OK hier sind die Logs:
FRST.txt:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-01-2014 01
Ran by Chef (administrator) on MORITZ-LAPTOP on 02-01-2014 19:39:46
Running from C:\Users\Chef\Downloads
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
() C:\Program Files\GNU\GnuPG\dirmngr.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Acronis) C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
(Acronis) C:\Program Files\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Motorola Inc.) C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
(TrueCrypt Foundation) C:\Program Files\TrueCrypt\TrueCrypt.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(Acronis) C:\Program Files\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-27] (AVAST Software)
HKLM\...\Run: [TrueImageMonitor.exe] - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [6405376 2013-03-28] (Acronis)
HKLM\...\Run: [AcronisTibMounterMonitor] - C:\Program Files\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1105848 2013-01-10] (Acronis)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [413464 2013-02-15] (Acronis)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuschd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12017368 2013-10-24] (Realtek Semiconductor)
HKLM\...\Run: [SMSERIAL] - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1458176 2009-10-26] (Motorola Inc.)
HKCU\...\Run: [HP Deskjet 3050A J611 series (NET)] - C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [1804648 2011-06-08] (Hewlett-Packard Co.)
HKCU\...\Run: [TrueCrypt] - C:\Program Files\TrueCrypt\TrueCrypt.exe [1516496 2013-11-25] (TrueCrypt Foundation)
HKCU\...\Run: [SandboxieControl] - C:\Program Files\Sandboxie\SbieCtrl.exe [543432 2013-10-16] (Sandboxie Holdings, LLC)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKCU\...\Policies\Explorer: [NoInternetOpenWith] 1
HKCU\...\Policies\Explorer: [NoRecentDocsHistory] 1
HKCU\...\Policies\Explorer: [NoRecentDocsMenu] 1
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1777021643E8CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Chef\AppData\Roaming\Mozilla\Firefox\Profiles\v55ycn86.default
FF Homepage: https://www.google.de/
FF NetworkProxy: "http", "127.0.0.1"
FF NetworkProxy: "http_port", 8118
FF NetworkProxy: "socks", "127.0.0.1"
FF NetworkProxy: "socks_port", 9050
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "127.0.0.1"
FF NetworkProxy: "ssl_port", 8118
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: HTTPS-Everywhere - C:\Users\Chef\AppData\Roaming\Mozilla\Firefox\Profiles\v55ycn86.default\Extensions\https-everywhere@eff.org
FF Extension: NoScript - C:\Users\Chef\AppData\Roaming\Mozilla\Firefox\Profiles\v55ycn86.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
========================== Services (Whitelisted) =================
R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [831360 2013-02-15] (Acronis)
R2 afcdpsrv; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [3816440 2013-11-23] (Acronis)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-27] (AVAST Software)
R2 DirMngr; C:\Program Files\GNU\GnuPG\dirmngr.exe [218112 2013-10-07] ()
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [130248 2013-10-16] (Sandboxie Holdings, LLC)
R2 syncagentsrv; C:\Program Files\Common Files\Acronis\SyncAgent\syncagentsrv.exe [7094592 2013-03-20] (Acronis)
==================== Drivers (Whitelisted) ====================
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [26112 2010-04-29] (Google Inc)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2013-12-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2013-11-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2013-11-23] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2013-12-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2013-12-27] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [64168 2013-12-27] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [180248 2013-12-27] ()
R3 BazisVirtualCDBus; C:\Windows\System32\DRIVERS\BazisVirtualCDBus.sys [117584 2011-08-08] (SysProgs.org)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2007-07-31] (ATK0100)
R3 NIWinCDEmu; C:\Windows\System32\DRIVERS\NIWinCDEmu.sys [62544 2013-12-01] ()
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [159840 2013-10-16] (Sandboxie Holdings, LLC)
S3 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [888640 2013-11-23] (Acronis International GmbH)
R0 tib; C:\Windows\System32\DRIVERS\tib.sys [736192 2013-11-23] (Acronis International GmbH)
R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [130488 2013-11-23] (Acronis)
R0 vididr; C:\Windows\System32\DRIVERS\vididr.sys [116000 2013-11-23] (Acronis International GmbH)
R0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [85280 2013-11-23] (Acronis International GmbH)
========================== Drivers MD5 =======================
C:\Windows\System32\DRIVERS\1394ohci.sys ==> MD5 is legit
C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit
C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit
C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\afcdp.sys DF139E5866C19E0B3217EF210198D875
C:\Windows\system32\drivers\afd.sys F81BB7E487EDCEAB630A7EE66CF23913
C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit
C:\Windows\system32\drivers\djsvs.sys ==> MD5 is legit
C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdagp.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdsata.sys D320BF87125326F996D4904FE24300FC
C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit
C:\Windows\System32\drivers\amdxata.sys 46387FB17B086D16DEA267D5BE23A2F2
C:\Windows\System32\Drivers\androidusb.sys DB0FEB51DFA00543BF381D2014550FA3
C:\Windows\system32\drivers\appid.sys ==> MD5 is legit
C:\Windows\system32\drivers\arc.sys ==> MD5 is legit
C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit
C:\Windows\system32\drivers\aswMonFlt.sys 6F1505608202BBD179095A6A150D103F
C:\Windows\system32\drivers\aswRdr2.sys 2206985EF126AB90F3D7F1A020589DC9
C:\Windows\System32\Drivers\aswRvrt.sys F385467DF95D0A73775CB3B076B8B969
C:\Windows\system32\drivers\aswSnx.sys 0F639D0526820BA7872C963813E0EB8D
C:\Windows\system32\drivers\aswSP.sys 7BA7543EA7936A7ADA615F6DE7C95494
C:\Windows\system32\drivers\aswStm.sys 37A6A39C1792BA961EE6172A0F3CA236
C:\Windows\System32\Drivers\aswVmm.sys 1B0662514A68C3A42E60D240C5ABEF28
C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit
C:\Windows\system32\drivers\bxvbdx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\b57nd60x.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\BazisVirtualCDBus.sys A2ECECE11639FEA1CCB66D853451F7E2
C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit
C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit
C:\Windows\System32\CLFS.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\CmBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit
C:\Windows\System32\Drivers\cng.sys 85449EEBE8F8EBD6481EFBF0F352B4EB
C:\Windows\System32\DRIVERS\compbatt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit
C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit
C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
C:\Windows\System32\drivers\disk.sys ==> MD5 is legit
C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit
C:\Windows\System32\drivers\dxgkrnl.sys 71BC35067CABC02C9453AEAA42B2E43E
C:\Windows\system32\drivers\evbdx.sys ==> MD5 is legit
C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit
C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit
C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit
C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit
C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit
C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legitB
C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\fltsrv.sys 0494CF9AA76F5A90366722AF1DD0E510
C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Fs_Rec.sys 7DAE5EBCC80E45D3253F4923DC424D05
C:\Windows\System32\DRIVERS\fvevol.sys E306A24D9694C724FA2491278BF50FDB
C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit
C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
C:\Windows\System32\drivers\HdAudio.sys A5EF29D5315111C80A5C1ABAD14C8972
C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit
C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit
C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit
C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 is legit
C:\Windows\system32\drivers\iaStorV.sys 5CD5F9A5444E6CDCB0AC89BD62D8B76E
C:\Windows\System32\DRIVERS\igdkmd32.sys 9467514EA189475A6E7FDC5D7BDE9D3F
C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit
C:\Windows\System32\drivers\RTKVHDA.sys 816EEF1A714ABF9A633F478EFAC8F24C
C:\Windows\System32\drivers\intelide.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit
C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\ksecdd.sys F286830298323272260332D6ABC905C1
C:\Windows\System32\Drivers\ksecpkg.sys D7C760D57B1656DD748B9E4AB6CB5A51
C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit
C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit
C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit
C:\Windows\System32\drivers\modem.sys ==> MD5 is legit
C:\Windows\System32\drivers\MODEMCSA.sys 25483F9D590D5F00BD951E1181453EC2
C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit
C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\mrxdav.sys 21F4B24ACFC79A483515BD986DD9043F
C:\Windows\System32\DRIVERS\mrxsmb.sys 5D16C921E3671636C0EBA3BBAAC5FD25
C:\Windows\System32\DRIVERS\mrxsmb10.sys 6D17A4791ACA19328C685D256349FEFC
C:\Windows\System32\DRIVERS\mrxsmb20.sys B81F204D146000BE76651A50670A5E9E
C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ATKACPI.sys 97AFFA9D95FFE20EEE6229BC6BE166CF
C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
C:\Windows\System32\drivers\ndis.sys 8C9C922D71F1CD4DEF73F186416B7896
C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netw5v32.sys 58218EC6B61B1169CF54AAB0D00F5FE2
C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\NIWinCDEmu.sys EA7BB4CC7C9AB8A3B70F4F696E6B3DDB
C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Ntfs.sys 5E43D2B0EE64123D4880DFA6626DEFDE
C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
C:\Windows\system32\drivers\nvraid.sys B3E25EE28883877076E0E1FF877D02E0
C:\Windows\system32\drivers\nvstor.sys 4380E59A170D88C4F1022EFF6719A8A4
C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit
C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit
C:\Windows\system32\drivers\parport.sys ==> MD5 is legit
C:\Windows\System32\drivers\partmgr.sys 3F34A1B4C5F6475F320C275E63AFCE9B
C:\Windows\system32\drivers\parvdm.sys ==> MD5 is legit
C:\Windows\System32\drivers\pci.sys ==> MD5 is legit
C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit
C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit
C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
C:\Windows\system32\drivers\processr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
C:\Windows\system32\drivers\rdpbus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpvideominiport.sys 65375DF758CA1872AB7EBBBA457FD5E6
C:\Windows\System32\Drivers\RDPWD.sys F031683E6D1FEA157ABB2FF260B51E61
C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rimmptsk.sys DF672613FBBCD58C38BB0BC2694BCFB0
C:\Windows\System32\DRIVERS\rimsptsk.sys 9BFB54D3559F2FF7301271D29D383564
C:\Windows\System32\DRIVERS\rixdptsk.sys DCB87DA83CC1010CBC9FC4DC9E395BBC
C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\Rt86win7.sys 5283B9A27FF230F2FF70D92451FF409A
C:\Program Files\Sandboxie\SbieDrv.sys 4741F34251878FD0F12866FF94E3AA8D
C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\sdbus.sys 0328BE1C7F1CBA23848179F8762E391C
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\serenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\serial.sys ==> MD5 is legit
C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\sffdisk.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\sffp_sd.sys ==> MD5 is legit
C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit
C:\Windows\system32\drivers\sisagp.sys ==> MD5 is legit
C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit
C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\smserial.sys 859E3ADC59D1C89A66AA6492C14D379E
C:\Windows\System32\DRIVERS\snapman.sys B8A2D4B57799555546F5A72FB82F838B
C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\srv.sys E4C2764065D66EA1D2D3EBC28FE99C46
C:\Windows\System32\DRIVERS\srv2.sys 03F0545BD8D4C77FA0AE1CEEDFCC71AB
C:\Windows\System32\DRIVERS\srvnet.sys BE6BD660CAA6F291AE06A718A4FA8ABC
C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serscan.sys EDB05BD63148796F23EA78506404A538
C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit
C:\Windows\System32\drivers\tcpip.sys CA59F7C570AF70BC174F477CFE2D9EE3
C:\Windows\System32\DRIVERS\tcpip.sys CA59F7C570AF70BC174F477CFE2D9EE3
C:\Windows\System32\drivers\tcpipreg.sys 3EEBD3BD93DA46A26E89893C7AB2FF3B
C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tdrpman.sys FF985011AC9FFE29866003F41361AA8D
C:\Windows\System32\drivers\tdtcp.sys 2C2C5AFE7EE4F620D69C23C0617651A8
C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tib.sys D8101E21C746F8234B3DB6AACC3A55BB
C:\Windows\System32\DRIVERS\tib_mounter.sys F6A890A7FE12CCF0D34D3C15AB1D2B46
C:\Windows\System32\drivers\truecrypt.sys ED5E4CE36C54F55E7698642E94D32EC7
C:\Windows\System32\DRIVERS\tssecsrv.sys B37B08F2E5EEB1A37E448E09BACE1101
C:\Windows\System32\drivers\tsusbflt.sys 9CE253214ACAA5A7D323327D2055EFAA
C:\Windows\system32\drivers\TsUsbGD.sys 57C527AF84748B5C2F5178C499C0B81F
C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\usbccgp.sys 71D97F1A3CC47A56728F7A400A3F8295
C:\Windows\system32\drivers\usbcir.sys 2352AB5F9F8F097BF9D41D5A4718A041
C:\Windows\System32\DRIVERS\usbehci.sys C4FB8E7ADEA9B5CEEA885A1B504B7E40
C:\Windows\System32\DRIVERS\usbhub.sys 86AA95ACB611001E26CD2C0145F2225A
C:\Windows\system32\drivers\usbohci.sys DCDF9855145A14DFCA0AB32308871961
C:\Windows\system32\drivers\usbprint.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\USBSTOR.SYS F991AB9CC6B908DB552166768176896A
C:\Windows\System32\DRIVERS\usbuhci.sys 8E51D04175BAA14C4F79AA5F6D248770
C:\Windows\System32\Drivers\usbvideo.sys DE014425522610BEDCA3821BB8C0F1D5
C:\Windows\System32\DRIVERS\VBoxDrv.sys 1BB1E3F1BA9384FE72AF7E3CB663E419
C:\Windows\System32\DRIVERS\VBoxNetAdp.sys 696A6F7146BC1E45945B3EE2E3BA72D3
C:\Windows\System32\DRIVERS\VBoxNetFlt.sys BB0D1AE9A0EF2441FDC4E6378DA558E8
C:\Windows\System32\Drivers\VBoxUSB.sys D1C0A900435C1FD61B3941EEAC44FE3A
C:\Windows\System32\DRIVERS\VBoxUSBMon.sys CB9C840A7BE244F421E9B0438E9CD78E
C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaagp.sys ==> MD5 is legit
C:\Windows\system32\drivers\viac7.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vididr.sys 32CE9263994A4C714FBA8AA5408741CD
C:\Windows\System32\DRIVERS\vidsflt.sys 1DD53BB11BDAB317E065FFE429831751
C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit
C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit
C:\Windows\System32\drivers\vwifibus.sys ==> MD5 is legit
C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\system32\drivers\wd.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys 25944D2CC49E0A6C581D02A74B7D6645
C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\WinUsb.sys A67E5F9A400F3BD1BE3D80613B45F708
C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit
C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
C:\Windows\System32\drivers\WudfPf.sys 06E6F32C8D0A3F66D956F57B43A2E070
C:\Windows\System32\DRIVERS\WUDFRd.sys 867C301E8B790040AE9CF6486E8041DF
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-02 19:39 - 2014-01-02 19:40 - 00026251 _____ C:\Users\Chef\Downloads\FRST.txt
2014-01-02 19:39 - 2014-01-02 19:39 - 00000000 ____D C:\Users\Chef\Downloads\FRST-OlderVersion
2014-01-02 19:37 - 2014-01-02 19:37 - 00000022 _____ C:\Windows\S.dirmngr
2014-01-02 13:13 - 2014-01-02 19:39 - 00000000 ____D C:\FRST
2014-01-02 11:40 - 2014-01-02 19:39 - 01064581 _____ (Farbar) C:\Users\Chef\Downloads\FRST.exe
2013-12-31 18:43 - 2014-01-02 12:31 - 00000000 ____D C:\Users\Chef\AppData\Roaming\Skype
2013-12-31 18:43 - 2013-12-31 18:43 - 00002687 _____ C:\Users\Public\Desktop\Skype.lnk
2013-12-31 18:43 - 2013-12-31 18:43 - 00000000 ___RD C:\Program Files\Skype
2013-12-31 18:43 - 2013-12-31 18:43 - 00000000 ____D C:\Program Files\Common Files\Skype
2013-12-31 18:42 - 2013-12-31 18:43 - 00000000 ____D C:\ProgramData\Skype
2013-12-31 18:40 - 2013-12-31 18:40 - 01551008 _____ (Skype Technologies S.A.) C:\Users\Chef\Downloads\SkypeSetup.exe
2013-12-27 17:00 - 2013-12-27 17:00 - 00069908 _____ C:\Windows\PFRO.log
2013-12-27 12:50 - 2013-12-30 19:01 - 00000000 ____D C:\Users\Chef\AppData\Roaming\TIPP10
2013-12-27 12:50 - 2013-12-27 12:50 - 00000000 ____D C:\Program Files\Tipp10
2013-12-27 12:49 - 2013-12-27 12:49 - 04441861 _____ ((c) 2006-2011, Tom Thielicke IT Solutions ) C:\Users\Chef\Downloads\tipp10_win_v2-1-0.exe
2013-12-27 12:43 - 2013-12-27 12:43 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-25 18:26 - 2013-12-27 12:47 - 00000000 ____D C:\Medion
2013-12-25 18:26 - 2013-12-25 18:26 - 06341080 _____ (SWE Sven Ritter ) C:\Users\Chef\Downloads\adb_lifetab_win.exe
2013-12-25 18:23 - 2013-12-25 18:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_androidusb_01009.Wdf
2013-12-25 18:18 - 2013-12-25 18:18 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01011.Wdf
2013-12-25 18:17 - 2013-12-25 18:18 - 00000306 __RSH C:\ProgramData\ntuser.pol
2013-12-25 18:16 - 2013-12-25 18:16 - 01629040 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2013-12-25 18:16 - 2013-12-25 18:16 - 00851176 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll
2013-12-25 17:59 - 2013-12-25 17:58 - 11937023 _____ C:\Users\Chef\Downloads\rooten.zip
2013-12-25 13:11 - 2013-12-25 13:11 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2013-12-22 15:44 - 2013-12-22 15:44 - 00010536 _____ C:\Users\Chef\AppData\Local\recently-used.xbel
2013-12-21 13:00 - 2012-08-23 15:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-12-21 13:00 - 2012-08-23 15:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-12-21 13:00 - 2012-08-23 15:41 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2013-12-21 13:00 - 2012-08-23 15:40 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-12-21 13:00 - 2012-08-23 15:10 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-12-21 13:00 - 2012-08-23 15:10 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-12-21 13:00 - 2012-08-23 14:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-12-21 13:00 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-12-21 13:00 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-12-21 13:00 - 2012-08-23 14:32 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-12-21 13:00 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-12-21 13:00 - 2012-08-23 12:40 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-12-21 13:00 - 2012-08-23 12:32 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-12-21 13:00 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-12-21 13:00 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-12-21 13:00 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-12-21 13:00 - 2012-08-23 11:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-12-21 13:00 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-12-21 12:59 - 2013-12-21 12:59 - 00000000 ____D C:\Program Files\Motorola
2013-12-21 12:49 - 2012-05-04 10:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2013-12-19 18:59 - 2013-12-19 18:59 - 00000000 ____D C:\Program Files\Avidemux 2.6
2013-12-19 18:58 - 2013-12-19 18:58 - 17848828 _____ C:\Users\Chef\Downloads\avidemux_2.6.7_win32.exe
2013-12-17 18:27 - 2013-12-19 15:24 - 00000000 ____D C:\Users\Chef\VirtualBox VMs
2013-12-17 18:26 - 2013-12-19 15:23 - 00000000 ____D C:\Users\Chef\.VirtualBox
2013-12-17 18:25 - 2013-12-17 18:25 - 00000000 ____D C:\Program Files\Oracle
2013-12-17 18:25 - 2013-11-29 19:55 - 00203024 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2013-12-17 18:25 - 2013-11-29 19:54 - 00103696 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2013-12-16 17:11 - 2013-12-16 17:13 - 106404624 _____ (Oracle Corporation) C:\Users\Chef\Downloads\VirtualBox-4.3.4-91027-Win.exe
2013-12-15 20:27 - 2013-12-15 20:27 - 00000000 ____D C:\Program Files\WinCDEmu
2013-12-15 20:21 - 2013-12-15 20:21 - 00831496 _____ (SysProgs.org) C:\Users\Chef\Downloads\WinCDEmu-3.6.exe
2013-12-13 14:27 - 2013-12-13 14:27 - 00000000 ___RD C:\Sandbox
2013-12-13 14:19 - 2013-12-15 15:07 - 00002368 _____ C:\Windows\Sandboxie.ini
2013-12-13 14:19 - 2013-12-13 14:19 - 00000000 ____D C:\Program Files\Sandboxie
2013-12-13 14:16 - 2013-12-13 14:17 - 02600648 _____ (Sandboxie Holdings, LLC) C:\Users\Chef\Downloads\SandboxieInstall_4.06.exe
2013-12-11 19:12 - 2013-12-11 19:12 - 00007597 _____ C:\Users\Chef\AppData\Local\Resmon.ResmonCfg
2013-12-11 18:07 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 18:07 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 18:07 - 2013-11-26 10:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-11 18:07 - 2013-11-26 09:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-11 18:07 - 2013-11-26 09:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-11 18:07 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 18:07 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 18:07 - 2013-11-26 09:36 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-11 18:07 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 18:07 - 2013-11-26 09:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-11 18:07 - 2013-11-26 09:29 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-11 18:07 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-11 18:07 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 18:07 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-11 18:07 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-11 18:07 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 18:07 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-11 18:07 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 18:07 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 18:04 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-11 18:04 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-11 14:58 - 2013-12-11 18:54 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-12-11 13:44 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 13:44 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 13:44 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 13:44 - 2013-10-30 02:27 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 13:44 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 13:44 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 13:44 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 13:44 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 13:44 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 13:44 - 2013-10-04 02:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 13:44 - 2013-10-04 02:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-09 16:57 - 2013-12-09 16:57 - 00000000 __RSH C:\MSDOS.SYS
2013-12-09 16:57 - 2013-12-09 16:57 - 00000000 __RSH C:\IO.SYS
2013-12-08 11:38 - 2013-12-11 13:40 - 00000000 ____D C:\Users\Chef\AppData\Roaming\tor
2013-12-07 20:13 - 2013-12-11 13:40 - 00000000 ____D C:\Users\Chef\AppData\Local\Vidalia
2013-12-07 20:09 - 2013-12-07 20:13 - 00000000 ____D C:\Program Files\Sicherheit
2013-12-07 20:08 - 2013-12-20 14:22 - 00000000 ____D C:\Program Files\Tor
2013-12-07 13:20 - 2014-01-02 19:37 - 00008827 _____ C:\Windows\setupact.log
2013-12-07 13:20 - 2013-12-11 18:26 - 00322904 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-07 13:20 - 2013-12-07 13:20 - 00000000 _____ C:\Windows\setuperr.log
2013-12-06 19:36 - 2013-12-07 13:54 - 00000000 ____D C:\Users\Chef\SecurityScans
2013-12-06 19:35 - 2013-12-06 19:35 - 00001087 _____ C:\Users\Public\Desktop\Microsoft Baseline Security Analyzer 2.3.lnk
2013-12-06 19:35 - 2013-12-06 19:35 - 00000000 ____D C:\Program Files\Microsoft Baseline Security Analyzer 2
2013-12-06 19:25 - 2013-12-06 19:25 - 00078152 _____ C:\Users\Chef\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-06 19:12 - 2013-12-06 19:12 - 00000000 ____D C:\Users\Chef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\g
2013-12-06 19:12 - 2013-12-06 19:12 - 00000000 ____D C:\Program Files\xp-AntiSpy
==================== One Month Modified Files and Folders =======
2014-01-02 19:40 - 2014-01-02 19:39 - 00026251 _____ C:\Users\Chef\Downloads\FRST.txt
2014-01-02 19:39 - 2014-01-02 19:39 - 00000000 ____D C:\Users\Chef\Downloads\FRST-OlderVersion
2014-01-02 19:39 - 2014-01-02 13:13 - 00000000 ____D C:\FRST
2014-01-02 19:39 - 2014-01-02 11:40 - 01064581 _____ (Farbar) C:\Users\Chef\Downloads\FRST.exe
2014-01-02 19:37 - 2014-01-02 19:37 - 00000022 _____ C:\Windows\S.dirmngr
2014-01-02 19:37 - 2013-12-07 13:20 - 00008827 _____ C:\Windows\setupact.log
2014-01-02 19:37 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-02 13:24 - 2013-11-22 09:25 - 01092915 _____ C:\Windows\WindowsUpdate.log
2014-01-02 12:31 - 2013-12-31 18:43 - 00000000 ____D C:\Users\Chef\AppData\Roaming\Skype
2014-01-01 21:34 - 2009-07-14 05:34 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-01 21:34 - 2009-07-14 05:34 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-01 13:12 - 2010-11-20 22:01 - 01618320 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-31 18:43 - 2013-12-31 18:43 - 00002687 _____ C:\Users\Public\Desktop\Skype.lnk
2013-12-31 18:43 - 2013-12-31 18:43 - 00000000 ___RD C:\Program Files\Skype
2013-12-31 18:43 - 2013-12-31 18:43 - 00000000 ____D C:\Program Files\Common Files\Skype
2013-12-31 18:43 - 2013-12-31 18:42 - 00000000 ____D C:\ProgramData\Skype
2013-12-31 18:40 - 2013-12-31 18:40 - 01551008 _____ (Skype Technologies S.A.) C:\Users\Chef\Downloads\SkypeSetup.exe
2013-12-30 19:01 - 2013-12-27 12:50 - 00000000 ____D C:\Users\Chef\AppData\Roaming\TIPP10
2013-12-27 17:00 - 2013-12-27 17:00 - 00069908 _____ C:\Windows\PFRO.log
2013-12-27 12:50 - 2013-12-27 12:50 - 00000000 ____D C:\Program Files\Tipp10
2013-12-27 12:49 - 2013-12-27 12:49 - 04441861 _____ ((c) 2006-2011, Tom Thielicke IT Solutions ) C:\Users\Chef\Downloads\tipp10_win_v2-1-0.exe
2013-12-27 12:47 - 2013-12-25 18:26 - 00000000 ____D C:\Medion
2013-12-27 12:44 - 2013-11-23 13:08 - 00002053 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-27 12:43 - 2013-12-27 12:43 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-27 12:43 - 2013-11-23 13:07 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-12-27 12:43 - 2013-11-23 13:07 - 00410528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-12-27 12:43 - 2013-11-23 13:07 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-27 12:43 - 2013-11-23 13:07 - 00180248 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-27 12:43 - 2013-11-23 13:07 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-12-27 12:43 - 2013-11-23 13:07 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-12-25 18:26 - 2013-12-25 18:26 - 06341080 _____ (SWE Sven Ritter ) C:\Users\Chef\Downloads\adb_lifetab_win.exe
2013-12-25 18:23 - 2013-12-25 18:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_androidusb_01009.Wdf
2013-12-25 18:18 - 2013-12-25 18:18 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01011.Wdf
2013-12-25 18:18 - 2013-12-25 18:17 - 00000306 __RSH C:\ProgramData\ntuser.pol
2013-12-25 18:17 - 2009-07-14 03:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-12-25 18:16 - 2013-12-25 18:16 - 01629040 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2013-12-25 18:16 - 2013-12-25 18:16 - 00851176 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll
2013-12-25 17:58 - 2013-12-25 17:59 - 11937023 _____ C:\Users\Chef\Downloads\rooten.zip
2013-12-25 13:11 - 2013-12-25 13:11 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2013-12-22 18:16 - 2013-11-30 11:05 - 00000000 ____D C:\Users\Chef\.gimp-2.8
2013-12-22 15:44 - 2013-12-22 15:44 - 00010536 _____ C:\Users\Chef\AppData\Local\recently-used.xbel
2013-12-22 15:44 - 2013-12-01 11:54 - 00000000 ____D C:\Users\Chef\AppData\Local\gtk-2.0
2013-12-21 20:02 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-12-21 15:11 - 2010-11-21 01:46 - 00000000 ____D C:\Windows\system32\Drivers\de-DE
2013-12-21 15:11 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-12-21 13:22 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-12-21 12:59 - 2013-12-21 12:59 - 00000000 ____D C:\Program Files\Motorola
2013-12-20 14:22 - 2013-12-07 20:08 - 00000000 ____D C:\Program Files\Tor
2013-12-19 18:59 - 2013-12-19 18:59 - 00000000 ____D C:\Program Files\Avidemux 2.6
2013-12-19 18:58 - 2013-12-19 18:58 - 17848828 _____ C:\Users\Chef\Downloads\avidemux_2.6.7_win32.exe
2013-12-19 15:24 - 2013-12-17 18:27 - 00000000 ____D C:\Users\Chef\VirtualBox VMs
2013-12-19 15:23 - 2013-12-17 18:26 - 00000000 ____D C:\Users\Chef\.VirtualBox
2013-12-17 18:27 - 2013-11-22 10:04 - 00000000 ____D C:\Users\Chef
2013-12-17 18:25 - 2013-12-17 18:25 - 00000000 ____D C:\Program Files\Oracle
2013-12-16 18:03 - 2013-11-23 20:14 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-12-16 17:13 - 2013-12-16 17:11 - 106404624 _____ (Oracle Corporation) C:\Users\Chef\Downloads\VirtualBox-4.3.4-91027-Win.exe
2013-12-16 16:30 - 2013-11-23 20:14 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-16 08:16 - 2013-11-25 17:08 - 00000000 ____D C:\Users\Chef\AppData\Roaming\TrueCrypt
2013-12-15 20:27 - 2013-12-15 20:27 - 00000000 ____D C:\Program Files\WinCDEmu
2013-12-15 20:21 - 2013-12-15 20:21 - 00831496 _____ (SysProgs.org) C:\Users\Chef\Downloads\WinCDEmu-3.6.exe
2013-12-15 15:07 - 2013-12-13 14:19 - 00002368 _____ C:\Windows\Sandboxie.ini
2013-12-13 14:27 - 2013-12-13 14:27 - 00000000 ___RD C:\Sandbox
2013-12-13 14:19 - 2013-12-13 14:19 - 00000000 ____D C:\Program Files\Sandboxie
2013-12-13 14:17 - 2013-12-13 14:16 - 02600648 _____ (Sandboxie Holdings, LLC) C:\Users\Chef\Downloads\SandboxieInstall_4.06.exe
2013-12-11 19:12 - 2013-12-11 19:12 - 00007597 _____ C:\Users\Chef\AppData\Local\Resmon.ResmonCfg
2013-12-11 18:54 - 2013-12-11 14:58 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-12-11 18:27 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Public\Libraries
2013-12-11 18:26 - 2013-12-07 13:20 - 00322904 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-11 18:07 - 2013-11-24 11:26 - 00000000 ____D C:\Windows\system32\MRT
2013-12-11 18:05 - 2013-11-24 11:26 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-11 13:48 - 2013-11-24 10:26 - 00000000 ____D C:\Users\Chef\AppData\Local\Thunderbird
2013-12-11 13:40 - 2013-12-08 11:38 - 00000000 ____D C:\Users\Chef\AppData\Roaming\tor
2013-12-11 13:40 - 2013-12-07 20:13 - 00000000 ____D C:\Users\Chef\AppData\Local\Vidalia
2013-12-10 13:57 - 2013-11-24 10:23 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-12-10 13:57 - 2013-11-24 10:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-12-10 13:57 - 2013-11-24 10:22 - 00000000 ____D C:\Users\Chef\AppData\Local\Adobe
2013-12-09 16:57 - 2013-12-09 16:57 - 00000000 __RSH C:\MSDOS.SYS
2013-12-09 16:57 - 2013-12-09 16:57 - 00000000 __RSH C:\IO.SYS
2013-12-07 20:13 - 2013-12-07 20:09 - 00000000 ____D C:\Program Files\Sicherheit
2013-12-07 13:54 - 2013-12-06 19:36 - 00000000 ____D C:\Users\Chef\SecurityScans
2013-12-07 13:20 - 2013-12-07 13:20 - 00000000 _____ C:\Windows\setuperr.log
2013-12-06 19:47 - 2013-11-22 10:04 - 00000000 ____D C:\Users\Chef\AppData\Local\VirtualStore
2013-12-06 19:35 - 2013-12-06 19:35 - 00001087 _____ C:\Users\Public\Desktop\Microsoft Baseline Security Analyzer 2.3.lnk
2013-12-06 19:35 - 2013-12-06 19:35 - 00000000 ____D C:\Program Files\Microsoft Baseline Security Analyzer 2
2013-12-06 19:25 - 2013-12-06 19:25 - 00078152 _____ C:\Users\Chef\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-06 19:14 - 2013-11-22 09:20 - 00000000 ____D C:\Windows\Panther
2013-12-06 19:14 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\Msdtc
2013-12-06 19:12 - 2013-12-06 19:12 - 00000000 ____D C:\Users\Chef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\g
2013-12-06 19:12 - 2013-12-06 19:12 - 00000000 ____D C:\Program Files\xp-AntiSpy
2013-12-05 19:22 - 2013-11-24 14:28 - 00000000 ____D C:\Users\Chef\.android
2013-12-04 14:22 - 2013-11-24 13:54 - 00000000 ____D C:\Program Files\androidappentwicklung
2013-12-03 14:30 - 2013-12-01 14:21 - 00000000 ____D C:\Users\Chef\AppData\Roaming\Audacity
2013-12-03 13:49 - 2013-11-30 11:02 - 00000000 ____D C:\Program Files\GIMP 2
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== BCD ================================
Windows-Start-Manager
---------------------
Bezeichner {bootmgr}
device partition=\Device\HarddiskVolume1
description Windows Boot Manager
locale de-DE
inherit {globalsettings}
default {current}
resumeobject {f9dd0348-534e-11e3-8642-de810d628c33}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 0
Windows-Startladeprogramm
-------------------------
Bezeichner {current}
device partition=C:
path \Windows\system32\winload.exe
description Windows 7
locale de-DE
inherit {bootloadersettings}
recoverysequence {f9dd034a-534e-11e3-8642-de810d628c33}
recoveryenabled Yes
osdevice partition=C:
systemroot \Windows
resumeobject {f9dd0348-534e-11e3-8642-de810d628c33}
nx OptIn
Windows-Startladeprogramm
-------------------------
Bezeichner {f9dd034a-534e-11e3-8642-de810d628c33}
device ramdisk=[C:]\Recovery\f9dd034a-534e-11e3-8642-de810d628c33\Winre.wim,{f9dd034b-534e-11e3-8642-de810d628c33}
path \windows\system32\winload.exe
description Windows Recovery Environment
inherit {bootloadersettings}
osdevice ramdisk=[C:]\Recovery\f9dd034a-534e-11e3-8642-de810d628c33\Winre.wim,{f9dd034b-534e-11e3-8642-de810d628c33}
systemroot \windows
nx OptIn
winpe Yes
Wiederaufnahme aus dem Ruhezustand
----------------------------------
Bezeichner {f9dd0348-534e-11e3-8642-de810d628c33}
device partition=C:
path \Windows\system32\winresume.exe
description Windows Resume Application
locale de-DE
inherit {resumeloadersettings}
filedevice partition=C:
filepath \hiberfil.sys
pae Yes
debugoptionenabled No
Windows-Speichertestprogramm
----------------------------
Bezeichner {memdiag}
device partition=\Device\HarddiskVolume1
path \boot\memtest.exe
description Windows-Speicherdiagnose
locale de-DE
inherit {globalsettings}
badmemoryaccess Yes
EMS-Einstellungen
-----------------
Bezeichner {emssettings}
bootems Yes
Debuggereinstellungen
---------------------
Bezeichner {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200
RAM-Defekte
-----------
Bezeichner {badmemory}
Globale Einstellungen
---------------------
Bezeichner {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}
Startladeprogramm-Einstellungen
-------------------------------
Bezeichner {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}
Hypervisoreinstellungen
-------------------
Bezeichner {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Einstellungen zur Ladeprogrammfortsetzung
-----------------------------------------
Bezeichner {resumeloadersettings}
inherit {globalsettings}
Ger„teoptionen
--------------
Bezeichner {f9dd034b-534e-11e3-8642-de810d628c33}
description Ramdisk Options
ramdisksdidevice partition=C:
ramdisksdipath \Recovery\f9dd034a-534e-11e3-8642-de810d628c33\boot.sdi
LastRegBack: 2013-12-30 19:21
==================== End Of Log ============================ --- --- ---
--- --- ---
Addition.txt: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02-01-2014 01
Ran by Chef at 2014-01-02 19:40:37
Running from C:\Users\Chef\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05 - Adobe Systems Incorporated)
Audacity 2.0.5 (Version: 2.0.5 - Audacity Team)
avast! Free Antivirus (Version: 9.0.2011 - Avast Software)
Avidemux 2.6 (32-bit) (Version: 2.6.7.8981 - )
GIMP 2.8.8 (Version: 2.8.8 - The GIMP Team)
Gpg4win (2.2.1) (Version: 2.2.1 - The Gpg4win Project)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (Version: 25.0.571.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (Version: 140.0.2.2 - Hewlett Packard)
HP Update (Version: 5.003.000.004 - Hewlett-Packard)
Intel(R) Graphics Media Accelerator Driver (Version: 8.15.10.1930 - Intel Corporation)
Java 7 Update 45 (Version: 7.0.450 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java SE Development Kit 7 Update 45 (Version: 1.7.0.450 - Oracle)
Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709 - Microsoft Corporation)
Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Baseline Security Analyzer 2.3 (Version: 2.3.2208 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Motorola SM56 Speakerphone Modem (Version: 6.12.25.06 - Motorola Inc)
Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (Version: 26.0 - Mozilla)
Mozilla Thunderbird 24.2.0 (x86 de) (Version: 24.2.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation)
OpenOffice 4.0.1 (Version: 4.01.9714 - Apache Software Foundation)
Oracle VM VirtualBox 4.3.4 (Version: 4.3.4 - Oracle Corporation)
Realtek High Definition Audio Driver (Version: 6.0.1.7083 - Realtek Semiconductor Corp.)
RICOH Media Driver (Version: 2.10.00.04 - RICOH)
Sandboxie 4.06 (32-bit) (Version: 4.06 - Sandboxie Holdings, LLC)
Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.)
TIPP10 Version 2.1.0 (Version: - (c) 2006-2011, Tom Thielicke IT Solutions)
True Image 2013 (Version: 16.0.6514 - Acronis) Hidden
TrueCrypt (Version: 7.1a - TrueCrypt Foundation)
WinCDEmu (Version: 3.6 - Bazis)
xp-AntiSpy 3.98-2 (Version: - Christian Taubenheim)
==================== Restore Points =========================
16-12-2013 16:15:03 Installed Oracle VM VirtualBox 4.3.4
17-12-2013 13:02:05 Windows Update
17-12-2013 17:14:47 Removed Oracle VM VirtualBox 4.3.4
17-12-2013 17:24:52 Installed Oracle VM VirtualBox 4.3.4
21-12-2013 11:50:01 Windows Update
25-12-2013 17:17:35 Gerätetreiber-Paketinstallation: libusbx.org
27-12-2013 11:41:40 avast! antivirus system restore point
27-12-2013 11:44:26 Windows Update
31-12-2013 11:56:33 Windows Update
==================== Hosts content: ==========================
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {45D1A9A8-8AE8-4FB7-A5E2-E178F9BAC77E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-12-27] (AVAST Software)
==================== Loaded Modules (whitelisted) =============
2013-03-27 22:36 - 2013-03-27 22:36 - 00021312 _____ () C:\Program Files\Acronis\TrueImageHome\ti_managers_proxy_stub.dll
2013-11-23 13:07 - 2013-11-23 13:07 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2013-03-28 00:37 - 2013-03-28 00:37 - 13627872 _____ () C:\Program Files\Acronis\TrueImageHome\ti_managers.dll
2013-01-10 13:43 - 2013-01-10 13:43 - 00014360 _____ () C:\Program Files\Common Files\Acronis\TibMounter\icudt38.dll
2013-11-23 20:14 - 2013-12-16 16:30 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2013-12-11 14:58 - 2013-12-11 14:58 - 03017840 _____ () C:\Program Files\Mozilla Thunderbird\mozjs.dll
2013-12-11 14:58 - 2013-12-11 14:58 - 00158832 _____ () C:\Program Files\Mozilla Thunderbird\NSLDAP32V60.dll
2013-12-11 14:58 - 2013-12-11 14:58 - 00023152 _____ () C:\Program Files\Mozilla Thunderbird\NSLDAPPR32V60.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/02/2014 07:38:16 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/02/2014 00:30:35 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/01/2014 09:57:57 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/01/2014 09:27:09 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/01/2014 06:14:07 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/01/2014 01:10:12 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/31/2013 00:30:36 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (12/30/2013 07:22:32 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (12/30/2013 06:16:13 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/27/2013 05:30:37 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (01/01/2014 01:09:50 PM) (Source: Microsoft-Windows-Application-Experience) (User: NT-AUTORITÄT)
Description: Der Dienst "Programmkompatibilitäts-Assistent" konnte Phase 2 nicht initialisieren.
Error: (12/29/2013 03:02:34 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Wlansvc erreicht.
Error: (12/23/2013 10:36:57 AM) (Source: DCOM) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (12/16/2013 06:02:13 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (12/16/2013 06:02:12 PM) (Source: DCOM) (User: )
Description: {1EF75F33-893B-4E8F-9655-C3D602BA4897}
Error: (12/15/2013 08:17:46 PM) (Source: Microsoft-Windows-BitLocker-Driver) (User: NT-AUTORITÄT)
Description: Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf "" können nicht gelesen werden.
Error: (12/15/2013 07:54:37 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (12/15/2013 07:54:37 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (12/15/2013 07:54:37 PM) (Source: DCOM) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}
Error: (12/15/2013 07:54:37 PM) (Source: DCOM) (User: )
Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Microsoft Office Sessions:
=========================
Error: (01/02/2014 07:38:16 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/02/2014 00:30:35 AM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\WinCDEmu\vmnt64.exe
Error: (01/01/2014 09:57:57 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\WinCDEmu\vmnt64.exe
Error: (01/01/2014 09:27:09 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/01/2014 06:14:07 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/01/2014 01:10:12 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/31/2013 00:30:36 AM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\WinCDEmu\vmnt64.exe
Error: (12/30/2013 07:22:32 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\WinCDEmu\vmnt64.exe
Error: (12/30/2013 06:16:13 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/27/2013 05:30:37 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Percentage of memory in use: 43%
Total physical RAM: 2935.25 MB
Available physical RAM: 1666.13 MB
Total Pagefile: 5868.78 MB
Available Pagefile: 4673.85 MB
Total Virtual: 2047.88 MB
Available Virtual: 1907.35 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:154.76 GB) (Free:110.59 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 233 GB) (Disk ID: 4E13B6C1)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=155 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Hoffentlich kann mir jemand helfen. |