![]() |
Log-Analyse und Auswertung: Windows 7: Startseite wird ständig geändertWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
![]() | #1 |
| ![]() Windows 7: Startseite wird ständig geändert Hallo, ich bin neu im Forum und hier ist auch schon mein Problem: Ich stieß beim Surfen auf eine scamsite, getrieben von meiner Neugierde installierte ich trotzdem den media player classic. (aufgrund von typischen surveys) Nun öffnet Google Chrome beim Start qone8.com, jegliche Änderungen der Einstellungen trotzend, und ich schätze das ist nicht der einzige Effekt der Installation. Ich würde also in erster Linie meine Startwebsite selbst wählen, jedoch auch Viren, Malware etc. von meinem PC abschütteln wollen. defogger_disable: Code:
ATTFilter defogger_disable by jpshortstuff ( Log created at 18:35 on 10/10/2013 (DarkyDonut) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. HKCU:DAEMON Tools Pro Agent -> Removed Checking for services/drivers... SPTD -> Disabled (Service running -> reboot required) -=E.O.F=- FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by DarkyDonut (administrator) on DARKYDONUT-PC on 10-10-2013 18:40:19 Running from D:\Users\DarkyDonut\Desktop\Anti-Virus-stuff\Programme Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) D:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) D:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) D:\Windows\system32\nvvsvc.exe (Wsys Co., Ltd.) D:\ProgramData\eSafe\eGdpSvc.exe (ASUSTeK Computer Inc.) D:\Windows\Chipset\AsusSetup.exe (Realtek Semiconductor) D:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) D:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation) D:\Program Files\Microsoft Security Client\msseces.exe (DT Soft Ltd) D:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe () D:\Users\DarkyDonut\Local Settings\Apps\F.lux\flux.exe () D:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (Skype Technologies S.A.) D:\Program Files (x86)\Skype\Phone\Skype.exe (Electronic Arts) D:\Program Files (x86)\Origin\Origin.exe () D:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe (NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AVM Berlin) D:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Hewlett-Packard) D:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe () D:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (ROCCAT GmbH) D:\Program Files (x86)\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.exe (shbox.de) D:\Program Files (x86)\FreePDF_XP\fpassist.exe (Oracle Corporation) D:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Google Inc.) D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\chrome.exe (AVM Berlin) D:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Hi-Rez Studios) D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe () D:\Windows\SysWOW64\srvany.exe () D:\Windows\SysWOW64\PnkBstrA.exe () D:\Windows\KMService.exe (Skype Technologies) D:\Program Files (x86)\Skype\Updater\Updater.exe (Microsoft Corporation) D:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corporation) d:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) d:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) d:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) d:\Program Files\Microsoft Security Client\MpCmdRun.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - D:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11545192 2010-11-02] (Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] - D:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [BCSSync] - D:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [Zune Launcher] - D:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [MSC] - d:\Program Files\Microsoft Security Client\msseces.exe [1281512 2013-01-27] (Microsoft Corporation) HKCU\...\Run: [KPeerNexonEU] - D:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe [438272 2012-04-09] (NEXON Inc.) HKCU\...\Run: [Google Update] - D:\Users\DarkyDonut\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-08-03] (Google Inc.) HKCU\...\Run: [Steam] - D:\Program Files (x86)\Steam\steam.exe [1813928 2013-10-09] (Valve Corporation) HKCU\...\Run: [F.lux] - D:\Users\DarkyDonut\Local Settings\Apps\F.lux\flux.exe [966656 2009-08-29] () HKCU\...\Run: [Pando Media Booster] - D:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2012-11-17] () HKCU\...\Run: [NetLimiter] - D:\Program Files\NetLimiter 3\NLClientApp.exe /tray HKCU\...\Run: [Skype] - D:\Program Files (x86)\Skype\Phone\Skype.exe [20684656 2013-07-25] (Skype Technologies S.A.) HKCU\...\Run: [Yontoo Desktop] - "D:\Users\DarkyDonut\AppData\Roaming\Yontoo\YontooDesktop.exe" HKCU\...\Run: [Browser Infrastructure Helper] - D:\Users\DarkyDonut\AppData\Local\Smartbar\Application\Smartbar.exe startup HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [EADM] - D:\Program Files (x86)\Origin\Origin.exe [3551576 2013-10-04] (Electronic Arts) MountPoints2: J - J:\SETUP.EXE MountPoints2: {5d2dde2e-9c11-11e2-b1a7-001f3f02063f} - I:\Autorun.exe MountPoints2: {bfdb044a-5bb4-11e1-9f6b-b63d974242ae} - I:\pushinst.exe HKLM-x32\...\Run: [SwitchBoard] - D:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] - D:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVMWlanClient] - D:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [Adobe ARM] - D:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - D:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [DivXUpdate] - D:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM-x32\...\Run: [RoccatKone+] - D:\Program Files (x86)\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.EXE [552960 2011-07-12] (ROCCAT GmbH) HKLM-x32\...\Run: [FreePDF Assistant] - D:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de) HKLM-x32\...\Run: [QuickTime Task] - D:\Program Files (x86)\QuickTime\QTTask.exe [413696 2008-05-27] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - D:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) Startup: D:\Users\DarkyDonut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk ShortcutTarget: Product Registration.lnk -> D:\Users\DarkyDonut\AppData\Local\Temp\is-NBCUG.tmp\ATR1.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=TJ&userid=c89d2f5e-12db-416f-8606-5bfebe48f274&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=03/04/2013&type=hp1000 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=TJ&userid=c89d2f5e-12db-416f-8606-5bfebe48f274&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=03/04/2013&type=hp1000 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988 StartMenuInternet: IEXPLORE.EXE - D:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.qone8.com/web/?type=ds&ts=1381421076&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.qone8.com/web/?type=ds&ts=1381421076&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.qone8.com/web/?type=ds&ts=1381421076&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988&q={searchTerms} SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=c89d2f5e-12db-416f-8606-5bfebe48f274&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=03/04/2013&type=hp1000 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.qone8.com/web/?type=ds&ts=1381421076&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.qone8.com/web/?type=ds&ts=1381421076&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988&q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=TJ&userid=c89d2f5e-12db-416f-8606-5bfebe48f274&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=03/04/2013&type=hp1000 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.qone8.com/web/?type=ds&ts=1381421076&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988&q={searchTerms} BHO: Yahoo Community Smartbar (by Linkury)Engine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - D:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - d:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Yahoo Community Smartbar (by Linkury)Engine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - D:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - D:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - d:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Yahoo Community Smartbar (by Linkury) - {ae07101b-46d4-4a98-af68-0333ea26e113} - D:\Windows\System32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Yahoo Community Smartbar (by Linkury) - {ae07101b-46d4-4a98-af68-0333ea26e113} - D:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) DPF: HKLM-x32 {24896211-7A6C-4C7A-A4D9-686B5490B8DC} hxxp://wk2.gameheart.jp/GameheartWebStart.