Minimumm | 17.09.2013 14:39 | Hallo schrauber,
erst einmal großes Danke! Hier sind die Ergebnisse (FRST 64-Bit)
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-09-2013 03
Ran by PC1 (administrator) on PC1-PC on 17-09-2013 15:28:47
Running from C:\Users\PC1\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(The Eraser Project) C:\Program Files\Eraser\Eraser.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Alcor Micro Corp.) C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
() C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
() C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-23] (Realtek Semiconductor)
HKLM\...\Run: [RunDLLEntry_THXCfg] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
HKLM\...\Run: [RunDLLEntry_EptMon] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\EptMon64.dll,RunDLLEntry EptMon64
HKLM\...\Run: [DellStage] - C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj [207845 2011-04-29] ()
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [403656 2012-04-27] (Acronis)
HKLM\...\Run: [Eraser] - C:\PROGRA~1\Eraser\Eraser.exe [980368 2010-11-04] (The Eraser Project)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe [963584 2009-12-01] (Creative Technology Ltd)
HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5993136 2012-04-27] (Acronis)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKLM-x32\...\Run: [ShwiconXP9106] - C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2010-03-10] (Alcor Micro Corp.)
HKLM-x32\...\Run: [LWS] - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.)
HKLM-x32\...\Run: [TrayServer] - C:\Program Files (x86)\MAGIX\Video_deluxe_16_Plus\Trayserver.exe [90112 2008-08-07] (MAGIX AG)
HKLM-x32\...\Run: [AcronisTimounterMonitor] - C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe [1173680 2012-04-27] (Acronis)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/USCON/8
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
SearchScopes: HKLM - DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM-x32 - DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {C57B9FD7-7525-4151-AC6B-6DE5CB74C531} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
SearchScopes: HKCU - {49606DC7-976D-4030-A74E-9FB5C842FA68} URL =
SearchScopes: HKCU - {C57B9FD7-7525-4151-AC6B-6DE5CB74C531} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\PC1\AppData\Roaming\Mozilla\Firefox\Profiles\vicv1ppp.default
FF user.js: detected! => C:\Users\PC1\AppData\Roaming\Mozilla\Firefox\Profiles\vicv1ppp.default\user.js
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @parallelgraphics.com/Cortona - C:\Program Files (x86)\Common Files\ParallelGraphics\Cortona\npCortona.dll (ParallelGraphics)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\PC1\AppData\Roaming\Mozilla\Firefox\Profiles\vicv1ppp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR HKLM-x32\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonChrome.crx
CHR HKLM-x32\...\Chrome\Extension: [icdlfehblmklkikfigmjhbmmpmkmpooj] - C:\Program Files (x86)\Common Files\Spigot\GC\errorassistant_1.1.crx
CHR HKLM-x32\...\Chrome\Extension: [mhkaekfpcppmmioggniknbnbdbcigpkk] - C:\Program Files (x86)\Common Files\Spigot\GC\coupons_2.4.crx
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [137960 2013-08-30] (AVAST Software)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R1 aswFW; C:\Windows\System32\Drivers\aswFW.sys [131232 2013-08-30] (AVAST Software)
R0 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12368 2011-09-06] (ALWIL Software)
R0 aswNdis2; C:\Windows\System32\Drivers\aswNdis2.sys [270824 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [303616 2012-08-04] ()
S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [35328 2012-08-04] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-17 15:28 - 2013-09-17 15:28 - 00000000 ____D C:\FRST
2013-09-17 15:27 - 2013-09-17 15:27 - 01950524 _____ (Farbar) C:\Users\PC1\Downloads\FRST64.exe
2013-09-17 15:26 - 2013-09-17 15:26 - 01083437 _____ (Farbar) C:\Users\PC1\Downloads\FRST.exe
2013-09-17 09:16 - 2013-09-17 09:16 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\PC1\Downloads\tdsskiller.exe
2013-09-17 09:15 - 2013-09-17 09:15 - 04745728 _____ (AVAST Software) C:\Users\PC1\Downloads\aswMBR.exe
2013-09-16 22:57 - 2013-09-16 22:57 - 16901198 _____ C:\Users\PC1\Documents\A fly on the wall in Cupertino - Microsoft produced then Microsoft removed..mp4
2013-09-16 13:22 - 2013-09-17 15:09 - 00000392 _____ C:\Windows\setupact.log
2013-09-16 13:22 - 2013-09-16 13:22 - 00000000 _____ C:\Windows\setuperr.log
2013-09-15 22:16 - 2013-09-15 22:16 - 01095080 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-15 22:16 - 2013-09-15 22:16 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-15 22:16 - 2013-09-15 22:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-15 22:16 - 2013-09-15 22:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-15 22:16 - 2013-09-15 22:16 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-09-15 22:16 - 2013-09-15 22:16 - 00000000 ____D C:\Program Files\Java
2013-09-15 21:57 - 2013-09-15 21:57 - 00002043 _____ C:\Users\PC1\Desktop\JDownloader.lnk
2013-09-12 18:55 - 2013-09-17 06:27 - 00000000 ____D C:\Users\PC1\Documents\ZL Ü YT09
