musicrespect | 02.12.2013 10:32 | FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2013
Ran by Christian (administrator) on RECHENKNECHT on 02-12-2013 00:05:05
Running from C:\Users\Christian\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(CrypKey (Canada) Ltd.) C:\Windows\System32\Crypserv.exe
(Hewlett-Packard Development Company, L.P) C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(ArcSoft, Inc.) C:\Windows\system\uArcCapture.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dropbox, Inc.) C:\Users\Christian\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Portrait Displays, Inc) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [489472 2013-02-23] (IDT, Inc.)
HKLM\...\Run: [HPPowerAssistant] - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2945080 2011-09-12] (Hewlett-Packard Company)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2013-11-27] (Hewlett-Packard)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
HKCU\...\Runonce: [Uninstall C:\Users\Christian\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] - C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Christian\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
HKCU\...\Policies\Explorer: []
MountPoints2: D - D:\LGAutoRun.exe
MountPoints2: {abc1089e-0efd-11e3-9582-e02a8290144c} - D:\LGAutoRun.exe
MountPoints2: {fcac42e5-a2dd-11e2-a738-e02a8290144c} - D:\Startme.exe
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [File Sanitizer] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe [11265536 2009-12-12] (Hewlett-Packard)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-05] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [334240 2012-09-12] (Hewlett-Packard Company)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Christian\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\thunderbird.lnk
ShortcutTarget: thunderbird.lnk -> C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM/10
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Object Browser - {11111111-1111-1111-1111-110311281150} - C:\Program Files (x86)\Object Browser\Object Browser-bho64.dll No File
BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
BHO-x32: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default
FF user.js: detected! => C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\user.js
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Object Browser - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\Extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com
FF Extension: DownloadHelper - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: firebug - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\Extensions\firebug@software.joehewitt.com.xpi
FF Extension: firepicker - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\Extensions\firepicker@thedarkone.xpi
FF Extension: newtabgoogle - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\Extensions\newtabgoogle@graememcc.co.uk.xpi
FF Extension: rainbow - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\Extensions\rainbow@colors.org.xpi
FF Extension: searchdictcc - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\Extensions\searchdictcc@roughael.xpi
FF Extension: searchy - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\Extensions\searchy@searchy.xpi
FF Extension: prefs - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
FF Extension: Adblock Plus - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\vkxsdwof.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
R2 Crypkey License; C:\Windows\System32\crypserv.exe [122880 2007-05-23] (CrypKey (Canada) Ltd.)
R3 DEBridge; C:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [704512 2010-02-01] (McAfee, Inc.)
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [462160 2010-07-16] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [362040 2009-11-17] (Hewlett-Packard Ltd)
R2 HP ProtectTools Service; C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [32768 2010-10-19] (Hewlett-Packard Development Company, L.P)
R2 HpFkCryptService; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [281192 2010-02-01] (McAfee, Inc.)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [523680 2012-09-12] (Hewlett-Packard Company)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 uArcCapture; C:\windows\system\uArcCapture.exe [506472 2009-12-04] (ArcSoft, Inc.)
S2 TcSysSrv; C:\TwinCAT\TCATSysSrv.exe [x]
==================== Drivers (Whitelisted) ====================
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2013-04-18] (Google Inc)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 AndNetDiag2; C:\Windows\System32\DRIVERS\lgandnetdiag264.sys [29696 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93696 2013-04-23] (LG Electronics Inc.)
R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [32640 2009-12-04] (ArcSoft, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106904 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [40760 2009-10-21] (Hewlett-Packard Development Company L.P.)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R1 NetworkX; C:\Windows\system32\ckldrv.sys [27904 2007-05-17] ()
R1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [58184 2010-02-01] (McAfee, Inc.)
R1 RsvLock; C:\Windows\SysWow64\Drivers\RsvLock.sys [40088 2010-02-01] (McAfee, Inc.)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [89216 2009-12-22] (Realtek Semiconductor Corp.)
R0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [56648 2010-02-01] ()
R0 SafeBoot; C:\Windows\SysWow64\Drivers\SafeBoot.sys [110520 2010-02-01] (McAfee, Inc.)
R0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2009-06-04] (McAfee, Inc.)
R0 SbAlg; C:\Windows\SysWow64\Drivers\SbAlg.sys [51800 2010-02-01] (McAfee, Inc.)
R0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15688 2010-02-01] (McAfee, Inc.)
R0 SbFsLock; C:\Windows\SysWow64\Drivers\SbFsLock.sys [13256 2010-02-01] (McAfee, Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-02 00:05 - 2013-12-02 00:06 - 00020038 _____ C:\Users\Christian\Downloads\FRST.txt
2013-12-02 00:04 - 2013-12-02 00:04 - 01959184 _____ (Farbar) C:\Users\Christian\Downloads\FRST64.exe
2013-12-02 00:04 - 2013-12-02 00:04 - 00000000 ____D C:\FRST
2013-12-02 00:02 - 2013-12-02 00:02 - 00000480 _____ C:\Users\Christian\Downloads\defogger_disable.log
2013-12-02 00:02 - 2013-12-02 00:02 - 00000000 _____ C:\Users\Christian\defogger_reenable
2013-12-02 00:01 - 2013-12-02 00:01 - 00050477 _____ C:\Users\Christian\Downloads\Defogger.exe
2013-12-01 23:17 - 2013-12-01 23:17 - 00012872 _____ (SurfRight B.V.) C:\windows\system32\bootdelete.exe
