Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 27-09-2013 02
Ran by ITSC-admin at 2013-09-30 22:59:53 Run:5
Running from C:\Users\ITSC-admin\Downloads
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {0BD0D271-429F-4F3A-93D8-1B67A6B83D91} URL =
SearchScopes: HKCU - {0BD0D271-429F-4F3A-93D8-1B67A6B83D91} URL =
BHO-x32: No Name - {29AAADC9-DA30-4264-BCC4-D447F7146FC1} - No File
*****************
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0BD0D271-429F-4F3A-93D8-1B67A6B83D91} => Key deleted successfully.
HKCR\CLSID\{0BD0D271-429F-4F3A-93D8-1B67A6B83D91} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{29AAADC9-DA30-4264-BCC4-D447F7146FC1} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{29AAADC9-DA30-4264-BCC4-D447F7146FC1} => Key not found.
==== End of Fixlog ====
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-09-2013 02
Ran by ITSC-admin (administrator) on WIWI-PC on 30-09-2013 23:01:15
Running from C:\Users\ITSC-admin\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Aladdin Knowledge Systems, Ltd.) C:\Program Files\Aladdin\eToken\PKIClient\x64\eTSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Windows\system32\IProsetMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe
() c:\Windows\SysWOW64\srvany.exe
(O2Micro.) c:\Windows\sysWOW64\SDIOAssist.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Dell Inc.) c:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe
(Aladdin Knowledge Systems, Ltd.) C:\Program Files\Aladdin\eToken\PKIClient\x64\PKIMonitor.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Dropbox, Inc.) C:\Users\ITSC-admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [DFEPApplication] - C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7077432 2012-08-15] (Dell Inc.)
HKLM\...\Run: [eTMonitor] - C:\Program Files\Aladdin\eToken\PKIClient\x64\PKIMonitor.exe [186880 2009-03-26] (Aladdin Knowledge Systems, Ltd.)
HKLM\...\Run: [IntelPROSet] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4805936 2012-08-23] (Intel(R) Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
Startup: C:\Users\ITSC-admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled ()
Startup: C:\Users\ITSC-admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\ITSC-admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\ITSC-admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USREL/8
SearchScopes: HKLM - DefaultScope {0BD0D271-429F-4F3A-93D8-1B67A6B83D91} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLRDF8&pc=MDDR&src=IE-SearchBox
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{DE7C8638-735E-41F6-BAE2-C784765E136B}: [NameServer]132.252.51.1,132.252.51.2
FireFox:
========
FF ProfilePath: C:\Users\ITSC-admin\AppData\Roaming\Mozilla\Firefox\Profiles\l71r1zhe.default
FF DefaultSearchEngine: Google
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.38 - C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\ITSC-admin\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\ITSC-admin\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\ITSC-admin\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\ITSC-admin\AppData\Roaming\Mozilla\Firefox\Profiles\l71r1zhe.default\Extensions\{DB981CCA-088E-4731-A4A2-2FE218703C0E}.xpi
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\29.0.1547.76\pdf.dll ()
CHR Plugin: (Microsoft Lync 2010 Meeting Join Plug-in) - C:\Program Files (x86)\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\ITSC-admin\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Users\ITSC-admin\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (Google Docs) - C:\Users\ITSC-A~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\ITSC-A~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\ITSC-A~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\ITSC-A~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\ITSC-A~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1
CHR Extension: (Gmail) - C:\Users\ITSC-A~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
==================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 DFEPService; c:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2280504 2012-08-15] (Dell Inc.)
R2 eTSrv; C:\Program Files\Aladdin\eToken\PKIClient\x64\eTSrv.exe [8192 2009-03-26] (Aladdin Knowledge Systems, Ltd.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] ()
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1435928 2013-09-10] (Trusteer Ltd.)
S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1637888 2011-10-08] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3342640 2012-08-23] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R3 AKSIFDH; C:\Windows\System32\DRIVERS\aksifdh.sys [62632 2008-07-30] (Aladdin Knowledge Systems, Ltd.)
S3 AKSUP; C:\Windows\System32\drivers\aksup.sys [44712 2008-07-30] (Aladdin Knowledge Systems, Ltd.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
S3 Ctafiltv; C:\Windows\System32\drivers\Ctafiltv.sys [24064 2008-08-14] (Creative Technology Ltd.)
S3 HBtnKey; C:\Windows\system32\drivers\HBtnKey.sys [20424 2011-07-20] (Dell Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R1 RapportCerberus_56758; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_56758.sys [589872 2013-08-21] ()
R1 RapportCerberus_56758; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_56758.sys [589872 2013-08-21] ()
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [265872 2013-09-10] (Trusteer Ltd.)
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [265872 2013-09-10] (Trusteer Ltd.)
