Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: PUP optional Candy

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 09.02.2014, 09:29   #46
schrauber
/// the machine
/// TB-Ausbilder
 

PUP optional Candy - Standard

PUP optional Candy



Du lädst die ISO
Du lädst das kleine Removal ZIP und lässt es laufen
Dann kannst Du die ISO auf die DVD brennen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.02.2014, 20:53   #47
drud
 
PUP optional Candy - Standard

PUP optional Candy



danke :-) ich versuch das morgen abend!
__________________


Alt 10.02.2014, 17:13   #48
schrauber
/// the machine
/// TB-Ausbilder
 

PUP optional Candy - Standard

PUP optional Candy



ok
__________________
__________________

Alt 11.02.2014, 09:22   #49
drud
 
PUP optional Candy - Standard

PUP optional Candy



so, das upgrade läuft :-) hoffe ich hab nun das richtige windows erwischt. aber ich denke sonst hätt er wieder reklamiert. hab mich irgendwie relativ flüchtig durchgeklickt, weil ich ja schon do oft angefangen hatte. es hatte dann vier zur auswahl. könnt mich höchstens verklickt haben. aber das glaub ich nicht. ich denk das kommt jetzt gut. eben sonst hät er sicher wieder reklamiert wenns eine andere version gewesen wär... mal gucken wie es dann morgen aussieht. läuft jetzt über nacht...

gute Nachrichten

Es scheint geklappt zu haben mit der ISO und dem windows upgrade

nun bin ich gespannt, wie es weitergeht. ich denke wir müssen irgendwie noch prüfen ob nun von dem pup.optional zeugs wirklich alles weg ist.

also her mit neuen aufgaben


Alt 11.02.2014, 19:03   #50
schrauber
/// the machine
/// TB-Ausbilder
 

PUP optional Candy - Standard

PUP optional Candy



nice job

dann bitte mal ein frisches FRST Logfile, und bitte mal aufzählen was noch an Problemen da ist

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 11.02.2014, 22:28   #51
drud
 
PUP optional Candy - Standard

PUP optional Candy



also normalerweise gehe ich ja mit firefox ins netz. da jetzt die symbole anders sind, kam ich vorher zufällig auf internet explorer. da meldet mir secure banking malware.

windows explorer bleibt immer noch hängen das ist unverändert, trotz windwos reparatur.

frst-log folgt nachher. muss erst was fertig machen. aber wollte das vorab schreiben, nicht dass ich es aufs mal noch vergesse...

so sachen wie lautstärkeanzeige (mitten auf dem bilschirm, nicht unten rechts) oder anzeige von ein-/ausschalten des touchpads gehen auch nicht.


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-02-2014 01
Ran by ***** (administrator) on *****-PC on 11-02-2014 22:27:07
Running from C:\Users\*****\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
() C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(ASUS) C:\Windows\AsScrPro.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Splashtop Inc.) C:\ASUS.SYS\SIONExportService.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(FreeDownloadManager.ORG) C:\Program Files (x86)\Free Download Manager\fdm.exe
(Secure Banking) C:\Program Files (x86)\Secure Banking\SecureBanking.exe
(syncables, LLC) C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
() C:\Program Files (x86)\Secure Banking\sbservice.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-06-03] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.)
HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379552 2011-03-13] (Atheros Commnucations)
HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [617120 2011-03-13] (Atheros Communications)
HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4156 2010-04-16] ()
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [SynAsusAcpi] - C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-09] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.)
HKLM-x32\...\Run: [TrayServer] - C:\Program Files (x86)\MAGIX\Video_deluxe_17_Plus_Sonderedition\TrayServer.exe [90112 2008-08-07] (MAGIX AG)
HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4073853582-3472843793-526417432-1001\...\Run: [Free Download Manager] - C:\Program Files (x86)\Free Download Manager\fdm.exe [6950400 2013-10-25] (FreeDownloadManager.ORG)
HKU\S-1-5-21-4073853582-3472843793-526417432-1001\...\Run: [SecureBanking] - C:\Program Files (x86)\Secure Banking\SecureBanking.exe [507904 2013-07-06] (Secure Banking)
HKU\S-1-5-21-4073853582-3472843793-526417432-1001\...\Run: [Syncables] - C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-07-19] (syncables, LLC)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-11-14] (NVIDIA Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-11-14] (NVIDIA Corporation)
Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\phase-6 Reminder.lnk
ShortcutTarget: phase-6 Reminder.lnk -> C:\Users\*****\AppData\Local\phase-6\phase-6-compendio\reminder\reminder.exe (phase-6)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.ch/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {FAD6394E-D719-45AD-8C59-99A8E90A359C} URL = hxxp://ch.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: No Name - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -  No File
BHO-x32: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
BHO-x32: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
Toolbar: HKCU - WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mpazrgl1.default
FF Homepage: hxxp://www.google.ch/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Garmin Communicator - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mpazrgl1.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013-11-23]
FF Extension: WOT - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mpazrgl1.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-28]
FF Extension: Adblock Plus - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mpazrgl1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-10-06]

Chrome: 
=======
CHR HomePage: hxxp://www.google.com/ig/redirectdomain?brand=ASUT&bmod=ASUT

==================== Services (Whitelisted) =================

R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [908856 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-03-13] (Atheros)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [249856 2011-02-15] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1328736 2012-09-24] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [656480 2012-09-24] (Secunia)
R2 Splashtop MDES; C:\ASUS.SYS\SIONExportService.exe [338208 2011-05-10] (Splashtop Inc.)

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-09] (Avira Operations GmbH & Co. KG)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-11-14] (NVIDIA Corporation)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-17] ()

