Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Virus auf USB-Stick? (https://www.trojaner-board.de/154028-virus-usb-stick.html)

Nirtaka 18.05.2014 12:55

Virus auf USB-Stick?
 
Hallo Ihr Lieben

Ich bin mir nicht sicher ob ich einen Virus auf meinem USB Stick habe. Aber zumindest sind iwelche Dateien mit wirren Zeichen aufgetaucht und da ist eine Datei bei die, wenn ich sie lösche, immer wieder auftaucht. Das ist leider der Stick auf dem ich die meisten wichtigen Dokumente oder auch Bilder gespeichert habe. Wie kann ich den Stick bereinigen ohne die Daten zu verlieren? Oder überhaupt zu checken ob der Stick verseucht ist? :eek:

Viele Grüße Kati

sunjojo 18.05.2014 13:05

Hallo Nirtaka, :hallo:

mein Name ist Jonas und ich werde dir bei deiner Bereinigung helfen. Diese kann mit viel Arbeit für dich verbunden sein. Bevor wir anfangen können, lies bitte die Bereinigungsregeln und Hinweise:
Regeln zum Ablauf der Bereinigung
  • Arbeite die Anleitungen und Schritte sorgfältig und nacheinander ab.
  • Wenn du etwas nicht verstehst oder du dir unsicher bist, frage nach und schildere das Problem, so gut es geht. Handle nicht auf eigene Faust.
    • Die Ausführung diverser Bereinigungsprogramme (mit Scripts aus anderen Threads) können dein Betriebssystem zerschießen!
  • Die Bereinigung eines Rechners in verschiedenen Foren zur selben Zeit ist verboten (Crossposting).
  • Installiere oder deinstalliere keine zusätzlichen Programme, lösche keine Dateien und führe nicht selbstständig Systemupdates durch.
  • Die Symptome können verschwunden sein, jedoch bedeutet das Verschwinden von äußeren Merkmalen einer Infektion nicht, dass du wieder clean bist.
    • Ich werde dir ein eindeutiges Clean geben, solange arbeite bitte mit.
Hinweis
  • Die von uns benutzten Programme erstellen meist ein Ergebnisprotokoll (Logfile genannt). Bitte füge alle von mir in einem Schritt geforderten Logfiles in einer Antwort/einem Post ein.
Wenn du alles gelesen hast, kann es losgehen. Bitte speichere alle Programme auf dem Desktop und führe sie von dort aus. :)



Schritt 1
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Poste folgende Logfiles in deiner nächsten Antwort:
  • FRST.txt und Addition.txt

Nirtaka 18.05.2014 13:40

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014
Ran by Kati (administrator) on KATI-PC on 18-05-2014 14:32:59
Running from C:\Users\Kati\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(BUP) C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Facebook Inc.) C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
(Spotify Ltd) C:\Users\Kati\AppData\Roaming\Spotify\spotify.exe
(Spotify Ltd) C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIGJE.EXE
(simplitec) C:\Program Files (x86)\simplitec\simplicheck\simplicheck.exe
(Dropbox, Inc.) C:\Users\Kati\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\POsd.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
() C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Farbar) C:\Users\Kati\Downloads\FRST64(1).exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-22] (Alcor Micro Corp.)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [MedionReminder] => C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [PHotkey] => C:\Program Files (x86)\PHotkey\PHotkey.exe [819720 2011-02-23] (Pegatron Corporation)
HKLM-x32\...\Run: [MsgTranAgt] => C:\Program Files (x86)\PHotkey\MsgTranAgt.exe [117256 2010-01-12] ()
HKLM-x32\...\Run: [MsgTranAgt64] => C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe [121864 2010-01-12] ()
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [847872 2009-12-03] (SEIKO EPSON CORPORATION)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Facebook Update] => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-09-20] (Facebook Inc.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [449760 2013-10-31] (Sony)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Spotify] => C:\Users\Kati\AppData\Roaming\Spotify\Spotify.exe [6170168 2014-05-15] (Spotify Ltd)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Spotify Web Helper] => C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-15] (Spotify Ltd)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-09-20] (Google Inc.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [EPSON BX305 Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGJE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk
ShortcutTarget: simplicheck.lnk -> C:\Program Files (x86)\simplitec\simplicheck\simplicheck.exe (simplitec)
Startup: C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Kati\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9A119BA29CEBCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: No Name - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - C:\Users\Kati\AppData\LocalLow\systems ie bho\bho.dll ()
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default
FF user.js: detected! => C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 - C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Kati\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: sony.com/MediaGoDetector - C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\Kati\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Foxy Security - C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\Extensions\sys@foxysecurity.com [2014-04-28]
FF Extension: DownloadHelper - C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-31]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2013-09-11]

Chrome:
=======
CHR HomePage:
CHR DefaultSearchKeyword: delta-search.com
CHR DefaultSearchProvider: Delta Search
CHR DefaultSearchURL: hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=FA2578929C739985&affID=121562&tt=250613_gr4&tsp=4928
CHR DefaultNewTabURL:
CHR Extension: (DVDVideoSoft) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-12-24]
CHR Extension: (Google Wallet) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-03]
CHR Extension: (Citavi Picker) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\piehhloihgjjiomhieeddiidpekaajio [2013-12-24]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-06-29]
CHR HKLM-x32\...\Chrome\Extension: [dghncoeocefmhkhiphdgikkamjeglbfh] - C:\Program Files (x86)\mystarttb\chrome-newtab-search.crx [2013-06-29]
CHR HKLM-x32\...\Chrome\Extension: [piehhloihgjjiomhieeddiidpekaajio] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Chrome\ChromePicker.crx [2013-09-11]

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 bupService; C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe [642048 2014-04-14] (BUP)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-06] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-30] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-30] (pdfforge GmbH)
S2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [X]
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe" [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-18 14:23 - 2014-05-18 14:23 - 02067456 _____ (Farbar) C:\Users\Kati\Downloads\FRST64(1).exe
2014-05-18 13:50 - 2014-05-18 13:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{422F2530-3EF2-4E9C-A789-485C1206D1AC}
2014-05-17 23:57 - 2014-05-17 23:59 - 00000000 ____D () C:\Users\Kati\Desktop\Fotos
2014-05-17 23:56 - 2014-05-17 23:58 - 00000000 ____D () C:\Users\Kati\Desktop\Kinderfotos
2014-05-17 23:51 - 2014-05-17 23:55 - 00000000 ____D () C:\Users\Kati\Downloads\Uni
2014-05-17 22:55 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-05-17 22:55 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-17 22:55 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-17 22:55 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-05-17 22:55 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-05-17 22:55 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-05-17 22:55 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-05-17 22:55 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-05-17 22:55 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-05-17 22:55 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-05-17 22:55 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-05-17 22:55 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-05-17 22:55 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-05-17 22:55 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-05-17 22:55 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-05-17 22:55 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-05-17 22:55 - 2013-10-01 22:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-05-17 22:55 - 2013-10-01 22:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-05-17 22:54 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-05-17 22:54 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-05-17 22:08 - 2014-05-17 22:08 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4BE87CCE-750B-4228-B62E-246699B53E05}
2014-05-17 20:59 - 2014-05-17 20:59 - 00383343 _____ () C:\Users\Kati\Desktop\Report.htm
2014-05-17 20:58 - 2014-05-17 20:58 - 00000000 ____D () C:\Users\Kati\Documents\EVEREST Reports
2014-05-17 20:41 - 2014-05-17 20:42 - 215448505 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\wlane6221_inw7.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 18857054 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\tpde6221_se_wxpvstw7_32_64.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 09144982 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\usb3e6221_e722xw7.exe
2014-05-17 20:39 - 2014-05-17 20:40 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(2).exe
2014-05-17 20:39 - 2014-05-17 20:39 - 31119378 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\mnme6221_e722xvstw7_w8.exe
2014-05-17 20:39 - 2014-05-17 20:39 - 02620971 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\lane6221_e722xxpvstw7.exe
2014-05-17 20:38 - 2014-05-17 20:38 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8(1).exe
2014-05-17 20:34 - 2014-05-17 20:37 - 195993064 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\vgae6221_e722x_in_w7_w8.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 03987373 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\chpe6221_e722xxpvstw7.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 01798895 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\bioe722x_p762x.exe
2014-05-17 20:33 - 2014-05-17 20:34 - 11290483 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ahcie6221vstw7_w8.exe
2014-05-17 20:31 - 2014-05-17 20:31 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8.exe
2014-05-17 20:26 - 2014-05-17 20:26 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(1).exe
2014-05-17 20:25 - 2014-05-17 20:25 - 00229008 _____ () C:\Users\Kati\Downloads\MEDION_Treibersuche.exe
2014-05-17 20:18 - 2014-05-17 20:18 - 00001130 _____ () C:\Users\Kati\Desktop\EVEREST Ultimate Edition.lnk
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\Program Files (x86)\Lavalys
2014-05-17 20:17 - 2014-05-17 20:17 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Kati\Downloads\everestultimate550.exe
2014-05-17 18:20 - 2014-05-17 18:45 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-17 18:20 - 2014-05-17 18:20 - 00001266 _____ () C:\Users\Public\Desktop\NCH Software.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\Users\Public\Desktop\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001142 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\ProgramData\NCH Software
2014-05-17 18:19 - 2014-05-17 18:43 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\NCH Software
2014-05-17 18:19 - 2014-05-17 18:20 - 00000000 ____D () C:\Program Files (x86)\NCH Software
2014-05-17 18:19 - 2014-05-17 18:19 - 00001130 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00001118 _____ () C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:18 - 2014-05-17 18:18 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kati\Downloads\Debut Video Capture - CHIP-Downloader.exe
2014-05-16 22:17 - 2014-05-16 22:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2611705F-FCFF-44F2-9C4B-EC29E5A67B46}
2014-05-16 09:09 - 2014-05-16 09:09 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69A1EF25-1F79-4775-BA26-5F9375FE9B95}
2014-05-16 08:35 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-16 08:35 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-16 08:35 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-16 08:35 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-16 08:35 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-16 08:35 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 14:27 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-15 14:27 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-15 14:27 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 14:27 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-15 14:26 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 14:26 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 14:26 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 14:26 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 14:26 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-15 14:26 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-15 14:26 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 14:26 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 14:26 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 14:26 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 14:26 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 14:26 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-15 14:26 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-15 14:17 - 2014-05-15 14:18 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4DD5F804-7106-4564-8BC2-F943268098E6}
2014-05-14 19:25 - 2014-05-14 19:25 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:12 - 00001021 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-05-14 19:12 - 2014-05-14 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-14 19:11 - 2014-05-14 19:12 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-14 19:11 - 2014-05-14 19:11 - 00000000 ____D () C:\Users\Kati\Documents\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:12 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-14 19:10 - 2014-05-14 19:10 - 00001039 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\pdfforge
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-14 19:10 - 2014-04-25 17:44 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-05-14 19:10 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-05-14 19:10 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6DE.DLL
2014-05-14 19:10 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCDE.DLL
2014-05-14 19:10 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCC2DE.DLL
2014-05-14 19:07 - 2014-05-14 19:08 - 27843432 _____ (pdfforge ) C:\Users\Kati\Downloads\PDFCreator-1_7_3_setup.exe
2014-05-14 16:28 - 2014-05-14 16:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{AFF51EAF-1EEE-4D30-9A8D-532258456C17}
2014-05-13 17:17 - 2014-05-13 17:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B0C594E1-1C40-46AD-9B29-7C5B4986A6E6}
2014-05-13 16:53 - 2014-05-13 16:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{98AC1C21-B103-44EE-AC7B-2C114FD85585}
2014-05-12 20:54 - 2014-05-12 20:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{BE16BDD7-B89C-4024-B9F6-AD6FF1E9E786}
2014-05-11 19:59 - 2014-05-11 19:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-11 19:46 - 2014-05-11 19:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{C2B4150E-0C6B-4799-9C08-B1E8DFC269ED}
2014-05-10 21:55 - 2014-05-10 21:55 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9A0AD5CC-139C-491B-9266-50616B3EF2EC}
2014-05-09 17:57 - 2014-05-09 17:57 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9C638A68-5F34-48C1-898B-3689CD978999}
2014-05-08 15:00 - 2014-05-08 15:00 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B51A953C-DD2F-4FB8-AA87-F6AD0AFB9AC2}
2014-05-07 19:04 - 2014-05-16 08:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-07 19:04 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-07 19:04 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-07 19:04 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-07 19:04 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-07 19:04 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-07 19:04 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-07 19:04 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-07 19:04 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-07 19:04 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-07 19:04 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-07 19:04 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-07 19:04 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-07 19:04 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-07 19:04 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-07 19:04 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-07 19:04 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-07 19:04 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-07 19:04 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-07 19:04 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-07 19:04 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-07 19:04 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-07 19:04 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-07 19:04 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-07 19:04 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-07 19:04 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-07 19:04 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-07 19:04 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-07 19:04 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-07 19:04 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-07 19:04 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-07 19:04 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-07 19:04 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-07 19:04 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-07 19:04 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-07 19:04 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-07 19:04 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-07 19:04 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-07 19:04 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-07 19:04 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-07 19:04 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-07 19:04 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-07 19:04 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-07 19:04 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-07 19:04 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-07 19:02 - 2014-05-07 19:03 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DFB33308-901D-4EAF-9C6E-A5DEA8364065}
2014-05-06 15:35 - 2014-05-06 15:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{01097470-E215-4F09-8B1E-B904D4356792}
2014-05-05 18:20 - 2014-05-05 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Local\{8837D2BF-2261-45A5-975D-F775DFD9FD39}
2014-05-04 21:59 - 2014-05-04 21:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{30370F42-121E-48B3-B315-481D08085F3A}
2014-05-03 21:27 - 2014-05-03 21:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DB63567F-3788-43B8-BCFB-ED07BD306540}
2014-05-03 02:36 - 2014-05-03 02:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3CD5C54C-8659-40F2-AE16-BB7B404718E6}
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-05-02 14:35 - 2014-05-02 14:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DC60EB2C-B723-4FA9-A38E-31AC1A6775EA}
2014-05-01 13:21 - 2014-05-01 13:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B1833989-708E-4FC2-AADF-908BFAC0A56F}
2014-04-30 18:53 - 2014-04-30 18:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5EF441A7-91AC-4C8E-9DF8-3CA8C25B701E}
2014-04-29 16:21 - 2014-04-29 16:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6AB88698-1939-4E66-BCF8-9C5E2800911A}
2014-04-28 17:05 - 2014-04-28 17:05 - 00128000 ____H () C:\Users\Kati\Desktop\photothumb.db
2014-04-28 17:04 - 2014-04-28 17:06 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PhotoScape
2014-04-28 17:04 - 2014-04-28 17:04 - 00001039 _____ () C:\Users\Kati\Desktop\PhotoScape.lnk
2014-04-28 17:04 - 2014-04-28 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2014-04-28 17:03 - 2014-04-28 17:04 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Security Systems
2014-04-28 17:03 - 2014-04-28 17:04 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-04-28 17:03 - 2014-04-28 17:03 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\BupSystem
2014-04-28 17:02 - 2014-04-28 17:03 - 21331096 _____ (Mooii) C:\Users\Kati\Desktop\PhotoScape_V3-6-5.exe
2014-04-28 17:00 - 2014-04-28 17:00 - 00386904 _____ (Softonic ) C:\Users\Kati\Downloads\SoftonicDownloader_fuer_photoscape.exe
2014-04-28 16:22 - 2014-04-28 16:22 - 00000000 ____D () C:\Users\Kati\AppData\Local\{E6EF1C33-8457-4043-B475-28B37C804CF7}
2014-04-27 12:51 - 2014-04-27 12:51 - 00000000 ____D () C:\Users\Kati\AppData\Local\{50566B36-6424-40FE-8E57-875DA3FE0D99}
2014-04-26 20:36 - 2014-04-26 20:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3B71D42C-D487-4B7F-A90D-DF6ABC7D9BEE}
2014-04-26 02:43 - 2014-04-26 02:44 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B4704FBF-46C6-4E83-9C9B-F811FBCF29C8}
2014-04-25 14:36 - 2014-04-25 14:37 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3D4FFA91-C31D-42D3-98D3-55D24540A116}
2014-04-24 20:48 - 2014-04-24 20:48 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6B75591B-A85D-449D-8566-C3803B21D41A}
2014-04-23 19:06 - 2014-04-23 19:06 - 00000000 ____D () C:\Users\Kati\AppData\Local\{05C9CB18-5353-481E-B307-AC526C8EAD50}
2014-04-22 17:25 - 2014-04-22 17:25 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DEA26C1D-154A-44C1-B6B0-8D0C9CE3E56A}
2014-04-22 01:11 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-22 01:11 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-22 01:11 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-22 01:11 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-22 01:11 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-22 01:11 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-22 01:11 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-22 01:11 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-22 01:11 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-22 01:11 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-22 01:11 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-22 01:11 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-22 01:11 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-22 00:59 - 2014-04-22 00:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5A0297BB-2640-42E9-B94D-6AD8D30F5957}

==================== One Month Modified Files and Folders =======

2014-05-18 14:33 - 2013-11-29 01:51 - 00019052 _____ () C:\Users\Kati\Downloads\FRST.txt
2014-05-18 14:32 - 2013-11-26 14:29 - 00000000 ____D () C:\FRST
2014-05-18 14:27 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-18 14:27 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-18 14:23 - 2014-05-18 14:23 - 02067456 _____ (Farbar) C:\Users\Kati\Downloads\FRST64(1).exe
2014-05-18 14:19 - 2012-09-20 19:21 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-18 14:08 - 2012-09-20 21:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-18 14:03 - 2013-07-24 18:55 - 01992708 _____ () C:\Windows\WindowsUpdate.log
2014-05-18 13:50 - 2014-05-18 13:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{422F2530-3EF2-4E9C-A789-485C1206D1AC}
2014-05-18 13:36 - 2012-11-10 23:07 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Spotify
2014-05-18 13:24 - 2012-09-20 22:19 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001UA.job
2014-05-18 13:06 - 2012-09-20 19:21 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-18 13:05 - 2012-09-21 13:58 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\SoftGrid Client
2014-05-18 12:34 - 2014-02-24 22:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\Windows Live
2014-05-18 12:07 - 2011-05-16 16:04 - 00699794 _____ () C:\Windows\system32\perfh007.dat
2014-05-18 12:07 - 2011-05-16 16:04 - 00149644 _____ () C:\Windows\system32\perfc007.dat
2014-05-18 12:07 - 2009-07-14 07:13 - 01620836 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-18 12:04 - 2014-01-27 22:53 - 00000470 _____ () C:\Windows\Tasks\SDMsgUpdate (TE).job
2014-05-18 12:03 - 2014-01-08 01:02 - 00000000 ___RD () C:\Users\Kati\Dropbox
2014-05-18 12:03 - 2014-01-08 01:00 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Dropbox
2014-05-18 12:01 - 2014-01-27 22:53 - 00000478 _____ () C:\Windows\Tasks\SDMsgUpdate (Local).job
2014-05-18 12:01 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-18 12:01 - 2009-07-14 06:51 - 02331598 _____ () C:\Windows\setupact.log
2014-05-17 23:59 - 2014-05-17 23:57 - 00000000 ____D () C:\Users\Kati\Desktop\Fotos
2014-05-17 23:58 - 2014-05-17 23:56 - 00000000 ____D () C:\Users\Kati\Desktop\Kinderfotos
2014-05-17 23:55 - 2014-05-17 23:51 - 00000000 ____D () C:\Users\Kati\Downloads\Uni
2014-05-17 23:52 - 2013-11-24 21:13 - 00000000 ____D () C:\Users\Kati\Downloads\verschiedene Bilder
2014-05-17 22:24 - 2012-09-20 22:19 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001Core.job
2014-05-17 22:08 - 2014-05-17 22:08 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4BE87CCE-750B-4228-B62E-246699B53E05}
2014-05-17 20:59 - 2014-05-17 20:59 - 00383343 _____ () C:\Users\Kati\Desktop\Report.htm
2014-05-17 20:58 - 2014-05-17 20:58 - 00000000 ____D () C:\Users\Kati\Documents\EVEREST Reports
2014-05-17 20:48 - 2012-09-23 18:09 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Skype
2014-05-17 20:42 - 2014-05-17 20:41 - 215448505 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\wlane6221_inw7.exe
2014-05-17 20:42 - 2013-12-16 20:47 - 00000000 ____D () C:\Medion
2014-05-17 20:40 - 2014-05-17 20:40 - 18857054 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\tpde6221_se_wxpvstw7_32_64.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 09144982 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\usb3e6221_e722xw7.exe
2014-05-17 20:40 - 2014-05-17 20:39 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(2).exe
2014-05-17 20:39 - 2014-05-17 20:39 - 31119378 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\mnme6221_e722xvstw7_w8.exe
2014-05-17 20:39 - 2014-05-17 20:39 - 02620971 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\lane6221_e722xxpvstw7.exe
2014-05-17 20:38 - 2014-05-17 20:38 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8(1).exe
2014-05-17 20:37 - 2014-05-17 20:34 - 195993064 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\vgae6221_e722x_in_w7_w8.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 03987373 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\chpe6221_e722xxpvstw7.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 01798895 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\bioe722x_p762x.exe
2014-05-17 20:34 - 2014-05-17 20:33 - 11290483 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ahcie6221vstw7_w8.exe
2014-05-17 20:31 - 2014-05-17 20:31 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8.exe
2014-05-17 20:26 - 2014-05-17 20:26 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(1).exe
2014-05-17 20:25 - 2014-05-17 20:25 - 00229008 _____ () C:\Users\Kati\Downloads\MEDION_Treibersuche.exe
2014-05-17 20:18 - 2014-05-17 20:18 - 00001130 _____ () C:\Users\Kati\Desktop\EVEREST Ultimate Edition.lnk
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\Program Files (x86)\Lavalys
2014-05-17 20:17 - 2014-05-17 20:17 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Kati\Downloads\everestultimate550.exe
2014-05-17 18:45 - 2014-05-17 18:20 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-17 18:43 - 2014-05-17 18:19 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\NCH Software
2014-05-17 18:20 - 2014-05-17 18:20 - 00001266 _____ () C:\Users\Public\Desktop\NCH Software.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\Users\Public\Desktop\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001142 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\ProgramData\NCH Software
2014-05-17 18:20 - 2014-05-17 18:19 - 00000000 ____D () C:\Program Files (x86)\NCH Software
2014-05-17 18:19 - 2014-05-17 18:19 - 00001130 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00001118 _____ () C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:18 - 2014-05-17 18:18 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kati\Downloads\Debut Video Capture - CHIP-Downloader.exe
2014-05-16 22:17 - 2014-05-16 22:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2611705F-FCFF-44F2-9C4B-EC29E5A67B46}
2014-05-16 10:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-16 09:12 - 2013-01-07 00:52 - 00002023 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-05-16 09:12 - 2011-06-28 21:31 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-16 09:09 - 2014-05-16 09:09 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69A1EF25-1F79-4775-BA26-5F9375FE9B95}
2014-05-16 09:06 - 2012-09-20 18:26 - 00000000 ___RD () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-16 09:06 - 2012-09-20 18:26 - 00000000 ___RD () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 08:55 - 2014-05-07 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-16 08:34 - 2013-07-29 22:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-16 08:31 - 2013-07-25 12:48 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-16 00:24 - 2012-09-20 19:21 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-05-15 15:18 - 2012-11-10 23:07 - 00000000 ____D () C:\Users\Kati\AppData\Local\Spotify
2014-05-15 14:18 - 2014-05-15 14:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4DD5F804-7106-4564-8BC2-F943268098E6}
2014-05-14 19:25 - 2014-05-14 19:25 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:12 - 00001021 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-05-14 19:12 - 2014-05-14 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:11 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:10 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-14 19:11 - 2014-05-14 19:11 - 00000000 ____D () C:\Users\Kati\Documents\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00001039 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\pdfforge
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-14 19:08 - 2014-05-14 19:07 - 27843432 _____ (pdfforge ) C:\Users\Kati\Downloads\PDFCreator-1_7_3_setup.exe
2014-05-14 17:08 - 2013-12-16 21:08 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 17:08 - 2012-09-20 21:54 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-14 17:08 - 2011-07-18 19:57 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-14 16:28 - 2014-05-14 16:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{AFF51EAF-1EEE-4D30-9A8D-532258456C17}
2014-05-14 16:06 - 2014-01-08 01:02 - 00001017 _____ () C:\Users\Kati\Desktop\Dropbox.lnk
2014-05-14 16:06 - 2014-01-08 01:01 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-13 17:17 - 2014-05-13 17:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B0C594E1-1C40-46AD-9B29-7C5B4986A6E6}
2014-05-13 16:54 - 2014-05-13 16:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{98AC1C21-B103-44EE-AC7B-2C114FD85585}
2014-05-13 16:49 - 2014-01-29 16:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-12 20:54 - 2014-05-12 20:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{BE16BDD7-B89C-4024-B9F6-AD6FF1E9E786}
2014-05-11 22:59 - 2013-09-30 12:13 - 00000000 ____D () C:\Users\Kati\Documents\Citavi 4
2014-05-11 19:59 - 2014-05-11 19:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-11 19:46 - 2014-05-11 19:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{C2B4150E-0C6B-4799-9C08-B1E8DFC269ED}
2014-05-10 21:55 - 2014-05-10 21:55 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9A0AD5CC-139C-491B-9266-50616B3EF2EC}
2014-05-09 17:57 - 2014-05-09 17:57 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9C638A68-5F34-48C1-898B-3689CD978999}
2014-05-09 08:14 - 2014-05-15 14:27 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 14:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-08 15:00 - 2014-05-08 15:00 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B51A953C-DD2F-4FB8-AA87-F6AD0AFB9AC2}
2014-05-07 20:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-07 19:03 - 2014-05-07 19:02 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DFB33308-901D-4EAF-9C6E-A5DEA8364065}
2014-05-06 15:35 - 2014-05-06 15:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{01097470-E215-4F09-8B1E-B904D4356792}
2014-05-06 06:40 - 2014-05-16 08:35 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-16 08:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-16 08:35 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-16 08:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-16 08:35 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-16 08:35 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-05 23:14 - 2012-09-20 19:21 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-05 23:14 - 2012-09-20 19:21 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-05 18:20 - 2014-05-05 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Local\{8837D2BF-2261-45A5-975D-F775DFD9FD39}
2014-05-04 21:59 - 2014-05-04 21:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{30370F42-121E-48B3-B315-481D08085F3A}
2014-05-03 21:28 - 2014-05-03 21:27 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DB63567F-3788-43B8-BCFB-ED07BD306540}
2014-05-03 02:36 - 2014-05-03 02:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3CD5C54C-8659-40F2-AE16-BB7B404718E6}
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-05-03 01:55 - 2013-04-19 13:10 - 00000000 ____D () C:\ProgramData\Sony Ericsson
2014-05-03 01:55 - 2013-04-19 13:10 - 00000000 ____D () C:\Program Files (x86)\Sony Ericsson
2014-05-02 14:36 - 2014-05-02 14:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DC60EB2C-B723-4FA9-A38E-31AC1A6775EA}
2014-05-01 13:21 - 2014-05-01 13:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B1833989-708E-4FC2-AADF-908BFAC0A56F}
2014-04-30 18:53 - 2014-04-30 18:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5EF441A7-91AC-4C8E-9DF8-3CA8C25B701E}
2014-04-29 16:21 - 2014-04-29 16:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6AB88698-1939-4E66-BCF8-9C5E2800911A}
2014-04-28 17:06 - 2014-04-28 17:04 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PhotoScape
2014-04-28 17:05 - 2014-04-28 17:05 - 00128000 ____H () C:\Users\Kati\Desktop\photothumb.db
2014-04-28 17:04 - 2014-04-28 17:04 - 00001039 _____ () C:\Users\Kati\Desktop\PhotoScape.lnk
2014-04-28 17:04 - 2014-04-28 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2014-04-28 17:04 - 2014-04-28 17:03 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Security Systems
2014-04-28 17:04 - 2014-04-28 17:03 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-04-28 17:03 - 2014-04-28 17:03 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\BupSystem
2014-04-28 17:03 - 2014-04-28 17:02 - 21331096 _____ (Mooii) C:\Users\Kati\Desktop\PhotoScape_V3-6-5.exe
2014-04-28 17:03 - 2012-09-20 18:26 - 00000000 ____D () C:\Users\Kati\AppData\Local\Google
2014-04-28 17:00 - 2014-04-28 17:00 - 00386904 _____ (Softonic ) C:\Users\Kati\Downloads\SoftonicDownloader_fuer_photoscape.exe
2014-04-28 16:22 - 2014-04-28 16:22 - 00000000 ____D () C:\Users\Kati\AppData\Local\{E6EF1C33-8457-4043-B475-28B37C804CF7}
2014-04-27 12:51 - 2014-04-27 12:51 - 00000000 ____D () C:\Users\Kati\AppData\Local\{50566B36-6424-40FE-8E57-875DA3FE0D99}
2014-04-26 20:36 - 2014-04-26 20:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3B71D42C-D487-4B7F-A90D-DF6ABC7D9BEE}
2014-04-26 02:44 - 2014-04-26 02:43 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B4704FBF-46C6-4E83-9C9B-F811FBCF29C8}
2014-04-25 17:44 - 2014-05-14 19:10 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-04-25 17:44 - 2014-05-14 19:10 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-04-25 17:44 - 2014-05-14 19:10 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2014-04-25 17:44 - 2014-05-14 19:10 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-04-25 17:44 - 2014-05-14 19:10 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-04-25 14:37 - 2014-04-25 14:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3D4FFA91-C31D-42D3-98D3-55D24540A116}
2014-04-24 20:48 - 2014-04-24 20:48 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6B75591B-A85D-449D-8566-C3803B21D41A}
2014-04-23 19:06 - 2014-04-23 19:06 - 00000000 ____D () C:\Users\Kati\AppData\Local\{05C9CB18-5353-481E-B307-AC526C8EAD50}
2014-04-22 17:25 - 2014-04-22 17:25 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DEA26C1D-154A-44C1-B6B0-8D0C9CE3E56A}
2014-04-22 01:00 - 2011-07-18 18:45 - 00298486 _____ () C:\Windows\DPINST.LOG
2014-04-22 00:59 - 2014-04-22 00:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5A0297BB-2640-42E9-B94D-6AD8D30F5957}

Some content of TEMP:
====================
C:\Users\Kati\AppData\Local\Temp\avgnt.exe
C:\Users\Kati\AppData\Local\Temp\burnsetup.exe
C:\Users\Kati\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp0pu8zb.dll
C:\Users\Kati\AppData\Local\Temp\FoxySecuritySetup.exe
C:\Users\Kati\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Kati\AppData\Local\Temp\Quarantine.exe
C:\Users\Kati\AppData\Local\Temp\sjy8mvbh.dll
C:\Users\Kati\AppData\Local\Temp\vpsetup.exe
C:\Users\Kati\AppData\Local\Temp\_is6454.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe
[2014-05-15 14:26] - [2014-03-04 11:43] - 0455168 ____A (Microsoft Corporation) 88AB9B72B4BF3963A0DE0820B4B0B06C

C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-09 20:47

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-05-2014
Ran by Kati at 2014-05-18 14:33:29
Running from C:\Users\Kati\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.7.0.19530 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 2.7.0.19530 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.8.1217.36096 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.8.1217.36096 - Alcor Micro Corp.) Hidden
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.35 - Atheros Communications Inc.)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
Citavi 4 (HKLM-x32\...\{CC0A85B2-734A-45B3-B678-05F6A6499AC7}) (Version: 4.1.0.3 - Swiss Academic Software)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.)
CyberLink LabelPrint (x32 Version: 2.5.3624 - CyberLink Corp.) Hidden
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1327 - CyberLink Corp.)
CyberLink Power2Go (x32 Version: 7.0.0.1327 - CyberLink Corp.) Hidden
CyberLink PowerDVD Copy (HKLM-x32\...\InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}) (Version: 1.5.1306 - CyberLink Corp.)
CyberLink PowerDVD Copy (x32 Version: 1.5.1306 - CyberLink Corp.) Hidden
CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.4125 - CyberLink Corp.)
CyberLink PowerRecover (x32 Version: 5.5.4125 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Debut Video Capture Software (HKLM-x32\...\Debut) (Version: 1.82 - NCH Software)
Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.7000.4 - Dolby Laboratories Inc)
Dropbox (HKCU\...\Dropbox) (Version: 2.6.33 - Dropbox, Inc.)
Druckerdeinstallation für EPSON BX305 Series (HKLM\...\EPSON BX305 Series) (Version:  - SEIKO EPSON Corporation)
EPSON BX305 Series Handbuch (HKLM-x32\...\EPSON BX305 Series Manual) (Version:  - )
Epson Easy Photo Print 2 (HKLM-x32\...\{310C1558-F6B5-4889-98B0-7471966BA7F2}) (Version: 2.2.3.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION)
Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.10.00 - SEIKO EPSON CORPORATION)
Epson PC-FAX Driver (HKLM-x32\...\EPSON PC-FAX Driver 2) (Version:  - )
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EVEREST Ultimate Edition v5.50 (HKLM-x32\...\EVEREST Ultimate Edition_is1) (Version: 5.50 - Lavalys, Inc.)
Express Burn (HKLM-x32\...\ExpressBurn) (Version: 4.68 - NCH Software)
Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Foxy Security (HKLM-x32\...\Foxy Security) (Version:  - )
Free YouTube to MP3 Converter version 3.12.4.622 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.4.622 - DVDVideoSoft Ltd.)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.137 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
Intel PROSet Wireless (Version:  - ) Hidden
Intel PROSet Wireless (x32 Version:  - ) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Media Go (HKLM-x32\...\{8D92969D-A6A3-44C8-9D63-D377E94F44B5}) (Version: 2.6.205 - Sony)
Media Go Video Playback Engine 2.0.114.09020 (HKLM-x32\...\{49D9CE9D-C8B7-B941-90E1-608044A0FC8D}) (Version: 2.0.114.09020 - Sony)
Medion Home Cinema (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2608 - CyberLink Corp.)
Medion Home Cinema (x32 Version: 8.0.2608 - CyberLink Corp.) Hidden
Memeo Instant Backup (HKLM-x32\...\{8E666407-AC41-46a2-9692-6C7BFCBFDD37}) (Version: 4.60.0.7943 - Memeo Inc.)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 24.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.2.0 (x86 de)) (Version: 24.2.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
OpenOffice.org 3.4.1 (HKLM-x32\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
PDF Architect 2 View Module (HKLM-x32\...\{46889070-D447-4936-A5D3-246DB972FA2E}) (Version: 2.0.6.16537 - pdfforge GmbH)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
PHotkey (HKLM-x32\...\{E50C224A-BBF2-428D-9DCF-DBF9DF85C40E}) (Version: 1.00.0032 - Pegatron Corporation)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.18.0.15698 - Sony Computer Entertainment Inc.)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Real Alternative 2.0.2 (HKLM-x32\...\RealAlt_is1) (Version: 2.0.2 - )
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.34.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0 - Renesas Electronics Corporation) Hidden
simplitec simplicheck (HKLM-x32\...\{DF103EDA-7937-4966-8EFB-5EF5C38301F2}) (Version: 1.3.9.0 - simplitec GmbH)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.14.6.201404170858 - Sony Mobile Communications AB)
Sony PC Companion 2.10.197 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.197 - Sony)
Spelling Dictionaries Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-A00000000004}) (Version: 10.0.0 - Adobe Systems Incorporated)
Spotify (HKCU\...\Spotify) (Version: 0.9.10.14.g578d350b - Spotify AB)
Versandhelfer (HKLM-x32\...\dpdhl.versandhelfer.medionlap.CDA82DC3FEDD13302C6424313D9A2999F162D21A.1) (Version: 0.9.511 - Deutsche Post AG)
Versandhelfer (x32 Version: 0.9.511 - Deutsche Post AG) Hidden
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 3.43 - NCH Software)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

==================== Restore Points  =========================

11-05-2014 17:01:12 Windows-Sicherung
13-05-2014 15:43:54 Windows Update
14-05-2014 17:11:10 Installed PDF Architect 2 View Module
15-05-2014 23:55:09 Windows Update
17-05-2014 20:54:20 Windows Update

==================== Hosts content: ==========================

2009-07-14 04:34 - 2013-11-27 19:32 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {034DE29C-F314-4EF6-AA30-F41EA690459A} - System32\Tasks\{2F89727A-459E-4B4D-930C-BBE1BB2B89DA} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {0E6756EC-AB9F-457D-9E13-8B7E0DE552CE} - System32\Tasks\{C8B02F6F-26AA-4C1E-9F11-A74638E25655} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {1DDFF83B-A000-44B2-BABD-F93C569357AB} - System32\Tasks\SDMsgUpdate (TE) => C:\Program Files (x86)\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
Task: {6909DD31-57AE-41BD-AC1D-5BB68BD52DF8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-20] (Google Inc.)
Task: {72FBA1FA-6555-474E-839A-DE1345DDAEB2} - System32\Tasks\NCH Software\ExpressBurnSevenDays => C:\Program Files (x86)\NCH Software\ExpressBurn\ExpressBurn.exe [2013-10-22] (NCH Software)
Task: {7D992CC4-E9F7-45EE-BD1C-A7BAF9709211} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001Core => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-20] (Facebook Inc.)
Task: {888E1D6E-F6CA-41D9-B12E-6AA1735CEABE} - System32\Tasks\NCH Software\VideoPadSevenDays => C:\Program Files (x86)\NCH Software\VideoPad\VideoPad.exe [2014-05-14] (NCH Software)
Task: {90ECD563-BF9E-4787-A09A-067D6B852D30} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated)
Task: {9315BE9E-067E-4E6D-8342-9AF58AA3CB58} - System32\Tasks\{1213522D-9C14-4C2F-92C8-B7642739D3F0} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {9419C930-531A-487B-AA2A-99024DC7722F} - System32\Tasks\{F45986F9-5137-4AEB-8D01-99429AFE06F1} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {A1B1F5E3-6EF9-401F-AD53-236250C780B5} - System32\Tasks\{AF42A676-BE29-4A78-8F78-1D534D9F6083} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {A6DCC19F-03AF-4EBF-8580-2B05A6868616} - System32\Tasks\{A7A76573-64B0-4C4E-8E1E-14D4EF6C8DFA} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {B9F43966-B617-4C1A-B8A5-3E2F75F89F93} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001UA => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-20] (Facebook Inc.)
Task: {C121E428-A976-49B6-86CA-98384607FBAA} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {E6701FA2-AD4F-4801-B4FD-906F04400206} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-20] (Google Inc.)
Task: {EB68740B-AD6D-4AEB-84BD-22535DC745B1} - System32\Tasks\{1E1D7AC9-1B64-4443-B674-9C49CA794A03} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {ED7DCDD3-8E7C-43D6-AC25-91AF9B1E5A46} - System32\Tasks\SDMsgUpdate (Local) => C:\Program Files (x86)\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001Core.job => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001UA.job => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SDMsgUpdate (Local).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe
Task: C:\Windows\Tasks\SDMsgUpdate (TE).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe

==================== Loaded Modules (whitelisted) =============

2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2013-12-28 22:48 - 2010-10-06 18:46 - 00159752 ____R () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-07-18 18:12 - 2011-03-06 21:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-03-17 11:25 - 2013-10-31 12:35 - 00070880 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
2013-12-28 22:48 - 2010-01-12 18:36 - 00117256 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
2013-12-28 22:48 - 2010-01-12 18:36 - 00121864 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
2013-12-28 22:48 - 2010-12-01 12:36 - 00589320 ____R () C:\Program Files (x86)\PHotkey\PVDesktop.exe
2013-12-28 22:48 - 2010-12-01 12:37 - 00462344 ____R () C:\Program Files (x86)\PHotkey\PVDAgent.exe
2013-09-25 00:35 - 2014-05-15 15:17 - 00598072 _____ () C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
2010-02-28 02:33 - 2010-02-28 02:33 - 00077664 _____ () C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
2012-11-04 22:30 - 2012-09-19 20:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-04-28 17:04 - 2014-04-28 17:04 - 00374272 _____ () C:\Users\Kati\AppData\Roaming\BupSystem\sub\default.dll
2013-03-17 11:25 - 2012-04-30 11:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll
2013-03-17 11:25 - 2013-09-13 11:02 - 00208896 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll
2011-07-07 14:54 - 2011-07-07 14:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll
2013-04-19 13:08 - 2013-05-20 12:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll
2014-03-06 15:42 - 2014-03-06 15:42 - 00528384 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll
2012-11-10 23:07 - 2014-05-15 15:17 - 36966968 _____ () C:\Users\Kati\AppData\Roaming\Spotify\Data\libcef.dll
2014-05-18 12:02 - 2014-05-18 12:02 - 00041984 _____ () c:\users\kati\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp0pu8zb.dll
2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\Kati\AppData\Roaming\Dropbox\bin\libcef.dll
2012-08-10 17:51 - 2012-08-10 17:51 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
2010-08-04 00:39 - 2010-08-04 00:39 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2010-08-04 00:39 - 2010-08-04 00:39 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2013-12-28 22:48 - 2009-12-18 16:36 - 00973432 ____R () C:\Program Files (x86)\PHotkey\acAuth.dll
2013-12-28 22:48 - 2009-12-18 16:41 - 00129544 ____R () C:\Program Files (x86)\PHotkey\GFNEX.dll
2013-09-25 00:35 - 2014-05-15 15:17 - 00886840 _____ () C:\Users\Kati\AppData\Roaming\Spotify\Data\libglesv2.dll
2013-09-25 00:35 - 2014-05-15 15:17 - 00108600 _____ () C:\Users\Kati\AppData\Roaming\Spotify\Data\libegl.dll
2014-05-11 19:59 - 2014-05-11 19:59 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-02-13 17:27 - 2014-02-13 17:27 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\0a0467413a424068d1471448ff6ca6cc\IsdiInterop.ni.dll
2011-07-18 18:18 - 2010-11-06 08:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2014-05-14 17:08 - 2014-05-14 17:08 - 16361136 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/18/2014 00:02:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 10:58:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 10:58:36 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/17/2014 08:46:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 08:45:55 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/17/2014 07:35:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 29.0.1.5239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1cec

Startzeit: 01cf71f2740894dd

Endzeit: 60

Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID: ac8d6dfc-dde9-11e3-9365-e840f22b5625

Error: (05/17/2014 07:07:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 29.0.1.5239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 14e0

Startzeit: 01cf70d59421dcd1

Endzeit: 252

Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID: a46d7c2f-dde5-11e3-9365-e840f22b5625

Error: (05/16/2014 08:57:19 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/16/2014 08:57:11 AM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/15/2014 03:18:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (05/18/2014 00:02:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MemeoBackgroundService" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (05/18/2014 00:02:00 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MemeoBackgroundService erreicht.

