|
Log-Analyse und Auswertung: Conduit Search Befall, Pop-Ups und WerbungWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
04.02.2014, 12:11 | #1 |
| Conduit Search Befall, Pop-Ups und Werbung Hallo, habe mir eine befallene Datei runtergeladen, die tzsätzlich etwa 5 Programme zum Pc tweaken installiert hat. Diese habe ich sofort deinstalliert, jedoch bekomme ich die conduit Search im Firefox nicht weg und dazu öffnen sich ständig Werbefenster Pop Ups. Bitte um Hilfe .) 1.defogger: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 11:50 on 04/02/2014 (Kevin) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- 2.FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2014 Ran by Kevin (administrator) on WORKSTATION on 04-02-2014 11:53:21 Running from E:\Benutzer\Kevin\Downloads Windows 8.1 Pro (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () E:\Program Files (x64)\EslWire\service\WireHelperSvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Universal Updater\UpdaterService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.4.9600.16384_x64__8wekyb3d8bbwe\livecomm.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-01-31] (Advanced Micro Devices, Inc.) HKU\S-1-5-21-3231436611-243068960-233781985-1001\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2014-01-31] (AMD) HKU\S-1-5-21-3231436611-243068960-233781985-1001\...\MountPoints2: {aa816282-8d2b-11e3-827e-bc5ff4f1074d} - "G:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-3231436611-243068960-233781985-1001\...\MountPoints2: {cd9a2cb6-807e-11e3-825b-bc5ff4f1074d} - "G:\HTC_Sync_Manager_PC.exe" ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFE78C9400112CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE,de;q=0.8,en-US;q=0.5,en;q=0.3 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3320691&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP757E336E-2A51-47CF-B421-4A40397B0355&q={searchTerms}&SSPV= SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3320691&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP757E336E-2A51-47CF-B421-4A40397B0355&q={searchTerms}&SSPV= BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\relp9n8x.default FF NewTab: hxxp://search.conduit.com/?ctid=CT3320691&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SP757E336E-2A51-47CF-B421-4A40397B0355 FF Homepage: hxxp://google.de/ FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20nq-us05.personalitycores.com%3A8000%3B%20PROXY%20nq-us07.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000%3B%20PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us04.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000%3B%20PROXY%20nq-us10.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\relp9n8x.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: HD Streamer - C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\relp9n8x.default\Extensions\hd_streamer@iMedia [2014-02-04] FF Extension: ProxMate - Proxy on steroids! - C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\relp9n8x.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2014-01-15] FF Extension: WinToFlash Suggestor - C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\relp9n8x.default\Extensions\{285ACFBB-8E53-4feb-90E6-F02A128927F3}.xpi [2014-01-15] FF Extension: Updated Ad Blocker for Firefox 11+ - C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\relp9n8x.default\Extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi [2014-01-15] FF Extension: Adblock Plus - C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\relp9n8x.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-15] Chrome: ======= CHR HomePage: http:\/\/search.conduit.com\/?ctid=CT3320691&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP757E336E-2A51-47CF-B421-4A40397B0355&SSPV= CHR DefaultSearchKeyword: conduit.search CHR DefaultSearchURL: http:\/\/search.conduit.com\/Results.aspx?ctid=CT3320691&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP757E336E-2A51-47CF-B421-4A40397B0355&q={searchTerms}&SSPV= CHR Extension: (Docs) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-15] CHR Extension: (Google Drive) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-15] CHR Extension: (YouTube) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-15] CHR Extension: (Google Search) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-15] CHR Extension: (Google Wallet) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-15] CHR Extension: (Gmail) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-15] ==================== Services (Whitelisted) ================= R2 EslWireHelper; E:\Program Files (x64)\EslWire\service\WireHelperSvc.exe [663056 2013-06-11] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-01-15] () R2 UniversalUpdater; C:\Program Files (x86)\Universal Updater\UpdaterService.exe [402872 2014-01-29] () R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-12-19] (Advanced Micro Devices) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider) S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider) R0 ESLWireAC; C:\Windows\System32\drivers\ESLWireACD.sys [184968 2014-01-16] (<Turtle Entertainment>) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) S3 ALSysIO; \??\C:\Users\Kevin\AppData\Local\Temp\ALSysIO64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-04 11:53 - 2014-02-04 11:53 - 00000000 ____D () C:\FRST 2014-02-04 11:50 - 2014-02-04 11:50 - 00000000 _____ () C:\Users\Kevin\defogger_reenable 2014-02-04 03:57 - 2014-02-04 03:58 - 00000000 ____D () C:\ProgramData\SpeedyPC Software 2014-02-04 03:57 - 2014-02-04 03:57 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\SpeedyPC Software 2014-02-04 03:57 - 2014-02-04 03:57 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\DriverCure 2014-02-04 03:57 - 2014-02-04 03:57 - 00000000 ____D () C:\Program Files (x86)\Universal Updater 2014-02-04 03:57 - 2014-02-04 03:57 - 00000000 _____ () C:\END 2014-02-02 16:28 - 2014-02-02 16:28 - 00000000 ____D () C:\Users\Kevin\AppData\Local\next car game technology sneak peek 2014-02-02 15:31 - 2014-02-02 15:31 - 00055617 _____ () C:\Windows\SysWOW64\CCCInstall_201402021531075772.log 2014-02-02 15:31 - 2014-02-02 15:31 - 00000000 ____D () C:\ProgramData\ATI 2014-02-02 15:31 - 2014-02-02 15:31 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-02-02 15:30 - 2014-02-02 15:31 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-02-02 15:30 - 2014-02-02 15:30 - 00054596 _____ () C:\Windows\SysWOW64\CCCInstall_201402021530538062.log 2014-02-02 15:30 - 2014-02-02 15:30 - 00000000 ____D () C:\Windows\LastGood 2014-02-02 15:29 - 2014-02-02 15:31 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-02-02 15:29 - 2014-02-02 15:29 - 00000000 ____D () C:\Program Files\ATI 2014-02-02 15:26 - 2014-02-02 15:26 - 00054772 _____ () C:\Windows\SysWOW64\CCCInstall_201402021526020243.log 2014-02-02 15:26 - 2014-02-02 15:26 - 00049669 _____ () C:\Windows\SysWOW64\CCCInstall_201402021526194660.log 2014-02-02 15:25 - 2014-02-02 15:25 - 00000000 ____D () C:\Windows\LastGood.Tmp 2014-01-31 22:07 - 2014-01-31 22:07 - 10145128 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00127872 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00117560 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00098496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2014-01-31 22:06 - 2014-01-31 22:06 - 06716264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2014-01-31 21:57 - 2014-01-31 21:57 - 13929472 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2014-01-31 21:43 - 2014-01-31 21:43 - 00230912 _____ () C:\Windows\system32\clinfo.exe 2014-01-31 21:43 - 2014-01-31 21:43 - 00098816 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2014-01-31 21:43 - 2014-01-31 21:43 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2014-01-31 21:43 - 2014-01-31 21:43 - 00083456 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2014-01-31 21:43 - 2014-01-31 21:43 - 00073216 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2014-01-31 21:42 - 2014-01-31 21:42 - 28424704 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2014-01-31 21:40 - 2014-01-31 21:40 - 23903232 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2014-01-31 21:38 - 2014-01-31 21:38 - 00065024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-01-31 21:38 - 2014-01-31 21:38 - 00058880 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-01-31 21:27 - 2014-01-31 21:27 - 00576040 _____ () C:\Windows\SysWOW64\atiapfxx.blb 2014-01-31 21:27 - 2014-01-31 21:27 - 00576040 _____ () C:\Windows\system32\atiapfxx.blb 2014-01-31 21:26 - 2014-01-31 21:26 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2014-01-31 21:26 - 2014-01-31 21:26 - 00415744 _____ () C:\Windows\system32\amdmiracast.dll 2014-01-31 21:26 - 2014-01-31 21:26 - 00368640 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2014-01-31 21:26 - 2014-01-31 21:26 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2014-01-31 21:26 - 2014-01-31 21:26 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2014-01-31 21:26 - 2014-01-31 21:26 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2014-01-31 21:26 - 2014-01-31 21:26 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2014-01-31 21:24 - 2014-01-31 21:24 - 00126464 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll 2014-01-31 21:24 - 2014-01-31 21:24 - 00113152 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll 2014-01-31 21:23 - 2014-01-31 21:23 - 05350400 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll 2014-01-31 21:22 - 2014-01-31 21:22 - 27152384 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2014-01-31 21:22 - 2014-01-31 21:22 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2014-01-31 21:10 - 2014-01-31 21:10 - 04286976 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll 2014-01-31 21:06 - 2014-01-31 21:06 - 00586240 _____ (AMD) C:\Windows\system32\atieclxx.exe 2014-01-31 21:06 - 2014-01-31 21:06 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2014-01-31 21:05 - 2014-01-31 21:05 - 00240128 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2014-01-31 21:03 - 2014-01-31 21:03 - 22834688 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2014-01-31 21:03 - 2014-01-31 21:03 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2014-01-31 20:59 - 2014-01-31 20:59 - 00081920 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll 2014-01-31 20:59 - 2014-01-31 20:59 - 00079360 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll 2014-01-31 20:48 - 2014-01-31 20:48 - 00044544 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll 2014-01-31 20:47 - 2014-01-31 20:47 - 00035840 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll 2014-01-31 20:43 - 2014-01-31 20:43 - 03434288 _____ () C:\Windows\system32\atiumd6a.cap 2014-01-31 20:37 - 2014-01-31 20:37 - 00806912 _____ (AMD) C:\Windows\system32\coinst_13.350.dll 2014-01-31 20:32 - 2014-01-31 20:32 - 03468336 _____ () C:\Windows\SysWOW64\atiumdva.cap 2014-01-31 20:30 - 2014-01-31 20:30 - 00828416 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2014-01-31 20:29 - 2014-01-31 20:29 - 00146432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2014-01-31 20:29 - 2014-01-31 20:29 - 00133120 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2014-01-31 20:29 - 2014-01-31 20:29 - 00075264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2014-01-31 20:29 - 2014-01-31 20:29 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2014-01-31 20:29 - 2014-01-31 20:29 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2014-01-31 20:28 - 2014-01-31 20:28 - 00636928 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2014-01-31 20:25 - 2014-01-31 20:25 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2014-01-31 20:23 - 2014-01-31 20:23 - 00095744 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll 2014-01-31 20:23 - 2014-01-31 20:23 - 00090112 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll 2014-01-31 20:23 - 2014-01-31 20:23 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll 2014-01-31 20:23 - 2014-01-31 20:23 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll 2014-01-31 20:20 - 2014-01-31 20:20 - 00134144 _____ () C:\Windows\system32\amdhdl64.dll 2014-01-31 20:20 - 2014-01-31 20:20 - 00123392 _____ () C:\Windows\SysWOW64\amdhdl32.dll 2014-01-31 15:53 - 2014-01-31 15:53 - 00051200 _____ () C:\Windows\system32\kdbsdk64.dll 2014-01-31 15:49 - 2014-01-31 15:49 - 00038912 _____ () C:\Windows\SysWOW64\kdbsdk32.dll 2014-01-31 09:43 - 