Matrocheck | 10.10.2013 12:17 |
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by Matro (administrator) on MATRO-PC on 10-10-2013 13:12:33
Running from C:\Users\Matro\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\STacSV64.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\AESTSr64.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHKE.EXE
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
() C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-15] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [456192 2009-08-13] (IDT, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-11-07] (Sun Microsystems, Inc.)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-08-20] (Hewlett-Packard Company)
HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHKE.EXE [283232 2013-08-10] (SEIKO EPSON CORPORATION)
HKCU\...\Run: [HPADVISOR] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1685048 2009-09-29] (Hewlett-Packard)
MountPoints2: {e16301f7-fd08-11e2-92ef-806e6f6e6963} - D:\RunGame.exe
HKLM-x32\...\Run: [QlbCtrl.exe] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [322104 2009-08-20] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [60464 2009-09-02] (EasyBits Software AS)
HKLM-x32\...\Run: [WirelessAssistant] - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1603024 2013-09-12] (APN)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=1E930026C711F7E6&affID=119357&tt=240913_91213&tsp=5016
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=1E930026C711F7E6&affID=119357&tt=240913_91213&tsp=5016
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=1E930026C711F7E6&affID=119357&tt=240913_91213&tsp=5016
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL [52272 2009-11-07] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Users\Matro\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
Chrome:
=======
CHR HomePage: hxxp://www.google.de/
CHR RestoreOnStartup: "hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=1E930026C711F7E6&affID=119357&tt=240913_91213&tsp=5016"
CHR DefaultSearchURL: (SearchGol) - hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=1E930026C711F7E6&affID=119357&tt=240913_91213&tsp=5016
CHR DefaultSuggestURL: (SearchGol) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.150.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeploytk.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U15) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\Matro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh\24.57772_0
CHR Extension: (Google Docs) - C:\Users\Matro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Matro\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Matro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Adblock Plus) - C:\Users\Matro\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6_0
CHR Extension: (Google Search) - C:\Users\Matro\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Matro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\Matro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\Matro\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-22] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [164816 2013-09-12] (APN LLC.)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-06] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\STacSV64.exe [240640 2009-08-13] (IDT, Inc.)
R2 ezSharedSvc; C:\Windows\System32\ezsvc7.dll [x]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-09-22] (Avira Operations GmbH & Co. KG)
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-10 13:12 - 2013-10-10 13:12 - 01954124 _____ (Farbar) C:\Users\Matro\Downloads\FRST64.exe
2013-10-10 13:12 - 2013-10-10 13:12 - 00000000 ____D C:\FRST
2013-09-30 16:57 - 2013-09-30 16:57 - 00000000 ____D C:\Users\Matro\Desktop\zu verkaufen
2013-09-26 15:47 - 2013-09-26 15:47 - 00268264 _____ (Citrix Online) C:\Users\Matro\Downloads\Citrix Online Launcher.exe
2013-09-26 13:16 - 2013-09-26 13:17 - 02828552 _____ (AVAST Software) C:\Users\Matro\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-09-25 18:01 - 2013-09-25 18:01 - 00000000 ____D C:\Users\Matro\Documents\Optimizer Pro
2013-09-25 17:59 - 2013-09-25 17:59 - 00090283 _____ C:\Users\Matro\Documents\Unbenannt (3).wma
2013-09-25 17:59 - 2013-09-25 17:59 - 00067833 _____ C:\Users\Matro\Documents\Unbenannt (2).wma
2013-09-25 17:58 - 2013-09-25 17:58 - 00090283 _____ C:\Users\Matro\Documents\Unbenannt.wma
2013-09-25 17:57 - 2013-09-26 12:58 - 00000292 _____ C:\Windows\Tasks\UpdaterEX.job