2013-09-12 10:55 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-12 10:55 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-12 10:55 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-12 10:55 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-12 10:55 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-12 10:55 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-12 10:55 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-12 10:55 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-12 10:55 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-12 10:55 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-12 10:55 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-12 10:55 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-12 10:55 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-12 10:55 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-12 10:55 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-12 10:55 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-12 10:55 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-12 10:55 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-12 10:55 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-12 10:55 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-12 10:55 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-12 10:55 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-12 10:55 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-12 10:55 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-12 10:55 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-12 10:55 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-12 10:55 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-11 11:45 - 2013-09-11 11:45 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf
2013-09-11 11:42 - 2013-09-11 11:42 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01009.Wdf
2013-09-11 11:40 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2013-09-11 11:40 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-09-10 13:46 - 2013-09-10 13:46 - 00000000 ____D C:\Users\PC1\AppData\Roaming\EleFun Games
2013-09-10 13:42 - 2013-09-10 13:42 - 00000000 ____D C:\ProgramData\Big Fish
2013-09-10 13:41 - 2013-09-10 22:58 - 00000000 ____D C:\BigFishCache
2013-09-10 13:41 - 2013-09-10 13:42 - 00000000 ____D C:\Users\PC1\AppData\Local\Big Fish
2013-09-09 13:44 - 2013-09-17 06:16 - 00000000 ____D C:\Users\PC1\Documents\ZL Ü Dokum
2013-09-09 11:52 - 2013-09-09 11:52 - 00000000 ____D C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Becker
2013-09-09 11:52 - 2013-09-09 11:52 - 00000000 ____D C:\Users\PC1\AppData\Roaming\becker
2013-09-09 11:52 - 2013-09-09 11:52 - 00000000 ____D C:\Program Files (x86)\Becker
2013-09-05 18:43 - 2013-09-05 18:43 - 00005873 _____ C:\Users\PC1\AppData\Local\recently-used.xbel
2013-09-05 12:07 - 2013-09-05 12:07 - 00000000 ____D C:\Users\PC1\AppData\Local\gtk-2.0
2013-09-04 12:06 - 2013-09-04 12:06 - 00000000 ____D C:\Users\PC1\AppData\Local\webkit
2013-09-03 12:14 - 2013-09-05 18:44 - 00000000 ____D C:\Users\PC1\.gimp-2.8
2013-09-03 12:14 - 2013-09-03 12:14 - 00000000 ____D C:\Users\PC1\AppData\Local\gegl-0.2
2013-09-03 12:13 - 2013-09-03 12:14 - 00000000 ____D C:\Program Files\GIMP 2
2013-08-27 07:53 - 2013-08-27 07:53 - 27786528 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 21106464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 15149048 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 13419112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 12431872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 11248416 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-08-27 07:53 - 2013-08-27 07:53 - 09281544 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 07719528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 07642344 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 06324896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 02958112 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 02780960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 02598368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 02362656 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 02002720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432078.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432078.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00928744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00620832 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00570656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00548128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00467744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00266448 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00218592 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00214960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00181488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-08-22 16:46 - 2013-08-22 16:46 - 00001483 _____ C:\Users\Public\Desktop\Free MP4 Video Converter.lnk
2013-08-22 16:46 - 2013-08-22 16:46 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-08-22 08:08 - 2009-06-10 22:44 - 00159598 _____ C:\Users\PC1\Documents\Memo.jtp
2013-08-22 08:08 - 2009-06-10 22:44 - 00123228 _____ C:\Users\PC1\Documents\Graph.jtp
2013-08-22 08:08 - 2009-06-10 22:44 - 00087898 _____ C:\Users\PC1\Documents\Shorthand.jtp
2013-08-22 08:08 - 2009-06-10 22:44 - 00043354 _____ C:\Users\PC1\Documents\Seyes.jtp
2013-08-22 08:08 - 2009-06-10 22:44 - 00040792 _____ C:\Users\PC1\Documents\Music.jtp
2013-08-22 08:08 - 2009-06-10 22:44 - 00032602 _____ C:\Users\PC1\Documents\To_Do_List.jtp
2013-08-22 08:08 - 2009-06-10 22:44 - 00019596 _____ C:\Users\PC1\Documents\Genko_2.jtp
2013-08-22 08:08 - 2009-06-10 22:44 - 00013852 _____ C:\Users\PC1\Documents\Genko_1.jtp
2013-08-22 08:08 - 2009-06-10 22:44 - 00011494 _____ C:\Users\PC1\Documents\Dotted_Line.jtp
2013-08-22 08:08 - 2009-06-10 22:44 - 00010076 _____ C:\Users\PC1\Documents\Month_Calendar.jtp
2013-08-22 08:08 - 2009-06-10 22:44 - 00005470 _____ C:\Users\PC1\Documents\blank.jtp