2014-01-31 09:43 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\MPC-HC 2014-01-29 09:43 - 2014-01-29 09:43 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\LolClient 2014-01-28 21:40 - 2014-02-03 07:06 - 00000000 ____D () C:\Users\Kevin\AppData\Local\PMB Files 2014-01-28 21:40 - 2014-02-02 07:20 - 00000000 ____D () C:\ProgramData\PMB Files 2014-01-28 21:40 - 2014-01-28 21:40 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-01-28 21:40 - 2014-01-28 21:40 - 00000000 ____D () C:\Program Files (x86)\Pando Networks 2014-01-28 21:40 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2014-01-28 21:40 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2014-01-28 21:40 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2014-01-28 21:39 - 2014-01-28 21:40 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Riot Games 2014-01-18 21:27 - 2014-01-18 21:27 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-01-18 21:02 - 2014-01-18 21:27 - 00000000 ___RD () C:\Windows\BrowserChoice 2014-01-18 21:02 - 2014-01-18 21:02 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer 2014-01-18 21:02 - 2014-01-18 21:02 - 00000000 ____D () C:\Program Files\Reference Assemblies 2014-01-18 21:02 - 2014-01-18 21:02 - 00000000 ____D () C:\Program Files\MSBuild 2014-01-18 21:02 - 2014-01-18 21:02 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies 2014-01-18 21:02 - 2014-01-18 21:02 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2014-01-18 16:31 - 2013-08-03 05:48 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2014-01-18 16:31 - 2013-08-03 05:48 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-01-18 16:31 - 2013-08-03 05:48 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-01-18 16:31 - 2013-08-03 05:41 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll 2014-01-18 16:31 - 2013-08-03 05:41 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2014-01-18 16:31 - 2013-08-03 05:41 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-01-18 16:13 - 2014-01-18 16:13 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help 2014-01-18 16:13 - 2014-01-18 16:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help 2014-01-18 16:11 - 2014-01-18 16:12 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-18 16:11 - 2014-01-06 16:20 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-17 19:20 - 2014-01-17 19:20 - 00000022 _____ () C:\Program Files\zipnew.dat 2014-01-17 19:20 - 2014-01-17 19:20 - 00000020 _____ () C:\Program Files\rarnew.dat 2014-01-17 19:20 - 2014-01-17 19:20 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\WinRAR 2014-01-17 19:20 - 2014-01-17 19:20 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-01-17 19:20 - 2013-12-01 14:09 - 01315928 _____ (Alexander Roshal) C:\Program Files\WinRAR.exe 2014-01-17 19:20 - 2013-12-01 14:09 - 00522840 _____ (Alexander Roshal) C:\Program Files\Rar.exe 2014-01-17 19:20 - 2013-12-01 14:09 - 00330328 _____ (Alexander Roshal) C:\Program Files\UnRAR.exe 2014-01-17 19:20 - 2013-12-01 14:09 - 00214616 _____ (Alexander Roshal) C:\Program Files\RarExt.dll 2014-01-17 19:20 - 2013-12-01 14:09 - 00185432 _____ (Alexander Roshal) C:\Program Files\RarExt32.dll 2014-01-17 19:20 - 2013-12-01 14:09 - 00149592 _____ (Alexander Roshal) C:\Program Files\Uninstall.exe 2014-01-17 19:20 - 2013-12-01 14:09 - 00000675 _____ () C:\Program Files\Uninstall.lst 2014-01-17 19:20 - 2013-12-01 14:08 - 00297422 _____ () C:\Program Files\WinRAR.chm 2014-01-17 19:20 - 2013-12-01 14:08 - 00243200 _____ () C:\Program Files\Default64.SFX 2014-01-17 19:20 - 2013-12-01 14:08 - 00197632 _____ () C:\Program Files\Default.SFX 2014-01-17 19:20 - 2013-12-01 14:08 - 00165376 _____ () C:\Program Files\Zip64.SFX 2014-01-17 19:20 - 2013-12-01 14:08 - 00141824 _____ () C:\Program Files\Zip.SFX 2014-01-17 19:20 - 2013-12-01 14:07 - 00238592 _____ (Alexander Roshal) C:\Program Files\WinCon64.SFX 2014-01-17 19:20 - 2013-12-01 14:07 - 00198656 _____ (Alexander Roshal) C:\Program Files\WinCon.SFX 2014-01-17 19:20 - 2013-12-01 14:07 - 00043616 _____ () C:\Program Files\WhatsNew.txt 2014-01-17 19:20 - 2013-11-07 20:32 - 00098840 _____ () C:\Program Files\Rar.txt 2014-01-17 19:20 - 2013-10-22 09:18 - 01287064 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-01-17 19:20 - 2013-10-22 08:55 - 02328872 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2014-01-17 19:20 - 2013-10-22 07:03 - 02065448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2014-01-17 19:20 - 2013-10-22 03:07 - 02617344 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-01-17 19:20 - 2013-10-22 02:53 - 01584128 _____ (Microsoft Corporation) C:\Windows\system32\workfolderssvc.dll 2014-01-17 19:20 - 2013-10-22 02:47 - 02295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-01-17 19:20 - 2013-10-19 09:51 - 00481392 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll 2014-01-17 19:20 - 2013-10-19 08:12 - 00380656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll 2014-01-17 19:20 - 2013-10-19 04:26 - 01231360 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll 2014-01-17 19:20 - 2013-10-19 04:14 - 00888832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll 2014-01-17 19:20 - 2013-10-17 16:42 - 01399176 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll 2014-01-17 19:20 - 2013-10-08 11:13 - 02551640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-01-17 19:20 - 2013-10-08 06:09 - 01160704 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Http.dll 2014-01-17 19:20 - 2013-10-07 03:13 - 03532288 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-01-17 19:20 - 2013-10-05 15:21 - 00699840 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2014-01-17 19:20 - 2013-10-05 09:56 - 01147904 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll 2014-01-17 19:20 - 2013-10-05 09:21 - 00920064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll 2014-01-17 19:20 - 2013-10-05 08:43 - 00578560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll 2014-01-17 19:20 - 2013-10-05 08:39 - 06639616 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-01-17 19:20 - 2013-10-05 08:32 - 05769728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-01-17 19:20 - 2013-09-17 10:06 - 01067080 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll 2014-01-17 19:20 - 2013-09-17 07:31 - 00883184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll 2014-01-17 19:20 - 2013-09-14 15:07 - 02134120 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll 2014-01-17 19:20 - 2013-09-10 06:26 - 04599808 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-01-17 19:20 - 2013-09-04 15:59 - 00000000 ____D () C:\Program Files\Formats 2014-01-17 19:20 - 2013-07-31 22:33 - 00006882 _____ () C:\Program Files\License.txt 2014-01-17 19:20 - 2013-05-02 22:43 - 00000912 _____ () C:\Program Files\Descript.ion 2014-01-17 19:20 - 2013-01-11 21:13 - 00001284 _____ () C:\Program Files\ReadMe.txt 2014-01-17 19:20 - 2010-11-26 19:23 - 00001233 _____ () C:\Program Files\RarFiles.lst 2014-01-17 19:20 - 2010-11-25 14:15 - 00003266 _____ () C:\Program Files\Order.htm 2014-01-17 19:19 - 2013-10-23 12:29 - 00044936 _____ (Microsoft Corporation) C:\Windows\system32\wldp.dll 2014-01-17 19:19 - 2013-10-23 12:21 - 00155480 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-17 19:19 - 2013-10-23 12:13 - 00171864 _____ (Microsoft Corporation) C:\Windows\system32\kd_02_8086.dll 2014-01-17 19:19 - 2013-10-22 09:18 - 00096088 _____ (Microsoft Corporation) C:\Windows\system32\embeddedapplauncher.exe 2014-01-17 19:19 - 2013-10-22 06:15 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2014-01-17 19:19 - 2013-10-22 05:04 - 00618496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll 2014-01-17 19:19 - 2013-10-22 05:02 - 01036288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-01-17 19:19 - 2013-10-22 04:56 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\WorkFoldersShell.dll 2014-01-17 19:19 - 2013-10-22 04:44 - 00761856 _____ (Microsoft Corporation) C:\Windows\system32\WorkfoldersControl.dll 2014-01-17 19:19 - 2013-10-22 03:38 - 01362944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2014-01-17 19:19 - 2013-10-22 03:22 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2014-01-17 19:19 - 2013-10-22 03:13 - 01704448 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-01-17 19:19 - 2013-10-19 05:48 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll 2014-01-17 19:19 - 2013-10-19 05:03 - 00531968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll 2014-01-17 19:19 - 2013-10-17 16:42 - 01373872 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2014-01-17 19:19 - 2013-10-17 15:04 - 01204968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll 2014-01-17 19:19 - 2013-10-16 10:34 - 00518656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe 2014-01-17 19:19 - 2013-10-16 10:33 - 00631296 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe 2014-01-17 19:19 - 2013-10-13 04:06 - 00258904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys 2014-01-17 19:19 - 2013-10-13 03:43 - 00708616 _____ (Microsoft Corporation) C:\Windows\system32\iuilp.dll 2014-01-17 19:19 - 2013-10-10 17:44 - 00031064 _____ (Microsoft Corporation) C:\Windows\system32\ploptin.dll 2014-01-17 19:19 - 2013-10-10 17:26 - 00317616 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2014-01-17 19:19 - 2013-10-10 17:26 - 00104320 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll 2014-01-17 19:19 - 2013-10-10 15:53 - 00235960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2014-01-17 19:19 - 2013-10-10 15:53 - 00088272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll 2014-01-17 19:19 - 2013-10-10 12:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2014-01-17 19:19 - 2013-10-09 06:40 - 00385528 _____ () C:\Windows\system32\ApnDatabase.xml 2014-01-17 19:19 - 2013-10-08 11:28 - 00523096 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys 2014-01-17 19:19 - 2013-10-08 07:46 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll 2014-01-17 19:19 - 2013-10-08 06:58 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shsetup.dll 2014-01-17 19:19 - 2013-10-08 06:50 - 00656384 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2014-01-17 19:19 - 2013-10-08 06:48 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2014-01-17 19:19 - 2013-10-08 06:15 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2014-01-17 19:19 - 2013-10-08 05:50 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2014-01-17 19:19 - 2013-10-08 05:50 - 00762368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Http.dll 2014-01-17 19:19 - 2013-10-07 08:21 - 00054776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-01-17 19:19 - 2013-10-05 16:25 - 00057176 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys 2014-01-17 19:19 - 2013-10-05 13:05 - 00578952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2014-01-17 19:19 - 2013-10-05 12:01 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2014-01-17 19:19 - 2013-10-05 10:36 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-01-17 19:19 - 2013-10-05 10:18 - 01011712 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-01-17 19:19 - 2013-10-05 10:07 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2014-01-17 19:19 - 2013-10-05 09:55 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\miutils.dll 2014-01-17 19:19 - 2013-10-05 09:40 - 00795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-01-17 19:19 - 2013-10-05 09:24 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\miutils.dll 2014-01-17 19:19 - 2013-10-05 09:15 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\pcsvDevice.dll 2014-01-17 19:19 - 2013-10-05 08:35 - 00411648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2014-01-17 19:19 - 2013-10-04 09:10 - 00533504 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll 2014-01-17 19:19 - 2013-09-19 06:04 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll 2014-01-17 19:19 - 2013-09-17 10:06 - 00465960 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-01-17 19:19 - 2013-09-17 08:01 - 00270848 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2014-01-17 19:19 - 2013-09-17 07:31 - 00326024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2014-01-17 19:19 - 2013-09-17 05:37 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\dafBth.dll 2014-01-17 19:19 - 2013-09-14 15:00 - 00391512 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll 2014-01-17 19:19 - 2013-09-14 13:39 - 