bei einer formatierung werde ich ja jeglichen schädling los oder muss ich selbst das mit speziellen programmen machen umsicher zu gehen?
ich frage nur weil ich schwerst davon ausgehe, dass pc1 wirklich "nur" ein prozessor problem hat.
bei pc2 gehe ich aber von schadsoftware aus, kann aber nicht sagen woher da es wie gesagt der pc meines vaters ist und dieser sich gerade im urlaub befindet. probleme gab es soweit mir bekannt ist aber zuvor keine.
bei pc2, hab ich gerade ein gpu treiber update gemacht um zu prüfen ob er dann wieder funktioniert ohne zu "freezen". mal sehen was passiert
habe hier den test am pc2 gemacht: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-11-2013 02
Ran by Philipp at 2013-11-17 19:43:26
Running from E:\erstintal
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
1310 (x32 Version: 140.0.425.000)
1310_Help (x32 Version: 82.0.58.000)
1310Trb (x32 Version: 82.0.242.000)
64 Bit HP CIO Components Installer (Version: 7.2.8)
Adobe AIR (x32 Version: 3.9.0.1030)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05)
AIO_CDB_ProductContext (x32 Version: 140.0.425.000)
AIO_CDB_Software (x32 Version: 140.0.428.000)
AIO_Scan (x32 Version: 130.0.421.000)
AMD Catalyst Install Manager (Version: 8.0.915.0)
Ashampoo AppLauncher (Medion) v.1.0.0 (x32 Version: 1.0.0)
Avira Free Antivirus (x32 Version: 13.0.0.4052)
Avira SearchFree Toolbar (x32 Version: 12.6.0.1898)
Bing Bar (x32 Version: 7.2.241.0)
BufferChm (x32 Version: 140.0.298.000)
Catalyst Control Center InstallProxy (x32 Version: 2013.1008.932.15229)
Copy (x32 Version: 140.0.298.000)
CyberLink Home Cinema (x32 Version: 1.1.7717)
CyberLink LabelPrint 2.5 (x32 Version: 2.5.5415)
CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3807_46074)
CyberLink PhotoDirector 3 (x32 Version: 3.0.3925)
CyberLink Power2Go 8 (x32 Version: 8.0.0.2426b)
CyberLink PowerDirector (Version: 9.0.0.4911)
CyberLink PowerDVD 10 (x32 Version: 10.0.5108.02)
CyberLink PowerDVD Copy 1.5 (x32 Version: 1.5.0.3725)
CyberLink PowerRecover (Version: 5.7.0.0913)
CyberLink PowerRecover (x32 Version: 5.7.0.0913)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
Destinations (x32 Version: 140.0.253.000)
DeviceDiscovery (x32 Version: 140.0.298.000)
DocProc (x32 Version: 140.0.185.000)
Document_Installer (x32 Version: 1.00.0000)
DVBT Driver (x32 Version: 1.1.3.1)
eReg (x32 Version: 1.20.138.34)
EWA net (x32)
EWA_net_Admin (x32 Version: 1.00.0000)
EWA_net_Client_Applications (x32 Version: 1.00.0000)
EWA_net_Core (x32 Version: 1.00.0000)
EWA_net_EPC (x32 Version: 1.00.0000)
EWA_net_Server (x32 Version: 1.00.0000)
EWA_net_WIS (x32 Version: 1.00.0000)
EWA_net_WIS_CaseOnline_Importer (x32 Version: 1.00.0000)
Fax (x32 Version: 140.0.307.000)
Fotogalerie (x32 Version: 16.4.3505.0912)
Fotogalerija (x32 Version: 16.4.3505.0912)
Fotogalleri (x32 Version: 16.4.3505.0912)
Fotogalleriet (x32 Version: 16.4.3505.0912)
Fotoğraf Galerisi (x32 Version: 16.4.3505.0912)
Fotótár (x32 Version: 16.4.3505.0912)
Galeria de Fotografias (x32 Version: 16.4.3505.0912)
Galería de fotos (x32 Version: 16.4.3505.0912)
Galeria fotografii (x32 Version: 16.4.3505.0912)
Galerie de photos (x32 Version: 16.4.3505.0912)
Google Earth (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
GPBaseService2 (x32 Version: 140.0.297.000)
HP Customer Participation Program 14.0 (Version: 14.0)
HP IDF Software (x32 Version: 11.15.1000)
HP Imaging Device Functions 14.0 (Version: 14.0)
HP Photosmart Officejet and Deskjet All-In-One Driver Software (Version: 14.0)
HP Solution Center 14.0 (Version: 14.0)
HP Update (x32 Version: 5.002.006.003)
HPPhotoGadget (x32 Version: 140.0.524.000)
HPProductAssistant (x32 Version: 140.0.298.000)
HPSSupply (x32 Version: 140.0.297.000)
League of Legends (x32 Version: 3.0.1)
Logitech SetPoint 6.61 (Version: 6.61.15)
MarketResearch (x32 Version: 140.0.299.000)
Mediathek (x32 Version: 1.4.0)
Medion Home Cinema 10 (x32 Version: 10.0)
Medion Home Cinema 10 (x32 Version: 10.2419)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office (x32 Version: 15.0.4454.1510)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (x32 Version: 11.0.50727.1)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (x32 Version: 11.0.50727.1)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727)
Movie Maker (x32 Version: 16.4.3505.0912)
Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1)
Mozilla Maintenance Service (x32 Version: 25.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
Network64 (Version: 140.0.306.000)
OCR Software by I.R.I.S. 14.0 (Version: 14.0)
Photo Common (x32 Version: 16.4.3505.0912)
Photo Gallery (x32 Version: 16.4.3505.0912)
Podstawowe programy Windows Live (x32 Version: 16.4.3505.0912)
Raccolta foto (x32 Version: 16.4.3505.0912)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6777)
Scan (x32 Version: 140.0.253.000)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32)
Shop for HP Supplies (Version: 14.0)
SolutionCenter (x32 Version: 140.0.299.000)
Status (x32 Version: 140.0.342.000)
Toolbox (x32 Version: 140.0.596.000)
TrayApp (x32 Version: 140.0.297.000)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32)
Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32)
Valokuvavalikoima (x32 Version: 16.4.3505.0912)
WebReg (x32 Version: 140.0.297.017)
Windows Live (x32 Version: 16.4.3505.0912)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912)
Windows Live Essentials (x32 Version: 16.4.3505.0912)
Windows Live Installer (x32 Version: 16.4.3505.0912)
Windows Live Photo Common (x32 Version: 16.4.3505.0912)
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912)
Windows Live SOXE (x32 Version: 16.4.3505.0912)
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912)
Windows Live Temel Parçalar (x32 Version: 16.4.3505.0912)
Windows Live UX Platform (x32 Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912)
Windows Liven peruspaketti (x32 Version: 16.4.3505.0912)
WinRAR 5.00 (64-bit) (Version: 5.00.0)
Συλλογή φωτογραφιών (x32 Version: 16.4.3505.0912)
==================== Restore Points =========================
04-11-2013 10:11:14 Windows Update
06-11-2013 19:53:40 Windows Modules Installer
09-11-2013 14:33:57 Microsoft Visual C++ 2005 Redistributable (x64) wird installiert
14-11-2013 15:31:42 Windows Update
17-11-2013 16:23:35 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
17-11-2013 16:24:02 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
==================== Hosts content: ==========================
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {333F9219-0B58-41DF-A6EC-7E59B6B65403} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-27] (Google Inc.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\System32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4A531460-4C8A-4F40-B339-AEBB984611D2} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {676F633D-723A-412A-BFF2-088E4AF419C5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-27] (Google Inc.)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => C:\Windows\System32\AppXDeploymentClient.dll [2013-09-30] (Microsoft Corporation)
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {AE95C9E4-DA30-4DD7-88A6-BF2A871F1CD1} - System32\Tasks\DealPly => C:\Users\Josef\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe [2013-04-23] ()
