|
Plagegeister aller Art und deren Bekämpfung: PUP optional CandyWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.02.2014, 09:29 | #46 |
/// the machine /// TB-Ausbilder | PUP optional Candy Du lädst die ISO Du lädst das kleine Removal ZIP und lässt es laufen Dann kannst Du die ISO auf die DVD brennen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.02.2014, 20:53 | #47 |
| PUP optional Candy danke :-) ich versuch das morgen abend!
__________________ |
10.02.2014, 17:13 | #48 |
/// the machine /// TB-Ausbilder | PUP optional Candy ok
__________________
__________________ |
11.02.2014, 09:22 | #49 |
| PUP optional Candy so, das upgrade läuft :-) hoffe ich hab nun das richtige windows erwischt. aber ich denke sonst hätt er wieder reklamiert. hab mich irgendwie relativ flüchtig durchgeklickt, weil ich ja schon do oft angefangen hatte. es hatte dann vier zur auswahl. könnt mich höchstens verklickt haben. aber das glaub ich nicht. ich denk das kommt jetzt gut. eben sonst hät er sicher wieder reklamiert wenns eine andere version gewesen wär... mal gucken wie es dann morgen aussieht. läuft jetzt über nacht... gute Nachrichten Es scheint geklappt zu haben mit der ISO und dem windows upgrade nun bin ich gespannt, wie es weitergeht. ich denke wir müssen irgendwie noch prüfen ob nun von dem pup.optional zeugs wirklich alles weg ist. also her mit neuen aufgaben |
11.02.2014, 19:03 | #50 |
/// the machine /// TB-Ausbilder | PUP optional Candy nice job dann bitte mal ein frisches FRST Logfile, und bitte mal aufzählen was noch an Problemen da ist
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.02.2014, 22:28 | #51 |
| PUP optional Candy also normalerweise gehe ich ja mit firefox ins netz. da jetzt die symbole anders sind, kam ich vorher zufällig auf internet explorer. da meldet mir secure banking malware. windows explorer bleibt immer noch hängen das ist unverändert, trotz windwos reparatur. frst-log folgt nachher. muss erst was fertig machen. aber wollte das vorab schreiben, nicht dass ich es aufs mal noch vergesse... so sachen wie lautstärkeanzeige (mitten auf dem bilschirm, nicht unten rechts) oder anzeige von ein-/ausschalten des touchpads gehen auch nicht. FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-02-2014 01 Ran by ***** (administrator) on *****-PC on 11-02-2014 22:27:07 Running from C:\Users\*****\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Splashtop Inc.) C:\ASUS.SYS\SIONExportService.exe (Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (FreeDownloadManager.ORG) C:\Program Files (x86)\Free Download Manager\fdm.exe (Secure Banking) C:\Program Files (x86)\Secure Banking\SecureBanking.exe (syncables, LLC) C:\Program Files (x86)\syncables\syncables desktop\syncables.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe () C:\Program Files (x86)\Secure Banking\sbservice.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-06-03] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated) HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379552 2011-03-13] (Atheros Commnucations) HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [617120 2011-03-13] (Atheros Communications) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4156 2010-04-16] () HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation) HKLM\...\Run: [SynAsusAcpi] - C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-09] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de) HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.) HKLM-x32\...\Run: [TrayServer] - C:\Program Files (x86)\MAGIX\Video_deluxe_17_Plus_Sonderedition\TrayServer.exe [90112 2008-08-07] (MAGIX AG) HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-4073853582-3472843793-526417432-1001\...\Run: [Free Download Manager] - C:\Program Files (x86)\Free Download Manager\fdm.exe [6950400 2013-10-25] (FreeDownloadManager.ORG) HKU\S-1-5-21-4073853582-3472843793-526417432-1001\...\Run: [SecureBanking] - C:\Program Files (x86)\Secure Banking\SecureBanking.exe [507904 2013-07-06] (Secure Banking) HKU\S-1-5-21-4073853582-3472843793-526417432-1001\...\Run: [Syncables] - C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-07-19] (syncables, LLC) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-11-14] (NVIDIA Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-11-14] (NVIDIA Corporation) Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\phase-6 Reminder.lnk ShortcutTarget: phase-6 Reminder.lnk -> C:\Users\*****\AppData\Local\phase-6\phase-6-compendio\reminder\reminder.exe (phase-6) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.ch/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {FAD6394E-D719-45AD-8C59-99A8E90A359C} URL = hxxp://ch.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll () BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: No Name - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No File BHO-x32: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll () BHO-x32: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll () Toolbar: HKCU - WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll () Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll () Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mpazrgl1.default FF Homepage: hxxp://www.google.ch/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Garmin Communicator - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mpazrgl1.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013-11-23] FF Extension: WOT - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mpazrgl1.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-28] FF Extension: Adblock Plus - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mpazrgl1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-10-06] Chrome: ======= CHR HomePage: hxxp://www.google.com/ig/redirectdomain?brand=ASUT&bmod=ASUT ==================== Services (Whitelisted) ================= R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [908856 2013-12-09] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-09] (Avira Operations GmbH & Co. KG) R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-03-13] (Atheros) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation) R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [249856 2011-02-15] () R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1328736 2012-09-24] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [656480 2012-09-24] (Secunia) R2 Splashtop MDES; C:\ASUS.SYS\SIONExportService.exe [338208 2011-05-10] (Splashtop Inc.) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-09] (Avira Operations GmbH & Co. KG) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-11-14] (NVIDIA Corporation) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-17] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-11 20:57 - 2014-02-11 20:57 - 00183920 _____ () C:\Users\*****\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-11 07:09 - 2014-02-11 07:09 - 01593564 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-11 07:03 - 2014-02-11 07:03 - 00001407 _____ () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-02-11 07:02 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2014-02-11 07:02 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2014-02-11 07:02 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2014-02-11 07:02 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2014-02-11 07:02 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2014-02-11 07:02 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2014-02-11 07:01 - 2014-02-11 07:03 - 00001441 _____ () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-11 07:00 - 2014-02-11 07:00 - 00000020 ___SH () C:\Users\*****\ntuser.ini 2014-02-11 07:00 - 2011-11-19 15:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-02-11 07:00 - 2011-11-19 15:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Programme 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Favoriten 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Dokumente und Einstellungen 2014-02-11 01:13 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2014-02-11 01:13 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2014-02-11 01:13 - 2012-02-17 05:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-02-11 01:13 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2014-02-11 01:07 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-02-11 01:07 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-02-11 01:07 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-02-11 01:07 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-02-11 01:07 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-02-11 01:07 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-02-11 01:07 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-02-11 01:07 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-02-11 01:07 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-02-11 00:37 - 2014-02-11 00:37 - 00022960 _____ () C:\Windows\system32\emptyregdb.dat 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Apple Computer 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\ifolor 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\Apple Computer 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Apple Computer 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\ifolor 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\Apple Computer 2014-02-10 23:32 - 2014-02-11 07:00 - 00000000 ____D () C:\Users\***** 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Vorlagen 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Startmenü 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Netzwerkumgebung 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Lokale Einstellungen 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Eigene Dateien 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Druckumgebung 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Documents\Eigene Musik 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Documents\Eigene Bilder 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Local\Verlauf 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Local\Anwendungsdaten 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Anwendungsdaten 2014-02-10 23:32 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-10 23:32 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-10 23:31 - 2014-02-10 23:31 - 00001355 _____ () C:\Windows\TSSysprep.log 2014-02-10 23:30 - 2014-02-10 23:30 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2014-02-10 23:30 - 2014-02-10 23:30 - 00000000 ____D () C:\Program Files\Synaptics 2014-02-10 23:29 - 2014-02-11 20:57 - 01572853 _____ () C:\Windows\WindowsUpdate.log 2014-02-10 23:29 - 2014-02-11 00:00 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-10 23:29 - 2014-02-10 23:54 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-02-10 23:29 - 2014-02-10 23:35 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-10 23:29 - 2014-02-10 23:29 - 00000000 ____D () C:\ProgramData\SonicFocus 2014-02-10 23:29 - 2013-11-11 16:02 - 06674208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-02-10 23:29 - 2013-11-11 16:02 - 03490080 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-02-10 23:29 - 2013-11-11 16:01 - 03467927 _____ () C:\Windows\system32\nvcoproc.bin 2014-02-10 23:29 - 2013-11-11 16:01 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-02-10 23:29 - 2013-11-11 16:01 - 01065248 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2014-02-10 23:29 - 2013-11-11 16:01 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-02-10 23:29 - 2013-11-11 16:01 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-02-10 23:29 - 2013-11-11 16:01 - 00067072 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2014-02-10 23:29 - 2013-11-11 16:01 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-02-10 23:28 - 2014-02-10 23:28 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2014-02-10 23:28 - 2014-02-10 23:28 - 00000000 ____D () C:\Program Files\Realtek 2014-02-10 23:24 - 2014-02-11 06:59 - 00000000 ____D () C:\Windows\Panther 2014-02-10 23:21 - 2014-02-10 23:21 - 00262144 _____ () C:\Windows\system32\config\userdiff 2014-02-10 23:07 - 2014-02-11 00:39 - 00000000 ___HD () C:\$WINDOWS.~Q 2014-02-10 22:47 - 2014-02-10 23:00 - 00000000 ___HD () C:\$INPLACE.~TR 2014-02-10 22:04 - 2014-02-11 00:39 - 00006165 _____ () C:\Windows\comsetup.log 2014-02-10 21:24 - 2014-02-11 00:28 - 00000000 ____D () C:\Users\*****\Downloads\eicfg_removal_utility 2014-02-10 21:24 - 2014-02-10 21:24 - 00005347 _____ () C:\Users\*****\Downloads\eicfg_removal_utility.zip 2014-02-10 21:23 - 2014-02-11 00:28 - 00000000 ____D () C:\Users\*****\Documents\Iso alt 2014-02-10 21:23 - 2014-02-10 21:23 - 00000000 ____D () C:\Users\*****\Desktop\Neuer Ordner (2) 2014-02-10 21:22 - 2014-02-10 21:22 - 00000000 ____D () C:\Users\*****\Desktop\Neuer Ordner 2014-02-10 21:13 - 2014-02-11 00:27 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-02-02 17:31 - 2014-02-02 18:33 - 00002020 _____ () C:\Users\*****\Desktop\Windows Compatibility Report.htm 2014-01-27 18:27 - 2014-02-05 19:51 - 00003320 _____ () C:\Users\*****\Desktop\Windows-Kompatibilitätsbericht.htm 2014-01-27 18:25 - 2014-02-10 21:49 - 00002544 _____ () C:\Windows\diagwrn.xml 2014-01-27 18:25 - 2014-02-10 21:49 - 00001890 _____ () C:\Windows\diagerr.xml 2014-01-19 18:22 - 2014-02-11 00:26 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Free Download Manager 2014-01-19 18:22 - 2014-02-10 23:56 - 00000000 ____D () C:\ProgramData\Free Download Manager 2014-01-19 18:22 - 2014-02-10 23:41 - 00000000 ____D () C:\Program Files (x86)\Free Download Manager 2014-01-19 18:22 - 2014-01-19 18:22 - 00001069 _____ () C:\Users\*****\Desktop\Free Download Manager.lnk 2014-01-19 18:20 - 2014-01-19 18:20 - 00614784 _____ (Chip Digital GmbH) C:\Users\*****\Desktop\Free Download Manager - CHIP-Downloader.exe 2014-01-17 19:01 - 2014-02-11 00:26 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Avira 2014-01-17 19:00 - 2014-02-10 23:36 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-01-17 19:00 - 2014-01-17 19:00 - 00002068 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-01-17 19:00 - 2013-12-09 11:37 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-01-17 19:00 - 2013-12-09 11:37 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-01-17 19:00 - 2013-12-09 11:37 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-01-17 19:00 - 2013-12-09 11:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-01-17 18:53 - 2014-01-17 18:58 - 140300048 _____ () C:\Users\*****\Downloads\avira_antivirus_suite_de.exe 2014-01-15 20:27 - 2014-01-15 20:27 - 00448512 _____ (OldTimer Tools) C:\Users\*****\Desktop\TFC.exe 2014-01-14 06:45 - 2014-01-14 06:45 - 00987410 _____ () C:\Users\*****\Desktop\SecurityCheck.exe 2014-01-13 21:04 - 2014-01-13 21:05 - 02347384 _____ (ESET) C:\Users\*****\Desktop\esetsmartinstaller_enu.exe 2014-01-13 20:21 - 2014-01-13 20:45 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2014-01-13 20:17 - 2014-01-13 20:17 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-*****-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat 2014-01-13 20:17 - 2014-01-13 20:17 - 00000000 ____D () C:\RegBackup 2014-01-13 19:32 - 2014-02-11 00:27 - 00000000 ____D () C:\Users\*****\Desktop\tweaking.com_windows_repair_aio 2014-01-13 19:31 - 2014-01-13 19:31 - 02903255 _____ () C:\Users\*****\Desktop\tweaking.com_windows_repair_aio.zip ==================== One Month Modified Files and Folders ======= 2014-02-11 22:27 - 2014-01-04 09:34 - 00019717 _____ () C:\Users\*****\Desktop\FRST.txt 2014-02-11 22:27 - 2014-01-04 09:34 - 00000000 ____D () C:\FRST 2014-02-11 22:26 - 2014-01-07 22:03 - 00000000 ____D () C:\Users\*****\Desktop\FRST-OlderVersion 2014-02-11 22:26 - 2014-01-04 09:29 - 02151424 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe 2014-02-11 22:23 - 2009-07-14 05:45 - 00018224 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-11 22:23 - 2009-07-14 05:45 - 00018224 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-11 22:22 - 2012-09-29 21:19 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-11 21:18 - 2014-02-10 23:29 - 01572853 _____ () C:\Windows\WindowsUpdate.log 2014-02-11 20:58 - 2011-11-11 10:23 - 00000000 ____D () C:\Users\*****\AppData\Local\VirtualStore 2014-02-11 20:57 - 2014-02-11 20:57 - 00183920 _____ () C:\Users\*****\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-11 20:54 - 2010-11-21 07:50 - 00699342 _____ () C:\Windows\system32\perfh007.dat 2014-02-11 20:54 - 2010-11-21 07:50 - 00149450 _____ () C:\Windows\system32\perfc007.dat 2014-02-11 20:54 - 2009-07-14 06:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-11 20:48 - 2011-11-11 10:23 - 00000000 ___HD () C:\ASUS.DAT 2014-02-11 20:48 - 2011-09-15 07:37 - 00000012 ____H () C:\dvmexp.idx 2014-02-11 20:47 - 2011-09-15 07:23 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-11 20:47 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-11 20:47 - 2009-07-14 05:51 - 00754607 _____ () C:\Windows\setupact.log 2014-02-11 07:16 - 2011-12-26 13:15 - 00000000 ____D () C:\Users\*****\Documents\Outlook-Dateien 2014-02-11 07:09 - 2014-02-11 07:09 - 01593564 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-11 07:05 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-02-11 07:03 - 2014-02-11 07:03 - 00001407 _____ () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-02-11 07:03 - 2014-02-11 07:01 - 00001441 _____ () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-11 07:03 - 2011-11-11 10:24 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-11 07:03 - 2011-11-11 10:24 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-02-11 07:00 - 2014-02-11 07:00 - 00000020 ___SH () C:\Users\*****\ntuser.ini 2014-02-11 07:00 - 2014-02-10 23:32 - 00000000 ____D () C:\Users\***** 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Programme 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Favoriten 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Dokumente und Einstellungen 2014-02-11 06:59 - 2014-02-10 23:24 - 00000000 ____D () C:\Windows\Panther 2014-02-11 06:59 - 2009-07-29 06:10 - 00000000 ____D () C:\Recovery 2014-02-11 06:59 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-11 06:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Recovery 2014-02-11 06:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Windows NT 2014-02-11 06:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-02-11 01:07 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\restore 2014-02-11 01:00 - 2010-11-21 04:47 - 00011170 _____ () C:\Windows\PFRO.log 2014-02-11 00:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Registration 2014-02-11 00:39 - 2014-02-10 23:07 - 00000000 ___HD () C:\$WINDOWS.~Q 2014-02-11 00:39 - 2014-02-10 22:04 - 00006165 _____ () C:\Windows\comsetup.log 2014-02-11 00:37 - 2014-02-11 00:37 - 00022960 _____ () C:\Windows\system32\emptyregdb.dat 2014-02-11 00:36 - 2012-11-27 07:19 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-02-11 00:36 - 2011-12-25 20:04 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform 2014-02-11 00:33 - 2009-07-14 05:45 - 00585064 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Apple Computer 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\ifolor 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\Apple Computer 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Apple Computer 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\ifolor 2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\Apple Computer 2014-02-11 00:30 - 2009-07-14 05:46 - 00005157 _____ () C:\Windows\DtcInstall.log 2014-02-11 00:30 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-11 00:30 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-11 00:30 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-11 00:30 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-11 00:28 - 2014-02-10 21:24 - 00000000 ____D () C:\Users\*****\Downloads\eicfg_removal_utility 2014-02-11 00:28 - 2014-02-10 21:23 - 00000000 ____D () C:\Users\*****\Documents\Iso alt 2014-02-11 00:28 - 2013-08-03 14:45 - 00000000 ____D () C:\Users\*****\Documents\MAGIX Speed 2014-02-11 00:28 - 2013-01-26 23:58 - 00000000 ____D () C:\Users\*****\Documents\MAGIX_Video_deluxe_17_Plus_Sonderedition 2014-02-11 00:28 - 2012-08-31 20:11 - 00000000 ____D () C:\Users\*****\Documents\My Digital Editions 2014-02-11 00:28 - 2011-11-24 21:07 - 00000000 ____D () C:\Users\*****\Documents\ifolor Designer Dateien 2014-02-11 00:28 - 2011-11-12 08:05 - 00000000 ___RD () C:\Users\*****\Documents\MAGIX 2014-02-11 00:27 - 2014-02-10 21:13 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-02-11 00:27 - 2014-01-13 19:32 - 00000000 ____D () C:\Users\*****\Desktop\tweaking.com_windows_repair_aio 2014-02-11 00:27 - 2013-05-24 19:32 - 00000000 ____D () C:\Users\*****\Desktop\Sprachen 2014-02-11 00:27 - 2013-05-14 13:59 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Phase6 2014-02-11 00:27 - 2013-05-14 13:59 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\phase-6 2014-02-11 00:27 - 2013-01-08 19:38 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\digital publishing 2014-02-11 00:27 - 2012-12-05 19:49 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Opera 2014-02-11 00:27 - 2012-10-05 18:22 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Mozilla 2014-02-11 00:27 - 2012-09-23 16:54 - 00000000 ____D () C:\Users\*****\Desktop\Ricardo Bilder 2014-02-11 00:27 - 2012-04-06 10:39 - 00000000 ____D () C:\Users\*****\AppData\Roaming\XMedia Recode 2014-02-11 00:27 - 2012-03-23 22:01 - 00000000 ____D () C:\Users\*****\Documents\ifolor 2014-02-11 00:27 - 2012-01-14 18:01 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Sync App Settings 2014-02-11 00:27 - 2011-12-26 18:01 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-02-11 00:27 - 2011-11-27 17:09 - 00000000 ____D () C:\Users\*****\Documents\CyberLink 2014-02-11 00:27 - 2011-11-24 20:23 - 00000000 ____D () C:\Users\*****\AppData\Roaming\TuneUp Software 2014-02-11 00:27 - 2011-11-23 20:05 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Skype 2014-02-11 00:27 - 2011-11-13 20:19 - 00000000 ____D () C:\Users\*****\AppData\Roaming\OpenOffice.org 2014-02-11 00:27 - 2011-11-11 10:25 - 00000000 ____D () C:\Users\*****\Documents\Bluetooth Folder 2014-02-11 00:27 - 2011-11-11 10:22 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite 2014-02-11 00:27 - 2011-11-11 10:22 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic 2014-02-11 00:26 - 2014-01-19 18:22 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Free Download Manager 2014-02-11 00:26 - 2014-01-17 19:01 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Avira 2014-02-11 00:26 - 2014-01-05 17:32 - 00000000 ____D () C:\Users\*****\AppData\Local\NVIDIA Corporation 2014-02-11 00:26 - 2014-01-05 17:30 - 00000000 ____D () C:\Users\*****\AppData\Local\NVIDIA 2014-02-11 00:26 - 2014-01-03 18:44 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Google 2014-02-11 00:26 - 2013-05-14 13:59 - 00000000 ____D () C:\Users\*****\AppData\Local\phase-6 2014-02-11 00:26 - 2013-01-11 19:25 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Langenscheidt 2014-02-11 00:26 - 2013-01-11 19:15 - 00000000 ____D () C:\Users\*****\AppData\Roaming\lingDIALOG 2014-02-11 00:26 - 2013-01-11 18:30 - 00000000 ____D () C:\Users\*****\AppData\Roaming\conkeror.mozdev.org 2014-02-11 00:26 - 2012-12-05 19:49 - 00000000 ____D () C:\Users\*****\AppData\Local\Opera 2014-02-11 00:26 - 2012-11-26 19:34 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Malwarebytes 2014-02-11 00:26 - 2012-08-27 19:16 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Garmin 2014-02-11 00:26 - 2012-08-14 17:47 - 00000000 ____D () C:\Users\*****\AppData\Roaming\ACD Systems 2014-02-11 00:26 - 2012-07-29 13:01 - 00000000 ____D () C:\Users\*****\AppData\Local\Mozilla 2014-02-11 00:26 - 2012-04-21 09:30 - 00000000 ____D () C:\Users\*****\AppData\Roaming\FileZilla 2014-02-11 00:26 - 2012-04-06 10:49 - 00000000 ____D () C:\Users\*****\AppData\Roaming\DVDVideoSoft 2014-02-11 00:26 - 2012-01-19 21:42 - 00000000 ____D () C:\Users\*****\AppData\Local\Windows Live Writer 2014-02-11 00:26 - 2011-12-19 21:42 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Apple Computer 2014-02-11 00:26 - 2011-11-26 10:49 - 00000000 ____D () C:\Users\*****\AppData\Local\mquadr.at 2014-02-11 00:26 - 2011-11-24 20:54 - 00000000 ____D () C:\Users\*****\AppData\Roaming\ifolor 2014-02-11 00:26 - 2011-11-13 12:50 - 00000000 ____D () C:\Users\*****\AppData\Roaming\CyberLink 2014-02-11 00:26 - 2011-11-13 12:25 - 00000000 ____D () C:\Users\*****\AppData\Local\OLYMPUS 2014-02-11 00:26 - 2011-11-12 08:04 - 