michasnet | 29.09.2013 19:22 | Hi und schon mal Vielen Dank!
hab jetzt genau deine Anweisungen befolgt, hab auch gesehen, dass ich mir vor ner woche schon mal FRST runtergeladen hatte und auch schon nen Scan gemacht hatte (hatte dann aber keine Folgen, weil ich ziemlich direkt danach gelesen habe, dass man die Ratschläge an die anderen User auf keinen Fall am eigenen Computer so nachmachen soll). Aber deshalb ist Addition.txt vom 15.9.
Hier FRST.txt:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-09-2013 02
Ran by Michael Schoenball (administrator) on MICHAELSCHOENBA on 29-09-2013 20:06:35
Running from C:\Users\Michael Schoenball\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Validity Sensors, Inc.) C:\Windows\system32\vcsFPService.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
(Conexant Systems, Inc.) C:\Program Files\Conexant\SA3\CxUtilSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Whilokii) C:\Program Files (x86)\Whilokii\updateWhilokii.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DPAgent.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
() C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Conexant Systems, Inc.) C:\Program Files\Conexant\SA3\SmartAudio3.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiSeAgnt.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
() C:\Users\Michael Schoenball\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe
(Dropbox, Inc.) C:\Users\Michael Schoenball\AppData\Roaming\Dropbox\bin\Dropbox.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SA3\SACpl.exe [1573504 2011-06-24] (Conexant Systems, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2780968 2011-04-30] (Synaptics Incorporated)
HKLM\...\Run: [FreeFallProtection] - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-17] ()
HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\QuickSet.exe [3668336 2011-03-24] (Dell Inc.)
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-07-28] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [Trend Micro Client Framework] - C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [192520 2011-05-21] (Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Titanium] - C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe [1119392 2011-05-21] (Trend Micro Inc.)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Udac] - rundll32 "C:\Users\Michael Schoenball\AppData\Roaming\msfeedsbsh.dll",Bwpybonxxw
HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [503942 2011-04-13] (Creative Technology Ltd)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [Dell DataSafe Online] - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-16] (Adobe Systems Incorporated)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\Michael Schoenball\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CNET TechTracker.lnk
ShortcutTarget: CNET TechTracker.lnk -> C:\Users\Michael Schoenball\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe ()
Startup: C:\Users\Michael Schoenball\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Michael Schoenball\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Michael Schoenball\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
ProxyServer: proxy.drsintra.de:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115&type=default&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115&type=default&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115&type=default&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115&type=default&q={searchTerms}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115&type=default&q={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=7C4EAC7289E1E5F2&affID=119357&tsp=5020
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115&type=default&q={searchTerms}
BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1077\TmIEPlg.dll (Trend Micro Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe64.dll (Trend Micro Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: iminent Helper Object - {112BA211-334C-4A90-90EC-2AD1CDAB287C} - C:\Program Files (x86)\IminentToolbar\1.8.25.0\bh\iminent.dll No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1077\TmIEPlg32.dll (Trend Micro Inc.)
BHO-x32: Whilokii - {204df522-9a96-4a72-abb0-60f7a216d6d2} - C:\Program Files (x86)\Whilokii\Whilokiibho.dll (Whilokii)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.24.6\bh\delta.dll (Delta-search.com)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: BonanzaDeals - {fe063412-bea4-4d76-8ed3-183be6220d17} - C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE.dll (BonanzaDeals)
Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.24.6\deltaTlbr.dll (Delta-search.com)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe64.dll (Trend Micro Inc.)
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1077\TmIEPlg.dll (Trend Micro Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1077\TmIEPlg32.dll (Trend Micro Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Michael Schoenball\AppData\Roaming\Mozilla\Firefox\Profiles\6z3bu6ez.default
FF user.js: detected! => C:\Users\Michael Schoenball\AppData\Roaming\Mozilla\Firefox\Profiles\6z3bu6ez.default\user.js
FF NewTab: hxxp://www.qvo6.com/newtab/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=nt&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115
FF DefaultSearchEngine: qvo6
FF SearchEngineOrder.1: Google.at
FF SelectedSearchEngine: qvo6
FF Homepage: hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115
FF NetworkProxy: "ftp", "proxy.drsintra.net"
FF NetworkProxy: "ftp_port", 8080
FF NetworkProxy: "http", "proxy.drsintra.net"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "socks", "proxy.drsintra.net"
FF NetworkProxy: "socks_port", 8080
FF NetworkProxy: "ssl", "proxy.drsintra.net"
FF NetworkProxy: "ssl_port", 8080
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=3 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals)
FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=9 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Users\Michael Schoenball\AppData\Roaming\Mozilla\Firefox\Profiles\6z3bu6ez.default\searchplugins\iminent.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\qvo6.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Delta Toolbar - C:\Users\Michael Schoenball\AppData\Roaming\Mozilla\Firefox\Profiles\6z3bu6ez.default\Extensions\ffxtlbr@delta.com
FF Extension: BonanzaDeals - C:\Users\Michael Schoenball\AppData\Roaming\Mozilla\Firefox\Profiles\6z3bu6ez.default\Extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}
FF Extension: firefox - C:\Users\Michael Schoenball\AppData\Roaming\Mozilla\Firefox\Profiles\6z3bu6ez.default\Extensions\firefox@whilokii.net.xpi
FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1077\firefoxextension\
FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1077\firefoxextension\
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=TOSHIBAXMK5061GSYN_91QIT4V9TXX91QIT4V9T&ts=1380477115
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (BonanzaDeals) - C:\Users\MICHAE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0
CHR Extension: (Iminent Chrome Toolbar) - C:\Users\MICHAE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0
CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Michael Schoenball\AppData\Roaming\BabSolution\CR\Delta.crx
CHR HKLM-x32\...\Chrome\Extension: [hpomcmndppalndoljdilmfkkjkcnongl] - C:\Program Files (x86)\1clickmoviedownloader.com\clickmoviedownloader10.crx
CHR HKLM-x32\...\Chrome\Extension: [pkhojieggfgllhllcegoffdcnmdeojgb] - C:\Program Files (x86)\IminentToolbar\1.8.25.0\iminent.crx
==================== Services (Whitelisted) =================
S2 bonanzadealslive; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-09-29] (BonanzaDeals)
S3 bonanzadealslivem; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-09-29] (BonanzaDeals)
R2 CxUtilSvc; C:\Program Files\Conexant\SA3\CxUtilSvc.exe [28288 2011-06-24] (Conexant Systems, Inc.)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-07-28] ()
R2 Update Whilokii; C:\Program Files (x86)\Whilokii\updateWhilokii.exe [206616 2013-09-26] (Whilokii)
R2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [x]
==================== Drivers (Whitelisted) ====================
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [13088 2011-03-02] ()
R2 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [90896 2011-05-21] (Trend Micro Inc.)