2013-09-25 17:57 - 2013-09-25 17:57 - 20586496 _____ C:\Users\Matro\Downloads\SkypeSetup [1].exe
2013-09-25 17:57 - 2013-09-25 17:57 - 00003232 _____ C:\Windows\System32\Tasks\UpdaterEX
2013-09-25 17:57 - 2013-09-25 17:57 - 00000000 ____D C:\Users\Matro\AppData\Roaming\UpdaterEX
2013-09-25 17:56 - 2013-09-26 13:01 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive
2013-09-25 17:56 - 2013-09-25 17:56 - 00000000 ____D C:\Users\Matro\AppData\Local\BonanzaDealsLive
2013-09-25 17:56 - 2013-09-25 17:56 - 00000000 ____D C:\ProgramData\BonanzaDealsLive
2013-09-25 17:56 - 2013-09-25 17:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-25 17:55 - 2013-09-26 12:56 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals
2013-09-25 17:55 - 2013-09-25 17:55 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Babylon
2013-09-25 17:55 - 2013-09-25 17:55 - 00000000 ____D C:\ProgramData\Babylon
2013-09-25 17:54 - 2013-09-25 17:54 - 00676072 _____ C:\Users\Matro\Downloads\SkypeSetup.exe
2013-09-25 17:51 - 2013-10-10 12:11 - 00000000 ____D C:\Program Files (x86)\Citrix
2013-09-25 17:50 - 2013-09-26 12:54 - 00000000 ____D C:\Users\Matro\AppData\Local\Citrix
2013-09-24 13:34 - 2013-09-24 13:34 - 00008423 _____ C:\Users\Matro\Downloads\industry_quadrupler.zip
2013-09-24 12:57 - 2013-09-24 12:57 - 00000000 ____D C:\Program Files (x86)\Traffic Simulator Configuration Tool
2013-09-24 12:54 - 2013-09-24 12:54 - 00000000 ____D C:\Users\Matro\Downloads\Dokumentation
2013-09-24 12:54 - 2011-12-25 23:49 - 22403861 _____ C:\Users\Matro\Downloads\NetworkAddonMod_Setup.exe
2013-09-24 12:54 - 2011-12-23 22:14 - 00014142 _____ C:\Users\Matro\Downloads\Bitte zuerst lesen.htm
2013-09-24 12:54 - 2011-02-08 12:14 - 00016790 _____ C:\Users\Matro\Downloads\Cleanitol_NetworkAddonMod.txt
2013-09-24 12:49 - 2013-09-24 12:51 - 17915242 _____ C:\Users\Matro\Downloads\SimCity_4_Rush_Hour_v116380_Patch_International.exe
2013-09-24 12:49 - 2013-09-24 12:50 - 09390527 _____ C:\Users\Matro\Downloads\SimCity_4_Patch_v102720_European.exe
2013-09-24 12:47 - 2013-09-24 12:49 - 23140223 _____ C:\Users\Matro\Downloads\NetworkAddonMod_Setup_v30de.zip
2013-09-23 16:43 - 2013-10-08 13:41 - 00000000 ____D C:\Users\Matro\AppData\Local\CrashDumps
2013-09-22 20:02 - 2013-09-22 20:01 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-09-22 14:42 - 2013-10-04 15:56 - 00000000 ____D C:\Users\Matro\Documents\SimCity 4
2013-09-22 14:26 - 2013-09-22 14:26 - 00000534 _____ C:\Windows\eReg.dat
2013-09-22 14:26 - 2013-09-22 14:26 - 00000000 ____D C:\Program Files (x86)\Maxis
2013-09-22 14:07 - 2013-04-02 20:42 - 00000000 ____D C:\Users\Matro\Downloads\Sim.City.Crack.Only.OFFLINE.Mode
2013-09-22 14:06 - 2013-09-22 14:06 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Avira
2013-09-22 14:02 - 2013-09-22 14:04 - 26404527 _____ C:\Users\Matro\Downloads\Sim.City.Crack.Only.OFFLINE.Mode.rar
2013-09-22 14:01 - 2013-09-22 14:01 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Mozilla
2013-09-22 14:01 - 2013-09-22 14:01 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-09-22 14:01 - 2013-09-22 14:01 - 00000000 ____D C:\ProgramData\APN
2013-09-22 14:01 - 2013-09-22 14:01 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2013-09-22 14:00 - 2013-09-22 14:00 - 00002066 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-09-22 13:59 - 2013-09-22 14:00 - 00000000 ____D C:\ProgramData\Avira
2013-09-22 13:59 - 2013-09-22 13:59 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-09-22 13:59 - 2013-09-22 13:59 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-09-22 13:59 - 2013-09-22 13:59 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-09-22 13:59 - 2013-09-22 13:59 - 00000000 ____D C:\Program Files (x86)\Avira
2013-09-22 13:48 - 2013-09-22 13:48 - 02092792 _____ C:\Users\Matro\Downloads\avira_free_antivirus (1).exe
2013-09-22 13:44 - 2013-09-22 13:44 - 02092792 _____ C:\Users\Matro\Downloads\avira_free_antivirus.exe
2013-09-22 13:43 - 2013-09-22 13:45 - 00000000 ____D C:\AdwCleaner
2013-09-22 13:42 - 2013-09-22 13:43 - 01039554 _____ C:\Users\Matro\Downloads\adwcleaner004.exe
2013-09-22 13:35 - 2013-06-14 13:02 - 00000340 _____ C:\Users\Matro\Downloads\readme(password).txt
2013-09-22 13:32 - 2013-04-19 19:09 - 00000000 _____ C:\Users\Matro\Downloads\Simcity 5 crack.exe
2013-09-22 13:31 - 2013-09-22 13:32 - 07273696 _____ C:\Users\Matro\Downloads\Simcity+5+crack.rar
2013-09-22 13:17 - 2013-09-22 13:17 - 00509944 _____ C:\Users\Matro\Downloads\PricePeep_RocketFuelInstaller.exe