2013-12-01 18:53 - 2013-12-01 23:18 - 00000000 ____D C:\ProgramData\HitmanPro
2013-12-01 18:51 - 2013-12-01 18:53 - 10264904 _____ (SurfRight B.V.) C:\Users\Christian\Downloads\hitmanpro_x64.exe
2013-12-01 18:41 - 2013-12-01 18:41 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 18:41 - 2013-12-01 18:41 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Malwarebytes
2013-12-01 18:41 - 2013-12-01 18:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 18:40 - 2013-12-01 18:41 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 18:40 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-12-01 18:39 - 2013-12-01 18:40 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Christian\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-23 12:16 - 2013-11-23 12:16 - 00000000 ____D C:\Users\Christian\AppData\Roaming\EurekaLab s.a.s
2013-11-23 12:01 - 2013-11-23 12:15 - 00000000 ____D C:\Users\Christian\AppData\Roaming\LevelCheck_2013
2013-11-21 20:12 - 2013-11-21 20:12 - 00000000 ____D C:\Users\Christian\Downloads\EASE Akustiksimulation
2013-11-21 15:25 - 2013-11-21 15:26 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AFMG
2013-11-21 15:24 - 2013-12-01 23:20 - 00002108 _____ C:\windows\error.log
2013-11-21 15:24 - 2013-11-21 15:26 - 00000000 ____D C:\Program Files (x86)\AFMG
2013-11-21 15:24 - 2013-11-21 15:25 - 00000000 ____D C:\Users\Christian\AppData\Local\AFMG
2013-11-21 15:24 - 2013-11-21 15:24 - 00000074 _____ C:\windows\Crypkey.ini
2013-11-21 15:24 - 2013-11-21 15:24 - 00000000 ____D C:\Users\Christian\Documents\AFMG
2013-11-21 15:24 - 2007-05-23 19:29 - 00122880 _____ (CrypKey (Canada) Ltd.) C:\windows\system32\Crypserv.exe
2013-11-21 15:24 - 2007-05-17 23:01 - 00027904 _____ C:\windows\system32\Ckldrv.sys
2013-11-21 15:24 - 1999-06-18 22:49 - 00165888 _____ (Kenonic Controls) C:\windows\Ckconfig.exe
2013-11-21 15:24 - 1996-05-03 18:21 - 00027648 ____R C:\windows\Setup_ck.exe
2013-11-21 15:24 - 1996-05-03 16:36 - 00018432 _____ C:\windows\Setup_ck.dll
2013-11-21 15:24 - 1995-07-04 19:33 - 00011776 _____ C:\windows\Ckrfresh.exe
2013-11-21 15:21 - 2013-11-21 15:25 - 00000000 ____D C:\Users\Public\Documents\EASE40Data
2013-11-21 15:21 - 2013-11-21 15:21 - 00001995 _____ C:\Users\Public\Desktop\EASE 4.3.lnk
2013-11-21 15:21 - 2013-11-21 15:21 - 00000042 _____ C:\windows\EASE40.DIR
2013-11-21 15:21 - 2013-11-21 15:21 - 00000040 _____ C:\windows\EASELIC.DIR
2013-11-21 15:21 - 2013-11-21 15:21 - 00000040 _____ C:\windows\EASE40.UID
2013-11-21 15:21 - 2013-11-21 15:21 - 00000000 ____D C:\ProgramData\AFMG
2013-11-21 15:21 - 2013-11-21 15:21 - 00000000 ____D C:\Program Files (x86)\EASE 4.3
2013-11-21 15:21 - 2002-04-16 00:36 - 00237568 _____ (Acudata) C:\windows\SysWOW64\SlsApi.dll
2013-11-21 15:21 - 1998-10-15 17:51 - 00136192 ____R (Desaware) C:\windows\SysWOW64\DWSPY32.DLL
2013-11-21 15:21 - 1998-10-09 13:02 - 00075776 ____R (Desaware Inc.) C:\windows\SysWOW64\DWSPY36.DLL
2013-11-21 15:21 - 1997-07-31 09:01 - 00019968 _____ C:\windows\SysWOW64\cpuinf32.dll
2013-11-21 15:21 - 1996-08-24 11:11 - 00004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\RSRC32.DLL
2013-11-21 15:21 - 1996-08-24 11:11 - 00001312 _____ (Microsoft Corporation) C:\windows\SysWOW64\RSRC16.DLL
2013-11-21 15:18 - 2013-11-21 15:18 - 00889416 _____ (Microsoft Corporation) C:\Users\Christian\Downloads\dotNetFx40_Full_setup.exe
2013-11-20 17:12 - 2013-11-20 17:12 - 00015599 _____ C:\Users\Christian\AppData\Local\recently-used.xbel
2013-11-20 15:34 - 2013-11-20 15:34 - 00000000 ____D C:\Din
2013-11-20 13:32 - 2013-11-20 13:32 - 464969671 _____ C:\windows\MEMORY.DMP
2013-11-20 13:32 - 2013-11-20 13:32 - 00274888 _____ C:\windows\Minidump\112013-18189-01.dmp
2013-11-20 00:08 - 2013-11-20 17:45 - 00000000 ____D C:\Users\Christian\Downloads\Website erstellen mit WordPress
2013-11-16 17:19 - 2013-11-19 22:59 - 00000000 ____D C:\Users\Christian\AppData\Local\Thunderbird
2013-11-16 17:19 - 2013-11-16 17:19 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Thunderbird
2013-11-16 17:17 - 2013-11-21 15:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-11-16 16:41 - 2013-11-16 16:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-16 08:53 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-11-16 08:53 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-11-16 08:53 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-11-16 08:53 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-11-16 08:53 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-11-16 08:53 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-11-16 08:53 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-11-16 08:53 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-11-16 08:53 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-11-16 08:53 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-11-16 08:53 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-11-16 08:53 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-11-16 08:53 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-11-16 08:53 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-11-16 08:53 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-11-16 08:53 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-11-16 08:53 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-11-16 08:53 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-11-16 08:53 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-11-16 08:53 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-11-16 08:53 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-11-16 08:53 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-16 08:52 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-11-16 08:52 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-11-16 08:52 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-11-16 08:52 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-11-16 08:52 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-11-16 08:52 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-11-16 08:52 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-11-16 08:52 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-11-16 08:52 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-11-12 21:44 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-11-12 21:44 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2013-11-12 21:39 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2013-11-12 21:39 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2013-11-12 21:39 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2013-11-12 21:39 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-12 21:39 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2013-11-12 21:39 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\credui.dll