R2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [144656 2011-05-21] (Trend Micro Inc.)
R2 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [69392 2011-05-21] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105552 2011-05-21] (Trend Micro Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-29 20:02 - 2013-09-29 20:02 - 01953880 _____ (Farbar) C:\Users\Michael Schoenball\Downloads\FRST64.exe
2013-09-29 19:47 - 2013-09-29 19:55 - 00000946 _____ C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job
2013-09-29 19:47 - 2013-09-29 19:52 - 00000950 _____ C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job
2013-09-29 19:47 - 2013-09-29 19:47 - 00003946 _____ C:\windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA
2013-09-29 19:47 - 2013-09-29 19:47 - 00003694 _____ C:\windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore
2013-09-29 19:47 - 2013-09-29 19:47 - 00003434 _____ C:\windows\System32\Tasks\EPUpdater
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\BabSolution
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Local\BonanzaDealsLive
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\ProgramData\DSearchLink
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\ProgramData\BonanzaDealsLive
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\Program Files (x86)\Delta
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive
2013-09-29 19:46 - 2013-09-29 19:57 - 00003304 _____ C:\windows\System32\Tasks\DigitalSite
2013-09-29 19:46 - 2013-09-29 19:57 - 00000324 _____ C:\windows\Tasks\DigitalSite.job
2013-09-29 19:46 - 2013-09-29 19:47 - 00000000 ____D C:\Program Files (x86)\Whilokii
2013-09-29 19:46 - 2013-09-29 19:46 - 00749248 _____ C:\Users\Michael Schoenball\Downloads\ZipExtractorSetup.exe
2013-09-29 19:46 - 2013-09-29 19:46 - 00003412 _____ C:\windows\System32\Tasks\BonanzaDealsUpdate
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\DigitalSite
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\Babylon
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\ProgramData\Babylon
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\Program Files (x86)\OpenIt
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals
2013-09-29 19:43 - 2013-09-29 19:43 - 00060510 _____ C:\Users\Michael Schoenball\Desktop\Extras.Txt
2013-09-29 19:41 - 2013-09-29 19:41 - 00112384 _____ C:\Users\Michael Schoenball\Desktop\OTL.Txt
2013-09-29 19:24 - 2013-09-29 19:43 - 00060510 _____ C:\Users\Michael Schoenball\Downloads\Extras.Txt
2013-09-29 19:23 - 2013-09-29 19:23 - 00112384 _____ C:\Users\Michael Schoenball\Downloads\OTL.Txt
2013-09-29 18:41 - 2013-09-29 18:41 - 00602112 _____ (OldTimer Tools) C:\Users\Michael Schoenball\Downloads\OTL.exe
2013-09-28 18:29 - 2013-09-28 18:30 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Local\{42CD3EEC-23F5-44FA-B066-5A3017DF5D98}
2013-09-28 18:29 - 2013-09-28 18:29 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\Windows Live Writer
2013-09-28 18:29 - 2013-09-28 18:29 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Local\Windows Live Writer
2013-09-27 20:20 - 2013-09-27 20:20 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk
2013-09-27 20:20 - 2013-09-27 20:20 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\OpenOffice
2013-09-27 20:19 - 2013-09-27 20:19 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-27 20:10 - 2013-09-27 20:13 - 163606685 _____ C:\Users\Michael Schoenball\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe
2013-09-27 11:40 - 2013-09-27 13:22 - 00000000 ____D C:\Users\Michael Schoenball\Desktop\Lieder 30 WFD
2013-09-27 11:26 - 2013-09-19 22:09 - 16999796 ____C C:\Users\Michael Schoenball\Downloads\jens_kober1 - Kopie.jpg.tif
2013-09-26 09:56 - 2013-09-26 09:57 - 00000000 ____D C:\Users\Michael Schoenball\Downloads\Marie Kees fotos
2013-09-26 09:32 - 2013-09-26 09:32 - 02650026 _____ C:\Users\Michael Schoenball\Downloads\awfotos30jahrewfd.zip
2013-09-26 09:29 - 2013-09-26 09:29 - 00010460 _____ C:\Users\Michael Schoenball\Downloads\rooming list academic orchestra 2013.xlsx
2013-09-23 14:39 - 2013-09-29 19:51 - 00001445 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-19 22:07 - 2013-09-19 22:09 - 16999796 _____ C:\Users\Michael Schoenball\Downloads\jens_kober1.tif
2013-09-19 12:38 - 2013-09-23 14:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-17 15:06 - 2013-09-17 15:08 - 05216044 _____ C:\Users\Michael Schoenball\Downloads\cusanus2.wav
2013-09-17 00:23 - 2013-09-17 00:23 - 00827392 _____ () C:\Users\Michael Schoenball\Downloads\videoperformerSetup.exe
2013-09-17 00:20 - 2013-09-17 00:20 - 00575704 _____ C:\Users\Michael Schoenball\Downloads\Player_Setup.exe
2013-09-16 13:05 - 2013-09-16 13:05 - 00007898 _____ C:\Users\Michael Schoenball\Downloads\Raster Bühnenprogramm.odt
2013-09-16 01:18 - 2013-09-16 01:19 - 00000000 ____D C:\Users\Michael Schoenball\Documents\Initiativen, Kampagnen
2013-09-15 21:39 - 2013-09-15 21:39 - 97671483 _____ C:\windows\SysWOW64\Ꮆ㶊
2013-09-15 15:40 - 2013-09-15 15:40 - 00000000 ____D C:\FRST
2013-09-15 15:30 - 2013-09-15 15:30 - 00000000 ____D C:\windows\ERUNT
2013-09-15 15:24 - 2013-09-16 14:16 - 00000000 ____D C:\AdwCleaner
2013-09-15 15:23 - 2013-09-15 15:23 - 01039554 _____ C:\Users\Michael Schoenball\Downloads\adwcleaner.exe
2013-09-14 01:52 - 2013-09-14 01:52 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Local\Google
2013-09-14 01:50 - 2013-09-14 01:50 - 00000000 ____D C:\Program Files (x86)\1clickmoviedownloader.com