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt FireFox: ======== FF ProfilePath: D:\Users\DarkyDonut\AppData\Roaming\Mozilla\Firefox\Profiles\tttcyaun.default FF NewTab: hxxp://start.qone8.com/newtab/?type=nt&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988 FF DefaultSearchEngine: qone8 FF SelectedSearchEngine: qone8 FF Homepage: hxxp://start.qone8.com/?type=hp&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988 FF Keyword.URL: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=TJ&userid=c89d2f5e-12db-416f-8606-5bfebe48f274&searchtype=ds&fr=linkury-tb&installDate=03/04/2013&type=hp1000&p= FF Plugin: @adobe.com/FlashPlayer - D:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - D:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/JavaPlugin - D:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - d:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - D:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - D:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - D:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - D:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - D:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - D:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - D:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - D:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - d:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - D:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - D:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nexon.net/NxGame - D:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon) FF Plugin-x32: @ngm.nexoneu.com/NxGame - D:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon) FF Plugin-x32: @nvidia.com/3DVision - D:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - D:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - D:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - D:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - D:\Users\DarkyDonut\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - D:\Users\DarkyDonut\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - D:\Users\DarkyDonut\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - D:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: D:\Users\DarkyDonut\AppData\Roaming\Mozilla\Firefox\Profiles\tttcyaun.default\searchplugins\Web Search.xml FF SearchPlugin: D:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: D:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: D:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: D:\Program Files (x86)\mozilla firefox\searchplugins\qone8.xml FF SearchPlugin: D:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - D:\Users\DarkyDonut\AppData\Roaming\Mozilla\Firefox\Profiles\tttcyaun.default\Extensions\ich@maltegoetz.de FF Extension: No Name - D:\Users\DarkyDonut\AppData\Roaming\Mozilla\Firefox\Profiles\tttcyaun.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} FF Extension: No Name - D:\Users\DarkyDonut\AppData\Roaming\Mozilla\Firefox\Profiles\tttcyaun.default\Extensions\{c89d2f5e-12db-416f-8606-5bfebe48f274} FF Extension: DivXWebPlayer - D:\Users\DarkyDonut\AppData\Roaming\Mozilla\Firefox\Profiles\tttcyaun.default\Extensions\DivXWebPlayer@divx.com.xpi FF Extension: elemhidehelper - D:\Users\DarkyDonut\AppData\Roaming\Mozilla\Firefox\Profiles\tttcyaun.default\Extensions\elemhidehelper@adblockplus.org.xpi FF Extension: movie2kdownloader - D:\Users\DarkyDonut\AppData\Roaming\Mozilla\Firefox\Profiles\tttcyaun.default\Extensions\movie2kdownloader@movie2kdownloader.com.xpi FF Extension: youtubeunblocker - D:\Users\DarkyDonut\AppData\Roaming\Mozilla\Firefox\Profiles\tttcyaun.default\Extensions\youtubeunblocker@unblocker.yt.xpi FF Extension: No Name - D:\Users\DarkyDonut\AppData\Roaming\Mozilla\Firefox\Profiles\tttcyaun.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Java Console - D:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - D:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - D:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - D:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - D:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF StartMenuInternet: FIREFOX.EXE - D:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://start.qone8.com/?type=sc&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988 Chrome: ======= CHR HomePage: hxxp://google.com/ CHR RestoreOnStartup: "hxxp://start.qone8.com/?type=hp&ts=1381421074&from=vtt&uid=WDCXWD10EACS-22D6B0_WD-WCAU4376498864988" CHR Plugin: (Shockwave Flash) - D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\30.0.1599.69\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - D:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\30.0.1599.69\pdf.dll () CHR Plugin: (Adobe Acrobat) - D:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - D:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - D:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (DivX VOD Helper Plug-in) - D:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - D:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Java(TM) Platform SE 6 U35) - D:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.350.10) - D:\Windows\SysWOW64\npdeployJava1.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - D:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - D:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Pando Web Plugin) - D:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (VLC Web Plugin) - D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Nexon Game Controller) - D:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon) CHR Plugin: (Nexon Game Controller) - D:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon) CHR Plugin: (Unity Player) - D:\Users\DarkyDonut\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Facebook Video Calling Plugin) - D:\Users\DarkyDonut\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (Google Update) - D:\Users\DarkyDonut\AppData\Local\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - d:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Extension: (Fruit Ninja HD (Samurai Edition)) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknldfkjakifbdbednkjoenifmjgbiod\1.2_0 CHR Extension: (Angry Birds) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\ CHR Extension: (YouTube) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Extended Protection) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0 CHR Extension: (Adblock Plus) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6_0 CHR Extension: (ProxMate - Proxy on steroids!) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm\3.0.9_0 CHR Extension: (Dropbox) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl\3.0.8_0 CHR Extension: (Chrome In-App Payments service) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\ CHR Extension: (YouTube Unblocker) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl\0.4.5_0 CHR Extension: (Battlefield Play4Free) - D:\Users\DARKYD~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh\ CHR HKLM-x32\...\Chrome\Extension: [cekcjpgehmohobmdiikfnopibipmgnml] - D:\Users\DarkyDonut\AppData\Local\Google\Chrome\User Data\Default\Extensions\ CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - D:\Users\DarkyDonut\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - D:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= R2 AVM WLAN Connection Service; D:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S3 BEService; D:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-07-12] () R2 KMService; D:\Windows\SysWow64\srvany.exe [8192 2012-03-17] () R2 MsMpSvc; d:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation) R3 NisSrv; d:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation) S3 npggsvc; D:\Windows\SysWow64\GameMon.des [3975544 2012-05-09] (INCA Internet Co., Ltd.) S3 OverwolfUpdaterService; D:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2012-05-09] (Overwolf Ltd) R2 PnkBstrA; D:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-04] () S3 rpcapd; D:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.) S3 TunngleService; D:\Program Files (x86)\Tunngle\TnglCtrl.exe [757144 2013-08-16] (Tunngle.net GmbH) R2 WsysSvc; D:\ProgramData\eSafe\eGdpSvc.exe [1706064 2013-10-10] (Wsys Co., Ltd.) ==================== Drivers (Whitelisted) ==================== S3 avmeject; D:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R1 dtsoftbus01; D:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-04-03] (DT Soft Ltd) S3 fwlanusbn; D:\Windows\System32\DRIVERS\fwlanusbn.sys [714368 2010-10-22] (AVM GmbH) R0 MpFilter; D:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation) R2 NisDrv; D:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation) R2 NPF; D:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.) S4 sptd; D:\Windows\System32\Drivers\sptd.sys [564824 2013-04-03] (Duplex Secure Ltd.) R3 tap0901t; D:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) S3 ALSysIO; \??\D:\Users\DARKYD~1\AppData\Local\Temp\ALSysIO64.sys [x] S3 EagleX64; \??\D:\Windows\system32\drivers\EagleX64.sys [x] S3 NLNdisMP; system32\DRIVERS\nlndis.sys [x] S3 NLNdisPT; system32\DRIVERS\nlndis.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-09-20 18:06 - 2014-09-20 18:06 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\hawkthorne_release 2014-09-20 10:42 - 2014-09-20 10:42 - 00000000 ____D D:\Program Files (x86)\WinPcap 2013-10-10 18:40 - 2013-10-10 18:40 - 00000000 ____D D:\FRST 2013-10-10 18:35 - 2013-10-10 18:35 - 00000198 _____ D:\Users\DarkyDonut\defogger_reenable 2013-10-10 18:33 - 2013-10-10 18:38 - 00000000 ____D D:\Users\DarkyDonut\Desktop\Anti-Virus-stuff 2013-10-10 18:05 - 2013-10-10 18:05 - 00002205 _____ D:\Users\DarkyDonut\Desktop\Media Player Classic - Home Cinema.lnk 2013-10-10 18:05 - 2013-10-10 18:05 - 00000000 ____D D:\Program Files (x86)\Media Player Classic - Home Cinema 2013-10-10 18:04 - 2013-10-10 18:04 - 00000000 ____D D:\ProgramData\eSafe 2013-10-09 21:52 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) D:\Windows\SysWOW64\wininet.dll 2013-10-09 21:52 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) D:\Windows\SysWOW64\urlmon.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) D:\Windows\SysWOW64\mshtml.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ieframe.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) D:\Windows\SysWOW64\jscript9.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) D:\Windows\SysWOW64\iertutil.