janderman | 05.02.2014 07:08 | hallo und merci,
ESET hat nichts gefunden, Protokoll und Ordner zu ESET habe ich aber keine. weiß auch nicht, warum. Code:
Results of screen317's Security Check version 0.99.79
Windows 7 Service Pack 1 x64 (UAC is enabled) ``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:`````````
xp-AntiSpy 3.98-2
Secunia PSI (3.0.0.9016)
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 51
Adobe Flash Player 12.0.0.43 Flash Player out of Date!
Adobe Reader XI
Mozilla Firefox (26.0) ````````Process Check: objlist.exe by Laurent````````
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
Kaspersky Lab Kaspersky Security Scan 2.0 kss.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2014
Ran by Jan (administrator) on JAN-DELL on 05-02-2014 06:58:01
Running from C:\Users\Jan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EN4T21H8
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
(iAnywhere Solutions, Inc.) C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
(Malwarebytes Corporation) D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(3CX Ltd) D:\Program Files (x86)\3CX Assistant\tcx.assistant.client.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Geek Software GmbH) D:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(QFX Software Corporation) D:\Program Files (x86)\KeyScrambler\KeyScrambler.exe
(QFX Software Corporation) D:\Program Files (x86)\KeyScrambler\x64\KeyScrambler.exe
(3CX Ltd) D:\Program Files (x86)\3CX Assistant\CRM\3CX Assistant CRM.exe
(Mozilla Corporation) D:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_38_ActiveX.exe
(Farbar) C:\Users\Jan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EN4T21H8\FRST64[1].exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - D:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [PDFPrint] - d:\Program Files (x86)\PDF24\pdf24.exe [186408 2013-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [KeyScrambler] - d:\Program Files (x86)\KeyScrambler\keyscrambler.exe [508144 2013-11-14] (QFX Software Corporation)
Startup: C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://d8n4mx4j/argoweb/aaf001web/Login.aspx
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE2F4D1615D05CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
BHO: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: haufereader - No CLSID Value -
Handler-x32: haufereader - No CLSID Value -
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{63D26AE7-4F39-40B0-B427-CE9528B32860}: [NameServer]8.8.8.8,192.168.3.12
FireFox:
========
FF ProfilePath: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default
FF Homepage: www.startpage.com
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - D:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - D:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\searchplugins\dictcc.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\searchplugins\duckduckgo.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\searchplugins\ixquick-https.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\searchplugins\metapedia-de.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\searchplugins\startpage-https.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\searchplugins\wortschatz-deutsch.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\searchplugins\youtube-ssl.xml
FF Extension: Print pages to PDF - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\Extensions\printPages2Pdf@reinhold.ripper [2014-01-24]
FF Extension: Ghostery - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\Extensions\firefox@ghostery.com.xpi [2014-01-23]
FF Extension: NoScript - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-25]
FF Extension: Adblock Plus - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\ugmq4ru4.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-23]
FF StartMenuInternet: FIREFOX.EXE - D:\Program Files (x86)\Mozilla Firefox\firefox.exe
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Jan\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx []
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-06-07] (Adobe Systems)
R2 AntiVirFirewallService; D:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [1012280 2013-12-12] (Avira Operations GmbH & Co. KG)
S2 AntiVirMailService; D:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [896056 2013-12-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; D:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; D:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; D:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-12] (Avira Operations GmbH & Co. KG)
R2 KSS; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202328 2012-12-07] (Kaspersky Lab ZAO)
R2 Lexware_Datenbank_Plus; C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [83248 2010-11-05] (iAnywhere Solutions, Inc.)
