|
Plagegeister aller Art und deren Bekämpfung: Pc hängt sich auf.Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
26.12.2013, 12:54 | #1 |
| Pc hängt sich auf. Hallo Leute! Ich bin neu hier im Trojaner Board. Seit Monaten hab ich ein sehr großes Problem! Manchmal wenn ich meinen Pc im Internet Rum Surfe und gleichzeitig ein Spiel spiele Endet dies meist mit einen Kompletten System Hänger! manchmal entfriert er sich aus der Lage aber sobald ich ein Spiel starte ist mein Bildschirm schwarz und nix passiert mehr! habe ein bisschen Beschäftigt und da fiel mir auf dies passiert wenn ich entweder im Firefox surfe ein spiel spiele und gleichzeitig Surfe aber eins Verstehe ich nicht an der Sache. Wenn der Pc sich entfriert und ich starte ein spiel im Fenster Modus passiert Rein nichts kein Schwarz Bild oder aufhänger Aber sobald ich im Vollbild Modus gehe Passierts Befürchte es liegt an meiner Grafik Karte :/ Bitte Sehr Um Hilfe bin echt Verzweifelt Leute Alle Danke Schon mal die mir Helfen möchten! M.F.G Djzeroman! |
26.12.2013, 12:56 | #2 |
/// the machine /// TB-Ausbilder | Pc hängt sich auf. hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
26.12.2013, 13:07 | #3 |
| Pc hängt sich auf. WOW! Danke für eine Schnelle antwort!
__________________Hier sind Die Logs die sie Wollten [FRST Logfile] FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-12-2013 Ran by Mark (administrator) on FONON-TECHNOLOG on 26-12-2013 13:00:38 Running from C:\Users\Mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SFH9VB6E Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (The Within Network, LLC) C:\Windows\UnsignedThemesSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe () C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe (AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe () C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\VC10Play.exe (H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\VC10SecS.exe (Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit_manager.exe (Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit.exe (H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\vc10tray.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe () D:\setup.exe () C:\Users\Mark\AppData\Local\Temp\is-A5UQI.tmp\setup.tmp () D:\setup.exe () C:\Users\Mark\AppData\Local\Temp\is-M7364.tmp\setup.tmp () C:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\sbc.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_11_9_900_152_ActiveX.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1612504 2013-11-11] (COMODO) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-09-25] (Adobe Systems Incorporated) HKLM\...\Run: [COMODO] - C:\Program Files\COMODO\COMODO livePCsupport\CLPSLA.exe HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [VC10Player] - C:\Program Files (x86)\Virtual CD v10\System\VC10Play.exe [409456 2013-11-19] (H+H Software GmbH) HKLM-x32\...\Run: [tvncontrol] - "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-11-05] (Adobe Systems Incorporated) HKCU\...\Run: [Cracked Steam Service] - C:\Program Files (x86)\Cracked Steam\AntiSteam.exe [257024 2013-05-19] (Steam006) HKCU\...\Run: [d5a38e9b5f206c41f8851bf04a251d26] - "C:\Users\Mark\AppData\Local\Temp\chrome.exe" .. <===== ATTENTION HKCU\...\Run: [GarenaPlus] - C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [9890608 2013-12-13] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.windowsxlive.net HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xEF28658F32DECE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {9A9825C1-8A41-4FDA-BC07-7F5FBECC02E6} hxxp://item.koramgame.com/st/login/activex/KoramGameStarter.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{0A61855D-CFA3-484E-937F-E05CEE114134}: [NameServer]156.154.70.25,156.154.71.25 Tcpip\..\Interfaces\{81177033-799C-433F-8DBD-546E82E9D0F2}: [NameServer]156.154.70.25,156.154.71.25 FireFox: ======== FF ProfilePath: C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\piwcxyav.default-1384116424947 FF Homepage: hxxp://www.windowsxlive.net FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nexon.net/NxGame - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon) FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @t.garena.com/garenatalk - C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Mark\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: anonymoX - C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\piwcxyav.default-1384116424947\Extensions\client@anonymox.net.xpi FF Extension: Exif Viewer - C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\piwcxyav.default-1384116424947\Extensions\exif_viewer@mozilla.doslash.org.xpi FF Extension: ipFuck - C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\piwcxyav.default-1384116424947\Extensions\ipfuck@p4ul.info.xpi FF Extension: Adblock Plus - C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\piwcxyav.default-1384116424947\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ==================== Services (Whitelisted) ================= R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70352 2013-12-13] (Comodo Security Solutions, Inc.) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6254152 2013-10-20] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [164056 2013-09-24] (COMODO) R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2098880 2013-11-11] () R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [906024 2013-11-27] (AnchorFree Inc.) S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2013-11-13] () R2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [555304 2013-11-27] () S3 npggsvc; C:\Windows\SysWow64\GameMon.des [5221784 2013-12-04] (INCA Internet Co., Ltd.) R2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-13] (The Within Network, LLC) R2 VC10SecS; C:\Program Files (x86)\Virtual CD v10\System\VC10SecS.exe [147464 2013-01-08] (H+H Software GmbH) S2 GeekBuddyRSP; "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -service [x] ==================== Drivers (Whitelisted) ==================== R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [37976 2013-05-07] (Windows (R) Win 7 DDK provider) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2013-09-24] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [709144 2013-11-14] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [48872 2013-09-24] (COMODO) R3 HH10Help.sys; C:\Windows\system32\drivers\HH10Help.sys [24088 2009-07-09] (H+H Software GmbH) R1 HMD; C:\Windows\System32\DRIVERS\hmd.sys [14888 2013-10-07] () R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [44744 2013-11-13] (AnchorFree Inc.) R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [96800 2013-09-24] (COMODO) R3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1627520 2009-06-10] (NXP Semiconductors) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-11-13] (Anchorfree Inc.) R2 uxpatch; C:\Windows\system32\drivers\uxpatch.sys [30568 2009-07-13] () S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [x] S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys [x] R5 vdrv1000; C:\Windows\System32\Drivers\vdrv1000.sys [226080 2012-12-06] (H+H Software GmbH) S3 X6va008; \??\C:\Users\Mark\AppData\Local\Temp\0084394.tmp [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-26 13:00 - 2013-12-26 13:00 - 00000000 ____D C:\FRST 2013-12-26 11:40 - 2013-12-26 11:40 - 00002300 _____ C:\Users\Mark\Desktop\Grand Theft Auto IV.lnk 2013-12-26 11:36 - 2013-12-26 11:36 - 00001180 _____ C:\Users\Mark\Desktop\GTA4_ENG_DVD2 (D) 0 Bytes.lnk 2013-12-26 11:12 - 2009-07-09 10:24 - 00024088 _____ (H+H Software GmbH) C:\Windows\system32\Drivers\hh10help.sys 2013-12-26 11:09 - 2013-12-26 11:09 - 00000000 ____D C:\Program Files (x86)\VoiceDB 2013-12-23 14:43 - 2013-12-24 05:59 - 01844244 _____ C:\Windows\system32\Drivers\fvstore.dat 2013-12-23 14:43 - 2013-12-23 14:43 - 00000000 ___HD C:\VTRoot 2013-12-23 12:28 - 2013-12-23 14:17 - 00000034 _____ C:\Windows\RarPwdDecry.INI 2013-12-23 12:14 - 2013-12-23 12:14 - 00000019 _____ C:\Users\Mark\rarrecovery.ini 2013-12-23 12:10 - 2013-09-13 23:54 - 05222115 _____ C:\Users\Mark\Desktop\Nexon Cash Code Generator.rar.bak 2013-12-23 11:37 - 2013-12-23 12:11 - 05222115 _____ C:\Users\Mark\Desktop\Nexon Cash Code Generator.rar 2013-12-22 14:04 - 2013-12-22 14:46 - 00000000 ____D C:\Users\Mark\Documents\GTA San Andreas User Files 2013-12-22 14:04 - 2013-12-22 14:04 - 00098304 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll 2013-12-22 14:04 - 2013-12-22 14:04 - 00002120 _____ C:\Users\Public\Desktop\MTA San Andreas 1.3.lnk 2013-12-22 14:03 - 2013-12-22 14:04 - 00000000 ____D C:\ProgramData\MTA San Andreas All 2013-12-22 14:03 - 2013-12-22 14:03 - 20676200 _____ (Multi Theft Auto) C:\Users\Mark\Downloads\mtasa-1.3.4.exe 2013-12-22 14:00 - 2013-12-22 14:04 - 00000000 ____D C:\Program Files (x86)\MTA San Andreas 1.3 2013-12-22 13:35 - 2013-12-26 11:14 - 00000000 ____D C:\Program Files (x86)\Rockstar Games 2013-12-22 13:16 - 2013-12-22 13:16 - 00000000 ____D C:\Users\Mark\AppData\Local\Unity 2013-12-22 09:50 - 2013-12-22 09:50 - 00000000 ____D C:\ProgramData\Hotspot Shield 2013-12-22 09:49 - 2013-12-22 09:53 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield 2013-12-22 09:49 - 2013-12-22 09:49 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Hotspot Shield 2013-12-22 09:49 - 2013-11-13 11:49 - 00044744 _____ (AnchorFree Inc.) C:\Windows\system32\Drivers\hssdrv6.sys 2013-12-20 21:42 - 2013-12-20 21:42 - 00002954 _____ C:\Windows\System32\Tasks\{0712A47E-0185-4F78-B9A6-EB323942C401} 2013-12-20 21:41 - 2013-12-20 21:41 - 00002954 _____ C:\Windows\System32\Tasks\{8EC0057F-DC6E-4FF2-BBCE-11561ED52C1A} 2013-12-20 15:07 - 2013-12-20 15:07 - 00001166 _____ C:\Users\Public\Desktop\Elsword.lnk 2013-12-20 15:07 - 2013-12-20 15:07 - 00000000 ____D C:\Program Files (x86)\Gameforge4D 2013-12-15 20:25 - 2013-12-15 20:25 - 00001168 _____ C:\Users\Public\Desktop\AION Free-to-Play.lnk 2013-12-15 20:23 - 2013-12-15 20:23 - 00001067 _____ C:\Users\Public\Desktop\Gameforge Live.lnk 2013-12-15 20:23 - 2013-12-15 20:23 - 00000000 ____D C:\Users\Mark\Downloads\Gameforge Live 2013-12-15 20:23 - 2013-12-15 20:23 - 00000000 ____D C:\Users\Mark\AppData\Local\Gameforge4d 2013-12-15 20:22 - 2013-12-15 20:23 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-12-15 20:22 - 2013-12-15 20:22 - 19364088 _____ (Gameforge ) C:\Users\Mark\Downloads\AION_GameforgeLiveSetup.exe 2013-12-15 01:51 - 2013-12-15 01:51 - 00000000 ____D C:\Program Files (x86)\alaplaya 2013-12-15 01:51 - 2008-12-18 11:33 - 00278528 _____ C:\Users\Mark\Desktop\patcher_s4.exe 2013-12-15 01:39 - 2013-12-15 01:49 - 319687284 _____ (InstallShield Software Corporation) C:\Users\Mark\Downloads\S4_League_EU_v1012_2009_01_19.exe 2013-12-15 01:01 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-12-15 01:01 - 2010-11-21 04:25 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2013-12-15 01:01 - 2010-11-21 04:24 - 00898560 _____ (Microsoft Corporation) C:\Windows\system32\oobefldr.dll 2013-12-15 01:01 - 2010-11-21 04:24 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\taskmgr.exe 2013-12-15 01:01 - 2010-11-21 04:24 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll 2013-12-15 01:01 - 2010-11-21 04:24 - 00143360 _____ (Microsoft Corporation) C:\Windows\system32\mydocs.dll 2013-12-15 01:01 - 2010-11-21 04:23 - 02652160 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll 2013-12-15 01:01 - 2010-11-21 04:23 - 01808384 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll 2013-12-15 01:01 - 2010-11-21 04:23 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\sndvolsso.dll 2013-12-15 01:01 - 2009-07-14 02:39 - 06676480 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe 2013-12-15 01:01 - 2009-07-14 02:39 - 00431104 _____ (Microsoft Corporation) C:\Windows\system32\snippingtool.exe 2013-12-15 01:01 - 2009-07-14 02:39 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe 2013-12-15 01:00 - 2010-11-21 04:24 - 00300032 _____ (Microsoft Corporation) C:\Windows\system32\msconfig.exe 2013-12-15 00:59 - 2013-12-15 02:03 - 00000000 ____D C:\Windows\UXBackup 2013-12-15 00:59 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-15 00:59 - 2013-02-27 06:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-12-15 00:59 - 2010-11-21 04:24 - 02872320 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-12-15 00:59 - 2010-11-21 04:24 - 01866240 _____ (Microsoft Corporation) C:\Windows\system32\explorerframe.dll 2013-12-15 00:59 - 2010-11-21 04:24 - 00780800 _____ (Microsoft Corporation) C:\Windows\system32\actioncenter.dll 2013-12-15 00:59 - 2010-11-21 04:24 - 00749568 _____ (Microsoft Corporation) C:\Windows\system32\batmeter.dll 2013-12-15 00:59 - 2010-11-21 04:24 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\browseui.dll 