01799944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll 2014-01-17 19:19 - 2013-09-14 13:33 - 00345552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll 2014-01-17 19:19 - 2013-09-14 11:05 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe 2014-01-17 19:19 - 2013-09-14 10:11 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\ipnathlp.dll 2014-01-17 19:19 - 2013-09-13 09:22 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe 2014-01-17 19:19 - 2013-09-13 08:47 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ftp.exe 2014-01-17 19:19 - 2013-09-12 09:45 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll 2014-01-17 19:19 - 2013-09-12 09:08 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll 2014-01-17 19:19 - 2013-09-12 09:08 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\WiFiDisplay.dll 2014-01-17 19:19 - 2013-09-12 09:02 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll 2014-01-17 19:19 - 2013-09-12 08:44 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll 2014-01-17 19:19 - 2013-09-12 08:37 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll 2014-01-17 19:19 - 2013-09-12 08:37 - 00184832 _____ (Microsoft Corporation) C:\Windows\system32\dafWfdProvider.dll 2014-01-17 19:19 - 2013-09-12 08:21 - 00262144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll 2014-01-17 19:19 - 2013-09-12 08:16 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll 2014-01-17 19:19 - 2013-09-12 08:01 - 00272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll 2014-01-17 19:19 - 2013-09-10 05:52 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\msched.dll 2014-01-17 19:19 - 2013-09-10 05:34 - 03934208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-01-17 19:18 - 2013-11-11 03:48 - 00039768 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\intelpep.sys 2014-01-17 19:18 - 2013-11-09 07:37 - 01756160 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe 2014-01-17 19:18 - 2013-11-08 11:26 - 00358896 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll 2014-01-17 19:18 - 2013-11-08 05:43 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll 2014-01-17 19:18 - 2013-11-08 05:28 - 13177344 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-01-17 19:18 - 2013-11-08 05:26 - 11674624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-01-17 19:18 - 2013-11-08 05:16 - 00225792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll 2014-01-17 19:18 - 2013-11-08 05:15 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2014-01-17 19:18 - 2013-11-08 04:41 - 01302528 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2014-01-17 19:18 - 2013-11-05 21:21 - 21196664 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-01-17 19:18 - 2013-11-05 19:51 - 18642504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-01-17 19:18 - 2013-11-05 17:20 - 13925888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2014-01-17 19:18 - 2013-11-05 17:11 - 18577408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2014-01-17 19:18 - 2013-11-05 15:03 - 00637952 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe 2014-01-17 19:18 - 2013-11-05 14:57 - 00479744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe 2014-01-17 19:18 - 2013-11-05 14:32 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll 2014-01-17 19:18 - 2013-11-04 18:13 - 01530200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-01-17 19:18 - 2013-11-04 18:13 - 00382808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2014-01-17 19:18 - 2013-11-04 12:50 - 02143744 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2014-01-17 19:18 - 2013-11-04 11:32 - 02570240 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll 2014-01-17 19:18 - 2013-11-04 02:30 - 01765376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2014-01-17 19:18 - 2013-11-01 07:08 - 00747008 _____ (Microsoft Corporation) C:\Windows\system32\wlidcli.dll 2014-01-17 19:18 - 2013-10-31 01:58 - 00372568 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys 2014-01-17 19:18 - 2013-10-31 01:42 - 07399256 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-01-17 19:18 - 2013-10-31 01:33 - 01345536 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2014-01-17 19:18 - 2013-10-17 12:21 - 02896896 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2014-01-17 19:18 - 2013-10-10 12:53 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll 2014-01-17 19:18 - 2013-10-10 12:26 - 02801664 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2014-01-17 19:18 - 2013-10-10 12:21 - 00139776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll 2014-01-17 19:18 - 2013-10-10 12:05 - 01019392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2014-01-17 19:18 - 2013-10-10 11:34 - 01085952 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll 2014-01-17 19:18 - 2013-10-10 11:27 - 00869888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll 2014-01-17 19:18 - 2013-10-05 15:21 - 02140888 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2014-01-17 19:18 - 2013-10-05 15:21 - 00516496 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-01-17 19:18 - 2013-10-05 13:05 - 01765384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2014-01-17 19:18 - 2013-10-05 13:05 - 00406400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2014-01-17 19:17 - 2013-11-09 12:55 - 00325464 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2014-01-17 19:17 - 2013-11-09 06:56 - 01391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPDMC.exe 2014-01-17 19:17 - 2013-11-08 06:23 - 00449024 _____ (Microsoft Corporation) C:\Windows\system32\appmgr.dll 2014-01-17 19:17 - 2013-11-08 05:42 - 00366080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appmgr.dll 2014-01-17 19:17 - 2013-11-08 05:07 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll 2014-01-17 19:17 - 2013-11-08 04:14 - 00922624 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll 2014-01-17 19:17 - 2013-11-05 15:19 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll 2014-01-17 19:17 - 2013-11-05 14:33 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll 2014-01-17 19:17 - 2013-11-04 14:07 - 01843712 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll 2014-01-17 19:17 - 2013-11-04 03:28 - 01816576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Display.dll 2014-01-17 19:17 - 2013-11-01 12:39 - 00086872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys 2014-01-17 19:17 - 2013-11-01 06:57 - 00544768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcli.dll 2014-01-17 19:17 - 2013-10-31 01:33 - 01642016 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2014-01-17 19:17 - 2013-10-31 01:33 - 01506680 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2014-01-17 19:17 - 2013-10-31 01:33 - 01476184 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2014-01-17 19:17 - 2013-10-26 02:54 - 00146776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\SerCx2.sys 2014-01-17 19:17 - 2013-10-24 10:31 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\CredentialMigrationHandler.dll 2014-01-17 19:17 - 2013-10-24 10:12 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredentialMigrationHandler.dll 2014-01-17 19:17 - 2013-10-17 11:36 - 02266624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2014-01-17 19:15 - 2014-01-19 08:38 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-01-17 19:15 - 2013-12-09 01:15 - 00787968 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll 2014-01-17 19:15 - 2013-11-27 16:36 - 03395920 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll 2014-01-17 19:15 - 2013-11-27 12:41 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\WSCollect.exe 2014-01-17 19:15 - 2013-11-27 11:34 - 00138240 _____ () C:\Windows\system32\OEMLicense.dll 2014-01-17 19:15 - 2013-11-27 10:54 - 00103936 _____ () C:\Windows\SysWOW64\OEMLicense.dll 2014-01-17 19:15 - 2013-11-27 09:48 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-17 19:15 - 2013-11-27 09:45 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll 2014-01-17 19:15 - 2013-11-27 09:40 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-17 19:15 - 2013-11-27 09:38 - 00174592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll 2014-01-17 19:15 - 2013-11-27 09:17 - 00695808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-01-17 19:15 - 2013-11-27 09:12 - 00848384 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-01-17 19:15 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-17 19:15 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-17 19:15 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-17 19:15 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-17 19:15 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-17 19:15 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-17 19:15 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-01-17 19:15 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-17 19:15 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-17 19:15 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-01-17 19:15 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-17 19:15 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-17 19:15 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-17 19:15 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-17 19:15 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-01-17 19:15 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-17 19:15 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-01-17 19:15 - 2013-11-23 05:34 - 00393216 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-01-17 19:15 - 2013-11-23 05:13 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-01-17 19:15 - 2013-11-23 04:32 - 04105728 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll 2014-01-17 19:15 - 2013-11-23 04:10 - 00568832 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe 2014-01-17 19:15 - 2013-11-09 07:34 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe 2014-01-17 19:15 - 2013-11-09 07:34 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\mdmregistration.dll 2014-01-17 19:15 - 2013-11-09 06:52 - 00240128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mdmregistration.dll 2014-01-17 19:15 - 2013-11-08 08:21 - 04191744 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-17 19:15 - 2013-10-23 12:01 - 00872840 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2014-01-17 19:15 - 2013-10-23 09:59 - 00698232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2014-01-17 19:15 - 2013-10-19 09:53 - 00075360 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-01-17 19:15 - 2013-10-19 08:14 - 00070680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2014-01-17 19:15 - 2013-10-19 06:37 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-17 19:15 - 2013-10-16 16:58 - 01943536 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2014-01-17 19:15 - 2013-10-16 14:54 - 01581968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2014-01-17 19:15 - 2013-10-15 09:54 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-01-17 19:15 - 2013-10-15 09:03 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2014-01-17 19:15 - 2013-10-13 03:48 - 00136536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys 2014-01-17 19:15 - 2013-10-12 22:48 - 00828416 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL 2014-01-17 19:15 - 2013-10-12 22:34 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2014-01-17 19:15 - 2013-10-11 14:24 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2014-01-17 19:15 - 2013-10-11 14:03 - 00621056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll 2014-01-17 19:15 - 2013-10-05 15:21 - 01341288 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-01-17 19:15 - 2013-10-05 09:39 - 01067008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-01-17 19:15 - 2013-10-03 10:16 - 00294400 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll 2014-01-17 19:15 - 2013-10-03 10:02 - 00225792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll 2014-01-17 19:15 - 2013-10-02 12:00 - 01286552 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2014-01-17 19:15 - 2013-10-02 10:47 - 01018960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2014-01-17 19:15 - 2013-10-01 04:42 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll 2014-01-17 19:15 - 2013-10-01 04:36 - 00977408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll 2014-01-16 16:14 - 2014-01-16 16:14 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader 2014-01-16 16:12 - 2014-01-31 