wecker23 | 21.02.2014 14:00 | FRST.txt
[CODE]
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-02-2014
Ran by Henry (administrator) on HENRY-PC on 21-02-2014 13:42:20
Running from C:\users\Henry.Henry-PC\Downloads
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVM Berlin) C:\Program Files\avmwlanstick\WlanNetService.exe
(VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
(AVM Berlin) C:\Program Files\avmwlanstick\WLanGUI.exe
() C:\Program Files\RocketDock\RocketDock.exe
(Dropbox, Inc.) C:\Users\Henry.Henry-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IELowutil.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [AMD AVT] - C:\Program Files\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM\...\Run: [HDAudDeck] - C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [2159216 2011-05-06] (VIA)
HKLM\...\Run: [AVMWlanClient] - C:\Program Files\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [280576 2013-04-30] (Microsoft Corporation)
HKU\S-1-5-21-1978416703-2945353608-3729288318-1010\...\Run: [RocketDock] - C:\Program Files\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-1978416703-2945353608-3729288318-1010\...\MountPoints2: {c75eb168-6a70-11e3-9866-bcaec52cac5a} - H:\pushinst.exe
HKU\S-1-5-21-1978416703-2945353608-3729288318-1010\...\MountPoints2: {d08c7607-0267-11e3-9147-bcaec52cac5a} - H:\LaunchU3.exe -a
AppInit_DLLs: c:\progra~1\sk.enhancer\psupport.dll => C:\Program Files\Sk.Enhancer\psupport.dll [857600 2013-10-06] ()
AppInit_DLLs: c:\progra~2\keepnbrowse\keepnbrowse.dll => C:\ProgramData\KeepnBrowse\KeepnBrowse.dll [4197376 2014-02-09] ()
IFEO\utilman.exe: [Debugger] c:\windows\system32\cmd.exe
Startup: C:\users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\users\Henry.Henry-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\users\Henry.Henry-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\users\Henry.Henry-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7541AE830A45CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKLM - DefaultScope value is missing.
BHO: YoTuberAaDusRemov - {369F5546-C477-4CF6-602B-B5D8B737BEF3} - C:\ProgramData\YoTuberAaDusRemov\RBIO1Ar.dll ()
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Chrome:
=======
CHR HomePage:
CHR RestoreOnStartup: ""
CHR Extension: (Magic Actions for YouTube™) - C:\users\Henry.Henry-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2014-01-02]
CHR Extension: (Google Drive) - C:\users\Henry.Henry-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-02]
CHR Extension: (YouTube) - C:\users\Henry.Henry-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-02]
CHR Extension: (Last updated at $time$ on $date$) - C:\users\Henry.Henry-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-02]
CHR Extension: (YoTuberAaDusRemov) - C:\users\Henry.Henry-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\clfijelobcllnifdbihdpblmagdjmbim [2014-02-16]
CHR Extension: (Google Search) - C:\users\Henry.Henry-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-02]
CHR Extension: (Google Wallet) - C:\users\Henry.Henry-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-02]
CHR Extension: (NotScripts) - C:\users\Henry.Henry-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\odjhifogjcknibkahlpidmdajjpkkcfn [2014-01-02]
CHR Extension: (Gmail) - C:\users\Henry.Henry-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-02]
CHR Extension: (GreatSave4U) - C:\ProgramData\pkenkpaapkaeghlaaakgljppfholildn [2014-01-01]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
R2 a6bb4a82; C:\ProgramData\KeepnBrowse\keepnbrowseSvc.dll [179024 2014-02-09] ()
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2012-11-16] (Advanced Micro Devices, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
S4 DragonSvc; C:\Program Files\Common Files\Nuance\dgnsvc.exe [296808 2011-06-05] (Nuance Communications, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-03-29] (VIA Technologies, Inc.)
R3 WinHttpAutoProxySvc; winhttp.dll [X]
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [45184 2012-03-05] (Advanced Micro Devices)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2010-10-22] (AVM Berlin)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [265088 2007-01-26] (AVM GmbH)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1804400 2011-03-29] (VIA Technologies, Inc.)
