|
Plagegeister aller Art und deren Bekämpfung: PC bereinigen und schneller machenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
30.12.2013, 16:54 | #1 |
| PC bereinigen und schneller machen Hallo Leute, mein PC ist zur Zeit sehr langsam. Ich hatte einen defekten Windows Installer und musste eine Reparaturinstallation alias Inplace-Upgrade durchführen. Der Installer funktioniert nun wieder, nur leider ist mein Rechner seitdem sehr langsam. Außerdem habe ich höchstwahrscheinlich einige Dateien/Programme auf dem Rechner, die kein Mensch braucht und würde daher gerne den PC bereinigen. Habe mir bereits FRST 64-Bit runtergeladen und einen Scan durchgeführt. Die Logdateien stehen unten. Hoffe, es kann mir jemand helfen. LG Tweety FRST.txt FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-12-2013 01 Ran by Jacky (administrator) on JACKY-PC on 30-12-2013 16:43:06 Running from C:\Users\Jacky\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe () C:\Windows\System32\dmwu.exe (RealNetworks, Inc.) C:\Program Files (x86)\Online Games Manager\ogmservice.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (GamersFirst) C:\Users\Jacky\AppData\Local\GamersFirst\LIVE!\Live.exe (Windows Net) C:\Users\Jacky\AppData\Roaming\Windows Net Data\net.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe () C:\Windows\SysWOW64\jmdp\stij.exe () C:\Windows\System32\ljkb\stij.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_170_ActiveX.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup HKLM-x32\...\Run: [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start HKLM-x32\...\Run: [RoxWatchTray] - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [221184 2006-10-27] (Sonic Solutions) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-13] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Policies\Explorer: [DisallowRun] 1 AppInit_DLLs: [ ] () AppInit_DLLs-x32: [ ] () Startup: C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk ShortcutTarget: GamersFirst LIVE!.lnk -> C:\Users\Jacky\AppData\Local\GamersFirst\LIVE!\Live.exe (GamersFirst) Startup: C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Jacky\AppData\Roaming\Windows Net Data\net.exe (Windows Net) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184962 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x27FEC7DD7524CE01 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184962 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184962 URLSearchHook: HKCU - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184963&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184963&type=default&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=362&systemid=406&v=a9396-116&apn_uid=4138502541114806&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184963&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184963&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=362&systemid=406&v=a9396-116&apn_uid=4138502541114806&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10039&barid={0F0CAE4C-B87A-11E2-A126-8C89A599A6F8} SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_uid=4138502541114806&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=120519&babsrc=SP_ss&mntrId=56B78C89A599A6F8 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_uid=4138502541114806&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/?a=6PR8dQeNuD&loc=skw&search={searchTerms} SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={0F0CAE4C-B87A-11E2-A126-8C89A599A6F8}&crg=3.1010000.10039&st=23 BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Search-Results Toolbar - {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll No File BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: No Name - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM-x32 - Search-Results Toolbar - {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll No File Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default FF user.js: detected! => C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\user.js FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\dokotoolbar.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\iminent.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\MyStart Search.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\Search_Results.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\SweetIM Search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\qvo6.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Amazon-Icon - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\amazon-icon@giga.de FF Extension: pricealarm - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM FF Extension: dokotoolbar.com - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\ffxtlbr@dokotoolbar.com FF Extension: Spartipps von SparPilot.com - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\sparpilot@sparpilot.com FF Extension: ReloadEvery - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi FF Extension: New Tab - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{C4A4F5A0-4B89-4392-AFAC-D58010E349AF}.xpi FF Extension: BonanzaDeals - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}.xpi FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR Extension: (Price Alarm) - C:\Users\Jacky\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [ieadcoanfjloocmfafkebdnfefmohngj] - C:\Program Files (x86)\BonanzaDeals\BonanzaDeals.crx CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Jacky\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1833776 2013-12-29] () R2 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [559552 2013-08-08] (RealNetworks, Inc.) ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-09-07] () R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-10-10] (Kaspersky Lab ZAO) S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-19] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-04-24] (Kaspersky Lab ZAO) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-09-07] () S1 RxFilter; C:\Windows\SysWow64\DRIVERS\RxFilter.sys [58880 2006-10-27] (Sonic Solutions) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-30 16:43 - 2013-12-30 16:43 - 00022432 _____ C:\Users\Jacky\Desktop\FRST.txt 2013-12-30 16:42 - 2013-12-30 16:42 - 00000000 ____D C:\FRST 2013-12-30 16:40 - 2013-12-30 16:41 - 01931302 _____ (Farbar) C:\Users\Jacky\Desktop\FRST64.exe 2013-12-30 13:21 - 2013-12-30 13:22 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele Dirk 2013-12-30 13:21 - 2013-12-30 13:22 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele 2013-12-30 09:45 - 2013-12-30 09:45 - 00000000 ____D C:\Windows\PCHEALTH 2013-12-30 09:45 - 2010-02-23 09:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe 2013-12-30 09:44 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2013-12-30 09:44 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2013-12-30 09:44 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2013-12-30 09:44 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2013-12-30 09:44 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2013-12-30 09:43 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2013-12-30 09:43 - 2012-03-01 07:38 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-12-30 09:43 - 2012-03-01 07:33 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-30 09:43 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2013-12-30 09:43 - 2012-03-01 06:37 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-12-30 09:43 - 2012-03-01 06:33 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-30 09:43 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2013-12-30 09:35 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-12-30 09:35 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-12-30 09:35 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-12-30 09:35 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-12-30 09:35 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-12-30 09:35 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2013-12-30 09:35 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2013-12-30 09:34 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-12-30 09:15 - 2011-11-19 15:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2013-12-30 09:15 - 2011-11-19 15:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2013-12-30 05:16 - 2013-12-29 21:19 - 00000000 ____D C:\Windows\Panther 2013-12-30 05:15 - 2013-12-30 05:15 - 00262144 _____ C:\Windows\system32\config\userdiff 2013-12-30 04:55 - 2013-12-29 21:03 - 00000000 ___HD C:\$WINDOWS.~Q 2013-12-30 04:48 - 2013-12-30 04:51 - 00000000 ___HD C:\$INPLACE.~TR 2013-12-29 23:36 - 2013-12-29 23:36 - 00000000 ____D C:\Program Files\Windows XP Mode 2013-12-29 23:25 - 2013-12-29 23:35 - 486678800 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsXPMode_de-de.exe 2013-12-29 23:23 - 2013-12-29 23:23 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(4).exe 2013-12-29 23:11 - 2013-12-30 12:10 - 00000000 ___RD C:\Users\Jacky\Virtual Machines 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\th-TH 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ro-RO 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\he-IL 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ar-SA 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Program Files (x86)\Windows Virtual PC 2013-12-29 23:01 - 2010-11-20 14:34 - 00360832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcvmm.sys 2013-12-29 23:01 - 2010-11-20 14:34 - 00194944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpchbus.sys 2013-12-29 23:01 - 2010-11-20 14:27 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\vpchbuspipe.dll 2013-12-29 23:01 - 2010-11-20 14:25 - 04514816 _____ (Microsoft Corporation) C:\Windows\system32\vpc.exe 2013-12-29 23:01 - 2010-11-20 14:25 - 02264064 _____ (Microsoft Corporation) C:\Windows\system32\VPCWizard.exe 2013-12-29 23:01 - 2010-11-20 14:25 - 01369600 _____ (Microsoft Corporation) C:\Windows\system32\VPCSettings.exe 2013-12-29 23:01 - 2010-11-20 12:37 - 01210368 _____ (Microsoft Corporation) C:\Windows\system32\VMWindow.exe 2013-12-29 23:01 - 2010-11-20 12:37 - 00936448 _____ (Microsoft Corporation) C:\Windows\system32\vmsal.exe 2013-12-29 23:01 - 2010-11-20 12:35 - 00562176 _____ (Microsoft Corporation) C:\Windows\system32\VMCPropertyHandler.dll 2013-12-29 23:01 - 2010-11-20 12:35 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcusb.sys 2013-12-29 23:01 - 2010-11-20 12:35 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcnfltr.sys 2013-12-29 23:01 - 2010-11-20 11:52 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vmsal.exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(3).exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(2).exe 2013-12-29 21:36 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2013-12-29 21:36 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2013-12-29 21:36 - 2012-02-17 05:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2013-12-29 21:36 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2013-12-29 21:33 - 2013-12-29 21:33 - 09566298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-12-29 21:24 - 2013-12-29 21:24 - 00125128 _____ C:\Users\Jacky\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-29 21:22 - 2013-12-29 21:22 - 00001413 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-12-29 21:21 - 2013-12-29 21:22 - 00001447 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-29 21:21 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-12-29 21:21 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-12-29 21:21 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-12-29 21:21 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-12-29 21:20 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-12-29 21:20 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-12-29 21:20 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-12-29 21:19 - 2013-12-29 21:19 - 00000020 ___SH C:\Users\Jacky\ntuser.ini 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-12-29 21:16 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-12-29 21:16 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-12-29 21:13 - 2013-12-30 15:34 - 01964127 _____ C:\Windows\WindowsUpdate.log 2013-12-29 20:59 - 2013-12-29 20:59 - 00022960 _____ C:\Windows\system32\emptyregdb.dat 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-12-29 20:31 - 2013-12-29 23:11 - 00000000 ____D C:\Users\Jacky 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Vorlagen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Startmenü 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Netzwerkumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Lokale Einstellungen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Eigene Dateien 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Druckumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Musik 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Bilder 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Verlauf 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Anwendungsdaten 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Anwendungsdaten 2013-12-29 20:31 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:31 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:30 - 2013-12-29 20:30 - 00001355 _____ C:\Windows\TSSysprep.log 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-12-29 19:25 - 2013-12-29 21:03 - 00006155 _____ C:\Windows\comsetup.log 2013-12-29 18:57 - 2013-12-29 19:04 - 00013897 _____ C:\Windows\diagwrn.xml 2013-12-29 18:57 - 2013-12-29 19:04 - 00001890 _____ C:\Windows\diagerr.xml 2013-12-29 16:17 - 2013-12-29 20:42 - 00000000 ____D C:\Windows\SysWOW64\jmdp 2013-12-29 16:17 - 2013-12-29 20:42 - 00000000 ____D C:\Windows\system32\ljkb 2013-12-29 16:17 - 2013-12-29 20:42 - 00000000 ____D C:\Windows\pss 2013-12-29 15:37 - 2013-12-30 16:37 - 00000290 _____ C:\Windows\Tasks\Bonanza.job 2013-12-29 15:37 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Bonanza 2013-12-29 15:37 - 2013-12-29 15:37 - 00003226 _____ C:\Windows\System32\Tasks\Bonanza 2013-12-29 13:36 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.technic 2013-12-29 13:36 - 2013-12-29 13:36 - 02304092 _____ () C:\Users\Jacky\Downloads\TechnicLauncher.exe 2013-12-29 10:15 - 2013-12-29 10:15 - 02014840 _____ (DriverBoost) C:\Users\Jacky\Downloads\DriverBoostPro_Setup.exe 2013-12-29 10:12 - 2013-12-29 10:12 - 08054042 _____ C:\Users\Jacky\Downloads\windowsinstaller45(1).zip 2013-12-28 21:42 - 2013-12-28 21:44 - 63443792 _____ C:\Users\Jacky\Downloads\thegameoflifedownload.exe 2013-12-26 21:59 - 2013-12-26 22:00 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-12-26 20:37 - 2013-12-26 20:37 - 00401784 _____ (Softonic ) C:\Users\Jacky\Downloads\SoftonicDownloader_fuer_windows-installer-clean-up.exe 2013-12-26 19:39 - 2013-12-26 19:39 - 02585872 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsInstaller-KB893803-v2-x86.exe 2013-12-26 11:19 - 2013-12-29 20:36 - 00000000 ____D C:\Program Files (x86)\directx 2013-12-26 11:19 - 2013-12-26 11:19 - 00000278 _____ C:\Windows\Directx.log 2013-12-25 21:07 - 2013-12-29 20:41 - 00000000 ____D C:\ProgramData\Windows Genuine Advantage 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck.exe 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(1).exe 2013-12-25 20:59 - 2013-12-25 20:59 - 02311827 _____ C:\Users\Jacky\Downloads\sdl3ewin.zip 2013-12-25 20:57 - 2013-12-25 20:57 - 00397154 _____ C:\Users\Jacky\Downloads\SpieldesLebensWin.zip 2013-12-25 20:53 - 2013-12-25 20:53 - 00002890 _____ C:\Windows\System32\Tasks\{E03E12C0-F94B-4CA6-A09A-515468D6FAA3} 2013-12-25 20:46 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Windows Net Data 2013-12-25 20:46 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp3f96eefeb2049202da2178bd45059162 2013-12-25 20:45 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\Downloads\Spiel-des-Lebens 2013-12-25 20:45 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\ChromeExtensions 2013-12-25 20:45 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp6ec2be2b619d18ef522057d14578d2f7 2013-12-25 20:45 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp52da00fd457103be90f4c5f287980f49 2013-12-25 20:45 - 2013-12-25 20:45 - 00943872 _____ C:\Users\Jacky\Downloads\Spiel-des-Lebens-Setup.exe 2013-12-25 20:41 - 2013-12-25 20:41 - 00003018 _____ C:\Windows\System32\Tasks\{476505DD-F30E-4FF4-8920-CB14D92EB605} 2013-12-25 20:29 - 2013-12-25 20:29 - 00003018 _____ C:\Windows\System32\Tasks\{01014E7C-EF80-4994-94A4-7882BBE1FC4D} 2013-12-25 20:03 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Zylom 2013-12-25 20:03 - 2013-12-29 09:40 - 00000000 ____D C:\Users\Jacky\AppData\Local\Zylom Games 2013-12-25 16:26 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Das Spiel des Lebens 2013-12-25 16:26 - 2013-12-29 20:36 - 00000000 ____D C:\Program Files (x86)\Das Spiel des Lebens 2013-12-25 16:22 - 2013-12-25 16:22 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p200715036_s2_l2.exe 2013-12-25 16:19 - 2013-12-25 16:19 - 00002890 _____ C:\Windows\System32\Tasks\{D5C4E481-AC90-46F2-A2E0-FC0AF1374D57} 2013-12-21 13:39 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Realore_Whiterra Roads Of Rome 3 2013-12-20 10:03 - 2013-12-29 20:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-15 11:33 - 2013-12-29 20:41 - 00000000 ____D C:\ProgramData\Sony 2013-12-15 11:33 - 2013-12-29 20:39 - 00000000 ____D C:\Program Files (x86)\Sony 2013-12-15 11:33 - 2013-12-15 11:36 - 00181280 _____ C:\Windows\DPINST.LOG 2013-12-15 11:33 - 2013-12-15 11:33 - 00002106 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2013-12-12 00:27 - 2013-11-26 11:18 - 00004096 ____N (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-12 00:27 - 2013-11-26 10:46 - 00048640 ____N (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-12 00:27 - 2013-11-26 10:18 - 00111616 ____N (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-12 00:27 - 2013-11-26 10:16 - 00708608 ____N (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-12 00:27 - 2013-11-26 09:35 - 05769216 ____N (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 00:27 - 2013-11-26 09:28 - 00553472 ____N (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-12 00:27 - 2013-11-26 09:16 - 04243968 ____N (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-30 19:51 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Das Koenigreich der Kobolde 2013-11-30 19:51 - 2013-12-29 20:35 - 00000000 ____D C:\Program Files (x86)\Awakening - Das Koenigreich der Kobolde 2013-11-30 19:40 - 2013-11-30 19:40 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p132398476_s2_l2(1).exe 2013-11-30 19:36 - 2013-11-30 19:36 - 00003150 _____ C:\Windows\System32\Tasks\{D9FF8CB0-8D45-4811-B5EE-E5A392CEF7CF} ==================== One Month Modified Files and Folders ======= 2013-12-30 16:43 - 2013-12-30 16:43 - 00022432 _____ C:\Users\Jacky\Desktop\FRST.txt 2013-12-30 16:42 - 2013-12-30 16:42 - 00000000 ____D C:\FRST 2013-12-30 16:41 - 2013-12-30 16:40 - 01931302 _____ (Farbar) C:\Users\Jacky\Desktop\FRST64.exe 2013-12-30 16:37 - 2013-12-29 15:37 - 00000290 _____ C:\Windows\Tasks\Bonanza.job 2013-12-30 15:46 - 2013-03-20 18:27 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-30 15:44 - 2013-05-22 16:18 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-30 15:34 - 2013-12-29 21:13 - 01964127 _____ C:\Windows\WindowsUpdate.log 2013-12-30 14:43 - 2013-03-18 20:52 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-12-30 13:33 - 2009-07-14 05:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-30 13:33 - 2009-07-14 05:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-30 13:26 - 2013-05-22 16:18 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-30 13:25 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-30 13:25 - 2009-07-14 05:51 - 00581851 _____ C:\Windows\setupact.log 2013-12-30 13:22 - 2013-12-30 13:21 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele Dirk 2013-12-30 13:22 - 2013-12-30 13:21 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele 2013-12-30 13:22 - 2013-03-18 20:55 - 00000000 ___RD C:\Users\Jacky\Desktop\Jacky 2013-12-30 13:20 - 2013-08-25 09:18 - 00000000 ____D C:\Users\Jacky\Desktop\Die Sims 3 (Download) 2013-12-30 13:20 - 2013-07-29 18:31 - 00000000 ____D C:\Users\Jacky\Desktop\BigFish 2013-12-30 13:18 - 2013-05-22 16:18 - 00000000 ____D C:\Program Files (x86)\Google 2013-12-30 12:10 - 2013-12-29 23:11 - 00000000 ___RD C:\Users\Jacky\Virtual Machines 2013-12-30 12:06 - 2010-11-21 04:47 - 00015340 _____ C:\Windows\PFRO.log 2013-12-30 10:11 - 2013-03-19 18:33 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-30 09:54 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2013-12-30 09:54 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sl-SI 2013-12-30 09:45 - 2013-12-30 09:45 - 00000000 ____D C:\Windows\PCHEALTH 2013-12-30 08:59 - 2013-10-28 15:50 - 00000000 ____D C:\Program Files (x86)\Steam 2013-12-30 05:16 - 2009-07-14 06:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2013-12-30 05:16 - 2009-07-14 06:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2013-12-30 05:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\oobe 2013-12-30 05:15 - 2013-12-30 05:15 - 00262144 _____ C:\Windows\system32\config\userdiff 2013-12-30 04:51 - 2013-12-30 04:48 - 00000000 ___HD C:\$INPLACE.~TR 2013-12-29 23:36 - 2013-12-29 23:36 - 00000000 ____D C:\Program Files\Windows XP Mode 2013-12-29 23:35 - 2013-12-29 23:25 - 486678800 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsXPMode_de-de.exe 2013-12-29 23:23 - 2013-12-29 23:23 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(4).exe 2013-12-29 23:15 - 2011-05-16 16:16 - 00646378 _____ C:\Windows\system32\perfh01F.dat 2013-12-29 23:15 - 2011-05-16 16:16 - 00137204 _____ C:\Windows\system32\perfc01F.dat 2013-12-29 23:15 - 2011-05-16 16:03 - 00716756 _____ C:\Windows\system32\prfh0816.dat 2013-12-29 23:15 - 2011-05-16 16:03 - 00150122 _____ C:\Windows\system32\prfc0816.dat 2013-12-29 23:15 - 2011-05-16 15:55 - 00727012 _____ C:\Windows\system32\perfh015.dat 2013-12-29 23:15 - 2011-05-16 15:55 - 00151786 _____ C:\Windows\system32\perfc015.dat 2013-12-29 23:15 - 2011-05-16 15:47 - 00729558 _____ C:\Windows\system32\perfh013.dat 2013-12-29 23:15 - 2011-05-16 15:47 - 00149498 _____ C:\Windows\system32\perfc013.dat 2013-12-29 23:15 - 2011-05-16 15:39 - 00727436 _____ C:\Windows\system32\perfh010.dat 2013-12-29 23:15 - 2011-05-16 15:39 - 00143600 _____ C:\Windows\system32\perfc010.dat 2013-12-29 23:15 - 2011-05-16 15:31 - 00670640 _____ C:\Windows\system32\perfh00E.dat 2013-12-29 23:15 - 2011-05-16 15:31 - 00166482 _____ C:\Windows\system32\perfc00E.dat 2013-12-29 23:15 - 2011-05-16 15:25 - 00732362 _____ C:\Windows\system32\perfh00C.dat 2013-12-29 23:15 - 2011-05-16 15:25 - 00146270 _____ C:\Windows\system32\perfc00C.dat 2013-12-29 23:15 - 2011-05-16 15:17 - 00731974 _____ C:\Windows\system32\perfh00A.dat 2013-12-29 23:15 - 2011-05-16 15:17 - 00154536 _____ C:\Windows\system32\perfc00A.dat 2013-12-29 23:15 - 2011-05-16 15:11 - 00591216 _____ C:\Windows\system32\perfh008.dat 2013-12-29 23:15 - 2011-05-16 15:11 - 00106810 _____ C:\Windows\system32\perfc008.dat 2013-12-29 23:15 - 2011-05-16 15:04 - 00698006 _____ C:\Windows\system32\perfh007.dat 2013-12-29 23:15 - 2011-05-16 15:04 - 00148062 _____ C:\Windows\system32\perfc007.dat 2013-12-29 23:15 - 2011-05-16 14:58 - 00498524 _____ C:\Windows\system32\perfh006.dat 2013-12-29 23:15 - 2011-05-16 14:58 - 00095894 _____ C:\Windows\system32\perfc006.dat 2013-12-29 23:15 - 2009-07-14 06:13 - 09772048 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-29 23:11 - 2013-12-29 20:31 - 00000000 ____D C:\Users\Jacky 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\th-TH 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ro-RO 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\he-IL 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ar-SA 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Program Files (x86)\Windows Virtual PC 2013-12-29 23:06 - 2011-05-16 16:15 - 00000000 ____D C:\Windows\system32\Drivers\tr-TR 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\th-TH 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\ro-RO 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\he-IL 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\ar-SA 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\th-TH 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ro-RO 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\he-IL 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ar-SA 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(3).exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(2).exe 2013-12-29 21:33 - 2013-12-29 21:33 - 09566298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-12-29 21:24 - 2013-12-29 21:24 - 00125128 _____ C:\Users\Jacky\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-29 21:22 - 2013-12-29 21:22 - 00001413 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-12-29 21:22 - 2013-12-29 21:21 - 00001447 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-29 21:22 - 2013-03-18 19:15 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-29 21:22 - 2013-03-18 19:15 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-12-29 21:22 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-29 21:19 - 2013-12-30 05:16 - 00000000 ____D C:\Windows\Panther 2013-12-29 21:19 - 2013-12-29 21:19 - 00000020 ___SH C:\Users\Jacky\ntuser.ini 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-12-29 21:19 - 2012-02-04 14:06 - 00000000 __SHD C:\Recovery 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Recovery 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT 2013-12-29 21:18 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-29 21:16 - 2009-07-14 05:51 - 00000261 _____ C:\Windows\setuperr.log 2013-12-29 21:14 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\restore 2013-12-29 21:03 - 2013-12-30 04:55 - 00000000 ___HD C:\$WINDOWS.~Q 2013-12-29 21:03 - 2013-12-29 19:25 - 00006155 _____ C:\Windows\comsetup.log 2013-12-29 21:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration 2013-12-29 20:59 - 2013-12-29 20:59 - 00022960 _____ C:\Windows\system32\emptyregdb.dat 2013-12-29 20:55 - 2009-07-14 05:45 - 00468632 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-29 20:53 - 2013-04-26 19:01 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-12-29 20:53 - 2009-07-14 05:46 - 00005157 _____ C:\Windows\DtcInstall.log 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:51 - 2013-12-25 20:46 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Windows Net Data 2013-12-29 20:51 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\Downloads\Spiel-des-Lebens 2013-12-29 20:51 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\ChromeExtensions 2013-12-29 20:51 - 2013-12-25 20:03 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Zylom 2013-12-29 20:51 - 2013-12-25 16:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Das Spiel des Lebens 2013-12-29 20:51 - 2013-12-21 13:39 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Realore_Whiterra Roads Of Rome 3 2013-12-29 20:51 - 2013-11-30 19:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Das Koenigreich der Kobolde 2013-12-29 20:51 - 2013-11-14 19:31 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals 2013-12-29 20:51 - 2013-11-03 10:16 - 00000000 ____D C:\Users\Jacky\Downloads\Konto 2013-12-29 20:51 - 2013-10-29 13:53 - 00000000 ____D C:\Users\Jacky\Documents\My Games 2013-12-29 20:51 - 2013-10-21 10:08 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\PlayFirst 2013-12-29 20:51 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Systweak 2013-12-29 20:51 - 2013-09-28 16:13 - 00000000 ____D C:\Users\Jacky\Downloads\ActiveSync 2013-12-29 20:51 - 2013-09-28 15:40 - 00000000 ____D C:\Users\Jacky\Documents\FalkData 2013-12-29 20:51 - 2013-09-22 19:21 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\PlayFavoriteGames 2013-12-29 20:51 - 2013-08-25 12:53 - 00000000 __RHD C:\Users\Jacky\AppData\Roaming\SecuROM 2013-12-29 20:51 - 2013-08-25 12:52 - 00000000 ____D C:\Users\Jacky\Documents\Electronic Arts 2013-12-29 20:51 - 2013-08-25 12:25 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Origin 2013-12-29 20:51 - 2013-07-29 19:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roads of Rome III 2013-12-29 20:51 - 2013-07-29 19:08 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Christmas Stories - Nussknacker Sammleredition 2013-12-29 20:51 - 2013-07-29 18:45 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Schloss ohne Traeume 2013-12-29 20:51 - 2013-07-29 18:42 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening 2 - Der Mondenwald 2013-12-29 20:51 - 2013-07-29 18:36 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\9 - The Dark Side Sammleredition 2013-12-29 20:51 - 2013-07-15 14:12 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1 Moment of Time - Silentville 2013-12-29 20:51 - 2013-05-25 17:01 - 00000000 ____D C:\Users\Jacky\Documents\BlackMirror2 2013-12-29 20:51 - 2013-05-25 17:01 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\ProtectDisc 2013-12-29 20:51 - 2013-05-09 09:13 - 00000000 ____D C:\Users\Jacky\Documents\My Cheat Tables 2013-12-29 20:51 - 2013-05-09 08:43 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Ubisoft 2013-12-29 20:51 - 2013-05-06 19:37 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\OpenCandy 2013-12-29 20:51 - 2013-05-04 09:25 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2013-12-29 20:51 - 2013-04-26 18:46 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2013-12-29 20:51 - 2013-04-06 15:59 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Roxio 2013-12-29 20:51 - 2013-03-20 20:24 - 00000000 ____D C:\Users\Jacky\Documents\Euro Truck Simulator 2 2013-12-29 20:51 - 2013-03-20 19:31 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mystery of the Ancients - Der Fluch des Schwarzen Wassers Sammleredition 2013-12-29 20:51 - 2013-03-20 19:05 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Party 2013-12-29 20:51 - 2013-03-20 17:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Nero 2013-12-29 20:51 - 2013-03-19 20:06 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Das Himmelsschloss Sammleredition 2013-12-29 20:51 - 2013-03-19 19:59 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\WinRAR 2013-12-29 20:51 - 2013-03-19 19:58 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-12-29 20:51 - 2013-03-19 18:45 - 00000000 ____D C:\Users\Jacky\Documents\DVDFab 2013-12-29 20:51 - 2013-03-18 20:21 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Mozilla 2013-12-29 20:50 - 2013-12-29 15:37 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Bonanza 2013-12-29 20:50 - 2013-12-29 13:36 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.technic 2013-12-29 20:50 - 2013-12-25 20:46 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp3f96eefeb2049202da2178bd45059162 2013-12-29 20:50 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp6ec2be2b619d18ef522057d14578d2f7 2013-12-29 20:50 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp52da00fd457103be90f4c5f287980f49 2013-12-29 20:50 - 2013-10-29 13:56 - 00000000 ____D C:\Users\Jacky\AppData\Local\Skyrim 2013-12-29 20:50 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\LavFilters 2013-12-29 20:50 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\CDXReader 2013-12-29 20:50 - 2013-10-19 13:15 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\DigitalSite 2013-12-29 20:50 - 2013-10-18 14:32 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Elephant Games 2013-12-29 20:50 - 