02 - 00483328 ____A (Simon Tatham) C:\Users\Oguzhan\Downloads\putty062.exe 2013-05-11 12:40 - 2013-05-11 11:28 - 00000000 ____D C:\Users\Oguzhan\Desktop\mathe blau gelb 2013-05-11 11:27 - 2013-05-11 09:57 - 00000000 ____D C:\Users\Oguzhan\Desktop\blau mathe u 2013-05-11 09:58 - 2013-05-10 21:09 - 00000000 ____D C:\Users\Oguzhan\Desktop\leerformate 2013-05-11 06:55 - 2013-05-11 06:55 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{6DA835BE-F53D-4245-B0D0-C099C5874B62} 2013-05-10 21:06 - 2013-05-10 21:05 - 00000000 ____D C:\Users\Oguzhan\Desktop\Projekt 3 U und Ankreuz 2013-05-10 21:04 - 2013-05-10 21:02 - 00000000 ____D C:\Users\Oguzhan\Desktop\Projekt 1 - 1.2 2013-05-10 18:39 - 2012-10-01 23:10 - 00039936 ____A (Absolute Software Corporation) C:\Windows\SysWOW64\identprv.dll 2013-05-10 17:51 - 2013-05-10 17:51 - 00000000 ____D C:\Program Files (x86)\Tipp10 2013-05-10 17:50 - 2013-05-10 17:50 - 04441861 ____A ((c) 2006-2011, Tom Thielicke IT Solutions ) C:\Users\Oguzhan\Downloads\tipp10_win_v2-1-0.exe 2013-05-10 07:54 - 2013-05-10 07:54 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{AEA7AA68-E931-4447-BC3C-C3572ACD7D74} 2013-05-09 20:11 - 2013-05-09 20:11 - 00575354 ____A C:\Users\Oguzhan\Downloads\Settings allround.rar 2013-05-09 07:22 - 2013-05-09 07:21 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{F6318BD2-3015-4D49-A765-394782345AEE} 2013-05-08 21:03 - 2013-01-31 17:39 - 00000000 ____D C:\Users\Oguzhan\.gimp-2.8 2013-05-08 21:02 - 2013-05-08 21:02 - 00002708 ____A C:\Users\Oguzhan\AppData\Local\recently-used.xbel 2013-05-08 11:58 - 2013-05-08 11:58 - 00501248 ____A (Facebook Inc.) C:\Users\Oguzhan\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe 2013-05-08 11:58 - 2013-05-08 11:58 - 00501248 ____A (Facebook Inc.) C:\Users\Oguzhan\Downloads\FacebookVideoCallSetup_v1.2.205.0 (1).exe 2013-05-08 06:34 - 2013-05-08 06:34 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{11CBCCE2-D04F-4398-A784-659690175F04} 2013-05-07 14:55 - 2013-05-07 14:55 - 00001300 ____A C:\Users\Oguzhan\Desktop\samp - Verknüpfung.lnk 2013-05-07 06:41 - 2013-05-07 06:41 - 00000000 ____D C:\Users\Oguzhan\AppData\Local\{AD03949B-FBFF-4D45-A418-5EA71821D269} ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit Last Boot: 2013-06-04 16:13 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-06-2013 01 Ran by Oguzhan at 2013-06-06 20:26:45 Run: Running from C:\Users\Oguzhan\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe AIR (Version: Adobe Flash Player 11 ActiveX (Version: 11.5.502.149) Adobe Flash Player 11 Plugin (Version: 11.7.700.202) Adobe Reader X (10.1.4) MUI (Version: 10.1.4) Apple Application Support (Version: 2.3.3) Apple Mobile Device Support (Version: Apple Software Update (Version: Audacity 2.0.2 (Version: 2.0.2) AutoHotkey (Version: Avira Free Antivirus (Version: Bandicam (Version: Bandisoft MPEG-1 Decoder Bonjour (Version: Brother MFL-Pro Suite DCP-115C (Version: Call of Duty: Black Ops - Multiplayer Call of Duty: Modern Warfare 3 Call of Duty: Modern Warfare 3 - Multiplayer CCleaner (Version: 3.21) COMPUTERBILD Vorteil-Center (Version: 1.1.23) Control ActiveX de Windows Live Mesh para conexiones remotas (Version: 15.4.5722.2) Contrôle ActiveX Windows Live Mesh pour connexions à distance (Version: 15.4.5722.2) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (Version: 15.4.5722.2) Core Temp 1.0 RC4 (Version: 1.0) Counter-Strike: Source CyberLink LabelPrint (Version: 2.5.3624) CyberLink Power2Go (Version: CyberLink PowerDVD Copy (Version: 1.5.1306) CyberLink PowerRecover (Version: 5.5.4125) CyberLink YouCam (Version: 3.1.4013) D3DX10 (Version: 15.4.2368.0902) DAEMON Tools Lite (Version: Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Dolby Home Theater v4 (Version: 7.2.7000.4) Facebook Video Calling (Version: 1.2.287) FileZilla Client (Version: Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsluge polaczen zdalnych (Version: 15.4.5722.2) Fotogalerija Windows Live (Version: 15.4.3502.0922) Free Audio Converter version (Version: Free YouTube Download version (Version: Free YouTube to MP3 Converter version (Version: Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922) Galería fotográfica de Windows Live (Version: 15.4.3502.0922) Galeria fotografii uslugi Windows Live (Version: 15.4.3502.0922) Galerie de photos Windows Live (Version: 15.4.3502.0922) GIMP 2.8.0 (Version: 2.8.0) Google Chrome (Version: 27.0.1453.110) Google Earth (Version: Google Update Helper (Version: Grand Theft Auto San Andreas (Version: 1.00.00001) Intel PROSet Wireless Intel(R) Processor Graphics (Version: Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (Version: Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: Intel(R) PROSet/Wireless WiFi Software (Version: 14.01.1000) Intel(R) Rapid Storage Technology (Version: iTunes (Version: Java Auto Updater (Version: Java(TM) 6 Update 26 (64-bit) (Version: 6.0.260) Java(TM) 6 Update 26 (Version: 6.0.260) Junk Mail filter update (Version: 15.4.3502.0922) Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (Version: 15.4.5722.2) League of Legends (Version: 1.3) Malwarebytes Anti-Malware Version (Version: Medion Home Cinema (Version: 8.0.3216) Memeo Instant Backup (Version: Mesh Runtime (Version: 15.4.5722.2) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320) Microsoft .NET Framework 4 Extended (Version: 4.0.30320) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30320) Microsoft .NET Framework 4 Multi-Targeting Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Help Viewer 1.0 (Version: 1.0.30319) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319) Microsoft Office 2010 (Version: 14.0.4763.1000) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft SQL Server 2008 R2 Management Objects (Version: 10.50.1447.4) Microsoft SQL Server Compact 3.5 SP2 DEU (Version: 3.5.8080.0) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (Version: 3.5.8080.0) Microsoft SQL Server System CLR Types (Version: 10.50.1447.4) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (Version: 10.0.30319) Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (Version: 10.0.30319) Mozilla Firefox 21.0 (x86 de) (Version: 21.0) Mozilla Maintenance Service (Version: 21.0) MSVCRT (Version: 15.4.2862.0708) MSVCRT Redists (Version: 1.0) MSVCRT_amd64 (Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Need For Speed™ World (Version: Nexon Game Manager NVIDIA Control Panel 275.48 (Version: 275.48) NVIDIA Graphics Driver 275.48 (Version: 275.48) NVIDIA Install Application (Version: NVIDIA Optimus 1.3.6 (Version: 1.3.6) NVIDIA PhysX (Version: 9.10.0513) NVIDIA Update Components (Version: 1.3.6) Pando Media Booster (Version: PHotkey (Version: 1.00.0038) Pixlr-o-matic (Version: 2.1) PlayReady PC Runtime amd64 (Version: 1.3.0) Poczta uslugi Windows Live (Version: 15.4.3502.0922) Podstawowe programy Windows Live (Version: 15.4.3502.0922) Pošta Windows Live (Version: 15.4.3502.0922) PremiumSoft Navicat Lite 10.0 Protector Suite 2011 (Version: Raccolta foto di Windows Live (Version: 15.4.3502.0922) Realtek Ethernet Controller Driver (Version: Realtek High Definition Audio Driver (Version: Realtek USB 2.0 Card Reader (Version: 6.1.7600.30127) Renesas Electronics USB 3.0 Host Controller Driver (Version: S?????? f?t???af??? t?? Windows Live (Version: 15.4.3502.0922) Samsung Kies (Version: SAMSUNG Mobile Composite Device Software Samsung Mobile phone USB driver Drive Software Samsung PC Studio 3 (Version: SAMSUNG USB Driver for Mobile Phones (Version: Sanny Builder 3.04 Skype™ 5.10 (Version: 5.10.116) Special Effects Voices (Version: 1.0.2) Spelling Dictionaries Support For Adobe Reader X (Version: 10.0.0) St???e?? e?????? ActiveX t?? Windows Live Mesh ??a ap?µa???sµ??e? s??d?se?? (Version: 15.4.5722.2) Steam (Version: Synaptics Pointing Device Driver (Version: TeamSpeak 3 Client (Version: TeamViewer 8 (Version: 8.0.16642) TIPP10 Version 2.1.0 Überwachungstool für die Intel® Turbo-Boost-Technik 2.6 (Version: Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition Uzak Baglantilar Için Windows Live Mesh ActiveX Denetimi (Version: 15.4.5722.2) Virtual Audio Cable 4.10 Virtual Machine (Version: 3.00.0000) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (Version: 4.0.8080.0) watchmi (Version: 2.7.0) Winamp (Version: 5.63 ) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3555.0308) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live Fotograf Galerisi (Version: 15.4.3502.0922) Windows Live Fotótár (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3555.0308) Windows Live Mail (Version: 15.4.3502.0922) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (Version: 15.4.5722.2) Windows Live Mesh (Version: 15.4.3502.0922) Windows Live Mesh ActiveX control for remote connections (Version: 15.4.5722.2) Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2) Windows Live Mesh ActiveX-objekt til fjernforbindelser (Version: 15.4.5722.2) Windows Live Mesh ActiveX-vezérlo távoli kapcsolatokhoz (Version: 15.4.5722.2) Windows Live Messenger (Version: 15.4.3538.0513) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live Temel Parçalar (Version: 15.4.3502.0922) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) Windows Live Writer (Version: 15.4.3502.0922) Windows Live Writer Resources (Version: 15.4.3502.0922) WinRAR 4.20 (64-Bit) (Version: 4.20.0) XAMPP 1.8.1 ==================== Restore Points ========================= 19-05-2013 20:02:33 Windows Update 23-05-2013 17:35:51 Installed MorphVOX Pro 23-05-2013 17:36:37 Installed MorphVOX Pro 23-05-2013 17:57:51 Removed MorphVOX Pro 23-05-2013 18:07:58 Removed MorphVOX Pro 31-05-2013 10:03:38 Geplanter Prüfpunkt 05-06-2013 11:34:31 