2013-11-12 21:39 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2013-11-12 21:39 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2013-11-12 21:39 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2013-11-12 21:39 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2013-11-12 21:39 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2013-11-12 21:39 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2013-11-12 21:39 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2013-11-12 21:39 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2013-11-12 21:39 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2013-11-12 21:39 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2013-11-12 21:39 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2013-11-12 21:39 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2013-11-12 21:39 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2013-11-12 21:39 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2013-11-12 21:39 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2013-11-12 21:23 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2013-11-12 21:23 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2013-11-12 21:23 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2013-11-12 21:23 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2013-11-12 21:23 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2013-11-12 21:23 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2013-11-12 21:23 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2013-11-12 21:08 - 2013-11-29 18:15 - 00000348 _____ C:\windows\Tasks\HPCeeScheduleForChristian.job
2013-11-12 21:08 - 2013-11-29 02:50 - 00003210 _____ C:\windows\System32\Tasks\HPCeeScheduleForChristian
2013-11-07 21:03 - 2013-11-07 21:09 - 00000000 ____D C:\Users\Christian\Desktop\Speicherkarte Backup
2013-11-04 12:41 - 2013-12-01 21:25 - 00234920 _____ C:\windows\PFRO.log
2013-11-03 18:04 - 2013-11-03 18:04 - 00007617 _____ C:\Users\Christian\AppData\Local\Resmon.ResmonCfg
2013-11-03 11:21 - 2013-12-01 23:20 - 00004924 _____ C:\windows\setupact.log
2013-11-03 11:21 - 2013-11-03 11:21 - 00000000 _____ C:\windows\setuperr.log
2013-11-02 21:26 - 2013-11-02 21:26 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft VideoCacheView
2013-11-02 21:26 - 2013-11-02 21:26 - 00000000 ____D C:\Program Files (x86)\NirSoft
2013-11-02 20:57 - 2013-11-02 21:31 - 00010576 _____ C:\Users\Christian\Documents\wsrp2013-agent.txt
2013-11-02 20:57 - 2013-11-02 21:26 - 00045732 _____ C:\Users\Christian\Documents\wsr2013.txt
2013-11-02 20:56 - 2013-11-02 20:56 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Bolide(R) Software
2013-11-02 20:21 - 2013-11-02 20:21 - 00004353 _____ C:\windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-11-02 20:21 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-02 20:21 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-11-02 20:21 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-11-02 20:21 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-11-02 19:59 - 2013-11-02 20:00 - 00000000 ____D C:\Users\Christian\Documents\My CamStudio Temp Files
2013-11-02 19:52 - 2013-11-02 20:02 - 00004535 _____ C:\Users\Christian\AppData\Roaming\CamStudio.cfg
2013-11-02 19:52 - 2013-11-02 20:01 - 00000408 _____ C:\Users\Christian\AppData\Roaming\CamShapes.ini
2013-11-02 19:52 - 2013-11-02 20:01 - 00000408 _____ C:\Users\Christian\AppData\Roaming\CamLayout.ini
2013-11-02 19:52 - 2013-11-02 20:01 - 00000096 _____ C:\Users\Christian\AppData\Roaming\Camdata.ini
2013-11-02 19:49 - 2013-11-02 21:45 - 00000000 ____D C:\Program Files\CamStudio 2.7
2013-11-02 19:49 - 2013-11-02 19:52 - 00000096 _____ C:\Users\Christian\AppData\Roaming\version2.xml
==================== One Month Modified Files and Folders =======
2013-12-02 00:06 - 2013-12-02 00:05 - 00020038 _____ C:\Users\Christian\Downloads\FRST.txt
2013-12-02 00:04 - 2013-12-02 00:04 - 01959184 _____ (Farbar) C:\Users\Christian\Downloads\FRST64.exe
2013-12-02 00:04 - 2013-12-02 00:04 - 00000000 ____D C:\FRST
2013-12-02 00:02 - 2013-12-02 00:02 - 00000480 _____ C:\Users\Christian\Downloads\defogger_disable.log
2013-12-02 00:02 - 2013-12-02 00:02 - 00000000 _____ C:\Users\Christian\defogger_reenable
2013-12-02 00:02 - 2013-02-22 20:05 - 00000000 ____D C:\Users\Christian
2013-12-02 00:01 - 2013-12-02 00:01 - 00050477 _____ C:\Users\Christian\Downloads\Defogger.exe
2013-12-01 23:56 - 2013-02-22 21:18 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Skype
2013-12-01 23:56 - 2013-02-22 20:29 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-12-01 23:30 - 2009-07-14 05:45 - 00020720 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-01 23:30 - 2009-07-14 05:45 - 00020720 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-01 23:26 - 2013-02-23 04:54 - 01170615 _____ C:\windows\WindowsUpdate.log
2013-12-01 23:26 - 2010-12-06 00:48 - 00698764 _____ C:\windows\system32\perfh007.dat
2013-12-01 23:26 - 2010-12-06 00:48 - 00148788 _____ C:\windows\system32\perfc007.dat
2013-12-01 23:26 - 2009-07-14 06:13 - 01612484 _____ C:\windows\system32\PerfStringBackup.INI
2013-12-01 23:24 - 2013-02-22 21:16 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Dropbox
2013-12-01 23:21 - 2013-02-22 21:21 - 00000000 ___RD C:\Users\Christian\Dropbox
2013-12-01 23:21 - 2010-12-06 00:48 - 00000000 ____D C:\ProgramData\HPQLOG
2013-12-01 23:20 - 2013-11-21 15:24 - 00002108 _____ C:\windows\error.log
2013-12-01 23:20 - 2013-11-03 11:21 - 00004924 _____ C:\windows\setupact.log
2013-12-01 23:20 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-12-01 23:18 - 2013-12-01 18:53 - 00000000 ____D C:\ProgramData\HitmanPro
2013-12-01 23:17 - 2013-12-01 23:17 - 00012872 _____ (SurfRight B.V.) C:\windows\system32\bootdelete.exe
2013-12-01 21:25 - 2013-11-04 12:41 - 00234920 _____ C:\windows\PFRO.log
2013-12-01 21:23 - 2013-05-01 22:59 - 00000000 ____D C:\Program Files (x86)\PriceGong
2013-12-01 18:53 - 2013-12-01 18:51 - 10264904 _____ (SurfRight B.V.) C:\Users\Christian\Downloads\hitmanpro_x64.exe
2013-12-01 18:41 - 2013-12-01 18:41 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 18:41 - 2013-12-01 18:41 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Malwarebytes