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-11 20:57 - 2014-02-11 20:57 - 00183920 _____ () C:\Users\*****\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-11 07:09 - 2014-02-11 07:09 - 01593564 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-11 07:03 - 2014-02-11 07:03 - 00001407 _____ () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-02-11 07:02 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-02-11 07:02 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-02-11 07:02 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-02-11 07:02 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-02-11 07:02 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-02-11 07:02 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-02-11 07:01 - 2014-02-11 07:03 - 00001441 _____ () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-02-11 07:00 - 2014-02-11 07:00 - 00000020 ___SH () C:\Users\*****\ntuser.ini
2014-02-11 07:00 - 2011-11-19 15:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-02-11 07:00 - 2011-11-19 15:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Programme
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Favoriten
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2014-02-11 01:13 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-02-11 01:13 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-02-11 01:13 - 2012-02-17 05:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-02-11 01:13 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-02-11 01:07 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-02-11 01:07 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-02-11 01:07 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-02-11 01:07 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-02-11 01:07 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-02-11 01:07 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-02-11 01:07 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-02-11 01:07 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-02-11 01:07 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-02-11 00:37 - 2014-02-11 00:37 - 00022960 _____ () C:\Windows\system32\emptyregdb.dat
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Apple Computer
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\ifolor
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\Apple Computer
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Apple Computer
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\ifolor
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\Apple Computer
2014-02-10 23:32 - 2014-02-11 07:00 - 00000000 ____D () C:\Users\*****
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Vorlagen
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Startmenü
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Netzwerkumgebung
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Lokale Einstellungen
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Eigene Dateien
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Druckumgebung
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Documents\Eigene Musik
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Documents\Eigene Bilder
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Local\Verlauf
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Local\Anwendungsdaten
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Anwendungsdaten
2014-02-10 23:32 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-02-10 23:32 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-02-10 23:31 - 2014-02-10 23:31 - 00001355 _____ () C:\Windows\TSSysprep.log
2014-02-10 23:30 - 2014-02-10 23:30 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2014-02-10 23:30 - 2014-02-10 23:30 - 00000000 ____D () C:\Program Files\Synaptics
2014-02-10 23:29 - 2014-02-11 20:57 - 01572853 _____ () C:\Windows\WindowsUpdate.log
2014-02-10 23:29 - 2014-02-11 00:00 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-02-10 23:29 - 2014-02-10 23:54 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-10 23:29 - 2014-02-10 23:35 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-02-10 23:29 - 2014-02-10 23:29 - 00000000 ____D () C:\ProgramData\SonicFocus
2014-02-10 23:29 - 2013-11-11 16:02 - 06674208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-02-10 23:29 - 2013-11-11 16:02 - 03490080 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2014-02-10 23:29 - 2013-11-11 16:01 - 03467927 _____ () C:\Windows\system32\nvcoproc.bin
2014-02-10 23:29 - 2013-11-11 16:01 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-02-10 23:29 - 2013-11-11 16:01 - 01065248 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2014-02-10 23:29 - 2013-11-11 16:01 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-02-10 23:29 - 2013-11-11 16:01 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-02-10 23:29 - 2013-11-11 16:01 - 00067072 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2014-02-10 23:29 - 2013-11-11 16:01 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-02-10 23:28 - 2014-02-10 23:28 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2014-02-10 23:28 - 2014-02-10 23:28 - 00000000 ____D () C:\Program Files\Realtek
2014-02-10 23:24 - 2014-02-11 06:59 - 00000000 ____D () C:\Windows\Panther
2014-02-10 23:21 - 2014-02-10 23:21 - 00262144 _____ () C:\Windows\system32\config\userdiff
2014-02-10 23:07 - 2014-02-11 00:39 - 00000000 ___HD () C:\$WINDOWS.~Q
2014-02-10 22:47 - 2014-02-10 23:00 - 00000000 ___HD () C:\$INPLACE.~TR
2014-02-10 22:04 - 2014-02-11 00:39 - 00006165 _____ () C:\Windows\comsetup.log
2014-02-10 21:24 - 2014-02-11 00:28 - 00000000 ____D () C:\Users\*****\Downloads\eicfg_removal_utility
2014-02-10 21:24 - 2014-02-10 21:24 - 00005347 _____ () C:\Users\*****\Downloads\eicfg_removal_utility.zip
2014-02-10 21:23 - 2014-02-11 00:28 - 00000000 ____D () C:\Users\*****\Documents\Iso alt
2014-02-10 21:23 - 2014-02-10 21:23 - 00000000 ____D () C:\Users\*****\Desktop\Neuer Ordner (2)
2014-02-10 21:22 - 2014-02-10 21:22 - 00000000 ____D () C:\Users\*****\Desktop\Neuer Ordner
2014-02-10 21:13 - 2014-02-11 00:27 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-02-02 17:31 - 2014-02-02 18:33 - 00002020 _____ () C:\Users\*****\Desktop\Windows Compatibility Report.htm
2014-01-27 18:27 - 2014-02-05 19:51 - 00003320 _____ () C:\Users\*****\Desktop\Windows-Kompatibilitätsbericht.htm
2014-01-27 18:25 - 2014-02-10 21:49 - 00002544 _____ () C:\Windows\diagwrn.xml
2014-01-27 18:25 - 2014-02-10 21:49 - 00001890 _____ () C:\Windows\diagerr.xml
2014-01-19 18:22 - 2014-02-11 00:26 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Free Download Manager
2014-01-19 18:22 - 2014-02-10 23:56 - 00000000 ____D () C:\ProgramData\Free Download Manager
2014-01-19 18:22 - 2014-02-10 23:41 - 00000000 ____D () C:\Program Files (x86)\Free Download Manager
2014-01-19 18:22 - 2014-01-19 18:22 - 00001069 _____ () C:\Users\*****\Desktop\Free Download Manager.lnk
2014-01-19 18:20 - 2014-01-19 18:20 - 00614784 _____ (Chip Digital GmbH) C:\Users\*****\Desktop\Free Download Manager - CHIP-Downloader.exe
2014-01-17 19:01 - 2014-02-11 00:26 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Avira
2014-01-17 19:00 - 2014-02-10 23:36 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-01-17 19:00 - 2014-01-17 19:00 - 00002068 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-01-17 19:00 - 2013-12-09 11:37 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-01-17 19:00 - 2013-12-09 11:37 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-01-17 19:00 - 2013-12-09 11:37 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-01-17 19:00 - 2013-12-09 11:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-01-17 18:53 - 2014-01-17 18:58 - 140300048 _____ () C:\Users\*****\Downloads\avira_antivirus_suite_de.exe
2014-01-15 20:27 - 2014-01-15 20:27 - 00448512 _____ (OldTimer Tools) C:\Users\*****\Desktop\TFC.exe
2014-01-14 06:45 - 2014-01-14 06:45 - 00987410 _____ () C:\Users\*****\Desktop\SecurityCheck.exe
2014-01-13 21:04 - 2014-01-13 21:05 - 02347384 _____ (ESET) C:\Users\*****\Desktop\esetsmartinstaller_enu.exe
2014-01-13 20:21 - 2014-01-13 20:45 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2014-01-13 20:17 - 2014-01-13 20:17 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-*****-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-01-13 20:17 - 2014-01-13 20:17 - 00000000 ____D () C:\RegBackup
2014-01-13 19:32 - 2014-02-11 00:27 - 00000000 ____D () C:\Users\*****\Desktop\tweaking.com_windows_repair_aio
2014-01-13 19:31 - 2014-01-13 19:31 - 02903255 _____ () C:\Users\*****\Desktop\tweaking.com_windows_repair_aio.zip