2013-09-21 19:46 - 2013-09-21 19:46 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Apple Computer
2013-09-21 18:43 - 2013-09-21 18:44 - 00000000 ____D C:\Users\Matro\Desktop\Pkmn Schwarz
2013-09-21 18:42 - 2011-08-12 16:30 - 00000000 ____D C:\Users\Matro\Downloads\NO$GBA v2.6a + GBA BIOS + NDS BIOS + NDS Firmware (German)
2013-09-21 18:29 - 2013-09-21 18:34 - 73712376 _____ C:\Users\Matro\Downloads\Emu2011.rar
2013-09-21 18:24 - 2013-09-21 18:24 - 00313624 _____ C:\Users\Matro\Downloads\ideas1040.zip
2013-09-21 16:38 - 2013-09-21 16:41 - 39401336 _____ (Apple Inc.) C:\Users\Matro\Downloads\QuickTimeInstaller (1).exe
2013-09-21 16:37 - 2013-09-21 16:37 - 00001845 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2013-09-21 16:37 - 2013-09-21 16:37 - 00000000 ____D C:\ProgramData\Apple Computer
2013-09-21 16:37 - 2013-09-21 16:37 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-09-21 16:36 - 2013-09-21 16:36 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2013-09-21 16:36 - 2013-09-21 16:36 - 00000000 ____D C:\Users\Matro\AppData\Local\Apple
2013-09-21 16:36 - 2013-09-21 16:36 - 00000000 ____D C:\ProgramData\Apple
2013-09-21 16:36 - 2013-09-21 16:36 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-09-21 16:28 - 2013-09-21 16:31 - 41404760 _____ (Apple Inc.) C:\Users\Matro\Downloads\QuickTimeInstaller.exe
2013-09-17 18:27 - 2013-09-17 18:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-17 18:27 - 2013-09-17 18:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-17 18:26 - 2013-09-17 18:26 - 00000000 ____D C:\Windows\system32\Macromed
2013-09-15 16:45 - 2013-09-15 16:45 - 00773296 _____ (RealNetworks, Inc.) C:\Users\Matro\Downloads\RealPlayer.exe
2013-09-15 16:45 - 2013-09-15 16:45 - 00773296 _____ (RealNetworks, Inc.) C:\Users\Matro\Downloads\RealPlayer (1).exe
2013-09-14 14:24 - 2013-09-12 16:01 - 00675988 _____ C:\Users\Matro\Desktop\Minecraft.exe
2013-09-14 14:06 - 2013-09-14 14:17 - 04155007 _____ C:\Users\Matro\Downloads\minecraftforge-installer-1.6.2-9.10.0.799.jar
2013-09-14 14:03 - 2013-09-14 14:13 - 84734859 _____ C:\Users\Matro\Downloads\Pixelmon 2.3.1 install.zip
2013-09-14 13:36 - 2013-09-14 13:36 - 00000000 ____D C:\Users\Matro\AppData\Local\Tific
2013-09-14 13:35 - 2013-09-14 13:35 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Tific
2013-09-14 13:34 - 2013-09-14 13:34 - 00000000 ____D C:\Users\Matro\AppData\Local\Symantec
2013-09-13 17:26 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-13 17:26 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-13 17:26 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-13 17:26 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-13 17:26 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-13 17:26 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-13 17:26 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-13 17:26 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-13 17:26 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-13 17:26 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-13 17:26 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-13 17:26 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-13 17:26 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-13 17:26 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-13 17:26 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-13 17:26 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-13 17:26 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-13 17:26 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-13 17:26 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-13 17:26 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-13 17:26 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-13 15:11 - 2013-09-13 15:12 - 09092696 _____ C:\Users\Matro\Downloads\Pokémon Kanto.rar