2013-12-01 18:41 - 2013-12-01 18:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 18:41 - 2013-12-01 18:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 18:40 - 2013-12-01 18:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Christian\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-30 21:03 - 2013-02-22 20:55 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2013-11-30 21:02 - 2013-02-23 19:19 - 00000000 _____ C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-11-30 15:23 - 2013-02-24 19:23 - 00000257 _____ C:\windows\Brownie.ini
2013-11-29 22:47 - 2013-02-22 22:58 - 00000000 ____D C:\Users\Christian\AppData\Local\cache
2013-11-29 18:15 - 2013-11-12 21:08 - 00000348 _____ C:\windows\Tasks\HPCeeScheduleForChristian.job
2013-11-29 02:50 - 2013-11-12 21:08 - 00003210 _____ C:\windows\System32\Tasks\HPCeeScheduleForChristian
2013-11-25 23:48 - 2013-02-22 21:45 - 00000000 ____D C:\Users\Christian\AppData\Roaming\vlc
2013-11-25 12:38 - 2013-06-21 21:59 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-11-23 15:26 - 2013-02-22 20:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-23 12:16 - 2013-11-23 12:16 - 00000000 ____D C:\Users\Christian\AppData\Roaming\EurekaLab s.a.s
2013-11-23 12:15 - 2013-11-23 12:01 - 00000000 ____D C:\Users\Christian\AppData\Roaming\LevelCheck_2013
2013-11-21 20:12 - 2013-11-21 20:12 - 00000000 ____D C:\Users\Christian\Downloads\EASE Akustiksimulation
2013-11-21 15:37 - 2013-11-16 17:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-11-21 15:26 - 2013-11-21 15:25 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AFMG
2013-11-21 15:26 - 2013-11-21 15:24 - 00000000 ____D C:\Program Files (x86)\AFMG
2013-11-21 15:25 - 2013-11-21 15:24 - 00000000 ____D C:\Users\Christian\AppData\Local\AFMG
2013-11-21 15:25 - 2013-11-21 15:21 - 00000000 ____D C:\Users\Public\Documents\EASE40Data
2013-11-21 15:24 - 2013-11-21 15:24 - 00000074 _____ C:\windows\Crypkey.ini
2013-11-21 15:24 - 2013-11-21 15:24 - 00000000 ____D C:\Users\Christian\Documents\AFMG
2013-11-21 15:22 - 2010-12-06 00:43 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-11-21 15:21 - 2013-11-21 15:21 - 00001995 _____ C:\Users\Public\Desktop\EASE 4.3.lnk
2013-11-21 15:21 - 2013-11-21 15:21 - 00000042 _____ C:\windows\EASE40.DIR
2013-11-21 15:21 - 2013-11-21 15:21 - 00000040 _____ C:\windows\EASELIC.DIR
2013-11-21 15:21 - 2013-11-21 15:21 - 00000040 _____ C:\windows\EASE40.UID
2013-11-21 15:21 - 2013-11-21 15:21 - 00000000 ____D C:\ProgramData\AFMG
2013-11-21 15:21 - 2013-11-21 15:21 - 00000000 ____D C:\Program Files (x86)\EASE 4.3
2013-11-21 15:18 - 2013-11-21 15:18 - 00889416 _____ (Microsoft Corporation) C:\Users\Christian\Downloads\dotNetFx40_Full_setup.exe
2013-11-20 17:45 - 2013-11-20 00:08 - 00000000 ____D C:\Users\Christian\Downloads\Website erstellen mit WordPress
2013-11-20 17:12 - 2013-11-20 17:12 - 00015599 _____ C:\Users\Christian\AppData\Local\recently-used.xbel
2013-11-20 17:12 - 2013-03-17 11:04 - 00000000 ____D C:\Users\Christian\.gimp-2.8
2013-11-20 15:34 - 2013-11-20 15:34 - 00000000 ____D C:\Din
2013-11-20 13:32 - 2013-11-20 13:32 - 464969671 _____ C:\windows\MEMORY.DMP
2013-11-20 13:32 - 2013-11-20 13:32 - 00274888 _____ C:\windows\Minidump\112013-18189-01.dmp
2013-11-20 13:32 - 2013-04-20 18:47 - 00000000 ____D C:\windows\Minidump
2013-11-20 11:56 - 2013-02-22 20:24 - 00000000 ___RD C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-19 22:59 - 2013-11-16 17:19 - 00000000 ____D C:\Users\Christian\AppData\Local\Thunderbird
2013-11-19 14:48 - 2013-05-09 17:11 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2013-11-19 14:48 - 2013-03-31 18:12 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2013-11-19 14:48 - 2013-03-31 18:12 - 00106904 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2013-11-19 14:48 - 2013-03-31 18:12 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2013-11-16 19:29 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\NDF
2013-11-16 17:19 - 2013-11-16 17:19 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Thunderbird
2013-11-16 16:49 - 2009-07-27 16:04 - 00000000 ____D C:\windows\Panther
2013-11-16 16:41 - 2013-11-16 16:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-13 23:07 - 2013-02-22 21:06 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-13 11:42 - 2013-02-23 05:01 - 00000000 ____D C:\windows\rescache
2013-11-13 10:55 - 2013-10-08 19:25 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Audionet
2013-11-13 10:08 - 2013-07-31 13:41 - 00000000 ____D C:\windows\system32\MRT
2013-11-13 10:04 - 2013-02-25 13:03 - 82896128 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-11-07 21:09 - 2013-11-07 21:03 - 00000000 ____D C:\Users\Christian\Desktop\Speicherkarte Backup
2013-11-05 23:53 - 2013-10-02 14:39 - 00000000 ___HD C:\jexepackres
2013-11-05 23:53 - 2013-10-02 13:40 - 00000000 ____D C:\Users\Christian\REW
2013-11-05 22:21 - 2013-02-22 20:17 - 00000000 ____D C:\ProgramData\Skype
2013-11-05 02:26 - 2009-07-14 03:34 - 00000478 _____ C:\windows\win.ini
2013-11-03 18:04 - 2013-11-03 18:04 - 00007617 _____ C:\Users\Christian\AppData\Local\Resmon.ResmonCfg
2013-11-03 11:21 - 2013-11-03 11:21 - 00000000 _____ C:\windows\setuperr.log
2013-11-02 21:46 - 2013-02-26 16:58 - 00002782 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2013-11-02 21:45 - 2013-11-02 19:49 - 00000000 ____D C:\Program Files\CamStudio 2.7
2013-11-02 21:31 - 2013-11-02 20:57 - 00010576 _____ C:\Users\Christian\Documents\wsrp2013-agent.txt
2013-11-02 21:26 - 2013-11-02 21:26 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft VideoCacheView
2013-11-02 21:26 - 2013-11-02 21:26 - 00000000 ____D C:\Program Files (x86)\NirSoft
2013-11-02 21:26 - 2013-11-02 20:57 - 00045732 _____ C:\Users\Christian\Documents\wsr2013.txt
2013-11-02 20:56 - 2013-11-02 20:56 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Bolide(R) Software
2013-11-02 20:32 - 2013-09-17 13:46 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 20:21 - 2013-11-02 20:21 - 00004353 _____ C:\windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-11-02 20:21 - 2013-09-17 13:46 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-02 20:07 - 2013-05-13 21:07 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Audacity
2013-11-02 20:02 - 2013-11-02 19:52 - 00004535 _____ C:\Users\Christian\AppData\Roaming\CamStudio.cfg
2013-11-02 20:01 - 2013-11-02 19:52 - 00000408 _____ C:\Users\Christian\AppData\Roaming\CamShapes.ini
2013-11-02 20:01 - 2013-11-02 19:52 - 00000408 _____ C:\Users\Christian\AppData\Roaming\CamLayout.ini
2013-11-02 20:01 - 2013-11-02 19:52 - 00000096 _____ C:\Users\Christian\AppData\Roaming\Camdata.ini
2013-11-02 20:00 - 2013-11-02 19:59 - 00000000 ____D C:\Users\Christian\Documents\My CamStudio Temp Files