R2 MBAMScheduler; d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
==================== Drivers (Whitelisted) ====================
R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [114608 2013-07-01] (Avira GmbH)
R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [141376 2013-07-01] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-14] (Avira Operations GmbH & Co. KG)
R3 KeyScrambler; C:\Windows\System32\drivers\keyscrambler.sys [222200 2013-05-31] (QFX Software Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-05 06:57 - 2014-02-05 06:58 - 00000000 ____D () C:\FRST
2014-02-05 06:49 - 2014-02-05 06:49 - 00987425 _____ () C:\Users\Jan\Desktop\SecurityCheck.exe
2014-02-04 07:15 - 2014-02-05 06:03 - 00000392 _____ () C:\Windows\setupact.log
2014-02-04 07:15 - 2014-02-04 07:15 - 00000000 _____ () C:\Windows\setuperr.log
2014-01-31 18:45 - 2014-01-31 18:45 - 00000338 _____ () C:\Users\Jan\Desktop\Notizen zu Patrik Baumann.txt
2014-01-30 23:55 - 2014-01-30 23:55 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-01-29 19:31 - 2014-01-29 19:38 - 00010649 _____ () C:\Users\Jan\Desktop\Vorschlag Expansion Visilab.xlsx
2014-01-29 18:09 - 2014-01-29 18:09 - 00000000 ____D () C:\Users\Jan\AppData\Local\Skype
2014-01-29 18:08 - 2014-01-30 18:47 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-01-29 18:08 - 2014-01-29 18:08 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-01-29 18:07 - 2014-01-29 18:07 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Jan\Downloads\SkypeSetup.exe
2014-01-28 09:51 - 2014-01-28 09:51 - 17888136 _____ (Adobe Systems Incorporated) C:\Users\Jan\Downloads\install_flash_player_12_plugin.exe
2014-01-27 17:29 - 2014-01-27 17:29 - 00000911 _____ () C:\Users\Jan\Desktop\Revo Uninstaller.lnk
2014-01-26 16:41 - 2014-01-26 16:41 - 00002962 _____ () C:\Users\Jan\Documents\cc_20140126_164138.reg
2014-01-26 00:13 - 2014-01-26 00:13 - 00003258 _____ () C:\Windows\System32\Tasks\{9936B1E6-E85D-48CD-88B5-0872C4354D62}
2014-01-25 15:00 - 2014-01-25 15:00 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-01-25 15:00 - 2014-01-25 15:00 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-01-25 14:49 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-01-25 14:49 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-01-25 14:49 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-01-25 14:49 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-01-25 14:49 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-01-25 14:49 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-01-25 14:49 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-01-25 14:49 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-01-25 14:49 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-01-25 14:48 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-01-25 14:48 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-01-25 14:48 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-01-25 14:48 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-01-25 14:48 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-01-25 14:48 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-01-25 14:37 - 2014-01-25 14:37 - 00000870 _____ () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Temp File Cleaner.lnk
2014-01-25 14:37 - 2014-01-25 14:37 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\addpcs
2014-01-25 14:37 - 2014-01-25 14:37 - 00000000 ____D () C:\Program Files\Temp File Cleaner
2014-01-25 14:35 - 2014-01-25 14:35 - 00930440 _____ (CNET Download.com) C:\Users\Jan\Downloads\cbsidlm-cbsi176-Temp_File_Cleaner-ORG_DE-10628816.exe
2014-01-25 14:34 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-01-25 14:34 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-01-25 14:34 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-01-25 14:34 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-01-25 14:32 - 2014-01-25 14:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-01-25 14:32 - 2014-01-25 14:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2014-01-25 14:30 - 2014-01-25 14:31 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-01-25 14:30 - 2014-01-25 14:31 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-01-25 14:24 - 2014-01-25 14:24 - 64988040 _____ (Adobe Systems Incorporated) C:\Users\Jan\Downloads\ApplicationManager7.0_all.exe
2014-01-25 14:22 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-25 14:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-01-25 14:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-01-25 14:21 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-01-25 14:21 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-01-25 14:21 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-01-25 14:21 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-01-25 14:21 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-01-25 14:21 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2014-01-25 14:21 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-01-25 14:21 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2014-01-25 14:18 - 2014-01-25 14:18 - 02434048 _____ () C:\Users\Jan\Downloads\msxml.msi
