Part II
Code:
Alles auswählen Aufklappen ATTFilter
==================== One Month Modified Files and Folders =======
2014-04-20 02:35 - 2014-04-20 02:34 - 00015921 _____ () C:\Users\WorkStation\Downloads\FRST.txt
2014-04-20 02:34 - 2014-04-20 02:34 - 00000000 ____D () C:\FRST
2014-04-20 02:33 - 2014-04-20 02:33 - 02055680 _____ (Farbar) C:\Users\WorkStation\Downloads\FRST64.exe
2014-04-20 02:07 - 2014-04-19 17:37 - 00000296 _____ () C:\windows\Tasks\FF Watcher {53456B2D-7B0E-4FCF-B29B-DE3E5BF558D7}.job
2014-04-20 02:00 - 2014-04-16 18:01 - 00000000 ____D () C:\Users\WorkStation\AppData\Local\Adobe
2014-04-20 02:00 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\sru
2014-04-20 01:12 - 2014-04-16 18:27 - 00000000 ____D () C:\Users\WorkStation\AppData\Roaming\vlc
2014-04-20 00:57 - 2014-04-15 18:50 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-19 21:18 - 2014-04-16 18:19 - 00000000 ____D () C:\Users\WorkStation\Desktop\projekte
2014-04-19 20:08 - 2014-04-19 20:08 - 544052291 _____ () C:\Users\WorkStation\Desktop\gata bom sicherheit.mp4
2014-04-19 18:17 - 2012-12-01 20:16 - 00745562 _____ () C:\windows\system32\perfh007.dat
2014-04-19 18:17 - 2012-12-01 20:16 - 00169488 _____ () C:\windows\system32\perfc007.dat
2014-04-19 18:17 - 2012-07-26 09:28 - 01752720 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-19 18:12 - 2014-04-19 18:12 - 04916872 _____ () C:\windows\system32\FNTCACHE.DAT
2014-04-19 18:12 - 2012-08-01 19:02 - 00753500 _____ () C:\windows\PFRO.log
2014-04-19 18:12 - 2012-07-26 09:22 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-19 18:04 - 2014-04-15 20:50 - 00000000 ____D () C:\Users\Config\AppData\Local\Adobe
2014-04-19 18:03 - 2014-04-19 18:03 - 00000000 ___RD () C:\Users\Config\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-19 18:03 - 2014-04-19 18:03 - 00000000 ___RD () C:\Users\Config\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-19 17:59 - 2014-04-19 17:51 - 00000000 ___RD () C:\windows\BrowserChoice
2014-04-19 17:59 - 2014-04-14 23:11 - 00000000 ___RD () C:\Users\WorkStation\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-19 17:59 - 2014-04-14 23:11 - 00000000 ___RD () C:\Users\WorkStation\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-19 17:59 - 2012-08-01 19:06 - 00000000 ____D () C:\ProgramData\PRICache
2014-04-19 17:58 - 2014-04-19 17:38 - 00000380 _____ () C:\windows\Tasks\APSnotifierPP1.job
2014-04-19 17:54 - 2014-04-19 17:38 - 00000378 _____ () C:\windows\Tasks\APSnotifierPP3.job
2014-04-19 17:54 - 2014-04-19 17:38 - 00000378 _____ () C:\windows\Tasks\APSnotifierPP2.job
2014-04-19 17:52 - 2012-07-26 11:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-04-19 17:52 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-04-19 17:51 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-04-19 17:51 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\WinStore
2014-04-19 17:51 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-04-19 17:51 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-04-19 17:49 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\SysWOW64\en-GB
2014-04-19 17:49 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\en-GB
2014-04-19 17:49 - 2012-07-26 07:38 - 00000000 ____D () C:\windows\system32\oobe
2014-04-19 17:47 - 2012-07-26 10:12 - 00000000 ___RD () C:\windows\ToastData
2014-04-19 17:47 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-04-19 17:47 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-04-19 17:47 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2014-04-19 17:47 - 2012-07-26 07:38 - 00000000 ____D () C:\windows\SysWOW64\Dism
2014-04-19 17:47 - 2012-07-26 07:38 - 00000000 ____D () C:\windows\system32\Dism
2014-04-19 17:41 - 2014-04-14 23:08 - 01369057 _____ () C:\windows\WindowsUpdate.log
2014-04-19 17:39 - 2014-04-19 17:38 - 00000320 _____ () C:\Users\Config\AppData\Roaming\aps.uninstall.scan.results
2014-04-19 17:38 - 2014-04-19 17:38 - 01097384 _____ (AnyProtect.com) C:\Users\Config\AppData\Local\nsfD7C2.tmp
2014-04-19 17:38 - 2014-04-19 17:38 - 00002812 _____ () C:\windows\System32\Tasks\APSnotifierPP1
2014-04-19 17:38 - 2014-04-19 17:38 - 00002810 _____ () C:\windows\System32\Tasks\APSnotifierPP3
2014-04-19 17:38 - 2014-04-19 17:38 - 00002810 _____ () C:\windows\System32\Tasks\APSnotifierPP2
2014-04-19 17:37 - 2014-04-19 17:37 - 00003242 _____ () C:\windows\System32\Tasks\FF Watcher {53456B2D-7B0E-4FCF-B29B-DE3E5BF558D7}
