Upsiii *rotwerd* da war dann wohl ein e zu viel :lach::lach:
Anweisung erfolgreich ausgeführt: FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by Enqel (administrator) on ENQEL-PC on 09-10-2013 00:01:14
Running from C:\Users\Enqel\Downloads
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Windows Net) C:\Users\Enqel\AppData\Roaming\Windows Net Data\net.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
(WebConnect) C:\Program Files (x86)\WebConnect\updateWebConnect.exe
(WebConnect) C:\Program Files (x86)\WebConnect\bin\utilWebConnect.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(IncrediMail, Ltd.) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2184520 2009-03-24] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [767312 2009-03-18] (CANON INC.)
HKCU\...\Run: [IncrediMail] - C:\Program Files (x86)\IncrediMail\bin\IncMail.exe [444840 2013-09-30] (IncrediMail, Ltd.)
HKCU\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
HKCU\...\Run: [AppleIEDAV] - C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe
HKCU\...\Run: [EA Core] - "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
MountPoints2: {5ea53601-154f-11e3-8744-00241d0b681e} - E:\LaunchU3.exe -a
MountPoints2: {dfe9b47a-2f6b-11e3-9c58-00241d0b681e} - D:\Autorun.exe
MountPoints2: {e5e8a616-bf42-11e2-b11f-806e6f6e6963} - D:\CD_Start.exe
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [681032 2013-09-30] (Avira Operations GmbH & Co. KG)
AppInit_DLLs: [0 ] ()
AppInit_DLLs-x32: [0 ] ()
Startup: C:\Users\Enqel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
ShortcutTarget: net.lnk -> C:\Users\Enqel\AppData\Roaming\Windows Net Data\net.exe (Windows Net)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=a1a753c0-2f19-6318-8cf8-1f2f64ace6b1&searchtype=ds&q={searchTerms}&installDate=07/10/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF77D56F45353CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=a1a753c0-2f19-6318-8cf8-1f2f64ace6b1&searchtype=ds&q={searchTerms}&installDate=07/10/2013
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2414} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=135&systemid=414&v=n8822-91&apn_uid=3024493021854457&apn_dtid=BND414&o=APN10649&apn_ptnrs=AGA&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=a1a753c0-2f19-6318-8cf8-1f2f64ace6b1&searchtype=ds&q={searchTerms}&installDate=07/10/2013
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=a1a753c0-2f19-6318-8cf8-1f2f64ace6b1&searchtype=ds&q={searchTerms}&installDate=07/10/2013
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2414} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=135&systemid=414&v=n8822-91&apn_uid=3024493021854457&apn_dtid=BND414&o=APN10649&apn_ptnrs=AGA&q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=a1a753c0-2f19-6318-8cf8-1f2f64ace6b1&searchtype=ds&q={searchTerms}&installDate=07/10/2013
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=a1a753c0-2f19-6318-8cf8-1f2f64ace6b1&searchtype=ds&q={searchTerms}&installDate=07/10/2013
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.dalesearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=707900241D0B681E&affID=124844&tsp=5025
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2414} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=135&systemid=414&v=n8822-91&apn_uid=3024493021854457&apn_dtid=BND414&o=APN10649&apn_ptnrs=AGA&q={searchTerms}
BHO: No Name - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No File
BHO-x32: WebConnect - {2316c625-b487-4410-a1a5-ff040b65245f} - C:\Program Files (x86)\WebConnect\WebConnectbho.dll (Web Connect)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: No Name - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKCU - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\Enqel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Enqel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Enqel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Enqel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Enqel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\Enqel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [ieakfmpjhljbpbfpldjkddkjmmgjmgon] - C:\Program Files (x86)\WebConnect\ieakfmpjhljbpbfpldjkddkjmmgjmgon.crx
CHR HKLM-x32\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\Enqel\AppData\Local\Wajam\Chrome\wajam.crx
CHR HKLM-x32\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\Enqel\AppData\Local\Torch\Plugins\TorchPlugin.crx
CHR HKLM-x32\...\Chrome\Extension: [pialekdjmfmckiccfkgbbgphficjdekh] - C:\Users\Enqel\AppData\Roaming\BabSolution\CR\dalesearch.crx
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440392 2013-09-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440392 2013-09-30] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1164360 2013-09-30] (Avira Operations GmbH & Co. KG)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
R2 Update WebConnect; C:\Program Files (x86)\WebConnect\updateWebConnect.exe [65320 2013-10-04] (WebConnect)
R2 Util WebConnect; C:\Program Files (x86)\WebConnect\bin\utilWebConnect.exe [65320 2013-10-04] (WebConnect)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105856 2013-09-30] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-09-30] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-09-30] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [83160 2013-09-30] (Avira Operations GmbH & Co. KG)