R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [295696 2013-09-10] (Trusteer Ltd.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [384432 2013-09-10] (Trusteer Ltd.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [384432 2013-09-10] (Trusteer Ltd.)
S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x]
U5 GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [33240 2012-08-21] (GEAR Software Inc.)
S0 PBADRV; system32\DRIVERS\PBADRV.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-30 22:59 - 2013-09-30 22:59 - 01953880 _____ (Farbar) C:\Users\ITSC-admin\Downloads\FRST64.exe
2013-09-30 14:32 - 2013-09-30 14:33 - 00000000 ____D C:\Users\ITSC-admin\Desktop\Mama
2013-09-27 14:07 - 2013-09-30 15:52 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-09-27 14:07 - 2013-09-27 14:07 - 00000000 ____D C:\Program Files\AVAST Software
2013-09-27 14:07 - 2013-09-27 14:07 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-09-27 14:07 - 2013-08-30 09:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-09-27 14:07 - 2013-08-30 09:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-09-27 14:07 - 2013-08-30 09:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-09-27 14:07 - 2013-08-30 09:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-09-27 14:07 - 2013-08-30 09:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-09-27 14:07 - 2013-08-30 09:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-09-27 14:07 - 2013-08-30 09:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-09-27 14:07 - 2013-08-30 09:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-09-27 14:07 - 2013-08-30 09:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-09-27 14:07 - 2013-08-30 09:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-09-27 14:06 - 2013-09-27 14:07 - 00000000 ____D C:\ProgramData\AVAST Software
2013-09-27 13:51 - 2013-09-27 13:53 - 131918888 _____ C:\Users\ITSC-admin\Downloads\avast_free_antivirus_setup_8.0.1497.376.exe
2013-09-27 09:01 - 2013-09-27 09:01 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\WinEdt Team
2013-09-27 08:59 - 2013-09-27 08:59 - 00000000 ____D C:\Program Files (x86)\WinEdt Team
2013-09-27 01:04 - 2013-09-27 01:04 - 00001726 _____ C:\Users\Public\Desktop\Defraggler.lnk
2013-09-27 01:04 - 2013-09-27 01:04 - 00000000 ____D C:\Program Files\Defraggler
2013-09-27 01:02 - 2013-09-27 01:02 - 04104448 _____ (Piriform Ltd) C:\Users\ITSC-admin\Downloads\dfsetup215.exe
2013-09-25 19:24 - 2013-09-25 19:24 - 00000000 ____D C:\Users\ITSC-admin\Downloads\Autoruns
2013-09-25 19:23 - 2013-09-25 19:23 - 00550371 _____ C:\Users\ITSC-admin\Downloads\Autoruns.zip
2013-09-25 19:17 - 2013-09-30 22:07 - 00001568 _____ C:\Windows\setupact.log
2013-09-25 19:17 - 2013-09-25 19:17 - 00000000 _____ C:\Windows\setuperr.log
2013-09-25 19:06 - 2013-09-25 19:06 - 00000000 ____D C:\ProgramData\PDF Architect
2013-09-25 12:21 - 2013-09-25 12:21 - 00448512 _____ (OldTimer Tools) C:\Users\ITSC-admin\Downloads\TFC.exe
2013-09-24 18:21 - 2013-09-24 18:21 - 00000000 ____D C:\Users\ITSC-admin\Documents\CyberLink
2013-09-24 18:21 - 2013-09-24 18:21 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\CyberLink
2013-09-24 18:21 - 2013-09-24 18:21 - 00000000 ____D C:\Users\ITSC-admin\AppData\Local\Cyberlink
2013-09-24 18:21 - 2013-09-24 18:21 - 00000000 ____D C:\ProgramData\CyberLink
2013-09-24 18:08 - 2013-09-24 18:08 - 00002493 _____ C:\Users\ITSC-admin\Downloads\FSS.txt
2013-09-24 18:07 - 2013-09-24 18:07 - 00358923 _____ (Farbar) C:\Users\ITSC-admin\Downloads\FSS.exe
2013-09-23 15:22 - 2013-09-23 15:22 - 02347384 _____ (ESET) C:\Users\ITSC-admin\Downloads\esetsmartinstaller_enu.exe
2013-09-23 13:31 - 2013-09-23 13:31 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\ITSC-admin\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-21 22:31 - 2013-09-21 22:31 - 00151809 _____ C:\Users\ITSC-admin\Desktop\sicherheitskopie.tex
2013-09-20 00:22 - 2013-09-20 00:22 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-09-20 00:21 - 2013-09-30 22:31 - 00001140 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000UA.job
2013-09-20 00:21 - 2013-09-30 00:31 - 00001088 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000Core.job
