Sorry, hatte "anhängen" wörtlich genommen...
1) Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 12:41 on 05/09/2013 (Petersplatz)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- 2)
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-09-2013
Ran by Petersplatz (administrator) on PPLAPTOP on 05-09-2013 12:45:01
Running from C:\Users\Petersplatz\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
() C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe
() C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Dropbox, Inc.) C:\Users\Petersplatz\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
() C:\Program Files (x86)\AVG Secure Search\vprot.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Petersplatz\Downloads\Defogger.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [608112 2011-03-29] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-05-27] (IDT, Inc.)
HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\QuickSet.exe [3668336 2011-03-24] (Dell Inc.)
HKLM\...\Run: [Stage Remote] - C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe [2022976 2011-06-28] ()
HKLM\...\Run: [DellStage] - C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj [483424 2012-02-01] ()
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\RunOnce: [Launcher] - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe [163040 2010-08-12] (Softthinks)
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1
HKCU\...\Run: [GoogleChromeAutoLaunch_DC2C44A93382AC9B5634D9F68269EB5C] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [829392 2013-08-24] (Google Inc.)
HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [503942 2011-04-13] (Creative Technology Ltd)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-13] (Intel Corporation)
HKLM-x32\...\Run: [RoxWatchTray] - c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] - c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\...\Run: [AccuWeatherWidget] - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj [2835443 2012-02-01] ()
HKLM-x32\...\Run: [AdobeCS4ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [642664 2013-05-08] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Adobe_ID0ENQBO] - C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe [378224 2008-08-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411440 2013-07-01] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG Secure Search\vprot.exe [2314416 2013-08-15] ()
HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-01-30] (DivX, LLC)
Startup: C:\Users\Petersplatz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Petersplatz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
BHO-x32: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll (Adobe Systems Incorporated.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll (Adobe Systems Incorporated.)
Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1 217.15.0.1 217.15.0.2
FireFox:
========
FF ProfilePath: C:\Users\Petersplatz\AppData\Roaming\Mozilla\Firefox\Profiles\lv4h1kzg.default
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32.dll No File
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0\\npsitesafety.dll (AVG Technologies)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.at/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 7.0.10.8) - C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U1) - C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (Google Drive) - C:\Users\PETERS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\PETERS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\PETERS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AVG Secure Search) - C:\Users\PETERS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.5.0.2_0
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\PETERS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\PETERS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\PETERS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0
CHR Extension: (Gmail) - C:\Users\PETERS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\15.5.0.2\avg.crx
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
==================== Services (Whitelisted) =================
S3 Adobe Version Cue CS4; C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [284016 2008-08-15] (Adobe Systems Incorporated)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)
S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2013-06-13] ()
R2 vToolbarUpdater15.5.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [1643184 2013-08-15] (AVG Secure Search)
==================== Drivers (Whitelisted) ====================
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206648 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-07-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [45856 2013-08-15] (AVG Technologies)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-05 12:43 - 2013-09-05 12:43 - 01947160 _____ (Farbar) C:\Users\Petersplatz\Desktop\FRST64.exe
2013-09-05 12:43 - 2013-09-05 12:43 - 00000765 _____ C:\Users\Petersplatz\Desktop\defogger_disable - Verknüpfung.lnk
2013-09-05 12:43 - 2013-09-05 12:43 - 00000725 _____ C:\Users\Petersplatz\Desktop\Defogger - Verknüpfung.lnk
2013-09-05 12:41 - 2013-09-05 12:41 - 00000484 _____ C:\Users\Petersplatz\Downloads\defogger_disable.log
2013-09-05 12:41 - 2013-09-05 12:41 - 00000000 _____ C:\Users\Petersplatz\defogger_reenable
2013-09-05 10:55 - 2013-09-05 10:55 - 00050477 _____ C:\Users\Petersplatz\Downloads\Defogger.exe
2013-09-01 10:24 - 2013-09-01 10:24 - 05294724 _____ C:\Users\Petersplatz\Downloads\Messbuch1309 (1).zip