S3 ATICDSDr; \??\C:\Users\Henry\AppData\Local\Temp\ATICDSDr.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-21 13:41 - 2014-02-21 13:41 - 00034384 _____ () C:\users\Henry.Henry-PC\Downloads\Addition.txt
2014-02-21 13:40 - 2014-02-21 13:42 - 00008665 _____ () C:\users\Henry.Henry-PC\Downloads\FRST.txt
2014-02-21 13:39 - 2014-02-21 13:42 - 00000000 ____D () C:\FRST
2014-02-21 13:39 - 2014-02-21 13:39 - 01142784 _____ (Farbar) C:\users\Henry.Henry-PC\Downloads\FRST.exe
2014-02-16 09:53 - 2014-02-16 09:53 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-02-16 09:53 - 2014-02-16 09:53 - 00000000 ____D () C:\ProgramData\YoTuberAaDusRemov
2014-02-16 09:53 - 2014-02-16 09:53 - 00000000 ____D () C:\ProgramData\clfijelobcllnifdbihdpblmagdjmbim
2014-02-12 19:14 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-12 19:14 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-12 19:14 - 2014-02-06 11:19 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-12 19:14 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-12 19:14 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-12 19:14 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-12 19:14 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-12 19:14 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-12 19:14 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-12 19:14 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-12 19:14 - 2014-02-06 10:47 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-12 19:14 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-12 19:14 - 2014-02-06 10:34 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-12 19:14 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-12 19:14 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-12 19:14 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-12 19:14 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-12 19:14 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-12 19:14 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-12 19:14 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-12 19:14 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-12 19:09 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-12 16:52 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-12 16:52 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 16:52 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-12 16:52 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-09 01:00 - 2014-02-09 01:00 - 00000000 ____D () C:\ProgramData\KeepnBrowse
2014-02-02 19:04 - 2014-02-02 19:11 - 146040379 _____ () C:\users\Henry.Henry-PC\Downloads\Haussicherung-Test-08-06-2013-720.mp4
2014-01-31 22:00 - 2014-02-01 20:38 - 00000403 _____ () C:\users\Henry.Henry-PC\Desktop\expotential zineszins.py
2014-01-31 22:00 - 2014-01-31 22:00 - 00000129 _____ () C:\users\Henry.Henry-PC\Desktop\zinsen.py
2014-01-31 20:04 - 2014-01-31 20:08 - 00000000 ____D () C:\users\Henry.Henry-PC\.idlerc
2014-01-28 21:04 - 2014-01-28 21:04 - 00000941 _____ () C:\users\Public\Desktop\Winamp.lnk
2014-01-28 21:03 - 2014-01-28 21:12 - 00000000 ____D () C:\users\Henry.Henry-PC\AppData\Roaming\Winamp
2014-01-28 20:46 - 2014-01-28 20:51 - 12855384 _____ (Nullsoft, Inc.) C:\users\Henry.Henry-PC\Downloads\winamp5666_full_de-de.exe
2014-01-24 12:10 - 2014-01-24 12:10 - 00000571 _____ () C:\users\Henry.Henry-PC\Desktop\new 1.txt
==================== One Month Modified Files and Folders =======
2014-02-21 13:42 - 2014-02-21 13:40 - 00008665 _____ () C:\users\Henry.Henry-PC\Downloads\FRST.txt
2014-02-21 13:42 - 2014-02-21 13:39 - 00000000 ____D () C:\FRST
2014-02-21 13:41 - 2014-02-21 13:41 - 00034384 _____ () C:\users\Henry.Henry-PC\Downloads\Addition.txt
2014-02-21 13:41 - 2013-03-21 19:33 - 01795754 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-21 13:41 - 2013-03-21 19:31 - 01286120 _____ () C:\Windows\WindowsUpdate.log
2014-02-21 13:39 - 2014-02-21 13:39 - 01142784 _____ (Farbar) C:\users\Henry.Henry-PC\Downloads\FRST.exe
2014-02-21 13:39 - 2013-03-22 21:15 - 00000000 ____D () C:\users\Henry.Henry-PC\AppData\Roaming\Dropbox
2014-02-21 13:38 - 2012-09-16 15:49 - 00000000 ___RD () C:\users\Henry.Henry-PC\Dropbox