2013-10-17 19:30 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\AlawarEntertainment 2013-12-29 20:50 - 2013-09-16 16:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Artifex Mundi 2013-12-29 20:50 - 2013-08-25 12:25 - 00000000 ____D C:\Users\Jacky\AppData\Local\Origin 2013-12-29 20:50 - 2013-07-19 14:15 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\2monkeys 2013-12-29 20:50 - 2013-06-01 16:23 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\cerasus.media 2013-12-29 20:50 - 2013-05-09 09:03 - 00000000 ____D C:\Users\Jacky\AppData\Local\Ubisoft Game Launcher 2013-12-29 20:50 - 2013-05-07 14:14 - 00000000 ____D C:\Users\Jacky\AppData\Local\PunkBuster 2013-12-29 20:50 - 2013-04-09 18:38 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Apple Computer 2013-12-29 20:50 - 2013-04-06 16:06 - 00000000 ____D C:\Users\Jacky\AppData\Local\Power2Go8 2013-12-29 20:50 - 2013-04-01 14:41 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\HP 2013-12-29 20:50 - 2013-03-24 19:15 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Babylon 2013-12-29 20:50 - 2013-03-21 20:04 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.minecraft 2013-12-29 20:50 - 2013-03-20 19:05 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\cef-cache 2013-12-29 20:50 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Macromedia 2013-12-29 20:50 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Adobe 2013-12-29 20:50 - 2013-03-20 17:52 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\CyberLink 2013-12-29 20:50 - 2013-03-20 16:40 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Boomzap 2013-12-29 20:50 - 2013-03-19 18:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\ATI 2013-12-29 20:50 - 2013-03-18 20:21 - 00000000 ____D C:\Users\Jacky\AppData\Local\Mozilla 2013-12-29 20:50 - 2013-03-18 19:15 - 00000000 ____D C:\Users\Jacky\AppData\Local\VirtualStore 2013-12-29 20:49 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Local\BonanzaDealsLive 2013-12-29 20:49 - 2013-07-15 14:00 - 00000000 ____D C:\Users\Jacky\AppData\Local\Big Fish 2013-12-29 20:49 - 2013-05-22 16:18 - 00000000 ____D C:\Users\Jacky\AppData\Local\Google 2013-12-29 20:49 - 2013-05-04 09:30 - 00000000 ____D C:\Users\Jacky\AppData\Local\GamersFirst LIVE! 2013-12-29 20:49 - 2013-05-04 09:25 - 00000000 ____D C:\Users\Jacky\AppData\Local\GamersFirst 2013-12-29 20:49 - 2013-04-09 18:38 - 00000000 ____D C:\Users\Jacky\AppData\Local\Apple Computer 2013-12-29 20:49 - 2013-04-09 18:37 - 00000000 ____D C:\Users\Jacky\AppData\Local\Apple 2013-12-29 20:49 - 2013-04-01 14:35 - 00000000 ____D C:\Users\Jacky\AppData\Local\HP 2013-12-29 20:49 - 2013-04-01 14:13 - 00000000 ____D C:\Users\Jacky\AppData\Local\Adobe 2013-12-29 20:49 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Local\Macromedia 2013-12-29 20:49 - 2013-03-19 18:26 - 00000000 ____D C:\Users\Jacky\AppData\Local\ATI 2013-12-29 20:42 - 2013-12-29 16:17 - 00000000 ____D C:\Windows\SysWOW64\jmdp 2013-12-29 20:42 - 2013-12-29 16:17 - 00000000 ____D C:\Windows\system32\ljkb 2013-12-29 20:42 - 2013-12-29 16:17 - 00000000 ____D C:\Windows\pss 2013-12-29 20:42 - 2013-09-28 14:51 - 00000000 ____D C:\Windows\WindowsMobile 2013-12-29 20:42 - 2013-05-09 08:28 - 00000000 ____D C:\Windows\SysWOW64\WNLT 2013-12-29 20:42 - 2013-05-09 08:28 - 00000000 ____D C:\Windows\SysWOW64\ARFC 2013-12-29 20:42 - 2013-04-01 14:33 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-12-29 20:42 - 2013-03-20 18:27 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-12-29 20:42 - 2013-03-20 18:27 - 00000000 ____D C:\Windows\system32\Macromed 2013-12-29 20:42 - 2011-04-12 09:28 - 00000000 ____D C:\Windows\ShellNew 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-29 20:41 - 2013-12-25 21:07 - 00000000 ____D C:\ProgramData\Windows Genuine Advantage 2013-12-29 20:41 - 2013-12-15 11:33 - 00000000 ____D C:\ProgramData\Sony 2013-12-29 20:41 - 2013-11-15 15:30 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2013-12-29 20:41 - 2013-11-14 19:32 - 00000000 ____D C:\ProgramData\Systweak 2013-12-29 20:41 - 2013-10-21 10:08 - 00000000 ____D C:\ProgramData\PlayFirst 2013-12-29 20:41 - 2013-08-25 12:24 - 00000000 ____D C:\ProgramData\Origin 2013-12-29 20:41 - 2013-07-23 07:43 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-12-29 20:41 - 2013-05-26 08:50 - 00000000 ____D C:\ProgramData\Trymedia 2013-12-29 20:41 - 2013-05-09 09:02 - 00000000 ____D C:\ProgramData\Solidshield 2013-12-29 20:41 - 2013-05-09 08:29 - 00000000 ____D C:\ProgramData\SweetIM 2013-12-29 20:41 - 2013-05-06 22:33 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-29 20:41 - 2013-04-06 15:58 - 00000000 ____D C:\ProgramData\Sonic 2013-12-29 20:41 - 2013-04-06 15:57 - 00000000 ____D C:\ProgramData\Roxio 2013-12-29 20:41 - 2013-04-01 14:41 - 00000000 ____D C:\ProgramData\WEBREG 2013-12-29 20:41 - 2013-03-20 18:31 - 00000000 ____D C:\ProgramData\Sun 2013-12-29 20:41 - 2013-03-20 18:13 - 00000000 ____D C:\ProgramData\vsosdk 2013-12-29 20:41 - 2013-03-20 17:52 - 00000000 ____D C:\Users\Public\CyberLink 2013-12-29 20:41 - 2013-03-20 17:24 - 00000000 ____D C:\ProgramData\Nero 2013-12-29 20:41 - 2013-03-18 20:52 - 00000000 ____D C:\Windows\ELAMBKUP 2013-12-29 20:41 - 2013-03-18 20:21 - 00000000 ____D C:\ProgramData\Mozilla 2013-12-29 20:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports 2013-12-29 20:40 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\Xvid 2013-12-29 20:40 - 2013-10-23 13:06 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-12-29 20:40 - 2013-10-19 13:16 - 00000000 ____D C:\ProgramData\DivX 2013-12-29 20:40 - 2013-10-19 13:16 - 00000000 ____D C:\ProgramData\BonanzaDealsLive 2013-12-29 20:40 - 2013-10-18 14:32 - 00000000 ____D C:\ProgramData\Elephant Games 2013-12-29 20:40 - 2013-08-25 13:06 - 00000000 ____D C:\ProgramData\EA Core 2013-12-29 20:40 - 2013-08-25 12:24 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-12-29 20:40 - 2013-07-29 18:10 - 00000000 ____D C:\ProgramData\Big Fish 2013-12-29 20:40 - 2013-05-26 08:58 - 00000000 ____D C:\ProgramData\GameHouse 2013-12-29 20:40 - 2013-05-09 08:29 - 00000000 ____D C:\Program Files (x86)\SweetIM 2013-12-29 20:40 - 2013-05-09 08:22 - 00000000 ____D C:\Program Files (x86)\Ubisoft 2013-12-29 20:40 - 2013-04-11 17:54 - 00000000 ____D C:\ProgramData\McAfee 2013-12-29 20:40 - 2013-04-09 18:38 - 00000000 ____D C:\ProgramData\Apple Computer 2013-12-29 20:40 - 2013-04-09 18:36 - 00000000 ____D C:\ProgramData\Apple 2013-12-29 20:40 - 2013-04-06 15:59 - 00000000 ____D C:\ProgramData\InstallShield 2013-12-29 20:40 - 2013-04-01 14:33 - 00000000 ____D C:\ProgramData\HP Product Assistant 2013-12-29 20:40 - 2013-04-01 14:29 - 00000000 ____D C:\ProgramData\HP 2013-12-29 20:40 - 2013-03-27 07:08 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2013-12-29 20:40 - 2013-03-20 18:26 - 00000000 ____D C:\ProgramData\Adobe 2013-12-29 20:40 - 2013-03-20 17:51 - 00000000 ____D C:\ProgramData\CyberLink 2013-12-29 20:40 - 2013-03-20 17:48 - 00000000 ____D C:\ProgramData\install_clap 2013-12-29 20:40 - 2013-03-19 18:45 - 00000000 ____D C:\ProgramData\dvdfab 2013-12-29 20:40 - 2013-03-19 18:26 - 00000000 ____D C:\ProgramData\ATI 2013-12-29 20:39 - 2013-12-15 11:33 - 00000000 ____D C:\Program Files (x86)\Sony 2013-12-29 20:39 - 2013-08-25 12:41 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-12-29 20:39 - 2013-08-25 12:24 - 00000000 ____D C:\Program Files (x86)\Origin 2013-12-29 20:39 - 2013-07-29 19:16 - 00000000 ____D C:\Program Files (x86)\Roads of Rome III 2013-12-29 20:39 - 2013-05-26 08:50 - 00000000 ____D C:\Program Files (x86)\Online Games Manager 2013-12-29 20:39 - 2013-05-26 08:49 - 00000000 ____D C:\Program Files (x86)\RealArcade 2013-12-29 20:39 - 2013-05-06 22:25 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-12-29 20:39 - 2013-04-06 15:57 - 00000000 ____D C:\Program Files (x86)\Roxio 2013-12-29 20:39 - 2013-03-20 19:31 - 00000000 ____D C:\Program Files (x86)\Mystery of the Ancients - Der Fluch des Schwarzen Wassers Sammleredition 2013-12-29 20:39 - 2013-03-20 17:25 - 00000000 ____D C:\Program Files (x86)\Nero 2013-12-29 20:39 - 2013-03-18 20:14 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-12-29 20:38 - 2013-12-20 10:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-29 20:38 - 2013-10-22 19:21 - 00000000 ____D C:\Program Files (x86)\Java 2013-12-29 20:38 - 2013-10-19 13:18 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-12-29 20:38 - 2013-10-19 13:16 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-12-29 20:38 - 2013-10-09 10:27 - 00000000 ____D C:\Program Files (x86)\MAESTIA 2013-12-29 20:38 - 2013-09-17 08:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-12-29 20:38 - 2013-04-26 18:50 - 00000000 ____D C:\Program Files (x86)\LucasArts 2013-12-29 20:38 - 2013-04-01 14:30 - 00000000 ____D C:\Program Files (x86)\HP 2013-12-29 20:38 - 2013-03-19 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Works 2013-12-29 20:38 - 2013-03-19 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 2013-12-29 20:38 - 2013-03-19 18:34 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8 2013-12-29 20:38 - 2013-03-19 18:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-12-29 20:38 - 2013-03-18 20:52 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2013-12-29 20:38 - 2013-03-18 20:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-29 20:38 - 2013-03-18 20:14 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-29 20:38 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\MSBuild 2013-12-29 20:37 - 2013-04-26 18:46 - 00000000 ____D C:\Program Files (x86)\GameSpy Arcade 2013-12-29 20:36 - 2013-12-26 11:19 - 00000000 ____D C:\Program Files (x86)\directx 2013-12-29 20:36 - 2013-12-25 16:26 - 00000000 ____D C:\Program Files (x86)\Das Spiel des Lebens 2013-12-29 20:36 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\ffdshow 2013-12-29 20:36 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\DirectVobSub 2013-12-29 20:36 - 2013-10-19 13:16 - 00000000 ____D C:\Program Files (x86)\DSP-worx 2013-12-29 20:36 - 2013-09-28 16:13 - 00000000 ____D C:\Program Files (x86)\Falk 2013-12-29 20:36 - 2013-08-25 12:15 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-12-29 20:36 - 2013-06-01 15:57 - 00000000 ____D C:\Program Files (x86)\Dark Mysteries - Der Seelensammler 2013-12-29 20:36 - 2013-05-26 09:02 - 00000000 ____D C:\Program Files (x86)\dtp 2013-12-29 20:36 - 2013-05-06 19:37 - 00000000 ____D C:\Program Files (x86)\GamersFirst 2013-12-29 20:36 - 2013-04-06 15:57 - 00000000 ____D C:\Program Files (x86)\DivX 2013-12-29 20:36 - 2013-03-20 20:22 - 00000000 ____D C:\Program Files (x86)\Euro Truck Simulator 2 2013-12-29 20:36 - 2013-03-19 18:45 - 00000000 ____D C:\Program Files (x86)\DVDFab 8 Qt 2013-12-29 20:35 - 2013-11-30 19:51 - 00000000 ____D C:\Program Files (x86)\Awakening - Das Koenigreich der Kobolde 2013-12-29 20:35 - 2013-11-15 15:31 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-12-29 20:35 - 2013-11-15 15:20 - 00000000 ____D C:\Program Files\SmartPCFixer 2013-12-29 20:35 - 2013-11-14 19:32 - 00000000 ____D C:\Program Files (x86)\Advanced System Protector 2013-12-29 20:35 - 2013-10-29 17:39 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories 2013-12-29 20:35 - 2013-10-23 13:06 - 00000000 ____D C:\Program Files\iTunes 2013-12-29 20:35 - 2013-10-23 13:06 - 00000000 ____D C:\Program Files\iPod 2013-12-29 20:35 - 2013-10-19 13:18 - 00000000 ____D C:\Program Files\DivX 2013-12-29 20:35 - 2013-10-19 13:16 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive 2013-12-29 20:35 - 2013-10-19 13:15 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals 2013-12-29 20:35 - 2013-09-17 08:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-12-29 20:35 - 2013-09-07 19:09 - 00000000 ____D C:\Program Files (x86)\Anno 1701 2013-12-29 20:35 - 2013-07-29 19:08 - 00000000 ____D C:\Program Files (x86)\Christmas Stories - Nussknacker Sammleredition 2013-12-29 20:35 - 2013-07-29 18:45 - 00000000 ____D C:\Program Files (x86)\Awakening - Schloss ohne Traeume 2013-12-29 20:35 - 2013-07-29 18:42 - 00000000 ____D C:\Program Files (x86)\Awakening 2 - Der Mondenwald 2013-12-29 20:35 - 2013-07-29 18:36 - 00000000 ____D C:\Program Files (x86)\9 - The Dark Side Sammleredition 2013-12-29 20:35 - 2013-07-15 14:12 - 00000000 ____D C:\Program Files (x86)\1 Moment of Time - Silentville 2013-12-29 20:35 - 2013-05-23 17:44 - 00000000 ____D C:\Program Files (x86)\Black Mirror 2 2013-12-29 20:35 - 2013-05-09 08:29 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.2 2013-12-29 20:35 - 2013-04-06 15:59 - 00000000 ____D C:\Program Files\Roxio 2013-12-29 20:35 - 2013-04-01 14:10 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-12-29 20:35 - 2013-03-19 20:06 - 00000000 ____D C:\Program Files (x86)\Awakening - Das Himmelsschloss Sammleredition 2013-12-29 20:35 - 2013-03-19 19:58 - 00000000 ____D C:\Program Files\WinRAR 2013-12-29 20:35 - 2013-03-19 19:53 - 00000000 ____D C:\Program Files (x86)\bfgclient 2013-12-29 20:35 - 2013-03-19 18:34 - 00000000 ____D C:\Program Files\Microsoft Office 2013-12-29 20:35 - 2013-03-19 18:23 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-12-29 20:35 - 2013-03-19 18:22 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:21 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:20 - 00000000 ____D C:\Program Files\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:20 - 00000000 ____D C:\Program Files\ATI 2013-12-29 20:35 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Vorlagen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Startmenü 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Netzwerkumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Lokale Einstellungen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Eigene Dateien 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Druckumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Musik 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Bilder 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Verlauf 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Anwendungsdaten 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Anwendungsdaten 2013-12-29 20:30 - 2013-12-29 20:30 - 00001355 _____ C:\Windows\TSSysprep.log 2013-12-29 20:30 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-12-29 19:44 - 2013-03-18 18:53 - 01852960 _____ C:\Windows\WindowsUpdate (1).log 2013-12-29 19:04 - 2013-12-29 18:57 - 00013897 _____ C:\Windows\diagwrn.xml 2013-12-29 19:04 - 2013-12-29 18:57 - 00001890 _____ C:\Windows\diagerr.xml 2013-12-29 15:37 - 2013-12-29 15:37 - 00003226 _____ C:\Windows\System32\Tasks\Bonanza 2013-12-29 13:36 - 2013-12-29 13:36 - 02304092 _____ () C:\Users\Jacky\Downloads\TechnicLauncher.exe 2013-12-29 11:12 - 2013-05-09 08:28 - 01833776 _____ C:\Windows\system32\dmwu.exe 2013-12-29 11:08 - 2013-05-09 08:28 - 00033792 _____ (IncrediMail, Ltd.) C:\Windows\system32\ImHttpComm.dll 2013-12-29 10:15 - 2013-12-29 10:15 - 02014840 _____ (DriverBoost) C:\Users\Jacky\Downloads\DriverBoostPro_Setup.exe 2013-12-29 10:12 - 2013-12-29 10:12 - 08054042 _____ C:\Users\Jacky\Downloads\windowsinstaller45(1).zip 2013-12-29 09:40 - 2013-12-25 20:03 - 00000000 ____D C:\Users\Jacky\AppData\Local\Zylom Games 2013-12-28 21:44 - 2013-12-28 21:42 - 63443792 _____ C:\Users\Jacky\Downloads\thegameoflifedownload.exe 2013-12-26 22:00 - 2013-12-26 21:59 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-12-26 20:37 - 2013-12-26 20:37 - 00401784 _____ (Softonic ) C:\Users\Jacky\Downloads\SoftonicDownloader_fuer_windows-installer-clean-up.exe 2013-12-26 19:39 - 2013-12-26 19:39 - 02585872 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsInstaller-KB893803-v2-x86.exe 2013-12-26 17:00 - 2013-07-15 14:00 - 00000000 ____D C:\BigFishCache 2013-12-26 11:19 - 2013-12-26 11:19 - 00000278 _____ C:\Windows\Directx.log 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck.exe 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(1).exe 2013-12-25 20:59 - 2013-12-25 20:59 - 02311827 _____ C:\Users\Jacky\Downloads\sdl3ewin.zip 2013-12-25 20:57 - 2013-12-25 20:57 - 00397154 _____ C:\Users\Jacky\Downloads\SpieldesLebensWin.zip 2013-12-25 20:53 - 2013-12-25 20:53 - 00002890 _____ C:\Windows\System32\Tasks\{E03E12C0-F94B-4CA6-A09A-515468D6FAA3} 2013-12-25 20:45 - 2013-12-25 20:45 - 00943872 _____ C:\Users\Jacky\Downloads\Spiel-des-Lebens-Setup.exe 2013-12-25 20:41 - 2013-12-25 20:41 - 00003018 _____ C:\Windows\System32\Tasks\{476505DD-F30E-4FF4-8920-CB14D92EB605} 2013-12-25 20:29 - 2013-12-25 20:29 - 00003018 _____ C:\Windows\System32\Tasks\{01014E7C-EF80-4994-94A4-7882BBE1FC4D} 2013-12-25 16:22 - 2013-12-25 16:22 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p200715036_s2_l2.exe 2013-12-25 16:19 - 2013-12-25 16:19 - 00002890 _____ C:\Windows\System32\Tasks\{D5C4E481-AC90-46F2-A2E0-FC0AF1374D57} 2013-12-25 09:03 - 2011-02-19 22:51 - 00608080 _____ (Microsoft Corporation) C:\Windows\system32\msvcp100.dll 2013-12-25 09:03 - 2011-02-19 00:52 - 00829264 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100.dll 2013-12-19 08:27 - 2013-03-20 19:09 - 00001525 _____ C:\Users\Jacky\Desktop\PartyCasino.lnk 2013-12-19 08:24 - 2013-03-20 19:05 - 00001531 _____ C:\Users\Jacky\Desktop\partypoker.lnk 2013-12-16 05:59 - 2013-08-14 07:15 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 11:36 - 2013-12-15 11:33 - 00181280 _____ C:\Windows\DPINST.LOG 2013-12-15 11:33 - 2013-12-15 11:33 - 00002106 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2013-12-11 18:46 - 2013-03-20 18:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 18:46 - 2013-03-20 18:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-11 18:46 - 2013-03-20 18:27 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-11 08:58 - 2012-08-02 15:09 - 00029792 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys 2013-12-11 08:58 - 2012-06-19 17:28 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2013-12-07 19:39 - 2013-05-22 16:18 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-07 19:39 - 2013-05-22 16:18 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-11-30 19:40 - 2013-11-30 19:40 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p132398476_s2_l2(1).exe 2013-11-30 19:36 - 2013-11-30 19:36 - 00003150 _____ C:\Windows\System32\Tasks\{D9FF8CB0-8D45-4811-B5EE-E5A392CEF7CF} Files to move or delete: ==================== C:\Users\Jacky\Firefox Setup 19.0.2.exe Some content of TEMP: ==================== C:\Users\Jacky\AppData\Local\Temp\eauninstall.exe C:\Users\Jacky\AppData\Local\Temp\SimCity 4 Deluxe_uninst.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-29 20:17 ==================== End Of Log ============================ --- --- --- --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-12-2013 01 Ran by Jacky at 2013-12-30 16:43:43 Running from C:\Users\Jacky\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5} AS: Kaspersky Internet Security (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E} ==================== Installed Programs ====================== 1 Moment of Time: Silentville (x32 Version: - ) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) 9: The Dark Side Sammleredition (x32 Version: - ) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated) AIO_CDA_ProductContext (x32 Version: 130.0.365.000 - Hewlett-Packard) AIO_CDA_Software (x32 Version: 130.0.365.000 - Hewlett-Packard) AIO_Scan (x32 Version: 130.0.365.000 - Hewlett-Packard) AMD APP SDK Runtime (Version: 2.5.793.1 - Advanced Micro Devices Inc.) AMD AVIVO64 Codecs (Version: 11.7.0.11013 - Advanced Micro Devices, Inc.) AMD Catalyst Install Manager (Version: 3.0.851.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) AMD Media Foundation Decoders (Version: 1.0.61013.1636 - Advanced Micro Devices, Inc.) Anno 1701 (x32 Version: 1.04 - Sunflowers) APB Reloaded (x32 Version: 1.6.1.607756 - ) Awakening 2: Der Mondenwald (x32 Version: - ) Awakening: Das Himmelsschloss Sammleredition (x32 Version: - ) Awakening: Das Königreich der Kobolde (x32 Version: - ) Awakening: Schloss ohne Träume (x32 Version: - ) Big Fish: Game Manager (x32 Version: 3.2.0.7 - ) Black Mirror 1.2 (x32 Version: - Digital Tainment Pool) Black Mirror 2 (x32 Version: - dtp) BrowserProtect (x32 Version: - Bit89 Inc) <==== ATTENTION BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) C3100 (x32 Version: 130.0.365.000 - Hewlett-Packard) c3100_Help (x32 Version: 82.0.256.000 - Hewlett-Packard) Catalyst Control Center (x32 Version: 2011.1013.1702.28713 - Ihr Firmenname) Catalyst Control Center InstallProxy (x32 Version: 2011.1013.1702.28713 - Advanced Micro Devices, Inc.) Catalyst Control Center Localization All (x32 Version: 2011.1013.1702.28713 - Advanced Micro Devices, Inc.) CCC Help Danish (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Dutch (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help English (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Finnish (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help French (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help German (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Italian (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Japanese (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Norwegian (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Spanish (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Swedish (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) ccc-utility64 (Version: 2011.1013.1702.28713 - Advanced Micro Devices, Inc.) Cheat Engine 6.2 (x32 Version: - Dark Byte) Christmas Stories: Nussknacker Sammleredition (x32 Version: - ) Copy (x32 Version: 130.0.428.000 - Hewlett-Packard) Dark Mysteries - Der Seelensammler (x32 Version: - cerasus.media GmbH) Das Spiel des Lebens (x32 Version: - ) Delicious - Emily's Tea Garden (x32 Version: - Zylom) Delicious Promo (x32 Version: - Zylom) Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Die Sims™ 3 (x32 Version: 1.63.4 - Electronic Arts) Die Sims™ 3 Einfach tierisch (x32 Version: 10.0.96 - Electronic Arts) Die Sims™ 3 Late Night (x32 Version: 6.0.81 - Electronic Arts) DivX-Setup (x32 Version: 2.6.1.8 - DivX, LLC) DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) DomaIQ (x32 Version: - Tuguu SLU) Dream Chronicles(R) - The Book of Air(TM) (x32 Version: - Zylom) DVDFab 8.1.5.8 (18/01/2012) Qt (x32 Version: - Fengtao Software Inc.) Euro Truck Simulator 2 (x32 Version: 1.1.1 - SCS Software) Falk Navi-Manager classic (x32 Version: 2.11.0 - United Navigation GmbH) Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) GamersFirst LIVE! (HKCU Version: - GamersFirst) GameSpy Arcade (x32 Version: - ) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) HP Customer Participation Program 13.0 (Version: 13.0 - HP) HP Imaging Device Functions 13.0 (Version: 13.0 - HP) HP Photosmart All-In-One Driver Software 13.0 Rel. A (Version: 13.0 - HP) HP Photosmart Essential 3.5 (Version: 3.5 - HP) HP Smart Web Printing 4.51 (Version: 4.51 - HP) HP Solution Center 13.0 (Version: 13.0 - HP) HP Update (x32 Version: 4.000.011.006 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Internet Explorer Toolbar 4.8 by SweetPacks (x32 Version: 4.8.0000 - SweetIM Technologies Ltd.) <==== ATTENTION iTunes (Version: 11.1.2.31 - Apple Inc.) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190 - Kaspersky Lab) LAME v3.99.3 (for Windows) (x32 Version: - ) MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Microsoft .NET Framework 4 Client Profile (Version: - ) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: - ) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: - ) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Groove Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (Version: 1.20.146.0 - Microsoft) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) Mystery of the Ancients: Der Fluch des Schwarzen Wassers Sammleredition (x32 Version: - ) Nero Burning ROM (x32 Version: 12.5.6000 - Nero AG) Nero Burning ROM Help (CHM) (x32 Version: 12.0.3000 - Nero AG) Nero BurningROM 12 (x32 Version: 12.5.00900 - Nero AG) Nero ControlCenter (x32 Version: 11.0.15600 - Nero AG) Nero ControlCenter Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Nero Core Components (x32 Version: 11.0.20900 - Nero AG) Nero SharedVideoCodecs (x32 Version: 1.0.12100.2.0 - Nero AG) Nero Update (x32 Version: 11.0.11800.31.0 - Nero AG) Network64 (Version: 130.0.572.000 - Hewlett-Packard) Network64 (Version: 140.0.221.000 - Hewlett-Packard) Nightmares from the Deep - The Cursed Heart Premium Edition (x32 Version: - Zylom) NVIDIA PhysX (x32 Version: 9.10.0129 - NVIDIA Corporation) OCR Software by I.R.I.S. 13.0 (Version: 13.0 - HP) Online Games Manager v1.21 (x32 Version: 1.21.2 - Real Networks, Inc.) Origin (x32 Version: 9.0.14.2148 - Electronic Arts, Inc.) PartyCasino (x32 Version: - PartyGaming) partypoker (x32 Version: - PartyGaming) Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) ProtectDisc Driver, Version 11 (x32 Version: 11.0.0.12 - ProtectDisc Software GmbH) PunkBuster Services (x32 Version: 0.993 - Even Balance, Inc.) Realtek Ethernet Controller Driver (x32 Version: 7.46.610.2011 - Realtek) Roads of Rome III (x32 Version: - ) Roxio WinOnCD 9 (x32 Version: 9.0.136 - Roxio, Inc.) Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Shop for HP Supplies (Version: 13.0 - HP) SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Sony PC Companion 2.10.181 (x32 Version: 2.10.181 - Sony) Star Wars Battlefront II (x32 Version: 1.0 - LucasArts) Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Steam (x32 Version: 1.0.0.0 - Valve Corporation) SweetIM Bundle by SweetPacks (x32 Version: 1.0.0.0 - SweetPacks LTD) <==== ATTENTION SweetIM for Messenger 3.7 (x32 Version: 3.7.0007 - SweetIM Technologies Ltd.) <==== ATTENTION SweetPacks Updater (x32 Version: 5.0.1.7 - ) <==== ATTENTION The Elder Scrolls V: Skyrim (x32 Version: - Bethesda Game Studios) Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Ubisoft Game Launcher (x32 Version: 1.0.0.0 - UBISOFT) UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Update for 2007 Microsoft Office System (KB967642) (x32 Version: - Microsoft) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft Office 2007 Help for Common Features (KB963673) (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Access 2007 Help (KB963663) (x32 Version: - Microsoft) Update for Microsoft Office Excel 2007 Help (KB963678) (x32 Version: - Microsoft) Update for Microsoft Office Infopath 2007 Help (KB963662) (x32 Version: - Microsoft) Update for Microsoft Office OneNote 2007 Help (KB963670) (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 Help (KB963677) (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version: - Microsoft) Update for Microsoft Office Publisher 2007 Help (KB963667) (x32 Version: - Microsoft) Update for Microsoft Office Script Editor Help (KB963671) (x32 Version: - Microsoft) Update for Microsoft Office Word 2007 Help (KB963665) (x32 Version: - Microsoft) Update_for_BonanzaDeals (HKCU Version: - Update_for_BonanzaDeals) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) VD64Inst (Version: 1.00.0000 - Roxio, Inc.) WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8 - Microsoft Corp) Windows Mobile-Gerätecenter (Version: 6.1.6965.0 - Microsoft Corporation) Windows Utils (x32 Version: - ) Windows XP Mode (Version: 1.3.7600.16422 - Microsoft Corporation) WinRAR 4.00 (64-bit) (Version: 4.00.0 - win.rar GmbH) Zuma Deluxe (x32 Version: - Zylom) ==================== Restore Points ========================= 29-12-2013 20:19:46 Windows Update 29-12-2013 20:24:46 Windows Update 29-12-2013 20:36:36 Windows Update 29-12-2013 21:32:10 Windows XP Mode wird installiert 29-12-2013 21:55:17 Windows XP Mode wird entfernt 29-12-2013 22:00:48 Windows Update 29-12-2013 22:12:51 Windows XP Mode wird installiert 29-12-2013 22:21:44 Windows XP Mode wird entfernt 29-12-2013 22:35:39 Windows XP Mode wird installiert 30-12-2013 08:40:01 Windows Update 30-12-2013 09:00:40 Removed Apple Application Support 30-12-2013 09:02:37 Removed Apple Mobile Device Support 30-12-2013 09:04:58 Removed Apple Software Update 30-12-2013 09:09:01 Windows Update 30-12-2013 12:15:44 Removed Bonjour 30-12-2013 12:17:19 Removed Google Earth. ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {139C862C-D1B9-4F0A-9C9A-073303D913EA} - System32\Tasks\{476505DD-F30E-4FF4-8920-CB14D92EB605} => C:\Users\Jacky\AppData\Local\Zylom Games\The Game of Life Deluxe\wrapper.exe Task: {14AB91D8-2263-44A9-9980-D459C2771FB5} - System32\Tasks\{D5C4E481-AC90-46F2-A2E0-FC0AF1374D57} => E:\SETUP.EXE Task: {359F6510-FCB7-4DDA-84B5-9D1285191442} - System32\Tasks\DigitalSite => C:\Users\Jacky\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {5D250DC8-F1DA-43F4-973B-F79C6E6D1007} - System32\Tasks\{E03E12C0-F94B-4CA6-A09A-515468D6FAA3} => E:\SETUP.EXE Task: {7DC5A4E5-DD7F-45A7-A9E2-4EE1E6528AF6} - \SidebarExecute No Task File Task: {9063E202-5ED9-4719-A733-5522E0B2A5A8} - System32\Tasks\Bonanza => C:\Users\Jacky\AppData\Roaming\Bonanza\UpdateProc\UpdateTask.exe [2013-04-30] () Task: {B586DBAA-DA3A-45E8-9DA9-D8805E14F874} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {C5BED6B3-6533-4EF5-912F-E79A5B6739DF} - System32\Tasks\{01014E7C-EF80-4994-94A4-7882BBE1FC4D} => C:\Users\Jacky\AppData\Local\Zylom Games\The Game of Life Deluxe\wrapper.exe Task: {CB5F5DE8-F364-4626-A773-6BE90832BBE3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-22] (Google Inc.) Task: {E66B1016-488B-49AA-A86F-07465CCFA953} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {E6BCC1F9-4A86-485A-95CB-B8ACDA1B47F3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-22] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Bonanza.job => C:\Users\Jacky\AppData\Roaming\Bonanza\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\Jacky\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-03-19 19:58 - 2011-03-02 12:40 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll 2013-12-29 11:12 - 2013-12-29 11:12 - 01429296 _____ () C:\Windows\System32\ljkb\lmrn.dll 2011-10-13 17:01 - 2011-10-13 17:01 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2012-12-14 13:45 - 2012-12-14 13:45 - 01310136 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kpcengine.2.2.dll 2006-10-27 07:13 - 2006-10-27 07:13 - 04587520 ____R () C:\Program Files (x86)\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll 2012-04-26 23:38 - 2012-04-26 23:38 - 20758016 _____ () C:\Users\Jacky\AppData\Local\GamersFirst\LIVE!\libcef.dll 2012-08-17 21:38 - 2012-08-17 21:38 - 00479160 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll 2013-08-29 01:25 - 2013-08-29 01:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2006-10-27 07:17 - 2006-10-27 07:17 - 00516096 _____ () C:\Program Files (x86)\Common Files\Roxio Shared\9.0\DLLShared\LayoutDll9.dll 2013-12-29 11:12 - 2013-12-29 11:12 - 01150256 _____ () C:\Windows\SysWOW64\jmdp\lmrn.dll 2013-12-20 10:03 - 2013-12-20 10:03 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-12-11 18:46 - 2013-12-11 18:46 - 16242056 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: USB (Universal Serial Bus)-Controller Description: USB (Universal Serial Bus)-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: SM-Bus-Controller Description: SM-Bus-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Kaspersky Anti-Virus NDIS 6 Filter Description: Kaspersky Anti-Virus NDIS 6 Filter Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: KLIM6 Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (12/30/2013 04:41:13 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (12/30/2013 01:26:04 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 01:20:37 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 26.0.0.5087, Zeitstempel: 0x52a0d273 Name des fehlerhaften Moduls: xul.dll, Version: 26.0.0.5087, Zeitstempel: 0x52a0d20a Ausnahmecode: 0xc0000005 Fehleroffset: 0x0014e1a8 ID des fehlerhaften Prozesses: 0x1628 Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Error: (12/30/2013 00:31:11 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:30:31 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:30:29 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:30:29 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:30:28 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:29:28 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:08:36 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "hpqcxs08" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst hpqcxs08 erreicht. Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "hpqcxs08" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst hpqcxs08 erreicht. Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "hpqcxs08" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst hpqcxs08 erreicht. Error: (12/30/2013 01:26:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "hpqcxs08" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/30/2013 01:26:00 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst hpqcxs08 erreicht. Error: (12/30/2013 01:25:52 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "hpqcxs08" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/30/2013 01:25:52 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst hpqcxs08 erreicht. Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-12-30 13:24:50.776 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 13:24:50.652 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 12:06:58.987 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 12:06:58.909 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:55:38.993 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:55:38.915 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:54:08.898 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:54:08.820 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:27:10.482 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:27:10.419 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 70% Total physical RAM: 4077.64 MB Available physical RAM: 1207.27 MB Total Pagefile: 8153.48 MB Available Pagefile: 4410.09 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:880.41 GB) (Free:621.5 GB) NTFS Drive d: (Recover) (Fixed) (Total:50 GB) (Free:15.62 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: C2D23E51) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=880 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ==================== End Of Log ============================ Geändert von Tweety741 (30.12.2013 um 17:51 Uhr) |