19:06 - 00000000 ____D () C:\Users\Kevin\AppData\Local\JDownloader v2.0 2014-01-16 09:34 - 2014-01-16 09:34 - 00723841 _____ () C:\Windows\system32\atiicdxx.dat 2014-01-16 01:13 - 2014-01-16 01:13 - 00184968 _____ (<Turtle Entertainment>) C:\Windows\system32\Drivers\ESLWireACD.sys 2014-01-16 01:02 - 2014-02-04 04:08 - 00000000 ____D () C:\Users\Kevin\AppData\Local\ESL Wire Game Client 2014-01-16 01:02 - 2014-01-16 01:02 - 00000000 ____D () C:\ProgramData\ESL Wire 2014-01-16 00:19 - 2014-01-16 00:19 - 00000000 ____D () C:\Users\Kevin\AppData\Local\PunkBuster 2014-01-16 00:18 - 2014-01-16 00:18 - 00000000 ____D () C:\Users\Kevin\AppData\Local\ESN 2014-01-16 00:16 - 2014-02-04 04:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-16 00:16 - 2014-01-16 00:16 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-01-16 00:16 - 2014-01-16 00:16 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Macromedia 2014-01-16 00:15 - 2014-01-16 00:16 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Adobe 2014-01-15 20:48 - 2014-01-15 20:48 - 00000000 ____D () C:\ProgramData\Hewlett-Packard 2014-01-15 18:36 - 2014-02-04 00:48 - 00214392 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-15 18:36 - 2014-02-04 00:48 - 00214392 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-15 18:36 - 2014-01-17 18:28 - 00027522 _____ () C:\Windows\DirectX.log 2014-01-15 18:36 - 2014-01-16 12:55 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-01-15 18:36 - 2014-01-15 18:36 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-15 18:36 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-01-15 18:36 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-01-15 18:36 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-01-15 18:36 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-01-15 18:36 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-01-15 18:36 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-01-15 18:36 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-01-15 18:36 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-01-15 18:36 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2014-01-15 18:36 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2014-01-15 18:36 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-01-15 18:36 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-01-15 18:36 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-01-15 18:36 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2014-01-15 18:36 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-01-15 18:36 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-01-15 18:36 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-01-15 18:36 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2014-01-15 18:36 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2014-01-15 18:36 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-01-15 18:36 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-01-15 18:36 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2014-01-15 18:36 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-01-15 18:36 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2014-01-15 18:36 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-01-15 18:36 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2014-01-15 18:36 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2014-01-15 18:36 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-01-15 18:36 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-01-15 18:36 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-01-15 18:36 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-01-15 18:36 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2014-01-15 18:36 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-01-15 18:36 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-01-15 18:36 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-01-15 18:36 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2014-01-15 18:36 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-01-15 18:36 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-01-15 18:36 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-01-15 18:36 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2014-01-15 18:36 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-01-15 18:36 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-01-15 18:36 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-01-15 18:36 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-01-15 18:36 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-01-15 18:36 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-01-15 18:36 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-01-15 18:36 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-01-15 18:36 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-01-15 18:36 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2014-01-15 18:36 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-01-15 18:36 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2014-01-15 18:36 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-01-15 18:36 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-01-15 18:36 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-01-15 18:36 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-01-15 18:36 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-01-15 18:36 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-01-15 18:36 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-01-15 18:36 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-01-15 18:36 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-01-15 18:36 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-01-15 18:36 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-01-15 18:36 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-01-15 18:36 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-01-15 18:36 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-01-15 18:36 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-01-15 18:36 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-01-15 18:36 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-01-15 18:36 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2014-01-15 18:36 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-01-15 18:36 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2014-01-15 18:36 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-01-15 18:36 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-01-15 18:36 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-01-15 18:36 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-01-15 18:36 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-01-15 18:36 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-01-15 18:36 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-01-15 18:36 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-01-15 18:36 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-01-15 18:36 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-01-15 18:36 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-01-15 18:36 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-01-15 18:36 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-01-15 18:36 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-01-15 18:36 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-01-15 18:36 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-01-15 18:36 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-01-15 18:36 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-01-15 18:36 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-01-15 18:36 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-01-15 18:36 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-01-15 18:36 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-01-15 18:36 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-01-15 18:36 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-01-15 18:36 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-01-15 18:36 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-01-15 18:36 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-01-15 18:36 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-01-15 18:36 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-01-15 18:36 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-01-15 18:36 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-01-15 18:36 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-01-15 18:36 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-01-15 18:36 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-01-15 18:36 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-01-15 18:36 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-01-15 18:36 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-01-15 18:36 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-01-15 18:36 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-01-15 18:36 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-01-15 18:36 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-01-15 18:36 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-01-15 18:36 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-01-15 18:36 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-01-15 18:36 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-01-15 18:36 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-01-15 18:36 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-01-15 18:36 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-01-15 18:36 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-01-15 18:36 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-01-15 18:36 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-01-15 18:36 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-01-15 18:36 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-01-15 18:36 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-01-15 18:36 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-01-15 18:36 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-01-15 18:36 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-01-15 18:36 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-01-15 18:36 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2014-01-15 18:36 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-01-15 18:36 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-01-15 18:36 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-01-15 18:36 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-01-15 18:36 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-01-15 18:36 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-01-15 18:36 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-01-15 18:36 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-01-15 18:36 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-01-15 18:36 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-01-15 18:36 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-01-15 18:36 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-01-15 18:36 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-01-15 18:36 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-01-15 18:36 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-01-15 18:36 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-01-15 18:36 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-01-15 18:36 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2014-01-15 18:36 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-01-15 18:36 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-01-15 18:36 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-01-15 18:36 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-01-15 18:36 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-01-15 18:36 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-01-15 18:36 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2014-01-15 18:36 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-01-15 18:36 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-01-15 18:36 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2014-01-15 18:36 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-01-15 18:36 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2014-01-15 18:36 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-01-15 18:36 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2014-01-15 18:36 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-01-15 18:36 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2014-01-15 