2013-08-20 15:10 - 2013-08-20 15:11 - 00000000 ____D C:\Program Files (x86)\PC 73 Virtual Piano Keyboard
2013-08-20 15:10 - 2013-08-20 15:10 - 00001253 _____ C:\Users\UpdatusUser\Desktop\PC 73 Virtual Piano Keyboard.lnk
2013-08-20 15:10 - 2013-08-20 15:10 - 00000000 ____D C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC 73 Virtual Piano Keyboard
2013-08-20 13:56 - 2013-09-08 12:27 - 00000000 ____D C:\Program Files (x86)\ChordPulse
2013-08-20 13:56 - 2013-08-20 13:56 - 00000033 _____ C:\Windows\SysWOW64\mnprxpd2f.bin
2013-08-20 13:45 - 2013-08-20 13:45 - 00000000 ____D C:\Users\PC1\AppData\Roaming\MusE
2013-08-20 13:45 - 2013-08-20 13:45 - 00000000 ____D C:\Users\PC1\AppData\Local\MusE
2013-08-20 13:45 - 2013-08-20 13:45 - 00000000 ____D C:\Program Files (x86)\MuseScore
==================== One Month Modified Files and Folders =======
2013-09-17 15:28 - 2013-09-17 15:28 - 00000000 ____D C:\FRST
2013-09-17 15:27 - 2013-09-17 15:27 - 01950524 _____ (Farbar) C:\Users\PC1\Downloads\FRST64.exe
2013-09-17 15:26 - 2013-09-17 15:26 - 01083437 _____ (Farbar) C:\Users\PC1\Downloads\FRST.exe
2013-09-17 15:17 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-17 15:17 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-17 15:12 - 2013-07-16 20:59 - 01579736 _____ C:\Windows\WindowsUpdate.log
2013-09-17 15:10 - 2012-08-15 11:01 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-17 15:10 - 2012-07-10 16:18 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-09-17 15:09 - 2013-09-16 13:22 - 00000392 _____ C:\Windows\setupact.log
2013-09-17 15:09 - 2011-08-11 02:01 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-17 15:09 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-17 13:37 - 2012-08-15 11:01 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-17 12:59 - 2012-04-17 11:50 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-17 09:57 - 2011-09-06 23:15 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-09-17 09:45 - 2011-11-17 16:47 - 00000000 ____D C:\Users\PC1\Documents\My PSP8 Files
2013-09-17 09:45 - 2010-11-21 08:50 - 00707446 _____ C:\Windows\system32\perfh007.dat
2013-09-17 09:45 - 2010-11-21 08:50 - 00153038 _____ C:\Windows\system32\perfc007.dat
2013-09-17 09:45 - 2009-07-14 07:13 - 01642606 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-17 09:16 - 2013-09-17 09:16 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\PC1\Downloads\tdsskiller.exe
2013-09-17 09:15 - 2013-09-17 09:15 - 04745728 _____ (AVAST Software) C:\Users\PC1\Downloads\aswMBR.exe
2013-09-17 09:09 - 2011-09-09 15:36 - 00000000 ____D C:\Users\PC1\Documents\MAGIX_Video_deluxe_16_Plus
2013-09-17 09:07 - 2012-11-04 15:49 - 00000000 ____D C:\Program Files (x86)\Steam
2013-09-17 06:27 - 2013-09-12 18:55 - 00000000 ____D C:\Users\PC1\Documents\ZL Ü YT09
2013-09-17 06:16 - 2013-09-09 13:44 - 00000000 ____D C:\Users\PC1\Documents\ZL Ü Dokum
2013-09-16 22:57 - 2013-09-16 22:57 - 16901198 _____ C:\Users\PC1\Documents\A fly on the wall in Cupertino - Microsoft produced then Microsoft removed..mp4
2013-09-16 17:01 - 2011-08-23 01:31 - 00000422 _____ C:\Windows\Tasks\SystemToolsDailyTest.job
2013-09-16 17:00 - 2011-10-14 17:00 - 00003488 _____ C:\Windows\System32\Tasks\PCDEventLauncher
2013-09-16 17:00 - 2011-08-23 01:31 - 00003440 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
2013-09-16 13:22 - 2013-09-16 13:22 - 00000000 _____ C:\Windows\setuperr.log
2013-09-15 22:16 - 2013-09-15 22:16 - 01095080 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-15 22:16 - 2013-09-15 22:16 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-15 22:16 - 2013-09-15 22:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-15 22:16 - 2013-09-15 22:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-15 22:16 - 2013-09-15 22:16 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-09-15 22:16 - 2013-09-15 22:16 - 00000000 ____D C:\Program Files\Java
2013-09-15 22:16 - 2011-08-11 03:14 - 00973736 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-09-15 22:01 - 2012-06-30 15:43 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-09-15 21:57 - 2013-09-15 21:57 - 00002043 _____ C:\Users\PC1\Desktop\JDownloader.lnk
2013-09-15 20:14 - 2012-11-10 11:27 - 00000000 ____D C:\Users\PC1\Documents\MAGIX_MusicEditor
2013-09-15 20:03 - 2011-09-07 21:41 - 00000000 ___RD C:\Users\PC1\Desktop\Video
2013-09-15 16:20 - 2011-09-09 13:26 - 00000000 ____D C:\Users\PC1\AppData\Local\Paint.NET
2013-09-14 23:37 - 2011-09-07 21:22 - 00000000 ___RD C:\Users\PC1\Desktop\Secret Service
2013-09-14 11:47 - 2012-02-05 16:31 - 00000000 ____D C:\Users\PC1\AppData\Roaming\dvdcss
2013-09-13 23:09 - 2012-07-03 22:31 - 00000000 ____D C:\ProgramData\YTD Video Downloader
2013-09-13 10:59 - 2012-04-17 11:50 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-13 10:59 - 2012-04-17 11:50 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-13 10:59 - 2011-08-11 03:08 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-12 15:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-12 13:03 - 2011-08-11 03:33 - 00000000 ____D C:\ProgramData\Sonic
2013-09-12 13:02 - 2011-08-23 01:31 - 00000000 ___RD C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-12 13:02 - 2011-08-23 01:31 - 00000000 ___RD C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-12 13:01 - 2009-07-14 06:45 - 00536848 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-12 11:14 - 2013-07-24 20:43 - 00000000 ____D C:\Windows\system32\MRT
2013-09-12 11:12 - 2011-09-23 17:49 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-12 11:12 - 2011-08-31 15:25 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-11 11:45 - 2013-09-11 11:45 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf
2013-09-11 11:45 - 2011-09-07 22:19 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-09-11 11:42 - 2013-09-11 11:42 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01009.Wdf
2013-09-10 22:58 - 2013-09-10 13:41 - 00000000 ____D C:\BigFishCache
2013-09-10 13:46 - 2013-09-10 13:46 - 00000000 ____D C:\Users\PC1\AppData\Roaming\EleFun Games
2013-09-10 13:42 - 2013-09-10 13:42 - 00000000 ____D C:\ProgramData\Big Fish
2013-09-10 13:42 - 2013-09-10 13:41 - 00000000 ____D C:\Users\PC1\AppData\Local\Big Fish
2013-09-09 11:52 - 2013-09-09 11:52 - 00000000 ____D C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Becker
2013-09-09 11:52 - 2013-09-09 11:52 - 00000000 ____D C:\Users\PC1\AppData\Roaming\becker
2013-09-09 11:52 - 2013-09-09 11:52 - 00000000 ____D C:\Program Files (x86)\Becker
2013-09-08 12:27 - 2013-08-20 13:56 - 00000000 ____D C:\Program Files (x86)\ChordPulse
2013-09-08 10:35 - 2011-09-09 13:16 - 00000000 ___RD C:\Users\PC1\Desktop\Grafik
2013-09-07 20:12 - 2012-07-03 22:31 - 00001052 _____ C:\Users\Public\Desktop\YTD Video Downloader.lnk
2013-09-05 18:44 - 2013-09-03 12:14 - 00000000 ____D C:\Users\PC1\.gimp-2.8
2013-09-05 18:43 - 2013-09-05 18:43 - 00005873 _____ C:\Users\PC1\AppData\Local\recently-used.xbel
2013-09-05 12:07 - 2013-09-05 12:07 - 00000000 ____D C:\Users\PC1\AppData\Local\gtk-2.0
2013-09-04 12:06 - 2013-09-04 12:06 - 00000000 ____D C:\Users\PC1\AppData\Local\webkit
2013-09-03 12:15 - 2011-08-23 01:28 - 00000000 ____D C:\Users\PC1
2013-09-03 12:14 - 2013-09-03 12:14 - 00000000 ____D C:\Users\PC1\AppData\Local\gegl-0.2
2013-09-03 12:14 - 2013-09-03 12:13 - 00000000 ____D C:\Program Files\GIMP 2
2013-08-30 09:48 - 2013-03-20 06:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-08-30 09:48 - 2013-03-20 06:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-08-30 09:48 - 2012-02-27 01:09 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-08-30 09:48 - 2012-02-27 01:09 - 00022600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2013-08-30 09:48 - 2011-10-10 09:20 - 00270824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdis2.sys
2013-08-30 09:48 - 2011-10-10 09:20 - 00131232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFW.sys
2013-08-30 09:48 - 2011-09-06 23:15 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-08-30 09:48 - 2011-09-06 23:15 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-08-30 09:48 - 2011-09-06 23:15 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-08-30 09:48 - 2011-09-06 23:15 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-08-30 09:48 - 2011-09-06 23:15 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-08-30 09:47 - 2011-09-06 23:15 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-08-30 09:47 - 2011-09-06 23:14 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-08-27 07:53 - 2013-08-27 07:53 - 27786528 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 21106464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 15149048 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 13419112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 12431872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 11248416 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-08-27 07:53 - 2013-08-27 07:53 - 09281544 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 07719528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 07642344 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 06324896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 02958112 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 02780960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 02598368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 02362656 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 02002720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432078.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432078.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00928744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00620832 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00570656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00548128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00467744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00266448 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00218592 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00214960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-08-27 07:53 - 2013-08-27 07:53 - 00181488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-08-27 07:53 - 2013-02-26 00:32 - 15928264 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-08-27 07:53 - 2013-02-26 00:32 - 02937256 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-08-27 07:53 - 2013-02-26 00:32 - 01061632 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-08-27 07:53 - 2011-08-11 10:46 - 00021638 _____ C:\Windows\system32\nvinfo.pb
2013-08-27 06:39 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-22 17:03 - 2011-09-07 22:05 - 00000000 ____D C:\Users\PC1\AppData\Roaming\vlc
2013-08-22 16:46 - 2013-08-22 16:46 - 00001483 _____ C:\Users\Public\Desktop\Free MP4 Video Converter.lnk
2013-08-22 16:46 - 2013-08-22 16:46 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-08-22 16:46 - 2011-09-09 13:37 - 00000000 ____D C:\Users\PC1\AppData\Roaming\DVDVideoSoft
2013-08-22 12:48 - 2012-11-10 11:27 - 00000000 ____D C:\Users\PC1\Documents\MAGIX
2013-08-20 15:11 - 2013-08-20 15:10 - 00000000 ____D C:\Program Files (x86)\PC 73 Virtual Piano Keyboard
2013-08-20 15:10 - 2013-08-20 15:10 - 00001253 _____ C:\Users\UpdatusUser\Desktop\PC 73 Virtual Piano Keyboard.lnk