2013-08-29 10:33 - 2013-08-29 10:33 - 00515927 _____ C:\Users\Petersplatz\Downloads\Messzettel1309.zip
2013-08-29 10:30 - 2013-08-29 10:31 - 05294724 _____ C:\Users\Petersplatz\Downloads\Messbuch1309.zip
2013-08-28 18:31 - 2013-08-28 18:31 - 01528184 _____ (Microsoft Corporation) C:\Users\Petersplatz\Downloads\GenuineCheck.exe
2013-08-28 18:12 - 2013-08-29 14:55 - 00000000 ____D C:\Users\Petersplatz\AppData\Roaming\Systweak
2013-08-28 18:12 - 2013-08-22 18:36 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\windows\system32\roboot64.exe
2013-08-28 18:11 - 2013-08-28 18:11 - 05541392 _____ (Systweak Inc ) C:\Users\Petersplatz\Downloads\rcpsetup_2005_file.net_ab_DE-iCh.exe
2013-08-28 14:32 - 2013-09-01 10:25 - 01335639 _____ C:\Users\Petersplatz\Desktop\Messbuch 1309.epub
2013-08-15 03:10 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-15 03:10 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-15 03:10 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-08-15 03:10 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-15 03:10 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-15 03:10 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-15 03:10 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-15 03:10 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-15 03:10 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-15 03:10 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-15 03:10 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-08-15 03:10 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-08-15 03:10 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-15 03:10 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-08-15 03:10 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-15 03:10 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-08-15 03:10 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-08-15 03:10 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-08-15 03:10 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-08-15 03:10 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-08-15 03:10 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-08-15 03:10 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-08-15 03:10 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-08-15 03:10 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-08-15 03:10 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-08-15 03:10 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-08-15 03:10 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-08-15 03:10 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-08-15 03:10 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-08-15 03:10 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-08-15 03:10 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 18:29 - 2013-08-14 18:29 - 00010908 _____ C:\Users\Petersplatz\Downloads\Budget2014 (1).xlsx
2013-08-14 14:25 - 2013-08-14 14:25 - 00011988 _____ C:\Users\Petersplatz\Downloads\Plan der Woche.xlsx
2013-08-14 12:57 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2013-08-14 12:57 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-08-14 12:57 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2013-08-14 12:57 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2013-08-14 12:57 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2013-08-14 12:57 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2013-08-14 12:57 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2013-08-14 12:57 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2013-08-14 12:55 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-14 12:55 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2013-08-14 12:55 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-08-14 12:55 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2013-08-14 12:55 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2013-08-14 12:55 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2013-08-14 12:54 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-14 12:54 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-08-14 12:54 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2013-08-14 12:54 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2013-08-14 12:54 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2013-08-14 12:54 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2013-08-14 12:54 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2013-08-14 12:54 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2013-08-14 12:54 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2013-08-14 12:54 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2013-08-14 12:54 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2013-08-14 12:54 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2013-08-14 12:54 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-08-13 18:51 - 2013-08-13 18:51 - 00014753 _____ C:\Users\Petersplatz\Downloads\Aufgabenforum.xlsm
2013-08-13 18:50 - 2013-08-13 18:51 - 00023954 _____ C:\Users\Petersplatz\Downloads\Forum2013.xlsm
2013-08-12 14:22 - 2013-08-12 14:22 - 00001106 _____ C:\Users\Petersplatz\Downloads\url.htm
2013-08-12 12:11 - 2013-08-12 12:14 - 00011696 _____ C:\Users\Petersplatz\Downloads\Budget2014.xlsx
2013-08-10 10:31 - 2013-08-10 10:35 - 37455597 _____ (A.I.SOFT,INC.) C:\Users\Petersplatz\Downloads\HL-2130-inst-B1-useu (1).EXE
2013-08-08 19:02 - 2013-08-08 19:02 - 00003132 _____ C:\windows\System32\Tasks\PCDoctorBackgroundMonitorTask-Retry
==================== One Month Modified Files and Folders =======