2014-01-25 14:14 - 2014-01-25 14:14 - 00000000 ____D () C:\Users\Jan\AppData\Local\WindowsUpdate
2014-01-25 14:13 - 2014-01-25 14:13 - 00000000 ____D () C:\Users\Jan\AppData\Local\Secunia PSI
2014-01-25 14:13 - 2014-01-25 14:13 - 00000000 ____D () C:\Program Files (x86)\Secunia
2014-01-25 14:12 - 2014-01-25 14:12 - 05329480 _____ (Secunia) C:\Users\Jan\Downloads\PSISetup.exe
2014-01-25 14:02 - 2014-01-28 09:55 - 00001131 _____ () C:\DelFix.txt
2014-01-23 17:55 - 2014-01-23 17:55 - 00001720 _____ () C:\Users\Jan\Documents\cc_20140123_175503.reg
2014-01-23 17:49 - 2014-01-23 17:49 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\QFX Software
2014-01-23 17:49 - 2014-01-23 17:49 - 00000000 ____D () C:\ProgramData\QFX Software
2014-01-23 17:46 - 2013-05-31 15:53 - 00222200 _____ (QFX Software Corporation) C:\Windows\system32\Drivers\keyscrambler.sys
2014-01-23 17:45 - 2014-01-23 17:45 - 01279384 _____ () C:\Users\Jan\Downloads\KeyScrambler_Setup(1).exe
2014-01-23 17:44 - 2014-01-23 17:44 - 01331344 _____ () C:\Users\Jan\Downloads\keyscrambler_setup.exe
2014-01-23 11:16 - 2014-01-24 20:26 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Delta Access
2014-01-22 14:10 - 2014-01-22 14:10 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
2014-01-22 14:10 - 2014-01-22 14:10 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-01-22 14:10 - 2014-01-22 14:10 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-01-21 18:45 - 2014-01-21 18:45 - 00000018 _____ () C:\Users\Jan\Desktop\jens.kaiser@gmx.de.txt
2014-01-21 08:53 - 2014-01-21 08:52 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-21 08:52 - 2014-01-21 08:52 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-21 08:52 - 2014-01-21 08:52 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-21 08:52 - 2014-01-21 08:52 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-21 08:46 - 2014-01-21 08:46 - 00002040 _____ () C:\Users\Jan\Documents\cc_20140121_084618.reg
2014-01-21 08:46 - 2014-01-21 08:46 - 00000162 _____ () C:\Users\Jan\Documents\cc_20140121_084641.reg
2014-01-21 08:45 - 2014-01-21 08:45 - 00008488 _____ () C:\Users\Jan\Documents\cc_20140121_084538.reg
2014-01-21 08:40 - 2014-01-21 08:40 - 00178484 _____ () C:\Users\Jan\Documents\cc_20140121_084017.reg
2014-01-20 13:08 - 2014-01-20 13:08 - 00005332 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-19 18:58 - 2014-01-19 18:58 - 00000786 _____ () C:\Users\Public\Desktop\PDF24 Creator.lnk
2014-01-18 13:51 - 2014-01-18 13:51 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Virtual Keyboard
2014-01-18 13:51 - 2014-01-18 13:51 - 00000000 ____D () C:\Users\Jan\AppData\Local\Andrej_Koch
2014-01-18 12:03 - 2014-01-25 14:04 - 00000000 ____D () C:\Windows\ERUNT
2014-01-17 22:03 - 2014-01-27 08:39 - 00000000 ____D () C:\Windows\erdnt
2014-01-17 10:55 - 2014-02-04 19:19 - 00065957 _____ () C:\Users\Jan\Desktop\Ziele (PC) (2).xlsx
2014-01-16 23:37 - 2014-01-25 14:18 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-01-16 15:30 - 2014-01-16 15:30 - 00001361 _____ () C:\Users\Public\Desktop\Die Macht des Steuerzahlers.lnk
2014-01-15 14:13 - 2014-01-15 14:13 - 00000000 ____D () C:\Users\Jan\AppData\Local\Netviewer
2014-01-15 14:11 - 2014-01-15 14:11 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Haufe Mediengruppe
2014-01-15 14:11 - 2014-01-15 14:11 - 00000000 ____D () C:\Users\Jan\AppData\Local\Haufe Mediengruppe
2014-01-15 14:00 - 2014-01-15 14:00 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Lexware
2014-01-15 14:00 - 2014-01-15 14:00 - 00000000 ____D () C:\Program Files (x86)\Lexware
2014-01-15 13:59 - 2014-01-15 13:59 - 00000153 _____ () C:\Windows\ODBC.INI
2014-01-15 13:58 - 2014-01-15 13:58 - 00000000 ____D () C:\Program Files (x86)\Sybase
2014-01-15 13:58 - 2014-01-15 13:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE
2014-01-15 13:54 - 2014-01-15 13:54 - 00002319 _____ () C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
2014-01-15 13:52 - 2014-01-16 08:20 - 00002669 _____ () C:\Users\Public\Desktop\TAXMAN 2012.lnk
2014-01-15 13:45 - 2014-01-15 15:18 - 00000000 ____D () C:\ProgramData\lexware
2014-01-15 13:45 - 2014-01-15 13:45 - 00000000 ____D () C:\ProgramData\Haufe
2014-01-15 13:45 - 2014-01-15 13:45 - 00000000 ____D () C:\Program Files (x86)\Haufe
2014-01-15 13:45 - 2006-06-26 15:58 - 01929216 _____ (Amyuni Technologies hxxp://www.amyuni.com) C:\Windows\SysWOW64\cdintf250.dll
2014-01-15 13:44 - 2014-01-15 13:44 - 00455680 _____ (Sun Microsystems, Inc.) C:\Windows\system32\deploytk.dll
2014-01-15 13:42 - 2014-01-17 20:29 - 00000000 ____D () C:\Users\Jan\AppData\Local\Lexware