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {E166EE0D-0151-43FC-8CF3-FF7D90695214} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2013-08-22] (Microsoft Corporation)
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {F7791105-100D-4A29-B1E4-1D2CEBC37529} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\System32\MRT.exe [2013-11-07] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-09-29 09:34 - 2013-09-29 09:32 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Josef\SkyDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: Fax
Description: Lokale Druckwarteschlange
Class Guid: {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
Manufacturer: Microsoft
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: An OneNote 2010 senden
Description: Lokale Druckwarteschlange
Class Guid: {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/17/2013 07:40:47 PM) (Source: EWA net Server) (User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/17/2013 05:32:02 PM) (Source: EWA net Server) (User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/17/2013 05:20:54 PM) (Source: EWA net Server) (User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/17/2013 05:18:22 PM) (Source: .NET Runtime) (User: )
Description: Anwendung: CLI.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
bei System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(System.Object, System.Object[], System.Object[])
bei System.Reflection.RuntimeMethodInfo.Invoke(System.Object, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
bei System.RuntimeType.InvokeMember(System.String, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object, System.Object[], System.Reflection.ParameterModifier[], System.Globalization.CultureInfo, System.String[])
bei ATI.ACE.CLI.EXE.CLI.Main(System.String[])
Error: (11/17/2013 05:16:24 PM) (Source: EWA net Server) (User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/17/2013 05:07:07 PM) (Source: .NET Runtime) (User: )
Description: Anwendung: MOM.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
bei System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(System.Object, System.Object[], System.Object[])
bei System.Reflection.RuntimeMethodInfo.Invoke(System.Object, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
bei System.RuntimeType.InvokeMember(System.String, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object, System.Object[], System.Reflection.ParameterModifier[], System.Globalization.CultureInfo, System.String[])
bei ATI.ACE.MOM.EXE.MOM.Main(System.String[])
Error: (11/17/2013 05:04:43 PM) (Source: EWA net Server) (User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/17/2013 04:51:45 PM) (Source: EWA net Server) (User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/16/2013 10:36:46 PM) (Source: .NET Runtime) (User: )
Description: Anwendung: MOM.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
bei System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(System.Object, System.Object[], System.Object[])
bei System.Reflection.RuntimeMethodInfo.Invoke(System.Object, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
bei System.RuntimeType.InvokeMember(System.String, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object, System.Object[], System.Reflection.ParameterModifier[], System.Globalization.CultureInfo, System.String[])
bei ATI.ACE.MOM.EXE.MOM.Main(System.String[])
Error: (11/16/2013 10:18:02 PM) (Source: EWA net Server) (User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
System errors:
=============
Error: (11/17/2013 07:43:39 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (11/17/2013 07:41:39 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}
Error: (11/17/2013 07:41:38 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}
Error: (11/17/2013 07:41:38 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}
Error: (11/17/2013 07:41:36 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}
Error: (11/17/2013 07:41:36 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}
Error: (11/17/2013 07:41:36 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}
Error: (11/17/2013 07:41:04 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}
Error: (11/17/2013 07:41:04 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}
Error: (11/17/2013 07:41:02 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}
Microsoft Office Sessions:
=========================
Error: (11/17/2013 07:40:47 PM) (Source: EWA net Server)(User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/17/2013 05:32:02 PM) (Source: EWA net Server)(User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/17/2013 05:20:54 PM) (Source: EWA net Server)(User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/17/2013 05:18:22 PM) (Source: .NET Runtime)(User: )
Description: Anwendung: CLI.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
bei System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(System.Object, System.Object[], System.Object[])
bei System.Reflection.RuntimeMethodInfo.Invoke(System.Object, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
bei System.RuntimeType.InvokeMember(System.String, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object, System.Object[], System.Reflection.ParameterModifier[], System.Globalization.CultureInfo, System.String[])
bei ATI.ACE.CLI.EXE.CLI.Main(System.String[])
Error: (11/17/2013 05:16:24 PM) (Source: EWA net Server)(User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/17/2013 05:07:07 PM) (Source: .NET Runtime)(User: )
Description: Anwendung: MOM.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
bei System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(System.Object, System.Object[], System.Object[])
bei System.Reflection.RuntimeMethodInfo.Invoke(System.Object, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
bei System.RuntimeType.InvokeMember(System.String, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object, System.Object[], System.Reflection.ParameterModifier[], System.Globalization.CultureInfo, System.String[])
bei ATI.ACE.MOM.EXE.MOM.Main(System.String[])
Error: (11/17/2013 05:04:43 PM) (Source: EWA net Server)(User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/17/2013 04:51:45 PM) (Source: EWA net Server)(User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
Error: (11/16/2013 10:36:46 PM) (Source: .NET Runtime)(User: )
Description: Anwendung: MOM.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
bei System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(System.Object, System.Object[], System.Object[])
bei System.Reflection.RuntimeMethodInfo.Invoke(System.Object, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
bei System.RuntimeType.InvokeMember(System.String, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object, System.Object[], System.Reflection.ParameterModifier[], System.Globalization.CultureInfo, System.String[])
bei ATI.ACE.MOM.EXE.MOM.Main(System.String[])
Error: (11/16/2013 10:18:02 PM) (Source: EWA net Server)(User: )
Description: The Java Virtual Machine has exited with a code of 1, the service is being stopped.