2013-08-20 15:10 - 2013-08-20 15:10 - 00000000 ____D C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC 73 Virtual Piano Keyboard
2013-08-20 13:56 - 2013-08-20 13:56 - 00000033 _____ C:\Windows\SysWOW64\mnprxpd2f.bin
2013-08-20 13:45 - 2013-08-20 13:45 - 00000000 ____D C:\Users\PC1\AppData\Roaming\MusE
2013-08-20 13:45 - 2013-08-20 13:45 - 00000000 ____D C:\Users\PC1\AppData\Local\MusE
2013-08-20 13:45 - 2013-08-20 13:45 - 00000000 ____D C:\Program Files (x86)\MuseScore
2013-08-20 08:35 - 2011-08-23 01:31 - 00000564 _____ C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2013-08-20 06:41 - 2011-08-23 01:31 - 00004260 _____ C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
2013-08-18 13:22 - 2011-09-09 15:35 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-08-18 13:21 - 2012-11-10 11:27 - 00000000 ____D C:\Users\Public\Documents\MAGIX
2013-08-18 05:38 - 2012-04-26 09:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-12 14:57
==================== End Of Log ============================ --- --- ---
--- --- ---
und die Addition.txt
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-09-2013 03
Ran by PC1 at 2013-09-17 15:29:09
Running from C:\Users\PC1\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Acronis*True*Image*Home 2012 (x32 Version: 15.0.7119)
Adobe AIR (x32 Version: 3.6.0.6090)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.174)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168)
Ashampoo Burning Studio 2012 v10.0.15 (x32 Version: 10.0.15)
Audacity 1.2.6 (x32)
Audiograbber 1.83 SE (x32 Version: 1.83 SE )
Audiograbber MP3-Plugin (x32 Version: 1.0)
avast! Internet Security (x32 Version: 8.0.1497.0)
Bandicam (x32)
Bandisoft MPEG-1 Decoder (x32)
CameraHelperMsi (x32 Version: 13.31.1038.0)
Canon CanoScan Toolbox 4.1 (x32)
Canon iP3600 series Benutzerregistrierung (x32)
Canon iP3600 series Printer Driver
CCleaner (Version: 4.02)
CDisplayEx 1.8 (x32)
Content Manager 2 (x32 Version: 3.10.0.52790)
Cortona3D Viewer (x32 Version: 6.0.180)
Data Lifeguard Diagnostic for Windows 1.24 (x32)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
Dell Edoc Viewer (Version: 1.0.0)
Dell Getting Started Guide (x32 Version: 1.00.0000)
Dell MusicStage (x32 Version: 1.5.201.0)
Dell PhotoStage (x32 Version: 1.5.0.65)
Dell Stage (x32 Version: 1.5.201.0)
Dell Support Center (Version: 3.1.5803.11)
Dell VideoStage (x32 Version: 1.2.0.1712)
DirectX 9 Runtime (x32 Version: 1.00.0000)
Dishonored (x32 Version: 1.0)
Easy Poster Printer (x32 Version: 2.0.3)
Eraser 6.0.8.2273 (Version: 6.0.2273)
erLT (x32 Version: 1.20.138.34)
Firebird SQL Server - MAGIX Edition (x32 Version: 2.1.32.0)
Fraps (remove only) (x32)
Free MP4 Video Converter version 5.0.28.812 (x32 Version: 5.0.28.812)
GIMP 2.8.6 (Version: 2.8.6)
Google Earth Plug-in (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.153)
Howie's Quick Screen Capture 1.1.1 (x32)
Intel(R) Rapid Storage Technology (x32 Version: 10.0.0.1046)
IsoBuster 3.0 (x32 Version: 3.0)
iWisoft Free Video Converter 1.2 (x32 Version: 1.2)
Jasc Paint Shop Pro 8 (x32 Version: 8.10.0000)
Java 7 Update 25 (x32 Version: 7.0.250)
Java 7 Update 40 (64-bit) (Version: 7.0.400)
Java Auto Updater (x32 Version: 2.1.9.5)
JavaFX 2.1.1 (x32 Version: 2.1.1)
JDownloader 0.9 (x32 Version: 0.9)
LinuxLive USB Creator (x32 Version: 2.8)
Logitech Webcam Software (x32 Version: 2.0)
LWS Facebook (x32 Version: 13.31.1038.0)
LWS Gallery (x32 Version: 13.31.1038.0)
LWS Help_main (x32 Version: 13.31.1044.0)
LWS Launcher (x32 Version: 13.31.1038.0)
LWS Motion Detection (x32 Version: 13.30.1395.0)
LWS Pictures And Video (x32 Version: 13.31.1038.0)
LWS Twitter (x32 Version: 13.30.1346.0)
LWS Video Mask Maker (x32 Version: 13.30.1379.0)
LWS VideoEffects (Version: 13.30.1379.0)
LWS Webcam Software (x32 Version: 13.31.1038.0)
LWS WLM Plugin (x32 Version: 1.30.1201.0)
LWS YouTube Plugin (x32 Version: 13.31.1038.0)
MAGIX 3D Maker (embeded) (x32 Version: 6.0.0.8)
MAGIX Content und Soundpools (x32 Version: 1.0.0.0)
MAGIX Foto Manager 10 Deluxe Update (Version: 9.0.2.256)
MAGIX Foto Manager MX Deluxe (Version: 9.0.1.250)
MAGIX Foto Manager MX Deluxe (x32 Version: 9.0.1.250)
MAGIX Goya burnR (MSI) (Version: 4.3.2.0)
MAGIX Goya burnR (MSI) (x32 Version: 4.3.2.0)
MAGIX Music Maker Rock Edition 5 Trial Soundpools (Version: 1.0.0.0)
MAGIX Music Maker Soundtrack Edition Trial Soundpools (Version: 1.0.0.0)
MAGIX Screenshare (x32 Version: 4.3.6.1987)
MAGIX Slideshow Maker 2 (Version: 2.0.1.9)
MAGIX Slideshow Maker 2 (x32 Version: 2.0.1.9)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6)
MAGIX Speed burnR (x32 Version: 6.0.1.4)
MAGIX Video deluxe 16 Plus 9.0.0.54 (D) (x32 Version: 9.0.0.54)
MAGIX Video deluxe 2013 Plus (Version: 12.0.0.30)
MAGIX Video deluxe 2013 Plus (x32 Version: 12.0.0.30)
MAGIX Video deluxe Plus 2013 Update (Version: 12.0.1.4)
MAGIX Video deluxe Plus 2013 Update (Version: 12.0.3.4)
MAGIX Xtreme Foto Designer 6 (x32 Version: 6.0.29.0)
Manual CanoScan 5000,5000F,8000F (x32)
MediaInfo 0.7.61 (Version: 0.7.61)
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322)
Microsoft .NET Framework 1.1 (x32)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Home and Student 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1)
Mozilla Maintenance Service (x32 Version: 23.0.1)
Mozilla Thunderbird 17.0.8 (x86 de) (x32 Version: 17.0.8)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
MSynth 1.5 alpha (x32 Version: 1.5.0)
Multimedia Card Reader (x32 Version: 1.7.915.93)
MuseScore 1.3 (x32 Version: 1.3.0)
Naviextras Toolbox Prerequesities (x32 Version: 1.0.0)
NVIDIA 3D Vision Controller Driver (x32 Version: 280.19)
NVIDIA 3D Vision Controller-Treiber 306.97 (Version: 306.97)
NVIDIA 3D Vision Treiber 320.78 (Version: 320.78)