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) D:\Windows\SysWOW64\jscript.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) D:\Windows\SysWOW64\msfeeds.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ieui.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) D:\Windows\SysWOW64\iesysprep.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) D:\Windows\SysWOW64\iesetup.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) D:\Windows\SysWOW64\jsproxy.dll 2013-10-09 21:52 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) D:\Windows\SysWOW64\iernonce.dll 2013-10-09 21:52 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) D:\Windows\system32\wininet.dll 2013-10-09 21:52 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) D:\Windows\system32\urlmon.dll 2013-10-09 21:52 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) D:\Windows\system32\ie4uinit.exe 2013-10-09 21:52 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) D:\Windows\system32\mshtml.dll 2013-10-09 21:52 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) D:\Windows\system32\ieframe.dll 2013-10-09 21:52 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) D:\Windows\system32\jscript9.dll 2013-10-09 21:52 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) D:\Windows\system32\iertutil.dll 2013-10-09 21:52 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) D:\Windows\system32\jscript.dll 2013-10-09 21:52 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) D:\Windows\system32\msfeeds.dll 2013-10-09 21:52 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) D:\Windows\system32\ieui.dll 2013-10-09 21:52 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) D:\Windows\system32\iesysprep.dll 2013-10-09 21:52 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) D:\Windows\system32\iesetup.dll 2013-10-09 21:52 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) D:\Windows\system32\jsproxy.dll 2013-10-09 21:52 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) D:\Windows\system32\iernonce.dll 2013-10-09 21:52 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) D:\Windows\system32\mshtml.tlb 2013-10-09 21:52 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) D:\Windows\SysWOW64\mshtml.tlb 2013-10-09 21:52 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) D:\Windows\system32\RegisterIEPKEYs.exe 2013-10-09 21:52 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) D:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-09 18:55 - 2013-10-09 19:55 - 17813896 _____ (Adobe Systems Incorporated) D:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-09 17:52 - 2013-10-09 17:52 - 00000000 ____D D:\Users\DarkyDonut\Downloads\lztboffflac 2013-10-09 17:46 - 2013-10-09 17:52 - 201720286 _____ D:\Users\DarkyDonut\Downloads\lztboffflac.part5.rar 2013-10-09 17:42 - 2013-10-09 17:46 - 209715200 _____ D:\Users\DarkyDonut\Downloads\lztboffflac.part4.rar 2013-10-09 17:39 - 2013-10-09 17:42 - 209715200 _____ D:\Users\DarkyDonut\Downloads\lztboffflac.part3.rar 2013-10-09 17:36 - 2013-10-09 17:39 - 209715200 _____ D:\Users\DarkyDonut\Downloads\lztboffflac.part2.rar 2013-10-09 17:33 - 2013-10-09 17:36 - 209715200 _____ D:\Users\DarkyDonut\Downloads\lztboffflac.part1.rar 2013-10-09 16:21 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\afd.sys 2013-10-09 16:21 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\tcpip.sys 2013-10-09 16:21 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) D:\Windows\system32\mswsock.dll 2013-10-09 16:21 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) D:\Windows\SysWOW64\mswsock.dll 2013-10-09 16:21 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) D:\Windows\system32\ntoskrnl.exe 2013-10-09 16:21 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) D:\Windows\system32\win32k.sys 2013-10-09 16:21 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\usbcir.sys 2013-10-09 16:21 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) D:\Windows\system32\WebClnt.dll 2013-10-09 16:21 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) D:\Windows\system32\comctl32.dll 2013-10-09 16:21 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) D:\Windows\system32\davclnt.dll 2013-10-09 16:21 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) D:\Windows\SysWOW64\WebClnt.dll 2013-10-09 16:21 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) D:\Windows\SysWOW64\davclnt.dll 2013-10-09 16:21 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) D:\Windows\SysWOW64\comctl32.dll 2013-10-09 16:21 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\mrxdav.sys 2013-10-09 16:21 - 2013-07-03 06:40 - 00042496 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\usbscan.sys 2013-10-09 16:21 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\hidclass.sys 2013-10-09 16:21 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\hidparse.sys 2013-10-09 16:21 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\Wdf01000.sys 2013-10-09 16:21 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) D:\Windows\system32\lpk.dll 2013-10-09 16:21 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) D:\Windows\system32\fontsub.dll 2013-10-09 16:21 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) D:\Windows\system32\dciman32.dll 2013-10-09 16:21 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) D:\Windows\system32\atmlib.dll 2013-10-09 16:21 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) D:\Windows\SysWOW64\lpk.dll 2013-10-09 16:21 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) D:\Windows\SysWOW64\fontsub.dll 2013-10-09 16:21 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) D:\Windows\SysWOW64\dciman32.dll 2013-10-09 16:21 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) D:\Windows\system32\atmfd.dll 2013-10-09 16:21 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) D:\Windows\SysWOW64\atmfd.dll 2013-10-09 16:21 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) D:\Windows\SysWOW64\atmlib.dll 2013-10-09 16:20 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\usbhub.sys 2013-10-09 16:20 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\usbport.sys 2013-10-09 16:20 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\usbccgp.sys 2013-10-09 16:20 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\usbehci.sys 2013-10-09 16:20 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\usbuhci.sys 2013-10-09 16:20 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\usbohci.sys 2013-10-09 16:20 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\usbd.sys 2013-10-09 16:20 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) D:\Windows\system32\ntdll.dll 2013-10-09 16:20 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) D:\Windows\system32\tdh.dll 2013-10-09 16:20 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) D:\Windows\system32\wow64.dll 2013-10-09 16:20 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) D:\Windows\system32\advapi32.dll 2013-10-09 16:20 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-09 16:20 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ntoskrnl.exe 2013-10-09 16:20 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ntdll.dll 2013-10-09 16:20 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) D:\Windows\SysWOW64\tdh.dll 2013-10-09 16:20 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) D:\Windows\SysWOW64\wow32.dll 2013-10-09 16:20 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) D:\Windows\SysWOW64\advapi32.dll 2013-10-09 16:20 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) D:\Windows\SysWOW64\setup16.exe 2013-10-09 16:20 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ntvdm64.dll 2013-10-09 16:20 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) D:\Windows\SysWOW64\instnm.exe 2013-10-09 16:20 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) D:\Windows\SysWOW64\user.exe 2013-10-09 16:20 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) D:\Windows\system32\scavengeui.dll 2013-10-09 16:20 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-09 16:20 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) D:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 16:20 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) D:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-08 19:13 - 2013-10-08 19:45 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\Tropico 4 2013-10-08 18:49 - 2013-10-08 18:49 - 00001314 _____ D:\Users\Public\Desktop\Tropico 4 Collectors Bundle.lnk 2013-10-08 18:42 - 2013-10-08 18:42 - 00000000 ____D D:\Program Files (x86)\Kalypso Media 2013-10-04 18:20 - 2013-10-04 18:20 - 00000000 ____D D:\Users\DarkyDonut\AppData\Local\ESN 2013-10-04 16:22 - 2013-10-04 16:22 - 00001213 _____ D:\Users\Public\Desktop\Battlefield 4™ Beta.lnk 2013-10-04 16:22 - 2013-10-04 16:22 - 00000000 ____D D:\Program Files (x86)\Battlelog Web Plugins 2013-10-04 15:00 - 2013-10-04 15:00 - 00000000 ____D D:\Program Files (x86)\Origin Games 2013-10-04 14:59 - 2013-10-05 12:42 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\Origin 2013-10-04 14:59 - 2013-10-04 15:00 - 00000000 ____D D:\Users\DarkyDonut\AppData\Local\Origin 2013-10-04 14:57 - 2013-10-10 18:37 - 00000000 ____D D:\Program Files (x86)\Origin 2013-10-04 14:57 - 2013-10-04 18:20 - 00000000 ____D D:\ProgramData\Origin 2013-10-04 14:57 - 2013-10-04 14:57 - 00000987 _____ D:\Users\Public\Desktop\Origin.lnk 2013-10-03 15:41 - 2013-10-03 15:41 - 00001015 _____ D:\Users\DarkyDonut\Desktop\Terraria.lnk 2013-10-03 14:09 - 2013-10-03 14:09 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 2.7 2013-10-03 14:09 - 2013-10-03 14:09 - 00000000 ____D D:\ProgramData\Damned 2013-10-03 14:08 - 2013-10-03 14:09 - 00000000 ____D D:\Python27 2013-10-03 14:05 - 2013-10-02 11:25 - 00000000 ____D D:\Users\DarkyDonut\Desktop\Damned.Alpha.v0.42b.Cracked-iND 2013-10-01 17:30 - 2013-10-01 17:30 - 00000000 ____D D:\ProgramData\Overwolf 2013-09-19 14:15 - 2013-09-19 14:15 - 3020816384 _____ D:\Users\DarkyDonut\Desktop\DragonBall Z - Budokai Tenkaichi 3 (USA) (En,Ja).iso 2013-09-19 06:51 - 2013-09-19 06:51 - 1926234112 _____ D:\Users\DarkyDonut\Desktop\Naruto Shippuden - Ultimate Ninja 5 (Europe) (En,Fr,De,Es,It).iso 2013-09-18 19:37 - 2013-09-18 19:37 - 00001081 _____ D:\Users\Public\Desktop\7 Days to Die - Alpha.lnk 2013-09-18 19:37 - 2013-09-18 19:37 - 00000000 ____D D:\Program Files (x86)\7DaysToDie-Alpha 2013-09-18 19:36 - 2013-09-12 11:03 - 314937589 _____ (The Fun Pimps LLC ) D:\Users\DarkyDonut\Desktop\7DTD_Alpha_1.1_win64.exe 2013-09-18 16:13 - 2013-09-18 16:14 - 00000000 ____D D:\Users\DarkyDonut\Downloads\Dragon Ball Z Budokai Tenkaichi 3 PAL PS2DVD-STRiKE 2013-09-18 15:43 - 2013-09-18 15:43 - 00000000 ____D D:\Program Files (x86)\WBFS to ISO 2013-09-18 06:32 - 2013-10-06 10:10 - 00000914 _____ D:\Users\DarkyDonut\Desktop\Dolphin.lnk 2013-09-12 06:18 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\ataport.sys 2013-09-12 06:18 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) D:\Windows\system32\winsrv.dll 2013-09-12 06:18 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) D:\Windows\system32\kernel32.dll 2013-09-12 06:18 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) D:\Windows\system32\KernelBase.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) D:\Windows\system32\csrsrv.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) D:\Windows\system32\apisetschema.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) D:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) D:\Windows\SysWOW64\kernel32.dll 2013-09-12 06:18 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) D:\Windows\SysWOW64\KernelBase.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) D:\Windows\SysWOW64\apisetschema.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) D:\Windows\system32\conhost.exe 2013-09-12 06:18 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) D:\Windows\system32\smss.exe 2013-09-12 06:18 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-12 06:18 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) D:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-12 06:17 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) D:\Windows\system32\shell32.dll 2013-09-12 06:17 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) D:\Windows\system32\shdocvw.dll 2013-09-12 06:17 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) D:\Windows\SysWOW64\shell32.dll 2013-09-12 06:17 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) D:\Windows\SysWOW64\shdocvw.dll 2013-09-10 23:56 - 2013-09-10 23:56 - 00280212 _____ D:\Users\DarkyDonut\Desktop\Minecraft.jar 2013-09-10 23:48 - 2013-09-10 23:48 - 00367332 _____ (hxxp://magiclauncher.com) D:\Users\DarkyDonut\Desktop\MagicLauncher_1.1.7.exe 2013-09-10 23:46 - 2013-09-10 23:46 - 00421588 _____ D:\Users\DarkyDonut\Desktop\OptiFine_1.6.2_HD_U_C4.jar 2013-09-10 23:40 - 2013-09-10 23:40 - 00255632 _____ D:\Users\DarkyDonut\Desktop\[1.6.2]ReiMinimap_v3.4_01.zip 2013-09-10 22:04 - 2013-09-10 22:04 - 00002239 _____ D:\Users\Public\Desktop\Total War™ Shogun 2.lnk 2013-09-10 21:26 - 2013-09-10 21:26 - 00000000 ____D D:\Users\DarkyDonut\AppData\Local\QfG 2013-09-10 21:26 - 2013-09-10 21:26 - 00000000 ____D D:\Program Files (x86)\QfG 2013-09-10 21:00 - 2013-09-10 21:02 - 00000000 ____D D:\Users\DarkyDonut\Downloads\Amnesia.A.Machine.for.Pigs-SKiDROW_arfa3 ==================== One Month Modified Files and Folders ======= 2014-09-20 18:06 - 2014-09-20 18:06 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\hawkthorne_release 2014-09-20 11:19 - 2012-02-28 00:35 - 00049602 _____ D:\Windows\avmfwlanci.log 2014-09-20 10:42 - 2014-09-20 10:42 - 00000000 ____D D:\Program Files (x86)\WinPcap 2013-10-10 18:41 - 2012-03-01 14:10 - 00000000 ____D D:\Users\DarkyDonut\AppData\Local\PMB Files 2013-10-10 18:40 - 2013-10-10 18:40 - 00000000 ____D D:\FRST 2013-10-10 18:40 - 2012-08-21 20:38 - 00000000 ____D D:\Program Files (x86)\Steam 2013-10-10 18:39 - 2012-02-20 13:58 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\Skype 2013-10-10 18:38 - 2013-10-10 18:33 - 00000000 ____D D:\Users\DarkyDonut\Desktop\Anti-Virus-stuff 2013-10-10 18:37 - 2013-10-04 14:57 - 00000000 ____D D:\Program Files (x86)\Origin 2013-10-10 18:37 - 2012-02-20 15:01 - 00000000 ____D D:\ProgramData\NVIDIA 2013-10-10 18:37 - 2009-07-14 07:08 - 00000006 ____H D:\Windows\Tasks\SA.DAT 2013-10-10 18:37 - 2009-07-14 06:51 - 00087620 _____ D:\Windows\setupact.log 2013-10-10 18:36 - 2012-02-20 12:44 - 01192656 _____ D:\Windows\WindowsUpdate.log 2013-10-10 18:35 - 2013-10-10 18:35 - 00000198 _____ D:\Users\DarkyDonut\defogger_reenable 2013-10-10 18:35 - 2012-02-20 13:21 - 00000000 ____D D:\Users\DarkyDonut 2013-10-10 18:18 - 2012-03-01 14:10 - 00000000 ____D D:\ProgramData\PMB Files 2013-10-10 18:05 - 2013-10-10 18:05 - 00002205 _____ D:\Users\DarkyDonut\Desktop\Media Player Classic - Home Cinema.lnk 2013-10-10 18:05 - 2013-10-10 18:05 - 00000000 ____D D:\Program Files (x86)\Media Player Classic - Home Cinema 2013-10-10 18:04 - 2013-10-10 18:04 - 00000000 ____D D:\ProgramData\eSafe 2013-10-10 18:04 - 2013-04-10 18:21 - 00002605 _____ D:\Users\DarkyDonut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2013-10-10 18:04 - 2012-02-20 13:22 - 00001641 _____ D:\Users\DarkyDonut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-10 17:58 - 2012-08-03 10:16 - 00001140 _____ D:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1667423135-4136561018-2920934541-1000UA.job 2013-10-10 17:55 - 2012-06-19 16:05 - 00000884 _____ D:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-10 15:21 - 2009-07-14 06:45 - 00014016 ____H D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-10 15:21 - 2009-07-14 06:45 - 00014016 ____H D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-10 07:15 - 2012-02-20 13:47 - 00000000 ____D D:\Users\DarkyDonut\AppData\Local\Adobe 2013-10-10 07:11 - 2009-07-14 19:58 - 00699416 _____ D:\Windows\system32\perfh007.dat 2013-10-10 07:11 - 2009-07-14 19:58 - 00149556 _____ D:\Windows\system32\perfc007.dat 2013-10-10 07:11 - 2009-07-14 07:13 - 01620612 _____ D:\Windows\system32\PerfStringBackup.INI 2013-10-10 07:04 - 2009-07-14 06:45 - 05088848 _____ D:\Windows\system32\FNTCACHE.DAT 2013-10-10 07:00 - 2013-03-13 08:11 - 00000000 ____D D:\Program Files\Microsoft Silverlight 2013-10-10 07:00 - 2013-03-13 08:11 - 00000000 ____D D:\Program Files (x86)\Microsoft Silverlight 2013-10-09 21:56 - 2012-02-20 15:23 - 01593956 _____ D:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-09 21:55 - 2012-03-15 23:08 - 00000000 ____D D:\ProgramData\Microsoft Help 2013-10-09 21:50 - 2013-08-15 02:30 - 00000000 ____D D:\Windows\system32\MRT 2013-10-09 21:46 - 2013-03-30 02:41 - 80541720 _____ (Microsoft Corporation) D:\Windows\system32\MRT.exe 2013-10-09 19:55 - 2013-10-09 18:55 - 17813896 _____ (Adobe Systems Incorporated) D:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-09 19:55 - 2012-06-19 16:05 - 00003822 _____ D:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-09 19:55 - 2012-06-19 15:48 - 00692616 _____ (Adobe Systems Incorporated) D:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 19:55 - 2012-02-20 15:05 - 00071048 _____ (Adobe Systems Incorporated) D:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 19:44 - 2012-08-17 20:48 - 00000000 ____D D:\Program Files (x86)\JDownloader 2 2013-10-09 18:17 - 2013-08-18 19:45 - 00031232 ___SH D:\Users\DarkyDonut\Thumbs.db 2013-10-09 18:03 - 2012-04-17 10:36 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\Audacity 2013-10-09 17:52 - 2013-10-09 17:52 - 00000000 ____D D:\Users\DarkyDonut\Downloads\lztboffflac 2013-10-09 17:52 - 2013-10-09 17:46 - 201720286 _____ D:\Users\DarkyDonut\Downloads\lztboffflac.part5.rar 2013-10-09 17:46 - 2013-10-09 17:42 - 209715200 _____ D:\Users\DarkyDonut\Downloads\lztboffflac.part4.rar 2013-10-09 17:42 - 2013-10-09 17:39 - 209715200 _____ D:\Users\DarkyDonut\Downloads\lztboffflac.part3.rar 2013-10-09 17:39 - 2013-10-09 17:36 - 209715200 _____ D:\Users\DarkyDonut\Downloads\lztboffflac.part2.rar 2013-10-09 17:36 - 2013-10-09 17:33 - 209715200 _____ D:\Users\DarkyDonut\Downloads\lztboffflac.part1.rar 2013-10-08 22:14 - 2012-03-03 12:53 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\TS3Client 2013-10-08 19:45 - 2013-10-08 19:13 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\Tropico 4 2013-10-08 18:49 - 2013-10-08 18:49 - 00001314 _____ D:\Users\Public\Desktop\Tropico 4 Collectors Bundle.lnk 2013-10-08 18:42 - 2013-10-08 18:42 - 00000000 ____D D:\Program Files (x86)\Kalypso Media 2013-10-06 10:10 - 2013-09-18 06:32 - 00000914 _____ D:\Users\DarkyDonut\Desktop\Dolphin.lnk 2013-10-06 08:58 - 2012-08-03 10:16 - 00001088 _____ D:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1667423135-4136561018-2920934541-1000Core.job 2013-10-06 08:57 - 2012-02-22 17:55 - 00542100 _____ D:\Windows\PFRO.log 2013-10-05 12:42 - 2013-10-04 14:59 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\Origin 