|
Log-Analyse und Auswertung: GreatSaver infiziertWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
24.01.2014, 14:42 | #16 |
| GreatSaver infiziert ESET hat nichts gefunden. FRST: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2014 Ran by 00yoshi (administrator) on 00YOSHIPC on 24-01-2014 14:35:26 Running from C:\Users\00yoshi\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft) C:\Program Files (x86)\AntiBrowserSpy\AntiBrowserSpyBrowserMaske.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (Dropbox, Inc.) C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\Dropbox.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\javaw.exe () C:\Users\00yoshi\Desktop\Der ganze Rest\Andere Spiele\Powdertoy\Powder Toy.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\javaw.exe (dotPDN LLC) C:\Program Files\Paint.NET\PaintDotNet.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe () C:\Pylo\MCreator\MCreator.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Oracle Corporation) C:\Windows\SysWOW64\java.exe (Mozilla Corporation) C:\Program Files (x86)\MF\firefox.exe (Microsoft Corporation) C:\Windows\System32\calc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\vbexpress.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink) HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-30] (Intel Corporation) HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-03] (CyberLink) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\RunOnce: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe /DeleteRunKey [443688 2011-05-26] (CyberLink) HKCU\...\Run: [BrowserMask] - C:\Program Files (x86)\AntiBrowserSpy\AntiBrowserSpyBrowserMaske.exe [101328 2012-08-14] (Microsoft) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKCU\...\Policies\system: [LogonHoursAction] 2 HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] () HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] () HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs Startup: C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: CBAbzockschutz.InitToolbarBHO - {2e250b90-0e7a-42a3-9d65-e39f9f227fa4} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - COMPUTERBILD-Abzockschutz - {353e2a48-6254-4bd3-88f4-3b51a0ca7870} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{84BF9EDE-124A-499C-AED4-CA030D3CFE4D}: [NameServer]62.109.121.2 62.109.121.1 FireFox: ======== FF ProfilePath: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\f2k8w897.default-1390041085465 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\00yoshi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: NoScript - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\f2k8w897.default-1390041085465\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-18] FF Extension: Adblock Plus - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\f2k8w897.default-1390041085465\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-18] FF Extension: DownThemAll! - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\f2k8w897.default-1390041085465\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2014-01-18] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} [2013-12-20] FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\MF\firefox.exe Chrome: ======= CHR DefaultSearchKeyword: search.snap.do CHR DefaultSearchProvider: Web CHR DefaultSearchURL: hxxp://feed.snap.do/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=a934f48a-0c33-4cb4-aa6e-ff61a74c7711&searchtype=ds&q={searchTerms}&installDate=29/06/2013 CHR DefaultNewTabURL: CHR Extension: (greAtsaaveR) - C:\Users\00yoshi\AppData\Local\Google\Chrome\User Data\Default\Extensions\belcdgkhhmfeilamilifdjfdillmmcjg [2014-01-05] CHR Extension: (Google Wallet) - C:\Users\00yoshi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-17] CHR HKLM-x32\...\Chrome\Extension: [ibnmbpihhamedhophbnjjpidokcknoid] - C:\Program Files (x86)\AP Suggestor\APSuggestor.crx [2013-12-17] ==================== Services (Whitelisted) ================= S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [43028328 2011-09-22] (Microsoft Corporation) S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) S4 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1328736 2012-09-24] (Secunia) S4 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [656480 2012-09-24] (Secunia) S4 SQLAgent$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [370024 2011-09-22] (Microsoft Corporation) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x] ==================== Drivers (Whitelisted) ==================== S3 DCamUSBET; C:\Windows\System32\DRIVERS\etDevice64.sys [527744 2007-07-23] (eMPIA Technology, Inc.) S3 FiltUSBET; C:\Windows\System32\DRIVERS\etFilter64.sys [281088 2007-06-14] (eMPIA Technology Inc.) S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32512 2014-01-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2012-01-18] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2012-01-18] () S3 ScanUSBET; C:\Windows\System32\DRIVERS\etScan64.sys [9216 2007-07-23] (eMPIA Technology, Inc.) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S4 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S0 nvpciflt; system32\DRIVERS\nvpciflt.sys [x] ========================== Drivers MD5 ======================= C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit C:\Windows\SysWow64\drivers\Afc.sys 6CCD1135320109D6B219F1A6E04AD9F6 C:\Windows\system32\drivers\afd.sys 79059559E89D06E8B80CE2944BE20228 C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49 C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048 C:\Windows\system32\drivers\appid.sys ==> MD5 is legit C:\Windows\system32\drivers\arc.sys ==> MD5 is legit C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit C:\Windows\system32\drivers\asmthub3.sys 0AA7A996792FB0287B33A57A8093AE44 C:\Windows\system32\drivers\asmtxhci.sys 125DC3ABF5BFCCFE82AD17D078E0B9EC C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\system32\drivers\atapi.sys ==> MD5 is legit C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\system32\drivers\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bridge.sys 5C2F352A4E961D72518261257AAE204B C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys ==> MD5 is legit C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys EBF28856F69CF094A902F884CF989706 C:\Windows\system32\drivers\compbatt.sys ==> MD5 is legit C:\Windows\system32\drivers\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\etDevice64.sys 04F1DC6D20E145FB29C9536A5E4FDA90 C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\drivers\disk.sys ==> MD5 is legit C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\drivers\dxgkrnl.sys 88612F1CE3BF42256913BF6E61C70D52 C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\etFilter64.sys 059B282B748D5E027B60E276CF424BAD C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0 C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hamachi.sys 1E6438D4EA6E1174A3B3B1EDC4DE660B C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A C:\Windows\system32\drivers\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit C:\Windows\system32\drivers\hitmanpro37.sys FCE2251FE4464DCAA2F4684F19A8EE9B C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit C:\Windows\System32\drivers\iaStor.sys 26CF4275034214ECEDD8EC17B0A18A99 C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366 C:\Windows\System32\DRIVERS\igdkmd64.sys ==> MD5 is legit C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit C:\Windows\System32\drivers\RTKVHD64.sys 8F6ED52134EBB4CE2953EC37C9275497 C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecdd.sys 8F489706472F7E9A06BAAA198703FA64 C:\Windows\System32\Drivers\ksecpkg.sys 