2014-02-21 13:37 - 2014-01-02 12:21 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-21 13:37 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-21 13:37 - 2009-07-14 05:39 - 00058358 _____ () C:\Windows\setupact.log
2014-02-20 23:00 - 2013-03-22 23:03 - 00000000 ____D () C:\users\Henry.Henry-PC\AppData\Roaming\vlc
2014-02-20 20:26 - 2014-01-02 12:21 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-20 17:24 - 2009-07-14 05:34 - 00014832 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-20 17:24 - 2009-07-14 05:34 - 00014832 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-19 22:14 - 2013-04-14 12:26 - 00000000 ____D () C:\users\Henry.Henry-PC\AppData\Roaming\Audacity
2014-02-19 17:53 - 2013-04-15 14:40 - 00012342 _____ () C:\Windows\PFRO.log
2014-02-18 20:50 - 2013-12-22 15:45 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-16 10:15 - 2014-01-02 12:23 - 00002199 _____ () C:\users\Public\Desktop\Google Chrome.lnk
2014-02-16 09:53 - 2014-02-16 09:53 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-02-16 09:53 - 2014-02-16 09:53 - 00000000 ____D () C:\ProgramData\YoTuberAaDusRemov
2014-02-16 09:53 - 2014-02-16 09:53 - 00000000 ____D () C:\ProgramData\clfijelobcllnifdbihdpblmagdjmbim
2014-02-16 09:53 - 2013-11-09 21:00 - 00000000 ____D () C:\ProgramData\5c2dc4d2c80604f
2014-02-16 09:53 - 2009-07-14 03:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-02-13 17:48 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-12 19:13 - 2013-08-16 21:42 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-12 19:11 - 2013-04-23 17:41 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-09 12:12 - 2013-08-30 16:24 - 00000000 ____D () C:\users\Henry.Henry-PC\Documents\Gitarre
2014-02-09 01:00 - 2014-02-09 01:00 - 00000000 ____D () C:\ProgramData\KeepnBrowse
2014-02-07 20:18 - 2013-03-23 12:34 - 00000000 ____D () C:\users\Henry.Henry-PC\Documents\Visual Studio 2010
2014-02-06 11:38 - 2014-02-12 19:14 - 17103872 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 11:20 - 2014-02-12 19:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 11:19 - 2014-02-12 19:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 11:01 - 2014-02-12 19:14 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 11:00 - 2014-02-12 19:14 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-12 19:14 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 10:52 - 2014-02-12 19:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 10:52 - 2014-02-12 19:14 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 10:49 - 2014-02-12 19:14 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 10:47 - 2014-02-12 19:14 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 10:47 - 2014-02-12 19:14 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 10:46 - 2014-02-12 19:14 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 10:34 - 2014-02-12 19:14 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 10:25 - 2014-02-12 19:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 10:25 - 2014-02-12 19:14 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 10:13 - 2014-02-12 19:14 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:09 - 2014-02-12 19:14 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:03 - 2014-02-12 19:14 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 09:41 - 2014-02-12 19:14 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 09:36 - 2014-02-12 19:14 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:34 - 2014-02-12 19:14 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-02 19:11 - 2014-02-02 19:04 - 146040379 _____ () C:\users\Henry.Henry-PC\Downloads\Haussicherung-Test-08-06-2013-720.mp4
2014-02-01 20:38 - 2014-01-31 22:00 - 00000403 _____ () C:\users\Henry.Henry-PC\Desktop\expotential zineszins.py
2014-01-31 22:00 - 2014-01-31 22:00 - 00000129 _____ () C:\users\Henry.Henry-PC\Desktop\zinsen.py
2014-01-31 20:08 - 2014-01-31 20:04 - 00000000 ____D () C:\users\Henry.Henry-PC\.idlerc
2014-01-31 20:04 - 2013-03-22 21:11 - 00000000 ____D () C:\users\Henry.Henry-PC
2014-01-28 21:20 - 2014-01-19 22:22 - 00000000 ____D () C:\users\Henry.Henry-PC\Documents\Any DVD Converter Professional
2014-01-28 21:19 - 2014-01-19 22:22 - 00000000 ____D () C:\users\Henry.Henry-PC\AppData\Roaming\AnvSoft