Error: (05/18/2014 00:01:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (05/18/2014 11:57:14 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}

Error: (05/18/2014 11:57:14 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {FE9617F6-E606-42AA-BECC-0E9CDA246D63}

Error: (05/17/2014 10:58:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (05/17/2014 10:57:04 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.

Error: (05/17/2014 08:45:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (05/17/2014 11:14:44 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (05/17/2014 11:14:44 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WinHttpAutoProxySvc erreicht.


Microsoft Office Sessions:
=========================
Error: (05/18/2014 00:02:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 10:58:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 10:58:36 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/17/2014 08:46:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 08:45:55 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/17/2014 07:35:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: firefox.exe29.0.1.52391cec01cf71f2740894dd60C:\Program Files (x86)\Mozilla Firefox\firefox.exeac8d6dfc-dde9-11e3-9365-e840f22b5625

Error: (05/17/2014 07:07:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: firefox.exe29.0.1.523914e001cf70d59421dcd1252C:\Program Files (x86)\Mozilla Firefox\firefox.exea46d7c2f-dde5-11e3-9365-e840f22b5625

Error: (05/16/2014 08:57:19 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/16/2014 08:57:11 AM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/15/2014 03:18:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2013-11-27 18:30:17.824
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-11-27 18:30:17.777
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Percentage of memory in use: 57%
Total physical RAM: 4007.12 MB
Available physical RAM: 1704.9 MB
Total Pagefile: 8012.42 MB
Available Pagefile: 5114.58 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB

==================== Drives ================================

Drive c: (Boot) (Fixed) (Total:414.66 GB) (Free:334.63 GB) NTFS
Drive d: (Recover) (Fixed) (Total:50 GB) (Free:0.02 GB) NTFS
Drive e: (EPSON) (CDROM) (Total:0.22 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: B2ED04DC)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=415 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)

==================== End Of Log ============================

Ehm, ich war so intelligent den Stick beim Scan gar nicht dran gehabt zu haben. Ich mache dann nochmal nen Scan mit Stick und poste es neu :-) Sorry

Nirtaka 18.05.2014 13:45


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014
Ran by Kati (administrator) on KATI-PC on 18-05-2014 14:41:09
Running from C:\Users\Kati\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(BUP) C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Facebook Inc.) C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
(Spotify Ltd) C:\Users\Kati\AppData\Roaming\Spotify\spotify.exe
(Spotify Ltd) C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIGJE.EXE
(simplitec) C:\Program Files (x86)\simplitec\simplicheck\simplicheck.exe
(Dropbox, Inc.) C:\Users\Kati\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\POsd.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
() C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Farbar) C:\Users\Kati\Downloads\FRST64(1).exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-22] (Alcor Micro Corp.)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [MedionReminder] => C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [PHotkey] => C:\Program Files (x86)\PHotkey\PHotkey.exe [819720 2011-02-23] (Pegatron Corporation)
HKLM-x32\...\Run: [MsgTranAgt] => C:\Program Files (x86)\PHotkey\MsgTranAgt.exe [117256 2010-01-12] ()
HKLM-x32\...\Run: [MsgTranAgt64] => C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe [121864 2010-01-12] ()
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [847872 2009-12-03] (SEIKO EPSON CORPORATION)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Facebook Update] => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-09-20] (Facebook Inc.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [449760 2013-10-31] (Sony)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Spotify] => C:\Users\Kati\AppData\Roaming\Spotify\Spotify.exe [6170168 2014-05-15] (Spotify Ltd)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Spotify Web Helper] => C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-15] (Spotify Ltd)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-09-20] (Google Inc.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [EPSON BX305 Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGJE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk
ShortcutTarget: simplicheck.lnk -> C:\Program Files (x86)\simplitec\simplicheck\simplicheck.exe (simplitec)
Startup: C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Kati\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9A119BA29CEBCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: No Name - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - C:\Users\Kati\AppData\LocalLow\systems ie bho\bho.dll ()
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default
FF user.js: detected! => C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 - C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Kati\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: sony.com/MediaGoDetector - C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\Kati\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Foxy Security - C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\Extensions\sys@foxysecurity.com [2014-04-28]
FF Extension: DownloadHelper - C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-31]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2013-09-11]

Chrome:
=======
CHR HomePage:
CHR DefaultSearchKeyword: delta-search.com
CHR DefaultSearchProvider: Delta Search
CHR DefaultSearchURL: hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=FA2578929C739985&affID=121562&tt=250613_gr4&tsp=4928
CHR DefaultNewTabURL:
CHR Extension: (DVDVideoSoft) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-12-24]
CHR Extension: (Google Wallet) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-03]
CHR Extension: (Citavi Picker) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\piehhloihgjjiomhieeddiidpekaajio [2013-12-24]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-06-29]
CHR HKLM-x32\...\Chrome\Extension: [dghncoeocefmhkhiphdgikkamjeglbfh] - C:\Program Files (x86)\mystarttb\chrome-newtab-search.crx [2013-06-29]
CHR HKLM-x32\...\Chrome\Extension: [piehhloihgjjiomhieeddiidpekaajio] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Chrome\ChromePicker.crx [2013-09-11]

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 bupService; C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe [642048 2014-04-14] (BUP)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-06] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-30] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-30] (pdfforge GmbH)
S2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [X]
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe" [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-18 14:23 - 2014-05-18 14:23 - 02067456 _____ (Farbar) C:\Users\Kati\Downloads\FRST64(1).exe
2014-05-18 13:50 - 2014-05-18 13:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{422F2530-3EF2-4E9C-A789-485C1206D1AC}
2014-05-17 23:57 - 2014-05-17 23:59 - 00000000 ____D () C:\Users\Kati\Desktop\Fotos
2014-05-17 23:56 - 2014-05-17 23:58 - 00000000 ____D () C:\Users\Kati\Desktop\Kinderfotos
2014-05-17 23:51 - 2014-05-17 23:55 - 00000000 ____D () C:\Users\Kati\Downloads\Uni
2014-05-17 22:55 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-05-17 22:55 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-17 22:55 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-17 22:55 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-05-17 22:55 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-05-17 22:55 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-05-17 22:55 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-05-17 22:55 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-05-17 22:55 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-05-17 22:55 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-05-17 22:55 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-05-17 22:55 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-05-17 22:55 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-05-17 22:55 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-05-17 22:55 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-05-17 22:55 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-05-17 22:55 - 2013-10-01 22:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-05-17 22:55 - 2013-10-01 22:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-05-17 22:54 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-05-17 22:54 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-05-17 22:08 - 2014-05-17 22:08 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4BE87CCE-750B-4228-B62E-246699B53E05}
2014-05-17 20:59 - 2014-05-17 20:59 - 00383343 _____ () C:\Users\Kati\Desktop\Report.htm
2014-05-17 20:58 - 2014-05-17 20:58 - 00000000 ____D () C:\Users\Kati\Documents\EVEREST Reports
2014-05-17 20:41 - 2014-05-17 20:42 - 215448505 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\wlane6221_inw7.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 18857054 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\tpde6221_se_wxpvstw7_32_64.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 09144982 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\usb3e6221_e722xw7.exe
2014-05-17 20:39 - 2014-05-17 20:40 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(2).exe
2014-05-17 20:39 - 2014-05-17 20:39 - 31119378 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\mnme6221_e722xvstw7_w8.exe
2014-05-17 20:39 - 2014-05-17 20:39 - 02620971 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\lane6221_e722xxpvstw7.exe
2014-05-17 20:38 - 2014-05-17 20:38 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8(1).exe
2014-05-17 20:34 - 2014-05-17 20:37 - 195993064 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\vgae6221_e722x_in_w7_w8.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 03987373 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\chpe6221_e722xxpvstw7.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 01798895 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\bioe722x_p762x.exe
2014-05-17 20:33 - 2014-05-17 20:34 - 11290483 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ahcie6221vstw7_w8.exe
2014-05-17 20:31 - 2014-05-17 20:31 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8.exe
2014-05-17 20:26 - 2014-05-17 20:26 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(1).exe
2014-05-17 20:25 - 2014-05-17 20:25 - 00229008 _____ () C:\Users\Kati\Downloads\MEDION_Treibersuche.exe
2014-05-17 20:18 - 2014-05-17 20:18 - 00001130 _____ () C:\Users\Kati\Desktop\EVEREST Ultimate Edition.lnk
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\Program Files (x86)\Lavalys
2014-05-17 20:17 - 2014-05-17 20:17 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Kati\Downloads\everestultimate550.exe
2014-05-17 18:20 - 2014-05-17 18:45 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-17 18:20 - 2014-05-17 18:20 - 00001266 _____ () C:\Users\Public\Desktop\NCH Software.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\Users\Public\Desktop\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001142 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\ProgramData\NCH Software
2014-05-17 18:19 - 2014-05-17 18:43 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\NCH Software
2014-05-17 18:19 - 2014-05-17 18:20 - 00000000 ____D () C:\Program Files (x86)\NCH Software
2014-05-17 18:19 - 2014-05-17 18:19 - 00001130 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00001118 _____ () C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:18 - 2014-05-17 18:18 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kati\Downloads\Debut Video Capture - CHIP-Downloader.exe
2014-05-16 22:17 - 2014-05-16 22:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2611705F-FCFF-44F2-9C4B-EC29E5A67B46}
2014-05-16 09:09 - 2014-05-16 09:09 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69A1EF25-1F79-4775-BA26-5F9375FE9B95}
2014-05-16 08:35 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-16 08:35 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-16 08:35 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-16 08:35 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-16 08:35 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-16 08:35 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 14:27 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-15 14:27 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-15 14:27 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 14:27 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-15 14:26 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 14:26 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 14:26 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 14:26 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 14:26 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-15 14:26 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-15 14:26 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 14:26 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 14:26 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 14:26 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 14:26 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 14:26 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-15 14:26 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-15 14:17 - 2014-05-15 14:18 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4DD5F804-7106-4564-8BC2-F943268098E6}
2014-05-14 19:25 - 2014-05-14 19:25 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:12 - 00001021 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-05-14 19:12 - 2014-05-14 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-14 19:11 - 2014-05-14 19:12 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-14 19:11 - 2014-05-14 19:11 - 00000000 ____D () C:\Users\Kati\Documents\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:12 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-14 19:10 - 2014-05-14 19:10 - 00001039 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\pdfforge
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-14 19:10 - 2014-04-25 17:44 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-05-14 19:10 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-05-14 19:10 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6DE.DLL
2014-05-14 19:10 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCDE.DLL
2014-05-14 19:10 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCC2DE.DLL
2014-05-14 19:07 - 2014-05-14 19:08 - 27843432 _____ (pdfforge ) C:\Users\Kati\Downloads\PDFCreator-1_7_3_setup.exe
2014-05-14 16:28 - 2014-05-14 16:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{AFF51EAF-1EEE-4D30-9A8D-532258456C17}
2014-05-13 17:17 - 2014-05-13 17:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B0C594E1-1C40-46AD-9B29-7C5B4986A6E6}
2014-05-13 16:53 - 2014-05-13 16:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{98AC1C21-B103-44EE-AC7B-2C114FD85585}
2014-05-12 20:54 - 2014-05-12 20:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{BE16BDD7-B89C-4024-B9F6-AD6FF1E9E786}
2014-05-11 19:59 - 2014-05-11 19:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-11 19:46 - 2014-05-11 19:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{C2B4150E-0C6B-4799-9C08-B1E8DFC269ED}
2014-05-10 21:55 - 2014-05-10 21:55 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9A0AD5CC-139C-491B-9266-50616B3EF2EC}
2014-05-09 17:57 - 2014-05-09 17:57 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9C638A68-5F34-48C1-898B-3689CD978999}
2014-05-08 15:00 - 2014-05-08 15:00 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B51A953C-DD2F-4FB8-AA87-F6AD0AFB9AC2}
2014-05-07 19:04 - 2014-05-16 08:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-07 19:04 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-07 19:04 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-07 19:04 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-07 19:04 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-07 19:04 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-07 19:04 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-07 19:04 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-07 19:04 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-07 19:04 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-07 19:04 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-07 19:04 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-07 19:04 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-07 19:04 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-07 19:04 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-07 19:04 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-07 19:04 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-07 19:04 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-07 19:04 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-07 19:04 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-07 19:04 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-07 19:04 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-07 19:04 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-07 19:04 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-07 19:04 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-07 19:04 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-07 19:04 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-07 19:04 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-07 19:04 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-07 19:04 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-07 19:04 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-07 19:04 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-07 19:04 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-07 19:04 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-07 19:04 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-07 19:04 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-07 19:04 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-07 19:04 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-07 19:04 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-07 19:04 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-07 19:04 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-07 19:04 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-07 19:04 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-07 19:04 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-07 19:04 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-07 19:02 - 2014-05-07 19:03 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DFB33308-901D-4EAF-9C6E-A5DEA8364065}
2014-05-06 15:35 - 2014-05-06 15:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{01097470-E215-4F09-8B1E-B904D4356792}
2014-05-05 18:20 - 2014-05-05 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Local\{8837D2BF-2261-45A5-975D-F775DFD9FD39}
2014-05-04 21:59 - 2014-05-04 21:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{30370F42-121E-48B3-B315-481D08085F3A}
2014-05-03 21:27 - 2014-05-03 21:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DB63567F-3788-43B8-BCFB-ED07BD306540}
2014-05-03 02:36 - 2014-05-03 02:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3CD5C54C-8659-40F2-AE16-BB7B404718E6}
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-05-02 14:35 - 2014-05-02 14:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DC60EB2C-B723-4FA9-A38E-31AC1A6775EA}
2014-05-01 13:21 - 2014-05-01 13:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B1833989-708E-4FC2-AADF-908BFAC0A56F}
2014-04-30 18:53 - 2014-04-30 18:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5EF441A7-91AC-4C8E-9DF8-3CA8C25B701E}
2014-04-29 16:21 - 2014-04-29 16:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6AB88698-1939-4E66-BCF8-9C5E2800911A}
2014-04-28 17:05 - 2014-04-28 17:05 - 00128000 ____H () C:\Users\Kati\Desktop\photothumb.db
2014-04-28 17:04 - 2014-04-28 17:06 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PhotoScape
2014-04-28 17:04 - 2014-04-28 17:04 - 00001039 _____ () C:\Users\Kati\Desktop\PhotoScape.lnk
2014-04-28 17:04 - 2014-04-28 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2014-04-28 17:03 - 2014-04-28 17:04 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Security Systems
2014-04-28 17:03 - 2014-04-28 17:04 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-04-28 17:03 - 2014-04-28 17:03 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\BupSystem
2014-04-28 17:02 - 2014-04-28 17:03 - 21331096 _____ (Mooii) C:\Users\Kati\Desktop\PhotoScape_V3-6-5.exe
2014-04-28 17:00 - 2014-04-28 17:00 - 00386904 _____ (Softonic ) C:\Users\Kati\Downloads\SoftonicDownloader_fuer_photoscape.exe
2014-04-28 16:22 - 2014-04-28 16:22 - 00000000 ____D () C:\Users\Kati\AppData\Local\{E6EF1C33-8457-4043-B475-28B37C804CF7}
2014-04-27 12:51 - 2014-04-27 12:51 - 00000000 ____D () C:\Users\Kati\AppData\Local\{50566B36-6424-40FE-8E57-875DA3FE0D99}
2014-04-26 20:36 - 2014-04-26 20:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3B71D42C-D487-4B7F-A90D-DF6ABC7D9BEE}
2014-04-26 02:43 - 2014-04-26 02:44 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B4704FBF-46C6-4E83-9C9B-F811FBCF29C8}
2014-04-25 14:36 - 2014-04-25 14:37 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3D4FFA91-C31D-42D3-98D3-55D24540A116}
2014-04-24 20:48 - 2014-04-24 20:48 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6B75591B-A85D-449D-8566-C3803B21D41A}
2014-04-23 19:06 - 2014-04-23 19:06 - 00000000 ____D () C:\Users\Kati\AppData\Local\{05C9CB18-5353-481E-B307-AC526C8EAD50}
2014-04-22 17:25 - 2014-04-22 17:25 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DEA26C1D-154A-44C1-B6B0-8D0C9CE3E56A}
2014-04-22 01:11 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-22 01:11 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-22 01:11 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-22 01:11 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-22 01:11 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-22 01:11 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-22 01:11 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-22 01:11 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-22 01:11 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-22 01:11 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-22 01:11 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-22 01:11 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-22 01:11 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-22 00:59 - 2014-04-22 00:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5A0297BB-2640-42E9-B94D-6AD8D30F5957}

==================== One Month Modified Files and Folders =======

2014-05-18 14:41 - 2013-11-29 01:51 - 00019052 _____ () C:\Users\Kati\Downloads\FRST.txt
2014-05-18 14:41 - 2013-11-26 14:29 - 00000000 ____D () C:\FRST
2014-05-18 14:27 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-18 14:27 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-18 14:23 - 2014-05-18 14:23 - 02067456 _____ (Farbar) C:\Users\Kati\Downloads\FRST64(1).exe
2014-05-18 14:19 - 2012-09-20 19:21 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-18 14:08 - 2012-09-20 21:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-18 14:03 - 2013-07-24 18:55 - 01992708 _____ () C:\Windows\WindowsUpdate.log
2014-05-18 13:50 - 2014-05-18 13:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{422F2530-3EF2-4E9C-A789-485C1206D1AC}
2014-05-18 13:36 - 2012-11-10 23:07 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Spotify
2014-05-18 13:24 - 2012-09-20 22:19 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001UA.job
2014-05-18 13:06 - 2012-09-20 19:21 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-18 13:05 - 2012-09-21 13:58 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\SoftGrid Client
2014-05-18 12:34 - 2014-02-24 22:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\Windows Live
2014-05-18 12:07 - 2011-05-16 16:04 - 00699794 _____ () C:\Windows\system32\perfh007.dat
2014-05-18 12:07 - 2011-05-16 16:04 - 00149644 _____ () C:\Windows\system32\perfc007.dat
2014-05-18 12:07 - 2009-07-14 07:13 - 01620836 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-18 12:04 - 2014-01-27 22:53 - 00000470 _____ () C:\Windows\Tasks\SDMsgUpdate (TE).job
2014-05-18 12:03 - 2014-01-08 01:02 - 00000000 ___RD () C:\Users\Kati\Dropbox
2014-05-18 12:03 - 2014-01-08 01:00 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Dropbox
2014-05-18 12:01 - 2014-01-27 22:53 - 00000478 _____ () C:\Windows\Tasks\SDMsgUpdate (Local).job
2014-05-18 12:01 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-18 12:01 - 2009-07-14 06:51 - 02331598 _____ () C:\Windows\setupact.log
2014-05-17 23:59 - 2014-05-17 23:57 - 00000000 ____D () C:\Users\Kati\Desktop\Fotos
2014-05-17 23:58 - 2014-05-17 23:56 - 00000000 ____D () C:\Users\Kati\Desktop\Kinderfotos
2014-05-17 23:55 - 2014-05-17 23:51 - 00000000 ____D () C:\Users\Kati\Downloads\Uni
2014-05-17 23:52 - 2013-11-24 21:13 - 00000000 ____D () C:\Users\Kati\Downloads\verschiedene Bilder
2014-05-17 22:24 - 2012-09-20 22:19 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001Core.job
2014-05-17 22:08 - 2014-05-17 22:08 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4BE87CCE-750B-4228-B62E-246699B53E05}
2014-05-17 20:59 - 2014-05-17 20:59 - 00383343 _____ () C:\Users\Kati\Desktop\Report.htm
2014-05-17 20:58 - 2014-05-17 20:58 - 00000000 ____D () C:\Users\Kati\Documents\EVEREST Reports
2014-05-17 20:48 - 2012-09-23 18:09 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Skype
2014-05-17 20:42 - 2014-05-17 20:41 - 215448505 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\wlane6221_inw7.exe
2014-05-17 20:42 - 2013-12-16 20:47 - 00000000 ____D () C:\Medion
2014-05-17 20:40 - 2014-05-17 20:40 - 18857054 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\tpde6221_se_wxpvstw7_32_64.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 09144982 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\usb3e6221_e722xw7.exe
2014-05-17 20:40 - 2014-05-17 20:39 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(2).exe
2014-05-17 20:39 - 2014-05-17 20:39 - 31119378 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\mnme6221_e722xvstw7_w8.exe
2014-05-17 20:39 - 2014-05-17 20:39 - 02620971 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\lane6221_e722xxpvstw7.exe
2014-05-17 20:38 - 2014-05-17 20:38 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8(1).exe
2014-05-17 20:37 - 2014-05-17 20:34 - 195993064 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\vgae6221_e722x_in_w7_w8.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 03987373 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\chpe6221_e722xxpvstw7.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 01798895 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\bioe722x_p762x.exe
2014-05-17 20:34 - 2014-05-17 20:33 - 11290483 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ahcie6221vstw7_w8.exe
2014-05-17 20:31 - 2014-05-17 20:31 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8.exe
2014-05-17 20:26 - 2014-05-17 20:26 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(1).exe
2014-05-17 20:25 - 2014-05-17 20:25 - 00229008 _____ () C:\Users\Kati\Downloads\MEDION_Treibersuche.exe
2014-05-17 20:18 - 2014-05-17 20:18 - 00001130 _____ () C:\Users\Kati\Desktop\EVEREST Ultimate Edition.lnk
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\Program Files (x86)\Lavalys
2014-05-17 20:17 - 2014-05-17 20:17 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Kati\Downloads\everestultimate550.exe
2014-05-17 18:45 - 2014-05-17 18:20 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-17 18:43 - 2014-05-17 18:19 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\NCH Software
2014-05-17 18:20 - 2014-05-17 18:20 - 00001266 _____ () C:\Users\Public\Desktop\NCH Software.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\Users\Public\Desktop\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001142 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\ProgramData\NCH Software
2014-05-17 18:20 - 2014-05-17 18:19 - 00000000 ____D () C:\Program Files (x86)\NCH Software
2014-05-17 18:19 - 2014-05-17 18:19 - 00001130 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00001118 _____ () C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:18 - 2014-05-17 18:18 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kati\Downloads\Debut Video Capture - CHIP-Downloader.exe
2014-05-16 22:17 - 2014-05-16 22:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2611705F-FCFF-44F2-9C4B-EC29E5A67B46}
2014-05-16 10:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-16 09:12 - 2013-01-07 00:52 - 00002023 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-05-16 09:12 - 2011-06-28 21:31 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-16 09:09 - 2014-05-16 09:09 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69A1EF25-1F79-4775-BA26-5F9375FE9B95}
2014-05-16 09:06 - 2012-09-20 18:26 - 00000000 ___RD () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-16 09:06 - 2012-09-20 18:26 - 00000000 ___RD () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 08:55 - 2014-05-07 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-16 08:34 - 2013-07-29 22:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-16 08:31 - 2013-07-25 12:48 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-16 00:24 - 2012-09-20 19:21 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-05-15 15:18 - 2012-11-10 23:07 - 00000000 ____D () C:\Users\Kati\AppData\Local\Spotify
2014-05-15 14:18 - 2014-05-15 14:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4DD5F804-7106-4564-8BC2-F943268098E6}
2014-05-14 19:25 - 2014-05-14 19:25 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:12 - 00001021 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-05-14 19:12 - 2014-05-14 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:11 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:10 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-14 19:11 - 2014-05-14 19:11 - 00000000 ____D () C:\Users\Kati\Documents\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00001039 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\pdfforge
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-14 19:08 - 2014-05-14 19:07 - 27843432 _____ (pdfforge ) C:\Users\Kati\Downloads\PDFCreator-1_7_3_setup.exe
2014-05-14 17:08 - 2013-12-16 21:08 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 17:08 - 2012-09-20 21:54 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-14 17:08 - 2011-07-18 19:57 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-14 16:28 - 2014-05-14 16:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{AFF51EAF-1EEE-4D30-9A8D-532258456C17}
2014-05-14 16:06 - 2014-01-08 01:02 - 00001017 _____ () C:\Users\Kati\Desktop\Dropbox.lnk
2014-05-14 16:06 - 2014-01-08 01:01 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-13 17:17 - 2014-05-13 17:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B0C594E1-1C40-46AD-9B29-7C5B4986A6E6}
2014-05-13 16:54 - 2014-05-13 16:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{98AC1C21-B103-44EE-AC7B-2C114FD85585}
2014-05-13 16:49 - 2014-01-29 16:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-12 20:54 - 2014-05-12 20:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{BE16BDD7-B89C-4024-B9F6-AD6FF1E9E786}
2014-05-11 22:59 - 2013-09-30 12:13 - 00000000 ____D () C:\Users\Kati\Documents\Citavi 4
2014-05-11 19:59 - 2014-05-11 19:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-11 19:46 - 2014-05-11 19:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{C2B4150E-0C6B-4799-9C08-B1E8DFC269ED}
2014-05-10 21:55 - 2014-05-10 21:55 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9A0AD5CC-139C-491B-9266-50616B3EF2EC}
2014-05-09 17:57 - 2014-05-09 17:57 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9C638A68-5F34-48C1-898B-3689CD978999}
2014-05-09 08:14 - 2014-05-15 14:27 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 14:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-08 15:00 - 2014-05-08 15:00 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B51A953C-DD2F-4FB8-AA87-F6AD0AFB9AC2}
2014-05-07 20:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-07 19:03 - 2014-05-07 19:02 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DFB33308-901D-4EAF-9C6E-A5DEA8364065}
2014-05-06 15:35 - 2014-05-06 15:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{01097470-E215-4F09-8B1E-B904D4356792}
2014-05-06 06:40 - 2014-05-16 08:35 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-16 08:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-16 08:35 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-16 08:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-16 08:35 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-16 08:35 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-05 23:14 - 2012-09-20 19:21 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-05 23:14 - 2012-09-20 19:21 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-05 18:20 - 2014-05-05 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Local\{8837D2BF-2261-45A5-975D-F775DFD9FD39}
2014-05-04 21:59 - 2014-05-04 21:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{30370F42-121E-48B3-B315-481D08085F3A}
2014-05-03 21:28 - 2014-05-03 21:27 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DB63567F-3788-43B8-BCFB-ED07BD306540}
2014-05-03 02:36 - 2014-05-03 02:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3CD5C54C-8659-40F2-AE16-BB7B404718E6}
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-05-03 01:55 - 2013-04-19 13:10 - 00000000 ____D () C:\ProgramData\Sony Ericsson
2014-05-03 01:55 - 2013-04-19 13:10 - 00000000 ____D () C:\Program Files (x86)\Sony Ericsson
2014-05-02 14:36 - 2014-05-02 14:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DC60EB2C-B723-4FA9-A38E-31AC1A6775EA}
2014-05-01 13:21 - 2014-05-01 13:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B1833989-708E-4FC2-AADF-908BFAC0A56F}
2014-04-30 18:53 - 2014-04-30 18:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5EF441A7-91AC-4C8E-9DF8-3CA8C25B701E}
2014-04-29 16:21 - 2014-04-29 16:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6AB88698-1939-4E66-BCF8-9C5E2800911A}
2014-04-28 17:06 - 2014-04-28 17:04 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PhotoScape
2014-04-28 17:05 - 2014-04-28 17:05 - 00128000 ____H () C:\Users\Kati\Desktop\photothumb.db
2014-04-28 17:04 - 2014-04-28 17:04 - 00001039 _____ () C:\Users\Kati\Desktop\PhotoScape.lnk
2014-04-28 17:04 - 2014-04-28 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2014-04-28 17:04 - 2014-04-28 17:03 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Security Systems
2014-04-28 17:04 - 2014-04-28 17:03 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-04-28 17:03 - 2014-04-28 17:03 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\BupSystem
2014-04-28 17:03 - 2014-04-28 17:02 - 21331096 _____ (Mooii) C:\Users\Kati\Desktop\PhotoScape_V3-6-5.exe
2014-04-28 17:03 - 2012-09-20 18:26 - 00000000 ____D () C:\Users\Kati\AppData\Local\Google
2014-04-28 17:00 - 2014-04-28 17:00 - 00386904 _____ (Softonic ) C:\Users\Kati\Downloads\SoftonicDownloader_fuer_photoscape.exe
2014-04-28 16:22 - 2014-04-28 16:22 - 00000000 ____D () C:\Users\Kati\AppData\Local\{E6EF1C33-8457-4043-B475-28B37C804CF7}
2014-04-27 12:51 - 2014-04-27 12:51 - 00000000 ____D () C:\Users\Kati\AppData\Local\{50566B36-6424-40FE-8E57-875DA3FE0D99}
2014-04-26 20:36 - 2014-04-26 20:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3B71D42C-D487-4B7F-A90D-DF6ABC7D9BEE}
2014-04-26 02:44 - 2014-04-26 02:43 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B4704FBF-46C6-4E83-9C9B-F811FBCF29C8}
2014-04-25 17:44 - 2014-05-14 19:10 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-04-25 17:44 - 2014-05-14 19:10 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-04-25 17:44 - 2014-05-14 19:10 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2014-04-25 17:44 - 2014-05-14 19:10 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-04-25 17:44 - 2014-05-14 19:10 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-04-25 14:37 - 2014-04-25 14:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3D4FFA91-C31D-42D3-98D3-55D24540A116}
2014-04-24 20:48 - 2014-04-24 20:48 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6B75591B-A85D-449D-8566-C3803B21D41A}
2014-04-23 19:06 - 2014-04-23 19:06 - 00000000 ____D () C:\Users\Kati\AppData\Local\{05C9CB18-5353-481E-B307-AC526C8EAD50}
2014-04-22 17:25 - 2014-04-22 17:25 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DEA26C1D-154A-44C1-B6B0-8D0C9CE3E56A}
2014-04-22 01:00 - 2011-07-18 18:45 - 00298486 _____ () C:\Windows\DPINST.LOG
2014-04-22 00:59 - 2014-04-22 00:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5A0297BB-2640-42E9-B94D-6AD8D30F5957}

Some content of TEMP:
====================
C:\Users\Kati\AppData\Local\Temp\avgnt.exe
C:\Users\Kati\AppData\Local\Temp\burnsetup.exe
C:\Users\Kati\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp0pu8zb.dll
C:\Users\Kati\AppData\Local\Temp\FoxySecuritySetup.exe
C:\Users\Kati\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Kati\AppData\Local\Temp\Quarantine.exe
C:\Users\Kati\AppData\Local\Temp\sjy8mvbh.dll
C:\Users\Kati\AppData\Local\Temp\vpsetup.exe
C:\Users\Kati\AppData\Local\Temp\_is6454.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe
[2014-05-15 14:26] - [2014-03-04 11:43] - 0455168 ____A (Microsoft Corporation) 88AB9B72B4BF3963A0DE0820B4B0B06C