868A2CAAB12EFC7A021682BCA0EEC54C C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\system32\drivers\mbam.sys 0BB97D43299910CBFBA59C461B99B910 C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit C:\Windows\system32\drivers\HECIx64.sys A6518DCC42F7A6E999BB3BEA8FD87567 C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\MpFilter.sys C6B88D62F20AC646C6BD5C032EC2FAF9 C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys 1A4F75E63C9FB84B85DFFC6B63FD5404 C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163 C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\system32\drivers\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88 C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\NisDrvWFP.sys ACE8C64C57E4A711473C8BC10ADF692B C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\System32\Drivers\Ntfs.sys B98F8C6E31CD07B2E6F71F7F648E38C0 C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit C:\Windows\System32\drivers\nvhda64v.sys 1F07B814C0BB5AABA703ABFF1F31F2E8 C:\Windows\System32\DRIVERS\nvlddmkm.sys E71E299FF15390E585BACF2C18F55078 C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit C:\Windows\system32\drivers\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C C:\Windows\System32\drivers\pci.sys ==> MD5 is legit C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\drivers\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\psi_mf.sys FB46E9A827A8799EBD7BFA9128C91F37 C:\Windows\system32\pwdrvio.sys FF40216A382B30CC39372B889AE1F785 C:\Windows\system32\pwdspio.sys BD08A9CDF23502B1C141D52D9D6A6648 C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit C:\Windows\system32\drivers\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34 C:\Windows\System32\Drivers\RDPWD.sys E61608AA35E98999AF9AAEEEA6114B0A C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Rt64win7.sys E50CFB92986DCAB49DE93788FD695813 C:\Windows\System32\DRIVERS\RTL8192su.sys B3F36B4B3F192EA87DDC119F3A0B3E45 C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\etScan64.sys 7AD81DB1549878DEEAAECED63981C8FC C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\serenum.sys ==> MD5 is legit C:\Windows\system32\drivers\serial.sys ==> MD5 is legit C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Sftfslh.sys 2046AA7491DE7EFA4D70E615D9BC9D09 C:\Windows\System32\DRIVERS\Sftplaylh.sys 0E0446BC4D51BE4263ACB7E33491191C C:\Windows\System32\DRIVERS\Sftredirlh.sys C5FB982CD266E604ED3142102C26D62C C:\Windows\System32\DRIVERS\Sftvollh.sys 2575511AF67AA1FA068CCC4918E2C2A3 C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28 C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3 C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit C:\Windows\system32\drivers\swenum.sys ==> MD5 is legit C:\Windows\System32\drivers\tcpip.sys 40AF23633D197905F03AB5628C558C51 C:\Windows\System32\DRIVERS\tcpip.sys 40AF23633D197905F03AB5628C558C51 C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8 C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit C:\Windows\system32\drivers\termdd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tosporte.sys C14882C535E97B180ACA9FC716C228FB C:\Windows\System32\DRIVERS\tosrfbd.sys A2242F46131F3BEE3D1DA279B74111BA C:\Windows\System32\Drivers\tosrfbnp.sys 0716088A07A468FFF2DBFCA1DE55C0B6 C:\Windows\System32\Drivers\tosrfcom.sys 98C10D5862C4C5E58A9E09BEB07FB6C5 C:\Windows\System32\DRIVERS\Tosrfhid.sys 33C90B98B74D01D179E1963A5BF5EDF9 C:\Windows\System32\DRIVERS\tosrfnds.sys 95552D0B11C70846299DCA2FF0082205 C:\Windows\System32\drivers\tosrfsnd.sys A99D0670095414C7B3244DC3D0314ACB C:\Windows\System32\DRIVERS\tosrfusb.sys A69030B8F4C73C475E81A35F93C9C964 C:\Windows\System32\DRIVERS\tssecsrv.sys 4CE278FC9671BA81A138D70823FCAA09 C:\Windows\System32\drivers\tsusbflt.sys 17C6B51CBCCDED95B3CC14E22791F85E C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07 C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbccgp.sys DCA68B0943D6FA415F0C56C92158A83A C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31 C:\Windows\system32\drivers\usbehci.sys 18A85013A3E0F7E1755365D287443965 C:\Windows\System32\DRIVERS\usbhub.sys 8D1196CFBB223621F2C67D45710F25BA C:\Windows\system32\drivers\usbohci.sys 765A92D428A8DB88B960DA5A8D6089DC C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\system32\drivers\usbscan.sys 9661DA76B4531B2DA272ECCE25A8AF24 C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6 C:\Windows\system32\drivers\usbuhci.sys DD253AFC3BC6CBA412342DE60C3647F3 C:\Windows\System32\Drivers\usbvideo.sys 1F775DA4CF1A3A1834207E975A72E9D7 C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\system32\drivers\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8 C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys 0C0195C48B6B8582FA6F6373032118DA C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wsvd.sys 82E8F5AA03DF7DBDB8A33F700D5D8CDA C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659 ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-24 14:35 - 2014-01-24 14:35 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Temporary Projects 2014-01-21 21:12 - 2014-01-22 08:15 - 00001525 _____ C:\Users\00yoshi\Desktop\MCreator.lnk 2014-01-21 18:01 - 2013-02-08 16:15 - 02347384 _____ (ESET) C:\Users\00yoshi\Desktop\esetsmartinstaller_deu.exe 2014-01-18 11:31 - 2014-01-18 11:31 - 00000000 ____D C:\Users\00yoshi\Desktop\Alte Firefox-Daten 2014-01-17 17:52 - 2014-01-17 17:52 - 04841353 _____ C:\Users\00yoshi\Downloads\qCraftMineconMapMC1_5_2.zip 2014-01-15 19:48 - 2014-01-15 19:49 - 00205307 _____ C:\Users\00yoshi\Desktop\WinRAR archive (neu).rar 2014-01-15 15:37 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 15:37 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 15:37 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 15:37 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 15:37 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 15:37 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 15:37 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 15:37 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 15:37 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-14 22:24 - 2014-01-14 22:24 - 09274970 _____ C:\Users\00yoshi\Downloads\Mekanism-v5.7.0.11.jar 2014-01-14 22:23 - 2014-01-14 22:23 - 00024919 _____ C:\Users\00yoshi\Downloads\MDK-v5.7.0.11.zip 2014-01-12 17:40 - 2014-01-12 17:40 - 00079269 _____ C:\Users\00yoshi\Downloads\Spleef.jar 2014-01-12 16:04 - 2014-01-12 16:06 - 00000000 ____D C:\Users\00yoshi\AppData\Local\{1065296E-22EC-438E-AD52-AF7F687A8F69} 2014-01-12 13:23 - 2014-01-24 14:35 - 00000000 ____D C:\Users\00yoshi\Downloads\FRST-OlderVersion 2014-01-12 13:19 - 2014-01-12 13:19 - 00001186 _____ C:\Users\00yoshi\Desktop\JRT.txt 2014-01-12 13:13 - 2014-01-12 13:13 - 01037068 _____ (Thisisu) C:\Users\00yoshi\Downloads\JRT(1).exe 2014-01-12 11:36 - 2014-01-12 11:36 - 01233962 _____ C:\Users\00yoshi\Desktop\adwcleaner.exe 2014-01-11 10:45 - 2014-01-11 10:47 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-11 10:45 - 2014-01-11 10:45 - 02365840 _____ C:\Users\00yoshi\Downloads\SecurityTaskManager_Setup(1).exe 2014-01-11 10:45 - 2014-01-11 10:45 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-10 18:36 - 2014-01-24 13:23 - 00003864 _____ C:\Windows\setupact.log 2014-01-10 18:36 - 2014-01-10 18:37 - 00473584 _____ C:\Windows\Minidump\011014-21730-01.dmp 2014-01-10 18:36 - 2014-01-10 18:36 - 663286171 _____ C:\Windows\MEMORY.DMP 2014-01-10 18:36 - 2014-01-10 18:36 - 00000000 ____D C:\Windows\Minidump 2014-01-10 18:36 - 2014-01-10 18:36 - 00000000 _____ C:\Windows\setuperr.log 2014-01-10 17:18 - 2014-01-10 17:18 - 00000000 ____D C:\Users\00yoshi\Desktop\log's 2014-01-10 17:17 - 2014-01-10 17:17 - 00011254 _____ C:\Users\00yoshi\Downloads\Neuer ZIP-komprimierter Ordner.zip 2014-01-10 17:15 - 2014-01-10 17:17 - 00011254 _____ C:\Users\00yoshi\Desktop\Neuer ZIP-komprimierter Ordner.zip 2014-01-10 17:05 - 2014-01-10 17:16 - 00141705 _____ C:\ComboFix.txt 2014-01-10 16:40 - 2014-01-10 17:06 - 00000000 ____D C:\ComboFix 2014-01-10 16:40 - 2014-01-10 17:05 - 00000000 ____D C:\Qoobox 2014-01-10 16:40 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-10 16:40 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-10 16:40 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-10 16:40 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-10 16:40 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-10 16:40 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-10 16:40 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-10 16:40 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-10 16:39 - 2014-01-10 17:01 - 00000000 ____D C:\Windows\erdnt 2014-01-10 16:18 - 2014-01-10 16:19 - 05162489 ____R (Swearware) C:\Users\00yoshi\Desktop\ComboFix.exe 2014-01-10 14:22 - 2014-01-10 14:22 - 00000474 _____ C:\Users\00yoshi\Downloads\defogger_disable.log 2014-01-10 14:22 - 2014-01-10 14:22 - 00000000 _____ C:\Users\00yoshi\defogger_reenable 2014-01-10 14:20 - 2014-01-12 13:25 - 00036130 _____ C:\Users\00yoshi\Downloads\Addition.txt 2014-01-10 14:19 - 2014-01-24 14:37 - 00034941 _____ C:\Users\00yoshi\Downloads\FRST.txt 2014-01-10 14:19 - 2014-01-24 14:35 - 00000000 ____D C:\FRST 2014-01-10 14:19 - 2014-01-10 14:19 - 00050477 _____ C:\Users\00yoshi\Downloads\Defogger.exe 2014-01-10 14:18 - 2014-01-24 14:35 - 02077696 _____ (Farbar) C:\Users\00yoshi\Downloads\FRST64.exe 2014-01-10 13:52 - 2014-01-10 13:52 - 00550371 _____ C:\Users\00yoshi\Downloads\Autoruns.zip 2014-01-09 22:32 - 2014-01-09 22:32 - 00032512 _____ C:\Windows\system32\Drivers\hitmanpro37.sys 2014-01-09 22:23 - 2014-01-09 22:23 - 00012092 _____ C:\Windows\system32\.crusader 2014-01-09 21:56 - 2014-01-09 21:56 - 00001909 _____ C:\Users\Public\Desktop\HitmanPro.lnk 2014-01-09 21:56 - 2014-01-09 21:56 - 00000000 ____D C:\Program Files\HitmanPro 2014-01-09 21:55 - 2014-01-09 22:31 - 00000000 ____D C:\ProgramData\HitmanPro 2014-01-09 21:55 - 2014-01-09 21:55 - 10264904 _____ (SurfRight B.V.) C:\Users\00yoshi\Downloads\HitmanPro_x64.exe 2014-01-09 21:45 - 2014-01-09 21:45 - 01037068 _____ (Thisisu) C:\Users\00yoshi\Downloads\JRT.exe 2014-01-09 21:45 - 2014-01-09 21:45 - 00000000 ____D C:\Windows\ERUNT 2014-01-09 21:37 - 2014-01-09 21:37 - 00001054 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-09 21:37 - 2014-01-09 21:37 - 00000000 ____D C:\Program Files (x86)\MF 2014-01-09 21:30 - 2014-01-09 21:30 - 23867560 _____ (Mozilla) C:\Users\00yoshi\Downloads\Firefox Setup 26.0.exe 2014-01-08 16:15 - 2014-01-12 13:07 - 00000000 ____D C:\AdwCleaner 2014-01-08 16:15 - 2014-01-08 16:15 - 01233962 _____ C:\Users\00yoshi\Downloads\adwcleaner_3.016.exe 2014-01-05 15:31 - 2014-01-05 15:31 - 00000000 ____D C:\ProgramData\SoftWarehouse 2014-01-05 15:24 - 2014-01-07 20:17 - 00000000 ____D C:\ProgramData\InstallMate 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$ 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\ProgramData\504c2cf8db11ac3b 2014-01-04 14:56 - 2014-01-04 14:56 - 00018589 _____ C:\Users\00yoshi\Downloads\169_EW-Biomes.rar 2014-01-04 14:55 - 2014-01-04 14:55 - 08037055 _____ C:\Users\00yoshi\Downloads\Millenaire5.1.11.zip 2014-01-03 22:50 - 2014-01-03 22:50 - 00790625 _____ C:\Users\00yoshi\Downloads\GoingBeyond1_Tutorial_Sample.zip 2014-01-03 22:44 - 2014-01-03 22:44 - 00193521 _____ C:\Users\00yoshi\Downloads\einfuehrung(1).zip 2014-01-03 22:24 - 2014-01-03 22:24 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source(1).zip 2014-01-03 22:08 - 2014-01-03 22:08 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source.zip 2014-01-03 18:54 - 2014-01-03 18:54 - 00569372 _____ (DotExE ) C:\Users\00yoshi\Downloads\MoonTools.exe 2014-01-02 17:03 - 2010-08-09 20:14 - 00089600 _____ (SoftwareDesign-Solution) C:\Users\00yoshi\Desktop\TextEffectsLib.dll 2014-01-02 17:02 - 2014-01-02 17:02 - 00043731 _____ C:\Users\00yoshi\Downloads\TextEffectsLib_1.1.0.0.zip 2014-01-02 16:59 - 2014-01-02 16:59 - 00117423 _____ C:\Users\00yoshi\Downloads\TextEffectsLibDemo_1.1.0.0.zip 2014-01-02 16:09 - 2014-01-02 16:09 - 00018432 _____ (MT Soft) C:\Users\00yoshi\Desktop\ZipLib.dll 2014-01-02 15:15 - 2014-01-02 15:16 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10(1).exe 2013-12-31 00:10 - 2013-12-31 00:12 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Start 2013-12-31 00:08 - 2013-12-31 00:08 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\nUpdate 2013-12-30 23:21 - 2013-12-30 23:22 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10.exe 2013-12-30 23:17 - 2013-12-30 23:17 - 00369345 _____ C:\Users\00yoshi\Downloads\nUpdate.rar 2013-12-30 22:53 - 2013-12-30 22:54 - 33841433 _____ C:\Users\00yoshi\Downloads\Minecraft_Modpack_1.6.2.rar 2013-12-27 22:24 - 2013-12-27 22:24 - 00095068 _____ C:\Users\00yoshi\Desktop\Paintball.jar 2013-12-27 13:26 - 2013-12-27 13:26 - 01927709 _____ C:\Users\00yoshi\Downloads\samp03x_svr_R2_win32.zip 2013-12-27 12:47 - 2013-12-27 12:47 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer 2013-12-27 12:45 - 2013-12-27 12:46 - 12022145 _____ C:\Users\00yoshi\Downloads\sa-mp-0.3x-R1-2-install.exe ==================== One Month Modified Files and Folders ======= 2014-01-24 14:37 - 2014-01-10 14:19 - 00034941 _____ C:\Users\00yoshi\Downloads\FRST.txt 2014-01-24 14:35 - 2014-01-24 14:35 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Temporary Projects 2014-01-24 14:35 - 2014-01-12 13:23 - 00000000 ____D C:\Users\00yoshi\Downloads\FRST-OlderVersion 2014-01-24 14:35 - 2014-01-10 14:19 - 00000000 ____D C:\FRST 2014-01-24 14:35 - 2014-01-10 14:18 - 02077696 _____ (Farbar) C:\Users\00yoshi\Downloads\FRST64.exe 2014-01-24 14:34 - 2012-05-18 07:14 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-24 14:29 - 2012-01-14 18:00 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-24 14:25 - 2013-07-28 17:40 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Skype 2014-01-24 13:36 - 2012-01-14 17:57 - 02039844 _____ C:\Windows\WindowsUpdate.log 2014-01-24 13:33 - 2012-01-28 11:17 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Paint.NET 2014-01-24 13:33 - 2012-01-25 17:27 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Adobe 2014-01-24 13:33 - 2009-07-14 05:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-24 13:33 - 2009-07-14 05:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-24 13:26 - 2013-11-10 20:10 - 00000000 ____D C:\Users\00yoshi\Desktop\atlauncher 2014-01-24 13:26 - 2013-01-29 18:38 - 00000000 ___RD C:\Users\00yoshi\Dropbox 2014-01-24 13:26 - 2013-01-29 18:37 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Dropbox 2014-01-24 13:23 - 2014-01-10 18:36 - 00003864 _____ C:\Windows\setupact.log 2014-01-24 13:23 - 2012-01-14 18:00 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-24 13:23 - 2011-09-05 23:24 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-24 13:23 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-23 21:16 - 2013-10-09 11:48 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\.minecraft 2014-01-23 17:36 - 2010-11-21 04:47 - 00440004 _____ C:\Windows\PFRO.log 2014-01-22 08:15 - 2014-01-21 21:12 - 00001525 _____ C:\Users\00yoshi\Desktop\MCreator.lnk 2014-01-19 22:03 - 2012-02-18 12:39 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\SoftGrid Client 2014-01-19 18:11 - 2013-11-16 12:17 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\.superc 2014-01-19 08:33 - 2010-11-21 04:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-01-18 