2013-09-20 00:21 - 2013-09-20 00:26 - 00004120 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000UA
2013-09-20 00:21 - 2013-09-20 00:26 - 00003724 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000Core
2013-09-20 00:21 - 2013-09-20 00:21 - 00739856 _____ (Google Inc.) C:\Users\ITSC-admin\Downloads\chrome_installer_29.0.1547.76.exe
2013-09-19 15:16 - 2013-09-19 17:03 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-09-19 15:12 - 2013-09-19 17:03 - 00000000 ____D C:\Users\ITSC-admin\Desktop\mbar
2013-09-19 15:11 - 2013-09-19 15:11 - 12907592 _____ (Malwarebytes Corp.) C:\Users\ITSC-admin\Desktop\mbar-1.07.0.1005.exe
2013-09-19 14:13 - 2013-09-19 14:15 - 00000000 ____D C:\AdwCleaner
2013-09-19 14:11 - 2013-09-19 14:11 - 01039554 _____ C:\Users\ITSC-admin\Desktop\adwcleaner.exe
2013-09-19 13:47 - 2013-09-25 18:30 - 00032950 _____ C:\Users\ITSC-admin\Downloads\Addition.txt
2013-09-19 13:45 - 2013-09-19 13:45 - 00000000 ____D C:\FRST
2013-09-19 10:01 - 2013-09-23 13:33 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-19 10:01 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-19 10:00 - 2013-09-19 10:00 - 00614816 _____ C:\Users\ITSC-admin\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe
2013-09-19 09:45 - 2013-09-23 19:26 - 02092792 _____ C:\Users\ITSC-admin\Downloads\avira_free_4052_antivirus.exe
2013-09-17 14:38 - 2013-09-17 14:38 - 00000000 ____D C:\Windows\pss
2013-09-13 17:45 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-13 17:45 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-13 17:45 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-13 17:45 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-13 17:45 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-13 17:45 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-13 17:45 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-13 17:45 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-13 17:45 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-13 17:45 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-13 17:45 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-13 17:45 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-13 17:45 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-13 17:45 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-13 17:45 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-13 17:45 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-13 17:45 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-13 17:45 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-13 17:45 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-13 17:45 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-13 17:45 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-13 10:29 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-13 10:28 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-13 10:28 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-13 10:28 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-13 10:28 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-13 10:28 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-13 10:28 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-13 10:28 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-13 10:28 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-13 10:28 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-13 10:28 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-13 10:28 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-13 10:28 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-13 10:28 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-13 10:28 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-13 10:28 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-13 10:28 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-13 10:28 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-13 10:28 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-13 10:28 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-13 10:28 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-13 10:28 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-13 10:28 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-13 10:28 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-13 10:28 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-13 10:28 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-13 10:28 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-12 12:01 - 2013-09-25 18:05 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\TaskUnifier