==================== Memory info ===========================
Percentage of memory in use: 35%
Total physical RAM: 3542.76 MB
Available physical RAM: 2295.88 MB
Total Pagefile: 4182.76 MB
Available Pagefile: 2756.71 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:869.46 GB) (Free:744.69 GB) NTFS
Drive d: (Recover) (Fixed) (Total:60 GB) (Free:41.97 GB) NTFS
Drive e: (KINGSTON) (Removable) (Total:14.88 GB) (Free:0.11 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 00000000)
Partition: GPT Partition Type
========================================================
Disk: 2 (Size: 15 GB) (Disk ID: 5F966045)
Partition 1: (Active) - (Size=15 GB) - (Type=0B)
==================== End Of Log ============================
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-11-2013 02
Ran by Philipp (administrator) on GÖRNY on 17-11-2013 19:42:25
Running from E:\erstintal
Windows 8.1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\WINDOWS\system32\atiesrxx.exe
(AMD) C:\WINDOWS\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
(Transaction Software, D 81737 Munich) C:\Program Files (x86)\EWA net\database\TransBase EWA\tbmux32.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Transaction Software, D 81737 Munich) C:\Program Files (x86)\EWA net\database\TransBase EPC\tbmux32.exe
(Transaction Software, D 81737 Munich) C:\Program Files (x86)\EWA net\database\TransBase WIS\tbmux32.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\svchost.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Microsoft Corporation) C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_fa1dc1539b4180d8\TiWorker.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13219984 2012-11-07] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.)
Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1
MountPoints2: {e42e40f2-49f1-11e3-bea6-d43d7e6caba0} - "E:\pushinst.exe"
HKLM-x32\...\Run: [CLMLServer_For_P2G8] - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [110144 2013-03-05] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [492248 2012-12-26] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-11] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-29] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-10-23] (APN)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
Startup: C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
ShortcutTarget: Logitech . Produktregistrierung.lnk -> C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
SearchScopes: HKCU - {F8A7760F-2711-4182-80CF-B27EA5860E2F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\6hy44hka.default
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: HP Detect - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\6hy44hka.default\Extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}
FF HKLM-x32\...\Firefox\Extensions: [OKitSpace@Vittalia.es] - C:\Users\Josef\AppData\Roaming\okitspace\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-29] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-29] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [815160 2013-09-29] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [74712 2013-03-11] (CyberLink)
R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [316376 2013-03-11] (CyberLink)
R2 EWA net DB Core; C:\Program Files (x86)\EWA net\database\TransBase EWA\tbmux32.exe [176128 2003-11-05] (Transaction Software, D 81737 Munich)
R2 EWA net DB EPC; C:\Program Files (x86)\EWA net\database\TransBase EPC\tbmux32.exe [176128 2003-11-05] (Transaction Software, D 81737 Munich)
R2 EWA net DB WIS; C:\Program Files (x86)\EWA net\database\TransBase WIS\tbmux32.exe [176128 2003-11-05] (Transaction Software, D 81737 Munich)
S2 EWA net Server; C:\Program Files (x86)\EWA net\server\bin\tomcat.exe [65536 2003-07-31] (Alexandria Software Consulting)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2010-08-19] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-17] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-29] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132088 2013-09-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-09-29] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [82136 2013-09-29] (Avira Operations GmbH & Co. KG)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-09-30] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1975000 2013-07-31] (Realtek Semiconductor Corporation )
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146272 2013-08-22] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [56672 2013-08-22] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-17 19:42 - 2013-11-17 19:42 - 00000000 ____D C:\FRST
2013-11-17 17:25 - 2013-11-17 17:25 - 00066765 _____ C:\WINDOWS\SysWOW64\CCCInstall_201311171725577425.log
2013-11-17 17:25 - 2013-11-17 17:25 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-11-17 17:23 - 2013-11-17 17:25 - 00000000 ____D C:\Program Files\ATI Technologies
2013-11-17 17:23 - 2013-11-17 17:24 - 00000000 ____D C:\ProgramData\Package Cache
2013-11-17 17:22 - 2013-11-17 17:22 - 00000000 ____D C:\AMD
2013-11-17 16:52 - 2013-11-17 16:52 - 104695876 _____ C:\WINDOWS\SysWOW64\֞枣LĆ
2013-11-16 23:27 - 2013-11-16 23:27 - 104637397 _____ C:\WINDOWS\SysWOW64\稲ⷅL‘
2013-11-15 19:11 - 2013-11-15 19:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-15 18:01 - 2013-11-15 18:01 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\HpUpdate
2013-11-15 17:45 - 2013-11-16 17:27 - 104559818 _____ C:\WINDOWS\SysWOW64\迭쇾L—