18:36 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-01-15 18:36 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2014-01-15 18:36 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-01-15 18:36 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2014-01-15 18:36 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-01-15 18:36 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2014-01-15 18:36 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-01-15 18:36 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2014-01-15 18:36 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-01-15 18:36 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2014-01-15 18:36 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-01-15 18:36 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2014-01-15 18:36 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-01-15 18:36 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2014-01-15 18:20 - 2014-02-04 02:27 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\TS3Client 2014-01-15 18:20 - 2014-01-15 18:20 - 00126223 _____ (TeamSpeak Systems GmbH) C:\Program Files (x86)\Uninstall.exe 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\translations 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\styles 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\soundbackends 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\sound 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\pluginsdk 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\plugins 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\news 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\imageformats 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\gfx 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\accessible 2014-01-15 18:17 - 2014-01-15 18:17 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Mozilla 2014-01-15 18:17 - 2014-01-15 18:17 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Mozilla 2014-01-15 18:17 - 2014-01-15 18:17 - 00000000 ____D () C:\ProgramData\Mozilla 2014-01-15 18:17 - 2014-01-15 18:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-15 18:17 - 2014-01-15 18:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-01-15 17:31 - 2014-01-15 17:31 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Google 2014-01-15 17:21 - 2014-01-15 18:31 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Origin 2014-01-15 17:21 - 2014-01-15 17:22 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Origin 2014-01-15 17:20 - 2014-01-31 16:38 - 00000000 ____D () C:\ProgramData\Origin 2014-01-15 17:20 - 2014-01-16 00:18 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-01-15 17:02 - 2014-02-04 11:37 - 00001136 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-15 17:02 - 2014-02-04 03:12 - 00001140 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-15 17:02 - 2014-01-15 17:07 - 00004112 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-01-15 17:02 - 2014-01-15 17:07 - 00003876 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-01-15 17:02 - 2014-01-15 17:03 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\Google 2014-01-15 17:02 - 2014-01-15 17:03 - 00000000 ____D () C:\Program Files (x86)\Google 2014-01-15 16:57 - 2014-01-18 16:15 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Windows\PCHEALTH 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\Microsoft Help 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services 2014-01-15 16:55 - 2014-01-15 16:55 - 00000000 __RHD () C:\MSOCache 2014-01-15 16:51 - 2014-01-15 16:51 - 00000000 ____D () C:\Users\jagod_000\AppData\Roaming\Macromedia 2014-01-15 16:33 - 2014-02-03 18:25 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3231436611-243068960-233781985-1004 2014-01-15 16:28 - 2014-01-15 16:28 - 00000000 ____D () C:\Users\jagod_000\AppData\Roaming\ATI 2014-01-15 16:28 - 2014-01-15 16:28 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\PackageStaging 2014-01-15 16:28 - 2014-01-15 16:28 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\ATI 2014-01-15 16:27 - 2014-01-20 06:39 - 00000000 ___RD () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-15 16:27 - 2014-01-20 06:39 - 00000000 ___RD () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-15 16:27 - 2014-01-20 06:39 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\Packages 2014-01-15 16:27 - 2014-01-15 16:39 - 00000000 ____D () C:\Users\jagod_000 2014-01-15 16:27 - 2014-01-15 16:27 - 00001450 _____ () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-15 16:27 - 2014-01-15 16:27 - 00000020 ___SH () C:\Users\jagod_000\ntuser.ini 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Vorlagen 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Startmenü 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Netzwerkumgebung 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Lokale Einstellungen 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Eigene Dateien 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Druckumgebung 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\AppData\Local\Verlauf 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\AppData\Local\Anwendungsdaten 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Anwendungsdaten 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 ____D () C:\Users\jagod_000\AppData\Roaming\Adobe 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\VirtualStore 2014-01-15 16:27 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-01-15 16:27 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-15 16:27 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-01-15 16:27 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-15 16:21 - 2014-02-02 15:31 - 00000000 ____D () C:\ProgramData\AMD 2014-01-15 16:21 - 2014-01-15 16:21 - 00055617 _____ () C:\Windows\SysWOW64\CCCInstall_201401151621277836.log 2014-01-15 16:21 - 2014-01-15 16:21 - 00054596 _____ () C:\Windows\SysWOW64\CCCInstall_201401151621140481.log 2014-01-15 16:15 - 2014-01-15 16:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2014-01-15 16:15 - 2014-01-15 16:15 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\ATI 2014-01-15 16:15 - 2014-01-15 16:15 - 00000000 ____D () C:\Users\Kevin\AppData\Local\ATI 2014-01-15 15:51 - 2014-01-15 15:51 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Macromedia 2014-01-15 15:35 - 2014-02-04 11:42 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3231436611-243068960-233781985-1001 2014-01-15 15:32 - 2014-02-02 15:26 - 00000000 ____D () C:\ProgramData\Package Cache 2014-01-15 15:32 - 2014-02-02 15:23 - 00000000 ____D () C:\AMD 2014-01-15 15:32 - 2014-01-15 15:32 - 00055441 _____ () C:\Windows\SysWOW64\CCCInstall_201401151532359789.log 2014-01-15 15:32 - 2014-01-15 15:32 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-01-15 15:32 - 2014-01-15 15:32 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies 2014-01-15 15:32 - 2014-01-15 15:32 - 00000000 ____D () C:\Program Files\AMD 2014-01-15 15:32 - 2014-01-15 15:32 - 00000000 _____ () C:\Windows\ativpsrm.bin 2014-01-15 15:29 - 2014-01-18 21:27 - 00000000 ___RD () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-15 15:29 - 2014-01-18 21:27 - 00000000 ___RD () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-15 15:29 - 2014-01-18 21:27 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Packages 2014-01-15 15:29 - 2014-01-15 15:30 - 00000000 ____D () C:\Users\Kevin\AppData\Local\PackageStaging 2014-01-15 15:29 - 2014-01-15 15:29 - 00001450 _____ () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-15 15:29 - 2014-01-15 15:29 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Adobe 2014-01-15 15:29 - 2014-01-15 15:29 - 00000000 ____D () C:\Users\Kevin\AppData\Local\VirtualStore 2014-01-15 15:27 - 2014-02-04 11:50 - 00000000 ____D () C:\Users\Kevin 2014-01-15 15:27 - 2014-01-15 15:27 - 00000020 ___SH () C:\Users\Kevin\ntuser.ini 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Vorlagen 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Startmenü 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Netzwerkumgebung 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Lokale Einstellungen 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Eigene Dateien 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Druckumgebung 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\AppData\Local\Verlauf 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\AppData\Local\Anwendungsdaten 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Anwendungsdaten 2014-01-15 15:27 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-01-15 15:27 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-15 15:27 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-01-15 15:27 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-15 15:25 - 2014-02-04 11:49 - 01446075 _____ () C:\Windows\WindowsUpdate.log 2014-01-15 15:25 - 2014-01-15 15:25 - 00000000 ____D () C:\Windows\CSC 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Programme 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Dokumente und Einstellungen 2014-01-15 15:23 - 2014-01-15 15:29 - 00000000 ____D () C:\Windows\Panther 2014-01-11 00:50 - 2014-01-11 00:50 - 00234676 _____ () C:\Windows\system32\ativvaxy_cik.dat ==================== One Month Modified Files and Folders ======= 2014-02-04 11:53 - 2014-02-04 11:53 - 00000000 ____D () C:\FRST 2014-02-04 11:50 - 2014-02-04 11:50 - 00000000 _____ () C:\Users\Kevin\defogger_reenable 2014-02-04 11:50 - 2014-01-15 15:27 - 00000000 ____D () C:\Users\Kevin 2014-02-04 11:49 - 2014-01-15 15:25 - 01446075 _____ () C:\Windows\WindowsUpdate.log 2014-02-04 11:42 - 2014-01-15 15:35 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3231436611-243068960-233781985-1001 2014-02-04 11:40 - 2013-09-30 05:14 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-04 11:40 - 2013-09-30 04:56 - 00764340 _____ () C:\Windows\system32\perfh007.dat 2014-02-04 11:40 - 2013-09-30 04:56 - 00159160 _____ () C:\Windows\system32\perfc007.dat 2014-02-04 11:37 - 2014-01-15 17:02 - 00001136 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-04 11:36 - 2013-09-29 20:04 - 00004010 _____ () C:\Windows\PFRO.log 2014-02-04 11:36 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-04 04:08 - 2014-01-16 01:02 - 00000000 ____D () C:\Users\Kevin\AppData\Local\ESL Wire Game Client 2014-02-04 04:08 - 2013-08-22 14:25 - 00524288 ___SH () C:\Windows\system32\config\BBI 2014-02-04 04:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2014-02-04 04:01 - 2014-01-16 00:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-04 03:58 - 2014-02-04 03:57 - 00000000 ____D () C:\ProgramData\SpeedyPC Software 2014-02-04 03:57 - 2014-02-04 03:57 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\SpeedyPC Software 2014-02-04 03:57 - 2014-02-04 03:57 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\DriverCure 2014-02-04 03:57 - 2014-02-04 03:57 - 00000000 ____D () C:\Program Files (x86)\Universal Updater 2014-02-04 03:57 - 2014-02-04 03:57 - 00000000 _____ () C:\END 2014-02-04 03:13 - 2013-08-22 15:46 - 00024838 _____ () C:\Windows\setupact.log 2014-02-04 03:12 - 2014-01-15 17:02 - 00001140 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-04 02:27 - 2014-01-15 18:20 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\TS3Client 2014-02-04 00:48 - 2014-01-15 18:36 - 00214392 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-02-04 00:48 - 2014-01-15 18:36 - 00214392 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-02-03 18:25 - 2014-01-15 16:33 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3231436611-243068960-233781985-1004 2014-02-03 07:06 - 2014-01-28 21:40 - 00000000 ____D () C:\Users\Kevin\AppData\Local\PMB Files 2014-02-02 16:28 - 2014-02-02 16:28 - 00000000 ____D () C:\Users\Kevin\AppData\Local\next car game technology sneak peek 2014-02-02 15:31 - 2014-02-02 15:31 - 00055617 _____ () C:\Windows\SysWOW64\CCCInstall_201402021531075772.log 2014-02-02 15:31 - 2014-02-02 15:31 - 00000000 ____D () C:\ProgramData\ATI 2014-02-02 15:31 - 2014-02-02 15:31 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-02-02 15:31 - 2014-02-02 15:30 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-02-02 15:31 - 2014-02-02 15:29 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-02-02 15:31 - 2014-01-15 16:21 - 00000000 ____D () C:\ProgramData\AMD 2014-02-02 15:30 - 2014-02-02 15:30 - 00054596 _____ () C:\Windows\SysWOW64\CCCInstall_201402021530538062.log 2014-02-02 15:30 - 2014-02-02 15:30 - 00000000 ____D () C:\Windows\LastGood 2014-02-02 15:29 - 2014-02-02 15:29 - 00000000 ____D () C:\Program Files\ATI 2014-02-02 15:26 - 2014-02-02 15:26 - 00054772 _____ () C:\Windows\SysWOW64\CCCInstall_201402021526020243.log 2014-02-02 15:26 - 2014-02-02 15:26 - 00049669 _____ () C:\Windows\SysWOW64\CCCInstall_201402021526194660.log 2014-02-02 15:26 - 2014-01-15 15:32 - 00000000 ____D () C:\ProgramData\Package Cache 2014-02-02 15:25 - 2014-02-02 15:25 - 00000000 ____D () C:\Windows\LastGood.Tmp 2014-02-02 15:23 - 2014-01-15 15:32 - 00000000 ____D () C:\AMD 2014-02-02 07:20 - 2014-01-28 21:40 - 00000000 ____D () C:\ProgramData\PMB Files 2014-01-31 22:07 - 2014-01-31 22:07 - 10145128 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00127872 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00117560 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00098496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2014-01-31 22:07 - 2014-01-31 22:07 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2014-01-31 22:07 - 2013-12-13 10:23 - 10171456 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll 2014-01-31 22:07 - 2013-12-13 10:23 - 08760320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2014-01-31 22:07 - 2013-12-13 10:23 - 01328328 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll 2014-01-31 22:07 - 2013-12-13 10:23 - 01106360 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2014-01-31 22:07 - 2013-12-13 10:23 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2014-01-31 22:07 - 2013-12-13 10:23 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2014-01-31 22:07 - 2013-12-13 10:23 - 00116024 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2014-01-31 22:06 - 2014-01-31 22:06 - 06716264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2014-01-31 22:06 - 2013-12-13 10:23 - 10899624 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2014-01-31 22:06 - 2013-12-13 10:23 - 07892000 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2014-01-31 21:57 - 2014-01-31 21:57 - 13929472 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2014-01-31 21:43 - 2014-01-31 21:43 - 00230912 _____ () C:\Windows\system32\clinfo.exe 2014-01-31 21:43 - 2014-01-31 21:43 - 00098816 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2014-01-31 21:43 - 2014-01-31 21:43 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2014-01-31 21:43 - 2014-01-31 21:43 - 00083456 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2014-01-31 21:43 - 2014-01-31 21:43 - 00073216 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2014-01-31 21:42 - 2014-01-31 21:42 - 28424704 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2014-01-31 21:40 - 2014-01-31 21:40 - 23903232 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2014-01-31 21:38 - 2014-01-31 21:38 - 00065024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-01-31 21:38 - 2014-01-31 21:38 - 00058880 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-01-31 21:27 - 2014-01-31 21:27 - 00576040 _____ () C:\Windows\SysWOW64\atiapfxx.blb 2014-01-31 21:27 - 2014-01-31 21:27 - 00576040 _____ () C:\Windows\system32\atiapfxx.blb 2014-01-31 21:26 - 2014-01-31 21:26 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2014-01-31 21:26 - 2014-01-31 21:26 - 00415744 _____ () C:\Windows\system32\amdmiracast.dll 2014-01-31 21:26 - 2014-01-31 21:26 - 00368640 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2014-01-31 21:26 - 2014-01-31 21:26 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2014-01-31 21:26 - 2014-01-31 21:26 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2014-01-31 21:26 - 2014-01-31 21:26 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2014-01-31 21:26 - 2014-01-31 21:26 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2014-01-31 21:24 - 2014-01-31 21:24 - 00126464 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll 2014-01-31 21:24 - 2014-01-31 21:24 - 00113152 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll 2014-01-31 21:23 - 2014-01-31 21:23 - 05350400 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll 2014-01-31 21:22 - 2014-01-31 21:22 - 27152384 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2014-01-31 21:22 - 2014-01-31 21:22 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2014-01-31 21:10 - 2014-01-31 21:10 - 04286976 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll 2014-01-31 21:06 - 2014-01-31 21:06 - 00586240 _____ (AMD) C:\Windows\system32\atieclxx.exe 2014-01-31 21:06 - 2014-01-31 21:06 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2014-01-31 21:06 - 2013-12-13 10:23 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2014-01-31 21:05 - 2014-01-31 21:05 - 00240128 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2014-01-31 21:03 - 2014-01-31 21:03 - 22834688 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2014-01-31 21:03 - 2014-01-31 21:03 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2014-01-31 20:59 - 2014-01-31 20:59 - 00081920 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll 2014-01-31 20:59 - 2014-01-31 20:59 - 00079360 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll 2014-01-31 20:48 - 2014-01-31 20:48 - 00044544 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll 2014-01-31 20:47 - 2014-01-31 20:47 - 00035840 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll 2014-01-31 20:43 - 2014-01-31 20:43 - 03434288 _____ () C:\Windows\system32\atiumd6a.cap 2014-01-31 20:37 - 2014-01-31 20:37 - 00806912 _____ (AMD) C:\Windows\system32\coinst_13.350.dll 2014-01-31 20:32 - 2014-01-31 20:32 - 03468336 _____ () C:\Windows\SysWOW64\atiumdva.cap 2014-01-31 20:30 - 2014-01-31 20:30 - 00828416 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2014-01-31 20:30 - 2013-12-13 10:23 - 01148416 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2014-01-31 20:29 - 2014-01-31 20:29 - 00146432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2014-01-31 20:29 - 2014-01-31 20:29 - 00133120 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2014-01-31 20:29 - 2014-01-31 20:29 - 00075264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2014-01-31 20:29 - 2014-01-31 20:29 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2014-01-31 20:29 - 2014-01-31 20:29 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2014-01-31 20:28 - 2014-01-31 20:28 - 00636928 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2014-01-31 20:25 - 2014-01-31 20:25 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2014-01-31 20:23 - 2014-01-31 20:23 - 00095744 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll 2014-01-31 20:23 - 2014-01-31 20:23 - 00090112 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll 2014-01-31 20:23 - 2014-01-31 20:23 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll 2014-01-31 20:23 - 2014-01-31 20:23 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll 2014-01-31 20:20 - 2014-01-31 20:20 - 00134144 _____ () C:\Windows\system32\amdhdl64.dll 2014-01-31 20:20 - 2014-01-31 20:20 - 00123392 _____ () C:\Windows\SysWOW64\amdhdl32.dll 2014-01-31 19:06 - 2014-01-16 16:12 - 00000000 ____D () C:\Users\Kevin\AppData\Local\JDownloader v2.0 2014-01-31 16:38 - 2014-01-15 17:20 - 00000000 ____D () C:\ProgramData\Origin 2014-01-31 15:53 - 2014-01-31 15:53 - 00051200 _____ () C:\Windows\system32\kdbsdk64.dll 2014-01-31 15:49 - 2014-01-31 15:49 - 00038912 _____ () C:\Windows\SysWOW64\kdbsdk32.dll 2014-01-31 09:43 - 2014-01-31 09:43 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\MPC-HC 2014-01-29 09:43 - 2014-01-29 09:43 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\LolClient 2014-01-28 21:40 - 2014-01-28 21:40 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-01-28 21:40 - 2014-01-28 21:40 - 00000000 ____D () C:\Program Files (x86)\Pando Networks 2014-01-28 21:40 - 2014-01-28 21:39 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Riot Games 2014-01-20 18:08 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2014-01-20 06:39 - 2014-01-15 16:27 - 00000000 ___RD () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-20 06:39 - 2014-01-15 16:27 - 00000000 ___RD () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-20 06:39 - 2014-01-15 16:27 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\Packages 2014-01-19 14:12 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache 2014-01-19 08:38 - 2014-01-17 19:15 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-01-18 21:27 - 2014-01-18 21:27 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-01-18 21:27 - 2014-01-18 21:02 - 00000000 ___RD () C:\Windows\BrowserChoice 2014-01-18 21:27 - 2014-01-15 15:29 - 00000000 ___RD () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-18 21:27 - 2014-01-15 15:29 - 00000000 ___RD () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-18 21:27 - 2014-01-15 15:29 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Packages 2014-01-18 21:26 - 2013-08-22 15:44 - 00409192 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-18 21:02 - 2014-01-18 21:02 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer 2014-01-18 21:02 - 2014-01-18 21:02 - 00000000 ____D () C:\Program Files\Reference Assemblies 2014-01-18 21:02 - 2014-01-18 21:02 - 00000000 ____D () C:\Program Files\MSBuild 2014-01-18 21:02 - 2014-01-18 21:02 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies 2014-01-18 21:02 - 2014-01-18 21:02 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2014-01-18 21:02 - 2013-08-22 16:36 - 00000000 ___RD () C:\Windows\ToastData 2014-01-18 21:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\WinStore 2014-01-18 21:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\SysWOW64\MUI 2014-01-18 21:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\MUI 2014-01-18 21:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\migwiz 2014-01-18 21:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-01-18 21:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\MediaViewer 2014-01-18 21:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\FileManager 2014-01-18 21:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Camera 2014-01-18 16:15 - 2014-01-15 16:57 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-01-18 16:13 - 2014-01-18 16:13 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help 2014-01-18 16:13 - 2014-01-18 16:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help 2014-01-18 16:12 - 2014-01-18 16:11 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-18 16:12 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-01-17 19:20 - 2014-01-17 19:20 - 00000022 _____ () C:\Program Files\zipnew.dat 2014-01-17 19:20 - 2014-01-17 19:20 - 00000020 _____ () C:\Program Files\rarnew.dat 2014-01-17 19:20 - 2014-01-17 19:20 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\WinRAR 2014-01-17 19:20 - 2014-01-17 19:20 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-01-17 18:28 - 2014-01-15 18:36 - 00027522 _____ () C:\Windows\DirectX.log 2014-01-16 16:14 - 2014-01-16 16:14 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader 2014-01-16 12:55 - 2014-01-15 18:36 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-01-16 09:34 - 2014-01-16 09:34 - 00723841 _____ () C:\Windows\system32\atiicdxx.dat 2014-01-16 01:13 - 2014-01-16 01:13 - 00184968 _____ (<Turtle Entertainment>) C:\Windows\system32\Drivers\ESLWireACD.sys 2014-01-16 01:02 - 2014-01-16 01:02 - 00000000 ____D () C:\ProgramData\ESL Wire 2014-01-16 00:19 - 2014-01-16 00:19 - 00000000 ____D () C:\Users\Kevin\AppData\Local\PunkBuster 2014-01-16 00:18 - 2014-01-16 00:18 - 00000000 ____D () C:\Users\Kevin\AppData\Local\ESN 2014-01-16 00:18 - 2014-01-15 17:20 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-01-16 00:16 - 2014-01-16 00:16 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-01-16 00:16 - 2014-01-16 00:16 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Macromedia 2014-01-16 00:16 - 2014-01-16 00:15 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Adobe 2014-01-15 20:48 - 2014-01-15 20:48 - 00000000 ____D () C:\ProgramData\Hewlett-Packard 2014-01-15 18:36 - 2014-01-15 18:36 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-15 18:31 - 2014-01-15 17:21 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Origin 2014-01-15 18:27 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-01-15 18:20 - 2014-01-15 18:20 - 00126223 _____ (TeamSpeak Systems GmbH) C:\Program Files (x86)\Uninstall.exe 