2013-11-02 19:52 - 2013-11-02 19:49 - 00000096 _____ C:\Users\Christian\AppData\Roaming\version2.xml
Files to move or delete:
====================
C:\Users\Christian\AppData\Roaming\Camdata.ini
C:\Users\Christian\AppData\Roaming\CamLayout.ini
C:\Users\Christian\AppData\Roaming\CamShapes.ini
C:\Users\Christian\x.exe
Some content of TEMP:
====================
C:\Users\Christian\AppData\Local\Temp\avgnt.exe
C:\Users\Christian\AppData\Local\Temp\HitmanPro.exe
C:\Users\Christian\AppData\Local\Temp\Kickstarter.exe
C:\Users\Christian\AppData\Local\Temp\vlc-2.1.1-win64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-01 17:44
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
ADDITION Log: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-12-2013
Ran by Christian at 2013-12-02 00:06:27
Running from C:\Users\Christian\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe AIR (x32 Version: 3.4.0.2540)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05)
AFMG Licence Manager (x32 Version: 1.0.5)
AFMG Software Prerequisites (x32 Version: 1.0.0)
Apple Application Support (x32 Version: 2.3)
ArcSoft Webcam Sharing Manager (x32 Version: 1.0.0.26)
ATI Catalyst Install Manager (Version: 3.0.778.0)
Audacity 2.0.3 (x32 Version: 2.0.3)
AutoCAD 2013 - Deutsch (German) (Version: 19.0.55.0)
AutoCAD 2013 Language Pack - Deutsch (German) (Version: 19.0.55.0)
Autodesk Content Service (x32 Version: 3.0.84.0)
Autodesk Content Service Language Pack (x32 Version: 3.0.84.0)
Autodesk Material Library 2013 (x32 Version: 3.0.13)
Autodesk Material Library Base Resolution Image Library 2013 (x32 Version: 3.0.13)
Autodesk Sync (Version: 3.5.24.0)
Avira Free Antivirus (x32 Version: 14.0.1.749)
Battlefield 2(TM) Demo (HKCU Version: 1.00.0000)
Broadcom 2070 Bluetooth 3.0 (Version: 6.3.0.5600)
Broadcom 802.11 Wireless LAN Adapter (Version: 5.60.350.6)
Brother HL-2030 (x32 Version: 1.00)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0805.358.5180)
Catalyst Control Center InstallProxy (x32 Version: 2010.0805.358.5180)
Catalyst Control Center Localization All (x32 Version: 2010.0805.358.5180)
CCC Help Chinese Standard (x32 Version: 2010.0805.0357.5180)
CCC Help Chinese Traditional (x32 Version: 2010.0805.0357.5180)
CCC Help Czech (x32 Version: 2010.0805.0357.5180)
CCC Help Danish (x32 Version: 2010.0805.0357.5180)
CCC Help Dutch (x32 Version: 2010.0805.0357.5180)
CCC Help English (x32 Version: 2010.0805.0357.5180)
CCC Help Finnish (x32 Version: 2010.0805.0357.5180)
CCC Help French (x32 Version: 2010.0805.0357.5180)
CCC Help German (x32 Version: 2010.0805.0357.5180)
CCC Help Greek (x32 Version: 2010.0805.0357.5180)
CCC Help Hungarian (x32 Version: 2010.0805.0357.5180)
CCC Help Italian (x32 Version: 2010.0805.0357.5180)
CCC Help Japanese (x32 Version: 2010.0805.0357.5180)
CCC Help Korean (x32 Version: 2010.0805.0357.5180)
CCC Help Norwegian (x32 Version: 2010.0805.0357.5180)
CCC Help Polish (x32 Version: 2010.0805.0357.5180)
CCC Help Portuguese (x32 Version: 2010.0805.0357.5180)
CCC Help Russian (x32 Version: 2010.0805.0357.5180)
CCC Help Spanish (x32 Version: 2010.0805.0357.5180)
CCC Help Swedish (x32 Version: 2010.0805.0357.5180)
CCC Help Thai (x32 Version: 2010.0805.0357.5180)
CCC Help Turkish (x32 Version: 2010.0805.0357.5180)
ccc-core-static (x32 Version: 2010.0805.358.5180)
ccc-utility64 (Version: 2010.0805.358.5180)
CCleaner (Version: 3.28)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
Device Access Manager for HP ProtectTools (Version: 5.0.1.5)
Drive Encryption for HP ProtectTools (Version: 5.0.6.0)
Drive Encryption for HP ProtectTools (x32 Version: 5.0.6.0)
Dropbox (HKCU Version: 2.0.22)
EASE 4.3 (x32)
EASE GLL Viewer (x32 Version: 1.01.12)
EASE SpeakerLab (x32 Version: 1.01.12)
EASEGUARD (x32)
EASETOOLS (x32)
Energy Star Digital Logo (x32 Version: 1.0.1)
Face Recognition for HP ProtectTools (Version: 2.02.4007)
FARO LS 1.1.406.58 (x32 Version: 4.6.58.2)
File Sanitizer For HP ProtectTools (x32 Version: 5.0.1.2)
Fotogalerie (x32 Version: 16.4.3508.0205)
Free YouTube Download version 3.2.2.426 (x32 Version: 3.2.2.426)
FreeFileSync 5.12 (x32 Version: 5.12)
FSTATIK (x32)
GIMP 2.8.4 (Version: 2.8.4)
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000)
HP 3D DriveGuard (Version: 4.0.4.1)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7)
HP Documentation (x32 Version: 1.7.0.0)
HP ESU for Microsoft Windows 7 (x32 Version: 1.1.8.1)
HP Hotkey Support (x32 Version: 4.6.11.2)
HP Power Assistant (Version: 2.0.6.0)
HP Power Data (Version: 1.0.35.187)
HP ProtectTools Security Manager (Version: 5.12.754)
HP QuickLook (Version: 3.3.1.2)
HP QuickWeb (x32 Version: 1.0.1.63)
HP Setup (x32 Version: 8.5.4371.3505)
HP SoftPaq Download Manager (x32 Version: 3.0.5.0)
HP Software Framework (x32 Version: 4.0.59.1)
HP Software Setup (x32 Version: 7.0.1.9)
HP Support Assistant (x32 Version: 7.0.39.15)
HP Webcam Driver (x32 Version: 6.1.7600.0024)
HP Wireless Assistant (Version: 4.0.6.0)
IDT Audio (x32 Version: 1.0.6300.0)
Intel(R) Management Engine Components (x32 Version: 6.0.0.1179)
Intel(R) Rapid Storage Technology (x32 Version: 9.6.0.1014)
Intel(R) Turbo Boost Technology Driver (x32 Version: 01.01.01.1007)
IrfanView (remove only) (x32 Version: 4.35)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Junk Mail filter update (x32 Version: 16.4.3508.0205)
K-Lite Codec Pack 9.7.5 (Basic) (x32 Version: 9.7.5)
LAME v3.99.3 (for Windows) (x32)
LD Calculator Lite 1.02 b1 (x32)
LG PC Suite (x32 Version: 5.3.03.20130809)
LG United Mobile Drivers (x32 Version: 3.10.1.0)
LightScribe System Software (x32 Version: 1.18.6.1)
Live 7.0.3 (x32)
LOGO!Soft Comfort V7.0 (Demo) (Version: 7.0.0.0)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Home and Business 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Outlook Connector (x32 Version: 14.0.5118.5000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (x32 Version: 14.0.5120.5000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU (Version: 8.0.52572)
Microsoft Visual Studio 2005 Tools for Applications - ENU (x32 Version: 8.0.50727.146)
Microsoft Visual Studio 2005 Tools for Applications - ENU (x32)
Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0)
Movie Maker (x32 Version: 16.4.3508.0205)
Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1)
Mozilla Maintenance Service (x32 Version: 24.1.1)
Mozilla Thunderbird 24.1.1 (x86 de) (x32 Version: 24.1.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MusicBrainz Picard (x32 Version: 1.1)
NirSoft VideoCacheView (x32)
OpenOffice.org 3.4.1 (x32 Version: 3.41.9593)
PDF24 Creator 5.7.0 (x32)
Photo Common (x32 Version: 16.4.3508.0205)
Photo Gallery (x32 Version: 16.4.3508.0205)