C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-09 20:47

==================== End Of Log ============================

--- --- ---



Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-05-2014
Ran by Kati at 2014-05-18 14:43:38
Running from C:\Users\Kati\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.7.0.19530 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 2.7.0.19530 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.8.1217.36096 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.8.1217.36096 - Alcor Micro Corp.) Hidden
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.35 - Atheros Communications Inc.)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
Citavi 4 (HKLM-x32\...\{CC0A85B2-734A-45B3-B678-05F6A6499AC7}) (Version: 4.1.0.3 - Swiss Academic Software)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.)
CyberLink LabelPrint (x32 Version: 2.5.3624 - CyberLink Corp.) Hidden
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1327 - CyberLink Corp.)
CyberLink Power2Go (x32 Version: 7.0.0.1327 - CyberLink Corp.) Hidden
CyberLink PowerDVD Copy (HKLM-x32\...\InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}) (Version: 1.5.1306 - CyberLink Corp.)
CyberLink PowerDVD Copy (x32 Version: 1.5.1306 - CyberLink Corp.) Hidden
CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.4125 - CyberLink Corp.)
CyberLink PowerRecover (x32 Version: 5.5.4125 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Debut Video Capture Software (HKLM-x32\...\Debut) (Version: 1.82 - NCH Software)
Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.7000.4 - Dolby Laboratories Inc)
Dropbox (HKCU\...\Dropbox) (Version: 2.6.33 - Dropbox, Inc.)
Druckerdeinstallation für EPSON BX305 Series (HKLM\...\EPSON BX305 Series) (Version:  - SEIKO EPSON Corporation)
EPSON BX305 Series Handbuch (HKLM-x32\...\EPSON BX305 Series Manual) (Version:  - )
Epson Easy Photo Print 2 (HKLM-x32\...\{310C1558-F6B5-4889-98B0-7471966BA7F2}) (Version: 2.2.3.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION)
Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.10.00 - SEIKO EPSON CORPORATION)
Epson PC-FAX Driver (HKLM-x32\...\EPSON PC-FAX Driver 2) (Version:  - )
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EVEREST Ultimate Edition v5.50 (HKLM-x32\...\EVEREST Ultimate Edition_is1) (Version: 5.50 - Lavalys, Inc.)
Express Burn (HKLM-x32\...\ExpressBurn) (Version: 4.68 - NCH Software)
Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Foxy Security (HKLM-x32\...\Foxy Security) (Version:  - )
Free YouTube to MP3 Converter version 3.12.4.622 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.4.622 - DVDVideoSoft Ltd.)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.137 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
Intel PROSet Wireless (Version:  - ) Hidden
Intel PROSet Wireless (x32 Version:  - ) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Media Go (HKLM-x32\...\{8D92969D-A6A3-44C8-9D63-D377E94F44B5}) (Version: 2.6.205 - Sony)
Media Go Video Playback Engine 2.0.114.09020 (HKLM-x32\...\{49D9CE9D-C8B7-B941-90E1-608044A0FC8D}) (Version: 2.0.114.09020 - Sony)
Medion Home Cinema (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2608 - CyberLink Corp.)
Medion Home Cinema (x32 Version: 8.0.2608 - CyberLink Corp.) Hidden
Memeo Instant Backup (HKLM-x32\...\{8E666407-AC41-46a2-9692-6C7BFCBFDD37}) (Version: 4.60.0.7943 - Memeo Inc.)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 24.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.2.0 (x86 de)) (Version: 24.2.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
OpenOffice.org 3.4.1 (HKLM-x32\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
PDF Architect 2 View Module (HKLM-x32\...\{46889070-D447-4936-A5D3-246DB972FA2E}) (Version: 2.0.6.16537 - pdfforge GmbH)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
PHotkey (HKLM-x32\...\{E50C224A-BBF2-428D-9DCF-DBF9DF85C40E}) (Version: 1.00.0032 - Pegatron Corporation)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.18.0.15698 - Sony Computer Entertainment Inc.)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Real Alternative 2.0.2 (HKLM-x32\...\RealAlt_is1) (Version: 2.0.2 - )
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.34.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0 - Renesas Electronics Corporation) Hidden
simplitec simplicheck (HKLM-x32\...\{DF103EDA-7937-4966-8EFB-5EF5C38301F2}) (Version: 1.3.9.0 - simplitec GmbH)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.14.6.201404170858 - Sony Mobile Communications AB)
Sony PC Companion 2.10.197 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.197 - Sony)
Spelling Dictionaries Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-A00000000004}) (Version: 10.0.0 - Adobe Systems Incorporated)
Spotify (HKCU\...\Spotify) (Version: 0.9.10.14.g578d350b - Spotify AB)
Versandhelfer (HKLM-x32\...\dpdhl.versandhelfer.medionlap.CDA82DC3FEDD13302C6424313D9A2999F162D21A.1) (Version: 0.9.511 - Deutsche Post AG)
Versandhelfer (x32 Version: 0.9.511 - Deutsche Post AG) Hidden
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 3.43 - NCH Software)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

==================== Restore Points  =========================

11-05-2014 17:01:12 Windows-Sicherung
13-05-2014 15:43:54 Windows Update
14-05-2014 17:11:10 Installed PDF Architect 2 View Module
15-05-2014 23:55:09 Windows Update
17-05-2014 20:54:20 Windows Update

==================== Hosts content: ==========================

2009-07-14 04:34 - 2013-11-27 19:32 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {034DE29C-F314-4EF6-AA30-F41EA690459A} - System32\Tasks\{2F89727A-459E-4B4D-930C-BBE1BB2B89DA} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {0E6756EC-AB9F-457D-9E13-8B7E0DE552CE} - System32\Tasks\{C8B02F6F-26AA-4C1E-9F11-A74638E25655} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {1DDFF83B-A000-44B2-BABD-F93C569357AB} - System32\Tasks\SDMsgUpdate (TE) => C:\Program Files (x86)\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
Task: {6909DD31-57AE-41BD-AC1D-5BB68BD52DF8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-20] (Google Inc.)
Task: {72FBA1FA-6555-474E-839A-DE1345DDAEB2} - System32\Tasks\NCH Software\ExpressBurnSevenDays => C:\Program Files (x86)\NCH Software\ExpressBurn\ExpressBurn.exe [2013-10-22] (NCH Software)
Task: {7D992CC4-E9F7-45EE-BD1C-A7BAF9709211} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001Core => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-20] (Facebook Inc.)
Task: {888E1D6E-F6CA-41D9-B12E-6AA1735CEABE} - System32\Tasks\NCH Software\VideoPadSevenDays => C:\Program Files (x86)\NCH Software\VideoPad\VideoPad.exe [2014-05-14] (NCH Software)
Task: {90ECD563-BF9E-4787-A09A-067D6B852D30} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated)
Task: {9315BE9E-067E-4E6D-8342-9AF58AA3CB58} - System32\Tasks\{1213522D-9C14-4C2F-92C8-B7642739D3F0} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {9419C930-531A-487B-AA2A-99024DC7722F} - System32\Tasks\{F45986F9-5137-4AEB-8D01-99429AFE06F1} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {A1B1F5E3-6EF9-401F-AD53-236250C780B5} - System32\Tasks\{AF42A676-BE29-4A78-8F78-1D534D9F6083} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {A6DCC19F-03AF-4EBF-8580-2B05A6868616} - System32\Tasks\{A7A76573-64B0-4C4E-8E1E-14D4EF6C8DFA} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {B9F43966-B617-4C1A-B8A5-3E2F75F89F93} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001UA => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-20] (Facebook Inc.)
Task: {C121E428-A976-49B6-86CA-98384607FBAA} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {E6701FA2-AD4F-4801-B4FD-906F04400206} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-20] (Google Inc.)
Task: {EB68740B-AD6D-4AEB-84BD-22535DC745B1} - System32\Tasks\{1E1D7AC9-1B64-4443-B674-9C49CA794A03} => D:\DRIVERS\09 Hotkey\Hotkey_V1.00.0032\setup.exe [2007-04-05] (Macrovision Corporation)
Task: {ED7DCDD3-8E7C-43D6-AC25-91AF9B1E5A46} - System32\Tasks\SDMsgUpdate (Local) => C:\Program Files (x86)\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001Core.job => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001UA.job => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SDMsgUpdate (Local).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe
Task: C:\Windows\Tasks\SDMsgUpdate (TE).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe

==================== Loaded Modules (whitelisted) =============

2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2013-12-28 22:48 - 2010-10-06 18:46 - 00159752 ____R () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-07-18 18:12 - 2011-03-06 21:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-03-17 11:25 - 2013-10-31 12:35 - 00070880 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
2013-12-28 22:48 - 2010-01-12 18:36 - 00117256 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
2013-12-28 22:48 - 2010-01-12 18:36 - 00121864 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
2013-12-28 22:48 - 2010-12-01 12:36 - 00589320 ____R () C:\Program Files (x86)\PHotkey\PVDesktop.exe
2013-12-28 22:48 - 2010-12-01 12:37 - 00462344 ____R () C:\Program Files (x86)\PHotkey\PVDAgent.exe
2013-09-25 00:35 - 2014-05-15 15:17 - 00598072 _____ () C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
2010-02-28 02:33 - 2010-02-28 02:33 - 00077664 _____ () C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
2012-11-04 22:30 - 2012-09-19 20:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-04-28 17:04 - 2014-04-28 17:04 - 00374272 _____ () C:\Users\Kati\AppData\Roaming\BupSystem\sub\default.dll
2013-03-17 11:25 - 2012-04-30 11:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll
2013-03-17 11:25 - 2013-09-13 11:02 - 00208896 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll
2011-07-07 14:54 - 2011-07-07 14:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll
2013-04-19 13:08 - 2013-05-20 12:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll
2014-03-06 15:42 - 2014-03-06 15:42 - 00528384 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll
2012-11-10 23:07 - 2014-05-15 15:17 - 36966968 _____ () C:\Users\Kati\AppData\Roaming\Spotify\Data\libcef.dll
2014-05-18 12:02 - 2014-05-18 12:02 - 00041984 _____ () c:\users\kati\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp0pu8zb.dll
2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\Kati\AppData\Roaming\Dropbox\bin\libcef.dll
2012-08-10 17:51 - 2012-08-10 17:51 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
2010-08-04 00:39 - 2010-08-04 00:39 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2010-08-04 00:39 - 2010-08-04 00:39 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2013-12-28 22:48 - 2009-12-18 16:36 - 00973432 ____R () C:\Program Files (x86)\PHotkey\acAuth.dll
2013-12-28 22:48 - 2009-12-18 16:41 - 00129544 ____R () C:\Program Files (x86)\PHotkey\GFNEX.dll
2013-09-25 00:35 - 2014-05-15 15:17 - 00886840 _____ () C:\Users\Kati\AppData\Roaming\Spotify\Data\libglesv2.dll
2013-09-25 00:35 - 2014-05-15 15:17 - 00108600 _____ () C:\Users\Kati\AppData\Roaming\Spotify\Data\libegl.dll
2014-05-11 19:59 - 2014-05-11 19:59 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-02-13 17:27 - 2014-02-13 17:27 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\0a0467413a424068d1471448ff6ca6cc\IsdiInterop.ni.dll
2011-07-18 18:18 - 2010-11-06 08:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2014-05-14 17:08 - 2014-05-14 17:08 - 16361136 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/18/2014 00:02:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 10:58:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 10:58:36 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/17/2014 08:46:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 08:45:55 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/17/2014 07:35:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 29.0.1.5239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1cec

Startzeit: 01cf71f2740894dd

Endzeit: 60

Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID: ac8d6dfc-dde9-11e3-9365-e840f22b5625

Error: (05/17/2014 07:07:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 29.0.1.5239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 14e0

Startzeit: 01cf70d59421dcd1

Endzeit: 252

Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID: a46d7c2f-dde5-11e3-9365-e840f22b5625

Error: (05/16/2014 08:57:19 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/16/2014 08:57:11 AM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/15/2014 03:18:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (05/18/2014 00:02:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MemeoBackgroundService" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (05/18/2014 00:02:00 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MemeoBackgroundService erreicht.

Error: (05/18/2014 00:01:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (05/18/2014 11:57:14 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}

Error: (05/18/2014 11:57:14 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {FE9617F6-E606-42AA-BECC-0E9CDA246D63}

Error: (05/17/2014 10:58:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (05/17/2014 10:57:04 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.

Error: (05/17/2014 08:45:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (05/17/2014 11:14:44 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (05/17/2014 11:14:44 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WinHttpAutoProxySvc erreicht.


Microsoft Office Sessions:
=========================
Error: (05/18/2014 00:02:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 10:58:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 10:58:36 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/17/2014 08:46:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/17/2014 08:45:55 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/17/2014 07:35:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: firefox.exe29.0.1.52391cec01cf71f2740894dd60C:\Program Files (x86)\Mozilla Firefox\firefox.exeac8d6dfc-dde9-11e3-9365-e840f22b5625

Error: (05/17/2014 07:07:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: firefox.exe29.0.1.523914e001cf70d59421dcd1252C:\Program Files (x86)\Mozilla Firefox\firefox.exea46d7c2f-dde5-11e3-9365-e840f22b5625

Error: (05/16/2014 08:57:19 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/16/2014 08:57:11 AM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
  bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
  bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
  bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
  bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
  bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Error: (05/15/2014 03:18:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2013-11-27 18:30:17.824
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-11-27 18:30:17.777
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Percentage of memory in use: 57%
Total physical RAM: 4007.12 MB
Available physical RAM: 1717.85 MB
Total Pagefile: 8012.42 MB
Available Pagefile: 5110.86 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB

==================== Drives ================================

Drive c: (Boot) (Fixed) (Total:414.66 GB) (Free:334.63 GB) NTFS
Drive d: (Recover) (Fixed) (Total:50 GB) (Free:0.02 GB) NTFS
Drive e: (EPSON) (CDROM) (Total:0.22 GB) (Free:0 GB) CDFS
Drive f: () (Removable) (Total:14.92 GB) (Free:3.61 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: B2ED04DC)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=415 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 15 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=15 GB) - (Type=0C)

==================== End Of Log ============================


sunjojo 19.05.2014 16:25

Ok, dann gehts so weiter:



Schritt 1
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).
Schritt 2
Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.

Schritt 3
Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, wird ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.

Schreibe bitte noch, welche Laufwerksbuchstaben der/die USB-Stick(s) haben und lasse der/die USB-Stick(s) während der Bereinigung angeschlossen.



Poste folgende Logfiles in deiner nächsten Antwort:
  • AdwCleaner.txt
  • mbam.txt
  • FRST.txt

Nirtaka 21.05.2014 18:30

Code:

# AdwCleaner v3.013 - Bericht erstellt am 21/05/2014 um 18:37:35
# Updated 24/11/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Kati - KATI-PC
# Gestartet von : C:\Users\Kati\Downloads\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\NCH Software
Ordner Gelöscht : C:\ProgramData\simplitec
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\simplitec
Ordner Gelöscht : C:\Program Files (x86)\NCH Software
Ordner Gelöscht : C:\Program Files (x86)\simplitec
Ordner Gelöscht : C:\Users\Kati\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Kati\AppData\Roaming\NCH Software
Ordner Gelöscht : C:\Users\Kati\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Kati\AppData\Roaming\simplitec
Datei Gelöscht : C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\user.js

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\NCH Software
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\NCH Software

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17041


-\\ Mozilla Firefox v29.0.1 (de)

[ Datei : C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\prefs.js ]


-\\ Google Chrome v34.0.1847.137

[ Datei : C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht : icon_url
Gelöscht : search_url
Gelöscht : keyword

*************************

AdwCleaner[R0].txt - [7633 octets] - [28/11/2013 22:41:59]
AdwCleaner[R1].txt - [7693 octets] - [29/11/2013 00:52:57]
AdwCleaner[R2].txt - [7753 octets] - [29/11/2013 00:56:12]
AdwCleaner[R3].txt - [3614 octets] - [21/05/2014 18:32:02]
AdwCleaner[R4].txt - [2416 octets] - [21/05/2014 18:37:03]
AdwCleaner[S0].txt - [7547 octets] - [29/11/2013 00:59:19]
AdwCleaner[S1].txt - [318 octets] - [21/05/2014 18:36:02]
AdwCleaner[S2].txt - [2153 octets] - [21/05/2014 18:37:35]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2213 octets] ##########

Code:

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 275396
Verstrichene Zeit: 15 Min, 24 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 6
PUP.Optional.VMNToolBar.A, HKLM\SOFTWARE\CLASSES\CLSID\{ccb24e92-62c4-4c53-95d2-65f9eed476bc}, In Quarantäne, [dc2e3a1aa9d242f425567ee429d9fe02],
PUP.Optional.VMNToolBar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}, In Quarantäne, [dc2e3a1aa9d242f425567ee429d9fe02],
Trojan.BHO, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, In Quarantäne, [0802c19392e934024e7ffd4039c9a65a],
Trojan.BHO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, In Quarantäne, [0802c19392e934024e7ffd4039c9a65a],
Trojan.BHO, HKU\S-1-5-21-2548312011-2494454960-3164520827-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, Löschen bei Neustart, [0802c19392e934024e7ffd4039c9a65a],
Trojan.BHO, HKU\S-1-5-21-2548312011-2494454960-3164520827-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, Löschen bei Neustart, [0802c19392e934024e7ffd4039c9a65a],

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 0
(No malicious items detected)

Dateien: 3
Trojan.BHO, C:\Users\Kati\AppData\LocalLow\systems ie bho\bho.dll, In Quarantäne, [0802c19392e934024e7ffd4039c9a65a],
PUP.Optional.OpenCandy, C:\Users\Kati\Desktop\PhotoScape_V3-6-5.exe, In Quarantäne, [ba504410027973c3d33f2a4c976d8d73],
PUP.Optional.Softonic.A, C:\Users\Kati\Downloads\SoftonicDownloader_fuer_photoscape.exe, In Quarantäne, [b3571044344752e464b640e0738e32ce],

Physische Sektoren: 0
(No malicious items detected)


(end)


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014
Ran by Kati (administrator) on KATI-PC on 21-05-2014 19:18:30
Running from C:\Users\Kati\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(BUP) C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Memeo) C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
(Spotify Ltd) C:\Users\Kati\AppData\Roaming\Spotify\spotify.exe
(Spotify Ltd) C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIGJE.EXE
(Dropbox, Inc.) C:\Users\Kati\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\POsd.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Farbar) C:\Users\Kati\Downloads\FRST64(1).exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-22] (Alcor Micro Corp.)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [MedionReminder] => C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [PHotkey] => C:\Program Files (x86)\PHotkey\PHotkey.exe [819720 2011-02-23] (Pegatron Corporation)
HKLM-x32\...\Run: [MsgTranAgt] => C:\Program Files (x86)\PHotkey\MsgTranAgt.exe [117256 2010-01-12] ()
HKLM-x32\...\Run: [MsgTranAgt64] => C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe [121864 2010-01-12] ()
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [847872 2009-12-03] (SEIKO EPSON CORPORATION)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Facebook Update] => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-09-20] (Facebook Inc.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [449760 2013-10-31] (Sony)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Spotify] => C:\Users\Kati\AppData\Roaming\Spotify\Spotify.exe [6170168 2014-05-15] (Spotify Ltd)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Spotify Web Helper] => C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-15] (Spotify Ltd)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-09-20] (Google Inc.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [EPSON BX305 Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGJE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk
ShortcutTarget: simplicheck.lnk -> C:\Program Files (x86)\simplitec\simplicheck\simplicheck.exe (No File)
Startup: C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Kati\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9A119BA29CEBCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 - C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Kati\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: sony.com/MediaGoDetector - C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\Kati\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Foxy Security - C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\Extensions\sys@foxysecurity.com [2014-04-28]
FF Extension: DownloadHelper - C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-31]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2013-09-11]

Chrome:
=======
CHR HomePage:
CHR DefaultSearchProvider: Delta Search
CHR DefaultSearchURL: hxxp://www.google.com
CHR DefaultNewTabURL:
CHR Extension: (DVDVideoSoft) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-12-24]
CHR Extension: (Google Wallet) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-03]
CHR Extension: (Citavi Picker) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\piehhloihgjjiomhieeddiidpekaajio [2013-12-24]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-06-29]
CHR HKLM-x32\...\Chrome\Extension: [dghncoeocefmhkhiphdgikkamjeglbfh] - C:\Program Files (x86)\mystarttb\chrome-newtab-search.crx [2013-06-29]
CHR HKLM-x32\...\Chrome\Extension: [piehhloihgjjiomhieeddiidpekaajio] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Chrome\ChromePicker.crx [2013-09-11]

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 bupService; C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe [642048 2014-04-14] (BUP)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-06] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-30] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-30] (pdfforge GmbH)
S2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [X]
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe" [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-21 19:17 - 2014-05-21 19:17 - 00002668 _____ () C:\Users\Kati\Desktop\mbam.text
2014-05-21 18:50 - 2014-05-21 19:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-21 18:49 - 2014-05-21 18:49 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-21 18:49 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-21 18:49 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-21 18:48 - 2014-05-21 18:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Kati\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-21 18:32 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-21 18:31 - 2014-05-21 18:31 - 01326389 _____ () C:\Users\Kati\Downloads\adwcleaner_3.210.exe
2014-05-21 16:12 - 2014-05-21 16:13 - 00000000 ____D () C:\Users\Kati\AppData\Local\{45C30B23-5900-4B42-9501-3B28B7579182}
2014-05-19 19:43 - 2014-05-19 19:43 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F1FFA1EE-9E79-4BE1-9F37-563DF59C3CB4}
2014-05-18 14:43 - 2014-05-18 14:44 - 00043884 _____ () C:\Users\Kati\Downloads\Addition.txt
2014-05-18 14:23 - 2014-05-18 14:23 - 02067456 _____ (Farbar) C:\Users\Kati\Downloads\FRST64(1).exe
2014-05-18 13:50 - 2014-05-18 13:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{422F2530-3EF2-4E9C-A789-485C1206D1AC}
2014-05-18 12:11 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-05-18 12:11 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-05-17 23:57 - 2014-05-17 23:59 - 00000000 ____D () C:\Users\Kati\Desktop\Fotos
2014-05-17 23:56 - 2014-05-17 23:58 - 00000000 ____D () C:\Users\Kati\Desktop\Kinderfotos
2014-05-17 23:51 - 2014-05-17 23:55 - 00000000 ____D () C:\Users\Kati\Downloads\Uni
2014-05-17 22:55 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-05-17 22:55 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-17 22:55 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-17 22:55 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-05-17 22:55 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-05-17 22:55 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-05-17 22:55 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-05-17 22:55 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-05-17 22:55 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-05-17 22:55 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-05-17 22:55 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-05-17 22:55 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-05-17 22:55 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-05-17 22:55 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-05-17 22:55 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-05-17 22:55 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-05-17 22:54 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-05-17 22:54 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-05-17 22:08 - 2014-05-17 22:08 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4BE87CCE-750B-4228-B62E-246699B53E05}
2014-05-17 20:59 - 2014-05-17 20:59 - 00383343 _____ () C:\Users\Kati\Desktop\Report.htm
2014-05-17 20:58 - 2014-05-17 20:58 - 00000000 ____D () C:\Users\Kati\Documents\EVEREST Reports
2014-05-17 20:41 - 2014-05-17 20:42 - 215448505 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\wlane6221_inw7.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 18857054 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\tpde6221_se_wxpvstw7_32_64.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 09144982 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\usb3e6221_e722xw7.exe
2014-05-17 20:39 - 2014-05-17 20:40 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(2).exe
2014-05-17 20:39 - 2014-05-17 20:39 - 31119378 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\mnme6221_e722xvstw7_w8.exe
2014-05-17 20:39 - 2014-05-17 20:39 - 02620971 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\lane6221_e722xxpvstw7.exe
2014-05-17 20:38 - 2014-05-17 20:38 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8(1).exe
2014-05-17 20:34 - 2014-05-17 20:37 - 195993064 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\vgae6221_e722x_in_w7_w8.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 03987373 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\chpe6221_e722xxpvstw7.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 01798895 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\bioe722x_p762x.exe
2014-05-17 20:33 - 2014-05-17 20:34 - 11290483 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ahcie6221vstw7_w8.exe
2014-05-17 20:31 - 2014-05-17 20:31 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8.exe
2014-05-17 20:26 - 2014-05-17 20:26 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(1).exe
2014-05-17 20:25 - 2014-05-17 20:25 - 00229008 _____ () C:\Users\Kati\Downloads\MEDION_Treibersuche.exe
2014-05-17 20:18 - 2014-05-17 20:18 - 00001130 _____ () C:\Users\Kati\Desktop\EVEREST Ultimate Edition.lnk
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\Program Files (x86)\Lavalys
2014-05-17 20:17 - 2014-05-17 20:17 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Kati\Downloads\everestultimate550.exe
2014-05-17 18:20 - 2014-05-17 18:45 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-17 18:20 - 2014-05-17 18:20 - 00001266 _____ () C:\Users\Public\Desktop\NCH Software.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\Users\Public\Desktop\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001142 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:19 - 2014-05-17 18:19 - 00001130 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00001118 _____ () C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:18 - 2014-05-17 18:18 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kati\Downloads\Debut Video Capture - CHIP-Downloader.exe
2014-05-16 22:17 - 2014-05-16 22:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2611705F-FCFF-44F2-9C4B-EC29E5A67B46}
2014-05-16 09:09 - 2014-05-16 09:09 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69A1EF25-1F79-4775-BA26-5F9375FE9B95}
2014-05-16 08:35 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-16 08:35 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-16 08:35 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-16 08:35 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-16 08:35 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-16 08:35 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 14:27 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-15 14:27 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-15 14:27 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 14:27 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-15 14:26 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 14:26 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 14:26 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 14:26 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 14:26 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-15 14:26 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-15 14:26 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 14:26 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 14:26 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 14:26 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 14:26 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 14:26 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-15 14:26 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-15 14:17 - 2014-05-15 14:18 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4DD5F804-7106-4564-8BC2-F943268098E6}
2014-05-14 19:25 - 2014-05-14 19:25 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:12 - 00001021 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-05-14 19:12 - 2014-05-14 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-14 19:11 - 2014-05-14 19:12 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-14 19:11 - 2014-05-14 19:11 - 00000000 ____D () C:\Users\Kati\Documents\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:12 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-14 19:10 - 2014-05-14 19:10 - 00001039 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-14 19:10 - 2014-04-25 17:44 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-05-14 19:10 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-05-14 19:10 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6DE.DLL
2014-05-14 19:10 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCDE.DLL
2014-05-14 19:10 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCC2DE.DLL
2014-05-14 19:07 - 2014-05-14 19:08 - 27843432 _____ (pdfforge ) C:\Users\Kati\Downloads\PDFCreator-1_7_3_setup.exe
2014-05-14 16:28 - 2014-05-14 16:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{AFF51EAF-1EEE-4D30-9A8D-532258456C17}
2014-05-13 17:17 - 2014-05-13 17:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B0C594E1-1C40-46AD-9B29-7C5B4986A6E6}
2014-05-13 16:53 - 2014-05-13 16:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{98AC1C21-B103-44EE-AC7B-2C114FD85585}
2014-05-12 20:54 - 2014-05-12 20:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{BE16BDD7-B89C-4024-B9F6-AD6FF1E9E786}
2014-05-11 19:59 - 2014-05-11 19:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-11 19:46 - 2014-05-11 19:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{C2B4150E-0C6B-4799-9C08-B1E8DFC269ED}
2014-05-10 21:55 - 2014-05-10 21:55 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9A0AD5CC-139C-491B-9266-50616B3EF2EC}
2014-05-09 17:57 - 2014-05-09 17:57 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9C638A68-5F34-48C1-898B-3689CD978999}
2014-05-08 15:00 - 2014-05-08 15:00 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B51A953C-DD2F-4FB8-AA87-F6AD0AFB9AC2}
2014-05-07 19:04 - 2014-05-16 08:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-07 19:04 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-07 19:04 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-07 19:04 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-07 19:04 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-07 19:04 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-07 19:04 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-07 19:04 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-07 19:04 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-07 19:04 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-07 19:04 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-07 19:04 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-07 19:04 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-07 19:04 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-07 19:04 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-07 19:04 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-07 19:04 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-07 19:04 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-07 19:04 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-07 19:04 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-07 19:04 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-07 19:04 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-07 19:04 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-07 19:04 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-07 19:04 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-07 19:04 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-07 19:04 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-07 19:04 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-07 19:04 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-07 19:04 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-07 19:04 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-07 19:04 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-07 19:04 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-07 19:04 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-07 19:04 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-07 19:04 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-07 19:04 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-07 19:04 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-07 19:04 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-07 19:04 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-07 19:04 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-07 19:04 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-07 19:04 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-07 19:04 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-07 19:04 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-07 19:02 - 2014-05-07 19:03 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DFB33308-901D-4EAF-9C6E-A5DEA8364065}
2014-05-06 15:35 - 2014-05-06 15:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{01097470-E215-4F09-8B1E-B904D4356792}
2014-05-05 18:20 - 2014-05-05 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Local\{8837D2BF-2261-45A5-975D-F775DFD9FD39}
2014-05-04 21:59 - 2014-05-04 21:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{30370F42-121E-48B3-B315-481D08085F3A}
2014-05-03 21:27 - 2014-05-03 21:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DB63567F-3788-43B8-BCFB-ED07BD306540}
2014-05-03 02:36 - 2014-05-03 02:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3CD5C54C-8659-40F2-AE16-BB7B404718E6}
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-05-02 14:35 - 2014-05-02 14:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DC60EB2C-B723-4FA9-A38E-31AC1A6775EA}
2014-05-01 13:21 - 2014-05-01 13:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B1833989-708E-4FC2-AADF-908BFAC0A56F}
2014-04-30 18:53 - 2014-04-30 18:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5EF441A7-91AC-4C8E-9DF8-3CA8C25B701E}
2014-04-29 16:21 - 2014-04-29 16:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6AB88698-1939-4E66-BCF8-9C5E2800911A}
2014-04-28 17:05 - 2014-04-28 17:05 - 00128000 ____H () C:\Users\Kati\Desktop\photothumb.db
2014-04-28 17:04 - 2014-04-28 17:06 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PhotoScape
2014-04-28 17:04 - 2014-04-28 17:04 - 00001039 _____ () C:\Users\Kati\Desktop\PhotoScape.lnk
2014-04-28 17:04 - 2014-04-28 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2014-04-28 17:03 - 2014-04-28 17:04 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Security Systems
2014-04-28 17:03 - 2014-04-28 17:04 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-04-28 17:03 - 2014-04-28 17:03 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\BupSystem
2014-04-28 16:22 - 2014-04-28 16:22 - 00000000 ____D () C:\Users\Kati\AppData\Local\{E6EF1C33-8457-4043-B475-28B37C804CF7}
2014-04-27 12:51 - 2014-04-27 12:51 - 00000000 ____D () C:\Users\Kati\AppData\Local\{50566B36-6424-40FE-8E57-875DA3FE0D99}
2014-04-26 20:36 - 2014-04-26 20:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3B71D42C-D487-4B7F-A90D-DF6ABC7D9BEE}
2014-04-26 02:43 - 2014-04-26 02:44 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B4704FBF-46C6-4E83-9C9B-F811FBCF29C8}
2014-04-25 14:36 - 2014-04-25 14:37 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3D4FFA91-C31D-42D3-98D3-55D24540A116}
2014-04-24 20:48 - 2014-04-24 20:48 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6B75591B-A85D-449D-8566-C3803B21D41A}
2014-04-23 19:06 - 2014-04-23 19:06 - 00000000 ____D () C:\Users\Kati\AppData\Local\{05C9CB18-5353-481E-B307-AC526C8EAD50}
2014-04-22 17:25 - 2014-04-22 17:25 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DEA26C1D-154A-44C1-B6B0-8D0C9CE3E56A}
2014-04-22 01:11 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-22 01:11 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-22 01:11 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-22 01:11 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-22 01:11 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-22 01:11 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-22 01:11 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-22 01:11 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-22 01:11 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-22 01:11 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-22 01:11 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-22 01:11 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-22 01:11 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-22 01:11 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-22 00:59 - 2014-04-22 00:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5A0297BB-2640-42E9-B94D-6AD8D30F5957}