11:47 - 2013-04-13 23:05 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\vlc 2014-01-18 11:31 - 2014-01-18 11:31 - 00000000 ____D C:\Users\00yoshi\Desktop\Alte Firefox-Daten 2014-01-17 17:52 - 2014-01-17 17:52 - 04841353 _____ C:\Users\00yoshi\Downloads\qCraftMineconMapMC1_5_2.zip 2014-01-17 17:40 - 2012-11-30 18:17 - 00000000 ____D C:\Users\00yoshi\Documents\Visual Studio 2010 2014-01-16 17:49 - 2013-01-29 18:37 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-16 17:49 - 2012-01-14 18:05 - 00000000 ___RD C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-15 19:49 - 2014-01-15 19:48 - 00205307 _____ C:\Users\00yoshi\Desktop\WinRAR archive (neu).rar 2014-01-15 17:49 - 2011-05-16 15:04 - 00766056 _____ C:\Windows\system32\perfh007.dat 2014-01-15 17:49 - 2011-05-16 15:04 - 00175028 _____ C:\Windows\system32\perfc007.dat 2014-01-15 17:49 - 2009-07-14 06:13 - 01808962 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-15 17:43 - 2009-07-14 05:45 - 05004344 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-15 16:56 - 2013-07-25 15:48 - 00000000 ____D C:\Windows\system32\MRT 2014-01-15 16:53 - 2011-07-18 21:31 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-14 22:24 - 2014-01-14 22:24 - 09274970 _____ C:\Users\00yoshi\Downloads\Mekanism-v5.7.0.11.jar 2014-01-14 22:23 - 2014-01-14 22:23 - 00024919 _____ C:\Users\00yoshi\Downloads\MDK-v5.7.0.11.zip 2014-01-14 20:57 - 2012-06-22 13:07 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Deployment 2014-01-13 08:31 - 2013-10-27 19:22 - 00000624 _____ C:\Users\00yoshi\AppData\Roaming\All CPU MeterV3_Settings.ini 2014-01-13 08:31 - 2012-01-27 23:07 - 00007595 _____ C:\Users\00yoshi\AppData\Local\Resmon.ResmonCfg 2014-01-12 17:40 - 2014-01-12 17:40 - 00079269 _____ C:\Users\00yoshi\Downloads\Spleef.jar 2014-01-12 16:06 - 2014-01-12 16:04 - 00000000 ____D C:\Users\00yoshi\AppData\Local\{1065296E-22EC-438E-AD52-AF7F687A8F69} 2014-01-12 13:25 - 2014-01-10 14:20 - 00036130 _____ C:\Users\00yoshi\Downloads\Addition.txt 2014-01-12 13:19 - 2014-01-12 13:19 - 00001186 _____ C:\Users\00yoshi\Desktop\JRT.txt 2014-01-12 13:13 - 2014-01-12 13:13 - 01037068 _____ (Thisisu) C:\Users\00yoshi\Downloads\JRT(1).exe 2014-01-12 13:07 - 2014-01-08 16:15 - 00000000 ____D C:\AdwCleaner 2014-01-12 11:36 - 2014-01-12 11:36 - 01233962 _____ C:\Users\00yoshi\Desktop\adwcleaner.exe 2014-01-11 10:47 - 2014-01-11 10:45 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-11 10:45 - 2014-01-11 10:45 - 02365840 _____ C:\Users\00yoshi\Downloads\SecurityTaskManager_Setup(1).exe 2014-01-11 10:45 - 2014-01-11 10:45 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-10 18:40 - 2012-06-22 13:07 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Apps\2.0 2014-01-10 18:37 - 2014-01-10 18:36 - 00473584 _____ C:\Windows\Minidump\011014-21730-01.dmp 2014-01-10 18:36 - 2014-01-10 18:36 - 663286171 _____ C:\Windows\MEMORY.DMP 2014-01-10 18:36 - 2014-01-10 18:36 - 00000000 ____D C:\Windows\Minidump 2014-01-10 18:36 - 2014-01-10 18:36 - 00000000 _____ C:\Windows\setuperr.log 2014-01-10 17:19 - 2013-11-01 16:18 - 00000000 ____D C:\Users\00yoshi\Desktop\vbdateien 2014-01-10 17:19 - 2013-10-19 12:49 - 00000000 ____D C:\Users\00yoshi\Desktop\Unbenutzt 2014-01-10 17:18 - 2014-01-10 17:18 - 00000000 ____D C:\Users\00yoshi\Desktop\log's 2014-01-10 17:17 - 2014-01-10 17:17 - 00011254 _____ C:\Users\00yoshi\Downloads\Neuer ZIP-komprimierter Ordner.zip 2014-01-10 17:17 - 2014-01-10 17:15 - 00011254 _____ C:\Users\00yoshi\Desktop\Neuer ZIP-komprimierter Ordner.zip 2014-01-10 17:16 - 2014-01-10 17:05 - 00141705 _____ C:\ComboFix.txt 2014-01-10 17:06 - 2014-01-10 16:40 - 00000000 ____D C:\ComboFix 2014-01-10 17:05 - 2014-01-10 16:40 - 00000000 ____D C:\Qoobox 2014-01-10 17:05 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-10 17:01 - 2014-01-10 16:39 - 00000000 ____D C:\Windows\erdnt 2014-01-10 17:00 - 2012-01-14 18:05 - 00000000 ____D C:\Users\00yoshi 2014-01-10 17:00 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-10 16:19 - 2014-01-10 16:18 - 05162489 ____R (Swearware) C:\Users\00yoshi\Desktop\ComboFix.exe 2014-01-10 14:22 - 2014-01-10 14:22 - 00000474 _____ C:\Users\00yoshi\Downloads\defogger_disable.log 2014-01-10 14:22 - 2014-01-10 14:22 - 00000000 _____ C:\Users\00yoshi\defogger_reenable 2014-01-10 14:19 - 2014-01-10 14:19 - 00050477 _____ C:\Users\00yoshi\Downloads\Defogger.exe 2014-01-10 13:54 - 2013-07-01 10:47 - 00003122 _____ C:\Windows\System32\Tasks\YourFile DownloaderUpdate 2014-01-10 13:52 - 2014-01-10 13:52 - 00550371 _____ C:\Users\00yoshi\Downloads\Autoruns.zip 2014-01-09 22:32 - 2014-01-09 22:32 - 00032512 _____ C:\Windows\system32\Drivers\hitmanpro37.sys 2014-01-09 22:32 - 2012-04-26 14:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-09 22:31 - 2014-01-09 21:55 - 00000000 ____D C:\ProgramData\HitmanPro 2014-01-09 22:23 - 2014-01-09 22:23 - 00012092 _____ C:\Windows\system32\.crusader 2014-01-09 21:56 - 2014-01-09 21:56 - 00001909 _____ C:\Users\Public\Desktop\HitmanPro.lnk 2014-01-09 21:56 - 2014-01-09 21:56 - 00000000 ____D C:\Program Files\HitmanPro 2014-01-09 21:55 - 2014-01-09 21:55 - 10264904 _____ (SurfRight B.V.) C:\Users\00yoshi\Downloads\HitmanPro_x64.exe 2014-01-09 21:45 - 2014-01-09 21:45 - 01037068 _____ (Thisisu) C:\Users\00yoshi\Downloads\JRT.exe 2014-01-09 21:45 - 2014-01-09 21:45 - 00000000 ____D C:\Windows\ERUNT 2014-01-09 21:37 - 2014-01-09 21:37 - 00001054 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-09 21:37 - 2014-01-09 21:37 - 00000000 ____D C:\Program Files (x86)\MF 2014-01-09 21:37 - 2013-12-20 15:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-09 21:30 - 2014-01-09 21:30 - 23867560 _____ (Mozilla) C:\Users\00yoshi\Downloads\Firefox Setup 26.0.exe 2014-01-08 16:15 - 2014-01-08 16:15 - 01233962 _____ C:\Users\00yoshi\Downloads\adwcleaner_3.016.exe 2014-01-07 20:17 - 2014-01-05 15:24 - 00000000 ____D C:\ProgramData\InstallMate 2014-01-07 16:50 - 2012-01-14 18:00 - 00000000 ____D C:\Program Files\Google 2014-01-07 16:50 - 2012-01-14 18:00 - 00000000 ____D C:\Program Files (x86)\Google 2014-01-06 19:48 - 2012-01-14 18:55 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Google 2014-01-05 15:31 - 2014-01-05 15:31 - 00000000 ____D C:\ProgramData\SoftWarehouse 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$ 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\ProgramData\504c2cf8db11ac3b 2014-01-04 14:56 - 2014-01-04 14:56 - 00018589 _____ C:\Users\00yoshi\Downloads\169_EW-Biomes.rar 2014-01-04 14:55 - 2014-01-04 14:55 - 08037055 _____ C:\Users\00yoshi\Downloads\Millenaire5.1.11.zip 2014-01-04 00:21 - 2013-12-19 08:21 - 00000075 _____ C:\Users\00yoshi\AppData\Roaming\WB.CFG 2014-01-04 00:04 - 2012-05-31 19:18 - 00000000 ____D C:\Users\00yoshi\Lange Nacht Der Wissenschaften 01-Dateien 2014-01-03 22:50 - 2014-01-03 22:50 - 00790625 _____ C:\Users\00yoshi\Downloads\GoingBeyond1_Tutorial_Sample.zip 2014-01-03 22:44 - 2014-01-03 22:44 - 00193521 _____ C:\Users\00yoshi\Downloads\einfuehrung(1).zip 2014-01-03 22:24 - 2014-01-03 22:24 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source(1).zip 2014-01-03 22:08 - 2014-01-03 22:08 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source.zip 2014-01-03 18:54 - 2014-01-03 18:54 - 00569372 _____ (DotExE ) C:\Users\00yoshi\Downloads\MoonTools.exe 2014-01-02 17:02 - 2014-01-02 17:02 - 00043731 _____ C:\Users\00yoshi\Downloads\TextEffectsLib_1.1.0.0.zip 2014-01-02 16:59 - 2014-01-02 16:59 - 00117423 _____ C:\Users\00yoshi\Downloads\TextEffectsLibDemo_1.1.0.0.zip 2014-01-02 16:09 - 2014-01-02 16:09 - 00018432 _____ (MT Soft) C:\Users\00yoshi\Desktop\ZipLib.dll 2014-01-02 15:16 - 2014-01-02 15:15 