2013-09-13 13:47 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-13 13:47 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-13 13:47 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-13 13:47 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-13 13:47 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-13 13:47 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-13 13:47 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-13 13:47 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-13 13:47 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-13 13:47 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-13 13:47 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-13 13:47 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-13 13:47 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-13 13:47 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-13 13:47 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-13 13:47 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-13 13:47 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-13 13:47 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-13 13:47 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-13 13:47 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-13 13:47 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-13 13:47 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-13 13:47 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-13 13:47 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-13 13:47 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-13 13:47 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-13 13:47 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-12 16:01 - 2013-09-14 17:32 - 00000000 ____D C:\Users\Matro\AppData\Roaming\.minecraft
2013-09-12 16:01 - 2013-09-12 16:01 - 00675988 _____ C:\Users\Matro\Downloads\Minecraft.exe
2013-09-12 14:47 - 2013-09-12 14:47 - 00000000 ____D C:\Users\Matro\restore
2013-09-12 14:44 - 2013-09-12 14:45 - 00000000 ____D C:\ProgramData\tmp
2013-09-12 14:44 - 2013-09-12 14:44 - 00000000 ____D C:\ProgramData\hps
2013-09-12 14:31 - 2013-09-12 15:38 - 00000000 ____D C:\Users\Matro\Desktop\joke fotoalbum
2013-09-12 14:29 - 2013-09-12 14:29 - 00000000 ____D C:\Program Files (x86)\Mueller Foto
2013-09-12 14:28 - 2013-09-12 14:28 - 01600152 _____ C:\Users\Matro\Downloads\setup_Mueller_Fotowelt.exe
2013-09-11 15:13 - 2013-09-11 15:13 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Watchtower
2013-09-11 15:06 - 2013-09-11 15:06 - 00001336 _____ C:\Users\Matro\Desktop\Watchtower Library 2012 - Deutsch.lnk
2013-09-11 15:06 - 2013-09-11 15:06 - 00000000 ____D C:\Program Files (x86)\Watchtower
==================== One Month Modified Files and Folders =======
2013-10-10 13:12 - 2013-10-10 13:12 - 01954124 _____ (Farbar) C:\Users\Matro\Downloads\FRST64.exe
2013-10-10 13:12 - 2013-10-10 13:12 - 00000000 ____D C:\FRST
2013-10-10 12:53 - 2013-08-04 15:41 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-10 12:32 - 2013-08-04 14:35 - 02004455 _____ C:\Windows\WindowsUpdate.log
2013-10-10 12:11 - 2013-09-25 17:51 - 00000000 ____D C:\Program Files (x86)\Citrix
2013-10-10 09:52 - 2013-08-04 15:41 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-10 09:42 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-10 09:42 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-10 09:33 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-10 09:33 - 2009-07-14 06:51 - 00060044 _____ C:\Windows\setupact.log
2013-10-09 09:48 - 2013-08-04 15:41 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-09 09:47 - 2013-08-04 15:41 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-08 13:41 - 2013-09-23 16:43 - 00000000 ____D C:\Users\Matro\AppData\Local\CrashDumps
2013-10-06 18:51 - 2013-08-04 15:44 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-04 15:56 - 2013-09-22 14:42 - 00000000 ____D C:\Users\Matro\Documents\SimCity 4
2013-09-30 16:57 - 2013-09-30 16:57 - 00000000 ____D C:\Users\Matro\Desktop\zu verkaufen
2013-09-27 13:25 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-26 15:47 - 2013-09-26 15:47 - 00268264 _____ (Citrix Online) C:\Users\Matro\Downloads\Citrix Online Launcher.exe
2013-09-26 13:17 - 2013-09-26 13:16 - 02828552 _____ (AVAST Software) C:\Users\Matro\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-09-26 13:04 - 2013-08-04 14:45 - 00204202 _____ C:\Windows\PFRO.log
2013-09-26 13:01 - 2013-09-25 17:56 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive
2013-09-26 12:58 - 2013-09-25 17:57 - 00000292 _____ C:\Windows\Tasks\UpdaterEX.job
2013-09-26 12:56 - 2013-09-25 17:55 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals
2013-09-26 12:54 - 2013-09-25 17:50 - 00000000 ____D C:\Users\Matro\AppData\Local\Citrix
2013-09-25 18:01 - 2013-09-25 18:01 - 00000000 ____D C:\Users\Matro\Documents\Optimizer Pro
2013-09-25 17:59 - 2013-09-25 17:59 - 00090283 _____ C:\Users\Matro\Documents\Unbenannt (3).wma
2013-09-25 17:59 - 2013-09-25 17:59 - 00067833 _____ C:\Users\Matro\Documents\Unbenannt (2).wma
2013-09-25 17:58 - 2013-09-25 17:58 - 00090283 _____ C:\Users\Matro\Documents\Unbenannt.wma