R3 e1kexpress; C:\Windows\System32\DRIVERS\e1k60x64.sys [220672 2009-06-10] (Intel Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-09 00:01 - 2013-10-09 00:01 - 00000000 ____D C:\FRST
2013-10-08 23:59 - 2013-10-08 23:59 - 01954124 _____ (Farbar) C:\Users\Enqel\Downloads\FRST64.exe
2013-10-08 22:17 - 2013-10-08 22:17 - 00010350 _____ C:\Users\Enqel\Desktop\Ereignisse.txt
2013-10-08 19:38 - 2013-10-08 19:38 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Avira
2013-10-08 19:25 - 2013-10-08 19:25 - 00002070 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-10-08 19:25 - 2013-10-08 19:25 - 00000000 ____D C:\ProgramData\Avira
2013-10-08 19:25 - 2013-10-08 19:25 - 00000000 ____D C:\Program Files (x86)\Avira
2013-10-08 19:25 - 2013-09-30 11:01 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-08 19:25 - 2013-09-30 11:01 - 00105856 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-08 19:25 - 2013-09-30 11:01 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-10-08 19:25 - 2013-09-30 11:01 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-10-08 19:23 - 2013-10-08 19:24 - 122946048 _____ C:\Users\Enqel\Downloads\avira14_free_antivirus_de.exe
2013-10-08 19:19 - 2013-10-08 19:19 - 00564076 _____ C:\Users\Enqel\Downloads\RatingBuster-1.6.7.zip
2013-10-08 19:18 - 2013-10-08 19:18 - 00700981 _____ C:\Users\Enqel\Downloads\TitanPanel-5.1.24.50400.zip
2013-10-08 17:50 - 2013-10-09 00:01 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-08 17:50 - 2013-10-08 23:01 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-08 17:50 - 2013-10-08 22:56 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-08 17:50 - 2013-10-08 22:56 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-08 17:50 - 2013-10-08 17:50 - 00002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-07 21:06 - 2013-10-07 21:06 - 00000000 ____D C:\ProgramData\EA Core
2013-10-07 21:02 - 2013-10-07 21:03 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Origin
2013-10-07 21:01 - 2013-10-08 17:14 - 00000000 ____D C:\ProgramData\Origin
2013-10-07 21:00 - 2013-10-07 21:00 - 00000554 _____ C:\Windows\KB893803v2.log
2013-10-07 20:37 - 2013-10-07 21:01 - 00000000 ____D C:\ProgramData\Electronic Arts
2013-10-07 20:11 - 2013-10-07 20:11 - 00000000 ____D C:\Program Files (x86)\Microsoft WSE
2013-10-07 20:10 - 2013-10-07 20:10 - 00000196 _____ C:\Windows\DirectX.log
2013-10-07 20:10 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2013-10-07 20:10 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2013-10-07 19:58 - 2013-10-08 17:13 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-07 19:54 - 2013-10-07 19:57 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\DAEMON Tools Lite
2013-10-07 19:54 - 2013-10-07 19:57 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2013-10-07 19:53 - 2013-10-07 19:54 - 13901152 _____ (Disc Soft Ltd) C:\Users\Enqel\Downloads\DTLite4471-0333.exe
2013-10-07 19:27 - 2013-10-07 19:27 - 00000000 ____D C:\Users\Enqel\Desktop\mi
2013-10-05 23:13 - 2013-10-05 23:13 - 00000000 ____D C:\ProgramData\Protexis
2013-10-05 16:27 - 2013-10-05 16:27 - 00000000 ____D C:\Users\Enqel\AppData\Local\Blizzard Entertainment
2013-10-05 13:18 - 2013-10-05 13:18 - 00003400 _____ C:\Windows\System32\Tasks\{936088AA-2254-48E5-8F31-3BFEBD3DC00A}
2013-10-05 13:16 - 2013-10-05 13:16 - 00003412 _____ C:\Windows\System32\Tasks\{DBDF3408-E571-4AAA-A8A0-F4B849415196}
2013-10-05 13:15 - 2013-10-07 22:06 - 00000000 ____D C:\Users\Enqel\Documents\Eigene PSP-Dateien
2013-10-05 13:06 - 2013-10-05 13:07 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Repplop
2013-10-04 21:18 - 2013-10-07 19:06 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-04 21:15 - 2013-10-08 12:51 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-10-04 19:02 - 2013-10-08 12:48 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Systweak
2013-10-04 19:02 - 2013-10-05 01:01 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\BabSolution
2013-10-04 19:01 - 2013-06-19 17:27 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
2013-10-04 19:00 - 2013-10-04 19:00 - 00168760 _____ (Firseria ) C:\Users\Enqel\Downloads\iTunes.exe
2013-10-04 17:58 - 2013-10-04 17:59 - 03682968 _____ ( ) C:\Users\Enqel\Downloads\UsenetNLSetup[84316EC1-05EA-3A2F-0C2D146F89F3F202].exe
2013-10-04 17:58 - 2013-10-04 17:58 - 03682968 _____ ( ) C:\Users\Enqel\Downloads\UsenetNLSetup[84313CFA-0913-4A3C-634901DCF9861D37].exe
2013-10-03 18:51 - 2013-10-03 18:54 - 00000000 ____D C:\ProgramData\Protexis64
2013-10-03 18:51 - 2013-10-03 18:51 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Corel
2013-10-03 18:47 - 2013-10-03 18:47 - 249069560 _____ (Acresso Software Inc.) C:\Users\Enqel\Downloads\PSPX6_TBYB30.exe
2013-10-03 15:34 - 2013-10-03 15:34 - 390585629 _____ C:\Windows\MEMORY.DMP
2013-10-03 15:34 - 2013-10-03 15:34 - 01262744 _____ C:\Windows\Minidump\100313-24882-01.dmp
2013-10-01 23:22 - 2013-10-01 23:22 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Downloaded Installations
2013-10-01 23:21 - 2013-10-01 23:21 - 01453920 _____ (Solid State Networks) C:\Users\Enqel\Downloads\nitro_pdf_pro_64_dlm.exe
2013-10-01 23:07 - 2013-10-01 23:08 - 39469712 _____ C:\Users\Enqel\Downloads\PdfEditor_64bit.exe
2013-10-01 22:51 - 2013-10-01 22:51 - 00000000 ____D C:\Users\Enqel\AppData\Local\PDF24
2013-10-01 22:49 - 2013-10-01 22:49 - 15911976 _____ (Geek Software GmbH ) C:\Users\Enqel\Downloads\pdf24-creator-5.7.0.exe