2013-09-12 12:00 - 2013-09-12 12:00 - 00000850 _____ C:\Users\Public\Desktop\TaskUnifier.lnk
2013-09-12 12:00 - 2013-09-12 12:00 - 00000000 ____D C:\Program Files\TaskUnifier
2013-09-12 11:58 - 2013-09-12 11:59 - 21835871 _____ C:\Users\ITSC-admin\Downloads\TaskUnifier_4_0_4_installer_windows.zip
2013-09-10 20:36 - 2013-09-10 20:38 - 00000000 ____D C:\Users\ITSC-admin\Desktop\gefunden
2013-09-09 16:57 - 2013-09-25 19:04 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-09-09 16:57 - 2013-09-09 16:57 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\ITSC-admin\Downloads\revosetup95.exe
2013-09-09 15:45 - 2013-09-09 15:45 - 00000000 ____D C:\Users\ITSC-admin\.pdfsam
2013-09-09 14:18 - 2013-09-09 14:18 - 00000000 ____D C:\Program Files\gs
2013-09-09 14:13 - 2013-09-09 14:14 - 00000000 ____D C:\Program Files (x86)\gs
2013-09-09 14:11 - 2013-09-09 15:57 - 00011303 _____ C:\Users\ITSC-admin\gsview64.ini
2013-09-09 14:11 - 2013-09-09 14:11 - 00000000 ____D C:\Program Files\Ghostgum
2013-09-09 13:45 - 2013-09-24 18:13 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\IrfanView
2013-09-09 13:44 - 2013-09-09 13:44 - 02145888 _____ (Irfan Skiljan) C:\Users\ITSC-admin\Downloads\iview436g_setup.exe
2013-09-07 11:34 - 2013-09-09 00:26 - 00000000 ____D C:\Users\ITSC-admin\Desktop\GRASS
2013-09-03 11:56 - 2013-09-03 11:56 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\GRASS6
2013-09-03 11:53 - 2013-09-07 11:38 - 00000000 ____D C:\Users\ITSC-admin\Documents\grassdata
2013-09-03 00:25 - 2013-09-03 00:25 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\Amazon
2013-09-03 00:24 - 2013-09-03 00:24 - 02328864 _____ C:\Users\ITSC-admin\Downloads\AmazonMP3DownloaderInstall._V383688031_.exe
2013-09-03 00:24 - 2013-09-03 00:24 - 00000000 ____D C:\Users\ITSC-admin\Documents\Amazon MP3
2013-09-03 00:24 - 2013-09-03 00:24 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon
2013-08-31 10:14 - 2013-08-31 10:17 - 00005288 _____ C:\Users\ITSC-admin\Documents\bsauto.dta
==================== One Month Modified Files and Folders =======
2013-09-30 22:59 - 2013-09-30 22:59 - 01953880 _____ (Farbar) C:\Users\ITSC-admin\Downloads\FRST64.exe
2013-09-30 22:59 - 2012-07-03 11:39 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\Dropbox
2013-09-30 22:32 - 2012-05-30 21:22 - 01247993 _____ C:\Windows\WindowsUpdate.log
2013-09-30 22:31 - 2013-09-20 00:21 - 00001140 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000UA.job
2013-09-30 22:29 - 2012-05-30 21:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-30 22:16 - 2009-07-14 06:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-30 22:16 - 2009-07-14 06:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-30 22:09 - 2012-05-30 21:53 - 00000000 ____D C:\ProgramData\Sonic
2013-09-30 22:08 - 2013-05-13 23:12 - 00000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2013-09-30 22:08 - 2012-07-03 11:40 - 00000000 ___RD C:\Users\ITSC-admin\Dropbox
2013-09-30 22:07 - 2013-09-25 19:17 - 00001568 _____ C:\Windows\setupact.log
2013-09-30 22:07 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-30 15:52 - 2013-09-27 14:07 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-09-30 15:50 - 2012-07-08 14:08 - 00000099 _____ C:\Users\Public\LMDebug.log
2013-09-30 14:33 - 2013-09-30 14:32 - 00000000 ____D C:\Users\ITSC-admin\Desktop\Mama
2013-09-30 00:31 - 2013-09-20 00:21 - 00001088 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000Core.job
2013-09-28 13:18 - 2010-11-21 08:50 - 00696870 _____ C:\Windows\system32\perfh007.dat
2013-09-28 13:18 - 2010-11-21 08:50 - 00148134 _____ C:\Windows\system32\perfc007.dat
2013-09-28 13:18 - 2009-07-14 07:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-27 14:16 - 2010-11-21 05:47 - 00124912 _____ C:\Windows\PFRO.log
2013-09-27 14:07 - 2013-09-27 14:07 - 00000000 ____D C:\Program Files\AVAST Software
2013-09-27 14:07 - 2013-09-27 14:07 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-09-27 14:07 - 2013-09-27 14:06 - 00000000 ____D C:\ProgramData\AVAST Software
