Log-Analyse und Auswertung: Trojaner? - egdpsvc.exe
| ![]() Trojaner? - egdpsvc.exe Hallo Leute ![]() Ich vermute, mir vor zwei Tagen einen Trojaner eingefangen zu haben ![]() Alles fing an, als ich einen Scan mit McAfee machte. Dieser fand dann eine Datei namens egdpsvc.exe im Dateipfad: C:\ProgramData\eSafe . Mitunter war auch ein Ordner namens "log" dabei. Ohne nachzudenken versuchte ich dann die Dateien zu löschen. Doch was passierte? Die Datei egdpsvc.exe blieb übrig mit der Nachricht: "Die Aktion kann nicht abgeschlossen werden, da die Datei in Wsys Service geöffnet ist." ![]() Datei-Eigenschaften: Dateityp: Anwendung (.exe) Beschreibung: Wsys Control Größe: 368 KB (376.896 Bytes) Größe auf Datenträger: 372 KB (380.928 Bytes) Erstellt: Montag, 10. Juni 2013, 19:34:51 Geändert: Freitag, 19. Juli 2013, 05:56:21 (Ich hab nichts verändert ![]() Letzter Zugriff: Freitag, 19. Juli 2013, 14:24:28 (Ich wars nicht ! ) Laptop: Windows 7 (Home Premium) 32 bit |
Trojaner? - egdpsvc.exe

hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
| ![]() Trojaner? - egdpsvc.exe Alles Klar! Hab ich gemacht:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-07-2013 Ran by Dakota (administrator) on 25-07-2013 14:04:57 Running from C:\Users\Dakota\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Wsys Co., Ltd.) C:\ProgramData\eSafe\eGdpSvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Akamai Technologies, Inc.) C:\Users\Dakota\AppData\Local\Akamai\netsession_win.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Akamai Technologies, Inc.) C:\Users\Dakota\AppData\Local\Akamai\netsession_win.exe () C:\Program Files (x86)\Drakonia Configurator\hid.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Aeria Games & Entertainment) C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe (Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe () C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MpCmdRun.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MpCmdRun.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe (Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\AM_Delta_Patch_1.155.585.0.exe (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [x] HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-15] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [450048 2009-07-22] (IDT, Inc.) HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1281512 2013-01-27] (Microsoft Corporation) HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-17] (Hewlett-Packard Company) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Dakota\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Policies\system: [WallpaperStyle] 2 HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [WirelessAssistant] - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard) HKLM-x32\...\Run: [NeroFilterCheck] - C:\Windows\system32\NeroCheck.exe [x] HKLM-x32\...\Run: [GamingMouse] - C:\Program Files (x86)\Drakonia Configurator\hid.exe [246784 2012-06-07] () HKLM-x32\...\Run: [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [Aeria Ignite] - "C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe" silent [1925656 2013-06-06] (Aeria Games & Entertainment) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [2255184 2013-06-28] (LogMeIn Inc.) HKU\Default\...\Run: [HPADVISOR] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [x] HKU\Default\...\Policies\system: [WallpaperStyle] 2 HKU\Default User\...\Run: [HPADVISOR] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [x] HKU\Default User\...\Policies\system: [WallpaperStyle] 2 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir= HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=ST9320325AS_5VD1RV3N&ts=1370885674 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=ST9320325AS_5VD1RV3N&ts=1370885674 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=39033&tid=114&bs=true&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=ST9320325AS_5VD1RV3N&ts=1370885674 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=39033&tid=114&bs=true&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.certified-toolbar.com?si=39033&home=true&tid=114 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=39033&tid=114&bs=true&q= StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=ST9320325AS_5VD1RV3N&ts=1370885674 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir= SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {06F9F46B-CA24-4E27-B4BF-5BC974431D7F} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 SearchScopes: HKLM - {1E57CFDA-69AF-4AD6-9E35-82271301F4C5} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de SearchScopes: HKLM - {307DFD14-6C59-47E5-BB64-071E595673BE} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir= SearchScopes: HKLM - {6F3C3AD9-CAB2-E898-831A-33A5E3C05B61} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=vtt&from=vtt&uid=ST9320325AS_5VD1RV3N&ts=3670069 SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir= SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {06F9F46B-CA24-4E27-B4BF-5BC974431D7F} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 SearchScopes: HKLM-x32 - {0D7562AE-8EF6-416d-A838-AB665251703A} URL = hxxp://start.facemoods.com/?a=wfxt3&s={searchTerms}&f=4&hl={language}&src=chrm SearchScopes: HKLM-x32 - {1E57CFDA-69AF-4AD6-9E35-82271301F4C5} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de SearchScopes: HKLM-x32 - {307DFD14-6C59-47E5-BB64-071E595673BE} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir= SearchScopes: HKLM-x32 - {3FC013CF-C6E5-CF77-47F1-78C6A1E4050E} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=vtt&from=vtt&uid=ST9320325AS_5VD1RV3N&ts=3670069 SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=39033&bs=true&tid=114&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir= SearchScopes: HKCU - {307DFD14-6C59-47E5-BB64-071E595673BE} URL = SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir= SearchScopes: HKCU - {6F3C3AD9-CAB2-E898-831A-33A5E3C05B61} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST9320325AS_5VD1RV3N&ts=0 BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: No Name - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - No File BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM-x32 - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - No File Handler: msdaipp - No CLSID Value - Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation) Handler-x32: msdaipp - No CLSID Value - Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] Chrome: ======= CHR HomePage: hxxp://start.mysearchdial.com/?f=1&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir= CHR RestoreOnStartup: "hxxp://start.mysearchdial.com/?f=1&a=airmsd&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyDyB0F0ByByB0C0CtAtCtN0D0Tzu0CyDyCtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1832575095&ir=", "hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=ST9320325AS_5VD1RV3N&ts=1370885674" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.225\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (WacomTabletPlugin) - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (Unity Player) - C:\Users\Dakota\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (Java Deployment Toolkit - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealJukebox NS Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Download Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) CHR Extension: (Fabulous) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\Default\Extensions\ambjmeohlajelahhhniggkkceagdlcgj\28.6_0 CHR Extension: (Turn Off the Lights) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\ CHR Extension: (YouTube) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Facebook) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm\1.0.3_0 CHR Extension: (Webpage & WebCam Screenshot) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckibcdccnfeookdmbahgiakhnjcddpki\9.2_0 CHR Extension: (Google Search) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (Facebook Courage Wolf) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfejcfgfpcifgkniepcdakpiplpjgam\ CHR Extension: (FabCam) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejilffmihldhlfocnabcgndjjpgadfl\1.3_0 CHR Extension: (Dead space) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfonhecologdflefapajbpfmojehlohb\1_0 CHR Extension: (Looper for YouTube) - C:\Users\Dakota\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggpfpnahkgpnindfkdncknoldgnccdg\4.8_0 CHR HKLM\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\Dakota\AppData\Local\mysearchdial_speedial_v9.0.2.crx CHR HKLM-x32\...