30.12.2013, 17:23 | #2 |
/// the machine /// TB-Ausbilder | PC bereinigen und schneller machen Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
30.12.2013, 17:52 | #3 |
| PC bereinigen und schneller machen Hallo schrauber,
__________________habe es entsprechend geändert. Danke für den Hinweis. LG Tweety |
31.12.2013, 14:55 | #4 | |
/// the machine /// TB-Ausbilder | PC bereinigen und schneller machenCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.01.2014, 17:25 | #5 |
| PC bereinigen und schneller machen Hallo schrauber, habe Combofix durchlaufen lassen, siehe Logfile. VG Tweety Code:
ATTFilter ComboFix 14-01-01.01 - Jacky 01.01.2014 17:11:37.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4078.2909 [GMT 1:00] ausgeführt von:: c:\users\Jacky\Desktop\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5} FW: Kaspersky Internet Security *Disabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E} SP: Kaspersky Internet Security *Disabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2013-12-01 bis 2014-01-01 )))))))))))))))))))))))))))))) . . 2014-01-01 16:17 . 2014-01-01 16:17 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-12-31 14:38 . 2013-12-31 14:38 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller 2013-12-30 20:29 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe 2013-12-30 20:29 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe 2013-12-30 20:29 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys 2013-12-30 20:29 . 2011-03-25 03:29 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2013-12-30 20:29 . 2011-03-25 03:29 325120 ----a-w- c:\windows\system32\drivers\usbport.sys 2013-12-30 20:29 . 2011-03-25 03:29 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys 2013-12-30 20:29 . 2011-03-25 03:29 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys 2013-12-30 20:29 . 2011-03-25 03:29 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2013-12-30 20:29 . 2011-03-25 03:28 7936 ----a-w- c:\windows\system32\drivers\usbd.sys 2013-12-30 19:55 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe 2013-12-30 19:55 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL 2013-12-30 19:55 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2013-12-30 19:55 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL 2013-12-30 19:55 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll 2013-12-30 19:28 . 2012-07-26 07:48 2560 ----a-w- c:\windows\system32\drivers\hu-HU\wdf01000.sys.mui 2013-12-30 19:28 . 2012-07-26 07:46 2560 ----a-w- c:\windows\system32\drivers\de-DE\wdf01000.sys.mui 2013-12-30 19:28 . 2012-07-26 05:39 2560 ----a-w- c:\windows\system32\drivers\tr-TR\wdf01000.sys.mui 2013-12-30 19:28 . 2012-07-26 05:05 2560 ----a-w- c:\windows\system32\drivers\es-ES\wdf01000.sys.mui 2013-12-30 19:28 . 2012-07-26 05:05 2560 ----a-w- c:\windows\system32\drivers\pl-PL\wdf01000.sys.mui 2013-12-30 19:28 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui 2013-12-30 18:36 . 2013-12-01 13:42 90708896 ----a-w- c:\windows\system32\MRT.exe 2013-12-30 15:42 . 2013-12-30 15:42 -------- d-----w- C:\FRST 2013-12-30 11:30 . 2013-07-04 12:50 633856 ----a-w- c:\windows\system32\comctl32.dll 2013-12-30 11:29 . 2013-10-04 02:16 116736 ----a-w- c:\windows\system32\drivers\drmk.sys 2013-12-30 11:29 . 2013-10-04 01:36 230400 ----a-w- c:\windows\system32\drivers\portcls.sys 2013-12-30 11:29 . 2013-07-04 12:57 259584 ----a-w- c:\windows\system32\WebClnt.dll 2013-12-30 11:29 . 2013-07-04 12:50 102400 ----a-w- c:\windows\system32\davclnt.dll 2013-12-30 11:29 . 2013-07-04 11:57 205824 ----a-w- c:\windows\SysWow64\WebClnt.dll 2013-12-30 11:29 . 2013-07-04 11:51 81920 ----a-w- c:\windows\SysWow64\davclnt.dll 2013-12-30 11:29 . 2013-07-04 10:11 140800 ----a-w- c:\windows\system32\drivers\mrxdav.sys 2013-12-30 11:25 . 2013-06-25 22:55 785624 ----a-w- c:\windows\system32\drivers\Wdf01000.sys 2013-12-30 11:25 . 2012-11-28 22:56 9728 ----a-w- c:\windows\system32\Wdfres.dll 2013-12-30 11:25 . 2012-11-28 22:56 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys 2013-12-30 11:19 . 2013-03-19 05:53 48640 ----a-w- c:\windows\system32\wwanprotdim.dll 2013-12-30 11:19 . 2013-03-19 05:53 230400 ----a-w- c:\windows\system32\wwansvc.dll 2013-12-30 11:19 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll 2013-12-30 11:19 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll 2013-12-30 11:19 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll 2013-12-30 11:19 . 2010-12-23 10:42 961024 ----a-w- c:\windows\system32\CPFilters.dll 2013-12-30 11:19 . 2010-12-23 10:36 259072 ----a-w- c:\windows\system32\mpg2splt.ax 2013-12-30 11:19 . 2010-12-23 05:54 850944 ----a-w- c:\windows\SysWow64\sbe.dll 2013-12-30 11:19 . 2010-12-23 05:54 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll 2013-12-30 11:19 . 2010-12-23 05:50 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax 2013-12-30 11:17 . 2013-06-06 05:49 14336 ----a-w- c:\windows\system32\dciman32.dll 2013-12-30 11:15 . 2012-11-02 05:59 478208 ----a-w- c:\windows\system32\dpnet.dll 2013-12-30 11:15 . 2012-11-02 05:11 376832 ----a-w- c:\windows\SysWow64\dpnet.dll 2013-12-30 11:15 . 2013-06-04 06:00 624128 ----a-w- c:\windows\system32\qedit.dll 2013-12-30 11:15 . 2013-06-04 04:53 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2013-12-30 11:15 . 2013-09-08 02:30 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-12-30 11:15 . 2013-09-08 02:27 327168 ----a-w- c:\windows\system32\mswsock.dll 2013-12-30 11:15 . 2013-09-08 02:03 231424 ----a-w- c:\windows\SysWow64\mswsock.dll 2013-12-30 11:12 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll 2013-12-30 11:12 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax 2013-12-30 11:12 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll 2013-12-30 11:12 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax 2013-12-30 11:12 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2013-12-30 11:12 . 2013-07-12 10:41 100864 ----a-w- c:\windows\system32\drivers\usbcir.sys 2013-12-30 11:12 . 2011-04-22 22:15 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys 2013-12-30 11:12 . 2012-08-11 00:56 715776 ----a-w- c:\windows\system32\kerberos.dll 2013-12-30 11:12 . 2012-08-10 23:56 542208 ----a-w- c:\windows\SysWow64\kerberos.dll 2013-12-30 09:12 . 2012-11-30 05:45 362496 ----a-w- c:\windows\system32\wow64win.dll 2013-12-30 09:12 . 2012-11-30 05:43 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2013-12-30 09:12 . 2012-11-30 05:45 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2013-12-30 09:10 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe 2013-12-30 09:10 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe 2013-12-30 09:10 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll 2013-12-30 09:10 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll 2013-12-30 09:09 . 2013-10-03 02:23 404480 ----a-w- c:\windows\system32\gdi32.dll 2013-12-30 09:09 . 2013-10-03 02:00 311808 ----a-w- c:\windows\SysWow64\gdi32.dll 2013-12-30 09:09 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe 2013-12-30 09:09 . 2013-01-24 06:01 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys 2013-12-30 09:09 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll 2013-12-30 09:09 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll 2013-12-30 09:07 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll 2013-12-30 09:07 . 2013-08-01 12:09 983488 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-12-30 09:07 . 2013-04-10 06:01 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-12-30 09:07 . 2011-02-03 11:25 144384 ----a-w- c:\windows\system32\cdd.dll 2013-12-30 08:45 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe 2013-12-30 08:45 . 2013-12-30 08:45 -------- d-----w- c:\windows\PCHEALTH 2013-12-30 08:44 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll 2013-12-30 08:44 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll 2013-12-30 08:44 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2013-12-30 08:44 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2013-12-30 08:44 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe 2013-12-30 08:44 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll 2013-12-30 08:44 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2013-12-30 08:43 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2013-12-30 08:43 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll 2013-12-30 08:43 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll 2013-12-30 08:34 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll 2013-12-30 08:15 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll 2013-12-30 08:15 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll 2013-12-30 04:16 . 2013-12-29 20:19 -------- d-----w- c:\windows\Panther 2013-12-30 03:55 . 2013-12-29 20:03 -------- d-----w- C:\$WINDOWS.~Q 2013-12-30 03:48 . 2013-12-30 03:51 -------- d-----w- C:\$INPLACE.~TR 2013-12-29 22:01 . 2010-11-20 04:46 2560 ----a-w- c:\windows\system32\drivers\pl-PL\vpcuxd.sys.mui 2013-12-29 20:36 . 2012-02-17 06:38 1031680 ----a-w- c:\windows\system32\rdpcore.dll 2013-12-29 20:36 . 2012-02-17 05:34 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll 2013-12-29 20:36 . 2012-02-17 04:57 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys 2013-12-29 20:21 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll 2013-12-29 20:21 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe 2013-12-29 20:21 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll 2013-12-29 20:21 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll 2013-12-29 20:20 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll 2013-12-29 20:20 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll 2013-12-29 20:20 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll 2013-12-29 20:16 . 2012-06-02 14:19 186752 ----a-w- c:\windows\system32\wuwebv.dll 2013-12-29 20:16 . 2012-06-02 14:15 36864 ----a-w- c:\windows\system32\wuapp.exe 2013-12-29 19:52 . 2013-12-29 19:52 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help 2013-12-29 19:31 . 2013-12-29 22:11 -------- d-----w- c:\users\Jacky 2013-12-29 19:29 . 2013-12-29 19:29 0 ----a-w- c:\windows\ativpsrm.bin 2013-12-29 15:17 . 2013-12-29 19:42 -------- d-----w- c:\windows\SysWow64\jmdp 2013-12-29 15:17 . 2013-12-29 19:42 -------- d-----w- c:\windows\system32\ljkb 2013-12-27 06:50 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BC2278A3-02EC-47E8-8828-6469FA903658}\mpengine.dll 2013-12-26 20:59 . 2013-12-26 21:00 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0 2013-12-26 10:19 . 2013-12-29 19:36 -------- d-----w- c:\program files (x86)\directx 2013-12-25 15:26 . 2013-12-29 19:36 -------- d-----w- c:\program files (x86)\Das Spiel des Lebens 2013-12-15 10:33 . 2013-12-29 19:41 -------- d-----w- c:\programdata\Sony 2013-12-15 10:33 . 2013-12-29 19:39 -------- d-----w- c:\program files (x86)\Sony 2013-12-11 23:27 . 2013-11-26 10:18 4096 ------w- c:\windows\system32\ieetwcollectorres.dll 2013-12-11 23:27 . 2013-11-26 09:46 48640 ------w- c:\windows\system32\ieetwproxystub.dll 2013-12-11 23:27 . 2013-11-26 09:18 111616 ------w- c:\windows\system32\ieetwcollector.exe 2013-12-11 23:27 . 2013-11-26 09:16 708608 ------w- c:\windows\system32\jscript9diag.dll . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-29 10:12 . 2013-05-09 07:28 1833776 ----a-w- c:\windows\system32\dmwu.exe 2013-12-29 10:08 . 2013-05-09 07:28 33792 ----a-w- c:\windows\system32\ImHttpComm.dll 2013-12-25 08:03 . 2011-02-19 21:51 608080 ----a-w- c:\windows\system32\msvcp100.dll 2013-12-25 08:03 . 2011-02-18 23:52 829264 ----a-w- c:\windows\system32\msvcr100.dll 2013-12-11 17:46 . 2013-03-20 17:27 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-12-11 17:46 . 2013-03-20 17:27 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-12-11 07:58 . 2012-08-02 14:09 29792 ----a-w- c:\windows\system32\drivers\klim6.sys 2013-12-11 07:58 . 2012-06-19 16:28 458336 ----a-w- c:\windows\system32\drivers\kl1.sys 2013-11-26 19:51 . 2013-11-26 19:51 940032 ------w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-11-26 19:51 . 2013-11-26 19:51 194048 ------w- c:\windows\SysWow64\elshyph.dll 2013-11-26 19:50 . 2013-11-26 19:50 645120 ------w- c:\windows\SysWow64\jsIntl.dll 2013-11-26 19:50 . 2013-11-26 19:50 34816 ------w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-11-26 19:50 . 2013-11-26 19:50 235008 ------w- c:\windows\system32\elshyph.dll 2013-11-26 19:50 . 2013-11-26 19:50 1051136 ------w- c:\windows\SysWow64\mshtmlmedia.dll 2013-11-26 19:50 . 2013-11-26 19:50 942592 ------w- c:\windows\system32\jsIntl.dll 2013-11-26 19:50 . 2013-11-26 19:50 83968 ------w- c:\windows\system32\MshtmlDac.dll 2013-11-26 19:50 . 2013-11-26 19:50 61952 ------w- c:\windows\SysWow64\MshtmlDac.dll 2013-11-26 19:50 . 2013-11-26 19:50 51200 ------w- c:\windows\SysWow64\ieetwproxystub.dll 2013-11-26 19:50 . 2013-11-26 19:50 40448 ------w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-26 19:50 . 2013-11-26 19:50 1228800 ------w- c:\windows\system32\mshtmlmedia.dll 2013-10-22 18:21 . 2013-10-22 18:21 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-10-19 03:31 . 2013-10-19 03:31 293192 ----a-w- C:\iTunesOutlookAddIn.dll 2013-10-19 03:31 . 2013-10-19 03:31 9789256 ----a-w- C:\iTunes.exe 2013-10-19 03:31 . 2013-10-19 03:31 405320 ----a-w- C:\iTunesAdmin.dll 2013-10-19 03:31 . 2013-10-19 03:31 152392 ----a-w- C:\iTunesHelper.exe 2013-10-19 03:31 . 2013-10-19 03:31 148808 ----a-w- C:\iTunesHelper.dll 2013-10-19 03:31 . 2013-10-19 03:31 25449288 ----a-w- C:\iTunes.dll 2013-10-19 03:30 . 2013-10-19 03:30 776216 ----a-w- C:\gnsdk_sdkmanager.dll 2013-10-19 03:30 . 2013-10-19 03:30 3008536 ----a-w- C:\gnsdk_dsp.dll 2013-10-19 03:30 . 2013-10-19 03:30 262680 ----a-w- C:\gnsdk_submit.dll 2013-10-19 03:30 . 2013-10-19 03:30 219672 ----a-w- C:\gnsdk_musicid.dll 2013-10-14 17:00 . 2013-11-26 19:54 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE 2013-10-10 07:10 . 2012-12-14 12:45 29280 ----a-w- c:\windows\system32\drivers\klmouflt.sys 2013-10-10 07:10 . 2012-12-14 12:45 29280 ----a-w- c:\windows\system32\drivers\klkbdflt.sys 2013-10-10 07:10 . 2013-03-18 19:52 626272 ----a-w- c:\windows\system32\drivers\klif.sys 2013-07-08 08:37 . 2013-09-28 14:40 1456640 ----a-w- c:\program files (x86)\Common Files\Falk Navi-Manager.msi 2012-05-15 08:33 . 2013-09-28 15:13 1456640 ----a-w- c:\program files (x86)\Common Files\Falk Navi-Manager classic.msi . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] 2013-03-18 14:53 1310480 ----a-r- c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2013-03-18 1310480] . [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1] [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" [2013-10-10 356128] "DivXMediaServer"="c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" [2013-08-21 450560] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2013-08-29 1861968] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-10-27 221184] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-13 343168] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] . c:\users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ GamersFirst LIVE!.lnk - c:\users\Jacky\AppData\Local\GamersFirst\LIVE!\Live.exe /silent [2013-6-25 2878504] net.lnk - c:\users\Jacky\AppData\Roaming\Windows Net Data\net.exe [2013-12-25 709120] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x] S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x] S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys;c:\windows\SYSNATIVE\drivers\acedrv11.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 IBUpdaterService;IBUpdaterService;c:\windows\system32\dmwu.exe;c:\windows\SYSNATIVE\dmwu.exe [x] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x] S2 ogmservice;Online Games Manager;c:\program files (x86)\Online Games Manager\ogmservice.exe;c:\program files (x86)\Online Games Manager\ogmservice.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2014-01-01 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-20 17:46] . 2014-01-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-22 15:18] . 2014-01-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-22 15:18] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = https://www.google.de/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: Hinzufügen zu Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\ FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/ FF - ExtSQL: 2013-11-14 19:31; {f9d03c26-0575-497e-821d-f7956d23e0ca}; c:\users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}.xpi FF - ExtSQL: !HIDDEN! 2013-04-01 15:34; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF - user.js: extensions.iminent.tlbrSrchUrl - hxxp://start.iminent.com/?ref=toolbarm#q= FF - user.js: extensions.iminent.id - 56b79f850000000000008c89a599a6f8 FF - user.js: extensions.iminent.appId - {0E4B2CAB-B859-4C57-B96E-63DDEC692BC4} FF - user.js: extensions.iminent.instlDay - 16065 FF - user.js: extensions.iminent.vrsn - 1.8.28.3 FF - user.js: extensions.iminent.vrsni - 1.8.28.3 FF - user.js: extensions.iminent.vrsnTs - 1.8.28.320:39 FF - user.js: extensions.iminent.prtnrId - iminent FF - user.js: extensions.iminent.prdct - iminent FF - user.js: extensions.iminent.aflt - orgnl FF - user.js: extensions.iminent.smplGrp - none FF - user.js: extensions.iminent.tlbrId - base FF - user.js: extensions.iminent.instlRef - FF - user.js: extensions.iminent.dfltLng - FF - user.js: extensions.iminent.excTlbr - false FF - user.js: extensions.iminent.ffxUnstlRst - false FF - user.js: extensions.iminent.admin - false FF - user.js: extensions.iminent.autoRvrt - false FF - user.js: extensions.iminent.rvrt - false FF - user.js: extensions.iminent.newTab - false . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file) BHO-{377e5d4d-77e5-476a-8716-7e70a9272da0} - c:\progra~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll BHO-{84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file) Toolbar-{377e5d4d-77e5-476a-8716-7e70a9272da0} - c:\progra~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll Wow6432Node-HKLM-Run-<NO NAME> - (no file) Wow6432Node-HKLM-Run-ISUSPM Startup - c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe Wow6432Node-HKLM-Run-ISUSScheduler - c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe AddRemove-{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693} - c:\programdata\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-01-01 17:20:21 ComboFix-quarantined-files.txt 2014-01-01 16:20 . Vor Suchlauf: 32 Verzeichnis(se), 665.070.542.848 Bytes frei Nach Suchlauf: 43 Verzeichnis(se), 665.225.863.168 Bytes frei . - - End Of File - - EF5DFCE65031AA3AB6192F89C641BD2B A36C5E4F47E84449FF07ED3517B43A31 |
02.01.2014, 09:43 | #6 |
/// the machine /// TB-Ausbilder | PC bereinigen und schneller machen Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> PC bereinigen und schneller machen |
02.01.2014, 18:07 | #7 |
| PC bereinigen und schneller machen Hallo schrauber, poste die Files in mehreren Antworten da der Text sonst zu groß wird. Logfile Malwarebytes Anti-Malware Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.02.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Jacky :: JACKY-PC [Administrator] 02.01.2014 17:21:48 mbam-log-2014-01-02 (17-21-48).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 216082 Laufzeit: 3 Minute(n), 49 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 29 HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB} (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Doko-Toolbar (PUP.Optional.DokoToolbar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\WNLT (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\InstallCore\1I1T1Q1S (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\BPROTECTSETTINGS (PUP.Optional.BProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Doko-Toolbar (PUP.Optional.DokoToolbar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\qvo6Software (PUP.Optional.qvo6.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (Adware.InstallBrain) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\Software\Iminent (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WNLT (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 7 HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Daten: -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\WNLT|URL (PUP.Optional.InstallBrain.A) -> Daten: MYSTART -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 1O1M1K1L2X1M1G1K1U -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {0F0CAE4C-B87A-11E2-A126-8C89A599A6F8} -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {0F0CAE4C-B87A-11E2-A126-8C89A599A6F8} -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES (X86)\SWEETIM\TOOLBARS\INTERNET EXPLORER\MGHELPERAPP.EXE (PUP.Optional.SweetIM.A) -> Daten: 1 -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES (X86)\SWEETIM\TOOLBARS\INTERNET EXPLORER\MGTOOLBARPROXY.DLL (PUP.Optional.SweetIM.A) -> Daten: 1 -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 1 HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|DefaultScope (PUP.Optional.Qone8) -> Bösartig: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}) Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 39 C:\Users\Jacky\AppData\Roaming\DigitalSite\UpdateProc (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector\clamunpack (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector\Troubleshooter (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDeals (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Systweak\Advanced System Protector (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Systweak\Advanced System Protector\2.1.1000.12150 (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Systweak\Advanced System Protector\signatures (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\Systweak\Advanced System Protector (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\Systweak\Advanced System Protector\2.1.1000.12150 (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\OpenCandy\72558EC696F24140ACEF765F00BD368C (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\OpenCandy\OpenCandy_72558EC696F24140ACEF765F00BD368C (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\conf (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation\Uninstall (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation\Uninstall (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\BonanzaDealsLive\Update (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\BonanzaDealsLive\Update\Log (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Local\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Local\BonanzaDealsLive\CrashReports (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDealsLive\CrashReports (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDealsLive\Update (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDealsLive\Update\Download (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDealsLive\Update\Install (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDealsLive\Update\Offline (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDealsLive\Update\Offline\{FF302C43-448E-4E2D-8E11-5AFD6C181D1A} (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 145 C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (PUP.Optional.SweetPacks) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\OpenCandy\72558EC696F24140ACEF765F00BD368C\DeltaTB.exe (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\Downloads\CheatEngine62.exe (PUP.Optional.Somoto) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\Downloads\FlashPlayer_V.35534305b.exe (Adware.DomaIQ) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\Downloads\iLividSetup-r362-n-bf.exe (PUP.Optional.Bandoo) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\Downloads\SoftonicDownloader_fuer_windows-installer-clean-up.exe (PUP.Optional.Softonic.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\Downloads\ZipOpenerSetup.exe (PUP.Optional.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\1cc19f.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\1cc1a5.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\DigitalSite\UpdateProc\config.dat (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\DigitalSite\UpdateProc\prod.dat (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\DigitalSite\UpdateProc\STTL.DAT (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\DigitalSite\UpdateProc\TTL.DAT (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector\loading_withWhiteBG.avi (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector\AspManager.exe (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector\Interop.IWshRuntimeLibrary.dll (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector\japanese_asp_JA.ini (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector\unins000.dat (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector\unins000.msg (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector\clamunpack\readme.txt (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Advanced System Protector\Troubleshooter\ASP-Troubleshooter.chm (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDeals\BonanzaDeals.crx (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDeals\BonanzaDeals.xpi (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE64.dll (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDeals\uninst.exe (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals\Bonanza Deals Help.url (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals\Bonanza Deals.url (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Systweak\Advanced System Protector\AddonSafelist (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Systweak\Advanced System Protector\log.xslt (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\Systweak\Advanced System Protector\Settings.db (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\Systweak\Advanced System Protector\2.1.1000.12150\ASPLog.txt (PUP.Optional.AdvancedSystemProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\OpenCandy\72558EC696F24140ACEF765F00BD368C\5472.ico (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\OpenCandy\72558EC696F24140ACEF765F00BD368C\EBB77268-338F-4C6A-8590-AD88FED26F4A (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jacky\AppData\Roaming\OpenCandy\72558EC696F24140ACEF765F00BD368C\OCBrowserHelper_1.0.6.125.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\default.xml (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\conf\logger.xml (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcm90.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcp90.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcr90.dll (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\about.html (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\affid.dat (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\basis.xml (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\bing.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\clear-history.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim-over.gif (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim.gif (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\content-notifier.js (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\dating.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\dictionary.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\eye_icon.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\eye_icon_over.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\e_cards.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\find.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\free_stuff.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\games.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\glitter.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\google.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\help.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\highlight.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\locales.xml (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\logo_16x16.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\logo_21x18.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\logo_32x32.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\logo_about.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\MenuExt.html (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\more-search-providers.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\music.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\news.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\onstart.js (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\options.html (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\photos.