NVIDIA Grafiktreiber 320.78 (Version: 320.78)
NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0)
NVIDIA Install Application (Version: 2.1002.124.810)
NVIDIA PhysX (x32 Version: 9.12.0604)
NVIDIA PhysX-Systemsoftware 9.12.0604 (Version: 9.12.0604)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2078)
NVIDIA Systemsteuerung 320.78 (Version: 320.78)
NVIDIA Update 1.14.17 (Version: 1.14.17)
NVIDIA Update Components (Version: 1.14.17)
OpenAL (x32)
Paint.NET v3.5.8 (Version: 3.58.0)
PC 73 Virtual Piano Keyboard (x32)
PDF-Viewer (Version: 2.5.198.0)
Pepakura Viewer 3 (x32)
PhotoShowExpress (x32 Version: 2.0.063)
RBVirtualFolder64Inst (Version: 1.00.0000)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6141)
Roxio Activation Module (x32 Version: 1.0)
Roxio BackOnTrack (x32 Version: 1.3.3)
Roxio Burn (x32 Version: 1.8)
Roxio Creator Starter (x32 Version: 1.0.439)
Roxio Creator Starter (x32 Version: 12.1.77.0)
Roxio Creator Starter (x32 Version: 5.0.0)
Roxio Express Labeler 3 (x32 Version: 3.2.2)
Roxio File Backup (Version: 1.3.2)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32)
Skype™ 5.10 (x32 Version: 5.10.116)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0)
Steam (x32 Version: 1.0.0.0)
SUPER © v2012.build.54 (Nov 18, 2012) Version v2012.build.54 (x32 Version: v2012.build.54)
SWF Opener (x32 Version: 1.3)
SWFPlayer 2.6.2.0 (x32 Version: 2.6.2.0)
Text-To-Speech-Runtime (x32 Version: 1.0.0.0)
THX TruStudio PC (x32 Version: 1.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2494150) (x32)
Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32)
VLC media player 1.1.11 (x32 Version: 1.1.11)
xat.com Image Optimizer (x32 Version: )
XMedia Recode Version 3.1.3.4 (x32 Version: 3.1.3.4)
Yahoo! Detect (x32)
YTD Video Downloader 4.5.1 (x32 Version: 4.5.1)
==================== Restore Points =========================
10-09-2013 09:06:38 Geplanter Prüfpunkt
11-09-2013 09:42:22 Windows Update
12-09-2013 09:07:59 Windows Update
15-09-2013 20:16:15 Installed Java 7 Update 40 (64-bit)
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started
Task: {10A51BA6-7F88-42B7-BDA7-A985227AC5E3} - System32\Tasks\PCDEventLauncher => C:\Program Files\Dell Support Center\sessionchecker.exe [2011-03-22] (PC-Doctor, Inc.)
Task: {183173FC-0A7F-4C13-A0E3-4DE5E47EE767} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {19B46A7C-1F58-457B-A968-C9F18F4EAB79} - System32\Tasks\SystemToolsDailyTest => C:\Program Files\Dell Support Center\pcdrcui.exe [2011-03-22] (PC-Doctor, Inc.)
Task: {2A374E77-803E-4C27-A7DD-AF3C77A3348D} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-21] (Microsoft Corporation)
Task: {32CF91D9-2F62-48EC-B35B-7B0E8D6CD0CB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-08-15] (Google Inc.)
Task: {49528EC8-D6AC-4BBA-A7FA-A3E61643F651} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software)
Task: {4D19430A-2062-4C00-9A1D-6AB0CBB2F464} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\System32\sdengin2.dll [2010-11-21] (Microsoft Corporation)
Task: {4FE368D6-B36A-4C67-8C8B-3893FED019D6} - System32\Tasks\{D46930EA-B5FC-4EC0-A6E9-77D523E9E051} => C:\Users\PC1\Downloads\IsoBuster_0.99.9\IsoBuster 0.99.9\isobuster.exe
Task: {59860940-B232-43F2-BDAD-D2AF7F297323} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell Support Center\uaclauncher.exe [2011-03-22] (PC-Doctor, Inc.)
Task: {60942460-DDAE-4D9C-B9AF-597DE0582249} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-13] (Adobe Systems Incorporated)
Task: {A0253708-E9A6-43C5-8DE1-D1AB6060F8EA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-08-15] (Google Inc.)
Task: {A95B63D3-89B8-462A-AB11-3AED46D91306} - System32\Tasks\{9A11D124-D80E-4BE8-8E72-CB4620D2E146} => C:\Users\PC1\Downloads\IsoBuster_0.99.9\IsoBuster 0.99.9\isobuster.exe
Task: {D0E99CA9-DEE6-43A2-8C81-8679152C8F15} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation)
Task: {DEEE1362-EF96-43C4-AA74-044688EBA0D6} - System32\Tasks\{63AC6234-AA0D-45A0-AB6D-0F86ED4F731E} => C:\Users\PC1\Downloads\IsoBuster_0.99.9\IsoBuster 0.99.9\isobuster.exe
Task: {EB61A0F8-00EC-4DDE-9077-A652044D2D00} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd)
Task: {FA8947A2-CDF9-4B33-A170-B629C6724324} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job => C:\Program Files\Dell Support Center\uaclauncher.exe
Task: C:\Windows\Tasks\SystemToolsDailyTest.job => C:\Program Files\Dell Support Center\pcdrcui.exe
==================== Loaded Modules (whitelisted) =============
2013-02-26 00:32 - 2013-08-27 07:53 - 15928264 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2010-11-10 23:54 - 2010-11-10 23:54 - 00177136 _____ (TODO: <Company name>) C:\Program Files\Roxio\Roxio Burn\RB_ContextMenu64.dll
2010-11-04 23:07 - 2010-11-04 23:07 - 00252816 _____ (The Eraser Project) C:\Program Files\Eraser\Eraser.Shell.dll
2013-03-03 15:32 - 2013-03-03 15:32 - 00178800 _____ (Sony DADC Austria AG.) c:\windows\SysWOW64\cmdlineext_x64.dll
2011-08-11 03:20 - 2009-10-15 14:38 - 00017920 ____N (Creative Technology Ltd.) C:\Windows\system32\THXCfg64.dll
2011-08-11 03:20 - 2009-10-15 14:32 - 00021504 ____N (Creative Technology Ltd.) C:\Windows\system32\EptMon64.dll
2010-11-04 23:07 - 2010-11-04 23:07 - 00109968 _____ (The Eraser Project) C:\Program Files\Eraser\Eraser.Manager.dll
2010-11-04 23:07 - 2010-11-04 23:07 - 00059792 _____ (The Eraser Project) C:\Program Files\Eraser\Eraser.Util.dll
2010-11-04 23:07 - 2010-11-04 23:07 - 00099728 _____ (The Eraser Project) C:\Program Files\Eraser\Plugins\Eraser.DefaultPlugins.dll
2010-11-04 23:07 - 2010-11-04 23:07 - 00025488 _____ (The Eraser Project) C:\Program Files\Eraser\en\Eraser.resources.dll