2013-09-12 10:42 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-09-12 10:42 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-09-12 10:42 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-09-12 10:42 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-09-12 10:42 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-09-12 10:42 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-09-12 10:42 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-09-12 10:42 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-09-12 10:42 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-09-12 10:42 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-09-12 10:42 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-09-12 10:42 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-09-12 10:42 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-09-12 10:42 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-09-12 10:42 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-12 09:36 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-09-12 09:36 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-09-12 09:36 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-09-12 09:36 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-09-12 09:36 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-09-12 09:36 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-09-12 09:36 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-09-12 09:36 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-09-12 09:36 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-09-12 09:36 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-09-12 09:36 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-09-12 09:36 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-09-12 09:36 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-09-12 09:36 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-09-12 09:36 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-09-12 09:36 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-09-11 09:37 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-09-11 09:37 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys
2013-09-11 09:37 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-09-11 09:37 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-09-11 09:37 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2013-09-11 09:37 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2013-09-11 09:37 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2013-09-11 09:37 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2013-09-11 09:37 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2013-09-11 09:37 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2013-09-11 09:37 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2013-09-11 09:37 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2013-09-11 09:37 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2013-09-11 09:37 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2013-09-11 09:37 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2013-09-11 09:37 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2013-09-11 09:37 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2013-09-11 09:37 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2013-09-11 09:37 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2013-09-11 09:37 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2013-09-11 09:37 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2013-09-11 09:37 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 09:37 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-11 09:37 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2013-09-11 09:37 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2013-09-11 09:37 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2013-09-11 09:37 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\shdocvw.dll
2013-09-11 09:20 - 2013-09-12 00:12 - 97181529 _____ C:\windows\SysWOW64\䌾懚X
2013-09-10 23:54 - 2013-09-29 19:53 - 00000000 ____D C:\ProgramData\Avira
2013-09-10 23:51 - 2013-09-10 23:51 - 02092792 _____ C:\Users\Michael Schoenball\Downloads\avira_free_4052_antivirus.exe
2013-09-10 18:19 - 2013-09-10 18:19 - 00442368 __RSH C:\Users\Michael Schoenball\AppData\Roaming\msfeedsbsh.dll
2013-09-04 11:59 - 2013-09-04 11:59 - 00019212 _____ C:\Users\Michael Schoenball\Documents\Trinksprüche.odt
==================== One Month Modified Files and Folders =======
2013-09-29 20:03 - 2009-07-14 06:45 - 00020720 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-29 20:03 - 2009-07-14 06:45 - 00020720 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-29 20:02 - 2013-09-29 20:02 - 01953880 _____ (Farbar) C:\Users\Michael Schoenball\Downloads\FRST64.exe
2013-09-29 19:59 - 2011-10-22 22:33 - 01591942 _____ C:\windows\WindowsUpdate.log
2013-09-29 19:57 - 2013-09-29 19:46 - 00003304 _____ C:\windows\System32\Tasks\DigitalSite
2013-09-29 19:57 - 2013-09-29 19:46 - 00000324 _____ C:\windows\Tasks\DigitalSite.job
2013-09-29 19:57 - 2012-02-28 16:29 - 00000000 ___RD C:\Users\Michael Schoenball\Dropbox
2013-09-29 19:57 - 2012-02-28 16:26 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\Dropbox
2013-09-29 19:55 - 2013-09-29 19:47 - 00000946 _____ C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job
2013-09-29 19:55 - 2011-10-28 11:41 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Local\SoftThinks
2013-09-29 19:55 - 2011-10-22 23:53 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2013-09-29 19:55 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-09-29 19:55 - 2009-07-14 06:51 - 00091974 _____ C:\windows\setupact.log
2013-09-29 19:54 - 2010-11-21 05:47 - 00383690 _____ C:\windows\PFRO.log
2013-09-29 19:53 - 2013-09-10 23:54 - 00000000 ____D C:\ProgramData\Avira