2013-11-14 16:00 - 2013-10-19 09:08 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-14 16:00 - 2013-10-19 07:37 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-11-14 16:00 - 2013-10-19 07:02 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-14 16:00 - 2013-10-19 06:37 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2013-11-14 16:00 - 2013-10-19 06:19 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-14 16:00 - 2013-10-19 06:10 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-14 16:00 - 2013-10-19 05:52 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-11-14 16:00 - 2013-10-19 05:44 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-11-14 16:00 - 2013-10-19 05:37 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-14 16:00 - 2013-10-19 05:31 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-11-14 16:00 - 2013-10-19 04:56 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-11-14 16:00 - 2013-10-19 04:55 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-11-14 16:00 - 2013-10-19 04:53 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-14 16:00 - 2013-10-19 04:23 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-14 16:00 - 2013-10-19 04:09 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-11-14 16:00 - 2013-10-19 04:02 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-11-14 16:00 - 2013-10-13 03:48 - 00136536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2013-11-14 16:00 - 2013-10-12 22:48 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2013-11-14 16:00 - 2013-10-12 22:34 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2013-11-14 16:00 - 2013-10-05 15:21 - 01341288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2013-11-14 16:00 - 2013-10-05 09:39 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2013-11-14 15:59 - 2013-11-14 15:59 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2013-11-14 15:59 - 2013-11-14 15:59 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2013-11-14 15:59 - 2013-10-16 16:58 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2013-11-14 15:59 - 2013-10-16 14:54 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2013-11-12 19:11 - 2013-11-12 19:11 - 00000000 ____D C:\Users\Philipp\Downloads\Screenshots
2013-11-12 16:09 - 2013-11-12 16:09 - 00002028 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2013-11-12 16:08 - 2013-11-12 16:09 - 06110144 _____ C:\Users\Philipp\Downloads\HPPSdr.exe
2013-11-12 16:05 - 2013-11-12 16:05 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2013-11-12 13:45 - 2013-11-12 13:45 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\HP
2013-11-12 12:55 - 2013-11-12 13:24 - 432790328 _____ C:\Users\Philipp\Downloads\AIO_CDB_NonNet_Full_Win_WW_140_408.exe
2013-11-10 19:28 - 2013-11-10 19:28 - 00000000 ____D C:\Users\Josef\AppData\Roaming\Logitech
2013-11-10 12:05 - 2013-11-12 15:11 - 00018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
2013-11-10 12:05 - 2013-11-12 15:11 - 00000576 _____ C:\WINDOWS\LkmdfCoInst.log
2013-11-10 12:05 - 2013-11-10 12:05 - 00000000 ____D C:\Users\Public\Documents\Logishrd
2013-11-10 12:05 - 2013-11-10 12:05 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Leadertech
2013-11-10 12:04 - 2013-11-10 12:05 - 00006540 _____ C:\WINDOWS\LDPINST.LOG
2013-11-10 12:04 - 2013-11-10 12:05 - 00000000 ____D C:\ProgramData\Logishrd
2013-11-10 12:04 - 2013-11-10 12:05 - 00000000 ____D C:\Program Files\Common Files\Logishrd
2013-11-10 12:04 - 2013-11-10 12:04 - 00000000 ____D C:\Program Files\Logitech
2013-11-10 12:02 - 2013-11-10 12:05 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Logitech
2013-11-10 12:02 - 2013-11-10 12:02 - 03672832 _____ (Logitech Inc.) C:\Users\Philipp\Downloads\setpoint6.61.15_smart.exe
2013-11-10 12:02 - 2013-11-10 12:02 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Logishrd
2013-11-10 11:30 - 2013-11-10 11:30 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\LolClient
2013-11-09 20:15 - 2013-11-09 20:15 - 00001714 _____ C:\Users\Public\Desktop\Play League of Legends.lnk
2013-11-09 20:14 - 2013-11-09 20:14 - 00000000 ____D C:\Users\Philipp\AppData\Local\Adobe
2013-11-09 20:14 - 2013-11-09 20:14 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-11-09 20:14 - 2013-11-09 20:14 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-11-09 20:13 - 2013-11-09 20:14 - 18080872 _____ (Adobe Systems Inc.) C:\Users\Philipp\Downloads\AdobeAIRInstaller.exe
2013-11-09 15:35 - 2013-11-17 17:35 - 00000000 ____D C:\Users\Philipp\Downloads\RADS
2013-11-09 15:35 - 2013-11-09 20:15 - 00000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2013-11-09 15:35 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2013-11-09 15:35 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2013-11-09 15:35 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2013-11-09 15:35 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2013-11-09 15:35 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2013-11-09 15:33 - 2013-11-09 15:33 - 00000000 ____D C:\Program Files (x86)\Pando Networks
2013-11-09 11:48 - 2013-11-09 15:33 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Riot Games
2013-11-09 11:47 - 2013-11-09 11:48 - 34888568 _____ (Riot Games) C:\Users\Philipp\Downloads\LeagueofLegends_EUW_Installer_06_12_13.exe
2013-11-06 20:54 - 2013-11-06 21:01 - 00000000 ___RD C:\WINDOWS\BrowserChoice
2013-11-04 11:00 - 2013-11-04 11:00 - 00001454 _____ C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-04 10:59 - 2013-11-09 15:32 - 00000660 __RSH C:\Users\Philipp\ntuser.pol
2013-11-04 10:59 - 2013-11-04 10:59 - 00000020 ___SH C:\Users\Philipp\ntuser.ini
2013-11-01 18:33 - 2013-11-12 20:43 - 00000000 __RDO C:\Users\Josef\SkyDrive
2013-11-01 18:30 - 2013-11-01 18:30 - 00001454 _____ C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-01 18:30 - 2013-11-01 18:30 - 00000656 __RSH C:\Users\Josef\ntuser.pol
2013-11-01 18:30 - 2013-11-01 18:30 - 00000020 ___SH C:\Users\Josef\ntuser.ini
2013-11-01 14:14 - 2013-11-17 19:42 - 01994371 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Programme
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\ProgramData\Vorlagen
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\ProgramData\Startmenü
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\ProgramData\Dokumente
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Dokumente und Einstellungen
2013-11-01 14:13 - 2013-11-01 14:13 - 00022960 _____ C:\WINDOWS\system32\emptyregdb.dat
2013-11-01 14:03 - 2013-11-01 14:03 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-11-01 14:03 - 2013-11-01 14:03 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-11-01 13:59 - 2013-11-01 13:59 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2013-11-01 13:58 - 2013-11-17 17:32 - 00000000 ____D C:\Users\Philipp