2013-09-27 13:53 - 2013-09-27 13:51 - 131918888 _____ C:\Users\ITSC-admin\Downloads\avast_free_antivirus_setup_8.0.1497.376.exe
2013-09-27 09:10 - 2012-06-08 13:25 - 00000000 ___RD C:\Users\ITSC-admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-27 09:01 - 2013-09-27 09:01 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\WinEdt Team
2013-09-27 08:59 - 2013-09-27 08:59 - 00000000 ____D C:\Program Files (x86)\WinEdt Team
2013-09-27 01:04 - 2013-09-27 01:04 - 00001726 _____ C:\Users\Public\Desktop\Defraggler.lnk
2013-09-27 01:04 - 2013-09-27 01:04 - 00000000 ____D C:\Program Files\Defraggler
2013-09-27 01:02 - 2013-09-27 01:02 - 04104448 _____ (Piriform Ltd) C:\Users\ITSC-admin\Downloads\dfsetup215.exe
2013-09-25 19:24 - 2013-09-25 19:24 - 00000000 ____D C:\Users\ITSC-admin\Downloads\Autoruns
2013-09-25 19:23 - 2013-09-25 19:23 - 00550371 _____ C:\Users\ITSC-admin\Downloads\Autoruns.zip
2013-09-25 19:17 - 2013-09-25 19:17 - 00000000 _____ C:\Windows\setuperr.log
2013-09-25 19:06 - 2013-09-25 19:06 - 00000000 ____D C:\ProgramData\PDF Architect
2013-09-25 19:04 - 2013-09-09 16:57 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-09-25 19:04 - 2013-06-26 01:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-25 19:03 - 2013-06-28 12:14 - 00000000 ____D C:\Program Files (x86)\MediaMonkey
2013-09-25 19:01 - 2012-10-31 16:14 - 00000000 ____D C:\Windows\Minidump
2013-09-25 18:30 - 2013-09-19 13:47 - 00032950 _____ C:\Users\ITSC-admin\Downloads\Addition.txt
2013-09-25 18:05 - 2013-09-12 12:01 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\TaskUnifier
2013-09-25 12:21 - 2013-09-25 12:21 - 00448512 _____ (OldTimer Tools) C:\Users\ITSC-admin\Downloads\TFC.exe
2013-09-24 18:21 - 2013-09-24 18:21 - 00000000 ____D C:\Users\ITSC-admin\Documents\CyberLink
2013-09-24 18:21 - 2013-09-24 18:21 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\CyberLink
2013-09-24 18:21 - 2013-09-24 18:21 - 00000000 ____D C:\Users\ITSC-admin\AppData\Local\Cyberlink
2013-09-24 18:21 - 2013-09-24 18:21 - 00000000 ____D C:\ProgramData\CyberLink
2013-09-24 18:19 - 2013-03-18 18:23 - 00000000 ____D C:\Users\ITSC-admin\AppData\Local\ABBYY
2013-09-24 18:19 - 2013-03-18 18:23 - 00000000 ____D C:\ProgramData\ABBYY
2013-09-24 18:15 - 2013-04-12 22:03 - 00000000 ____D C:\Program Files (x86)\ShellfireVPN
2013-09-24 18:13 - 2013-09-09 13:45 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\IrfanView
2013-09-24 18:08 - 2013-09-24 18:08 - 00002493 _____ C:\Users\ITSC-admin\Downloads\FSS.txt
2013-09-24 18:07 - 2013-09-24 18:07 - 00358923 _____ (Farbar) C:\Users\ITSC-admin\Downloads\FSS.exe
2013-09-24 16:49 - 2012-07-02 16:53 - 00000000 ____D C:\Users\ITSC-admin\Stata
2013-09-23 19:26 - 2013-09-19 09:45 - 02092792 _____ C:\Users\ITSC-admin\Downloads\avira_free_4052_antivirus.exe
2013-09-23 15:22 - 2013-09-23 15:22 - 02347384 _____ (ESET) C:\Users\ITSC-admin\Downloads\esetsmartinstaller_enu.exe
2013-09-23 13:33 - 2013-09-19 10:01 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-23 13:31 - 2013-09-23 13:31 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\ITSC-admin\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-22 14:29 - 2012-05-30 21:24 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-22 14:29 - 2012-05-30 21:24 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-22 14:29 - 2012-05-30 21:24 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-21 22:31 - 2013-09-21 22:31 - 00151809 _____ C:\Users\ITSC-admin\Desktop\sicherheitskopie.tex
2013-09-20 00:26 - 2013-09-20 00:21 - 00004120 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000UA
2013-09-20 00:26 - 2013-09-20 00:21 - 00003724 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000Core
2013-09-20 00:22 - 2013-09-20 00:22 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-09-20 00:21 - 2013-09-20 00:21 - 00739856 _____ (Google Inc.) C:\Users\ITSC-admin\Downloads\chrome_installer_29.0.1547.76.exe
2013-09-20 00:21 - 2013-06-27 12:12 - 00000000 ____D C:\Users\ITSC-admin\AppData\Local\Google
2013-09-19 22:41 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-09-19 17:03 - 2013-09-19 15:16 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-09-19 17:03 - 2013-09-19 15:12 - 00000000 ____D C:\Users\ITSC-admin\Desktop\mbar