2013-09-29 19:52 - 2013-09-29 19:47 - 00000950 _____ C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job
2013-09-29 19:51 - 2013-09-23 14:39 - 00001445 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-29 19:51 - 2011-10-28 11:45 - 00001731 _____ C:\Users\Michael Schoenball\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-09-29 19:47 - 2013-09-29 19:47 - 00003946 _____ C:\windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA
2013-09-29 19:47 - 2013-09-29 19:47 - 00003694 _____ C:\windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore
2013-09-29 19:47 - 2013-09-29 19:47 - 00003434 _____ C:\windows\System32\Tasks\EPUpdater
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\BabSolution
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Local\BonanzaDealsLive
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\ProgramData\DSearchLink
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\ProgramData\BonanzaDealsLive
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\Program Files (x86)\Delta
2013-09-29 19:47 - 2013-09-29 19:47 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive
2013-09-29 19:47 - 2013-09-29 19:46 - 00000000 ____D C:\Program Files (x86)\Whilokii
2013-09-29 19:46 - 2013-09-29 19:46 - 00749248 _____ C:\Users\Michael Schoenball\Downloads\ZipExtractorSetup.exe
2013-09-29 19:46 - 2013-09-29 19:46 - 00003412 _____ C:\windows\System32\Tasks\BonanzaDealsUpdate
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\DigitalSite
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\Babylon
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\ProgramData\Babylon
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\Program Files (x86)\OpenIt
2013-09-29 19:46 - 2013-09-29 19:46 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals
2013-09-29 19:43 - 2013-09-29 19:43 - 00060510 _____ C:\Users\Michael Schoenball\Desktop\Extras.Txt
2013-09-29 19:43 - 2013-09-29 19:24 - 00060510 _____ C:\Users\Michael Schoenball\Downloads\Extras.Txt
2013-09-29 19:41 - 2013-09-29 19:41 - 00112384 _____ C:\Users\Michael Schoenball\Desktop\OTL.Txt
2013-09-29 19:28 - 2013-02-14 20:59 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-09-29 19:23 - 2013-09-29 19:23 - 00112384 _____ C:\Users\Michael Schoenball\Downloads\OTL.Txt
2013-09-29 18:41 - 2013-09-29 18:41 - 00602112 _____ (OldTimer Tools) C:\Users\Michael Schoenball\Downloads\OTL.exe
2013-09-29 17:52 - 2011-10-23 01:23 - 10897636 _____ C:\windows\system32\perfh007.dat
2013-09-29 17:52 - 2011-10-23 01:23 - 03442566 _____ C:\windows\system32\perfc007.dat
2013-09-29 17:52 - 2009-07-14 07:13 - 00006756 _____ C:\windows\system32\PerfStringBackup.INI
2013-09-28 18:30 - 2013-09-28 18:29 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Local\{42CD3EEC-23F5-44FA-B066-5A3017DF5D98}
2013-09-28 18:29 - 2013-09-28 18:29 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\Windows Live Writer
2013-09-28 18:29 - 2013-09-28 18:29 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Local\Windows Live Writer
2013-09-28 18:23 - 2011-10-28 11:41 - 00068552 _____ C:\Users\Michael Schoenball\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-28 18:22 - 2009-07-14 06:45 - 00303664 _____ C:\windows\system32\FNTCACHE.DAT
2013-09-28 00:39 - 2011-11-10 01:42 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\SoftGrid Client
2013-09-27 20:20 - 2013-09-27 20:20 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk
2013-09-27 20:20 - 2013-09-27 20:20 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Roaming\OpenOffice
2013-09-27 20:19 - 2013-09-27 20:19 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-27 20:18 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-09-27 20:13 - 2013-09-27 20:10 - 163606685 _____ C:\Users\Michael Schoenball\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe
2013-09-27 13:22 - 2013-09-27 11:40 - 00000000 ____D C:\Users\Michael Schoenball\Desktop\Lieder 30 WFD
2013-09-26 09:57 - 2013-09-26 09:56 - 00000000 ____D C:\Users\Michael Schoenball\Downloads\Marie Kees fotos
2013-09-26 09:32 - 2013-09-26 09:32 - 02650026 _____ C:\Users\Michael Schoenball\Downloads\awfotos30jahrewfd.zip
2013-09-26 09:29 - 2013-09-26 09:29 - 00010460 _____ C:\Users\Michael Schoenball\Downloads\rooming list academic orchestra 2013.xlsx
2013-09-25 12:25 - 2013-06-03 23:22 - 00003440 _____ C:\windows\System32\Tasks\PCDEventLauncherTask
2013-09-23 14:39 - 2013-09-19 12:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-22 10:40 - 2012-06-10 19:28 - 00000000 ____D C:\Users\Michael Schoenball\Documents\Theologische Texte Impulse
2013-09-21 12:11 - 2013-06-03 23:22 - 00000000 ____D C:\Program Files\My Dell
2013-09-21 12:11 - 2012-03-06 16:00 - 00000000 ____D C:\ProgramData\PCDr
2013-09-20 11:28 - 2013-02-14 20:59 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-09-20 11:28 - 2013-02-14 20:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-20 11:28 - 2013-02-14 20:59 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-09-19 22:09 - 2013-09-27 11:26 - 16999796 ____C C:\Users\Michael Schoenball\Downloads\jens_kober1 - Kopie.jpg.tif
2013-09-19 22:09 - 2013-09-19 22:07 - 16999796 _____ C:\Users\Michael Schoenball\Downloads\jens_kober1.tif
2013-09-19 13:39 - 2011-10-28 16:49 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Local\Mozilla
2013-09-17 15:08 - 2013-09-17 15:06 - 05216044 _____ C:\Users\Michael Schoenball\Downloads\cusanus2.wav
2013-09-17 00:23 - 2013-09-17 00:23 - 00827392 _____ () C:\Users\Michael Schoenball\Downloads\videoperformerSetup.exe
2013-09-17 00:20 - 2013-09-17 00:20 - 00575704 _____ C:\Users\Michael Schoenball\Downloads\Player_Setup.exe