2013-10-05 07:13 - 2012-03-25 10:22 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\vlc 2013-10-04 18:24 - 2012-03-18 12:27 - 00214392 _____ D:\Windows\SysWOW64\PnkBstrB.exe 2013-10-04 18:20 - 2013-10-04 18:20 - 00000000 ____D D:\Users\DarkyDonut\AppData\Local\ESN 2013-10-04 18:20 - 2013-10-04 14:57 - 00000000 ____D D:\ProgramData\Origin 2013-10-04 18:20 - 2012-07-12 21:01 - 00000000 ____D D:\Users\DarkyDonut\AppData\Local\PunkBuster 2013-10-04 18:20 - 2012-03-18 12:27 - 00215416 _____ D:\Windows\SysWOW64\PnkBstrB.ex0 2013-10-04 16:22 - 2013-10-04 16:22 - 00001213 _____ D:\Users\Public\Desktop\Battlefield 4™ Beta.lnk 2013-10-04 16:22 - 2013-10-04 16:22 - 00000000 ____D D:\Program Files (x86)\Battlelog Web Plugins 2013-10-04 16:21 - 2012-03-18 12:27 - 00076888 _____ D:\Windows\SysWOW64\PnkBstrA.exe 2013-10-04 16:20 - 2012-09-27 21:01 - 00000000 ____D D:\ProgramData\Package Cache 2013-10-04 16:20 - 2012-02-20 14:33 - 01036505 _____ D:\Windows\DirectX.log 2013-10-04 15:00 - 2013-10-04 15:00 - 00000000 ____D D:\Program Files (x86)\Origin Games 2013-10-04 15:00 - 2013-10-04 14:59 - 00000000 ____D D:\Users\DarkyDonut\AppData\Local\Origin 2013-10-04 14:57 - 2013-10-04 14:57 - 00000987 _____ D:\Users\Public\Desktop\Origin.lnk 2013-10-04 14:57 - 2013-02-23 13:08 - 00000000 ____D D:\ProgramData\Electronic Arts 2013-10-03 15:48 - 2012-04-01 20:05 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\Hamachi 2013-10-03 15:41 - 2013-10-03 15:41 - 00001015 _____ D:\Users\DarkyDonut\Desktop\Terraria.lnk 2013-10-03 15:40 - 2012-04-01 19:57 - 00000000 ____D D:\Program Files (x86)\Terraria 2013-10-03 15:36 - 2012-03-03 12:53 - 00000000 ____D D:\Program Files\TeamSpeak 3 Client 2013-10-03 14:09 - 2013-10-03 14:09 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 2.7 2013-10-03 14:09 - 2013-10-03 14:09 - 00000000 ____D D:\ProgramData\Damned 2013-10-03 14:09 - 2013-10-03 14:08 - 00000000 ____D D:\Python27 2013-10-02 11:25 - 2013-10-03 14:05 - 00000000 ____D D:\Users\DarkyDonut\Desktop\Damned.Alpha.v0.42b.Cracked-iND 2013-10-01 17:30 - 2013-10-01 17:30 - 00000000 ____D D:\ProgramData\Overwolf 2013-10-01 17:30 - 2012-05-27 09:34 - 00000000 ____D D:\Users\DarkyDonut\AppData\Local\Overwolf 2013-09-23 01:28 - 2013-10-09 21:52 - 01767936 _____ (Microsoft Corporation) D:\Windows\SysWOW64\wininet.dll 2013-09-23 01:28 - 2013-10-09 21:52 - 01141248 _____ (Microsoft Corporation) D:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 14335488 _____ (Microsoft Corporation) D:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 13761024 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 02876928 _____ (Microsoft Corporation) D:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 02048512 _____ (Microsoft Corporation) D:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 00690688 _____ (Microsoft Corporation) D:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 00493056 _____ (Microsoft Corporation) D:\Windows\SysWOW64\msfeeds.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 00391168 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ieui.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 00109056 _____ (Microsoft Corporation) D:\Windows\SysWOW64\iesysprep.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 00061440 _____ (Microsoft Corporation) D:\Windows\SysWOW64\iesetup.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 00039424 _____ (Microsoft Corporation) D:\Windows\SysWOW64\jsproxy.dll 2013-09-23 01:27 - 2013-10-09 21:52 - 00033280 _____ (Microsoft Corporation) D:\Windows\SysWOW64\iernonce.dll 2013-09-23 00:55 - 2013-10-09 21:52 - 02241024 _____ (Microsoft Corporation) D:\Windows\system32\wininet.dll 2013-09-23 00:55 - 2013-10-09 21:52 - 01365504 _____ (Microsoft Corporation) D:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-09 21:52 - 00051712 _____ (Microsoft Corporation) D:\Windows\system32\ie4uinit.exe 2013-09-23 00:54 - 2013-10-09 21:52 - 19252224 _____ (Microsoft Corporation) D:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-09 21:52 - 15404544 _____ (Microsoft Corporation) D:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-09 21:52 - 03959296 _____ (Microsoft Corporation) D:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-09 21:52 - 02647552 _____ (Microsoft Corporation) D:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-09 21:52 - 00855552 _____ (Microsoft Corporation) D:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-09 21:52 - 00603136 _____ (Microsoft Corporation) D:\Windows\system32\msfeeds.dll 2013-09-23 00:54 - 2013-10-09 21:52 - 00526336 _____ (Microsoft Corporation) D:\Windows\system32\ieui.dll 2013-09-23 00:54 - 2013-10-09 21:52 - 00136704 _____ (Microsoft Corporation) D:\Windows\system32\iesysprep.dll 2013-09-23 00:54 - 2013-10-09 21:52 - 00067072 _____ (Microsoft Corporation) D:\Windows\system32\iesetup.dll 2013-09-23 00:54 - 2013-10-09 21:52 - 00053248 _____ (Microsoft Corporation) D:\Windows\system32\jsproxy.dll 2013-09-23 00:54 - 2013-10-09 21:52 - 00039936 _____ (Microsoft Corporation) D:\Windows\system32\iernonce.dll 2013-09-21 05:38 - 2013-10-09 21:52 - 02706432 _____ (Microsoft Corporation) D:\Windows\system32\mshtml.tlb 2013-09-21 05:30 - 2013-10-09 21:52 - 02706432 _____ (Microsoft Corporation) D:\Windows\SysWOW64\mshtml.tlb 2013-09-21 04:48 - 2013-10-09 21:52 - 00089600 _____ (Microsoft Corporation) D:\Windows\system32\RegisterIEPKEYs.exe 2013-09-21 04:39 - 2013-10-09 21:52 - 00071680 _____ (Microsoft Corporation) D:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-20 20:27 - 2009-07-14 05:20 - 00000000 ____D D:\Windows\rescache 2013-09-20 19:31 - 2011-01-21 18:53 - 00000000 ____D D:\Program Files (x86)\StarCraft II 2013-09-19 14:15 - 2013-09-19 14:15 - 3020816384 _____ D:\Users\DarkyDonut\Desktop\DragonBall Z - Budokai Tenkaichi 3 (USA) (En,Ja).iso 2013-09-19 06:51 - 2013-09-19 06:51 - 1926234112 _____ D:\Users\DarkyDonut\Desktop\Naruto Shippuden - Ultimate Ninja 5 (Europe) (En,Fr,De,Es,It).iso 2013-09-18 19:37 - 2013-09-18 19:37 - 00001081 _____ D:\Users\Public\Desktop\7 Days to Die - Alpha.lnk 2013-09-18 19:37 - 2013-09-18 19:37 - 00000000 ____D D:\Program Files (x86)\7DaysToDie-Alpha 2013-09-18 19:36 - 2012-08-21 19:42 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-09-18 16:14 - 2013-09-18 16:13 - 00000000 ____D D:\Users\DarkyDonut\Downloads\Dragon Ball Z Budokai Tenkaichi 3 PAL PS2DVD-STRiKE 2013-09-18 15:43 - 2013-09-18 15:43 - 00000000 ____D D:\Program Files (x86)\WBFS to ISO 2013-09-18 06:30 - 2013-02-13 01:55 - 00000000 ___RD D:\Program Files (x86)\Skype 2013-09-18 06:30 - 2012-02-20 13:58 - 00000000 ____D D:\ProgramData\Skype 2013-09-17 21:05 - 2012-02-20 14:30 - 00000000 ____D D:\Users\DarkyDonut\AppData\Roaming\.minecraft 2013-09-14 03:10 - 2013-10-09 16:21 - 00497152 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\afd.sys 2013-09-12 12:55 - 2012-03-31 13:21 - 00000000 ___RD D:\Users\DarkyDonut\Podcasts 2013-09-12 12:55 - 2012-02-20 13:22 - 00000000 ___RD D:\Users\DarkyDonut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-12 12:55 - 2012-02-20 13:22 - 00000000 ___RD D:\Users\DarkyDonut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 11:03 - 2013-09-18 19:36 - 314937589 _____ (The Fun Pimps LLC ) D:\Users\DarkyDonut\Desktop\7DTD_Alpha_1.1_win64.exe 2013-09-10 23:56 - 2013-09-10 23:56 - 00280212 _____ D:\Users\DarkyDonut\Desktop\Minecraft.jar 2013-09-10 23:48 - 2013-09-10 23:48 - 00367332 _____ (hxxp://magiclauncher.com) D:\Users\DarkyDonut\Desktop\MagicLauncher_1.1.7.exe 2013-09-10 23:46 - 2013-09-10 23:46 - 00421588 _____ D:\Users\DarkyDonut\Desktop\OptiFine_1.6.2_HD_U_C4.jar 2013-09-10 23:40 - 2013-09-10 23:40 - 00255632 _____ D:\Users\DarkyDonut\Desktop\[1.6.2]ReiMinimap_v3.4_01.zip 2013-09-10 22:04 - 2013-09-10 22:04 - 00002239 _____ D:\Users\Public\Desktop\Total War™ Shogun 2.lnk 2013-09-10 21:28 - 2013-07-09 20:24 - 00000000 ____D D:\Program Files (x86)\Electronic Arts 2013-09-10 21:28 - 2012-02-20 13:40 - 00000000 ___HD D:\Program Files (x86)\InstallShield Installation Information 2013-09-10 21:26 - 2013-09-10 21:26 - 00000000 ____D D:\Users\DarkyDonut\AppData\Local\QfG 2013-09-10 21:26 - 2013-09-10 21:26 - 00000000 ____D D:\Program Files (x86)\QfG 2013-09-10 21:02 - 2013-09-10 21:00 - 00000000 ____D D:\Users\DarkyDonut\Downloads\Amnesia.A.Machine.for.Pigs-SKiDROW_arfa3 Files to move or delete: ==================== D:\Users\DarkyDonut\MSVCR71.dll Some content of TEMP: ==================== D:\Users\DarkyDonut\AppData\Local\Temp\AskSLib.dll D:\Users\DarkyDonut\AppData\Local\Temp\bdfilters.dll D:\Users\DarkyDonut\AppData\Local\Temp\binkw32.dll D:\Users\DarkyDonut\AppData\Local\Temp\CH.dll D:\Users\DarkyDonut\AppData\Local\Temp\d2l_Install.exe D:\Users\DarkyDonut\AppData\Local\Temp\detectionapi_rd.dll D:\Users\DarkyDonut\AppData\Local\Temp\directx9tests_rd.dll D:\Users\DarkyDonut\AppData\Local\Temp\DivXSetup.exe D:\Users\DarkyDonut\AppData\Local\Temp\drm_dyndata_7370014.dll D:\Users\DarkyDonut\AppData\Local\Temp\drm_dyndata_7380014.dll D:\Users\DarkyDonut\AppData\Local\Temp\FP_PL_PFS_INSTALLER_32bit-1.exe D:\Users\DarkyDonut\AppData\Local\Temp\FP_PL_PFS_INSTALLER_32bit.exe D:\Users\DarkyDonut\AppData\Local\Temp\i4jdel0.exe D:\Users\DarkyDonut\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe D:\Users\DarkyDonut\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe D:\Users\DarkyDonut\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe D:\Users\DarkyDonut\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe D:\Users\DarkyDonut\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe D:\Users\DarkyDonut\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe D:\Users\DarkyDonut\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe D:\Users\DarkyDonut\AppData\Local\Temp\Launcher.exe D:\Users\DarkyDonut\AppData\Local\Temp\local.dll D:\Users\DarkyDonut\AppData\Local\Temp\NGMDll.dll D:\Users\DarkyDonut\AppData\Local\Temp\NGMResource.dll D:\Users\DarkyDonut\AppData\Local\Temp\NGMSetup.exe D:\Users\DarkyDonut\AppData\Local\Temp\Nv3DVStreaming.dll D:\Users\DarkyDonut\AppData\Local\Temp\nvSCPAPI.dll D:\Users\DarkyDonut\AppData\Local\Temp\nvSCPAPI64.dll D:\Users\DarkyDonut\AppData\Local\Temp\nvStereoApiI.dll D:\Users\DarkyDonut\AppData\Local\Temp\nvStereoApiI64.dll D:\Users\DarkyDonut\AppData\Local\Temp\nvStInst.exe D:\Users\DarkyDonut\AppData\Local\Temp\ose00001.exe D:\Users\DarkyDonut\AppData\Local\Temp\riftuninstall.exe D:\Users\DarkyDonut\AppData\Local\Temp\SIntf16.dll D:\Users\DarkyDonut\AppData\Local\Temp\SIntf32.dll D:\Users\DarkyDonut\AppData\Local\Temp\SIntfNT.dll D:\Users\DarkyDonut\AppData\Local\Temp\SkypeSetup.exe D:\Users\DarkyDonut\AppData\Local\Temp\sonarinst.exe D:\Users\DarkyDonut\AppData\Local\Temp\su-setup.exe D:\Users\DarkyDonut\AppData\Local\Temp\swt-win32-3349.dll D:\Users\DarkyDonut\AppData\Local\Temp\ubi45CE.tmp.exe D:\Users\DarkyDonut\AppData\Local\Temp\ubiB157.tmp.exe D:\Users\DarkyDonut\AppData\Local\Temp\unicows.dll D:\Users\DarkyDonut\AppData\Local\Temp\vty_install.exe D:\Users\DarkyDonut\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= D:\Windows\System32\winlogon.exe => MD5 is legit D:\Windows\System32\wininit.exe => MD5 is legit D:\Windows\SysWOW64\wininit.exe => MD5 is legit D:\Windows\explorer.exe => MD5 is legit D:\Windows\SysWOW64\explorer.exe => MD5 is legit D:\Windows\System32\svchost.exe => MD5 is legit D:\Windows\SysWOW64\svchost.exe => MD5 is legit D:\Windows\System32\services.exe => MD5 is legit D:\Windows\System32\User32.dll => MD5 is legit D:\Windows\SysWOW64\User32.dll => MD5 is legit D:\Windows\System32\userinit.exe => MD5 is legit D:\Windows\SysWOW64\userinit.exe => MD5 is legit D:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-05 01:02 ==================== End Of Log ============================ Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013 Ran by DarkyDonut at 2013-10-10 18:43:50 Running from D:\Users\DarkyDonut\Desktop\Anti-Virus-stuff\Programme Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {3F839487-C7A2-C958-E30C-E2825BA31FB5} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {84E27563-E198-C6D6-D9BC-D9F020245508} ==================== Installed Programs ====================== µTorrent (x32 Version: 3.1.3) 1&1 SmartFax (x32 Version: 2.00.231) 7 Days to Die - Alpha version 1.1 (x32 Version: 1.1) Adobe After Effects CS6 (x32 Version: 11) Adobe AIR (x32 Version: Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Help Manager (x32 Version: 4.0.244) Adobe Media Player (x32 Version: 1.8) Adobe Photoshop CS5 (x32 Version: 12.0) Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8) Apple Software Update (x32 Version: ARMA 2 (x32) ARMA 2: Operation Arrowhead (x32) Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: Audacity 2.0 (x32) AVM FRITZ!WLAN (x32) Battlefield 4™ Beta (x32 Version: Battlelog Web Plugins (x32 Version: 2.3.0) BattlEye for OA Uninstall (x32) BioShock Collector's Edition (x32 Version: v1.1) BioShock Infinite (x32) Black and White (x32) Borderlands 2 (x32) Castlevania: Lords of Shadow - Ultimate Edition (x32) Core Temp 1.0 RC3 (Version: 1.0) DAEMON Tools Pro (x32 Version: DayZ Commander (x32 Version: 1.09.65) Dead Island Riptide (c) Deep Silver version 1 (x32 Version: 1) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition Die Sims™ 3 Luxus-Accessoires (x32 Version: 3.0.38) Die Sims™ 3 Reiseabenteuer (x32 Version: 2.0.86) Die Sims™ 3 Showtime (x32 Version: 12.0.273) Die Sims™ 3 Stadt-Accessoires (x32 Version: 9.0.73) Die Sims™ 3 Supernatural (x32 Version: 15.0.135) Die Sims™ 3 Traumkarrieren (x32 Version: 4.0.87) Die Sims™ 3 Traumsuite-Accessoires (x32 Version: 11.0.84) DivX-Setup (x32 Version: Dota 2 (x32) ElsterFormular (x32 Version: 14.1.20130301) Entity Framework Designer für Visual Studio 2012 - DEU (x32 Version: 11.1.20810.00) Erforderliche Komponenten für SSDT (x32 Version: 11.0.2100.60) ESN Sonar (x32 Version: 0.70.4) F.lux (HKCU) Fallout 3 (x32 Version: 1.00.0000) Far Cry 3 (x32 Version: 1.01) Far Cry 3 Deutsch Patch Fix-TokZic 1.00 (x32 Version: 1.00) Far Cry 3 Deutsch Patch-TokZic 1.00 (x32 Version: 1.00) FireArc Arcade (x32 Version: 0.5.11) Fraps (remove only) (x32) Free YouTube Download version (x32 Version: FreePDF (Remove only) (x32) Garry's Mod (x32) GOG.com Gothic 2 Google Chrome (HKCU Version: 30.0.1599.69) Gothic 2 Gold (x32 Version: Gothic 2 Gold (x32) GPL Ghostscript (Version: 9.04) Grand Theft Auto IV (x32 Version: 1.0.0013.131) Grand Theft Auto IV (x32) Grand Theft Auto: Episodes from Liberty City (x32) Hamachi (x32) Hi-Rez Studios Authenticate and Update Service (x32 Version: HP Officejet 6500 E710a-f - Grundlegende Software für das Gerät (Version: HP Officejet 6500 E710a-f Hilfe (x32 Version: HP Update (x32 Version: I.R.I.S. OCR (x32 Version: IncrediMail (x32 Version: IncrediMail 2.0 (x32 Version: Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: Java(TM) 6 Update 22 (x32 Version: 6.0.220) Java(TM) 6 Update 29 (64-bit) (Version: 6.0.290) Java(TM) 6 Update 29 (x32 Version: 6.0.290) JDownloader 0.9 (x32 Version: 0.9) JDownloader 2 (x32 Version: 2) K-Lite Codec Pack 9.9.5 (Full) (x32 Version: 9.9.5) LAME v3.99.3 (for Windows) (x32) Le Bypass pour EMS (x32 Version: 1.0.0) Left 4 Dead 2 (x32) MapleStory (x32) marvell 91xx driver (x32 Version: Media Player Classic - Home Cinema x64 (Version: Media Player Classic - Home Cinema v1.5.2.3456 (x32 Version: Microsoft .NET Framework 4 Multi-Targeting Pack (x32 Version: 4.0.30319) Microsoft .NET Framework 4.5 (Version: 4.5.50709) Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709) Microsoft .NET Framework 4.5 Multi-Targeting Pack (x32 Version: 4.5.50709) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (x32 Version: 4.5.50709) Microsoft .NET Framework 4.5 SDK (x32 Version: 4.5.50709) Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2) Microsoft Games for Windows - LIVE Redistributable (x32 Version: Microsoft Games for Windows Marketplace (x32 Version: Microsoft Help Viewer 2.0 (x32 Version: 2.0.50727) Microsoft Help Viewer 2.0 Language Pack - DEU (x32 Version: 2.0.50727) Microsoft NuGet - Visual Studio Express 2012 for Windows Desktop (x32 Version: 2.0.30717.9005) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Security Client (Version: 4.2.0223.1) Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0) Microsoft Security Essentials (Version: Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2012 Command Line Utilities (Version: 11.0.2100.60) Microsoft SQL Server 2012 Data-Tier App Framework (Version: 11.0.2316.0) Microsoft SQL Server 2012 Data-Tier App Framework (x32 Version: 11.0.2316.0) Microsoft SQL Server 2012 Express LocalDB (Version: 11.0.2100.60) Microsoft SQL Server 2012 Management Objects (x32 Version: 11.0.2100.60) Microsoft SQL Server 2012 Management Objects (x64) (Version: 11.0.2100.60) Microsoft SQL Server 2012 Native Client (Version: 11.0.2100.60) Microsoft SQL Server 2012 Transact-SQL Compiler Service (Version: 11.0.2100.60) Microsoft SQL Server 2012 Transact-SQL ScriptDom (Version: 11.0.2100.60) Microsoft SQL Server 2012 T-SQL Language Service (x32 Version: 11.0.2100.60) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (Version: 4.0.8876.1) Microsoft SQL Server Data Tools - DEU (11.1.20828.01) (x32 Version: 11.1.20828.01) Microsoft SQL Server Data Tools Build Utilities - DEU (11.1.20828.01) (x32 Version: 11.1.20828.01) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 32bit Compilers - DEU Resources (x32 Version: 11.0.50727) Microsoft Visual C++ 2012 Core Libraries (x32 Version: 11.0.50727) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.50727 (Version: 11.0.50727) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106) Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.50727 (x32 Version: 11.0.50727) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106) Microsoft Visual C++ 2012 x86-x64 Compilers (x32 Version: 11.0.50727) Microsoft Visual Studio 2012 Express Prerequisites x64 - DEU (Version: 11.0.50727) Microsoft Visual Studio 2012 Shell (Minimum) (x32 Version: 11.0.50727) Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies (x32 Version: 11.0.50727) Microsoft Visual Studio 2012 Shell-(Mindest)-Ressourcen (x32 Version: 11.0.50727) Microsoft Visual Studio 2012 Tools für SQL Server Compact 4.0 SP1 DEU (x32 Version: 4.0.8876.1) Microsoft Visual Studio 2012-Vorbereitung (x32 Version: 11.0.50727) Microsoft Visual Studio Express 2012 for Windows Desktop (x32 Version: 11.0.50727) Microsoft Visual Studio Express 2012 für Windows Desktop - DEU (x32 Version: 11.0.50727) Microsoft Visual Studio Express 2012 für Windows Desktop - DEU (x32 Version: 11.0.50727.42) Microsoft Visual Studio Team Foundation Server 2012 Object Model (Version: 11.0.50727) Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - DEU (Version: 11.0.50727) Microsoft Visual Studio Team Foundation Server 2012 Team Explorer (x32 Version: 11.0.50727) Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - DEU (x32 Version: 11.0.50727) Microsoft Visual Studio Ultimate 