2013-10-01 21:01 - 2013-10-01 21:01 - 00014200 _____ C:\Users\Enqel\Downloads\miscellaneous_geschirrspuler-nordrhein-westfalen_nordrhein-westfalen-nw.kml
2013-09-30 17:35 - 2013-09-30 17:35 - 00000000 ____D C:\ProgramData\Photo Notifier and Animation Creator
2013-09-30 17:35 - 2013-09-30 17:35 - 00000000 ____D C:\Program Files (x86)\Photo Notifier and Animation Creator
2013-09-30 17:34 - 2013-09-30 18:06 - 00000000 ____D C:\Users\Enqel\AppData\Local\IM
2013-09-30 17:34 - 2013-09-30 17:35 - 00000000 ____D C:\ProgramData\IM
2013-09-30 17:34 - 2013-09-30 17:34 - 00000000 ____D C:\ProgramData\IncrediMail
2013-09-30 17:34 - 2013-09-30 17:34 - 00000000 ____D C:\Program Files (x86)\IncrediMail
2013-09-29 18:09 - 2013-09-29 18:09 - 00000400 _____ C:\Windows\ODBC.INI
2013-09-29 18:06 - 2013-09-29 18:06 - 00000000 ____D C:\Windows\PCHEALTH
2013-09-26 20:54 - 2013-09-26 20:54 - 00000000 _____ C:\end
2013-09-25 23:23 - 2013-09-25 23:24 - 01269936 _____ C:\Windows\Minidump\092513-73648-01.dmp
2013-09-24 18:27 - 2013-10-08 17:27 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Apple Computer
2013-09-24 18:27 - 2013-10-04 21:48 - 00000000 ____D C:\Users\Enqel\AppData\Local\Apple Computer
2013-09-24 18:26 - 2013-09-24 18:26 - 00000000 ____D C:\ProgramData\Apple Computer
2013-09-24 18:11 - 2013-10-04 21:31 - 00000000 ____D C:\Users\Enqel\AppData\Local\Apple
2013-09-24 18:10 - 2013-09-24 18:11 - 00000000 ____D C:\ProgramData\Apple
2013-09-23 20:16 - 2013-09-23 20:16 - 01653360 _____ C:\Windows\Minidump\092313-18610-01.dmp
2013-09-23 14:26 - 2013-09-23 14:26 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\File Scout
2013-09-21 21:50 - 2013-09-21 21:50 - 01653808 _____ C:\Windows\Minidump\092113-32588-01.dmp
2013-09-21 02:19 - 2013-09-21 02:19 - 00000000 ____D C:\Users\Enqel\.appwork
2013-09-21 00:43 - 2013-10-04 14:32 - 00000000 ____D C:\Program Files (x86)\WebConnect
2013-09-21 00:43 - 2013-09-21 02:20 - 00000000 ____D C:\Users\Enqel\AppData\Local\JDownloader v2.0
2013-09-19 18:02 - 2013-09-29 20:34 - 00000000 ____D C:\Users\Enqel\AppData\Local\Canon Easy-PhotoPrint EX
2013-09-19 18:01 - 2013-09-19 18:01 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX
2013-09-19 17:47 - 2013-09-19 17:47 - 00000000 ____D C:\Users\Enqel\AppData\Local\Wajam
2013-09-12 15:42 - 2013-09-12 15:42 - 00000000 ___HD C:\ProgramData\CanonIJSolutionMenu
2013-09-12 15:29 - 2013-09-12 15:29 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\CD-LabelPrint
2013-09-12 15:26 - 2013-10-03 20:52 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-09-12 15:26 - 2013-09-12 15:26 - 00000000 ___HD C:\ProgramData\CanonIJMyPrinter
2013-09-12 15:17 - 2013-09-12 15:17 - 00000000 ____D C:\Program Files\Canon
2013-09-12 15:14 - 2013-09-12 15:26 - 00000000 ____D C:\Program Files (x86)\Canon
2013-09-12 01:43 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-12 01:43 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-12 01:43 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-12 01:43 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-12 01:43 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-12 01:43 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-12 01:43 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-12 01:43 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-12 01:43 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-12 01:43 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-12 01:43 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-12 01:43 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-12 01:43 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-12 01:43 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-12 01:43 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-12 01:43 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-12 01:43 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-12 01:43 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-12 01:43 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-12 01:43 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-12 01:43 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-12 01:43 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-12 01:43 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-12 01:42 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-12 01:42 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-12 01:42 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-12 01:42 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-12 01:42 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-12 01:42 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-12 01:42 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-12 01:42 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-11 18:47 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-11 18:47 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-11 18:47 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-11 18:47 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-11 18:47 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-11 18:47 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-11 18:47 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-11 18:47 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-11 18:47 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-11 18:47 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-11 