Pre-Boot Security for HP ProtectTools (Version: 5.0.7.1)
PriceGong 2.6.11 (x32 Version: 2.6.11)
Privacy Manager for HP ProtectTools (Version: 5.11.814)
QuickShare (x32 Version: 1.6.1.950)
QuickTime (x32 Version: 7.73.80.64)
Realtek Ethernet Controller All-In-One Windows Driver (x32 Version: 1.12.0011)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30109)
Room EQ Wizard V5 (x32)
SDK (x32 Version: 2.26.012)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (x32)
Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7 (x32 Version: 6.2.00)
Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7_2 (c:\SiLabs\MCU\CP210x\Windows_XP_S2K3_Vista_7_2) (x32 Version: 6.2.00)
Skype™ 6.10 (x32 Version: 6.10.104)
SolidWorks 2012 x64 Edition SP02 (Version: 20.120.55)
SolidWorks 2012 x64 Edition SP02 (x32 Version: 20.2.0.55)
SolidWorks 2012 x64 German Resources (Version: 20.120.55)
SolidWorks eDrawings 2012 x64 Edition SP02 (Version: 12.2.110)
Synaptics Pointing Device Driver (Version: 15.0.24.0)
TeamViewer 8 (x32 Version: 8.0.20202)
Theft Recovery (x32 Version: 5.1.0.18)
Tom Clancy's Splinter Cell (x32 Version: 1.00.000)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32)
Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32)
Validity Fingerprint Driver (Version: 4.0.15.0)
Vectorworks 2013 Hilfe (x32 Version: 1.1)
VLC media player 2.1.1 (Version: 2.1.1)
Windows 7 Default Setting (x32 Version: 1.0.1.6)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205)
Windows Live Essentials (x32 Version: 16.4.3508.0205)
Windows Live Family Safety (Version: 16.4.3508.0205)
Windows Live Family Safety (x32 Version: 16.4.3508.0205)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (x32 Version: 16.4.3508.0205)
Windows Live Mail (x32 Version: 16.4.3508.0205)
Windows Live Messenger (x32 Version: 16.4.3508.0205)
Windows Live MIME IFilter (Version: 16.4.3508.0205)
Windows Live Photo Common (x32 Version: 16.4.3508.0205)
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205)
Windows Live SOXE (x32 Version: 16.4.3508.0205)
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205)
Windows Live UX Platform (x32 Version: 16.4.3508.0205)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205)
Windows Live Writer (x32 Version: 16.4.3508.0205)
Windows Live Writer Resources (x32 Version: 16.4.3508.0205)
==================== Restore Points =========================
16-11-2013 07:52:05 Windows Update
21-11-2013 14:22:18 Installed EASEGUARD
21-11-2013 14:23:11 Installed AFMG Software Prerequisites
21-11-2013 14:24:17 Installed EASE SpeakerLab
21-11-2013 14:25:30 Installed EASE GLL Viewer
21-11-2013 14:26:20 Installed AFMG Licence Manager
22-11-2013 18:03:44 HPSF Restore Point
==================== Hosts content: ==========================
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {52960F82-B490-4840-A9B4-0B4C60170D9E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {57D76D63-3C60-46D4-8459-6DC335C3F34F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-02-25] (Piriform Ltd)
Task: {6325596A-09C1-4308-80F2-A7F16ADFDD11} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {80EB2FBB-1DC7-435B-AC6F-E9D4382D89A4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe [2013-11-27] (Microsoft)
Task: {894C8EAC-160B-4913-8762-D78B36C58C26} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\MouseKeyboardCenter.exe [2013-05-13] (Microsoft)
Task: {8A400DEF-FAB5-4D26-A0A3-B013A4BB2E03} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {9AAFD871-7D5C-41C5-94F3-F245F84136FB} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {A129E455-CDF0-4EF7-8798-46EEDF088394} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {BB2192F3-4CCA-4EB7-9682-7C79D0BD8E8C} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {BD29A7B0-08C4-4B3A-88DB-E99DAF82D0CC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {BFD004F2-4E63-45D0-AB7D-66AF5BE8972C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-04-01] (Hewlett-Packard Company)
Task: {C40532A6-037F-4C6A-A33E-715156D56366} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {FF0334B3-A36F-4B3C-940E-D79D28988E22} - System32\Tasks\HPCeeScheduleForChristian => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\HPCeeScheduleForChristian.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Loaded Modules (whitelisted) =============
2010-06-22 02:54 - 2010-06-22 02:54 - 00098304 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2010-08-05 12:57 - 2010-08-05 12:57 - 00270336 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2010-04-05 20:11 - 2010-04-05 20:11 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll
2010-04-05 20:12 - 2010-04-05 20:12 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll
2010-04-05 20:12 - 2010-04-05 20:12 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll
2011-09-12 17:02 - 2011-09-12 17:02 - 01083392 _____ () C:\Program Files\Hewlett-Packard\HP Power Assistant\System.Data.SQLite.dll
2013-03-31 18:12 - 2013-01-25 08:25 - 00397704 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2010-02-11 22:50 - 2010-02-11 22:50 - 00746256 _____ () C:\windows\system32\SUPSDK.dll
2009-11-23 18:24 - 2009-11-23 18:24 - 01412608 ____R () C:\windows\system32\LIBEAY32.dll
2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Christian\AppData\Roaming\Dropbox\bin\libcef.dll
2013-11-16 16:41 - 2013-11-16 16:41 - 03363952 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-08-15 20:40 - 2013-08-15 20:40 - 00170496 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\44bfa824a3b8a6f789fda79a2e01a8db\IsdiInterop.ni.dll
2010-12-06 00:43 - 2010-03-04 05:08 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-10-09 23:01 - 2013-10-09 23:01 - 16233864 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
2013-11-16 17:17 - 2013-11-21 15:37 - 03008624 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2013-11-16 17:17 - 2013-11-21 15:37 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2013-11-16 17:17 - 2013-11-21 15:37 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\desktop.ini:35340d435cf44cc6501a886ab2bae8c5
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (12/01/2013 07:02:59 PM) (Source: Application Hang) (User: )
Description: Programm Skype.exe, Version 6.10.0.104 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1258
Startzeit: 01ceeeb9ae1ca861
Endzeit: 210
Anwendungspfad: C:\Program Files (x86)\Skype\Phone\Skype.exe
Berichts-ID:
Error: (12/01/2013 06:49:38 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Die E/A-Schreibvorgänge können während des Schattenkopie-Erstellungszeitraums auf Volume "C:\" nicht gespeichert werden.