2013-09-25 17:57 - 2013-09-25 17:57 - 20586496 _____ C:\Users\Matro\Downloads\SkypeSetup [1].exe
2013-09-25 17:57 - 2013-09-25 17:57 - 00003232 _____ C:\Windows\System32\Tasks\UpdaterEX
2013-09-25 17:57 - 2013-09-25 17:57 - 00000000 ____D C:\Users\Matro\AppData\Roaming\UpdaterEX
2013-09-25 17:56 - 2013-09-25 17:56 - 00000000 ____D C:\Users\Matro\AppData\Local\BonanzaDealsLive
2013-09-25 17:56 - 2013-09-25 17:56 - 00000000 ____D C:\ProgramData\BonanzaDealsLive
2013-09-25 17:56 - 2013-09-25 17:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-25 17:55 - 2013-09-25 17:55 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Babylon
2013-09-25 17:55 - 2013-09-25 17:55 - 00000000 ____D C:\ProgramData\Babylon
2013-09-25 17:54 - 2013-09-25 17:54 - 00676072 _____ C:\Users\Matro\Downloads\SkypeSetup.exe
2013-09-24 13:34 - 2013-09-24 13:34 - 00008423 _____ C:\Users\Matro\Downloads\industry_quadrupler.zip
2013-09-24 12:57 - 2013-09-24 12:57 - 00000000 ____D C:\Program Files (x86)\Traffic Simulator Configuration Tool
2013-09-24 12:54 - 2013-09-24 12:54 - 00000000 ____D C:\Users\Matro\Downloads\Dokumentation
2013-09-24 12:51 - 2013-09-24 12:49 - 17915242 _____ C:\Users\Matro\Downloads\SimCity_4_Rush_Hour_v116380_Patch_International.exe
2013-09-24 12:50 - 2013-09-24 12:49 - 09390527 _____ C:\Users\Matro\Downloads\SimCity_4_Patch_v102720_European.exe
2013-09-24 12:49 - 2013-09-24 12:47 - 23140223 _____ C:\Users\Matro\Downloads\NetworkAddonMod_Setup_v30de.zip
2013-09-22 20:01 - 2013-09-22 20:02 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-09-22 19:38 - 2013-08-04 15:36 - 00000000 ____D C:\Users\Matro\AppData\Local\VirtualStore
2013-09-22 19:37 - 2013-08-04 15:36 - 00000000 ____D C:\Users\Matro\AppData\Local\Hewlett-Packard
2013-09-22 19:37 - 2013-08-04 15:33 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Hewlett-Packard
2013-09-22 14:26 - 2013-09-22 14:26 - 00000534 _____ C:\Windows\eReg.dat
2013-09-22 14:26 - 2013-09-22 14:26 - 00000000 ____D C:\Program Files (x86)\Maxis
2013-09-22 14:06 - 2013-09-22 14:06 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Avira
2013-09-22 14:04 - 2013-09-22 14:02 - 26404527 _____ C:\Users\Matro\Downloads\Sim.City.Crack.Only.OFFLINE.Mode.rar
2013-09-22 14:01 - 2013-09-22 14:01 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Mozilla
2013-09-22 14:01 - 2013-09-22 14:01 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-09-22 14:01 - 2013-09-22 14:01 - 00000000 ____D C:\ProgramData\APN
2013-09-22 14:01 - 2013-09-22 14:01 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2013-09-22 14:00 - 2013-09-22 14:00 - 00002066 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-09-22 14:00 - 2013-09-22 13:59 - 00000000 ____D C:\ProgramData\Avira
2013-09-22 13:59 - 2013-09-22 13:59 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-09-22 13:59 - 2013-09-22 13:59 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-09-22 13:59 - 2013-09-22 13:59 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-09-22 13:59 - 2013-09-22 13:59 - 00000000 ____D C:\Program Files (x86)\Avira
2013-09-22 13:48 - 2013-09-22 13:48 - 02092792 _____ C:\Users\Matro\Downloads\avira_free_antivirus (1).exe
2013-09-22 13:45 - 2013-09-22 13:43 - 00000000 ____D C:\AdwCleaner
2013-09-22 13:44 - 2013-09-22 13:44 - 02092792 _____ C:\Users\Matro\Downloads\avira_free_antivirus.exe
2013-09-22 13:44 - 2013-08-06 08:50 - 00000995 _____ C:\Users\Matro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-09-22 13:43 - 2013-09-22 13:42 - 01039554 _____ C:\Users\Matro\Downloads\adwcleaner004.exe
2013-09-22 13:39 - 2013-08-04 15:37 - 00000000 ___RD C:\Users\Matro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-22 13:32 - 2013-09-22 13:31 - 07273696 _____ C:\Users\Matro\Downloads\Simcity+5+crack.rar
2013-09-22 13:17 - 2013-09-22 13:17 - 00509944 _____ C:\Users\Matro\Downloads\PricePeep_RocketFuelInstaller.exe
2013-09-21 19:46 - 2013-09-21 19:46 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Apple Computer
2013-09-21 18:44 - 2013-09-21 18:43 - 00000000 ____D C:\Users\Matro\Desktop\Pkmn Schwarz
2013-09-21 18:34 - 2013-09-21 18:29 - 73712376 _____ C:\Users\Matro\Downloads\Emu2011.rar
2013-09-21 18:24 - 2013-09-21 18:24 - 00313624 _____ C:\Users\Matro\Downloads\ideas1040.zip
2013-09-21 16:41 - 2013-09-21 16:38 - 39401336 _____ (Apple Inc.) C:\Users\Matro\Downloads\QuickTimeInstaller (1).exe
2013-09-21 16:37 - 2013-09-21 16:37 - 00001845 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2013-09-21 16:37 - 2013-09-21 16:37 - 00000000 ____D C:\ProgramData\Apple Computer