==================== One Month Modified Files and Folders =======

2014-05-21 19:19 - 2012-09-20 19:21 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-21 19:18 - 2013-11-29 01:51 - 00018162 _____ () C:\Users\Kati\Downloads\FRST.txt
2014-05-21 19:18 - 2013-11-26 14:29 - 00000000 ____D () C:\FRST
2014-05-21 19:18 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-21 19:18 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-21 19:17 - 2014-05-21 19:17 - 00002668 _____ () C:\Users\Kati\Desktop\mbam.text
2014-05-21 19:13 - 2014-05-21 18:50 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-21 19:12 - 2014-01-08 01:02 - 00000000 ___RD () C:\Users\Kati\Dropbox
2014-05-21 19:12 - 2014-01-08 01:00 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Dropbox
2014-05-21 19:12 - 2012-11-10 23:07 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Spotify
2014-05-21 19:10 - 2014-01-27 22:53 - 00000478 _____ () C:\Windows\Tasks\SDMsgUpdate (Local).job
2014-05-21 19:10 - 2014-01-27 22:53 - 00000470 _____ () C:\Windows\Tasks\SDMsgUpdate (TE).job
2014-05-21 19:10 - 2012-09-20 19:21 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-21 19:09 - 2010-11-21 05:47 - 00147674 _____ () C:\Windows\PFRO.log
2014-05-21 19:09 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-21 19:09 - 2009-07-14 06:51 - 02343866 _____ () C:\Windows\setupact.log
2014-05-21 19:08 - 2013-07-24 18:55 - 02052839 _____ () C:\Windows\WindowsUpdate.log
2014-05-21 19:08 - 2012-09-20 21:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-21 19:07 - 2013-12-17 16:48 - 00000000 ____D () C:\Windows\Minidump
2014-05-21 18:49 - 2014-05-21 18:49 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2013-05-14 19:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-21 18:48 - 2014-05-21 18:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Kati\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-21 18:41 - 2012-11-10 23:07 - 00000000 ____D () C:\Users\Kati\AppData\Local\Spotify
2014-05-21 18:40 - 2012-09-23 18:09 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Skype
2014-05-21 18:37 - 2013-11-28 22:41 - 00000000 ____D () C:\AdwCleaner
2014-05-21 18:36 - 2012-09-21 13:58 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\SoftGrid Client
2014-05-21 18:31 - 2014-05-21 18:31 - 01326389 _____ () C:\Users\Kati\Downloads\adwcleaner_3.210.exe
2014-05-21 16:24 - 2012-09-20 22:19 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001UA.job
2014-05-21 16:18 - 2012-09-20 22:19 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001Core.job
2014-05-21 16:13 - 2014-05-21 16:12 - 00000000 ____D () C:\Users\Kati\AppData\Local\{45C30B23-5900-4B42-9501-3B28B7579182}
2014-05-19 19:43 - 2014-05-19 19:43 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F1FFA1EE-9E79-4BE1-9F37-563DF59C3CB4}
2014-05-18 15:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-18 14:44 - 2014-05-18 14:43 - 00043884 _____ () C:\Users\Kati\Downloads\Addition.txt
2014-05-18 14:23 - 2014-05-18 14:23 - 02067456 _____ (Farbar) C:\Users\Kati\Downloads\FRST64(1).exe
2014-05-18 13:50 - 2014-05-18 13:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{422F2530-3EF2-4E9C-A789-485C1206D1AC}
2014-05-18 12:34 - 2014-02-24 22:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\Windows Live
2014-05-18 12:07 - 2011-05-16 16:04 - 00699794 _____ () C:\Windows\system32\perfh007.dat
2014-05-18 12:07 - 2011-05-16 16:04 - 00149644 _____ () C:\Windows\system32\perfc007.dat
2014-05-18 12:07 - 2009-07-14 07:13 - 01620836 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-17 23:59 - 2014-05-17 23:57 - 00000000 ____D () C:\Users\Kati\Desktop\Fotos
2014-05-17 23:58 - 2014-05-17 23:56 - 00000000 ____D () C:\Users\Kati\Desktop\Kinderfotos
2014-05-17 23:55 - 2014-05-17 23:51 - 00000000 ____D () C:\Users\Kati\Downloads\Uni
2014-05-17 23:52 - 2013-11-24 21:13 - 00000000 ____D () C:\Users\Kati\Downloads\verschiedene Bilder
2014-05-17 22:08 - 2014-05-17 22:08 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4BE87CCE-750B-4228-B62E-246699B53E05}
2014-05-17 20:59 - 2014-05-17 20:59 - 00383343 _____ () C:\Users\Kati\Desktop\Report.htm
2014-05-17 20:58 - 2014-05-17 20:58 - 00000000 ____D () C:\Users\Kati\Documents\EVEREST Reports
2014-05-17 20:42 - 2014-05-17 20:41 - 215448505 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\wlane6221_inw7.exe
2014-05-17 20:42 - 2013-12-16 20:47 - 00000000 ____D () C:\Medion
2014-05-17 20:40 - 2014-05-17 20:40 - 18857054 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\tpde6221_se_wxpvstw7_32_64.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 09144982 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\usb3e6221_e722xw7.exe
2014-05-17 20:40 - 2014-05-17 20:39 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(2).exe
2014-05-17 20:39 - 2014-05-17 20:39 - 31119378 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\mnme6221_e722xvstw7_w8.exe
2014-05-17 20:39 - 2014-05-17 20:39 - 02620971 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\lane6221_e722xxpvstw7.exe
2014-05-17 20:38 - 2014-05-17 20:38 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8(1).exe
2014-05-17 20:37 - 2014-05-17 20:34 - 195993064 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\vgae6221_e722x_in_w7_w8.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 03987373 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\chpe6221_e722xxpvstw7.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 01798895 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\bioe722x_p762x.exe
2014-05-17 20:34 - 2014-05-17 20:33 - 11290483 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ahcie6221vstw7_w8.exe
2014-05-17 20:31 - 2014-05-17 20:31 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8.exe
2014-05-17 20:26 - 2014-05-17 20:26 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(1).exe
2014-05-17 20:25 - 2014-05-17 20:25 - 00229008 _____ () C:\Users\Kati\Downloads\MEDION_Treibersuche.exe
2014-05-17 20:18 - 2014-05-17 20:18 - 00001130 _____ () C:\Users\Kati\Desktop\EVEREST Ultimate Edition.lnk
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\Program Files (x86)\Lavalys
2014-05-17 20:17 - 2014-05-17 20:17 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Kati\Downloads\everestultimate550.exe
2014-05-17 18:45 - 2014-05-17 18:20 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-17 18:20 - 2014-05-17 18:20 - 00001266 _____ () C:\Users\Public\Desktop\NCH Software.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\Users\Public\Desktop\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001142 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:19 - 2014-05-17 18:19 - 00001130 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00001118 _____ () C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:18 - 2014-05-17 18:18 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kati\Downloads\Debut Video Capture - CHIP-Downloader.exe
2014-05-16 22:17 - 2014-05-16 22:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2611705F-FCFF-44F2-9C4B-EC29E5A67B46}
2014-05-16 09:12 - 2013-01-07 00:52 - 00002023 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-05-16 09:12 - 2011-06-28 21:31 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-16 09:09 - 2014-05-16 09:09 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69A1EF25-1F79-4775-BA26-5F9375FE9B95}
2014-05-16 09:06 - 2012-09-20 18:26 - 00000000 ___RD () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-16 09:06 - 2012-09-20 18:26 - 00000000 ___RD () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 08:55 - 2014-05-07 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-16 08:34 - 2013-07-29 22:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-16 08:31 - 2013-07-25 12:48 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-16 00:24 - 2012-09-20 19:21 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-05-15 14:18 - 2014-05-15 14:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4DD5F804-7106-4564-8BC2-F943268098E6}
2014-05-14 19:25 - 2014-05-14 19:25 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:12 - 00001021 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-05-14 19:12 - 2014-05-14 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:11 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:10 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-14 19:11 - 2014-05-14 19:11 - 00000000 ____D () C:\Users\Kati\Documents\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00001039 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-14 19:08 - 2014-05-14 19:07 - 27843432 _____ (pdfforge ) C:\Users\Kati\Downloads\PDFCreator-1_7_3_setup.exe
2014-05-14 17:08 - 2013-12-16 21:08 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 17:08 - 2012-09-20 21:54 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-14 17:08 - 2011-07-18 19:57 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-14 16:28 - 2014-05-14 16:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{AFF51EAF-1EEE-4D30-9A8D-532258456C17}
2014-05-14 16:06 - 2014-01-08 01:02 - 00001017 _____ () C:\Users\Kati\Desktop\Dropbox.lnk
2014-05-14 16:06 - 2014-01-08 01:01 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-13 17:17 - 2014-05-13 17:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B0C594E1-1C40-46AD-9B29-7C5B4986A6E6}
2014-05-13 16:54 - 2014-05-13 16:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{98AC1C21-B103-44EE-AC7B-2C114FD85585}
2014-05-13 16:49 - 2014-01-29 16:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-12 20:54 - 2014-05-12 20:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{BE16BDD7-B89C-4024-B9F6-AD6FF1E9E786}
2014-05-12 07:26 - 2014-05-21 18:49 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-21 18:49 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-21 18:49 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 22:59 - 2013-09-30 12:13 - 00000000 ____D () C:\Users\Kati\Documents\Citavi 4
2014-05-11 19:59 - 2014-05-11 19:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-11 19:46 - 2014-05-11 19:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{C2B4150E-0C6B-4799-9C08-B1E8DFC269ED}
2014-05-10 21:55 - 2014-05-10 21:55 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9A0AD5CC-139C-491B-9266-50616B3EF2EC}
2014-05-09 17:57 - 2014-05-09 17:57 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9C638A68-5F34-48C1-898B-3689CD978999}
2014-05-09 08:14 - 2014-05-15 14:27 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 14:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-08 15:00 - 2014-05-08 15:00 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B51A953C-DD2F-4FB8-AA87-F6AD0AFB9AC2}
2014-05-07 20:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-07 19:03 - 2014-05-07 19:02 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DFB33308-901D-4EAF-9C6E-A5DEA8364065}
2014-05-06 15:35 - 2014-05-06 15:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{01097470-E215-4F09-8B1E-B904D4356792}
2014-05-06 06:40 - 2014-05-16 08:35 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-16 08:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-16 08:35 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-16 08:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-16 08:35 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-16 08:35 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-05 23:14 - 2012-09-20 19:21 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-05 23:14 - 2012-09-20 19:21 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-05 18:20 - 2014-05-05 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Local\{8837D2BF-2261-45A5-975D-F775DFD9FD39}
2014-05-04 21:59 - 2014-05-04 21:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{30370F42-121E-48B3-B315-481D08085F3A}
2014-05-03 21:28 - 2014-05-03 21:27 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DB63567F-3788-43B8-BCFB-ED07BD306540}
2014-05-03 02:36 - 2014-05-03 02:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3CD5C54C-8659-40F2-AE16-BB7B404718E6}
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-05-03 01:55 - 2013-04-19 13:10 - 00000000 ____D () C:\ProgramData\Sony Ericsson
2014-05-03 01:55 - 2013-04-19 13:10 - 00000000 ____D () C:\Program Files (x86)\Sony Ericsson
2014-05-02 14:36 - 2014-05-02 14:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DC60EB2C-B723-4FA9-A38E-31AC1A6775EA}
2014-05-01 13:21 - 2014-05-01 13:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B1833989-708E-4FC2-AADF-908BFAC0A56F}
2014-04-30 18:53 - 2014-04-30 18:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5EF441A7-91AC-4C8E-9DF8-3CA8C25B701E}
2014-04-29 16:21 - 2014-04-29 16:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6AB88698-1939-4E66-BCF8-9C5E2800911A}
2014-04-28 17:06 - 2014-04-28 17:04 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PhotoScape
2014-04-28 17:05 - 2014-04-28 17:05 - 00128000 ____H () C:\Users\Kati\Desktop\photothumb.db
2014-04-28 17:04 - 2014-04-28 17:04 - 00001039 _____ () C:\Users\Kati\Desktop\PhotoScape.lnk
2014-04-28 17:04 - 2014-04-28 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2014-04-28 17:04 - 2014-04-28 17:03 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Security Systems
2014-04-28 17:04 - 2014-04-28 17:03 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-04-28 17:03 - 2014-04-28 17:03 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\BupSystem
2014-04-28 17:03 - 2012-09-20 18:26 - 00000000 ____D () C:\Users\Kati\AppData\Local\Google
2014-04-28 16:22 - 2014-04-28 16:22 - 00000000 ____D () C:\Users\Kati\AppData\Local\{E6EF1C33-8457-4043-B475-28B37C804CF7}
2014-04-27 12:51 - 2014-04-27 12:51 - 00000000 ____D () C:\Users\Kati\AppData\Local\{50566B36-6424-40FE-8E57-875DA3FE0D99}
2014-04-26 20:36 - 2014-04-26 20:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3B71D42C-D487-4B7F-A90D-DF6ABC7D9BEE}
2014-04-26 02:44 - 2014-04-26 02:43 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B4704FBF-46C6-4E83-9C9B-F811FBCF29C8}
2014-04-25 17:44 - 2014-05-14 19:10 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-04-25 17:44 - 2014-05-14 19:10 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-04-25 17:44 - 2014-05-14 19:10 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2014-04-25 17:44 - 2014-05-14 19:10 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-04-25 17:44 - 2014-05-14 19:10 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-04-25 14:37 - 2014-04-25 14:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3D4FFA91-C31D-42D3-98D3-55D24540A116}
2014-04-24 20:48 - 2014-04-24 20:48 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6B75591B-A85D-449D-8566-C3803B21D41A}
2014-04-23 19:06 - 2014-04-23 19:06 - 00000000 ____D () C:\Users\Kati\AppData\Local\{05C9CB18-5353-481E-B307-AC526C8EAD50}
2014-04-22 17:25 - 2014-04-22 17:25 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DEA26C1D-154A-44C1-B6B0-8D0C9CE3E56A}
2014-04-22 01:00 - 2011-07-18 18:45 - 00298486 _____ () C:\Windows\DPINST.LOG
2014-04-22 00:59 - 2014-04-22 00:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5A0297BB-2640-42E9-B94D-6AD8D30F5957}

Some content of TEMP:
====================
C:\Users\Kati\AppData\Local\Temp\avgnt.exe
C:\Users\Kati\AppData\Local\Temp\burnsetup.exe
C:\Users\Kati\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpefvu0o.dll
C:\Users\Kati\AppData\Local\Temp\FoxySecuritySetup.exe
C:\Users\Kati\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Kati\AppData\Local\Temp\Quarantine.exe
C:\Users\Kati\AppData\Local\Temp\sjy8mvbh.dll
C:\Users\Kati\AppData\Local\Temp\vpsetup.exe
C:\Users\Kati\AppData\Local\Temp\_is6454.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe
[2014-05-15 14:26] - [2014-03-04 11:43] - 0455168 ____A (Microsoft Corporation) 88AB9B72B4BF3963A0DE0820B4B0B06C

C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-19 09:55

==================== End Of Log ============================

--- --- ---


Und daaaaaaaann? :)

sunjojo 21.05.2014 18:39

Die Laufwerksbuchstaben von den/m Usb-Stick/s :).

Nirtaka 21.05.2014 20:20

Ups,:stirn: hab ich glatt vergessen! Der Stick ist auf Laufwerk F!

sunjojo 22.05.2014 16:57

Ok, dann bitte den USB-Stick jetzt angeschlossen haben:



Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

R2 bupService; C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe [642048 2014-04-14] (BUP)
(BUP) C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe
 C:\Users\Kati\AppData\Roaming\BupSystem
2014-04-28 17:03 - 2014-04-28 17:04 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Security Systems
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk
SearchScopes: HKLM - DefaultScope value is missing.
CHR HKLM-x32\...\Chrome\Extension: [dghncoeocefmhkhiphdgikkamjeglbfh] - C:\Program Files (x86)\mystarttb\chrome-newtab-search.crx [2013-06-29]
cmd: dir F:\ /a


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Poste folgende Logfiles in deiner nächsten Antwort:
  • Fixlog.txt

Nirtaka 26.05.2014 22:05

Hey sorry, dass ich mich so spät zurückmelde, ich war ein paar Tage nicht Zuhause. Aber jetzt gehts weiter:


Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-05-2014 02
Ran by Kati at 2014-05-26 23:02:57 Run:1
Running from C:\Users\Kati\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
R2 bupService; C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe [642048 2014-04-14] (BUP)
(BUP) C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe
 C:\Users\Kati\AppData\Roaming\BupSystem
2014-04-28 17:03 - 2014-04-28 17:04 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Security Systems
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk
SearchScopes: HKLM - DefaultScope value is missing.
CHR HKLM-x32\...\Chrome\Extension: [dghncoeocefmhkhiphdgikkamjeglbfh] - C:\Program Files (x86)\mystarttb\chrome-newtab-search.crx [2013-06-29]
cmd: dir F:\ /a
*****************

bupService => Service stopped successfully.
bupService => Service deleted successfully.
C:\Users\Kati\AppData\Roaming\BupSystem\bup.exe => No running process found
C:\Users\Kati\AppData\Roaming\BupSystem => Moved successfully.
C:\Users\Kati\AppData\Roaming\Security Systems => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk => Moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dghncoeocefmhkhiphdgikkamjeglbfh => Key deleted successfully.
"C:\Program Files (x86)\mystarttb\chrome-newtab-search.crx" => File/Directory not found.

=========  dir F:\ /a =========

 Volume in Laufwerk F: hat keine Bezeichnung.
 Volumeseriennummer: BC31-D49E

 Verzeichnis von F:\

28.10.2012  10:23            8.192 V1_134.SSU
21.05.2014  17:53    <DIR>          FOUND.000
28.10.2012  10:17        1.032.192 Soft_HD_3__plus_max_k (1).zip
26.11.2012  13:06    <DIR>          Bilder alt
26.11.2012  13:55    <DIR>          Bewerbung
26.11.2012  13:55    <DIR>          August 2011
26.11.2012  13:56    <DIR>          Party Silent Sinners Januar 2012
26.11.2012  13:57    <DIR>          Schweinchen 2012
26.11.2012  13:58    <DIR>          Herr Soldo
26.11.2012  13:58    <DIR>          Schindlerhof
26.11.2012  14:03    <DIR>          Sch�ner Tag
26.11.2012  14:05    <DIR>          z�hne
26.11.2012  14:05    <DIR>          Onion
26.11.2012  14:06    <DIR>          Party Village
26.11.2012  14:06    <DIR>          27. Geburtstag!
26.11.2012  14:07    <DIR>          ROMA 2012
26.11.2012  15:10    <DIR>          Westfalenpark
26.11.2012  18:01    <DIR>          Downloads
02.01.2013  20:14            13.738 AntragAufBefreiung.pdf
18.05.2014  12:16    <DIR>          Fotos
              3 Datei(en),      1.054.122 Bytes
              17 Verzeichnis(se),  3.875.422.208 Bytes frei

========= End of CMD: =========


==== End of Fixlog ====


sunjojo 27.05.2014 18:08

Ok, alles klar. Alle Dateien, die du nicht kennst auf dem USB-Stick bitte löschen. Den USB-Stick für den 1. Schritt bitte angeschlossen haben :).



Schritt 1

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

Schritt 2
Öffne Google Chrome.
  • Klicke auf das Chrome-Menü http://www.trojaner-board.de/picture...&pictureid=489 (rechts im Browser).
  • Wähle nun "Einstellungen" in dem Menü aus.
  • Scrolle nach unten und klicke "Erweiterte Einstellungen anzeigen" an.
  • Nun werden dir weitere Optionen angezeigt. Wähle http://www.trojaner-board.de/picture...&pictureid=490 aus (letzter Punkt der Einstellungsmöglichkeiten).
  • Ein Fenster wird geöffnet, in welchem du "Zurücksetzen" auswählst.
  • Jetzt werden deine aktuellen Browsereinstellungen zurückgesetzt (Startseite, Suchseite, ...), Erweiterungen und Designs deaktiviert.

Schritt 3
Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, wird ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.

Hast du noch i-welche Probleme mit deinem Rechner?



Poste folgende Logfiles in deiner nächsten Antwort:
  • Log.txt
  • FRST.txt

Nirtaka 28.05.2014 18:26

Ähm... Hi Jonas.. sag mal, ist das normal, dass der ESET über 20 Stunden läuft? Ist jetzt nach der Zeit erst bei 51% :-O habe das eigentlich nach der Anleitung gestartet, oder woran könnte es liegen? LG Kati

sunjojo 28.05.2014 19:11

Das kann schon so lange dauern, je nachdem wie viele Dateien du auf deinem Rechner hast :).

Nirtaka 28.05.2014 19:34

Okeee, dann werde ich mal geduldig weiter warten :) Danke!

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=9ecb13bea9aa394f887726469b2e3bea
# engine=18435
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-05-28 06:18:32
# local_time=2014-05-28 08:18:32 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 96 80921 266720802 73676 0
# compatibility_mode=5893 16776573 100 94 165801 152930962 0 0
# scanned=213699
# found=0
# cleaned=0
# scan_time=78034

Hey, du hattest ja noch gefragt, ob iwas anderes nicht stimmen würde am Rechner und ich hätte da noch was :-D weiss nicht ob du mir da auch helfen kannst, auf jeden Fall wäre es toll... undzwar geht der Ton immer nach einigen Sekunden aus.. wenn ich mit Rechtsklick auf das Lautsprecherzeichen klicke und zwischen den Reitern Wiedergabe- und Ausgabegerät hin und herspringe kommt der Ton für einige Sekunden wieder... Ich habe mir von Medion die aktuellen Treiber runtergeladen und weiss nicht woran es liegt.. Energieeinstellungen hab ich auch umgeändert aber keine Besserung. Der Akku des Lappis ist platt und das Notebook läuft nur wenn ich das Netzwerkkabel angeschlossen habe aber das hat damit nichts zu tun, oder? Das ist die einzige Sache die sonst nicht stimmt aber ist auch extrem nervig auf Dauer ohne Ton. Vllt hast du ja Rat?!

sunjojo 28.05.2014 20:49

Als erstes bräuchte ich noch ein frisches FRST Logfile, um zu gucken, ob sich noch Malware auf dem Rechner befindet. Danach kümmern wir uns um dein anderes Problem :).

Nirtaka 28.05.2014 22:36


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by Kati (administrator) on KATI-PC on 28-05-2014 23:31:31
Running from C:\Users\Kati\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Memeo) C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Spotify Ltd) C:\Users\Kati\AppData\Roaming\Spotify\spotify.exe
(Spotify Ltd) C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIGJE.EXE
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
(Pegatron Corporation) C:\Program Files (x86)\PHotkey\POsd.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Dropbox, Inc.) C:\Users\Kati\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
(Avanquest Software) C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-22] (Alcor Micro Corp.)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [MedionReminder] => C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [PHotkey] => C:\Program Files (x86)\PHotkey\PHotkey.exe [819720 2011-02-23] (Pegatron Corporation)
HKLM-x32\...\Run: [MsgTranAgt] => C:\Program Files (x86)\PHotkey\MsgTranAgt.exe [117256 2010-01-12] ()
HKLM-x32\...\Run: [MsgTranAgt64] => C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe [121864 2010-01-12] ()
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [847872 2009-12-03] (SEIKO EPSON CORPORATION)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Facebook Update] => C:\Users\Kati\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-09-20] (Facebook Inc.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-04-01] (Sony)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Spotify] => C:\Users\Kati\AppData\Roaming\Spotify\Spotify.exe [6170168 2014-05-15] (Spotify Ltd)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [Spotify Web Helper] => C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-15] (Spotify Ltd)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-09-20] (Google Inc.)
HKU\S-1-5-21-2548312011-2494454960-3164520827-1001\...\Run: [EPSON BX305 Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGJE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
Startup: C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Kati\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9A119BA29CEBCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 - C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Kati\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: sony.com/MediaGoDetector - C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\Kati\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Foxy Security - C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\Extensions\sys@foxysecurity.com [2014-04-28]
FF Extension: DownloadHelper - C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-31]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2013-09-11]

Chrome:
=======
CHR Extension: (DVDVideoSoft) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-12-24]
CHR Extension: (Google Wallet) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-03]
CHR Extension: (Citavi Picker) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\piehhloihgjjiomhieeddiidpekaajio [2013-12-24]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-06-29]
CHR HKLM-x32\...\Chrome\Extension: [piehhloihgjjiomhieeddiidpekaajio] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Chrome\ChromePicker.crx [2013-09-11]

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-06] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-30] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-30] (pdfforge GmbH)
S2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [X]
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe" [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-28 21:50 - 2014-05-28 21:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F2AB505A-9B93-4418-A77B-6FE7CFE310E2}
2014-05-28 21:42 - 2014-05-28 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-05-28 09:49 - 2014-05-28 09:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2ACACF29-6012-45DA-A401-2A8DFDF9A934}
2014-05-27 22:35 - 2014-05-27 22:35 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-27 22:00 - 2014-05-27 22:00 - 00002030 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-05-27 21:49 - 2014-05-27 21:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\{85A3F08A-7AD4-41EC-BF4F-83F3A8A35608}
2014-05-26 22:49 - 2014-05-26 22:50 - 00000590 _____ () C:\Users\Kati\Desktop\fixlist.txt
2014-05-26 22:49 - 2014-05-26 22:49 - 00000000 ____D () C:\Users\Kati\Downloads\FRST-OlderVersion
2014-05-26 22:46 - 2014-05-26 22:47 - 00000000 ____D () C:\Users\Kati\AppData\Local\{EA1C1BC9-C916-4615-8BC9-F292C39BED84}
2014-05-22 13:34 - 2014-05-22 13:34 - 00000000 ____D () C:\Users\Kati\AppData\Local\{D9C4C62D-5ECD-405A-A8D1-08CB33718E33}
2014-05-21 19:17 - 2014-05-21 19:17 - 00002668 _____ () C:\Users\Kati\Desktop\mbam.text
2014-05-21 18:50 - 2014-05-21 19:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-21 18:49 - 2014-05-21 18:49 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-21 18:49 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-21 18:49 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-21 18:48 - 2014-05-21 18:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Kati\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-21 18:32 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-21 18:31 - 2014-05-21 18:31 - 01326389 _____ () C:\Users\Kati\Downloads\adwcleaner_3.210.exe
2014-05-21 16:12 - 2014-05-21 16:13 - 00000000 ____D () C:\Users\Kati\AppData\Local\{45C30B23-5900-4B42-9501-3B28B7579182}
2014-05-19 19:43 - 2014-05-19 19:43 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F1FFA1EE-9E79-4BE1-9F37-563DF59C3CB4}
2014-05-18 14:43 - 2014-05-18 14:44 - 00043884 _____ () C:\Users\Kati\Downloads\Addition.txt
2014-05-18 13:50 - 2014-05-18 13:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{422F2530-3EF2-4E9C-A789-485C1206D1AC}
2014-05-18 12:11 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-05-18 12:11 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-05-17 23:57 - 2014-05-28 21:01 - 00000000 ____D () C:\Users\Kati\Desktop\Fotos
2014-05-17 23:56 - 2014-05-17 23:58 - 00000000 ____D () C:\Users\Kati\Desktop\Kinderfotos
2014-05-17 23:51 - 2014-05-17 23:55 - 00000000 ____D () C:\Users\Kati\Downloads\Uni
2014-05-17 22:55 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-05-17 22:55 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-17 22:55 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-17 22:55 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-05-17 22:55 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-05-17 22:55 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-05-17 22:55 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-05-17 22:55 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-05-17 22:55 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-05-17 22:55 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-05-17 22:55 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-05-17 22:55 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-05-17 22:55 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-05-17 22:55 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-05-17 22:55 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-05-17 22:55 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-05-17 22:54 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-05-17 22:54 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-05-17 22:08 - 2014-05-17 22:08 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4BE87CCE-750B-4228-B62E-246699B53E05}
2014-05-17 20:59 - 2014-05-17 20:59 - 00383343 _____ () C:\Users\Kati\Desktop\Report.htm
2014-05-17 20:58 - 2014-05-17 20:58 - 00000000 ____D () C:\Users\Kati\Documents\EVEREST Reports
2014-05-17 20:41 - 2014-05-17 20:42 - 215448505 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\wlane6221_inw7.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 18857054 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\tpde6221_se_wxpvstw7_32_64.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 09144982 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\usb3e6221_e722xw7.exe
2014-05-17 20:39 - 2014-05-17 20:40 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(2).exe
2014-05-17 20:39 - 2014-05-17 20:39 - 31119378 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\mnme6221_e722xvstw7_w8.exe
2014-05-17 20:39 - 2014-05-17 20:39 - 02620971 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\lane6221_e722xxpvstw7.exe
2014-05-17 20:38 - 2014-05-17 20:38 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8(1).exe
2014-05-17 20:34 - 2014-05-17 20:37 - 195993064 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\vgae6221_e722x_in_w7_w8.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 03987373 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\chpe6221_e722xxpvstw7.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 01798895 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\bioe722x_p762x.exe
2014-05-17 20:33 - 2014-05-17 20:34 - 11290483 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ahcie6221vstw7_w8.exe
2014-05-17 20:31 - 2014-05-17 20:31 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8.exe
2014-05-17 20:26 - 2014-05-17 20:26 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(1).exe
2014-05-17 20:25 - 2014-05-17 20:25 - 00229008 _____ () C:\Users\Kati\Downloads\MEDION_Treibersuche.exe
2014-05-17 20:18 - 2014-05-17 20:18 - 00001130 _____ () C:\Users\Kati\Desktop\EVEREST Ultimate Edition.lnk
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\Program Files (x86)\Lavalys
2014-05-17 20:17 - 2014-05-17 20:17 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Kati\Downloads\everestultimate550.exe
2014-05-17 18:20 - 2014-05-17 18:45 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-17 18:20 - 2014-05-17 18:20 - 00001266 _____ () C:\Users\Public\Desktop\NCH Software.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\Users\Public\Desktop\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001142 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:19 - 2014-05-17 18:19 - 00001130 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00001118 _____ () C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:18 - 2014-05-17 18:18 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kati\Downloads\Debut Video Capture - CHIP-Downloader.exe
2014-05-16 22:17 - 2014-05-16 22:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2611705F-FCFF-44F2-9C4B-EC29E5A67B46}
2014-05-16 09:09 - 2014-05-16 09:09 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69A1EF25-1F79-4775-BA26-5F9375FE9B95}
2014-05-16 08:35 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-16 08:35 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-16 08:35 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-16 08:35 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-16 08:35 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-16 08:35 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 14:27 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-15 14:27 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-15 14:27 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 14:27 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-15 14:26 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 14:26 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 14:26 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 14:26 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 14:26 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-15 14:26 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-15 14:26 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 14:26 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 14:26 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 14:26 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 14:26 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 14:26 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-15 14:26 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-15 14:17 - 2014-05-15 14:18 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4DD5F804-7106-4564-8BC2-F943268098E6}
2014-05-14 19:25 - 2014-05-14 19:25 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:12 - 00001021 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-05-14 19:12 - 2014-05-14 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-14 19:11 - 2014-05-14 19:12 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-14 19:11 - 2014-05-14 19:11 - 00000000 ____D () C:\Users\Kati\Documents\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:12 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-14 19:10 - 2014-05-14 19:10 - 00001039 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-14 19:10 - 2014-04-25 17:44 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-05-14 19:10 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-05-14 19:10 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6DE.DLL
2014-05-14 19:10 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCDE.DLL
2014-05-14 19:10 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCC2DE.DLL
2014-05-14 19:07 - 2014-05-14 19:08 - 27843432 _____ (pdfforge ) C:\Users\Kati\Downloads\PDFCreator-1_7_3_setup.exe
2014-05-14 16:28 - 2014-05-14 16:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{AFF51EAF-1EEE-4D30-9A8D-532258456C17}
2014-05-13 17:17 - 2014-05-13 17:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B0C594E1-1C40-46AD-9B29-7C5B4986A6E6}
2014-05-13 16:53 - 2014-05-13 16:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{98AC1C21-B103-44EE-AC7B-2C114FD85585}
2014-05-12 20:54 - 2014-05-12 20:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{BE16BDD7-B89C-4024-B9F6-AD6FF1E9E786}
2014-05-11 19:59 - 2014-05-11 19:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-11 19:46 - 2014-05-11 19:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{C2B4150E-0C6B-4799-9C08-B1E8DFC269ED}
2014-05-10 21:55 - 2014-05-10 21:55 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9A0AD5CC-139C-491B-9266-50616B3EF2EC}
2014-05-09 17:57 - 2014-05-09 17:57 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9C638A68-5F34-48C1-898B-3689CD978999}
2014-05-08 15:00 - 2014-05-08 15:00 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B51A953C-DD2F-4FB8-AA87-F6AD0AFB9AC2}
2014-05-07 19:04 - 2014-05-16 08:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-07 19:04 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-07 19:04 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-07 19:04 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-07 19:04 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-07 19:04 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-07 19:04 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-07 19:04 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-07 19:04 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-07 19:04 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-07 19:04 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-07 19:04 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-07 19:04 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-07 19:04 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-07 19:04 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-07 19:04 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-07 19:04 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-07 19:04 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-07 19:04 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-07 19:04 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-07 19:04 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-07 19:04 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-07 19:04 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-07 19:04 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-07 19:04 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-07 19:04 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-07 19:04 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-07 19:04 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-07 19:04 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-07 19:04 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-07 19:04 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-07 19:04 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-07 19:04 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-07 19:04 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-07 19:04 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-07 19:04 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-07 19:04 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-07 19:04 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-07 19:04 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-07 19:04 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-07 19:04 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-07 19:04 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-07 19:04 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-07 19:04 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-07 19:04 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-07 19:02 - 2014-05-07 19:03 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DFB33308-901D-4EAF-9C6E-A5DEA8364065}
2014-05-06 15:35 - 2014-05-06 15:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{01097470-E215-4F09-8B1E-B904D4356792}
2014-05-05 18:20 - 2014-05-05 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Local\{8837D2BF-2261-45A5-975D-F775DFD9FD39}
2014-05-04 21:59 - 2014-05-04 21:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{30370F42-121E-48B3-B315-481D08085F3A}
2014-05-03 21:27 - 2014-05-03 21:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DB63567F-3788-43B8-BCFB-ED07BD306540}
2014-05-03 02:36 - 2014-05-03 02:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3CD5C54C-8659-40F2-AE16-BB7B404718E6}
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-05-02 14:35 - 2014-05-02 14:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DC60EB2C-B723-4FA9-A38E-31AC1A6775EA}
2014-05-01 13:21 - 2014-05-01 13:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B1833989-708E-4FC2-AADF-908BFAC0A56F}
2014-04-30 18:53 - 2014-04-30 18:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5EF441A7-91AC-4C8E-9DF8-3CA8C25B701E}
2014-04-29 16:21 - 2014-04-29 16:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6AB88698-1939-4E66-BCF8-9C5E2800911A}
2014-04-28 17:05 - 2014-04-28 17:05 - 00128000 ____H () C:\Users\Kati\Desktop\photothumb.db
2014-04-28 17:04 - 2014-04-28 17:06 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PhotoScape
2014-04-28 17:04 - 2014-04-28 17:04 - 00001039 _____ () C:\Users\Kati\Desktop\PhotoScape.lnk
2014-04-28 17:04 - 2014-04-28 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2014-04-28 17:03 - 2014-04-28 17:04 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-04-28 16:22 - 2014-04-28 16:22 - 00000000 ____D () C:\Users\Kati\AppData\Local\{E6EF1C33-8457-4043-B475-28B37C804CF7}

==================== One Month Modified Files and Folders =======

2014-05-28 23:31 - 2013-11-29 01:51 - 00018173 _____ () C:\Users\Kati\Downloads\FRST.txt
2014-05-28 23:31 - 2013-11-26 14:29 - 00000000 ____D () C:\FRST
2014-05-28 23:19 - 2012-09-20 19:21 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-28 23:19 - 2012-09-20 19:21 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-28 23:08 - 2012-11-10 23:07 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Spotify
2014-05-28 23:08 - 2012-09-20 21:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-28 22:24 - 2012-09-20 22:19 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001UA.job
2014-05-28 22:24 - 2012-09-20 22:19 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001Core.job
2014-05-28 21:56 - 2013-07-24 18:55 - 01074664 _____ () C:\Windows\WindowsUpdate.log
2014-05-28 21:50 - 2014-05-28 21:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F2AB505A-9B93-4418-A77B-6FE7CFE310E2}
2014-05-28 21:42 - 2014-05-28 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-05-28 21:42 - 2012-09-20 19:21 - 00002255 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-05-28 21:01 - 2014-05-17 23:57 - 00000000 ____D () C:\Users\Kati\Desktop\Fotos
2014-05-28 17:31 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-28 17:31 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-28 12:15 - 2012-09-23 18:09 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Skype
2014-05-28 09:50 - 2014-05-28 09:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2ACACF29-6012-45DA-A401-2A8DFDF9A934}
2014-05-28 09:44 - 2012-11-10 23:07 - 00000000 ____D () C:\Users\Kati\AppData\Local\Spotify
2014-05-27 22:35 - 2014-05-27 22:35 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-27 22:00 - 2014-05-27 22:00 - 00002030 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-05-27 22:00 - 2013-03-17 11:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-05-27 22:00 - 2011-07-18 18:45 - 00306972 _____ () C:\Windows\DPINST.LOG
2014-05-27 21:59 - 2011-03-15 00:29 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-27 21:49 - 2014-05-27 21:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\{85A3F08A-7AD4-41EC-BF4F-83F3A8A35608}
2014-05-26 23:03 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-26 22:50 - 2014-05-26 22:49 - 00000590 _____ () C:\Users\Kati\Desktop\fixlist.txt
2014-05-26 22:49 - 2014-05-26 22:49 - 00000000 ____D () C:\Users\Kati\Downloads\FRST-OlderVersion
2014-05-26 22:49 - 2013-11-26 14:23 - 02066944 _____ (Farbar) C:\Users\Kati\Downloads\FRST64.exe
2014-05-26 22:47 - 2014-05-26 22:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{EA1C1BC9-C916-4615-8BC9-F292C39BED84}
2014-05-26 22:01 - 2014-01-08 01:12 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\DropboxMaster
2014-05-26 22:01 - 2014-01-08 01:02 - 00001017 _____ () C:\Users\Kati\Desktop\Dropbox.lnk
2014-05-26 22:01 - 2014-01-08 01:02 - 00000000 ___RD () C:\Users\Kati\Dropbox
2014-05-26 22:01 - 2014-01-08 01:01 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-26 22:01 - 2014-01-08 01:00 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Dropbox
2014-05-26 22:01 - 2012-09-20 18:26 - 00000000 ___RD () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-26 21:58 - 2014-01-27 22:53 - 00000478 _____ () C:\Windows\Tasks\SDMsgUpdate (Local).job
2014-05-26 21:58 - 2014-01-27 22:53 - 00000470 _____ () C:\Windows\Tasks\SDMsgUpdate (TE).job
2014-05-26 21:52 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-26 21:52 - 2009-07-14 06:51 - 02351618 _____ () C:\Windows\setupact.log
2014-05-26 21:51 - 2010-11-21 05:47 - 00148028 _____ () C:\Windows\PFRO.log
2014-05-22 13:34 - 2014-05-22 13:34 - 00000000 ____D () C:\Users\Kati\AppData\Local\{D9C4C62D-5ECD-405A-A8D1-08CB33718E33}
2014-05-22 13:34 - 2013-03-30 19:06 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-22 13:34 - 2013-03-30 19:06 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-05-21 20:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-21 19:17 - 2014-05-21 19:17 - 00002668 _____ () C:\Users\Kati\Desktop\mbam.text
2014-05-21 19:13 - 2014-05-21 18:50 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-21 19:09 - 2013-12-17 16:48 - 00000000 ____D () C:\Windows\Minidump
2014-05-21 18:49 - 2014-05-21 18:49 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2013-05-14 19:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-21 18:48 - 2014-05-21 18:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Kati\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-21 18:37 - 2013-11-28 22:41 - 00000000 ____D () C:\AdwCleaner
2014-05-21 18:36 - 2012-09-21 13:58 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\SoftGrid Client
2014-05-21 18:31 - 2014-05-21 18:31 - 01326389 _____ () C:\Users\Kati\Downloads\adwcleaner_3.210.exe
2014-05-21 16:13 - 2014-05-21 16:12 - 00000000 ____D () C:\Users\Kati\AppData\Local\{45C30B23-5900-4B42-9501-3B28B7579182}
2014-05-19 19:43 - 2014-05-19 19:43 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F1FFA1EE-9E79-4BE1-9F37-563DF59C3CB4}
2014-05-18 14:44 - 2014-05-18 14:43 - 00043884 _____ () C:\Users\Kati\Downloads\Addition.txt
2014-05-18 13:50 - 2014-05-18 13:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{422F2530-3EF2-4E9C-A789-485C1206D1AC}
2014-05-18 12:34 - 2014-02-24 22:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\Windows Live
2014-05-18 12:07 - 2011-05-16 16:04 - 00699794 _____ () C:\Windows\system32\perfh007.dat
2014-05-18 12:07 - 2011-05-16 16:04 - 00149644 _____ () C:\Windows\system32\perfc007.dat
2014-05-18 12:07 - 2009-07-14 07:13 - 01620836 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-17 23:58 - 2014-05-17 23:56 - 00000000 ____D () C:\Users\Kati\Desktop\Kinderfotos
2014-05-17 23:55 - 2014-05-17 23:51 - 00000000 ____D () C:\Users\Kati\Downloads\Uni
2014-05-17 23:52 - 2013-11-24 21:13 - 00000000 ____D () C:\Users\Kati\Downloads\verschiedene Bilder
2014-05-17 22:08 - 2014-05-17 22:08 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4BE87CCE-750B-4228-B62E-246699B53E05}
2014-05-17 20:59 - 2014-05-17 20:59 - 00383343 _____ () C:\Users\Kati\Desktop\Report.htm
2014-05-17 20:58 - 2014-05-17 20:58 - 00000000 ____D () C:\Users\Kati\Documents\EVEREST Reports
2014-05-17 20:42 - 2014-05-17 20:41 - 215448505 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\wlane6221_inw7.exe
2014-05-17 20:42 - 2013-12-16 20:47 - 00000000 ____D () C:\Medion
2014-05-17 20:40 - 2014-05-17 20:40 - 18857054 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\tpde6221_se_wxpvstw7_32_64.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 09144982 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\usb3e6221_e722xw7.exe
2014-05-17 20:40 - 2014-05-17 20:39 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(2).exe
2014-05-17 20:39 - 2014-05-17 20:39 - 31119378 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\mnme6221_e722xvstw7_w8.exe
2014-05-17 20:39 - 2014-05-17 20:39 - 02620971 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\lane6221_e722xxpvstw7.exe
2014-05-17 20:38 - 2014-05-17 20:38 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8(1).exe
2014-05-17 20:37 - 2014-05-17 20:34 - 195993064 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\vgae6221_e722x_in_w7_w8.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 03987373 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\chpe6221_e722xxpvstw7.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 01798895 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\bioe722x_p762x.exe
2014-05-17 20:34 - 2014-05-17 20:33 - 11290483 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ahcie6221vstw7_w8.exe
2014-05-17 20:31 - 2014-05-17 20:31 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8.exe
2014-05-17 20:26 - 2014-05-17 20:26 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(1).exe
2014-05-17 20:25 - 2014-05-17 20:25 - 00229008 _____ () C:\Users\Kati\Downloads\MEDION_Treibersuche.exe
2014-05-17 20:18 - 2014-05-17 20:18 - 00001130 _____ () C:\Users\Kati\Desktop\EVEREST Ultimate Edition.lnk
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\Program Files (x86)\Lavalys
2014-05-17 20:17 - 2014-05-17 20:17 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Kati\Downloads\everestultimate550.exe
2014-05-17 18:45 - 2014-05-17 18:20 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-17 18:20 - 2014-05-17 18:20 - 00001266 _____ () C:\Users\Public\Desktop\NCH Software.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\Users\Public\Desktop\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001142 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:19 - 2014-05-17 18:19 - 00001130 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00001118 _____ () C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:18 - 2014-05-17 18:18 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kati\Downloads\Debut Video Capture - CHIP-Downloader.exe
2014-05-16 22:17 - 2014-05-16 22:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2611705F-FCFF-44F2-9C4B-EC29E5A67B46}
2014-05-16 09:12 - 2013-01-07 00:52 - 00002023 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-05-16 09:12 - 2011-06-28 21:31 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-16 09:09 - 2014-05-16 09:09 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69A1EF25-1F79-4775-BA26-5F9375FE9B95}
2014-05-16 09:06 - 2012-09-20 18:26 - 00000000 ___RD () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 08:55 - 2014-05-07 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-16 08:34 - 2013-07-29 22:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-16 08:31 - 2013-07-25 12:48 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-15 14:18 - 2014-05-15 14:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4DD5F804-7106-4564-8BC2-F943268098E6}
2014-05-14 19:25 - 2014-05-14 19:25 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:12 - 00001021 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-05-14 19:12 - 2014-05-14 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:11 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:10 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-14 19:11 - 2014-05-14 19:11 - 00000000 ____D () C:\Users\Kati\Documents\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00001039 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-14 19:08 - 2014-05-14 19:07 - 27843432 _____ (pdfforge ) C:\Users\Kati\Downloads\PDFCreator-1_7_3_setup.exe
2014-05-14 17:08 - 2013-12-16 21:08 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 17:08 - 2012-09-20 21:54 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-14 17:08 - 2011-07-18 19:57 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-14 16:28 - 2014-05-14 16:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{AFF51EAF-1EEE-4D30-9A8D-532258456C17}
2014-05-13 17:17 - 2014-05-13 17:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B0C594E1-1C40-46AD-9B29-7C5B4986A6E6}
2014-05-13 16:54 - 2014-05-13 16:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{98AC1C21-B103-44EE-AC7B-2C114FD85585}
2014-05-13 16:49 - 2014-01-29 16:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-12 20:54 - 2014-05-12 20:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{BE16BDD7-B89C-4024-B9F6-AD6FF1E9E786}
2014-05-12 07:26 - 2014-05-21 18:49 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-21 18:49 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-21 18:49 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 22:59 - 2013-09-30 12:13 - 00000000 ____D () C:\Users\Kati\Documents\Citavi 4
2014-05-11 19:59 - 2014-05-11 19:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-11 19:46 - 2014-05-11 19:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{C2B4150E-0C6B-4799-9C08-B1E8DFC269ED}
2014-05-10 21:55 - 2014-05-10 21:55 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9A0AD5CC-139C-491B-9266-50616B3EF2EC}
2014-05-09 17:57 - 2014-05-09 17:57 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9C638A68-5F34-48C1-898B-3689CD978999}
2014-05-09 08:14 - 2014-05-15 14:27 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 14:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-08 15:00 - 2014-05-08 15:00 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B51A953C-DD2F-4FB8-AA87-F6AD0AFB9AC2}
2014-05-07 20:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-07 19:03 - 2014-05-07 19:02 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DFB33308-901D-4EAF-9C6E-A5DEA8364065}
2014-05-06 15:35 - 2014-05-06 15:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{01097470-E215-4F09-8B1E-B904D4356792}
2014-05-06 06:40 - 2014-05-16 08:35 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-16 08:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-16 08:35 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-16 08:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-16 08:35 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-16 08:35 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-05 23:14 - 2012-09-20 19:21 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-05 23:14 - 2012-09-20 19:21 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-05 18:20 - 2014-05-05 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Local\{8837D2BF-2261-45A5-975D-F775DFD9FD39}
2014-05-04 21:59 - 2014-05-04 21:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{30370F42-121E-48B3-B315-481D08085F3A}
2014-05-03 21:28 - 2014-05-03 21:27 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DB63567F-3788-43B8-BCFB-ED07BD306540}
2014-05-03 02:36 - 2014-05-03 02:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3CD5C54C-8659-40F2-AE16-BB7B404718E6}
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-05-03 01:55 - 2013-04-19 13:10 - 00000000 ____D () C:\ProgramData\Sony Ericsson
2014-05-03 01:55 - 2013-04-19 13:10 - 00000000 ____D () C:\Program Files (x86)\Sony Ericsson
2014-05-02 14:36 - 2014-05-02 14:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DC60EB2C-B723-4FA9-A38E-31AC1A6775EA}
2014-05-01 13:21 - 2014-05-01 13:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B1833989-708E-4FC2-AADF-908BFAC0A56F}
2014-04-30 18:53 - 2014-04-30 18:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{5EF441A7-91AC-4C8E-9DF8-3CA8C25B701E}
2014-04-29 16:21 - 2014-04-29 16:21 - 00000000 ____D () C:\Users\Kati\AppData\Local\{6AB88698-1939-4E66-BCF8-9C5E2800911A}
2014-04-28 17:06 - 2014-04-28 17:04 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PhotoScape
2014-04-28 17:05 - 2014-04-28 17:05 - 00128000 ____H () C:\Users\Kati\Desktop\photothumb.db
2014-04-28 17:04 - 2014-04-28 17:04 - 00001039 _____ () C:\Users\Kati\Desktop\PhotoScape.lnk
2014-04-28 17:04 - 2014-04-28 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2014-04-28 17:04 - 2014-04-28 17:03 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-04-28 17:03 - 2012-09-20 18:26 - 00000000 ____D () C:\Users\Kati\AppData\Local\Google
2014-04-28 16:22 - 2014-04-28 16:22 - 00000000 ____D () C:\Users\Kati\AppData\Local\{E6EF1C33-8457-4043-B475-28B37C804CF7}

Some content of TEMP:
====================
C:\Users\Kati\AppData\Local\Temp\avgnt.exe
C:\Users\Kati\AppData\Local\Temp\burnsetup.exe
C:\Users\Kati\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpboeoje.dll
C:\Users\Kati\AppData\Local\Temp\FoxySecuritySetup.exe
C:\Users\Kati\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Kati\AppData\Local\Temp\Quarantine.exe
C:\Users\Kati\AppData\Local\Temp\sjy8mvbh.dll
C:\Users\Kati\AppData\Local\Temp\vpsetup.exe
C:\Users\Kati\AppData\Local\Temp\_is6454.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-19 09:55

==================== End Of Log ============================

--- --- ---




Sorry, hab das mit FRST voll verpeilt, aber jetzt haben wir alles beisammen :D

sunjojo 30.05.2014 11:02

Ok, das Logfile sieht im Moment für mich erstmal sauber aus :).

Jetzt zu dem Audioproblem. Hörst du etwas, wenn du einen Kopfhörer an deinen Rechner anschließt?

Geh mal auf Wartungscenter öffnen - Problembehandlung - Audiowiedergabeprobleme behandeln und gucke, ob es etwas gebracht hat. Wenn nicht, bitte einen Clean Boot machen, damit wir ausschließen können, das nicht i-eine Software etwas blockiert: Gewusst wie: Durchführen eines sauberen Neustarts in Windows (unter dem Abschnitt "Windows 7 und Windows Vista).

Nirtaka 30.05.2014 12:39

Hey Jonas, tausend Dank erstmal für die Hilfe bei dem ersten Problem!!! Super Betreuung! :-) Zum anderen Problem: ich habe gemäß der Anleitung den Neustart machen wollen, aber nachdem beim ersten Mal noch Programme geschlossen werden sollten, reagiert das Programm nicht mehr auf den Neustart. Hab jetzt alles Programme geschlossen und wenn ich das alles unter msconfig.exe wieder so einstelle und auf OK drücke passiert gar nichts, beim ersten Mal stand etwas von "wird jetzt neu gestartet" aber da waren ja noch Programme offen. Öhm, wie krieg ich den Neustart denn noch hin? :/

sunjojo 30.05.2014 12:47

Wenn ich das richtig verstanden habe, hast du unter msconfig.exe ein zweites Mal nach der Anleitung alles eingestellt und bekommst aber keine Meldung für einen Neustart? Dann einfach normal einen Neustart durchführen (Start -> den Pfeil neben Herunterfahren auswählen -> Neu starten auswählen). Oder habe ich dein Problem falsch verstanden?

Nirtaka 30.05.2014 13:00

Ja, du hast das genau richtig verstanden :-) . Dachte die Neustartmeldung müsste von selbst wiederkommen aber dann starte ich eben manuell alles neu. Danke, ich sag danach Bescheid!

Sooo, Problem is leider immernoch da :-(

sunjojo 31.05.2014 17:52

Ok, dann kannst du wieder erstmal alles aktivieren unter msconfig. Außerdem müsste ich noch wissen, ob du Ton auf Kopfhören hören kannst :).

Nirtaka 01.06.2014 13:00

Hi Jonas! Also mit Kopfhörern kann ich ganz normal hören hab ich gerad festgestellt... LG

sunjojo 02.06.2014 15:53

Merkwürdig, aber wenn du die "Audiowiedergabeprobleme behandeln" bereits ausgeführt hast und mit msconfig auch alles deaktiviert hast, fällt mir zu diesem sehr speziellen Thema nichts mehr ein. Ich würde mir noch ein FRST Logfile angucken und dich dann "entlassen", sodass du in der Hardwareecke ein Thema aufmachen kannst. Dort kann dir dann jeder helfen. Außerdem frage ich nochmal ein bissel rum, vll. kennt ja jemand das Problem, ok? :)



Schritt 1
Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, wird ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.



Poste folgende Logfiles in deiner nächsten Antwort:
  • FRST.txt

Nirtaka 02.06.2014 17:26


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-06-2014 01
Ran by Kati (administrator) on KATI-PC on 02-06-2014 18:22:38
Running from C:\Users\Kati\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Dropbox, Inc.) C:\Users\Kati\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Spotify Ltd) C:\Users\Kati\AppData\Roaming\Spotify\spotify.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Users\Kati\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-22] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Startup: C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Kati\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9A119BA29CEBCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 - C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Kati\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: sony.com/MediaGoDetector - C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\Kati\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Foxy Security - C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\Extensions\sys@foxysecurity.com [2014-04-28]
FF Extension: DownloadHelper - C:\Users\Kati\AppData\Roaming\Mozilla\Firefox\Profiles\g2jmug2y.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-31]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2013-09-11]

Chrome:
=======
CHR Extension: (DVDVideoSoft) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-12-24]
CHR Extension: (Google Wallet) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-03]
CHR Extension: (Citavi Picker) - C:\Users\Kati\AppData\Local\Google\Chrome\User Data\Default\Extensions\piehhloihgjjiomhieeddiidpekaajio [2013-12-24]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-06-29]
CHR HKLM-x32\...\Chrome\Extension: [piehhloihgjjiomhieeddiidpekaajio] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Chrome\ChromePicker.crx [2013-09-11]

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG)
S2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-06] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-30] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-30] (pdfforge GmbH)
S2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [X]
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe" [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-02 15:12 - 2014-06-02 15:12 - 00000000 ____D () C:\Users\Kati\AppData\Local\{A2181A0D-51B7-49DC-97B9-34829FFC9BDE}
2014-06-02 03:11 - 2014-06-02 03:12 - 00000000 ____D () C:\Users\Kati\AppData\Local\{CA6EBB6F-FF2C-464B-AFA8-B78BF507B378}
2014-06-01 19:16 - 2014-06-01 19:16 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-06-01 19:16 - 2014-06-01 19:16 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-06-01 19:16 - 2014-06-01 19:16 - 00000000 ____D () C:\Users\Kati\AppData\Local\Skype
2014-06-01 19:16 - 2014-06-01 19:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-06-01 15:10 - 2014-06-01 15:11 - 00000000 ____D () C:\Users\Kati\AppData\Local\{1A2725A8-DDD5-47DD-8F17-BDBF5CD0B568}
2014-05-31 22:11 - 2014-05-31 22:11 - 00000000 ____D () C:\Users\Kati\AppData\Local\{254439CF-BF1F-4EFB-9754-65057B304622}
2014-05-31 09:54 - 2014-05-31 09:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{D0DF0879-509A-4CEA-BCAF-FB66920A34CE}
2014-05-30 21:54 - 2014-05-30 21:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9229D0C5-FCB2-4C74-8F31-D3401F034EC0}
2014-05-30 15:04 - 2014-05-30 16:48 - 00000000 ____D () C:\Users\Kati\Downloads\hochzeit karte hans 1
2014-05-30 14:51 - 2014-05-30 15:00 - 1950459778 _____ () C:\Users\Kati\Downloads\hochzeit karte hans 1.zip
2014-05-30 14:50 - 2014-06-01 16:01 - 00000000 ____D () C:\Users\Kati\Downloads\Hochzeit karte tina cf
2014-05-30 14:50 - 2014-05-30 14:50 - 00000000 ____D () C:\Users\Kati\Downloads\__MACOSX
2014-05-30 14:38 - 2014-05-30 16:59 - 00000000 ____D () C:\Users\Kati\Downloads\2014-05-25 HT Tina Martin
2014-05-30 14:38 - 2014-05-30 00:18 - 1013683995 ____N () C:\Users\Kati\Downloads\Hochzeit karte tina cf.zip
2014-05-30 14:38 - 2014-05-30 00:17 - 156470781 ____N () C:\Users\Kati\Downloads\2014-05-25 HT Tina Martin.zip
2014-05-30 13:26 - 2014-05-30 13:26 - 00000000 ____D () C:\Windows\pss
2014-05-30 09:53 - 2014-05-30 09:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69436961-43C9-4FD8-AD3F-843B692B5A63}
2014-05-30 09:22 - 2014-05-30 14:22 - 00000000 ____D () C:\Users\Kati\Downloads\wetransfer-44a6f7
2014-05-30 09:22 - 2014-05-30 09:22 - 00000000 ____D () C:\Users\Kati\Documents\2014-05-25 HT Tina Martin
2014-05-30 08:49 - 2014-05-30 09:09 - 00000000 ____D () C:\Users\Kati\Documents\Hochzeit karte tina cf
2014-05-30 08:29 - 2014-05-30 08:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-05-30 08:29 - 2014-05-30 08:29 - 00000000 ____D () C:\Program Files\7-Zip
2014-05-30 08:18 - 2014-05-30 08:18 - 01444352 _____ () C:\Users\Kati\Downloads\7z922-x64.msi
2014-05-30 07:37 - 2014-05-30 07:42 - 1170155164 _____ () C:\Users\Kati\Downloads\wetransfer-44a6f7.zip
2014-05-29 21:51 - 2014-05-29 21:52 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F43FC16C-442D-4D18-9481-530BCCDABD42}
2014-05-29 11:52 - 2014-05-29 11:52 - 00004563 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-05-29 11:52 - 2014-05-29 11:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-29 11:52 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-29 11:52 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-29 11:52 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-29 11:52 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-29 09:51 - 2014-05-29 09:51 - 00000000 ____D () C:\Users\Kati\AppData\Local\{684E1D48-8A55-4799-9F60-A31775D8F3A2}
2014-05-28 21:50 - 2014-05-28 21:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F2AB505A-9B93-4418-A77B-6FE7CFE310E2}
2014-05-28 21:42 - 2014-05-28 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-05-28 09:49 - 2014-05-28 09:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2ACACF29-6012-45DA-A401-2A8DFDF9A934}
2014-05-27 22:35 - 2014-05-27 22:35 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-27 22:00 - 2014-05-27 22:00 - 00002030 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-05-27 21:49 - 2014-05-27 21:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\{85A3F08A-7AD4-41EC-BF4F-83F3A8A35608}
2014-05-26 22:49 - 2014-06-02 18:22 - 00000000 ____D () C:\Users\Kati\Downloads\FRST-OlderVersion
2014-05-26 22:49 - 2014-05-26 22:50 - 00000590 _____ () C:\Users\Kati\Desktop\fixlist.txt
2014-05-26 22:46 - 2014-05-26 22:47 - 00000000 ____D () C:\Users\Kati\AppData\Local\{EA1C1BC9-C916-4615-8BC9-F292C39BED84}
2014-05-22 13:34 - 2014-05-22 13:34 - 00000000 ____D () C:\Users\Kati\AppData\Local\{D9C4C62D-5ECD-405A-A8D1-08CB33718E33}
2014-05-21 19:17 - 2014-05-21 19:17 - 00002668 _____ () C:\Users\Kati\Desktop\mbam.text
2014-05-21 18:50 - 2014-05-21 19:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-21 18:49 - 2014-05-21 18:49 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-21 18:49 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-21 18:49 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-21 18:48 - 2014-05-21 18:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Kati\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-21 18:32 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-21 18:31 - 2014-05-21 18:31 - 01326389 _____ () C:\Users\Kati\Downloads\adwcleaner_3.210.exe
2014-05-21 16:12 - 2014-05-21 16:13 - 00000000 ____D () C:\Users\Kati\AppData\Local\{45C30B23-5900-4B42-9501-3B28B7579182}
2014-05-19 19:43 - 2014-05-19 19:43 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F1FFA1EE-9E79-4BE1-9F37-563DF59C3CB4}
2014-05-18 14:43 - 2014-05-18 14:44 - 00043884 _____ () C:\Users\Kati\Downloads\Addition.txt
2014-05-18 13:50 - 2014-05-18 13:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{422F2530-3EF2-4E9C-A789-485C1206D1AC}
2014-05-18 12:11 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-05-18 12:11 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-05-17 23:57 - 2014-05-28 21:01 - 00000000 ____D () C:\Users\Kati\Desktop\Fotos
2014-05-17 23:56 - 2014-05-17 23:58 - 00000000 ____D () C:\Users\Kati\Desktop\Kinderfotos
2014-05-17 23:51 - 2014-05-17 23:55 - 00000000 ____D () C:\Users\Kati\Downloads\Uni
2014-05-17 22:55 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-05-17 22:55 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-17 22:55 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-17 22:55 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-05-17 22:55 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-05-17 22:55 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-05-17 22:55 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-05-17 22:55 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-05-17 22:55 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-05-17 22:55 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-05-17 22:55 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-05-17 22:55 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-05-17 22:55 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-05-17 22:55 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-05-17 22:55 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-05-17 22:55 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-05-17 22:54 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-05-17 22:54 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-05-17 22:08 - 2014-05-17 22:08 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4BE87CCE-750B-4228-B62E-246699B53E05}
2014-05-17 20:59 - 2014-05-17 20:59 - 00383343 _____ () C:\Users\Kati\Desktop\Report.htm
2014-05-17 20:58 - 2014-05-17 20:58 - 00000000 ____D () C:\Users\Kati\Documents\EVEREST Reports
2014-05-17 20:41 - 2014-05-17 20:42 - 215448505 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\wlane6221_inw7.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 18857054 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\tpde6221_se_wxpvstw7_32_64.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 09144982 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\usb3e6221_e722xw7.exe
2014-05-17 20:39 - 2014-05-17 20:40 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(2).exe
2014-05-17 20:39 - 2014-05-17 20:39 - 31119378 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\mnme6221_e722xvstw7_w8.exe
2014-05-17 20:39 - 2014-05-17 20:39 - 02620971 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\lane6221_e722xxpvstw7.exe
2014-05-17 20:38 - 2014-05-17 20:38 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8(1).exe
2014-05-17 20:34 - 2014-05-17 20:37 - 195993064 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\vgae6221_e722x_in_w7_w8.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 03987373 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\chpe6221_e722xxpvstw7.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 01798895 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\bioe722x_p762x.exe
2014-05-17 20:33 - 2014-05-17 20:34 - 11290483 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ahcie6221vstw7_w8.exe
2014-05-17 20:31 - 2014-05-17 20:31 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8.exe
2014-05-17 20:26 - 2014-05-17 20:26 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(1).exe
2014-05-17 20:25 - 2014-05-17 20:25 - 00229008 _____ () C:\Users\Kati\Downloads\MEDION_Treibersuche.exe
2014-05-17 20:18 - 2014-05-17 20:18 - 00001130 _____ () C:\Users\Kati\Desktop\EVEREST Ultimate Edition.lnk
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\Program Files (x86)\Lavalys
2014-05-17 20:17 - 2014-05-17 20:17 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Kati\Downloads\everestultimate550.exe
2014-05-17 18:20 - 2014-05-17 18:45 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-17 18:20 - 2014-05-17 18:20 - 00001266 _____ () C:\Users\Public\Desktop\NCH Software.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\Users\Public\Desktop\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001142 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:19 - 2014-05-17 18:19 - 00001118 _____ () C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:18 - 2014-05-17 18:18 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kati\Downloads\Debut Video Capture - CHIP-Downloader.exe
2014-05-16 22:17 - 2014-05-16 22:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2611705F-FCFF-44F2-9C4B-EC29E5A67B46}
2014-05-16 09:09 - 2014-05-16 09:09 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69A1EF25-1F79-4775-BA26-5F9375FE9B95}
2014-05-16 08:35 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-16 08:35 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-16 08:35 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-16 08:35 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-16 08:35 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-16 08:35 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 14:27 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-15 14:27 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-15 14:27 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 14:27 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-15 14:26 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 14:26 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 14:26 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 14:26 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 14:26 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 14:26 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-15 14:26 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-15 14:26 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 14:26 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 14:26 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 14:26 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 14:26 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 14:26 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 14:26 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 14:26 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 14:26 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-15 14:26 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-15 14:17 - 2014-05-15 14:18 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4DD5F804-7106-4564-8BC2-F943268098E6}
2014-05-14 19:25 - 2014-05-14 19:25 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:12 - 00001021 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-05-14 19:12 - 2014-05-14 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-14 19:11 - 2014-05-14 19:12 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-14 19:11 - 2014-05-14 19:11 - 00000000 ____D () C:\Users\Kati\Documents\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:12 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-14 19:10 - 2014-05-14 19:10 - 00001039 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-14 19:10 - 2014-04-25 17:44 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2014-05-14 19:10 - 2014-04-25 17:44 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-05-14 19:10 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2014-05-14 19:10 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6DE.DLL
2014-05-14 19:10 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCDE.DLL
2014-05-14 19:10 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCC2DE.DLL
2014-05-14 19:07 - 2014-05-14 19:08 - 27843432 _____ (pdfforge ) C:\Users\Kati\Downloads\PDFCreator-1_7_3_setup.exe
2014-05-14 16:28 - 2014-05-14 16:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{AFF51EAF-1EEE-4D30-9A8D-532258456C17}
2014-05-13 17:17 - 2014-05-13 17:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B0C594E1-1C40-46AD-9B29-7C5B4986A6E6}
2014-05-13 16:53 - 2014-05-13 16:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{98AC1C21-B103-44EE-AC7B-2C114FD85585}
2014-05-12 20:54 - 2014-05-12 20:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{BE16BDD7-B89C-4024-B9F6-AD6FF1E9E786}
2014-05-11 19:59 - 2014-05-11 19:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-11 19:46 - 2014-05-11 19:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{C2B4150E-0C6B-4799-9C08-B1E8DFC269ED}
2014-05-10 21:55 - 2014-05-10 21:55 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9A0AD5CC-139C-491B-9266-50616B3EF2EC}
2014-05-09 17:57 - 2014-05-09 17:57 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9C638A68-5F34-48C1-898B-3689CD978999}
2014-05-08 15:00 - 2014-05-08 15:00 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B51A953C-DD2F-4FB8-AA87-F6AD0AFB9AC2}
2014-05-07 19:04 - 2014-05-16 08:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-07 19:04 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-07 19:04 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-07 19:04 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-07 19:04 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-07 19:04 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-07 19:04 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-07 19:04 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-07 19:04 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-07 19:04 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-07 19:04 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-07 19:04 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-07 19:04 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-07 19:04 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-07 19:04 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-07 19:04 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-07 19:04 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-07 19:04 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-07 19:04 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-07 19:04 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-07 19:04 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-07 19:04 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-07 19:04 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-07 19:04 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-07 19:04 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-07 19:04 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-07 19:04 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-07 19:04 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-07 19:04 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-07 19:04 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-07 19:04 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-07 19:04 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-07 19:04 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-07 19:04 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-07 19:04 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-07 19:04 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-07 19:04 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-07 19:04 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-07 19:04 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-07 19:04 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-07 19:04 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-07 19:04 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-07 19:04 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-07 19:04 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-07 19:04 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-07 19:02 - 2014-05-07 19:03 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DFB33308-901D-4EAF-9C6E-A5DEA8364065}
2014-05-06 15:35 - 2014-05-06 15:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{01097470-E215-4F09-8B1E-B904D4356792}
2014-05-05 18:20 - 2014-05-05 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Local\{8837D2BF-2261-45A5-975D-F775DFD9FD39}
2014-05-04 21:59 - 2014-05-04 21:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{30370F42-121E-48B3-B315-481D08085F3A}
2014-05-03 21:27 - 2014-05-03 21:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DB63567F-3788-43B8-BCFB-ED07BD306540}
2014-05-03 02:36 - 2014-05-03 02:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3CD5C54C-8659-40F2-AE16-BB7B404718E6}
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile

==================== One Month Modified Files and Folders =======

2014-06-02 18:22 - 2014-05-26 22:49 - 00000000 ____D () C:\Users\Kati\Downloads\FRST-OlderVersion
2014-06-02 18:22 - 2013-11-29 01:51 - 00011854 _____ () C:\Users\Kati\Downloads\FRST.txt
2014-06-02 18:22 - 2013-11-26 14:29 - 00000000 ____D () C:\FRST
2014-06-02 18:22 - 2013-11-26 14:23 - 02067456 _____ (Farbar) C:\Users\Kati\Downloads\FRST64.exe
2014-06-02 18:22 - 2013-07-24 18:10 - 00000000 ____D () C:\Users\Kati\AppData\Local\Temp
2014-06-02 18:19 - 2012-09-20 19:21 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-02 18:17 - 2012-09-23 18:09 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Skype
2014-06-02 18:08 - 2012-09-20 21:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-02 17:18 - 2009-07-14 06:51 - 02415493 _____ () C:\Windows\setupact.log
2014-06-02 16:36 - 2012-11-10 23:07 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Spotify
2014-06-02 16:24 - 2012-09-20 22:19 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001UA.job
2014-06-02 15:43 - 2013-08-19 23:13 - 00000000 ____D () C:\Users\Kati\dwhelper
2014-06-02 15:12 - 2014-06-02 15:12 - 00000000 ____D () C:\Users\Kati\AppData\Local\{A2181A0D-51B7-49DC-97B9-34829FFC9BDE}
2014-06-02 05:15 - 2013-07-24 18:55 - 01188653 _____ () C:\Windows\WindowsUpdate.log
2014-06-02 03:12 - 2014-06-02 03:11 - 00000000 ____D () C:\Users\Kati\AppData\Local\{CA6EBB6F-FF2C-464B-AFA8-B78BF507B378}
2014-06-01 23:19 - 2012-09-20 19:21 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-01 22:24 - 2012-09-20 22:19 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2548312011-2494454960-3164520827-1001Core.job
2014-06-01 19:16 - 2014-06-01 19:16 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-06-01 19:16 - 2014-06-01 19:16 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-06-01 19:16 - 2014-06-01 19:16 - 00000000 ____D () C:\Users\Kati\AppData\Local\Skype
2014-06-01 19:16 - 2014-06-01 19:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-06-01 19:16 - 2012-09-23 18:09 - 00000000 ____D () C:\ProgramData\Skype
2014-06-01 16:01 - 2014-05-30 14:50 - 00000000 ____D () C:\Users\Kati\Downloads\Hochzeit karte tina cf
2014-06-01 15:11 - 2014-06-01 15:10 - 00000000 ____D () C:\Users\Kati\AppData\Local\{1A2725A8-DDD5-47DD-8F17-BDBF5CD0B568}
2014-05-31 22:11 - 2014-05-31 22:11 - 00000000 ____D () C:\Users\Kati\AppData\Local\{254439CF-BF1F-4EFB-9754-65057B304622}
2014-05-31 09:54 - 2014-05-31 09:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{D0DF0879-509A-4CEA-BCAF-FB66920A34CE}
2014-05-31 07:54 - 2014-01-27 22:53 - 00000478 _____ () C:\Windows\Tasks\SDMsgUpdate (Local).job
2014-05-31 07:54 - 2014-01-27 22:53 - 00000470 _____ () C:\Windows\Tasks\SDMsgUpdate (TE).job
2014-05-30 21:54 - 2014-05-30 21:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9229D0C5-FCB2-4C74-8F31-D3401F034EC0}
2014-05-30 19:07 - 2014-01-08 01:00 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Dropbox
2014-05-30 16:59 - 2014-05-30 14:38 - 00000000 ____D () C:\Users\Kati\Downloads\2014-05-25 HT Tina Martin
2014-05-30 16:59 - 2014-01-08 01:02 - 00000000 ___RD () C:\Users\Kati\Dropbox
2014-05-30 16:51 - 2014-01-08 01:12 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\DropboxMaster
2014-05-30 16:51 - 2012-09-20 18:26 - 00000000 ___RD () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-30 16:48 - 2014-05-30 15:04 - 00000000 ____D () C:\Users\Kati\Downloads\hochzeit karte hans 1
2014-05-30 15:00 - 2014-05-30 14:51 - 1950459778 _____ () C:\Users\Kati\Downloads\hochzeit karte hans 1.zip
2014-05-30 14:50 - 2014-05-30 14:50 - 00000000 ____D () C:\Users\Kati\Downloads\__MACOSX
2014-05-30 14:22 - 2014-05-30 09:22 - 00000000 ____D () C:\Users\Kati\Downloads\wetransfer-44a6f7
2014-05-30 14:11 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-30 14:11 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-30 14:02 - 2010-11-21 05:47 - 00148646 _____ () C:\Windows\PFRO.log
2014-05-30 14:02 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-30 13:26 - 2014-05-30 13:26 - 00000000 ____D () C:\Windows\pss
2014-05-30 09:53 - 2014-05-30 09:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69436961-43C9-4FD8-AD3F-843B692B5A63}
2014-05-30 09:22 - 2014-05-30 09:22 - 00000000 ____D () C:\Users\Kati\Documents\2014-05-25 HT Tina Martin
2014-05-30 09:09 - 2014-05-30 08:49 - 00000000 ____D () C:\Users\Kati\Documents\Hochzeit karte tina cf
2014-05-30 08:29 - 2014-05-30 08:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-05-30 08:29 - 2014-05-30 08:29 - 00000000 ____D () C:\Program Files\7-Zip
2014-05-30 08:18 - 2014-05-30 08:18 - 01444352 _____ () C:\Users\Kati\Downloads\7z922-x64.msi
2014-05-30 08:02 - 2014-02-24 22:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\Windows Live
2014-05-30 07:42 - 2014-05-30 07:37 - 1170155164 _____ () C:\Users\Kati\Downloads\wetransfer-44a6f7.zip
2014-05-30 00:18 - 2014-05-30 14:38 - 1013683995 ____N () C:\Users\Kati\Downloads\Hochzeit karte tina cf.zip
2014-05-30 00:17 - 2014-05-30 14:38 - 156470781 ____N () C:\Users\Kati\Downloads\2014-05-25 HT Tina Martin.zip
2014-05-29 21:52 - 2014-05-29 21:51 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F43FC16C-442D-4D18-9481-530BCCDABD42}
2014-05-29 11:52 - 2014-05-29 11:52 - 00004563 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-05-29 11:52 - 2014-05-29 11:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-29 11:52 - 2013-08-31 01:24 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-29 09:51 - 2014-05-29 09:51 - 00000000 ____D () C:\Users\Kati\AppData\Local\{684E1D48-8A55-4799-9F60-A31775D8F3A2}
2014-05-28 21:50 - 2014-05-28 21:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F2AB505A-9B93-4418-A77B-6FE7CFE310E2}
2014-05-28 21:42 - 2014-05-28 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-05-28 21:42 - 2012-09-20 19:21 - 00002255 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-05-28 21:01 - 2014-05-17 23:57 - 00000000 ____D () C:\Users\Kati\Desktop\Fotos
2014-05-28 09:50 - 2014-05-28 09:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2ACACF29-6012-45DA-A401-2A8DFDF9A934}
2014-05-28 09:44 - 2012-11-10 23:07 - 00000000 ____D () C:\Users\Kati\AppData\Local\Spotify
2014-05-27 22:35 - 2014-05-27 22:35 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-27 22:00 - 2014-05-27 22:00 - 00002030 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-05-27 22:00 - 2013-03-17 11:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-05-27 22:00 - 2011-07-18 18:45 - 00306972 _____ () C:\Windows\DPINST.LOG
2014-05-27 21:59 - 2011-03-15 00:29 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-27 21:49 - 2014-05-27 21:49 - 00000000 ____D () C:\Users\Kati\AppData\Local\{85A3F08A-7AD4-41EC-BF4F-83F3A8A35608}
2014-05-26 23:03 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-26 22:50 - 2014-05-26 22:49 - 00000590 _____ () C:\Users\Kati\Desktop\fixlist.txt
2014-05-26 22:47 - 2014-05-26 22:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{EA1C1BC9-C916-4615-8BC9-F292C39BED84}
2014-05-26 22:01 - 2014-01-08 01:02 - 00001017 _____ () C:\Users\Kati\Desktop\Dropbox.lnk
2014-05-26 22:01 - 2014-01-08 01:01 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-22 13:34 - 2014-05-22 13:34 - 00000000 ____D () C:\Users\Kati\AppData\Local\{D9C4C62D-5ECD-405A-A8D1-08CB33718E33}
2014-05-22 13:34 - 2013-03-30 19:06 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-22 13:34 - 2013-03-30 19:06 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-05-21 20:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-21 19:17 - 2014-05-21 19:17 - 00002668 _____ () C:\Users\Kati\Desktop\mbam.text
2014-05-21 19:13 - 2014-05-21 18:50 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-21 19:09 - 2013-12-17 16:48 - 00000000 ____D () C:\Windows\Minidump
2014-05-21 18:49 - 2014-05-21 18:49 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2014-05-21 18:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-21 18:49 - 2013-05-14 19:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-21 18:48 - 2014-05-21 18:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Kati\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-21 18:37 - 2013-11-28 22:41 - 00000000 ____D () C:\AdwCleaner
2014-05-21 18:36 - 2012-09-21 13:58 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\SoftGrid Client
2014-05-21 18:31 - 2014-05-21 18:31 - 01326389 _____ () C:\Users\Kati\Downloads\adwcleaner_3.210.exe
2014-05-21 16:13 - 2014-05-21 16:12 - 00000000 ____D () C:\Users\Kati\AppData\Local\{45C30B23-5900-4B42-9501-3B28B7579182}
2014-05-19 19:43 - 2014-05-19 19:43 - 00000000 ____D () C:\Users\Kati\AppData\Local\{F1FFA1EE-9E79-4BE1-9F37-563DF59C3CB4}
2014-05-18 14:44 - 2014-05-18 14:43 - 00043884 _____ () C:\Users\Kati\Downloads\Addition.txt
2014-05-18 13:50 - 2014-05-18 13:50 - 00000000 ____D () C:\Users\Kati\AppData\Local\{422F2530-3EF2-4E9C-A789-485C1206D1AC}
2014-05-18 12:07 - 2011-05-16 16:04 - 00699794 _____ () C:\Windows\system32\perfh007.dat
2014-05-18 12:07 - 2011-05-16 16:04 - 00149644 _____ () C:\Windows\system32\perfc007.dat
2014-05-18 12:07 - 2009-07-14 07:13 - 01620836 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-17 23:58 - 2014-05-17 23:56 - 00000000 ____D () C:\Users\Kati\Desktop\Kinderfotos
2014-05-17 23:55 - 2014-05-17 23:51 - 00000000 ____D () C:\Users\Kati\Downloads\Uni
2014-05-17 23:52 - 2013-11-24 21:13 - 00000000 ____D () C:\Users\Kati\Downloads\verschiedene Bilder
2014-05-17 22:08 - 2014-05-17 22:08 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4BE87CCE-750B-4228-B62E-246699B53E05}
2014-05-17 20:59 - 2014-05-17 20:59 - 00383343 _____ () C:\Users\Kati\Desktop\Report.htm
2014-05-17 20:58 - 2014-05-17 20:58 - 00000000 ____D () C:\Users\Kati\Documents\EVEREST Reports
2014-05-17 20:42 - 2014-05-17 20:41 - 215448505 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\wlane6221_inw7.exe
2014-05-17 20:42 - 2013-12-16 20:47 - 00000000 ____D () C:\Medion
2014-05-17 20:40 - 2014-05-17 20:40 - 18857054 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\tpde6221_se_wxpvstw7_32_64.exe
2014-05-17 20:40 - 2014-05-17 20:40 - 09144982 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\usb3e6221_e722xw7.exe
2014-05-17 20:40 - 2014-05-17 20:39 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(2).exe
2014-05-17 20:39 - 2014-05-17 20:39 - 31119378 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\mnme6221_e722xvstw7_w8.exe
2014-05-17 20:39 - 2014-05-17 20:39 - 02620971 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\lane6221_e722xxpvstw7.exe
2014-05-17 20:38 - 2014-05-17 20:38 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8(1).exe
2014-05-17 20:37 - 2014-05-17 20:34 - 195993064 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\vgae6221_e722x_in_w7_w8.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 03987373 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\chpe6221_e722xxpvstw7.exe
2014-05-17 20:34 - 2014-05-17 20:34 - 01798895 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\bioe722x_p762x.exe
2014-05-17 20:34 - 2014-05-17 20:33 - 11290483 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ahcie6221vstw7_w8.exe
2014-05-17 20:31 - 2014-05-17 20:31 - 10364287 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\keye6221_e722xw7w8.exe
2014-05-17 20:26 - 2014-05-17 20:26 - 47783495 _____ (SWE Sven Ritter ) C:\Users\Kati\Downloads\ske6221_e722x_cx_wxpw7(1).exe
2014-05-17 20:25 - 2014-05-17 20:25 - 00229008 _____ () C:\Users\Kati\Downloads\MEDION_Treibersuche.exe
2014-05-17 20:18 - 2014-05-17 20:18 - 00001130 _____ () C:\Users\Kati\Desktop\EVEREST Ultimate Edition.lnk
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2014-05-17 20:18 - 2014-05-17 20:18 - 00000000 ____D () C:\Program Files (x86)\Lavalys
2014-05-17 20:17 - 2014-05-17 20:17 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Kati\Downloads\everestultimate550.exe
2014-05-17 18:45 - 2014-05-17 18:20 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-17 18:20 - 2014-05-17 18:20 - 00001266 _____ () C:\Users\Public\Desktop\NCH Software.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\Users\Public\Desktop\Express Burn.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001154 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00001142 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2014-05-17 18:20 - 2014-05-17 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:19 - 2014-05-17 18:19 - 00001118 _____ () C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2014-05-17 18:19 - 2014-05-17 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-05-17 18:18 - 2014-05-17 18:18 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kati\Downloads\Debut Video Capture - CHIP-Downloader.exe
2014-05-16 22:17 - 2014-05-16 22:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{2611705F-FCFF-44F2-9C4B-EC29E5A67B46}
2014-05-16 09:12 - 2013-01-07 00:52 - 00002023 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-05-16 09:12 - 2011-06-28 21:31 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-16 09:09 - 2014-05-16 09:09 - 00000000 ____D () C:\Users\Kati\AppData\Local\{69A1EF25-1F79-4775-BA26-5F9375FE9B95}
2014-05-16 09:06 - 2012-09-20 18:26 - 00000000 ___RD () C:\Users\Kati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 08:55 - 2014-05-07 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-16 08:34 - 2013-07-29 22:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-16 08:31 - 2013-07-25 12:48 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-15 14:18 - 2014-05-15 14:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{4DD5F804-7106-4564-8BC2-F943268098E6}
2014-05-14 19:25 - 2014-05-14 19:25 - 00000000 ____D () C:\Users\Kati\AppData\Roaming\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:12 - 00001021 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-05-14 19:12 - 2014-05-14 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:11 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-05-14 19:12 - 2014-05-14 19:10 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-05-14 19:11 - 2014-05-14 19:11 - 00000000 ____D () C:\Users\Kati\Documents\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00001039 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-05-14 19:10 - 2014-05-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-05-14 19:08 - 2014-05-14 19:07 - 27843432 _____ (pdfforge ) C:\Users\Kati\Downloads\PDFCreator-1_7_3_setup.exe
2014-05-14 17:08 - 2013-12-16 21:08 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 17:08 - 2012-09-20 21:54 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-14 17:08 - 2011-07-18 19:57 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-14 16:28 - 2014-05-14 16:28 - 00000000 ____D () C:\Users\Kati\AppData\Local\{AFF51EAF-1EEE-4D30-9A8D-532258456C17}
2014-05-13 17:17 - 2014-05-13 17:17 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B0C594E1-1C40-46AD-9B29-7C5B4986A6E6}
2014-05-13 16:54 - 2014-05-13 16:53 - 00000000 ____D () C:\Users\Kati\AppData\Local\{98AC1C21-B103-44EE-AC7B-2C114FD85585}
2014-05-13 16:49 - 2014-01-29 16:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-12 20:54 - 2014-05-12 20:54 - 00000000 ____D () C:\Users\Kati\AppData\Local\{BE16BDD7-B89C-4024-B9F6-AD6FF1E9E786}
2014-05-12 07:26 - 2014-05-21 18:49 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-21 18:49 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-21 18:49 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 22:59 - 2013-09-30 12:13 - 00000000 ____D () C:\Users\Kati\Documents\Citavi 4
2014-05-11 19:59 - 2014-05-11 19:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-11 19:46 - 2014-05-11 19:46 - 00000000 ____D () C:\Users\Kati\AppData\Local\{C2B4150E-0C6B-4799-9C08-B1E8DFC269ED}
2014-05-10 21:55 - 2014-05-10 21:55 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9A0AD5CC-139C-491B-9266-50616B3EF2EC}
2014-05-09 17:57 - 2014-05-09 17:57 - 00000000 ____D () C:\Users\Kati\AppData\Local\{9C638A68-5F34-48C1-898B-3689CD978999}
2014-05-09 08:14 - 2014-05-15 14:27 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 14:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-08 15:00 - 2014-05-08 15:00 - 00000000 ____D () C:\Users\Kati\AppData\Local\{B51A953C-DD2F-4FB8-AA87-F6AD0AFB9AC2}
2014-05-07 20:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-07 19:03 - 2014-05-07 19:02 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DFB33308-901D-4EAF-9C6E-A5DEA8364065}
2014-05-07 15:02 - 2014-05-29 11:52 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-07 14:59 - 2014-05-29 11:52 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-07 14:59 - 2014-05-29 11:52 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-07 14:58 - 2014-05-29 11:52 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-06 15:35 - 2014-05-06 15:35 - 00000000 ____D () C:\Users\Kati\AppData\Local\{01097470-E215-4F09-8B1E-B904D4356792}
2014-05-06 06:40 - 2014-05-16 08:35 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-16 08:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-16 08:35 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-16 08:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-16 08:35 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-16 08:35 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-05 23:14 - 2012-09-20 19:21 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-05 23:14 - 2012-09-20 19:21 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-05 18:20 - 2014-05-05 18:20 - 00000000 ____D () C:\Users\Kati\AppData\Local\{8837D2BF-2261-45A5-975D-F775DFD9FD39}
2014-05-04 21:59 - 2014-05-04 21:59 - 00000000 ____D () C:\Users\Kati\AppData\Local\{30370F42-121E-48B3-B315-481D08085F3A}
2014-05-03 21:28 - 2014-05-03 21:27 - 00000000 ____D () C:\Users\Kati\AppData\Local\{DB63567F-3788-43B8-BCFB-ED07BD306540}
2014-05-03 02:36 - 2014-05-03 02:36 - 00000000 ____D () C:\Users\Kati\AppData\Local\{3CD5C54C-8659-40F2-AE16-BB7B404718E6}
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-05-03 01:56 - 2014-05-03 01:56 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-05-03 01:55 - 2013-04-19 13:10 - 00000000 ____D () C:\ProgramData\Sony Ericsson
2014-05-03 01:55 - 2013-04-19 13:10 - 00000000 ____D () C:\Program Files (x86)\Sony Ericsson