2014-04-19 17:34 - 2014-04-19 17:34 - 08704856 _____ () C:\Users\WorkStation\Downloads\FreeVideoCutterSetup.exe
2014-04-19 17:02 - 2014-04-19 17:02 - 00000117 _____ () C:\windows\system32\netcfg-102830625.txt
2014-04-19 17:02 - 2014-04-19 17:02 - 00000117 _____ () C:\windows\system32\netcfg-102827250.txt
2014-04-19 14:32 - 2014-04-19 14:32 - 00000000 ____D () C:\Program Files (x86)\Video Thumbnails Maker
2014-04-19 14:31 - 2014-04-19 14:31 - 11280561 _____ () C:\Users\WorkStation\Downloads\VideoThumbnailsMaker_Setup.exe
2014-04-19 10:46 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\SecureBootUpdates
2014-04-19 09:53 - 2014-04-19 09:53 - 00000117 _____ () C:\windows\system32\netcfg-77135312.txt
2014-04-19 09:53 - 2014-04-19 09:53 - 00000117 _____ () C:\windows\system32\netcfg-77135078.txt
2014-04-19 03:19 - 2014-04-16 18:22 - 00000000 ____D () C:\Users\WorkStation\AppData\Local\LooksBuilder
2014-04-19 00:46 - 2014-04-19 00:46 - 547013323 _____ () C:\Users\WorkStation\Desktop\gata bom song1.mp4
2014-04-18 20:19 - 2013-03-24 18:34 - 00000000 ____D () C:\Users\WorkStation\dwhelper
2014-04-18 18:31 - 2014-04-18 18:31 - 533465266 _____ () C:\Users\WorkStation\Desktop\gata bom intro_1.mp4
2014-04-18 16:01 - 2014-04-18 16:01 - 100956940 _____ () C:\Users\WorkStation\Desktop\gata bom intro.mp4
2014-04-18 15:59 - 2014-04-14 23:11 - 00000000 ____D () C:\Users\WorkStation\AppData\Roaming\Adobe
2014-04-18 12:57 - 2014-04-18 12:57 - 00000117 _____ () C:\windows\system32\netcfg-1772125.txt
2014-04-18 12:38 - 2014-04-18 12:38 - 00000117 _____ () C:\windows\system32\netcfg-637687.txt
2014-04-18 02:19 - 2012-07-26 07:37 - 00000000 ____D () C:\windows\servicing
2014-04-18 01:38 - 2014-04-16 21:41 - 00002249 ____H () C:\windows\SysWOW64\BTImages.dat
2014-04-18 01:38 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\rescache
2014-04-18 01:35 - 2014-04-15 08:56 - 00000000 ____D () C:\Windows.old
2014-04-17 20:31 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\AUInstallAgent
2014-04-17 20:29 - 2014-04-17 20:29 - 00000117 _____ () C:\windows\system32\netcfg-168964640.txt
2014-04-17 20:29 - 2014-04-17 20:29 - 00000117 _____ () C:\windows\system32\netcfg-168964281.txt
2014-04-16 22:06 - 2014-04-16 22:04 - 00000000 ____D () C:\windows\system32\MRT
2014-04-16 21:57 - 2014-04-16 18:06 - 00003596 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-69289416-3157116417-3177412604-1002
2014-04-16 21:33 - 2014-04-16 21:33 - 00000117 _____ () C:\windows\system32\netcfg-86373750.txt
2014-04-16 19:31 - 2014-04-16 19:31 - 00000117 _____ () C:\windows\system32\netcfg-79074937.txt
2014-04-16 18:24 - 2014-04-16 18:24 - 00003508 _____ () C:\windows\System32\Tasks\AdobeAAMUpdater-1.0-admin-WorkStation
2014-04-16 18:22 - 2014-04-16 18:22 - 00000000 ____D () C:\Users\WorkStation\AppData\Roaming\PACE Anti-Piracy
2014-04-16 18:22 - 2014-04-16 18:22 - 00000000 ____D () C:\Users\WorkStation\AppData\Roaming\NVIDIA
2014-04-16 18:22 - 2014-04-16 18:22 - 00000000 ____D () C:\Users\WorkStation\AppData\Local\PACE Anti-Piracy
2014-04-16 18:22 - 2014-02-23 05:14 - 00000000 ___HD () C:\Users\WorkStation\AppData\Local\mZ283xtrtcGz7AN
2014-04-16 18:22 - 2014-02-04 19:25 - 00000000 ___HD () C:\Users\WorkStation\AppData\Local\LTJrmit4XT5W
2014-04-16 18:22 - 2013-11-05 16:06 - 00000000 ___HD () C:\Users\WorkStation\AppData\Local\9l4678IreENu
2014-04-16 18:22 - 2013-06-01 02:14 - 00000000 ___HD () C:\Users\WorkStation\AppData\Local\lnqP02F2DLh
2014-04-16 18:19 - 2014-04-16 18:19 - 00001102 _____ () C:\Users\WorkStation\Desktop\Desktop - Verknüpfung.lnk
2014-04-16 18:15 - 2014-04-16 18:15 - 00000000 ____D () C:\Users\WorkStation\AppData\Roaming\Macromedia
2014-04-16 18:15 - 2014-04-16 18:15 - 00000000 ____D () C:\Users\WorkStation\AppData\Local\Macromedia
2014-04-16 18:11 - 2014-04-16 18:11 - 00000000 ____D () C:\Users\WorkStation\AppData\Roaming\WinRAR
2014-04-16 18:07 - 2014-04-16 18:07 - 00000000 ____D () C:\Users\WorkStation\AppData\Roaming\Avira
2014-04-16 18:05 - 2014-04-16 18:05 - 00000000 ____D () C:\Users\WorkStation\AppData\Roaming\Mozilla
2014-04-16 18:05 - 2014-04-16 18:05 - 00000000 ____D () C:\Users\WorkStation\AppData\Local\Mozilla
2014-04-16 18:01 - 2014-04-16 18:01 - 00000117 _____ () C:\windows\system32\netcfg-73675968.txt
2014-04-16 07:14 - 2014-04-16 07:14 - 00000117 _____ () C:\windows\system32\netcfg-34855515.txt
2014-04-16 07:03 - 2014-04-15 22:48 - 00000000 ____D () C:\Users\Config\AppData\Roaming\vlc