2014-01-15 08:07 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 08:07 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 08:07 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 08:07 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 08:07 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 08:07 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 08:07 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 08:07 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-09 18:05 - 2014-01-09 18:05 - 00000000 ____D () C:\Users\Jan\Documents\Steuer-Sparbuch
2014-01-07 12:21 - 2014-01-07 12:21 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Nitro
2014-01-07 12:21 - 2014-01-07 12:21 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\FileOpen
2014-01-07 12:21 - 2014-01-07 12:21 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Downloaded Installations
2014-01-07 12:21 - 2014-01-07 12:21 - 00000000 ____D () C:\ProgramData\Nitro
2014-01-07 12:21 - 2014-01-07 12:21 - 00000000 ____D () C:\ProgramData\FileOpen
2014-01-07 12:12 - 2014-01-07 12:12 - 00118784 _____ () C:\Windows\system32\dmusic64.exe
2014-01-07 12:11 - 2014-01-07 12:11 - 00000000 ____D () C:\Users\Jan\AppData\Local\Google
2014-01-07 11:32 - 2014-01-07 11:32 - 00000028 _____ () C:\Users\Jan\AppData\Roaming\PhonerLitesettings.ini
2014-01-07 11:32 - 2014-01-07 11:32 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\PhonerLite
==================== One Month Modified Files and Folders =======
2014-02-05 06:58 - 2014-02-05 06:57 - 00000000 ____D () C:\FRST
2014-02-05 06:49 - 2014-02-05 06:49 - 00987425 _____ () C:\Users\Jan\Desktop\SecurityCheck.exe
2014-02-05 06:46 - 2013-09-28 07:44 - 01256077 _____ () C:\Windows\WindowsUpdate.log
2014-02-05 06:41 - 2009-07-14 18:58 - 00702964 _____ () C:\Windows\system32\perfh007.dat
2014-02-05 06:41 - 2009-07-14 18:58 - 00150604 _____ () C:\Windows\system32\perfc007.dat
2014-02-05 06:41 - 2009-07-14 06:13 - 01650254 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-05 06:40 - 2013-02-07 18:50 - 01602716 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-05 06:11 - 2009-07-14 05:45 - 00015040 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-05 06:11 - 2009-07-14 05:45 - 00015040 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-05 06:03 - 2014-02-04 07:15 - 00000392 _____ () C:\Windows\setupact.log
2014-02-05 06:03 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-04 23:00 - 2013-02-07 18:10 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-04 19:19 - 2014-01-17 10:55 - 00065957 _____ () C:\Users\Jan\Desktop\Ziele (PC) (2).xlsx
2014-02-04 07:15 - 2014-02-04 07:15 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-03 23:18 - 2013-02-10 17:23 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Winamp
2014-02-03 20:06 - 2013-10-31 23:44 - 00001940 _____ () C:\Users\Jan\Desktop\argo.web - notizen zu anfragen.txt
2014-02-03 19:43 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-01-31 18:45 - 2014-01-31 18:45 - 00000338 _____ () C:\Users\Jan\Desktop\Notizen zu Patrik Baumann.txt
2014-01-30 23:55 - 2014-01-30 23:55 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-01-30 18:47 - 2014-01-29 18:08 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-01-30 18:47 - 2013-03-10 20:39 - 00000000 ____D () C:\ProgramData\Skype
2014-01-30 14:39 - 2013-03-10 20:39 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Skype
2014-01-29 19:38 - 2014-01-29 19:31 - 00010649 _____ () C:\Users\Jan\Desktop\Vorschlag Expansion Visilab.xlsx
2014-01-29 18:09 - 2014-01-29 18:09 - 00000000 ____D () C:\Users\Jan\AppData\Local\Skype
2014-01-29 18:08 - 2014-01-29 18:08 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-01-29 18:07 - 2014-01-29 18:07 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Jan\Downloads\SkypeSetup.exe
2014-01-28 09:55 - 2014-01-25 14:02 - 00001131 _____ () C:\DelFix.txt
2014-01-28 09:51 - 2014-01-28 09:51 - 17888136 _____ (Adobe Systems Incorporated) C:\Users\Jan\Downloads\install_flash_player_12_plugin.exe
2014-01-28 09:51 - 2013-02-07 18:10 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-01-28 09:51 - 2013-02-07 18:09 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-28 09:51 - 2013-02-07 18:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-27 22:14 - 2013-02-07 16:19 - 00000000 ____D () C:\Users\Jan\AppData\Local\VirtualStore
2014-01-27 17:29 - 2014-01-27 17:29 - 00000911 _____ () C:\Users\Jan\Desktop\Revo Uninstaller.lnk
2014-01-27 10:17 - 2013-11-22 14:44 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\vlc
2014-01-27 08:44 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-01-27 08:39 - 2014-01-17 22:03 - 00000000 ____D () C:\Windows\erdnt
2014-01-26 18:55 - 2013-04-07 12:41 - 00000000 ____D () C:\Users\Jan\AppData\Local\Adobe
2014-01-26 16:41 - 2014-01-26 16:41 - 00002962 _____ () C:\Users\Jan\Documents\cc_20140126_164138.reg
2014-01-26 00:13 - 2014-01-26 00:13 - 00003258 _____ () C:\Windows\System32\Tasks\{9936B1E6-E85D-48CD-88B5-0872C4354D62}
2014-01-25 16:30 - 2013-10-31 11:08 - 00000000 ____D () C:\Windows\rescache
2014-01-25 15:01 - 2013-02-07 18:00 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-01-25 15:00 - 2014-01-25 15:00 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-01-25 15:00 - 2014-01-25 15:00 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-01-25 14:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-01-25 14:37 - 2014-01-25 14:37 - 00000870 _____ () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Temp File Cleaner.lnk
2014-01-25 14:37 - 2014-01-25 14:37 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\addpcs
2014-01-25 14:37 - 2014-01-25 14:37 - 00000000 ____D () C:\Program Files\Temp File Cleaner
2014-01-25 14:35 - 2014-01-25 14:35 - 00930440 _____ (CNET Download.com) C:\Users\Jan\Downloads\cbsidlm-cbsi176-Temp_File_Cleaner-ORG_DE-10628816.exe
2014-01-25 14:32 - 2014-01-25 14:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-01-25 14:32 - 2014-01-25 14:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2014-01-25 14:31 - 2014-01-25 14:30 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-01-25 14:31 - 2014-01-25 14:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-01-25 14:26 - 2009-07-14 03:34 - 00000478 _____ () C:\Windows\win.ini
2014-01-25 14:24 - 2014-01-25 14:24 - 64988040 _____ (Adobe Systems Incorporated) C:\Users\Jan\Downloads\ApplicationManager7.0_all.exe
2014-01-25 14:18 - 2014-01-25 14:18 - 02434048 _____ () C:\Users\Jan\Downloads\msxml.msi
2014-01-25 14:18 - 2014-01-16 23:37 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-01-25 14:14 - 2014-01-25 14:14 - 00000000 ____D () C:\Users\Jan\AppData\Local\WindowsUpdate
2014-01-25 14:13 - 2014-01-25 14:13 - 00000000 ____D () C:\Users\Jan\AppData\Local\Secunia PSI
2014-01-25 14:13 - 2014-01-25 14:13 - 00000000 ____D () C:\Program Files (x86)\Secunia
2014-01-25 14:12 - 2014-01-25 14:12 - 05329480 _____ (Secunia) C:\Users\Jan\Downloads\PSISetup.exe
2014-01-25 14:04 - 2014-01-18 12:03 - 00000000 ____D () C:\Windows\ERUNT
2014-01-24 20:26 - 2014-01-23 11:16 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Delta Access
2014-01-23 17:55 - 2014-01-23 17:55 - 00001720 _____ () C:\Users\Jan\Documents\cc_20140123_175503.reg
2014-01-23 17:49 - 2014-01-23 17:49 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\QFX Software
2014-01-23 17:49 - 2014-01-23 17:49 - 00000000 ____D () C:\ProgramData\QFX Software
2014-01-23 17:45 - 2014-01-23 17:45 - 01279384 _____ () C:\Users\Jan\Downloads\KeyScrambler_Setup(1).exe
2014-01-23 17:44 - 2014-01-23 17:44 - 01331344 _____ () C:\Users\Jan\Downloads\keyscrambler_setup.exe
2014-01-23 11:37 - 2013-02-07 16:19 - 00000000 ____D () C:\Users\Jan
2014-01-22 15:38 - 2013-06-05 14:00 - 00000000 ____D () C:\Users\Public\Documents\Kyocera
2014-01-22 14:10 - 2014-01-22 14:10 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
2014-01-22 14:10 - 2014-01-22 14:10 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-01-22 14:10 - 2014-01-22 14:10 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-01-21 18:45 - 2014-01-21 18:45 - 00000018 _____ () C:\Users\Jan\Desktop\jens.kaiser@gmx.de.txt
2014-01-21 08:53 - 2013-11-17 08:24 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-21 08:52 - 2014-01-21 08:53 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-21 08:52 - 2014-01-21 08:52 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-21 08:52 - 2014-01-21 08:52 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-21 08:52 - 2014-01-21 08:52 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-21 08:50 - 2013-03-12 09:07 - 00003224 _____ () C:\Windows\System32\Tasks\{53BBD940-B381-4607-B00D-DAAF057755BE}
2014-01-21 08:46 - 2014-01-21 08:46 - 00002040 _____ () C:\Users\Jan\Documents\cc_20140121_084618.reg
2014-01-21 08:46 - 2014-01-21 08:46 - 00000162 _____ () C:\Users\Jan\Documents\cc_20140121_084641.reg
2014-01-21 08:45 - 2014-01-21 08:45 - 00008488 _____ () C:\Users\Jan\Documents\cc_20140121_084538.reg
2014-01-21 08:40 - 2014-01-21 08:40 - 00178484 _____ () C:\Users\Jan\Documents\cc_20140121_084017.reg
2014-01-20 22:02 - 2013-02-07 19:13 - 00002222 ____H () C:\Users\Jan\Documents\Default.rdp
2014-01-20 13:41 - 2013-02-07 18:16 - 00007593 _____ () C:\Users\Jan\AppData\Local\Resmon.ResmonCfg
2014-01-20 13:08 - 2014-01-20 13:08 - 00005332 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-19 18:58 - 2014-01-19 18:58 - 00000786 _____ () C:\Users\Public\Desktop\PDF24 Creator.lnk
2014-01-18 13:51 - 2014-01-18 13:51 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Virtual Keyboard
2014-01-18 13:51 - 2014-01-18 13:51 - 00000000 ____D () C:\Users\Jan\AppData\Local\Andrej_Koch
2014-01-17 22:18 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-01-17 20:29 - 2014-01-15 13:42 - 00000000 ____D () C:\Users\Jan\AppData\Local\Lexware
2014-01-16 15:30 - 2014-01-16 15:30 - 00001361 _____ () C:\Users\Public\Desktop\Die Macht des Steuerzahlers.lnk
2014-01-16 15:30 - 2013-12-04 18:39 - 00000000 ____D () C:\Program Files (x86)\Rademacher
2014-01-16 08:20 - 2014-01-15 13:52 - 00002669 _____ () C:\Users\Public\Desktop\TAXMAN 2012.lnk
2014-01-16 08:07 - 2009-07-14 05:45 - 00552792 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-01-15 23:30 - 2013-07-28 02:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-15 23:29 - 2013-02-07 16:58 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 15:18 - 2014-01-15 13:45 - 00000000 ____D () C:\ProgramData\lexware
2014-01-15 14:13 - 2014-01-15 14:13 - 00000000 ____D () C:\Users\Jan\AppData\Local\Netviewer
2014-01-15 14:11 - 2014-01-15 14:11 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Haufe Mediengruppe
2014-01-15 14:11 - 2014-01-15 14:11 - 00000000 ____D () C:\Users\Jan\AppData\Local\Haufe Mediengruppe
2014-01-15 14:00 - 2014-01-15 14:00 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Lexware
2014-01-15 14:00 - 2014-01-15 14:00 - 00000000 ____D () C:\Program Files (x86)\Lexware
2014-01-15 14:00 - 2013-02-07 18:45 - 00146024 _____ () C:\Users\Jan\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-15 14:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help
2014-01-15 13:59 - 2014-01-15 13:59 - 00000153 _____ () C:\Windows\ODBC.INI
2014-01-15 13:58 - 2014-01-15 13:58 - 00000000 ____D () C:\Program Files (x86)\Sybase
2014-01-15 13:58 - 2014-01-15 13:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE
2014-01-15 13:54 - 2014-01-15 13:54 - 00002319 _____ () C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
2014-01-15 13:50 - 2013-03-12 10:45 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\InstallShield Installation Information
2014-01-15 13:50 - 2013-02-07 16:19 - 00000000 ___RD () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-15 13:45 - 2014-01-15 13:45 - 00000000 ____D () C:\ProgramData\Haufe
2014-01-15 13:45 - 2014-01-15 13:45 - 00000000 ____D () C:\Program Files (x86)\Haufe
2014-01-15 13:44 - 2014-01-15 13:44 - 00455680 _____ (Sun Microsystems, Inc.) C:\Windows\system32\deploytk.dll
2014-01-11 21:11 - 2013-11-19 22:32 - 00000654 _____ () C:\Users\Jan\Desktop\Worüber alle Bürger klagen.txt
2014-01-11 06:41 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-09 18:05 - 2014-01-09 18:05 - 00000000 ____D () C:\Users\Jan\Documents\Steuer-Sparbuch
2014-01-09 17:16 - 2013-03-12 11:55 - 00000000 ____D () C:\ProgramData\Buhl Data Service GmbH
2014-01-09 17:14 - 2013-03-12 11:55 - 00000981 _____ () C:\Windows\wiso.ini
2014-01-09 17:14 - 2013-03-12 10:46 - 00000000 ____D () C:\Users\Jan\AppData\Local\Buhl
2014-01-09 09:06 - 2013-07-17 16:44 - 00000000 ____D () C:\Windows\pss
2014-01-07 12:21 - 2014-01-07 12:21 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Nitro
2014-01-07 12:21 - 2014-01-07 12:21 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\FileOpen
2014-01-07 12:21 - 2014-01-07 12:21 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Downloaded Installations
2014-01-07 12:21 - 2014-01-07 12:21 - 00000000 ____D () C:\ProgramData\Nitro
2014-01-07 12:21 - 2014-01-07 12:21 - 00000000 ____D () C:\ProgramData\FileOpen
2014-01-07 12:12 - 2014-01-07 12:12 - 00118784 _____ () C:\Windows\system32\dmusic64.exe
2014-01-07 12:11 - 2014-01-07 12:11 - 00000000 ____D () C:\Users\Jan\AppData\Local\Google
2014-01-07 11:32 - 2014-01-07 11:32 - 00000028 _____ () C:\Users\Jan\AppData\Roaming\PhonerLitesettings.ini
2014-01-07 11:32 - 2014-01-07 11:32 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\PhonerLite
Some content of TEMP:
====================
C:\Users\Jan\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-29 12:40
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-02-2014
Ran by Jan at 2014-02-05 06:58:32
Running from C:\Users\Jan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EN4T21H8
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
3CX Assistant (Version: 9.0.15770 - 3CX Ltd)
Adobe Bridge 1.0 (x32 Version: 001.000.001 - Adobe Systems) Hidden
Adobe Common File Installer (x32 Version: 1.00.001 - Adobe System Incorporated) Hidden
Adobe Flash Player 12 ActiveX (x32 Version: 12.0.0.38 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.43 - Adobe Systems Incorporated)
Adobe Help Center 2.1 (x32 Version: 2.1 - Adobe Systems)
Adobe InDesign CS2 (x32 Version: 004.000.000 - Adobe Systems Incorporated)
Adobe InDesign CS2 (x32 Version: 004.000.000 - Adobe Systems Incorporated) Hidden
Adobe Reader XI (11.0.06) - Deutsch (x32 Version: 11.0.06 - Adobe Systems Incorporated)
Adobe Stock Photos 1.0 (x32 Version: 1.0.1 - Adobe Systems) Hidden
Advanced Archive Password Recovery (x32 Version: 4.54.48.1338 - Elcomsoft Co. Ltd.)