2013-09-19 15:11 - 2013-09-19 15:11 - 12907592 _____ (Malwarebytes Corp.) C:\Users\ITSC-admin\Desktop\mbar-1.07.0.1005.exe
2013-09-19 14:15 - 2013-09-19 14:13 - 00000000 ____D C:\AdwCleaner
2013-09-19 14:11 - 2013-09-19 14:11 - 01039554 _____ C:\Users\ITSC-admin\Desktop\adwcleaner.exe
2013-09-19 13:45 - 2013-09-19 13:45 - 00000000 ____D C:\FRST
2013-09-19 10:00 - 2013-09-19 10:00 - 00614816 _____ C:\Users\ITSC-admin\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe
2013-09-17 14:38 - 2013-09-17 14:38 - 00000000 ____D C:\Windows\pss
2013-09-16 13:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-13 20:31 - 2012-06-08 13:26 - 00000000 ___RD C:\Users\ITSC-admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-13 20:30 - 2009-07-14 06:45 - 00461776 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-13 17:45 - 2013-07-31 06:03 - 00000000 ____D C:\Windows\system32\MRT
2013-09-13 17:42 - 2012-06-08 13:55 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-13 17:42 - 2012-06-08 13:48 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-12 12:00 - 2013-09-12 12:00 - 00000850 _____ C:\Users\Public\Desktop\TaskUnifier.lnk
2013-09-12 12:00 - 2013-09-12 12:00 - 00000000 ____D C:\Program Files\TaskUnifier
2013-09-12 11:59 - 2013-09-12 11:58 - 21835871 _____ C:\Users\ITSC-admin\Downloads\TaskUnifier_4_0_4_installer_windows.zip
2013-09-10 23:18 - 2013-05-26 14:36 - 00295696 _____ (Trusteer Ltd.) C:\Windows\system32\Drivers\RapportKE64.sys
2013-09-10 20:38 - 2013-09-10 20:36 - 00000000 ____D C:\Users\ITSC-admin\Desktop\gefunden
2013-09-09 17:20 - 2012-07-12 16:12 - 00000000 ____D C:\Windows\system32\appmgmt
2013-09-09 16:57 - 2013-09-09 16:57 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\ITSC-admin\Downloads\revosetup95.exe
2013-09-09 15:57 - 2013-09-09 14:11 - 00011303 _____ C:\Users\ITSC-admin\gsview64.ini
2013-09-09 15:45 - 2013-09-09 15:45 - 00000000 ____D C:\Users\ITSC-admin\.pdfsam
2013-09-09 15:45 - 2012-06-08 13:25 - 00000000 ____D C:\Users\ITSC-admin
2013-09-09 14:18 - 2013-09-09 14:18 - 00000000 ____D C:\Program Files\gs
2013-09-09 14:14 - 2013-09-09 14:13 - 00000000 ____D C:\Program Files (x86)\gs
2013-09-09 14:11 - 2013-09-09 14:11 - 00000000 ____D C:\Program Files\Ghostgum
2013-09-09 13:44 - 2013-09-09 13:44 - 02145888 _____ (Irfan Skiljan) C:\Users\ITSC-admin\Downloads\iview436g_setup.exe
2013-09-09 09:41 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-09 00:26 - 2013-09-07 11:34 - 00000000 ____D C:\Users\ITSC-admin\Desktop\GRASS
2013-09-07 21:25 - 2013-06-28 12:14 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\MediaMonkey
2013-09-07 11:38 - 2013-09-03 11:53 - 00000000 ____D C:\Users\ITSC-admin\Documents\grassdata
2013-09-07 11:03 - 2013-08-28 17:20 - 67984482 _____ C:\Users\ITSC-admin\Downloads\WinGRASS-6.4.3-1-Setup.exe
2013-09-03 11:56 - 2013-09-03 11:56 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\GRASS6
2013-09-03 00:25 - 2013-09-03 00:25 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\Amazon
2013-09-03 00:24 - 2013-09-03 00:24 - 02328864 _____ C:\Users\ITSC-admin\Downloads\AmazonMP3DownloaderInstall._V383688031_.exe
2013-09-03 00:24 - 2013-09-03 00:24 - 00000000 ____D C:\Users\ITSC-admin\Documents\Amazon MP3
2013-09-03 00:24 - 2013-09-03 00:24 - 00000000 ____D C:\Users\ITSC-admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon
2013-08-31 10:17 - 2013-08-31 10:14 - 00005288 _____ C:\Users\ITSC-admin\Documents\bsauto.dta
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-21 10:10
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-09-2013 02
Ran by ITSC-admin at 2013-09-30 23:02:22
Running from C:\Users\ITSC-admin\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
AccelerometerP11 (x32 Version: 2.00.10.34)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.175)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168)
Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8)
Adobe Shockwave Player 12.0 (x32 Version: 12.0.0.112)
Amazon MP3-Downloader 1.0.18 (HKCU Version: 1.0.18)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
ArcSoft TotalMedia 3.5 (x32 Version: 3.5.28.291)
avast! Free Antivirus (x32 Version: 8.0.1497.0)