2010-11-04 23:07 - 2010-11-04 23:07 - 00014736 _____ (DELMATIC) C:\Program Files\Eraser\BevelLine.dll
2010-11-04 23:07 - 2010-11-04 23:07 - 00017808 _____ (The Eraser Project) C:\Program Files\Eraser\Plugins\en\Eraser.DefaultPlugins.resources.dll
2010-11-04 23:07 - 2010-11-04 23:07 - 00030608 _____ (The Eraser Project) C:\Program Files\Eraser\en\Eraser.Manager.resources.dll
2012-02-08 18:18 - 2008-10-09 07:00 - 02793984 _____ (CANON INC.) C:\Windows\system32\spool\DRIVERS\x64\3\CNMUI99.DLL
2012-02-08 18:18 - 2008-10-09 07:00 - 00636928 _____ (CANON INC.) C:\Windows\system32\spool\DRIVERS\x64\3\CNMDR99.DLL
2012-02-08 18:18 - 2008-10-09 07:00 - 00097280 _____ (CANON INC.) C:\Windows\system32\spool\DRIVERS\x64\3\CNMCP99.DLL
2013-08-15 15:56 - 2013-08-15 15:56 - 00475136 _____ (Intel Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\ebdb3050959d9be47d33d2c77d6cc291\IAStorUtil.ni.dll
2013-07-10 08:04 - 2013-07-10 08:04 - 00014336 _____ (Intel Corp.) C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\34002b75cd0faab68bf8079299c1aa46\IAStorCommon.ni.dll
2012-04-27 22:21 - 2012-04-27 22:21 - 13005104 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\Common\ti_managers.dll
2011-08-12 13:18 - 2011-08-12 13:18 - 02145304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll
2011-08-12 13:18 - 2011-08-12 13:18 - 07956504 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll
2011-08-12 13:18 - 2011-08-12 13:18 - 00342552 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll
2011-08-12 13:18 - 2011-08-12 13:18 - 00029208 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll
2011-08-12 13:18 - 2011-08-12 13:18 - 00128536 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll
2011-11-11 15:09 - 2011-11-11 15:09 - 00336408 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
2012-04-27 19:09 - 2012-04-27 19:09 - 00018784 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers_proxy_stub.dll
==================== Alternate Data Streams (whitelisted) ==========
AlternateDataStreams: C:\ProgramData:gs5sys
AlternateDataStreams: C:\Users\All Users:gs5sys
AlternateDataStreams: C:\Users\PC1:gs5sys
AlternateDataStreams: C:\ProgramData\Anwendungsdaten:gs5sys
AlternateDataStreams: C:\ProgramData\Application Data:gs5sys
AlternateDataStreams: C:\ProgramData\Temp:1FA4C06F
AlternateDataStreams: C:\ProgramData\Temp:2CB9631F
AlternateDataStreams: C:\ProgramData\Temp:A02025CE
AlternateDataStreams: C:\ProgramData\Templates:gs5sys
AlternateDataStreams: C:\ProgramData\Vorlagen:gs5sys
AlternateDataStreams: C:\Users\PC1\Anwendungsdaten:gs5sys
AlternateDataStreams: C:\Users\PC1\Cookies:gs5sys
AlternateDataStreams: C:\Users\PC1\Lokale Einstellungen:gs5sys
AlternateDataStreams: C:\Users\PC1\Vorlagen:gs5sys
AlternateDataStreams: C:\Users\PC1\AppData\Local:gs5sys
AlternateDataStreams: C:\Users\PC1\AppData\Roaming:gs5sys
AlternateDataStreams: C:\Users\PC1\AppData\Local\Anwendungsdaten:gs5sys
AlternateDataStreams: C:\Users\PC1\AppData\Local\Verlauf:gs5sys
AlternateDataStreams: C:\Users\PC1\Documents\desktop.ini:gs5sys
AlternateDataStreams: C:\Users\Public\Pictures:gs5sys
AlternateDataStreams: C:\Users\Public\Documents\desktop.ini:gs5sys
AlternateDataStreams: C:\Users\Public\Documents\Eigene Bilder:gs5sys
AlternateDataStreams: C:\Users\Public\Documents\My Pictures:gs5sys
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/17/2013 03:10:02 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/17/2013 09:25:54 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: aswMBR.exe, Version: 0.9.9.1771, Zeitstempel: 0x5147644e
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1072
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e3be
ID des fehlerhaften Prozesses: 0x14d8
Startzeit der fehlerhaften Anwendung: 0xaswMBR.exe0
Pfad der fehlerhaften Anwendung: aswMBR.exe1
Pfad des fehlerhaften Moduls: aswMBR.exe2
Berichtskennung: aswMBR.exe3
Error: (09/17/2013 09:21:46 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: aswMBR.exe, Version: 0.9.9.1771, Zeitstempel: 0x5147644e
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1072
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e3be
ID des fehlerhaften Prozesses: 0x15fc
Startzeit der fehlerhaften Anwendung: 0xaswMBR.exe0
Pfad der fehlerhaften Anwendung: aswMBR.exe1
Pfad des fehlerhaften Moduls: aswMBR.exe2
Berichtskennung: aswMBR.exe3
Error: (09/17/2013 09:19:36 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: aswMBR.exe, Version: 0.9.9.1771, Zeitstempel: 0x5147644e
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1072
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e3be
ID des fehlerhaften Prozesses: 0x110c
Startzeit der fehlerhaften Anwendung: 0xaswMBR.exe0
Pfad der fehlerhaften Anwendung: aswMBR.exe1
Pfad des fehlerhaften Moduls: aswMBR.exe2
Berichtskennung: aswMBR.exe3
Error: (09/17/2013 07:52:53 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/17/2013 07:37:52 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1ddfa
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000028cfd2
ID des fehlerhaften Prozesses: 0xfc4
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3
Error: (09/17/2013 07:37:29 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1ddfa
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000028cfd2
ID des fehlerhaften Prozesses: 0x85c
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