00000000 ____D () C:\Users\*****\AppData\Roaming\MAGIX 2014-02-11 00:26 - 2011-11-12 08:04 - 00000000 ____D () C:\Users\*****\AppData\Local\Xara 2014-02-11 00:26 - 2011-11-11 19:43 - 00000000 ____D () C:\Users\*****\AppData\Roaming\ASUS WebStorage 2014-02-11 00:26 - 2011-11-11 19:36 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Macromedia 2014-02-11 00:26 - 2011-11-11 19:28 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Adobe 2014-02-11 00:26 - 2011-11-11 19:16 - 00000000 ____D () C:\Users\*****\AppData\Local\Power2Go 2014-02-11 00:26 - 2011-11-11 12:33 - 00000000 ____D () C:\Users\*****\AppData\Roaming\FLEXnet 2014-02-11 00:21 - 2012-09-29 21:34 - 00000000 ____D () C:\Users\*****\AppData\Local\Macromedia 2014-02-11 00:21 - 2011-12-25 20:01 - 00000000 ____D () C:\Users\*****\AppData\Local\Microsoft Help 2014-02-11 00:21 - 2011-11-26 10:41 - 00000000 ____D () C:\Users\*****\AppData\Local\IM 2014-02-11 00:21 - 2011-11-12 08:22 - 00000000 ____D () C:\Users\*****\AppData\Local\MAGIX_AG 2014-02-11 00:21 - 2011-11-12 08:04 - 00000000 ____D () C:\Users\*****\AppData\Local\MAGIX 2014-02-11 00:21 - 2011-11-11 12:39 - 00000000 ____D () C:\Users\*****\AppData\Local\Microsoft Games 2014-02-11 00:20 - 2013-05-14 13:59 - 00000000 ____D () C:\Users\*****\.swt 2014-02-11 00:20 - 2013-05-14 13:59 - 00000000 ____D () C:\Users\*****\.phase-6 2014-02-11 00:20 - 2013-01-11 19:15 - 00000000 ____D () C:\Users\*****\.pknowledge 2014-02-11 00:20 - 2013-01-11 18:30 - 00000000 ____D () C:\Users\*****\AppData\Local\conkeror.mozdev.org 2014-02-11 00:20 - 2013-01-08 19:42 - 00000000 ____D () C:\Users\*****\AppData\Local\digital publishing 2014-02-11 00:20 - 2012-08-14 17:47 - 00000000 ____D () C:\Users\*****\AppData\Local\ACD Systems 2014-02-11 00:20 - 2012-08-14 17:44 - 00000000 ____D () C:\Users\*****\AppData\Local\Downloaded Installations 2014-02-11 00:20 - 2012-04-20 18:03 - 00000000 ____D () C:\Users\*****\AppData\Local\Fujifilm 2014-02-11 00:20 - 2011-12-20 22:03 - 00000000 ____D () C:\Users\*****\AppData\Local\Cyberlink 2014-02-11 00:20 - 2011-12-19 21:42 - 00000000 ____D () C:\Users\*****\AppData\Local\Apple Computer 2014-02-11 00:20 - 2011-12-19 21:39 - 00000000 ____D () C:\Users\*****\AppData\Local\Apple 2014-02-11 00:20 - 2011-11-20 13:19 - 00000000 ____D () C:\Users\*****\AppData\Local\BMExplorer 2014-02-11 00:20 - 2011-11-13 20:03 - 00000000 ____D () C:\Users\*****\AppData\Local\Adobe 2014-02-11 00:20 - 2011-11-11 20:57 - 00000000 ____D () C:\Users\*****\AppData\Local\CrashDumps 2014-02-11 00:20 - 2011-11-11 19:25 - 00000000 ____D () C:\Users\*****\AppData\Local\Google 2014-02-11 00:20 - 2011-11-11 10:23 - 00000000 ____D () C:\Users\*****\AppData\Local\ASUS 2014-02-11 00:03 - 2014-01-05 17:20 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-02-11 00:03 - 2012-12-12 14:47 - 00000000 __SHD () C:\Windows\SysWOW64\%APPDATA% 2014-02-11 00:03 - 2011-04-13 03:47 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-02-11 00:03 - 2011-02-18 21:08 - 00000000 ____D () C:\Windows\system32\SPReview 2014-02-11 00:03 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns 2014-02-11 00:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK 2014-02-11 00:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR 2014-02-11 00:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\zh-HK 2014-02-11 00:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\tr-TR 2014-02-11 00:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep 2014-02-11 00:02 - 2014-01-05 17:20 - 00000000 ____D () C:\Windows\system32\NV 2014-02-11 00:02 - 2013-03-13 21:59 - 00000000 __SHD () C:\Windows\system32\%APPDATA% 2014-02-11 00:02 - 2012-02-17 20:10 - 00000000 ____D () C:\Windows\system32\Macromed 2014-02-11 00:02 - 2011-09-15 07:46 - 00000000 ____D () C:\Windows\system32\AsMakeLink 2014-02-11 00:02 - 2011-04-13 03:44 - 00000000 ____D () C:\Windows\ru 2014-02-11 00:02 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\nl 2014-02-11 00:02 - 2011-02-18 20:48 - 00000000 ____D () C:\Windows\system32\EventProviders 2014-02-11 00:02 - 2010-11-21 08:00 - 00000000 ____D () C:\Windows\ShellNew 2014-02-11 00:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\oobe 2014-02-11 00:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-02-11 00:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-02-11 00:01 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\it 2014-02-11 00:01 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\he 2014-02-11 00:01 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\fr 2014-02-11 00:01 - 2009-07-29 06:20 - 00000000 ____D () C:\Windows\Log 2014-02-11 00:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\IME 2014-02-11 00:00 - 2014-02-10 23:29 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-11 00:00 - 2014-01-03 20:49 - 00000000 ____D () C:\Windows\ERUNT 2014-02-11 00:00 - 2013-12-25 12:38 - 00000000 ____D () C:\Users\Public\Documents\MAGIX 2014-02-11 00:00 - 2013-07-07 20:44 - 00000000 ____D () C:\ProgramData\Magix Shared 2014-02-11 00:00 - 2013-05-14 13:59 - 00000000 ____D () C:\ProgramData\Phase6 2014-02-11 00:00 - 2013-02-19 19:34 - 00000000 ____D () C:\ProgramData\tmp 2014-02-11 00:00 - 2012-12-02 17:21 - 00000000 ____D () C:\Windows\erdnt 2014-02-11 00:00 - 2012-12-02 16:42 - 00000000 ____D () C:\Users\mõder 2014-02-11 00:00 - 2012-11-27 07:19 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-02-11 00:00 - 2012-11-26 19:34 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-11 00:00 - 2012-07-29 13:01 - 00000000 ____D () C:\ProgramData\Mozilla 2014-02-11 00:00 - 2012-03-20 21:51 - 00000000 __HDC () C:\ProgramData\{D3257C41-1D3A-407B-A943-682D251F5FD2} 2014-02-11 00:00 - 2012-02-18 18:40 - 00000000 ____D () C:\ProgramData\Photo Notifier and Animation Creator 2014-02-11 00:00 - 2012-01-14 17:55 - 00000000 ____D () C:\ProgramData\Sync App Settings 2014-02-11 00:00 - 2011-12-25 20:01 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-02-11 00:00 - 2011-12-19 21:40 - 00000000 ____D () C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} 2014-02-11 00:00 - 2011-11-26 10:49 - 00000000 ____D () C:\ProgramData\mquadr.at 2014-02-11 00:00 - 2011-11-24 20:21 - 00000000 __SHD () C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2014-02-11 00:00 - 2011-11-24 20:21 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-02-11 00:00 - 2011-11-23 20:05 - 00000000 ____D () C:\ProgramData\Skype 2014-02-11 00:00 - 2011-11-13 20:17 - 00000000 ____D () C:\ProgramData\Sun 2014-02-11 00:00 - 2011-11-13 12:50 - 00000000 ____D () C:\Users\Public\CyberLink 2014-02-11 00:00 - 2011-11-11 20:58 - 00000000 ____D () C:\ProgramData\NETGEAR 2014-02-11 00:00 - 2011-11-11 20:57 - 00000000 ____D () C:\Windows\Downloaded Installations 2014-02-11 00:00 - 2011-09-15 07:49 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite 2014-02-11 00:00 - 2011-09-15 07:46 - 00000000 ____D () C:\ProgramData\USBChargerPlus 2014-02-11 00:00 - 2011-09-15 07:43 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic 2014-02-11 00:00 - 2011-09-15 07:38 - 00000000 ____D () C:\Users\Public\Documents\ASUS Music Maker 2014-02-11 00:00 - 2011-09-15 07:35 - 00000000 ____D () C:\ProgramData\P4G 2014-02-11 00:00 - 2011-09-15 07:24 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-11 00:00 - 2011-09-15 07:24 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-11 00:00 - 2011-04-13 03:51 - 00000000 ____D () C:\ProgramData\Trend Micro 2014-02-11 00:00 - 2011-04-13 03:48 - 00000000 ____D () C:\ProgramData\OberonGameConsole 2014-02-11 00:00 - 2011-04-13 03:46 - 00000000 ____D () C:\Windows\en 2014-02-11 00:00 - 2011-04-13 03:44 - 00000000 ____D () C:\Windows\de 2014-02-11 00:00 - 2011-04-13 03:44 - 00000000 ____D () C:\Windows\ar 2014-02-11 00:00 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\es 2014-02-11 00:00 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\el 2014-02-11 00:00 - 2011-04-13 03:33 - 00000000 ____D () C:\ProgramData\ScanSoft 2014-02-11 00:00 - 2011-04-13 03:33 - 00000000 ____D () C:\ProgramData\Nuance 2014-02-11 00:00 - 2010-11-21 08:00 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-02-11 00:00 - 2009-07-29 06:20 - 00000000 ____D () C:\Windows\ASUS 2014-02-11 00:00 - 2009-07-29 06:20 - 00000000 ____D () C:\Windows\ABLKSR 2014-02-11 00:00 - 2009-07-14 06:37 - 00000000 ____D () C:\Windows\DigitalLocker 2014-02-10 23:58 - 2011-09-15 07:38 - 00000000 ____D () C:\ProgramData\MAGIX 2014-02-10 23:56 - 2014-01-19 18:22 - 00000000 ____D () C:\ProgramData\Free Download Manager 2014-02-10 23:56 - 2013-02-19 19:34 - 00000000 ____D () C:\ProgramData\hps 2014-02-10 23:56 - 2013-01-11 19:25 - 00000000 ____D () C:\ProgramData\Langenscheidt 2014-02-10 23:56 - 2011-11-26 10:40 - 00000000 ____D () C:\ProgramData\IncrediMail 2014-02-10 23:56 - 2011-11-26 10:40 - 00000000 ____D () C:\ProgramData\IM 2014-02-10 23:56 - 2011-11-24 20:54 - 00000000 ____D () C:\ProgramData\ifolor 2014-02-10 23:56 - 2011-11-11 20:25 - 00000000 ____D () C:\ProgramData\Avira 2014-02-10 23:56 - 2011-11-11 10:23 - 00000000 ____D () C:\ProgramData\FolderView 2014-02-10 23:56 - 2011-09-15 07:38 - 00000000 ____D () C:\ProgramData\CyberLink 2014-02-10 23:56 - 2011-09-15 07:38 - 00000000 ____D () C:\ProgramData\ASUS Music Maker 2014-02-10 23:56 - 2011-09-15 07:30 - 00000000 ____D () C:\ProgramData\Atheros 2014-02-10 23:56 - 2011-09-15 07:22 - 00000000 ____D () C:\ProgramData\Intel 2014-02-10 23:56 - 2011-04-13 03:49 - 00000000 ____D () C:\ProgramData\ChangeFolderView 2014-02-10 23:56 - 2011-04-13 03:33 - 00000000 ____D () C:\ProgramData\FLEXnet 2014-02-10 23:56 - 2011-04-13 03:33 - 00000000 ____D () C:\ProgramData\Downloaded Installations 2014-02-10 23:55 - 2013-01-11 18:28 - 00000000 ____D () C:\Program Files (x86)\WEVOSYS 2014-02-10 23:55 - 2012-12-05 18:43 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-02-10 23:55 - 2012-12-05 18:38 - 00000000 ____D () C:\Program Files (x86)\WOT 2014-02-10 23:55 - 2012-08-14 17:46 - 00000000 ____D () C:\ProgramData\ACD Systems 2014-02-10 23:55 - 2012-02-18 10:09 - 00000000 ___HD () C:\ProgramData\.syncID 2014-02-10 23:55 - 2012-02-18 10:08 - 00000000 ___HD () C:\ProgramData\.Syncables 2014-02-10 23:55 - 2011-12-19 21:40 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-02-10 23:55 - 2011-12-19 21:38 - 00000000 ____D () C:\ProgramData\Apple 2014-02-10 23:55 - 2011-11-13 12:12 - 00000000 ____D () C:\Program Files (x86)\WebSite X5 v8 - Evolution 2014-02-10 23:55 - 2011-11-12 14:06 - 00000000 ____D () C:\ProgramData\Adobe 2014-02-10 23:55 - 2011-09-15 07:28 - 00000000 ____D () C:\ProgramData\AmUStor 2014-02-10 23:55 - 2011-04-13 03:38 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-02-10 23:54 - 2014-02-10 23:29 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-02-10 23:54 - 2013-12-21 23:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-10 23:54 - 2013-03-20 20:55 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-10 23:54 - 2013-01-11 19:23 - 00000000 ____D () C:\Program Files (x86)\Vokabeltrainer 6 2014-02-10 23:54 - 2013-01-11 19:08 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-02-10 23:54 - 2012-12-09 09:53 - 00000000 ____D () C:\Program Files (x86)\Secure Banking 2014-02-10 23:54 - 2012-12-05 19:49 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-02-10 23:54 - 2012-12-05 19:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-10 23:54 - 2012-11-27 19:28 - 00000000 ____D () C:\Program Files (x86)\Secunia 2014-02-10 23:54 - 2012-11-27 07:19 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-02-10 23:54 - 2012-04-12 18:23 - 00000000 ____D () C:\Program Files (x86)\PDFCreator 2014-02-10 23:54 - 2012-02-18 18:40 - 00000000 ____D () C:\Program Files (x86)\Photo Notifier and Animation Creator 2014-02-10 23:54 - 2011-11-13 20:18 - 00000000 ____D () C:\Program Files (x86)\OpenOffice.org 3 2014-02-10 23:54 - 2011-11-11 11:18 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0 2014-02-10 23:54 - 2011-09-15 07:27 - 00000000 ____D () C:\Program Files (x86)\Realtek 2014-02-10 23:54 - 2011-04-13 03:49 - 00000000 ____D () C:\Program Files (x86)\syncables 2014-02-10 23:54 - 2011-04-13 03:33 - 00000000 ____D () C:\Program Files (x86)\Nuance 2014-02-10 23:54 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2014-02-10 23:52 - 2011-11-12 13:56 - 00000000 ____D () C:\Program Files (x86)\MotionStudios 2014-02-10 23:51 - 2013-02-19 19:29 - 00000000 ____D () C:\Program Files (x86)\Migros 2014-02-10 23:51 - 2012-12-04 19:51 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-02-10 23:51 - 2011-12-25 20:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services 2014-02-10 23:51 - 2011-12-25 20:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Sync Framework 2014-02-10 23:51 - 2011-12-25 20:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8 2014-02-10 23:51 - 2011-04-13 03:42 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2014-02-10 23:51 - 2011-04-13 03:25 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-02-10 23:50 - 2012-11-26 19:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-10 23:50 - 2011-12-25 20:02 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services 2014-02-10 23:49 - 2011-11-12 08:02 - 00000000 ____D () C:\Program Files (x86)\MAGIX 2014-02-10 23:45 - 2013-01-11 18:24 - 00000000 ____D () C:\Program Files (x86)\Langenscheidt 2014-02-10 23:41 - 2014-01-19 18:22 - 00000000 ____D () C:\Program Files (x86)\Free Download Manager 2014-02-10 23:41 - 2013-07-21 17:31 - 00000000 ____D () C:\Program Files (x86)\Garmin 2014-02-10 23:41 - 2013-01-08 19:35 - 00000000 ____D () C:\Program Files (x86)\digital publishing 2014-02-10 23:41 - 2012-04-21 09:30 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-02-10 23:41 - 2012-04-06 10:49 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-02-10 23:41 - 2012-01-02 13:38 - 00000000 ____D () C:\Program Files (x86)\FreePDF_XP 2014-02-10 23:41 - 2011-11-26 10:40 - 00000000 ____D () C:\Program Files (x86)\IncrediMail 2014-02-10 23:41 - 2011-11-24 20:54 - 00000000 ____D () C:\Program Files (x86)\ifolor 2014-02-10 23:41 - 2011-11-13 20:17 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-10 23:41 - 2011-09-15 07:38 - 00000000 ____D () C:\Program Files (x86)\CyberLink 2014-02-10 23:41 - 2011-09-15 07:18 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-02-10 23:41 - 2011-09-15 07:15 - 00000000 ____D () C:\Program Files (x86)\Intel 2014-02-10 23:41 - 2011-04-13 03:33 - 00000000 ____D () C:\Program Files (x86)\Google 2014-02-10 23:36 - 2014-01-17 19:00 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-02-10 23:36 - 2011-12-19 21:39 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2014-02-10 23:36 - 2011-09-15 07:38 - 00000000 ____D () C:\Program Files (x86)\ASUS Music Maker 2014-02-10 23:36 - 2011-09-15 07:32 - 00000000 ____D () C:\Program Files (x86)\Bluetooth Suite 2014-02-10 23:36 - 2011-09-15 07:30 - 00000000 ____D () C:\Program Files (x86)\Atheros 2014-02-10 23:36 - 2011-04-13 03:47 - 00000000 ____D () C:\Program Files (x86)\ASUS 2014-02-10 23:35 - 2014-02-10 23:29 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-10 23:35 - 2012-12-05 18:38 - 00000000 ____D () C:\Program Files\WOT 2014-02-10 23:35 - 2012-08-14 17:46 - 00000000 ____D () C:\Program Files (x86)\ACD Systems 2014-02-10 23:35 - 2012-01-14 17:54 - 00000000 ____D () C:\Program Files (x86)\Allway Sync 2014-02-10 23:35 - 2011-11-12 14:07 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-02-10 23:35 - 2011-09-15 07:35 - 00000000 ____D () C:\Program Files\P4G 2014-02-10 23:35 - 2011-09-15 07:28 - 00000000 ____D () C:\Program Files (x86)\ASM104xUSB3 2014-02-10 23:35 - 2011-09-15 07:28 - 00000000 ____D () C:\Program Files (x86)\AmIcoSingLun 2014-02-10 23:35 - 2011-04-13 03:36 - 00000000 ____D () C:\Program Files\Windows Live 2014-02-10 23:34 - 2014-01-03 18:47 - 00000000 ____D () C:\Program Files\Java 2014-02-10 23:34 - 2012-12-30 12:31 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-10 23:34 - 2012-12-04 19:51 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-02-10 23:34 - 2012-01-02 13:37 - 00000000 ____D () C:\Program Files\gs 2014-02-10 23:34 - 2011-12-25 20:02 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-02-10 23:34 - 2011-12-19 21:39 - 00000000 ____D () C:\Program Files\Bonjour 2014-02-10 23:34 - 2011-11-13 12:24 - 00000000 ____D () C:\Program Files\DIFX 2014-02-10 23:34 - 2011-09-15 07:36 - 00000000 ____D () C:\Program Files\ASUS 2014-02-10 23:34 - 2011-09-15 07:35 - 00000000 ____D () C:\Program Files\Intel 2014-02-10 23:34 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\DVD Maker 2014-02-10 23:34 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Vorlagen 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Startmenü 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Netzwerkumgebung 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Lokale Einstellungen 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Eigene Dateien 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Druckumgebung 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Documents\Eigene Musik 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Documents\Eigene Bilder 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Local\Verlauf 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Local\Anwendungsdaten 2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Anwendungsdaten 2014-02-10 23:31 - 2014-02-10 23:31 - 00001355 _____ () C:\Windows\TSSysprep.log 2014-02-10 23:31 - 2009-07-14 05:51 - 00000084 _____ () C:\Windows\setuperr.log 2014-02-10 23:30 - 2014-02-10 23:30 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2014-02-10 23:30 - 2014-02-10 23:30 - 00000000 ____D () C:\Program Files\Synaptics 2014-02-10 23:29 - 2014-02-10 23:29 - 00000000 ____D () C:\ProgramData\SonicFocus 2014-02-10 23:29 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help 2014-02-10 23:28 - 2014-02-10 23:28 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2014-02-10 23:28 - 2014-02-10 23:28 - 00000000 ____D () C:\Program Files\Realtek 2014-02-10 23:24 - 2009-07-29 07:03 - 00008192 __RSH () C:\BOOTSECT.BAK 2014-02-10 23:24 - 2009-07-14 06:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG 2014-02-10 23:24 - 2009-07-14 06:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template 2014-02-10 23:21 - 2014-02-10 23:21 - 00262144 _____ () C:\Windows\system32\config\userdiff 2014-02-10 23:00 - 2014-02-10 22:47 - 00000000 ___HD () C:\$INPLACE.