2013-12-15 00:59 - 2010-11-21 04:23 - 00345088 _____ (Microsoft Corporation) C:\Windows\system32\cmd.exe 2013-12-15 00:59 - 2009-07-14 02:39 - 00183296 _____ (Microsoft Corp.) C:\Windows\system32\defrag.exe 2013-12-15 00:59 - 2009-07-14 02:39 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2013-12-15 00:59 - 2009-07-14 02:39 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\control.exe 2013-12-15 00:59 - 2009-07-14 02:39 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\dpiscaling.exe 2013-12-15 00:59 - 2009-07-14 02:38 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe 2013-12-15 00:59 - 2009-07-14 02:28 - 20268032 _____ (Microsoft Corporation) C:\Windows\system32\imageres.dll 2013-12-15 00:59 - 2009-07-14 02:14 - 00398336 _____ (Microsoft Corporation) C:\Windows\regedit.exe 2013-12-15 00:58 - 2011-08-11 12:47 - 00076288 _____ C:\Windows\SysWOW64\moveex.exe 2013-12-15 00:58 - 2003-08-19 01:44 - 00118845 _____ (Matt Ginzton) C:\Windows\Flurry.scr 2013-12-15 00:17 - 2013-12-15 00:17 - 00003514 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-FONON-TECHNOLOG-Mark 2013-12-15 00:17 - 2013-12-15 00:17 - 00000000 ____D C:\Users\Mark\Documents\Adobe 2013-12-15 00:15 - 2013-12-15 00:17 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-12-14 23:42 - 2013-12-15 00:03 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-12-14 23:42 - 2013-12-15 00:01 - 00000000 ____D C:\Program Files\Adobe 2013-12-14 23:26 - 2013-12-14 23:26 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA 2013-12-14 23:23 - 2013-12-17 17:53 - 00000000 ____D C:\Users\Mark\Desktop\XNALara 2013-12-14 23:23 - 2013-12-14 23:23 - 00000000 ____D C:\Users\Mark\AppData\Local\Deployment 2013-12-14 23:23 - 2013-12-14 23:23 - 00000000 ____D C:\Users\Mark\AppData\Local\Apps\2.0 2013-12-14 23:16 - 2013-12-14 23:49 - 00000000 ____D C:\ProgramData\Adobe 2013-12-14 23:13 - 2013-12-14 23:13 - 00001070 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2013-12-14 23:12 - 2013-12-14 23:12 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-12-14 22:56 - 2013-12-14 22:56 - 00000000 ____D C:\Program Files (x86)\CAPCOM 2013-12-14 22:54 - 2013-12-15 20:26 - 00062671 _____ C:\Windows\DirectX.log 2013-12-14 22:54 - 2013-12-14 22:55 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-12-14 22:54 - 2013-12-14 22:54 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-12-14 22:41 - 2013-12-14 22:41 - 00000000 ____D C:\Windows\System32\Tasks\Abelssoft 2013-12-14 22:41 - 2013-12-14 22:41 - 00000000 ____D C:\Users\Mark\AppData\Local\Abelssoft 2013-12-14 22:30 - 2013-12-14 22:30 - 00000000 ____D C:\Users\Public\Documents\COMODO 2013-12-14 19:14 - 2013-11-15 23:18 - 00000000 ____D C:\Users\Mark\Desktop\Tor Browser 2013-12-14 17:13 - 2013-12-14 17:13 - 46003592 _____ C:\Users\Mark\Desktop\Emuclient 2013-12-14 17-13-25-96.avi 2013-12-14 12:00 - 2013-12-14 12:00 - 00000000 ____D C:\Users\Mark\AppData\Local\S4Launcher 2013-12-14 11:58 - 2013-12-14 12:58 - 00001656 _____ C:\Users\Mark\Desktop\OLYMP S34.lnk 2013-12-14 11:48 - 2013-12-18 06:28 - 00000000 ____D C:\Users\Mark\Desktop\S4Olympus 2013-12-14 11:24 - 2013-12-14 11:24 - 00001756 _____ C:\Users\Mark\Desktop\Sims - Verknüpfung.lnk 2013-12-14 11:14 - 2013-12-14 11:14 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxis 2013-12-14 09:56 - 2013-12-14 09:56 - 00000000 ____D C:\Program Files (x86)\Maxis 2013-12-14 09:54 - 2011-01-04 19:58 - 2056910848 _____ C:\Users\Mark\Desktop\The Sims 1 +All Expansions.iso 2013-12-13 20:19 - 2013-12-13 20:20 - 00003447 _____ C:\Windows\hhdrvi.log 2013-12-13 20:19 - 2013-12-13 20:20 - 00000000 ___SD C:\Users\Public\Virtual CDs 2013-12-13 20:19 - 2013-12-13 20:20 - 00000000 ___SD C:\Users\Public\Virtual CD v10 2013-12-13 20:19 - 2013-12-13 20:20 - 00000000 ___SD C:\Users\Mark\AppData\Roaming\Virtual CD v10 2013-12-13 20:19 - 2013-12-13 20:19 - 00002077 _____ C:\Users\Public\Desktop\Virtual CD v10.lnk 2013-12-13 20:19 - 2013-12-13 20:19 - 00000000 ____D C:\Program Files (x86)\Virtual CD v10 2013-12-13 20:19 - 2012-12-06 11:09 - 00226080 _____ (H+H Software GmbH) C:\Windows\system32\Drivers\vdrv1000.sys 2013-12-13 20:19 - 2009-07-09 10:24 - 00024088 _____ (H+H Software GmbH) C:\Windows\system32\Drivers\HH10Help.dat 2013-12-13 20:18 - 2013-12-13 20:18 - 00000000 ____D C:\Users\Mark\AppData\Roaming\InstallShield 2013-12-13 20:18 - 2008-06-17 08:22 - 00040464 _____ (H+H Software GmbH) C:\Windows\system32\Drivers\vcd10bus.sys 2013-12-12 20:28 - 2013-12-13 17:35 - 00000000 ____D C:\Users\Mark\Desktop\BGM 2013-12-12 19:53 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 19:53 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-12 19:53 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 19:53 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-12 19:53 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 19:53 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-12 19:52 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 19:52 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-12 19:52 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-12 19:52 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-12 19:52 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 19:52 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-12 19:52 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 19:52 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-12 19:52 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-12 19:52 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-12 19:52 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-12 19:52 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-12 19:52 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 19:52 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-12 19:52 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-12 19:52 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 19:52 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-12 19:52 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-12 19:52 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 19:52 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 19:52 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-12 19:52 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-12 19:52 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-12 19:52 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-12 16:50 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-12 16:50 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-12 16:50 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 16:50 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 16:50 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-12 16:50 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 16:50 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 16:50 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-12 16:50 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-12 16:50 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 16:50 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-12 16:50 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-12 16:50 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-12 16:50 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-12 16:50 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-10 21:22 - 2013-12-10 21:22 - 00000000 ____D C:\Users\Mark\Documents\NurienGame 2013-12-08 19:57 - 2013-12-04 01:17 - 05221784 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des 2013-12-08 19:56 - 2013-12-08 19:56 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Garena 2013-12-08 19:56 - 2013-12-08 19:56 - 00000000 ____D C:\ProgramData\Garena 2013-12-08 19:56 - 2013-12-08 19:56 - 00000000 ____D C:\Program Files\Common Files\INCA Shared 2013-12-08 19:44 - 2013-12-08 19:44 - 00045270 _____ C:\Users\Mark\AppData\Roaming\room_v3.dat 2013-12-08 19:37 - 2013-12-26 10:01 - 00000000 ____D C:\Users\Mark\AppData\Roaming\GarenaPlus 2013-12-08 19:37 - 2013-12-08 19:37 - 00001053 _____ C:\Users\Public\Desktop\Mstar.lnk 2013-12-08 19:21 - 2013-12-08 19:21 - 00001063 _____ C:\Users\Public\Desktop\Garena Plus.lnk 2013-12-08 19:20 - 2013-12-26 10:01 - 00000000 ____D C:\ProgramData\GarenaMessenger 2013-12-08 19:20 - 2013-12-20 18:01 - 00000000 ____D C:\Program Files (x86)\Garena Plus 2013-12-08 19:20 - 2013-12-08 19:37 - 00000000 ____D C:\Program Files (x86)\GarenaMstar 2013-12-08 18:58 - 2013-12-08 19:18 - 00207735 _____ C:\Users\Mark\Desktop\GarenaMStar_Installer_201312040.exe 2013-12-08 18:12 - 2013-12-08 19:18 - 2097152000 _____ C:\Users\Mark\Desktop\GarenaMStar_Installer_201312040.1.dat 2013-12-08 18:12 - 2013-12-08 19:18 - 1652105114 _____ C:\Users\Mark\Desktop\GarenaMStar_Installer_201312040.2.dat 2013-12-08 18:12 - 2013-12-08 18:12 - 00000000 ____D C:\Users\Mark\AppData\Local\Garena 2013-12-07 22:25 - 2013-12-07 22:25 - 00002202 _____ C:\Users\Public\Desktop\Die Sims™ 3 Supernatural.lnk 2013-12-07 22:24 - 2013-12-07 22:24 - 00002210 _____ C:\Users\Public\Desktop\Die Sims™ 3 Late Night.lnk 2013-12-07 16:58 - 2013-12-07 16:58 - 00002060 _____ C:\Users\Public\Desktop\Die*Sims™*3.lnk 2013-12-07 15:03 - 2013-12-07 15:03 - 00002256 _____ C:\Users\Public\Desktop\Die Sims™ 3 Into the Future.lnk 2013-12-07 14:45 - 2013-12-13 18:04 - 00000037 _____ C:\Users\Mark\Desktop\MicrosoftNummer.txt 2013-12-01 09:16 - 2013-12-01 09:16 - 00003524 _____ C:\Windows\System32\Tasks\RunAsStdUser Task 2013-12-01 09:15 - 2013-12-01 09:17 - 00000000 ____D C:\Users\Mark\AppData\Local\Oxy 2013-12-01 09:15 - 2013-12-01 09:15 - 00000000 ____D C:\Users\Mark\AppData\Local\Chromium 2013-12-01 09:14 - 2013-12-01 13:12 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Oxy 2013-12-01 08:11 - 2013-12-01 08:11 - 00798183 _____ C:\Users\Mark\Downloads\Karma Koin Generator.zip 2013-12-01 08:07 - 2013-12-15 01:59 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Appnimi 2013-12-01 08:07 - 2013-12-15 01:59 - 00000000 ____D C:\Program Files (x86)\Appnimi 2013-12-01 08:07 - 2013-12-01 08:07 - 00000000 ____D C:\Users\Mark\AppData\Local\Appnimi ZIP Password Kit 2013-12-01 05:14 - 2013-12-22 04:10 - 00000000 ____D C:\Users\Mark\Desktop\NX HAX 2013-12-01 03:59 - 2013-12-25 11:18 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Skype 2013-12-01 03:59 - 2013-12-25 10:15 - 00000000 ____D C:\ProgramData\Skype 2013-12-01 03:59 - 2013-12-01 03:59 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk 2013-12-01 03:59 - 2013-12-01 03:59 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-12-01 00:42 - 2013-12-01 00:42 - 03499570 _____ C:\Users\Mark\Downloads\1391496_3823818_P.mp4 2013-11-30 20:36 - 2013-11-30 20:37 - 273457816 _____ C:\Users\Mark\Desktop\mugen 2013-11-30 20-36-19-54.avi 2013-11-30 20:06 - 2013-12-15 00:16 - 00000000 ____D C:\Users\Mark\AppData\Roaming\NVIDIA 2013-11-30 20:06 - 2013-11-30 20:07 - 524389112 _____ C:\Users\Mark\Desktop\mugen 2013-11-30 20-06-27-52.avi 2013-11-30 20:00 - 2013-11-30 20:00 - 67572904 _____ C:\Users\Mark\Desktop\IEXPLORE 2013-11-30 20-00-14-09.avi 2013-11-30 19:45 - 2013-11-30 20:21 - 00000000 ____D C:\Fraps 2013-11-30 19:45 - 2013-11-30 19:45 - 00000562 _____ C:\Users\Mark\Desktop\Fraps.lnk 2013-11-30 19:45 - 2013-11-30 19:45 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps 2013-11-30 16:19 - 2013-11-30 16:19 - 00001975 _____ C:\Users\Mark\Desktop\patcher.lnk 2013-11-30 15:52 - 2013-11-30 15:52 - 00266288 _____ C:\Windows\Minidump\113013-19156-01.dmp 2013-11-30 15:52 - 2013-11-30 15:52 - 00000000 ____D C:\Windows\Minidump 2013-11-30 00:09 - 2013-11-30 00:09 - 00002001 _____ C:\Users\Public\Desktop\The Sims Online.lnk 2013-11-30 00:06 - 2013-11-30 00:06 - 00000000 ____D C:\Program Files\Maxis 2013-11-29 21:47 - 2013-11-29 21:47 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Audition Online 2013-11-29 20:20 - 2012-08-30 12:26 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2013-11-29 20:13 - 2013-11-29 20:13 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\msvcr71.dll 2013-11-29 20:07 - 2013-11-29 20:08 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlorensiaEN 2013-11-29 20:02 - 2013-11-29 20:08 - 00000000 ____D C:\AHA Entertainment 2013-11-29 19:41 - 2013-11-29 20:10 - 00000000 ____D C:\ProgramData\Solid State Networks 2013-11-29 19:41 - 2013-11-29 19:56 - 1105972422 _____ C:\Users\Mark\Desktop\flo_setup_en_rs_130911.exe 2013-11-29 19:32 - 2013-11-29 19:32 - 01173504 _____ (ProSiebenSat.1 Games) C:\Users\Mark\Downloads\florensia-dlm(1).exe 2013-11-29 18:27 - 2013-11-29 19:11 - 2925954266 _____ (ProSiebenSat1Games) C:\Users\Mark\Desktop\Audition_Setup.exe 2013-11-29 18:26 - 2013-11-29 18:26 - 01173504 _____ (ProSiebenSat.1 Games) C:\Users\Mark\Downloads\florensia-dlm.exe 2013-11-29 18:26 - 2013-11-29 18:26 - 01047960 _____ (Solid State Networks) C:\Users\Mark\Downloads\audition-dlm.exe 