==================== One Month Modified Files and Folders =======

2014-02-11 22:27 - 2014-01-04 09:34 - 00019717 _____ () C:\Users\*****\Desktop\FRST.txt
2014-02-11 22:27 - 2014-01-04 09:34 - 00000000 ____D () C:\FRST
2014-02-11 22:26 - 2014-01-07 22:03 - 00000000 ____D () C:\Users\*****\Desktop\FRST-OlderVersion
2014-02-11 22:26 - 2014-01-04 09:29 - 02151424 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe
2014-02-11 22:23 - 2009-07-14 05:45 - 00018224 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-11 22:23 - 2009-07-14 05:45 - 00018224 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-11 22:22 - 2012-09-29 21:19 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-11 21:18 - 2014-02-10 23:29 - 01572853 _____ () C:\Windows\WindowsUpdate.log
2014-02-11 20:58 - 2011-11-11 10:23 - 00000000 ____D () C:\Users\*****\AppData\Local\VirtualStore
2014-02-11 20:57 - 2014-02-11 20:57 - 00183920 _____ () C:\Users\*****\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-11 20:54 - 2010-11-21 07:50 - 00699342 _____ () C:\Windows\system32\perfh007.dat
2014-02-11 20:54 - 2010-11-21 07:50 - 00149450 _____ () C:\Windows\system32\perfc007.dat
2014-02-11 20:54 - 2009-07-14 06:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-11 20:48 - 2011-11-11 10:23 - 00000000 ___HD () C:\ASUS.DAT
2014-02-11 20:48 - 2011-09-15 07:37 - 00000012 ____H () C:\dvmexp.idx
2014-02-11 20:47 - 2011-09-15 07:23 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-02-11 20:47 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-11 20:47 - 2009-07-14 05:51 - 00754607 _____ () C:\Windows\setupact.log
2014-02-11 07:16 - 2011-12-26 13:15 - 00000000 ____D () C:\Users\*****\Documents\Outlook-Dateien
2014-02-11 07:09 - 2014-02-11 07:09 - 01593564 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-11 07:05 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-02-11 07:03 - 2014-02-11 07:03 - 00001407 _____ () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-02-11 07:03 - 2014-02-11 07:01 - 00001441 _____ () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-02-11 07:03 - 2011-11-11 10:24 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-11 07:03 - 2011-11-11 10:24 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-02-11 07:00 - 2014-02-11 07:00 - 00000020 ___SH () C:\Users\*****\ntuser.ini
2014-02-11 07:00 - 2014-02-10 23:32 - 00000000 ____D () C:\Users\*****
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Programme
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Favoriten
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-02-11 06:59 - 2014-02-11 06:59 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2014-02-11 06:59 - 2014-02-10 23:24 - 00000000 ____D () C:\Windows\Panther
2014-02-11 06:59 - 2009-07-29 06:10 - 00000000 ____D () C:\Recovery
2014-02-11 06:59 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-02-11 06:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Recovery
2014-02-11 06:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Windows NT
2014-02-11 06:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-11 01:07 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\restore
2014-02-11 01:00 - 2010-11-21 04:47 - 00011170 _____ () C:\Windows\PFRO.log
2014-02-11 00:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Registration
2014-02-11 00:39 - 2014-02-10 23:07 - 00000000 ___HD () C:\$WINDOWS.~Q
2014-02-11 00:39 - 2014-02-10 22:04 - 00006165 _____ () C:\Windows\comsetup.log
2014-02-11 00:37 - 2014-02-11 00:37 - 00022960 _____ () C:\Windows\system32\emptyregdb.dat
2014-02-11 00:36 - 2012-11-27 07:19 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-02-11 00:36 - 2011-12-25 20:04 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-02-11 00:33 - 2009-07-14 05:45 - 00585064 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Apple Computer
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\ifolor
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default\AppData\Local\Apple Computer
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Apple Computer
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\ifolor
2014-02-11 00:30 - 2014-02-11 00:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\Apple Computer
2014-02-11 00:30 - 2009-07-14 05:46 - 00005157 _____ () C:\Windows\DtcInstall.log
2014-02-11 00:30 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-02-11 00:30 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-02-11 00:30 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-02-11 00:30 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-02-11 00:28 - 2014-02-10 21:24 - 00000000 ____D () C:\Users\*****\Downloads\eicfg_removal_utility
2014-02-11 00:28 - 2014-02-10 21:23 - 00000000 ____D () C:\Users\*****\Documents\Iso alt
2014-02-11 00:28 - 2013-08-03 14:45 - 00000000 ____D () C:\Users\*****\Documents\MAGIX Speed
2014-02-11 00:28 - 2013-01-26 23:58 - 00000000 ____D () C:\Users\*****\Documents\MAGIX_Video_deluxe_17_Plus_Sonderedition
2014-02-11 00:28 - 2012-08-31 20:11 - 00000000 ____D () C:\Users\*****\Documents\My Digital Editions
2014-02-11 00:28 - 2011-11-24 21:07 - 00000000 ____D () C:\Users\*****\Documents\ifolor Designer Dateien
2014-02-11 00:28 - 2011-11-12 08:05 - 00000000 ___RD () C:\Users\*****\Documents\MAGIX
2014-02-11 00:27 - 2014-02-10 21:13 - 00000000 ___RD () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-02-11 00:27 - 2014-01-13 19:32 - 00000000 ____D () C:\Users\*****\Desktop\tweaking.com_windows_repair_aio
2014-02-11 00:27 - 2013-05-24 19:32 - 00000000 ____D () C:\Users\*****\Desktop\Sprachen
2014-02-11 00:27 - 2013-05-14 13:59 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Phase6
2014-02-11 00:27 - 2013-05-14 13:59 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\phase-6
2014-02-11 00:27 - 2013-01-08 19:38 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\digital publishing
2014-02-11 00:27 - 2012-12-05 19:49 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Opera
2014-02-11 00:27 - 2012-10-05 18:22 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Mozilla