BioAPI Framework (Version: 1.0.2)
Bonjour (Version: 3.0.0.10)
CyberLink PowerDVD 9.5 (x32 Version: 9.5.1.4822)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
Defraggler (Version: 2.15)
Dell Client System Update (x32 Version: 1.3.0)
Dell Data Protection | Access (x32 Version: 2.1.00001.002)
Dell Edoc Viewer (Version: 1.0.0)
Dell Feature Enhancement Pack (Version: 2.2.1)
Dell Touchpad (Version: 7.1211.101.118)
Dell Webcam Central (x32 Version: 1.40.54)
DirectX 9 Runtime (x32 Version: 1.00.0000)
Dropbox (HKCU Version: 2.0.22)
eToken PKI Client 5.1 (Version: 5.1.32.0)
Gemalto (Version: 01.64.01.0010)
Google Chrome (HKCU Version: 29.0.1547.76)
Human Development Trends 2005 (x32 Version: 1.0.0)
Intel PROSet Wireless
Intel(R) Control Center (x32 Version: 1.2.1.1007)
Intel(R) Identity Protection Technology 1.2.27.0 (x32 Version: 1.2.27.0)
Intel(R) Management Engine Components (x32 Version: 7.1.50.1172)
Intel(R) Network Connections 16.5.2.0 (Version: 16.5.2.0)
Intel(R) Processor Graphics (x32 Version: 9.17.10.2867)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149)
Intel® PROSet/Wireless WiFi-Software (Version: 15.03.1000.1637)
iTunes (Version: 11.0.4.4)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Lync 2010 (Version: 4.0.7577.4398)
Microsoft Office 2010 Service Pack 1 (SP1) (x32)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
MiKTeX 2.9 (x32 Version: 2.9)
Mozilla Maintenance Service (x32 Version: 17.0.8)
Mozilla Thunderbird 17.0.8 (x86 de) (x32 Version: 17.0.8)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
NTRU TCG Software Stack (Version: 2.1.37)
O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.23)
PC-CCID (Version: 2.0.0)
PDFCreator (x32 Version: 1.7.1)
PhotoShowExpress (x32 Version: 2.0.063)
Rapport (x32 Version: 3.5.1302.61)
RBVirtualFolder64Inst (Version: 1.00.0000)
Roxio Activation Module (x32 Version: 1.0)
Roxio BackOnTrack (x32 Version: 1.3.3)
Roxio Burn (x32 Version: 1.8)
Roxio Creator Starter (x32 Version: 1.0.439)
Roxio Creator Starter (x32 Version: 12.1.77.0)
Roxio Creator Starter (x32 Version: 5.0.0)
Roxio Express Labeler 3 (x32 Version: 3.2.2)
Roxio File Backup (Version: 1.3.2)
Samsung SCX-3200 Series (x32)
Scan Assistant (x32 Version: 1.01.014)
Skype™ 6.6 (x32 Version: 6.6.106)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0)
SPBA 5.9 (Version: 5.9.4.6901)
Stata 12 (x32 Version: 12.0)
swMSM (x32 Version: 12.0.0.1)
TaskUnifier version 4.0.4 (Version: 4.0.4)
Trusteer Endpunkt-Sicherheit (x32 Version: 3.5.1302.61)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553065) (x32)
Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2566458) (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32)
Upek Touchchip Fingerprint Reader (Version: 1.2.004)
Wartung Samsung ML-191x 252x Series (x32)
Wave Infrastructure Installer (Version: 07.67.17.0010)
Wave Support Software Installer (Version: 05.13.00.033)
WIDCOMM Bluetooth Software (Version: 6.3.0.7900)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3508.1109)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
WinEdt 7 (x32 Version: 7.0)
WinRAR Archivierer (x32)
==================== Restore Points =========================
27-09-2013 04:18:29 Geplanter Prüfpunkt
27-09-2013 12:06:49 avast! Free Antivirus Setup
28-09-2013 00:38:16 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {050100B7-3F7D-4190-AE3F-B9A248379AAF} - System32\Tasks\Dell\Client System Update => C:\Program Files (x86)\Dell\ClientSystemUpdate\DellClientSystemUpdate.exe [2012-10-11] (Dell Inc.)
Task: {1604A167-3F8C-4CDD-8FA7-FC950448AE75} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software)
Task: {28093F5D-1276-4830-A9C5-B9ADE3DC1F64} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2013-02-14] (Microsoft Corporation)
Task: {73E73B97-B735-49D6-A8DD-5CE951F6AC51} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {752C3E22-F68D-440F-A832-D39ECACEA17D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000Core => C:\Users\ITSC-admin\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-20] (Google Inc.)
Task: {85A3D5CB-8453-480A-9285-A89FFC34F10E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000UA => C:\Users\ITSC-admin\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-20] (Google Inc.)