2013-09-05 12:44 - 2013-09-05 12:44 - 00000000 ____D C:\FRST
2013-09-05 12:43 - 2013-09-05 12:43 - 01947160 _____ (Farbar) C:\Users\Petersplatz\Desktop\FRST64.exe
2013-09-05 12:43 - 2013-09-05 12:43 - 00000765 _____ C:\Users\Petersplatz\Desktop\defogger_disable - Verknüpfung.lnk
2013-09-05 12:43 - 2013-09-05 12:43 - 00000725 _____ C:\Users\Petersplatz\Desktop\Defogger - Verknüpfung.lnk
2013-09-05 12:41 - 2013-09-05 12:41 - 00000484 _____ C:\Users\Petersplatz\Downloads\defogger_disable.log
2013-09-05 12:41 - 2013-09-05 12:41 - 00000000 _____ C:\Users\Petersplatz\defogger_reenable
2013-09-05 12:41 - 2013-01-04 12:10 - 00000000 ____D C:\Users\Petersplatz
2013-09-05 12:22 - 2013-02-24 10:38 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-09-05 12:14 - 2012-01-27 14:39 - 00696870 _____ C:\windows\system32\perfh007.dat
2013-09-05 12:14 - 2012-01-27 14:39 - 00148134 _____ C:\windows\system32\perfc007.dat
2013-09-05 12:14 - 2009-07-14 07:13 - 01612484 _____ C:\windows\system32\PerfStringBackup.INI
2013-09-05 12:12 - 2012-01-27 12:47 - 01652702 _____ C:\windows\WindowsUpdate.log
2013-09-05 12:11 - 2013-01-04 12:43 - 00001120 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-05 10:55 - 2013-09-05 10:55 - 00050477 _____ C:\Users\Petersplatz\Downloads\Defogger.exe
2013-09-05 10:42 - 2009-07-14 06:45 - 00020928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-05 10:42 - 2009-07-14 06:45 - 00020928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-05 10:39 - 2013-02-08 16:09 - 00000000 ____D C:\ProgramData\MFAData
2013-09-05 10:36 - 2013-01-08 12:44 - 00000000 ___RD C:\Users\Petersplatz\Dropbox
2013-09-05 10:36 - 2013-01-08 12:38 - 00000000 ____D C:\Users\Petersplatz\AppData\Roaming\Dropbox
2013-09-05 10:34 - 2013-01-04 12:43 - 00001116 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-05 10:34 - 2013-01-04 12:10 - 00000000 ____D C:\Users\PETERS~1\AppData\Local\SoftThinks
2013-09-05 10:34 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-09-05 10:34 - 2009-07-14 06:51 - 00074784 _____ C:\windows\setupact.log
2013-09-03 18:06 - 2012-01-27 13:16 - 00000000 ____D C:\ProgramData\Sonic
2013-09-02 17:46 - 2013-03-22 20:43 - 00000000 ____D C:\Users\Petersplatz\AppData\Roaming\vlc
2013-09-01 20:20 - 2013-01-04 20:47 - 00000000 ____D C:\Users\Petersplatz\Documents\Petersplatz Haus
2013-09-01 20:02 - 2012-01-27 13:31 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2013-09-01 10:25 - 2013-08-28 14:32 - 01335639 _____ C:\Users\Petersplatz\Desktop\Messbuch 1309.epub
2013-09-01 10:24 - 2013-09-01 10:24 - 05294724 _____ C:\Users\Petersplatz\Downloads\Messbuch1309 (1).zip
2013-08-31 10:44 - 2009-07-14 07:08 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-08-31 10:37 - 2013-05-01 15:50 - 00000375 _____ C:\windows\system32\Drivers\etc\hosts.ics
2013-08-29 16:10 - 2010-11-21 05:47 - 00034714 _____ C:\windows\PFRO.log
2013-08-29 14:57 - 2012-01-27 13:21 - 00000000 ____D C:\ProgramData\WildTangent
2013-08-29 14:55 - 2013-08-28 18:12 - 00000000 ____D C:\Users\Petersplatz\AppData\Roaming\Systweak
2013-08-29 10:33 - 2013-08-29 10:33 - 00515927 _____ C:\Users\Petersplatz\Downloads\Messzettel1309.zip
2013-08-29 10:31 - 2013-08-29 10:30 - 05294724 _____ C:\Users\Petersplatz\Downloads\Messbuch1309.zip
2013-08-28 18:33 - 2013-06-07 20:25 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-28 18:31 - 2013-08-28 18:31 - 01528184 _____ (Microsoft Corporation) C:\Users\Petersplatz\Downloads\GenuineCheck.exe
2013-08-28 18:11 - 2013-08-28 18:11 - 05541392 _____ (Systweak Inc ) C:\Users\Petersplatz\Downloads\rcpsetup_2005_file.net_ab_DE-iCh.exe
2013-08-28 15:44 - 2013-08-04 18:02 - 00000000 ____D C:\Users\Petersplatz\AppData\Roaming\dvdcss
2013-08-28 14:44 - 2013-05-22 15:50 - 00003440 _____ C:\windows\System32\Tasks\PCDEventLauncherTask
2013-08-27 18:12 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\NDF
2013-08-24 17:17 - 2012-01-27 13:17 - 00000000 ____D C:\ProgramData\Nero
2013-08-24 17:17 - 2012-01-27 13:17 - 00000000 ____D C:\Program Files (x86)\Nero
2013-08-23 16:07 - 2013-01-04 12:30 - 00000000 ____D C:\Users\PETERS~1\AppData\Local\Nero
2013-08-22 20:58 - 2013-02-24 10:38 - 00692104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-08-22 20:58 - 2013-02-24 10:38 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-08-22 20:58 - 2012-01-27 12:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-22 18:36 - 2013-08-28 18:12 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\windows\system32\roboot64.exe
2013-08-16 10:57 - 2009-07-14 05:20 - 00000000 ____D C:\windows\rescache
2013-08-15 14:25 - 2013-02-08 16:14 - 00045856 _____ (AVG Technologies) C:\windows\system32\Drivers\avgtpx64.sys
2013-08-15 14:25 - 2013-02-08 16:14 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search
2013-08-15 03:05 - 2013-07-25 20:49 - 00000000 ____D C:\windows\system32\MRT
2013-08-15 03:02 - 2013-01-04 13:42 - 78161360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-08-14 18:29 - 2013-08-14 18:29 - 00010908 _____ C:\Users\Petersplatz\Downloads\Budget2014 (1).xlsx
2013-08-14 14:25 - 2013-08-14 14:25 - 00011988 _____ C:\Users\Petersplatz\Downloads\Plan der Woche.xlsx
2013-08-13 18:51 - 2013-08-13 18:51 - 00014753 _____ C:\Users\Petersplatz\Downloads\Aufgabenforum.xlsm
2013-08-13 18:51 - 2013-08-13 18:50 - 00023954 _____ C:\Users\Petersplatz\Downloads\Forum2013.xlsm
2013-08-12 14:22 - 2013-08-12 14:22 - 00001106 _____ C:\Users\Petersplatz\Downloads\url.htm
2013-08-12 12:14 - 2013-08-12 12:11 - 00011696 _____ C:\Users\Petersplatz\Downloads\Budget2014.xlsx