2014-04-16 06:58 - 2014-04-15 20:24 - 00003594 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-69289416-3157116417-3177412604-1001
2014-04-16 06:55 - 2014-04-15 20:51 - 00000000 ____D () C:\ProgramData\Adobe
2014-04-16 06:52 - 2014-04-16 06:52 - 00000117 _____ () C:\windows\system32\netcfg-33559437.txt
2014-04-16 01:19 - 2014-04-15 23:24 - 00261574 _____ () C:\Users\Config\Documents\Unbenanntes Projekt.aep
2014-04-16 01:12 - 2014-04-16 01:12 - 12462619 _____ () C:\Users\Config\Desktop\teaser.mp4
2014-04-16 00:50 - 2014-04-16 00:50 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2014-04-16 00:33 - 2014-04-16 00:33 - 03439449 _____ () C:\Users\Config\Desktop\Sequenz 01.mp4
2014-04-15 22:46 - 2014-04-15 22:46 - 00000000 ____D () C:\Program Files\VideoLAN
2014-04-15 22:44 - 2014-04-15 22:44 - 25910056 _____ () C:\Users\Config\Downloads\vlc-2.1.4-win64.exe
2014-04-15 22:44 - 2014-04-15 22:44 - 25531584 _____ () C:\Users\Config\Downloads\vlc-2.1.3-win32.exe
2014-04-15 22:43 - 2014-04-15 22:43 - 00001235 _____ () C:\Users\Config\Desktop\gata bom - Verknüpfung.lnk
2014-04-15 22:31 - 2014-04-15 22:31 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-04-15 22:31 - 2012-07-26 09:21 - 00032374 _____ () C:\windows\setupact.log
2014-04-15 22:28 - 2014-04-15 22:26 - 00000000 ____D () C:\Users\Config\AppData\Local\LooksBuilder
2014-04-15 22:26 - 2014-04-15 22:26 - 00000000 ____D () C:\Program Files (x86)\LooksBuilder
2014-04-15 22:26 - 2014-04-15 20:57 - 00000000 ____D () C:\Program Files\Adobe
2014-04-15 22:26 - 2012-12-01 11:25 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-15 22:21 - 2014-04-15 22:21 - 00000000 ____D () C:\ProgramData\RedGiant
2014-04-15 22:20 - 2014-04-15 21:29 - 00000000 ____D () C:\Users\Config\AppData\Local\Downloaded Installations
2014-04-15 22:17 - 2014-04-15 22:16 - 00000000 ____D () C:\Users\Config\Downloads\RGMBSuite11
2014-04-15 22:16 - 2014-04-15 22:16 - 02087616 _____ () C:\Users\Config\Downloads\winrar-x64-501d.exe
2014-04-15 22:16 - 2014-04-15 22:16 - 00000000 ____D () C:\Users\Config\AppData\Roaming\WinRAR
2014-04-15 22:16 - 2014-04-15 22:16 - 00000000 ____D () C:\Program Files (x86)\WinRAR
2014-04-15 22:06 - 2014-04-15 22:03 - 23251132 _____ () C:\Users\Config\Downloads\RGMBSuite11.part2.rar
2014-04-15 22:02 - 2014-04-15 21:48 - 104857600 _____ () C:\Users\Config\Downloads\RGMBSuite11.part1.rar
2014-04-15 21:53 - 2014-04-14 22:42 - 00000000 ___HD () C:\$SysReset
2014-04-15 21:29 - 2014-04-15 21:14 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-04-15 21:29 - 2014-04-15 18:27 - 00000000 ____D () C:\Users\Config\AppData\Roaming\Adobe
2014-04-15 21:28 - 2014-04-15 21:28 - 00000000 ____D () C:\Program Files\Neat Video for Premiere
2014-04-15 21:17 - 2014-04-15 21:16 - 00000000 ____D () C:\Users\Config\AppData\Roaming\NVIDIA
2014-04-15 21:16 - 2014-04-15 21:16 - 00000000 ____D () C:\Users\Config\AppData\Roaming\PACE Anti-Piracy
2014-04-15 21:16 - 2014-04-15 21:16 - 00000000 ____D () C:\Users\Config\AppData\Local\PACE Anti-Piracy
2014-04-15 21:16 - 2014-04-15 21:16 - 00000000 ____D () C:\ProgramData\PACE Anti-Piracy
2014-04-15 21:16 - 2014-04-08 23:21 - 00000294 _____ () C:\Users\Config\Desktop\key cs6 08042014.txt
2014-04-15 21:16 - 2014-01-14 07:51 - 00000000 ___HD () C:\Users\Config\AppData\Local\LTJrmit4XT5W
2014-04-15 21:16 - 2013-09-13 07:56 - 00000000 ___HD () C:\Users\Config\AppData\Local\lnqP02F2DLh
2014-04-15 21:16 - 2013-01-22 03:19 - 00000000 ___HD () C:\Users\Config\AppData\Local\9l4678IreENu
2014-04-15 21:16 - 2013-01-15 17:44 - 00000000 ___HD () C:\Users\Config\AppData\Local\mZ283xtrtcGz7AN
2014-04-15 21:12 - 2014-04-15 20:57 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-04-15 21:12 - 2014-04-15 20:56 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-04-15 21:09 - 2014-04-15 21:09 - 00000000 ____D () C:\ProgramData\ALM
2014-04-15 21:02 - 2014-04-15 21:02 - 00000000 ____D () C:\Program Files (x86)\My Company Name
2014-04-15 20:59 - 2014-04-15 20:59 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-04-15 20:50 - 2014-04-15 20:50 - 00000117 _____ () C:\windows\system32\netcfg-502843.txt
2014-04-15 20:41 - 2012-12-01 11:37 - 00000000 ____D () C:\ProgramData\Norton
2014-04-15 20:38 - 2014-04-15 20:38 - 00000117 _____ () C:\windows\system32\netcfg-77377375.txt
2014-04-15 20:37 - 2014-04-15 20:37 - 00000117 _____ () C:\windows\system32\netcfg-77325765.txt