~TR 2014-02-10 22:39 - 2011-09-15 07:11 - 02049309 _____ () C:\Windows\WindowsUpdate (1).log 2014-02-10 21:49 - 2014-01-27 18:25 - 00002544 _____ () C:\Windows\diagwrn.xml 2014-02-10 21:49 - 2014-01-27 18:25 - 00001890 _____ () C:\Windows\diagerr.xml 2014-02-10 21:24 - 2014-02-10 21:24 - 00005347 _____ () C:\Users\*****\Downloads\eicfg_removal_utility.zip 2014-02-10 21:23 - 2014-02-10 21:23 - 00000000 ____D () C:\Users\*****\Desktop\Neuer Ordner (2) 2014-02-10 21:22 - 2014-02-10 21:22 - 00000000 ____D () C:\Users\*****\Desktop\Neuer Ordner 2014-02-05 20:22 - 2012-09-29 21:19 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-05 20:22 - 2012-09-29 21:19 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-05 20:22 - 2011-11-20 12:36 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-05 19:51 - 2014-01-27 18:27 - 00003320 _____ () C:\Users\*****\Desktop\Windows-Kompatibilitätsbericht.htm 2014-02-02 18:33 - 2014-02-02 17:31 - 00002020 _____ () C:\Users\*****\Desktop\Windows Compatibility Report.htm 2014-01-20 12:42 - 2011-09-15 07:36 - 00002638 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-01-19 18:22 - 2014-01-19 18:22 - 00001069 _____ () C:\Users\*****\Desktop\Free Download Manager.lnk 2014-01-19 18:20 - 2014-01-19 18:20 - 00614784 _____ (Chip Digital GmbH) C:\Users\*****\Desktop\Free Download Manager - CHIP-Downloader.exe 2014-01-17 19:05 - 2013-08-17 09:11 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-17 19:00 - 2014-01-17 19:00 - 00002068 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-01-17 18:58 - 2014-01-17 18:53 - 140300048 _____ () C:\Users\*****\Downloads\avira_antivirus_suite_de.exe 2014-01-15 20:27 - 2014-01-15 20:27 - 00448512 _____ (OldTimer Tools) C:\Users\*****\Desktop\TFC.exe 2014-01-14 06:45 - 2014-01-14 06:45 - 00987410 _____ () C:\Users\*****\Desktop\SecurityCheck.exe 2014-01-13 21:05 - 2014-01-13 21:04 - 02347384 _____ (ESET) C:\Users\*****\Desktop\esetsmartinstaller_enu.exe 2014-01-13 20:45 - 2014-01-13 20:21 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2014-01-13 20:44 - 2009-07-14 03:34 - 00000514 _____ () C:\Windows\win.ini 2014-01-13 20:17 - 2014-01-13 20:17 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-*****-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat 2014-01-13 20:17 - 2014-01-13 20:17 - 00000000 ____D () C:\RegBackup 2014-01-13 19:31 - 2014-01-13 19:31 - 02903255 _____ () C:\Users\*****\Desktop\tweaking.com_windows_repair_aio.zip Some content of TEMP: ==================== C:\Users\*****\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-10 23:26 ==================== End Of Log ============================ --- --- --- |
12.02.2014, 18:23 | #52 |
/// the machine /// TB-Ausbilder | PUP optional Candy Trotz der Rep Installation? Irgendwas ist da total im Ars..... Ich würde jetzt Daten sichern und dann einmal formatieren und neu aufsetzen, wenn dann immer noch Stress ist ist es die Hardware.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.02.2014, 22:14 | #53 |
| PUP optional Candy ja trotz der rep. das war eigentlcih nicht das, was ich von dir hören wollte aber da kannst du ja nichts dafür die programme kann ich nicht sichern oder, nur die daten, also fotos etc.? macht ev. auch nicht sinn, die software zu sichern? wie formatiere ich? und wie kann ich nachher windows installieren? mit dieser ISO-dvd die ich für die reparatur gemacht habe? DANKE! hab noch das sfc/scannow gemacht über start ausführen. da findet es nichts: Der Windows-Ressourcenschutz hat keine Integritätsverletzungen gefunden. ich hab nun beim googeln noch gefunden, dass asus web storage daran schuld sein könnte. so wie ich gelesen habe wird eine deinstallation empfohlen. bei anderen hat das offenbar genützt. soll/darf ich das probieren? heute ist er nicht hängen geblieben. |
13.02.2014, 21:48 | #54 |
/// the machine /// TB-Ausbilder | PUP optional Candy Daten sichern, Programme nicht. Einfach die vollwertige WIndows Scheibe rein (sollte auch mit der ISO gehen) von der booten und formatieren
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.02.2014, 23:24 | #55 |
| PUP optional Candy ausser die gebrannte ISO-dvd hab ich ja eben keine windows cd :-( ? hab das asus webstorage heute abend deinstalliert. ich guck jetzt bis samstag was passiert. formatieren könnt ich eh nicht vor dem wochenende. danke :-) |
14.02.2014, 17:37 | #56 |
/// the machine /// TB-Ausbilder | PUP optional Candy ok
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.02.2014, 11:19 | #57 |
| PUP optional Candy hey, die windwos explorer meldung kommt tatsächlich nicht mehr nur habe ich jetzt ein anderes problem. es geht ein fenster auf, zum aktivieren von windows. ich gebe also erneut meinen produkte key, der unten auf meinem laoptop aufgeklebt ist, ein. aber es heisst es sei "anscheinend kein gültiger windows 7 produkte key".was soll ich nun tun? ich hab ihn richtig abgeschrieben und eingegeben. ah, hat sich erledigt konnte das über diese automatische telefon hotline aktivieren lassen von windows ist jetzt aktiviert und in ordnung. nun bin ich gespannt auf die nächsten schritte. weiss gar nicht ob mein pc jetzt sauber ist oder nicht. beim aufstarten ist er noch extrem langsam. |
16.02.2014, 07:12 | #58 |
/// the machine /// TB-Ausbilder | PUP optional Candy poste mal en frisches FRST Logfile, ich schaue mal drüber
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.02.2014, 10:18 | #59 |
| PUP optional Candy hallöchen ich kann das log-file spätestens morgen abend machen. hab extra noch ein bisschen zugewartet zum gucken, wie es sich entwickelt. bis jetzt alles i.o. habe treiber für die FN-tasten neu runtergeladen von asus sowie für das touch-pad, funktioniert alles. auch die explorer meldung kam definitiv nicht mehr. nur langsam ist er beim aufstarten geworden. das passt mir noch nicht. log-file kommt also heute oder wahrscheinlicher morgen abend! danke & gruss |
21.02.2014, 09:54 | #60 |
/// the machine /// TB-Ausbilder | PUP optional Candy ok
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu PUP optional Candy |
administrator, anti-malware, asus, avira, cc cleaner, detected, explorer, home, hängen, laptop, logfiles, maleware, malwarebytes, mozilla, office, programm, prüfen, pup optional, registry, software, system, update, updates, was tun?, windows, windows explorer, windows update |