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10(1).exe 2014-01-02 00:17 - 2012-11-22 15:06 - 00015872 _____ C:\Users\00yoshi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-12-31 00:12 - 2013-12-31 00:10 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Start 2013-12-31 00:08 - 2013-12-31 00:08 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\nUpdate 2013-12-30 23:50 - 2012-12-28 13:39 - 00000000 ____D C:\Users\00yoshi\Desktop\Der ganze Rest 2013-12-30 23:22 - 2013-12-30 23:21 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10.exe 2013-12-30 23:17 - 2013-12-30 23:17 - 00369345 _____ C:\Users\00yoshi\Downloads\nUpdate.rar 2013-12-30 22:54 - 2013-12-30 22:53 - 33841433 _____ C:\Users\00yoshi\Downloads\Minecraft_Modpack_1.6.2.rar 2013-12-27 22:24 - 2013-12-27 22:24 - 00095068 _____ C:\Users\00yoshi\Desktop\Paintball.jar 2013-12-27 13:26 - 2013-12-27 13:26 - 01927709 _____ C:\Users\00yoshi\Downloads\samp03x_svr_R2_win32.zip 2013-12-27 12:47 - 2013-12-27 12:47 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer 2013-12-27 12:47 - 2012-05-20 19:55 - 00000000 ____D C:\Users\00yoshi\Documents\GTA San Andreas User Files 2013-12-27 12:46 - 2013-12-27 12:45 - 12022145 _____ C:\Users\00yoshi\Downloads\sa-mp-0.3x-R1-2-install.exe 2013-12-26 01:29 - 2013-04-13 21:41 - 00000000 ____D C:\Users\00yoshi\AppData\Local\CrashDumps Some content of TEMP: ==================== C:\Users\00yoshi\AppData\Local\Temp\elodnno3.dll C:\Users\00yoshi\AppData\Local\Temp\jansi-64-git-Bukkit-1.7.2-R0.2-3-g530fcb7-b2982jnks.dll C:\Users\00yoshi\AppData\Local\Temp\jansi-64-git-Spigot-1245.dll C:\Users\00yoshi\AppData\Local\Temp\jshortcut-3692249118532635938.dll C:\Users\00yoshi\AppData\Local\Temp\jshortcut-6610917082064035010.dll C:\Users\00yoshi\AppData\Local\Temp\jshortcut-863361224654920151.dll C:\Users\00yoshi\AppData\Local\Temp\jshortcut-994826625581406291.dll C:\Users\00yoshi\AppData\Local\Temp\Quarantine.exe C:\Users\00yoshi\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll C:\Users\00yoshi\AppData\Local\Temp\v3ytxki6.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== BCD ================================ Windows-Start-Manager --------------------- Bezeichner {bootmgr} device partition=\Device\HarddiskVolume1 description Windows Boot Manager locale de-DE inherit {globalsettings} default {current} resumeobject {81be9816-e38b-11e0-af49-99356d797b37} displayorder {current} toolsdisplayorder {memdiag} timeout 30 Windows-Startladeprogramm ------------------------- Bezeichner {current} device partition=C: path \Windows\system32\winload.exe description Windows 7 locale de-DE inherit {bootloadersettings} recoverysequence {81be9818-e38b-11e0-af49-99356d797b37} recoveryenabled Yes osdevice partition=C: systemroot \Windows resumeobject {81be9816-e38b-11e0-af49-99356d797b37} nx OptIn vga No quietboot No usefirmwarepcisettings No bootlog No sos No Windows-Startladeprogramm ------------------------- Bezeichner {81be9818-e38b-11e0-af49-99356d797b37} device ramdisk=[C:]\Recovery\81be9818-e38b-11e0-af49-99356d797b37\Winre.wim,{81be9819-e38b-11e0-af49-99356d797b37} path \windows\system32\winload.exe description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\81be9818-e38b-11e0-af49-99356d797b37\Winre.wim,{81be9819-e38b-11e0-af49-99356d797b37} systemroot \windows nx OptIn winpe Yes Wiederaufnahme aus dem Ruhezustand ---------------------------------- Bezeichner {81be9816-e38b-11e0-af49-99356d797b37} device partition=C: path \Windows\system32\winresume.exe description Windows Resume Application locale de-DE inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys debugoptionenabled No Windows-Speichertestprogramm ---------------------------- Bezeichner {memdiag} device partition=\Device\HarddiskVolume1 path \boot\memtest.exe description Windows Memory Diagnostic locale de-DE inherit {globalsettings} badmemoryaccess Yes EMS-Einstellungen ----------------- Bezeichner {emssettings} bootems Yes Debuggereinstellungen --------------------- Bezeichner {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM-Defekte ----------- Bezeichner {badmemory} Globale Einstellungen --------------------- Bezeichner {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Startladeprogramm-Einstellungen ------------------------------- Bezeichner {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisoreinstellungen ------------------- Bezeichner {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Einstellungen zur Ladeprogrammfortsetzung ----------------------------------------- Bezeichner {resumeloadersettings} inherit {globalsettings} Ger„teoptionen -------------- Bezeichner {81be9819-e38b-11e0-af49-99356d797b37} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\81be9818-e38b-11e0-af49-99356d797b37\boot.sdi LastRegBack: 2014-01-22 15:31 ==================== End Of Log ============================ --- --- --- [/CODE] ADDITION: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-01-2014 Ran by 00yoshi at 2014-01-24 14:38:02 Running from C:\Users\00yoshi\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov) Adobe AIR (x32 Version: 3.7.0.1860 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.7.0.1860 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (x32 Version: 1.2.3 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.2.3 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.152 - Adobe Systems Incorporated) Adobe Photoshop CS6 (x32 Version: 13.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (x32 Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (x32 Version: 12.0.4.144 - Adobe Systems, Inc.) AIDA64 Extreme v4.00 (x32 Version: 4.00 - FinalWire Ltd.) Alice-Installationsdateien entfernen (x32 Version: - ) AntiBrowserSpy (x32 Version: 4.0.110 - Abelssoft) Ashampoo Burning Studio (x32 Version: 10.0.10 - Ashampoo GmbH & Co. KG) Ashampoo Photo Commander (x32 Version: 9.2.0 - Ashampoo GmbH & Co. KG) Ashampoo Photo Optimizer (x32 Version: 4.0.0 - Ashampoo GmbH & Co. KG) Ashampoo Registry Cleaner v.1.0.0 (x32 Version: 1.0.0 - Ashampoo GmbH & Co. KG) Ashampoo Snap (x32 Version: 4.3.0 - Ashampoo GmbH & Co. KG) Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: 1.12.5.0 - Asmedia Technology) Audacity 2.0.3 (x32 Version: 2.0.3 - Audacity Team) Bluetooth Stack for Windows by Toshiba (Version: v5.10.14 - ) Camtasia Studio 7 (x32 Version: 7.0.1 - TechSmith Corporation) Camtasia Studio 8 (x32 Version: 8.0.4.1060 - TechSmith Corporation) CCleaner (Version: 3.19 - Piriform) COMPUTERBILD Alles-Öffner (x32 Version: 1.0.8 - J3S) COMPUTERBILD Alles-Öffner (x32 Version: 1.0.8 - J3S) Hidden COMPUTERBILD-Abzockschutz (x32 Version: 1.0.42 - J3S) Corel Graphics - Windows Shell Extension (x32 Version: 15.2.0.686 - Corel Corporation) Corel Graphics - Windows Shell Extension (x32 Version: 15.2.686 - Corel Corporation) Hidden Corel Graphics - Windows Shell Extension 64 Bit (Version: 15.2.686 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Common (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Connect (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Custom Data (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - DE (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Draw (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - EN (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - ES (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Extra Content (x32 Version: - Corel Corporation) CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Filters (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - FR (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - IPM (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - IT (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - PHOTO-PAINT (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Redist (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Setup Files (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - WT (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 (x32 Version: 15.2.0.686 - Corel Corporation) CorelDRAW Essentials X5 (x32 Version: 15.3 - Corel Corporation) Hidden Counter-Strike 1.6 (x32 Version: - ) Counter-Strike Xtreme V6 (x32 Version: - ) Craften Terminal 3.4.5011.37604 (x32 Version: 3.4.5011.37604 - Craften.de) Crazy Machines II - Gold (x32 Version: 1.03 - FAKT Software GmbH) CS16 Full v32.1 Non-Steam (x32 Version: - ) CyberLink LabelPrint (x32 Version: 2.5.3418 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.3418 - CyberLink Corp.) Hidden CyberLink MediaEspresso (x32 Version: 6.5.1817_38674 - CyberLink Corp.) CyberLink MediaEspresso (x32 Version: 6.5.1817_38674 - CyberLink Corp.) Hidden CyberLink Power2Go (x32 Version: 7.0.0.1327 - CyberLink Corp.) CyberLink Power2Go (x32 Version: 7.0.0.1327 - CyberLink Corp.) Hidden CyberLink PowerDVD Copy (x32 Version: 1.5.1306 - CyberLink Corp.) CyberLink PowerDVD Copy (x32 Version: 1.5.1306 - CyberLink Corp.) Hidden CyberLink PowerRecover (x32 Version: 5.5.4125 - CyberLink Corp.) CyberLink PowerRecover (x32 Version: 5.5.4125 - CyberLink Corp.) Hidden CyberLink YouPaint (x32 Version: 1.2.1928 - CyberLink Corp.) CyberLink YouPaint (x32 Version: 1.2.1928 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.) Entity Framework Tools for Visual Studio 2013 (x32 Version: 12.0.20912.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (x32 Version: 11.1.3000.0 - Microsoft Corporation) EVEREST Home Edition v2.20 (x32 Version: 2.20 - Lavalys Inc) FileZilla Client 3.7.1 (x32 Version: 3.7.1 - FileZilla Project) foobar2000 v1.2.4 (x32 Version: 1.2.4 - Peter Pawlowski) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Free Screen To Video V 2.0 (x32 Version: 2.0.0.0 - Koyote Soft) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii uslugi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Booster 3 (x32 Version: 3.4 - IObit) Google Chrome (x32 Version: 32.0.1700.76 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Greenfish Icon Editor Pro 3.25 (x32 Version: - Greenfish Corporation) Haskell Platform 2013.2.0.0 (x32 Version: - Haskell.org) HitmanPro 3.7 (Version: 3.7.8.208 - SurfRight B.V.) Hotfix für Microsoft Visual Basic 2010 Express - DEU (KB2635973) (x32 Version: 1 - Microsoft Corporation) HP Foto- und Bildbearbeitung 2.0 - All-in-One (x32 Version: 1.10.0000 - Hewlett-Packard Company) Hidden HP Foto- und Bildbearbeitung 2.0 All-in-One Treiber (x32 Version: 1.10.0000 - Hewlett-Packard Company) Hidden HTML Tester (HKCU Version: 1.0.0.2 - HTML Tester) IIS 8.0 Express (Version: 8.0.1557 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (Version: - ) IIS Express Application Compatibility Database for x86 (Version: - ) Installer (HKCU Version: 1.0.0.0 - Installer) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation) Intel(R) Rapid Storage Technology (x32 Version: 10.5.0.1026 - Intel Corporation) Internetbrowser(testversion) (HKCU Version: 1.0.0.2 - 00yoshi) Java 7 Update 45 (64-bit) (Version: 7.0.450 - Oracle) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 45 (x32 Version: 6.0.450 - Oracle) Java(TM) 7 (64-bit) (Version: 7.0.0 - Oracle) Java(TM) SE Development Kit 6 Update 45 (x32 Version: 1.6.0.450 - Oracle) JavaFX 2.1.0 (64-bit) (Version: 2.1.0 - Oracle Corporation) JavaFX 2.1.0 SDK (64-bit) (Version: 2.1.0 - Oracle Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden K-Lite Codec Pack 7.0.0 (Standard) (x32 Version: 7.0.0 - ) L&H TTS3000 Deutsch (x32 Version: - ) League of Legends (x32 Version: 1.02.0000 - Riot Games) League of Legends (x32 Version: 1.3 - Riot Games) LogMeIn Hamachi (x32 Version: 2.1.0.166 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.1.0.166 - LogMeIn, Inc.) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Media converter (x32 Version: - ) MediaConverter 1.3.2 (x32 Version: 1.3.2 - SoMud) MediaFire Express (x32 Version: 0.15.4.4888 - MediaFire) Medion Home Cinema (x32 Version: 8.0.2926 - CyberLink Corp.) Medion Home Cinema (x32 Version: 8.0.2926 - CyberLink Corp.) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (x32 Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5 Multi-Targeting Pack (x32 Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (x32 Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (x32 Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (x32 Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (Deutsch) (x32 Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (x32 Version: 4.5.51641 - Microsoft Corporation) Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Exchange Web Services Managed API 2.0 (x32 Version: 15.0.516.14 - Microsoft Corporation) Hidden Microsoft Flight Simulator 2002 (x32 Version: - ) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.1 (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 (Version: 1.1.40219 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.1 Language Pack - DEU (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 Language Pack - DEU (Version: 1.1.40219 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.1 (x32 Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.1 (x32 Version: 2.1.21005 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.1 Sprachpaket - DEU (x32 Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.1 Sprachpaket - DEU (x32 Version: 2.1.21005 - Microsoft Corporation) Hidden Microsoft Identity Extensions (Version: 2.0.1459.0 - Microsoft Corporation) Hidden Microsoft Office 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel Viewer (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft PowerPoint Viewer (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (Version: 4.4.304.0 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK - DEU (x32 Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU Version: 16.4.6010.0727 - Microsoft Corporation) Microsoft Small Basic v0.6 (x32 Version: 0.6 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2008 (x32 Version: - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Browser (x32 Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2008 Common Files (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Services (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Shared (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Native Client (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (x32 Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server 2008 RsFx Driver (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Setup Support Files (x32 Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x32 Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x64) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x32 Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL-Sprachdienst (x32 Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 Design Tools English (x32 Version: 3.5.5692.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 English (x32 Version: 3.5.5692.