Task: {8EF807EC-33D6-444B-BB5D-1C43B8AC364D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-22] (Adobe Systems Incorporated)
Task: {9BA7F418-E01D-4BAB-A843-7D26A9864F59} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000Core.job => C:\Users\ITSC-admin\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201769430-2905060512-2310320027-1000UA.job => C:\Users\ITSC-admin\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2011-03-17 00:07 - 2011-03-17 00:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2007-03-27 20:03 - 2007-03-27 20:03 - 02173952 ____R () C:\Program Files\Aladdin\eToken\PKIClient\x64\QtCore4.dll
2007-03-27 20:03 - 2007-03-27 20:03 - 08048640 ____R () C:\Program Files\Aladdin\eToken\PKIClient\x64\QtGui4.dll
2007-03-29 15:11 - 2007-03-29 15:11 - 00317440 _____ () C:\Program Files\Aladdin\eToken\PKIClient\x64\QtXml4.dll
2007-03-27 20:03 - 2007-03-27 20:03 - 00175104 ____R () C:\Program Files\Aladdin\eToken\PKIClient\x64\plugins\imageformats\qjpeg1.dll
2013-05-26 14:36 - 2013-08-21 09:16 - 00991984 _____ () C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportMS.dll
2013-09-30 11:04 - 2013-09-30 09:17 - 02102784 _____ () C:\Program Files\AVAST Software\Avast\defs\13093000\algo.dll
2013-04-21 22:44 - 2013-04-21 22:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-04-21 22:44 - 2013-04-21 22:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-06-27 15:09 - 2012-06-27 15:09 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll
2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\ITSC-admin\AppData\Roaming\Dropbox\bin\libcef.dll
2011-03-17 00:11 - 2011-03-17 00:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-08-09 19:04 - 2013-08-09 19:04 - 02244504 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2013-08-09 19:04 - 2013-08-09 19:04 - 00158104 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2013-08-09 19:04 - 2013-08-09 19:04 - 00022424 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2013-09-20 00:22 - 2013-09-17 05:20 - 00709584 _____ () C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\29.0.1547.76\libglesv2.dll
2013-09-20 00:22 - 2013-09-17 05:20 - 00099792 _____ () C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\29.0.1547.76\libegl.dll
2013-09-20 00:22 - 2013-09-17 05:21 - 04053456 _____ () C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\29.0.1547.76\pdf.dll
2013-09-20 00:22 - 2013-09-17 05:21 - 00410576 _____ () C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll
2013-09-20 00:22 - 2013-09-17 05:20 - 01604560 _____ () C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\29.0.1547.76\ffmpegsumo.dll
2013-09-20 00:22 - 2013-09-17 05:21 - 13611984 _____ () C:\Users\ITSC-admin\AppData\Local\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Faulty Device Manager Devices =============
Name: MATSHITA DVD+-RW UJ8B2
Description: CD-ROM-Laufwerk
Class Guid: {4d36e965-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard-CD-ROM-Laufwerke)
Service: cdrom
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
Name: Dell Wireless 375 Bluetooth Module
Description: Dell Wireless 375 Bluetooth Module
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Broadcom
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (09/30/2013 10:57:54 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (09/30/2013 10:08:06 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/30/2013 00:56:09 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/30/2013 00:49:53 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/30/2013 00:44:50 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/30/2013 00:42:34 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/30/2013 00:42:15 PM) (Source: DellFeatureEnhancementPack) (User: )
Description: Unable to initialize the DellSmartSettingsSys.dll. Error number = 0xa0000008
Error: (09/30/2013 11:03:15 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/29/2013 10:41:28 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/29/2013 07:00:00 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "D:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)"
System errors:
=============
Error: (09/30/2013 10:32:07 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (09/30/2013 10:30:48 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (09/30/2013 10:30:48 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (09/30/2013 10:08:34 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (09/30/2013 10:08:34 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (09/30/2013 10:07:45 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
PBADRV
Error: (09/30/2013 10:07:27 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/30/2013 10:07:25 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NTRU TSS v1.2.1.37 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (09/30/2013 01:16:25 PM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "LAPTOP",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{CC629C84-32A0-4999-BCFE-7DCFF031B6A5}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (09/30/2013 01:15:58 PM) (Source: ipnathlp) (User: )
Description: 0
Microsoft Office Sessions:
=========================
Error: (09/30/2013 10:57:54 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\ITSC-admin\Downloads\esetsmartinstaller_enu.exe
Error: (09/30/2013 10:08:06 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/30/2013 00:56:09 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/30/2013 00:49:53 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/30/2013 00:44:50 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/30/2013 00:42:34 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/30/2013 00:42:15 PM) (Source: DellFeatureEnhancementPack)(User: )
Description: Unable to initialize the DellSmartSettingsSys.dll. Error number = 0xa0000008
Error: (09/30/2013 11:03:15 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/29/2013 10:41:28 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/29/2013 07:00:00 PM) (Source: Windows Backup)(User: )
Description: D:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)
==================== Memory info ===========================
Percentage of memory in use: 37%
Total physical RAM: 8072.9 MB
Available physical RAM: 5024.16 MB
Total Pagefile: 22071.08 MB
Available Pagefile: 18815.92 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:464.98 GB) (Free:209.77 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 4423CD31)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=752 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=465 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Hattest Du nicht gesagt, die Bootzeiten wären normal? |