Error: (09/17/2013 05:28:58 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/16/2013 11:28:04 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/16/2013 07:36:07 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (09/17/2013 03:09:44 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lirsgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (09/17/2013 03:09:43 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "atksgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (09/17/2013 07:52:42 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lirsgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (09/17/2013 07:52:42 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "atksgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (09/17/2013 05:28:36 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lirsgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (09/17/2013 05:28:35 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "atksgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (09/16/2013 11:27:47 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lirsgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (09/16/2013 11:27:46 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "atksgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (09/16/2013 07:35:53 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lirsgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (09/16/2013 07:35:53 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "atksgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Microsoft Office Sessions:
=========================
Error: (09/17/2013 03:10:02 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/17/2013 09:25:54 AM) (Source: Application Error)(User: )
Description: aswMBR.exe0.9.9.17715147644entdll.dll6.1.7601.1822951fb1072c00000050002e3be14d801ceb376df3d27cbC:\Users\PC1\Downloads\aswMBR.exeC:\Windows\SysWOW64\ntdll.dll62934953-1f6a-11e3-b3d5-782bcbad0310
Error: (09/17/2013 09:21:46 AM) (Source: Application Error)(User: )
Description: aswMBR.exe0.9.9.17715147644entdll.dll6.1.7601.1822951fb1072c00000050002e3be15fc01ceb37651a6920fC:\Users\PC1\Downloads\aswMBR.exeC:\Windows\SysWOW64\ntdll.dllcec469dd-1f69-11e3-b3d5-782bcbad0310
Error: (09/17/2013 09:19:36 AM) (Source: Application Error)(User: )
Description: aswMBR.exe0.9.9.17715147644entdll.dll6.1.7601.1822951fb1072c00000050002e3be110c01ceb375ee198a50C:\Users\PC1\Downloads\aswMBR.exeC:\Windows\SysWOW64\ntdll.dll8172dc4d-1f69-11e3-b3d5-782bcbad0310
Error: (09/17/2013 07:52:53 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/17/2013 07:37:52 AM) (Source: Application Error)(User: )
Description: explorer.exe6.1.7601.175674d672ee4SHELL32.dll6.1.7601.1822251f1ddfac0000005000000000028cfd2fc401ceb368012e6446C:\Windows\explorer.exeC:\Windows\system32\SHELL32.dll4ae277ec-1f5b-11e3-995e-782bcbad0310
Error: (09/17/2013 07:37:29 AM) (Source: Application Error)(User: )
Description: Explorer.EXE6.1.7601.175674d672ee4SHELL32.dll6.1.7601.1822251f1ddfac0000005000000000028cfd285c01ceb355b63b5466C:\Windows\Explorer.EXEC:\Windows\system32\SHELL32.dll3d5e12fa-1f5b-11e3-995e-782bcbad0310
Error: (09/17/2013 05:28:58 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/16/2013 11:28:04 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/16/2013 07:36:07 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity Errors:
===================================
Date: 2013-09-17 15:09:44.440
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\lirsgt.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-09-17 15:09:44.362
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\lirsgt.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-09-17 15:09:43.941
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\atksgt.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-09-17 15:09:43.691
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\atksgt.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-09-17 07:52:42.653
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\lirsgt.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-09-17 07:52:42.591
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\lirsgt.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-09-17 07:52:42.326
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\atksgt.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-09-17 07:52:42.092
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\atksgt.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-09-17 05:28:36.232
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\lirsgt.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-09-17 05:28:36.107
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\lirsgt.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 26%
Total physical RAM: 6126.45 MB
Available physical RAM: 4503.14 MB
Total Pagefile: 15312.63 MB
Available Pagefile: 13623.05 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:709.61 GB) (Free:561.39 GB) NTFS
Drive i: (Volume) (Fixed) (Total:674.37 GB) (Free:592.06 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 1397 GB) (Disk ID: D5C44AF2)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=13 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=710 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=674 GB) - (Type=OF Extended)
==================== End Of Log ============================ --- --- ---
In der zwischenzeit hatte ich heute morgen Avast (Internet Suite) nochmal in höchsten Einstellungen scannen lassen.
Jetzt fand es 10 infizierte Dateien, allein folgendem Ordner:
Windows\Temp\_avast_\unp93755507.tmp
Hoffentlich richtig notiert. War beim nochmaligen Pre-Start-Scan (nach der Suche unter Windows). Alle gefundenen Dateien hatten Namen wie unp93xxxxxx.tmp
Avast meldete sie als Trojaner
Java: Malware-gen
Java: Downloader-FS
Die Dateien hatte ich löschen lassen. Falls es geklappt hat…
Die FRST-Ergebnisse sind also der Zustand nach dem Löschversuch von vorhin.
Schon mal danke fürs Durchsehen der Logs! Für mich ist das wie Chinesisch... |