2012 XAML UI Designer Core (x32 Version: 11.0.50727) Microsoft Visual Studio Ultimate 2012 XAML UI Designer deu Resources (x32 Version: 11.0.50727) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft XNA Framework Redistributable 3.1 (x32 Version: 3.1.10527.0) Microsoft XNA Framework Redistributable 4.0 Refresh (x32 Version: 4.0.30901.0) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Microsoft-System-CLR-Typen für SQL Server 2012 (x32 Version: 11.0.2100.60) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (Version: 11.0.2100.60) Mozilla Firefox 14.0.1 (x86 de) (x32 Version: 14.0.1) Mozilla Maintenance Service (x32 Version: 14.0.1) Mp3tag v2.52 (x32 Version: v2.52) MSVCRT Redists (Version: 1.0) My Game Long Name NC Launcher (GameForge) (x32) New Star Soccer 5 v1.07 (x32) Nexon Game Manager (x32) Notepad++ (x32 Version: 5.9.8) NVIDIA 3D Vision Controller-Treiber 310.70 (Version: 310.70) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA Install Application (Version: 2.1002.108.688) NVIDIA PhysX (x32 Version: 9.12.1031) NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031) NVIDIA Stereoscopic 3D Driver (x32 Version: NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) Oblivion mod manager 1.1.12 (x32) OpenOffice.org 3.3 (x32 Version: 3.3.9567) Origin (x32 Version: Outlast (x32 Version: 1) Overwolf (x32 Version: 0.32.194) Pando Media Booster (x32 Version: PAYDAY: The Heist (x32) PCSX2 - Playstation 2 Emulator (x32) PDF Settings CS5 (x32 Version: 10.0) Photo Notifier and Animation Creator (x32 Version: Pokemon World Online version 1.83 (x32 Version: 1.83) Prince of Persia (x32 Version: 1.0) PS2 Emulator r5135 + BIOS (x32) PunkBuster Services (x32 Version: 0.993) Python 2.7.5 (x32 Version: 2.7.5150) Quick Batch File Compiler (x32 Version: QuickTime (x32 Version: RealSpeak Solo fur Deutsch - Steffi (x32 Version: 4.00.0000) Realtek Ethernet Controller Driver (x32 Version: 7.37.1229.2010) Realtek High Definition Audio Driver (x32 Version: Red Faction Armageddon (x32) RedMon - Redirection Port Monitor ROCCAT Kone[+] Mouse Driver (x32) Rockstar Games Social Club (x32 Version: Rogue Legacy version (x32 Version: RTP for RM2K (Png, Wav, Midi, Fonts) (x32) Skype™ 6.7 (x32 Version: 6.7.102) Sleeping Dogs (x32) Solid Edge ST5 (x32 Version: 105.00.00102) StarCraft II (x32 Version: Steam (x32 Version: TeamSpeak 3 Client (Version: 3.0.13) TeamViewer 8 (x32 Version: 8.0.17396) TechPowerUp GPU-Z (x32) The Elder Scrolls V Skyrim - Dawnguard DLC Deutsche Version PLus UPDATE 10 1.00 (x32) The Elder Scrolls V Skyrim Dragonborn (c) Bethesda Softworks version 1 (x32 Version: 1) Total War™ Shogun 2 DELUXE EDITION (x32 Version: 1.1) Tropico 4 Collectors Bundle (x32) Tunngle beta (x32) Ubisoft Game Launcher (x32 Version: Ulead GIF Animator 5 Test (x32) Unity Web Player (HKCU Version: ) Update for (KB2504637) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition Update for Microsoft Visual Studio 2012 (KB2781514) (x32 Version: 11.0.50727) Update for Microsoft Word 2010 (KB2827323) 64-Bit Edition Uplay (x32 Version: 2.1) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) Vegas Pro 12.0 (64-bit) (Version: 12.0.367) VLC media player 2.0.1 (x32 Version: 2.0.1) VoiceMaster VTFEdit 1.2.5 (x32) WBFS to ISO (x32) WC3Banlist (x32 Version: 3.0) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0) Windows Media Player 64-bit Plug-in Fix Windows Mobile Device Updater Component (Version: 04.08.2345.00) Windows Phone Engineering Flashing Tool (Version: 04.08.2134.00) Windows Software Development Kit (x32 Version: 8.59.25584) Windows Software Development Kit DirectX x64 Remote (Version: 8.59.25584) Windows Software Development Kit DirectX x86 Remote (x32 Version: 8.59.25584) Windows Software Development Kit for Windows Store Apps (x32 Version: 8.59.25584) Windows Software Development Kit for Windows Store Apps DirectX x64 Remote (Version: 8.59.25584) Windows Software Development Kit for Windows Store Apps DirectX x86 Remote (x32 Version: 8.59.25584) WinPcap 4.1.2 (x32 Version: WinRAR 4.20 (64-Bit) (Version: 4.20.0) WMP Tag Plus version 2.1 (x32 Version: 2.1) WMPKeys (x32 Version: Wsys Control (x32 Version: XCOM: Enemy Unknown (x32) Xiph.Org Open Codecs 0.85.17777 (x32 Version: 0.85.17777) Yahoo Community Smartbar (x32 Version: Yahoo Community Smartbar Engine (HKCU Version: Zune (Version: 04.08.2345.00) Zune Language Pack (CHS) (Version: 04.08.2345.00) Zune Language Pack (CHT) (Version: 04.08.2345.00) Zune Language Pack (CSY) (Version: 04.08.2345.00) Zune Language Pack (DAN) (Version: 04.08.2345.00) Zune Language Pack (DEU) (Version: 04.08.2345.00) Zune Language Pack (ELL) (Version: 04.08.2345.00) Zune Language Pack (ESP) (Version: 04.08.2345.00) Zune Language Pack (FIN) (Version: 04.08.2345.00) Zune Language Pack (FRA) (Version: 04.08.2345.00) Zune Language Pack (HUN) (Version: 04.08.2345.00) Zune Language Pack (IND) (Version: 04.08.2345.00) Zune Language Pack (ITA) (Version: 04.08.2345.00) Zune Language Pack (JPN) (Version: 04.08.2345.00) Zune Language Pack (KOR) (Version: 04.08.2345.00) Zune Language Pack (MSL) (Version: 04.08.2345.00) Zune Language Pack (NLD) (Version: 04.08.2345.00) Zune Language Pack (NOR) (Version: 04.08.2345.00) Zune Language Pack (PLK) (Version: 04.08.2345.00) Zune Language Pack (PTB) (Version: 04.08.2345.00) Zune Language Pack (PTG) (Version: 04.08.2345.00) Zune Language Pack (RUS) (Version: 04.08.2345.00) Zune Language Pack (SVE) (Version: 04.08.2345.00) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2013-05-18 17:43 - 2013-05-18 17:43 - 00000894 ____A D:\Windows\system32\Drivers\etc\hosts lmlicenses.wip4.adobe.com lm.licenses.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {15A786CD-97DB-4D87-949B-5466BB6A7D72} - System32\Tasks\AdobeAAMUpdater-1.0-DarkyDonut-PC-DarkyDonut => D:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated) Task: {5AD4386E-AE49-41BA-B738-072B2120AD29} - System32\Tasks\Apple\AppleSoftwareUpdate => D:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2008-04-11] (Apple Inc.) Task: {6031B32E-B94A-40B7-A6F0-FDFB54776984} - System32\Tasks\{723BDE7B-1B51-4A82-9D90-97C187E258AD} => D:\Program Files (x86)\Lionhead Studios Ltd\Black & White\black_white_patch_v1.300.exe Task: {60E84A29-F09D-4934-AC60-FE2509F44626} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1667423135-4136561018-2920934541-1000Core => D:\Users\DarkyDonut\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-03] (Google Inc.) Task: {BC17E1F8-C8B3-482A-AA6E-CB8E2F34C724} - System32\Tasks\ASUS\i-Setup124235 => D:\Windows\Chipset\AsusSetup.exe [2010-08-12] (ASUSTeK Computer Inc.) Task: {BE0652D6-0A76-4AE2-B47C-E256200BC888} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1667423135-4136561018-2920934541-1000UA => D:\Users\DarkyDonut\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-03] (Google Inc.) Task: {BEB2E10F-51D1-4F2C-B323-DC5C4F11BA97} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {D1A49AF1-5C4D-4B3F-A743-DA4001FCB485} - System32\Tasks\Adobe Flash Player Updater => D:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated) Task: D:\Windows\Tasks\Adobe Flash Player Updater.job => D:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: D:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1667423135-4136561018-2920934541-1000Core.job => D:\Users\DarkyDonut\AppData\Local\Google\Update\GoogleUpdate.exe Task: D:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1667423135-4136561018-2920934541-1000UA.job => D:\Users\DarkyDonut\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-17 01:07 - 2011-03-17 01:07 - 04297568 _____ () D:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2013-04-03 14:06 - 2013-04-03 14:23 - 00107520 _____ () D:\Program Files (x86)\DAEMON Tools Pro\BRD.dll 2013-03-12 18:10 - 2013-08-22 00:18 - 00687104 _____ () D:\Program Files (x86)\Steam\SDL2.dll 2012-08-21 20:41 - 2013-10-09 04:19 - 01121704 _____ () D:\Program Files (x86)\Steam\bin\chromehtml.DLL 2012-08-21 20:41 - 2013-09-11 00:20 - 20625832 _____ () D:\Program Files (x86)\Steam\bin\libcef.dll 2012-08-21 20:41 - 2013-06-15 01:49 - 01100800 _____ () D:\Program Files (x86)\Steam\bin\avcodec-53.dll 2012-08-21 20:41 - 2013-06-15 01:49 - 00124416 _____ () D:\Program Files (x86)\Steam\bin\avutil-51.dll 2012-08-21 20:41 - 2013-06-15 01:49 - 00192000 _____ () D:\Program Files (x86)\Steam\bin\avformat-53.dll 2011-03-17 01:11 - 2011-03-17 01:11 - 04297568 _____ () D:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-10-04 14:58 - 2013-10-04 14:58 - 00062976 _____ () D:\Program Files (x86)\Origin\tufao.dll 2011-07-29 01:09 - 2011-07-29 01:09 - 00096112 _____ () D:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2012-04-30 16:32 - 2010-06-22 13:50 - 00061440 _____ () D:\Program Files (x86)\ROCCAT\Kone[+] Mouse\hiddriver.dll 2013-10-05 00:00 - 2013-10-03 08:02 - 00698832 _____ () D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\30.0.1599.69\libglesv2.dll 2013-10-05 00:00 - 2013-10-03 08:02 - 00099792 _____ () D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\30.0.1599.69\libegl.dll 2013-10-05 00:00 - 2013-10-03 08:03 - 04055504 _____ () D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\30.0.1599.69\pdf.dll 2013-10-05 00:00 - 2013-10-03 08:03 - 00415184 _____ () D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll 2013-10-05 00:00 - 2013-10-03 08:02 - 01604560 _____ () D:\Users\DarkyDonut\AppData\Local\Google\Chrome\Application\30.0.1599.69\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: OHCI-konformer VIA 1394-Hostcontroller Description: OHCI-konformer VIA 1394-Hostcontroller Class Guid: {6bdd1fc1-810f-11d0-bec7-08002be2092f} Manufacturer: VIA Service: 1394ohci Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: SM-Bus-Controller Description: SM-Bus-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (10/10/2013 06:38:00 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AsusSetup.