\Chrome\Extension: [bcfjehbfanfhgoehogmbiebedkidedjb] - C:\Users\Dakota\AppData\Local\CRE\bcfjehbfanfhgoehogmbiebedkidedjb.crx CHR HKLM-x32\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonChrome.crx CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx CHR HKLM-x32\...\Chrome\Extension: [lbbbdmbjkgojacipgefbifkiebpcdjhn] - C:\Program Files (x86)\Movie2KDownloader.com\m2kDownloader10.crx CHR HKLM-x32\...\Chrome\Extension: [nbmafkdmkkckhggblphicnnhlgljnoje] - C:\Program Files (x86)\TornTV.com\torn2_10.crx CHR HKLM-x32\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\Dakota\AppData\Local\mysearchdial_speedial_v9.0.2.crx ==================== Services (Whitelisted) ================= S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-07-01] (Adobe Systems) R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation) S3 npggsvc; C:\Windows\SysWow64\GameMon.des [3889424 2011-08-02] (INCA Internet Co., Ltd.) R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe [240128 2009-07-22] (IDT, Inc.) R2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [376896 2013-07-19] (Wsys Co., Ltd.) R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.) S2 ezSharedSvc; C:\Windows\System32\ezsvc7.dll [x] ==================== Drivers (Whitelisted) ==================== R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation) S3 NPPTNT2; C:\Windows\SysWow64\npptNT2.sys [4682 2005-01-01] (INCA Internet Co., Ltd.) S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [572416 2006-12-05] (PixArt Imaging Inc.) S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd) S3 VMUVC; C:\Windows\System32\Drivers\VMUVC.sys [198400 2009-03-11] (Vimicro Corporation) S3 vvftUVC; C:\Windows\System32\drivers\vvftUVC.sys [303616 2008-07-01] (Vimicro Corporation) S3 dump_wmimmc; \??\C:\AeriaGames\WolfTeam-DE\GameGuard\dump_wmimmc.sys [x] U4 eabfiltr; S3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x] S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x] S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x] S3 wolf; \??\C:\AeriaGames\WolfTeam-DE\avital\wolf64.sys [x] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-25 14:03 - 2013-07-25 14:03 - 00000000 ____D C:\FRST 2013-07-25 14:02 - 2013-07-25 14:02 - 01779761 _____ (Farbar) C:\Users\Dakota\Downloads\FRST64.exe 2013-07-25 13:59 - 2013-07-25 13:59 - 00726464 _____ (Enigma Software Group USA, LLC.) C:\Users\Dakota\Downloads\SpyHunter-Installer.exe 2013-07-22 22:12 - 2013-07-22 22:13 - 00000000 ____D C:\Users\Dakota\Documents\Cross Fire 2013-07-22 22:12 - 2013-07-22 22:12 - 00000000 ____D C:\CFLog 2013-07-22 20:56 - 2013-07-22 20:56 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-07-22 20:52 - 2013-07-22 20:56 - 00000886 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk 2013-07-22 20:49 - 2013-07-22 20:50 - 04292608 _____ C:\Users\Dakota\Downloads\hamachi_2.1.0.362.msi 2013-07-22 20:40 - 2013-07-22 20:40 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crossfire Europe 2013-07-22 20:16 - 2013-07-22 20:16 - 00000000 ____D C:\SG Interactive 2013-07-22 19:12 - 2013-07-22 19:56 - 00000000 ____D C:\Download 2013-07-22 19:09 - 2013-07-22 21:14 - 00000000 ____D C:\Program Files (x86)\Pando Networks 2013-07-22 19:09 - 2013-07-22 19:09 - 02999088 _____ C:\Users\Dakota\Downloads\Crossfire_downloader.exe 2013-07-22 18:50 - 2013-07-22 18:50 - 08227433 _____ C:\Users\Dakota\Downloads\giantsforest.zip 2013-07-21 20:29 - 2013-07-21 20:29 - 00000000 ____D C:\Program Files (x86)\Aeria Games 2013-07-21 17:52 - 2013-07-21 20:29 - 00000000 ____D C:\AeriaGames 2013-07-21 17:52 - 2013-07-21 17:52 - 00489056 _____ (Aeria Games & Entertainment) C:\Users\Dakota\Downloads\edeneternal_de_downloader.exe 2013-07-21 17:13 - 2013-07-21 17:31 - 175523943 _____ (Procedural Arts) C:\Users\Dakota\Downloads\FacadeInstaller1.1b.exe 2013-07-20 20:45 - 2013-07-20 20:45 - 00000000 ____D C:\Fraps 2013-07-20 20:43 - 2013-07-20 20:44 - 02632904 _____ C:\Users\Dakota\Downloads\F_v3.5.99.zip 2013-07-20 19:55 - 2013-07-20 20:04 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Audacity 2013-07-20 19:54 - 2013-07-20 19:55 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-07-20 19:52 - 2013-07-20 19:53 - 21281052 _____ (Audacity Team ) C:\Users\Dakota\Downloads\audacity-win-2.0.3.exe 2013-07-20 18:17 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2013-07-20 18:17 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2013-07-20 18:17 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2013-07-20 18:17 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2013-07-20 18:17 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2013-07-20 18:17 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2013-07-20 18:17 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2013-07-20 18:17 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2013-07-20 18:17 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2013-07-20 18:17 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2013-07-20 18:17 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2013-07-20 18:17 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2013-07-20 18:17 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2013-07-20 18:17 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2013-07-20 18:17 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2013-07-20 18:17 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2013-07-20 18:17 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2013-07-20 18:17 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2013-07-20 18:17 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2013-07-20 18:17 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2013-07-20 18:17 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2013-07-20 18:17 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2013-07-20 18:17 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2013-07-20 18:17 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2013-07-20 18:17 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2013-07-20 18:17 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2013-07-20 18:17 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2013-07-20 18:17 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2013-07-20 18:17 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2013-07-20 18:17 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2013-07-20 18:17 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2013-07-20 18:17 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2013-07-20 18:17 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2013-07-20 18:17 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2013-07-20 18:17 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2013-07-20 18:17 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2013-07-20 18:17 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2013-07-20 18:17 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2013-07-20 18:17 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2013-07-20 18:17 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2013-07-20 18:17 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2013-07-20 18:17 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2013-07-20 18:17 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2013-07-20 18:17 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2013-07-20 18:17 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2013-07-20 18:17 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2013-07-20 18:17 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2013-07-20 18:17 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2013-07-20 18:17 