2013-09-16 14:16 - 2013-09-15 15:24 - 00000000 ____D C:\AdwCleaner
2013-09-16 13:05 - 2013-09-16 13:05 - 00007898 _____ C:\Users\Michael Schoenball\Downloads\Raster Bühnenprogramm.odt
2013-09-16 01:22 - 2012-09-26 22:29 - 00000000 ____D C:\Users\Michael Schoenball\Documents\Noten
2013-09-16 01:20 - 2013-04-19 16:51 - 00000000 ____D C:\Users\Michael Schoenball\Documents\Cusanuswerk
2013-09-16 01:19 - 2013-09-16 01:18 - 00000000 ____D C:\Users\Michael Schoenball\Documents\Initiativen, Kampagnen
2013-09-15 21:39 - 2013-09-15 21:39 - 97671483 _____ C:\windows\SysWOW64\Ꮆ㶊
2013-09-15 15:40 - 2013-09-15 15:40 - 00000000 ____D C:\FRST
2013-09-15 15:30 - 2013-09-15 15:30 - 00000000 ____D C:\windows\ERUNT
2013-09-15 15:23 - 2013-09-15 15:23 - 01039554 _____ C:\Users\Michael Schoenball\Downloads\adwcleaner.exe
2013-09-14 10:11 - 2013-02-14 20:59 - 00002592 _____ C:\windows\SysWOW64\InstallUtil.InstallLog
2013-09-14 09:59 - 2011-10-28 11:45 - 00000000 ___RD C:\Users\Michael Schoenball\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-14 09:59 - 2011-10-28 11:45 - 00000000 ___RD C:\Users\Michael Schoenball\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-14 01:52 - 2013-09-14 01:52 - 00000000 ____D C:\Users\Michael Schoenball\AppData\Local\Google
2013-09-14 01:50 - 2013-09-14 01:50 - 00000000 ____D C:\Program Files (x86)\1clickmoviedownloader.com
2013-09-12 09:36 - 2011-11-10 01:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2013-09-12 00:12 - 2013-09-11 09:20 - 97181529 _____ C:\windows\SysWOW64\䌾懚X
2013-09-10 23:51 - 2013-09-10 23:51 - 02092792 _____ C:\Users\Michael Schoenball\Downloads\avira_free_4052_antivirus.exe
2013-09-10 18:19 - 2013-09-10 18:19 - 00442368 __RSH C:\Users\Michael Schoenball\AppData\Roaming\msfeedsbsh.dll
2013-09-04 16:15 - 2012-11-05 00:12 - 00000000 ____D C:\Users\Michael Schoenball\Documents\Collegium musicum
2013-09-04 11:59 - 2013-09-04 11:59 - 00019212 _____ C:\Users\Michael Schoenball\Documents\Trinksprüche.odt
Some content of TEMP:
====================
C:\Users\Michael Schoenball\AppData\Local\Temp\GenericUninstall.exe
C:\Users\Michael Schoenball\AppData\Local\Temp\ICReinstall_ZipExtractorSetup.exe
C:\Users\Michael Schoenball\AppData\Local\Temp\mgsqlite3.dll
C:\Users\Michael Schoenball\AppData\Local\Temp\MSN8CBE.exe
C:\Users\Michael Schoenball\AppData\Local\Temp\Player_Setup.exe
C:\Users\Michael Schoenball\AppData\Local\Temp\Quarantine.exe
C:\Users\Michael Schoenball\AppData\Local\Temp\Shortcut_BundleSweetIMSetup.exe
C:\Users\Michael Schoenball\AppData\Local\Temp\SHSetup.exe
C:\Users\Michael Schoenball\AppData\Local\Temp\SimboApp.exe
C:\Users\Michael Schoenball\AppData\Local\Temp\SIMEEIInstaller.exe
C:\Users\Michael Schoenball\AppData\Local\Temp\uninstaller.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-21 13:45
==================== End Of Log ============================ --- --- ---
Und noch Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-09-2013 04
Ran by Michael Schoenball at 2013-09-15 15:41:49
Running from C:\Users\Michael Schoenball\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
AccelerometerP11 (x32 Version: 2.00.11.22)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.174)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168)
Adobe Reader X MUI (x32 Version: 10.0.0)
Advanced Audio FX Engine (x32 Version: 1.12.05)
ALDI Bestellsoftware 4.12.2 (x32 Version: 4.12.2)
Avira Free Antivirus (x32 Version: 13.0.0.4052)
CNET TechTracker (HKCU Version: 2.0.4)
Conexant SmartAudio HD (Version: 8.54.16.0)
D3DX10 (x32 Version: 15.4.2368.0902)
Dell DataSafe Local Backup - Support Software (x32 Version: 9.4.57)
Dell DataSafe Local Backup (x32 Version: 9.4.57)
Dell DataSafe Online (x32 Version: 2.1.19634)
Dell Edoc Viewer (Version: 1.0.0)
Dell Touchpad (Version: 15.3.5.0)
Dell Webcam Central (x32 Version: 2.00.44)
DigitalPersona Fingerprint Software 5.20 (Version: 5.20.230)
Dropbox (HKCU Version: 2.0.22)
ffdshow v1.2.4422 [2012-04-09] (x32 Version: 1.2.4422.0)
Intel PROSet Wireless
Intel PROSet Wireless (x32)
Intel(R) Control Center (x32 Version: 1.2.1.1007)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2418)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 1.2.0.0587)
Intel(R) PROSet/Wireless WiFi-Software (Version: 14.2.0000)
Intel(R) Rapid Storage Technology (x32 Version: 10.1.5.1001)
Intel(R) WiDi (x32 Version: 2.1.35.0)
Intel(R) Wireless Display
Java Auto Updater (x32 Version: 2.0.6.1)
Java(TM) 6 Update 22 (x32 Version: 6.0.220)
Java(TM) 6 Update 27 (64-bit) (Version: 6.0.270)
Java(TM) 6 Update 27 (x32 Version: 6.0.270)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Lidl-Druckservice (x32)
McAfee Security Scan Plus (x32 Version: 3.0.318.3)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1)
Mozilla Maintenance Service (x32 Version: 23.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
My Dell (Version: 3.3.6280.92)
Online Sheet Music Viewer 8.3.4.0 (x32 Version: 8.3.4.0)
OpenOffice.org 3.3 (x32 Version: 3.3.9567)
PDF-XChange Viewer (Version: 2.5.203.0)
Quickset64 (Version: 10.09.25)
Realtek Ethernet Controller Driver (x32 Version: 7.43.321.2011)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30127)
Skype Toolbars (x32 Version: 1.0.4051)
Skype™ 6.0 (x32 Version: 6.0.126)
SpyHunter (Version: 4.14.5.4268)
TI USB 3.0 Host Controller Driver (x32 Version: 1.12.14.0)
TI USB3 Host Driver (x32 Version: 1.12.14.0)
Trend Micro Titanium Internet Security (Version: 3.00)
Trend Micro Titanium Internet Security (Version: 3.1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Validity Sensors DDK (Version: 4.3.108.0)
VLC media player 2.0.3 (x32 Version: 2.0.3)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3508.1109)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
==================== Restore Points =========================
17-08-2013 01:00:50 Windows Update
17-08-2013 21:25:50 Removed SpyHunter
17-08-2013 21:26:29 Removed SpyHunter
17-08-2013 21:27:15 Removed SpyHunter
17-08-2013 21:27:56 Removed SpyHunter
17-08-2013 21:28:25 Removed SpyHunter
01-09-2013 01:00:43 Windows Update
10-09-2013 11:25:19 Geplanter Prüfpunkt
11-09-2013 23:21:02 Windows Update
12-09-2013 07:28:51 Windows Update
14-09-2013 08:02:38 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {014BB435-4429-4308-A8DB-01D00A3CF27A} - \Plus-HD-2.2-enabler No Task File
Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started
Task: {15B84A37-73AA-4869-A06D-E7AA88C6D47B} - \Plus-HD-2.2-codedownloader No Task File
Task: {2CEC6748-7224-4E2B-85AC-024798B46651} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1894675805-202365497-958786631-1000
Task: {2E19A77F-AED3-4314-AE61-B2DC582AAE87} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2013-06-27] (Enigma Software Group USA, LLC.)
Task: {3181EBD2-583D-4DB6-9F96-EFFD47F1FB1E} - \Plus-HD-2.2-firefoxinstaller No Task File
Task: {4555AB94-DFF8-4A1F-BF68-0D0553D8055F} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-14] (Adobe Systems Incorporated)
Task: {51D4C549-BA97-4F67-814E-495B7373F6E1} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {59757BBF-ECEB-4B65-8EC6-49B33C1BCBE1} - \Plus-HD-2.2-updater No Task File
Task: {8661A60D-040C-4BE9-AC93-9CF122458CA1} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-21] (Microsoft Corporation)
Task: {89A46F7C-B61F-441E-856C-FF6FF96CF401} - System32\Tasks\SystemToolsDailyTest => C:\Windows\System32\uaclauncher.exe
Task: {9A8F6E69-17A1-4339-9826-EC467D275E7A} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {AA758349-3C25-4FA7-9648-32663E049FBB} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2013-05-07] (PC-Doctor, Inc.)
Task: {C94F73EB-1379-48A1-8757-BED7BE825626} - System32\Tasks\JavaUpdateSched => %COMMONPROGRAMFILES(x86)%\Java\Java Update\jusched.exe
Task: {E40C5598-2CD6-4BEE-A5F6-03F1157A20B0} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2013-07-18] (PC-Doctor, Inc.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2013-01-09 17:38 - 2012-11-23 05:13 - 00068608 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe
2010-12-29 20:53 - 2010-12-29 20:53 - 00931664 _____ (DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpoFeedb.dll
2009-07-14 02:18 - 2009-07-14 03:38 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\imaadp32.acm
2009-07-14 02:18 - 2009-07-14 03:38 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\msg711.acm
2009-07-14 02:18 - 2009-07-14 03:38 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\msgsm32.acm
2009-07-14 02:18 - 2009-07-14 03:38 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\msadp32.acm
2009-07-14 02:22 - 2009-07-14 03:38 - 00081408 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\System32\l3codeca.acm
2010-12-29 19:45 - 2010-12-29 19:45 - 00178512 _____ (DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpoSet.dll
2010-12-29 20:54 - 2010-12-29 20:54 - 00740688 _____ (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
2009-07-14 01:37 - 2009-07-14 03:39 - 00120320 _____ (Microsoft Corporation) C:\windows\system32\Dwm.exe
2011-10-23 01:04 - 2011-06-20 09:16 - 00167704 _____ (Intel Corporation) C:\Windows\System32\igfxtray.exe
2011-10-23 01:04 - 2011-06-10 20:45 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrDEU.lrc
2011-10-23 01:04 - 2011-06-20 09:16 - 00392472 _____ (Intel Corporation) C:\Windows\System32\hkcmd.exe
2011-10-23 01:04 - 2011-06-20 09:16 - 00416024 _____ (Intel Corporation) C:\Windows\System32\igfxpers.exe
2011-10-23 01:04 - 2011-06-10 20:36 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-10-23 01:04 - 2011-04-30 04:00 - 02780968 _____ (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2011-10-23 01:04 - 2011-04-30 04:00 - 00411432 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll
2011-10-23 01:04 - 2011-04-30 04:00 - 00226088 _____ (Synaptics Incorporated) C:\windows\system32\SynTPAPI.dll
2011-10-22 22:56 - 2010-12-17 17:25 - 00686704 _____ () C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
2011-03-24 21:13 - 2011-03-24 21:13 - 03668336 _____ (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
2011-07-28 03:51 - 2011-07-28 03:51 - 01935120 _____ (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
2011-07-28 03:44 - 2011-07-28 03:44 - 01077248 _____ (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\PsRegApi.dll
2011-07-28 03:07 - 2011-07-28 03:07 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-07-28 04:20 - 2011-07-28 04:20 - 00045568 _____ (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\LangResources\DEU\FrWrkDEU.dll
2011-07-28 03:55 - 2011-07-28 03:55 - 01746432 _____ (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\FrameworkPlugins\PanTray.dll
2011-07-28 03:46 - 2011-07-28 03:46 - 01045504 _____ (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\TraceAPI.DLL
2011-07-28 03:44 - 2011-07-28 03:44 - 00234496 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\WiMAXCoEx.dll
2011-07-28 03:50 - 2011-07-28 03:50 - 02072576 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\PfMgrApi.dll
2011-07-28 03:51 - 2011-07-28 03:51 - 01278976 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\MurocApi.dll
2011-07-28 03:46 - 2011-07-28 03:46 - 00841728 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\IntStngs.dll
2011-07-28 03:53 - 2011-07-28 03:53 - 00570368 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\PanApi.dll