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\translations 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\styles 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\soundbackends 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\sound 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\pluginsdk 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\plugins 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\news 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\imageformats 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\gfx 2014-01-15 18:20 - 2014-01-15 18:20 - 00000000 ____D () C:\Program Files (x86)\accessible 2014-01-15 18:17 - 2014-01-15 18:17 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Mozilla 2014-01-15 18:17 - 2014-01-15 18:17 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Mozilla 2014-01-15 18:17 - 2014-01-15 18:17 - 00000000 ____D () C:\ProgramData\Mozilla 2014-01-15 18:17 - 2014-01-15 18:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-15 18:17 - 2014-01-15 18:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-01-15 17:31 - 2014-01-15 17:31 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Google 2014-01-15 17:22 - 2014-01-15 17:21 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Origin 2014-01-15 17:07 - 2014-01-15 17:02 - 00004112 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-01-15 17:07 - 2014-01-15 17:02 - 00003876 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-01-15 17:03 - 2014-01-15 17:02 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\Google 2014-01-15 17:03 - 2014-01-15 17:02 - 00000000 ____D () C:\Program Files (x86)\Google 2014-01-15 16:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\System 2014-01-15 16:58 - 2013-08-22 14:25 - 00000167 _____ () C:\Windows\win.ini 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Windows\PCHEALTH 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\Microsoft Help 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-01-15 16:57 - 2014-01-15 16:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services 2014-01-15 16:57 - 2013-09-30 04:59 - 00000000 ____D () C:\Windows\ShellNew 2014-01-15 16:55 - 2014-01-15 16:55 - 00000000 __RHD () C:\MSOCache 2014-01-15 16:51 - 2014-01-15 16:51 - 00000000 ____D () C:\Users\jagod_000\AppData\Roaming\Macromedia 2014-01-15 16:39 - 2014-01-15 16:27 - 00000000 ____D () C:\Users\jagod_000 2014-01-15 16:28 - 2014-01-15 16:28 - 00000000 ____D () C:\Users\jagod_000\AppData\Roaming\ATI 2014-01-15 16:28 - 2014-01-15 16:28 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\PackageStaging 2014-01-15 16:28 - 2014-01-15 16:28 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\ATI 2014-01-15 16:27 - 2014-01-15 16:27 - 00001450 _____ () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-15 16:27 - 2014-01-15 16:27 - 00000020 ___SH () C:\Users\jagod_000\ntuser.ini 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Vorlagen 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Startmenü 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Netzwerkumgebung 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Lokale Einstellungen 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Eigene Dateien 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Druckumgebung 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\AppData\Local\Verlauf 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\AppData\Local\Anwendungsdaten 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 _SHDL () C:\Users\jagod_000\Anwendungsdaten 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 ____D () C:\Users\jagod_000\AppData\Roaming\Adobe 2014-01-15 16:27 - 2014-01-15 16:27 - 00000000 ____D () C:\Users\jagod_000\AppData\Local\VirtualStore 2014-01-15 16:21 - 2014-01-15 16:21 - 00055617 _____ () C:\Windows\SysWOW64\CCCInstall_201401151621277836.log 2014-01-15 16:21 - 2014-01-15 16:21 - 00054596 _____ () C:\Windows\SysWOW64\CCCInstall_201401151621140481.log 2014-01-15 16:15 - 2014-01-15 16:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2014-01-15 16:15 - 2014-01-15 16:15 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\ATI 2014-01-15 16:15 - 2014-01-15 16:15 - 00000000 ____D () C:\Users\Kevin\AppData\Local\ATI 2014-01-15 15:51 - 2014-01-15 15:51 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Macromedia 2014-01-15 15:32 - 2014-01-15 15:32 - 00055441 _____ () C:\Windows\SysWOW64\CCCInstall_201401151532359789.log 2014-01-15 15:32 - 2014-01-15 15:32 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-01-15 15:32 - 2014-01-15 15:32 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies 2014-01-15 15:32 - 2014-01-15 15:32 - 00000000 ____D () C:\Program Files\AMD 2014-01-15 15:32 - 2014-01-15 15:32 - 00000000 _____ () C:\Windows\ativpsrm.bin 2014-01-15 15:30 - 2014-01-15 15:29 - 00000000 ____D () C:\Users\Kevin\AppData\Local\PackageStaging 2014-01-15 15:29 - 2014-01-15 15:29 - 00001450 _____ () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-15 15:29 - 2014-01-15 15:29 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Adobe 2014-01-15 15:29 - 2014-01-15 15:29 - 00000000 ____D () C:\Users\Kevin\AppData\Local\VirtualStore 2014-01-15 15:29 - 2014-01-15 15:23 - 00000000 ____D () C:\Windows\Panther 2014-01-15 15:27 - 2014-01-15 15:27 - 00000020 ___SH () C:\Users\Kevin\ntuser.ini 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Vorlagen 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Startmenü 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Netzwerkumgebung 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Lokale Einstellungen 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Eigene Dateien 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Druckumgebung 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\AppData\Local\Verlauf 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\AppData\Local\Anwendungsdaten 2014-01-15 15:27 - 2014-01-15 15:27 - 00000000 _SHDL () C:\Users\Kevin\Anwendungsdaten 2014-01-15 15:25 - 2014-01-15 15:25 - 00000000 ____D () C:\Windows\CSC 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Programme 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2014-01-15 15:24 - 2014-01-15 15:24 - 00000000 _SHDL () C:\Dokumente und Einstellungen 2014-01-15 15:24 - 2013-08-22 16:37 - 00002664 _____ () C:\Windows\DtcInstall.log 2014-01-15 15:24 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\Recovery 2014-01-15 15:24 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows NT 2014-01-15 15:24 - 2013-08-22 14:36 - 00000000 __RHD () C:\Users\Default 2014-01-15 15:22 - 2013-08-22 16:36 - 00262144 _____ () C:\Windows\system32\config\BCD-Template 2014-01-11 00:50 - 2014-01-11 00:50 - 00234676 _____ () C:\Windows\system32\ativvaxy_cik.dat 2014-01-06 23:31 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-06 23:31 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-06 16:20 - 2014-01-18 16:11 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\Kevin\AppData\Local\Temp\bitool.dll C:\Users\Kevin\AppData\Local\Temp\EslWireSetup-1.17.3.7769-x64.exe C:\Users\Kevin\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Kevin\AppData\Local\Temp\hd_streamer_install_new.exe C:\Users\Kevin\AppData\Local\Temp\LiveSupport_setup.exe C:\Users\Kevin\AppData\Local\Temp\nse3401.exe C:\Users\Kevin\AppData\Local\Temp\nsf1F2B.exe C:\Users\Kevin\AppData\Local\Temp\nsk6DF4.exe C:\Users\Kevin\AppData\Local\Temp\nsm2170.exe C:\Users\Kevin\AppData\Local\Temp\nsq2055.exe C:\Users\Kevin\AppData\Local\Temp\nst32D7.exe C:\Users\Kevin\AppData\Local\Temp\nsx31BC.exe C:\Users\Kevin\AppData\Local\Temp\OptimizerPro.exe C:\Users\Kevin\AppData\Local\Temp\proxy_vole5781912420039153741.dll C:\Users\Kevin\AppData\Local\Temp\sonarinst.exe C:\Users\Kevin\AppData\Local\Temp\SSStub_Somo_SpeedyPC.exe C:\Users\Kevin\AppData\Local\Temp\swt-win32-3349.dll C:\Users\Kevin\AppData\Local\Temp\Uninstall.exe C:\Users\Kevin\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-29 19:51 ==================== End Of Log ============================ Geändert von emery (04.02.2014 um 12:23 Uhr) |
04.02.2014, 12:12 | #2 |
| Conduit Search Befall, Pop-Ups und Werbung Addition:
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-02-2014 Ran by Kevin at 2014-02-04 11:53:38 Running from E:\Benutzer\Kevin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.43 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 13.30.100.40131 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2014.0131.1535.27922 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Battlefield 4™ (x32 Version: 1.0.0.1 - Electronic Arts) Battlelog Web Plugins (x32 Version: 2.3.2 - EA Digital Illusions CE AB) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2014.0131.1535.27922 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2014.0131.1535.27922 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2014.0131.1535.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2014.0131.1534.27922 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2014.0131.1535.27922 - Advanced Micro Devices, Inc.) Hidden Counter-Strike: Source (x32 Version: - Valve) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (Version: - Microsoft) ESL Wire 1.17.3 (Version: - Turtle Entertainment GmbH) ESN Sonar (x32 Version: 0.70.4 - ESN Social Software AB) F1 2013 (x32 Version: 1.0 - Codemasters) Google Chrome (x32 Version: 32.0.1700.102 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden HydraVision (x32 Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden JDownloader 2 (Version: 2.0 - AppWork GmbH) League of Legends (x32 Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (x32 Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (x32 Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MPC-HC 1.7.2 (64-bit) (Version: 1.7.2 - MPC-HC Team) Origin (x32 Version: 9.3.11.2762 - Electronic Arts, Inc.) Pando Media Booster (x32 Version: 2.6.0.7 - Pando Networks Inc.) PunkBuster Services (x32 Version: 0.993 - Even Balance, Inc.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden Steam (x32 Version: - Valve Corporation) TeamSpeak 3 Client (HKCU Version: 3.0.13 - TeamSpeak Systems GmbH) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2553092) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition (Version: - Microsoft) WinRAR 5.01 (64-bit) (Version: 5.01.0 - win.rar GmbH) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {8CF3BFAA-6948-4E9C-B065-A5E6A2A7CF3B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-01-06] (Microsoft Corporation) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {AA693B90-5B5D-43B4-8EEC-ABA2E89811DD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-15] (Google Inc.) Task: {C0B89AA9-32CA-4434-869B-67BAA671B23B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-15] (Google Inc.) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {FCA195EE-54CF-44C7-A2E2-CFDEE8A1F5A5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-16] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-15 18:17 - 2013-12-05 20:36 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: PCI-Kommunikationscontroller (einfach) Description: PCI-Kommunikationscontroller (einfach) Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: SM-Bus-Controller Description: SM-Bus-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (02/04/2014 11:47:32 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: rpcs3-x64_0.0.0.4.exe, Version: 0.0.0.0, Zeitstempel: 0x521cc7de Name des fehlerhaften Moduls: rpcs3-x64_0.0.0.4.exe, Version: 0.0.0.0, Zeitstempel: 0x521cc7de Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000180352 ID des fehlerhaften Prozesses: 0xdfc Startzeit der fehlerhaften Anwendung: 0xrpcs3-x64_0.0.0.4.exe0 Pfad der fehlerhaften Anwendung: rpcs3-x64_0.0.0.4.exe1 Pfad des fehlerhaften Moduls: rpcs3-x64_0.0.0.4.exe2 Berichtskennung: rpcs3-x64_0.0.0.4.exe3 Vollständiger Name des fehlerhaften Pakets: rpcs3-x64_0.0.0.4.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rpcs3-x64_0.0.0.4.exe5 Error: (02/04/2014 01:14:32 AM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (02/02/2014 04:42:52 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Next Car Game Technology Sneak Peek.exe, Version: 0.0.0.0, Zeitstempel: 0x528f4f34 Name des fehlerhaften Moduls: Next Car Game Technology Sneak Peek.exe, Version: 0.0.0.0, Zeitstempel: 0x528f4f34 Ausnahmecode: 0xc000041d Fehleroffset: 0x00204c2a ID des fehlerhaften Prozesses: 0x1154 Startzeit der fehlerhaften Anwendung: 0xNext Car Game Technology Sneak Peek.exe0 Pfad der fehlerhaften Anwendung: Next Car Game Technology Sneak Peek.exe1 Pfad des fehlerhaften Moduls: Next Car Game Technology Sneak Peek.exe2 Berichtskennung: Next Car Game Technology Sneak Peek.exe3 Vollständiger Name des fehlerhaften Pakets: Next Car Game Technology Sneak Peek.