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/06/2013 06:05:29 PM) (Source: MemeoBackgroundService) (User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (06/06/2013 03:41:37 PM) (Source: MemeoBackgroundService) (User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (06/06/2013 03:36:16 PM) (Source: MemeoBackgroundService) (User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (06/06/2013 03:34:34 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Vom Kryptografiedienst konnte das VSS-Sicherungsobjekt "System Writer" nicht initialisiert werden. Details: Could not query the status of the EventSystem service. System Error: Der Computer wird heruntergefahren. . Error: (06/06/2013 07:51:20 AM) (Source: Application Hang) (User: ) Description: Programm ts3client_win64.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: f30 Startzeit: 01ce62796f8160d3 Endzeit: 0 Anwendungspfad: C:\Users\Oguzhan\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe Berichts-ID: 0caa6707-ce6d-11e2-9c52-e840f21902df Error: (06/06/2013 07:16:44 AM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/06/2013 07:16:44 AM) (Source: Windows Search Service) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/06/2013 07:16:44 AM) (Source: Windows Search Service) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/06/2013 07:16:44 AM) (Source: Windows Search Service) (User: ) Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Error: (06/06/2013 07:16:43 AM) (Source: Windows Search Service) (User: ) Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (06/06/2013 06:06:29 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: StarOpen Error: (06/06/2013 06:04:50 PM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (06/06/2013 03:49:31 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/06/2013 03:49:31 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Google Update-Dienst (gupdate) erreicht. Error: (06/06/2013 03:48:37 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X64 erreicht. Error: (06/06/2013 03:48:04 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht. Error: (06/06/2013 03:41:47 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: StarOpen Error: (06/06/2013 03:40:22 PM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (06/06/2013 03:36:22 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: StarOpen Error: (06/06/2013 03:35:02 PM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Microsoft Office Sessions: ========================= Error: (06/06/2013 06:05:29 PM) (Source: MemeoBackgroundService)(User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (06/06/2013 03:41:37 PM) (Source: MemeoBackgroundService)(User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (06/06/2013 03:36:16 PM) (Source: MemeoBackgroundService)(User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (06/06/2013 03:34:34 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: Could not query the status of the EventSystem service. System Error: Der Computer wird heruntergefahren. Error: (06/06/2013 07:51:20 AM) (Source: Application Hang)(User: ) Description: ts3client_win64.exe3.0.10.0f3001ce62796f8160d30C:\Users\Oguzhan\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe0caa6707-ce6d-11e2-9c52-e840f21902df Error: (06/06/2013 07:16:44 AM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/06/2013 07:16:44 AM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/06/2013 07:16:44 AM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/06/2013 07:16:44 AM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Search.TripoliIndexer Error: (06/06/2013 07:16:43 AM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Search.JetPropStore ==================== Memory info =========================== Percentage of memory in use: 49% Total physical RAM: 4007.05 MB Available physical RAM: 2042.78 MB Total Pagefile: 8012.29 MB Available Pagefile: 5780 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:414.66 GB) (Free:286.43 GB) NTFS (Disk=0 Partition=2) Drive d: (Recover) (Fixed) (Total:50 GB) (Free:29.14 GB) NTFS (Disk=0 Partition=3) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 2BD2C32A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=415 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ==================== End Of Log ============================ Geändert von Zopfguy05 (06.06.2013 um 19:33 Uhr) |
![]() | #4 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Ist mein PC sauber`? Soweit nix zu sehen, deinstalliere alles von Samsung und reboote. PRoblem weg?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
Themen zu Ist mein PC sauber`? |
avira, computer, datei, error, files, guten, heute, hängt, hören, keine rückmeldung, lange, minute, musik, nichts, programme, rückmeldung, schließe, skype, start, tr/crypt.zpack.gen, trojan, unerwünschtes programm, virus, warum, überall, öffnen |