18:47 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-11 18:47 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-11 18:47 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-11 18:47 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-11 18:47 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-11 18:47 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 18:47 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-11 18:47 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-11 18:47 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-11 18:46 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-11 18:46 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-11 18:46 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-11 18:46 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-11 18:46 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 18:46 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-11 18:46 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-11 18:46 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-11 18:46 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-11 18:46 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
==================== One Month Modified Files and Folders =======
2013-10-09 00:01 - 2013-10-09 00:01 - 00000000 ____D C:\FRST
2013-10-09 00:01 - 2013-10-08 17:50 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-08 23:59 - 2013-10-08 23:59 - 01954124 _____ (Farbar) C:\Users\Enqel\Downloads\FRST64.exe
2013-10-08 23:20 - 2013-08-18 18:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-08 23:01 - 2013-10-08 17:50 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-08 22:56 - 2013-10-08 17:50 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-08 22:56 - 2013-10-08 17:50 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-08 22:17 - 2013-10-08 22:17 - 00010350 _____ C:\Users\Enqel\Desktop\Ereignisse.txt
2013-10-08 20:36 - 2013-05-18 00:45 - 01940497 _____ C:\Windows\WindowsUpdate.log
2013-10-08 20:21 - 2013-08-18 18:12 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-08 20:21 - 2013-08-18 18:12 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-08 20:21 - 2013-08-18 18:12 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-08 19:43 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-08 19:43 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-08 19:38 - 2013-10-08 19:38 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Avira
2013-10-08 19:31 - 2013-05-19 04:22 - 00043840 _____ C:\Windows\PFRO.log
2013-10-08 19:31 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-08 19:31 - 2009-07-14 06:51 - 00060607 _____ C:\Windows\setupact.log
2013-10-08 19:29 - 2013-09-05 00:23 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Ihilon
2013-10-08 19:25 - 2013-10-08 19:25 - 00002070 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-10-08 19:25 - 2013-10-08 19:25 - 00000000 ____D C:\ProgramData\Avira
2013-10-08 19:25 - 2013-10-08 19:25 - 00000000 ____D C:\Program Files (x86)\Avira
2013-10-08 19:24 - 2013-10-08 19:23 - 122946048 _____ C:\Users\Enqel\Downloads\avira14_free_antivirus_de.exe
2013-10-08 19:19 - 2013-10-08 19:19 - 00564076 _____ C:\Users\Enqel\Downloads\RatingBuster-1.6.7.zip
2013-10-08 19:18 - 2013-10-08 19:18 - 00700981 _____ C:\Users\Enqel\Downloads\TitanPanel-5.1.24.50400.zip
2013-10-08 18:52 - 2013-09-05 00:23 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\tor
2013-10-08 17:50 - 2013-10-08 17:50 - 00002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-08 17:50 - 2013-05-18 01:42 - 00000000 ____D C:\Users\Enqel\AppData\Local\Google
2013-10-08 17:50 - 2013-05-18 01:42 - 00000000 ____D C:\Program Files (x86)\Google
2013-10-08 17:50 - 2013-05-18 01:41 - 00000000 ____D C:\Users\Enqel\AppData\Local\Deployment
2013-10-08 17:45 - 2013-09-04 22:55 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\UseNeXT
2013-10-08 17:27 - 2013-09-24 18:27 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Apple Computer
2013-10-08 17:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-10-08 17:14 - 2013-10-07 21:01 - 00000000 ____D C:\ProgramData\Origin
2013-10-08 17:13 - 2013-10-07 19:58 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-08 12:51 - 2013-10-04 21:15 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-10-08 12:48 - 2013-10-04 19:02 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Systweak
2013-10-07 22:06 - 2013-10-05 13:15 - 00000000 ____D C:\Users\Enqel\Documents\Eigene PSP-Dateien
2013-10-07 21:06 - 2013-10-07 21:06 - 00000000 ____D C:\ProgramData\EA Core
2013-10-07 21:03 - 2013-10-07 21:02 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Origin
2013-10-07 21:01 - 2013-10-07 20:37 - 00000000 ____D C:\ProgramData\Electronic Arts
2013-10-07 21:00 - 2013-10-07 21:00 - 00000554 _____ C:\Windows\KB893803v2.log
2013-10-07 20:11 - 2013-10-07 20:11 - 00000000 ____D C:\Program Files (x86)\Microsoft WSE
2013-10-07 20:10 - 2013-10-07 20:10 - 00000196 _____ C:\Windows\DirectX.log
2013-10-07 19:58 - 2009-07-14 19:58 - 00653928 _____ C:\Windows\system32\perfh007.dat
2013-10-07 19:58 - 2009-07-14 19:58 - 00129800 _____ C:\Windows\system32\perfc007.dat
2013-10-07 19:58 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-07 19:57 - 2013-10-07 19:54 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\DAEMON Tools Lite