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\search-current-site.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\shopping.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\SmileySmile.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\SmileyWink.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\sweetim_text.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\toolbar.xml (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\video.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\web-search.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\yahoo.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_bing.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_blank.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_current.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_dictionary.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_google.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_hover.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_left.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_photo.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_video.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_web.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_yahoo.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_bing.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_current.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_dictionary.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_google.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_hover.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_left.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_photo.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_video.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_web.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_yahoo.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_bing.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_current.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_dictionary.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_google.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_hover.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_left.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_photo.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_video.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_web.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_yahoo.png (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation\Config.bin (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation\HSChromeRegSetup.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation\SKSetup.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation\uninstaller.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation\WSSetup.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation\Uninstall\msvcp100.dll (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation\Uninstall\msvcr100.dll (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation\Uninstall\uninstaller.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\WNLT\Installation\Uninstall\UninstallerLauncher.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation\Config.bin (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation\HSChromeRegSetup.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation\SKSetup.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation\uninstaller.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation\WSSetup.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation\Uninstall\msvcp100.dll (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation\Uninstall\msvcr100.dll (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation\Uninstall\uninstaller.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\SysWOW64\WNLT\Installation\Uninstall\UninstallerLauncher.exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\BonanzaDealsLive\Update\Log\BonanzaDealsLive.log (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 02/01/2014 um 17:42:40 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Jacky - JACKY-PC # Gestartet von : C:\Users\Jacky\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\SweetIM Ordner Gelöscht : C:\ProgramData\Systweak Ordner Gelöscht : C:\ProgramData\Trymedia Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup Ordner Gelöscht : C:\Program Files (x86)\SweetIM Ordner Gelöscht : C:\Program Files (x86)\sweetpacks bundle uninstaller Ordner Gelöscht : C:\Windows\Installer\{A0C9DF2B-89B5-4483-8983-18A68200F1B4} Ordner Gelöscht : C:\Windows\SysWOW64\ARFC Ordner Gelöscht : C:\Windows\SysWOW64\jmdp Ordner Gelöscht : C:\Windows\SysWOW64\WNLT Ordner Gelöscht : C:\Program Files\DomaIQ Uninstaller Ordner Gelöscht : C:\Windows\System32\ljkb Ordner Gelöscht : C:\Users\Jacky\AppData\LocalLow\IminentToolbar Ordner Gelöscht : C:\Users\Jacky\AppData\LocalLow\searchresultstb Ordner Gelöscht : C:\Users\Jacky\AppData\LocalLow\SweetIM Ordner Gelöscht : C:\Users\Jacky\AppData\Roaming\digitalsite Ordner Gelöscht : C:\Users\Jacky\AppData\Roaming\Systweak Ordner Gelöscht : C:\Users\Jacky\AppData\Roaming\Windows Net Data Ordner Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM Ordner Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\ffxtlbr@dokotoolbar.com Ordner Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\sparpilot@sparpilot.com Ordner Gelöscht : C:\Users\Jacky\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab Datei Gelöscht : C:\Windows\System32\dmwu.exe Datei Gelöscht : C:\Windows\System32\ImhxxpComm.dll Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\bprotector_extensions.sqlite Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\bprotector_prefs.js Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Ask.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\Ask.xml Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\Babylon.xml Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\delta.xml Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\dokotoolbar.xml Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\iminent.xml Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\MyStart Search.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\qvo6.xml Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\Search_Results.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\SweetIM Search.xml Datei Gelöscht : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\user.js Datei Gelöscht : C:\Windows\System32\Tasks\digitalsite ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ieadcoanfjloocmfafkebdnfefmohngj Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sim-packages Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe Schlüssel Gelöscht : HKCU\Software\5e08cdebd6ae444 Schlüssel Gelöscht : HKLM\SOFTWARE\5e08cdebd6ae444 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{377E5D4D-77E5-476A-8716-7E70A9272DA0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{377E5D4D-77E5-476A-8716-7E70A9272DA0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{377E5D4D-77E5-476A-8716-7E70A9272DA0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{377E5D4D-77E5-476A-8716-7E70A9272DA0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{377E5D4D-77E5-476A-8716-7E70A9272DA0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{377E5D4D-77E5-476A-8716-7E70A9272DA0}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Schlüssel Gelöscht : HKCU\Software\dsiteproducts Schlüssel Gelöscht : HKCU\Software\ilivid Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\ImInstaller Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\iLividSRTB Schlüssel Gelöscht : HKLM\Software\systweak Schlüssel Gelöscht : HKLM\Software\Trymedia Systems Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A0C9DF2B-89B5-4483-8983-18A68200F1B4} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DD85D6BF-4787-4A93-99A5-3F0CF0AE8834} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DomaIQ Uninstaller Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SweetIM Bundle by SweetPacks Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Iminent Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\wnlt Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\B2FD9C0A5B9838449838816A28001F4B Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\B2FD9C0A5B9838449838816A28001F4B ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16526 Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\prefs.js ] Zeile gelöscht : user_pref("avg.install.userHPSettings", "hxxp://www.delta-search.com/?affID=120519&babsrc=HP_ss&mntrId=56B78C89A599A6F8"); Zeile gelöscht : user_pref("avg.install.userSPSettings", "Delta Search"); Zeile gelöscht : user_pref("extensions.delta.admin", false); Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst"); Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.dfltLng", "en"); Zeile gelöscht : user_pref("extensions.delta.excTlbr", false); Zeile gelöscht : user_pref("extensions.delta.id", "56b79f850000000000008c89a599a6f8"); Zeile gelöscht : user_pref("extensions.delta.instlDay", "15788"); Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst"); Zeile gelöscht : user_pref("extensions.delta.newTab", false); Zeile gelöscht : user_pref("extensions.delta.prdct", "delta"); Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta"); Zeile gelöscht : user_pref("extensions.delta.rvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", ""); Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.10.0"); Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.10.019:15:55"); Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.10.0"); Zeile gelöscht : user_pref("extensions.dokotoolbar.tb_url", "hxxp://www.doko-search.com/?q={searchTerms}&babsrc=TB_ss&mntrId=56B78C89A599A6F8&affID=125836&tsp=5040"); Zeile gelöscht : user_pref("extensions.dokotoolbar.tlbrSrchUrl", "hxxp://www.doko-search.com/?q={searchTerms}&babsrc=TB_ss&mntrId=56B78C89A599A6F8&affID=125836&tsp=5040"); Zeile gelöscht : user_pref("extensions.iminent.admin", false); Zeile gelöscht : user_pref("extensions.iminent.aflt", "orgnl"); Zeile gelöscht : user_pref("extensions.iminent.appId", "{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}"); Zeile gelöscht : user_pref("extensions.iminent.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.iminent.dfltLng", ""); Zeile gelöscht : user_pref("extensions.iminent.excTlbr", false); Zeile gelöscht : user_pref("extensions.iminent.ffxUnstlRst", false); Zeile gelöscht : user_pref("extensions.iminent.id", "56b79f850000000000008c89a599a6f8"); Zeile gelöscht : user_pref("extensions.iminent.instlDay", "16065"); Zeile gelöscht : user_pref("extensions.iminent.instlRef", ""); Zeile gelöscht : user_pref("extensions.iminent.newTab", false); Zeile gelöscht : user_pref("extensions.iminent.prdct", "iminent"); Zeile gelöscht : user_pref("extensions.iminent.prtnrId", "iminent"); Zeile gelöscht : user_pref("extensions.iminent.rvrt", "false"); Zeile gelöscht : user_pref("extensions.iminent.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.iminent.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q="); Zeile gelöscht : user_pref("extensions.iminent.vrsn", "1.8.28.3"); Zeile gelöscht : user_pref("extensions.iminent.vrsnTs", "1.8.28.320:39:04"); Zeile gelöscht : user_pref("extensions.iminent.vrsni", "1.8.28.3"); Zeile gelöscht : user_pref("iminent.LayoutId", "28"); Zeile gelöscht : user_pref("iminent.ShowThankyouPixel", "0"); Zeile gelöscht : user_pref("iminent.adapters", "{\"softonic\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"Status\":2,\"expireTime\":\"1388086773174250138\"},\"drwindows\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"Status[...] Zeile gelöscht : user_pref("iminent.enabledAds", "false"); Zeile gelöscht : user_pref("iminent.registerToolbarEvent102", "1388304625053"); Zeile gelöscht : user_pref("iminent.registerToolbarEvent109", "1388262007849"); Zeile gelöscht : user_pref("iminent.registerToolbarEvent111", "1388262007853"); Zeile gelöscht : user_pref("iminent.registerToolbarEvent112", "1388262015316"); Zeile gelöscht : user_pref("iminent.registerToolbarEvent122", "1388262007857"); Zeile gelöscht : user_pref("iminent.registerToolbarEvent140", "1388315243087"); Zeile gelöscht : user_pref("iminent.version", "7.51.3.1"); Zeile gelöscht : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.51.3.1\",\"InstallEventCTime\":1388355289359,\"InstallEvent\":\"True\"}"); -\\ Google Chrome v [ Datei : C:\Users\Jacky\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [15358 octets] - [02/01/2014 17:36:43] AdwCleaner[S0].txt - [14282 octets] - [02/01/2014 17:42:40] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14343 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.9 (01.01.2014:1) OS: Windows 7 Home Premium x64 Ran by Jacky on 02.01.2014 at 17:48:28,35 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2195699789-3413303425-2103154922-1000\Software\sweetim ~~~ Files Successfully deleted: [File] "C:\Users\Jacky\appdata\locallow\SkwConfig.bin" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\big fish" Successfully deleted: [Folder] "C:\ProgramData\big fish games" Successfully deleted: [Folder] "C:\Users\Jacky\appdata\local\big fish" Successfully deleted: [Folder] "C:\Users\Jacky\appdata\locallow\datamngr" Successfully deleted: [Folder] "C:\bigfishcache" ~~~ FireFox Successfully deleted: [File] C:\user.js Emptied folder: C:\Users\Jacky\AppData\Roaming\mozilla\firefox\profiles\0tw6hpe0.default\minidumps [94 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 02.01.2014 at 17:52:58,10 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
02.01.2014, 18:12 | #8 |
| PC bereinigen und schneller machen Den FRST Log muss ich noch mal teilen, weil sie zu groß ist. Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-01-2014 01 Ran by Jacky (administrator) on JACKY-PC on 02-01-2014 17:56:22 Running from C:\Users\Jacky\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (RealNetworks, Inc.) C:\Program Files (x86)\Online Games Manager\ogmservice.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (GamersFirst) C:\Users\Jacky\AppData\Local\GamersFirst\LIVE!\Live.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\Run: [RoxWatchTray] - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [221184 2006-10-27] (Sonic Solutions) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-13] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Startup: C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk ShortcutTarget: GamersFirst LIVE!.lnk -> C:\Users\Jacky\AppData\Local\GamersFirst\LIVE!\Live.exe (GamersFirst) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x87B9B8029C05CF01 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Amazon-Icon - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\amazon-icon@giga.de FF Extension: ReloadEvery - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi FF Extension: New Tab - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{C4A4F5A0-4B89-4392-AFAC-D58010E349AF}.xpi FF Extension: BonanzaDeals - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}.xpi FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Jacky\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) R2 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [559552 2013-08-08] (RealNetworks, Inc.) ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-09-07] () R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-10-10] (Kaspersky Lab ZAO) S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-19] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-04-24] (Kaspersky Lab ZAO) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-09-07] () S1 RxFilter; C:\Windows\SysWow64\DRIVERS\RxFilter.sys [58880 2006-10-27] (Sonic Solutions) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-02 17:56 - 2014-01-02 17:56 - 00014812 _____ C:\Users\Jacky\Desktop\FRST.txt 2014-01-02 17:56 - 2014-01-02 17:56 - 00000000 ____D C:\Users\Jacky\Desktop\FRST-OlderVersion 2014-01-02 17:52 - 2014-01-02 17:52 - 00001389 _____ C:\Users\Jacky\Desktop\JRT.txt 2014-01-02 17:48 - 2014-01-02 17:48 - 00000000 ____D C:\Windows\ERUNT 2014-01-02 17:47 - 2014-01-02 17:47 - 01036305 _____ (Thisisu) C:\Users\Jacky\Desktop\JRT.exe 2014-01-02 17:45 - 2014-01-02 17:45 - 00014460 _____ C:\Users\Jacky\Desktop\AdwCleaner[S0].txt 2014-01-02 17:36 - 2014-01-02 17:42 - 00000000 ____D C:\AdwCleaner 2014-01-02 17:35 - 2014-01-02 17:35 - 01233962 _____ C:\Users\Jacky\Desktop\adwcleaner.exe 2014-01-02 17:16 - 2014-01-02 17:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Malwarebytes 2014-01-02 17:15 - 2014-01-02 17:15 - 00000712 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-02 17:15 - 2014-01-02 17:15 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-02 17:15 - 2014-01-02 17:15 - 00000000 ____D C:\Malwarebytes' Anti-Malware 2014-01-02 17:15 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-01 17:20 - 2014-01-01 17:20 - 00029197 _____ C:\ComboFix.txt 2014-01-01 17:10 - 2014-01-01 17:20 - 00000000 ____D C:\Qoobox 2014-01-01 17:10 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-01 17:10 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-01 17:10 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-01 17:10 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-01 17:10 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-01 17:10 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-01 17:10 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-01 17:10 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-01 17:09 - 2014-01-01 17:19 - 00000000 ____D C:\Windows\erdnt 2014-01-01 17:08 - 2014-01-01 17:08 - 05160282 ____R (Swearware) C:\Users\Jacky\Desktop\ComboFix.exe 2013-12-31 16:34 - 2013-12-31 16:34 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Need for Speed World 2013-12-31 16:00 - 2013-12-31 16:00 - 00000000 ____D C:\Users\Jacky\AppData\Local\Electronic_Arts_Inc 2013-12-31 15:38 - 2013-12-31 15:38 - 00001278 _____ C:\Users\Public\Desktop\Need for Speed World.lnk 2013-12-30 21:29 - 2011-03-25 04:29 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-12-30 21:29 - 2011-03-25 04:29 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-12-30 21:29 - 2011-03-25 04:29 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-12-30 21:29 - 2011-03-25 04:29 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-12-30 21:29 - 2011-03-25 04:29 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-12-30 21:29 - 2011-03-25 04:29 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-12-30 21:29 - 2011-03-25 04:28 - 00007936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-12-30 21:29 - 2011-02-25 07:19 - 02871808 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-12-30 21:29 - 2011-02-25 06:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2013-12-30 21:28 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2013-12-30 21:28 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe 2013-12-30 21:28 - 2011-03-11 07:41 - 00410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys 2013-12-30 21:28 - 2011-03-11 07:41 - 00189824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2013-12-30 21:28 - 2011-03-11 07:41 - 00166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys 2013-12-30 21:28 - 2011-03-11 07:41 - 00148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys 2013-12-30 21:28 - 2011-03-11 07:41 - 00107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys 2013-12-30 21:28 - 2011-03-11 07:41 - 00027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys 2013-12-30 21:28 - 2011-03-11 07:33 - 02565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2013-12-30 21:28 - 2011-03-11 07:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe 2013-12-30 21:28 - 2011-03-11 06:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll 2013-12-30 21:28 - 2011-03-11 06:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe 2013-12-30 21:28 - 2011-03-11 05:37 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2013-12-30 20:55 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-30 20:55 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-30 20:55 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-30 20:55 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 17847296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 12344320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-30 20:01 - 2013-12-30 20:01 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-30 20:01 - 2013-12-30 20:01 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-30 20:01 - 2013-12-30 20:01 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-30 20:01 - 2013-12-30 20:01 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-30 20:01 - 2013-12-30 20:01 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-30 20:01 - 2013-12-30 20:01 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-30 20:01 - 2013-12-30 20:01 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-30 20:01 - 2013-12-30 20:01 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-30 20:01 - 2013-12-30 20:01 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-30 20:01 - 2013-12-30 20:01 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-30 19:57 - 2013-12-30 20:16 - 00013301 _____ C:\Windows\IE9_main.log 2013-12-30 19:51 - 2013-12-30 19:51 - 00000134 _____ C:\Users\Jacky\Desktop\Internet Explorer-Problembehebung.url 2013-12-30 19:43 - 2013-12-30 19:53 - 00015787 _____ C:\Windows\IE10_main.log 2013-12-30 19:42 - 2013-12-30 19:43 - 51415040 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\IE10-Windows6.1-x64-de-de_b16521.exe 2013-12-30 19:36 - 2013-12-01 14:42 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-30 16:42 - 2014-01-02 17:56 - 00000000 ____D C:\FRST 2013-12-30 16:40 - 2014-01-02 17:56 - 01931426 _____ (Farbar) C:\Users\Jacky\Desktop\FRST64.exe 2013-12-30 13:21 - 2013-12-30 13:22 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele Dirk 2013-12-30 13:21 - 2013-12-30 13:22 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele 2013-12-30 12:31 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-30 12:31 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-30 12:31 - 2011-06-16 06:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll 2013-12-30 12:31 - 2011-06-16 05:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll 2013-12-30 12:31 - 2011-06-15 11:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll 2013-12-30 12:31 - 2011-06-15 11:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll 2013-12-30 12:31 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll 2013-12-30 12:31 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll 2013-12-30 12:31 - 2011-06-15 09:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll 2013-12-30 12:31 - 2011-06-15 09:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll 2013-12-30 12:31 - 2011-06-15 09:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll 2013-12-30 12:31 - 2011-06-15 09:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll 2013-12-30 12:31 - 2011-06-15 09:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll 2013-12-30 12:31 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2013-12-30 12:31 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2013-12-30 12:30 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-30 12:30 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-30 12:30 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-30 12:30 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-30 12:30 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-12-30 12:30 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-12-30 12:30 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-12-30 12:30 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-12-30 12:30 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-12-30 12:30 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-12-30 12:30 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-12-30 12:30 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-12-30 12:30 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-12-30 12:30 - 2013-04-12 15:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-12-30 12:30 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2013-12-30 12:30 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2013-12-30 12:30 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2013-12-30 12:30 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2013-12-30 12:30 - 2011-12-30 07:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl 2013-12-30 12:30 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl 2013-12-30 12:29 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-30 12:29 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-30 12:29 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-12-30 12:29 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-12-30 12:29 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-12-30 12:29 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-12-30 12:29 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-12-30 12:25 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-12-30 12:25 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2013-12-30 12:25 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2013-12-30 12:25 - 2012-11-28 23:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2013-12-30 12:22 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-12-30 12:22 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-12-30 12:22 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-12-30 12:22 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-12-30 12:22 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-12-30 12:22 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-12-30 12:22 - 2013-02-15 07:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-12-30 12:22 - 2013-02-15 07:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-12-30 12:22 - 2013-02-15 07:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-12-30 12:22 - 2013-02-15 05:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-12-30 12:22 - 2013-02-15 05:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-12-30 12:22 - 2013-02-15 04:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-12-30 12:22 - 2011-10-26 06:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2013-12-30 12:22 - 2011-10-26 06:25 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-12-30 12:22 - 2011-10-26 05:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2013-12-30 12:22 - 2011-10-26 05:32 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-12-30 12:19 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-12-30 12:19 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-12-30 12:19 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-12-30 12:19 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2013-12-30 12:19 - 2010-12-23 11:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll 2013-12-30 12:19 - 2010-12-23 11:42 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2013-12-30 12:19 - 2010-12-23 11:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax 2013-12-30 12:19 - 2010-12-23 06:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll 2013-12-30 12:19 - 2010-12-23 06:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2013-12-30 12:19 - 2010-12-23 06:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax 2013-12-30 12:18 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-30 12:18 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-12-30 12:18 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-12-30 12:18 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-12-30 12:18 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-12-30 12:18 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-12-30 12:18 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-12-30 12:18 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-12-30 12:18 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-12-30 12:18 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-12-30 12:18 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-12-30 12:18 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-12-30 12:18 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-12-30 12:18 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-12-30 12:18 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-12-30 12:18 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-12-30 12:18 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-12-30 12:18 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-12-30 12:18 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-12-30 12:18 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-12-30 12:18 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-12-30 12:18 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-12-30 12:18 - 2013-02-27 07:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-12-30 12:18 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2013-12-30 12:18 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2013-12-30 12:18 - 2012-01-04 11:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll 2013-12-30 12:18 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2013-12-30 12:18 - 2011-11-17 07:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2013-12-30 12:18 - 2011-11-17 06:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2013-12-30 12:18 - 2011-07-09 03:46 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2013-12-30 12:18 - 2011-05-04 06:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2013-12-30 12:18 - 2011-05-04 06:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2013-12-30 12:18 - 2011-05-04 06:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2013-12-30 12:18 - 2011-05-04 06:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2013-12-30 12:18 - 2011-05-04 06:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2013-12-30 12:18 - 2011-05-04 06:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2013-12-30 12:18 - 2011-05-04 06:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2013-12-30 12:18 - 2011-05-04 06:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2013-12-30 12:18 - 2011-05-04 06:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2013-12-30 12:18 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-12-30 12:18 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-12-30 12:18 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-12-30 12:18 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-12-30 12:18 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-12-30 12:18 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2013-12-30 12:18 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-12-30 12:18 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-12-30 12:18 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-12-30 12:18 - 2011-04-27 03:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2013-12-30 12:18 - 2011-04-27 03:39 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2013-12-30 12:17 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-12-30 12:17 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-12-30 12:17 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-12-30 12:17 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-12-30 12:17 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-12-30 12:17 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-12-30 12:17 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-12-30 12:17 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-12-30 12:17 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-12-30 12:17 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-12-30 12:17 