2013-08-10 15:13 - 2013-05-11 16:14 - 03207168 _____ C:\Users\Petersplatz\Desktop\Aktuelle Filmliste.xls
2013-08-10 10:35 - 2013-08-10 10:31 - 37455597 _____ (A.I.SOFT,INC.) C:\Users\Petersplatz\Downloads\HL-2130-inst-B1-useu (1).EXE
2013-08-08 19:02 - 2013-08-08 19:02 - 00003132 _____ C:\windows\System32\Tasks\PCDoctorBackgroundMonitorTask-Retry
Files to move or delete:
====================
C:\Users\PETERS~1\AppData\Local\Temp\jna2282236172047180976.dll
C:\Users\PETERS~1\AppData\Local\Temp\{3D5AD9C7-EC19-4412-9C45-37F1F7B39E20}\{E2A97415-BD97-4867-B906-05E39E9EE51F}\difxapi.dll
C:\Users\PETERS~1\AppData\Local\Temp\SDIAG_f6fa8d54-e0cd-4151-8ce0-3b81c4f3e653\DiagPackage.dll
C:\Users\PETERS~1\AppData\Local\Temp\SDIAG_f6fa8d54-e0cd-4151-8ce0-3b81c4f3e653\UpdatePrinterDriver.dll
C:\Users\PETERS~1\AppData\Local\Temp\SDIAG_8c599cb5-0260-41a4-80c3-98962b18ee83\DiagPackage.dll
C:\Users\PETERS~1\AppData\Local\Temp\SDIAG_71813271-f82a-4be0-b379-d33d2fe3588d\DiagPackage.dll
C:\Users\PETERS~1\AppData\Local\Temp\SDIAG_65409e00-5a65-4f40-a4fa-640ebc468d46\DiagPackage.dll
C:\Users\PETERS~1\AppData\Local\Temp\SDIAG_65409e00-5a65-4f40-a4fa-640ebc468d46\UpdatePrinterDriver.dll
C:\Users\PETERS~1\AppData\Local\Temp\SDIAG_55338015-dd51-4121-8ed5-4f9059b4f63f\DiagPackage.dll
C:\Users\PETERS~1\AppData\Local\Temp\SDIAG_419f4ee8-aa3e-4535-9f00-b8030fd1eac3\DiagPackage.dll
C:\Users\PETERS~1\AppData\Local\Temp\SDIAG_2ad0926b-1978-4933-a236-69abdc70aaac\DiagPackage.dll
C:\Users\PETERS~1\AppData\Local\Temp\nstD0D7.tmp\DropboxNSISTools.dll
C:\Users\PETERS~1\AppData\Local\Temp\nstD0D7.tmp\UAC.dll
C:\Users\PETERS~1\AppData\Local\Temp\776D.tmp\osppc.dll
C:\Users\PETERS~1\AppData\Local\Temp\776D.tmp\ospprearm.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-01 20:41
==================== End Of Log ============================ --- --- ---
3) Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-09-2013
Ran by Petersplatz at 2013-09-05 12:45:51
Running from C:\Users\Petersplatz\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
2013 (Version: 2013.0.3392)
7-Zip 9.20 (x32)
Acrobat.com (x32 Version: 0.0.0)
Acrobat.com (x32 Version: 1.2.443)
Adobe Acrobat 9 Pro - English, Français, Deutsch (x32 Version: 9.5.5)
Adobe Acrobat 9.5.5 - CPSID_83708 (x32)
Adobe After Effects CS4 (x32 Version: 9)
Adobe After Effects CS4 Presets (x32 Version: 9)
Adobe After Effects CS4 Third Party Content (x32 Version: 9)
Adobe AIR (x32 Version: 2.6.0.19120)
Adobe Anchor Service CS4 (x32 Version: 2.0)
Adobe Anchor Service x64 CS4 (Version: 2.0)
Adobe Asset Services CS4 (x32 Version: 4)
Adobe Bridge CS4 (x32 Version: 3)
Adobe CMaps CS4 (x32 Version: 2.0)
Adobe CMaps x64 CS4 (Version: 2.0)
Adobe Color - Photoshop Specific CS4 (x32 Version: 2.0)
Adobe Color EU Recommended Settings CS4 (x32 Version: 2.0)
Adobe Color JA Extra Settings CS4 (x32 Version: 2.0)
Adobe Color NA Extra Settings CS4 (x32 Version: 2.0)
Adobe Color Video Profiles AE CS4 (x32 Version: 2.0)
Adobe Color Video Profiles CS CS4 (x32 Version: 2.0)
Adobe Contribute CS4 (x32 Version: 5.0)
Adobe Creative Suite 4 Master Collection (x32 Version: 4.0)
Adobe CS4 American English Speech Analysis Models (x32 Version: 1)
Adobe CSI CS4 (x32 Version: 1)
Adobe CSI CS4 x64 (Version: 1)
Adobe Default Language CS4 (x32 Version: 2.0)
Adobe Device Central CS4 (x32 Version: 2)
Adobe Dreamweaver CS4 (x32 Version: 10.0)
Adobe Drive CS4 (x32 Version: 1)
Adobe Drive CS4 x64 (Version: 1)
Adobe Dynamiclink Support (x32 Version: 1)
Adobe Encore CS4 (x32 Version: 4)
Adobe Encore CS4 Codecs (x32 Version: 4)
Adobe ExtendScript Toolkit CS4 (x32 Version: 3.0.0)
Adobe Extension Manager CS4 (x32 Version: 2.0)
Adobe Fireworks CS4 (x32 Version: 10.0)
Adobe Flash CS4 (x32 Version: 10.0)
Adobe Flash CS4 Extension - Flash Lite STI others (x32 Version: 3.0)
Adobe Flash CS4 STI-other (x32 Version: 10.0)
Adobe Flash Player 10 Plugin (x32 Version: 10.0.2.54)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94)
Adobe Fonts All (x32 Version: 2.0)
Adobe Fonts All x64 (Version: 2.0)
Adobe Illustrator CS4 (x32 Version: 14.0)
Adobe InDesign CS4 (x32 Version: 6.0)
Adobe InDesign CS4 Application Feature Set Files (Roman) (x32 Version: 6.0)
Adobe InDesign CS4 Common Base Files (x32 Version: 6.0)
Adobe InDesign CS4 Icon Handler (x32 Version: 6.0)
Adobe InDesign CS4 Icon Handler x64 (Version: 6.0)
Adobe Linguistics CS4 (x32 Version: 4.0.0)
Adobe Linguistics CS4 x64 (Version: 4.0.0)
Adobe Media Encoder CS4 (x32 Version: 1.0)
Adobe Media Encoder CS4 Additional Exporter (x32 Version: 1.0)
Adobe Media Encoder CS4 Dolby (x32 Version: 1.0)
Adobe Media Encoder CS4 Exporter (x32 Version: 1.0)
Adobe Media Encoder CS4 Importer (x32 Version: 1.0)
Adobe Media Player (x32 Version: 0.0.0)
Adobe Media Player (x32 Version: 1.1)
Adobe MotionPicture Color Files CS4 (x32 Version: 2.0)
Adobe OnLocation CS4 (x32 Version: 4)
Adobe Output Module (x32 Version: 2.0)
Adobe PDF Library Files CS4 (x32 Version: 9.0)
Adobe PDF Library Files x64 CS4 (Version: 9.0)
Adobe Photoshop CS4 (64 Bit) (Version: 11.0)
Adobe Photoshop CS4 (x32 Version: 11.0)
Adobe Photoshop CS4 Support (x32 Version: 11.0)
Adobe Premiere Pro CS4 (x32 Version: 4)
Adobe Premiere Pro CS4 Functional Content (x32 Version: 4)
Adobe Premiere Pro CS4 Third Party Content (x32 Version: 4)
Adobe Reader X (10.1.6) MUI (x32 Version: 10.1.6)
Adobe Search for Help (x32 Version: 1.0)
Adobe Service Manager Extension (x32 Version: 1.0)
Adobe Setup (x32 Version: 2.0)
Adobe SGM CS4 (x32 Version: 3.0)
Adobe SING CS4 (x32 Version: 2.0)
Adobe Soundbooth CS4 (x32 Version: 2)
Adobe Soundbooth CS4 Codecs (x32 Version: 2)
Adobe Type Support CS4 (x32 Version: 9.0)