2013-10-07 19:57 - 2013-10-07 19:54 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2013-10-07 19:54 - 2013-10-07 19:53 - 13901152 _____ (Disc Soft Ltd) C:\Users\Enqel\Downloads\DTLite4471-0333.exe
2013-10-07 19:54 - 2013-08-31 04:43 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\OpenCandy
2013-10-07 19:27 - 2013-10-07 19:27 - 00000000 ____D C:\Users\Enqel\Desktop\mi
2013-10-07 19:16 - 2013-05-18 01:28 - 00000000 ____D C:\Windows.old.000
2013-10-07 19:07 - 2013-08-19 08:13 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-10-07 19:07 - 2013-05-18 01:10 - 00000000 ___RD C:\Users\Enqel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-07 19:06 - 2013-10-04 21:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-07 18:46 - 2013-09-01 19:19 - 00000000 ____D C:\Windows\system32\appmgmt
2013-10-05 23:13 - 2013-10-05 23:13 - 00000000 ____D C:\ProgramData\Protexis
2013-10-05 16:27 - 2013-10-05 16:27 - 00000000 ____D C:\Users\Enqel\AppData\Local\Blizzard Entertainment
2013-10-05 15:27 - 2013-05-18 13:17 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-10-05 13:18 - 2013-10-05 13:18 - 00003400 _____ C:\Windows\System32\Tasks\{936088AA-2254-48E5-8F31-3BFEBD3DC00A}
2013-10-05 13:16 - 2013-10-05 13:16 - 00003412 _____ C:\Windows\System32\Tasks\{DBDF3408-E571-4AAA-A8A0-F4B849415196}
2013-10-05 13:15 - 2013-08-06 21:34 - 00000000 ____D C:\Program Files (x86)\Jasc Software Inc
2013-10-05 13:07 - 2013-10-05 13:06 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Repplop
2013-10-05 01:01 - 2013-10-04 19:02 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\BabSolution
2013-10-04 21:48 - 2013-09-24 18:27 - 00000000 ____D C:\Users\Enqel\AppData\Local\Apple Computer
2013-10-04 21:43 - 2013-09-05 00:23 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Onytvi
2013-10-04 21:31 - 2013-09-24 18:11 - 00000000 ____D C:\Users\Enqel\AppData\Local\Apple
2013-10-04 19:00 - 2013-10-04 19:00 - 00168760 _____ (Firseria ) C:\Users\Enqel\Downloads\iTunes.exe
2013-10-04 17:59 - 2013-10-04 17:58 - 03682968 _____ ( ) C:\Users\Enqel\Downloads\UsenetNLSetup[84316EC1-05EA-3A2F-0C2D146F89F3F202].exe
2013-10-04 17:58 - 2013-10-04 17:58 - 03682968 _____ ( ) C:\Users\Enqel\Downloads\UsenetNLSetup[84313CFA-0913-4A3C-634901DCF9861D37].exe
2013-10-04 14:32 - 2013-09-21 00:43 - 00000000 ____D C:\Program Files (x86)\WebConnect
2013-10-03 20:52 - 2013-09-12 15:26 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-10-03 18:54 - 2013-10-03 18:51 - 00000000 ____D C:\ProgramData\Protexis64
2013-10-03 18:51 - 2013-10-03 18:51 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Corel
2013-10-03 18:47 - 2013-10-03 18:47 - 249069560 _____ (Acresso Software Inc.) C:\Users\Enqel\Downloads\PSPX6_TBYB30.exe
2013-10-03 18:28 - 2013-08-31 04:05 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\DVDVideoSoft
2013-10-03 18:23 - 2013-09-02 14:04 - 00000056 __RSH C:\Windows\SysWOW64\C908648B09.sys
2013-10-03 18:23 - 2013-09-02 13:57 - 00000000 ____D C:\Users\Enqel\Documents\My PSP Files
2013-10-03 18:23 - 2013-08-06 21:34 - 00003558 ___SH C:\Windows\SysWOW64\KGyGaAvL.sys
2013-10-03 15:34 - 2013-10-03 15:34 - 390585629 _____ C:\Windows\MEMORY.DMP
2013-10-03 15:34 - 2013-10-03 15:34 - 01262744 _____ C:\Windows\Minidump\100313-24882-01.dmp
2013-10-03 15:34 - 2013-08-08 15:50 - 00000000 ____D C:\Windows\Minidump
2013-10-01 23:22 - 2013-10-01 23:22 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\Downloaded Installations
2013-10-01 23:21 - 2013-10-01 23:21 - 01453920 _____ (Solid State Networks) C:\Users\Enqel\Downloads\nitro_pdf_pro_64_dlm.exe
2013-10-01 23:08 - 2013-10-01 23:07 - 39469712 _____ C:\Users\Enqel\Downloads\PdfEditor_64bit.exe
2013-10-01 22:51 - 2013-10-01 22:51 - 00000000 ____D C:\Users\Enqel\AppData\Local\PDF24
2013-10-01 22:49 - 2013-10-01 22:49 - 15911976 _____ (Geek Software GmbH ) C:\Users\Enqel\Downloads\pdf24-creator-5.7.0.exe
2013-10-01 21:01 - 2013-10-01 21:01 - 00014200 _____ C:\Users\Enqel\Downloads\miscellaneous_geschirrspuler-nordrhein-westfalen_nordrhein-westfalen-nw.kml
2013-09-30 18:06 - 2013-09-30 17:34 - 00000000 ____D C:\Users\Enqel\AppData\Local\IM
2013-09-30 17:35 - 2013-09-30 17:35 - 00000000 ____D C:\ProgramData\Photo Notifier and Animation Creator
2013-09-30 17:35 - 2013-09-30 17:35 - 00000000 ____D C:\Program Files (x86)\Photo Notifier and Animation Creator
2013-09-30 17:35 - 2013-09-30 17:34 - 00000000 ____D C:\ProgramData\IM
2013-09-30 17:34 - 2013-09-30 17:34 - 00000000 ____D C:\ProgramData\IncrediMail
2013-09-30 17:34 - 2013-09-30 17:34 - 00000000 ____D C:\Program Files (x86)\IncrediMail
2013-09-30 14:34 - 2009-07-14 06:45 - 00376144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-30 11:01 - 2013-10-08 19:25 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-09-30 11:01 - 2013-10-08 19:25 - 00105856 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-09-30 11:01 - 2013-10-08 19:25 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-09-30 11:01 - 2013-10-08 19:25 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-09-29 23:01 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-09-29 20:34 - 2013-09-19 18:02 - 00000000 ____D C:\Users\Enqel\AppData\Local\Canon Easy-PhotoPrint EX
2013-09-29 20:30 - 2013-05-18 01:41 - 00092608 _____ C:\Users\Enqel\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-29 18:09 - 2013-09-29 18:09 - 00000400 _____ C:\Windows\ODBC.INI
2013-09-29 18:08 - 2009-07-14 20:18 - 00000000 ____D C:\Windows\ShellNew