2014-04-15 20:29 - 2012-07-26 10:12 - 00000000 ___HD () C:\windows\ELAMBKUP
2014-04-15 20:29 - 2012-07-26 07:26 - 00262144 ___SH () C:\windows\system32\config\ELAM
2014-04-15 20:28 - 2014-04-15 20:28 - 00000000 ____D () C:\Users\Config\AppData\Local\Hewlett-Packard
2014-04-15 20:25 - 2014-04-15 20:25 - 00431135 _____ () C:\windows\system32\Drivers\vsconfig.xml
2014-04-15 20:25 - 2014-04-15 20:25 - 00000229 _____ () C:\windows\system32\netcfg-76564656.txt
2014-04-15 20:25 - 2014-04-15 20:25 - 00000117 _____ () C:\windows\system32\netcfg-76567578.txt
2014-04-15 20:25 - 2014-04-15 20:25 - 00000117 _____ () C:\windows\system32\netcfg-76567484.txt
2014-04-15 20:24 - 2014-04-15 20:22 - 00000000 ____D () C:\Program Files (x86)\CheckPoint
2014-04-15 20:20 - 2014-04-15 20:20 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-04-15 20:18 - 2014-04-15 20:18 - 00000117 _____ () C:\windows\system32\netcfg-76194187.txt
2014-04-15 19:33 - 2014-04-15 19:33 - 00000117 _____ () C:\windows\system32\netcfg-73471531.txt
2014-04-15 19:29 - 2014-04-15 19:29 - 00000117 _____ () C:\windows\system32\netcfg-73210093.txt
2014-04-15 19:29 - 2014-04-15 19:29 - 00000117 _____ () C:\windows\system32\netcfg-73208921.txt
2014-04-15 19:04 - 2014-04-15 19:04 - 00000117 _____ () C:\windows\system32\netcfg-71755765.txt
2014-04-15 19:04 - 2014-04-15 19:04 - 00000117 _____ () C:\windows\system32\netcfg-71750890.txt
2014-04-15 18:52 - 2014-04-15 18:47 - 00000000 ____D () C:\ProgramData\Avira
2014-04-15 18:52 - 2014-04-15 18:47 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-04-15 18:50 - 2014-04-15 18:50 - 00003772 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-04-15 18:50 - 2014-04-15 18:50 - 00000000 ____D () C:\Users\Config\AppData\Roaming\Avira
2014-04-15 18:50 - 2014-04-15 18:50 - 00000000 ____D () C:\Users\Config\AppData\Local\Macromedia
2014-04-15 18:40 - 2014-04-15 18:40 - 04464256 _____ (Avira Operations GmbH & Co. KG) C:\Users\Config\Downloads\avira_de_av___ws.exe
2014-04-15 18:40 - 2014-04-15 18:40 - 03356760 _____ (Check Point Software Technologies Ltd.) C:\Users\Config\Downloads\zaSetupWeb_130_208_000.exe
2014-04-15 18:36 - 2014-04-15 18:36 - 00000000 ____D () C:\Program Files\Classic Shell
2014-04-15 18:36 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\restore
2014-04-15 18:35 - 2014-04-15 18:35 - 07039112 _____ (IObit ) C:\Users\Config\Downloads\startmenu-setup_1.4.0.0.exe
2014-04-15 18:33 - 2014-04-15 18:26 - 00000000 ____D () C:\Users\Config\AppData\Roaming\Hewlett-Packard
2014-04-15 18:32 - 2014-04-15 18:32 - 00000000 ____D () C:\Users\Config\AppData\Roaming\Mozilla
2014-04-15 18:32 - 2014-04-15 18:32 - 00000000 ____D () C:\Users\Config\AppData\Local\Mozilla
2014-04-15 18:32 - 2014-04-15 18:32 - 00000000 ____D () C:\ProgramData\Mozilla
2014-04-15 18:32 - 2014-04-15 18:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-15 18:32 - 2014-04-15 18:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-15 18:31 - 2014-04-15 18:31 - 00000000 ____D () C:\Users\Config\Desktop\neuer shit april
2014-04-15 18:30 - 2014-04-15 18:30 - 00283192 _____ (Mozilla) C:\Users\Config\Downloads\Firefox Setup Stub 28.0.exe
2014-04-15 18:30 - 2014-04-15 18:30 - 00000000 ____D () C:\Users\Config\AppData\Roaming\Macromedia
2014-04-15 18:27 - 2014-04-15 18:27 - 00017560 _____ () C:\Users\Config\Desktop\Entfernte Anwendungen.html
2014-04-15 18:27 - 2014-04-15 18:27 - 00000000 ____D () C:\Users\Config\AppData\Local\Power2Go8
2014-04-15 18:27 - 2013-03-12 20:57 - 00000000 ____D () C:\Users\Config\AppData\Local\Packages
2014-04-15 18:27 - 2012-12-01 11:36 - 00000000 ___RD () C:\Program Files\Online Services
2014-04-15 18:27 - 2012-12-01 11:29 - 00000000 ___RD () C:\Program Files (x86)\Online Services
2014-04-15 18:27 - 2012-10-12 18:51 - 00000000 _RSHD () C:\hp
2014-04-15 18:27 - 2012-08-02 05:15 - 00000000 ____D () C:\SWSETUP
2014-04-15 18:27 - 2012-08-02 04:02 - 00000000 ____D () C:\windows\Panther
2014-04-15 18:27 - 2012-08-01 11:57 - 00000000 _RSHD () C:\SYSTEM.SAV
2014-04-15 18:27 - 2012-07-26 10:12 - 00000000 __SHD () C:\Program Files\Windows Sidebar
2014-04-15 18:26 - 2014-04-15 18:26 - 00000000 __RSH () C:\windows\SysWOW64\Drivers\103C_HP_cPC_h8-1425eg_Y53316J_0U_QCZC24891KS_E12CE3RR8606_4A_I2AD5_SPEGATRON CORPORATION_V1.03_B8.11_T121023_W8101-0_L407_M12226_J16_7Intel_86A9_93.40_#121201_N19691091_Z_G10DE1185_Ohp DVD-RAM GH82N_DSAM05CC.MRK