2014-02-11 00:27 - 2012-09-23 16:54 - 00000000 ____D () C:\Users\*****\Desktop\Ricardo Bilder
2014-02-11 00:27 - 2012-04-06 10:39 - 00000000 ____D () C:\Users\*****\AppData\Roaming\XMedia Recode
2014-02-11 00:27 - 2012-03-23 22:01 - 00000000 ____D () C:\Users\*****\Documents\ifolor
2014-02-11 00:27 - 2012-01-14 18:01 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Sync App Settings
2014-02-11 00:27 - 2011-12-26 18:01 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-02-11 00:27 - 2011-11-27 17:09 - 00000000 ____D () C:\Users\*****\Documents\CyberLink
2014-02-11 00:27 - 2011-11-24 20:23 - 00000000 ____D () C:\Users\*****\AppData\Roaming\TuneUp Software
2014-02-11 00:27 - 2011-11-23 20:05 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Skype
2014-02-11 00:27 - 2011-11-13 20:19 - 00000000 ____D () C:\Users\*****\AppData\Roaming\OpenOffice.org
2014-02-11 00:27 - 2011-11-11 10:25 - 00000000 ____D () C:\Users\*****\Documents\Bluetooth Folder
2014-02-11 00:27 - 2011-11-11 10:22 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
2014-02-11 00:27 - 2011-11-11 10:22 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic
2014-02-11 00:26 - 2014-01-19 18:22 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Free Download Manager
2014-02-11 00:26 - 2014-01-17 19:01 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Avira
2014-02-11 00:26 - 2014-01-05 17:32 - 00000000 ____D () C:\Users\*****\AppData\Local\NVIDIA Corporation
2014-02-11 00:26 - 2014-01-05 17:30 - 00000000 ____D () C:\Users\*****\AppData\Local\NVIDIA
2014-02-11 00:26 - 2014-01-03 18:44 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Google
2014-02-11 00:26 - 2013-05-14 13:59 - 00000000 ____D () C:\Users\*****\AppData\Local\phase-6
2014-02-11 00:26 - 2013-01-11 19:25 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Langenscheidt
2014-02-11 00:26 - 2013-01-11 19:15 - 00000000 ____D () C:\Users\*****\AppData\Roaming\lingDIALOG
2014-02-11 00:26 - 2013-01-11 18:30 - 00000000 ____D () C:\Users\*****\AppData\Roaming\conkeror.mozdev.org
2014-02-11 00:26 - 2012-12-05 19:49 - 00000000 ____D () C:\Users\*****\AppData\Local\Opera
2014-02-11 00:26 - 2012-11-26 19:34 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Malwarebytes
2014-02-11 00:26 - 2012-08-27 19:16 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Garmin
2014-02-11 00:26 - 2012-08-14 17:47 - 00000000 ____D () C:\Users\*****\AppData\Roaming\ACD Systems
2014-02-11 00:26 - 2012-07-29 13:01 - 00000000 ____D () C:\Users\*****\AppData\Local\Mozilla
2014-02-11 00:26 - 2012-04-21 09:30 - 00000000 ____D () C:\Users\*****\AppData\Roaming\FileZilla
2014-02-11 00:26 - 2012-04-06 10:49 - 00000000 ____D () C:\Users\*****\AppData\Roaming\DVDVideoSoft
2014-02-11 00:26 - 2012-01-19 21:42 - 00000000 ____D () C:\Users\*****\AppData\Local\Windows Live Writer
2014-02-11 00:26 - 2011-12-19 21:42 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Apple Computer
2014-02-11 00:26 - 2011-11-26 10:49 - 00000000 ____D () C:\Users\*****\AppData\Local\mquadr.at
2014-02-11 00:26 - 2011-11-24 20:54 - 00000000 ____D () C:\Users\*****\AppData\Roaming\ifolor
2014-02-11 00:26 - 2011-11-13 12:50 - 00000000 ____D () C:\Users\*****\AppData\Roaming\CyberLink
2014-02-11 00:26 - 2011-11-13 12:25 - 00000000 ____D () C:\Users\*****\AppData\Local\OLYMPUS
2014-02-11 00:26 - 2011-11-12 08:04 - 00000000 ____D () C:\Users\*****\AppData\Roaming\MAGIX
2014-02-11 00:26 - 2011-11-12 08:04 - 00000000 ____D () C:\Users\*****\AppData\Local\Xara
2014-02-11 00:26 - 2011-11-11 19:43 - 00000000 ____D () C:\Users\*****\AppData\Roaming\ASUS WebStorage
2014-02-11 00:26 - 2011-11-11 19:36 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Macromedia
2014-02-11 00:26 - 2011-11-11 19:28 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Adobe
2014-02-11 00:26 - 2011-11-11 19:16 - 00000000 ____D () C:\Users\*****\AppData\Local\Power2Go
2014-02-11 00:26 - 2011-11-11 12:33 - 00000000 ____D () C:\Users\*****\AppData\Roaming\FLEXnet
2014-02-11 00:21 - 2012-09-29 21:34 - 00000000 ____D () C:\Users\*****\AppData\Local\Macromedia
2014-02-11 00:21 - 2011-12-25 20:01 - 00000000 ____D () C:\Users\*****\AppData\Local\Microsoft Help
2014-02-11 00:21 - 2011-11-26 10:41 - 00000000 ____D () C:\Users\*****\AppData\Local\IM
2014-02-11 00:21 - 2011-11-12 08:22 - 00000000 ____D () C:\Users\*****\AppData\Local\MAGIX_AG
2014-02-11 00:21 - 2011-11-12 08:04 - 00000000 ____D () C:\Users\*****\AppData\Local\MAGIX
2014-02-11 00:21 - 2011-11-11 12:39 - 00000000 ____D () C:\Users\*****\AppData\Local\Microsoft Games
2014-02-11 00:20 - 2013-05-14 13:59 - 00000000 ____D () C:\Users\*****\.swt
2014-02-11 00:20 - 2013-05-14 13:59 - 00000000 ____D () C:\Users\*****\.phase-6
2014-02-11 00:20 - 2013-01-11 19:15 - 00000000 ____D () C:\Users\*****\.pknowledge
2014-02-11 00:20 - 2013-01-11 18:30 - 00000000 ____D () C:\Users\*****\AppData\Local\conkeror.mozdev.org
2014-02-11 00:20 - 2013-01-08 19:42 - 00000000 ____D () C:\Users\*****\AppData\Local\digital publishing
2014-02-11 00:20 - 2012-08-14 17:47 - 00000000 ____D () C:\Users\*****\AppData\Local\ACD Systems
2014-02-11 00:20 - 2012-08-14 17:44 - 00000000 ____D () C:\Users\*****\AppData\Local\Downloaded Installations
2014-02-11 00:20 - 2012-04-20 18:03 - 00000000 ____D () C:\Users\*****\AppData\Local\Fujifilm
2014-02-11 00:20 - 2011-12-20 22:03 - 00000000 ____D () C:\Users\*****\AppData\Local\Cyberlink
2014-02-11 00:20 - 2011-12-19 21:42 - 00000000 ____D () C:\Users\*****\AppData\Local\Apple Computer
2014-02-11 00:20 - 2011-12-19 21:39 - 00000000 ____D () C:\Users\*****\AppData\Local\Apple
2014-02-11 00:20 - 2011-11-20 13:19 - 00000000 ____D () C:\Users\*****\AppData\Local\BMExplorer
2014-02-11 00:20 - 2011-11-13 20:03 - 00000000 ____D () C:\Users\*****\AppData\Local\Adobe
2014-02-11 00:20 - 2011-11-11 20:57 - 00000000 ____D () C:\Users\*****\AppData\Local\CrashDumps
2014-02-11 00:20 - 2011-11-11 19:25 - 00000000 ____D () C:\Users\*****\AppData\Local\Google
2014-02-11 00:20 - 2011-11-11 10:23 - 00000000 ____D () C:\Users\*****\AppData\Local\ASUS