2013-09-29 18:08 - 2009-07-14 04:34 - 00000499 _____ C:\Windows\win.ini
2013-09-29 18:07 - 2013-08-30 13:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-09-29 18:06 - 2013-09-29 18:06 - 00000000 ____D C:\Windows\PCHEALTH
2013-09-29 18:05 - 2013-05-18 01:10 - 00000000 ____D C:\Users\Enqel\AppData\Local\VirtualStore
2013-09-29 18:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2013-09-26 20:54 - 2013-09-26 20:54 - 00000000 _____ C:\end
2013-09-25 23:24 - 2013-09-25 23:23 - 01269936 _____ C:\Windows\Minidump\092513-73648-01.dmp
2013-09-24 18:26 - 2013-09-24 18:26 - 00000000 ____D C:\ProgramData\Apple Computer
2013-09-24 18:11 - 2013-09-24 18:10 - 00000000 ____D C:\ProgramData\Apple
2013-09-23 20:16 - 2013-09-23 20:16 - 01653360 _____ C:\Windows\Minidump\092313-18610-01.dmp
2013-09-23 14:26 - 2013-09-23 14:26 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\File Scout
2013-09-21 21:50 - 2013-09-21 21:50 - 01653808 _____ C:\Windows\Minidump\092113-32588-01.dmp
2013-09-21 02:20 - 2013-09-21 00:43 - 00000000 ____D C:\Users\Enqel\AppData\Local\JDownloader v2.0
2013-09-21 02:19 - 2013-09-21 02:19 - 00000000 ____D C:\Users\Enqel\.appwork
2013-09-21 02:19 - 2013-05-18 01:08 - 00000000 ____D C:\Users\Enqel
2013-09-19 18:01 - 2013-09-19 18:01 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX
2013-09-19 17:47 - 2013-09-19 17:47 - 00000000 ____D C:\Users\Enqel\AppData\Local\Wajam
2013-09-12 16:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-12 15:42 - 2013-09-12 15:42 - 00000000 ___HD C:\ProgramData\CanonIJSolutionMenu
2013-09-12 15:29 - 2013-09-12 15:29 - 00000000 ____D C:\Users\Enqel\AppData\Roaming\CD-LabelPrint
2013-09-12 15:26 - 2013-09-12 15:26 - 00000000 ___HD C:\ProgramData\CanonIJMyPrinter
2013-09-12 15:26 - 2013-09-12 15:14 - 00000000 ____D C:\Program Files (x86)\Canon
2013-09-12 15:17 - 2013-09-12 15:17 - 00000000 ____D C:\Program Files\Canon
2013-09-12 14:39 - 2013-05-18 01:10 - 00000000 ___RD C:\Users\Enqel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
Some content of TEMP:
====================
C:\Users\Enqel\AppData\Local\Temp\appshat-distribution.exe
C:\Users\Enqel\AppData\Local\Temp\avgnt.exe
C:\Users\Enqel\AppData\Local\Temp\BackupSetup.exe
C:\Users\Enqel\AppData\Local\Temp\bi_cleaner.exe
C:\Users\Enqel\AppData\Local\Temp\EADF4BC.exe
C:\Users\Enqel\AppData\Local\Temp\Installer.exe
C:\Users\Enqel\AppData\Local\Temp\MoviesToolbarSetup_Somoto.exe
C:\Users\Enqel\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Enqel\AppData\Local\Temp\nitro_pro8_x64.exe
C:\Users\Enqel\AppData\Local\Temp\OpenCL.dll
C:\Users\Enqel\AppData\Local\Temp\OptimizerPro.exe
C:\Users\Enqel\AppData\Local\Temp\pricepeep_130001_0101.exe
C:\Users\Enqel\AppData\Local\Temp\proxy_vole6444957357995825916.dll
C:\Users\Enqel\AppData\Local\Temp\RegClean.exe
C:\Users\Enqel\AppData\Local\Temp\setup_fsu_cid.exe
C:\Users\Enqel\AppData\Local\Temp\uninst1.exe
C:\Users\Enqel\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Enqel\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\Enqel\AppData\Local\Temp\wajam_download.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-01 01:01
==================== End Of Log ============================ --- --- ---
--- --- ---FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013
Ran by Enqel at 2013-10-09 00:02:02
Running from C:\Users\Enqel\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
Avira Free Antivirus (x32 Version: 14.0.0.383)
Canon Easy-WebPrint EX (x32 Version: 1.3.5.0)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32)
Canon iP4700 series Benutzerregistrierung (x32)
Canon iP4700 series Printer Driver
Canon Utilities Easy-PhotoPrint EX (x32)
Canon Utilities My Printer (x32)
Canon Utilities Solution Menu (x32)
CD-LabelPrint (x32)
Compatibility Pack for the 2007 Office system (x32 Version: 12.0.6514.5001)
Google Chrome (x32 Version: 30.0.1599.69)
Google Update Helper (x32 Version: 1.3.21.165)
IncrediMail (x32 Version: 6.6.0.5282)
IncrediMail 2.5 (x32 Version: 6.6.0.5282)
Jasc Paint Shop Pro 9 (x32 Version: 9.00.0000)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Office Professional Edition 2003 (x32 Version: 11.0.6361.0)
Microsoft Office Word Viewer 2003 (x32 Version: 11.0.8173.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0)
Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1)
Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1)
MSVC80_x64_v2 (Version: 1.0.3.0)
MSVC80_x86_v2 (x32 Version: 1.0.3.0)
MSVC90_x64 (Version: 1.0.1.2)
MSVC90_x86 (x32 Version: 1.0.1.2)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Photo Notifier and Animation Creator (x32 Version: 1.0.0.1009)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
WebConnect 3.0.0 (Version: 3.0.0)
Windows 7 USB/DVD Download Tool (x32 Version: 1.0.30)
Windows Movie Maker 2.0 (x32 Version: 2.0.0000)
Windows Utils (x32)
WinRAR 4.00 (64-Bit) (Version: 4.00.0)
World of Warcraft (x32 Version: 5.4.0.17399)
==================== Restore Points =========================
08-10-2013 14:42:54 Installiert The Sims 3
08-10-2013 14:58:55 Installiert The Sims 3
08-10-2013 15:12:41 Entfernt The Sims 3
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {074958FD-6910-4DFF-9DEC-96C6114AAE24} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08] (Adobe Systems Incorporated)
Task: {55DD7B09-FD1A-4B70-9FF1-06C7AC1C37F1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-08] (Google Inc.)