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Next Car Game Technology Sneak Peek.exe5 Error: (02/02/2014 04:42:47 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Next Car Game Technology Sneak Peek.exe, Version: 0.0.0.0, Zeitstempel: 0x528f4f34 Name des fehlerhaften Moduls: Next Car Game Technology Sneak Peek.exe, Version: 0.0.0.0, Zeitstempel: 0x528f4f34 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00204c2a ID des fehlerhaften Prozesses: 0x1154 Startzeit der fehlerhaften Anwendung: 0xNext Car Game Technology Sneak Peek.exe0 Pfad der fehlerhaften Anwendung: Next Car Game Technology Sneak Peek.exe1 Pfad des fehlerhaften Moduls: Next Car Game Technology Sneak Peek.exe2 Berichtskennung: Next Car Game Technology Sneak Peek.exe3 Vollständiger Name des fehlerhaften Pakets: Next Car Game Technology Sneak Peek.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Next Car Game Technology Sneak Peek.exe5 Error: (02/02/2014 03:25:41 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (02/01/2014 06:37:41 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: bf4.exe, Version: 1.1.0.0, Zeitstempel: 0x52e6656f Name des fehlerhaften Moduls: bf4.exe, Version: 1.1.0.0, Zeitstempel: 0x52e6656f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004a1045 ID des fehlerhaften Prozesses: 0x84c Startzeit der fehlerhaften Anwendung: 0xbf4.exe0 Pfad der fehlerhaften Anwendung: bf4.exe1 Pfad des fehlerhaften Moduls: bf4.exe2 Berichtskennung: bf4.exe3 Vollständiger Name des fehlerhaften Pakets: bf4.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: bf4.exe5 Error: (02/01/2014 05:57:33 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: bf4.exe, Version: 1.1.0.0, Zeitstempel: 0x52e6656f Name des fehlerhaften Moduls: bf4.exe, Version: 1.1.0.0, Zeitstempel: 0x52e6656f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004a1045 ID des fehlerhaften Prozesses: 0x900 Startzeit der fehlerhaften Anwendung: 0xbf4.exe0 Pfad der fehlerhaften Anwendung: bf4.exe1 Pfad des fehlerhaften Moduls: bf4.exe2 Berichtskennung: bf4.exe3 Vollständiger Name des fehlerhaften Pakets: bf4.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: bf4.exe5 Error: (02/01/2014 05:54:36 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: bf4.exe, Version: 1.1.0.0, Zeitstempel: 0x52e6656f Name des fehlerhaften Moduls: bf4.exe, Version: 1.1.0.0, Zeitstempel: 0x52e6656f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004a1045 ID des fehlerhaften Prozesses: 0x15e0 Startzeit der fehlerhaften Anwendung: 0xbf4.exe0 Pfad der fehlerhaften Anwendung: bf4.exe1 Pfad des fehlerhaften Moduls: bf4.exe2 Berichtskennung: bf4.exe3 Vollständiger Name des fehlerhaften Pakets: bf4.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: bf4.exe5 Error: (02/01/2014 05:40:35 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: bf4.exe, Version: 1.1.0.0, Zeitstempel: 0x52e6656f Name des fehlerhaften Moduls: bf4.exe, Version: 1.1.0.0, Zeitstempel: 0x52e6656f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004a1045 ID des fehlerhaften Prozesses: 0xc94 Startzeit der fehlerhaften Anwendung: 0xbf4.exe0 Pfad der fehlerhaften Anwendung: bf4.exe1 Pfad des fehlerhaften Moduls: bf4.exe2 Berichtskennung: bf4.exe3 Vollständiger Name des fehlerhaften Pakets: bf4.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: bf4.exe5 Error: (02/01/2014 05:37:27 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: bf4.exe, Version: 1.1.0.0, Zeitstempel: 0x52e6656f Name des fehlerhaften Moduls: bf4.exe, Version: 1.1.0.0, Zeitstempel: 0x52e6656f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004a1045 ID des fehlerhaften Prozesses: 0x1980 Startzeit der fehlerhaften Anwendung: 0xbf4.exe0 Pfad der fehlerhaften Anwendung: bf4.exe1 Pfad des fehlerhaften Moduls: bf4.exe2 Berichtskennung: bf4.exe3 Vollständiger Name des fehlerhaften Pakets: bf4.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: bf4.exe5 System errors: ============= Error: (02/04/2014 03:57:48 AM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (02/04/2014 00:42:36 AM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 43. Der Windows-SChannel-Fehlerstatus lautet: 252. Error: (02/03/2014 02:24:27 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 43. Der Windows-SChannel-Fehlerstatus lautet: 252. Error: (02/02/2014 03:32:58 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 43. Der Windows-SChannel-Fehlerstatus lautet: 252. Error: (02/02/2014 03:23:54 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (02/02/2014 03:23:51 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (02/02/2014 03:23:48 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (02/02/2014 03:23:44 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (02/02/2014 03:23:41 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (02/02/2014 03:23:38 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Microsoft Office Sessions: ========================= Error: (02/04/2014 11:47:32 AM) (Source: Application Error)(User: ) Description: rpcs3-x64_0.0.0.4.exe0.0.0.0521cc7derpcs3-x64_0.0.0.4.exe0.0.0.0521cc7dec00000050000000000180352dfc01cf219681c86b16C:\Users\Kevin\AppData\Local\Temp\Rar$EXa0.269\rpcs3-x64_0.0.0.4.exeC:\Users\Kevin\AppData\Local\Temp\Rar$EXa0.269\rpcs3-x64_0.0.0.4.exebf7d467a-8d89-11e3-827f-bc5ff4f1074d Error: (02/04/2014 01:14:32 AM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (02/02/2014 04:42:52 PM) (Source: Application Error)(User: ) Description: Next Car Game Technology Sneak Peek.exe0.0.0.0528f4f34Next Car Game Technology Sneak Peek.exe0.0.0.0528f4f34c000041d00204c2a115401cf202b76df7749E:\Games\Next Car Game\Next Car Game Technology Sneak Peek.exeE:\Games\Next Car Game\Next Car Game Technology Sneak Peek.exeacddd466-8c20-11e3-827b-bc5ff4f1074d Error: (02/02/2014 04:42:47 PM) (Source: Application Error)(User: ) Description: Next Car Game Technology Sneak Peek.exe0.0.0.0528f4f34Next Car Game Technology Sneak Peek.exe0.0.0.0528f4f34c000000500204c2a115401cf202b76df7749E:\Games\Next Car Game\Next Car Game Technology Sneak Peek.exeE:\Games\Next Car Game\Next Car Game Technology Sneak Peek.exea9cddeda-8c20-11e3-827b-bc5ff4f1074d Error: (02/02/2014 03:25:41 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert Error: (02/01/2014 06:37:41 PM) (Source: Application Error)(User: ) Description: bf4.exe1.1.0.052e6656fbf4.exe1.1.0.052e6656fc000000500000000004a104584c01cf1f6eec962f34E:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exeE:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe8c2f8da9-8b67-11e3-8277-bc5ff4f1074d Error: (02/01/2014 05:57:33 PM) (Source: Application Error)(User: ) Description: bf4.exe1.1.0.052e6656fbf4.exe1.1.0.052e6656fc000000500000000004a104590001cf1f6e552bacceE:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exeE:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exef136f2d1-8b61-11e3-8277-bc5ff4f1074d Error: (02/01/2014 05:54:36 PM) (Source: Application Error)(User: ) Description: bf4.exe1.1.0.052e6656fbf4.exe1.1.0.052e6656fc000000500000000004a104515e001cf1f6cc6184617E:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exeE:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe877f7cf8-8b61-11e3-8277-bc5ff4f1074d Error: (02/01/2014 05:40:35 PM) (Source: Application Error)(User: ) Description: bf4.exe1.1.0.052e6656fbf4.exe1.1.0.052e6656fc000000500000000004a1045c9401cf1f6bf6eb4506E:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exeE:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe92227f37-8b5f-11e3-8277-bc5ff4f1074d Error: (02/01/2014 05:37:27 PM) (Source: Application Error)(User: ) Description: bf4.exe1.1.0.052e6656fbf4.exe1.1.0.052e6656fc000000500000000004a1045198001cf1f6bc25b32e1E:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exeE:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe222d5680-8b5f-11e3-8277-bc5ff4f1074d ==================== Memory info =========================== Percentage of memory in use: 20% Total physical RAM: 8111.41 MB Available physical RAM: 6417.4 MB Total Pagefile: 9391.41 MB Available Pagefile: 7410.73 MB Total Virtual: 131072 MB Available Virtual: 131071.78 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.27 GB) (Free:91.25 GB) NTFS Drive e: (Volume) (Fixed) (Total:465.76 GB) (Free:325.53 GB) NTFS Drive f: (TOSHIBA) (Removable) (Total:1.92 GB) (Free:0.19 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 00000000) Partition: GPT Partition Type ======================================================== Disk: 1 (Size: 466 GB) (Disk ID: F46AD61A) Partition: GPT Partition Type ======================================================== Disk: 2 (Size: 2 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=2 GB) - (Type=06) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-02-04 12:03:46 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000025 Samsung_SSD_840_EVO_120GB rev.EXT0BB0Q 111,79GB Running: Gmer-19357.exe; Driver: C:\Users\Kevin\AppData\Local\Temp\kglorpoc.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000187700 15 bytes [00, EA, 0F, 02, 00, 7F, 6F, ...] .text C:\Windows\System32\win32k.sys!W32pServiceTable + 16 fffff96000187710 11 bytes [00, 1F, FC, FF, 80, 52, DE, ...] ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\atiesrxx.exe[760] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffdc549169a 4 bytes [49, C5, FD, 7F] .text C:\Windows\system32\atiesrxx.exe[760] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffdc54916a2 4 bytes [49, C5, FD, 7F] .text C:\Windows\system32\atiesrxx.exe[760] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffdc549181a 4 bytes [49, C5, FD, 7F] .text C:\Windows\system32\atiesrxx.exe[760] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffdc5491832 4 bytes [49, C5, FD, 7F] .text C:\Windows\system32\atieclxx.exe[240] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffdc549169a 4 bytes [49, C5, FD, 7F] .text C:\Windows\system32\atieclxx.exe[240] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffdc54916a2 4 bytes [49, C5, FD, 7F] .text C:\Windows\system32\atieclxx.exe[240] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffdc549181a 4 bytes [49, C5, FD, 7F] .text C:\Windows\system32\atieclxx.exe[240] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffdc5491832 4 bytes [49, C5, FD, 7F] .text E:\Program Files (x64)\EslWire\service\WireHelperSvc.exe[1352] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffdc549169a 4 bytes [49, C5, FD, 7F] .text E:\Program Files (x64)\EslWire\service\WireHelperSvc.exe[1352] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffdc54916a2 4 bytes [49, C5, FD, 7F] .text E:\Program Files (x64)\EslWire\service\WireHelperSvc.exe[1352] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffdc549181a 4 bytes [49, C5, FD, 7F] .text E:\Program Files (x64)\EslWire\service\WireHelperSvc.exe[1352] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffdc5491832 4 bytes [49, C5, FD, 7F] .text C:\Program Files\Windows Defender\MsMpEng.exe[1580] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 506 00007ffdc549169a 4 bytes [49, C5, FD, 7F] .text C:\Program Files\Windows Defender\MsMpEng.exe[1580] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 514 00007ffdc54916a2 4 bytes [49, C5, FD, 7F] .text C:\Program Files\Windows Defender\MsMpEng.exe[1580] C:\Windows\system32\psapi.dll!QueryWorkingSet + 118 00007ffdc549181a 4 bytes [49, C5, FD, 7F] .text C:\Program Files\Windows Defender\MsMpEng.exe[1580] C:\Windows\system32\psapi.dll!QueryWorkingSet + 142 00007ffdc5491832 4 bytes [49, C5, FD, 7F] ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [456:492] fffff960008624d0 ---- EOF - GMER 2.1 ---- |
19.02.2014, 23:10 | #3 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Conduit Search Befall, Pop-Ups und Werbung Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
Themen zu Conduit Search Befall, Pop-Ups und Werbung |
administrator, adobe, adobe flash player, browser, conduit search, defender, explorer, firefox, flash player, hd streamer, homepage, installation, microsoft, mozilla, newtab, pop-ups, programme, registry, scan, services.exe, software, svchost.exe, system, teamspeak, temp, vcredist, werbefenster, werbung, windowsapps, winlogon.exe |