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2013-07-20 18:17 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2013-07-20 18:17 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2013-07-20 18:17 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2013-07-20 18:17 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2013-07-20 18:17 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2013-07-20 18:17 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2013-07-20 18:17 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2013-07-20 18:17 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2013-07-20 18:17 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2013-07-20 18:17 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2013-07-20 18:17 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2013-07-20 18:17 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2013-07-20 18:17 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2013-07-20 18:17 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2013-07-20 18:17 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2013-07-20 18:17 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2013-07-20 18:17 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2013-07-20 18:17 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2013-07-20 18:17 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2013-07-20 18:17 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2013-07-20 18:17 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2013-07-20 18:17 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2013-07-20 18:17 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2013-07-20 18:17 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2013-07-20 18:17 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2013-07-20 18:17 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2013-07-20 18:17 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2013-07-20 18:17 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2013-07-20 18:17 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2013-07-20 18:17 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2013-07-20 18:17 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2013-07-20 18:17 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2013-07-20 18:17 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2013-07-20 18:17 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2013-07-20 18:17 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2013-07-20 18:17 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2013-07-20 18:17 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2013-07-20 18:17 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2013-07-20 18:17 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2013-07-20 18:17 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2013-07-20 18:17 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2013-07-20 18:17 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2013-07-20 18:17 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2013-07-20 18:17 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2013-07-20 18:17 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2013-07-20 18:17 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2013-07-20 18:17 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2013-07-20 18:17 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2013-07-20 18:17 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2013-07-20 18:17 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2013-07-20 18:17 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2013-07-20 18:17 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2013-07-20 18:17 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2013-07-20 18:17 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2013-07-20 18:17 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2013-07-20 18:17 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2013-07-20 18:17 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2013-07-20 18:17 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2013-07-20 18:17 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2013-07-20 18:17 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2013-07-20 18:17 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2013-07-20 18:17 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2013-07-20 18:17 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2013-07-20 18:17 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2013-07-20 18:17 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2013-07-20 18:17 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2013-07-20 18:17 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2013-07-20 18:17 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2013-07-20 18:17 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2013-07-20 18:17 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2013-07-20 18:17 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2013-07-20 18:17 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2013-07-20 18:17 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2013-07-20 18:17 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2013-07-20 18:17 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2013-07-20 18:17 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2013-07-20 18:17 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2013-07-20 18:17 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2013-07-20 18:16 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2013-07-20 18:16 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2013-07-20 18:16 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2013-07-20 18:16 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2013-07-20 18:16 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2013-07-20 18:16 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2013-07-20 18:16 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2013-07-20 18:16 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2013-07-20 18:16 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2013-07-20 18:16 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2013-07-20 18:16 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2013-07-20 18:16 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2013-07-20 18:16 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2013-07-20 18:16 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2013-07-20 18:16 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2013-07-20 18:16 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2013-07-20 18:16 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2013-07-20 18:16 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2013-07-20 18:16 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2013-07-20 18:16 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2013-07-20 18:16 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2013-07-20 18:16 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2013-07-20 18:16 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2013-07-20 18:16 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2013-07-20 18:16 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2013-07-20 18:16 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2013-07-20 18:16 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2013-07-20 18:16 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2013-07-20 18:16 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2013-07-20 18:16 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2013-07-20 18:09 - 2013-07-21 14:39 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-07-20 18:09 - 2013-07-20 18:09 - 00000000 ____D C:\Users\Dakota\AppData\Local\Gameforge4d 2013-07-20 18:06 - 2013-07-20 18:06 - 19330312 _____ (Gameforge ) C:\Users\Dakota\Downloads\AION_GameforgeLiveSetup.exe 2013-07-20 00:25 - 2013-07-20 00:25 - 00445064 _____ (Font2U) C:\Users\Dakota\Downloads\DeadSpaceBoxArt.exe 2013-07-20 00:24 - 2013-07-20 00:25 - 00445064 _____ (Font2U) C:\Users\Dakota\Downloads\DeadSpace.exe 2013-07-20 00:01 - 2013-07-20 00:01 - 03512666 _____ C:\Users\Dakota\Downloads\Amnesia_Logo_RGB_black_2.0.psd 2013-07-19 22:13 - 2013-07-19 22:13 - 00027555 _____ C:\Users\Dakota\AppData\Local\recently-used.xbel 2013-07-18 20:50 - 2013-07-21 14:39 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Solveig Multimedia 2013-07-18 20:50 - 2013-07-20 20:32 - 00006144 _____ C:\Users\Dakota\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-07-18 20:40 - 2013-07-20 20:31 - 00000000 ____D C:\Users\Dakota\Documents\HyperCam3 2013-07-18 20:37 - 2013-07-18 20:38 - 15518288 _____ C:\Users\Dakota\Downloads\SolveigMM_HyperCam_3_5_1210_30.exe 2013-07-18 14:10 - 2013-07-18 14:10 - 00000000 ____D C:\Users\Dakota\Documents\Amnesia 2013-07-18 14:06 - 2013-07-18 14:08 - 00000000 ____D C:\Program Files (x86)\Amnesia - The Dark Descent Demo 2013-07-18 13:50 - 2013-07-18 14:05 - 164755352 _____ (Frictional Games ) C:\Users\Dakota\Downloads\amnesia_tdd_demo_1.0.1.exe 2013-07-18 13:18 - 2013-07-18 13:18 - 01873863 _____ (Infernum Productions AG ) C:\Users\Dakota\Downloads\DragonsProphetDownloader.exe 2013-07-18 00:15 - 2013-07-18 00:39 - 00000000 ____D C:\Users\Dakota\Documents\VirtualDJ 2013-07-18 00:15 - 2013-07-18 00:15 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ 2013-07-18 00:15 - 2013-07-18 00:15 - 00000000 ____D C:\Program Files (x86)\VirtualDJ 2013-07-18 00:00 - 2013-07-18 00:13 - 38944576 _____ (Atomix Productions) C:\Users\Dakota\Downloads\install_virtualdj_home_v7.4.exe 2013-07-16 04:03 - 2013-07-16 04:07 - 65812970 _____ C:\Users\Dakota\Downloads\Slender_v0_9_7.zip 2013-07-14 21:19 - 2013-07-14 21:20 - 00000000 ____D C:\Program Files (x86)\Minecraft 2013-07-14 21:19 - 2013-07-14 21:19 - 00423709 _____ C:\Users\Dakota\AppData\Local\mysearchdial_speedial_v9.0.2.crx 2013-07-14 21:19 - 2013-07-14 21:19 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft 2013-07-14 17:39 - 2013-07-14 17:39 - 00000000 ____D C:\037296bcc2f620cf5a33e9a6 2013-07-14 16:13 - 2013-07-14 16:13 - 00445064 _____ (Font2U) C:\Users\Dakota\Downloads\ShogunsClan.exe 2013-07-14 13:43 - 2013-07-14 13:43 - 00000000 ____D C:\2131f5bc6b69e7befb43 2013-07-14 00:16 - 2013-07-14 00:17 - 00000000 ____D C:\db8d7f0816ff4f950a09d94b 2013-07-12 19:34 - 2013-07-12 19:34 - 00000000 ____D C:\4db5e680af4c9f209868f2b0c2b4 2013-07-12 15:35 - 2013-07-12 15:35 - 00298595 _____ C:\Users\Dakota\Documents\lupaxcf.xcf 2013-07-12 01:21 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-12 01:21 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-12 01:21 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-12 01:21 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-12 01:21 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-12 01:21 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-12 01:21 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-12 01:21 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-12 01:21 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-12 01:21 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-12 01:21 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-12 01:21 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-12 01:21 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-12 01:21 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-12 01:21 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-12 01:21 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-12 01:21 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-12 01:21 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-12 01:21 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-12 01:21 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-12 01:21 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-12 01:21 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-12 01:21 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-12 01:21 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-12 01:21 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-12 01:21 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-12 01:21 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-12 01:21 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-12 01:21 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-12 01:21 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-12 01:21 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-12 00:41 - 2013-07-12 00:47 - 01004589 _____ C:\Users\Dakota\Documents\lupa11.xcf 2013-07-12 00:01 - 2013-07-12 00:01 - 00000000 ____D C:\Users\Dakota\AppData\Local\webkit 2013-07-11 23:48 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-11 23:48 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-11 23:48 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-11 23:48 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-11 23:47 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-11 23:47 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-11 23:47 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-10 23:56 - 2013-07-10 23:56 - 00000000 ____D C:\Users\Public\Documents\Avanquest Software 2013-07-10 23:56 - 2013-07-10 23:56 - 00000000 ____D C:\ProgramData\Avanquest 2013-07-10 14:44 - 2013-07-10 15:02 - 20840808 _____ C:\Users\Dakota\Documents\h.xcf 2013-07-09 22:53 - 2013-07-09 22:53 - 00000000 ____D C:\Users\Dakota\Documents\DVDVideoSoft 2013-07-09 22:10 - 2013-07-09 22:52 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-07-09 20:07 - 2013-07-09 21:30 - 02750212 _____ C:\Users\Dakota\Documents\intro.blend 2013-07-09 20:07 - 2013-07-09 21:13 - 03291024 _____ C:\Users\Dakota\Documents\intro.blend2 2013-07-09 20:07 - 2013-07-09 21:13 - 02722236 _____ C:\Users\Dakota\Documents\intro.blend1 2013-07-08 21:48 - 2013-07-15 15:00 - 00000000 ____D C:\Users\Dakota\AppData\Local\SwvUpdater 2013-07-06 15:46 - 2013-07-06 15:46 - 02178214 _____ C:\Users\Dakota\Documents\hg.xcf 2013-07-06 02:51 - 2013-07-06 02:51 - 00187040 _____ C:\Users\Dakota\Documents\Herobrine.xcf 2013-07-04 18:16 - 2013-07-04 22:37 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Origin 2013-07-04 18:15 - 2013-07-04 23:14 - 00000000 ____D C:\ProgramData\Origin 2013-07-04 18:15 - 2013-07-04 18:15 - 00000554 _____ C:\Windows\KB893803v2.log 2013-07-04 18:15 - 2013-07-04 18:15 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-07-04 11:51 - 2013-07-04 11:51 - 01034889 _____ C:\Users\Dakota\2013-07-04_11.45.39.xcf 2013-07-04 11:34 - 2013-07-04 11:34 - 00254695 _____ C:\Users\Dakota\Documents\frg.xcf 2013-07-04 00:34 - 2013-07-04 00:44 - 00112455 _____ C:\Users\Dakota\Documents\21323.xcf 2013-07-03 22:10 - 2013-07-23 22:43 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\.minecraft 2013-07-02 17:41 - 2013-07-02 17:41 - 00000000 ____D C:\Users\Dakota\Documents\AdobeStockPhotos 2013-07-02 11:38 - 2013-07-02 11:38 - 00000000 ____D C:\Users\Dakota\Documents\Updater 2013-07-01 19:58 - 2013-07-01 19:59 - 00000000 ____D C:\Users\Public\Documents\Adobe PDF 2013-07-01 19:53 - 2013-07-01 19:53 - 00000000 ____D C:\PS_CS2_Gr_NonRet 2013-07-01 16:34 - 2013-07-23 23:33 - 00000000 ____D C:\Users\Dakota\minecraft 2013-07-01 13:05 - 2013-07-01 13:05 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-07-01 13:05 - 2013-07-01 13:05 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-06-29 00:28 - 2013-06-29 00:36 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\PhotoScape 2013-06-28 23:43 - 2013-07-15 15:02 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\SoundSpectrum 2013-06-28 23:43 - 2013-06-28 23:43 - 00000000 ____D C:\Users\Dakota\AppData\Local\SoundSpectrum 2013-06-28 17:49 - 2013-06-28 17:49 - 00000000 ____D C:\Users\Dakota\Documents\Electronic Arts 2013-06-26 22:52 - 2013-06-26 23:20 - 00103956 _____ C:\Users\Dakota\Documents\pr.xcf 2013-06-25 21:35 - 2013-07-16 01:10 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Minecraft Version Changer 2013-06-25 21:35 - 2013-06-25 21:35 - 00000000 ____D C:\Users\Dakota\AppData\Local\Craften_Dev_Team 2013-06-25 21:35 - 2013-06-25 21:35 - 00000000 ____D C:\Program Files (x86)\Craften Terminal 2013-06-25 21:32 - 2013-06-25 21:32 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Sun 2013-06-25 07:45 - 2013-06-25 