Task: {D79C796B-F62E-401F-B63B-893BF7B7BF12} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-08] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-10-08 19:25 - 2013-09-30 11:01 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2013-09-30 17:34 - 2013-09-30 17:34 - 00033128 _____ () C:\Program Files (x86)\IncrediMail\Bin\IMHttpComm.dll
2013-09-30 17:34 - 2013-09-30 17:34 - 00072104 _____ () C:\Program Files (x86)\IncrediMail\Bin\wlessfp1.dll
2013-09-30 17:34 - 2013-09-30 17:34 - 00272808 _____ () C:\Program Files (x86)\IncrediMail\Bin\ImLookExU.dll
2013-09-30 17:34 - 2013-09-30 17:34 - 00080296 _____ () C:\Program Files (x86)\IncrediMail\bin\ImAppRU.dll
2013-09-30 17:34 - 2013-09-30 17:34 - 00133544 _____ () C:\Program Files (x86)\IncrediMail\Bin\ImComUtlU.dll
2013-10-08 17:50 - 2013-10-03 08:02 - 00698832 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\libglesv2.dll
2013-10-08 17:50 - 2013-10-03 08:02 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\libegl.dll
2013-10-08 17:50 - 2013-10-03 08:03 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll
2013-10-08 17:50 - 2013-10-03 08:03 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll
2013-10-08 17:50 - 2013-10-03 08:02 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: PCI-Kommunikationscontroller (einfach)
Description: PCI-Kommunikationscontroller (einfach)
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Serieller PCI-Anschluss
Description: Serieller PCI-Anschluss
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Paralleler PCI-Anschluss
Description: Paralleler PCI-Anschluss
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Serieller PCI-Anschluss
Description: Serieller PCI-Anschluss
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/08/2013 00:51:03 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: MsiExec.exe, Version: 5.0.7601.17514, Zeitstempel: 0x4ce792c4
Name des fehlerhaften Moduls: QuickTime.qts_unloaded, Version: 0.0.0.0, Zeitstempel: 0x5180f322
Ausnahmecode: 0xc0000005
Fehleroffset: 0x687fcc49
ID des fehlerhaften Prozesses: 0x1104
Startzeit der fehlerhaften Anwendung: 0xMsiExec.exe0
Pfad der fehlerhaften Anwendung: MsiExec.exe1
Pfad des fehlerhaften Moduls: MsiExec.exe2
Berichtskennung: MsiExec.exe3
Error: (10/08/2013 04:53:50 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: TuneUpUtilitiesService64.exe, Version: 13.0.3000.132, Zeitstempel: 0x50b779bd
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000004e4e4
ID des fehlerhaften Prozesses: 0x6a4
Startzeit der fehlerhaften Anwendung: 0xTuneUpUtilitiesService64.exe0
Pfad der fehlerhaften Anwendung: TuneUpUtilitiesService64.exe1
Pfad des fehlerhaften Moduls: TuneUpUtilitiesService64.exe2
Berichtskennung: TuneUpUtilitiesService64.exe3
Error: (10/07/2013 09:48:45 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: TS3W.exe, Version: 0.2.0.188, Zeitstempel: 0x5109c1bd
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6195, Zeitstempel: 0x4dcddbf3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001510c
ID des fehlerhaften Prozesses: 0xb60
Startzeit der fehlerhaften Anwendung: 0xTS3W.exe0
Pfad der fehlerhaften Anwendung: TS3W.exe1
Pfad des fehlerhaften Moduls: TS3W.exe2
Berichtskennung: TS3W.exe3
Error: (10/07/2013 09:47:22 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: TS3W.exe, Version: 0.2.0.188, Zeitstempel: 0x5109c1bd
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6195, Zeitstempel: 0x4dcddbf3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001510c
ID des fehlerhaften Prozesses: 0x1938
Startzeit der fehlerhaften Anwendung: 0xTS3W.exe0
Pfad der fehlerhaften Anwendung: TS3W.exe1
Pfad des fehlerhaften Moduls: TS3W.exe2
Berichtskennung: TS3W.exe3
Error: (10/07/2013 09:46:40 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: TS3W.exe, Version: 0.2.0.188, Zeitstempel: 0x5109c1bd
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6195, Zeitstempel: 0x4dcddbf3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001510c
ID des fehlerhaften Prozesses: 0x1a64
Startzeit der fehlerhaften Anwendung: 0xTS3W.exe0
Pfad der fehlerhaften Anwendung: TS3W.exe1
Pfad des fehlerhaften Moduls: TS3W.exe2
Berichtskennung: TS3W.exe3
Error: (10/07/2013 09:46:14 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: TS3W.exe, Version: 0.2.0.188, Zeitstempel: 0x5109c1bd
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6195, Zeitstempel: 0x4dcddbf3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001510c
ID des fehlerhaften Prozesses: 0xfe4
Startzeit der fehlerhaften Anwendung: 0xTS3W.exe0
Pfad der fehlerhaften Anwendung: TS3W.exe1
Pfad des fehlerhaften Moduls: TS3W.exe2
Berichtskennung: TS3W.exe3
Error: (10/07/2013 09:00:59 PM) (Source: Windows Installer 3.1) (User: )
Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar.