2013-09-21 16:37 - 2013-09-21 16:37 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-09-21 16:36 - 2013-09-21 16:36 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2013-09-21 16:36 - 2013-09-21 16:36 - 00000000 ____D C:\Users\Matro\AppData\Local\Apple
2013-09-21 16:36 - 2013-09-21 16:36 - 00000000 ____D C:\ProgramData\Apple
2013-09-21 16:36 - 2013-09-21 16:36 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-09-21 16:31 - 2013-09-21 16:28 - 41404760 _____ (Apple Inc.) C:\Users\Matro\Downloads\QuickTimeInstaller.exe
2013-09-21 16:11 - 2013-08-04 14:59 - 00000000 ____D C:\ProgramData\Norton
2013-09-17 18:27 - 2013-09-17 18:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-17 18:27 - 2013-09-17 18:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-17 18:26 - 2013-09-17 18:26 - 00000000 ____D C:\Windows\system32\Macromed
2013-09-16 19:58 - 2009-11-08 05:20 - 00654166 _____ C:\Windows\system32\perfh007.dat
2013-09-16 19:58 - 2009-11-08 05:20 - 00130006 _____ C:\Windows\system32\perfc007.dat
2013-09-16 19:58 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-15 16:45 - 2013-09-15 16:45 - 00773296 _____ (RealNetworks, Inc.) C:\Users\Matro\Downloads\RealPlayer.exe
2013-09-15 16:45 - 2013-09-15 16:45 - 00773296 _____ (RealNetworks, Inc.) C:\Users\Matro\Downloads\RealPlayer (1).exe
2013-09-14 17:32 - 2013-09-12 16:01 - 00000000 ____D C:\Users\Matro\AppData\Roaming\.minecraft
2013-09-14 14:17 - 2013-09-14 14:06 - 04155007 _____ C:\Users\Matro\Downloads\minecraftforge-installer-1.6.2-9.10.0.799.jar
2013-09-14 14:13 - 2013-09-14 14:03 - 84734859 _____ C:\Users\Matro\Downloads\Pixelmon 2.3.1 install.zip
2013-09-14 13:36 - 2013-09-14 13:36 - 00000000 ____D C:\Users\Matro\AppData\Local\Tific
2013-09-14 13:35 - 2013-09-14 13:35 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Tific
2013-09-14 13:34 - 2013-09-14 13:34 - 00000000 ____D C:\Users\Matro\AppData\Local\Symantec
2013-09-13 21:28 - 2013-08-04 15:37 - 00000000 ___RD C:\Users\Matro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-13 21:26 - 2009-07-14 06:45 - 00348696 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-13 15:12 - 2013-09-13 15:11 - 09092696 _____ C:\Users\Matro\Downloads\Pokémon Kanto.rar
2013-09-12 16:01 - 2013-09-14 14:24 - 00675988 _____ C:\Users\Matro\Desktop\Minecraft.exe
2013-09-12 16:01 - 2013-09-12 16:01 - 00675988 _____ C:\Users\Matro\Downloads\Minecraft.exe
2013-09-12 15:38 - 2013-09-12 14:31 - 00000000 ____D C:\Users\Matro\Desktop\joke fotoalbum
2013-09-12 14:47 - 2013-09-12 14:47 - 00000000 ____D C:\Users\Matro\restore
2013-09-12 14:47 - 2013-08-04 15:30 - 00000000 ____D C:\Users\Matro
2013-09-12 14:45 - 2013-09-12 14:44 - 00000000 ____D C:\ProgramData\tmp
2013-09-12 14:44 - 2013-09-12 14:44 - 00000000 ____D C:\ProgramData\hps
2013-09-12 14:29 - 2013-09-12 14:29 - 00000000 ____D C:\Program Files (x86)\Mueller Foto
2013-09-12 14:28 - 2013-09-12 14:28 - 01600152 _____ C:\Users\Matro\Downloads\setup_Mueller_Fotowelt.exe
2013-09-11 15:13 - 2013-09-11 15:13 - 00000000 ____D C:\Users\Matro\AppData\Roaming\Watchtower
2013-09-11 15:06 - 2013-09-11 15:06 - 00001336 _____ C:\Users\Matro\Desktop\Watchtower Library 2012 - Deutsch.lnk
2013-09-11 15:06 - 2013-09-11 15:06 - 00000000 ____D C:\Program Files (x86)\Watchtower
2013-09-11 12:35 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
Some content of TEMP:
====================
C:\Users\Matro\AppData\Local\Temp\AutoRun.exe
C:\Users\Matro\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Matro\AppData\Local\Temp\HPQSi.exe
C:\Users\Matro\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Matro\AppData\Local\Temp\Quarantine.exe
C:\Users\Matro\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll
C:\Users\Matro\AppData\Local\Temp\uninst1.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-27 13:16
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013
Ran by Matro at 2013-10-10 13:14:42
Running from C:\Users\Matro\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.22 (x64 edition) (Version: 9.22.00.0)
Acrobat.com (x32 Version: 1.6.65)
ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.1)
Adobe AIR (x32 Version: 1.5.0.7220)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.174)
Adobe Reader XI (11.0.04) - Deutsch (x32 Version: 11.0.04)
Adobe Shockwave Player (x32 Version: 11.0)
Age of Wulin (x32 Version: 0.0.1.011)
Apple Application Support (x32 Version: 2.3.4)
Apple Software Update (x32 Version: 2.1.3.127)