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 DEU (x32 Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (12.0.30919.1) (x32 Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - DEU (12.0.30919.1) (x32 Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x32 Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x64) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server VSS Writer (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft Visual Basic 2010 Express - DEU (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Basic 2010 Express - DEU (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual C++ Compilers 2010 Standard - enu - x86 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU (Version: - Microsoft Corporation) Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU (Version: 9.0.30729 - Microsoft Corporation) Hidden Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU Service Pack 1 (KB945140) (x32 Version: 1 - Microsoft Corporation) Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40820 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40825 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU (Version: 10.0.40820 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (Version: 10.0.40820 - Microsoft Corporation) Microsoft Web Deploy 3.5 (Version: 3.1237.1762 - Microsoft Corporation) Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu (Version: 3.5.30729 - Microsoft Corporation) Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 (Version: 6.1.5295.17011 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.0 (x32 Version: 3.0.11010.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (x32 Version: 4.0.20823.0 - Microsoft Corporation) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft-System-CLR-Typen für SQL Server 2012 (x32 Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (Version: 11.1.3366.16 - Microsoft Corporation) Minecraft Editor 64 bits (Version: 1.8.0 - Axialmedia) Minecraft Recipe Creator (HKCU Version: 1.0.0.6 - Christopher Everitt) Minecraft Texturepack Editor (x32 Version: - ) Minecraft2d extented (HKCU Version: 1.0.0.0 - Minecraft2d extented) MinecraftAlpha (x32 Version: - ) MiniTool Partition Wizard Home Edition 7.1 (x32 Version: - MiniTool Solution Ltd.) MODINSTALLER (HKCU Version: 1.0.0.0 - Technikminer) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden myMugle (x32 Version: 3.0.0.0 - Computer Business Solutions) Notepad++ (x32 Version: 6.1.3 - ) NVIDIA 3D Vision Treiber 331.65 (Version: 331.65 - NVIDIA Corporation) NVIDIA Grafiktreiber 331.65 (Version: 331.65 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.11.0621 - NVIDIA Corporation) Hidden NVIDIA PhysX System Software 9.11.0621 (Version: 9.11.0621 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden NVIDIA Update 1.15.2 (Version: 1.15.2 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden Open Freely (Version: 1.0 - Download Freely, LLC) Open XML SDK 2.5 for Microsoft Office (x32 Version: 2.5.5631 - Microsoft Corporation) Hidden Paint.NET v3.5.11 (Version: 3.61.0 - dotPDN LLC) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (x32 Version: 4.5.50932 - Microsoft Corporation) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden PlayReady PC Runtime amd64 (Version: 1.3.0 - Microsoft Corporation) Poczta uslugi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Postal 2 STP - Free Multiplayer Edition (x32 Version: - ) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (x32 Version: 6.0.1.6368 - Realtek Semiconductor Corp.) Secunia PSI (3.0.0.4001) (x32 Version: 3.0.0.4001 - Secunia) Security Task Manager 1.8g (x32 Version: 1.8g - Neuber Software) server auto ip (HKCU Version: 1.0.0.2 - server auto ip) Service Pack 3 für SQL Server 2008 (KB2546951) (x32 Version: 10.3.5500.0 - Microsoft Corporation) SharePoint Client Components (Version: 15.0.4481.1505 - Microsoft Corporation) Hidden SharpDX (x32 Version: 2.5.0 - SharpDX) SigmaTel MSCN Audio Player (x32 Version: - ) Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) SmartFTP Client (Version: 4.1.1320.0 - SmartSoft Ltd.) Spelling Dictionaries Support For Adobe Reader X (x32 Version: 10.0.0 - Adobe Systems Incorporated) Spiel2 (HKCU Version: 1.0.0.0 - Spiel2) Sprechprogramm (HKCU Version: 1.0.0.0 - Sprechprogramm) Sql Server Customer Experience Improvement Program (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Start (HKCU Version: 1.0.0.1 - Start) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (Version: 3.0.11.1 - TeamSpeak Systems GmbH) TeamViewer 9 (x32 Version: 9.0.24482 - TeamViewer) Techne (HKCU Version: 1.3.0.15 - ZeuX and r4wk) TmNationsForever (x32 Version: - Nadeo) TmSunriseDemoMag 1.4.5 (x32 Version: - Nadeo) Ultimate Browser (HKCU Version: 1.0.0.0 - Ultimate Browser) Unigine Valley Benchmark version 1.0 (x32 Version: 1.0 - Unigine Corp.) Unity Web Player (HKCU Version: - Unity Technologies ApS) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (x32 Version: 4.0.8080.0 - Microsoft Corporation) VLC media player 2.1.0 (x32 Version: 2.1.0 - VideoLAN) WCF RIA Services V1.0 SP2 (x32 Version: 4.1.62812.0 - Microsoft Corporation) Websiteclicker (HKCU Version: 1.0.0.0 - Websiteclicker) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotograf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinRAR 4.01 (32-Bit) (x32 Version: 4.01.0 - win.rar GmbH) WorldPainter 1.2.5 (Version: 1.2.5 - pepsoft.org) S?????? f?t???af??? t?? Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 12-01-2014 10:25:19 Windows Update 15-01-2014 15:53:16 Windows Update 18-01-2014 21:22:56 Windows Update 24-01-2014 12:34:40 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2014-01-10 17:00 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {31F1DB6D-AB3B-4D6E-B0E5-2C8500B361B4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-14] (Google Inc.) Task: {421201ED-2AB8-46F7-9D54-8705CD4CB5B8} - \Dealply No Task File Task: {4C61322B-F811-4F12-AB4E-62E62078723E} - System32\Tasks\AdobeAAMUpdater-1.0-00yoshisPC-00yoshi => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20] (Adobe Systems Incorporated) Task: {88A0DEF9-9A59-44E3-8A87-F1CFF07322D7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-07] (Adobe Systems Incorporated) Task: {91D73C45-2EDB-4192-A266-0FB73C3B64AF} - System32\Tasks\YourFile DownloaderUpdate => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION Task: {B7282210-9ABB-4F65-8FFF-91654F170006} - System32\Tasks\PCMeter\Startup => C:\Users\00yoshi\AppData\Local\Temp\Rar$EX26.952\PCMeter\PCMeterV0.3.exe <==== ATTENTION Task: {C2D7B5BC-EEBC-4306-99BC-BB4FE30A143E} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe [2013-06-24] () Task: {D88B83B1-49FB-49B8-9F83-3F549C74E636} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-14] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 07027664 _____ () C:\Program Files (x86)\AntiBrowserSpy\Commons.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 00177616 _____ () C:\Program Files (x86)\AntiBrowserSpy\AbBrowserLibs.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 00028112 _____ () C:\Program Files (x86)\AntiBrowserSpy\VersionInfo.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 00012752 _____ () C:\Program Files (x86)\AntiBrowserSpy\AbProcessManager.dll 2014-01-05 14:09 - 2014-01-05 14:09 - 00306176 _____ () C:\Users\00yoshi\Desktop\atlauncher\Instances\ASolitaryCraft\bin\natives\lwjgl64.dll 2014-01-05 14:09 - 2014-01-05 14:09 - 00382464 _____ () C:\Users\00yoshi\Desktop\atlauncher\Instances\ASolitaryCraft\bin\natives\OpenAL64.dll 2013-10-11 18:20 - 2013-10-11 18:20 - 00240640 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\PaintDotNet.SystemL#\7c45449cd3c24eec7abd4b46d45c4aeb\PaintDotNet.SystemLayer.Native.x64.ni.dll 2013-08-17 13:01 - 2013-08-17 13:01 - 00129600 _____ () C:\Program Files\Paint.NET\Native.x64\PaintDotNet.Native.x64.dll 2013-08-17 13:01 - 2013-08-17 13:01 - 00085568 _____ () C:\Program Files\Paint.NET\PaintDotNet.SystemLayer.Native.x64.dll 2013-10-27 18:11 - 2013-10-27 18:11 - 00012520 _____ () C:\Users\00yoshi\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\CoreTempReader.dll 2013-10-27 18:11 - 2013-10-27 18:11 - 00015080 _____ () C:\Users\00yoshi\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\GetCoreTempInfoNET.dll 2013-10-27 