Error: (10/07/2013 08:06:55 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (10/07/2013 08:06:54 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (10/07/2013 08:00:51 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
System errors:
=============
Error: (10/08/2013 07:33:18 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Volumeschattenkopie" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (10/08/2013 07:33:18 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Volumeschattenkopie erreicht.
Error: (10/08/2013 07:33:18 PM) (Source: DCOM) (User: )
Description: 1053VSS{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}
Error: (10/08/2013 06:48:59 PM) (Source: BROWSER) (User: )
Description: Das Einlesen der Sicherungsliste durch den Suchdienst schlug auf Transport "\Device\NetBT_Tcpip_{2D3A601D-1D2A-4EEC-9EDC-25FD5F32816F}" zu oft fehl.
Der Sicherungssuchdienst wird beendet.
Error: (10/08/2013 06:32:31 PM) (Source: BROWSER) (User: )
Description: Das Einlesen der Sicherungsliste durch den Suchdienst schlug auf Transport "\Device\NetBT_Tcpip_{2D3A601D-1D2A-4EEC-9EDC-25FD5F32816F}" zu oft fehl.
Der Sicherungssuchdienst wird beendet.
Error: (10/07/2013 07:16:22 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error: (10/07/2013 06:57:43 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Apple Mobile Device" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (10/07/2013 06:57:43 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Apple Mobile Device erreicht.
Error: (10/07/2013 06:37:45 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error: (10/07/2013 06:18:55 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Microsoft Office Sessions:
=========================
Error: (10/08/2013 00:51:03 PM) (Source: Application Error)(User: )
Description: MsiExec.exe5.0.7601.175144ce792c4QuickTime.qts_unloaded0.0.0.05180f322c0000005687fcc49110401cec41447a94de9C:\Windows\syswow64\MsiExec.exeQuickTime.qts8662052f-3007-11e3-9c43-00241d0b681e
Error: (10/08/2013 04:53:50 AM) (Source: Application Error)(User: )
Description: TuneUpUtilitiesService64.exe13.0.3000.13250b779bdntdll.dll6.1.7601.1822951fb164ac0000005000000000004e4e46a401cec3b81274677fC:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exeC:\Windows\SYSTEM32\ntdll.dlldbcf1ecf-2fc4-11e3-93af-00241d0b681e
Error: (10/07/2013 09:48:45 PM) (Source: Application Error)(User: )
Description: TS3W.exe0.2.0.1885109c1bdMSVCR80.dll8.0.50727.61954dcddbf3c00000050001510cb6001cec39638b280c0C:\Program Files (x86)\Electronic Arts\Die Sims 3\Game\Bin\TS3W.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll79990920-2f89-11e3-9c58-00241d0b681e
Error: (10/07/2013 09:47:22 PM) (Source: Application Error)(User: )
Description: TS3W.exe0.2.0.1885109c1bdMSVCR80.dll8.0.50727.61954dcddbf3c00000050001510c193801cec39606e99b4cC:\Program Files (x86)\Electronic Arts\Die Sims 3\Game\Bin\TS3W.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll47cb60eb-2f89-11e3-9c58-00241d0b681e
Error: (10/07/2013 09:46:40 PM) (Source: Application Error)(User: )
Description: TS3W.exe0.2.0.1885109c1bdMSVCR80.dll8.0.50727.61954dcddbf3c00000050001510c1a6401cec395ede924c1C:\Program Files (x86)\Electronic Arts\Die Sims 3\Game\Bin\TS3W.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll2f01aa07-2f89-11e3-9c58-00241d0b681e
Error: (10/07/2013 09:46:14 PM) (Source: Application Error)(User: )
Description: TS3W.exe0.2.0.1885109c1bdMSVCR80.dll8.0.50727.61954dcddbf3c00000050001510cfe401cec395dc6d8cb5C:\Program Files (x86)\Electronic Arts\Die Sims 3\Game\Bin\TS3W.exeC:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll1fae5139-2f89-11e3-9c58-00241d0b681e
Error: (10/07/2013 09:00:59 PM) (Source: Windows Installer 3.1)(User: )
Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar.
Error: (10/07/2013 08:06:55 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\MFC80U.DLL
Error: (10/07/2013 08:06:54 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\MFC80U.DLL
Error: (10/07/2013 08:00:51 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\MFC80U.DLL
==================== Memory info ===========================
Percentage of memory in use: 37%
Total physical RAM: 3551.11 MB
Available physical RAM: 2222.62 MB
Total Pagefile: 7100.4 MB
Available Pagefile: 5438.49 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:149.04 GB) (Free:46.87 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (NEU) (CDROM) (Total:1.65 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: DC48DC48)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)
==================== End Of Log ============================ --- --- --- |