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-12-30 12:17 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-12-30 12:17 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-12-30 12:17 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-12-30 12:17 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-12-30 12:17 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-12-30 12:17 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-12-30 12:17 - 2012-11-01 06:43 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2013-12-30 12:17 - 2012-11-01 06:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2013-12-30 12:17 - 2012-11-01 05:47 - 01389568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2013-12-30 12:17 - 2012-11-01 05:47 - 01236992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2013-12-30 12:17 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2013-12-30 12:17 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2013-12-30 12:17 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2013-12-30 12:17 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2013-12-30 12:17 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2013-12-30 12:17 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2013-12-30 12:17 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2013-12-30 12:17 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2013-12-30 12:17 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2013-12-30 12:17 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2013-12-30 12:17 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-12-30 12:17 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2013-12-30 12:17 - 2012-05-01 06:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2013-12-30 12:17 - 2012-04-26 06:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2013-12-30 12:17 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2013-12-30 12:17 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2013-12-30 12:17 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2013-12-30 12:17 - 2011-03-11 07:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2013-12-30 12:17 - 2011-03-11 07:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2013-12-30 12:17 - 2011-03-11 06:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2013-12-30 12:17 - 2011-03-11 06:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2013-12-30 12:17 - 2011-03-03 07:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2013-12-30 12:17 - 2011-03-03 07:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2013-12-30 12:17 - 2011-03-03 07:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2013-12-30 12:17 - 2011-03-03 06:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2013-12-30 12:17 - 2011-03-03 06:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe 2013-12-30 12:17 - 2010-06-26 04:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2013-12-30 12:17 - 2010-06-26 04:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2013-12-30 12:15 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-12-30 12:15 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-12-30 12:15 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-12-30 12:15 - 2013-06-04 07:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-12-30 12:15 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-12-30 12:15 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2013-12-30 12:15 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2013-12-30 12:14 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-12-30 12:14 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2013-12-30 12:14 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2013-12-30 12:14 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2013-12-30 12:14 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2013-12-30 12:14 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2013-12-30 12:14 - 2012-11-22 06:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2013-12-30 12:14 - 2012-11-22 05:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2013-12-30 12:14 - 2011-04-29 04:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2013-12-30 12:14 - 2011-04-29 04:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2013-12-30 12:14 - 2011-04-29 04:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2013-12-30 12:12 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-12-30 12:12 - 2012-08-11 01:56 - 00715776 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2013-12-30 12:12 - 2012-08-11 00:56 - 00542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2013-12-30 12:12 - 2012-04-28 04:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2013-12-30 12:12 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2013-12-30 12:12 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2013-12-30 12:12 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll 2013-12-30 12:12 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax 2013-12-30 12:12 - 2011-04-22 23:15 - 00027520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2013-12-30 12:11 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-12-30 12:11 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-12-30 12:11 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-12-30 12:11 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-12-30 12:11 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-12-30 12:11 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-12-30 12:11 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-12-30 12:11 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-12-30 12:11 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-12-30 12:11 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-12-30 12:11 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-12-30 12:11 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-12-30 12:11 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-12-30 12:11 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-12-30 12:11 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-12-30 12:11 - 2012-04-07 13:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2013-12-30 12:11 - 2012-04-07 12:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2013-12-30 12:11 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2013-12-30 10:12 - 2012-11-30 06:45 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-12-30 10:12 - 2012-11-30 06:45 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-12-30 10:12 - 2012-11-30 06:43 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-12-30 10:12 - 2012-11-30 00:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2013-12-30 10:12 - 2012-11-30 00:15 - 00420064 _____ C:\Windows\system32\locale.nls 2013-12-30 10:11 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-12-30 10:11 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-12-30 10:11 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-12-30 10:11 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-12-30 10:11 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-12-30 10:11 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-12-30 10:11 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll 2013-12-30 10:11 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2013-12-30 10:11 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2013-12-30 10:11 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll 2013-12-30 10:11 - 2011-02-05 18:10 - 00642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-12-30 10:11 - 2011-02-05 18:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2013-12-30 10:11 - 2011-02-05 18:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2013-12-30 10:11 - 2011-02-05 18:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2013-12-30 10:11 - 2011-02-05 18:06 - 00605552 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-12-30 10:11 - 2011-02-05 18:06 - 00566208 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-12-30 10:11 - 2011-02-05 18:06 - 00518672 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-12-30 10:10 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-12-30 10:10 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-12-30 10:10 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-12-30 10:10 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-12-30 10:09 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-12-30 10:09 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-12-30 10:09 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-12-30 10:09 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-12-30 10:09 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2013-12-30 10:09 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2013-12-30 10:08 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-30 10:08 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-30 10:08 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-30 10:08 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-30 10:08 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-30 10:08 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-30 10:08 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-30 10:08 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-30 10:08 - 2013-08-27 10:01 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-12-30 10:08 - 2013-08-27 10:01 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-12-30 10:08 - 2013-08-27 09:21 - 01077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-12-30 10:08 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-12-30 10:08 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-12-30 10:08 - 2013-01-03 07:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2013-12-30 10:08 - 2012-08-22 19:12 - 00376688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2013-12-30 10:08 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2013-12-30 10:08 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll 2013-12-30 10:08 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll 2013-12-30 10:08 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2013-12-30 10:08 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2013-12-30 10:08 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2013-12-30 10:08 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2013-12-30 10:08 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2013-12-30 10:08 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2013-12-30 10:08 - 2011-08-27 06:37 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2013-12-30 10:08 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll 2013-12-30 10:08 - 2011-08-27 05:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2013-12-30 10:08 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll 2013-12-30 10:08 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2013-12-30 10:08 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll 2013-12-30 10:08 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll 2013-12-30 10:08 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll 2013-12-30 10:08 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe 2013-12-30 10:08 - 2011-05-03 06:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2013-12-30 10:08 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2013-12-30 10:08 - 2011-02-23 05:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2013-12-30 10:08 - 2011-02-18 11:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe 2013-12-30 10:08 - 2011-02-18 06:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe 2013-12-30 10:08 - 2011-02-12 12:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe 2013-12-30 10:07 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-12-30 10:07 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-12-30 10:07 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2013-12-30 10:07 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-12-30 09:45 - 2013-12-30 09:45 - 00000000 ____D C:\Windows\PCHEALTH 2013-12-30 09:45 - 2010-02-23 09:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe 2013-12-30 09:44 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2013-12-30 09:44 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2013-12-30 09:44 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2013-12-30 09:44 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2013-12-30 09:44 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2013-12-30 09:43 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2013-12-30 09:43 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2013-12-30 09:43 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2013-12-30 09:35 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-12-30 09:35 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-12-30 09:35 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-12-30 09:35 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-12-30 09:35 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-12-30 09:35 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2013-12-30 09:35 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2013-12-30 09:34 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-12-30 09:15 - 2011-11-19 15:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2013-12-30 09:15 - 2011-11-19 15:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2013-12-30 05:16 - 2013-12-29 21:19 - 00000000 ____D C:\Windows\Panther 2013-12-30 05:15 - 2013-12-30 05:15 - 00262144 _____ C:\Windows\system32\config\userdiff 2013-12-30 04:55 - 2013-12-29 21:03 - 00000000 ____D C:\$WINDOWS.~Q 2013-12-30 04:48 - 2013-12-30 04:51 - 00000000 ____D C:\$INPLACE.~TR 2013-12-29 23:25 - 2013-12-29 23:35 - 486678800 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsXPMode_de-de.exe 2013-12-29 23:23 - 2013-12-29 23:23 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(4).exe 2013-12-29 23:11 - 2013-12-30 21:15 - 00000000 ___RD C:\Users\Jacky\Virtual Machines 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\th-TH 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ro-RO 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\he-IL 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ar-SA 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Program Files (x86)\Windows Virtual PC 2013-12-29 23:01 - 2010-11-20 14:34 - 00360832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcvmm.sys 2013-12-29 23:01 - 2010-11-20 14:34 - 00194944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpchbus.sys 2013-12-29 23:01 - 2010-11-20 14:27 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\vpchbuspipe.dll 2013-12-29 23:01 - 2010-11-20 14:25 - 04514816 _____ (Microsoft Corporation) C:\Windows\system32\vpc.exe 2013-12-29 23:01 - 2010-11-20 14:25 - 02264064 _____ (Microsoft Corporation) C:\Windows\system32\VPCWizard.exe 2013-12-29 23:01 - 2010-11-20 14:25 - 01369600 _____ (Microsoft Corporation) C:\Windows\system32\VPCSettings.exe 2013-12-29 23:01 - 2010-11-20 12:37 - 01210368 _____ (Microsoft Corporation) C:\Windows\system32\VMWindow.exe 2013-12-29 23:01 - 2010-11-20 12:37 - 00936448 _____ (Microsoft Corporation) C:\Windows\system32\vmsal.exe 2013-12-29 23:01 - 2010-11-20 12:35 - 00562176 _____ (Microsoft Corporation) C:\Windows\system32\VMCPropertyHandler.dll 2013-12-29 23:01 - 2010-11-20 12:35 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcusb.sys 2013-12-29 23:01 - 2010-11-20 12:35 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcnfltr.sys 2013-12-29 23:01 - 2010-11-20 11:52 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vmsal.exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(3).exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(2).exe 2013-12-29 21:36 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2013-12-29 21:36 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2013-12-29 21:36 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2013-12-29 21:33 - 2013-12-29 21:33 - 09566298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-12-29 21:24 - 2013-12-30 21:15 - 00125128 _____ C:\Users\Jacky\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-29 21:22 - 2013-12-30 21:15 - 00001413 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-12-29 21:21 - 2013-12-30 21:15 - 00001447 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-29 21:21 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-12-29 21:21 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-12-29 21:21 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-12-29 21:21 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-12-29 21:20 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-12-29 21:20 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-12-29 21:20 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-12-29 21:19 - 2013-12-29 21:19 - 00000020 ___SH C:\Users\Jacky\ntuser.ini 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-12-29 21:16 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-12-29 21:16 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-12-29 21:13 - 2014-01-02 17:42 - 01788976 _____ C:\Windows\WindowsUpdate.log 2013-12-29 20:59 - 2013-12-29 20:59 - 00022960 _____ C:\Windows\system32\emptyregdb.dat 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default User\AppData\Lo |
02.01.2014, 18:13 | #9 |
| PC bereinigen und schneller machen 2. Teil FRST Log: Code:
ATTFilter 2013-12-29 20:31 - 2013-12-29 23:11 - 00000000 ____D C:\Users\Jacky 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Vorlagen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Startmenü 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Netzwerkumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Lokale Einstellungen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Eigene Dateien 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Druckumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Musik 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Bilder 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Verlauf 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Anwendungsdaten 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Anwendungsdaten 2013-12-29 20:31 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:31 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:30 - 2013-12-29 20:30 - 00001355 _____ C:\Windows\TSSysprep.log 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-12-29 19:25 - 2013-12-29 21:03 - 00006155 _____ C:\Windows\comsetup.log 2013-12-29 18:57 - 2013-12-29 19:04 - 00013897 _____ C:\Windows\diagwrn.xml 2013-12-29 18:57 - 2013-12-29 19:04 - 00001890 _____ C:\Windows\diagerr.xml 2013-12-29 16:17 - 2013-12-29 20:42 - 00000000 ____D C:\Windows\pss 2013-12-29 15:37 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Bonanza 2013-12-29 13:36 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.technic 2013-12-29 13:36 - 2013-12-29 13:36 - 02304092 _____ () C:\Users\Jacky\Downloads\TechnicLauncher.exe 2013-12-29 10:15 - 2013-12-29 10:15 - 02014840 _____ (DriverBoost) C:\Users\Jacky\Downloads\DriverBoostPro_Setup.exe 2013-12-29 10:12 - 2013-12-29 10:12 - 08054042 _____ C:\Users\Jacky\Downloads\windowsinstaller45(1).zip 2013-12-28 21:42 - 2013-12-28 21:44 - 63443792 _____ C:\Users\Jacky\Downloads\thegameoflifedownload.exe 2013-12-26 21:59 - 2013-12-26 22:00 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-12-26 19:39 - 2013-12-26 19:39 - 02585872 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsInstaller-KB893803-v2-x86.exe 2013-12-26 11:19 - 2013-12-29 20:36 - 00000000 ____D C:\Program Files (x86)\directx 2013-12-26 11:19 - 2013-12-26 11:19 - 00000278 _____ C:\Windows\Directx.log 2013-12-25 21:07 - 2013-12-29 20:41 - 00000000 ____D C:\ProgramData\Windows Genuine Advantage 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck.exe 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(1).exe 2013-12-25 20:59 - 2013-12-25 20:59 - 02311827 _____ C:\Users\Jacky\Downloads\sdl3ewin.zip 2013-12-25 20:57 - 2013-12-25 20:57 - 00397154 _____ C:\Users\Jacky\Downloads\SpieldesLebensWin.zip 2013-12-25 20:53 - 2013-12-25 20:53 - 00002890 _____ C:\Windows\System32\Tasks\{E03E12C0-F94B-4CA6-A09A-515468D6FAA3} 2013-12-25 20:46 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp3f96eefeb2049202da2178bd45059162 2013-12-25 20:45 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\Downloads\Spiel-des-Lebens 2013-12-25 20:45 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\ChromeExtensions 2013-12-25 20:45 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp6ec2be2b619d18ef522057d14578d2f7 2013-12-25 20:45 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp52da00fd457103be90f4c5f287980f49 2013-12-25 20:45 - 2013-12-25 20:45 - 00943872 _____ C:\Users\Jacky\Downloads\Spiel-des-Lebens-Setup.exe 2013-12-25 20:41 - 2013-12-25 20:41 - 00003018 _____ C:\Windows\System32\Tasks\{476505DD-F30E-4FF4-8920-CB14D92EB605} 2013-12-25 20:29 - 2013-12-25 20:29 - 00003018 _____ C:\Windows\System32\Tasks\{01014E7C-EF80-4994-94A4-7882BBE1FC4D} 2013-12-25 20:03 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Zylom 2013-12-25 20:03 - 2013-12-29 09:40 - 00000000 ____D C:\Users\Jacky\AppData\Local\Zylom Games 2013-12-25 16:26 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Das Spiel des Lebens 2013-12-25 16:26 - 2013-12-29 20:36 - 00000000 ____D C:\Program Files (x86)\Das Spiel des Lebens 2013-12-25 16:22 - 2013-12-25 16:22 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p200715036_s2_l2.exe 2013-12-25 16:19 - 2013-12-25 16:19 - 00002890 _____ C:\Windows\System32\Tasks\{D5C4E481-AC90-46F2-A2E0-FC0AF1374D57} 2013-12-21 13:39 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Realore_Whiterra Roads Of Rome 3 2013-12-20 10:03 - 2013-12-29 20:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-15 11:33 - 2013-12-29 20:41 - 00000000 ____D C:\ProgramData\Sony 2013-12-15 11:33 - 2013-12-29 20:39 - 00000000 ____D C:\Program Files (x86)\Sony 2013-12-15 11:33 - 2013-12-15 11:36 - 00181280 _____ C:\Windows\DPINST.LOG 2013-12-15 11:33 - 2013-12-15 11:33 - 00002106 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2013-12-12 00:27 - 2013-11-26 11:18 - 00004096 ____N (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-12 00:27 - 2013-11-26 10:46 - 00048640 ____N (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-12 00:27 - 2013-11-26 10:18 - 00111616 ____N (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-12 00:27 - 2013-11-26 10:16 - 00708608 ____N (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-12 00:27 - 2013-11-26 09:28 - 00553472 ____N (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll ==================== One Month Modified Files and Folders ======= 2014-01-02 17:56 - 2014-01-02 17:56 - 00014812 _____ C:\Users\Jacky\Desktop\FRST.txt 2014-01-02 17:56 - 2014-01-02 17:56 - 00000000 ____D C:\Users\Jacky\Desktop\FRST-OlderVersion 2014-01-02 17:56 - 2013-12-30 16:42 - 00000000 ____D C:\FRST 2014-01-02 17:56 - 2013-12-30 16:40 - 01931426 _____ (Farbar) C:\Users\Jacky\Desktop\FRST64.exe 2014-01-02 17:52 - 2014-01-02 17:52 - 00001389 _____ C:\Users\Jacky\Desktop\JRT.txt 2014-01-02 17:51 - 2009-07-14 05:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-02 17:51 - 2009-07-14 05:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-02 17:48 - 2014-01-02 17:48 - 00000000 ____D C:\Windows\ERUNT 2014-01-02 17:48 - 2013-12-29 21:13 - 01788976 _____ C:\Windows\WindowsUpdate.log 2014-01-02 17:47 - 2014-01-02 17:47 - 01036305 _____ (Thisisu) C:\Users\Jacky\Desktop\JRT.exe 2014-01-02 17:46 - 2013-03-20 18:27 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-02 17:45 - 2014-01-02 17:45 - 00014460 _____ C:\Users\Jacky\Desktop\AdwCleaner[S0].txt 2014-01-02 17:45 - 2013-03-18 20:52 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2014-01-02 17:44 - 2013-05-22 16:18 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-02 17:44 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-02 17:44 - 2009-07-14 05:51 - 00634473 _____ C:\Windows\setupact.log 2014-01-02 17:42 - 2014-01-02 17:36 - 00000000 ____D C:\AdwCleaner 2014-01-02 17:42 - 2013-03-18 19:15 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-02 17:35 - 2014-01-02 17:35 - 01233962 _____ C:\Users\Jacky\Desktop\adwcleaner.exe 2014-01-02 17:30 - 2010-11-21 04:47 - 00068666 _____ C:\Windows\PFRO.log 2014-01-02 17:16 - 2014-01-02 17:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Malwarebytes 2014-01-02 17:15 - 2014-01-02 17:15 - 00000712 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-02 17:15 - 2014-01-02 17:15 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-02 17:15 - 2014-01-02 17:15 - 00000000 ____D C:\Malwarebytes' Anti-Malware 2014-01-02 16:44 - 2013-05-22 16:18 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-02 10:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2014-01-01 20:28 - 2011-05-16 16:15 - 00000000 ____D C:\Windows\system32\Drivers\tr-TR 2014-01-01 20:28 - 2011-05-16 14:57 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2014-01-01 20:28 - 2011-04-12 09:28 - 00000000 ____D C:\Program Files\Windows Journal 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\SysWOW64\winrm 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\SysWOW64\WCN 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\SysWOW64\sysprep 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\SysWOW64\slmgr 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\system32\winrm 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\system32\WCN 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\system32\slmgr 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Setup 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\oobe 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\MUI 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\com 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Setup 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\oobe 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\MUI 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\migwiz 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\com 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\servicing 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System 2014-01-01 20:27 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\sl-SI 2014-01-01 20:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sl-SI 2014-01-01 17:48 - 2011-05-16 15:04 - 00698006 _____ C:\Windows\system32\perfh007.dat 2014-01-01 17:48 - 2011-05-16 15:04 - 00148062 _____ C:\Windows\system32\perfc007.dat 2014-01-01 17:48 - 2009-07-14 06:13 - 04993660 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-01 17:20 - 2014-01-01 17:20 - 00029197 _____ C:\ComboFix.txt 2014-01-01 17:20 - 2014-01-01 17:10 - 00000000 ____D C:\Qoobox 2014-01-01 17:19 - 2014-01-01 17:09 - 00000000 ____D C:\Windows\erdnt 2014-01-01 17:17 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-01 17:08 - 2014-01-01 17:08 - 05160282 ____R (Swearware) C:\Users\Jacky\Desktop\ComboFix.exe 2014-01-01 16:20 - 2013-03-21 20:04 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.minecraft 2013-12-31 16:34 - 2013-12-31 16:34 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Need for Speed World 2013-12-31 16:00 - 2013-12-31 16:00 - 00000000 ____D C:\Users\Jacky\AppData\Local\Electronic_Arts_Inc 2013-12-31 16:00 - 2013-08-25 12:24 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-12-31 15:58 - 2013-08-25 12:24 - 00000000 ____D C:\Program Files (x86)\Origin 2013-12-31 15:45 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker 2013-12-31 15:38 - 2013-12-31 15:38 - 00001278 _____ C:\Users\Public\Desktop\Need for Speed World.lnk 2013-12-31 15:24 - 2013-03-20 20:24 - 00000000 ____D C:\Users\Jacky\Documents\Euro Truck Simulator 2 2013-12-31 09:44 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-30 21:15 - 2013-12-29 23:11 - 00000000 ___RD C:\Users\Jacky\Virtual Machines 2013-12-30 21:15 - 2013-12-29 21:24 - 00125128 _____ C:\Users\Jacky\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-30 21:15 - 2013-12-29 21:22 - 00001413 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-12-30 21:15 - 2013-12-29 21:21 - 00001447 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-30 21:15 - 2013-03-18 19:15 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-12-30 21:12 - 2009-07-14 05:45 - 00468576 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-30 21:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-30 20:16 - 2013-12-30 19:57 - 00013301 _____ C:\Windows\IE9_main.log 2013-12-30 20:01 - 2013-12-30 20:01 - 17847296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 12344320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-30 20:01 - 2013-12-30 20:01 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-30 20:01 - 2013-12-30 20:01 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-30 20:01 - 2013-12-30 20:01 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-30 20:01 - 2013-12-30 20:01 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-30 20:01 - 2013-12-30 20:01 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-30 20:01 - 2013-12-30 20:01 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-30 20:01 - 2013-12-30 20:01 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-30 20:01 - 2013-12-30 20:01 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-30 20:01 - 2013-12-30 20:01 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-30 20:01 - 2013-12-30 20:01 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-30 19:53 - 2013-12-30 19:43 - 00015787 _____ C:\Windows\IE10_main.log 2013-12-30 19:51 - 2013-12-30 19:51 - 00000134 _____ C:\Users\Jacky\Desktop\Internet Explorer-Problembehebung.url 2013-12-30 19:43 - 2013-12-30 19:42 - 51415040 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\IE10-Windows6.1-x64-de-de_b16521.exe 2013-12-30 19:38 - 2013-08-14 07:15 - 00000000 ____D C:\Windows\system32\MRT 2013-12-30 13:22 - 2013-12-30 13:21 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele Dirk 2013-12-30 13:22 - 2013-12-30 13:21 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele 2013-12-30 13:22 - 2013-03-18 20:55 - 00000000 ___RD C:\Users\Jacky\Desktop\Jacky 2013-12-30 13:20 - 2013-08-25 09:18 - 00000000 ____D C:\Users\Jacky\Desktop\Die Sims 3 (Download) 2013-12-30 13:20 - 2013-07-29 18:31 - 00000000 ____D C:\Users\Jacky\Desktop\BigFish 2013-12-30 13:18 - 2013-05-22 16:18 - 00000000 ____D C:\Program Files (x86)\Google 2013-12-30 10:11 - 2013-03-19 18:33 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-30 09:45 - 2013-12-30 09:45 - 00000000 ____D C:\Windows\PCHEALTH 2013-12-30 08:59 - 2013-10-28 15:50 - 00000000 ____D C:\Program Files (x86)\Steam 2013-12-30 05:16 - 2009-07-14 06:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2013-12-30 05:16 - 2009-07-14 06:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2013-12-30 05:15 - 2013-12-30 05:15 - 00262144 _____ C:\Windows\system32\config\userdiff 2013-12-30 04:51 - 2013-12-30 04:48 - 00000000 ____D C:\$INPLACE.