2014-01-28 21:12 - 2014-01-28 21:03 - 00000000 ____D () C:\users\Henry.Henry-PC\AppData\Roaming\Winamp
2014-01-28 21:04 - 2014-01-28 21:04 - 00000941 _____ () C:\users\Public\Desktop\Winamp.lnk
2014-01-28 21:04 - 2013-04-14 11:23 - 00000000 ____D () C:\Program Files\Winamp
2014-01-28 20:51 - 2014-01-28 20:46 - 12855384 _____ (Nullsoft, Inc.) C:\users\Henry.Henry-PC\Downloads\winamp5666_full_de-de.exe
2014-01-26 15:14 - 2013-09-29 20:16 - 00000000 ____D () C:\bb
2014-01-24 12:10 - 2014-01-24 12:10 - 00000571 _____ () C:\users\Henry.Henry-PC\Desktop\new 1.txt
Some content of TEMP:
====================
C:\users\Henry\AppData\Local\Temp\13-1-legacy_vista_win7_win8_32_dd_ccc.exe
C:\users\Henry\AppData\Local\Temp\xmlUpdater.exe
C:\users\Henry.Henry-PC\AppData\Local\Temp\dateinj01.dll
C:\users\Henry.Henry-PC\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-13 20:37
==================== End Of Log ============================ --- --- ---
--- --- ---
Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-02-2014
Ran by Henry at 2014-02-21 13:42:35
Running from C:\users\Henry.Henry-PC\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Microsoft Security Essentials (Enabled - Up to date) {3F839487-C7A2-C958-E30C-E2825BA31FB5}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {84E27563-E198-C6D6-D9BC-D9F020245508}
==================== Installed Programs ======================
7-Zip 9.22beta (Version: - )
Adobe Anchor Service CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Bridge CS4 (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe CMaps CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Color - Photoshop Specific CS4 (Version: 2.0 - Adobe Systems Inacorporated) Hidden
Adobe Color EU Recommended Settings CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Color JA Extra Settings CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Color NA Extra Settings CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Color Video Profiles CS CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe CSI CS4 (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Default Language CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe ExtendScript Toolkit CS4 (Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 ActiveX (Version: 11.7.700.202 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (Version: 11.6.602.180 - Adobe Systems Incorporated)
Adobe Fonts All (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Linguistics CS4 (Version: 4.0.0 - Adobe Systems Incorporated) Hidden
Adobe Output Module (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe PDF Library Files CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS4 (Version: 11.0 - Adobe Systems Incorporated)
Adobe Photoshop CS4 (Version: 11.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS4 Support (Version: 11.0 - Adobe Systems Incorporated) Hidden
Adobe Reader XI (11.0.02) - Deutsch (Version: 11.0.02 - Adobe Systems Incorporated)
Adobe Search for Help (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Service Manager Extension (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Setup (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Type Support CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe Update Manager CS4 (Version: 6.0.0 - Adobe Systems Incorporated) Hidden
Adobe WinSoft Linguistics Plugin (Version: 1.1 - Adobe Systems Incorporated) Hidden
Adobe XMP Panels CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
AdobeColorCommonSetCMYK (Version: 2.0 - Adobe Systems Incorporated) Hidden
AdobeColorCommonSetRGB (Version: 2.0 - Adobe Systems Incorporated) Hidden
AMD Accelerated Video Transcoding (Version: 12.5.100.21116 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.937.2 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (Version: 8.0.877.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Fuel (Version: 2012.1116.1515.27190 - Ihr Firmenname) Hidden
AMD Media Foundation Decoders (Version: 1.0.71116.1554 - Advanced Micro Devices, Inc.) Hidden
AMD VISION Engine Control Center (Version: 2012.1116.1515.27190 - Ihr Firmenname) Hidden
Any DVD Converter Professional 4.6.2 (Version: - Any-DVD-Converter.com)
Audacity 2.0.3 (Version: 2.0.3 - Audacity Team)
AVM FRITZ!WLAN (Version: - AVM Berlin)
Band-in-a-Box Server (Version: - PG Music Inc.)