18:11 - 2013-10-27 18:11 - 00014056 _____ () C:\Users\00yoshi\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\SystemInfo.dll 2010-08-03 23:39 - 2010-08-03 23:39 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2010-08-03 23:39 - 2010-08-03 23:39 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\libcef.dll 2013-08-15 07:46 - 2013-08-15 07:46 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\f7b8fe4da9013ce331d3363fe18a775d\IsdiInterop.ni.dll 2011-08-11 21:01 - 2011-04-30 08:28 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2013-06-18 21:08 - 2013-06-18 21:08 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2014-01-09 21:37 - 2013-12-05 20:36 - 03559024 _____ () C:\Program Files (x86)\MF\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:430C6D84 AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== Faulty Device Manager Devices ============= Name: Hamachi Network Interface Description: Hamachi Network Interface Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: LogMeIn, Inc. Service: hamachi Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/24/2014 01:34:40 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler . Error: (01/24/2014 01:34:40 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler . Error: (01/24/2014 01:26:24 PM) (Source: MsiInstaller) (User: 00YOSHIPC) Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011006}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/23/2014 09:22:21 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (01/23/2014 08:57:31 PM) (Source: CVHSVC) (User: ) Description: Nur zur Information. (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Der Servername oder die Serveradresse konnte nicht verarbeitet werden. Error: (01/23/2014 05:47:21 PM) (Source: CVHSVC) (User: ) Description: Nur zur Information. (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Der Servername oder die Serveradresse konnte nicht verarbeitet werden. Error: (01/22/2014 04:23:25 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (01/22/2014 04:23:22 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (01/22/2014 01:34:20 PM) (Source: MsiInstaller) (User: 00YOSHIPC) Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011006}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/22/2014 08:26:22 AM) (Source: MsiInstaller) (User: 00YOSHIPC) Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011006}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 System errors: ============= Error: (01/24/2014 01:23:38 PM) (Source: NETLOGON) (User: ) Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser Konfiguration nicht gestartet zu sein. Error: (01/23/2014 08:57:47 PM) (Source: Microsoft Antimalware) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.165.2328.0 Aktualisierungsquelle: %NT-AUTORITÄT59 Aktualisierungsphase: 4.4.0304.00 Quellpfad: 4.4.0304.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (01/23/2014 08:47:10 PM) (Source: NETLOGON) (User: ) Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser Konfiguration nicht gestartet zu sein. Error: (01/23/2014 05:47:43 PM) (Source: Microsoft Antimalware) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.165.2328.0 Aktualisierungsquelle: %NT-AUTORITÄT59 Aktualisierungsphase: 4.4.0304.00 Quellpfad: 4.4.0304.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (01/23/2014 05:37:02 PM) (Source: NETLOGON) (User: ) Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser Konfiguration nicht gestartet zu sein. Error: (01/22/2014 01:31:12 PM) (Source: NETLOGON) (User: ) Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser Konfiguration nicht gestartet zu sein. Error: (01/22/2014 08:23:55 AM) (Source: NETLOGON) (User: ) Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser Konfiguration nicht gestartet zu sein. Error: (01/22/2014 08:23:54 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am ?22.?01.?2014 um 08:21:57 unerwartet heruntergefahren. Error: (01/22/2014 08:19:09 AM) (Source: NETLOGON) (User: ) Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser Konfiguration nicht gestartet zu sein. Error: (01/22/2014 08:19:08 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am ?22.?01.?2014 um 08:17:23 unerwartet heruntergefahren. Microsoft Office Sessions: ========================= Error: (01/24/2014 01:34:40 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler Error: (01/24/2014 01:34:40 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler Error: (01/24/2014 01:26:24 PM) (Source: MsiInstaller)(User: 00YOSHIPC) Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011006}1625(NULL)(NULL)(NULL) Error: (01/23/2014 09:22:21 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\00yoshi\Desktop\esetsmartinstaller_deu.exe Error: (01/23/2014 08:57:31 PM) (Source: CVHSVC)(User: ) Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Der Servername oder die Serveradresse konnte nicht verarbeitet werden. Error: (01/23/2014 05:47:21 PM) (Source: CVHSVC)(User: ) Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Der Servername oder die Serveradresse konnte nicht verarbeitet werden. Error: (01/22/2014 04:23:25 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\00yoshi\Desktop\esetsmartinstaller_deu.exe Error: (01/22/2014 04:23:22 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\00yoshi\Desktop\esetsmartinstaller_deu.exe Error: (01/22/2014 01:34:20 PM) (Source: MsiInstaller)(User: 00YOSHIPC) Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011006}1625(NULL)(NULL)(NULL) Error: (01/22/2014 08:26:22 AM) (Source: MsiInstaller)(User: 00YOSHIPC) Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011006}1625(NULL)(NULL)(NULL) CodeIntegrity Errors: =================================== Date: 2014-01-10 17:00:03.782 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-10 17:00:03.720 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.988 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\00yoshi\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.942 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\00yoshi\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.622 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.576 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 82% Total physical RAM: 8173.64 MB Available physical RAM: 1394.53 MB Total Pagefile: 32747.82 MB Available Pagefile: 24242.68 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:1811.92 GB) (Free:1444.99 GB) NTFS Drive d: (Recover) (Fixed) (Total:50 GB) (Free:24.38 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 1863 GB) (Disk ID: 2BD2C32A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=-253492199424) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ==================== End Of Log ============================ |
25.01.2014, 12:07 | #17 |
/// the machine /// TB-Ausbilder | GreatSaver infiziert Noch Probleme mit dem Rechner?
__________________
__________________ |
26.01.2014, 09:29 | #18 |
| GreatSaver infiziert Nein. Tipp: hardwarebeschleunigung bei FF ausmachen, sonst stürzt manchmal PC ab. (war nach neiinstallation von FF an)
__________________ |
27.01.2014, 07:27 | #19 |
/// the machine /// TB-Ausbilder | GreatSaver infiziert Du meinst im Flash Video? Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu GreatSaver infiziert |
4d36e972-e325-11ce-bfc1-08002be10318, abelssoft, adblock, administrator, adware, bootmgr, converter, cpu, desktop, entfernen, error, excel, explorer, firefox, flash player, ftp, great, hdaudio.sys, helper, home, homepage, junkware, koyote, neue tabs, newtab, nvpciflt.sys, photoshop, plug-in, popup, registry, saver, security, server, services.exe, software, svchost.exe, temp, texturepack, usb, usbvideo.sys, windows, winlogon.exe |