2014-02-11 00:03 - 2014-01-05 17:20 - 00000000 ____D () C:\Windows\SysWOW64\NV
2014-02-11 00:03 - 2012-12-12 14:47 - 00000000 __SHD () C:\Windows\SysWOW64\%APPDATA%
2014-02-11 00:03 - 2011-04-13 03:47 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-02-11 00:03 - 2011-02-18 21:08 - 00000000 ____D () C:\Windows\system32\SPReview
2014-02-11 00:03 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns
2014-02-11 00:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-02-11 00:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-02-11 00:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-02-11 00:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-02-11 00:03 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep
2014-02-11 00:02 - 2014-01-05 17:20 - 00000000 ____D () C:\Windows\system32\NV
2014-02-11 00:02 - 2013-03-13 21:59 - 00000000 __SHD () C:\Windows\system32\%APPDATA%
2014-02-11 00:02 - 2012-02-17 20:10 - 00000000 ____D () C:\Windows\system32\Macromed
2014-02-11 00:02 - 2011-09-15 07:46 - 00000000 ____D () C:\Windows\system32\AsMakeLink
2014-02-11 00:02 - 2011-04-13 03:44 - 00000000 ____D () C:\Windows\ru
2014-02-11 00:02 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\nl
2014-02-11 00:02 - 2011-02-18 20:48 - 00000000 ____D () C:\Windows\system32\EventProviders
2014-02-11 00:02 - 2010-11-21 08:00 - 00000000 ____D () C:\Windows\ShellNew
2014-02-11 00:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\oobe
2014-02-11 00:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-02-11 00:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-02-11 00:01 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\it
2014-02-11 00:01 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\he
2014-02-11 00:01 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\fr
2014-02-11 00:01 - 2009-07-29 06:20 - 00000000 ____D () C:\Windows\Log
2014-02-11 00:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\IME
2014-02-11 00:00 - 2014-02-10 23:29 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-02-11 00:00 - 2014-01-03 20:49 - 00000000 ____D () C:\Windows\ERUNT
2014-02-11 00:00 - 2013-12-25 12:38 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-02-11 00:00 - 2013-07-07 20:44 - 00000000 ____D () C:\ProgramData\Magix Shared
2014-02-11 00:00 - 2013-05-14 13:59 - 00000000 ____D () C:\ProgramData\Phase6
2014-02-11 00:00 - 2013-02-19 19:34 - 00000000 ____D () C:\ProgramData\tmp
2014-02-11 00:00 - 2012-12-02 17:21 - 00000000 ____D () C:\Windows\erdnt
2014-02-11 00:00 - 2012-12-02 16:42 - 00000000 ____D () C:\Users\mõder
2014-02-11 00:00 - 2012-11-27 07:19 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-11 00:00 - 2012-11-26 19:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-11 00:00 - 2012-07-29 13:01 - 00000000 ____D () C:\ProgramData\Mozilla
2014-02-11 00:00 - 2012-03-20 21:51 - 00000000 __HDC () C:\ProgramData\{D3257C41-1D3A-407B-A943-682D251F5FD2}
2014-02-11 00:00 - 2012-02-18 18:40 - 00000000 ____D () C:\ProgramData\Photo Notifier and Animation Creator
2014-02-11 00:00 - 2012-01-14 17:55 - 00000000 ____D () C:\ProgramData\Sync App Settings
2014-02-11 00:00 - 2011-12-25 20:01 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-11 00:00 - 2011-12-19 21:40 - 00000000 ____D () C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2014-02-11 00:00 - 2011-11-26 10:49 - 00000000 ____D () C:\ProgramData\mquadr.at
2014-02-11 00:00 - 2011-11-24 20:21 - 00000000 __SHD () C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2014-02-11 00:00 - 2011-11-24 20:21 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-02-11 00:00 - 2011-11-23 20:05 - 00000000 ____D () C:\ProgramData\Skype
2014-02-11 00:00 - 2011-11-13 20:17 - 00000000 ____D () C:\ProgramData\Sun
2014-02-11 00:00 - 2011-11-13 12:50 - 00000000 ____D () C:\Users\Public\CyberLink
2014-02-11 00:00 - 2011-11-11 20:58 - 00000000 ____D () C:\ProgramData\NETGEAR
2014-02-11 00:00 - 2011-11-11 20:57 - 00000000 ____D () C:\Windows\Downloaded Installations
2014-02-11 00:00 - 2011-09-15 07:49 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
2014-02-11 00:00 - 2011-09-15 07:46 - 00000000 ____D () C:\ProgramData\USBChargerPlus
2014-02-11 00:00 - 2011-09-15 07:43 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic
2014-02-11 00:00 - 2011-09-15 07:38 - 00000000 ____D () C:\Users\Public\Documents\ASUS Music Maker
2014-02-11 00:00 - 2011-09-15 07:35 - 00000000 ____D () C:\ProgramData\P4G
2014-02-11 00:00 - 2011-09-15 07:24 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-02-11 00:00 - 2011-09-15 07:24 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-02-11 00:00 - 2011-04-13 03:51 - 00000000 ____D () C:\ProgramData\Trend Micro
2014-02-11 00:00 - 2011-04-13 03:48 - 00000000 ____D () C:\ProgramData\OberonGameConsole
2014-02-11 00:00 - 2011-04-13 03:46 - 00000000 ____D () C:\Windows\en
2014-02-11 00:00 - 2011-04-13 03:44 - 00000000 ____D () C:\Windows\de
2014-02-11 00:00 - 2011-04-13 03:44 - 00000000 ____D () C:\Windows\ar
2014-02-11 00:00 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\es
2014-02-11 00:00 - 2011-04-13 03:43 - 00000000 ____D () C:\Windows\el
2014-02-11 00:00 - 2011-04-13 03:33 - 00000000 ____D () C:\ProgramData\ScanSoft
2014-02-11 00:00 - 2011-04-13 03:33 - 00000000 ____D () C:\ProgramData\Nuance
2014-02-11 00:00 - 2010-11-21 08:00 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-02-11 00:00 - 2009-07-29 06:20 - 00000000 ____D () C:\Windows\ASUS
2014-02-11 00:00 - 2009-07-29 06:20 - 00000000 ____D () C:\Windows\ABLKSR
2014-02-11 00:00 - 2009-07-14 06:37 - 00000000 ____D () C:\Windows\DigitalLocker
2014-02-10 23:58 - 2011-09-15 07:38 - 00000000 ____D () C:\ProgramData\MAGIX
2014-02-10 23:56 - 2014-01-19 18:22 - 00000000 ____D () C:\ProgramData\Free Download Manager
2014-02-10 23:56 - 2013-02-19 19:34 - 00000000 ____D () C:\ProgramData\hps
2014-02-10 23:56 - 2013-01-11 19:25 - 00000000 ____D () C:\ProgramData\Langenscheidt
2014-02-10 23:56 - 2011-11-26 10:40 - 00000000 ____D () C:\ProgramData\IncrediMail
2014-02-10 23:56 - 2011-11-26 10:40 - 00000000 ____D () C:\ProgramData\IM
2014-02-10 23:56 - 2011-11-24 20:54 - 00000000 ____D () C:\ProgramData\ifolor
2014-02-10 23:56 - 2011-11-11 20:25 - 00000000 ____D () C:\ProgramData\Avira
2014-02-10 23:56 - 2011-11-11 10:23 - 00000000 ____D () C:\ProgramData\FolderView
2014-02-10 23:56 - 2011-09-15 07:38 - 00000000 ____D () C:\ProgramData\CyberLink
2014-02-10 23:56 - 2011-09-15 07:38 - 00000000 ____D () C:\ProgramData\ASUS Music Maker
2014-02-10 23:56 - 2011-09-15 07:30 - 00000000 ____D () C:\ProgramData\Atheros
2014-02-10 23:56 - 2011-09-15 07:22 - 00000000 ____D () C:\ProgramData\Intel
2014-02-10 23:56 - 2011-04-13 03:49 - 00000000 ____D () C:\ProgramData\ChangeFolderView
2014-02-10 23:56 - 2011-04-13 03:33 - 00000000 ____D () C:\ProgramData\FLEXnet
2014-02-10 23:56 - 2011-04-13 03:33 - 00000000 ____D () C:\ProgramData\Downloaded Installations
2014-02-10 23:55 - 2013-01-11 18:28 - 00000000 ____D () C:\Program Files (x86)\WEVOSYS
2014-02-10 23:55 - 2012-12-05 18:43 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-02-10 23:55 - 2012-12-05 18:38 - 00000000 ____D () C:\Program Files (x86)\WOT
2014-02-10 23:55 - 2012-08-14 17:46 - 00000000 ____D () C:\ProgramData\ACD Systems
2014-02-10 23:55 - 2012-02-18 10:09 - 00000000 ___HD () C:\ProgramData\.syncID
2014-02-10 23:55 - 2012-02-18 10:08 - 00000000 ___HD () C:\ProgramData\.Syncables
2014-02-10 23:55 - 2011-12-19 21:40 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-02-10 23:55 - 2011-12-19 21:38 - 00000000 ____D () C:\ProgramData\Apple
2014-02-10 23:55 - 2011-11-13 12:12 - 00000000 ____D () C:\Program Files (x86)\WebSite X5 v8 - Evolution
2014-02-10 23:55 - 2011-11-12 14:06 - 00000000 ____D () C:\ProgramData\Adobe
2014-02-10 23:55 - 2011-09-15 07:28 - 00000000 ____D () C:\ProgramData\AmUStor
2014-02-10 23:55 - 2011-04-13 03:38 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-02-10 23:54 - 2014-02-10 23:29 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-10 23:54 - 2013-12-21 23:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-10 23:54 - 2013-03-20 20:55 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-02-10 23:54 - 2013-01-11 19:23 - 00000000 ____D () C:\Program Files (x86)\Vokabeltrainer 6
2014-02-10 23:54 - 2013-01-11 19:08 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-02-10 23:54 - 2012-12-09 09:53 - 00000000 ____D () C:\Program Files (x86)\Secure Banking
2014-02-10 23:54 - 2012-12-05 19:49 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-02-10 23:54 - 2012-12-05 19:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-10 23:54 - 2012-11-27 19:28 - 00000000 ____D () C:\Program Files (x86)\Secunia
2014-02-10 23:54 - 2012-11-27 07:19 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-02-10 23:54 - 2012-04-12 18:23 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-02-10 23:54 - 2012-02-18 18:40 - 00000000 ____D () C:\Program Files (x86)\Photo Notifier and Animation Creator
2014-02-10 23:54 - 2011-11-13 20:18 - 00000000 ____D () C:\Program Files (x86)\OpenOffice.org 3
2014-02-10 23:54 - 2011-11-11 11:18 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-02-10 23:54 - 2011-09-15 07:27 - 00000000 ____D () C:\Program Files (x86)\Realtek
2014-02-10 23:54 - 2011-04-13 03:49 - 00000000 ____D () C:\Program Files (x86)\syncables
2014-02-10 23:54 - 2011-04-13 03:33 - 00000000 ____D () C:\Program Files (x86)\Nuance
2014-02-10 23:54 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-02-10 23:52 - 2011-11-12 13:56 - 00000000 ____D () C:\Program Files (x86)\MotionStudios
2014-02-10 23:51 - 2013-02-19 19:29 - 00000000 ____D () C:\Program Files (x86)\Migros
2014-02-10 23:51 - 2012-12-04 19:51 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-02-10 23:51 - 2011-12-25 20:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
2014-02-10 23:51 - 2011-12-25 20:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Sync Framework
2014-02-10 23:51 - 2011-12-25 20:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-02-10 23:51 - 2011-04-13 03:42 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-02-10 23:51 - 2011-04-13 03:25 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-02-10 23:50 - 2012-11-26 19:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-10 23:50 - 2011-12-25 20:02 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services
2014-02-10 23:49 - 2011-11-12 08:02 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-02-10 23:45 - 2013-01-11 18:24 - 00000000 ____D () C:\Program Files (x86)\Langenscheidt
2014-02-10 23:41 - 2014-01-19 18:22 - 00000000 ____D () C:\Program Files (x86)\Free Download Manager
2014-02-10 23:41 - 2013-07-21 17:31 - 00000000 ____D () C:\Program Files (x86)\Garmin
2014-02-10 23:41 - 2013-01-08 19:35 - 00000000 ____D () C:\Program Files (x86)\digital publishing
2014-02-10 23:41 - 2012-04-21 09:30 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client
2014-02-10 23:41 - 2012-04-06 10:49 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-02-10 23:41 - 2012-01-02 13:38 - 00000000 ____D () C:\Program Files (x86)\FreePDF_XP
2014-02-10 23:41 - 2011-11-26 10:40 - 00000000 ____D () C:\Program Files (x86)\IncrediMail
2014-02-10 23:41 - 2011-11-24 20:54 - 00000000 ____D () C:\Program Files (x86)\ifolor
2014-02-10 23:41 - 2011-11-13 20:17 - 00000000 ____D () C:\Program Files (x86)\Java
2014-02-10 23:41 - 2011-09-15 07:38 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2014-02-10 23:41 - 2011-09-15 07:18 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-02-10 23:41 - 2011-09-15 07:15 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-02-10 23:41 - 2011-04-13 03:33 - 00000000 ____D () C:\Program Files (x86)\Google
2014-02-10 23:36 - 2014-01-17 19:00 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-02-10 23:36 - 2011-12-19 21:39 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-02-10 23:36 - 2011-09-15 07:38 - 00000000 ____D () C:\Program Files (x86)\ASUS Music Maker
2014-02-10 23:36 - 2011-09-15 07:32 - 00000000 ____D () C:\Program Files (x86)\Bluetooth Suite
2014-02-10 23:36 - 2011-09-15 07:30 - 00000000 ____D () C:\Program Files (x86)\Atheros
2014-02-10 23:36 - 2011-04-13 03:47 - 00000000 ____D () C:\Program Files (x86)\ASUS
2014-02-10 23:35 - 2014-02-10 23:29 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-02-10 23:35 - 2012-12-05 18:38 - 00000000 ____D () C:\Program Files\WOT
2014-02-10 23:35 - 2012-08-14 17:46 - 00000000 ____D () C:\Program Files (x86)\ACD Systems
2014-02-10 23:35 - 2012-01-14 17:54 - 00000000 ____D () C:\Program Files (x86)\Allway Sync
2014-02-10 23:35 - 2011-11-12 14:07 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-02-10 23:35 - 2011-09-15 07:35 - 00000000 ____D () C:\Program Files\P4G
2014-02-10 23:35 - 2011-09-15 07:28 - 00000000 ____D () C:\Program Files (x86)\ASM104xUSB3
2014-02-10 23:35 - 2011-09-15 07:28 - 00000000 ____D () C:\Program Files (x86)\AmIcoSingLun
2014-02-10 23:35 - 2011-04-13 03:36 - 00000000 ____D () C:\Program Files\Windows Live
2014-02-10 23:34 - 2014-01-03 18:47 - 00000000 ____D () C:\Program Files\Java
2014-02-10 23:34 - 2012-12-30 12:31 - 00000000 ____D () C:\Program Files\CCleaner
2014-02-10 23:34 - 2012-12-04 19:51 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-02-10 23:34 - 2012-01-02 13:37 - 00000000 ____D () C:\Program Files\gs
2014-02-10 23:34 - 2011-12-25 20:02 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-02-10 23:34 - 2011-12-19 21:39 - 00000000 ____D () C:\Program Files\Bonjour
2014-02-10 23:34 - 2011-11-13 12:24 - 00000000 ____D () C:\Program Files\DIFX
2014-02-10 23:34 - 2011-09-15 07:36 - 00000000 ____D () C:\Program Files\ASUS
2014-02-10 23:34 - 2011-09-15 07:35 - 00000000 ____D () C:\Program Files\Intel
2014-02-10 23:34 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\DVD Maker
2014-02-10 23:34 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Vorlagen
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Startmenü
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Netzwerkumgebung
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Lokale Einstellungen
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Eigene Dateien
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Druckumgebung
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Documents\Eigene Musik
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Documents\Eigene Bilder
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Local\Verlauf
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\AppData\Local\Anwendungsdaten
2014-02-10 23:32 - 2014-02-10 23:32 - 00000000 _SHDL () C:\Users\*****\Anwendungsdaten
2014-02-10 23:31 - 2014-02-10 23:31 - 00001355 _____ () C:\Windows\TSSysprep.log
2014-02-10 23:31 - 2009-07-14 05:51 - 00000084 _____ () C:\Windows\setuperr.log
2014-02-10 23:30 - 2014-02-10 23:30 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2014-02-10 23:30 - 2014-02-10 23:30 - 00000000 ____D () C:\Program Files\Synaptics
2014-02-10 23:29 - 2014-02-10 23:29 - 00000000 ____D () C:\ProgramData\SonicFocus
2014-02-10 23:29 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help
2014-02-10 23:28 - 2014-02-10 23:28 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2014-02-10 23:28 - 2014-02-10 23:28 - 00000000 ____D () C:\Program Files\Realtek
2014-02-10 23:24 - 2009-07-29 07:03 - 00008192 __RSH () C:\BOOTSECT.BAK
2014-02-10 23:24 - 2009-07-14 06:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2014-02-10 23:24 - 2009-07-14 06:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2014-02-10 23:21 - 2014-02-10 23:21 - 00262144 _____ () C:\Windows\system32\config\userdiff
2014-02-10 23:00 - 2014-02-10 22:47 - 00000000 ___HD () C:\$INPLACE.~TR
2014-02-10 22:39 - 2011-09-15 07:11 - 02049309 _____ () C:\Windows\WindowsUpdate (1).log
2014-02-10 21:49 - 2014-01-27 18:25 - 00002544 _____ () C:\Windows\diagwrn.xml
2014-02-10 21:49 - 2014-01-27 18:25 - 00001890 _____ () C:\Windows\diagerr.xml
2014-02-10 21:24 - 2014-02-10 21:24 - 00005347 _____ () C:\Users\*****\Downloads\eicfg_removal_utility.zip
2014-02-10 21:23 - 2014-02-10 21:23 - 00000000 ____D () C:\Users\*****\Desktop\Neuer Ordner (2)
2014-02-10 21:22 - 2014-02-10 21:22 - 00000000 ____D () C:\Users\*****\Desktop\Neuer Ordner
2014-02-05 20:22 - 2012-09-29 21:19 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-05 20:22 - 2012-09-29 21:19 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-05 20:22 - 2011-11-20 12:36 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-05 19:51 - 2014-01-27 18:27 - 00003320 _____ () C:\Users\*****\Desktop\Windows-Kompatibilitätsbericht.htm
2014-02-02 18:33 - 2014-02-02 17:31 - 00002020 _____ () C:\Users\*****\Desktop\Windows Compatibility Report.htm
2014-01-20 12:42 - 2011-09-15 07:36 - 00002638 _____ () C:\Windows\system32\AutoRunFilter.ini
2014-01-19 18:22 - 2014-01-19 18:22 - 00001069 _____ () C:\Users\*****\Desktop\Free Download Manager.lnk
2014-01-19 18:20 - 2014-01-19 18:20 - 00614784 _____ (Chip Digital GmbH) C:\Users\*****\Desktop\Free Download Manager - CHIP-Downloader.exe
2014-01-17 19:05 - 2013-08-17 09:11 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-17 19:00 - 2014-01-17 19:00 - 00002068 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-01-17 18:58 - 2014-01-17 18:53 - 140300048 _____ () C:\Users\*****\Downloads\avira_antivirus_suite_de.exe
2014-01-15 20:27 - 2014-01-15 20:27 - 00448512 _____ (OldTimer Tools) C:\Users\*****\Desktop\TFC.exe
2014-01-14 06:45 - 2014-01-14 06:45 - 00987410 _____ () C:\Users\*****\Desktop\SecurityCheck.exe
2014-01-13 21:05 - 2014-01-13 21:04 - 02347384 _____ (ESET) C:\Users\*****\Desktop\esetsmartinstaller_enu.exe
2014-01-13 20:45 - 2014-01-13 20:21 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2014-01-13 20:44 - 2009-07-14 03:34 - 00000514 _____ () C:\Windows\win.ini
2014-01-13 20:17 - 2014-01-13 20:17 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-*****-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-01-13 20:17 - 2014-01-13 20:17 - 00000000 ____D () C:\RegBackup
2014-01-13 19:31 - 2014-01-13 19:31 - 02903255 _____ () C:\Users\*****\Desktop\tweaking.com_windows_repair_aio.zip