07:45 - 00271048 _____ C:\Users\Dakota\Documents\doof.xcf ==================== One Month Modified Files and Folders ======= 2013-07-25 14:05 - 2011-01-02 23:20 - 01752610 _____ C:\Windows\WindowsUpdate.log 2013-07-25 14:03 - 2013-07-25 14:03 - 00000000 ____D C:\FRST 2013-07-25 14:02 - 2013-07-25 14:02 - 01779761 _____ (Farbar) C:\Users\Dakota\Downloads\FRST64.exe 2013-07-25 14:02 - 2013-06-02 00:19 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Skype 2013-07-25 13:59 - 2013-07-25 13:59 - 00726464 _____ (Enigma Software Group USA, LLC.) C:\Users\Dakota\Downloads\SpyHunter-Installer.exe 2013-07-25 13:57 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-25 13:57 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-25 13:54 - 2013-06-10 19:34 - 00000000 ____D C:\ProgramData\eSafe 2013-07-25 13:50 - 2013-06-01 17:09 - 00000000 ____D C:\Users\Dakota\AppData\Local\LogMeIn Hamachi 2013-07-25 13:48 - 2013-06-01 21:24 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-25 13:48 - 2013-05-31 05:13 - 00015652 _____ C:\Windows\setupact.log 2013-07-25 13:48 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-25 03:40 - 2013-06-01 21:24 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-25 03:34 - 2012-09-08 18:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-25 01:40 - 2013-04-12 16:35 - 00000932 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3206992381-2132139690-1252408596-1000UA.job 2013-07-24 17:56 - 2013-06-22 13:34 - 00000000 ___RD C:\Users\Dakota\Desktop\Anwendungen 2013-07-24 17:56 - 2013-06-01 17:30 - 00000000 ___RD C:\Users\Dakota\Desktop\Videospiele 2013-07-24 16:40 - 2013-04-12 16:35 - 00000910 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3206992381-2132139690-1252408596-1000Core.job 2013-07-23 23:33 - 2013-07-01 16:34 - 00000000 ____D C:\Users\Dakota\minecraft 2013-07-23 23:24 - 2013-06-01 22:06 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\vlc 2013-07-23 22:43 - 2013-07-03 22:10 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\.minecraft 2013-07-22 22:13 - 2013-07-22 22:12 - 00000000 ____D C:\Users\Dakota\Documents\Cross Fire 2013-07-22 22:12 - 2013-07-22 22:12 - 00000000 ____D C:\CFLog 2013-07-22 21:14 - 2013-07-22 19:09 - 00000000 ____D C:\Program Files (x86)\Pando Networks 2013-07-22 20:56 - 2013-07-22 20:56 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-07-22 20:56 - 2013-07-22 20:52 - 00000886 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk 2013-07-22 20:50 - 2013-07-22 20:49 - 04292608 _____ C:\Users\Dakota\Downloads\hamachi_2.1.0.362.msi 2013-07-22 20:40 - 2013-07-22 20:40 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crossfire Europe 2013-07-22 20:16 - 2013-07-22 20:16 - 00000000 ____D C:\SG Interactive 2013-07-22 19:56 - 2013-07-22 19:12 - 00000000 ____D C:\Download 2013-07-22 19:09 - 2013-07-22 19:09 - 02999088 _____ C:\Users\Dakota\Downloads\Crossfire_downloader.exe 2013-07-22 18:50 - 2013-07-22 18:50 - 08227433 _____ C:\Users\Dakota\Downloads\giantsforest.zip 2013-07-22 17:38 - 2009-08-19 23:42 - 00711890 _____ C:\Windows\system32\perfh007.dat 2013-07-22 17:38 - 2009-08-19 23:42 - 00153098 _____ C:\Windows\system32\perfc007.dat 2013-07-22 17:38 - 2009-07-14 07:13 - 01642392 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-22 00:14 - 2013-06-01 22:03 - 00016986 _____ C:\Windows\PFRO.log 2013-07-21 23:26 - 2013-06-07 13:43 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\TeamViewer 2013-07-21 20:29 - 2013-07-21 20:29 - 00000000 ____D C:\Program Files (x86)\Aeria Games 2013-07-21 20:29 - 2013-07-21 17:52 - 00000000 ____D C:\AeriaGames 2013-07-21 20:29 - 2013-03-30 22:00 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin 2013-07-21 17:52 - 2013-07-21 17:52 - 00489056 _____ (Aeria Games & Entertainment) C:\Users\Dakota\Downloads\edeneternal_de_downloader.exe 2013-07-21 17:31 - 2013-07-21 17:13 - 175523943 _____ (Procedural Arts) C:\Users\Dakota\Downloads\FacadeInstaller1.1b.exe 2013-07-21 14:39 - 2013-07-20 18:09 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-07-21 14:39 - 2013-07-18 20:50 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Solveig Multimedia 2013-07-21 13:04 - 2012-05-25 12:02 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2013-07-21 13:04 - 2011-01-09 17:48 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log 2013-07-21 13:02 - 2013-06-14 20:46 - 00000000 ____D C:\Users\Dakota\AppData\Local\Adobe 2013-07-21 12:56 - 2012-09-08 18:59 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-21 12:56 - 2012-09-08 18:59 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-07-21 12:56 - 2011-05-20 06:37 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-20 20:45 - 2013-07-20 20:45 - 00000000 ____D C:\Fraps 2013-07-20 20:44 - 2013-07-20 20:43 - 02632904 _____ C:\Users\Dakota\Downloads\F_v3.5.99.zip 2013-07-20 20:32 - 2013-07-18 20:50 - 00006144 _____ C:\Users\Dakota\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-07-20 20:31 - 2013-07-18 20:40 - 00000000 ____D C:\Users\Dakota\Documents\HyperCam3 2013-07-20 20:22 - 2013-06-01 19:29 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\DVDVideoSoft 2013-07-20 20:04 - 2013-07-20 19:55 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Audacity 2013-07-20 19:55 - 2013-07-20 19:54 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-07-20 19:53 - 2013-07-20 19:52 - 21281052 _____ (Audacity Team ) C:\Users\Dakota\Downloads\audacity-win-2.0.3.exe 2013-07-20 18:17 - 2013-06-01 23:37 - 00010796 _____ C:\Windows\DirectX.log 2013-07-20 18:09 - 2013-07-20 18:09 - 00000000 ____D C:\Users\Dakota\AppData\Local\Gameforge4d 2013-07-20 18:06 - 2013-07-20 18:06 - 19330312 _____ (Gameforge ) C:\Users\Dakota\Downloads\AION_GameforgeLiveSetup.exe 2013-07-20 15:23 - 2013-06-01 17:09 - 00098800 _____ C:\Users\Dakota\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-20 15:23 - 2009-07-14 06:45 - 00391520 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-20 00:28 - 2013-06-02 18:08 - 00000000 ____D C:\Users\Dakota\.gimp-2.8 2013-07-20 00:25 - 2013-07-20 00:25 - 00445064 _____ (Font2U) C:\Users\Dakota\Downloads\DeadSpaceBoxArt.exe 2013-07-20 00:25 - 2013-07-20 00:24 - 00445064 _____ (Font2U) C:\Users\Dakota\Downloads\DeadSpace.exe 2013-07-20 00:01 - 2013-07-20 00:01 - 03512666 _____ C:\Users\Dakota\Downloads\Amnesia_Logo_RGB_black_2.0.psd 2013-07-19 22:13 - 2013-07-19 22:13 - 00027555 _____ C:\Users\Dakota\AppData\Local\recently-used.xbel 2013-07-19 21:49 - 2013-06-14 15:36 - 01313286 _____ C:\Users\Dakota\Documents\Unbenannt.xcf 2013-07-18 20:38 - 2013-07-18 20:37 - 15518288 _____ C:\Users\Dakota\Downloads\SolveigMM_HyperCam_3_5_1210_30.exe 2013-07-18 14:10 - 2013-07-18 14:10 - 00000000 ____D C:\Users\Dakota\Documents\Amnesia 2013-07-18 14:08 - 2013-07-18 14:06 - 00000000 ____D C:\Program Files (x86)\Amnesia - The Dark Descent Demo 2013-07-18 14:05 - 2013-07-18 13:50 - 164755352 _____ (Frictional Games ) C:\Users\Dakota\Downloads\amnesia_tdd_demo_1.0.1.exe 2013-07-18 13:18 - 2013-07-18 13:18 - 01873863 _____ (Infernum Productions AG ) C:\Users\Dakota\Downloads\DragonsProphetDownloader.exe 2013-07-18 00:39 - 2013-07-18 00:15 - 00000000 ____D C:\Users\Dakota\Documents\VirtualDJ 2013-07-18 00:15 - 2013-07-18 00:15 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ 2013-07-18 00:15 - 2013-07-18 00:15 - 00000000 ____D C:\Program Files (x86)\VirtualDJ 2013-07-18 00:13 - 2013-07-18 00:00 - 38944576 _____ (Atomix Productions) C:\Users\Dakota\Downloads\install_virtualdj_home_v7.4.exe 2013-07-16 04:07 - 2013-07-16 04:03 - 65812970 _____ C:\Users\Dakota\Downloads\Slender_v0_9_7.zip 2013-07-16 01:10 - 2013-06-25 21:35 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Minecraft Version Changer 2013-07-15 15:02 - 2013-06-28 23:43 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\SoundSpectrum 2013-07-15 15:02 - 2013-04-25 15:47 - 00000000 ____D C:\Program Files (x86)\SoundSpectrum 2013-07-15 15:00 - 2013-07-08 21:48 - 00000000 ____D C:\Users\Dakota\AppData\Local\SwvUpdater 2013-07-14 21:20 - 2013-07-14 21:19 - 00000000 ____D C:\Program Files (x86)\Minecraft 2013-07-14 21:19 - 2013-07-14 21:19 - 00423709 _____ C:\Users\Dakota\AppData\Local\mysearchdial_speedial_v9.0.2.crx 2013-07-14 21:19 - 2013-07-14 21:19 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft 2013-07-14 17:39 - 2013-07-14 17:39 - 00000000 ____D C:\037296bcc2f620cf5a33e9a6 2013-07-14 16:13 - 2013-07-14 16:13 - 00445064 _____ (Font2U) C:\Users\Dakota\Downloads\ShogunsClan.exe 2013-07-14 13:44 - 2012-05-25 12:03 - 01620286 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-07-14 13:43 - 2013-07-14 13:43 - 00000000 ____D C:\2131f5bc6b69e7befb43 2013-07-14 10:47 - 2013-06-02 00:19 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-07-14 10:47 - 2013-06-02 00:19 - 00000000 ____D C:\ProgramData\Skype 2013-07-14 00:17 - 2013-07-14 00:16 - 00000000 ____D C:\db8d7f0816ff4f950a09d94b 2013-07-13 14:58 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-07-13 14:35 - 2013-06-01 21:24 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-13 14:35 - 2013-06-01 21:24 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-12 19:34 - 2013-07-12 19:34 - 00000000 ____D C:\4db5e680af4c9f209868f2b0c2b4 2013-07-12 15:35 - 2013-07-12 15:35 - 00298595 _____ C:\Users\Dakota\Documents\lupaxcf.xcf 2013-07-12 06:45 - 2013-03-28 22:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-12 06:45 - 2013-03-28 22:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-12 06:45 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-12 06:45 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-12 01:22 - 2011-01-03 17:20 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-07-12 00:47 - 2013-07-12 00:41 - 01004589 _____ C:\Users\Dakota\Documents\lupa11.xcf 2013-07-12 00:01 - 2013-07-12 00:01 - 00000000 ____D C:\Users\Dakota\AppData\Local\webkit 2013-07-10 23:56 - 2013-07-10 23:56 - 00000000 ____D C:\Users\Public\Documents\Avanquest Software 2013-07-10 23:56 - 2013-07-10 23:56 - 00000000 ____D C:\ProgramData\Avanquest 2013-07-10 23:56 - 2009-08-19 13:54 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-10 15:02 - 2013-07-10 14:44 - 20840808 _____ C:\Users\Dakota\Documents\h.xcf 2013-07-09 22:53 - 2013-07-09 22:53 - 00000000 ____D C:\Users\Dakota\Documents\DVDVideoSoft 2013-07-09 22:52 - 2013-07-09 22:10 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-07-09 21:30 - 2013-07-09 20:07 - 02750212 _____ C:\Users\Dakota\Documents\intro.blend 2013-07-09 21:13 - 2013-07-09 20:07 - 03291024 _____ C:\Users\Dakota\Documents\intro.blend2 2013-07-09 21:13 - 2013-07-09 20:07 - 02722236 _____ C:\Users\Dakota\Documents\intro.blend1 2013-07-06 15:46 - 2013-07-06 15:46 - 02178214 _____ C:\Users\Dakota\Documents\hg.xcf 2013-07-06 02:51 - 2013-07-06 02:51 - 00187040 _____ C:\Users\Dakota\Documents\Herobrine.xcf 2013-07-05 16:45 - 2013-06-01 17:08 - 00000000 ____D C:\Users\Dakota 2013-07-05 13:25 - 2013-06-24 07:20 - 00000000 ____D C:\Users\Dakota\AppData\Local\Facebook 2013-07-04 23:25 - 2009-08-19 14:43 - 00000000 ___RD C:\Program Files\Online Services 2013-07-04 23:14 - 2013-07-04 18:15 - 00000000 ____D C:\ProgramData\Origin 2013-07-04 23:11 - 2013-04-11 17:53 - 00000000 ____D C:\Windows\System32\Tasks\Games 2013-07-04 22:37 - 2013-07-04 18:16 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Origin 2013-07-04 18:15 - 2013-07-04 18:15 - 00000554 _____ C:\Windows\KB893803v2.log 2013-07-04 18:15 - 2013-07-04 18:15 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-07-04 18:04 - 2013-05-01 13:02 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-07-04 11:51 - 2013-07-04 11:51 - 01034889 _____ C:\Users\Dakota\2013-07-04_11.45.39.xcf 2013-07-04 11:34 - 2013-07-04 11:34 - 00254695 _____ C:\Users\Dakota\Documents\frg.xcf 2013-07-04 00:44 - 2013-07-04 00:34 - 00112455 _____ C:\Users\Dakota\Documents\21323.xcf 2013-07-02 18:17 - 2013-06-01 17:08 - 00000000 ____D C:\Users\Dakota\AppData\Local\VirtualStore 2013-07-02 18:02 - 2013-06-01 17:08 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Adobe 2013-07-02 17:41 - 2013-07-02 17:41 - 00000000 ____D C:\Users\Dakota\Documents\AdobeStockPhotos 2013-07-02 15:27 - 2013-06-01 17:08 - 00000000 ___RD C:\Users\Dakota\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-02 11:38 - 2013-07-02 11:38 - 00000000 ____D C:\Users\Dakota\Documents\Updater 2013-07-02 11:38 - 2009-07-14 04:34 - 00000499 _____ C:\Windows\win.ini 2013-07-01 20:04 - 2009-08-19 15:30 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-01 19:59 - 2013-07-01 19:58 - 00000000 ____D C:\Users\Public\Documents\Adobe PDF 2013-07-01 19:55 - 2009-08-19 15:30 - 00000000 ____D C:\ProgramData\Adobe 2013-07-01 19:53 - 2013-07-01 19:53 - 00000000 ____D C:\PS_CS2_Gr_NonRet 2013-07-01 13:05 - 2013-07-01 13:05 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-07-01 13:05 - 2013-07-01 13:05 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-07-01 13:05 - 2013-03-28 22:15 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-07-01 13:05 - 2013-03-28 22:15 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-07-01 13:05 - 2012-05-25 11:59 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npdeployJava1.dll 2013-07-01 13:05 - 2011-01-03 16:43 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-07-01 13:05 - 2009-08-19 16:12 - 00000000 ____D C:\Program Files (x86)\Java 2013-06-29 11:04 - 2013-06-01 23:35 - 00000000 ____D C:\Users\Dakota\AppData\Local\Windows Live 2013-06-29 00:36 - 2013-06-29 00:28 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\PhotoScape 2013-06-28 23:43 - 2013-06-28 23:43 - 00000000 ____D C:\Users\Dakota\AppData\Local\SoundSpectrum 2013-06-28 23:40 - 2009-08-19 14:35 - 00000000 ___RD C:\Program Files (x86)\Online Services 2013-06-28 23:29 - 2009-08-19 13:52 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard 2013-06-28 18:38 - 2013-06-06 19:48 - 00000000 ____D C:\Users\Dakota\AppData\Local\Akamai 2013-06-28 17:49 - 2013-06-28 17:49 - 00000000 ____D C:\Users\Dakota\Documents\Electronic Arts 2013-06-26 23:20 - 2013-06-26 22:52 - 00103956 _____ C:\Users\Dakota\Documents\pr.xcf 2013-06-25 21:35 - 2013-06-25 21:35 - 00000000 ____D C:\Users\Dakota\AppData\Local\Craften_Dev_Team 2013-06-25 21:35 - 2013-06-25 21:35 - 00000000 ____D C:\Program Files (x86)\Craften Terminal 2013-06-25 21:32 - 2013-06-25 21:32 - 00000000 ____D C:\Users\Dakota\AppData\Roaming\Sun 2013-06-25 07:45 - 2013-06-25 07:45 - 00271048 _____ C:\Users\Dakota\Documents\doof.xcf ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-24 19:17 ==================== End Of Log ============================ Addition: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-07-2013 Ran by Dakota at 2013-07-25 14:06:51 Running from C:\Users\Dakota\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: Adobe Bridge 1.0 (x32 Version: 001.000.001) Adobe Common File Installer (x32 Version: 1.00.001) Adobe Flash Player 10 ActiveX (x32 Version: Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Adobe Help Center 1.0 (x32 Version: 1.0.1) Adobe Photoshop CS2 (x32 Version: 9.0) Adobe Reader X (10.1.7) - Deutsch (x32 Version: 10.1.7) Adobe Shockwave Player 12.0 (x32 Version: Adobe Stock Photos 1.0 (x32 Version: 1.0.1) Advanced Driver Updater (x32 Version: 1.0.850.11203) Aeria Ignite (x32 Version: 1.13.3296) Akamai NetSession Interface (HKCU) Amnesia - The Dark Descent Demo (x32 Version: 1.0.1) Audacity 2.0.3 (x32 Version: 2.0.3) Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000) Corel Shell Extension - 64Bit (Version: 14.0) CorelDRAW Graphics Suite X4 - Capture (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Content (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Draw (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Filters (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - FontNav (x32 Version: 14.0) CorelDRAW Graphics SUite X4 - ICA (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - IPM (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang BR (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang CZ (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang DE (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang EN (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang ES (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang FR (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang IT (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang NL (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang PL (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang SU (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - Lang SV (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - PP (x32 Version: 14.0) CorelDRAW Graphics Suite X4 - VBA (x32 Version: 14.0) CorelDRAW Graphics Suite X4 (x32 Version: 14.0) CorelDRAW(R) Graphics Suite X4 - Windows Shell Extension (x32 Version: 1.0) CorelDRAW(R) Graphics Suite X4 - Windows Shell Extension (x32) CorelDRAW(R) Graphics Suite X4 (x32) Craften Terminal 3.3.4897.28268 (x32 Version: 3.3.4897.28268) Crossfire Europe (x32 Version: 1.172) D3DX10 (x32 Version: 15.4.2368.0902) Die Sims™ 3 (x32 Version: 1.26.89) Die Sims™ 3 Einfach tierisch (x32 Version: 10.0.96) DomaIQ (x32) Drakonia Configurator (x32) EdenEternal-DE (x32) Facebook Video Calling (x32 Version: 1.2.287) Fotogalerie (x32 Version: 16.4.3508.0205) Fraps (remove only) (x32) Free Audio Dub version (x32 Version: Free Studio version 2013 (x32 Version: GIMP 2.8.4 (Version: 2.8.4) Google Chrome (x32 Version: 28.0.1500.72) Google Update Helper (x32 Version: Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000) HP DVD Play 3.7 (x32 Version: HP Games (x32 Version: HP Quick Launch Buttons (x32 Version: HP Setup (x32 Version: 1.2.3220.3079) HP Support Assistant (x32 Version: HP Update (x32 Version: HP User Guides 0148 (x32 Version: 1.01.0005) HP Wireless Assistant (x32 Version: IDT Audio (x32 Version: 1.0.6225.0) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: Java(TM) 6 Update 14 (64-bit) (Version: 6.0.140) Java(TM) 6 Update 20 (x32 Version: 6.0.200) Junk Mail filter update (x32 Version: 16.4.3508.0205) LightScribe System Software (x32 Version: LogMeIn Hamachi (x32 Version: ManyCam 3.1.53 (x32 Version: 3.1.53) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office XP Professional mit FrontPage (x32 Version: 10.0.6626.0) Microsoft Security Client (Version: 4.2.0223.1) Microsoft Security Essentials (Version: Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Movie Maker (x32 Version: 16.4.3508.0205) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MSVCRT110 (x32 Version: 16.4.1108.0727) MSVCRT110_amd64 (Version: 16.4.1109.0912) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) nder (Version: 2.67b) neroxml (x32 Version: 1.0.0) NVIDIA Drivers (Version: 1.5) Photo Common (x32 Version: 16.4.3508.0205) Photo Gallery (x32 Version: 16.4.3508.0205) PhotoScape (x32) PowerRecover (x32 Version: 5.5.1923) ProtectDisc Driver, Version 11 (x32 Version: QLBCASL (x32 Version: RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0) RealPlayer (x32 Version: 15.0.6) Realtek 8136 8168 8169 Ethernet Driver (x32 Version: 1.00.0007) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7100.30094) RealUpgrade 1.1 (x32 Version: 1.1.0) Screenshot Captor 4.03.00 (x32) Skype™ 6.6 (x32 Version: 6.6.106) swMSM (x32 Version: Synaptics Pointing Device Driver (Version: Synthesia (x32 Version: 8.5) TeamViewer 8 (x32 Version: 8.0.19617) Unity Web Player (HKCU Version: ) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) VCRedistSetup (x32 Version: 1.0.0) VirtualDJ Home FREE (x32 Version: 7.4) Visual Basic for Applications (R) Core - English (x32 Version: Visual Basic for Applications (R) Core - German (x32 Version: Visual Basic for Applications (R) Core (x32 Version: VLC media player 2.0.5 (x32 Version: 2.0.5) Wacom (Version: 5.3.2-1) WebTablet FB Plugin 32 bit (x32 Version: WebTablet FB Plugin 64 bit (Version: Windows Live Communications Platform (x32 Version: 16.4.3508.0205) Windows Live Essentials (x32 Version: 16.4.3508.0205) Windows Live ID Sign-in Assistant (Version: 7.250.4311.0) Windows Live Installer (x32 Version: 16.4.3508.0205) Windows Live Mail (x32 Version: 16.4.3508.0205) Windows Live Messenger (x32 Version: 16.4.3508.0205) Windows Live MIME IFilter (Version: 16.4.3508.0205) Windows Live Photo Common (x32 Version: 16.4.3508.0205) Windows Live PIMT Platform (x32 Version: 16.4.3508.0205) Windows Live SOXE (x32 Version: 16.4.3508.0205) Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205) Windows Live Sync (x32 Version: 14.0.8064.206) Windows Live UX Platform (x32 Version: 16.4.3508.0205) Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205) Windows Live Writer (x32 Version: 16.4.3508.0205) Windows Live Writer Resources (x32 Version: 16.4.3508.0205) Windows Movie Maker (Version: 6.0.6002.18005) WinRAR 4.10 (64-Bit) (Version: 4.10.0) ==================== Restore Points ========================= 17-07-2013 17:17:50 Windows Update 20-07-2013 16:15:48 DirectX wurde installiert 21-07-2013 13:10:16 Windows Update 22-07-2013 18:44:20 Removed LogMeIn Hamachi 22-07-2013 18:51:08 Installed LogMeIn Hamachi 25-07-2013 12:01:55 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {051EA064-EFBD-43DE-933D-540AACD1337F} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3206992381-2132139690-1252408596-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-07-27] (RealNetworks, Inc.) Task: {0E088732-F9DE-4C10-B6D8-2F4591AB06BF} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3206992381-2132139690-1252408596-1000UA => C:\Users\Fossie\AppData\Local\Facebook\Update\FacebookUpdate.exe No File Task: {11CC0629-77AC-4C3C-AC9C-66E0EF43CAC6} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP TCS\RemEngine.exe [2009-07-08] () Task: {138E81AE-AF0A-4782-BBA3-3FB42868A4E2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {206490C7-E72C-4D04-95BC-6EAF3E9B0FE0} - System32\Tasks\{51B86A52-385A-4267-952B-15F409E53C94} => C:\Program Files\MyPaint\mypaint.exe No File Task: {3DD7F5EC-A3E3-43E4-9575-F90E9F4E747D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-01] (Google Inc.) Task: {5C4D15F3-2631-4A16-AD1E-35918831EB00} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe No File Task: {5E41DB60-26E1-4139-9B41-3869B9934730} - System32\Tasks\Sun Microsystems-Online-Aktualisierungsprogramm => C:\Program Files\Java\jre6\bin\jusched.exe [2009-08-19] (Sun Microsystems, Inc.) Task: {64D15177-57CE-43BC-B6E1-D1C3ABF07404} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {65E32387-98E5-4F85-8906-BCF864D8BEE8} - System32\Tasks\Real Player-Online-Aktualisierungsprogramm => c:\program files (x86)\real\realplayer\Update\realsched.exe [2012-09-08] (RealNetworks, Inc.) Task: {6DF5A1EF-C434-4C8E-BB1A-F5777EE9754C} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08] (Hewlett-Packard) Task: {8A3C0EB9-FCC0-4268-9DB7-A31912359D39} - System32\Tasks\WPD\SqmUpload_S-1-5-21-3206992381-2132139690-1252408596-1005 => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {8C413BD7-FE53-4C97-A8B1-B47F34DB4736} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {8C417769-6DC2-4D0B-B8EF-34EC7A854C02} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-21] (Adobe Systems Incorporated) Task: {8F3BE65B-5430-4D54-BA42-33AF70ED98CE} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {97726675-68AF-4BD4-A618-93E0D12BDFC5} - System32\Tasks\{AD9FC128-5F11-4DED-8C6D-AE7FA8E3B142} => C:\Program Files\MyPaint\mypaint.exe No File Task: {9C359D41-96A3-4529-AC84-AA14CDDAD354} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-04-01] (Hewlett-Packard Company) Task: {B5DE3B7C-3837-4041-BDC4-171EFB831CEA} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3206992381-2132139690-1252408596-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-07-27] (RealNetworks, Inc.) Task: {BC21AC44-A37C-4CAA-8672-BFD1E391A16C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-01] (Google Inc.) Task: {C4DE2F08-9669-4EF7-90FF-3001FE843455} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation) Task: {C60EAED6-AE12-449B-982D-7E20D15A2A0E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe [2013-07-09] (Microsoft) Task: {C6876A0F-808D-4D10-BB06-1660D5D2F42A} - System32\Tasks\Express FilesUpdate => C:\Program Files (x86)\ExpressFiles\EFUpdater.exe No File Task: {CA89CD47-BE9F-4B77-8E07-A39C0EE4E063} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe [2013-01-27] (Microsoft Corporation) Task: {DAB6DB10-4FB5-45B1-8898-37286633D9E3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3206992381-2132139690-1252408596-1000Core => C:\Users\Fossie\AppData\Local\Facebook\Update\FacebookUpdate.exe No File Task: {E4B27A37-67C7-41AD-9E2E-E49AF8E3F273} - System32\Tasks\Google Updater and Installer => C:\Users\Fossie\AppData\Local\Google\Update\GoogleUpdate.exe No File Task: {EFD88F7A-A868-45F2-8345-2B3B81B5DC92} - System32\Tasks\{C6E500AD-6E4A-4C5A-A37E-A1512F244E33} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {F1E49559-6529-4792-9180-87092CE3B46E} - System32\Tasks\User_Feed_Synchronization-{5EE66E76-E894-4511-96F6-B8FD8764EA67} => C:\Windows\system32\msfeedssync.exe [2013-04-09] (Microsoft Corporation) Task: {F59373DB-8A0C-45BD-97F9-2180D2858A5C} - System32\Tasks\{A34F3205-E248-4F8F-ABB1-F0D8D9923A6E} => C:\Program Files\MyPaint\mypaint.exe No File Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3206992381-2132139690-1252408596-1000Core.job => C:\Users\Fossie\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3206992381-2132139690-1252408596-1000UA.job => C:\Users\Fossie\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/25/2013 02:04:31 PM) (Source: Application Hang) (User: ) Description: Programm FRST64.