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0x00000000 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x7d8 Startzeit der fehlerhaften Anwendung: 0xAsusSetup.exe0 Pfad der fehlerhaften Anwendung: AsusSetup.exe1 Pfad des fehlerhaften Moduls: AsusSetup.exe2 Berichtskennung: AsusSetup.exe3 Error: (10/10/2013 03:12:12 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AsusSetup.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0x00000000 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x8ec Startzeit der fehlerhaften Anwendung: 0xAsusSetup.exe0 Pfad der fehlerhaften Anwendung: AsusSetup.exe1 Pfad des fehlerhaften Moduls: AsusSetup.exe2 Berichtskennung: AsusSetup.exe3 Error: (10/10/2013 07:08:54 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AsusSetup.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0x00000000 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x6a0 Startzeit der fehlerhaften Anwendung: 0xAsusSetup.exe0 Pfad der fehlerhaften Anwendung: AsusSetup.exe1 Pfad des fehlerhaften Moduls: AsusSetup.exe2 Berichtskennung: AsusSetup.exe3 Error: (10/09/2013 04:08:48 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AsusSetup.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0x00000000 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x6c0 Startzeit der fehlerhaften Anwendung: 0xAsusSetup.exe0 Pfad der fehlerhaften Anwendung: AsusSetup.exe1 Pfad des fehlerhaften Moduls: AsusSetup.exe2 Berichtskennung: AsusSetup.exe3 Error: (10/09/2013 06:49:10 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AsusSetup.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0x00000000 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0xc78 Startzeit der fehlerhaften Anwendung: 0xAsusSetup.exe0 Pfad der fehlerhaften Anwendung: AsusSetup.exe1 Pfad des fehlerhaften Moduls: AsusSetup.exe2 Berichtskennung: AsusSetup.exe3 Error: (10/08/2013 01:57:04 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AsusSetup.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0x00000000 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x8a8 Startzeit der fehlerhaften Anwendung: 0xAsusSetup.exe0 Pfad der fehlerhaften Anwendung: AsusSetup.exe1 Pfad des fehlerhaften Moduls: AsusSetup.exe2 Berichtskennung: AsusSetup.exe3 Error: (10/08/2013 06:41:58 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AsusSetup.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0x00000000 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x810 Startzeit der fehlerhaften Anwendung: 0xAsusSetup.exe0 Pfad der fehlerhaften Anwendung: AsusSetup.exe1 Pfad des fehlerhaften Moduls: AsusSetup.exe2 Berichtskennung: AsusSetup.exe3 Error: (10/08/2013 06:41:37 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Origin.exe, Version:, Zeitstempel: 0x5244e5cc Name des fehlerhaften Moduls: OriginClient.dll, Version:, Zeitstempel: 0x5244e5b4 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00156ded ID des fehlerhaften Prozesses: 0xb04 Startzeit der fehlerhaften Anwendung: 0xOrigin.exe0 Pfad der fehlerhaften Anwendung: Origin.exe1 Pfad des fehlerhaften Moduls: Origin.exe2 Berichtskennung: Origin.exe3 Error: (10/07/2013 03:57:01 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AsusSetup.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0x00000000 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x84c Startzeit der fehlerhaften Anwendung: 0xAsusSetup.exe0 Pfad der fehlerhaften Anwendung: AsusSetup.exe1 Pfad des fehlerhaften Moduls: AsusSetup.exe2 Berichtskennung: AsusSetup.exe3 Error: (10/07/2013 06:54:52 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AsusSetup.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0x00000000 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0xaec Startzeit der fehlerhaften Anwendung: 0xAsusSetup.exe0 Pfad der fehlerhaften Anwendung: AsusSetup.exe1 Pfad des fehlerhaften Moduls: AsusSetup.exe2 Berichtskennung: AsusSetup.exe3 System errors: ============= Error: (10/10/2013 06:41:10 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (10/10/2013 06:41:10 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (10/10/2013 06:38:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Wsys Service" wurde nicht richtig gestartet. Error: (10/10/2013 03:14:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (10/10/2013 03:14:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (10/10/2013 07:09:19 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/10/2013 07:09:19 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (10/10/2013 07:07:56 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (10/10/2013 07:07:56 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (10/09/2013 09:54:58 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "D:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Microsoft Office Sessions: ========================= Error: (10/10/2013 06:38:00 PM) (Source: Application Error)(User: ) Description: AsusSetup.exe2.0.17.200000000unknown0.0.0.00000000000000000000000007d801cec5d701317f9dD:\Windows\Chipset\AsusSetup.exeunknown52c7bfab-31ca-11e3-9926-5404a66924d4 Error: (10/10/2013 03:12:12 PM) (Source: Application Error)(User: ) Description: AsusSetup.exe2.0.17.200000000unknown0.0.0.00000000000000000000000008ec01cec5ba419958ffD:\Windows\Chipset\AsusSetup.exeunknown92c1244a-31ad-11e3-9f10-5404a66924d4 Error: (10/10/2013 07:08:54 AM) (Source: Application Error)(User: ) Description: AsusSetup.exe2.0.17.200000000unknown0.0.0.00000000000000000000000006a001cec5769b0f329fD:\Windows\Chipset\AsusSetup.exeunknown0ea186f5-316a-11e3-9136-5404a66924d4 Error: (10/09/2013 04:08:48 PM) (Source: Application Error)(User: ) Description: AsusSetup.exe2.0.17.200000000unknown0.0.0.00000000000000000000000006c001cec4f8d80ae32aD:\Windows\Chipset\AsusSetup.exeunknown50974a89-30ec-11e3-be41-5404a66924d4 Error: (10/09/2013 06:49:10 AM) (Source: Application Error)(User: ) Description: AsusSetup.exe2.0.17.200000000unknown0.0.0.0000000000000000000000000c7801cec4aaccf99a6cD:\Windows\Chipset\AsusSetup.exeunknown22b51535-309e-11e3-b9b3-5404a66924d4 Error: (10/08/2013 01:57:04 PM) (Source: Application Error)(User: ) Description: AsusSetup.exe2.0.17.200000000unknown0.0.0.00000000000000000000000008a801cec41d5cb02e8eD:\Windows\Chipset\AsusSetup.exeunknownbee11ad2-3010-11e3-a40b-5404a66924d4 Error: (10/08/2013 06:41:58 AM) (Source: Application Error)(User: ) Description: AsusSetup.exe2.0.17.200000000unknown0.0.0.000000000000000000000000081001cec3e07eb6f6ffD:\Windows\Chipset\AsusSetup.exeunknownf6aee0fa-2fd3-11e3-88e8-5404a66924d4 Error: (10/08/2013 06:41:37 AM) (Source: Application Error)(User: ) Description: Origin.exe9.3.7.27355244e5ccOriginClient.dll9.3.7.27355244e5b4c000000500156dedb0401cec3e086e757c9D:\Program Files (x86)\Origin\Origin.exeD:\Program Files (x86)\Origin\OriginClient.dllea3cd6d5-2fd3-11e3-88e8-5404a66924d4 Error: (10/07/2013 03:57:01 PM) (Source: Application Error)(User: ) Description: AsusSetup.exe2.0.17.200000000unknown0.0.0.000000000000000000000000084c01cec364e211d672D:\Windows\Chipset\AsusSetup.exeunknown567d6262-2f58-11e3-acc3-5404a66924d4 Error: (10/07/2013 06:54:52 AM) (Source: Application Error)(User: ) Description: AsusSetup.exe2.0.17.200000000unknown0.0.0.0000000000000000000000000aec01cec319364a3d91D:\Windows\Chipset\AsusSetup.exeunknown99a1b728-2f0c-11e3-9a55-5404a66924d4 ==================== Memory info =========================== Percentage of memory in use: 29% Total physical RAM: 8168.76 MB Available physical RAM: 5753.66 MB Total Pagefile: 9289.78 MB Available Pagefile: 6702.43 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:20.01 GB) (Free:0.04 GB) NTFS Drive d: (BOOT) (Fixed) (Total:911.5 GB) (Free:6.26 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: B0D6CFB1) Partition 1: (Active) - (Size=912 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended) ==================== End Of Log ============================ Aufgrund von zu hoher Zeichenzahl im Anhang. Ich bedanke mich im Voraus. Geändert von DarkyDonut (10.10.2013 um 18:25 Uhr) |
![]() | #2 | |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 7: Startseite wird ständig geändert![]() Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
auf deinem Rechner wird illegale Software verwendet: Zitat:
Sobald du jegliche illegale Software entfernt hast, können wir mit der Bereinigung fortfahren. Sollte ich dann jedoch noch einmal etwas entdecken, ist Schluss. Bitte lesen: Cracks, Keygens und andere illegale Software |
![]() | #3 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 7: Startseite wird ständig geändert Fehlende Rückmeldung
__________________Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
![]() |
Themen zu Windows 7: Startseite wird ständig geändert |
.com, browser, computer, desktop, downloader, excel, failed, farbar, farbar recovery scan tool, flash player, google, helper, homepage, iexplore.exe, malware, newtab, officejet, origin, plug-in, problem, proxy, realtek, refresh, required, scan, security, server, smartbar, software, super, svchost.exe, system, teamspeak, viren, windows, yahoo community smartbar |