2014-04-15 18:26 - 2014-04-15 18:26 - 00000000 __RSH () C:\windows\system32\Drivers\103C_HP_cPC_h8-1425eg_Y53316J_0U_QCZC24891KS_E12CE3RR8606_4A_I2AD5_SPEGATRON CORPORATION_V1.03_B8.11_T121023_W8101-0_L407_M12226_J16_7Intel_86A9_93.40_#121201_N19691091_Z_G10DE1185_Ohp DVD-RAM GH82N_DSAM05CC.MRK
2014-04-15 18:25 - 2014-04-15 18:25 - 00000020 ___SH () C:\Users\Config\ntuser.ini
2014-04-15 18:25 - 2014-04-15 18:25 - 00000000 ____D () C:\Users\Config\AppData\Local\VirtualStore
2014-04-15 18:22 - 2014-04-15 18:22 - 00000117 _____ () C:\windows\system32\netcfg-69248640.txt
2014-04-15 18:22 - 2014-04-15 18:22 - 00000117 _____ () C:\windows\system32\netcfg-69248265.txt
2014-04-15 08:56 - 2014-04-15 08:56 - 00262144 _____ () C:\windows\system32\config\userdiff
2014-04-15 08:56 - 2012-07-26 10:13 - 00262144 _____ () C:\windows\system32\config\BCD-Template
2014-04-14 23:14 - 2014-04-14 23:14 - 00000000 ____D () C:\Users\WorkStation\AppData\Local\Hewlett-Packard
2014-04-14 23:13 - 2014-04-14 23:13 - 00000141 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2014-04-14 23:13 - 2014-04-14 23:13 - 00000000 ____D () C:\Users\WorkStation\AppData\Roaming\Hewlett-Packard
2014-04-14 23:12 - 2014-04-14 23:12 - 00000000 ____D () C:\Users\WorkStation\AppData\Local\Power2Go8
2014-04-14 23:11 - 2014-04-14 23:11 - 00001440 _____ () C:\Users\WorkStation\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-14 23:11 - 2014-04-14 23:00 - 00000000 ____D () C:\Users\WorkStation
2014-04-14 23:11 - 2013-03-14 19:39 - 00000000 ____D () C:\Users\WorkStation\AppData\Local\Packages
2014-04-14 23:10 - 2014-04-14 23:10 - 00000000 ____D () C:\Users\WorkStation\AppData\Local\VirtualStore
2014-04-14 23:09 - 2014-04-14 23:09 - 00000020 ___SH () C:\Users\WorkStation\ntuser.ini
2014-04-14 23:02 - 2014-04-14 23:02 - 00004477 _____ () C:\Users\Administrator\AppData\Local\Application.xml
2014-04-14 23:02 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\Recovery
2014-04-14 23:02 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\Vorlagen
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\Startmenü
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\Netzwerkumgebung
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\Lokale Einstellungen
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\Druckumgebung
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\Documents\Eigene Musik
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\Documents\Eigene Bilder
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\AppData\Local\Verlauf
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\AppData\Local\Anwendungsdaten
2014-04-14 23:01 - 2014-04-14 23:01 - 00000000 _SHDL () C:\Users\Config\Anwendungsdaten
2014-04-14 23:01 - 2014-04-14 23:00 - 00024768 _____ () C:\windows\diagwrn.xml
2014-04-14 23:01 - 2014-04-14 23:00 - 00024768 _____ () C:\windows\diagerr.xml
2014-04-14 23:01 - 2014-04-14 23:00 - 00000000 ___HD () C:\Users\WorkStation\Documents\hp.system.package.metadata
2014-04-14 23:01 - 2014-04-14 23:00 - 00000000 ___HD () C:\Users\Neu.admin.002\Documents\hp.system.package.metadata
2014-04-14 23:01 - 2014-04-14 23:00 - 00000000 ___HD () C:\Users\Config\Documents\hp.system.package.metadata
2014-04-14 23:01 - 2014-04-14 23:00 - 00000000 ____D () C:\Users\Neu.admin.002
2014-04-14 23:01 - 2014-04-14 21:16 - 00000000 ____D () C:\Users\Neu.admin.002\AppData\Local\Packages
2014-04-14 23:01 - 2012-07-26 10:12 - 00000000 __RHD () C:\Users\Public\Libraries
2014-04-14 23:00 - 2014-04-14 23:00 - 00000117 _____ () C:\windows\system32\netcfg-96750.txt
2014-04-14 23:00 - 2014-04-14 23:00 - 00000117 _____ () C:\windows\system32\netcfg-101984.txt
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\Vorlagen
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\Startmenü
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\Netzwerkumgebung
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\Lokale Einstellungen
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\Eigene Dateien
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\Druckumgebung
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\Documents\Eigene Musik
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\Documents\Eigene Bilder
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\AppData\Local\Verlauf
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\AppData\Local\Anwendungsdaten
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\WorkStation\Anwendungsdaten