Some content of TEMP:
====================
C:\Users\Kati\AppData\Local\Temp\avgnt.exe
C:\Users\Kati\AppData\Local\Temp\burnsetup.exe
C:\Users\Kati\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmppilipj.dll
C:\Users\Kati\AppData\Local\Temp\FoxySecuritySetup.exe
C:\Users\Kati\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Kati\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\Kati\AppData\Local\Temp\Quarantine.exe
C:\Users\Kati\AppData\Local\Temp\sjy8mvbh.dll
C:\Users\Kati\AppData\Local\Temp\vpsetup.exe
C:\Users\Kati\AppData\Local\Temp\_is6454.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-29 00:47

==================== End Of Log ============================

--- --- ---




Danke Jonas! Du hast mir so oder so mega gut geholfen! :daumenhoc :dankeschoen: Dann verkrümel ich mich mal für weiteres in die andere Ecke :singsing:

sunjojo 03.06.2014 17:12

Ok, dann sind wir mit der Bereinigung soweit fertig :).



Updates
Deinstallieren veralteter Software
  • Java 7 Update 51
Gehe dafür auf:
Windows XP: Start -> Systemsteuerung -> Kategorieansicht auswählen (falls nicht voreingestellt) -> Software
Windows Vista/7: Start -> Systemsteuerung -> Anzeige (oben-rechts) auf Kategorie stellen (falls nicht voreingestellt) -> Programme deinstallieren (Unterpunkt von Programme)
Windows 8: Suchen --> "Systemsteuerung" in das Suchfeld eingeben --> Systemsteuerung auswählen --> Programme deinstallieren (Unterpunkt von Programme)
und wähle die angegeben Programme aus. Drücke Entfernen (Windows XP) oder Deinstallieren (Windows Vista/7/8).

Adobe Reader Version XI (11.0.07)
Cleanup
Falls du Malwarebytes Anti-Malware und den ESET Online Scanner nicht mehr behalten möchtest, kannst du diese über die Systemsteuerung deinstallieren. Ich empfehle dir, mindestens ein Programm zu behalten (näheres in den Tipps).
Windows XP: Start --> Systemsteuerung --> Kategorieansicht auswählen (falls nicht voreingestellt) --> Software
Windows Vista/7: Start --> Systemsteuerung --> Anzeige (oben-rechts) auf Kategorie stellen (falls nicht voreingestellt) --> Programme deinstallieren (Unterpunkt von Programme)
Windows 8: Suchen --> "Systemsteuerung" in das Suchfeld eingeben --> Systemsteuerung auswählen --> Programme deinstallieren (Unterpunkt von Programme)
Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



In deinen Logfiles sehe ich im Moment keine schädlichen Einträge mehr, du bist in meinen Augen Clean. Für die Zukunft habe ich dir Tipps aufgeschrieben, damit du uns in nächster Zeit nicht mehr brauchst :).




Tipps - Frequently Asked Questions (FAQ)/Häufig gestellte Fragen

Welcher Antivirenscanner ist der beste?
  • Die Antwort auf die Frage ist im Grunde einfach: keiner. Es gibt keinen Antivirenscanner, der immer alle Schädlinge sofort erkennt und dich 100%ig schützt. Alles vom Menschen geschaffene ist fehlerhaft und es ist ratsam, sich nur begrenzt darauf zu verlassen. Das heißt nicht, dass die Verwendung eines Antivirenprogramms keinen Sinn macht, aber es sollte als zusätzliche Hilfe angesehen werden. Die Hauptverantwortung liegt bei dir und deinem Verhalten im Internet selbst.
  • Benutze nur einen Antivirenscanner/Hintergrundwächter, niemals zwei oder mehrere. Diese könnten sich gegenseitig blockieren und dir mehr schaden, als helfen. Achte darauf, dass immer die neuesten Updates heruntergeladen werden. Ein veralteter Antivirenscanner ist nutzlos!
  • Außerdem kannst du dein Betriebssystem mit On-Demand Sannern überprüfen. Solche Scanner laufen nicht permanent im Hintergrund, sondern scannen nur "auf Knopfdruck" dein System. Damit holst du dir eine zweite Meinung ein. Gute On-Demand Scanner, die auch wir zur Kontrolle benutzen, sind Malwarebytes Anti Malware und der ESET Online Scanner.
    • Malwarebytes Anti-Malware (Anleitung zur Verwendung) ist eines der besten und zuverlässigsten Programme in der Malwareentfernung. Scanne dein System einmal pro Woche oder einmal in zwei Wochen.
    • Der ESET Online Scanner (Anleitung zur Verwendung) ist kostenlos und scannt dein System und deine Dateien sehr gründlich. Deswegen kann der Scan bei vielen Dateien mehrere Stunden dauern. Scanne dein System nach deinem eigenem Ermessen. Falls schädliche Dateien gefunden werden, handle nicht eigenmächtig!
Aber Updates muss ich immer installieren, oder?
  • Die Aktualität von Software ist sehr wichtig und unbedingt notwendig. Veraltete Programme stellen Schwachstellen dar, die sich Angreifer gerne zur Nutze machen. Daher ist es wichtig, immer die neueste Version der jeweiligen Software installiert zu haben. Dies fängt beim Betriebssystem an. Du solltest das neueste Service Pack installiert und automatische Updates eingeschaltet haben.
    Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
    Windows 8: Suchen --> "Systemsteuerung" in das Suchfeld eingeben --> Systemsteuerung auswählen --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Häufig werden Sicherheitslücken von älteren Java Versionen, dem Flash-Player und PDF-Reader ausgenutzt. Du kannst hier überprüfen, ob diese häufig missbrauchte Software aktuell ist: PluginCheck
Ok, muss ich auf etwas achten, wenn ich im Internet surfe?
  • Mit dem richtigen Verhalten im Internet fängt der Schutz vor Infektionen an. Es gibt inzwischen viele virtuelle Betrugsversuche oder Tricks zum Täuschen, sowie im echten Leben. Um sich dort zu schützen, hast du bestimmte Angewohnheiten. Diese können auf das Surfverhalten übertragen werden. Zur Verdeutlichung stelle ich dir einen kleinen Vergleich zum Leben her:

    Verhalten im LebenVerhalten im Internet
    Du überprüfst vorher die Läden, in denen du einkaufst.Klicke nicht auf alle Seiten/Werbungen/PopUps, weil diese bunt sind oder tolle Preise versprechen.
    Du achtest auf die Qualität, wenn du Produkte kaufst.Lade dir Programme nur von original Herstellerseiten herunter und nicht von Softonic oder ähnlichem. Diese birgen häufig die Gefahr, sich zusätzlich Adware herunterzuladen.
    Du öffnest keine Briefe oder Pakete ohne zu gucken, von wem diese sind.Öffne nur Anhänge von Emails, wenn der Absender bekannt ist. Überprüfe, ob zum Beispiel eine Rechnung im Anhang wirklich von der Firma versendet wurde. Häufig werden gefälschte Emails mit schädlichem Anhang verschickt!

    Handle mit Bedacht und überlege zuerst, bevor du etwas anklickst, herunterlädst oder öffnest!
  • Vermeide das Besuchen von pornographischen, Pokerspiel oder weiteren dubiosen Webseiten. Diese birgen ein besonders großes Infektionsrisiko.
Welche Programme sollte ich nicht verwenden?
  • Wenn du neue Software installierst, besteht häufig die Auswahl, eine weitere Toolbar (oder ähnliches) zu installieren. Entferne generell den Haken bei optionalen Zusatzprogrammen. Diese verlangsamen in der Regel deinen Browser und können ein erhöhtes Infektionsrisiko bedeuten.
  • Registry Cleaner versprechen meist einen großen Performancegewinn, wenn verwaiste Einträge in der Regsitry entfernt werden. Dieser angebliche Gewinn ist kaum bis gar nicht bemerkbar. Außerdem wird häufig verschwiegen, dass falsche Änderungen der Registry zu schwerwiegenden Folgen führen können. Deswegen sollte so wenig wie möglich an der Registry verändert werden. Zerstörst du die Registry, zerstörst du Windows!
  • Filesharing oder Peer-to-Peer Programme ermöglichen es, Dateien mit anderen Nutzern auszutauschen. Es ist möglich, dass du dir eine infizierte Datei herunterlädst (auch versteckt in angeblich legalen Versionen von bekannten Programmen). Du kannst niemals wissen, woher diese stammen. Daher sollte diese Art von Software mit äußerster Vorsicht oder gar nicht benutzt werden.
    • Lade dir vor allem keine Cracks (illegale Version einer Software) herunter. Das ist rechtlich nicht erlaubt und du kannst dafür bestraft werden. Außerdem ist bei solcher Software das Infektionsrisiko am höchsten, da Cracks sehr häufig versteckte Malware enthalten.
Gibt es noch weitere Tipps, um mich zu schützen?
  • Achte auf die Endung von Dateien, die dir zugesendet wurden. Häufig versuchen Malwareschreiber mit Tricks wie Rechnung.pdf.exe dich zu täuschen. Wenn die Dateiendung ausgeblendet wird, bleibt Rechnung.pdf übrig, was den Anschein einer normalen PDF-Datei macht. Lass dir daher bekannte Dateiendung anzeigen (Anleitung: http://www.trojaner-board.de/59624-a...-sichtbar.html)
  • Surfe mit einem Konto mit eingeschränkten Rechten. Durch Administratorrechte kann Malware ohne Probleme zahlreiche Änderungen am System vornehmen, zum Beispiel Sicherheitseinstellungen verändern oder auf Systemdateien zugreifen.
  • Verwende nicht immer das gleiche Passwort. Falls dein Passwort durch entsprechende Malware herausgefunden wird, könnte auf alle Konten von dir zugegriffen werden.
  • Lege in regelmäßigen Abständen Backups (Was sind Backups?) von deinem System an. Dadurch ist ein Datenverlust durch Malware oder Hardwareschäden verkraftbar und es ist vergleichsweise einfach, den Rechner auf den Stand des letzten Backups zu bringen. Damit du deine Daten nicht manuell sichern musst, gibt es Backup-Programme wie Paragon Backup & Recovery.
  • Deaktiviere das Autorun-Feature von Windows. Dies ermöglicht, dass zum Beispiel CDs, DVDs oder Programme auf USB-Sticks alleine starten. Häufig nutzen Malwareschreiber genau diese Funktion aus. In solchen Fällen befindet sich Malware auf dem USB-Stick und wird automatisch beim Anschließen an den Computer ausgeführt. Um das zu verhinden, deaktiviere die Autorun-Funktion: http://www.trojaner-board.de/83238-a...sschalten.html.
Wenn dich das Thema Computersicherheit interessiert und du noch mehr Tipps und Tricks zum Schutz deines Rechners haben willst, ist der Emsisoft Blog genau richtig für dich ;).


Wenn du die Arbeit des Trojaner-Boards unterstützen möchtest, kannst du gerne spenden :).

Ich wünsche dir eine schöne und malwarefreie Zeit :daumenhoc.

Larusso 03.06.2014 21:05

Hallo.
Jonas hat mich bezüglich deines Audioproblems angeschrieben.
Ich lese mir dein Thema morgen nochmals genau durch und werde sehen ob ich dahinter komme.
Ich bin halt derzeit beruflich sehr eingespannt und versuche so schnell wie möglich zu antworten.

Kurz. Kopfhörer gehen also normal und das Problem tritt nur bei den internen Boxen auf ?

Nirtaka 03.06.2014 21:23

Hi Daniel,

das ist nett von Jonas! Und ja, mit Kopfhörern läuft der Ton normal, nur wenn ich über die internen Lautsprecher hören will verschwindet der Ton nach einigen Sekunden. Antworte wie du es schaffst, ich weiss wie es ist, wenn man nebenbei noch beruflich eingespannt ist, also kein Stress :) ! Bin froh, dass es euch überhaupt hier gibt und sehr dankbar. Sobald ich es kann, werde ich auch eine kleine Spende überweisen, da ich finde, dass es hier immer super klappt (zletzt mit Jonas und auch im letzten Jahr mit einem anderen Helfer) und ich sehr zufrieden bin.:daumenhoc

LG Kati

Larusso 04.06.2014 16:39

Hy again

1. Trat das Problem schon vor dem Malware Problem auf ?
2. Würde ich gerne einen Screenshot von den vorhandenen Wiedergabegeräten sehen.
( wenn möglich, wenn gerade irgendwas übern Media Player o.Ä. läuft auch wenn du nichts hörst )

3.

Bitte lade VEW.exe von Vino Rosso herunter und speichere das Tool auf Deinem Desktop.
Starte die vew.exe mit Rechtsklick -> Als Admin ausführen und mache folgende Einstellungen:

http://image.hijackthis.eu/upload/vew.jpg

Drücke den Button Run, um den Suchlauf zu starten.
Wenn der Suchlauf beendet ist, öffnet sich der Editor mit dem Logfile.
Kopiere das Logfile (C:\vew.txt) hier in den Thread.

Nirtaka 04.06.2014 17:44

Hi Daniel,

also, soweit ich weiss trat das Audioproblem schon länger vor dem Malwareproblem auf!

Code:

Vino's Event Viewer v01c run on Windows 2008 in German
Report run at 04/06/2014 18:31:10

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Kritisch Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Fehler Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 04/06/2014 12:20:24
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 04/06/2014 10:57:20
Type: Fehler Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Log: 'Application' Date/Time: 04/06/2014 10:57:13
Type: Fehler Category: 0
Event: 0 Source: MemeoBackgroundService
Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)    bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)    --- Ende der internen Ausnahmestapelüberwachung ---    bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)    bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)    bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)    bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)    bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)

Log: 'Application' Date/Time: 01/06/2014 22:58:44
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 01/06/2014 17:06:17
Type: Fehler Category: 0
Event: 4104 Source: Windows Backup
Die Sicherung war nicht erfolgreich. Fehler: "Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)"

Log: 'Application' Date/Time: 31/05/2014 11:18:40
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 31/05/2014 08:41:47
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 31/05/2014 05:59:04
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 30/05/2014 12:04:22
Type: Fehler Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Log: 'Application' Date/Time: 30/05/2014 06:45:14
Type: Fehler Category: 0
Event: 513 Source: Microsoft-Windows-CAPI2
Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddWin32ServiceFiles: Unable to back up image of service BUP Service since QueryServiceConfig API failed

System Error:
Das System kann die angegebene Datei nicht finden. .

Log: 'Application' Date/Time: 30/05/2014 06:28:13
Type: Fehler Category: 0
Event: 513 Source: Microsoft-Windows-CAPI2
Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddWin32ServiceFiles: Unable to back up image of service BUP Service since QueryServiceConfig API failed

System Error:
Das System kann die angegebene Datei nicht finden. .

Log: 'Application' Date/Time: 29/05/2014 23:22:07
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 29/05/2014 09:51:39
Type: Fehler Category: 0
Event: 513 Source: Microsoft-Windows-CAPI2
Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddWin32ServiceFiles: Unable to back up image of service BUP Service since QueryServiceConfig API failed

System Error:
Das System kann die angegebene Datei nicht finden. .

Log: 'Application' Date/Time: 28/05/2014 20:31:52
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 27/05/2014 20:34:59
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Kati\Downloads\esetsmartinstaller_enu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 27/05/2014 20:34:53
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Kati\Downloads\esetsmartinstaller_enu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 27/05/2014 20:34:48
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Kati\Downloads\esetsmartinstaller_enu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 27/05/2014 20:34:47
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Kati\Downloads\esetsmartinstaller_enu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 26/05/2014 20:06:40
Type: Fehler Category: 0
Event: 4104 Source: Windows Backup
Die Sicherung war nicht erfolgreich. Fehler: "Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)"

Log: 'Application' Date/Time: 26/05/2014 19:52:28
Type: Fehler Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Informationen Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 04/06/2014 16:19:05
Type: Informationen Category: 0
Event: 0 Source: gupdate
The event description cannot be found.

Log: 'Application' Date/Time: 04/06/2014 12:44:28
Type: Informationen Category: 0
Event: 258 Source: Microsoft-Windows-Defrag
"Defragmentierung" wurde von der Defragmentierung auf Recover (D:) abgeschlossen.

Log: 'Application' Date/Time: 04/06/2014 12:44:23
Type: Informationen Category: 0
Event: 258 Source: Microsoft-Windows-Defrag
"Defragmentierung" wurde von der Defragmentierung auf Boot (C:) abgeschlossen.

Log: 'Application' Date/Time: 04/06/2014 12:27:52
Type: Informationen Category: 0
Event: 8224 Source: VSS
Der VSS-Dienst wird aufgrund eines Leerlaufzeitlimits heruntergefahren.

Log: 'Application' Date/Time: 04/06/2014 12:18:20
Type: Informationen Category: 0
Event: 258 Source: Microsoft-Windows-Defrag
"Defragmentierung" wurde von der Defragmentierung auf \\?\Volume{e532f744-0391-11e2-992e-806e6f6e6963}\ abgeschlossen.

Log: 'Application' Date/Time: 04/06/2014 11:29:40
Type: Informationen Category: 0
Event: 1001 Source: Windows Error Reporting
Fehlerbucket 3728726078, Typ 5 Ereignisname: MpTelemetry Antwort: Nicht verfügbar CAB-Datei-ID: 0  Problemsignatur: P1: 80072efe P2: EndSearch P3: Search P4: 6.1.7601.18170 P5: MpSigDwn.dll P6: 6.1.7600.16385 P7: Windows Defender P8:  P9:  P10:  Angefügte Dateien: C:\Windows\temp\MPTelemetrySubmit\client_manifest.txt  Diese Dateien befinden sich möglicherweise hier: C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_80072efe_f96a2c54d4aa2d5ad89e29fceb398f967eb2a1_01564ecb  Analysesymbol:  Es wird erneut nach einer Lösung gesucht: 0 Berichts-ID: 135440ce-ea04-11e3-92a8-e840f22b5625 Berichtstatus: 0

Log: 'Application' Date/Time: 04/06/2014 11:16:29
Type: Informationen Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
Der Winlogon-Benachrichtigungsabonnent <SessionEnv> war nicht verfügbar, um das Benachrichtigungsereignis zu verarbeiten.

Log: 'Application' Date/Time: 04/06/2014 11:16:29
Type: Informationen Category: 0
Event: 4101 Source: Microsoft-Windows-Winlogon
Die Windows-Lizenz wurde überprüft.

Log: 'Application' Date/Time: 04/06/2014 11:07:19
Type: Informationen Category: 0
Event: 8224 Source: VSS
Der VSS-Dienst wird aufgrund eines Leerlaufzeitlimits heruntergefahren.

Log: 'Application' Date/Time: 04/06/2014 11:04:57
Type: Informationen Category: 0
Event: 903 Source: Microsoft-Windows-Security-SPP
Der Softwareschutzdienst wurde beendet.

Log: 'Application' Date/Time: 04/06/2014 11:04:07
Type: Informationen Category: 0
Event: 8194 Source: System Restore
Der Wiederherstellungspunkt wurde erfolgreich erstellt (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update).

Log: 'Application' Date/Time: 04/06/2014 11:00:09
Type: Informationen Category: 0
Event: 0 Source: gupdate
The event description cannot be found.

Log: 'Application' Date/Time: 04/06/2014 10:59:58
Type: Informationen Category: 1
Event: 1003 Source: Microsoft-Windows-Search
Windows Search wurde gestartet.


Log: 'Application' Date/Time: 04/06/2014 10:59:56
Type: Informationen Category: 0
Event: 902 Source: Microsoft-Windows-Security-SPP
Der Softwareschutzdienst wurde gestartet. 6.1.7601.17514

Log: 'Application' Date/Time: 04/06/2014 10:59:56
Type: Informationen Category: 0
Event: 1003 Source: Microsoft-Windows-Security-SPP
Der Softwareschutzdienst hat die Überprüfung des Lizenzierungsstatus abgeschlossen. Anwendungs-ID=55c92734-d682-4d71-983e-d6ec3f16059f Lizenzierungsstatus=
1: 01f5fc37-a99e-45c5-b65e-d762f3518ead, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 2e7d060d-4714-40f2-9896-1e4f15b612ad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 3b965dfc-31d9-4903-886f-873a0382776c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 586bc076-c93d-429a-afe5-a69fbc644e88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 5e35dc43-389b-47c5-b889-2088b06738cb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6a7d5d8a-92af-4e6a-af4b-8fddaec800e5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ab82e0c-ffc9-4107-baa1-c65a8bd3ccc3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: 9f83d90f-a151-4665-ae69-30b3f63ec659, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: a63275f4-530c-48a7-b0d3-4f00d688d151, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b8a4bb91-69b1-460d-93f8-40e0670af04a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: d2c04e90-c3dd-4260-b0f3-f845f5d27d64, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )]
13: e68b141f-4dfa-4387-b3b7-e65c4889216e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: ee4e1629-bcdc-4b42-a68f-b92e135f78d7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]



Log: 'Application' Date/Time: 04/06/2014 10:59:56
Type: Informationen Category: 3
Event: 302 Source: ESENT
Windows (3640) Windows: Das Datenbankmodul hat erfolgreich die Schritte zur Wiederherstellung abgeschlossen.

Log: 'Application' Date/Time: 04/06/2014 10:59:56
Type: Informationen Category: 0
Event: 1066 Source: Microsoft-Windows-Security-SPP
Initialisierungsstatus für Dienstobjekte. C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000


Log: 'Application' Date/Time: 04/06/2014 10:59:55
Type: Informationen Category: 3
Event: 301 Source: ESENT
Windows (3640) Windows: Das Datenbankmodul gibt die Protokolldatei C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log wieder.

Log: 'Application' Date/Time: 04/06/2014 10:59:55
Type: Informationen Category: 3
Event: 301 Source: ESENT
Windows (3640) Windows: Das Datenbankmodul gibt die Protokolldatei C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS004F9.log wieder.

Log: 'Application' Date/Time: 04/06/2014 10:59:55
Type: Informationen Category: 3
Event: 300 Source: ESENT
Windows (3640) Windows: Das Datenbankmodul initiiert Schritte zur Wiederherstellung.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warnung Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 04/06/2014 12:24:52
Type: Warnung Category: 0
Event: 12348 Source: VSS
Volumeschattenkopie-Dienst-Warnung: Dem Volumeschattenkopie-Dienst wurde der Zugriff auf Volume "\\?\Volume{d1fc47f9-03e2-11e2-a2a1-e840f22b5625}\" verweigert. Wenn Administratoren der Zugriff auf den Volumestamm verweigert  wird, kann dies dazu führen, dass unerwartete Fehler auftreten und dass VSS nicht mehr  ordnungsgemäß funktioniert. Prüfen Sie die Sicherheit auf dem Volume, und wiederholen Sie dann  den Vorgang.

Vorgang:
  Automatisch freigegebene Schattenkopien werden entfernt
  Anbieter wird geladen

Kontext:
  Ausführungskontext: System Provider

Log: 'Application' Date/Time: 04/06/2014 11:07:26
Type: Warnung Category: 1
Event: 100 Source: CVHSVC
Nur zur Information. CurrentSoftGridPrereq: Click2Run installation (version = 14.0.4763.1000) is found on the machine; skipping installation...

Log: 'Application' Date/Time: 04/06/2014 11:07:26
Type: Warnung Category: 1
Event: 100 Source: CVHSVC
Nur zur Information. C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE is trusted.

Log: 'Application' Date/Time: 04/06/2014 11:03:33
Type: Warnung Category: 0
Event: 12348 Source: VSS
Volumeschattenkopie-Dienst-Warnung: Dem Volumeschattenkopie-Dienst wurde der Zugriff auf Volume "\\?\Volume{d1fc47f9-03e2-11e2-a2a1-e840f22b5625}\" verweigert. Wenn Administratoren der Zugriff auf den Volumestamm verweigert  wird, kann dies dazu führen, dass unerwartete Fehler auftreten und dass VSS nicht mehr  ordnungsgemäß funktioniert. Prüfen Sie die Sicherheit auf dem Volume, und wiederholen Sie dann  den Vorgang.

Vorgang:
  Automatisch freigegebene Schattenkopien werden entfernt
  Anbieter wird geladen

Kontext:
  Ausführungskontext: System Provider

Log: 'Application' Date/Time: 04/06/2014 10:57:25
Type: Warnung Category: 6
Event: 3057 Source: Application Virtualization Client
{tid=B98}
Der Application Virtualization Client-Kern wurde richtig initialisiert.  Installiertes Produkt:  Version: 4.6.2.22610 Installationspfad: C:\Program Files (x86)\Microsoft Application Virtualization Client Globales Datenverzeichnis: C:\ProgramData\Microsoft\Application Virtualization Client\ Computername: KATI-PC Betriebssystem: Windows 7 64-bit Service Pack 1.0 Build 7601 OSD-Befehl:

Log: 'Application' Date/Time: 04/06/2014 10:57:21
Type: Warnung Category: 3
Event: 3191 Source: Application Virtualization Client
{tid=B98}
-------------------------------------------------------- Clientprotokoll initialisiert (C:\ProgramData\Microsoft\Application Virtualization Client\sftlog.txt)

Log: 'Application' Date/Time: 04/06/2014 10:45:21
Type: Warnung Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Es wurde festgestellt, dass Ihre Registrierungsdatei noch von anderen Anwendungen oder Diensten verwendet wird. Die Datei wird nun entladen. Die Anwendungen oder Dienste, die Ihre Registrierungsdatei anhalten, funktionieren anschließend u. U. nicht mehr ordnungsgemäß.    DETAIL -  1 user registry handles leaked from \Registry\User\S-1-5-21-2548312011-2494454960-3164520827-1001:
Process 1560 (\Device\HarddiskVolume2\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe) has opened key \REGISTRY\USER\S-1-5-21-2548312011-2494454960-3164520827-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon


Log: 'Application' Date/Time: 02/06/2014 22:00:02
Type: Warnung Category: 0
Event: 12348 Source: VSS
Volumeschattenkopie-Dienst-Warnung: Dem Volumeschattenkopie-Dienst wurde der Zugriff auf Volume "\\?\Volume{d1fc47f9-03e2-11e2-a2a1-e840f22b5625}\" verweigert. Wenn Administratoren der Zugriff auf den Volumestamm verweigert  wird, kann dies dazu führen, dass unerwartete Fehler auftreten und dass VSS nicht mehr  ordnungsgemäß funktioniert. Prüfen Sie die Sicherheit auf dem Volume, und wiederholen Sie dann  den Vorgang.

Vorgang:
  Automatisch freigegebene Schattenkopien werden entfernt
  Anbieter wird geladen

Kontext:
  Ausführungskontext: System Provider

Log: 'Application' Date/Time: 02/06/2014 19:13:28
Type: Warnung Category: 1
Event: 100 Source: CVHSVC
Nur zur Information. CurrentSoftGridPrereq: Click2Run installation (version = 14.0.4763.1000) is found on the machine; skipping installation...

Log: 'Application' Date/Time: 02/06/2014 19:13:28
Type: Warnung Category: 1
Event: 100 Source: CVHSVC
Nur zur Information. C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE is trusted.

Log: 'Application' Date/Time: 01/06/2014 17:00:50
Type: Warnung Category: 0
Event: 12348 Source: VSS
Volumeschattenkopie-Dienst-Warnung: Dem Volumeschattenkopie-Dienst wurde der Zugriff auf Volume "\\?\Volume{d1fc47f9-03e2-11e2-a2a1-e840f22b5625}\" verweigert. Wenn Administratoren der Zugriff auf den Volumestamm verweigert  wird, kann dies dazu führen, dass unerwartete Fehler auftreten und dass VSS nicht mehr  ordnungsgemäß funktioniert. Prüfen Sie die Sicherheit auf dem Volume, und wiederholen Sie dann  den Vorgang.

Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Log: 'Application' Date/Time: 01/06/2014 17:00:50
Type: Warnung Category: 0
Event: 12348 Source: VSS
Volumeschattenkopie-Dienst-Warnung: Dem Volumeschattenkopie-Dienst wurde der Zugriff auf Volume "\\?\Volume{d1fc47f9-03e2-11e2-a2a1-e840f22b5625}\" verweigert. Wenn Administratoren der Zugriff auf den Volumestamm verweigert  wird, kann dies dazu führen, dass unerwartete Fehler auftreten und dass VSS nicht mehr  ordnungsgemäß funktioniert. Prüfen Sie die Sicherheit auf dem Volume, und wiederholen Sie dann  den Vorgang.

Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Log: 'Application' Date/Time: 01/06/2014 17:00:05
Type: Warnung Category: 0
Event: 12348 Source: VSS
Volumeschattenkopie-Dienst-Warnung: Dem Volumeschattenkopie-Dienst wurde der Zugriff auf Volume "\\?\Volume{d1fc47f9-03e2-11e2-a2a1-e840f22b5625}\" verweigert. Wenn Administratoren der Zugriff auf den Volumestamm verweigert  wird, kann dies dazu führen, dass unerwartete Fehler auftreten und dass VSS nicht mehr  ordnungsgemäß funktioniert. Prüfen Sie die Sicherheit auf dem Volume, und wiederholen Sie dann  den Vorgang.

Vorgang:
  Automatisch freigegebene Schattenkopien werden entfernt
  Anbieter wird geladen

Kontext:
  Ausführungskontext: System Provider

Log: 'Application' Date/Time: 01/06/2014 14:50:40
Type: Warnung Category: 0
Event: 12348 Source: VSS
Volumeschattenkopie-Dienst-Warnung: Dem Volumeschattenkopie-Dienst wurde der Zugriff auf Volume "\\?\Volume{d1fc47f9-03e2-11e2-a2a1-e840f22b5625}\" verweigert. Wenn Administratoren der Zugriff auf den Volumestamm verweigert  wird, kann dies dazu führen, dass unerwartete Fehler auftreten und dass VSS nicht mehr  ordnungsgemäß funktioniert. Prüfen Sie die Sicherheit auf dem Volume, und wiederholen Sie dann  den Vorgang.

Vorgang:
  Automatisch freigegebene Schattenkopien werden entfernt
  Anbieter wird geladen

Kontext:
  Ausführungskontext: System Provider

Log: 'Application' Date/Time: 01/06/2014 11:03:48
Type: Warnung Category: 1
Event: 100 Source: CVHSVC
Nur zur Information. CurrentSoftGridPrereq: Click2Run installation (version = 14.0.4763.1000) is found on the machine; skipping installation...

Log: 'Application' Date/Time: 01/06/2014 11:03:42
Type: Warnung Category: 1
Event: 100 Source: CVHSVC
Nur zur Information. C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE is trusted.

Log: 'Application' Date/Time: 30/05/2014 23:21:50
Type: Warnung Category: 0
Event: 12348 Source: VSS
Volumeschattenkopie-Dienst-Warnung: Dem Volumeschattenkopie-Dienst wurde der Zugriff auf Volume "\\?\Volume{d1fc47f9-03e2-11e2-a2a1-e840f22b5625}\" verweigert. Wenn Administratoren der Zugriff auf den Volumestamm verweigert  wird, kann dies dazu führen, dass unerwartete Fehler auftreten und dass VSS nicht mehr  ordnungsgemäß funktioniert. Prüfen Sie die Sicherheit auf dem Volume, und wiederholen Sie dann  den Vorgang.

Vorgang:
  Automatisch freigegebene Schattenkopien werden entfernt
  Anbieter wird geladen

Kontext:
  Ausführungskontext: System Provider

Log: 'Application' Date/Time: 30/05/2014 17:37:40
Type: Warnung Category: 0
Event: 12348 Source: VSS
Volumeschattenkopie-Dienst-Warnung: Dem Volumeschattenkopie-Dienst wurde der Zugriff auf Volume "\\?\Volume{d1fc47f9-03e2-11e2-a2a1-e840f22b5625}\" verweigert. Wenn Administratoren der Zugriff auf den Volumestamm verweigert  wird, kann dies dazu führen, dass unerwartete Fehler auftreten und dass VSS nicht mehr  ordnungsgemäß funktioniert. Prüfen Sie die Sicherheit auf dem Volume, und wiederholen Sie dann  den Vorgang.

Vorgang:
  Automatisch freigegebene Schattenkopien werden entfernt
  Anbieter wird geladen

Kontext:
  Ausführungskontext: System Provider

Log: 'Application' Date/Time: 30/05/2014 12:12:54
Type: Warnung Category: 1
Event: 100 Source: CVHSVC
Nur zur Information. CurrentSoftGridPrereq: Click2Run installation (version = 14.0.4763.1000) is found on the machine; skipping installation...

Log: 'Application' Date/Time: 30/05/2014 12:12:54
Type: Warnung Category: 1
Event: 100 Source: CVHSVC
Nur zur Information. C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE is trusted.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Kritisch Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 15/05/2014 13:16:00
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 13/05/2014 14:56:59
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 11/05/2014 16:11:52
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 09/05/2014 15:52:31
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 09/05/2014 15:47:15
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 08/05/2014 18:02:49
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 07/05/2014 20:28:26
Type: Kritisch Category: 64
Event: 10111 Source: Microsoft-Windows-DriverFrameworks-UserMode
Das Gerät "Xperia miro" (Ort "Port_#0003.Hub_#0001") ist aufgrund eines Ausfalls eines Benutzermodustreibers offline. Ein Neustart des Geräts wird 5 Mal versucht. Weitere Informationen zu diesem Problem erhalten Sie beim Gerätehersteller.

Log: 'System' Date/Time: 07/05/2014 20:28:26
Type: Kritisch Category: 64
Event: 10110 Source: Microsoft-Windows-DriverFrameworks-UserMode
Bei mindestens einem Benutzermodustreiber ist ein Problem aufgetreten, und der Hostprozess wurde beendet. Möglicherweise können Sie vorübergehend nicht auf die Geräte zugreifen.

Log: 'System' Date/Time: 24/04/2014 18:35:16
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 23/04/2014 18:43:22
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 22/04/2014 16:44:30
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 22/04/2014 15:21:39
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 21/04/2014 22:50:11
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 06/04/2014 07:55:09
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 25/03/2014 22:47:15
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 24/03/2014 18:08:38
Type: Kritisch Category: 64
Event: 10111 Source: Microsoft-Windows-DriverFrameworks-UserMode
Das Gerät "Kati " (Ort "Port_#0003.Hub_#0001") ist aufgrund eines Ausfalls eines Benutzermodustreibers offline. Ein Neustart des Geräts wird 5 Mal versucht. Weitere Informationen zu diesem Problem erhalten Sie beim Gerätehersteller.

Log: 'System' Date/Time: 24/03/2014 18:08:38
Type: Kritisch Category: 64
Event: 10110 Source: Microsoft-Windows-DriverFrameworks-UserMode
Bei mindestens einem Benutzermodustreiber ist ein Problem aufgetreten, und der Hostprozess wurde beendet. Möglicherweise können Sie vorübergehend nicht auf die Geräte zugreifen.

Log: 'System' Date/Time: 23/03/2014 14:00:46
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 18/03/2014 18:39:41
Type: Kritisch Category: 64
Event: 10111 Source: Microsoft-Windows-DriverFrameworks-UserMode
Das Gerät "Kati" (Ort "Port_#0003.Hub_#0001") ist aufgrund eines Ausfalls eines Benutzermodustreibers offline. Ein Neustart des Geräts wird 5 Mal versucht. Weitere Informationen zu diesem Problem erhalten Sie beim Gerätehersteller.

Log: 'System' Date/Time: 18/03/2014 18:39:41
Type: Kritisch Category: 64
Event: 10110 Source: Microsoft-Windows-DriverFrameworks-UserMode
Bei mindestens einem Benutzermodustreiber ist ein Problem aufgetreten, und der Hostprozess wurde beendet. Möglicherweise können Sie vorübergehend nicht auf die Geräte zugreifen.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Fehler Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 04/06/2014 10:57:02
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

Log: 'System' Date/Time: 30/05/2014 12:02:43
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

Log: 'System' Date/Time: 30/05/2014 12:01:12
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 12:01:12
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 11:36:35
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 11:36:35
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 11:35:48
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 11:35:48
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 11:34:04
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 11:34:04
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 11:33:04
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 11:33:04
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 11:30:24
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 30/05/2014 11:30:24
Type: Fehler Category: 0
Event: 7006 Source: Service Control Manager
Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:  Zugriff verweigert

Log: 'System' Date/Time: 29/05/2014 07:48:52
Type: Fehler Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
Der Server "{F9717507-6651-4EDB-BFF7-AE615179BCCF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Log: 'System' Date/Time: 26/05/2014 19:52:11
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

Log: 'System' Date/Time: 21/05/2014 17:09:32
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

Log: 'System' Date/Time: 21/05/2014 16:39:51
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "MemeoBackgroundService" wurde aufgrund folgenden Fehlers nicht gestartet:  Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Log: 'System' Date/Time: 21/05/2014 16:39:51
Type: Fehler Category: 0
Event: 7009 Source: Service Control Manager
Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst MemeoBackgroundService erreicht.

Log: 'System' Date/Time: 21/05/2014 16:39:17
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "ASLDR Service" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Informationen Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 04/06/2014 16:27:43
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Tablet PC-Eingabedienst" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 16:24:33
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Anwendungserfahrung" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 16:19:05
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Google Update-Dienst (gupdate)" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 04/06/2014 16:19:04
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Google Update-Dienst (gupdate)" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 16:17:46
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Anwendungserfahrung" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 04/06/2014 16:08:00
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Adobe Flash Player Update Service" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 04/06/2014 16:08:00
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Adobe Flash Player Update Service" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 16:04:46
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Anwendungserfahrung" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 15:50:04
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 15:23:52
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 04/06/2014 15:22:03
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Anwendungserfahrung" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 04/06/2014 15:08:00
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Adobe Flash Player Update Service" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 04/06/2014 15:08:00
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Adobe Flash Player Update Service" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 15:07:22
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 15:06:37
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Anwendungserfahrung" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 15:03:36
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Windows Driver Foundation - Benutzermodus-Treiberframework" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 15:03:33
Type: Informationen Category: 101
Event: 10114 Source: Microsoft-Windows-DriverFrameworks-UserMode
Der UMDF-Reflektor konnte den Start nicht abschließen, da der Dienst WUDFPf nicht gefunden wurde. Dieser Dienst wird ggf. später beim Start aufgerufen, und dann wird versucht, das Gerät erneut zu starten.

Log: 'System' Date/Time: 04/06/2014 14:47:02
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 04/06/2014 14:30:32
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 04/06/2014 14:27:10
Type: Informationen Category: 0
Event: 1 Source: Microsoft-Windows-Power-Troubleshooter
Das System wurde aus dem Energiesparmodus reaktiviert.  Zeit im Energiesparmodus: ?2014?-?06?-?04T13:00:26.130490000Z Reaktivierungszeit: ?2014?-?06?-?04T14:27:06.527230400Z  Reaktivierungsquelle: Netzschalter

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warnung Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 04/06/2014 15:03:33
Type: Warnung Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
Fehler beim Laden des Treibers \Driver\WUDFRd für das Gerät USB\VID_04E8&PID_6860\065af19c.

Log: 'System' Date/Time: 04/06/2014 13:00:32
Type: Warnung Category: 0
Event: 134 Source: Microsoft-Windows-Time-Service
Aufgrund eines DNS-Auflösungsfehlers auf "" konnte vom "NtpClient" kein manueller Peer als Zeitquelle festgelegt werden. In 3473457 Minuten wird ein weiterer Versuch ausgeführt und das Intervall für weitere Versuche anschließend verdoppelt. Fehler: Der angeforderte Name ist gültig, es wurden jedoch keine Daten des angeforderten Typs gefunden. (0x80072AFC)

Log: 'System' Date/Time: 04/06/2014 10:45:47
Type: Warnung Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
Der Dienst für die automatische WLAN-Konfiguration wurde erfolgreich beendet.

Log: 'System' Date/Time: 04/06/2014 10:45:46
Type: Warnung Category: 0
Event: 10002 Source: Microsoft-Windows-WLAN-AutoConfig
Das WLAN-Erweiterungsmodul wurde beendet.  Modulpfad: C:\Windows\System32\IWMSSvc.dll

Log: 'System' Date/Time: 04/06/2014 10:44:59
Type: Warnung Category: 0
Event: 18 Source: avgntflt
TIMEOUT<System> C:\...e4bcf10ad6e7b20729add4e1b01.notification-center_0.localstorage-journal

Log: 'System' Date/Time: 02/06/2014 11:03:30
Type: Warnung Category: 0
Event: 36 Source: Microsoft-Windows-Time-Service
Der Zeitdienst hat die Systemzeit für 86400 Sekunden nicht synchronisiert, weil keiner der Zeitdienstanbieter einen verwendbaren Zeitstempel bereitgestellt hat. Der Zeitdienst aktualisiert die lokale Systemzeit nur dann, wenn die Synchronisierung mit einer Zeitquelle möglich ist. Wenn das lokale System als Zeitserver für Clients konfiguriert ist, beendet es die Ankündigung als Zeitquelle für Clients. Der Zeitdienst versucht weiter, die Zeit mit den Zeitquellen zu synchronisieren. Überprüfen Sie, ob das Systemereignisprotokoll andere W32time-Ereignisse enthält, um weitere Details zu erhalten. Führen Sie "w32tm /resync" aus, um eine sofortige Zeitsynchronisierung zu erzwingen.

Log: 'System' Date/Time: 30/05/2014 12:22:35
Type: Warnung Category: 0
Event: 18 Source: avgntflt
TIMEOUT<explorer.exe> C:\Users\Kati\Downloads\wlane6221_inw7.exe

Log: 'System' Date/Time: 30/05/2014 12:03:56
Type: Warnung Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
Fehler beim Laden des Treibers \Driver\WUDFRd für das Gerät WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_SMI&PROD_USB_DISK&REV_1100#7&3891C103&0#.

Log: 'System' Date/Time: 30/05/2014 11:27:39
Type: Warnung Category: 0
Event: 1073 Source: USER32
Der Versuch von Benutzer Kati-PC\Kati, Computer KATI-PC neu zu starten bzw. herunterzufahren ist fehlgeschlagen.

Log: 'System' Date/Time: 29/05/2014 20:43:13
Type: Warnung Category: 0
Event: 18 Source: avgntflt
TIMEOUT<System> C:\...Live Mail\Arcor (kati 74d\Inbox\305F4CFE-00002D8C.eml:OECustomProperty

Log: 'System' Date/Time: 29/05/2014 10:35:57
Type: Warnung Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Zeitüberschreitung bei der Namensauflösung für den Namen pixel.facebook.com, nachdem keiner der konfigurierten DNS-Server geantwortet hat.

Log: 'System' Date/Time: 28/05/2014 13:58:50
Type: Warnung Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Zeitüberschreitung bei der Namensauflösung für den Namen dns.msftncsi.com, nachdem keiner der konfigurierten DNS-Server geantwortet hat.

Log: 'System' Date/Time: 28/05/2014 13:58:34
Type: Warnung Category: 0
Event: 18 Source: avgntflt
TIMEOUT<OnlineCmdLineS> C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Entity.dll

Log: 'System' Date/Time: 28/05/2014 10:15:39
Type: Warnung Category: 0
Event: 18 Source: avgntflt
TIMEOUT<OnlineCmdLineS> C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrcompression.dll

Log: 'System' Date/Time: 28/05/2014 00:25:21
Type: Warnung Category: 0
Event: 18 Source: avgntflt
TIMEOUT<svchost.exe> C:\Windows\System32\microsoft-windows-kernel-power-events.dll

Log: 'System' Date/Time: 26/05/2014 20:01:26
Type: Warnung Category: 0
Event: 134 Source: Microsoft-Windows-Time-Service
Aufgrund eines DNS-Auflösungsfehlers auf "" konnte vom "NtpClient" kein manueller Peer als Zeitquelle festgelegt werden. In 3473457 Minuten wird ein weiterer Versuch ausgeführt und das Intervall für weitere Versuche anschließend verdoppelt. Fehler: Der angeforderte Name ist gültig, es wurden jedoch keine Daten des angeforderten Typs gefunden. (0x80072AFC)

Log: 'System' Date/Time: 26/05/2014 19:59:43
Type: Warnung Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Zeitüberschreitung bei der Namensauflösung für den Namen client99.dropbox.com, nachdem keiner der konfigurierten DNS-Server geantwortet hat.

Log: 'System' Date/Time: 26/05/2014 19:57:51
Type: Warnung Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Zeitüberschreitung bei der Namensauflösung für den Namen download.windowsupdate.com, nachdem keiner der konfigurierten DNS-Server geantwortet hat.

Log: 'System' Date/Time: 26/05/2014 19:53:00
Type: Warnung Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
Fehler beim Laden des Treibers \Driver\WUDFRd für das Gerät WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_SMI&PROD_USB_DISK&REV_1100#7&3891C103&0#.

Log: 'System' Date/Time: 22/05/2014 12:24:44
Type: Warnung Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
Der Dienst für die automatische WLAN-Konfiguration wurde erfolgreich beendet.

Ehm und ich checke gerade nicht, wie ich den Screenshot hier einfügen kann :O ?! LG Kati

Larusso 04.06.2014 21:20

Antworten auf erweitert klicken, Anhänge verwalten

Nirtaka 05.06.2014 14:22

Liste der Anhänge anzeigen (Anzahl: 1)
OK, hoffe das klappt jetzt :wtf:

Larusso 05.06.2014 16:16

Hy.
Sorry für die kurze,knappe Antwort. Handy halt :D

Wenn du im Mediaplayer was startest, siehst du dann unter Speakers einen grünen Balken auf und ab gehen ?
Zitat:

Ich habe mir von Medion die aktuellen Treiber runtergeladen
Ich hätte dazu gerne den Link was du dir herunter geladen hast.


Downloade dir bitte Farbar Service Scanner Farbar Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.

Poste bitte den Inhalt hier.



Nirtaka 05.06.2014 20:33

Hey :)

Die grünen Balken bewegen sich beim Speaker ganz normal, auch wenn der Ton weggeht und das Lied weiterläuft.

Wegen der Treiber bin ich einfach auf die Medion-Homepage gegangen und hab was runtergeladen, ich habe auch keinen Plan ob das die richtigen waren, habe da auch wirklich null Ahnung von:hxxp://www.medion.com/de/service/_lightbox/treiber.php?msn=10010251

Wenn du genau wissen willst welche Treiber es waren, gibts da iwie n Trick, wo letzte Downloads angezeigt werden? Ich erkenne die Dateien iwie nicht mehr :balla:

Der Rest folgt gleich..
LG

Larusso 05.06.2014 20:56

Okay, unter diesem Link is genau nichts für dein Betriebssystem.

Nachdem die FSS Logfile erstellt wurde bitte

Die Windows + R Taste drücken. In die Befehlszeile dxdiag eingeben und OK klicken
In den Reiter System wechseln und auf Informationen speichern klicken.
Speichere die .txt Datei auf dem Desktop und poste mir den Inhalt.

Das selbe bitte mit dem Reiter SOund.


Wenn da dann auch alles I.O ist wirds knifflig und wahrscheinlich irgendwas verbogen :/

Nirtaka 05.06.2014 21:04

Code:

Farbar Service Scanner Version: 21-05-2014
Ran by Kati (administrator) on 05-06-2014 at 21:38:04
Running from "C:\Users\Kati\Downloads"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****


Code:

Farbar Service Scanner Version: 21-05-2014
Ran by Kati (administrator) on 05-06-2014 at 21:38:04
Running from "C:\Users\Kati\Downloads"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****


SOUND1:

Code:

------------------
System Information
------------------
Time of this report: 6/5/2014, 22:04:56
      Machine name: KATI-PC
  Operating System: Windows 7 Home Premium 64-bit (6.1, Build 7601) Service Pack 1 (7601.win7sp1_gdr.140303-2144)
          Language: German (Regional Setting: German)
System Manufacturer: Medion
      System Model: E7219
              BIOS: BIOS Date: 10/25/11 09:34:46 Ver: 04.06.03
          Processor: Intel(R) Pentium(R) CPU B960 @ 2.20GHz (2 CPUs), ~2.2GHz
            Memory: 4096MB RAM
Available OS Memory: 4008MB RAM
          Page File: 1982MB used, 6029MB available
        Windows Dir: C:\Windows
    DirectX Version: DirectX 11
DX Setup Parameters: Not found
  User DPI Setting: Using System DPI
 System DPI Setting: 96 DPI (100 percent)
    DWM DPI Scaling: Disabled
    DxDiag Version: 6.01.7601.17514 32bit Unicode

------------
DxDiag Notes
------------
      Display Tab 1: No problems found.
        Sound Tab 1: No problems found.
        Sound Tab 2: No problems found.
          Input Tab: No problems found.

--------------------
DirectX Debug Levels
--------------------
Direct3D:    0/4 (retail)
DirectDraw:  0/4 (retail)
DirectInput: 0/5 (retail)
DirectMusic: 0/5 (retail)
DirectPlay:  0/9 (retail)
DirectSound: 0/5 (retail)
DirectShow:  0/6 (retail)

---------------
Display Devices
---------------
          Card name: Intel(R) HD Graphics
      Manufacturer: Intel Corporation
          Chip type: Intel(R) HD Graphics Family
          DAC type: Internal
        Device Key: Enum\PCI\VEN_8086&DEV_0106&SUBSYS_20801B0A&REV_09
    Display Memory: 1696 MB
  Dedicated Memory: 64 MB
      Shared Memory: 1632 MB
      Current Mode: 1600 x 900 (32 bit) (60Hz)
      Monitor Name: PnP-Monitor (Standard)
      Monitor Model: unknown
        Monitor Id: AUO129E
        Native Mode: 1600 x 900(p) (60.307Hz)
        Output Type: Internal
        Driver Name: igdumd64.dll,igd10umd64.dll,igd10umd64.dll,igdumd32,igd10umd32,igd10umd32
Driver File Version: 9.17.0010.3347 (English)
    Driver Version: 9.17.10.3347
        DDI Version: 10.1
      Driver Model: WDDM 1.1
  Driver Attributes: Final Retail
  Driver Date/Size: 11/7/2013 02:52:50, 12617216 bytes
        WHQL Logo'd: Yes
    WHQL Date Stamp:
  Device Identifier: {D7B78E66-4246-11CF-A975-8A00B7C2C435}
          Vendor ID: 0x8086
          Device ID: 0x0106
          SubSys ID: 0x20801B0A
        Revision ID: 0x0009
 Driver Strong Name: oem85.inf:Intel.Mfg.NTamd64:iSNBM0:9.17.10.3347:pci\ven_8086&dev_0106
    Rank Of Driver: 00E02001
        Video Accel: ModeMPEG2_A ModeMPEG2_C ModeWMV9_C ModeVC1_C
  Deinterlace Caps: {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
      D3D9 Overlay: Supported
            DXVA-HD: Supported
      DDraw Status: Enabled
        D3D Status: Enabled
        AGP Status: Enabled

-------------
Sound Devices
-------------
            Description: Speakers (Conexant SmartAudio HD)
 Default Sound Playback: Yes
 Default Voice Playback: Yes
            Hardware ID: HDAUDIO\FUNC_01&VEN_14F1&DEV_5069&SUBSYS_1B0A20AF&REV_1003
        Manufacturer ID: 1
            Product ID: 100
                  Type: WDM
            Driver Name: CHDRT64.sys
        Driver Version: 8.54.0014.0000 (German)
      Driver Attributes: Final Retail
            WHQL Logo'd: Yes
          Date and Size: 5/26/2011 09:24:16, 1590912 bytes
            Other Files:
        Driver Provider: Conexant
        HW Accel Level: Basic
              Cap Flags: 0xF1F
    Min/Max Sample Rate: 100, 200000
Static/Strm HW Mix Bufs: 1, 0
 Static/Strm HW 3D Bufs: 0, 0
              HW Memory: 0
      Voice Management: No
 EAX(tm) 2.0 Listen/Src: No, No
  I3DL2(tm) Listen/Src: No, No
Sensaura(tm) ZoomFX(tm): No

            Description: SPDIF Interface (Conexant SmartAudio HD)
 Default Sound Playback: No
 Default Voice Playback: No
            Hardware ID: HDAUDIO\FUNC_01&VEN_14F1&DEV_5069&SUBSYS_1B0A20AF&REV_1003
        Manufacturer ID: 1
            Product ID: 100
                  Type: WDM
            Driver Name: CHDRT64.sys
        Driver Version: 8.54.0014.0000 (German)
      Driver Attributes: Final Retail
            WHQL Logo'd: Yes
          Date and Size: 5/26/2011 09:24:16, 1590912 bytes
            Other Files:
        Driver Provider: Conexant
        HW Accel Level: Basic
              Cap Flags: 0xF1F
    Min/Max Sample Rate: 100, 200000
Static/Strm HW Mix Bufs: 1, 0
 Static/Strm HW 3D Bufs: 0, 0
              HW Memory: 0
      Voice Management: No
 EAX(tm) 2.0 Listen/Src: No, No
  I3DL2(tm) Listen/Src: No, No
Sensaura(tm) ZoomFX(tm): No

---------------------
Sound Capture Devices
---------------------
            Description: Internal Microphone (Conexant SmartAudio HD)
  Default Sound Capture: Yes
  Default Voice Capture: Yes
            Driver Name: CHDRT64.sys
        Driver Version: 8.54.0014.0000 (German)
      Driver Attributes: Final Retail
          Date and Size: 5/26/2011 09:24:16, 1590912 bytes
              Cap Flags: 0x1
          Format Flags: 0xFFFFF

-------------------
DirectInput Devices
-------------------
      Device Name: Maus
        Attached: 1
    Controller ID: n/a
Vendor/Product ID: n/a
        FF Driver: n/a

      Device Name: Tastatur
        Attached: 1
    Controller ID: n/a
Vendor/Product ID: n/a
        FF Driver: n/a

Poll w/ Interrupt: No

-----------
USB Devices
-----------
+ USB-Root-Hub
| Vendor/Product ID: 0x8086, 0x1C26
| Matching Device ID: usb\root_hub20
| Service: usbhub
|
+-+ Generic USB Hub
| | Vendor/Product ID: 0x8087, 0x0024
| | Location: Port_#0001.Hub_#0002
| | Matching Device ID: usb\class_09
| | Service: usbhub

----------------
Gameport Devices
----------------

------------
PS/2 Devices
------------
+ Standardtastatur (PS/2)
| Matching Device ID: *pnp0303
| Service: i8042prt
|
+ Terminalserver-Tastaturtreiber
| Matching Device ID: root\rdp_kbd
| Upper Filters: kbdclass
| Service: TermDD
|
+ PS/2-kompatible Maus
| Matching Device ID: *pnp0f13
| Service: i8042prt
|
+ Terminalserver-Maustreiber
| Matching Device ID: root\rdp_mou
| Upper Filters: mouclass
| Service: TermDD

------------------------
Disk & DVD/CD-ROM Drives
------------------------
      Drive: C:
 Free Space: 336.5 GB
Total Space: 424.6 GB
File System: NTFS
      Model: ST9500325AS

      Drive: D:
 Free Space: 0.0 GB
Total Space: 51.2 GB
File System: NTFS
      Model: ST9500325AS

      Drive: Q:
      Model: n/a

      Drive: E:
      Model: HL-DT-ST DVDRAM GT60N
    Driver: c:\windows\system32\drivers\cdrom.sys, 6.01.7601.17514 (German), , 0 bytes

--------------
System Devices
--------------
    Name: Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 6 - 1C1A
Device ID: PCI\VEN_8086&DEV_1C1A&SUBSYS_20941B0A&REV_B5\3&11583659&0&E5
  Driver: n/a

    Name: Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
Device ID: PCI\VEN_1969&DEV_1083&SUBSYS_208D1B0A&REV_C0\4&1103D9C7&0&00E5
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 4 - 1C16
Device ID: PCI\VEN_8086&DEV_1C16&SUBSYS_20941B0A&REV_B5\3&11583659&0&E3
  Driver: n/a

    Name: Renesas Electronics USB 3.0 Host Controller
Device ID: PCI\VEN_1033&DEV_0194&SUBSYS_20931B0A&REV_04\4&34F9DAD2&0&00E3
  Driver: n/a

    Name: Intel(R) HM65 Express Chipset Family LPC Interface Controller - 1C49
Device ID: PCI\VEN_8086&DEV_1C49&SUBSYS_20941B0A&REV_05\3&11583659&0&F8
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 2 - 1C12
Device ID: PCI\VEN_8086&DEV_1C12&SUBSYS_20941B0A&REV_B5\3&11583659&0&E1
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Management Engine Interface - 1C3A
Device ID: PCI\VEN_8086&DEV_1C3A&SUBSYS_20941B0A&REV_04\3&11583659&0&B0
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 1 - 1C10
Device ID: PCI\VEN_8086&DEV_1C10&SUBSYS_20941B0A&REV_B5\3&11583659&0&E0
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family USB Enhanced Host Controller - 1C2D
Device ID: PCI\VEN_8086&DEV_1C2D&SUBSYS_20941B0A&REV_05\3&11583659&0&D0
  Driver: n/a

    Name: Intel(R) Mobile Express Chipset SATA AHCI Controller
Device ID: PCI\VEN_8086&DEV_1C03&SUBSYS_20941B0A&REV_05\3&11583659&0&FA
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family USB Enhanced Host Controller - 1C26
Device ID: PCI\VEN_8086&DEV_1C26&SUBSYS_20941B0A&REV_05\3&11583659&0&E8
  Driver: n/a

    Name: Intel(R) Centrino(R) Wireless-N 100
Device ID: PCI\VEN_8086&DEV_08AE&SUBSYS_10058086&REV_00\4&25CFAFF5&0&00E1
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family SMBus Controller - 1C22
Device ID: PCI\VEN_8086&DEV_1C22&SUBSYS_20941B0A&REV_05\3&11583659&0&FB
  Driver: n/a

    Name: Intel(R) HD Graphics
Device ID: PCI\VEN_8086&DEV_0106&SUBSYS_20801B0A&REV_09\3&11583659&0&10
  Driver: n/a

    Name: High Definition Audio-Controller
Device ID: PCI\VEN_8086&DEV_1C20&SUBSYS_20AF1B0A&REV_05\3&11583659&0&D8
  Driver: n/a

    Name: 2nd generation Intel(R) Core(TM) processor family DRAM Controller - 0104
Device ID: PCI\VEN_8086&DEV_0104&SUBSYS_20941B0A&REV_09\3&11583659&0&00
  Driver: n/a

------------------
DirectShow Filters
------------------

DirectShow Filters:
WMAudio Decoder DMO,0x00800800,1,1,WMADMOD.DLL,6.01.7601.17514
WMAPro over S/PDIF DMO,0x00600800,1,1,WMADMOD.DLL,6.01.7601.17514
WMSpeech Decoder DMO,0x00600800,1,1,WMSPDMOD.DLL,6.01.7601.17514
MP3 Decoder DMO,0x00600800,1,1,mp3dmod.dll,6.01.7600.16385
Mpeg4s Decoder DMO,0x00800001,1,1,mp4sdecd.dll,6.01.7600.16385
WMV Screen decoder DMO,0x00600800,1,1,wmvsdecd.dll,6.01.7601.17514
WMVideo Decoder DMO,0x00800001,1,1,wmvdecod.dll,6.01.7601.18221
Mpeg43 Decoder DMO,0x00800001,1,1,mp43decd.dll,6.01.7600.16385
Mpeg4 Decoder DMO,0x00800001,1,1,mpg4decd.dll,6.01.7600.16385
Xiph.Org Vorbis Decoder,0x00600000,1,1,dsfVorbisDecoder.dll,
WMT VIH2 Fix,0x00200000,1,1,WLXVAFilt.dll,15.04.3508.1109
Record Queue,0x00200000,1,1,WLXVAFilt.dll,15.04.3508.1109
WMT Switch Filter,0x00200000,1,1,WLXVAFilt.dll,15.04.3508.1109
WMT Virtual Renderer,0x00200000,1,0,WLXVAFilt.dll,15.04.3508.1109
WMT DV Extract,0x00200000,1,1,WLXVAFilt.dll,15.04.3508.1109
WMT Virtual Source,0x00200000,0,1,WLXVAFilt.dll,15.04.3508.1109
WMT Sample Information Filter,0x00200000,1,1,WLXVAFilt.dll,15.04.3508.1109
Sony CF DXVA AVC Decoder,0x00800000,1,1,sjvtdfcf.ax,2.00.0114.9020
CyberLink MP3/WAV Wrapper,0x00200000,1,1,P2GMP3Wrap.ax,3.07.0000.1314
DV Muxer,0x00400000,0,0,qdv.dll,6.06.7601.17514
CyberLink AudioCD Filter,0x00200000,0,1,P2GAudioCD.ax,5.00.0000.1321
Color Space Converter,0x00400001,1,1,quartz.dll,6.06.7601.17713
WM ASF Reader,0x00400000,0,0,qasf.dll,12.00.7601.17514
Screen Capture filter,0x00200000,0,1,wmpsrcwp.dll,12.00.7601.17514
AVI Splitter,0x00600000,1,1,quartz.dll,6.06.7601.17713
VGA 16 Color Ditherer,0x00400000,1,1,quartz.dll,6.06.7601.17713
SBE2MediaTypeProfile,0x00200000,0,0,sbe.dll,6.06.7601.17528
Microsoft DTV-DVD Video Decoder,0x005fffff,2,4,msmpeg2vdec.dll,12.00.9200.16426
MPC - RealVideo Decoder,0x00600000,1,1,RealMediaSplitter.ax,1.03.1572.0000
AC3 Parser Filter,0x00600000,1,1,mpg2splt.ax,6.06.7601.17528
Sony CF IntelVA AVC Decoder,0x00800000,1,1,sjvtdfcf.ax,2.00.0114.9020
StreamBufferSink,0x00200000,0,0,sbe.dll,6.06.7601.17528
MJPEG Decompressor,0x00600000,1,1,quartz.dll,6.06.7601.17713
MPEG-I Stream Splitter,0x00600000,1,2,quartz.dll,6.06.7601.17713
SAMI (CC) Parser,0x00400000,1,1,quartz.dll,6.06.7601.17713
VBI Codec,0x00600000,1,4,VBICodec.ax,6.06.7601.17514
MPEG-2 Splitter,0x005fffff,1,0,mpg2splt.ax,6.06.7601.17528
Closed Captions Analysis Filter,0x00200000,2,5,cca.dll,6.06.7601.17514
Sony CF AVC Decoder,0x00800000,1,1,sjvtdfcf.ax,2.00.0114.9020
SBE2FileScan,0x00200000,0,0,sbe.dll,6.06.7601.17528
Microsoft MPEG-2 Video Encoder,0x00200000,1,1,msmpeg2enc.dll,6.01.7601.17514
Sony CF MP4 File Source,0x00800000,0,1,MP4FileSource.ax,2.00.0114.9020
Internal Script Command Renderer,0x00800001,1,0,quartz.dll,6.06.7601.17713
CyberLink Video Regulator,0x00200000,1,1,P2GRGL.ax,2.00.0000.3328
MPEG Audio Decoder,0x03680001,1,1,quartz.dll,6.06.7601.17713
DV Splitter,0x00600000,1,2,qdv.dll,6.06.7601.17514
Video Mixing Renderer 9,0x00200000,1,0,quartz.dll,6.06.7601.17713
Xiph.Org Vorbis Encoder,0x00200000,1,1,dsfVorbisEncoder.dll,
CyberLink Audio Noise Reduction,0x00200000,1,1,P2GAuNRWrapper.ax,2.00.0000.1017
Microsoft MPEG-2 Encoder,0x00200000,2,1,msmpeg2enc.dll,6.01.7601.17514
CyberLink Audio VolumeBooster,0x00200000,1,1,P2GVB.ax,1.00.0000.1008
ACM Wrapper,0x00600000,1,1,quartz.dll,6.06.7601.17713
Video Renderer,0x00800001,1,0,quartz.dll,6.06.7601.17713
MPEG-2 Video Stream Analyzer,0x00200000,0,0,sbe.dll,6.06.7601.17528
Line 21 Decoder,0x00600000,1,1,qdvd.dll,6.06.7601.17835
Video Port Manager,0x00600000,2,1,quartz.dll,6.06.7601.17713
CyberLink Line21 Decoder Filter (PDC 1.0),0x00200000,0,2,CLLine21.ax,4.00.0000.3924
Video Renderer,0x00400000,1,0,quartz.dll,6.06.7601.17713
CyberLink Audio Resampler,0x00200000,1,1,P2GAuRsmpl.ax,1.00.0000.2625
MPC - RealMedia Source,0x00600000,0,0,RealMediaSplitter.ax,1.03.1572.0000
File Writer,0x00200000,1,0,WLXVAFilt.dll,15.04.3508.1109
VPS Decoder,0x00200000,0,0,WSTPager.ax,6.06.7601.17514
WM ASF Writer,0x00400000,0,0,qasf.dll,12.00.7601.17514
VBI Surface Allocator,0x00600000,1,1,vbisurf.ax,6.01.7601.17514
CuttlefishSubtitleParser Filter,0x00200000,1,1,CuttlefishSubtitleParser.ax,2.00.0114.9020
CyberLink DVD Navigator (PDC 1.0),0x00200000,0,3,CLNavX.ax,6.00.0000.1321
File writer,0x00200000,1,0,qcap.dll,6.06.7601.17514
Sony CF AAC decoder,0x00600000,1,1,cfaac.ax,2.00.0114.9020
iTV Data Sink,0x00600000,1,0,itvdata.dll,6.06.7601.17514
iTV Data Capture filter,0x00600000,1,1,itvdata.dll,6.06.7601.17514
Cyberlink File Reader (Async.),0x00200000,0,1,P2GReader.ax,3.00.0000.3016
MPC - RealAudio Decoder,0x00600000,1,1,RealMediaSplitter.ax,1.03.1572.0000
CyberLink PCM Wrapper,0x00200000,1,1,P2GPCMEnc.ax,1.01.0000.0321
DVD Navigator,0x00200000,0,3,qdvd.dll,6.06.7601.17835
Overlay Mixer2,0x00200000,1,1,qdvd.dll,6.06.7601.17835
AVI Draw,0x00600064,9,1,quartz.dll,6.06.7601.17713
RDP DShow Redirection Filter,0xffffffff,1,0,DShowRdpFilter.dll,
Microsoft MPEG-2 Audio Encoder,0x00200000,1,1,msmpeg2enc.dll,6.01.7601.17514
WST Pager,0x00200000,1,1,WSTPager.ax,6.06.7601.17514
MPEG-2 Demultiplexer,0x00600000,1,1,mpg2splt.ax,6.06.7601.17528
DV Video Decoder,0x00800000,1,1,qdv.dll,6.06.7601.17514
SampleGrabber,0x00200000,1,1,qedit.dll,6.06.7601.18386
Null Renderer,0x00200000,1,0,qedit.dll,6.06.7601.18386
MPEG-2 Sections and Tables,0x005fffff,1,0,Mpeg2Data.ax,6.06.7601.17514
Microsoft AC3 Encoder,0x00200000,1,1,msac3enc.dll,6.01.7601.17514
StreamBufferSource,0x00200000,0,0,sbe.dll,6.06.7601.17528
Smart Tee,0x00200000,1,2,qcap.dll,6.06.7601.17514
Overlay Mixer,0x00200000,0,0,qdvd.dll,6.06.7601.17835
AVI Decompressor,0x00600000,1,1,quartz.dll,6.06.7601.17713
AVI/WAV File Source,0x00400000,0,2,quartz.dll,6.06.7601.17713
Wave Parser,0x00400000,1,1,quartz.dll,6.06.7601.17713
MIDI Parser,0x00400000,1,1,quartz.dll,6.06.7601.17713
Multi-file Parser,0x00400000,1,1,quartz.dll,6.06.7601.17713
File stream renderer,0x00400000,1,1,quartz.dll,6.06.7601.17713
CuttlefishClosedCaption Filter,0x00400000,1,1,CuttlefishSubtitleParser.ax,2.00.0114.9020
Microsoft DTV-DVD Audio Decoder,0x005fffff,1,1,msmpeg2adec.dll,6.01.7140.0000
MPC - RealMedia Splitter,0x00600000,1,1,RealMediaSplitter.ax,1.03.1572.0000
StreamBufferSink2,0x00200000,0,0,sbe.dll,6.06.7601.17528
AVI Mux,0x00200000,1,0,qcap.dll,6.06.7601.17514
Line 21 Decoder 2,0x00600002,1,1,quartz.dll,6.06.7601.17713
File Source (Async.),0x00400000,0,1,quartz.dll,6.06.7601.17713
File Source (URL),0x00400000,0,1,quartz.dll,6.06.7601.17713
PDC Video Decoder,0x00200000,2,3,CLVSD.ax,5.00.0000.3009
P2G Audio Encoder,0x00200000,2,0,P2GAudEnc.ax,2.00.0000.4815
Infinite Pin Tee Filter,0x00200000,1,1,qcap.dll,6.06.7601.17514
Enhanced Video Renderer,0x00200000,1,0,evr.dll,6.01.7601.17514
BDA MPEG2 Transport Information Filter,0x00200000,2,0,psisrndr.ax,6.06.7601.17669
MPEG Video Decoder,0x40000001,1,1,quartz.dll,6.06.7601.17713

WDM Streaming Tee/Splitter Devices:
Tee/Sink-to-Sink-Konvertierung,0x00200000,1,1,ksproxy.ax,6.01.7601.17514

Video Compressors:
WMVideo8 Encoder DMO,0x00600800,1,1,wmvxencd.dll,6.01.7600.16385
WMVideo9 Encoder DMO,0x00600800,1,1,wmvencod.dll,6.01.7600.16385
MSScreen 9 encoder DMO,0x00600800,1,1,wmvsencd.dll,6.01.7600.16385
DV Video Encoder,0x00200000,0,0,qdv.dll,6.06.7601.17514
MJPEG Compressor,0x00200000,0,0,quartz.dll,6.06.7601.17713
Cinepak Codec von Radius,0x00200000,1,1,qcap.dll,6.06.7601.17514
Intel IYUV Codec,0x00200000,1,1,qcap.dll,6.06.7601.17514
Intel IYUV Codec,0x00200000,1,1,qcap.dll,6.06.7601.17514
Microsoft RLE,0x00200000,1,1,qcap.dll,6.06.7601.17514
Microsoft Video 1,0x00200000,1,1,qcap.dll,6.06.7601.17514

Audio Compressors:
WM Speech Encoder DMO,0x00600800,1,1,WMSPDMOE.DLL,6.01.7600.16385
WMAudio Encoder DMO,0x00600800,1,1,WMADMOE.DLL,6.01.7600.16385
Xiph.Org Vorbis Encoder,0x00200000,1,1,dsfVorbisEncoder.dll,
IMA ADPCM,0x00200000,1,1,quartz.dll,6.06.7601.17713
PCM,0x00200000,1,1,quartz.dll,6.06.7601.17713
Microsoft ADPCM,0x00200000,1,1,quartz.dll,6.06.7601.17713
GSM 6.10,0x00200000,1,1,quartz.dll,6.06.7601.17713
Messenger Audio Codec,0x00200000,1,1,quartz.dll,6.06.7601.17713
CCITT A-Law,0x00200000,1,1,quartz.dll,6.06.7601.17713
CCITT u-Law,0x00200000,1,1,quartz.dll,6.06.7601.17713
MPEG Layer-3,0x00200000,1,1,quartz.dll,6.06.7601.17713

Audio Capture Sources:
Internal Microphone (Conexant S,0x00200000,0,0,qcap.dll,6.06.7601.17514

PBDA CP Filters:
PBDA DTFilter,0x00600000,1,1,CPFilters.dll,6.06.7601.17528
PBDA ETFilter,0x00200000,0,0,CPFilters.dll,6.06.7601.17528
PBDA PTFilter,0x00200000,0,0,CPFilters.dll,6.06.7601.17528

Midi Renderers:
Default MidiOut Device,0x00800000,1,0,quartz.dll,6.06.7601.17713
Microsoft GS Wavetable Synth,0x00200000,1,0,quartz.dll,6.06.7601.17713

WDM Streaming Capture Devices:
Conexant HD Audio capture,0x00200000,1,1,ksproxy.ax,6.01.7601.17514
,0x00000000,0,0,,
,0x00000000,0,0,,
USB2.0 UVC 1.3M Webcam,0x00200000,1,2,ksproxy.ax,6.01.7601.17514

WDM Streaming Rendering Devices:
,0x00000000,0,0,,
Conexant HD Audio digital out,0x00200000,1,1,ksproxy.ax,6.01.7601.17514
Conexant HD Audio output,0x00200000,1,1,ksproxy.ax,6.01.7601.17514

BDA Network Providers:
Microsoft ATSC Network Provider,0x00200000,0,1,MSDvbNP.ax,6.06.7601.17514
Microsoft DVBC Network Provider,0x00200000,0,1,MSDvbNP.ax,6.06.7601.17514
Microsoft DVBS Network Provider,0x00200000,0,1,MSDvbNP.ax,6.06.7601.17514
Microsoft DVBT Network Provider,0x00200000,0,1,MSDvbNP.ax,6.06.7601.17514
Microsoft Network Provider,0x00200000,0,1,MSNP.ax,6.06.7601.17514

Video Capture Sources:
USB2.0 UVC 1.3M Webcam,0x00200000,1,2,ksproxy.ax,6.01.7601.17514

Multi-Instance Capable VBI Codecs:
VBI Codec,0x00600000,1,4,VBICodec.ax,6.06.7601.17514

BDA Transport Information Renderers:
BDA MPEG2 Transport Information Filter,0x00600000,2,0,psisrndr.ax,6.06.7601.17669
MPEG-2 Sections and Tables,0x00600000,1,0,Mpeg2Data.ax,6.06.7601.17514

BDA CP/CA Filters:
Decrypt/Tag,0x00600000,1,1,EncDec.dll,6.06.7601.17708
Encrypt/Tag,0x00200000,0,0,EncDec.dll,6.06.7601.17708
PTFilter,0x00200000,0,0,EncDec.dll,6.06.7601.17708
XDS Codec,0x00200000,0,0,EncDec.dll,6.06.7601.17708

WDM Streaming Communication Transforms:
Tee/Sink-to-Sink-Konvertierung,0x00200000,1,1,ksproxy.ax,6.01.7601.17514

Audio Renderers:
Speakers (Conexant SmartAudio H,0x00200000,1,0,quartz.dll,6.06.7601.17713
Default DirectSound Device,0x00800000,1,0,quartz.dll,6.06.7601.17713
Default WaveOut Device,0x00200000,1,0,quartz.dll,6.06.7601.17713
DirectSound: SPDIF Interface (Conexant SmartAudio HD),0x00200000,1,0,quartz.dll,6.06.7601.17713
DirectSound: Speakers (Conexant SmartAudio HD),0x00200000,1,0,quartz.dll,6.06.7601.17713
SPDIF Interface (Conexant Smart,0x00200000,1,0,quartz.dll,6.06.7601.17713

---------------
EVR Power Information
---------------
Current Setting: {5C67A112-A4C9-483F-B4A7-1D473BECAFDC} (Quality)
  Quality Flags: 2576
    Enabled:
    Force throttling
    Allow half deinterlace
    Allow scaling
    Decode Power Usage: 100
  Balanced Flags: 1424
    Enabled:
    Force throttling
    Allow batching
    Force half deinterlace
    Force scaling
    Decode Power Usage: 50
  PowerFlags: 1424
    Enabled:
    Force throttling
    Allow batching
    Force half deinterlace
    Force scaling
    Decode Power Usage: 0


SOUND2:

Code:

------------------
System Information
------------------
Time of this report: 6/5/2014, 22:04:56
      Machine name: KATI-PC
  Operating System: Windows 7 Home Premium 64-bit (6.1, Build 7601) Service Pack 1 (7601.win7sp1_gdr.140303-2144)
          Language: German (Regional Setting: German)
System Manufacturer: Medion
      System Model: E7219
              BIOS: BIOS Date: 10/25/11 09:34:46 Ver: 04.06.03
          Processor: Intel(R) Pentium(R) CPU B960 @ 2.20GHz (2 CPUs), ~2.2GHz
            Memory: 4096MB RAM
Available OS Memory: 4008MB RAM
          Page File: 1982MB used, 6029MB available
        Windows Dir: C:\Windows
    DirectX Version: DirectX 11
DX Setup Parameters: Not found
  User DPI Setting: Using System DPI
 System DPI Setting: 96 DPI (100 percent)
    DWM DPI Scaling: Disabled
    DxDiag Version: 6.01.7601.17514 32bit Unicode

------------
DxDiag Notes
------------
      Display Tab 1: No problems found.
        Sound Tab 1: No problems found.
        Sound Tab 2: No problems found.
          Input Tab: No problems found.

--------------------
DirectX Debug Levels
--------------------
Direct3D:    0/4 (retail)
DirectDraw:  0/4 (retail)
DirectInput: 0/5 (retail)
DirectMusic: 0/5 (retail)
DirectPlay:  0/9 (retail)
DirectSound: 0/5 (retail)
DirectShow:  0/6 (retail)

---------------
Display Devices
---------------
          Card name: Intel(R) HD Graphics
      Manufacturer: Intel Corporation
          Chip type: Intel(R) HD Graphics Family
          DAC type: Internal
        Device Key: Enum\PCI\VEN_8086&DEV_0106&SUBSYS_20801B0A&REV_09
    Display Memory: 1696 MB
  Dedicated Memory: 64 MB
      Shared Memory: 1632 MB
      Current Mode: 1600 x 900 (32 bit) (60Hz)
      Monitor Name: PnP-Monitor (Standard)
      Monitor Model: unknown
        Monitor Id: AUO129E
        Native Mode: 1600 x 900(p) (60.307Hz)
        Output Type: Internal
        Driver Name: igdumd64.dll,igd10umd64.dll,igd10umd64.dll,igdumd32,igd10umd32,igd10umd32
Driver File Version: 9.17.0010.3347 (English)
    Driver Version: 9.17.10.3347
        DDI Version: 10.1
      Driver Model: WDDM 1.1
  Driver Attributes: Final Retail
  Driver Date/Size: 11/7/2013 02:52:50, 12617216 bytes
        WHQL Logo'd: Yes
    WHQL Date Stamp:
  Device Identifier: {D7B78E66-4246-11CF-A975-8A00B7C2C435}
          Vendor ID: 0x8086
          Device ID: 0x0106
          SubSys ID: 0x20801B0A
        Revision ID: 0x0009
 Driver Strong Name: oem85.inf:Intel.Mfg.NTamd64:iSNBM0:9.17.10.3347:pci\ven_8086&dev_0106
    Rank Of Driver: 00E02001
        Video Accel: ModeMPEG2_A ModeMPEG2_C ModeWMV9_C ModeVC1_C
  Deinterlace Caps: {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
                    {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
                    {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
                    {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
      D3D9 Overlay: Supported
            DXVA-HD: Supported
      DDraw Status: Enabled
        D3D Status: Enabled
        AGP Status: Enabled

-------------
Sound Devices
-------------
            Description: Speakers (Conexant SmartAudio HD)
 Default Sound Playback: Yes
 Default Voice Playback: Yes
            Hardware ID: HDAUDIO\FUNC_01&VEN_14F1&DEV_5069&SUBSYS_1B0A20AF&REV_1003
        Manufacturer ID: 1
            Product ID: 100
                  Type: WDM
            Driver Name: CHDRT64.sys
        Driver Version: 8.54.0014.0000 (German)
      Driver Attributes: Final Retail
            WHQL Logo'd: Yes
          Date and Size: 5/26/2011 09:24:16, 1590912 bytes
            Other Files:
        Driver Provider: Conexant
        HW Accel Level: Basic
              Cap Flags: 0xF1F
    Min/Max Sample Rate: 100, 200000
Static/Strm HW Mix Bufs: 1, 0
 Static/Strm HW 3D Bufs: 0, 0
              HW Memory: 0
      Voice Management: No
 EAX(tm) 2.0 Listen/Src: No, No
  I3DL2(tm) Listen/Src: No, No
Sensaura(tm) ZoomFX(tm): No

            Description: SPDIF Interface (Conexant SmartAudio HD)
 Default Sound Playback: No
 Default Voice Playback: No
            Hardware ID: HDAUDIO\FUNC_01&VEN_14F1&DEV_5069&SUBSYS_1B0A20AF&REV_1003
        Manufacturer ID: 1
            Product ID: 100
                  Type: WDM
            Driver Name: CHDRT64.sys
        Driver Version: 8.54.0014.0000 (German)
      Driver Attributes: Final Retail
            WHQL Logo'd: Yes
          Date and Size: 5/26/2011 09:24:16, 1590912 bytes
            Other Files:
        Driver Provider: Conexant
        HW Accel Level: Basic
              Cap Flags: 0xF1F
    Min/Max Sample Rate: 100, 200000
Static/Strm HW Mix Bufs: 1, 0
 Static/Strm HW 3D Bufs: 0, 0
              HW Memory: 0
      Voice Management: No
 EAX(tm) 2.0 Listen/Src: No, No
  I3DL2(tm) Listen/Src: No, No
Sensaura(tm) ZoomFX(tm): No

---------------------
Sound Capture Devices
---------------------
            Description: Internal Microphone (Conexant SmartAudio HD)
  Default Sound Capture: Yes
  Default Voice Capture: Yes
            Driver Name: CHDRT64.sys
        Driver Version: 8.54.0014.0000 (German)
      Driver Attributes: Final Retail
          Date and Size: 5/26/2011 09:24:16, 1590912 bytes
              Cap Flags: 0x1
          Format Flags: 0xFFFFF

-------------------
DirectInput Devices
-------------------
      Device Name: Maus
        Attached: 1
    Controller ID: n/a
Vendor/Product ID: n/a
        FF Driver: n/a

      Device Name: Tastatur
        Attached: 1
    Controller ID: n/a
Vendor/Product ID: n/a
        FF Driver: n/a

Poll w/ Interrupt: No

-----------
USB Devices
-----------
+ USB-Root-Hub
| Vendor/Product ID: 0x8086, 0x1C26
| Matching Device ID: usb\root_hub20
| Service: usbhub
|
+-+ Generic USB Hub
| | Vendor/Product ID: 0x8087, 0x0024
| | Location: Port_#0001.Hub_#0002
| | Matching Device ID: usb\class_09
| | Service: usbhub

----------------
Gameport Devices
----------------

------------
PS/2 Devices
------------
+ Standardtastatur (PS/2)
| Matching Device ID: *pnp0303
| Service: i8042prt
|
+ Terminalserver-Tastaturtreiber
| Matching Device ID: root\rdp_kbd
| Upper Filters: kbdclass
| Service: TermDD
|
+ PS/2-kompatible Maus
| Matching Device ID: *pnp0f13
| Service: i8042prt
|
+ Terminalserver-Maustreiber
| Matching Device ID: root\rdp_mou
| Upper Filters: mouclass
| Service: TermDD

------------------------
Disk & DVD/CD-ROM Drives
------------------------
      Drive: C:
 Free Space: 336.5 GB
Total Space: 424.6 GB
File System: NTFS
      Model: ST9500325AS

      Drive: D:
 Free Space: 0.0 GB
Total Space: 51.2 GB
File System: NTFS
      Model: ST9500325AS

      Drive: Q:
      Model: n/a

      Drive: E:
      Model: HL-DT-ST DVDRAM GT60N
    Driver: c:\windows\system32\drivers\cdrom.sys, 6.01.7601.17514 (German), , 0 bytes

--------------
System Devices
--------------
    Name: Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 6 - 1C1A
Device ID: PCI\VEN_8086&DEV_1C1A&SUBSYS_20941B0A&REV_B5\3&11583659&0&E5
  Driver: n/a

    Name: Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
Device ID: PCI\VEN_1969&DEV_1083&SUBSYS_208D1B0A&REV_C0\4&1103D9C7&0&00E5
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 4 - 1C16
Device ID: PCI\VEN_8086&DEV_1C16&SUBSYS_20941B0A&REV_B5\3&11583659&0&E3
  Driver: n/a

    Name: Renesas Electronics USB 3.0 Host Controller
Device ID: PCI\VEN_1033&DEV_0194&SUBSYS_20931B0A&REV_04\4&34F9DAD2&0&00E3
  Driver: n/a

    Name: Intel(R) HM65 Express Chipset Family LPC Interface Controller - 1C49
Device ID: PCI\VEN_8086&DEV_1C49&SUBSYS_20941B0A&REV_05\3&11583659&0&F8
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 2 - 1C12
Device ID: PCI\VEN_8086&DEV_1C12&SUBSYS_20941B0A&REV_B5\3&11583659&0&E1
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Management Engine Interface - 1C3A
Device ID: PCI\VEN_8086&DEV_1C3A&SUBSYS_20941B0A&REV_04\3&11583659&0&B0
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 1 - 1C10
Device ID: PCI\VEN_8086&DEV_1C10&SUBSYS_20941B0A&REV_B5\3&11583659&0&E0
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family USB Enhanced Host Controller - 1C2D
Device ID: PCI\VEN_8086&DEV_1C2D&SUBSYS_20941B0A&REV_05\3&11583659&0&D0
  Driver: n/a

    Name: Intel(R) Mobile Express Chipset SATA AHCI Controller
Device ID: PCI\VEN_8086&DEV_1C03&SUBSYS_20941B0A&REV_05\3&11583659&0&FA
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family USB Enhanced Host Controller - 1C26
Device ID: PCI\VEN_8086&DEV_1C26&SUBSYS_20941B0A&REV_05\3&11583659&0&E8
  Driver: n/a

    Name: Intel(R) Centrino(R) Wireless-N 100
Device ID: PCI\VEN_8086&DEV_08AE&SUBSYS_10058086&REV_00\4&25CFAFF5&0&00E1
  Driver: n/a

    Name: Intel(R) 6 Series/C200 Series Chipset Family SMBus Controller - 1C22
Device ID: PCI\VEN_8086&DEV_1C22&SUBSYS_20941B0A&REV_05\3&11583659&0&FB
  Driver: n/a

    Name: Intel(R) HD Graphics
Device ID: PCI\VEN_8086&DEV_0106&SUBSYS_20801B0A&REV_09\3&11583659&0&10
  Driver: n/a

    Name: High Definition Audio-Controller
Device ID: PCI\VEN_8086&DEV_1C20&SUBSYS_20AF1B0A&REV_05\3&11583659&0&D8
  Driver: n/a

    Name: 2nd generation Intel(R) Core(TM) processor family DRAM Controller - 0104
Device ID: PCI\VEN_8086&DEV_0104&SUBSYS_20941B0A&REV_09\3&11583659&0&00
  Driver: n/a

------------------
DirectShow Filters
------------------

DirectShow Filters:
WMAudio Decoder DMO,0x00800800,1,1,WMADMOD.DLL,6.01.7601.17514
WMAPro over S/PDIF DMO,0x00600800,1,1,WMADMOD.DLL,6.01.7601.17514
WMSpeech Decoder DMO,0x00600800,1,1,WMSPDMOD.DLL,6.01.7601.17514
MP3 Decoder DMO,0x00600800,1,1,mp3dmod.dll,6.01.7600.16385
Mpeg4s Decoder DMO,0x00800001,1,1,mp4sdecd.dll,6.01.7600.16385
WMV Screen decoder DMO,0x00600800,1,1,wmvsdecd.dll,6.01.7601.17514
WMVideo Decoder DMO,0x00800001,1,1,wmvdecod.dll,6.01.7601.18221
Mpeg43 Decoder DMO,0x00800001,1,1,mp43decd.dll,6.01.7600.16385
Mpeg4 Decoder DMO,0x00800001,1,1,mpg4decd.dll,6.01.7600.16385
Xiph.Org Vorbis Decoder,0x00600000,1,1,dsfVorbisDecoder.dll,
WMT VIH2 Fix,0x00200000,1,1,WLXVAFilt.dll,15.04.3508.1109
Record Queue,0x00200000,1,1,WLXVAFilt.dll,15.04.3508.1109
WMT Switch Filter,0x00200000,1,1,WLXVAFilt.dll,15.04.3508.1109
WMT Virtual Renderer,0x00200000,1,0,WLXVAFilt.dll,15.04.3508.1109
WMT DV Extract,0x00200000,1,1,WLXVAFilt.dll,15.04.3508.1109
WMT Virtual Source,0x00200000,0,1,WLXVAFilt.dll,15.04.3508.1109
WMT Sample Information Filter,0x00200000,1,1,WLXVAFilt.dll,15.04.3508.1109
Sony CF DXVA AVC Decoder,0x00800000,1,1,sjvtdfcf.ax,2.00.0114.9020
CyberLink MP3/WAV Wrapper,0x00200000,1,1,P2GMP3Wrap.ax,3.07.0000.1314
DV Muxer,0x00400000,0,0,qdv.dll,6.06.7601.17514
CyberLink AudioCD Filter,0x00200000,0,1,P2GAudioCD.ax,5.00.0000.1321
Color Space Converter,0x00400001,1,1,quartz.dll,6.06.7601.17713
WM ASF Reader,0x00400000,0,0,qasf.dll,12.00.7601.17514
Screen Capture filter,0x00200000,0,1,wmpsrcwp.dll,12.00.7601.17514
AVI Splitter,0x00600000,1,1,quartz.dll,6.06.7601.17713
VGA 16 Color Ditherer,0x00400000,1,1,quartz.dll,6.06.7601.17713
SBE2MediaTypeProfile,0x00200000,0,0,sbe.dll,6.06.7601.17528
Microsoft DTV-DVD Video Decoder,0x005fffff,2,4,msmpeg2vdec.dll,12.00.9200.16426
MPC - RealVideo Decoder,0x00600000,1,1,RealMediaSplitter.ax,1.03.1572.0000
AC3 Parser Filter,0x00600000,1,1,mpg2splt.ax,6.06.7601.17528
Sony CF IntelVA AVC Decoder,0x00800000,1,1,sjvtdfcf.ax,2.00.0114.9020
StreamBufferSink,0x00200000,0,0,sbe.dll,6.06.7601.17528
MJPEG Decompressor,0x00600000,1,1,quartz.dll,6.06.7601.17713
MPEG-I Stream Splitter,0x00600000,1,2,quartz.dll,6.06.7601.17713
SAMI (CC) Parser,0x00400000,1,1,quartz.dll,6.06.7601.17713
VBI Codec,0x00600000,1,4,VBICodec.ax,6.06.7601.17514
MPEG-2 Splitter,0x005fffff,1,0,mpg2splt.ax,6.06.7601.17528
Closed Captions Analysis Filter,0x00200000,2,5,cca.dll,6.06.7601.17514
Sony CF AVC Decoder,0x00800000,1,1,sjvtdfcf.ax,2.00.0114.9020
SBE2FileScan,0x00200000,0,0,sbe.dll,6.06.7601.17528
Microsoft MPEG-2 Video Encoder,0x00200000,1,1,msmpeg2enc.dll,6.01.7601.17514
Sony CF MP4 File Source,0x00800000,0,1,MP4FileSource.ax,2.00.0114.9020
Internal Script Command Renderer,0x00800001,1,0,quartz.dll,6.06.7601.17713
CyberLink Video Regulator,0x00200000,1,1,P2GRGL.ax,2.00.0000.3328
MPEG Audio Decoder,0x03680001,1,1,quartz.dll,6.06.7601.17713
DV Splitter,0x00600000,1,2,qdv.dll,6.06.7601.17514
Video Mixing Renderer 9,0x00200000,1,0,quartz.dll,6.06.7601.17713
Xiph.Org Vorbis Encoder,0x00200000,1,1,dsfVorbisEncoder.dll,
CyberLink Audio Noise Reduction,0x00200000,1,1,P2GAuNRWrapper.ax,2.00.0000.1017
Microsoft MPEG-2 Encoder,0x00200000,2,1,msmpeg2enc.dll,6.01.7601.17514
CyberLink Audio VolumeBooster,0x00200000,1,1,P2GVB.ax,1.00.0000.1008
ACM Wrapper,0x00600000,1,1,quartz.dll,6.06.7601.17713
Video Renderer,0x00800001,1,0,quartz.dll,6.06.7601.17713
MPEG-2 Video Stream Analyzer,0x00200000,0,0,sbe.dll,6.06.7601.17528
Line 21 Decoder,0x00600000,1,1,qdvd.dll,6.06.7601.17835
Video Port Manager,0x00600000,2,1,quartz.dll,6.06.7601.17713
CyberLink Line21 Decoder Filter (PDC 1.0),0x00200000,0,2,CLLine21.ax,4.00.0000.3924
Video Renderer,0x00400000,1,0,quartz.dll,6.06.7601.17713
CyberLink Audio Resampler,0x00200000,1,1,P2GAuRsmpl.ax,1.00.0000.2625
MPC - RealMedia Source,0x00600000,0,0,RealMediaSplitter.ax,1.03.1572.0000
File Writer,0x00200000,1,0,WLXVAFilt.dll,15.04.3508.1109
VPS Decoder,0x00200000,0,0,WSTPager.ax,6.06.7601.17514
WM ASF Writer,0x00400000,0,0,qasf.dll,12.00.7601.17514
VBI Surface Allocator,0x00600000,1,1,vbisurf.ax,6.01.7601.17514
CuttlefishSubtitleParser Filter,0x00200000,1,1,CuttlefishSubtitleParser.ax,2.00.0114.9020
CyberLink DVD Navigator (PDC 1.0),0x00200000,0,3,CLNavX.ax,6.00.0000.1321
File writer,0x00200000,1,0,qcap.dll,6.06.7601.17514
Sony CF AAC decoder,0x00600000,1,1,cfaac.ax,2.00.0114.9020
iTV Data Sink,0x00600000,1,0,itvdata.dll,6.06.7601.17514
iTV Data Capture filter,0x00600000,1,1,itvdata.dll,6.06.7601.17514
Cyberlink File Reader (Async.),0x00200000,0,1,P2GReader.ax,3.00.0000.3016
MPC - RealAudio Decoder,0x00600000,1,1,RealMediaSplitter.ax,1.03.1572.0000
CyberLink PCM Wrapper,0x00200000,1,1,P2GPCMEnc.ax,1.01.0000.0321
DVD Navigator,0x00200000,0,3,qdvd.dll,6.06.7601.17835
Overlay Mixer2,0x00200000,1,1,qdvd.dll,6.06.7601.17835
AVI Draw,0x00600064,9,1,quartz.dll,6.06.7601.17713
RDP DShow Redirection Filter,0xffffffff,1,0,DShowRdpFilter.dll,
Microsoft MPEG-2 Audio Encoder,0x00200000,1,1,msmpeg2enc.dll,6.01.7601.17514
WST Pager,0x00200000,1,1,WSTPager.ax,6.06.7601.17514
MPEG-2 Demultiplexer,0x00600000,1,1,mpg2splt.ax,6.06.7601.17528
DV Video Decoder,0x00800000,1,1,qdv.dll,6.06.7601.17514
SampleGrabber,0x00200000,1,1,qedit.dll,6.06.7601.18386
Null Renderer,0x00200000,1,0,qedit.dll,6.06.7601.18386
MPEG-2 Sections and Tables,0x005fffff,1,0,Mpeg2Data.ax,6.06.7601.17514
Microsoft AC3 Encoder,0x00200000,1,1,msac3enc.dll,6.01.7601.17514
StreamBufferSource,0x00200000,0,0,sbe.dll,6.06.7601.17528
Smart Tee,0x00200000,1,2,qcap.dll,6.06.7601.17514
Overlay Mixer,0x00200000,0,0,qdvd.dll,6.06.7601.17835
AVI Decompressor,0x00600000,1,1,quartz.dll,6.06.7601.17713
AVI/WAV File Source,0x00400000,0,2,quartz.dll,6.06.7601.17713
Wave Parser,0x00400000,1,1,quartz.dll,6.06.7601.17713
MIDI Parser,0x00400000,1,1,quartz.dll,6.06.7601.17713
Multi-file Parser,0x00400000,1,1,quartz.dll,6.06.7601.17713
File stream renderer,0x00400000,1,1,quartz.dll,6.06.7601.17713
CuttlefishClosedCaption Filter,0x00400000,1,1,CuttlefishSubtitleParser.ax,2.00.0114.9020
Microsoft DTV-DVD Audio Decoder,0x005fffff,1,1,msmpeg2adec.dll,6.01.7140.0000
MPC - RealMedia Splitter,0x00600000,1,1,RealMediaSplitter.ax,1.03.1572.0000
StreamBufferSink2,0x00200000,0,0,sbe.dll,6.06.7601.17528
AVI Mux,0x00200000,1,0,qcap.dll,6.06.7601.17514
Line 21 Decoder 2,0x00600002,1,1,quartz.dll,6.06.7601.17713
File Source (Async.),0x00400000,0,1,quartz.dll,6.06.7601.17713
File Source (URL),0x00400000,0,1,quartz.dll,6.06.7601.17713
PDC Video Decoder,0x00200000,2,3,CLVSD.ax,5.00.0000.3009
P2G Audio Encoder,0x00200000,2,0,P2GAudEnc.ax,2.00.0000.4815
Infinite Pin Tee Filter,0x00200000,1,1,qcap.dll,6.06.7601.17514
Enhanced Video Renderer,0x00200000,1,0,evr.dll,6.01.7601.17514
BDA MPEG2 Transport Information Filter,0x00200000,2,0,psisrndr.ax,6.06.7601.17669
MPEG Video Decoder,0x40000001,1,1,quartz.dll,6.06.7601.17713

WDM Streaming Tee/Splitter Devices:
Tee/Sink-to-Sink-Konvertierung,0x00200000,1,1,ksproxy.ax,6.01.7601.17514

Video Compressors:
WMVideo8 Encoder DMO,0x00600800,1,1,wmvxencd.dll,6.01.7600.16385
WMVideo9 Encoder DMO,0x00600800,1,1,wmvencod.dll,6.01.7600.16385
MSScreen 9 encoder DMO,0x00600800,1,1,wmvsencd.dll,6.01.7600.16385
DV Video Encoder,0x00200000,0,0,qdv.dll,6.06.7601.17514
MJPEG Compressor,0x00200000,0,0,quartz.dll,6.06.7601.17713
Cinepak Codec von Radius,0x00200000,1,1,qcap.dll,6.06.7601.17514
Intel IYUV Codec,0x00200000,1,1,qcap.dll,6.06.7601.17514
Intel IYUV Codec,0x00200000,1,1,qcap.dll,6.06.7601.17514
Microsoft RLE,0x00200000,1,1,qcap.dll,6.06.7601.17514
Microsoft Video 1,0x00200000,1,1,qcap.dll,6.06.7601.17514

Audio Compressors:
WM Speech Encoder DMO,0x00600800,1,1,WMSPDMOE.DLL,6.01.7600.16385
WMAudio Encoder DMO,0x00600800,1,1,WMADMOE.DLL,6.01.7600.16385
Xiph.Org Vorbis Encoder,0x00200000,1,1,dsfVorbisEncoder.dll,
IMA ADPCM,0x00200000,1,1,quartz.dll,6.06.7601.17713
PCM,0x00200000,1,1,quartz.dll,6.06.7601.17713
Microsoft ADPCM,0x00200000,1,1,quartz.dll,6.06.7601.17713
GSM 6.10,0x00200000,1,1,quartz.dll,6.06.7601.17713
Messenger Audio Codec,0x00200000,1,1,quartz.dll,6.06.7601.17713
CCITT A-Law,0x00200000,1,1,quartz.dll,6.06.7601.17713
CCITT u-Law,0x00200000,1,1,quartz.dll,6.06.7601.17713
MPEG Layer-3,0x00200000,1,1,quartz.dll,6.06.7601.17713

Audio Capture Sources:
Internal Microphone (Conexant S,0x00200000,0,0,qcap.dll,6.06.7601.17514

PBDA CP Filters:
PBDA DTFilter,0x00600000,1,1,CPFilters.dll,6.06.7601.17528
PBDA ETFilter,0x00200000,0,0,CPFilters.dll,6.06.7601.17528
PBDA PTFilter,0x00200000,0,0,CPFilters.dll,6.06.7601.17528

Midi Renderers:
Default MidiOut Device,0x00800000,1,0,quartz.dll,6.06.7601.17713
Microsoft GS Wavetable Synth,0x00200000,1,0,quartz.dll,6.06.7601.17713

WDM Streaming Capture Devices:
Conexant HD Audio capture,0x00200000,1,1,ksproxy.ax,6.01.7601.17514
,0x00000000,0,0,,
,0x00000000,0,0,,
USB2.0 UVC 1.3M Webcam,0x00200000,1,2,ksproxy.ax,6.01.7601.17514

WDM Streaming Rendering Devices:
,0x00000000,0,0,,
Conexant HD Audio digital out,0x00200000,1,1,ksproxy.ax,6.01.7601.17514
Conexant HD Audio output,0x00200000,1,1,ksproxy.ax,6.01.7601.17514

BDA Network Providers:
Microsoft ATSC Network Provider,0x00200000,0,1,MSDvbNP.ax,6.06.7601.17514
Microsoft DVBC Network Provider,0x00200000,0,1,MSDvbNP.ax,6.06.7601.17514
Microsoft DVBS Network Provider,0x00200000,0,1,MSDvbNP.ax,6.06.7601.17514
Microsoft DVBT Network Provider,0x00200000,0,1,MSDvbNP.ax,6.06.7601.17514
Microsoft Network Provider,0x00200000,0,1,MSNP.ax,6.06.7601.17514

Video Capture Sources:
USB2.0 UVC 1.3M Webcam,0x00200000,1,2,ksproxy.ax,6.01.7601.17514

Multi-Instance Capable VBI Codecs:
VBI Codec,0x00600000,1,4,VBICodec.ax,6.06.7601.17514

BDA Transport Information Renderers:
BDA MPEG2 Transport Information Filter,0x00600000,2,0,psisrndr.ax,6.06.7601.17669
MPEG-2 Sections and Tables,0x00600000,1,0,Mpeg2Data.ax,6.06.7601.17514

BDA CP/CA Filters:
Decrypt/Tag,0x00600000,1,1,EncDec.dll,6.06.7601.17708
Encrypt/Tag,0x00200000,0,0,EncDec.dll,6.06.7601.17708
PTFilter,0x00200000,0,0,EncDec.dll,6.06.7601.17708
XDS Codec,0x00200000,0,0,EncDec.dll,6.06.7601.17708

WDM Streaming Communication Transforms:
Tee/Sink-to-Sink-Konvertierung,0x00200000,1,1,ksproxy.ax,6.01.7601.17514

Audio Renderers:
Speakers (Conexant SmartAudio H,0x00200000,1,0,quartz.dll,6.06.7601.17713
Default DirectSound Device,0x00800000,1,0,quartz.dll,6.06.7601.17713
Default WaveOut Device,0x00200000,1,0,quartz.dll,6.06.7601.17713
DirectSound: SPDIF Interface (Conexant SmartAudio HD),0x00200000,1,0,quartz.dll,6.06.7601.17713
DirectSound: Speakers (Conexant SmartAudio HD),0x00200000,1,0,quartz.dll,6.06.7601.17713
SPDIF Interface (Conexant Smart,0x00200000,1,0,quartz.dll,6.06.7601.17713

---------------
EVR Power Information
---------------
Current Setting: {5C67A112-A4C9-483F-B4A7-1D473BECAFDC} (Quality)
  Quality Flags: 2576
    Enabled:
    Force throttling
    Allow half deinterlace
    Allow scaling
    Decode Power Usage: 100
  Balanced Flags: 1424
    Enabled:
    Force throttling
    Allow batching
    Force half deinterlace
    Force scaling
    Decode Power Usage: 50
  PowerFlags: 1424
    Enabled:
    Force throttling
    Allow batching
    Force half deinterlace
    Force scaling
    Decode Power Usage: 0


Larusso 06.06.2014 11:11

Hy. So sieht jetzt eigentlich alles so aus wie es soll.
Ich schließe hier jetzt keinen Hardware defekt aus aber ich will denoch prüfen ob es nicht doch Windows Itself ist.

Dazu müssen wir eine Linux Distro verwenden.

How to create a bootable USB stick on Windows | Ubuntu

Versuche dann ob du hier normalen SOund hast.
Solltest du Hilfe brauchen bei etwas einfach fragen.

Nirtaka 08.06.2014 11:06

Hey, öhm, also ich checke nicht so ganz wie ich das Teil richtig installiere :-O. Wenn ich das Setup aufrufe, muss ich dann auch dieses Unbuntu-Mopped aufrufen oder einfach mein Windows 7 eintragen? Und was muss ich im 3.Schritt auswählen? Iwas mit USB.. ich bin verwirrt , bitte einmal die Erklärung für Computerleghasteniker :-D LG Kati

Larusso 08.06.2014 12:28

Was meinst du mit ubuntu mopped ? :D

Larusso 12.06.2014 04:51

Gibt es noch weitere Probleme ?

sunjojo 19.06.2014 09:28

Fehlende Rückmeldung

Dieses Thema wurde aus meinen Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. Falls du weitermachen willst, schicke mir bitte eine private Nachricht.

Jeder andere bitte folgendes lesen: http://www.trojaner-board.de/69886-a...-beachten.html und einen eigenen Thread erstellen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 20:56 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131