2013-11-29 18:13 - 2013-12-01 06:05 - 00000000 ____D C:\Program Files (x86)\Audition Online 2013-11-28 22:08 - 2013-12-15 00:09 - 00000000 ____D C:\Users\Mark\Desktop\Project-Dollhouse-master 2013-11-28 20:53 - 2013-12-22 14:04 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-11-28 19:52 - 2013-11-28 20:36 - 00000000 ____D C:\Users\Mark\Downloads\The Sims Online Setup Files 2013-11-28 19:51 - 2013-11-28 19:51 - 00126976 _____ C:\Users\Mark\Downloads\Setup The Sims Online.exe 2013-11-26 23:32 - 2013-11-30 15:52 - 355608758 _____ C:\Windows\MEMORY.DMP 2013-11-26 23:20 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-26 23:15 - 2013-11-26 23:15 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-26 23:15 - 2013-11-26 23:15 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-26 23:15 - 2013-11-26 23:15 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-26 23:15 - 2013-11-26 23:15 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-26 23:15 - 2013-11-26 23:15 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-26 23:15 - 2013-11-26 23:15 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-26 23:15 - 2013-11-26 23:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-11-26 23:12 - 2013-11-26 23:20 - 00011363 _____ C:\Windows\IE11_main.log 2013-11-26 23:12 - 2013-11-26 23:12 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-11-26 23:12 - 2013-11-26 23:12 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-11-26 23:12 - 2013-11-26 23:12 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-11-26 23:02 - 2013-11-26 23:02 - 00002130 _____ C:\Users\Public\Desktop\Die Sims™ 3 Einfach tierisch.lnk 2013-11-26 23:00 - 2013-12-07 22:15 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-11-26 23:00 - 2013-11-26 23:08 - 00000000 ____D C:\Users\Mark\Desktop\Die Sims 3 Late Night 2013-11-26 21:51 - 2013-11-26 21:51 - 00000000 __RHD C:\Users\Mark\AppData\Roaming\SecuROM 2013-11-26 21:47 - 2013-11-26 21:47 - 00000000 ____D C:\ProgramData\EA Core 2013-11-26 21:37 - 2013-12-07 16:57 - 00447752 _____ (On2.com) C:\Windows\SysWOW64\vp6vfw.dll 2013-11-26 21:37 - 2013-11-26 21:37 - 00000000 ____D C:\Program Files (x86)\Microsoft WSE 2013-11-26 20:37 - 2013-12-26 09:57 - 00049222 _____ C:\Windows\PFRO.log 2013-11-26 19:37 - 2013-12-07 17:25 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-11-26 19:36 - 2013-11-26 20:38 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Origin 2013-11-26 19:36 - 2013-11-26 19:37 - 00000000 ____D C:\Users\Mark\AppData\Local\Origin 2013-11-26 19:34 - 2013-12-08 18:00 - 00000000 ____D C:\Program Files (x86)\Origin 2013-11-26 19:34 - 2013-11-30 00:34 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-11-26 19:34 - 2013-11-26 19:37 - 00000000 ____D C:\ProgramData\Origin 2013-11-26 19:34 - 2013-11-26 19:34 - 00000979 _____ C:\Users\Public\Desktop\Origin.lnk 2013-11-26 19:31 - 2013-11-26 19:32 - 16959688 _____ (Electronic Arts, Inc.) C:\Users\Mark\Downloads\OriginThinSetup_9.2.1.4399.exe 2013-11-26 18:54 - 2013-11-26 18:54 - 00000000 ____D C:\ProgramData\VirtuallTek 2013-11-26 18:54 - 2013-11-26 18:54 - 00000000 ____D C:\Program Files (x86)\VirtuallTek 2013-11-26 18:53 - 2013-11-26 18:53 - 01743576 _____ (VirtuallTek Systems ) C:\Users\Mark\Downloads\Fighter Factory Ultimate 2.5 Setup.exe 2013-11-26 18:49 - 2013-11-26 18:49 - 00628696 _____ C:\Users\Mark\Downloads\ffu26.exe ==================== One Month Modified Files and Folders ======= 2013-12-26 13:00 - 2013-12-26 13:00 - 00000000 ____D C:\FRST 2013-12-26 11:59 - 2009-07-14 05:45 - 00033872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-26 11:59 - 2009-07-14 05:45 - 00033872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-26 11:40 - 2013-12-26 11:40 - 00002300 _____ C:\Users\Mark\Desktop\Grand Theft Auto IV.lnk 2013-12-26 11:36 - 2013-12-26 11:36 - 00001180 _____ C:\Users\Mark\Desktop\GTA4_ENG_DVD2 (D) 0 Bytes.lnk 2013-12-26 11:14 - 2013-12-22 13:35 - 00000000 ____D C:\Program Files (x86)\Rockstar Games 2013-12-26 11:11 - 2011-04-12 08:43 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-12-26 11:11 - 2011-04-12 08:43 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-12-26 11:11 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-26 11:09 - 2013-12-26 11:09 - 00000000 ____D C:\Program Files (x86)\VoiceDB 2013-12-26 10:07 - 2013-11-10 17:40 - 00000000 ____D C:\Users\Mark\AppData\Local\Adobe 2013-12-26 10:01 - 2013-12-08 19:37 - 00000000 ____D C:\Users\Mark\AppData\Roaming\GarenaPlus 2013-12-26 10:01 - 2013-12-08 19:20 - 00000000 ____D C:\ProgramData\GarenaMessenger 2013-12-26 10:01 - 2013-11-23 19:54 - 01440291 _____ C:\Windows\WindowsUpdate.log 2013-12-26 09:57 - 2013-11-26 20:37 - 00049222 _____ C:\Windows\PFRO.log 2013-12-26 09:57 - 2013-11-23 23:49 - 00003506 _____ C:\Windows\setupact.log 2013-12-26 09:57 - 2013-11-13 00:26 - 00000000 ____D C:\ProgramData\NVIDIA 2013-12-26 09:57 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-25 11:18 - 2013-12-01 03:59 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Skype 2013-12-25 10:15 - 2013-12-01 03:59 - 00000000 ____D C:\ProgramData\Skype 2013-12-24 20:08 - 2013-11-14 22:40 - 00000324 _____ C:\Users\Mark\Desktop\ Mabinogi .lnk 2013-12-24 05:59 - 2013-12-23 14:43 - 01844244 _____ C:\Windows\system32\Drivers\fvstore.dat 2013-12-23 14:43 - 2013-12-23 14:43 - 00000000 ___HD C:\VTRoot 2013-12-23 14:17 - 2013-12-23 12:28 - 00000034 _____ C:\Windows\RarPwdDecry.INI 2013-12-23 12:14 - 2013-12-23 12:14 - 00000019 _____ C:\Users\Mark\rarrecovery.ini 2013-12-23 12:14 - 2013-11-10 14:45 - 00000000 ____D C:\Users\Mark 2013-12-23 12:11 - 2013-12-23 11:37 - 05222115 _____ C:\Users\Mark\Desktop\Nexon Cash Code Generator.rar 2013-12-22 14:46 - 2013-12-22 14:04 - 00000000 ____D C:\Users\Mark\Documents\GTA San Andreas User Files 2013-12-22 14:04 - 2013-12-22 14:04 - 00098304 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll 2013-12-22 14:04 - 2013-12-22 14:04 - 00002120 _____ C:\Users\Public\Desktop\MTA San Andreas 1.3.lnk 2013-12-22 14:04 - 2013-12-22 14:03 - 00000000 ____D C:\ProgramData\MTA San Andreas All 2013-12-22 14:04 - 2013-12-22 14:00 - 00000000 ____D C:\Program Files (x86)\MTA San Andreas 1.3 2013-12-22 14:04 - 2013-11-28 20:53 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-12-22 14:03 - 2013-12-22 14:03 - 20676200 _____ (Multi Theft Auto) C:\Users\Mark\Downloads\mtasa-1.3.4.exe 2013-12-22 13:35 - 2013-11-16 02:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-22 13:16 - 2013-12-22 13:16 - 00000000 ____D C:\Users\Mark\AppData\Local\Unity 2013-12-22 09:53 - 2013-12-22 09:49 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield 2013-12-22 09:50 - 2013-12-22 09:50 - 00000000 ____D C:\ProgramData\Hotspot Shield 2013-12-22 09:49 - 2013-12-22 09:49 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Hotspot Shield 2013-12-22 09:19 - 2013-11-10 17:56 - 01474832 _____ C:\Windows\system32\Drivers\sfi.dat 2013-12-22 04:10 - 2013-12-01 05:14 - 00000000 ____D C:\Users\Mark\Desktop\NX HAX 2013-12-20 21:42 - 2013-12-20 21:42 - 00002954 _____ C:\Windows\System32\Tasks\{0712A47E-0185-4F78-B9A6-EB323942C401} 2013-12-20 21:41 - 2013-12-20 21:41 - 00002954 _____ C:\Windows\System32\Tasks\{8EC0057F-DC6E-4FF2-BBCE-11561ED52C1A} 2013-12-20 18:01 - 2013-12-08 19:20 - 00000000 ____D C:\Program Files (x86)\Garena Plus 2013-12-20 17:38 - 2013-11-20 17:32 - 00000000 ____D C:\Users\Mark\Desktop\Hatsune Miku Project MUGEN S.P (WithoutStages) 2013-12-20 15:07 - 2013-12-20 15:07 - 00001166 _____ C:\Users\Public\Desktop\Elsword.lnk 2013-12-20 15:07 - 2013-12-20 15:07 - 00000000 ____D C:\Program Files (x86)\Gameforge4D 2013-12-19 20:10 - 2013-11-14 20:00 - 00000000 ____D C:\Users\Mark\Documents\Mabinogi 2013-12-19 17:52 - 2013-11-14 22:20 - 00000000 ____D C:\Users\Mark\Documents\MabinogiSetup169R 2013-12-18 06:28 - 2013-12-14 11:48 - 00000000 ____D C:\Users\Mark\Desktop\S4Olympus 2013-12-17 17:53 - 2013-12-14 23:23 - 00000000 ____D C:\Users\Mark\Desktop\XNALara 2013-12-15 22:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-15 20:26 - 2013-12-14 22:54 - 00062671 _____ C:\Windows\DirectX.log 2013-12-15 20:25 - 2013-12-15 20:25 - 00001168 _____ C:\Users\Public\Desktop\AION Free-to-Play.lnk 2013-12-15 20:23 - 2013-12-15 20:23 - 00001067 _____ C:\Users\Public\Desktop\Gameforge Live.lnk 2013-12-15 20:23 - 2013-12-15 20:23 - 00000000 ____D C:\Users\Mark\Downloads\Gameforge Live 2013-12-15 20:23 - 2013-12-15 20:23 - 00000000 ____D C:\Users\Mark\AppData\Local\Gameforge4d 2013-12-15 20:23 - 2013-12-15 20:22 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-12-15 20:22 - 2013-12-15 20:22 - 19364088 _____ (Gameforge ) C:\Users\Mark\Downloads\AION_GameforgeLiveSetup.exe 2013-12-15 13:02 - 2013-11-16 02:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-15 02:03 - 2013-12-15 00:59 - 00000000 ____D C:\Windows\UXBackup 2013-12-15 02:03 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2013-12-15 01:59 - 2013-12-01 08:07 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Appnimi 2013-12-15 01:59 - 2013-12-01 08:07 - 00000000 ____D C:\Program Files (x86)\Appnimi 2013-12-15 01:51 - 2013-12-15 01:51 - 00000000 ____D C:\Program Files (x86)\alaplaya 2013-12-15 01:49 - 2013-12-15 01:39 - 319687284 _____ (InstallShield Software Corporation) C:\Users\Mark\Downloads\S4_League_EU_v1012_2009_01_19.exe 2013-12-15 01:04 - 2013-11-10 14:45 - 00000000 ____D C:\Users\Mark\AppData\Local\VirtualStore 2013-12-15 01:03 - 2009-07-14 05:45 - 04936888 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-15 01:01 - 2013-11-10 17:58 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 00:59 - 2013-11-10 17:57 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-15 00:58 - 2009-07-14 04:20 - 00000000 __RSD C:\Windows\Media 2013-12-15 00:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Cursors 2013-12-15 00:17 - 2013-12-15 00:17 - 00003514 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-FONON-TECHNOLOG-Mark 2013-12-15 00:17 - 2013-12-15 00:17 - 00000000 ____D C:\Users\Mark\Documents\Adobe 2013-12-15 00:17 - 2013-12-15 00:15 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-12-15 00:16 - 2013-11-30 20:06 - 00000000 ____D C:\Users\Mark\AppData\Roaming\NVIDIA 2013-12-15 00:16 - 2013-11-10 17:50 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Adobe 2013-12-15 00:09 - 2013-11-28 22:08 - 00000000 ____D C:\Users\Mark\Desktop\Project-Dollhouse-master 2013-12-15 00:05 - 2013-11-10 17:56 - 00057560 _____ C:\Users\Mark\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-15 00:03 - 2013-12-14 23:42 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-12-15 00:01 - 2013-12-14 23:42 - 00000000 ____D C:\Program Files\Adobe 2013-12-14 23:49 - 2013-12-14 23:16 - 00000000 ____D C:\ProgramData\Adobe 2013-12-14 23:26 - 2013-12-14 23:26 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA 2013-12-14 23:23 - 2013-12-14 23:23 - 00000000 ____D C:\Users\Mark\AppData\Local\Deployment 2013-12-14 23:23 - 2013-12-14 23:23 - 00000000 ____D C:\Users\Mark\AppData\Local\Apps\2.0 2013-12-14 23:13 - 2013-12-14 23:13 - 00001070 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2013-12-14 23:12 - 2013-12-14 23:12 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-12-14 22:56 - 2013-12-14 22:56 - 00000000 ____D C:\Program Files (x86)\CAPCOM 2013-12-14 22:56 - 2013-11-14 20:09 - 00002013 _____ C:\Users\Public\Desktop\GeekBuddy.lnk 2013-12-14 22:55 - 2013-12-14 22:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-12-14 22:54 - 2013-12-14 22:54 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-12-14 22:41 - 2013-12-14 22:41 - 00000000 ____D C:\Windows\System32\Tasks\Abelssoft 2013-12-14 22:41 - 2013-12-14 22:41 - 00000000 ____D C:\Users\Mark\AppData\Local\Abelssoft 2013-12-14 22:30 - 2013-12-14 22:30 - 00000000 ____D C:\Users\Public\Documents\COMODO 2013-12-14 22:26 - 2013-11-10 17:54 - 00000000 ____D C:\Program Files\COMODO 2013-12-14 17:13 - 2013-12-14 17:13 - 46003592 _____ C:\Users\Mark\Desktop\Emuclient 2013-12-14 17-13-25-96.avi 2013-12-14 12:58 - 2013-12-14 11:58 - 00001656 _____ C:\Users\Mark\Desktop\OLYMP S34.lnk 2013-12-14 12:00 - 2013-12-14 12:00 - 00000000 ____D C:\Users\Mark\AppData\Local\S4Launcher 2013-12-14 11:24 - 2013-12-14 11:24 - 00001756 _____ C:\Users\Mark\Desktop\Sims - Verknüpfung.lnk 2013-12-14 11:14 - 2013-12-14 11:14 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxis 2013-12-14 09:56 - 2013-12-14 09:56 - 00000000 ____D C:\Program Files (x86)\Maxis 2013-12-13 20:20 - 2013-12-13 20:19 - 00003447 _____ C:\Windows\hhdrvi.log 2013-12-13 20:20 - 2013-12-13 20:19 - 00000000 ___SD C:\Users\Public\Virtual CDs 2013-12-13 20:20 - 2013-12-13 20:19 - 00000000 ___SD C:\Users\Public\Virtual CD v10 2013-12-13 20:20 - 2013-12-13 20:19 - 00000000 ___SD C:\Users\Mark\AppData\Roaming\Virtual CD v10 2013-12-13 20:19 - 2013-12-13 20:19 - 00002077 _____ C:\Users\Public\Desktop\Virtual CD v10.lnk 2013-12-13 20:19 - 2013-12-13 20:19 - 00000000 ____D C:\Program Files (x86)\Virtual CD v10 2013-12-13 20:18 - 2013-12-13 20:18 - 00000000 ____D C:\Users\Mark\AppData\Roaming\InstallShield 2013-12-13 18:04 - 2013-12-07 14:45 - 00000037 _____ C:\Users\Mark\Desktop\MicrosoftNummer.txt 2013-12-13 17:35 - 2013-12-12 20:28 - 00000000 ____D C:\Users\Mark\Desktop\BGM 2013-12-10 21:22 - 2013-12-10 21:22 - 00000000 ____D C:\Users\Mark\Documents\NurienGame 2013-12-08 19:56 - 2013-12-08 19:56 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Garena 2013-12-08 19:56 - 2013-12-08 19:56 - 00000000 ____D C:\ProgramData\Garena 2013-12-08 19:56 - 2013-12-08 19:56 - 00000000 ____D C:\Program Files\Common Files\INCA Shared 2013-12-08 19:44 - 2013-12-08 19:44 - 00045270 _____ C:\Users\Mark\AppData\Roaming\room_v3.dat 2013-12-08 19:37 - 2013-12-08 19:37 - 00001053 _____ C:\Users\Public\Desktop\Mstar.lnk 2013-12-08 19:37 - 2013-12-08 19:20 - 00000000 ____D C:\Program Files (x86)\GarenaMstar 2013-12-08 19:21 - 2013-12-08 19:21 - 00001063 _____ C:\Users\Public\Desktop\Garena Plus.lnk 2013-12-08 19:18 - 2013-12-08 18:58 - 00207735 _____ C:\Users\Mark\Desktop\GarenaMStar_Installer_201312040.exe 2013-12-08 19:18 - 2013-12-08 18:12 - 2097152000 _____ C:\Users\Mark\Desktop\GarenaMStar_Installer_201312040.1.dat 2013-12-08 19:18 - 2013-12-08 18:12 - 1652105114 _____ C:\Users\Mark\Desktop\GarenaMStar_Installer_201312040.2.dat 2013-12-08 18:12 - 2013-12-08 18:12 - 00000000 ____D C:\Users\Mark\AppData\Local\Garena 2013-12-08 18:00 - 2013-11-26 19:34 - 00000000 ____D C:\Program Files (x86)\Origin 2013-12-07 22:25 - 2013-12-07 22:25 - 00002202 _____ C:\Users\Public\Desktop\Die Sims™ 3 Supernatural.lnk 2013-12-07 22:24 - 2013-12-07 22:24 - 00002210 _____ C:\Users\Public\Desktop\Die Sims™ 3 Late Night.lnk 2013-12-07 22:15 - 2013-11-26 23:00 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-12-07 17:25 - 2013-11-26 19:37 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-12-07 16:58 - 2013-12-07 16:58 - 00002060 _____ C:\Users\Public\Desktop\Die*Sims™*3.lnk 2013-12-07 16:57 - 2013-11-26 21:37 - 00447752 _____ (On2.com) C:\Windows\SysWOW64\vp6vfw.dll 2013-12-07 15:03 - 2013-12-07 15:03 - 00002256 _____ C:\Users\Public\Desktop\Die Sims™ 3 Into the Future.lnk 2013-12-04 01:17 - 2013-12-08 19:57 - 05221784 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des 2013-12-01 13:12 - 2013-12-01 09:14 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Oxy 2013-12-01 09:17 - 2013-12-01 09:15 - 00000000 ____D C:\Users\Mark\AppData\Local\Oxy 2013-12-01 09:17 - 2013-11-10 14:45 - 00000000 ___RD C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-01 09:16 - 2013-12-01 09:16 - 00003524 _____ C:\Windows\System32\Tasks\RunAsStdUser Task 2013-12-01 09:15 - 2013-12-01 09:15 - 00000000 ____D C:\Users\Mark\AppData\Local\Chromium 2013-12-01 08:11 - 2013-12-01 08:11 - 00798183 _____ C:\Users\Mark\Downloads\Karma Koin Generator.zip 2013-12-01 08:07 - 2013-12-01 08:07 - 00000000 ____D C:\Users\Mark\AppData\Local\Appnimi ZIP Password Kit 2013-12-01 06:05 - 2013-11-29 18:13 - 00000000 ____D C:\Program Files (x86)\Audition Online 2013-12-01 03:59 - 2013-12-01 03:59 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk 2013-12-01 03:59 - 2013-12-01 03:59 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-12-01 00:42 - 2013-12-01 00:42 - 03499570 _____ C:\Users\Mark\Downloads\1391496_3823818_P.mp4 2013-11-30 21:40 - 2013-11-10 17:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-11-30 21:40 - 2013-11-10 17:43 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-30 20:37 - 2013-11-30 20:36 - 273457816 _____ C:\Users\Mark\Desktop\mugen 2013-11-30 20-36-19-54.avi 2013-11-30 20:21 - 2013-11-30 19:45 - 00000000 ____D C:\Fraps 2013-11-30 20:07 - 2013-11-30 20:06 - 524389112 _____ C:\Users\Mark\Desktop\mugen 2013-11-30 20-06-27-52.avi 2013-11-30 20:00 - 2013-11-30 20:00 - 67572904 _____ C:\Users\Mark\Desktop\IEXPLORE 2013-11-30 20-00-14-09.avi 2013-11-30 19:45 - 2013-11-30 19:45 - 00000562 _____ C:\Users\Mark\Desktop\Fraps.lnk 2013-11-30 19:45 - 2013-11-30 19:45 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps 2013-11-30 16:19 - 2013-11-30 16:19 - 00001975 _____ C:\Users\Mark\Desktop\patcher.lnk 2013-11-30 15:52 - 2013-11-30 15:52 - 00266288 _____ C:\Windows\Minidump\113013-19156-01.dmp 2013-11-30 15:52 - 2013-11-30 15:52 - 00000000 ____D C:\Windows\Minidump 2013-11-30 15:52 - 2013-11-26 23:32 - 355608758 _____ C:\Windows\MEMORY.DMP 2013-11-30 00:34 - 2013-11-26 19:34 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-11-30 00:09 - 2013-11-30 00:09 - 00002001 _____ C:\Users\Public\Desktop\The Sims Online.lnk 2013-11-30 00:06 - 2013-11-30 00:06 - 00000000 ____D C:\Program Files\Maxis 2013-11-29 21:47 - 2013-11-29 21:47 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Audition Online 2013-11-29 20:13 - 2013-11-29 20:13 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\msvcr71.dll 2013-11-29 20:10 - 2013-11-29 19:41 - 00000000 ____D C:\ProgramData\Solid State Networks 2013-11-29 20:08 - 2013-11-29 20:07 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlorensiaEN 2013-11-29 20:08 - 2013-11-29 20:02 - 00000000 ____D C:\AHA Entertainment 2013-11-29 19:56 - 2013-11-29 19:41 - 1105972422 _____ C:\Users\Mark\Desktop\flo_setup_en_rs_130911.exe 2013-11-29 19:32 - 2013-11-29 19:32 - 01173504 _____ (ProSiebenSat.1 Games) C:\Users\Mark\Downloads\florensia-dlm(1).exe 2013-11-29 19:11 - 2013-11-29 18:27 - 2925954266 _____ (ProSiebenSat1Games) C:\Users\Mark\Desktop\Audition_Setup.exe 2013-11-29 18:26 - 2013-11-29 18:26 - 01173504 _____ (ProSiebenSat.1 Games) C:\Users\Mark\Downloads\florensia-dlm.exe 2013-11-29 18:26 - 2013-11-29 18:26 - 01047960 _____ (Solid State Networks) C:\Users\Mark\Downloads\audition-dlm.exe 2013-11-28 20:36 - 2013-11-28 19:52 - 00000000 ____D C:\Users\Mark\Downloads\The Sims Online Setup Files 2013-11-28 19:51 - 2013-11-28 19:51 - 00126976 _____ C:\Users\Mark\Downloads\Setup The Sims Online.exe 2013-11-26 23:35 - 2013-11-10 14:45 - 00001421 _____ C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-26 23:35 - 2013-11-10 14:22 - 00000000 ____D C:\Windows\Panther 2013-11-26 23:32 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-26 23:20 - 2013-11-26 23:12 - 00011363 _____ C:\Windows\IE11_main.log 2013-11-26 23:15 - 2013-11-26 23:15 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-26 23:15 - 2013-11-26 23:15 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-26 23:15 - 2013-11-26 23:15 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-26 23:15 - 2013-11-26 23:15 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-26 23:15 - 2013-11-26 23:15 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-26 23:15 - 2013-11-26 23:15 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-26 23:15 - 2013-11-26 23:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-26 23:15 - 2013-11-26 23:15 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-26 23:15 - 2013-11-26 23:15 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-11-26 23:13 - 2013-11-26 23:13 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-11-26 23:13 - 2013-11-26 23:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-11-26 23:12 - 2013-11-26 23:12 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-11-26 23:12 - 2013-11-26 23:12 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-11-26 23:12 - 2013-11-26 23:12 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-11-26 23:08 - 2013-11-26 23:00 - 00000000 ____D C:\Users\Mark\Desktop\Die Sims 3 Late Night 2013-11-26 23:02 - 2013-11-26 23:02 - 00002130 _____ C:\Users\Public\Desktop\Die Sims™ 3 Einfach tierisch.lnk 2013-11-26 21:51 - 2013-11-26 21:51 - 00000000 __RHD C:\Users\Mark\AppData\Roaming\SecuROM 2013-11-26 21:47 - 2013-11-26 21:47 - 00000000 ____D C:\ProgramData\EA Core 2013-11-26 21:37 - 2013-11-26 21:37 - 00000000 ____D C:\Program Files (x86)\Microsoft WSE 2013-11-26 20:38 - 2013-11-26 19:36 - 00000000 ____D C:\Users\Mark\AppData\Roaming\Origin 2013-11-26 19:37 - 2013-11-26 19:36 - 00000000 ____D C:\Users\Mark\AppData\Local\Origin 2013-11-26 19:37 - 2013-11-26 19:34 - 00000000 ____D C:\ProgramData\Origin 2013-11-26 19:34 - 2013-11-26 19:34 - 00000979 _____ C:\Users\Public\Desktop\Origin.lnk 2013-11-26 19:34 - 2013-11-12 23:02 - 00000000 ____D C:\Program Files (x86)\Steam 2013-11-26 19:34 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-11-26 19:32 - 2013-11-26 19:31 - 16959688 _____ (Electronic Arts, Inc.) C:\Users\Mark\Downloads\OriginThinSetup_9.2.1.4399.exe 2013-11-26 19:27 - 2013-11-10 17:55 - 00000000 ____D C:\ProgramData\COMODO 2013-11-26 18:54 - 2013-11-26 18:54 - 00000000 ____D C:\ProgramData\VirtuallTek 2013-11-26 18:54 - 2013-11-26 18:54 - 00000000 ____D C:\Program Files (x86)\VirtuallTek 2013-11-26 18:53 - 2013-11-26 18:53 - 01743576 _____ (VirtuallTek Systems ) C:\Users\Mark\Downloads\Fighter Factory Ultimate 2.5 Setup.exe 2013-11-26 18:49 - 2013-11-26 18:49 - 00628696 _____ C:\Users\Mark\Downloads\ffu26.exe 2013-11-26 16:41 - 2013-11-25 19:16 - 00137663 _____ C:\Users\Mark\Downloads\dark-arc-angel,05,12,2012.zip 2013-11-26 12:54 - 2013-12-12 19:52 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-26 11:19 - 2013-12-12 19:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-26 11:18 - 2013-12-12 19:53 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-26 11:11 - 2013-12-12 19:52 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-26 10:48 - 2013-12-12 19:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-26 10:46 - 2013-12-12 19:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-26 10:41 - 2013-12-12 19:52 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-26 10:29 - 2013-12-12 19:53 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-26 10:27 - 2013-12-12 19:52 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-26 10:23 - 2013-12-12 19:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-26 10:21 - 2013-12-12 19:53 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-26 10:18 - 2013-12-12 19:52 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-26 10:18 - 2013-12-12 19:52 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-26 10:16 - 2013-12-12 19:52 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-26 09:57 - 2013-12-12 19:52 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-26 09:38 - 2013-12-12 19:52 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-26 09:38 - 2013-12-12 19:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-26 09:35 - 2013-12-12 19:52 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-26 09:32 - 2013-12-12 19:53 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-26 09:28 - 2013-12-12 19:52 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-26 09:16 - 2013-12-12 19:52 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-26 09:02 - 2013-12-12 19:52 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-26 08:48 - 2013-12-15 00:59 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-26 08:32 - 2013-12-12 19:52 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-26 08:26 - 2013-12-12 19:52 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-26 08:07 - 2013-12-12 19:52 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-26 07:40 - 2013-12-12 19:52 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-26 07:34 - 2013-12-12 19:52 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-26 07:34 - 2013-12-12 19:52 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-26 07:33 - 2013-12-12 19:52 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-26 07:27 - 2013-12-12 19:52 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll Some content of TEMP: ==================== C:\Users\Mark\AppData\Local\Temp\Appnimi ZIP Password Kit.exe C:\Users\Mark\AppData\Local\Temp\app_setup1.exe C:\Users\Mark\AppData\Local\Temp\app_setup2.exe C:\Users\Mark\AppData\Local\Temp\bitool.dll C:\Users\Mark\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\Mark\AppData\Local\Temp\game_patcher_201312180.exe C:\Users\Mark\AppData\Local\Temp\htmlayout.dll C:\Users\Mark\AppData\Local\Temp\Installmanager.exe C:\Users\Mark\AppData\Local\Temp\jna3131863785577991303.dll C:\Users\Mark\AppData\Local\Temp\jna792872623991524100.dll C:\Users\Mark\AppData\Local\Temp\setup.exe C:\Users\Mark\AppData\Local\Temp\tmp2628.exe C:\Users\Mark\AppData\Local\Temp\tmpB2B.exe C:\Users\Mark\AppData\Local\Temp\Uninstall.exe C:\Users\Mark\AppData\Local\Temp\vcredist_x86.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-21 15:28 ==================== End Of Log ============================ --- --- --- [Addition Logfile] Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-12-2013 Ran by Mark at 2013-12-26 13:03:38 Running from C:\Users\Mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SFH9VB6E Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: COMODO Antivirus (Enabled - Up to date) {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: COMODO Antivirus (Enabled - Up to date) {0C2D2636-923D-EE52-2A83-E643204A8275} FW: COMODO Firewall (Enabled) {8F7746F7-FE68-E084-3B6C-7404A51E8FB3} ==================== Installed Programs ====================== 7-Zip 9.20 (x32) Adobe After Effects CC (x32 Version: 12.1) Adobe Creative Cloud (x32 Version: 2.2.1.260) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.152) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) AION Free-to-Play (x32) Audition Online (x32 Version: 1.2.6064) CCleaner (Version: 4.07) Comodo Dragon (x32 Version: 30.0.0.0) COMODO Internet Security Premium (Version: 6.3.32439.2937) Die Sims™ 3 (x32 Version: 1.63.4) Die Sims™ 3 Einfach tierisch (x32 Version: 10.0.96) Die Sims™ 3 Into the Future (x32 Version: 21.0.150) Die Sims™ 3 Late Night (x32 Version: 6.0.81) Die Sims™ 3 Supernatural (x32 Version: 15.0.135) Elsword_DE (x32) Fighter Factory Ultimate (x32 Version: 2.5.22.2009) Flashtool (x32 Version: 0.9.13.0) FlorensiaEN 2.01.01 (x32 Version: 2.01.01) Fraps (remove only) (x32) Gameforge Live 1.9.0 "Legend" (x32 Version: 1.9.0) Garena - Mstar (x32) Garena Plus (x32 Version: 2011) GeekBuddy (Version: 4.10.79) Grand Theft Auto IV v1.0 Eng (x32) Grand Theft Auto San Andreas (x32 Version: 1.00.00001) Hatsune Miku English Vocaloid3 Library (x32 Version: Vocaloid3 Library) Hotspot Shield 3.20 (x32 Version: 3.20) IZArc 4.1.8 (x32 Version: 4.1.8) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Games for Windows - LIVE (x32 Version: 2.0.687.0) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 2.0.687.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft XNA Framework Redistributable 3.0 (x32 Version: 3.0.11010.0) MTA:SA v1.3.4 (x32 Version: v1.3.4) NVIDIA 3D Vision Controller-Treiber 331.65 (Version: 331.65) NVIDIA 3D Vision Treiber 331.65 (Version: 331.65) NVIDIA Grafiktreiber 331.65 (Version: 331.65) NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4) NVIDIA Install Application (Version: 2.1002.140.952) NVIDIA PhysX (x32 Version: 9.13.0725) NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165) NVIDIA Systemsteuerung 331.65 (Version: 331.65) Origin (x32 Version: 9.2.1.4399) PlayReady PC Runtime amd64 (Version: 1.3.0) S4 League_EU (x32 Version: 1.00.0000) Skype™ 6.11 (x32 Version: 6.11.102) Steam (x32 Version: 1.0.0.0) STOnline (x32 Version: 1.0000) STREET FIGHTER IV (x32 Version: 1.00.3013) The Sims Online (x32) Unity Web Player (HKCU Version: ) UxStyle Core Beta (Version: 0.2.1.1) Virtual CD v10 (x32 Version: 10.00.0) ==================== Restore Points ========================= 14-12-2013 23:59:29 Windows Update 15-12-2013 19:25:23 DirectX wurde installiert 20-12-2013 14:05:11 Windows Update 20-12-2013 18:49:37 Installiert The Sims 3 22-12-2013 08:49:37 Gerätetreiber-Paketinstallation: Anchorfree Inc Netzwerkdienst 22-12-2013 08:51:06 Gerätetreiber-Paketinstallation: Anchorfree HSS VPN Adapter Netzwerkadapter 22-12-2013 12:35:05 Installiert Grand Theft Auto San Andreas 25-12-2013 09:11:48 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {06017397-3581-4C02-8719-7B56C695BA4F} - System32\Tasks\RunAsStdUser Task => C:\Users\Mark\AppData\Local\Oxy\Application\oxy.exe Task: {0EC88AA4-C011-4857-B696-2753E4D44B99} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-11-11] (COMODO) Task: {52A3CB36-36F0-411E-92E2-BEA7FFF577D0} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-11-11] (COMODO) Task: {59367FCB-10D6-46B3-B8E7-FCCBF8E12491} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-11-11] (COMODO) Task: {5BACD0FE-820F-44C9-B4A1-38D4D393A649} - System32\Tasks\{0712A47E-0185-4F78-B9A6-EB323942C401} => C:\Users\Mark\Desktop\Sims 4 Setup.exe Task: {62787662-7C63-43C6-8F0D-86EB0DADC42C} - System32\Tasks\{8EC0057F-DC6E-4FF2-BBCE-11561ED52C1A} => C:\Users\Mark\Desktop\Sims 4 Setup.exe Task: {69C81B09-CDDF-4866-B5DE-D10087C8A7C8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd) Task: {B56B739C-5306-4D21-8EF8-341A6C8FBDBA} - System32\Tasks\COMODO\COMODO Welcome {CEB54B45-2B5E-4FF5-9223-6735CD80FE69} => C:\Program Files\COMODO\COMODO Internet Security\cis.exe [2013-11-20] (COMODO) Task: {E216F536-45FD-49D0-B415-8C89868DC064} - System32\Tasks\Abelssoft\CheckDriveBackgroundGuard => C:\Program Files (x86)\CheckDrive\CheckDriveBackgroundGuard.exe Task: {E5D2E4FA-ADCF-45B2-A460-B42BFA2A27FB} - System32\Tasks\AdobeAAMUpdater-1.0-FONON-TECHNOLOG-Mark => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2013-09-25] (Adobe Systems Incorporated) Task: {F9F046D6-200E-4087-97FD-97ABAE7E01E4} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-11-11] (COMODO) ==================== Loaded Modules (whitelisted) ============= 2013-10-16 18:02 - 2013-10-16 18:02 - 03358064 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll 2013-11-27 01:35 - 2013-11-27 01:35 - 00903464 _____ () C:\Program Files (x86)\Hotspot Shield\bin\af_proxy.dll 2013-12-13 20:19 - 2008-08-18 15:08 - 00050688 _____ () C:\Program Files (x86)\Virtual CD v10\System\ogg.dll 2013-12-13 20:19 - 2008-08-18 15:11 - 01237504 _____ () C:\Program Files (x86)\Virtual CD v10\System\vorbis.dll 2013-12-26 11:13 - 2002-12-12 19:38 - 00011264 _____ () C:\Users\Mark\AppData\Local\Temp\is-D17RT.tmp\isxbb.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData:NT AlternateDataStreams: C:\Users\All Users:NT AlternateDataStreams: C:\ProgramData\Anwendungsdaten:NT AlternateDataStreams: C:\ProgramData\Application Data:NT AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT AlternateDataStreams: C:\Users\Mark\Anwendungsdaten:NT AlternateDataStreams: C:\Users\Mark\AppData\Roaming:NT ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: RF receiver Description: RF receiver Class Guid: Manufacturer: Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (12/26/2013 09:58:46 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2013 10:07:58 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/24/2013 07:45:10 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/24/2013 04:19:28 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7a144 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000003db0fd8 ID des fehlerhaften Prozesses: 0x614 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (12/24/2013 01:36:03 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/23/2013 00:23:09 PM) (Source: Application Hang) (User: ) Description: Programm IEXPLORE.EXE, Version 11.0.9600.16428 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2268 Startzeit: 01ceffcf4ce45e12 Endzeit: 469 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: Error: (12/23/2013 00:08:04 PM) (Source: Application Hang) (User: ) Description: Programm IEXPLORE.EXE, Version 11.0.9600.16428 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1f08 Startzeit: 01ceffcf23d66d8e Endzeit: 149 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: Error: (12/23/2013 00:07:16 PM) (Source: Application Hang) (User: ) Description: Programm IEXPLORE.EXE, Version 11.0.9600.16428 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 20a0 Startzeit: 01ceffcdd92f67af Endzeit: 204 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: Error: (12/23/2013 11:04:45 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2013 01:32:30 PM) (Source: Application Hang) (User: ) Description: Programm IEXPLORE.EXE, Version 11.0.9600.16428 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c88 Startzeit: 01ceff10e5b2b00e Endzeit: 0 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: System errors: ============= Error: (12/26/2013 01:04:00 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "Spiele" den Befehl "chkdsk" aus. Error: (12/26/2013 00:55:45 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "Spiele" den Befehl "chkdsk" aus. Error: (12/26/2013 11:39:59 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/26/2013 11:39:59 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/26/2013 11:39:59 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/26/2013 11:39:59 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/26/2013 11:39:59 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/26/2013 11:39:59 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/26/2013 11:39:59 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/26/2013 11:39:59 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Microsoft Office Sessions: ========================= Error: (12/26/2013 09:58:46 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2013 10:07:58 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/24/2013 07:45:10 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/24/2013 04:19:28 PM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce7a144unknown0.0.0.000000000c00000050000000003db0fd861401cf00a47de3b15dC:\Windows\Explorer.EXEunknownc7425fa6-6cae-11e3-93ef-001d922bd3d3 Error: (12/24/2013 01:36:03 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/23/2013 00:23:09 PM) (Source: Application Hang)(User: ) Description: IEXPLORE.EXE11.0.9600.16428226801ceffcf4ce45e12469C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Error: (12/23/2013 00:08:04 PM) (Source: Application Hang)(User: ) Description: IEXPLORE.EXE11.0.9600.164281f0801ceffcf23d66d8e149C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Error: (12/23/2013 00:07:16 PM) (Source: Application Hang)(User: ) Description: IEXPLORE.EXE11.0.9600.1642820a001ceffcdd92f67af204C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Error: (12/23/2013 11:04:45 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2013 01:32:30 PM) (Source: Application Hang)(User: ) Description: IEXPLORE.EXE11.0.9600.16428c8801ceff10e5b2b00e0C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE CodeIntegrity Errors: =================================== Date: 2013-11-12 22:41:33.970 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Mark\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-11-12 22:41:33.932 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Mark\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-11-12 22:41:33.627 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-11-12 22:41:33.588 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 53% Total physical RAM: 3198.18 MB Available physical RAM: 1479.58 MB Total Pagefile: 6394.53 MB Available Pagefile: 3980.61 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:249.07 GB) NTFS Drive d: (GTA4_ENG_DVD2) (CDROM) (Total:3.94 GB) (Free:0 GB) CDFS Drive j: () (Fixed) (Total:78.09 GB) (Free:78.09 GB) FAT32 Drive k: (Spiele) (Fixed) (Total:70.91 GB) (Free:7.75 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 2BAB359D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ======================================================== Disk: 4 (Size: 149 GB) (Disk ID: 540E9773) Partition 1: (Not Active) - (Size=78 GB) - (Type=0B) Partition 2: (Not Active) - (Size=71 GB) - (Type=OF Extended) ==================== End Of Log ============================[/CODE] Mfg Djzeroman p.s Als ich den Thema erstellt hatte hat er sich bereits aufgehangen! Geändert von djzeroman (26.12.2013 um 13:27 Uhr) |
27.12.2013, 10:34 | #4 | |
/// the machine /// TB-Ausbilder | Pc hängt sich auf. hi, So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.12.2013, 16:12 | #5 |
| Pc hängt sich auf. Vielen Vielen Dank für die Hilfe Schrauber! Code:
ATTFilter ComboFix 13-12-26.01 - Mark 27.12.2013 15:50:34.1.2 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3198.1682 [GMT 1:00] ausgeführt von:: c:\users\Mark\Desktop\ComboFix.exe AV: COMODO Antivirus *Disabled/Updated* {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8} FW: COMODO Firewall *Enabled* {8F7746F7-FE68-E084-3B6C-7404A51E8FB3} SP: COMODO Antivirus *Disabled/Updated* {0C2D2636-923D-EE52-2A83-E643204A8275} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\SysWow64\frapsvid.dll . . ((((((((((((((((((((((( Dateien erstellt von 2013-11-27 bis 2013-12-27 )))))))))))))))))))))))))))))) . . 2013-12-27 15:03 . 2013-12-27 15:03 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-12-27 14:41 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5D12CFA8-66A3-44B9-BCE7-713149E8E95C}\mpengine.dll 2013-12-26 12:45 . 2013-12-26 12:45 -------- d-----w- c:\users\Mark\AppData\Local\Rockstar Games 2013-12-26 12:45 . 2013-12-26 12:45 -------- d-sh--w- c:\programdata\SecuROM 2013-12-26 12:00 . 2013-12-26 12:00 -------- d-----w- C:\FRST 2013-12-26 10:12 . 2009-07-09 09:24 24088 ----a-w- c:\windows\system32\drivers\hh10help.sys 2013-12-26 10:09 . 2013-12-26 10:09 -------- d-----w- c:\program files (x86)\VoiceDB 2013-12-23 13:43 . 2013-12-23 13:43 -------- d-----w- C:\VTRoot 2013-12-22 13:04 . 2013-12-22 13:04 98304 ----a-w- c:\windows\SysWow64\CmdLineExt.dll 2013-12-22 13:03 . 2013-12-22 13:04 -------- d---a-w- c:\programdata\MTA San Andreas All 2013-12-22 13:00 . 2013-12-22 13:04 -------- d-----w- c:\program files (x86)\MTA San Andreas 1.3 2013-12-22 12:35 . 2013-12-26 10:14 -------- d-----w- c:\program files (x86)\Rockstar Games 2013-12-22 12:16 . 2013-12-22 12:16 -------- d-----w- c:\users\Mark\AppData\Local\Unity 2013-12-22 08:50 . 2013-12-22 08:50 -------- d-----w- c:\programdata\Hotspot Shield 2013-12-22 08:49 . 2013-11-13 10:49 44744 ----a-w- c:\windows\system32\drivers\hssdrv6.sys 2013-12-22 08:49 . 2013-12-22 08:53 -------- d-----w- c:\program files (x86)\Hotspot Shield 2013-12-22 08:49 . 2013-12-22 08:49 -------- d-----w- c:\users\Mark\AppData\Roaming\Hotspot Shield 2013-12-20 20:42 . 2013-12-20 20:42 -------- d-----w- c:\users\Mark\AppData\Local\Diagnostics 2013-12-20 14:07 . 2013-12-20 14:07 -------- d-----w- c:\program files (x86)\Gameforge4D 2013-12-15 19:23 . 2013-12-15 19:23 -------- d-----w- c:\users\Mark\AppData\Local\Gameforge4d 2013-12-15 19:22 . 2013-12-15 19:23 -------- d-----w- c:\program files (x86)\GameforgeLive 2013-12-15 00:51 . 2013-12-15 00:51 -------- d-----w- c:\program files (x86)\alaplaya 2013-12-15 00:50 . 2013-12-15 00:50 -------- d-----w- c:\program files (x86)\Common Files\InstallShield 2013-12-15 00:01 . 2010-11-21 03:24 257024 ----a-w- c:\windows\system32\taskmgr.exe 2013-12-15 00:01 . 2010-11-21 03:24 257024 ----a-w- c:\windows\system32\stobject.dll 2013-12-15 00:01 . 2009-07-14 01:39 431104 ----a-w- c:\windows\system32\snippingtool.exe 2013-12-15 00:01 . 2010-11-21 03:23 225280 ----a-w- c:\windows\system32\sndvolsso.dll 2013-12-15 00:01 . 2013-07-26 02:24 14172672 ----a-w- c:\windows\system32\shell32.dll 2013-12-15 00:01 . 2010-11-21 03:25 296960 ----a-w- c:\windows\system32\rstrui.exe 2013-12-15 00:01 . 2010-11-21 03:23 1808384 ----a-w- c:\windows\system32\pnidui.dll 2013-12-15 00:01 . 2010-11-21 03:24 898560 ----a-w- c:\windows\system32\oobefldr.dll 2013-12-15 00:01 . 2009-07-14 01:39 193536 ----a-w- c:\windows\system32\notepad.exe 2013-12-15 00:01 . 2010-11-21 03:23 2652160 ----a-w- c:\windows\system32\netshell.dll 2013-12-15 00:01 . 2010-11-21 03:24 143360 ----a-w- c:\windows\system32\mydocs.dll 2013-12-15 00:01 . 2009-07-14 01:39 6676480 ----a-w- c:\windows\system32\mspaint.exe 2013-12-15 00:00 . 2010-11-21 03:24 300032 ----a-w- c:\windows\system32\msconfig.exe 2013-12-14 23:58 . 2011-08-11 11:47 76288 ----a-w- c:\windows\SysWow64\moveex.exe 2013-12-14 23:58 . 2003-08-19 00:44 118845 ----a-w- c:\windows\Flurry.scr 2013-12-14 23:15 . 2013-12-14 23:17 -------- d-----w- c:\programdata\regid.1986-12.com.adobe 2013-12-14 22:42 . 2013-12-14 23:01 -------- d-----w- c:\program files\Adobe 2013-12-14 22:42 . 2013-12-14 23:03 -------- d-----w- c:\program files\Common Files\Adobe 2013-12-14 22:26 . 2013-12-14 22:26 -------- d-----w- c:\program files (x86)\Microsoft XNA 2013-12-14 22:23 . 2013-12-14 22:23 -------- d-----w- c:\users\Mark\AppData\Local\Deployment 2013-12-14 22:23 . 2013-12-14 22:23 -------- d-----w- c:\users\Mark\AppData\Local\Apps 2013-12-14 22:12 . 2013-12-14 23:09 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2013-12-14 21:56 . 2013-12-21 21:35 -------- d-----w- c:\program files (x86)\Common Files\COMODO 2013-12-14 21:56 . 2013-12-14 21:56 -------- d-----w- c:\program files (x86)\CAPCOM 2013-12-14 21:54 . 2013-12-14 21:55 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE 2013-12-14 21:54 . 2013-12-14 21:54 -------- d-----w- c:\windows\SysWow64\xlive 2013-12-14 21:41 . 2013-12-14 21:41 -------- d-----w- c:\users\Mark\AppData\Local\Abelssoft 2013-12-14 11:00 . 2013-12-14 11:00 -------- d-----w- c:\users\Mark\AppData\Local\S4Launcher 2013-12-14 08:56 . 2013-12-14 08:56 -------- d-----w- c:\program files (x86)\Maxis 2013-12-13 19:19 . 2012-12-06 10:09 226080 ----a-w- c:\windows\system32\drivers\vdrv1000.sys 2013-12-13 19:19 . 2009-07-09 09:24 24088 ----a-w- c:\windows\system32\drivers\HH10Help.dat 2013-12-13 19:19 . 2013-12-13 19:20 -------- d-s---w- c:\users\Public\Virtual CDs 2013-12-13 19:19 . 2013-12-13 19:20 -------- d-s---w- c:\users\Public\Virtual CD v10 2013-12-13 19:19 . 2013-12-13 19:20 -------- d-s---w- c:\users\Mark\AppData\Roaming\Virtual CD v10 2013-12-13 19:19 . 2013-12-13 19:19 -------- d-----w- c:\program files (x86)\Virtual CD v10 2013-12-13 19:18 . 2008-06-17 07:22 40464 ----a-w- c:\windows\system32\drivers\vcd10bus.sys 2013-12-13 19:18 . 2013-12-13 19:18 -------- d-----w- c:\users\Mark\AppData\Roaming\InstallShield 2013-12-12 18:52 . 2013-11-26 09:48 66048 ----a-w- c:\windows\system32\iesetup.dll 2013-12-12 15:50 . 2013-10-30 01:24 3155968 ----a-w- c:\windows\system32\win32k.sys 2013-12-08 18:57 . 2013-12-04 00:17 5221784 ----a-w- c:\windows\SysWow64\GameMon.des 2013-12-08 18:56 . 2013-12-08 18:56 -------- d-----w- c:\program files\Common Files\INCA Shared 2013-12-08 18:56 . 2013-12-08 18:56 -------- d-----w- c:\users\Mark\AppData\Roaming\Garena 2013-12-08 18:56 . 2013-12-08 18:56 -------- d-----w- c:\programdata\Garena 2013-12-08 18:20 . 2013-12-20 17:01 -------- d-----w- c:\program files (x86)\Garena Plus 2013-12-08 18:20 . 2013-12-08 18:37 -------- d-----w- c:\program files (x86)\GarenaMstar 2013-12-08 17:12 . 2013-12-08 17:12 -------- d-----w- c:\users\Mark\AppData\Local\Garena 2013-12-01 08:15 . 2013-12-01 08:15 -------- d-----w- c:\users\Mark\.config 2013-12-01 08:15 . 2013-12-01 08:17 -------- d-----w- c:\users\Mark\AppData\Local\Oxy 2013-12-01 08:15 . 2013-12-01 08:15 -------- d-----w- c:\users\Mark\AppData\Local\Chromium 2013-12-01 08:14 . 2013-12-01 12:12 -------- d-----w- c:\users\Mark\AppData\Roaming\Oxy 2013-12-01 07:07 . 2013-12-01 07:07 -------- d-----w- c:\users\Mark\AppData\Local\Appnimi ZIP Password Kit 2013-12-01 07:07 . 2013-12-15 00:59 -------- d-----w- c:\program files (x86)\Appnimi 2013-12-01 02:59 . 2013-12-25 10:18 -------- d-----w- c:\users\Mark\AppData\Roaming\Skype 2013-12-01 02:59 . 2013-12-01 02:59 -------- d-----w- c:\program files (x86)\Common Files\Skype 2013-12-01 02:59 . 2013-12-01 02:59 -------- d-----r- c:\program files (x86)\Skype 2013-12-01 02:59 . 2013-12-25 09:15 -------- d-----w- c:\programdata\Skype 2013-11-30 19:06 . 2013-12-14 23:16 -------- d-----w- c:\users\Mark\AppData\Roaming\NVIDIA 2013-11-30 18:45 . 2013-11-30 19:21 -------- d-----w- C:\Fraps 2013-11-29 23:06 . 2013-11-29 23:06 -------- d-----w- c:\program files\Maxis 2013-11-29 19:20 . 2012-08-30 11:26 503808 ----a-w- c:\windows\SysWow64\msvcp71.dll 2013-11-29 19:13 . 2013-11-29 19:13 348160 ----a-w- c:\windows\system32\msvcr71.dll 2013-11-29 19:02 . 2013-11-29 19:08 -------- d-----w- C:\AHA Entertainment 2013-11-29 18:41 . 2013-11-29 19:10 -------- d-----w- c:\programdata\Solid State Networks 2013-11-29 17:13 . 2013-12-01 05:05 -------- d-----w- c:\program files (x86)\Audition Online 2013-11-28 18:49 . 2013-11-28 18:49 -------- d-----w- c:\users\Mark\AppData\Local\ElevatedDiagnostics . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-14 23:59 . 2013-11-10 16:57 90708896 ----a-w- c:\windows\system32\MRT.exe 2013-12-07 15:57 . 2013-11-26 20:37 447752 ----a-w- c:\windows\SysWow64\vp6vfw.dll 2013-11-30 20:40 . 2013-11-10 16:43 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-11-30 20:40 . 2013-11-10 16:43 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-11-26 22:15 . 2013-11-26 22:15 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-11-26 22:15 . 2013-11-26 22:15 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-11-26 22:15 . 2013-11-26 22:15 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2013-11-26 22:15 . 2013-11-26 22:15 235008 ----a-w- c:\windows\system32\elshyph.dll 2013-11-26 22:15 . 2013-11-26 22:15 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-11-26 22:15 . 2013-11-26 22:15 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2013-11-26 22:15 . 2013-11-26 22:15 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-11-26 22:15 . 2013-11-26 22:15 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-11-26 22:15 . 2013-11-26 22:15 337408 ----a-w- c:\windows\SysWow64\html.iec 2013-11-26 22:15 . 2013-11-26 22:15 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-11-26 22:15 . 2013-11-26 22:15 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-11-26 22:15 . 2013-11-26 22:15 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-11-26 22:15 . 2013-11-26 22:15 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-11-26 22:15 . 2013-11-26 22:15 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2013-11-26 22:15 . 2013-11-26 22:15 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-11-26 22:15 . 2013-11-26 22:15 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-11-26 22:15 . 2013-11-26 22:15 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2013-11-26 22:15 . 2013-11-26 22:15 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-11-26 22:15 . 2013-11-26 22:15 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2013-11-26 22:15 . 2013-11-26 22:15 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2013-11-26 22:15 . 2013-11-26 22:15 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-11-26 22:15 . 2013-11-26 22:15 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-11-26 22:15 . 2013-11-26 22:15 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-11-26 22:15 . 2013-11-26 22:15 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-11-26 22:15 . 2013-11-26 22:15 942592 ----a-w- c:\windows\system32\jsIntl.dll 2013-11-26 22:15 . 2013-11-26 22:15 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-11-26 22:15 . 2013-11-26 22:15 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-11-26 22:15 . 2013-11-26 22:15 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-11-26 22:15 . 2013-11-26 22:15 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-11-26 22:15 . 2013-11-26 22:15 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-11-26 22:15 . 2013-11-26 22:15 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-26 22:15 . 2013-11-26 22:15 247808 ----a-w- c:\windows\system32\msls31.dll 2013-11-26 22:15 . 2013-11-26 22:15 195584 ----a-w- c:\windows\system32\msrating.dll 2013-11-26 22:15 . 2013-11-26 22:15 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2013-11-26 22:15 . 2013-11-26 22:15 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-11-26 22:15 . 2013-11-26 22:15 105984 ----a-w- c:\windows\system32\iesysprep.dll 2013-11-26 22:15 . 2013-11-26 22:15 84992 ----a-w- c:\windows\system32\mshtmled.dll 2013-11-26 22:15 . 2013-11-26 22:15 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2013-11-26 22:15 . 2013-11-26 22:15 81408 ----a-w- c:\windows\system32\icardie.dll 2013-11-26 22:15 . 2013-11-26 22:15 774144 ----a-w- c:\windows\system32\jscript.dll 2013-11-26 22:15 . 2013-11-26 22:15 626176 ----a-w- c:\windows\system32\msfeeds.dll 2013-11-26 22:15 . 2013-11-26 22:15 62464 ----a-w- c:\windows\system32\pngfilt.dll 2013-11-26 22:15 . 2013-11-26 22:15 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-11-26 22:15 . 2013-11-26 22:15 548352 ----a-w- c:\windows\system32\vbscript.dll 2013-11-26 22:15 . 2013-11-26 22:15 48128 ----a-w- c:\windows\system32\imgutil.dll 2013-11-26 22:15 . 2013-11-26 22:15 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2013-11-26 22:15 . 2013-11-26 22:15 413696 ----a-w- c:\windows\system32\html.iec 2013-11-26 22:15 . 2013-11-26 22:15 30208 ----a-w- c:\windows\system32\licmgr10.dll 2013-11-26 22:15 . 2013-11-26 22:15 296960 ----a-w- c:\windows\system32\dxtrans.dll 2013-11-26 22:15 . 2013-11-26 22:15 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2013-11-26 22:15 . 2013-11-26 22:15 243200 ----a-w- c:\windows\system32\webcheck.dll 2013-11-26 22:15 . 2013-11-26 22:15 235520 ----a-w- c:\windows\system32\url.dll 2013-11-26 22:15 . 2013-11-26 22:15 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-11-26 22:15 . 2013-11-26 22:15 147968 ----a-w- c:\windows\system32\occache.dll 2013-11-26 22:15 . 2013-11-26 22:15 143872 ----a-w- c:\windows\system32\wextract.exe 2013-11-26 22:15 . 2013-11-26 22:15 13824 ----a-w- c:\windows\system32\mshta.exe 2013-11-26 22:15 . 2013-11-26 22:15 135680 ----a-w- c:\windows\system32\iepeers.dll 2013-11-26 22:15 . 2013-11-26 22:15 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-11-26 22:15 . 2013-11-26 22:15 101376 ----a-w- c:\windows\system32\inseng.dll 2013-11-26 22:13 . 2013-11-26 22:13 878080 ----a-w- c:\windows\system32\advapi32.dll 2013-11-26 22:13 . 2013-11-26 22:13 859648 ----a-w- c:\windows\system32\tdh.dll 2013-11-26 22:13 . 2013-11-26 22:13 5549504 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-11-26 22:13 . 2013-11-26 22:13 3969472 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-11-26 22:13 . 2013-11-26 22:13 3914176 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-11-26 22:13 . 2013-11-26 22:13 362496 ----a-w- c:\windows\system32\wow64win.dll 2013-11-26 22:13 . 