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\Vorlagen
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\Startmenü
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\Netzwerkumgebung
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\Lokale Einstellungen
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\Eigene Dateien
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\Druckumgebung
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\Documents\Eigene Musik
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\Documents\Eigene Bilder
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\AppData\Local\Verlauf
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\AppData\Local\Anwendungsdaten
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Neu.admin.002\Anwendungsdaten
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Users\Config\Eigene Dateien
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-04-14 23:00 - 2014-04-14 23:00 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-04-14 22:58 - 2012-08-01 19:09 - 00008897 _____ () C:\windows\iis.log
2014-04-14 22:58 - 2012-07-26 10:13 - 00003608 _____ () C:\windows\DtcInstall.log
2014-04-14 22:58 - 2012-07-26 07:26 - 00524288 ___SH () C:\windows\system32\config\BBI
2014-04-14 19:39 - 2014-04-14 19:39 - 01686743 _____ () C:\Users\Config\Downloads\PSTools.zip
2014-04-14 19:39 - 2014-04-14 19:39 - 00000000 ____D () C:\Users\Config\Downloads\PSTools
2014-04-14 19:19 - 2014-04-14 19:19 - 00012540 _____ () C:\Users\Config\Desktop\cc_20140414_191854.reg
2014-04-14 18:03 - 2014-04-14 18:03 - 00000000 ____D () C:\Mozilla
2014-04-14 17:52 - 2014-04-14 17:52 - 00000000 __SHD () C:\found.001
2014-04-09 21:42 - 2014-02-08 10:50 - 00000000 ____D () C:\Users\WorkStation\Desktop\neuinstall cs6
2014-04-09 00:37 - 2013-03-13 18:42 - 00000000 ____D () C:\Users\Config\Desktop\adobe
2014-04-08 23:08 - 2014-04-08 23:08 - 00000000 ____D () C:\Users\Config\Adobe Flash Builder 4.6
2014-04-08 22:31 - 2014-04-08 22:31 - 00121660 _____ () C:\Users\Config\Desktop\cc_20140408_223056.reg
2014-04-08 22:10 - 2014-04-08 22:11 - 04787368 _____ (Piriform Ltd) C:\Users\Config\Downloads\ccsetup412.exe
2014-04-08 21:44 - 2014-04-08 21:44 - 00294420 _____ () C:\Users\Config\Desktop\cc_20140408_214401.reg
2014-03-31 23:18 - 2014-04-19 17:55 - 00694232 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-03-31 23:18 - 2014-04-19 17:55 - 00078296 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-31 03:51 - 2014-04-16 22:04 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Config\AppData\Local\Temp\avgnt.exe
C:\Users\Config\AppData\Local\Temp\nsgC732.exe
C:\Users\Config\AppData\Local\Temp\nsk6500.exe
C:\Users\Config\AppData\Local\Temp\nso171A.exe
C:\Users\Config\AppData\Local\Temp\nsr6A02.exe
C:\Users\Config\AppData\Local\Temp\nsv1B80.exe
C:\Users\WorkStation\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2012-08-01 19:02
==================== End Of Log ============================
und die Addition-txt:
Code:
Alles auswählen Aufklappen ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-04-2014
Ran by Config at 2014-04-20 02:36:15
Running from C:\Users\WorkStation\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: ZoneAlarm Antivirus (Enabled - Up to date) {DE038A5B-9EDD-18A9-2361-FF7D98D43730}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ZoneAlarm Anti-Spyware (Enabled - Up to date) {65626BBF-B8E7-1727-19D1-C40FE3537D8D}
FW: ZoneAlarm Firewall (Enabled) {E6380B7E-D4B2-19F1-083E-56486607704B}
==================== Installed Programs ======================
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Classic Shell (HKLM\...\{CB00799C-0E4F-4FD1-A046-BD24321BCDFF}) (Version: 3.6.5 - IvoSoft)
ExpressCache (HKLM\...\{2EBEFDA8-F905-4C39-AC1C-D5ABE7B3E0AE}) (Version: 1.0.86 - Diskeeper Corporation)
HP Postscript Converter (Version: 3.1.3591 - Hewlett-Packard) Hidden
HP Registration Service (HKLM\...\{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}) (Version: 1.0.5976.4186 - Hewlett-Packard)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
Magic Bullet Suite 64-bit (Version: 11.0 - Red Giant Software) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Neat Video for Premiere (HKLM\...\Neat Video for Premiere_is1) (Version: 3.5 - ABSoft)
NVIDIA Control Panel 305.29 (Version: 305.29 - NVIDIA Corporation) Hidden