2013-11-01 13:58 - 2013-11-01 18:33 - 00000000 ____D C:\Users\Josef
2013-11-01 13:58 - 2013-11-01 14:13 - 00036198 _____ C:\WINDOWS\diagwrn.xml
2013-11-01 13:58 - 2013-11-01 14:13 - 00036198 _____ C:\WINDOWS\diagerr.xml
2013-11-01 13:58 - 2013-11-01 13:59 - 00000000 ___RD C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-01 13:58 - 2013-11-01 13:59 - 00000000 ___RD C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Vorlagen
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Startmenü
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Netzwerkumgebung
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Lokale Einstellungen
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Eigene Dateien
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Druckumgebung
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Documents\Eigene Musik
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Documents\Eigene Bilder
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\AppData\Local\Verlauf
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\AppData\Local\Anwendungsdaten
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Anwendungsdaten
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Vorlagen
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Startmenü
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Netzwerkumgebung
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Lokale Einstellungen
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Eigene Dateien
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Druckumgebung
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Documents\Eigene Musik
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Documents\Eigene Bilder
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\AppData\Local\Verlauf
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\AppData\Local\Anwendungsdaten
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Anwendungsdaten
2013-11-01 13:58 - 2013-08-22 16:36 - 00000000 ___RD C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-01 13:58 - 2013-08-22 16:36 - 00000000 ___RD C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-01 13:58 - 2013-08-22 16:36 - 00000000 ___RD C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-01 13:58 - 2013-08-22 16:36 - 00000000 ___RD C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-01 13:58 - 2013-08-22 16:36 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-01 13:58 - 2013-08-22 16:36 - 00000000 ____D C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 ____D C:\Program Files\Realtek
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 ____D C:\Program Files\AMD
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2013-11-01 13:52 - 2013-11-01 18:30 - 00000000 ___DC C:\WINDOWS\Panther
2013-11-01 13:52 - 2013-11-01 13:52 - 00000000 __SHD C:\Recovery
2013-11-01 13:51 - 2013-11-01 13:51 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2013-11-01 13:51 - 2013-11-01 13:51 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 02144768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 01537880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-11-01 13:50 - 2013-11-01 13:50 - 01286552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 01018960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00977408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00837120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00698880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-11-01 13:50 - 2013-11-01 13:50 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-11-01 13:50 - 2013-11-01 13:50 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-01 13:48 - 2013-11-01 14:06 - 00000000 ____D C:\Program Files (x86)\MSBuild
2013-11-01 13:48 - 2013-11-01 14:02 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2013-11-01 13:48 - 2013-11-01 13:48 - 00000000 ____D C:\Program Files\Reference Assemblies
2013-11-01 13:48 - 2013-11-01 13:48 - 00000000 ____D C:\Program Files\MSBuild
2013-11-01 13:48 - 2013-11-01 13:48 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2013-11-01 13:48 - 2013-08-03 05:48 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2013-11-01 13:48 - 2013-08-03 05:48 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2013-11-01 13:48 - 2013-08-03 05:48 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2013-11-01 13:48 - 2013-08-03 05:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2013-11-01 13:48 - 2013-08-03 05:41 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-11-01 13:48 - 2013-08-03 05:41 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2013-11-01 13:17 - 2013-11-01 14:13 - 00006611 _____ C:\WINDOWS\comsetup.log
2013-10-31 11:48 - 2013-11-09 20:14 - 00000000 ____D C:\ProgramData\Adobe
2013-10-31 11:48 - 2013-11-09 20:14 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-10-31 11:47 - 2013-10-31 11:53 - 00000000 ____D C:\Users\Josef\AppData\Local\Adobe
2013-10-24 16:35 - 2013-10-31 11:26 - 104264581 _____ C:\WINDOWS\SysWOW64\Àn
==================== One Month Modified Files and Folders =======
2013-11-17 19:42 - 2013-11-17 19:42 - 00000000 ____D C:\FRST
2013-11-17 19:42 - 2013-11-01 14:14 - 01994371 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-17 19:41 - 2013-09-27 19:07 - 00001116 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-17 19:40 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-17 17:38 - 2013-09-29 13:37 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-769679036-298574570-2757043422-1003
2013-11-17 17:35 - 2013-11-09 15:35 - 00000000 ____D C:\Users\Philipp\Downloads\RADS
2013-11-17 17:32 - 2013-11-01 13:58 - 00000000 ____D C:\Users\Philipp
2013-11-17 17:25 - 2013-11-17 17:25 - 00066765 _____ C:\WINDOWS\SysWOW64\CCCInstall_201311171725577425.log
2013-11-17 17:25 - 2013-11-17 17:25 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-11-17 17:25 - 2013-11-17 17:23 - 00000000 ____D C:\Program Files\ATI Technologies
2013-11-17 17:25 - 2013-08-22 15:46 - 00327860 _____ C:\WINDOWS\setupact.log