Avira Free Antivirus (x32 Version: 13.0.0.4052)
Avira SearchFree Toolbar (x32 Version: 12.4.0.1130)
Compatibility Pack für 2007 Office System (x32 Version: 12.0.4518.1014)
CyberLink DVD Suite (x32 Version: 7.0.2111)
CyberLink MediaShow (x32 Version: 4.1.3325)
CyberLink PowerDVD 8 (x32 Version: 8.0.1.1005)
CyberLink YouCam (x32 Version: 3.0.2201)
Druckerdeinstallation für EPSON SX230 Series
EPSON Scan (x32)
Google Chrome (x32 Version: 30.0.1599.69)
Google Update Helper (x32 Version: 1.3.21.165)
HP Advisor (x32 Version: 3.3.9512.3162)
HP Customer Experience Enhancements (x32 Version: 6.0.1.3)
HP Games (x32 Version: 1.0.0.71)
HP Quick Launch Buttons (x32 Version: 6.50.7.1)
HP Setup (x32 Version: 1.2.3560.3170)
HP Support Assistant (x32 Version: 4.2.5.3)
HP Update (x32 Version: 5.005.000.001)
HP User Guides 0148 (x32 Version: 1.01.0005)
HP Wireless Assistant (x32 Version: 3.50.9.1)
HPAsset component for HP Active Support Library (x32 Version: 3.0.0.3)
IDT Audio (x32 Version: 1.0.6230.0)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Java(TM) 6 Update 15 (64-bit) (Version: 6.0.150)
Java(TM) SE Development Kit 6 Update 15 (64-bit) (Version: 1.6.0.150)
Junk Mail filter update (x32 Version: 14.0.8089.726)
LabelPrint (x32 Version: 2.5.2111)
LightScribe System Software (x32 Version: 1.18.8.1)
Magic Desktop (x32)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Choice Guard (x32 Version: 2.0.48.0)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.4518.1014)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office PowerPoint Viewer 2007 (German) (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Suite Activation Assistant (x32 Version: 2.9)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Search Enhancement Pack (x32 Version: 1.2.123.0)
Microsoft Silverlight (x32 Version: 3.0.40624.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0)
Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Works (x32 Version: 9.7.0621)
MSVCRT (x32 Version: 14.0.1468.721)
Müller Foto (x32 Version: 5.0.4)
muvee Reveal (x32 Version: 7.0.43.11502)
Network Addon Mod Version 30 mit Essentials r132 (HKCU Version: Version 30 mit Essentials r132)
NVIDIA Drivers (Version: 1.5)
PDF-XChange Lite 2012 (Version: 5.0.270.0)
Pflanzen gegen Zombies (x32)
Plants vs. Zombies (x32)
Power2Go (x32 Version: 6.0.3311)
PowerDirector (x32 Version: 7.0.3311)
QLBCASL (x32 Version: 6.40.17.2)
QuickTime (x32 Version: 7.74.80.86)
Realtek 8136 8168 8169 Ethernet Driver (x32 Version: 1.00.0007)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30104)
Recovery Manager (x32 Version: 5.5.2214)
SimCity 4 Deluxe (x32)
Synaptics Pointing Device Driver (Version: 13.2.4.12)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Office 2007 (KB934528) (x32)
Watchtower Library 2012 - Deutsch (x32 Version: 14.0)
Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5)
Windows Live Call (x32 Version: 14.0.8064.0206)
Windows Live Communications Platform (x32 Version: 14.0.8064.206)
Windows Live Essentials (x32 Version: 14.0.8089.0726)
Windows Live Essentials (x32 Version: 14.0.8089.726)
Windows Live Fotogalerie (x32 Version: 14.0.8081.709)
Windows Live Mail (x32 Version: 14.0.8089.0726)
Windows Live Messenger (x32 Version: 14.0.8089.0726)
Windows Live Movie Maker (x32 Version: 14.0.8091.0730)
Windows Live Sync (x32 Version: 14.0.8089.726)
Windows Live Toolbar (x32 Version: 14.0.8064.206)
Windows Live Writer (x32 Version: 14.0.8089.0726)
Windows Live-Uploadtool (x32 Version: 14.0.8014.1029)
WordToPDF 2.9 (x32 Version: 2.9)
==================== Restore Points =========================
20-09-2013 14:04:36 Removed Norton Online Backup
21-09-2013 14:19:42 Windows Update
21-09-2013 14:37:08 Installed QuickTime
26-09-2013 10:53:57 Removed Citrix Online Launcher
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {10D7E5AC-40A4-4FFE-A3E3-66244162B765} - System32\Tasks\Hewlett-Packard\HP Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2009-09-24] (Hewlett-Packard)
Task: {14B87DC2-E248-42E7-9353-2CDBB26BB8E3} - System32\Tasks\UpdaterEX => C:\Users\Matro\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE
Task: {189927C0-F49B-4396-91CC-C358E092B69D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {63969EA3-076B-4580-845F-B98FE20E1BCE} - System32\Tasks\Hewlett-Packard\HP Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2009-09-24] (Hewlett-Packard)
Task: {AA7035EE-F5A7-450F-9233-D4874C9595E2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-04] (Google Inc.)