NVIDIA Graphics Driver 305.29 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 305.29 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.82.513 - NVIDIA Corporation) Hidden
NVIDIA PhysX System Software 9.12.0613 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0613 - NVIDIA Corporation)
VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN)
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
==================== Restore Points =========================
15-04-2014 16:36:03 Installed Classic Shell
17-04-2014 23:36:41 Sprachpaketdeinstallation
==================== Hosts content: ==========================
2012-07-26 07:26 - 2014-04-15 21:22 - 00001771 ____A C:\windows\system32\Drivers\etc\hosts
There are 1 more lines.
==================== Scheduled Tasks (whitelisted) =============
Task: {173F7198-6982-4592-94A3-0ECE97F0F5DC} - System32\Tasks\AdobeAAMUpdater-1.0-admin-WorkStation => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated)
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {6178D609-8822-4A69-85D5-C1941B02972B} - System32\Tasks\FF Watcher {53456B2D-7B0E-4FCF-B29B-DE3E5BF558D7} => C:\Program Files\V-bates\PrefHelper.exe
Task: {6C7CACEF-8D86-416F-87B1-4B87E6CF4A42} - System32\Tasks\Microsoft\Windows\SetupSQMTask => C:\windows\SYSTEM32\OOBE\SETUPSQM.EXE [2012-07-26] (Microsoft Corporation)
Task: {6E5BE462-E066-4620-B90C-2B6BD1CA1F9C} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-15] (Adobe Systems Incorporated)
Task: {8CDD8425-0D11-4DDF-977A-BF7FB5E5C8EA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-08-15] (Hewlett-Packard Company)
Task: {9C8AB750-93DE-4BBA-9A77-7C0A44AF92E5} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {9CF5CBB2-99CF-4555-AFE0-7F0CFCF82F03} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-08-07] (Hewlett-Packard Company)
Task: {9DFC0268-6C48-4882-BA68-C59C02D20856} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {A28BBDD2-9F57-4E07-BA15-3BF19F8DBF26} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {C5968EC2-711B-465C-B291-3DB916196B80} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2012-07-13] (Hewlett-Packard)
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {C790E07C-DC8A-462E-9315-529F3548D7CE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-08-15] (Hewlett-Packard Company)
Task: {CEED6E82-B985-4952-B784-F4C0D245BC3E} - System32\Tasks\AdobeAAMUpdater-1.0-admin-Config => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {FD557AE9-DD7E-42C9-9BEE-541467C54C50} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-08-15] (Hewlett-Packard Company)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe
Task: C:\windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe
Task: C:\windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe
Task: C:\windows\Tasks\FF Watcher {53456B2D-7B0E-4FCF-B29B-DE3E5BF558D7}.job => C:\Program Files\V-bates\PrefHelper.exe
==================== Loaded Modules (whitelisted) =============
2012-08-29 12:02 - 2012-08-29 12:02 - 00120224 _____ () c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPItunesModule.dll
2012-08-29 12:02 - 2012-08-29 12:02 - 00048544 _____ () c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPItunesProxy.dll
2012-08-29 12:02 - 2012-08-29 12:02 - 00180224 _____ () c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\zxing.dll
2014-04-14 23:13 - 2014-04-14 23:13 - 00120224 _____ () C:\Users\WorkStation\AppData\Local\assembly\dl3\4PHMZHAJ.57W\KO2A01MB.PQR\a19f33cf\0017145d_cd85cd01\HPItunesModule.DLL
2014-04-15 18:49 - 2014-02-25 11:41 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2012-12-01 11:31 - 2012-06-08 05:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2012-06-08 13:34 - 2012-06-08 13:34 - 00016400 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2011-09-05 19:05 - 2011-09-05 19:05 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\acrotray.deu
2012-12-01 11:25 - 2012-07-18 10:50 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2014-04-15 18:32 - 2014-03-15 10:40 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2012-03-09 16:26 - 2012-03-09 16:26 - 00100352 _____ () C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\zlib1.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Config\AppData\Local\LTJrmit4XT5W:yKtINvgy1xurGioFxsC2taF
AlternateDataStreams: C:\Users\Config\AppData\Local\mZ283xtrtcGz7AN:5RwewPgGdlDBbI22CbMNhb9
AlternateDataStreams: C:\Users\WorkStation\AppData\Local\LTJrmit4XT5W:yKtINvgy1xurGioFxsC2taF