2013-11-17 17:25 - 2013-04-04 13:05 - 00000000 ____D C:\ProgramData\AMD
2013-11-17 17:24 - 2013-11-17 17:23 - 00000000 ____D C:\ProgramData\Package Cache
2013-11-17 17:23 - 2013-09-30 05:14 - 00005426 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-11-17 17:23 - 2013-09-30 04:56 - 00778714 _____ C:\WINDOWS\system32\perfh007.dat
2013-11-17 17:23 - 2013-09-30 04:56 - 00163510 _____ C:\WINDOWS\system32\perfc007.dat
2013-11-17 17:22 - 2013-11-17 17:22 - 00000000 ____D C:\AMD
2013-11-17 17:18 - 2013-09-27 19:07 - 00001120 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-17 16:52 - 2013-11-17 16:52 - 104695876 _____ C:\WINDOWS\SysWOW64\֞枣LĆ
2013-11-17 16:41 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru
2013-11-16 23:27 - 2013-11-16 23:27 - 104637397 _____ C:\WINDOWS\SysWOW64\稲ⷅL‘
2013-11-16 22:17 - 2013-09-27 16:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-16 17:27 - 2013-11-15 17:45 - 104559818 _____ C:\WINDOWS\SysWOW64\迭쇾L—
2013-11-15 19:15 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache
2013-11-15 19:11 - 2013-11-15 19:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-15 18:01 - 2013-11-15 18:01 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\HpUpdate
2013-11-14 16:35 - 2013-09-29 11:24 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-14 16:34 - 2013-09-28 20:01 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-14 15:59 - 2013-11-14 15:59 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2013-11-14 15:59 - 2013-11-14 15:59 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2013-11-12 20:43 - 2013-11-01 18:33 - 00000000 __RDO C:\Users\Josef\SkyDrive
2013-11-12 19:11 - 2013-11-12 19:11 - 00000000 ____D C:\Users\Philipp\Downloads\Screenshots
2013-11-12 16:09 - 2013-11-12 16:09 - 00002028 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2013-11-12 16:09 - 2013-11-12 16:08 - 06110144 _____ C:\Users\Philipp\Downloads\HPPSdr.exe
2013-11-12 16:09 - 2013-09-27 18:05 - 00000000 ____D C:\Program Files (x86)\HP
2013-11-12 16:05 - 2013-11-12 16:05 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2013-11-12 15:28 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2013-11-12 15:11 - 2013-11-10 12:05 - 00018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
2013-11-12 15:11 - 2013-11-10 12:05 - 00000576 _____ C:\WINDOWS\LkmdfCoInst.log
2013-11-12 14:30 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2013-11-12 13:57 - 2013-09-28 22:33 - 00000000 ___RD C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-12 13:45 - 2013-11-12 13:45 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\HP
2013-11-12 13:45 - 2013-09-27 17:58 - 00218037 _____ C:\WINDOWS\hpoins19.dat
2013-11-12 13:45 - 2013-09-27 17:58 - 00001608 _____ C:\ProgramData\hpzinstall.log
2013-11-12 13:24 - 2013-11-12 12:55 - 432790328 _____ C:\Users\Philipp\Downloads\AIO_CDB_NonNet_Full_Win_WW_140_408.exe
2013-11-11 16:48 - 2013-09-27 18:55 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-769679036-298574570-2757043422-1002
2013-11-10 19:28 - 2013-11-10 19:28 - 00000000 ____D C:\Users\Josef\AppData\Roaming\Logitech
2013-11-10 12:05 - 2013-11-10 12:05 - 00000000 ____D C:\Users\Public\Documents\Logishrd
2013-11-10 12:05 - 2013-11-10 12:05 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Leadertech
2013-11-10 12:05 - 2013-11-10 12:04 - 00006540 _____ C:\WINDOWS\LDPINST.LOG
2013-11-10 12:05 - 2013-11-10 12:04 - 00000000 ____D C:\ProgramData\Logishrd
2013-11-10 12:05 - 2013-11-10 12:04 - 00000000 ____D C:\Program Files\Common Files\Logishrd
2013-11-10 12:05 - 2013-11-10 12:02 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Logitech
2013-11-10 12:04 - 2013-11-10 12:04 - 00000000 ____D C:\Program Files\Logitech
2013-11-10 12:02 - 2013-11-10 12:02 - 03672832 _____ (Logitech Inc.) C:\Users\Philipp\Downloads\setpoint6.61.15_smart.exe
2013-11-10 12:02 - 2013-11-10 12:02 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Logishrd
2013-11-10 11:30 - 2013-11-10 11:30 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\LolClient
2013-11-10 10:28 - 2013-09-28 21:16 - 00000000 ___RD C:\Bilder1
2013-11-09 20:15 - 2013-11-09 20:15 - 00001714 _____ C:\Users\Public\Desktop\Play League of Legends.lnk
2013-11-09 20:15 - 2013-11-09 15:35 - 00000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2013-11-09 20:14 - 2013-11-09 20:14 - 00000000 ____D C:\Users\Philipp\AppData\Local\Adobe
2013-11-09 20:14 - 2013-11-09 20:14 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-11-09 20:14 - 2013-11-09 20:14 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-11-09 20:14 - 2013-11-09 20:13 - 18080872 _____ (Adobe Systems Inc.) C:\Users\Philipp\Downloads\AdobeAIRInstaller.exe
2013-11-09 20:14 - 2013-10-31 11:48 - 00000000 ____D C:\ProgramData\Adobe
2013-11-09 20:14 - 2013-10-31 11:48 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-11-09 20:14 - 2013-09-28 22:33 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Adobe
2013-11-09 19:49 - 2013-10-04 08:25 - 00000000 ____D C:\Users\Philipp\AppData\Local\Mozilla
2013-11-09 15:44 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2013-11-09 15:33 - 2013-11-09 15:33 - 00000000 ____D C:\Program Files (x86)\Pando Networks
2013-11-09 15:33 - 2013-11-09 11:48 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Riot Games
2013-11-09 15:32 - 2013-11-04 10:59 - 00000660 __RSH C:\Users\Philipp\ntuser.pol
2013-11-09 11:48 - 2013-11-09 11:47 - 34888568 _____ (Riot Games) C:\Users\Philipp\Downloads\LeagueofLegends_EUW_Installer_06_12_13.exe
2013-11-08 16:55 - 2013-09-27 16:00 - 00000000 ____D C:\Users\Josef\AppData\Local\Packages
2013-11-07 16:00 - 2013-01-07 18:56 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-06 21:01 - 2013-11-06 20:54 - 00000000 ___RD C:\WINDOWS\BrowserChoice
2013-11-06 21:01 - 2013-09-28 22:32 - 00000000 ____D C:\Users\Philipp\AppData\Local\Packages
2013-11-06 20:55 - 2013-09-29 08:04 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-11-06 20:55 - 2013-09-29 08:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-11-06 00:31 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2013-11-06 00:31 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-04 11:11 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\restore