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 166c Startzeit: 01ce892ee5d92849 Endzeit: 249 Anwendungspfad: C:\Users\Dakota\Downloads\FRST64.exe Berichts-ID: 57e7f3af-f522-11e2-a85b-00269e55d410 Error: (07/23/2013 10:44:37 PM) (Source: Application Hang) (User: ) Description: Programm javaw.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 145c Startzeit: 01ce87e53caca6ca Endzeit: 188 Anwendungspfad: C:\Windows\SysWOW64\javaw.exe Berichts-ID: a8b4d8ca-f3d8-11e2-ae00-00269e55d410 Error: (07/23/2013 10:42:58 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: javaw.exe, Version:, Zeitstempel: 0x51c4b3ff Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00037373 ID des fehlerhaften Prozesses: 0xef4 Startzeit der fehlerhaften Anwendung: 0xjavaw.exe0 Pfad der fehlerhaften Anwendung: javaw.exe1 Pfad des fehlerhaften Moduls: javaw.exe2 Berichtskennung: javaw.exe3 Error: (07/22/2013 09:40:31 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: javaw.exe, Version:, Zeitstempel: 0x51c4b3ff Name des fehlerhaften Moduls: nvoglv32.DLL, Version:, Zeitstempel: 0x4a68d8e2 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0059a5ca ID des fehlerhaften Prozesses: 0xad0 Startzeit der fehlerhaften Anwendung: 0xjavaw.exe0 Pfad der fehlerhaften Anwendung: javaw.exe1 Pfad des fehlerhaften Moduls: javaw.exe2 Berichtskennung: javaw.exe3 Error: (07/22/2013 09:11:14 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: DUI70.dll, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bdf25 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000001098 ID des fehlerhaften Prozesses: 0x628 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (07/22/2013 08:58:52 PM) (Source: Microsoft-Windows-RestartManager) (User: NT-AUTORITÄT) Description: Die Anwendung oder der Dienst "LogMeIn Hamachi Tunneling Engine" konnte nicht neu gestartet werden. Error: (07/22/2013 06:56:39 PM) (Source: Application Hang) (User: ) Description: Programm javaw.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1110 Startzeit: 01ce86fc21099f3f Endzeit: 245 Anwendungspfad: C:\Windows\SysWOW64\javaw.exe Berichts-ID: a35dd8b3-f2ef-11e2-9d7a-00269e55d410 Error: (07/22/2013 04:48:23 PM) (Source: WTabletServiceCon) (User: ) Description: Prefs: Failed to get user path Error: (07/21/2013 00:54:29 PM) (Source: WTabletServiceCon) (User: ) Description: Prefs: Failed to get user path Error: (07/19/2013 10:00:16 PM) (Source: Application Hang) (User: ) Description: Programm FreeImageConvertAndResize.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1518 Startzeit: 01ce84ba7a5a7ce7 Endzeit: 10 Anwendungspfad: C:\Program Files (x86)\DVDVideoSoft\Free Image Convert and Resize\FreeImageConvertAndResize.exe Berichts-ID: cd8fcc09-f0ad-11e2-a81f-00269e55d410 System errors: ============= Error: (07/25/2013 01:59:32 PM) (Source: Service Control Manager) (User: ) Description: Dienst "Easybits Shared Services for Windows" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/25/2013 01:50:04 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Wsys Service" wurde nicht richtig gestartet. Error: (07/24/2013 00:03:28 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Wsys Service" wurde nicht richtig gestartet. Error: (07/24/2013 11:42:42 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Wsys Service" wurde nicht richtig gestartet. Error: (07/24/2013 11:40:57 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 24.07.2013 um 02:20:28 unerwartet heruntergefahren. Error: (07/24/2013 01:34:03 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Wsys Service" wurde nicht richtig gestartet. Error: (07/23/2013 05:34:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Wsys Service" wurde nicht richtig gestartet. Error: (07/23/2013 03:01:14 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Wsys Service" wurde nicht richtig gestartet. Error: (07/22/2013 09:19:33 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (07/22/2013 09:19:03 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Microsoft Office Sessions: ========================= Error: (07/25/2013 02:04:31 PM) (Source: Application Hang)(User: ) Description: FRST64.exe3.3.8.1166c01ce892ee5d92849249C:\Users\Dakota\Downloads\FRST64.exe57e7f3af-f522-11e2-a85b-00269e55d410 Error: (07/23/2013 10:44:37 PM) (Source: Application Hang)(User: ) Description: javaw.exe7.0.250.17145c01ce87e53caca6ca188C:\Windows\SysWOW64\javaw.exea8b4d8ca-f3d8-11e2-ae00-00269e55d410 Error: (07/23/2013 10:42:58 PM) (Source: Application Error)(User: ) Description: javaw.exe7.0.250.1751c4b3ffntdll.dll6.1.7601.177254ec49b8fc000000500037373ef401ce87e4643b2407C:\Windows\SysWOW64\javaw.exeC:\Windows\SysWOW64\ntdll.dl l74f1f782-f3d8-11e2-ae00-00269e55d410 Error: (07/22/2013 09:40:31 PM) (Source: Application Error)(User: ) Description: javaw.exe7.0.250.1751c4b3ffnvoglv32.DLL8.15.11.86444a68d8e2c00000050059a5caad001ce8710d0278b4fC:\Program Files (x86)\Java\jre7\bin\javaw.exeC:\Windows\system32\nvoglv32.DLL911431d8-f306-11e2-9e08-00269e55d410 Error: (07/22/2013 09:11:14 PM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4DUI70.dll6.1.7600.163854a5bdf25c0000005000000000000109862801ce86f0a455a5b0C:\Windows\Explorer.EXEC:\Windows\system32 \DUI70.dll79d64535-f302-11e2-9d7a-00269e55d410 Error: (07/22/2013 08:58:52 PM) (Source: Microsoft-Windows-RestartManager)(User: NT-AUTORITÄT) Description: 0C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exeLogMeIn Hamachi Tunneling Engine03026217814760 Error: (07/22/2013 06:56:39 PM) (Source: Application Hang)(User: ) Description: javaw.exe7.0.250.17111001ce86fc21099f3f245C:\Windows\SysWOW64\javaw.exea35dd8b3-f2ef-11e2-9d7a-00269e55d410 Error: (07/22/2013 04:48:23 PM) (Source: WTabletServiceCon)(User: ) Description: Prefs: Failed to get user path Error: (07/21/2013 00:54:29 PM) (Source: WTabletServiceCon)(User: ) Description: Prefs: Failed to get user path Error: (07/19/2013 10:00:16 PM) (Source: Application Hang)(User: ) Description: FreeImageConvertAndResize.exe2.1.24.628151801ce84ba7a5a7ce710C:\Program Files (x86)\DVDVideoSoft\Free Image Convert and Resize\FreeImageConvertAndResize.execd8fcc09-f0ad-11e2-a81f-00269e55d410 ==================== Memory info =========================== Percentage of memory in use: 57% Total physical RAM: 4062.93 MB Available physical RAM: 1741.12 MB Total Pagefile: 8124.04 MB Available Pagefile: 5104.51 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:285.37 GB) (Free:203.73 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:12.52 GB) (Free:0.67 GB) NTFS (Disk=0 Partition=3) ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298 GB) (Disk ID: EA7CEF7D) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=285 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=13 GB) - (Type=07 NTFS) ==================== End Of Log ============================ ![]() |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Trojaner? - egdpsvc.exeCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