2011-07-28 03:44 - 2011-07-28 03:44 - 00177152 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\S24MUDLL.dll
2011-07-28 04:24 - 2011-07-28 04:24 - 00097280 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\LangResources\DEU\PanTrDEU.dll
2011-10-23 01:15 - 2011-05-21 09:45 - 01410504 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiSeAgnt.exe
2011-10-22 23:36 - 2011-05-21 10:01 - 00059168 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilDebugLog.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00047104 _____ () C:\Program Files\Trend Micro\AMSP\boost_thread-vc80-mt-1_36.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00042496 _____ () C:\Program Files\Trend Micro\AMSP\boost_date_time-vc80-mt-1_36.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00091104 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilMsgBuffer.dll
2011-10-22 23:37 - 2011-05-21 10:01 - 00144640 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilJsonHandle.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00376408 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\outer_AMSP_ClientLibrary.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00107584 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilIPC.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00024672 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilThread.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00137448 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilRPC.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00032912 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilAccessControl.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00528336 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilInstallation.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00095224 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilComponentInfo.dll
2011-10-22 23:36 - 2011-05-21 10:01 - 00030864 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilGenericLoader.dll
2011-10-22 22:40 - 2011-04-13 17:39 - 00503942 ____N (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
2010-11-21 05:24 - 2010-11-21 05:24 - 00464384 _____ (Microsoft Corporation) C:\windows\system32\taskeng.exe
2013-06-27 23:46 - 2013-06-27 23:46 - 07529344 _____ (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
2013-06-27 23:46 - 2013-06-27 23:46 - 00721792 _____ (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\ExecutionGuard.dll
2013-06-27 23:46 - 2013-06-27 23:46 - 03017088 _____ (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\ShScanner.dll
2013-06-27 23:46 - 2013-06-27 23:46 - 01190272 _____ (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\Defman.dll
2013-06-27 23:46 - 2013-06-27 23:46 - 00546688 _____ (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\Common.dll
2011-12-01 22:24 - 2011-12-01 22:24 - 02624512 _____ () C:\Users\Michael Schoenball\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe
2013-05-25 02:47 - 2013-05-25 02:47 - 27776968 _____ (Dropbox, Inc.) C:\Users\Michael Schoenball\AppData\Roaming\Dropbox\bin\Dropbox.exe
2009-07-14 01:56 - 2009-07-14 03:39 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\NOTEPAD.EXE
2011-10-22 22:53 - 2011-06-24 05:36 - 00417408 _____ (Conexant Systems, Inc.) C:\Program Files\Conexant\SA3\SmartAudio3.exe
2011-10-22 22:53 - 2011-06-24 05:36 - 00212096 _____ (Conexant Systems, Inc.) C:\Program Files\Conexant\SA3\SmartAudio.Core.dll
2011-10-22 22:53 - 2011-05-23 21:43 - 00114688 _____ ( ) C:\Program Files\Conexant\SA3\Interop.CxHDAudioAPILib.dll
2011-10-22 22:53 - 2011-05-23 21:43 - 01233408 _____ (Conexant Systems, Inc.) C:\Program Files\Conexant\SA3\CxHDAudioAPI.dll
2011-10-22 22:53 - 2011-05-26 01:53 - 00014848 _____ ( ) C:\Program Files\Conexant\SA3\Interop.SRSAPOInterface.dll
2011-10-22 22:53 - 2011-06-24 05:36 - 00030208 _____ (Conexant Systems, Inc.) C:\Program Files\Conexant\SA3\SmartAudio.Creative.dll
2011-10-22 22:53 - 2011-06-24 05:36 - 02534016 _____ (Conexant Systems, Inc.) C:\Program Files\Conexant\SA3\SmartAudio.Dell.dll
2011-10-22 22:53 - 2011-06-24 05:36 - 00414848 _____ (Conexant Systems, Inc.) C:\Program Files\Conexant\SA3\SmartAudio.Localization.dll
2011-10-22 22:53 - 2011-06-24 05:36 - 00098304 _____ (Conexant Systems, Inc.) C:\Program Files\Conexant\SA3\SmartAudio.SRS.dll
2011-10-22 22:53 - 2011-06-24 03:48 - 00356352 _____ (Conexant Systems, Inc.) C:\Program Files\Conexant\SA3\Languages\de-DE\SmartAudio.resources.dll
2011-10-22 22:53 - 2011-06-08 01:32 - 00464384 _____ (SRS Labs, Inc.) C:\Program Files\Conexant\SA3\slapoi64.dll
2010-12-29 20:54 - 2010-12-29 20:54 - 00386416 _____ (DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DPAgent.exe
2009-07-14 01:47 - 2009-07-14 03:39 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\wbem\unsecapp.exe
2011-10-22 23:53 - 2011-07-08 17:12 - 02749248 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
2011-10-23 01:04 - 2011-04-30 04:00 - 00121640 _____ (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
2010-11-21 05:24 - 2010-11-21 05:24 - 00302592 _____ (Microsoft Corporation) C:\windows\SysWOW64\cmd.exe
2013-09-11 09:37 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2012-07-12 14:09 - 2012-06-03 00:19 - 00057880 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2011-07-29 10:49 - 2011-02-25 08:19 - 02871808 _____ (Microsoft Corporation) C:\windows\explorer.exe
2013-09-12 00:13 - 2013-09-12 00:13 - 01862024 _____ (Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
2011-10-22 23:30 - 2011-05-04 07:19 - 00113664 _____ (Microsoft Corporation) C:\windows\system32\SearchFilterHost.exe