2013-11-04 11:00 - 2013-11-04 11:00 - 00001454 _____ C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-04 11:00 - 2013-09-28 22:33 - 00000000 ___RD C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-04 10:59 - 2013-11-04 10:59 - 00000020 ___SH C:\Users\Philipp\ntuser.ini
2013-11-01 18:33 - 2013-11-01 13:58 - 00000000 ____D C:\Users\Josef
2013-11-01 18:30 - 2013-11-01 18:30 - 00001454 _____ C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-01 18:30 - 2013-11-01 18:30 - 00000656 __RSH C:\Users\Josef\ntuser.pol
2013-11-01 18:30 - 2013-11-01 18:30 - 00000020 ___SH C:\Users\Josef\ntuser.ini
2013-11-01 18:30 - 2013-11-01 13:52 - 00000000 ___DC C:\WINDOWS\Panther
2013-11-01 18:30 - 2013-09-27 16:01 - 00000000 ___RD C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-01 18:30 - 2013-09-27 16:01 - 00000000 ___RD C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Programme
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\ProgramData\Vorlagen
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\ProgramData\Startmenü
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\ProgramData\Dokumente
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2013-11-01 14:14 - 2013-11-01 14:14 - 00000000 _SHDL C:\Dokumente und Einstellungen
2013-11-01 14:14 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Windows NT
2013-11-01 14:14 - 2013-08-22 14:36 - 00000000 __RHD C:\Users\Default
2013-11-01 14:13 - 2013-11-01 14:13 - 00022960 _____ C:\WINDOWS\system32\emptyregdb.dat
2013-11-01 14:13 - 2013-11-01 13:58 - 00036198 _____ C:\WINDOWS\diagwrn.xml
2013-11-01 14:13 - 2013-11-01 13:58 - 00036198 _____ C:\WINDOWS\diagerr.xml
2013-11-01 14:13 - 2013-11-01 13:17 - 00006611 _____ C:\WINDOWS\comsetup.log
2013-11-01 14:13 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Registration
2013-11-01 14:09 - 2013-08-22 16:36 - 00000000 __RSD C:\WINDOWS\Media
2013-11-01 14:09 - 2013-08-22 16:36 - 00000000 __RHD C:\Users\Public\Libraries
2013-11-01 14:07 - 2013-08-22 15:44 - 00505304 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-01 14:06 - 2013-11-01 13:48 - 00000000 ____D C:\Program Files (x86)\MSBuild
2013-11-01 14:06 - 2013-09-30 04:59 - 00000000 ____D C:\WINDOWS\ShellNew
2013-11-01 14:06 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2013-11-01 14:06 - 2013-08-22 14:25 - 00008192 ___SH C:\WINDOWS\system32\config\ELAM
2013-11-01 14:06 - 2013-01-08 10:44 - 00000000 ____D C:\WINDOWS\fi
2013-11-01 14:06 - 2013-01-08 10:27 - 00000000 ____D C:\WINDOWS\tr
2013-11-01 14:06 - 2013-01-08 10:27 - 00000000 ____D C:\WINDOWS\sv
2013-11-01 14:06 - 2013-01-08 10:27 - 00000000 ____D C:\WINDOWS\sl
2013-11-01 14:06 - 2013-01-08 10:27 - 00000000 ____D C:\WINDOWS\pl
2013-11-01 14:06 - 2013-01-08 10:27 - 00000000 ____D C:\WINDOWS\nl
2013-11-01 14:06 - 2013-01-08 10:27 - 00000000 ____D C:\WINDOWS\it
2013-11-01 14:06 - 2013-01-08 10:27 - 00000000 ____D C:\WINDOWS\hu
2013-11-01 14:06 - 2013-01-08 10:27 - 00000000 ____D C:\WINDOWS\fr
2013-11-01 14:06 - 2013-01-08 10:27 - 00000000 ____D C:\WINDOWS\es
2013-11-01 14:06 - 2013-01-08 10:27 - 00000000 ____D C:\WINDOWS\da
2013-11-01 14:06 - 2013-01-08 10:26 - 00000000 ____D C:\WINDOWS\el
2013-11-01 14:06 - 2013-01-08 10:26 - 00000000 ____D C:\WINDOWS\de
2013-11-01 14:06 - 2012-07-26 10:43 - 00000000 ____D C:\WINDOWS\en-GB
2013-11-01 14:03 - 2013-11-01 14:03 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-11-01 14:03 - 2013-11-01 14:03 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-11-01 14:03 - 2013-08-22 16:37 - 00004893 _____ C:\WINDOWS\DtcInstall.log
2013-11-01 14:03 - 2012-07-26 06:37 - 00000000 ____D C:\Users\Default.migrated
2013-11-01 14:02 - 2013-11-01 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2013-11-01 14:02 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2013-11-01 14:02 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2013-11-01 14:02 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2013-11-01 14:02 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2013-11-01 14:02 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2013-11-01 14:02 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\system32\winrm
2013-11-01 14:02 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\system32\WCN
2013-11-01 14:02 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\system32\slmgr
2013-11-01 14:02 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2013-11-01 14:02 - 2013-09-27 18:19 - 00000000 ____D C:\WINDOWS\SysWOW64\spool
2013-11-01 14:02 - 2013-08-22 16:43 - 00000000 ____D C:\WINDOWS\DigitalLocker
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\spool
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\MUI
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\IME
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\IME
2013-11-01 14:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Help
2013-11-01 14:02 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2013-11-01 14:02 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2013-11-01 14:02 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2013-11-01 14:02 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\system32\oobe
2013-11-01 14:02 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\system32\Dism
2013-11-01 14:02 - 2013-01-07 15:54 - 00000000 ____D C:\ProgramData\PRICache
2013-11-01 14:01 - 2013-09-30 04:59 - 00000000 ____D C:\Program Files\Windows Journal
2013-11-01 14:01 - 2013-08-22 16:36 - 00000000 __SHD C:\Program Files\Windows Sidebar
2013-11-01 14:01 - 2013-08-22 16:36 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2013-11-01 14:01 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-11-01 14:01 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\System
2013-11-01 14:01 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-01 14:01 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-11-01 13:59 - 2013-11-01 13:59 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2013-11-01 13:59 - 2013-11-01 13:58 - 00000000 ___RD C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-01 13:59 - 2013-11-01 13:58 - 00000000 ___RD C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-01 13:59 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\Recovery