AlternateDataStreams: C:\Users\WorkStation\AppData\Local\mZ283xtrtcGz7AN:5RwewPgGdlDBbI22CbMNhb9
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/20/2014 02:35:20 AM) (Source: Perflib) (User: )
Description: .NETFrameworkC:\windows\system32\mscoree.dll8
Error: (04/20/2014 02:16:13 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1250
Error: (04/20/2014 02:16:13 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1250
Error: (04/20/2014 02:16:13 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (04/19/2014 06:13:31 PM) (Source: Windows Search Service) (User: )
Description: Die Registrierungsinformationen der Leistungsindikatoren für WSearchIdxPi für die Instanz konnten wegen des folgenden Fehlers nicht abgerufen werden: Der Vorgang wurde erfolgreich beendet. 0x0.
Error: (04/19/2014 06:13:31 PM) (Source: Windows Search Service) (User: )
Description: Die Leistungsüberwachung für den Gatherer-Dienst kann nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut.
Kontext: Anwendung, SystemIndex Katalog
Error: (04/19/2014 06:13:31 PM) (Source: Windows Search Service) (User: )
Description: Die Leistungsüberwachung kann für den Gatherer-Dienst nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut.
Error: (04/19/2014 05:58:28 PM) (Source: Perflib) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8
Error: (04/19/2014 05:57:02 PM) (Source: Windows Search Service) (User: )
Description: Die Registrierungsinformationen der Leistungsindikatoren für WSearchIdxPi für die Instanz konnten wegen des folgenden Fehlers nicht abgerufen werden: Der Vorgang wurde erfolgreich beendet. 0x0.
Error: (04/19/2014 05:57:01 PM) (Source: Windows Search Service) (User: )
Description: Die Leistungsüberwachung für den Gatherer-Dienst kann nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut.
Kontext: Anwendung, SystemIndex Katalog
System errors:
=============
Error: (04/19/2014 06:15:28 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (04/19/2014 06:15:18 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (04/19/2014 06:05:15 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (04/19/2014 06:03:37 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (04/19/2014 05:59:18 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (04/19/2014 05:57:02 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (04/18/2014 00:58:11 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (04/18/2014 00:30:58 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (04/18/2014 11:32:31 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (04/18/2014 11:32:30 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Microsoft Office Sessions:
=========================
Error: (04/20/2014 02:35:20 AM) (Source: Perflib)(User: )
Description: .NETFrameworkC:\windows\system32\mscoree.dll8
Error: (04/20/2014 02:16:13 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1250
Error: (04/20/2014 02:16:13 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1250
Error: (04/20/2014 02:16:13 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (04/19/2014 06:13:31 PM) (Source: Windows Search Service)(User: )
Description: WSearchIdxPiDer Vorgang wurde erfolgreich beendet. 0x0
Error: (04/19/2014 06:13:31 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Anwendung, SystemIndex Katalog
Error: (04/19/2014 06:13:31 PM) (Source: Windows Search Service)(User: )
Description:
Error: (04/19/2014 05:58:28 PM) (Source: Perflib)(User: )
Description: BITSC:\Windows\System32\bitsperf.dll8
Error: (04/19/2014 05:57:02 PM) (Source: Windows Search Service)(User: )
Description: WSearchIdxPiDer Vorgang wurde erfolgreich beendet. 0x0
Error: (04/19/2014 05:57:01 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Anwendung, SystemIndex Katalog
==================== Memory info ===========================
Percentage of memory in use: 28%
Total physical RAM: 12225.05 MB
Available physical RAM: 8771.29 MB
Total Pagefile: 13016.91 MB
Available Pagefile: 9056.7 MB
Total Virtual: 8192 MB
Available Virtual: 8191.77 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:918.79 GB) (Free:432.3 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Recovery Image) (Fixed) (Total:11.25 GB) (Free:1.37 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: BAD8D1B8)
Partition: GPT Partition Type.
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 15 GB) (Disk ID: 18190133)
Partition 1: (Not Active) - (Size=15 GB) - (Type=73)
==================== End Of Log ============================