Adobe Type Support x64 CS4 (Version: 9.0)
Adobe Update Manager CS4 (x32 Version: 6.0.0)
Adobe Version Cue CS4 Server (x32 Version: 4.0)
Adobe WinSoft Linguistics Plugin (x32 Version: 1.1)
Adobe WinSoft Linguistics Plugin x64 (Version: 1.1)
Adobe XMP Panels CS4 (x32 Version: 2.0)
AdobeColorCommonSetCMYK (x32 Version: 2.0)
AdobeColorCommonSetRGB (x32 Version: 2.0)
Advanced Audio FX Engine (x32 Version: 1.12.05)
AVG 2013 (Version: 13.0.3222)
AVG 2013 (Version: 13.0.3392)
AVG Security Toolbar (x32 Version: 15.5.0.2)
Connect (x32 Version: 1.0.0.1)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
Dell DataSafe Local Backup - Support Software (x32)
Dell DataSafe Local Backup (x32 Version: 9.4.47)
Dell Edoc Viewer (Version: 1.0.0)
Dell Getting Started Guide (x32 Version: 1.00.0000)
Dell MusicStage (x32 Version: 1.5.201.0)
Dell PhotoStage (x32 Version: 1.5.0.65)
Dell Stage (x32 Version: 1.7.209.0)
Dell Stage Remote (x32 Version: 2.0.0.43)
Dell Touchpad (Version: 7.1207.101.225)
Dell VideoStage (x32 Version: 1.2.0.1712)
Dell Webcam Central (x32 Version: 2.00.44)
DirectX 9 Runtime (x32 Version: 1.00.0000)
DivX-Setup (x32 Version: 2.6.1.24)
Dropbox (HKCU Version: 2.0.22)
DW WLAN Card (Version: 5.100.82.88)
eBay (x32 Version: 1.4.0)
ELBA5 (C:\Program Files (x86)\ELBA5) (x32 Version: 5.4.1.0)
Free Video Converter V 3.1 (x32 Version: 3.1.0.0)
Free YouTube Download version 3.2.0.128 (x32 Version: 3.2.0.128)
Google Apps Migration For Microsoft Outlook® 2.3.12.34 (x32 Version: 2.3.12.34)
Google Apps Sync™ for Microsoft Outlook® 3.2.353.947 (x32 Version: 3.2.353.947)
Google Chrome (x32 Version: 29.0.1547.66)
Google Update Helper (x32 Version: 1.3.21.153)
HL-2130 (x32 Version: 1.0.7.0)
IDT Audio (x32 Version: 1.0.6341.0)
Intel(R) Control Center (x32 Version: 1.2.1.1007)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2342)
Intel(R) Rapid Storage Technology (x32 Version: 10.1.2.1004)
iSilo (x32 Version: 5.10.21)
Java 7 Update 21 (x32 Version: 7.0.210)
Java Auto Updater (x32 Version: 2.1.9.5)
Java(TM) 7 Update 1 (64-bit) (Version: 7.0.10)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
kuler (x32 Version: 2.0)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 19.0.2 (x86 de) (x32 Version: 19.0.2)
Mozilla Maintenance Service (x32 Version: 19.0.2)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
My Dell (Version: 3.3.6280.92)
PDF Settings CS4 (x32 Version: 9.0)
Photoshop Camera Raw (x32 Version: 5.0)
Photoshop Camera Raw_x64 (Version: 5.0)
PhotoShowExpress (x32 Version: 2.0.063)
Pixel Bender Toolkit (x32 Version: 1.0)
Quickset64 (Version: 10.09.25)
RBVirtualFolder64Inst (Version: 1.00.0000)
Realtek Ethernet Controller Driver (x32 Version: 7.45.516.2011)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30126)
Roxio Activation Module (x32 Version: 1.0)
Roxio BackOnTrack (x32 Version: 1.3.3)
Roxio Burn (x32 Version: 1.8)
Roxio Creator Starter (x32 Version: 1.0.439)
Roxio Creator Starter (x32 Version: 12.1.77.0)
Roxio Creator Starter (x32 Version: 5.0.0)
Roxio Express Labeler 3 (x32 Version: 3.2.2)
Roxio File Backup (Version: 1.3.2)
Shared C Run-time for x64 (Version: 10.0.0)
Skype™ 5.10 (x32 Version: 5.10.116)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0)
Suite Shared Configuration CS4 (x32 Version: 1.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 64-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 64-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
VLC media player 2.0.5 (x32 Version: 2.0.5)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3508.1109)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Mobile-Gerätecenter (Version: 6.1.6965.0)
Zinio Reader 4 (x32 Version: 4.2.4164)
==================== Restore Points =========================
02-08-2013 17:50:39 Geplanter Prüfpunkt
10-08-2013 12:54:25 Geplanter Prüfpunkt
15-08-2013 01:01:03 Windows Update
24-08-2013 15:15:22 Removed SyncUP.
28-08-2013 16:15:59 RegClean Pro Mi, Aug 28, 13 18:15
28-08-2013 16:32:28 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started
Task: {45BD0002-38EE-4897-A458-2580AC2670AE} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation)
Task: {485BC70C-A13D-40F6-970C-3F9EED5653F8} - System32\Tasks\SystemToolsDailyTest => C:\Windows\System32\uaclauncher.exe
Task: {550CE1BD-08AA-42E0-B52A-644224FE98B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-04] (Google Inc.)
Task: {57A4601C-616A-4D76-930C-3AF2F85776CE} - System32\Tasks\PCDoctorBackgroundMonitorTask-Retry => C:\Program Files\My Dell\uaclauncher.exe [2013-05-07] (PC-Doctor, Inc.)
Task: {6244938C-397A-40BB-B7BF-CF3B54A960A8} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\System32\sdengin2.dll [2010-11-21] (Microsoft Corporation)
Task: {7C0F1747-4BC1-4F64-89C2-05F7E7BE3BB8} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {8F50FB0F-5C4C-4E5C-A68F-720EAF36DE01} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2013-07-18] (PC-Doctor, Inc.)
Task: {A04700EB-16FE-424B-916A-E2B2B5E8065D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-04] (Google Inc.)
Task: {A5BC6CD7-CE17-4115-81B1-1CFCCF5C8EA7} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {AB4167B8-284D-4C23-A5BB-D176837E02EF} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-22] (Adobe Systems Incorporated)
Task: {B0B68EDB-8281-4EC0-B7BE-E58498B74E6C} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-21] (Microsoft Corporation)
Task: {B381A536-8355-4402-B4F0-3BAF438D9080} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {DE7FFB44-D3EB-47EA-9324-CC85A52702C6} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2013-05-07] (PC-Doctor, Inc.)