2013-09-15 15:40 - 2013-09-15 15:40 - 01951102 _____ (Farbar) C:\Users\Michael Schoenball\Downloads\FRST64.exe
2010-12-29 19:45 - 2010-12-29 19:45 - 00212304 _____ (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpOSet.dll
2010-12-29 20:54 - 2010-12-29 20:54 - 00649552 _____ (DigitalPersona, Inc.) C:\windows\system32\DPFPApi.DLL
2010-12-29 20:54 - 2010-12-29 20:54 - 00376656 _____ (DigitalPersona, Inc.) C:\windows\system32\DPCLBACK.dll
2010-12-29 20:52 - 2010-12-29 20:52 - 00619856 _____ (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DPAgentOtsPlugin.dll
2010-12-29 20:53 - 2010-12-29 20:53 - 01324368 _____ (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpFillin.dll
2010-12-29 19:45 - 2010-12-29 19:45 - 00248144 _____ (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpoPS.dll
2010-12-29 20:53 - 2010-12-29 20:53 - 00685392 _____ (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpOCache.dll
2010-12-29 20:53 - 2010-12-29 20:53 - 00644432 _____ (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpoFeedb.dll
2011-10-22 22:40 - 2009-09-08 17:01 - 00237056 ____N (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\CTLoadRs.dll
2011-10-22 22:40 - 2010-07-22 20:01 - 00065536 ____N (Creative Technology Ltd.) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\CtPinMgr.dll
2010-12-29 19:45 - 2010-12-29 19:45 - 00212304 _____ (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpoSet.dll
2013-08-17 03:36 - 2013-08-17 03:36 - 00475648 _____ (Intel Corporation) C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\aabbed019df19cbda3b3dfb80fa98bf0\IAStorUtil.ni.dll
2013-07-15 04:04 - 2013-07-15 04:04 - 00014336 _____ (Intel Corp.) C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\8fae59a3cc25d36da6f7f85ef16e441c\IAStorCommon.ni.dll
2010-07-15 04:08 - 2010-07-15 04:08 - 00063827 _____ (Zlib) C:\Users\Michael Schoenball\AppData\Roaming\CBS Interactive\CNET TechTracker\zlib.dll
2012-11-14 01:32 - 2012-11-14 01:32 - 03558400 _____ (wxWidgets development team) C:\Users\Michael Schoenball\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\Michael Schoenball\AppData\Roaming\Dropbox\bin\libcef.dll
2013-03-13 22:48 - 2013-03-13 22:48 - 09956864 _____ (The ICU Project) C:\Users\Michael Schoenball\AppData\Roaming\Dropbox\bin\icudt.dll
2011-01-17 16:19 - 2011-10-28 16:59 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
==================== Alternate Data Streams (whitelisted) ==========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/15/2013 03:34:07 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich.
Error: (09/15/2013 03:34:07 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error: (09/15/2013 03:34:06 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error: (09/15/2013 03:28:21 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/15/2013 09:21:35 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich.
Error: (09/15/2013 09:21:35 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error: (09/15/2013 09:21:35 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error: (09/15/2013 09:01:48 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich.
Error: (09/15/2013 09:01:48 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error: (09/15/2013 09:01:48 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
System errors:
=============
Error: (09/15/2013 03:27:50 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\windows\System32\IWMSSvc.dll
Fehlercode: 258
Error: (09/15/2013 00:17:28 AM) (Source: DCOM) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (09/15/2013 00:16:23 AM) (Source: DCOM) (User: )
Description: 1053Bluetooth Media Service{9AC233E9-AC75-4DB5-85C4-DAB13A484FEA}
Error: (09/15/2013 00:16:24 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht.
Error: (09/15/2013 00:16:23 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Bluetooth Media Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (09/15/2013 00:16:23 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Bluetooth Media Service erreicht.
Error: (09/15/2013 00:15:54 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht.
Error: (09/14/2013 10:02:04 AM) (Source: Service Control Manager) (User: )
Description: Dienst "SProtection" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/14/2013 09:58:51 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht.
Error: (09/14/2013 02:16:04 AM) (Source: DCOM) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Microsoft Office Sessions:
=========================
Error: (09/15/2013 03:34:07 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: WmiApRplWmiApRpl8F20300004D070000
Error: (09/15/2013 03:34:07 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: Performance1637070000000000000000000009030000
Error: (09/15/2013 03:34:06 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: Performance1637070000000000000000000009030000
Error: (09/15/2013 03:28:21 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/15/2013 09:21:35 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: WmiApRplWmiApRpl8F20300004D070000
Error: (09/15/2013 09:21:35 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: Performance1637070000000000000000000009030000
Error: (09/15/2013 09:21:35 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: Performance1637070000000000000000000009030000
Error: (09/15/2013 09:01:48 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: WmiApRplWmiApRpl8F20300004D070000
Error: (09/15/2013 09:01:48 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: Performance1637070000000000000000000009030000
Error: (09/15/2013 09:01:48 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: Performance1637070000000000000000000009030000 |