BestPractice (remove only) (Version: - )
burnatonce (Version: - )
Catalyst Control Center - Branding (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (Version: 2012.1116.1515.27190 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (Version: 2012.1116.1515.27190 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (Version: 2012.1116.1515.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
ccc-utility (Version: 2012.1116.1515.27190 - Advanced Micro Devices, Inc.) Hidden
Connect (Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
DivX-Setup (Version: 2.1.0.12 - DivX, Inc. )
Dragon NaturallySpeaking 11 (Version: 11.50.100 - Nuance Communications Inc.)
Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.)
EarMaster Pro 5 (Version: 5.0 - EarMaster ApS)
ffdshow [rev 2946] [2009-05-15] (Version: 1.0 - )
FileZilla Client 3.7.0.1 (Version: 3.7.0.1 - FileZilla Project)
Free Download Manager 3.9.2 (Version: - FreeDownloadManager.ORG)
Google Chrome (Version: 32.0.1700.107 - Google Inc.)
Google Update Helper (Version: 1.3.21.165 - Google Inc.) Hidden
Guitar Pro 6 (Version: - Arobas Music)
HP Officejet 6500 E710n-z - Grundlegende Software für das Gerät (Version: 28.0.1315.0 - Hewlett-Packard Co.)
I.R.I.S. OCR (Version: 12.3.4.0 - HP)
IrfanView (remove only) (Version: 4.36 - Irfan Skiljan)
Java 7 Update 45 (Version: 7.0.450 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java SE Development Kit 7 Update 45 (Version: 1.7.0.450 - Oracle)
KeepnBrowse (Version: - Team Work)
kuler (Version: 2.0 - Adobe Systems Incorporated) Hidden
LibreOffice 4.0.3.3 (Version: 4.0.3.3 - The Document Foundation)
Litecoin (HKCU Version: 0.8.6.2 - Litecoin project)
Macromedia Dreamweaver 8 (Version: 8.0.0.2751 - Macromedia)
Macromedia Extension Manager (Version: 1.7.270 - Ihr Firmenname)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Multi-Targeting Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Hidden
Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (Version: 4.4.304.0 - Microsoft Corporation)
Microsoft SQL Server 2008 (Version: - Microsoft Corporation) Hidden
Microsoft SQL Server 2008 Browser (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Common Files (Version: 10.0.1600.22 - Microsoft Corporation) Hidden
Microsoft SQL Server 2008 Common Files (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
Microsoft SQL Server 2008 Database Engine Services (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
Microsoft SQL Server 2008 Database Engine Shared (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
Microsoft SQL Server 2008 Native Client (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 RsFx Driver (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
Microsoft SQL Server Compact 3.5 SP2 DEU (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft Visual C# 2010 Express - DEU (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C# 2010 Express - DEU (Version: 10.0.30319 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (Version: 10.0.30319 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation)
MultiBit 0.5.15 (Version: 0.5.15 - )
Notepad++ (Version: 6.3.1 - )
PDF Settings CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Photoshop Camera Raw (Version: 5.0 - Adobe Systems Incorporated) Hidden
Platform (Version: 1.34 - VIA Technologies, Inc.) Hidden
Python 3.3.3 (Version: 3.3.3150 - Python Software Foundation)
RocketDock 1.3.5 (Version: - Punk Software)
RollerCoaster Tycoon 3 (Version: - Atari)
Samsung SSD Magician (Version: 3.2 - Samsung Electronics)
SAMSUNG USB Driver for Mobile Phones (Version: 1.3.1500.0 - SAMSUNG Electronics Co., Ltd.)
Service Pack 1 für SQL Server 2008 (KB 968369) (Version: 10.1.2531.0 - Microsoft Corporation)
Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.)
Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
StreamTransport version: 1.0.2.2171 (Version: - )
Suite Shared Configuration CS4 (Version: 1.0 - Adobe Systems Incorporated) Hidden
UltraISO Premium V9.53 (Version: - )
Undelete 360 (Version: - File Recovery Ltd.)
Unity Web Player (HKCU Version: - Unity Technologies ApS)
Unterstützungsdateien für Microsoft SQL Server 2008-Setup (Version: 10.1.2731.0 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0 - DivX, Inc) Hidden
VIA Plattform-Geräte-Manager (Version: 1.34 - VIA Technologies, Inc.)
Visual C++ 9.0 Runtime for Dragon NaturallySpeaking (Version: 11.0.200 - Nuance Communications Inc.)
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (Version: 4.0.8080.0 - Microsoft Corporation)
VLC media player 2.0.5 (Version: 2.0.5 - VideoLAN)
Winamp (Version: 5.666 - Nullsoft, Inc)
WinSetupFromUSB (HKCU Version: - )
YoTuberAaDusRemov (Version: - YoTuuBeorAddsuRemoov)
==================== Restore Points =========================
10-01-2014 21:31:34 Windows Update
10-01-2014 21:50:26 Windows Update
12-01-2014 20:30:42 Installed Python 3.3.3
13-01-2014 14:34:42 Installed AMD APP SDK 2.9.
14-01-2014 16:13:23 Windows Update
15-01-2014 19:40:45 Gerätetreiber-Paketinstallation: Anchorfree Inc Netzwerkdienst
15-01-2014 19:41:05 Gerätetreiber-Paketinstallation: Anchorfree HSS VPN Adapter Netzwerkadapter
15-01-2014 19:43:46 Removed AMD APP SDK 2.9.
15-01-2014 22:11:26 Windows Update
20-01-2014 16:19:01 Windows Update
23-01-2014 16:37:40 Windows Update
28-01-2014 18:05:49 Windows Update
02-02-2014 12:43:26 Windows Update
05-02-2014 17:36:45 Windows Update
08-02-2014 22:26:15 Windows Update
12-02-2014 15:57:37 Windows Update
12-02-2014 18:08:49 Windows Update
16-02-2014 08:57:12 Windows Update
19-02-2014 20:34:11 Windows Update
==================== Hosts content: ==========================
2013-12-19 19:56 - 2013-12-19 19:56 - 00006661 ____A C:\Windows\system32\Drivers\etc\hosts
192.168.178.1 fritz.box
There are 228 more lines.
==================== Scheduled Tasks (whitelisted) =============
Task: {02AA58BC-96A1-4068-8777-1BC60CBB340F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-29] (Google Inc.)
Task: {3E155AFB-8A3F-419B-A4C5-F0F6090CC2E4} - System32\Tasks\ScanToPCActivationApp.exe_{D3DC7982-3A07-4AE1-AC31-70313881F573} => C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {49265BB3-E432-4822-AFAB-58E3428513EF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-29] (Google Inc.)