2013-11-26 22:13 243712 ----a-w- c:\windows\system32\wow64.dll 2013-11-26 22:13 . 2013-11-26 22:13 1732032 ----a-w- c:\windows\system32\ntdll.dll 2013-11-26 22:13 . 2013-11-26 22:13 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2013-11-26 22:13 . 2013-11-26 22:13 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2013-11-26 22:13 . 2013-11-26 22:13 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2013-11-26 22:13 . 2013-11-26 22:13 2048 ----a-w- c:\windows\SysWow64\user.exe 2013-11-26 22:13 . 2013-11-26 22:13 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2013-11-26 22:13 . 2013-11-26 22:13 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-11-26 22:13 . 2013-11-26 22:13 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2013-11-26 22:13 . 2013-11-26 22:13 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2013-11-26 22:13 . 2013-11-26 22:13 640512 ----a-w- c:\windows\SysWow64\advapi32.dll 2013-11-26 22:13 . 2013-11-26 22:13 619520 ----a-w- c:\windows\SysWow64\tdh.dll 2013-11-26 22:13 . 2013-11-26 22:13 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll 2013-11-26 22:12 . 2013-11-26 22:12 327168 ----a-w- c:\windows\system32\mswsock.dll 2013-11-26 22:12 . 2013-11-26 22:12 231424 ----a-w- c:\windows\SysWow64\mswsock.dll 2013-11-26 22:12 . 2013-11-26 22:12 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-11-24 12:52 . 2013-11-24 12:52 108336 ----a-w- c:\windows\SysWow64\MSWINSCK.OCX 2013-11-19 02:33 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe 2013-11-14 11:38 . 2013-09-24 10:54 709144 ----a-w- c:\windows\system32\drivers\cmdguard.sys 2013-11-14 11:38 . 2013-09-24 10:53 43216 ----a-w- c:\windows\system32\cmdcsr.dll 2013-11-13 10:51 . 2013-11-13 10:51 42184 ----a-w- c:\windows\system32\drivers\taphss6.sys 2013-11-13 00:07 . 2013-11-10 16:54 57096 ----a-w- c:\windows\system32\certsentry.dll 2013-11-13 00:07 . 2013-11-10 16:54 48392 ----a-w- c:\windows\SysWow64\certsentry.dll 2013-11-12 23:25 . 2013-11-12 23:25 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-11-10 19:05 . 2013-11-10 19:05 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll 2013-11-10 19:05 . 2013-11-10 19:05 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll 2013-11-10 19:05 . 2013-11-10 19:05 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll 2013-11-10 17:30 . 2013-11-10 17:30 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-11-10 17:30 . 2013-11-10 17:30 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-11-10 17:30 . 2013-11-10 17:30 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-11-10 17:30 . 2013-11-10 17:30 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GarenaPlus"="c:\program files (x86)\Garena Plus\GarenaMessenger.exe" [2013-12-13 9890608] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "VC10Player"="c:\program files (x86)\Virtual CD v10\System\VC10Play.exe" [2013-11-19 409456] "Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-11-05 2237328] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Start GeekBuddy.lnk - c:\program files\COMODO\GeekBuddy\launcher.exe "unit_manager.exe" [2013-12-13 48848] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer4"=wdmaud.drv . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 GeekBuddyRSP;GeekBuddyRSP Server;c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe;c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [x] R2 MMCSS;Multimediaklassenplaner;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 adp94xx;adp94xx;c:\windows\system32\drivers\adp94xx.sys;c:\windows\SYSNATIVE\drivers\adp94xx.sys [x] R3 adpahci;adpahci;c:\windows\system32\drivers\adpahci.sys;c:\windows\SYSNATIVE\drivers\adpahci.sys [x] R3 arcsas;arcsas;c:\windows\system32\drivers\arcsas.sys;c:\windows\SYSNATIVE\drivers\arcsas.sys [x] R3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver;c:\windows\system32\drivers\BrFiltLo.sys;c:\windows\SYSNATIVE\drivers\BrFiltLo.sys [x] R3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver;c:\windows\system32\drivers\BrFiltUp.sys;c:\windows\SYSNATIVE\drivers\BrFiltUp.sys [x] R3 Brserid;Brother MFC Serial Port Interface Driver (WDM);c:\windows\System32\Drivers\Brserid.sys;c:\windows\SYSNATIVE\Drivers\Brserid.sys [x] R3 BrSerWdm;Brother WDM Serial driver;c:\windows\System32\Drivers\BrSerWdm.sys;c:\windows\SYSNATIVE\Drivers\BrSerWdm.sys [x] R3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\System32\Drivers\BrUsbMdm.sys;c:\windows\SYSNATIVE\Drivers\BrUsbMdm.sys [x] R3 BrUsbSer;Brother MFC USB Serial WDM Driver;c:\windows\System32\Drivers\BrUsbSer.sys;c:\windows\SYSNATIVE\Drivers\BrUsbSer.sys [x] R3 CertPropSvc;Zertifikatverteilung;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 circlass;Consumer IR Devices;c:\windows\system32\drivers\circlass.sys;c:\windows\SYSNATIVE\drivers\circlass.sys [x] R3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 e1yexpress;Intel(R) Gigabit-Netzwerkverbindungstreiber;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x] R3 ehRecvr;Windows Media Center-Empfängerdienst;c:\windows\ehome\ehRecvr.exe;c:\windows\ehome\ehRecvr.exe [x] R3 ehSched;Windows Media Center-Planerdienst;c:\windows\ehome\ehsched.exe;c:\windows\ehome\ehsched.exe [x] R3 elxstor;elxstor;c:\windows\system32\drivers\elxstor.sys;c:\windows\SYSNATIVE\drivers\elxstor.sys [x] R3 FairplayKD;FairplayKD;c:\programdata\MTA San Andreas All\Common\temp\FairplayKD.sys;c:\programdata\MTA San Andreas All\Common\temp\FairplayKD.sys [x] R3 Fax;Fax;c:\windows\system32\fxssvc.exe;c:\windows\SYSNATIVE\fxssvc.exe [x] R3 Filetrace;Filetrace;c:\windows\system32\drivers\filetrace.sys;c:\windows\SYSNATIVE\drivers\filetrace.sys [x] R3 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms;c:\windows\system32\drivers\gagp30kx.sys;c:\windows\SYSNATIVE\drivers\gagp30kx.sys [x] R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x] R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x] R3 ggsemc;SEMC USB Flash Driver;c:\windows\system32\DRIVERS\ggsemc.sys;c:\windows\SYSNATIVE\DRIVERS\ggsemc.sys [x] R3 HH10Help.sys;HH10Help.sys;c:\windows\system32\drivers\HH10Help.sys;c:\windows\SYSNATIVE\drivers\HH10Help.sys [x] R3 HidBth;Microsoft Bluetooth HID Miniport;c:\windows\system32\drivers\hidbth.sys;c:\windows\SYSNATIVE\drivers\hidbth.sys [x] R3 HidIr;Microsoft Infrared HID Driver;c:\windows\system32\drivers\hidir.sys;c:\windows\SYSNATIVE\drivers\hidir.sys [x] R3 HssTrayService;Hotspot Shield Tray Service;c:\program files (x86)\Hotspot Shield\bin\HssTrayService.EXE;c:\program files (x86)\Hotspot Shield\bin\HssTrayService.EXE [x] R3 iaStorV;iaStorV;c:\windows\system32\drivers\iaStorV.sys;c:\windows\SYSNATIVE\drivers\iaStorV.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 IPBusEnum;PnP-X-IP-Busenumerator;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 IPMIDRV;IPMIDRV;c:\windows\system32\drivers\IPMIDrv.sys;c:\windows\SYSNATIVE\drivers\IPMIDrv.sys [x] R3 iScsiPrt;iScsiPort Driver;c:\windows\system32\drivers\msiscsi.sys;c:\windows\SYSNATIVE\drivers\msiscsi.sys [x] R3 KtmRm;KtmRm für Distributed Transaction Coordinator;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 lltdsvc;Verbindungsschicht-Topologieerkennungs-Zuordnungsprogramm;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 LSI_FC;LSI_FC;c:\windows\system32\drivers\lsi_fc.sys;c:\windows\SYSNATIVE\drivers\lsi_fc.sys [x] R3 LSI_SAS;LSI_SAS;c:\windows\system32\drivers\lsi_sas.sys;c:\windows\SYSNATIVE\drivers\lsi_sas.sys [x] R3 LSI_SCSI;LSI_SCSI;c:\windows\system32\drivers\lsi_scsi.sys;c:\windows\SYSNATIVE\drivers\lsi_scsi.sys [x] R3 megasas;megasas;c:\windows\system32\drivers\megasas.sys;c:\windows\SYSNATIVE\drivers\megasas.sys [x] R3 mpio;mpio;c:\windows\system32\drivers\mpio.sys;c:\windows\SYSNATIVE\drivers\mpio.sys [x] R3 msdsm;msdsm;c:\windows\system32\drivers\msdsm.sys;c:\windows\SYSNATIVE\drivers\msdsm.sys [x] R3 MSiSCSI;Microsoft iSCSI-Initiator-Dienst;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 MsRPC;MsRPC; [x] R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series - Adaptertreiber für Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x] R3 nfrd960;nfrd960;c:\windows\system32\drivers\nfrd960.sys;c:\windows\SYSNATIVE\drivers\nfrd960.sys [x] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x] R3 nvstor;nvstor;c:\windows\system32\drivers\nvstor.sys;c:\windows\SYSNATIVE\drivers\nvstor.sys [x] R3 pla;Leistungsprotokolle und -warnungen;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 PNRPAutoReg;PNRP-Computernamenveröffentlichungs-Dienst;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 ql2300;ql2300;c:\windows\system32\drivers\ql2300.sys;c:\windows\SYSNATIVE\drivers\ql2300.sys [x] R3 ql40xx;ql40xx;c:\windows\system32\drivers\ql40xx.sys;c:\windows\SYSNATIVE\drivers\ql40xx.sys [x] R3 QWAVE;Verbessertes Windows-Audio/Video-Streaming;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 QWAVEdrv;QWAVE-Treiber;c:\windows\system32\drivers\qwavedrv.sys;c:\windows\SYSNATIVE\drivers\qwavedrv.sys [x] R3 sbp2port;sbp2port;c:\windows\system32\drivers\sbp2port.sys;c:\windows\SYSNATIVE\drivers\sbp2port.sys [x] R3 SCPolicySvc;Richtlinie zum Entfernen der Scmartcard;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 sermouse;Serial Mouse Driver;c:\windows\system32\drivers\sermouse.sys;c:\windows\SYSNATIVE\drivers\sermouse.sys [x] R3 SessionEnv;Konfiguration für Remotedesktops;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 sffdisk;SFF Storage Class Driver;c:\windows\system32\drivers\sffdisk.sys;c:\windows\SYSNATIVE\drivers\sffdisk.sys [x] R3 sffp_mmc;SFF Storage Protocol Driver for MMC;c:\windows\system32\drivers\sffp_mmc.sys;c:\windows\SYSNATIVE\drivers\sffp_mmc.sys [x] R3 sffp_sd;SFF Storage Protocol Driver for SDBus;c:\windows\system32\drivers\sffp_sd.sys;c:\windows\SYSNATIVE\drivers\sffp_sd.sys [x] R3 SiSRaid2;SiSRaid2;c:\windows\system32\drivers\SiSRaid2.sys;c:\windows\SYSNATIVE\drivers\SiSRaid2.sys [x] R3 SiSRaid4;SiSRaid4;c:\windows\system32\drivers\sisraid4.sys;c:\windows\SYSNATIVE\drivers\sisraid4.sys [x] R3 Smb;Nachrichtenorientiertes TCP/IP- und TCP/IPv6-Protokoll (SMB-Sitzung);c:\windows\system32\DRIVERS\smb.sys;c:\windows\SYSNATIVE\DRIVERS\smb.sys [x] R3 SNMPTRAP;SNMP-Trap;c:\windows\System32\snmptrap.exe;c:\windows\SYSNATIVE\snmptrap.exe [x] R3 TabletInputService;Tablet PC-Eingabedienst;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 TBS;TPM-Basisdienste;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 TCPIP6;Microsoft IPv6 Protocol Driver;c:\windows\system32\DRIVERS\tcpip.sys;c:\windows\SYSNATIVE\DRIVERS\tcpip.sys [x] R3 THREADORDER;Server für Threadsortierung;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 TrustedInstaller;Windows Modules Installer;c:\windows\servicing\TrustedInstaller.exe;c:\windows\servicing\TrustedInstaller.exe [x] R3 tssecsrv;Remote Desktop Services Security Filter Driver;c:\windows\system32\DRIVERS\tssecsrv.sys;c:\windows\SYSNATIVE\DRIVERS\tssecsrv.