Task: {F7F08BB2-6CFB-4474-B7D8-D5EF2E22AB65} - System32\Tasks\Divx-Online-Aktualisierungsprogramm => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2013-02-13] ()
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-05-25 02:36 - 2013-05-25 02:36 - 00164016 _____ (Dropbox, Inc.) C:\Users\Petersplatz\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
2011-03-17 00:07 - 2011-03-17 00:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2013-06-27 01:54 - 2013-06-27 01:54 - 01018416 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgsysa.dll
2010-11-11 06:54 - 2010-11-11 06:54 - 00177136 _____ (TODO: <Company name>) c:\Program Files\Roxio\Roxio Burn\RB_ContextMenu64.dll
2013-03-28 02:48 - 2013-03-28 02:48 - 00266288 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgsea.dll
2012-01-27 14:10 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrDEU.lrc
2012-01-27 14:10 - 2011-03-26 03:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-01-27 14:13 - 2011-03-02 20:30 - 01711472 _____ (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.dll
2012-01-27 14:13 - 2011-01-19 07:36 - 00110448 _____ (Alps Electric Co., Ltd.) C:\windows\system32\Vxdif.dll
2012-01-27 14:13 - 2010-06-01 07:23 - 00039792 _____ (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\EzAuto.dll
2012-01-27 13:02 - 2011-05-27 21:06 - 04780032 _____ (IDT, Inc.) C:\Program Files\IDT\WDM\STLang64.dll
2012-01-27 13:02 - 2011-05-27 21:06 - 00654336 ____N (IDT, Inc.) C:\Windows\system32\stapi64.dll
2012-01-27 14:13 - 2011-01-19 07:36 - 00110448 _____ (Alps Electric Co., Ltd.) C:\windows\system32\VXDIF.DLL
2012-01-27 14:13 - 2011-03-02 20:30 - 01711472 _____ (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.DLL
2012-01-27 13:31 - 2010-08-12 02:19 - 00126176 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
2012-01-27 13:31 - 2010-08-12 02:19 - 01121504 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll
2012-01-27 13:31 - 2010-08-12 02:19 - 00077024 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
2012-01-27 13:31 - 2010-08-12 02:19 - 00232672 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll
2012-01-27 13:31 - 2010-08-12 02:19 - 00072928 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll
2012-01-27 13:31 - 2010-08-12 02:19 - 00109792 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll
2012-01-27 13:31 - 2010-08-12 02:19 - 00119008 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll
2013-01-04 13:06 - 2012-10-16 09:39 - 00561664 _____ (Microsoft Corporation) C:\windows\AppPatch\AcLayers.DLL
2010-03-17 04:28 - 2010-03-17 04:28 - 01926144 _____ () C:\Program Files (x86)\Dell\Stage Remote\QtCore4.dll
2010-03-22 23:52 - 2010-03-22 23:52 - 06776832 _____ () C:\Program Files (x86)\Dell\Stage Remote\QtGui4.dll
2010-03-17 04:28 - 2010-03-17 04:28 - 00635904 _____ () C:\Program Files (x86)\Dell\Stage Remote\QtNetwork4.dll
2010-03-17 04:28 - 2010-03-17 04:28 - 00326144 _____ () C:\Program Files (x86)\Dell\Stage Remote\QtXml4.dll
2011-06-29 16:52 - 2011-06-29 16:52 - 00077376 _____ (ArcSoft Inc.) C:\Program Files (x86)\Dell\Stage Remote\DMSAdapter.dll
2011-06-28 03:25 - 2011-06-28 03:25 - 00491968 _____ (ArcSoft Inc.) C:\Program Files (x86)\Dell\Stage Remote\DHServerAgent.dll
2011-06-28 03:26 - 2011-06-28 03:26 - 00715400 _____ (ArcSoft Inc.) C:\Program Files (x86)\Dell\Stage Remote\UMediaManager.dll
2011-06-25 07:19 - 2011-06-25 07:19 - 00043584 _____ (ArcSoft Inc.) C:\Program Files (x86)\Dell\Stage Remote\ASDBTool.dll
2011-06-25 07:20 - 2011-06-25 07:20 - 00565968 _____ () C:\Program Files (x86)\Dell\Stage Remote\sqlite3.dll
2011-06-28 03:25 - 2011-06-28 03:25 - 00051264 _____ (ArcSoft Inc.) C:\Program Files (x86)\Dell\Stage Remote\ASTransMgr.dll
2011-06-25 07:19 - 2011-06-25 07:19 - 00043584 _____ (ArcSoft Inc.) C:\Program Files (x86)\Dell\Stage Remote\ASXmlTool.dll
2011-06-28 03:25 - 2011-06-28 03:25 - 00058944 _____ () C:\Program Files (x86)\Dell\Stage Remote\DataService.dll
2011-06-25 07:32 - 2011-06-25 07:32 - 00323136 _____ () C:\Program Files (x86)\Dell\Stage Remote\de-DE\UI\ManagerUI.dll
2010-03-12 03:52 - 2010-03-12 03:52 - 00028160 _____ () C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qgif4.dll
2010-03-05 23:07 - 2010-03-05 23:07 - 00031744 _____ () C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qico4.dll
2010-03-05 23:07 - 2010-03-05 23:07 - 00125952 _____ () C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qjpeg4.dll
2010-03-12 03:52 - 2010-03-12 03:52 - 00225280 _____ () C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qmng4.dll
2010-01-07 04:43 - 2010-01-07 04:43 - 00017408 _____ (ArcSoft Inc.) C:\Program Files (x86)\Dell\Stage Remote\EndPointCtrl.dll
2013-08-15 14:25 - 2013-08-15 14:25 - 01110704 _____ (AVG Technologies) C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0\npsitesafety.dll
2013-09-03 18:53 - 2013-08-24 19:48 - 09962960 _____ (The ICU Project) C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\icudt.dll
2013-05-25 02:36 - 2013-05-25 02:36 - 00130736 _____ (Dropbox, Inc.) C:\Users\Petersplatz\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
2011-03-17 00:11 - 2011-03-17 00:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-05-15 08:00 - 2013-04-13 06:45 - 00474624 _____ (Microsoft Corporation) C:\windows\AppPatch\AcSpecfc.DLL
2012-11-14 01:32 - 2012-11-14 01:32 - 03558400 _____ (wxWidgets development team) C:\Users\Petersplatz\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\Petersplatz\AppData\Roaming\Dropbox\bin\libcef.dll
2013-03-13 22:48 - 2013-03-13 22:48 - 09956864 _____ (The ICU Project) C:\Users\Petersplatz\AppData\Roaming\Dropbox\bin\icudt.dll
2012-01-27 12:53 - 2009-09-08 18:01 - 00237056 ____N (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\CTLoadRs.dll
2012-01-27 12:53 - 2010-07-22 21:01 - 00065536 ____N (Creative Technology Ltd.) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\CtPinMgr.dll
2013-08-15 04:30 - 2013-08-15 04:30 - 00475648 _____ (Intel Corporation) C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\6c1d55eed243331c944206f8608fb850\IAStorUtil.ni.dll
2013-07-12 11:42 - 2013-07-12 11:42 - 00014336 _____ (Intel Corp.) C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\571f0babf15ab38dc80829622caa99d3\IAStorCommon.ni.dll
2010-11-09 19:59 - 2010-11-09 19:59 - 04479472 _____ (Sonic Solutions) C:\Program Files (x86)\Roxio\OEM\Roxio Burn\AS_Storage_w32.dll
2010-11-25 06:34 - 2010-11-25 06:34 - 00632304 _____ (Sonic Solutions) c:\program files (x86)\common files\roxio shared\dllshared\homepermitsconfig13.dll
2010-11-22 21:27 - 2010-11-22 21:27 - 00190960 _____ (Roxio, Inc.) c:\program files (x86)\common files\roxio shared\dllshared\rsl.dll
2010-11-25 06:44 - 2010-11-25 06:44 - 00375280 _____ () c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
2010-11-22 21:27 - 2010-11-22 21:27 - 00186864 _____ (Sonic Solutions) c:\program files (x86)\common files\roxio shared\dllshared\rcsl.dll
2010-11-25 06:35 - 2010-11-25 06:35 - 00961008 _____ (Sonic Solutions) c:\program files (x86)\common files\roxio shared\dllshared\SonicHTTPClient13.dll