Task: {7D3C7871-A917-4EF0-82E8-5F0A96423051} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => BthUdTask.exe
Task: {D21F6024-191F-4454-BBBC-09A650DA2549} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => aitagent.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-10-06 14:27 - 2013-10-06 14:27 - 00857600 _____ () C:\Program Files\Sk.Enhancer\psupport.dll
2014-02-09 01:00 - 2014-02-09 01:00 - 04197376 _____ () C:\ProgramData\KeepnBrowse\KeepnBrowse.dll
2014-02-09 01:00 - 2014-02-09 01:00 - 00179024 _____ () C:\ProgramData\KeepnBrowse\keepnbrowseSvc.dll
2012-11-16 15:26 - 2012-11-16 15:26 - 00065024 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2013-03-21 21:07 - 2007-09-02 13:57 - 00069632 _____ () C:\Program Files\RocketDock\RocketDock.dll
2013-05-10 19:56 - 2013-05-10 19:56 - 00093696 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2013-03-21 21:50 - 2011-05-06 14:11 - 00080496 _____ () C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
2013-03-21 21:50 - 2011-05-06 14:11 - 00113264 _____ () C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
2013-03-21 21:50 - 2011-05-06 14:11 - 00623216 _____ () C:\Program Files\VIA\VIAudioi\VDeck\Skin.dll
2013-03-21 21:07 - 2007-09-02 13:58 - 00495616 _____ () C:\Program Files\RocketDock\RocketDock.exe
2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Henry.Henry-PC\AppData\Roaming\Dropbox\bin\libcef.dll
2014-02-16 10:15 - 2014-02-02 00:41 - 00715592 _____ () C:\Program Files\Google\Chrome\Application\32.0.1700.107\libglesv2.dll
2014-02-16 10:15 - 2014-02-02 00:41 - 00100168 _____ () C:\Program Files\Google\Chrome\Application\32.0.1700.107\libegl.dll
2014-02-16 10:15 - 2014-02-02 00:42 - 04055368 _____ () C:\Program Files\Google\Chrome\Application\32.0.1700.107\pdf.dll
2014-02-16 10:15 - 2014-02-02 00:42 - 00399688 _____ () C:\Program Files\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll
2014-02-16 10:15 - 2014-02-02 00:41 - 01634632 _____ () C:\Program Files\Google\Chrome\Application\32.0.1700.107\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:0FF263E8
AlternateDataStreams: C:\ProgramData\TEMP:FB1B13D8
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: bthserv => 3
MSCONFIG\Services: defragsvc => 3
MSCONFIG\Services: DragonSvc => 2
MSCONFIG\Services: ehRecvr => 3
MSCONFIG\Services: ehSched => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: HomeGroupListener => 3
MSCONFIG\Services: HomeGroupProvider => 3
MSCONFIG\Services: MpsSvc => 2
MSCONFIG\Services: MSSQL$SQLEXPRESS => 2
MSCONFIG\Services: p2pimsvc => 3
MSCONFIG\Services: p2psvc => 3
MSCONFIG\Services: SCardSvr => 3
MSCONFIG\Services: SCPolicySvc => 3
MSCONFIG\Services: SDRSVC => 3
MSCONFIG\Services: seclogon => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: sppuinotify => 3
MSCONFIG\Services: SQLWriter => 2
MSCONFIG\Services: SSDPSRV => 3
MSCONFIG\Services: SysMain => 2
MSCONFIG\Services: TrkWks => 2
MSCONFIG\Services: WinDefend => 3
MSCONFIG\Services: WMPNetworkSvc => 2
MSCONFIG\Services: wscsvc => 2
MSCONFIG\Services: WSearch => 2
MSCONFIG\startupfolder: C:^Users^Henry.Henry-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Samsung SSD Magician.lnk => C:\Windows\pss\Samsung SSD Magician.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeCS4ServiceManager => "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: AVMWlanClient => C:\Program Files\avmwlanstick\wlangui.exe
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: DNS7reminder => "C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini"
MSCONFIG\startupreg: HP Officejet 6500 E710n-z (NET) => "C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe" -deviceID "CN18T3305005JW:NW" -scfn "HP Officejet 6500 E710n-z (NET)" -AutoStart 1
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: KiesAirMessage => C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
MSCONFIG\startupreg: KiesPreload => C:\Program Files\Samsung\Kies\Kies.exe /preload
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: StartCCC => "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/19/2014 09:34:11 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {0712453f-b3e4-4fdf-8527-dd145f14b682}
Error: (02/16/2014 09:57:12 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {7cab7fef-e997-478f-91b4-a79c42027e64}
Error: (02/13/2014 08:40:42 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (02/13/2014 08:39:31 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (02/12/2014 07:08:49 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {4f1b898c-4ae3-4ee2-83f4-18e712575ac0}