Some content of TEMP:
====================
C:\Users\*****\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-10 23:26

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Alt 12.02.2014, 18:23   #52
schrauber
/// the machine
/// TB-Ausbilder
 

PUP optional Candy - Standard

PUP optional Candy



Trotz der Rep Installation? Irgendwas ist da total im Ars.....

Ich würde jetzt Daten sichern und dann einmal formatieren und neu aufsetzen, wenn dann immer noch Stress ist ist es die Hardware.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 12.02.2014, 22:14   #53
drud
 
PUP optional Candy - Standard

PUP optional Candy



ja trotz der rep. das war eigentlcih nicht das, was ich von dir hören wollte aber da kannst du ja nichts dafür

die programme kann ich nicht sichern oder, nur die daten, also fotos etc.? macht ev. auch nicht sinn, die software zu sichern?

wie formatiere ich?

und wie kann ich nachher windows installieren? mit dieser ISO-dvd die ich für die reparatur gemacht habe?

DANKE!

hab noch das sfc/scannow gemacht über start ausführen. da findet es nichts:

Der Windows-Ressourcenschutz hat keine Integritätsverletzungen gefunden.

ich hab nun beim googeln noch gefunden, dass asus web storage daran schuld sein könnte. so wie ich gelesen habe wird eine deinstallation empfohlen. bei anderen hat das offenbar genützt. soll/darf ich das probieren?

heute ist er nicht hängen geblieben.

Alt 13.02.2014, 21:48   #54
schrauber
/// the machine
/// TB-Ausbilder
 

PUP optional Candy - Standard

PUP optional Candy



Daten sichern, Programme nicht.

Einfach die vollwertige WIndows Scheibe rein (sollte auch mit der ISO gehen) von der booten und formatieren
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 13.02.2014, 23:24   #55
drud
 
PUP optional Candy - Standard

PUP optional Candy



ausser die gebrannte ISO-dvd hab ich ja eben keine windows cd :-( ?
hab das asus webstorage heute abend deinstalliert. ich guck jetzt bis samstag was passiert. formatieren könnt ich eh nicht vor dem wochenende. danke :-)

Alt 14.02.2014, 17:37   #56
schrauber
/// the machine
/// TB-Ausbilder
 

PUP optional Candy - Standard

PUP optional Candy



ok
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 15.02.2014, 11:19   #57
drud
 
PUP optional Candy - Standard

PUP optional Candy



hey, die windwos explorer meldung kommt tatsächlich nicht mehr

nur habe ich jetzt ein anderes problem. es geht ein fenster auf, zum aktivieren von windows. ich gebe also erneut meinen produkte key, der unten auf meinem laoptop aufgeklebt ist, ein. aber es heisst es sei "anscheinend kein gültiger windows 7 produkte key".was soll ich nun tun? ich hab ihn richtig abgeschrieben und eingegeben.

ah, hat sich erledigt konnte das über diese automatische telefon hotline aktivieren lassen von windows ist jetzt aktiviert und in ordnung.

nun bin ich gespannt auf die nächsten schritte. weiss gar nicht ob mein pc jetzt sauber ist oder nicht.

beim aufstarten ist er noch extrem langsam.

Alt 16.02.2014, 07:12   #58
schrauber
/// the machine
/// TB-Ausbilder
 

PUP optional Candy - Standard

PUP optional Candy



poste mal en frisches FRST Logfile, ich schaue mal drüber
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 20.02.2014, 10:18   #59
drud
 
PUP optional Candy - Standard

PUP optional Candy



hallöchen
ich kann das log-file spätestens morgen abend machen. hab extra noch ein bisschen zugewartet zum gucken, wie es sich entwickelt. bis jetzt alles i.o. habe treiber für die FN-tasten neu runtergeladen von asus sowie für das touch-pad, funktioniert alles. auch die explorer meldung kam definitiv nicht mehr.
nur langsam ist er beim aufstarten geworden. das passt mir noch nicht.
log-file kommt also heute oder wahrscheinlicher morgen abend!
danke & gruss

Alt 21.02.2014, 09:54   #60
schrauber
/// the machine
/// TB-Ausbilder
 

PUP optional Candy - Standard

PUP optional Candy



ok
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu PUP optional Candy
administrator, anti-malware, asus, avira, cc cleaner, detected, explorer, home, hängen, laptop, logfiles, maleware, malwarebytes, mozilla, office, programm, prüfen, pup optional, registry, software, system, update, updates, was tun?, windows, windows explorer, windows update




Ähnliche Themen: PUP optional Candy


  1. Ads By Candy Box entfernen
    Anleitungen, FAQs & Links - 15.09.2015 (2)
  2. Ads By Gaming Candy entfernen
    Anleitungen, FAQs & Links - 06.08.2015 (2)
  3. Open Candy
    Log-Analyse und Auswertung - 17.05.2015 (23)
  4. GMER stürzt ab - MBAM erkennt PUP.Optional.Agent, PUP.Optional.IEBho.A, PUP.Optional.MyFreeze.A
    Plagegeister aller Art und deren Bekämpfung - 07.02.2015 (13)
  5. WIN7: Fund PUP.Optional.DigitalSites.A, PUP.Optional.OpenCandy, PUP.Optional.Softonic.A, PUP.Optional.Updater.A. Weitere Vorgehensweise
    Log-Analyse und Auswertung - 08.10.2014 (11)
  6. Trojaner: PUP.Optional.CrossRider.A, PUP.Optional.MySearchDial.A, PUP.Optional.Babylon.A, PUP.Optional.BuenoSearch
    Plagegeister aller Art und deren Bekämpfung - 17.07.2014 (3)
  7. Security.Hijack, PUP.Optional.OpenCandy, PUP.Optional.Somoto, PUP.Optional.MoviesToolBar etc gefunden
    Plagegeister aller Art und deren Bekämpfung - 16.04.2014 (1)
  8. PUP.Optional.DomalQ / PUP.Optional.BProtector / PUP.Optional.InstallMonetizer.A
    Plagegeister aller Art und deren Bekämpfung - 11.03.2014 (9)
  9. Windows 8: Fund von TR/Dropper.gen, PUP.Optional.Iminent.A, PUP.Optional.BizzyBolt, PUP.Optional.DigitalSites.A
    Log-Analyse und Auswertung - 10.12.2013 (13)
  10. Open Candy
    Plagegeister aller Art und deren Bekämpfung - 21.11.2013 (15)
  11. Open Candy Virus
    Plagegeister aller Art und deren Bekämpfung - 07.11.2013 (3)
  12. Open Candy Virus
    Plagegeister aller Art und deren Bekämpfung - 04.11.2013 (2)
  13. Windows Vista: PUP.Optional.Tarma.A PUP.Optional.OpenCandy PUP.Optional.InstallCore.A
    Plagegeister aller Art und deren Bekämpfung - 11.09.2013 (13)
  14. 2x Windows Vista: PUP.Optional.Tarma.A PUP.Optional.OpenCandy PUP.Optional.InstallCore.A
    Mülltonne - 08.09.2013 (1)
  15. PUP.VShare.Redir und PUP.Optional.Open Candy auf dem Rechner
    Plagegeister aller Art und deren Bekämpfung - 30.08.2013 (24)
  16. Windows 7, Malwarebytes findet 1 infizierte Datei: Trojan.PUP.Optional.FileScout.A, bei einen anderen Benutzer Pub.Optional.Open.Candy
    Log-Analyse und Auswertung - 30.08.2013 (32)
  17. PUP.Optional.BrowserDefender.A, PUP.Optional.Babylon.A, PUP.Optional.Delta
    Log-Analyse und Auswertung - 25.08.2013 (8)

Zum Thema PUP optional Candy - Du lädst die ISO Du lädst das kleine Removal ZIP und lässt es laufen Dann kannst Du die ISO auf die DVD brennen - PUP optional Candy...
Archiv
Du betrachtest: PUP optional Candy auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.