2010-11-25 06:35 - 2010-11-25 06:35 - 00712688 _____ (Sonic Solutions) c:\program files (x86)\common files\roxio shared\dllshared\SonicLicenseManager13.dll
2012-02-01 12:44 - 2012-02-01 12:44 - 18858496 _____ (Unlimited Realities) C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\libumajin.dll
2012-02-01 12:44 - 2012-02-01 12:44 - 08151040 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll
2012-02-01 12:44 - 2012-02-01 12:44 - 02278400 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll
2013-07-27 11:57 - 2009-02-27 17:39 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.deu
2013-01-09 21:03 - 2009-02-27 17:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2013-01-09 21:03 - 2010-02-17 11:50 - 00626688 ____R (Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonWRes.dll
2009-07-14 02:29 - 2009-07-14 03:38 - 00701952 _____ (Microsoft Corporation) C:\windows\system32\hhctrl.ocx
2013-01-09 21:03 - 2009-12-25 16:08 - 00208896 ____R (Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrFirmUpdateCheck.dll
2013-02-19 05:01 - 2013-02-19 05:01 - 00890928 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgntopensslx.dll
2013-06-27 01:54 - 2013-06-27 01:54 - 00848432 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgsysx.dll
2013-02-19 05:01 - 2013-02-19 05:01 - 00309808 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avglogx.dll
2013-07-23 01:31 - 2013-07-23 01:31 - 02853936 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgkrnlapix.dll
2013-03-21 03:09 - 2013-03-21 03:09 - 01028144 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcfgx.dll
2013-07-26 01:33 - 2013-07-26 01:33 - 00455216 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcommx.dll
2013-02-19 05:01 - 2013-02-19 05:01 - 00273968 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidpmx.dll
2013-02-19 05:01 - 2013-02-19 05:01 - 00174640 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avglngx.dll
2013-03-29 02:54 - 2013-03-29 02:54 - 01799216 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avguires.dll
2013-02-19 05:00 - 2013-02-19 05:00 - 00279088 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgclitx.dll
2013-02-19 05:01 - 2013-02-19 05:01 - 00025648 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgapps.dll
2013-03-14 03:16 - 2013-03-14 03:16 - 00409648 _____ (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgdecider.dll
2009-07-14 02:18 - 2009-07-14 03:38 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\imaadp32.acm
2009-07-14 02:18 - 2009-07-14 03:38 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\msg711.acm
2009-07-14 02:18 - 2009-07-14 03:38 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\msgsm32.acm
2009-07-14 02:18 - 2009-07-14 03:38 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\msadp32.acm
2009-07-14 02:07 - 2009-07-14 03:14 - 00064000 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\SysWOW64\l3codeca.acm
2009-07-14 02:23 - 2009-07-14 03:38 - 00182272 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\windows\system32\l3codecp.acm
2013-08-15 14:25 - 2013-08-15 14:25 - 00521904 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\log4cplusU.dll
2013-08-15 14:25 - 2013-08-15 14:25 - 00144560 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0\SiteSafety.dll
2013-09-03 18:53 - 2013-08-24 19:49 - 00709584 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\libglesv2.dll
2013-09-03 18:53 - 2013-08-24 19:49 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\libegl.dll
2013-09-03 18:53 - 2013-08-24 19:49 - 04053456 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\pdf.dll
2013-09-03 18:53 - 2013-08-24 19:49 - 00410576 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll
2013-09-03 18:53 - 2013-08-24 19:48 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) ==========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/02/2013 05:22:46 PM) (Source: Application Hang) (User: )
Description: Programm Explorer.EXE, Version 6.1.7601.17567 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: a7c
Startzeit: 01cea7eba1a4c188
Endzeit: 31
Anwendungspfad: C:\windows\Explorer.EXE
Berichts-ID: 80d8675c-13e3-11e3-ae87-64273768c763
Error: (09/01/2013 08:11:38 PM) (Source: Application Hang) (User: )
Description: Programm WINWORD.EXE, Version 14.0.6129.5000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 84c
Startzeit: 01cea73d4cbd621d
Endzeit: 15
Anwendungspfad: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Berichts-ID: e88f5a00-1331-11e3-baae-24b6fd1d0888
Error: (08/31/2013 06:57:31 PM) (Source: Application Hang) (User: )
Description: Programm WINWORD.EXE, Version 14.0.6129.5000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: fd0
Startzeit: 01cea627e2e40d2a
Endzeit: 110
Anwendungspfad: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Berichts-ID: 6863bc6a-125e-11e3-a206-24b6fd1d0888
Error: (08/31/2013 06:57:21 PM) (Source: Application Hang) (User: )
Description: Programm WINWORD.EXE, Version 14.0.6129.5000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: a40
Startzeit: 01cea65400e93738
Endzeit: 47
Anwendungspfad: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Berichts-ID: 4d488123-125e-11e3-a206-24b6fd1d0888
Error: (08/31/2013 10:52:53 AM) (Source: Application Hang) (User: )
Description: Programm Explorer.EXE, Version 6.1.7601.17567 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: b10
Startzeit: 01cea62726114840
Endzeit: 16
Anwendungspfad: C:\windows\Explorer.EXE
Berichts-ID: b31dfd69-121a-11e3-a206-24b6fd1d0888
Error: (08/31/2013 10:22:11 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/30/2013 08:01:23 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/30/2013 10:25:08 AM) (Source: Application Hang) (User: )
Description: Programm WINWORD.EXE, Version 14.0.6129.5000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 139c
Startzeit: 01cea557ffb569a1
Endzeit: 0
Anwendungspfad: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Berichts-ID: a999c8a3-114d-11e3-8aec-24b6fd1d0888
Error: (08/30/2013 10:07:31 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/29/2013 04:12:42 PM) (Source: Application Hang) (User: )
Description: Programm Explorer.EXE, Version 6.1.7601.17567 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: c60
Startzeit: 01cea4c1957e8cc3
Endzeit: 47
Anwendungspfad: C:\windows\Explorer.EXE
Berichts-ID: 0faf7129-10b5-11e3-bb10-64273768c763
System errors:
=============
Error: (09/03/2013 08:46:21 PM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (09/03/2013 06:05:47 PM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (09/02/2013 06:13:33 PM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (09/02/2013 06:13:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
Error: (09/02/2013 06:08:18 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Error: (09/02/2013 06:07:11 PM) (Source: DCOM) (User: )
Description: {06622D85-6856-4460-8DE1-A81921B41C4B}
Error: (09/02/2013 04:49:31 PM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (09/01/2013 08:59:32 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst BrYNSvc erreicht.