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Vorlagen
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Startmenü
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Netzwerkumgebung
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Lokale Einstellungen
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Eigene Dateien
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Druckumgebung
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Documents\Eigene Musik
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Documents\Eigene Bilder
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\AppData\Local\Verlauf
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\AppData\Local\Anwendungsdaten
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Philipp\Anwendungsdaten
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Vorlagen
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Startmenü
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Netzwerkumgebung
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Lokale Einstellungen
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Eigene Dateien
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Druckumgebung
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Documents\Eigene Musik
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Documents\Eigene Bilder
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\AppData\Local\Verlauf
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\AppData\Local\Anwendungsdaten
2013-11-01 13:58 - 2013-11-01 13:58 - 00000000 _SHDL C:\Users\Josef\Anwendungsdaten
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 ____D C:\Program Files\Realtek
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 ____D C:\Program Files\AMD
2013-11-01 13:54 - 2013-11-01 13:54 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2013-11-01 13:53 - 2013-09-29 20:04 - 00000800 _____ C:\WINDOWS\PFRO.log
2013-11-01 13:52 - 2013-11-01 13:52 - 00000000 __SHD C:\Recovery
2013-11-01 13:51 - 2013-11-01 13:51 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2013-11-01 13:51 - 2013-11-01 13:51 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2013-11-01 13:51 - 2013-08-22 16:36 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
2013-11-01 13:50 - 2013-11-01 13:50 - 02144768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 01537880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-11-01 13:50 - 2013-11-01 13:50 - 01286552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 01018960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00977408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00837120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00698880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-11-01 13:50 - 2013-11-01 13:50 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-11-01 13:50 - 2013-11-01 13:50 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2013-11-01 13:50 - 2013-11-01 13:50 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-01 13:50 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Camera
2013-11-01 13:48 - 2013-11-01 13:48 - 00000000 ____D C:\Program Files\Reference Assemblies
2013-11-01 13:48 - 2013-11-01 13:48 - 00000000 ____D C:\Program Files\MSBuild
2013-11-01 13:48 - 2013-11-01 13:48 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2013-11-01 13:43 - 2013-09-27 16:00 - 01560582 _____ C:\WINDOWS\WindowsUpdate (1).log
2013-11-01 12:53 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-11-01 11:33 - 2013-01-07 16:49 - 00730346 _____ C:\WINDOWS\system32\perfh00E.dat
2013-11-01 11:33 - 2013-01-07 16:49 - 00173820 _____ C:\WINDOWS\system32\perfc00E.dat
2013-10-31 11:53 - 2013-10-31 11:47 - 00000000 ____D C:\Users\Josef\AppData\Local\Adobe
2013-10-31 11:49 - 2013-09-27 16:01 - 00000000 ____D C:\Users\Josef\AppData\Roaming\Adobe
2013-10-31 11:26 - 2013-10-24 16:35 - 104264581 _____ C:\WINDOWS\SysWOW64\Àn
2013-10-27 12:12 - 2013-09-27 19:07 - 00004092 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-27 12:12 - 2013-09-27 19:07 - 00003856 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-24 16:38 - 2013-09-29 13:29 - 00067072 _____ C:\Users\Josef\Desktop\Zug.Dat.xls.xls
2013-10-19 09:08 - 2013-11-14 16:00 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-10-19 07:37 - 2013-11-14 16:00 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-10-19 07:02 - 2013-11-14 16:00 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-10-19 06:37 - 2013-11-14 16:00 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2013-10-19 06:19 - 2013-11-14 16:00 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-10-19 06:10 - 2013-11-14 16:00 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-10-19 05:52 - 2013-11-14 16:00 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-10-19 05:44 - 2013-11-14 16:00 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-10-19 05:37 - 2013-11-14 16:00 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-10-19 05:31 - 2013-11-14 16:00 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-10-19 04:56 - 2013-11-14 16:00 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-10-19 04:55 - 2013-11-14 16:00 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-10-19 04:53 - 2013-11-14 16:00 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-10-19 04:23 - 2013-11-14 16:00 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-10-19 04:09 - 2013-11-14 16:00 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-10-19 04:02 - 2013-11-14 16:00 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
Some content of TEMP:
====================
C:\Users\Philipp\AppData\Local\Temp\LMkRstPt.exe
C:\Users\Philipp\AppData\Local\Temp\swt-win32-3349.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-17 00:25
==================== End Of Log ============================ --- --- ---
--- --- --- |