Error: (02/12/2014 04:57:37 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {5999bac8-7ce0-4727-b4ce-8adb315dec69}
Error: (02/08/2014 11:26:15 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {aa16bea3-d142-4a37-aafc-3037999e0239}
Error: (02/05/2014 06:36:45 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {7c1a15dc-7e5d-45c7-8574-ae0a47fe736b}
Error: (02/02/2014 01:43:26 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {a9b05f87-2c7c-4627-ad08-70d99ec8574f}
Error: (02/01/2014 09:22:44 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 31.0.1650.63, Zeitstempel: 0x529e8b45
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc000000d
Fehleroffset: 0x00097ca1
ID des fehlerhaften Prozesses: 0x274
Startzeit der fehlerhaften Anwendung: 0xchrome.exe0
Pfad der fehlerhaften Anwendung: chrome.exe1
Pfad des fehlerhaften Moduls: chrome.exe2
Berichtskennung: chrome.exe3
System errors:
=============
Error: (02/21/2014 01:37:39 PM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Error: (02/20/2014 05:17:47 PM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Error: (02/19/2014 09:27:27 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "UPnP-Gerätehost" ist vom Dienst "SSDP-Suche" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (02/19/2014 09:27:27 PM) (Source: DCOM) (User: )
Description: 1068upnphost{204810B9-73B2-11D4-BF42-00B0D0118B56}
Error: (02/19/2014 09:23:11 PM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Error: (02/19/2014 05:53:50 PM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Error: (02/18/2014 06:23:36 PM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Error: (02/16/2014 09:46:05 AM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Error: (02/15/2014 06:04:14 PM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Error: (02/15/2014 01:41:08 PM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Microsoft Office Sessions:
=========================
Error: (02/19/2014 09:34:11 PM) (Source: VSS)(User: )
Description: ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {0712453f-b3e4-4fdf-8527-dd145f14b682}
Error: (02/16/2014 09:57:12 AM) (Source: VSS)(User: )
Description: ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {7cab7fef-e997-478f-91b4-a79c42027e64}
Error: (02/13/2014 08:40:42 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Microsoft Visual Studio 10.0\Common7\Packages\Debugger\X64\msvsmon.exe
Error: (02/13/2014 08:39:31 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\HP\HP Officejet 6500 E710n-z\DriverStore\Pipeline\amd64\hpinkins5412.exe
Error: (02/12/2014 07:08:49 PM) (Source: VSS)(User: )
Description: ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {4f1b898c-4ae3-4ee2-83f4-18e712575ac0}
Error: (02/12/2014 04:57:37 PM) (Source: VSS)(User: )
Description: ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {5999bac8-7ce0-4727-b4ce-8adb315dec69}
Error: (02/08/2014 11:26:15 PM) (Source: VSS)(User: )
Description: ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {aa16bea3-d142-4a37-aafc-3037999e0239}
Error: (02/05/2014 06:36:45 PM) (Source: VSS)(User: )
Description: ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {7c1a15dc-7e5d-45c7-8574-ae0a47fe736b}
Error: (02/02/2014 01:43:26 PM) (Source: VSS)(User: )
Description: ConvertStringSidToSid(S-1-5-21-1978416703-2945353608-3729288318-1001.old)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt
Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {a9b05f87-2c7c-4627-ad08-70d99ec8574f}
Error: (02/01/2014 09:22:44 PM) (Source: Application Error)(User: )
Description: chrome.exe31.0.1650.63529e8b45ntdll.dll6.1.7601.18247521ea91cc000000d00097ca127401cf1f8b1d5e79a0C:\Program Files\Google\Chrome\Application\chrome.exeC:\Windows\SYSTEM32\ntdll.dll9b039864-8b7e-11e3-b170-001f3f036cb6
==================== Memory info ===========================
Percentage of memory in use: 43%
Total physical RAM: 3326.18 MB
Available physical RAM: 1874.55 MB
Total Pagefile: 3324.47 MB
Available Pagefile: 1689.68 MB
Total Virtual: 2047.88 MB
Available Virtual: 1885.29 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:111.79 GB) (Free:78.34 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Daten) (Fixed) (Total:39.06 GB) (Free:5.79 GB) NTFS
Drive g: (Volume) (Fixed) (Total:109.85 GB) (Free:87.6 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: BA3C0452)
Partition: GPT Partition Type.
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 0ABC0ABC)
Partition: GPT Partition Type.
==================== End Of Log ============================ |