Der Volumeindex im Schattenkopiesatz ist 0. Fehlerdetails: Offen[0x00000000, Der Vorgang wurde erfolgreich beendet.
], Leerung[0x00000000, Der Vorgang wurde erfolgreich beendet.
], Freigabe[0x80042314, Der Schattenkopieanbieter hat beim Warten auf den Schreibvorgang auf das Volume, von dem eine Schattenkopie erstellt wird, das Zeitlimit überschritten. Ursache hierfür könnte eine durch eine Anwendung oder einen Systemdienst verursachte hohe Aktivität auf dem Volume sein. Wiederholen Sie den Vorgang später, wenn das Volume nicht so stark ausgelastet ist.
], Ausführung[0x00000000, Der Vorgang wurde erfolgreich beendet.
].
Vorgang:
Asynchroner Vorgang wird ausgeführt
Kontext:
Aktueller Status: DoSnapshotSet
Error: (12/01/2013 06:49:38 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Die Schattenkopie kann nicht zugesichert werden - Vorgang hat das Zeitlimit überschritten.
Fehlerkontext: DeviceIoControl(\\?\Volume{0d3c7c9b-7d6c-11e2-801f-806e6f6e6963} - 0000000000000130,0x0053c010,000000000033C1F0,0,000000000037C3E0,4096,[0]).
Vorgang:
Schattenkopien werden übertragen
Kontext:
Ausführungskontext: System Provider
Error: (11/30/2013 08:58:32 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: wmpnetwk.exe, Version: 12.0.7601.17514, Zeitstempel: 0x4ce7ae7f
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677
Ausnahmecode: 0x0000046b
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x1570
Startzeit der fehlerhaften Anwendung: 0xwmpnetwk.exe0
Pfad der fehlerhaften Anwendung: wmpnetwk.exe1
Pfad des fehlerhaften Moduls: wmpnetwk.exe2
Berichtskennung: wmpnetwk.exe3
Error: (11/27/2013 00:51:27 AM) (Source: MySQL) (User: )
Description: Event Scheduler: An error occurred when initializing system tables. Disabling the Event Scheduler.
Error: (11/27/2013 00:51:27 AM) (Source: MySQL) (User: )
Description: Cannot open mysql.event
Error: (11/27/2013 00:51:27 AM) (Source: MySQL) (User: )
Description: mysql.user has no `Event_priv` column at position 29
Error: (11/27/2013 00:51:27 AM) (Source: MySQL) (User: )
Description: Column count of mysql.db is wrong. Expected 22, found 20. Created with MySQL 50041, now running 50146. Please use mysql_upgrade to fix this error.
Error: (11/27/2013 00:51:27 AM) (Source: MySQL) (User: )
Description: Can't open and lock privilege tables: Table 'mysql.servers' doesn't exist
Error: (11/27/2013 00:51:27 AM) (Source: MySQL) (User: )
Description: Can't open the mysql.plugin table. Please run mysql_upgrade to create it.
System errors:
=============
Error: (12/01/2013 11:20:46 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "TwinCAT System Service" ist von folgendem Dienst abhängig: TCROUTER. Dieser Dienst ist eventuell nicht installiert.
Error: (12/01/2013 11:19:24 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows-Zeitgeber" wurde mit folgendem Fehler beendet:
%%1115
Error: (12/01/2013 11:05:05 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "TwinCAT System Service" ist von folgendem Dienst abhängig: TCROUTER. Dieser Dienst ist eventuell nicht installiert.
Error: (12/01/2013 11:00:47 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intel(R) Rapid Storage Technology" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (12/01/2013 11:00:47 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Intel(R) Rapid Storage Technology erreicht.
Error: (12/01/2013 11:00:45 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "HP Wireless Assistant Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (12/01/2013 11:00:45 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst HP Wireless Assistant Service erreicht.
Error: (12/01/2013 11:00:44 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "HP Support Assistant Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (12/01/2013 11:00:44 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst HP Support Assistant Service erreicht.
Error: (12/01/2013 11:00:43 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "HP Power Assistant Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Microsoft Office Sessions:
=========================
Error: (12/01/2013 07:02:59 PM) (Source: Application Hang)(User: )
Description: Skype.exe6.10.0.104125801ceeeb9ae1ca861210C:\Program Files (x86)\Skype\Phone\Skype.exe
Error: (12/01/2013 06:49:38 PM) (Source: VSS)(User: )
Description: C:\00x00000000, Der Vorgang wurde erfolgreich beendet.
0x00000000, Der Vorgang wurde erfolgreich beendet.
0x80042314, Der Schattenkopieanbieter hat beim Warten auf den Schreibvorgang auf das Volume, von dem eine Schattenkopie erstellt wird, das Zeitlimit überschritten. Ursache hierfür könnte eine durch eine Anwendung oder einen Systemdienst verursachte hohe Aktivität auf dem Volume sein. Wiederholen Sie den Vorgang später, wenn das Volume nicht so stark ausgelastet ist.
0x00000000, Der Vorgang wurde erfolgreich beendet.