Task: {EC0B6365-95E6-407B-91CB-2E19FA168015} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-04] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\Matro\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE
==================== Loaded Modules (whitelisted) =============
2013-09-22 13:59 - 2013-09-22 13:58 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2009-08-20 12:35 - 2009-08-20 12:35 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
2009-08-20 12:35 - 2009-08-20 12:35 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
2009-08-20 12:35 - 2009-08-20 12:35 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2009-09-29 16:25 - 2009-09-29 16:25 - 00061440 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll
2009-09-29 16:25 - 2009-09-29 16:25 - 00131072 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\ECenter\ECLibrary.dll
2009-09-29 16:25 - 2009-09-29 16:25 - 00040960 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingServer.dll
2009-09-29 16:25 - 2009-09-29 16:25 - 00005632 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingInterface.dll
2009-09-29 16:25 - 2009-09-29 16:25 - 00018944 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingMessages.dll
2009-09-29 16:25 - 2009-09-29 16:25 - 00036864 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingClients.dll
2009-09-29 16:25 - 2009-09-29 16:25 - 00028672 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll
2009-09-29 16:25 - 2009-09-29 16:25 - 00007680 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\RemotingClient.dll
2013-10-06 18:51 - 2013-10-03 08:02 - 00698832 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\libglesv2.dll
2013-10-06 18:51 - 2013-10-03 08:02 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\libegl.dll
2013-10-06 18:51 - 2013-10-03 08:03 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll
2013-10-06 18:51 - 2013-10-03 08:03 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll
2013-10-06 18:51 - 2013-10-03 08:02 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (10/08/2013 01:41:17 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0xb24
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (10/07/2013 01:41:37 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0x9a4
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (10/06/2013 05:49:05 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0x9ac
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (10/03/2013 02:51:33 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0x910
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (09/30/2013 02:12:35 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0xc14
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (09/27/2013 01:23:27 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.
Error: (09/27/2013 01:22:36 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (09/27/2013 01:19:48 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error: (09/27/2013 00:32:45 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0x7d0
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (09/25/2013 05:56:26 PM) (Source: MsiInstaller) (User: Matro-PC)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\GoogleUpdateHelper.msi
System errors:
=============
Error: (10/10/2013 09:35:57 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (10/10/2013 09:35:57 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Player-Netzwerkfreigabedienst erreicht.
Error: (10/10/2013 09:34:13 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (10/10/2013 09:34:13 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Browser-Schutz" ist vom Dienst "Avira Echtzeit-Scanner" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (10/10/2013 09:34:13 AM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (10/10/2013 09:34:09 AM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (10/09/2013 04:39:15 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (10/09/2013 04:39:15 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Google Update-Dienst (gupdate) erreicht.
Error: (10/09/2013 04:39:15 PM) (Source: DCOM) (User: )
Description: 1053gupdate/comsvc{4EB61BAC-A3B6-4760-9581-655041EF4D69}
Error: (10/09/2013 09:31:06 AM) (Source: DCOM) (User: )
Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 42%
Total physical RAM: 4062.93 MB
Available physical RAM: 2354.54 MB
Total Pagefile: 8124.04 MB
Available Pagefile: 5693.11 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:72.93 GB) (Free:5.03 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (SC4DELUXE2) (CDROM) (Total:0.65 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 73 GB) (Disk ID: BD296E65)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=73 GB) - (Type=07 NTFS)
==================== End Of Log ============================
ich hoffe, das stimmt so. |