AntragsManager (x32 Version: - )
Avira Internet Security (x32 Version: 14.0.2.286 - Avira)
CCleaner (Version: 4.09 - Piriform)
Die Macht der Selbstbeherrschung (x32 Version: - )
Die Macht des Steuerzahlers (x32 Version: - )
ESET Online Scanner v3 (x32 Version: - )
Free YouTube Download version 3.2.10.812 (x32 Version: 3.2.10.812 - DVDVideoSoft Ltd.)
Google Update Helper (x32 Version: 1.3.21.145 - Google Inc.) Hidden
Haufe iDesk-Browser (x32 Version: 10.10.14.0000 - Haufe-Lexware GmbH & Co. KG)
Haufe iDesk-Service (x32 Version: 11.07.19.8023 - Haufe)
Java 7 Update 51 (x32 Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Kaspersky Security Scan (x32 Version: 12.0.1.340 - Kaspersky Lab)
Kaspersky Security Scan (x32 Version: 12.0.1.340 - Kaspersky Lab) Hidden
KeyScrambler (x32 Version: 3.3.0.0 - QFX Software Corporation)
Kyocera Product Library (Version: 2.0.0713 - Kyocera Mita Corporation)
Lexware Admintools Plus (x32 Version: 11.00.00.0066 - Haufe-Lexware GmbH & Co.KG)
Lexware buchhalter 2012 (x32 Version: 17.02.00.0185 - Haufe-Lexware GmbH & Co.KG)
Lexware Datenbank plus 2011 (x32 Version: 11.00.00.0074 - Haufe-Lexware GmbH & Co.KG)
Lexware Elster (x32 Version: 11.00.00.0109 - Haufe-Lexware GmbH & Co.KG)
Lexware Info Service (x32 Version: 2.80.00.0007 - Haufe-Lexware GmbH & Co.KG)
Lexware online banking (x32 Version: 11.00.00.0039 - Haufe-Lexware GmbH & Co.KG)
Lexware reisekosten plus 2011 (x32 Version: 11.22.00.0124 - ) Hidden
Lexware reisekosten plus 2011 (x32 Version: 11.22.00.0124 - Haufe-Lexware GmbH & Co.KG)
lookinglink (Version: 2014.01.25.024532 - lookinglink)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2005 Tools for Office Runtime (x32 Version: 8.0.60940.0 - Microsoft Corporation) Hidden
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft-Maus- und Tastatur-Center (Version: 2.0.162.0 - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (Version: 2.0.162.0 - Microsoft Corporation) Hidden
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 24.2.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0 - Microsoft Corporation)
PDF24 Creator 6.2.0 (x32 Version: - PDF24.org)
PhonerLite 1.95 (x32 Version: 1.95 - sipgate GmbH)
Revo Uninstaller 1.95 (x32 Version: 1.95 - VS Revo Group)
Secunia PSI (3.0.0.9016) (x32 Version: 3.0.0.9016 - Secunia)
Skype™ 6.13 (x32 Version: 6.13.104 - Skype Technologies S.A.)
SumatraPDF (x32 Version: 2.4 - Krzysztof Kowalczyk)
TAXMAN 2012 (x32 Version: 18.09.00.0004 - Haufe-Lexware GmbH & Co.KG)
TAXMAN Bibliothek 2012 (x32 Version: 18.1.0.0 - Haufe-Lexware GmbH & Co. KG)
Temp File Cleaner (Version: 4.3.0 - Addpcs, LLC)
Update for 2007 Microsoft Office System (KB967642) (x32 Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (x32 Version: - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32 Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (x32 Version: - Microsoft)
Virtual Keyboard 4.0.1 (x32 Version: 4.0.1 - Andrej Koch)
Visual C++ 9.0 CRT (x86) WinSXS MSM (x32 Version: 9.0 - Microsoft Corporation) Hidden
Visual Studio 2005 Tools for Office Second Edition Runtime (x32 Version: - Microsoft Corporation)
VLC media player 1.1.5 (x32 Version: 1.1.5 - VideoLAN)
Weiße Weste durch Umzug (x32 Version: - )
Winamp (x32 Version: 5.61 - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1 - Nullsoft, Inc)
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8 - Microsoft Corp)
WinRAR 4.00 beta 3 (64-bit) (Version: 4.00.3 - win.rar GmbH)
WISO Hausverwalter 2013 (HKCU Version: 7.00.7718 - Buhl Data Service GmbH)
WISO Sparbuch 2010 (HKCU Version: 17.10.6777 - Buhl Data Service GmbH)
xp-AntiSpy 3.98-2 (x32 Version: - Christian Taubenheim)
==================== Restore Points =========================
05-02-2014 05:37:29 Windows Update
==================== Hosts content: ==========================
2009-07-14 03:34 - 2014-01-27 08:44 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {19E1E6A4-15E5-4081-B990-0617BD4C74E6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-28] (Adobe Systems Incorporated)
Task: {B3A26813-5065-4889-A3B3-742CCDE54634} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
Task: {DC668594-341C-4A20-9B8E-E87434ABBF02} - \CreateChoiceProcessTask No Task File
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2013-02-11 09:27 - 2013-07-01 19:26 - 00394824 _____ () D:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2010-11-24 16:00 - 2010-11-24 16:00 - 00019456 _____ () D:\Program Files (x86)\3CX Assistant\3cxtapiclient.dll
2014-01-23 11:38 - 2013-12-05 20:36 - 03559024 _____ () D:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (02/04/2014 10:00:56 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (02/04/2014 10:00:27 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3.
Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird.
Error: (02/03/2014 09:03:59 AM) (Source: Windows Search Service) (User: )
Description: Der Index kann nicht initialisiert werden.
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/03/2014 09:03:59 AM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.
Kontext: Windows Anwendung
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/03/2014 09:03:59 AM) (Source: Windows Search Service) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.
Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/03/2014 09:03:59 AM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden.
Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490)
Error: (02/03/2014 09:03:59 AM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden.
Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/03/2014 09:03:59 AM) (Source: Windows Search Service) (User: )
Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden.
Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800)
Error: (02/03/2014 09:03:59 AM) (Source: Windows Search Service) (User: )
Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet.
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/03/2014 09:03:59 AM) (Source: Windows Search Service) (User: )
Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=4700} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben.
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
System errors:
=============
Error: (02/05/2014 06:36:58 AM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error: (02/05/2014 06:04:25 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Email Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1.
Error: (02/04/2014 09:08:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Email Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1.
Error: (02/04/2014 07:16:43 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Email Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1.
Error: (02/03/2014 11:16:55 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Microsoft .NET Framework 4.5.1 für Windows 7 x64-basierte Systeme (KB2858725)
Error: (02/03/2014 11:09:17 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Microsoft .NET Framework 4.5.1 für Windows 7 x64-basierte Systeme (KB2858725)
Error: (02/03/2014 06:56:00 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Microsoft .NET Framework 4.5.1 für Windows 7 x64-basierte Systeme (KB2858725)
Error: (02/03/2014 06:54:58 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Microsoft .NET Framework 4.5.1 für Windows 7 x64-basierte Systeme (KB2858725)
Error: (02/03/2014 09:04:02 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (02/03/2014 09:04:02 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht.
Microsoft Office Sessions:
=========================
Error: (01/29/2014 07:52:14 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 33202 seconds with 180 seconds of active time. This session ended with a crash.
Error: (01/15/2014 11:27:43 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 49748 seconds with 4680 seconds of active time. This session ended with a crash.
Error: (10/24/2013 08:09:57 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 39672 seconds with 420 seconds of active time. This session ended with a crash.
Error: (10/22/2013 10:54:33 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 49925 seconds with 180 seconds of active time. This session ended with a crash.
Error: (10/18/2013 01:59:01 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8371 seconds with 120 seconds of active time. This session ended with a crash.
Error: (10/14/2013 01:54:01 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 20834 seconds with 360 seconds of active time. This session ended with a crash.
Error: (09/22/2013 00:34:11 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6514.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 101 seconds with 0 seconds of active time. This session ended with a crash.
Error: (09/15/2013 09:45:28 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash.
Error: (08/22/2013 03:04:15 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 18990 seconds with 1440 seconds of active time. This session ended with a crash.
Error: (07/07/2013 11:19:14 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7520 seconds with 180 seconds of active time. This session ended with a crash.
CodeIntegrity Errors:
===================================
Date: 2014-01-27 08:43:56.406
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-01-27 08:43:56.344
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-01-27 08:43:56.297
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-01-27 08:43:56.250
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-01-17 22:16:47.795
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-01-17 22:16:47.717
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 39%
Total physical RAM: 4029.92 MB
Available physical RAM: 2441.79 MB
Total Pagefile: 8058.02 MB
Available Pagefile: 6087.57 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:50.78 GB) (Free:4.05 GB) NTFS
Drive d: () (Fixed) (Total:68.36 GB) (Free:51 GB) NTFS
Drive e: (FIGHTCLUB) (CDROM) (Total:7.22 GB) (Free:0 GB) UDF
Drive g: () (Removable) (Total:3.73 GB) (Free:3.54 GB) FAT32
Drive n: (Verbatim) (Fixed) (Total:465.65 GB) (Free:385.9 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 50BDE2E4)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=68 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=51 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 4 GB) (Disk ID: 6F20736B)
No partition Table on disk 1.
Disk 1 is a removable device.
========================================================
Disk: 6 (Size: 466 GB) (Disk ID: F91A9EE0)
Partition 1: (Not Active) - (Size=466 GB) - (Type=0C)
==================== End Of Log ============================ |