Vorgang:
Asynchroner Vorgang wird ausgeführt
Kontext:
Aktueller Status: DoSnapshotSet
Error: (12/01/2013 06:49:38 PM) (Source: VSS)(User: )
Description: DeviceIoControl(\\?\Volume{0d3c7c9b-7d6c-11e2-801f-806e6f6e6963} - 0000000000000130,0x0053c010,000000000033C1F0,0,000000000037C3E0,4096,[0])
Vorgang:
Schattenkopien werden übertragen
Kontext:
Ausführungskontext: System Provider
Error: (11/30/2013 08:58:32 PM) (Source: Application Error)(User: )
Description: wmpnetwk.exe12.0.7601.175144ce7ae7fKERNELBASE.dll6.1.7601.1822951fb16770000046b000000000000940d157001ceedd712bab43eC:\Program Files\Windows Media Player\wmpnetwk.exeC:\windows\system32\KERNELBASE.dllc98e7155-59f9-11e3-8005-e02a8290144c
Error: (11/27/2013 00:51:27 AM) (Source: MySQL)(User: )
Description: Event Scheduler: An error occurred when initializing system tables. Disabling the Event Scheduler.
Error: (11/27/2013 00:51:27 AM) (Source: MySQL)(User: )
Description: Cannot open mysql.event
Error: (11/27/2013 00:51:27 AM) (Source: MySQL)(User: )
Description: mysql.user has no `Event_priv` column at position 29
Error: (11/27/2013 00:51:27 AM) (Source: MySQL)(User: )
Description: Column count of mysql.db is wrong. Expected 22, found 20. Created with MySQL 50041, now running 50146. Please use mysql_upgrade to fix this error.
Error: (11/27/2013 00:51:27 AM) (Source: MySQL)(User: )
Description: Can't open and lock privilege tables: Table 'mysql.servers' doesn't exist
Error: (11/27/2013 00:51:27 AM) (Source: MySQL)(User: )
Description: Can't open the mysql.plugin table. Please run mysql_upgrade to create it.
==================== Memory info ===========================
Percentage of memory in use: 65%
Total physical RAM: 3951.43 MB
Available physical RAM: 1344.32 MB
Total Pagefile: 7901.04 MB
Available Pagefile: 4227.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:280.8 GB) (Free:52.7 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.47 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 48E147D4)
Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=281 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2 GB) - (Type=0C)
==================== End Of Log ============================ GMER Log: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-12-02 00:31:15
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PC3O 298,09GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\CHRIST~1\AppData\Local\Temp\uxdcafog.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002fb1000 64 bytes [E8, 5F, 6B, 04, 80, FA, FF, ...]
INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 593 fffff80002fb1041 21 bytes [40, 6B, 04, 80, FA, FF, FF, ...]
---- User code sections - GMER 2.1 ----
.text C:\windows\system\uArcCapture.exe[2884] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 35 000000006a1911a8 2 bytes [19, 6A]
.text C:\windows\system\uArcCapture.exe[2884] C:\Windows\SysWOW64\ksuser.dll!KsCreateAllocator + 21 000000006a1913a8 2 bytes [19, 6A]
.text C:\windows\system\uArcCapture.exe[2884] C:\Windows\SysWOW64\ksuser.dll!KsCreateClock + 21 000000006a191422 2 bytes [19, 6A]
.text C:\windows\system\uArcCapture.exe[2884] C:\Windows\SysWOW64\ksuser.dll!KsCreateTopologyNode + 19 000000006a191498 2 bytes [19, 6A]
.text C:\windows\system\uArcCapture.exe[2884] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 195 000000006a981b41 2 bytes [98, 6A]
.text C:\windows\system\uArcCapture.exe[2884] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 362 000000006a981be8 2 bytes [98, 6A]
.text C:\windows\system\uArcCapture.exe[2884] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 418 000000006a981c20 2 bytes [98, 6A]
.text C:\windows\system\uArcCapture.exe[2884] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 596 000000006a981cd2 2 bytes [98, 6A]
.text C:\windows\system\uArcCapture.exe[2884] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 628 000000006a981cf2 2 bytes [98, 6A]
.text C:\Users\Christian\AppData\Roaming\Dropbox\bin\Dropbox.exe[4420] C:\windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000077d11465 2 bytes [D1, 77]
.text C:\Users\Christian\AppData\Roaming\Dropbox\bin\Dropbox.exe[4420] C:\windows\syswow64\Psapi.dll!GetModuleInformation + 155 0000000077d114bb 2 bytes [D1, 77]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4852] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077d11465 2 bytes [D1, 77]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4852] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077d114bb 2 bytes [D1, 77]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\windows\system32\svchost.exe [1420:1592] 000007fefadb8274
Thread C:\windows\system32\svchost.exe [1420:3948] 000007fefadb8274
Thread C:\windows\system32\svchost.exe [1660:1704] 000007fefa83341c
Thread C:\windows\system32\svchost.exe [1660:1712] 000007fefa833a2c
Thread C:\windows\system32\svchost.exe [1660:1716] 000007fefa835c20
Thread C:\windows\system32\svchost.exe [1660:1720] 000007fefa833768
Thread C:\windows\system32\svchost.exe [1660:2704] 000007fef974bd88
Thread C:\windows\system32\svchost.exe [1660:5708] 000007fef4315170
Thread C:\windows\system32\svchost.exe [1660:2244] 000007fef9585124
Thread C:\windows\system32\svchost.exe [1660:2664] 000007fefe6652e0
Thread C:\windows\system32\svchost.exe [1660:708] 000007fef97f5240
Thread C:\windows\System32\spoolsv.exe [1848:3708] 000007fef82e10c8
Thread C:\windows\System32\spoolsv.exe [1848:3768] 000007fef8056144
Thread C:\windows\System32\spoolsv.exe [1848:3784] 000007fef8085fd0
Thread C:\windows\System32\spoolsv.exe [1848:3796] 000007fef7e73438
Thread C:\windows\System32\spoolsv.exe [1848:3800] 000007fef80863ec
Thread C:\windows\System32\spoolsv.exe [1848:3840] 000007fef8d15e5c
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [4140:4448] 000007fef0783e0c
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [4140:4328] 000007fef0783e0c
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [4140:4684] 000007feee27c680
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [4460:5128] 000007fef0783e0c
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [4460:5216] 000007feee3d838c
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [4460:5240] 000007fef0783e0c
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [4460:5276] 000007feee27c680
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [4460:5284] 000007fef0783e0c
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\e02a8290144c
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\e02a8290144c (not active ControlSet)
---- EOF - GMER 2.1 ---- |