Error: (09/01/2013 08:59:01 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst BrYNSvc erreicht.
Error: (09/01/2013 08:58:56 PM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Microsoft Office Sessions:
=========================
Error: (09/02/2013 05:22:46 PM) (Source: Application Hang)(User: )
Description: Explorer.EXE6.1.7601.17567a7c01cea7eba1a4c18831C:\windows\Explorer.EXE80d8675c-13e3-11e3-ae87-64273768c763
Error: (09/01/2013 08:11:38 PM) (Source: Application Hang)(User: )
Description: WINWORD.EXE14.0.6129.500084c01cea73d4cbd621d15C:\Program Files\Microsoft Office\Office14\WINWORD.EXEe88f5a00-1331-11e3-baae-24b6fd1d0888
Error: (08/31/2013 06:57:31 PM) (Source: Application Hang)(User: )
Description: WINWORD.EXE14.0.6129.5000fd001cea627e2e40d2a110C:\Program Files\Microsoft Office\Office14\WINWORD.EXE6863bc6a-125e-11e3-a206-24b6fd1d0888
Error: (08/31/2013 06:57:21 PM) (Source: Application Hang)(User: )
Description: WINWORD.EXE14.0.6129.5000a4001cea65400e9373847C:\Program Files\Microsoft Office\Office14\WINWORD.EXE4d488123-125e-11e3-a206-24b6fd1d0888
Error: (08/31/2013 10:52:53 AM) (Source: Application Hang)(User: )
Description: Explorer.EXE6.1.7601.17567b1001cea6272611484016C:\windows\Explorer.EXEb31dfd69-121a-11e3-a206-24b6fd1d0888
Error: (08/31/2013 10:22:11 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/30/2013 08:01:23 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/30/2013 10:25:08 AM) (Source: Application Hang)(User: )
Description: WINWORD.EXE14.0.6129.5000139c01cea557ffb569a10C:\Program Files\Microsoft Office\Office14\WINWORD.EXEa999c8a3-114d-11e3-8aec-24b6fd1d0888
Error: (08/30/2013 10:07:31 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/29/2013 04:12:42 PM) (Source: Application Hang)(User: )
Description: Explorer.EXE6.1.7601.17567c6001cea4c1957e8cc347C:\windows\Explorer.EXE0faf7129-10b5-11e3-bb10-64273768c763
==================== Memory info ===========================
Percentage of memory in use: 65%
Total physical RAM: 4004.27 MB
Available physical RAM: 1368.97 MB
Total Pagefile: 8006.73 MB
Available Pagefile: 5650.04 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:374.84 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: B3B3C776)
Partition 1: (Not Active) - (Size=100 MB) - (Type=DE)
Partition 2: (Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=451 GB) - (Type=07 NTFS)
==================== End Of Log ============================ 4) Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-09-05 16:18:37
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST500LM0 rev.2AR1 465,76GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\PETERS~1\AppData\Local\Temp\pgtiapow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 544 fffff800035a6000 45 bytes [00, 00, 10, 02, 4E, 74, 66, ...]
INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 591 fffff800035a602f 18 bytes [00, 01, 00, 06, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe[1848] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077491465 2 bytes [49, 77]
.text C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe[1848] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000774914bb 2 bytes [49, 77]
.text ... * 2
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[2016] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077491465 2 bytes [49, 77]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[2016] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000774914bb 2 bytes [49, 77]
.text ... * 2
.text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe[1956] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077491465 2 bytes [49, 77]
.text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe[1956] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000774914bb 2 bytes [49, 77]
.text ... * 2
.text C:\Users\Petersplatz\AppData\Roaming\Dropbox\bin\Dropbox.exe[4260] C:\windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000077491465 2 bytes [49, 77]
.text C:\Users\Petersplatz\AppData\Roaming\Dropbox\bin\Dropbox.exe[4260] C:\windows\syswow64\Psapi.dll!GetModuleInformation + 155 00000000774914bb 2 bytes [49, 77]
.text ... * 2
.text C:\Program Files (x86)\AVG Secure Search\vprot.exe[4628] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077491465 2 bytes [49, 77]
.text C:\Program Files (x86)\AVG Secure Search\vprot.exe[4628] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000774914bb 2 bytes [49, 77]
.text ... * 2
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{5B729DE4-EBFF-4188-8F2C-EFFA1B710AB2}\Connection@Name isatap.{335E881E-9033-47B8-B300-CF5EBBD7D085}
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind \Device\{8A23D3E6-01B2-422C-B8AE-2AD9144852F6}?\Device\{A8805CE8-CD4E-44C7-B29D-51F8B4E4E12B}?\Device\{5B729DE4-EBFF-4188-8F2C-EFFA1B710AB2}?\Device\{6DBA3FC3-B04D-4131-A77D-3B88E07B85DA}?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route "{8A23D3E6-01B2-422C-B8AE-2AD9144852F6}"?"{A8805CE8-CD4E-44C7-B29D-51F8B4E4E12B}"?"{5B729DE4-EBFF-4188-8F2C-EFFA1B710AB2}"?"{6DBA3FC3-B04D-4131-A77D-3B88E07B85DA}"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export \Device\TCPIP6TUNNEL_{8A23D3E6-01B2-422C-B8AE-2AD9144852F6}?\Device\TCPIP6TUNNEL_{A8805CE8-CD4E-44C7-B29D-51F8B4E4E12B}?\Device\TCPIP6TUNNEL_{5B729DE4-EBFF-4188-8F2C-EFFA1B710AB2}?\Device\TCPIP6TUNNEL_{6DBA3FC3-B04D-4131-A77D-3B88E07B85DA}?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0015007f6c3b
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0cb38d054a8
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{5B729DE4-EBFF-4188-8F2C-EFFA1B710AB2}@InterfaceName isatap.{335E881E-9033-47B8-B300-CF5EBBD7D085}
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{5B729DE4-EBFF-4188-8F2C-EFFA1B710AB2}@ReusableType 0
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0015007f6c3b (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0cb38d054a8 (not active ControlSet)
---- EOF - GMER 2.1 ---- Ich hoffe, jetzt ist´s OK...
Vielen Dank! |