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 uagp35;Microsoft AGPv3.5 Filter;c:\windows\system32\drivers\uagp35.sys;c:\windows\SYSNATIVE\drivers\uagp35.sys [x] R3 UI0Detect;Erkennung interaktiver Dienste;c:\windows\system32\UI0Detect.exe;c:\windows\SYSNATIVE\UI0Detect.exe [x] R3 uliagpkx;Uli AGP Bus Filter;c:\windows\system32\drivers\uliagpkx.sys;c:\windows\SYSNATIVE\drivers\uliagpkx.sys [x] R3 UmRdpService;Anschlussumleitung für Remotedesktopdienst im Benutzermodus;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 usbcir;eHome-Infrarotempfänger (USBCIR);c:\windows\system32\drivers\usbcir.sys;c:\windows\SYSNATIVE\drivers\usbcir.sys [x] R3 vsmraid;vsmraid;c:\windows\system32\drivers\vsmraid.sys;c:\windows\SYSNATIVE\drivers\vsmraid.sys [x] R3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\system32\drivers\wacompen.sys;c:\windows\SYSNATIVE\drivers\wacompen.sys [x] R3 wbengine;Blockebenen-Sicherungsmodul;c:\windows\system32\wbengine.exe;c:\windows\SYSNATIVE\wbengine.exe [x] R3 wcncsvc;Windows-Sofortverbindung - Konfigurationsregistrierungsstelle;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 WcsPlugInService;Windows-Farbsystem;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 Wd;Wd;c:\windows\system32\drivers\wd.sys;c:\windows\SYSNATIVE\drivers\wd.sys [x] R3 Wecsvc;Windows-Ereignissammlung;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 wercplsupport;Unterstützung in der Systemsteuerung unter Lösungen für Probleme;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 WerSvc;Windows-Fehlerberichterstattungsdienst;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 WinRM;Windows-Remoteverwaltung (WS-Verwaltung);c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 WinUSB;Sony Ericsson sa0102 ADB Interface;c:\windows\system32\DRIVERS\WinUSB.sys;c:\windows\SYSNATIVE\DRIVERS\WinUSB.sys [x] R3 WmiAcpi;Microsoft Windows Management Interface for ACPI;c:\windows\system32\drivers\wmiacpi.sys;c:\windows\SYSNATIVE\drivers\wmiacpi.sys [x] R3 WPCSvc;Parental Controls;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R3 X6va008;X6va008;c:\users\Mark\AppData\Local\Temp\0084394.tmp;c:\users\Mark\AppData\Local\Temp\0084394.tmp [x] R4 Mcx2Svc;Media Center Extender-Dienst;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] R4 NetMsmqActivator;Net.Msmq Listener Adapter;c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [x] R4 NetPipeActivator;Net.Pipe Listener Adapter;c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [x] R4 NetTcpActivator;Net.Tcp Listener Adapter;c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [x] S0 CLFS;Gemeinsames Protokoll (CLFS);c:\windows\System32\CLFS.sys;c:\windows\SYSNATIVE\CLFS.sys [x] S0 FileInfo;File Information FS MiniFilter;c:\windows\system32\drivers\fileinfo.sys;c:\windows\SYSNATIVE\drivers\fileinfo.sys [x] S0 fvevol;Filtertreiber der Bitlocker-Laufwerkverschlüsselung;c:\windows\System32\DRIVERS\fvevol.sys;c:\windows\SYSNATIVE\DRIVERS\fvevol.sys [x] S0 msahci;msahci;c:\windows\system32\drivers\msahci.sys;c:\windows\SYSNATIVE\drivers\msahci.sys [x] S0 msisadrv;msisadrv;c:\windows\system32\drivers\msisadrv.sys;c:\windows\SYSNATIVE\drivers\msisadrv.sys [x] S0 spldr;Security Processor Loader Driver; [x] S0 volmgr;Treiber für Volume-Manager;c:\windows\system32\drivers\volmgr.sys;c:\windows\SYSNATIVE\drivers\volmgr.sys [x] S0 volmgrx;Dynamischer Volume-Manager;c:\windows\System32\drivers\volmgrx.sys;c:\windows\SYSNATIVE\drivers\volmgrx.sys [x] S0 Wdf01000;Kernel Mode Driver Frameworks service;c:\windows\system32\drivers\Wdf01000.sys;c:\windows\SYSNATIVE\drivers\Wdf01000.sys [x] S1 blbdrive;blbdrive;c:\windows\system32\DRIVERS\blbdrive.sys;c:\windows\SYSNATIVE\DRIVERS\blbdrive.sys [x] S1 CFRMD;CFRMD;c:\windows\system32\DRIVERS\CFRMD.sys;c:\windows\SYSNATIVE\DRIVERS\CFRMD.sys [x] S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys;c:\windows\SYSNATIVE\DRIVERS\cmderd.sys [x] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys;c:\windows\SYSNATIVE\DRIVERS\cmdguard.sys [x] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys;c:\windows\SYSNATIVE\DRIVERS\cmdhlp.sys [x] S1 CSC;Treiber für Offlinedateien;c:\windows\system32\drivers\csc.sys;c:\windows\SYSNATIVE\drivers\csc.sys [x] S1 DfsC;DFS Namespace Client Driver;c:\windows\system32\Drivers\dfsc.sys;c:\windows\SYSNATIVE\Drivers\dfsc.sys [x] S1 HMD;COMODO livePCsupport Hardware Monitor Driver;c:\windows\system32\DRIVERS\hmd.sys;c:\windows\SYSNATIVE\DRIVERS\hmd.sys [x] S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys;c:\windows\SYSNATIVE\DRIVERS\hssdrv6.sys [x] S1 inspect;COMODO Internet Security Firewall Driver;c:\windows\system32\DRIVERS\inspect.sys;c:\windows\SYSNATIVE\DRIVERS\inspect.sys [x] S1 nsiproxy;NSI proxy service driver.;c:\windows\system32\drivers\nsiproxy.sys;c:\windows\SYSNATIVE\drivers\nsiproxy.sys [x] S1 RDPENCDD;RDP Encoder Mirror Driver;c:\windows\system32\drivers\rdpencdd.sys;c:\windows\SYSNATIVE\drivers\rdpencdd.sys [x] S1 tdx;NetIO-Legacy-TDI-Supporttreiber;c:\windows\system32\DRIVERS\tdx.sys;c:\windows\SYSNATIVE\DRIVERS\tdx.sys [x] S1 vdrv1000;vdrv1000;c:\windows\system32\DRIVERS\vdrv1000.sys;c:\windows\SYSNATIVE\DRIVERS\vdrv1000.sys [x] S1 VWiFiFlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys;c:\windows\SYSNATIVE\DRIVERS\vwififlt.sys [x] S1 Wanarpv6;Remotezugriff-IPv6-ARP-Treiber;c:\windows\system32\DRIVERS\wanarp.sys;c:\windows\SYSNATIVE\DRIVERS\wanarp.sys [x] S2 AudioEndpointBuilder;Windows-Audio-Endpunkterstellung;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 BFE;Basisfiltermodul;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 CLPSLauncher;COMODO LPS Launcher;c:\program files (x86)\Common Files\COMODO\launcher_service.exe;c:\program files (x86)\Common Files\COMODO\launcher_service.exe [x] S2 CscService;Offlinedateien;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 DPS;Diagnoserichtliniendienst;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 DragonUpdater;COMODO Dragon Update Service;c:\program files (x86)\Comodo\Dragon\dragon_updater.exe;c:\program files (x86)\Comodo\Dragon\dragon_updater.exe [x] S2 FontCache;Windows-Dienst für Schriftartencache;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 gpsvc;Gruppenrichtlinienclient;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 hshld;Hotspot Shield Service;c:\program files (x86)\Hotspot Shield\bin\cmw_srv.exe;c:\program files (x86)\Hotspot Shield\bin\cmw_srv.exe [x] S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [x] S2 IKEEXT;IKE- und AuthIP IPsec-Schlüsselerstellungsmodule;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 iphlpsvc;IP-Hilfsdienst;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver;c:\windows\system32\DRIVERS\lltdio.sys;c:\windows\SYSNATIVE\DRIVERS\lltdio.sys [x] S2 luafv;UAC-Dateivirtualisierung;c:\windows\system32\drivers\luafv.sys;c:\windows\SYSNATIVE\drivers\luafv.sys [x] S2 MpsSvc;Windows-Firewall;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 NlaSvc;NLA (Network Location Awareness);c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 nsi;Netzwerkspeicher-Schnittstellendienst;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 nvsvc;NVIDIA Display Driver Service;c:\windows\system32\nvvsvc.exe;c:\windows\SYSNATIVE\nvvsvc.exe [x] S2 PcaSvc;Programmkompatibilitäts-Assistent-Dienst;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 PEAUTH;PEAUTH;c:\windows\system32\drivers\peauth.sys;c:\windows\SYSNATIVE\drivers\peauth.sys [x] S2 ProfSvc;Benutzerprofildienst;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 rspndr;Link-Layer Topology Discovery Responder;c:\windows\system32\DRIVERS\rspndr.sys;c:\windows\SYSNATIVE\DRIVERS\rspndr.sys [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 SysMain;Superfetch;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 tcpipreg;TCP/IP Registry Compatibility;c:\windows\system32\drivers\tcpipreg.sys;c:\windows\SYSNATIVE\drivers\tcpipreg.sys [x] S2 UnsignedThemes;Unsigned Themes;c:\windows\UnsignedThemesSvc.exe;c:\windows\UnsignedThemesSvc.exe [x] S2 uxpatch;uxpatch;c:\windows\system32\drivers\uxpatch.sys;c:\windows\SYSNATIVE\drivers\uxpatch.sys [x] S2 UxSms;Sitzungs-Manager für Desktopfenster-Manager;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 VC10SecS;Virtual CD v10 Management Service;c:\program files (x86)\Virtual CD v10\System\VC10SecS.exe;c:\program files (x86)\Virtual CD v10\System\VC10SecS.exe [x] S2 WinDefend;Windows Defender;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 Wlansvc;Automatische WLAN-Konfiguration;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 WSearch;Windows Search;c:\windows\system32\SearchIndexer.exe;c:\windows\SYSNATIVE\SearchIndexer.exe [x] S3 Appinfo;Anwendungsinformationen;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S3 bowser;Browsersupporttreiber;c:\windows\system32\DRIVERS\bowser.sys;c:\windows\SYSNATIVE\DRIVERS\bowser.sys [x] S3 DXGKrnl;LDDM Graphics Subsystem;c:\windows\System32\drivers\dxgkrnl.sys;c:\windows\SYSNATIVE\drivers\dxgkrnl.sys [x] S3 e1express;Intel(R) PRO/1000 PCI Express-Netzwerkverbindungstreiber;c:\windows\system32\DRIVERS\e1e6032e.sys;c:\windows\SYSNATIVE\DRIVERS\e1e6032e.sys [x] S3 fdPHost;Funktionssuchanbieter-Host;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S3 FDResPub;Funktionssuche-Ressourcenveröffentlichung;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S3 HdAudAddService;Microsoft 1.1 UAA-Funktionstreiber für High Definition Audio-Dienst;c:\windows\system32\drivers\HdAudio.sys;c:\windows\SYSNATIVE\drivers\HdAudio.sys [x] S3 KeyIso;CNG-Schlüsselisolation;c:\windows\system32\lsass.exe;c:\windows\SYSNATIVE\lsass.exe [x] S3 monitor;Microsoft Monitor-Klassenfunktionstreiber-Dienst;c:\windows\system32\DRIVERS\monitor.sys;c:\windows\SYSNATIVE\DRIVERS\monitor.sys [x] S3 mpsdrv;Windows-Firewallautorisierungstreiber;c:\windows\system32\drivers\mpsdrv.sys;c:\windows\SYSNATIVE\drivers\mpsdrv.sys [x] S3 mrxsmb10;SMB 1.x-Miniredirector;c:\windows\system32\DRIVERS\mrxsmb10.sys;c:\windows\SYSNATIVE\DRIVERS\mrxsmb10.sys [x] S3 mrxsmb20;SMB 2.0-Miniredirector;c:\windows\system32\DRIVERS\mrxsmb20.sys;c:\windows\SYSNATIVE\DRIVERS\mrxsmb20.sys [x] S3 NativeWifiP;NativeWiFi Filter;c:\windows\system32\DRIVERS\nwifi.sys;c:\windows\SYSNATIVE\DRIVERS\nwifi.sys [x] S3 netprofm;Netzwerklistendienst;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S3 netr28ux;RT2870-USB-Drahtlos-LAN-Kartentreiber für Vista;c:\windows\system32\DRIVERS\netr28ux.sys;c:\windows\SYSNATIVE\DRIVERS\netr28ux.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys;c:\windows\SYSNATIVE\drivers\nvhda64v.sys [x] S3 nvlddmkm;nvlddmkm;c:\windows\system32\DRIVERS\nvlddmkm.sys;c:\windows\SYSNATIVE\DRIVERS\nvlddmkm.sys [x] S3 p2pimsvc;Peernetzwerkidentitäts-Manager;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S3 p2psvc;Peernetzwerk-Gruppenzuordnung;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S3 Ph3xIB64;Philips 713x Inbox PCI TV Card;c:\windows\system32\DRIVERS\Ph3xIB64.sys;c:\windows\SYSNATIVE\DRIVERS\Ph3xIB64.sys [x] S3 PNRPsvc;Peer Name Resolution-Protokoll;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S3 SDRSVC;Windows-Sicherung;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S3 srv2;Server-SMB-Treiber 2.xxx;c:\windows\system32\DRIVERS\srv2.sys;c:\windows\SYSNATIVE\DRIVERS\srv2.sys [x] S3 srvnet;srvnet;c:\windows\system32\DRIVERS\srvnet.sys;c:\windows\SYSNATIVE\DRIVERS\srvnet.sys [x] S3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x] S3 tunnel;Microsoft-Tunnelminiport-Adaptertreiber;c:\windows\system32\DRIVERS\tunnel.sys;c:\windows\SYSNATIVE\DRIVERS\tunnel.sys [x] S3 umbus;UMBusenumerator-Treiber;c:\windows\system32\DRIVERS\umbus.sys;c:\windows\SYSNATIVE\DRIVERS\umbus.sys [x] S3 vcd10bus;Virtual CD v10 Bus Enumerator;c:\windows\system32\DRIVERS\vcd10bus.sys;c:\windows\SYSNATIVE\DRIVERS\vcd10bus.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys;c:\windows\SYSNATIVE\DRIVERS\vwifimp.sys [x] S3 WdiServiceHost;Diagnosediensthost;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S3 WdiSystemHost;Diagnosesystemhost;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S3 WPDBusEnum;Enumeratordienst für tragbare Geräte;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] . . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cistray.exe" [2013-11-11 1612504] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-09-25 472984] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.windowsxlive.net mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{0A61855D-CFA3-484E-937F-E05CEE114134}: NameServer = 156.154.70.25,156.154.71.25 TCP: Interfaces\{81177033-799C-433F-8DBD-546E82E9D0F2}: NameServer = 156.154.70.25,156.154.71.25 DPF: {9A9825C1-8A41-4FDA-BC07-7F5FBECC02E6} - hxxp://item.koramgame.com/st/login/activex/KoramGameStarter.cab . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKLM-Run-tvncontrol - c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start HKLM-Run-COMODO - c:\program files\COMODO\COMODO livePCsupport\CLPSLA.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va008] "ImagePath"="\??\c:\users\Mark\AppData\Local\Temp\0084394.tmp" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vdrv1000] "ImagePath"="system32\DRIVERS\vdrv1000.sys" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:9e,2b,59,a9,52,de,ce,01 . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8d,f7,37,f3,92,ee,7b,40,b4,8f,c6,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8d,f7,37,f3,92,ee,7b,40,b4,8f,c6,\ . [HKEY_USERS\S-1-5-21-808128076-1346819028-3149336073-1000\Software\SecuROM\License information*] "datasecu"=hex:14,01,41,77,3c,6a,be,a7,b5,d5,2d,bd,e6,00,43,1b,60,c7,64,c8,9f, 79,77,97,09,31,76,ee,b7,c0,d3,a6,f1,eb,e8,e3,c8,3a,96,49,94,dd,db,5e,73,70,\ "rkeysecu"=hex:cc,52,2c,8f,04,79,90,17,8c,c4,49,5f,9c,1a,f2,a4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-12-27 16:09:48 ComboFix-quarantined-files.txt 2013-12-27 15:09 . Vor Suchlauf: 11 Verzeichnis(se), 243.721.678.848 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 243.783.159.808 Bytes frei . - - End Of File - - 59FCBA7768874A650055FC0F10AB6263 A36C5E4F47E84449FF07ED3517B43A31 Edit: Ich kann jetzt nicht mehr auf Facebook Google und ihrgendwas Runterladen. was soll das? Geändert von djzeroman (27.12.2013 um 16:31 Uhr) |
28.12.2013, 12:45 | #6 |
/// the machine /// TB-Ausbilder | Pc hängt sich auf. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Pc hängt sich auf. |
Themen zu Pc hängt sich auf. |
beschäftigt, bildschirm, bildschirm schwarz, fehler, fenster, firefox, friert, gleichzeitig, grafikkarte, großes, hängt, interne, internet, karte, leute, modus, neu, nichts, pc hängt, pc hängt sich auf, problem, rum, schwarz, schwarzschirm, spiel, spiele, system, trojaner |