~TR 2013-12-29 23:35 - 2013-12-29 23:25 - 486678800 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsXPMode_de-de.exe 2013-12-29 23:23 - 2013-12-29 23:23 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(4).exe 2013-12-29 23:11 - 2013-12-29 20:31 - 00000000 ____D C:\Users\Jacky 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\th-TH 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ro-RO 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\he-IL 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ar-SA 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Program Files (x86)\Windows Virtual PC 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\th-TH 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\ro-RO 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\he-IL 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\ar-SA 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\th-TH 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ro-RO 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\he-IL 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ar-SA 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(3).exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(2).exe 2013-12-29 21:33 - 2013-12-29 21:33 - 09566298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-12-29 21:19 - 2013-12-30 05:16 - 00000000 ____D C:\Windows\Panther 2013-12-29 21:19 - 2013-12-29 21:19 - 00000020 ___SH C:\Users\Jacky\ntuser.ini 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-12-29 21:19 - 2012-02-04 14:06 - 00000000 ____D C:\Recovery 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Recovery 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT 2013-12-29 21:16 - 2009-07-14 05:51 - 00000261 _____ C:\Windows\setuperr.log 2013-12-29 21:14 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\restore 2013-12-29 21:03 - 2013-12-30 04:55 - 00000000 ____D C:\$WINDOWS.~Q 2013-12-29 21:03 - 2013-12-29 19:25 - 00006155 _____ C:\Windows\comsetup.log 2013-12-29 21:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration 2013-12-29 20:59 - 2013-12-29 20:59 - 00022960 _____ C:\Windows\system32\emptyregdb.dat 2013-12-29 20:53 - 2013-04-26 19:01 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-12-29 20:53 - 2009-07-14 05:46 - 00005157 _____ C:\Windows\DtcInstall.log 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:51 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\Downloads\Spiel-des-Lebens 2013-12-29 20:51 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\ChromeExtensions 2013-12-29 20:51 - 2013-12-25 20:03 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Zylom 2013-12-29 20:51 - 2013-12-25 16:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Das Spiel des Lebens 2013-12-29 20:51 - 2013-12-21 13:39 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Realore_Whiterra Roads Of Rome 3 2013-12-29 20:51 - 2013-11-30 19:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Das Koenigreich der Kobolde 2013-12-29 20:51 - 2013-11-03 10:16 - 00000000 ____D C:\Users\Jacky\Downloads\Konto 2013-12-29 20:51 - 2013-10-29 13:53 - 00000000 ____D C:\Users\Jacky\Documents\My Games 2013-12-29 20:51 - 2013-10-21 10:08 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\PlayFirst 2013-12-29 20:51 - 2013-09-28 16:13 - 00000000 ____D C:\Users\Jacky\Downloads\ActiveSync 2013-12-29 20:51 - 2013-09-28 15:40 - 00000000 ____D C:\Users\Jacky\Documents\FalkData 2013-12-29 20:51 - 2013-09-22 19:21 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\PlayFavoriteGames 2013-12-29 20:51 - 2013-08-25 12:53 - 00000000 __RHD C:\Users\Jacky\AppData\Roaming\SecuROM 2013-12-29 20:51 - 2013-08-25 12:52 - 00000000 ____D C:\Users\Jacky\Documents\Electronic Arts 2013-12-29 20:51 - 2013-08-25 12:25 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Origin 2013-12-29 20:51 - 2013-07-29 19:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roads of Rome III 2013-12-29 20:51 - 2013-07-29 19:08 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Christmas Stories - Nussknacker Sammleredition 2013-12-29 20:51 - 2013-07-29 18:45 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Schloss ohne Traeume 2013-12-29 20:51 - 2013-07-29 18:42 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening 2 - Der Mondenwald 2013-12-29 20:51 - 2013-07-29 18:36 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\9 - The Dark Side Sammleredition 2013-12-29 20:51 - 2013-07-15 14:12 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1 Moment of Time - Silentville 2013-12-29 20:51 - 2013-05-25 17:01 - 00000000 ____D C:\Users\Jacky\Documents\BlackMirror2 2013-12-29 20:51 - 2013-05-25 17:01 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\ProtectDisc 2013-12-29 20:51 - 2013-05-09 09:13 - 00000000 ____D C:\Users\Jacky\Documents\My Cheat Tables 2013-12-29 20:51 - 2013-05-09 08:43 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Ubisoft 2013-12-29 20:51 - 2013-05-04 09:25 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2013-12-29 20:51 - 2013-04-26 18:46 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2013-12-29 20:51 - 2013-04-06 15:59 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Roxio 2013-12-29 20:51 - 2013-03-20 19:31 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mystery of the Ancients - Der Fluch des Schwarzen Wassers Sammleredition 2013-12-29 20:51 - 2013-03-20 19:05 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Party 2013-12-29 20:51 - 2013-03-20 17:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Nero 2013-12-29 20:51 - 2013-03-19 20:06 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Das Himmelsschloss Sammleredition 2013-12-29 20:51 - 2013-03-19 19:59 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\WinRAR 2013-12-29 20:51 - 2013-03-19 19:58 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-12-29 20:51 - 2013-03-19 18:45 - 00000000 ____D C:\Users\Jacky\Documents\DVDFab 2013-12-29 20:51 - 2013-03-18 20:21 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Mozilla 2013-12-29 20:50 - 2013-12-29 15:37 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Bonanza 2013-12-29 20:50 - 2013-12-29 13:36 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.technic 2013-12-29 20:50 - 2013-12-25 20:46 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp3f96eefeb2049202da2178bd45059162 2013-12-29 20:50 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp6ec2be2b619d18ef522057d14578d2f7 2013-12-29 20:50 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp52da00fd457103be90f4c5f287980f49 2013-12-29 20:50 - 2013-10-29 13:56 - 00000000 ____D C:\Users\Jacky\AppData\Local\Skyrim 2013-12-29 20:50 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\LavFilters 2013-12-29 20:50 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\CDXReader 2013-12-29 20:50 - 2013-10-18 14:32 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Elephant Games 2013-12-29 20:50 - 2013-10-17 19:30 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\AlawarEntertainment 2013-12-29 20:50 - 2013-09-16 16:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Artifex Mundi 2013-12-29 20:50 - 2013-08-25 12:25 - 00000000 ____D C:\Users\Jacky\AppData\Local\Origin 2013-12-29 20:50 - 2013-07-19 14:15 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\2monkeys 2013-12-29 20:50 - 2013-06-01 16:23 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\cerasus.media 2013-12-29 20:50 - 2013-05-09 09:03 - 00000000 ____D C:\Users\Jacky\AppData\Local\Ubisoft Game Launcher 2013-12-29 20:50 - 2013-05-07 14:14 - 00000000 ____D C:\Users\Jacky\AppData\Local\PunkBuster 2013-12-29 20:50 - 2013-04-09 18:38 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Apple Computer 2013-12-29 20:50 - 2013-04-06 16:06 - 00000000 ____D C:\Users\Jacky\AppData\Local\Power2Go8 2013-12-29 20:50 - 2013-04-01 14:41 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\HP 2013-12-29 20:50 - 2013-03-20 19:05 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\cef-cache 2013-12-29 20:50 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Macromedia 2013-12-29 20:50 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Adobe 2013-12-29 20:50 - 2013-03-20 17:52 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\CyberLink 2013-12-29 20:50 - 2013-03-20 16:40 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Boomzap 2013-12-29 20:50 - 2013-03-19 18:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\ATI 2013-12-29 20:50 - 2013-03-18 20:21 - 00000000 ____D C:\Users\Jacky\AppData\Local\Mozilla 2013-12-29 20:50 - 2013-03-18 19:15 - 00000000 ____D C:\Users\Jacky\AppData\Local\VirtualStore 2013-12-29 20:49 - 2013-05-22 16:18 - 00000000 ____D C:\Users\Jacky\AppData\Local\Google 2013-12-29 20:49 - 2013-05-04 09:30 - 00000000 ____D C:\Users\Jacky\AppData\Local\GamersFirst LIVE! 2013-12-29 20:49 - 2013-05-04 09:25 - 00000000 ____D C:\Users\Jacky\AppData\Local\GamersFirst 2013-12-29 20:49 - 2013-04-09 18:38 - 00000000 ____D C:\Users\Jacky\AppData\Local\Apple Computer 2013-12-29 20:49 - 2013-04-09 18:37 - 00000000 ____D C:\Users\Jacky\AppData\Local\Apple 2013-12-29 20:49 - 2013-04-01 14:35 - 00000000 ____D C:\Users\Jacky\AppData\Local\HP 2013-12-29 20:49 - 2013-04-01 14:13 - 00000000 ____D C:\Users\Jacky\AppData\Local\Adobe 2013-12-29 20:49 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Local\Macromedia 2013-12-29 20:49 - 2013-03-19 18:26 - 00000000 ____D C:\Users\Jacky\AppData\Local\ATI 2013-12-29 20:42 - 2013-12-29 16:17 - 00000000 ____D C:\Windows\pss 2013-12-29 20:42 - 2013-09-28 14:51 - 00000000 ____D C:\Windows\WindowsMobile 2013-12-29 20:42 - 2013-04-01 14:33 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-12-29 20:42 - 2013-03-20 18:27 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-12-29 20:42 - 2013-03-20 18:27 - 00000000 ____D C:\Windows\system32\Macromed 2013-12-29 20:42 - 2011-04-12 09:28 - 00000000 ____D C:\Windows\ShellNew 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-29 20:41 - 2013-12-25 21:07 - 00000000 ____D C:\ProgramData\Windows Genuine Advantage 2013-12-29 20:41 - 2013-12-15 11:33 - 00000000 ____D C:\ProgramData\Sony 2013-12-29 20:41 - 2013-11-15 15:30 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2013-12-29 20:41 - 2013-10-21 10:08 - 00000000 ____D C:\ProgramData\PlayFirst 2013-12-29 20:41 - 2013-08-25 12:24 - 00000000 ____D C:\ProgramData\Origin 2013-12-29 20:41 - 2013-07-23 07:43 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-12-29 20:41 - 2013-05-09 09:02 - 00000000 ____D C:\ProgramData\Solidshield 2013-12-29 20:41 - 2013-05-06 22:33 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-29 20:41 - 2013-04-06 15:58 - 00000000 ____D C:\ProgramData\Sonic 2013-12-29 20:41 - 2013-04-06 15:57 - 00000000 ____D C:\ProgramData\Roxio 2013-12-29 20:41 - 2013-04-01 14:41 - 00000000 ____D C:\ProgramData\WEBREG 2013-12-29 20:41 - 2013-03-20 18:31 - 00000000 ____D C:\ProgramData\Sun 2013-12-29 20:41 - 2013-03-20 18:13 - 00000000 ____D C:\ProgramData\vsosdk 2013-12-29 20:41 - 2013-03-20 17:52 - 00000000 ____D C:\Users\Public\CyberLink 2013-12-29 20:41 - 2013-03-20 17:24 - 00000000 ____D C:\ProgramData\Nero 2013-12-29 20:41 - 2013-03-18 20:52 - 00000000 ____D C:\Windows\ELAMBKUP 2013-12-29 20:41 - 2013-03-18 20:21 - 00000000 ____D C:\ProgramData\Mozilla 2013-12-29 20:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports 2013-12-29 20:40 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\Xvid 2013-12-29 20:40 - 2013-10-23 13:06 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-12-29 20:40 - 2013-10-19 13:16 - 00000000 ____D C:\ProgramData\DivX 2013-12-29 20:40 - 2013-10-18 14:32 - 00000000 ____D C:\ProgramData\Elephant Games 2013-12-29 20:40 - 2013-08-25 13:06 - 00000000 ____D C:\ProgramData\EA Core 2013-12-29 20:40 - 2013-05-26 08:58 - 00000000 ____D C:\ProgramData\GameHouse 2013-12-29 20:40 - 2013-05-09 08:22 - 00000000 ____D C:\Program Files (x86)\Ubisoft 2013-12-29 20:40 - 2013-04-11 17:54 - 00000000 ____D C:\ProgramData\McAfee 2013-12-29 20:40 - 2013-04-09 18:38 - 00000000 ____D C:\ProgramData\Apple Computer 2013-12-29 20:40 - 2013-04-09 18:36 - 00000000 ____D C:\ProgramData\Apple 2013-12-29 20:40 - 2013-04-06 15:59 - 00000000 ____D C:\ProgramData\InstallShield 2013-12-29 20:40 - 2013-04-01 14:33 - 00000000 ____D C:\ProgramData\HP Product Assistant 2013-12-29 20:40 - 2013-04-01 14:29 - 00000000 ____D C:\ProgramData\HP 2013-12-29 20:40 - 2013-03-27 07:08 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2013-12-29 20:40 - 2013-03-20 18:26 - 00000000 ____D C:\ProgramData\Adobe 2013-12-29 20:40 - 2013-03-20 17:51 - 00000000 ____D C:\ProgramData\CyberLink 2013-12-29 20:40 - 2013-03-20 17:48 - 00000000 ____D C:\ProgramData\install_clap 2013-12-29 20:40 - 2013-03-19 18:45 - 00000000 ____D C:\ProgramData\dvdfab 2013-12-29 20:40 - 2013-03-19 18:26 - 00000000 ____D C:\ProgramData\ATI 2013-12-29 20:39 - 2013-12-15 11:33 - 00000000 ____D C:\Program Files (x86)\Sony 2013-12-29 20:39 - 2013-08-25 12:41 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-12-29 20:39 - 2013-07-29 19:16 - 00000000 ____D C:\Program Files (x86)\Roads of Rome III 2013-12-29 20:39 - 2013-05-26 08:50 - 00000000 ____D C:\Program Files (x86)\Online Games Manager 2013-12-29 20:39 - 2013-05-26 08:49 - 00000000 ____D C:\Program Files (x86)\RealArcade 2013-12-29 20:39 - 2013-05-06 22:25 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-12-29 20:39 - 2013-04-06 15:57 - 00000000 ____D C:\Program Files (x86)\Roxio 2013-12-29 20:39 - 2013-03-20 19:31 - 00000000 ____D C:\Program Files (x86)\Mystery of the Ancients - Der Fluch des Schwarzen Wassers Sammleredition 2013-12-29 20:39 - 2013-03-20 17:25 - 00000000 ____D C:\Program Files (x86)\Nero 2013-12-29 20:39 - 2013-03-18 20:14 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-12-29 20:38 - 2013-12-20 10:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-29 20:38 - 2013-10-22 19:21 - 00000000 ____D C:\Program Files (x86)\Java 2013-12-29 20:38 - 2013-10-19 13:16 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-12-29 20:38 - 2013-10-09 10:27 - 00000000 ____D C:\Program Files (x86)\MAESTIA 2013-12-29 20:38 - 2013-09-17 08:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-12-29 20:38 - 2013-04-26 18:50 - 00000000 ____D C:\Program Files (x86)\LucasArts 2013-12-29 20:38 - 2013-04-01 14:30 - 00000000 ____D C:\Program Files (x86)\HP 2013-12-29 20:38 - 2013-03-19 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Works 2013-12-29 20:38 - 2013-03-19 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 2013-12-29 20:38 - 2013-03-19 18:34 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8 2013-12-29 20:38 - 2013-03-19 18:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-12-29 20:38 - 2013-03-18 20:52 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2013-12-29 20:38 - 2013-03-18 20:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-29 20:38 - 2013-03-18 20:14 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-29 20:38 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\MSBuild 2013-12-29 20:37 - 2013-04-26 18:46 - 00000000 ____D C:\Program Files (x86)\GameSpy Arcade 2013-12-29 20:36 - 2013-12-26 11:19 - 00000000 ____D C:\Program Files (x86)\directx 2013-12-29 20:36 - 2013-12-25 16:26 - 00000000 ____D C:\Program Files (x86)\Das Spiel des Lebens 2013-12-29 20:36 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\ffdshow 2013-12-29 20:36 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\DirectVobSub 2013-12-29 20:36 - 2013-10-19 13:16 - 00000000 ____D C:\Program Files (x86)\DSP-worx 2013-12-29 20:36 - 2013-09-28 16:13 - 00000000 ____D C:\Program Files (x86)\Falk 2013-12-29 20:36 - 2013-08-25 12:15 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-12-29 20:36 - 2013-06-01 15:57 - 00000000 ____D C:\Program Files (x86)\Dark Mysteries - Der Seelensammler 2013-12-29 20:36 - 2013-05-26 09:02 - 00000000 ____D C:\Program Files (x86)\dtp 2013-12-29 20:36 - 2013-05-06 19:37 - 00000000 ____D C:\Program Files (x86)\GamersFirst 2013-12-29 20:36 - 2013-04-06 15:57 - 00000000 ____D C:\Program Files (x86)\DivX 2013-12-29 20:36 - 2013-03-20 20:22 - 00000000 ____D C:\Program Files (x86)\Euro Truck Simulator 2 2013-12-29 20:36 - 2013-03-19 18:45 - 00000000 ____D C:\Program Files (x86)\DVDFab 8 Qt 2013-12-29 20:35 - 2013-11-30 19:51 - 00000000 ____D C:\Program Files (x86)\Awakening - Das Koenigreich der Kobolde 2013-12-29 20:35 - 2013-11-15 15:31 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-12-29 20:35 - 2013-11-15 15:20 - 00000000 ____D C:\Program Files\SmartPCFixer 2013-12-29 20:35 - 2013-10-29 17:39 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories 2013-12-29 20:35 - 2013-10-23 13:06 - 00000000 ____D C:\Program Files\iTunes 2013-12-29 20:35 - 2013-10-23 13:06 - 00000000 ____D C:\Program Files\iPod 2013-12-29 20:35 - 2013-10-19 13:18 - 00000000 ____D C:\Program Files\DivX 2013-12-29 20:35 - 2013-09-17 08:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-12-29 20:35 - 2013-09-07 19:09 - 00000000 ____D C:\Program Files (x86)\Anno 1701 2013-12-29 20:35 - 2013-07-29 19:08 - 00000000 ____D C:\Program Files (x86)\Christmas Stories - Nussknacker Sammleredition 2013-12-29 20:35 - 2013-07-29 18:45 - 00000000 ____D C:\Program Files (x86)\Awakening - Schloss ohne Traeume 2013-12-29 20:35 - 2013-07-29 18:42 - 00000000 ____D C:\Program Files (x86)\Awakening 2 - Der Mondenwald 2013-12-29 20:35 - 2013-07-29 18:36 - 00000000 ____D C:\Program Files (x86)\9 - The Dark Side Sammleredition 2013-12-29 20:35 - 2013-07-15 14:12 - 00000000 ____D C:\Program Files (x86)\1 Moment of Time - Silentville 2013-12-29 20:35 - 2013-05-23 17:44 - 00000000 ____D C:\Program Files (x86)\Black Mirror 2 2013-12-29 20:35 - 2013-05-09 08:29 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.2 2013-12-29 20:35 - 2013-04-06 15:59 - 00000000 ____D C:\Program Files\Roxio 2013-12-29 20:35 - 2013-04-01 14:10 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-12-29 20:35 - 2013-03-19 20:06 - 00000000 ____D C:\Program Files (x86)\Awakening - Das Himmelsschloss Sammleredition 2013-12-29 20:35 - 2013-03-19 19:58 - 00000000 ____D C:\Program Files\WinRAR 2013-12-29 20:35 - 2013-03-19 19:53 - 00000000 ____D C:\Program Files (x86)\bfgclient 2013-12-29 20:35 - 2013-03-19 18:34 - 00000000 ____D C:\Program Files\Microsoft Office 2013-12-29 20:35 - 2013-03-19 18:23 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-12-29 20:35 - 2013-03-19 18:22 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:21 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:20 - 00000000 ____D C:\Program Files\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:20 - 00000000 ____D C:\Program Files\ATI 2013-12-29 20:35 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Vorlagen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Startmenü 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Netzwerkumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Lokale Einstellungen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Eigene Dateien 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Druckumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Musik 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Bilder 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Verlauf 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Anwendungsdaten 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Anwendungsdaten 2013-12-29 20:30 - 2013-12-29 20:30 - 00001355 _____ C:\Windows\TSSysprep.log 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-12-29 19:44 - 2013-03-18 18:53 - 01852960 _____ C:\Windows\WindowsUpdate (1).log 2013-12-29 19:04 - 2013-12-29 18:57 - 00013897 _____ C:\Windows\diagwrn.xml 2013-12-29 19:04 - 2013-12-29 18:57 - 00001890 _____ C:\Windows\diagerr.xml 2013-12-29 13:36 - 2013-12-29 13:36 - 02304092 _____ () C:\Users\Jacky\Downloads\TechnicLauncher.exe 2013-12-29 10:15 - 2013-12-29 10:15 - 02014840 _____ (DriverBoost) C:\Users\Jacky\Downloads\DriverBoostPro_Setup.exe 2013-12-29 10:12 - 2013-12-29 10:12 - 08054042 _____ C:\Users\Jacky\Downloads\windowsinstaller45(1).zip 2013-12-29 09:40 - 2013-12-25 20:03 - 00000000 ____D C:\Users\Jacky\AppData\Local\Zylom Games 2013-12-28 21:44 - 2013-12-28 21:42 - 63443792 _____ C:\Users\Jacky\Downloads\thegameoflifedownload.exe 2013-12-26 22:00 - 2013-12-26 21:59 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-12-26 19:39 - 2013-12-26 19:39 - 02585872 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsInstaller-KB893803-v2-x86.exe 2013-12-26 11:19 - 2013-12-26 11:19 - 00000278 _____ C:\Windows\Directx.log 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck.exe 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(1).exe 2013-12-25 20:59 - 2013-12-25 20:59 - 02311827 _____ C:\Users\Jacky\Downloads\sdl3ewin.zip 2013-12-25 20:57 - 2013-12-25 20:57 - 00397154 _____ C:\Users\Jacky\Downloads\SpieldesLebensWin.zip 2013-12-25 20:53 - 2013-12-25 20:53 - 00002890 _____ C:\Windows\System32\Tasks\{E03E12C0-F94B-4CA6-A09A-515468D6FAA3} 2013-12-25 20:45 - 2013-12-25 20:45 - 00943872 _____ C:\Users\Jacky\Downloads\Spiel-des-Lebens-Setup.exe 2013-12-25 20:41 - 2013-12-25 20:41 - 00003018 _____ C:\Windows\System32\Tasks\{476505DD-F30E-4FF4-8920-CB14D92EB605} 2013-12-25 20:29 - 2013-12-25 20:29 - 00003018 _____ C:\Windows\System32\Tasks\{01014E7C-EF80-4994-94A4-7882BBE1FC4D} 2013-12-25 16:22 - 2013-12-25 16:22 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p200715036_s2_l2.exe 2013-12-25 16:19 - 2013-12-25 16:19 - 00002890 _____ C:\Windows\System32\Tasks\{D5C4E481-AC90-46F2-A2E0-FC0AF1374D57} 2013-12-25 09:03 - 2011-02-19 22:51 - 00608080 _____ (Microsoft Corporation) C:\Windows\system32\msvcp100.dll 2013-12-25 09:03 - 2011-02-19 00:52 - 00829264 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100.dll 2013-12-19 08:27 - 2013-03-20 19:09 - 00001525 _____ C:\Users\Jacky\Desktop\PartyCasino.lnk 2013-12-19 08:24 - 2013-03-20 19:05 - 00001531 _____ C:\Users\Jacky\Desktop\partypoker.lnk 2013-12-15 11:36 - 2013-12-15 11:33 - 00181280 _____ C:\Windows\DPINST.LOG 2013-12-15 11:33 - 2013-12-15 11:33 - 00002106 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2013-12-11 18:46 - 2013-03-20 18:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 18:46 - 2013-03-20 18:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-11 18:46 - 2013-03-20 18:27 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-11 08:58 - 2012-08-02 15:09 - 00029792 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys 2013-12-11 08:58 - 2012-06-19 17:28 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2013-12-07 19:39 - 2013-05-22 16:18 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-07 19:39 - 2013-05-22 16:18 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore Files to move or delete: ==================== C:\Users\Jacky\Firefox Setup 19.0.2.exe Some content of TEMP: ==================== C:\Users\Jacky\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-31 10:20 ==================== End Of Log ============================ |
03.01.2014, 12:34 | #10 |
/// the machine /// TB-Ausbilder | PC bereinigen und schneller machenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.01.2014, 23:05 | #11 |
| PC bereinigen und schneller machen Und die nächsten ;-). Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=e4eb84802cfda34b920a1e04a757f3d6 # engine=16505 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-03 09:34:55 # local_time=2014-01-03 10:34:55 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1286 16777213 100 98 47391 43551217 0 0 # compatibility_mode=5893 16776574 100 94 180371 140414745 0 0 # scanned=631947 # found=0 # cleaned=0 # scan_time=16873 Code:
ATTFilter Results of screen317's Security Check version 0.99.78 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Internet Security Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 45 Adobe Flash Player 11.9.900.170 Adobe Reader XI Mozilla Firefox (26.0) ````````Process Check: objlist.exe by Laurent```````` Online Games Manager ogmservice.exe Kaspersky Lab Kaspersky Internet Security 2013 avp.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-01-2014 Ran by Jacky (administrator) on JACKY-PC on 03-01-2014 22:57:43 Running from C:\Users\Jacky\Desktop\Bereiniger Logs Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (RealNetworks, Inc.) C:\Program Files (x86)\Online Games Manager\ogmservice.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (GamersFirst) C:\Users\Jacky\AppData\Local\GamersFirst\LIVE!\Live.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\Run: [RoxWatchTray] - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [221184 2006-10-27] (Sonic Solutions) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-13] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Startup: C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk ShortcutTarget: GamersFirst LIVE!.lnk -> C:\Users\Jacky\AppData\Local\GamersFirst\LIVE!\Live.exe (GamersFirst) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x87B9B8029C05CF01 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Amazon-Icon - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\amazon-icon@giga.de FF Extension: ReloadEvery - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi FF Extension: New Tab - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{C4A4F5A0-4B89-4392-AFAC-D58010E349AF}.xpi FF Extension: BonanzaDeals - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}.xpi FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Jacky\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) R2 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [559552 2013-08-08] (RealNetworks, Inc.) ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-09-07] () R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-10-10] (Kaspersky Lab ZAO) S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-19] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-04-24] (Kaspersky Lab ZAO) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-09-07] () S1 RxFilter; C:\Windows\SysWow64\DRIVERS\RxFilter.sys [58880 2006-10-27] (Sonic Solutions) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-03 22:57 - 2014-01-03 22:57 - 00000868 _____ C:\Users\Jacky\Desktop\checkup.txt 2014-01-03 22:42 - 2014-01-03 22:42 - 00987410 _____ C:\Users\Jacky\Desktop\SecurityCheck.exe 2014-01-03 17:50 - 2014-01-03 17:50 - 02347384 _____ (ESET) C:\Users\Jacky\Desktop\esetsmartinstaller_enu.exe 2014-01-02 17:48 - 2014-01-02 17:48 - 00000000 ____D C:\Windows\ERUNT 2014-01-02 17:36 - 2014-01-02 17:42 - 00000000 ____D C:\AdwCleaner 2014-01-02 17:16 - 2014-01-02 17:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Malwarebytes 2014-01-02 17:15 - 2014-01-02 17:15 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-02 17:15 - 2014-01-02 17:15 - 00000000 ____D C:\Malwarebytes' Anti-Malware 2014-01-02 17:15 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-01 17:20 - 2014-01-01 17:20 - 00029197 _____ C:\ComboFix.txt 2014-01-01 17:10 - 2014-01-01 17:20 - 00000000 ____D C:\Qoobox 2014-01-01 17:10 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-01 17:10 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-01 17:10 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-01 17:10 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-01 17:10 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-01 17:10 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-01 17:10 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-01 17:10 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-01 17:09 - 2014-01-01 17:19 - 00000000 ____D C:\Windows\erdnt 2013-12-31 16:34 - 2013-12-31 16:34 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Need for Speed World 2013-12-31 16:00 - 2013-12-31 16:00 - 00000000 ____D C:\Users\Jacky\AppData\Local\Electronic_Arts_Inc 2013-12-31 15:38 - 2013-12-31 15:38 - 00001278 _____ C:\Users\Public\Desktop\Need for Speed World.lnk 2013-12-30 21:29 - 2011-03-25 04:29 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-12-30 21:29 - 2011-03-25 04:29 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-12-30 21:29 - 2011-03-25 04:29 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-12-30 21:29 - 2011-03-25 04:29 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-12-30 21:29 - 2011-03-25 04:29 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-12-30 21:29 - 2011-03-25 04:29 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-12-30 21:29 - 2011-03-25 04:28 - 00007936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-12-30 21:29 - 2011-02-25 07:19 - 02871808 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-12-30 21:29 - 2011-02-25 06:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2013-12-30 21:28 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2013-12-30 21:28 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe 2013-12-30 21:28 - 2011-03-11 07:41 - 00410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys 2013-12-30 21:28 - 2011-03-11 07:41 - 00189824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2013-12-30 21:28 - 2011-03-11 07:41 - 00166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys 2013-12-30 21:28 - 2011-03-11 07:41 - 00148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys 2013-12-30 21:28 - 2011-03-11 07:41 - 00107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys 2013-12-30 21:28 - 2011-03-11 07:41 - 00027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys 2013-12-30 21:28 - 2011-03-11 07:33 - 02565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2013-12-30 21:28 - 2011-03-11 07:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe 2013-12-30 21:28 - 2011-03-11 06:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll 2013-12-30 21:28 - 2011-03-11 06:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe 2013-12-30 21:28 - 2011-03-11 05:37 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2013-12-30 20:55 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-30 20:55 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-30 20:55 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-30 20:55 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 17847296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 12344320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-30 20:01 - 2013-12-30 20:01 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-30 20:01 - 2013-12-30 20:01 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-30 20:01 - 2013-12-30 20:01 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-30 20:01 - 2013-12-30 20:01 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-30 20:01 - 2013-12-30 20:01 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-30 20:01 - 2013-12-30 20:01 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-30 20:01 - 2013-12-30 20:01 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-30 20:01 - 2013-12-30 20:01 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-30 20:01 - 2013-12-30 20:01 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-30 20:01 - 2013-12-30 20:01 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-30 19:57 - 2013-12-30 20:16 - 00013301 _____ C:\Windows\IE9_main.log 2013-12-30 19:51 - 2013-12-30 19:51 - 00000134 _____ C:\Users\Jacky\Desktop\Internet Explorer-Problembehebung.url 2013-12-30 19:43 - 2013-12-30 19:53 - 00015787 _____ C:\Windows\IE10_main.log 2013-12-30 19:42 - 2013-12-30 19:43 - 51415040 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\IE10-Windows6.1-x64-de-de_b16521.exe 2013-12-30 19:36 - 2013-12-01 14:42 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-30 16:42 - 2014-01-03 22:57 - 00000000 ____D C:\FRST 2013-12-30 13:21 - 2013-12-30 13:22 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele Dirk 2013-12-30 13:21 - 2013-12-30 13:22 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele 2013-12-30 12:31 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-30 12:31 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-30 12:31 - 2011-06-16 06:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll 2013-12-30 12:31 - 2011-06-16 05:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll 2013-12-30 12:31 - 2011-06-15 11:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll 2013-12-30 12:31 - 2011-06-15 11:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll 2013-12-30 12:31 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll 2013-12-30 12:31 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll 2013-12-30 12:31 - 2011-06-15 09:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll 2013-12-30 12:31 - 2011-06-15 09:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll 2013-12-30 12:31 - 2011-06-15 09:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll 2013-12-30 12:31 - 2011-06-15 09:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll 2013-12-30 12:31 - 2011-06-15 09:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll 2013-12-30 12:31 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2013-12-30 12:31 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2013-12-30 12:30 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-30 12:30 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-30 12:30 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-30 12:30 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-30 12:30 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-12-30 12:30 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-12-30 12:30 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-12-30 12:30 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-12-30 12:30 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-12-30 12:30 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-12-30 12:30 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-12-30 12:30 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-12-30 12:30 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-12-30 12:30 - 2013-04-12 15:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-12-30 12:30 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2013-12-30 12:30 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2013-12-30 12:30 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2013-12-30 12:30 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2013-12-30 12:30 - 2011-12-30 07:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl 2013-12-30 12:30 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl 2013-12-30 12:29 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-30 12:29 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-30 12:29 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-12-30 12:29 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-12-30 12:29 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-12-30 12:29 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-12-30 12:29 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-12-30 12:25 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-12-30 12:25 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2013-12-30 12:25 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2013-12-30 12:25 - 2012-11-28 23:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2013-12-30 12:22 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-12-30 12:22 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-12-30 12:22 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-12-30 12:22 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-12-30 12:22 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-12-30 12:22 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-12-30 12:22 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-12-30 12:22 - 2013-02-15 07:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-12-30 12:22 - 2013-02-15 07:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-12-30 12:22 - 2013-02-15 07:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-12-30 12:22 - 2013-02-15 05:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-12-30 12:22 - 2013-02-15 05:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-12-30 12:22 - 2013-02-15 04:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-12-30 12:22 - 2011-10-26 06:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2013-12-30 12:22 - 2011-10-26 06:25 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-12-30 12:22 - 2011-10-26 05:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2013-12-30 12:22 - 2011-10-26 05:32 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-12-30 12:19 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-12-30 12:19 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-12-30 12:19 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-12-30 12:19 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2013-12-30 12:19 - 2010-12-23 11:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll 2013-12-30 12:19 - 2010-12-23 11:42 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2013-12-30 12:19 - 2010-12-23 11:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax 2013-12-30 12:19 - 2010-12-23 06:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll 2013-12-30 12:19 - 2010-12-23 06:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2013-12-30 12:19 - 2010-12-23 06:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax 2013-12-30 12:18 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-30 12:18 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-12-30 12:18 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-12-30 12:18 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-12-30 12:18 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-12-30 12:18 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-12-30 12:18 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-12-30 12:18 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-12-30 12:18 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-12-30 12:18 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-12-30 12:18 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-12-30 12:18 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-12-30 12:18 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-12-30 12:18 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-12-30 12:18 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-12-30 12:18 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-12-30 12:18 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-12-30 12:18 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-12-30 12:18 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-12-30 12:18 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-12-30 12:18 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-12-30 12:18 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-12-30 12:18 - 2013-02-27 07:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-12-30 12:18 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo |
03.01.2014, 23:07 | #12 |
| PC bereinigen und schneller machen FRST Log Teil 2 Code:
ATTFilter 2013-12-30 12:18 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2013-12-30 12:18 - 2012-01-04 11:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll 2013-12-30 12:18 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2013-12-30 12:18 - 2011-11-17 07:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2013-12-30 12:18 - 2011-11-17 06:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2013-12-30 12:18 - 2011-07-09 03:46 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2013-12-30 12:18 - 2011-05-04 06:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2013-12-30 12:18 - 2011-05-04 06:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2013-12-30 12:18 - 2011-05-04 06:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2013-12-30 12:18 - 2011-05-04 06:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2013-12-30 12:18 - 2011-05-04 06:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2013-12-30 12:18 - 2011-05-04 06:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2013-12-30 12:18 - 2011-05-04 06:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2013-12-30 12:18 - 2011-05-04 06:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2013-12-30 12:18 - 2011-05-04 06:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2013-12-30 12:18 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-12-30 12:18 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-12-30 12:18 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-12-30 12:18 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-12-30 12:18 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-12-30 12:18 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2013-12-30 12:18 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-12-30 12:18 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-12-30 12:18 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-12-30 12:18 - 2011-04-27 03:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2013-12-30 12:18 - 2011-04-27 03:39 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2013-12-30 12:17 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-12-30 12:17 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-12-30 12:17 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-12-30 12:17 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-12-30 12:17 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-12-30 12:17 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-12-30 12:17 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-12-30 12:17 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-12-30 12:17 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-12-30 12:17 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-12-30 12:17 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-12-30 12:17 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-12-30 12:17 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-12-30 12:17 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-12-30 12:17 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-12-30 12:17 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-12-30 12:17 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-12-30 12:17 - 2012-11-01 06:43 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2013-12-30 12:17 - 2012-11-01 06:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2013-12-30 12:17 - 2012-11-01 05:47 - 01389568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2013-12-30 12:17 - 2012-11-01 05:47 - 01236992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2013-12-30 12:17 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2013-12-30 12:17 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2013-12-30 12:17 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2013-12-30 12:17 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2013-12-30 12:17 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2013-12-30 12:17 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2013-12-30 12:17 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2013-12-30 12:17 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2013-12-30 12:17 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2013-12-30 12:17 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2013-12-30 12:17 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-12-30 12:17 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2013-12-30 12:17 - 2012-05-01 06:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2013-12-30 12:17 - 2012-04-26 06:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2013-12-30 12:17 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2013-12-30 12:17 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2013-12-30 12:17 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2013-12-30 12:17 - 2011-03-11 07:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2013-12-30 12:17 - 2011-03-11 07:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2013-12-30 12:17 - 2011-03-11 06:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2013-12-30 12:17 - 2011-03-11 06:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2013-12-30 12:17 - 2011-03-03 07:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2013-12-30 12:17 - 2011-03-03 07:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2013-12-30 12:17 - 2011-03-03 07:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2013-12-30 12:17 - 2011-03-03 06:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2013-12-30 12:17 - 2011-03-03 06:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe 2013-12-30 12:17 - 2010-06-26 04:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2013-12-30 12:17 - 2010-06-26 04:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2013-12-30 12:15 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-12-30 12:15 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-12-30 12:15 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-12-30 12:15 - 2013-06-04 07:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-12-30 12:15 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-12-30 12:15 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2013-12-30 12:15 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2013-12-30 12:14 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-12-30 12:14 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2013-12-30 12:14 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2013-12-30 12:14 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2013-12-30 12:14 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2013-12-30 12:14 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2013-12-30 12:14 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2013-12-30 12:14 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2013-12-30 12:14 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2013-12-30 12:14 - 2012-11-22 06:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2013-12-30 12:14 - 2012-11-22 05:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2013-12-30 12:14 - 2011-04-29 04:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2013-12-30 12:14 - 2011-04-29 04:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2013-12-30 12:14 - 2011-04-29 04:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2013-12-30 12:12 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-12-30 12:12 - 2012-08-11 01:56 - 00715776 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2013-12-30 12:12 - 2012-08-11 00:56 - 00542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2013-12-30 12:12 - 2012-04-28 04:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2013-12-30 12:12 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2013-12-30 12:12 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2013-12-30 12:12 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll 2013-12-30 12:12 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax 2013-12-30 12:12 - 2011-04-22 23:15 - 00027520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2013-12-30 12:11 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-12-30 12:11 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-12-30 12:11 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-12-30 12:11 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-12-30 12:11 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-12-30 12:11 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-12-30 12:11 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-12-30 12:11 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-12-30 12:11 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-12-30 12:11 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-12-30 12:11 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-12-30 12:11 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-12-30 12:11 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-12-30 12:11 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-12-30 12:11 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-12-30 12:11 - 2012-04-07 13:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2013-12-30 12:11 - 2012-04-07 12:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2013-12-30 12:11 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2013-12-30 10:12 - 2012-11-30 06:45 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-12-30 10:12 - 2012-11-30 06:45 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-12-30 10:12 - 2012-11-30 06:43 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-12-30 10:12 - 2012-11-30 00:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2013-12-30 10:12 - 2012-11-30 00:15 - 00420064 _____ C:\Windows\system32\locale.nls 2013-12-30 10:11 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-12-30 10:11 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-12-30 10:11 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-12-30 10:11 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-12-30 10:11 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-12-30 10:11 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-12-30 10:11 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll 2013-12-30 10:11 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2013-12-30 10:11 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2013-12-30 10:11 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll 2013-12-30 10:11 - 2011-02-05 18:10 - 00642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-12-30 10:11 - 2011-02-05 18:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2013-12-30 10:11 - 2011-02-05 18:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2013-12-30 10:11 - 2011-02-05 18:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2013-12-30 10:11 - 2011-02-05 18:06 - 00605552 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-12-30 10:11 - 2011-02-05 18:06 - 00566208 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-12-30 10:11 - 2011-02-05 18:06 - 00518672 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-12-30 10:10 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-12-30 10:10 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-12-30 10:10 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-12-30 10:10 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-12-30 10:09 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-12-30 10:09 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-12-30 10:09 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-12-30 10:09 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-12-30 10:09 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2013-12-30 10:09 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2013-12-30 10:08 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-30 10:08 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-30 10:08 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-30 10:08 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-30 10:08 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-30 10:08 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-30 10:08 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-30 10:08 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-30 10:08 - 2013-08-27 10:01 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-12-30 10:08 - 2013-08-27 10:01 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-12-30 10:08 - 2013-08-27 09:21 - 01077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-12-30 10:08 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-12-30 10:08 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-12-30 10:08 - 2013-01-03 07:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2013-12-30 10:08 - 2012-08-22 19:12 - 00376688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2013-12-30 10:08 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2013-12-30 10:08 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll 2013-12-30 10:08 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll 2013-12-30 10:08 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2013-12-30 10:08 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2013-12-30 10:08 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2013-12-30 10:08 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2013-12-30 10:08 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2013-12-30 10:08 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2013-12-30 10:08 - 2011-08-27 06:37 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2013-12-30 10:08 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll 2013-12-30 10:08 - 2011-08-27 05:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2013-12-30 10:08 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll 2013-12-30 10:08 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2013-12-30 10:08 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll 2013-12-30 10:08 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll 2013-12-30 10:08 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll 2013-12-30 10:08 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe 2013-12-30 10:08 - 2011-05-03 06:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2013-12-30 10:08 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2013-12-30 10:08 - 2011-02-23 05:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2013-12-30 10:08 - 2011-02-18 11:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe 2013-12-30 10:08 - 2011-02-18 06:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe 2013-12-30 10:08 - 2011-02-12 12:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe 2013-12-30 10:07 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-12-30 10:07 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-12-30 10:07 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2013-12-30 10:07 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-12-30 09:45 - 2013-12-30 09:45 - 00000000 ____D C:\Windows\PCHEALTH 2013-12-30 09:45 - 2010-02-23 09:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe 2013-12-30 09:44 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2013-12-30 09:44 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2013-12-30 09:44 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2013-12-30 09:44 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2013-12-30 09:44 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2013-12-30 09:43 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2013-12-30 09:43 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2013-12-30 09:43 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2013-12-30 09:35 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-12-30 09:35 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-12-30 09:35 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-12-30 09:35 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-12-30 09:35 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-12-30 09:35 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2013-12-30 09:35 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2013-12-30 09:34 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-12-30 09:15 - 2011-11-19 15:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2013-12-30 09:15 - 2011-11-19 15:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2013-12-30 05:16 - 2013-12-29 21:19 - 00000000 ____D C:\Windows\Panther 2013-12-30 05:15 - 2013-12-30 05:15 - 00262144 _____ C:\Windows\system32\config\userdiff 2013-12-30 04:55 - 2013-12-29 21:03 - 00000000 ____D C:\$WINDOWS.~Q 2013-12-30 04:48 - 2013-12-30 04:51 - 00000000 ____D C:\$INPLACE.~TR 2013-12-29 23:25 - 2013-12-29 23:35 - 486678800 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsXPMode_de-de.exe 2013-12-29 23:23 - 2013-12-29 23:23 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(4).exe 2013-12-29 23:11 - 2013-12-30 21:15 - 00000000 ___RD C:\Users\Jacky\Virtual Machines 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\th-TH 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ro-RO 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\he-IL 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ar-SA 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Program Files (x86)\Windows Virtual PC 2013-12-29 23:01 - 2010-11-20 14:34 - 00360832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcvmm.sys 2013-12-29 23:01 - 2010-11-20 14:34 - 00194944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpchbus.sys 2013-12-29 23:01 - 2010-11-20 14:27 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\vpchbuspipe.dll 2013-12-29 23:01 - 2010-11-20 14:25 - 04514816 _____ (Microsoft Corporation) C:\Windows\system32\vpc.exe 2013-12-29 23:01 - 2010-11-20 14:25 - 02264064 _____ (Microsoft Corporation) C:\Windows\system32\VPCWizard.exe 2013-12-29 23:01 - 2010-11-20 14:25 - 01369600 _____ (Microsoft Corporation) C:\Windows\system32\VPCSettings.exe 2013-12-29 23:01 - 2010-11-20 12:37 - 01210368 _____ (Microsoft Corporation) C:\Windows\system32\VMWindow.exe 2013-12-29 23:01 - 2010-11-20 12:37 - 00936448 _____ (Microsoft Corporation) C:\Windows\system32\vmsal.exe 2013-12-29 23:01 - 2010-11-20 12:35 - 00562176 _____ (Microsoft Corporation) C:\Windows\system32\VMCPropertyHandler.dll 2013-12-29 23:01 - 2010-11-20 12:35 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcusb.sys 2013-12-29 23:01 - 2010-11-20 12:35 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcnfltr.sys 2013-12-29 23:01 - 2010-11-20 11:52 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vmsal.exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(3).exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(2).exe 2013-12-29 21:36 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2013-12-29 21:36 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2013-12-29 21:36 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2013-12-29 21:33 - 2013-12-29 21:33 - 09566298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-12-29 21:24 - 2013-12-30 21:15 - 00125128 _____ C:\Users\Jacky\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-29 21:22 - 2013-12-30 21:15 - 00001413 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-12-29 21:21 - 2013-12-30 21:15 - 00001447 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-29 21:21 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-12-29 21:21 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-12-29 21:21 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-12-29 21:21 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-12-29 21:20 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-12-29 21:20 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-12-29 21:20 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-12-29 21:19 - 2013-12-29 21:19 - 00000020 ___SH C:\Users\Jacky\ntuser.ini 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-12-29 21:16 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-12-29 21:16 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-12-29 21:13 - 2014-01-03 22:36 - 01853594 _____ C:\Windows\WindowsUpdate.log 2013-12-29 20:59 - 2013-12-29 20:59 - 00022960 _____ C:\Windows\system32\emptyregdb.dat 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-12-29 20:31 - 2013-12-29 23:11 - 00000000 ____D C:\Users\Jacky 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Vorlagen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Startmenü 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Netzwerkumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Lokale Einstellungen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Eigene Dateien 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Druckumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Musik 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Bilder 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Verlauf 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Anwendungsdaten 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Anwendungsdaten 2013-12-29 20:31 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:31 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:30 - 2013-12-29 20:30 - 00001355 _____ C:\Windows\TSSysprep.log 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-12-29 19:25 - 2013-12-29 21:03 - 00006155 _____ C:\Windows\comsetup.log 2013-12-29 18:57 - 2013-12-29 19:04 - 00013897 _____ C:\Windows\diagwrn.xml 2013-12-29 18:57 - 2013-12-29 19:04 - 00001890 _____ C:\Windows\diagerr.xml 2013-12-29 16:17 - 2013-12-29 20:42 - 00000000 ____D C:\Windows\pss 2013-12-29 15:37 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Bonanza 2013-12-29 13:36 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.technic 2013-12-29 13:36 - 2013-12-29 13:36 - 02304092 _____ () C:\Users\Jacky\Downloads\TechnicLauncher.exe 2013-12-29 10:15 - 2013-12-29 10:15 - 02014840 _____ (DriverBoost) C:\Users\Jacky\Downloads\DriverBoostPro_Setup.exe 2013-12-29 10:12 - 2013-12-29 10:12 - 08054042 _____ C:\Users\Jacky\Downloads\windowsinstaller45(1).zip 2013-12-28 21:42 - 2013-12-28 21:44 - 63443792 _____ C:\Users\Jacky\Downloads\thegameoflifedownload.exe 2013-12-26 21:59 - 2013-12-26 22:00 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-12-26 19:39 - 2013-12-26 19:39 - 02585872 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsInstaller-KB893803-v2-x86.exe 2013-12-26 11:19 - 2013-12-29 20:36 - 00000000 ____D C:\Program Files (x86)\directx 2013-12-26 11:19 - 2013-12-26 11:19 - 00000278 _____ C:\Windows\Directx.log 2013-12-25 21:07 - 2013-12-29 20:41 - 00000000 ____D C:\ProgramData\Windows Genuine Advantage 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck.exe 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(1).exe 2013-12-25 20:59 - 2013-12-25 20:59 - 02311827 _____ C:\Users\Jacky\Downloads\sdl3ewin.zip 2013-12-25 20:57 - 2013-12-25 20:57 - 00397154 _____ C:\Users\Jacky\Downloads\SpieldesLebensWin.zip 2013-12-25 20:53 - 2013-12-25 20:53 - 00002890 _____ C:\Windows\System32\Tasks\{E03E12C0-F94B-4CA6-A09A-515468D6FAA3} 2013-12-25 20:46 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp3f96eefeb2049202da2178bd45059162 2013-12-25 20:45 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\Downloads\Spiel-des-Lebens 2013-12-25 20:45 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\ChromeExtensions 2013-12-25 20:45 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp6ec2be2b619d18ef522057d14578d2f7 2013-12-25 20:45 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp52da00fd457103be90f4c5f287980f49 2013-12-25 20:45 - 2013-12-25 20:45 - 00943872 _____ C:\Users\Jacky\Downloads\Spiel-des-Lebens-Setup.exe 2013-12-25 20:41 - 2013-12-25 20:41 - 00003018 _____ C:\Windows\System32\Tasks\{476505DD-F30E-4FF4-8920-CB14D92EB605} 2013-12-25 20:29 - 2013-12-25 20:29 - 00003018 _____ C:\Windows\System32\Tasks\{01014E7C-EF80-4994-94A4-7882BBE1FC4D} 2013-12-25 20:03 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Zylom 2013-12-25 20:03 - 2013-12-29 09:40 - 00000000 ____D C:\Users\Jacky\AppData\Local\Zylom Games 2013-12-25 16:26 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Das Spiel des Lebens 2013-12-25 16:26 - 2013-12-29 20:36 - 00000000 ____D C:\Program Files (x86)\Das Spiel des Lebens 2013-12-25 16:22 - 2013-12-25 16:22 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p200715036_s2_l2.exe 2013-12-25 16:19 - 2013-12-25 16:19 - 00002890 _____ C:\Windows\System32\Tasks\{D5C4E481-AC90-46F2-A2E0-FC0AF1374D57} 2013-12-21 13:39 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Realore_Whiterra Roads Of Rome 3 2013-12-20 10:03 - 2013-12-29 20:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-15 11:33 - 2013-12-29 20:41 - 00000000 ____D C:\ProgramData\Sony 2013-12-15 11:33 - 2013-12-29 20:39 - 00000000 ____D C:\Program Files (x86)\Sony 2013-12-15 11:33 - 2013-12-15 11:36 - 00181280 _____ C:\Windows\DPINST.LOG 2013-12-15 11:33 - 2013-12-15 11:33 - 00002106 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2013-12-12 00:27 - 2013-11-26 11:18 - 00004096 ____N (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-12 00:27 - 2013-11-26 10:46 - 00048640 ____N (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-12 00:27 - 2013-11-26 10:18 - 00111616 ____N (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-12 00:27 - 2013-11-26 10:16 - 00708608 ____N (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-12 00:27 - 2013-11-26 09:28 - 00553472 ____N (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll ==================== One Month Modified Files and Folders ======= 2014-01-03 22:57 - 2014-01-03 22:57 - 00000868 _____ C:\Users\Jacky\Desktop\checkup.txt 2014-01-03 22:57 - 2013-12-30 16:42 - 00000000 ____D C:\FRST 2014-01-03 22:46 - 2013-03-20 18:27 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-03 22:44 - 2013-05-22 16:18 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-03 22:42 - 2014-01-03 22:42 - 00987410 _____ C:\Users\Jacky\Desktop\SecurityCheck.exe 2014-01-03 22:36 - 2013-12-29 21:13 - 01853594 _____ C:\Windows\WindowsUpdate.log 2014-01-03 21:21 - 2013-03-18 20:52 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2014-01-03 19:49 - 2009-07-14 05:51 - 00730289 _____ C:\Windows\setupact.log 2014-01-03 19:44 - 2013-05-22 16:18 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-03 17:50 - 2014-01-03 17:50 - 02347384 _____ (ESET) C:\Users\Jacky\Desktop\esetsmartinstaller_enu.exe 2014-01-03 09:32 - 2009-07-14 05:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-03 09:32 - 2009-07-14 05:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-03 09:24 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-02 17:48 - 2014-01-02 17:48 - 00000000 ____D C:\Windows\ERUNT 2014-01-02 17:42 - 2014-01-02 17:36 - 00000000 ____D C:\AdwCleaner 2014-01-02 17:42 - 2013-03-18 19:15 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-02 17:30 - 2010-11-21 04:47 - 00068666 _____ C:\Windows\PFRO.log 2014-01-02 17:16 - 2014-01-02 17:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Malwarebytes 2014-01-02 17:15 - 2014-01-02 17:15 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-02 17:15 - 2014-01-02 17:15 - 00000000 ____D C:\Malwarebytes' Anti-Malware 2014-01-02 10:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2014-01-01 20:28 - 2011-05-16 16:15 - 00000000 ____D C:\Windows\system32\Drivers\tr-TR 2014-01-01 20:28 - 2011-05-16 14:57 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2014-01-01 20:28 - 2011-04-12 09:28 - 00000000 ____D C:\Program Files\Windows Journal 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\SysWOW64\winrm 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\SysWOW64\WCN 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\SysWOW64\sysprep 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\SysWOW64\slmgr 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\system32\winrm 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\system32\WCN 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\system32\slmgr 2014-01-01 20:28 - 2011-04-12 09:17 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2014-01-01 20:28 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Setup 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\oobe 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\MUI 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\com 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Setup 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\oobe 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\MUI 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\migwiz 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\com 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\servicing 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME 2014-01-01 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System 2014-01-01 20:27 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\sl-SI 2014-01-01 20:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sl-SI 2014-01-01 17:48 - 2011-05-16 15:04 - 00698006 _____ C:\Windows\system32\perfh007.dat 2014-01-01 17:48 - 2011-05-16 15:04 - 00148062 _____ C:\Windows\system32\perfc007.dat 2014-01-01 17:48 - 2009-07-14 06:13 - 04993660 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-01 17:20 - 2014-01-01 17:20 - 00029197 _____ C:\ComboFix.txt 2014-01-01 17:20 - 2014-01-01 17:10 - 00000000 ____D C:\Qoobox 2014-01-01 17:19 - 2014-01-01 17:09 - 00000000 ____D C:\Windows\erdnt 2014-01-01 17:17 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-01 16:20 - 2013-03-21 20:04 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.minecraft 2013-12-31 16:34 - 2013-12-31 16:34 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Need for Speed World 2013-12-31 16:00 - 2013-12-31 16:00 - 00000000 ____D C:\Users\Jacky\AppData\Local\Electronic_Arts_Inc 2013-12-31 16:00 - 2013-08-25 12:24 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-12-31 15:58 - 2013-08-25 12:24 - 00000000 ____D C:\Program Files (x86)\Origin 2013-12-31 15:45 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker 2013-12-31 15:38 - 2013-12-31 15:38 - 00001278 _____ C:\Users\Public\Desktop\Need for Speed World.lnk 2013-12-31 15:24 - 2013-03-20 20:24 - 00000000 ____D C:\Users\Jacky\Documents\Euro Truck Simulator 2 2013-12-31 09:44 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-30 21:15 - 2013-12-29 23:11 - 00000000 ___RD C:\Users\Jacky\Virtual Machines 2013-12-30 21:15 - 2013-12-29 21:24 - 00125128 _____ C:\Users\Jacky\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-30 21:15 - 2013-12-29 21:22 - 00001413 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-12-30 21:15 - 2013-12-29 21:21 - 00001447 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-30 21:15 - 2013-03-18 19:15 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-12-30 21:12 - 2009-07-14 05:45 - 00468576 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-30 21:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-30 20:16 - 2013-12-30 19:57 - 00013301 _____ C:\Windows\IE9_main.log 2013-12-30 20:01 - 2013-12-30 20:01 - 17847296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 12344320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-30 20:01 - 2013-12-30 20:01 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-30 20:01 - 2013-12-30 20:01 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-30 20:01 - 2013-12-30 20:01 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-30 20:01 - 2013-12-30 20:01 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-30 20:01 - 2013-12-30 20:01 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-30 20:01 - 2013-12-30 20:01 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-30 20:01 - 2013-12-30 20:01 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-30 20:01 - 2013-12-30 20:01 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-30 20:01 - 2013-12-30 20:01 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-30 20:01 - 2013-12-30 20:01 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-30 20:01 - 2013-12-30 20:01 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-30 20:01 - 2013-12-30 20:01 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-30 19:53 - 2013-12-30 19:43 - 00015787 _____ C:\Windows\IE10_main.log 2013-12-30 19:51 - 2013-12-30 19:51 - 00000134 _____ C:\Users\Jacky\Desktop\Internet Explorer-Problembehebung.url 2013-12-30 19:43 - 2013-12-30 19:42 - 51415040 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\IE10-Windows6.1-x64-de-de_b16521.exe 2013-12-30 19:38 - 2013-08-14 07:15 - 00000000 ____D C:\Windows\system32\MRT 2013-12-30 13:22 - 2013-12-30 13:21 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele Dirk 2013-12-30 13:22 - 2013-12-30 13:21 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele 2013-12-30 13:22 - 2013-03-18 20:55 - 00000000 ___RD C:\Users\Jacky\Desktop\Jacky 2013-12-30 13:20 - 2013-08-25 09:18 - 00000000 ____D C:\Users\Jacky\Desktop\Die Sims 3 (Download) 2013-12-30 13:20 - 2013-07-29 18:31 - 00000000 ____D C:\Users\Jacky\Desktop\BigFish 2013-12-30 13:18 - 2013-05-22 16:18 - 00000000 ____D C:\Program Files (x86)\Google 2013-12-30 10:11 - 2013-03-19 18:33 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-30 09:45 - 2013-12-30 09:45 - 00000000 ____D C:\Windows\PCHEALTH 2013-12-30 08:59 - 2013-10-28 15:50 - 00000000 ____D C:\Program Files (x86)\Steam 2013-12-30 05:16 - 2009-07-14 06:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2013-12-30 05:16 - 2009-07-14 06:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2013-12-30 05:15 - 2013-12-30 05:15 - 00262144 _____ C:\Windows\system32\config\userdiff 2013-12-30 04:51 - 2013-12-30 04:48 - 00000000 ____D C:\$INPLACE.~TR 2013-12-29 23:35 - 2013-12-29 23:25 - 486678800 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsXPMode_de-de.exe 2013-12-29 23:23 - 2013-12-29 23:23 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(4).exe 2013-12-29 23:11 - 2013-12-29 20:31 - 00000000 ____D C:\Users\Jacky 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\th-TH 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ro-RO 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\he-IL 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ar-SA 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Program Files (x86)\Windows Virtual PC 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\th-TH 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\ro-RO 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\he-IL 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\ar-SA 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\th-TH 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ro-RO 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\he-IL 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ar-SA 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(3).exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(2).exe 2013-12-29 21:33 - 2013-12-29 21:33 - 09566298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-12-29 21:19 - 2013-12-30 05:16 - 00000000 ____D C:\Windows\Panther 2013-12-29 21:19 - 2013-12-29 21:19 - 00000020 ___SH C:\Users\Jacky\ntuser.ini 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-12-29 21:19 - 2012-02-04 14:06 - 00000000 ____D C:\Recovery 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Recovery 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT 2013-12-29 21:16 - 2009-07-14 05:51 - 00000261 _____ C:\Windows\setuperr.log 2013-12-29 21:14 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\restore 2013-12-29 21:03 - 2013-12-30 04:55 - 00000000 ____D C:\$WINDOWS.~Q 2013-12-29 21:03 - 2013-12-29 19:25 - 00006155 _____ C:\Windows\comsetup.log 2013-12-29 21:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration 2013-12-29 20:59 - 2013-12-29 20:59 - 00022960 _____ C:\Windows\system32\emptyregdb.dat 2013-12-29 20:53 - 2013-04-26 19:01 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-12-29 20:53 - 2009-07-14 05:46 - 00005157 _____ C:\Windows\DtcInstall.log 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:51 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\Downloads\Spiel-des-Lebens 2013-12-29 20:51 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\ChromeExtensions 2013-12-29 20:51 - 2013-12-25 20:03 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Zylom 2013-12-29 20:51 - 2013-12-25 16:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Das Spiel des Lebens 2013-12-29 20:51 - 2013-12-21 13:39 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Realore_Whiterra Roads Of Rome 3 2013-12-29 20:51 - 2013-11-30 19:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Das Koenigreich der Kobolde 2013-12-29 20:51 - 2013-11-03 10:16 - 00000000 ____D C:\Users\Jacky\Downloads\Konto 2013-12-29 20:51 - 2013-10-29 13:53 - 00000000 ____D C:\Users\Jacky\Documents\My Games 2013-12-29 20:51 - 2013-10-21 10:08 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\PlayFirst 2013-12-29 20:51 - 2013-09-28 16:13 - 00000000 ____D C:\Users\Jacky\Downloads\ActiveSync 2013-12-29 20:51 - 2013-09-28 15:40 - 00000000 ____D C:\Users\Jacky\Documents\FalkData 2013-12-29 20:51 - 2013-09-22 19:21 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\PlayFavoriteGames 2013-12-29 20:51 - 2013-08-25 12:53 - 00000000 __RHD C:\Users\Jacky\AppData\Roaming\SecuROM 2013-12-29 20:51 - 2013-08-25 12:52 - 00000000 ____D C:\Users\Jacky\Documents\Electronic Arts 2013-12-29 20:51 - 2013-08-25 12:25 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Origin 2013-12-29 20:51 - 2013-07-29 19:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roads of Rome III 2013-12-29 20:51 - 2013-07-29 19:08 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Christmas Stories - Nussknacker Sammleredition 2013-12-29 20:51 - 2013-07-29 18:45 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Schloss ohne Traeume 2013-12-29 20:51 - 2013-07-29 18:42 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening 2 - Der Mondenwald 2013-12-29 20:51 - 2013-07-29 18:36 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\9 - The Dark Side Sammleredition 2013-12-29 20:51 - 2013-07-15 14:12 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1 Moment of Time - Silentville 2013-12-29 20:51 - 2013-05-25 17:01 - 00000000 ____D C:\Users\Jacky\Documents\BlackMirror2 2013-12-29 20:51 - 2013-05-25 17:01 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\ProtectDisc 2013-12-29 20:51 - 2013-05-09 09:13 - 00000000 ____D C:\Users\Jacky\Documents\My Cheat Tables 2013-12-29 20:51 - 2013-05-09 08:43 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Ubisoft 2013-12-29 20:51 - 2013-05-04 09:25 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2013-12-29 20:51 - 2013-04-26 18:46 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2013-12-29 20:51 - 2013-04-06 15:59 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Roxio 2013-12-29 20:51 - 2013-03-20 19:31 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mystery of the Ancients - Der Fluch des Schwarzen Wassers Sammleredition 2013-12-29 20:51 - 2013-03-20 19:05 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Party 2013-12-29 20:51 - 2013-03-20 17:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Nero 2013-12-29 20:51 - 2013-03-19 20:06 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Das Himmelsschloss Sammleredition 2013-12-29 20:51 - 2013-03-19 19:59 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\WinRAR 2013-12-29 20:51 - 2013-03-19 19:58 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-12-29 20:51 - 2013-03-19 18:45 - 00000000 ____D C:\Users\Jacky\Documents\DVDFab 2013-12-29 20:51 - 2013-03-18 20:21 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Mozilla 2013-12-29 20:50 - 2013-12-29 15:37 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Bonanza 2013-12-29 20:50 - 2013-12-29 13:36 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.technic 2013-12-29 20:50 - 2013-12-25 20:46 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp3f96eefeb2049202da2178bd45059162 2013-12-29 20:50 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp6ec2be2b619d18ef522057d14578d2f7 2013-12-29 20:50 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp52da00fd457103be90f4c5f287980f49 2013-12-29 20:50 - 2013-10-29 13:56 - 00000000 ____D C:\Users\Jacky\AppData\Local\Skyrim 2013-12-29 20:50 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\LavFilters 2013-12-29 20:50 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\CDXReader 2013-12-29 20:50 - 2013-10-18 14:32 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Elephant Games 2013-12-29 20:50 - 2013-10-17 19:30 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\AlawarEntertainment 2013-12-29 20:50 - 2013-09-16 16:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Artifex Mundi 2013-12-29 20:50 - 2013-08-25 12:25 - 00000000 ____D C:\Users\Jacky\AppData\Local\Origin 2013-12-29 20:50 - 2013-07-19 14:15 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\2monkeys 2013-12-29 20:50 - 2013-06-01 16:23 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\cerasus.media 2013-12-29 20:50 - 2013-05-09 09:03 - 00000000 ____D C:\Users\Jacky\AppData\Local\Ubisoft Game Launcher 2013-12-29 20:50 - 2013-05-07 14:14 - 00000000 ____D C:\Users\Jacky\AppData\Local\PunkBuster 2013-12-29 20:50 - 2013-04-09 18:38 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Apple Computer 2013-12-29 20:50 - 2013-04-06 16:06 - 00000000 ____D C:\Users\Jacky\AppData\Local\Power2Go8 2013-12-29 20:50 - 2013-04-01 14:41 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\HP 2013-12-29 20:50 - 2013-03-20 19:05 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\cef-cache 2013-12-29 20:50 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Macromedia 2013-12-29 20:50 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Adobe 2013-12-29 20:50 - 2013-03-20 17:52 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\CyberLink 2013-12-29 20:50 - 2013-03-20 16:40 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Boomzap 2013-12-29 20:50 - 2013-03-19 18:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\ATI 2013-12-29 20:50 - 2013-03-18 20:21 - 00000000 ____D C:\Users\Jacky\AppData\Local\Mozilla 2013-12-29 20:50 - 2013-03-18 19:15 - 00000000 ____D C:\Users\Jacky\AppData\Local\VirtualStore 2013-12-29 20:49 - 2013-05-22 16:18 - 00000000 ____D C:\Users\Jacky\AppData\Local\Google 2013-12-29 20:49 - 2013-05-04 09:30 - 00000000 ____D C:\Users\Jacky\AppData\Local\GamersFirst LIVE! 2013-12-29 20:49 - 2013-05-04 09:25 - 00000000 ____D C:\Users\Jacky\AppData\Local\GamersFirst 2013-12-29 20:49 - 2013-04-09 18:38 - 00000000 ____D C:\Users\Jacky\AppData\Local\Apple Computer 2013-12-29 20:49 - 2013-04-09 18:37 - 00000000 ____D C:\Users\Jacky\AppData\Local\Apple 2013-12-29 20:49 - 2013-04-01 14:35 - 00000000 ____D C:\Users\Jacky\AppData\Local\HP 2013-12-29 20:49 - 2013-04-01 14:13 - 00000000 ____D C:\Users\Jacky\AppData\Local\Adobe 2013-12-29 20:49 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Local\Macromedia 2013-12-29 20:49 - 2013-03-19 18:26 - 00000000 ____D C:\Users\Jacky\AppData\Local\ATI 2013-12-29 20:42 - 2013-12-29 16:17 - 00000000 ____D C:\Windows\pss 2013-12-29 20:42 - 2013-09-28 14:51 - 00000000 ____D C:\Windows\WindowsMobile 2013-12-29 20:42 - 2013-04-01 14:33 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-12-29 20:42 - 2013-03-20 18:27 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-12-29 20:42 - 2013-03-20 18:27 - 00000000 ____D C:\Windows\system32\Macromed 2013-12-29 20:42 - 2011-04-12 09:28 - 00000000 ____D C:\Windows\ShellNew 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-29 20:41 - 2013-12-25 21:07 - 00000000 ____D C:\ProgramData\Windows Genuine Advantage 2013-12-29 20:41 - 2013-12-15 11:33 - 00000000 ____D C:\ProgramData\Sony 2013-12-29 20:41 - 2013-11-15 15:30 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2013-12-29 20:41 - 2013-10-21 10:08 - 00000000 ____D C:\ProgramData\PlayFirst 2013-12-29 20:41 - 2013-08-25 12:24 - 00000000 ____D C:\ProgramData\Origin 2013-12-29 20:41 - 2013-07-23 07:43 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-12-29 20:41 - 2013-05-09 09:02 - 00000000 ____D C:\ProgramData\Solidshield 2013-12-29 20:41 - 2013-05-06 22:33 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-29 20:41 - 2013-04-06 15:58 - 00000000 ____D C:\ProgramData\Sonic 2013-12-29 20:41 - 2013-04-06 15:57 - 00000000 ____D C:\ProgramData\Roxio 2013-12-29 20:41 - 2013-04-01 14:41 - 00000000 ____D C:\ProgramData\WEBREG 2013-12-29 20:41 - 2013-03-20 18:31 - 00000000 ____D C:\ProgramData\Sun 2013-12-29 20:41 - 2013-03-20 18:13 - 00000000 ____D C:\ProgramData\vsosdk 2013-12-29 20:41 - 2013-03-20 17:52 - 00000000 ____D C:\Users\Public\CyberLink 2013-12-29 20:41 - 2013-03-20 17:24 - 00000000 ____D C:\ProgramData\Nero 2013-12-29 20:41 - 2013-03-18 20:52 - 00000000 ____D C:\Windows\ELAMBKUP 2013-12-29 20:41 - 2013-03-18 20:21 - 00000000 ____D C:\ProgramData\Mozilla 2013-12-29 20:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports 2013-12-29 20:40 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\Xvid 2013-12-29 20:40 - 2013-10-23 13:06 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-12-29 20:40 - 2013-10-19 13:16 - 00000000 ____D C:\ProgramData\DivX 2013-12-29 20:40 - 2013-10-18 14:32 - 00000000 ____D C:\ProgramData\Elephant Games 2013-12-29 20:40 - 2013-08-25 13:06 - 00000000 ____D C:\ProgramData\EA Core 2013-12-29 20:40 - 2013-05-26 08:58 - 00000000 ____D C:\ProgramData\GameHouse 2013-12-29 20:40 - 2013-05-09 08:22 - 00000000 ____D C:\Program Files (x86)\Ubisoft 2013-12-29 20:40 - 2013-04-11 17:54 - 00000000 ____D C:\ProgramData\McAfee 2013-12-29 20:40 - 2013-04-09 18:38 - 00000000 ____D C:\ProgramData\Apple Computer 2013-12-29 20:40 - 2013-04-09 18:36 - 00000000 ____D C:\ProgramData\Apple 2013-12-29 20:40 - 2013-04-06 15:59 - 00000000 ____D C:\ProgramData\InstallShield 2013-12-29 20:40 - 2013-04-01 14:33 - 00000000 ____D C:\ProgramData\HP Product Assistant 2013-12-29 20:40 - 2013-04-01 14:29 - 00000000 ____D C:\ProgramData\HP 2013-12-29 20:40 - 2013-03-27 07:08 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2013-12-29 20:40 - 2013-03-20 18:26 - 00000000 ____D C:\ProgramData\Adobe 2013-12-29 20:40 - 2013-03-20 17:51 - 00000000 ____D C:\ProgramData\CyberLink 2013-12-29 20:40 - 2013-03-20 17:48 - 00000000 ____D C:\ProgramData\install_clap 2013-12-29 20:40 - 2013-03-19 18:45 - 00000000 ____D C:\ProgramData\dvdfab 2013-12-29 20:40 - 2013-03-19 18:26 - 00000000 ____D C:\ProgramData\ATI 2013-12-29 20:39 - 2013-12-15 11:33 - 00000000 ____D C:\Program Files (x86)\Sony 2013-12-29 20:39 - 2013-08-25 12:41 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-12-29 20:39 - 2013-07-29 19:16 - 00000000 ____D C:\Program Files (x86)\Roads of Rome III 2013-12-29 20:39 - 2013-05-26 08:50 - 00000000 ____D C:\Program Files (x86)\Online Games Manager 2013-12-29 20:39 - 2013-05-26 08:49 - 00000000 ____D C:\Program Files (x86)\RealArcade 2013-12-29 20:39 - 2013-05-06 22:25 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-12-29 20:39 - 2013-04-06 15:57 - 00000000 ____D C:\Program Files (x86)\Roxio 2013-12-29 20:39 - 2013-03-20 19:31 - 00000000 ____D C:\Program Files (x86)\Mystery of the Ancients - Der Fluch des Schwarzen Wassers Sammleredition 2013-12-29 20:39 - 2013-03-20 17:25 - 00000000 ____D C:\Program Files (x86)\Nero 2013-12-29 20:39 - 2013-03-18 20:14 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-12-29 20:38 - 2013-12-20 10:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-29 20:38 - 2013-10-22 19:21 - 00000000 ____D C:\Program Files (x86)\Java 2013-12-29 20:38 - 2013-10-19 13:16 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-12-29 20:38 - 2013-10-09 10:27 - 00000000 ____D C:\Program Files (x86)\MAESTIA 2013-12-29 20:38 - 2013-09-17 08:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-12-29 20:38 - 2013-04-26 18:50 - 00000000 ____D C:\Program Files (x86)\LucasArts 2013-12-29 20:38 - 2013-04-01 14:30 - 00000000 ____D C:\Program Files (x86)\HP 2013-12-29 20:38 - 2013-03-19 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Works 2013-12-29 20:38 - 2013-03-19 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 2013-12-29 20:38 - 2013-03-19 18:34 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8 2013-12-29 20:38 - 2013-03-19 18:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-12-29 20:38 - 2013-03-18 20:52 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2013-12-29 20:38 - 2013-03-18 20:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-29 20:38 - 2013-03-18 20:14 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-29 20:38 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\MSBuild 2013-12-29 20:37 - 2013-04-26 18:46 - 00000000 ____D C:\Program Files (x86)\GameSpy Arcade 2013-12-29 20:36 - 2013-12-26 11:19 - 00000000 ____D C:\Program Files (x86)\directx 2013-12-29 20:36 - 2013-12-25 16:26 - 00000000 ____D C:\Program Files (x86)\Das Spiel des Lebens 2013-12-29 20:36 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\ffdshow 2013-12-29 20:36 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\DirectVobSub 2013-12-29 20:36 - 2013-10-19 13:16 - 00000000 ____D C:\Program Files (x86)\DSP-worx 2013-12-29 20:36 - 2013-09-28 16:13 - 00000000 ____D C:\Program Files (x86)\Falk 2013-12-29 20:36 - 2013-08-25 12:15 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-12-29 20:36 - 2013-06-01 15:57 - 00000000 ____D C:\Program Files (x86)\Dark Mysteries - Der Seelensammler 2013-12-29 20:36 - 2013-05-26 09:02 - 00000000 ____D C:\Program Files (x86)\dtp 2013-12-29 20:36 - 2013-05-06 19:37 - 00000000 ____D C:\Program Files (x86)\GamersFirst 2013-12-29 20:36 - 2013-04-06 15:57 - 00000000 ____D C:\Program Files (x86)\DivX 2013-12-29 20:36 - 2013-03-20 20:22 - 00000000 ____D C:\Program Files (x86)\Euro Truck Simulator 2 2013-12-29 20:36 - 2013-03-19 18:45 - 00000000 ____D C:\Program Files (x86)\DVDFab 8 Qt 2013-12-29 20:35 - 2013-11-30 19:51 - 00000000 ____D C:\Program Files (x86)\Awakening - Das Koenigreich der Kobolde 2013-12-29 20:35 - 2013-11-15 15:31 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-12-29 20:35 - 2013-11-15 15:20 - 00000000 ____D C:\Program Files\SmartPCFixer 2013-12-29 20:35 - 2013-10-29 17:39 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories 2013-12-29 20:35 - 2013-10-23 13:06 - 00000000 ____D C:\Program Files\iTunes 2013-12-29 20:35 - 2013-10-23 13:06 - 00000000 ____D C:\Program Files\iPod 2013-12-29 20:35 - 2013-10-19 13:18 - 00000000 ____D C:\Program Files\DivX 2013-12-29 20:35 - 2013-09-17 08:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-12-29 20:35 - 2013-09-07 19:09 - 00000000 ____D C:\Program Files (x86)\Anno 1701 2013-12-29 20:35 - 2013-07-29 19:08 - 00000000 ____D C:\Program Files (x86)\Christmas Stories - Nussknacker Sammleredition 2013-12-29 20:35 - 2013-07-29 18:45 - 00000000 ____D C:\Program Files (x86)\Awakening - Schloss ohne Traeume 2013-12-29 20:35 - 2013-07-29 18:42 - 00000000 ____D C:\Program Files (x86)\Awakening 2 - Der Mondenwald 2013-12-29 20:35 - 2013-07-29 18:36 - 00000000 ____D C:\Program Files (x86)\9 - The Dark Side Sammleredition 2013-12-29 20:35 - 2013-07-15 14:12 - 00000000 ____D C:\Program Files (x86)\1 Moment of Time - Silentville 2013-12-29 20:35 - 2013-05-23 17:44 - 00000000 ____D C:\Program Files (x86)\Black Mirror 2 2013-12-29 20:35 - 2013-05-09 08:29 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.2 2013-12-29 20:35 - 2013-04-06 15:59 - 00000000 ____D C:\Program Files\Roxio 2013-12-29 20:35 - 2013-04-01 14:10 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-12-29 20:35 - 2013-03-19 20:06 - 00000000 ____D C:\Program Files (x86)\Awakening - Das Himmelsschloss Sammleredition 2013-12-29 20:35 - 2013-03-19 19:58 - 00000000 ____D C:\Program Files\WinRAR 2013-12-29 20:35 - 2013-03-19 19:53 - 00000000 ____D C:\Program Files (x86)\bfgclient 2013-12-29 20:35 - 2013-03-19 18:34 - 00000000 ____D C:\Program Files\Microsoft Office 2013-12-29 20:35 - 2013-03-19 18:23 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-12-29 20:35 - 2013-03-19 18:22 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:21 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:20 - 00000000 ____D C:\Program Files\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:20 - 00000000 ____D C:\Program Files\ATI 2013-12-29 20:35 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Vorlagen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Startmenü 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Netzwerkumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Lokale Einstellungen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Eigene Dateien 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Druckumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Musik 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Bilder 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Verlauf 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Anwendungsdaten 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Anwendungsdaten 2013-12-29 20:30 - 2013-12-29 20:30 - 00001355 _____ C:\Windows\TSSysprep.log 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-12-29 19:44 - 2013-03-18 18:53 - 01852960 _____ C:\Windows\WindowsUpdate (1).log 2013-12-29 19:04 - 2013-12-29 18:57 - 00013897 _____ C:\Windows\diagwrn.xml 2013-12-29 19:04 - 2013-12-29 18:57 - 00001890 _____ C:\Windows\diagerr.xml 2013-12-29 13:36 - 2013-12-29 13:36 - 02304092 _____ () C:\Users\Jacky\Downloads\TechnicLauncher.exe 2013-12-29 10:15 - 2013-12-29 10:15 - 02014840 _____ (DriverBoost) C:\Users\Jacky\Downloads\DriverBoostPro_Setup.exe 2013-12-29 10:12 - 2013-12-29 10:12 - 08054042 _____ C:\Users\Jacky\Downloads\windowsinstaller45(1).zip 2013-12-29 09:40 - 2013-12-25 20:03 - 00000000 ____D C:\Users\Jacky\AppData\Local\Zylom Games 2013-12-28 21:44 - 2013-12-28 21:42 - 63443792 _____ C:\Users\Jacky\Downloads\thegameoflifedownload.exe 2013-12-26 22:00 - 2013-12-26 21:59 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-12-26 19:39 - 2013-12-26 19:39 - 02585872 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsInstaller-KB893803-v2-x86.exe 2013-12-26 11:19 - 2013-12-26 11:19 - 00000278 _____ C:\Windows\Directx.log 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck.exe 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(1).exe 2013-12-25 20:59 - 2013-12-25 20:59 - 02311827 _____ C:\Users\Jacky\Downloads\sdl3ewin.zip 2013-12-25 20:57 - 2013-12-25 20:57 - 00397154 _____ C:\Users\Jacky\Downloads\SpieldesLebensWin.zip 2013-12-25 20:53 - 2013-12-25 20:53 - 00002890 _____ C:\Windows\System32\Tasks\{E03E12C0-F94B-4CA6-A09A-515468D6FAA3} 2013-12-25 20:45 - 2013-12-25 20:45 - 00943872 _____ C:\Users\Jacky\Downloads\Spiel-des-Lebens-Setup.exe 2013-12-25 20:41 - 2013-12-25 20:41 - 00003018 _____ C:\Windows\System32\Tasks\{476505DD-F30E-4FF4-8920-CB14D92EB605} 2013-12-25 20:29 - 2013-12-25 20:29 - 00003018 _____ C:\Windows\System32\Tasks\{01014E7C-EF80-4994-94A4-7882BBE1FC4D} 2013-12-25 16:22 - 2013-12-25 16:22 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p200715036_s2_l2.exe 2013-12-25 16:19 - 2013-12-25 16:19 - 00002890 _____ C:\Windows\System32\Tasks\{D5C4E481-AC90-46F2-A2E0-FC0AF1374D57} 2013-12-25 09:03 - 2011-02-19 22:51 - 00608080 _____ (Microsoft Corporation) C:\Windows\system32\msvcp100.dll 2013-12-25 09:03 - 2011-02-19 00:52 - 00829264 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100.dll 2013-12-19 08:27 - 2013-03-20 19:09 - 00001525 _____ C:\Users\Jacky\Desktop\PartyCasino.lnk 2013-12-19 08:24 - 2013-03-20 19:05 - 00001531 _____ C:\Users\Jacky\Desktop\partypoker.lnk 2013-12-15 11:36 - 2013-12-15 11:33 - 00181280 _____ C:\Windows\DPINST.LOG 2013-12-15 11:33 - 2013-12-15 11:33 - 00002106 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2013-12-11 18:46 - 2013-03-20 18:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 18:46 - 2013-03-20 18:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-11 18:46 - 2013-03-20 18:27 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-11 08:58 - 2012-08-02 15:09 - 00029792 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys 2013-12-11 08:58 - 2012-06-19 17:28 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2013-12-07 19:39 - 2013-05-22 16:18 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-07 19:39 - 2013-05-22 16:18 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore Files to move or delete: ==================== C:\Users\Jacky\Firefox Setup 19.0.2.exe Some content of TEMP: ==================== C:\Users\Jacky\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-31 10:20 ==================== End Of Log ============================ |
04.01.2014, 15:50 | #13 |
/// the machine /// TB-Ausbilder | PC bereinigen und schneller machen Fertig Falls Du Lob oder Kritik loswerden möchtest kannst Du das hier tun Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.01.2014, 16:20 | #14 |
| PC bereinigen und schneller machen Super :-). Vielen Dank für Deine tolle Hilfe. VG Tweety |
05.01.2014, 16:05 | #15 |
/// the machine /// TB-Ausbilder | PC bereinigen und schneller machen Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |