![]() |
|
Log-Analyse und Auswertung: Wichtige Windowsfunktionen funktionieren nicht.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Wichtige Windowsfunktionen funktionieren nicht. Guten Abend, seit heute funktionieren wichtige Windownsfunktionen nicht mehr. Das fängt beim Starten des Laptops an: cmd.exe ist offen wenn der Latop hochgefahren ist, das Programm msconfig lässt sich nicht öffnen (zeigt Ladeanzeige an öffnet das Programm aber nicht) und das selbe Problem habe ich bei der Systemwiederherstellung die ich leider auch nicht machen kann. Mein Laptop hat folgende technische Daten: Windows 7 Home Premium Service Pack 1 Prozessor: Intel(R) Core(TM) i3 CPU M 370 @ 2.40 GHz 2.40 GHz Installierter Arbeitsspeicher (RAM): 4,0 Systemtyp 64 Bit-Betriebssystem Nun habe ich schonmal die Sachen die beschrieben worden sind herunter geladen (defogger, FRST und GMER) Mit defogger habe ich Deamon Tools,etc. schon ausgeschaltet. Mit FRST den Scan gemacht. GMER lässt sich bei mir nicht öffnen. Wenn ich die GMER exe anklicke öffnet sie sich kurz und schließt sich dann sofort wieder. Dabei habe ich die Anweisungen den Viren Scanner auszuschalten, alle anderen Programme zu schließen und die Internetverbindung zu trennen, befolgt. Lg Yasmin PS: Der Laptop gehört meinem Bruder Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-03-2014 01 Ran by Yannik at 2014-03-08 01:07:57 Running from C:\Users\Yannik\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acer Crystal Eye Webcam Video Class Camera (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.31.500-1.0 - Suyin) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Age of Wulin (HKLM-x32\...\{A1CD76EB-30CA-45EE-9946-5FC20BA62012}) (Version: 0.0.1.011 - gPotato) Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.11 Beta1 - Michael Tippach) BitComet 1.37 (HKLM-x32\...\BitComet) (Version: 1.37 - CometNetwork) BitNami WAMP Stack (HKLM-x32\...\BitNami WAMP Stack 5.4.17-0) (Version: 5.4.17-0 - BitNami) BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.7.17.916 - BlueStack Systems, Inc.) BlueStacks Notification Center (HKLM-x32\...\{7E6316CA-5ED0-4EF9-9920-A92115E286B7}) (Version: 0.7.17.916 - BlueStack Systems, Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Broadcom Gigabit NetLink Controller (HKLM\...\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.6.1.2 - Broadcom Corporation) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.4003 - CDBurnerXP) Cheat Engine 6.3 (HKLM-x32\...\Cheat Engine 6.3_is1) (Version: - Cheat Engine) CoupExteNSion (HKLM-x32\...\{6933C2BA-C67D-42C7-8C77-1FF4B364AF54}) (Version: - CouupuExtensIonn) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) Die Sims™ 3 Late Night (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts) EAX4 Unified Redist (HKLM-x32\...\{89661B04-C646-4412-B6D3-5E19F02F1F37}) (Version: 4.001 - Creative Labs) EPSON SX235 Series Printer Uninstall (HKLM\...\EPSON SX235 Series) (Version: - SEIKO EPSON Corporation) FL Studio 11 (HKLM-x32\...\FL Studio 11) (Version: - Image-Line) FlowStone FL 3.0 (HKLM-x32\...\FlowStone) (Version: - ) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Free Mouse and Keyboard Recorder 3.1.3.2 (HKLM-x32\...\{9A6EBB57-EA22-4086-81A0-8FD9843D0CA1}_is1) (Version: - Robot-Soft.com, Inc.) Free YouTube to MP3 Converter version 3.12.14.1022 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.14.1022 - DVDVideoSoft Ltd.) GhostMouse (HKLM-x32\...\GhostMouse_is1) (Version: Free V3.2.1 - ghost-mouse.com) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.146 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden HighGrow Freeware Version 4.20 (HKLM-x32\...\HighGrow Freeware Version 4.20) (Version: 4.20 - Slick Software) IncrediMail (x32 Version: 6.6.0.5273 - IncrediMail) Hidden IncrediMail 2.5 (HKLM-x32\...\IncrediMail) (Version: 6.6.0.5273 - IncrediMail Ltd.) Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2182 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.2.1001 - Intel Corporation) Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Latinum ex Machina (HKLM-x32\...\Latinum ex Machina) (Version: - ) League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Advertising SDK for Windows Phone - DEU (HKLM-x32\...\{1B97BB75-7EBB-4F0D-845F-9A63E8CA72C4}) (Version: 5.2.819.0 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Expression Blend 3 SDK (HKLM-x32\...\{B006B9E9-41DD-4479-9177-3743A53B7735}) (Version: 1.0.1343.0 - Microsoft Corporation) Microsoft Expression Blend 4 (HKLM-x32\...\Blend_4.0.30816.0) (Version: 4.0.30816.0 - Microsoft Corporation) Microsoft Expression Blend 4 (x32 Version: 4.0.30816.0 - Microsoft Corporation) Hidden Microsoft Expression Blend 4 Add-in for Adobe FXG Import (HKLM-x32\...\{B2D1A01F-82CC-4025-B539-FE62D11C8EC8}) (Version: 1.0.20817.0 - Microsoft Corporation) Microsoft Expression Blend SDK for .NET 4 (HKLM-x32\...\{0536BCDF-7EF6-48F6-8765-A3C065A065A5}) (Version: 2.0.20621.0 - Microsoft Corporation) Microsoft Expression Blend SDK for Silverlight 4 (HKLM-x32\...\{B0682940-6FFB-4850-80BA-B2FEF0D64BA8}) (Version: 2.0.20621.0 - Microsoft Corporation) Microsoft Expression Blend SDK for Windows Phone 7 (HKLM-x32\...\{1762BA00-6EBE-4430-9FBB-16F516B4A46D}) (Version: 2.0.20901.0 - Microsoft Corporation) Microsoft Expression Blend SDK for Windows Phone OS 7.1 (HKLM-x32\...\{0688DA81-103D-4FEA-B953-FC8F0915A8E2}) (Version: 2.0.30816.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{8FB1B528-E260-451E-9B55-E9152F94B80B}) (Version: 3.2.3.0 - Microsoft Corporation) Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 (Version: 1.1.40219 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.1 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.1 Language Pack - DEU) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 Language Pack - DEU (Version: 1.1.40219 - Microsoft Corporation) Hidden Microsoft Reader für Pocket PC (HKLM-x32\...\{AEFD48FE-2A76-11D3-928B-00C04FB90523}) (Version: - ) Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.4.304.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Silverlight 3 SDK (HKLM-x32\...\{2012098D-EEE9-4769-8DD3-B038050854D4}) (Version: 3.0.40818.0 - Microsoft Corporation) Microsoft Silverlight 4 SDK - Deutsch (HKLM-x32\...\{8EA792A5-38AA-4F0E-8DFE-D1BAF1145431}) (Version: 4.0.60310.0 - Microsoft Corporation) Microsoft Silverlight Tools for Visual Studio 2010 (HKLM-x32\...\{558358E5-E4F3-4374-BA1D-26FF39EF87D9}) (Version: 10.0.30319.400 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 (HKLM\...\{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Express for Windows Phone - ENU (x32 Version: 10.0.30319 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Express for Windows Phone 7.1 - DEU (x32 Version: 10.1.40219 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (HKLM\...\{3C983A67-DFB2-3D3D-AD9E-CA1A5A09FD18}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Windows Phone Developer Tools - ENU (HKLM-x32\...\Microsoft Visual Studio 2010 Express for Windows Phone - ENU) (Version: 10.0.30319 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft XNA Game Studio 4.0 (Redists) (x32 Version: 4.0.20823.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 (Shared Components) (x32 Version: 4.0.20823.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 (Visual Studio) (x32 Version: 4.0.20823.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 (XnaLiveProxy) (x32 Version: 4.0.20823.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Documentation (x32 Version: 4.0.20823.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (ARP entry) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (HKLM-x32\...\XNA Game Studio 4.0) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft XNA Game Studio 4.0 Refresh (Redists) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (Shared Components) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (Visual Studio) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh Language Pack (de-DE) (HKLM-x32\...\{3A089FFA-C018-4E47-8CE9-6A82731E0E3A}) (Version: 4.0.30912.0 - Microsoft Corporation) Microsoft XNA Game Studio Platform Tools (HKLM-x32\...\{89690B51-2E21-4E93-914E-F9CAC5B24A84}) (Version: 1.4.0.0 - Microsoft Corporation) Mobistel Cynus T2 Drivers(x64) (HKLM-x32\...\{C3F57607-592D-458F-81AE-349FD05DFA74}) (Version: 1.00 - Mobistel) Mouse Recorder Pro 2.0.7.4 (HKLM-x32\...\{889E44CE-435C-4D37-B302-A7E43339E5FA}_is1) (Version: - Nemex Studios) Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 27.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla) MSConfig CleanUp 1.2 (HKLM-x32\...\MSConfig CleanUp_is1) (Version: - Virtuoza) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.4.5 - Notepad++ Team) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Notifier and Animation Creator (HKLM-x32\...\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.) Photo Notifier and Animation Creator (x32 Version: 1.0.0.1009 - Ihr Firmenname) Hidden Prince of Persia Warrior Within (HKLM-x32\...\{EE5BC0BB-9EDA-423C-8276-48857B735D68}) (Version: 1.00.999 - ) Qualcomm Atheros Fast Reconnect (HKLM-x32\...\{0CA2063D-D43F-41F2-A8AC-A3C4A4C722D2}) (Version: 1.0 - QualComm Atheros) QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements) Recorder (HKLM-x32\...\{CD6998C6-5291-44BE-AA89-EA01E359C0BA}) (Version: 7.0.0 - KraTronic) SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.9.0 - SAMSUNG Electronics Co., Ltd.) SIW 2013 Home Edition (HKLM-x32\...\{AB67580-257C-45FF-B8F4-C8C30682091A}_is1) (Version: 2013.05.14 - Topala Software Solutions) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SNT (HKLM-x32\...\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}) (Version: 2.0.0.1467 - SNT) <==== ATTENTION Software Version Updater (HKLM-x32\...\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}) (Version: 1.1.3.8 - ) <==== ATTENTION SupTab (HKLM-x32\...\SupTab) (Version: 1.1.1.0 - ) <==== ATTENTION Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.18.0 - Synaptics Incorporated) Tactical Ops (HKLM-x32\...\Tactical Ops) (Version: - Infogrames) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.13 - TeamSpeak Systems GmbH) Tinno S9050 Drivers(x64) (HKLM-x32\...\{2D1FB6BA-19C6-4CDD-AD96-65F13A5A07A6}) (Version: 1.00 - Tinno) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2468871) (Version: 1 - Microsoft Corporation) Vietcong 2 (HKCU\...\Vietcong 2) (Version: - ) VoiceOver Kit (HKLM-x32\...\{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}) (Version: 1.42.128.0 - Apple Inc.) WCF Data Services SDK for Windows Phone (HKLM-x32\...\{6F33C2E2-5E02-4344-90BC-ED55C48341D2}) (Version: 4.7.6.0 - Microsoft Corporation) websuave (HKLM-x32\...\{476D78C4-1DB0-2D88-7FCC-AA6559F59A8D}) (Version: 2.3.0.1483 - websave) <==== ATTENTION Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows Mobile-Gerätecenter: Treiberupdate (HKLM\...\{92DBCA36-9B41-4DD1-941A-AED149DD37F0}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows Phone Device Manager (HKLM-x32\...\{3959E064-5785-4DA1-9799-5A841F6B9DA5}) (Version: 1.10.0.0 - Julien Schapman) Windows Phone Emulator x64 - DEU (HKLM\...\{EAF1B5AF-AAA8-3EC4-8D4C-7595B70E9760}) (Version: 10.0.40219 - Microsoft Corporation) Windows Phone SDK 7.1 - Deutsch (HKLM-x32\...\Microsoft Visual Studio 2010 Express for Windows Phone 7.1 - DEU) (Version: 10.1.40219 - Microsoft Corporation) Windows Phone SDK 7.1 Add-in for Visual Studio 2010 - DEU (HKLM-x32\...\{57577803-E361-32E2-B33D-ADCE7016AFFF}) (Version: 10.0.40219 - Microsoft Corporation) Windows Phone SDK 7.1 Assemblies - deu (HKLM-x32\...\{3F75341E-8E48-3E06-9569-D2DCCB931253}) (Version: 10.0.40219 - Microsoft Corporation) Windows Phone SDK 7.1 Assemblies (HKLM-x32\...\{9E2F2BAC-A9FD-35BC-B8E0-253FEBED0F9B}) (Version: 10.0.40219 - Microsoft Corporation) Windows Phone SDK 7.1 Extensions for XNA Game Studio 4.0 (HKLM-x32\...\{A4CC18F6-DB05-4B03-B724-4128322FA85F}) (Version: 4.0.30901.0 - Microsoft Corporation) Windows Utils (HKLM-x32\...\Windows Utils) (Version: - ) WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) WPF Toolkit February 2010 (Version 3.5.50211.1) (HKLM-x32\...\{5EE6E987-1B79-4A93-832B-27472C7D1579}) (Version: 3.5.50211.1 - Microsoft Corporation) WS-Booster (HKLM-x32\...\S-46480778) (Version: 4.0.0.1195 - PremiumSoft) WS-Booster (HKLM-x32\...\S-975730335) (Version: 4.0.0.1972 - PremiumSoft) WS-Sustainer 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{84ef8d51}) (Version: - Certified Publisher) YoutubeAdblocker (HKLM-x32\...\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version: 2.3.0.1483 - YoutubeAdblocker) <==== ATTENTION ZTE Handset USB Driver (HKLM\...\{01D42BF0-ED08-463f-8A28-99EB6FEE962B}) (Version: - ZTE Corporation) ZTE Handset USB Driver (HKLM\...\{D2D77DC2-8299-11D1-8949-444553540000}_is1) (Version: 5.2066.1.A11B02 - ZTE Corporation) Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation) Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 07-03-2014 22:51:33 Removed iTunes ==================== Hosts content: ========================== 2009-07-14 03:34 - 2011-10-01 20:10 - 00000822 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0EB94300-FEBA-4412-8DC2-E2107436A97B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-07] (Google Inc.) Task: {173BBDBC-B805-4F10-B70B-D9AC07ED4D22} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-07] (Google Inc.) Task: {5DD2B541-C241-42B7-9055-2276570276BE} - System32\Tasks\GoforFilesUpdate => C:\Program Files (x86)\GoforFiles\GFFUpdater.exe <==== ATTENTION Task: {73EACE60-CD83-4425-9200-DF44AB6FA9D9} - System32\Tasks\WS-Booster-S-46480778 => c:\programdata\safesoft\ws-booster\WS-Booster.exe [2014-03-01] () Task: {85364706-626D-4F8D-A2CE-196C390ED51F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {86F0E419-6553-44F4-B3A7-8495DC54639F} - System32\Tasks\WS-Booster-S-975730335 => c:\programdata\right soft\ws-booster\WS-Booster.exe [2014-03-03] () Task: {BDA8D198-5B42-44D3-A3DC-82E8BE644A1F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-21] (Adobe Systems Incorporated) Task: {BEC8C8BE-AA0D-4E7C-8FDB-F95AC5A7BD5D} - System32\Tasks\YourFile DownloaderUpdate => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION Task: {C4F75551-3F95-4705-A3E4-BC46396E53C9} - System32\Tasks\AmiUpdXp => C:\Users\Yannik\AppData\Local\SwvUpdater\Updater.exe [2014-02-10] () <==== ATTENTION Task: {FE00E48C-3378-420E-AAD9-EB87E9090147} - System32\Tasks\RunAsStdUser Task => C:\Users\Yannik\AppData\Local\Oxy\Application\oxy.exe <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AmiUpdXp.job => C:\Users\Yannik\AppData\Local\SwvUpdater\Updater.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\WS-Booster-S-46480778.job => c:\programdata\safesoft\ws-booster\WS-Booster.exe Task: C:\Windows\Tasks\WS-Booster-S-975730335.job => c:\programdata\right soft\ws-booster\WS-Booster.exe ==================== Loaded Modules (whitelisted) ============= 2014-03-01 00:05 - 2014-03-01 00:05 - 04383232 _____ () C:\Program Files (x86)\WS-Booster\Assistant_x64.dll 2014-03-03 21:49 - 2014-03-03 21:49 - 00729600 _____ () c:\programdata\right soft\ws-booster\WS-Booster.exe 2014-03-01 00:10 - 2014-03-01 00:10 - 00729600 _____ () c:\programdata\safesoft\ws-booster\WS-Booster.exe 2014-01-27 21:45 - 2014-01-27 21:45 - 00710976 _____ () C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe 2013-08-09 18:41 - 2013-05-16 18:44 - 08151040 _____ () C:\BitNami\wampstack-5.4.17-0\mysql\bin\mysqld.exe 2014-02-11 12:59 - 2014-01-07 16:29 - 00425792 _____ () C:\Program Files (x86)\Iminent\WinkHandler.exe 2014-03-03 22:34 - 2014-02-13 03:36 - 00714752 _____ () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Temp\dllhost.exe 2014-03-01 00:05 - 2014-03-01 00:05 - 04408320 _____ () C:\Program Files (x86)\WS-Booster\Assistant.dll 2014-03-01 00:05 - 2014-03-01 00:05 - 00175952 _____ () C:\Program Files (x86)\WS-Booster\AssistantSvc.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-08-09 18:40 - 2012-12-24 12:49 - 00111616 _____ () C:\BitNami\WAMPST~1.17-\apache2\bin\pcre.dll 2013-08-09 18:40 - 2012-05-13 12:18 - 00067072 _____ () C:\BitNami\WAMPST~1.17-\apache2\bin\zlib1.dll 2013-08-09 18:41 - 2013-07-03 21:56 - 00097792 _____ () C:\BitNami\wampstack-5.4.17-0\php\libpq.dll 2013-08-09 18:41 - 2013-07-05 10:15 - 00025088 _____ () C:\BitNami\wampstack-5.4.17-0\php\php5apache2_4.dll 2014-02-19 15:42 - 2014-02-19 15:42 - 03578992 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-03-03 22:34 - 2014-02-26 22:31 - 00506880 _____ () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Temp\miner.dll 2014-03-03 22:34 - 2013-12-28 05:43 - 00848384 _____ () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Temp\usft_ext.dll 2014-03-03 22:34 - 2014-01-09 02:15 - 00142848 _____ () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Temp\coinutil.dll 2014-03-03 22:34 - 2013-11-26 18:58 - 00863744 _____ () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Temp\OPENSSL.dll 2014-02-21 02:01 - 2014-02-21 02:01 - 16265096 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll 2014-02-19 16:13 - 2014-02-19 16:13 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\29335dc88d799664dcd97362bcb687e9\IsdiInterop.ni.dll 2013-06-03 14:46 - 2010-04-13 08:52 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^Users^Yannik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^net.lnk => C:\Windows\pss\net.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: EA Core => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent MSCONFIG\startupreg: GoogleChromeAutoLaunch_096C503B644B0BC0C44B32F71917E8D8 => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe MSCONFIG\startupreg: Iminent => C:\Program Files (x86)\Iminent\Iminent.exe /warmup "F77F87E5-A6BD-4922-A530-EDF63D7E9F8C" MSCONFIG\startupreg: IminentMessenger => C:\Program Files (x86)\Iminent\Iminent.Messengers.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe MSCONFIG\startupreg: PLFSetL => C:\Windows\\PLFSetL.exe MSCONFIG\startupreg: PTS Software => C:\Users\Yannik\AppData\Roaming\PTS\PTS.exe MSCONFIG\startupreg: Raptr => C:\PROGRA~2\Raptr\raptrstub.exe --startup MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe MSCONFIG\startupreg: Windows Mobile Device Center => %windir%\WindowsMobile\wmdc.exe MSCONFIG\startupreg: Zune Launcher => "C:\Program Files\Zune\ZuneLauncher.exe" ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Lexmark X422 Description: Lexmark X422 Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Lexmark Service: usbscan Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (03/08/2014 01:02:10 AM) (Source: BstHdAndroidSvc) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/08/2014 00:38:01 AM) (Source: BstHdAndroidSvc) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/08/2014 00:20:53 AM) (Source: BstHdAndroidSvc) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/07/2014 11:14:43 PM) (Source: BstHdAndroidSvc) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/07/2014 03:07:15 PM) (Source: BstHdAndroidSvc) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/06/2014 01:00:29 AM) (Source: BstHdAndroidSvc) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/05/2014 09:58:29 PM) (Source: BstHdAndroidSvc) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/05/2014 08:35:28 PM) (Source: Application Hang) (User: ) Description: Programm firefox.exe, Version 27.0.1.5156 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1268 Startzeit: 01cf38a01227d31e Endzeit: 100 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: 4c33a0c3-a49d-11e3-9ee3-b870f4ea94aa Error: (03/05/2014 07:23:13 PM) (Source: Application Hang) (User: ) Description: Programm siw.exe, Version 4.4.0.5 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: aa8 Startzeit: 01cf389db7cac7e5 Endzeit: 18 Anwendungspfad: C:\Program Files (x86)\SIW 2013 Home Edition\siw.exe Berichts-ID: 34591d24-a493-11e3-9ee3-b870f4ea94aa Error: (03/05/2014 07:06:28 PM) (Source: BstHdAndroidSvc) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) System errors: ============= Error: (03/08/2014 01:02:55 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (03/08/2014 01:02:10 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet: %%1064 Error: (03/08/2014 00:38:49 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (03/08/2014 00:38:01 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet: %%1064 Error: (03/08/2014 00:21:42 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (03/08/2014 00:20:53 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet: %%1064 Error: (03/07/2014 11:15:45 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (03/07/2014 11:14:43 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet: %%1064 Error: (03/07/2014 11:14:12 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 07.03.2014 um 23:12:35 unerwartet heruntergefahren. Error: (03/07/2014 04:56:52 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht vergrößert werden kann. Microsoft Office Sessions: ========================= Error: (03/08/2014 01:02:10 AM) (Source: BstHdAndroidSvc)(User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/08/2014 00:38:01 AM) (Source: BstHdAndroidSvc)(User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/08/2014 00:20:53 AM) (Source: BstHdAndroidSvc)(User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/07/2014 11:14:43 PM) (Source: BstHdAndroidSvc)(User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/07/2014 03:07:15 PM) (Source: BstHdAndroidSvc)(User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/06/2014 01:00:29 AM) (Source: BstHdAndroidSvc)(User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/05/2014 09:58:29 PM) (Source: BstHdAndroidSvc)(User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (03/05/2014 08:35:28 PM) (Source: Application Hang)(User: ) Description: firefox.exe27.0.1.5156126801cf38a01227d31e100C:\Program Files (x86)\Mozilla Firefox\firefox.exe4c33a0c3-a49d-11e3-9ee3-b870f4ea94aa Error: (03/05/2014 07:23:13 PM) (Source: Application Hang)(User: ) Description: siw.exe4.4.0.5aa801cf389db7cac7e518C:\Program Files (x86)\SIW 2013 Home Edition\siw.exe34591d24-a493-11e3-9ee3-b870f4ea94aa Error: (03/05/2014 07:06:28 PM) (Source: BstHdAndroidSvc)(User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) CodeIntegrity Errors: =================================== Date: 2013-06-03 20:23:37.146 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\3f502dace040f45595d26b0152686861\815e8e31da5f12104f9b\c3441babc306c3b95332ab54\x86_microsoft-windows-userenv_31bf3856ad364e35_7.1.7601.17514_none_83b850a4346b9b7c\userenv.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-03 20:23:37.138 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\3f502dace040f45595d26b0152686861\815e8e31da5f12104f9b\c3441babc306c3b95332ab54\x86_microsoft-windows-userenv_31bf3856ad364e35_7.1.7601.17514_none_83b850a4346b9b7c\userenv.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-03 20:23:37.130 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\3f502dace040f45595d26b0152686861\815e8e31da5f12104f9b\c3441babc306c3b95332ab54\x86_microsoft-windows-userenv_31bf3856ad364e35_7.1.7601.17514_none_83b850a4346b9b7c\userenv.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-03 20:23:37.027 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\3f502dace040f45595d26b0152686861\815e8e31da5f12104f9b\c3441babc306c3b95332ab54\x86_microsoft-windows-userenv_31bf3856ad364e35_7.1.7601.17514_none_83b850a4346b9b7c\userenv.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-03 19:57:05.895 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\3f502dace040f45595d26b0152686861\815e8e31da5f12104f9b\c3441babc306c3b95332ab54\amd64_microsoft-windows-userenv_31bf3856ad364e35_7.1.7601.17514_none_dfd6ec27ecc90cb2\userenv.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-03 19:57:05.870 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\3f502dace040f45595d26b0152686861\815e8e31da5f12104f9b\c3441babc306c3b95332ab54\amd64_microsoft-windows-userenv_31bf3856ad364e35_7.1.7601.17514_none_dfd6ec27ecc90cb2\userenv.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-03 19:57:05.852 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\3f502dace040f45595d26b0152686861\815e8e31da5f12104f9b\c3441babc306c3b95332ab54\amd64_microsoft-windows-userenv_31bf3856ad364e35_7.1.7601.17514_none_dfd6ec27ecc90cb2\userenv.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-03 19:57:05.778 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\3f502dace040f45595d26b0152686861\815e8e31da5f12104f9b\c3441babc306c3b95332ab54\amd64_microsoft-windows-userenv_31bf3856ad364e35_7.1.7601.17514_none_dfd6ec27ecc90cb2\userenv.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 42% Total physical RAM: 3766.7 MB Available physical RAM: 2170.9 MB Total Pagefile: 7531.59 MB Available Pagefile: 5820.42 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (WindowsPartition) (Fixed) (Total:207.19 GB) (Free:31.17 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.03 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (LinuxPartition) (Fixed) (Total:97.66 GB) (Free:19.1 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: F78CF78C) Partition: GPT Partition Type. ==================== End Of Log ============================ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-03-2014 01 Ran by Yannik (administrator) on YANNIK-PC on 08-03-2014 01:06:00 Running from C:\Users\Yannik\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe () c:\programdata\right soft\ws-booster\WS-Booster.exe () c:\programdata\safesoft\ws-booster\WS-Booster.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHLE.EXE (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHLE.EXE () C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Iminent) C:\Program Files (x86)\Common Files\Umbrella\Umbrella.exe (AutoIt Team) C:\Users\Yannik\AppData\Roaming\AutoIt3\AutoIt3.exe (Apache Software Foundation) C:\BitNami\WAMPST~1.17-\apache2\bin\httpd.exe () C:\BitNami\wampstack-5.4.17-0\mysql\bin\mysqld.exe () C:\Program Files (x86)\Iminent\WinkHandler.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () C:\Program Files (x86)\Iminent\WinkHandler.exe (Atheros) C:\Program Files (x86)\Qualcomm Atheros Fast Reconnect\Ath_WlanAgent.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Apache Software Foundation) C:\BitNami\WAMPST~1.17-\apache2\bin\httpd.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Temp\dllhost.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2013-06-07] (Microsoft Corporation) HKU\S-1-5-21-715970464-193477571-3523406784-1000\...\Run: [EPSON3551B0 (Epson Stylus SX235)] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.EXE [232448 2011-01-20] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-715970464-193477571-3523406784-1000\...\Run: [EPSON3551B0 (Epson Stylus SX235) (Kopie 1)] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.EXE [232448 2011-01-20] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-715970464-193477571-3523406784-1000\...\Run: [GoogleChromeAutoLaunch_096C503B644B0BC0C44B32F71917E8D8] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [859464 2014-03-02] (Google Inc.) HKU\S-1-5-21-715970464-193477571-3523406784-1000\...\Run: [Java] - cmd /c cd %APPDATA%\AutoIt3 & AutoIt3.exe soundmng.txt HKU\S-1-5-21-715970464-193477571-3523406784-1000\...\RunOnce: [Temp] - C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Temp\system.vbs [2383 2014-03-03] () HKU\S-1-5-21-715970464-193477571-3523406784-1000\...\MountPoints2: {156dffc4-ccfb-11e2-a8c0-c4921d20002a} - H:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.A11B02 PID_0083 HKU\S-1-5-21-715970464-193477571-3523406784-1000\...\MountPoints2: {a7bbfd22-98ee-11e3-bce8-b870f4ea94aa} - G:\Autorun.exe AppInit_DLLs: C:\PROGRA~2\WS-BOO~1\ASSIST~2.DLL => C:\Program Files (x86)\WS-Booster\Assistant_x64.dll [4383232 2014-03-01] () AppInit_DLLs-x32: c:\progra~2\ws-boo~1\assist~1.dll => C:\Program Files (x86)\WS-Booster\Assistant.dll [4408320 2014-03-01] () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.webisawsome.info/?pid=2145&r=2014/02/28&hid=8598159249728063820&lg=EN&cc=DE&unqvl=49 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB8BC63E1FC64CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.awesomehp.com/?type=hp&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.webisawsome.info/?pid=2145&r=2014/02/28&hid=8598159249728063820&lg=EN&cc=DE&unqvl=49 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018&q={searchTerms} URLSearchHook: HKCU - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.webisawsome.info/?l=1&q={searchTerms}&pid=2145&r=2014/02/28&hid=8598159249728063820&lg=EN&cc=DE&unqvl=49 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018&q={searchTerms} SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.webisawsome.info/?l=1&q={searchTerms}&pid=2145&r=2014/02/28&hid=8598159249728063820&lg=EN&cc=DE&unqvl=49 SearchScopes: HKLM-x32 - {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://start.iminent.com/?appId=46806F84-7A02-4571-AFD5-E37F73BF4997&ref=toolbox&q={searchTerms} SearchScopes: HKCU - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.webisawsome.info/?l=1&q={searchTerms}&pid=2145&r=2014/02/28&hid=8598159249728063820&lg=EN&cc=DE&unqvl=49 SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3324678&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP74281AE3-4B40-4C60-B061-3576A2579A4F&q={searchTerms}&SSPV= SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=FCD8F2DF9A92ACA4&affID=119293&tt=240913_238&tsp=5016 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1392765942&from=tugs&uid=WDCXWD5000BPVT-22HXZT3_WD-WXE1A71S2018S2018&q={searchTerms} SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.webisawsome.info/?l=1&q={searchTerms}&pid=2145&r=2014/02/28&hid=8598159249728063820&lg=EN&cc=DE&unqvl=49 SearchScopes: HKCU - {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://start.iminent.com/?appId=46806F84-7A02-4571-AFD5-E37F73BF4997&ref=toolbox&q={searchTerms} BHO: websave - {3DB00AA0-FAEB-061A-C025-0B575B299ADA} - C:\Program Files (x86)\websave\GYTbK.x64.dll () BHO: SNT - {46EE71E0-2B82-B02F-451A-6E0004599717} - C:\Program Files (x86)\SNT\tWWmv86Q.x64.dll () BHO: websuave - {4A2F1856-74D4-7DE3-76C1-4BBA1CEDCC18} - C:\Program Files (x86)\websuave\5QXizw1BH.x64.dll () BHO: websave - {83C16BD2-B5ED-242D-098F-D55C68FEB8D2} - C:\Program Files (x86)\websave\C1eOzGTmn.x64.dll () BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: CoupExteNSion - {C21A2C2B-0949-E800-89FC-93F2AF7CFC7D} - C:\ProgramData\CoupExteNSion\l1F9X.x64.dll () BHO: YoutubeAdblocker - {E466969E-860A-9930-3C48-CAA1D0A8A340} - C:\Program Files (x86)\YoutubeAdblocker\p.x64.dll () BHO: SNT - {E6965F91-022B-A468-8054-E73A8802DD68} - C:\Program Files (x86)\SNT\RXtwKiLTq.x64.dll () BHO: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited) BHO-x32: websave - {3DB00AA0-FAEB-061A-C025-0B575B299ADA} - C:\Program Files (x86)\websave\GYTbK.dll () BHO-x32: SNT - {46EE71E0-2B82-B02F-451A-6E0004599717} - C:\Program Files (x86)\SNT\tWWmv86Q.dll () BHO-x32: websuave - {4A2F1856-74D4-7DE3-76C1-4BBA1CEDCC18} - C:\Program Files (x86)\websuave\5QXizw1BH.dll () BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: websave - {83C16BD2-B5ED-242D-098F-D55C68FEB8D2} - C:\Program Files (x86)\websave\C1eOzGTmn.dll () BHO-x32: No Name - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: CoupExteNSion - {C21A2C2B-0949-E800-89FC-93F2AF7CFC7D} - C:\ProgramData\CoupExteNSion\l1F9X.dll () BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: YoutubeAdblocker - {E466969E-860A-9930-3C48-CAA1D0A8A340} - C:\Program Files (x86)\YoutubeAdblocker\p.dll () BHO-x32: SNT - {E6965F91-022B-A468-8054-E73A8802DD68} - C:\Program Files (x86)\SNT\RXtwKiLTq.dll () BHO-x32: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default FF user.js: detected! => C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\user.js FF DefaultSearchEngine: WebSearch FF SearchEngineOrder.1: WebSearch FF SearchEngineOrder.user_pref("browser.search.order.1,S", "WebSearch");: user_pref("browser.search.order.1,S", "WebSearch"); FF SelectedSearchEngine: WebSearch FF Homepage: hxxp://websearch.webisawsome.info/?pid=2145&r=2014/02/28&hid=8598159249728063820&lg=EN&cc=DE&unqvl=49 FF Keyword.URL: hxxp://websearch.webisawsome.info/?pid=2145&r=2014/02/28&hid=8598159249728063820&lg=EN&cc=DE&unqvl=49&l=1&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\searchplugins\WebSearch.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\awesomehp.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: YoutubeAdblocker - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\097umilb@zrn-brpwu.net [2014-03-01] FF Extension: Torntv V9.0 - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\5a6bf058-b978-4b84-a2ec-6f5462cfccb2@10120365-d3c0-4ec9-8624-5fac2592d0df.com [2014-03-03] FF Extension: WeBsaave - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\b6_b@mbtpx-z.co.uk [2014-03-01] FF Extension: pricealarm - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM [2014-02-11] FF Extension: CoupExteNSion - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\oja9kolg@iujnfrk.org [2014-03-07] FF Extension: websuave - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\qtpzf@vltxlzef.com [2014-03-03] FF Extension: Quick Start - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\quick_start@gmail.com [2014-02-21] FF Extension: websave - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\szay.3agpc@riohyafh.co.uk [2014-03-01] FF Extension: SNT - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\uka6oeu@bqqmfsiu.com [2014-03-01] FF Extension: SNT - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\xvgof@yzxpzjab.co.uk [2014-03-01] FF Extension: Value Apps - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\{94cd2cc3-083f-49ba-a218-4cda4b4829fd} [2014-02-24] FF Extension: ep - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\jid1-0xtMKhXFEs4jIg@jetpack.xpi [2014-02-21] FF Extension: XJZ Survey Remover - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\survey-remover@gmx.com.xpi [2013-08-01] FF Extension: Adblock Plus - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-21] FF Extension: Greasemonkey - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-08-01] FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [] FF HKLM-x32\...\Firefox\Extensions: [lightningnewtab@gmail.com] - C:\Users\Yannik\AppData\Roaming\Mozilla\Firefox\Profiles\d9v5bfcz.default\extensions\lightningnewtab@gmail.com.xpi Chrome: ======= CHR DefaultSearchKeyword: start.iminent.com CHR DefaultSearchProvider: StartWeb CHR DefaultSearchURL: hxxp://start.iminent.com/?appId=46806F84-7A02-4571-AFD5-E37F73BF4997&ref=toolbox&q={searchTerms} CHR DefaultNewTabURL: CHR Extension: (CoupExteNSion) - C:\Users\Yannik\AppData\Local\Google\Chrome\User Data\Default\Extensions\alhnamgjgecpeegbmbfimfcalpclpmaf [2014-03-07] CHR Extension: (DVDVideoSoft) - C:\Users\Yannik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-10-27] CHR Extension: (Google Wallet) - C:\Users\Yannik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-02] CHR Extension: (websuave) - C:\Users\Yannik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbodnipbnidgkibcgacbpadmliimmeif [2014-03-03] CHR Extension: (Lightning speedDial) - C:\Users\Yannik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkndmigholgfjlniaohblojbhgjbkakn [2014-02-20] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-10-27] CHR HKLM-x32\...\Chrome\Extension: [igdhbblpcellaljokkpfhcjlagemhgjl] - "C:\Program Files (x86)\Iminent\Iminent.crx" [2013-10-27] CHR HKLM-x32\...\Chrome\Extension: [pkndmigholgfjlniaohblojbhgjbkakn] - C:\Users\Yannik\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx [2014-02-19] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 84ef8d51; C:\Program Files (x86)\WS-Booster\AssistantSvc.dll [175952 2014-03-01] () S3 BITCOMET_HELPER_SERVICE; C:\Program Files (x86)\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (www.BitComet.com) S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [393032 2013-08-07] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384840 2013-08-07] (BlueStack Systems, Inc.) R2 Level Quality Watcher; C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe [710976 2014-01-27] () R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 SProtection; C:\Program Files (x86)\Common Files\Umbrella\Umbrella.exe [2916672 2014-01-07] (Iminent) R2 wampstackApache; C:\BitNami\WAMPST~1.17-\apache2\bin\httpd.exe [22016 2013-02-23] (Apache Software Foundation) R2 wampstackMySQL; C:\BitNami\wampstack-5.4.17-0\mysql\bin\mysqld.exe [8151040 2013-05-16] () R2 WinkHandler; C:\Program Files (x86)\Iminent\WinkHandler.exe [425792 2014-01-07] () R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros Fast Reconnect\Ath_WlanAgent.exe [57344 2011-08-10] (Atheros) ==================== Drivers (Whitelisted) ==================== R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [70984 2013-08-07] (BlueStack Systems) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-02-17] (Disc Soft Ltd) S3 massfilter_hs; C:\Windows\System32\DRIVERS\massfilter_hs.sys [18456 2012-01-10] (HandSet Incorporated) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) S3 SaiK0621; C:\Windows\System32\DRIVERS\SaiK0621.sys [131584 2008-10-22] (Saitek) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2014-02-18] (Duplex Secure Ltd.) S3 sscdserd; C:\Windows\System32\DRIVERS\sscdserd.sys [141384 2012-06-27] (MCCI Corporation) S3 zghsdiag; C:\Windows\System32\DRIVERS\zghsdiag.sys [129432 2011-09-13] (ZTE Incorporated) S3 zghsmdm; C:\Windows\System32\DRIVERS\zghsmdm.sys [129432 2011-09-13] (ZTE Incorporated) S3 zghsnmea; C:\Windows\System32\DRIVERS\zghsnmea.sys [129432 2011-09-13] (ZTE Incorporated) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-08 01:06 - 2014-03-08 01:06 - 00022338 _____ () C:\Users\Yannik\Downloads\FRST.txt 2014-03-08 01:05 - 2014-03-08 01:06 - 00000000 ____D () C:\FRST 2014-03-08 01:04 - 2014-03-08 01:05 - 02156544 _____ (Farbar) C:\Users\Yannik\Downloads\FRST64.exe 2014-03-08 01:00 - 2014-03-08 01:00 - 00000584 _____ () C:\Users\Yannik\Downloads\defogger_disable.log 2014-03-08 01:00 - 2014-03-08 01:00 - 00000020 _____ () C:\Users\Yannik\defogger_reenable 2014-03-08 00:59 - 2014-03-08 00:59 - 00050477 _____ () C:\Users\Yannik\Downloads\Defogger.exe 2014-03-07 23:38 - 2014-03-07 23:38 - 00709421 _____ (Virtuoza ) C:\Users\Yannik\Downloads\msconfig-cleanup-setup.exe 2014-03-07 23:38 - 2014-03-07 23:38 - 00000000 ____D () C:\Program Files (x86)\MSConfig CleanUp 2014-03-07 15:14 - 2014-03-07 15:14 - 00000000 ____D () C:\ProgramData\CoupExteNSion 2014-03-05 16:27 - 2014-03-05 16:27 - 00000000 ____D () C:\Users\Yannik\Desktop\Spiele 2014-03-05 00:50 - 2014-03-05 00:50 - 00000558 _____ () C:\Users\Yannik\Desktop\Vietcong 2.lnk 2014-03-05 00:47 - 2014-03-05 00:47 - 00098304 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll 2014-03-04 18:21 - 2014-03-05 13:36 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\AutoIt3 2014-03-04 18:21 - 2014-03-04 18:21 - 42011090 _____ () C:\Users\Yannik\AppData\Roaming\launcher.exe 2014-03-04 18:21 - 2014-03-04 18:21 - 00933768 _____ (DivX, LLC) C:\Users\Yannik\AppData\Roaming\divx.exe 2014-03-04 18:21 - 2014-03-04 18:21 - 00000000 ____D () C:\ProgramData\DivX 2014-03-03 22:53 - 2014-03-03 22:53 - 00003520 _____ () C:\Windows\System32\Tasks\RunAsStdUser Task 2014-03-03 21:49 - 2014-03-08 01:01 - 00000450 ____H () C:\Windows\Tasks\WS-Booster-S-975730335.job 2014-03-03 21:49 - 2014-03-03 21:49 - 00002696 _____ () C:\Windows\System32\Tasks\WS-Booster-S-975730335 2014-03-03 21:49 - 2014-03-03 21:49 - 00000000 ____D () C:\ProgramData\Right Soft 2014-03-03 21:48 - 2014-03-03 21:48 - 00000000 ____D () C:\ProgramData\websuave 2014-03-03 21:48 - 2014-03-03 21:48 - 00000000 ____D () C:\Program Files (x86)\websuave 2014-03-03 21:12 - 2014-03-03 23:09 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Oxy 2014-03-03 21:10 - 2014-03-04 17:49 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Oxy 2014-03-01 03:34 - 2014-03-01 21:52 - 00004917 _____ () C:\Users\Yannik\Documents\TombRaider.log 2014-03-01 03:34 - 2014-03-01 03:34 - 00000000 ____D () C:\Users\Yannik\AppData\Local\SKIDROW 2014-03-01 02:56 - 2014-03-01 03:04 - 00000000 ____D () C:\Games 2014-03-01 00:31 - 2014-03-05 17:26 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\BitComet 2014-03-01 00:30 - 2014-03-01 00:31 - 00000000 ____D () C:\Program Files (x86)\BitComet 2014-03-01 00:08 - 2014-03-01 00:08 - 00052987 _____ () C:\tomb-raider-2013-pc-game-full-version.html 2014-03-01 00:07 - 2014-03-01 00:07 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\EZDownloader 2014-03-01 00:06 - 2014-03-01 00:11 - 00000000 ____D () C:\ProgramData\SNT 2014-03-01 00:06 - 2014-03-01 00:11 - 00000000 ____D () C:\Program Files (x86)\SNT 2014-03-01 00:05 - 2014-03-08 01:01 - 00000438 ____H () C:\Windows\Tasks\WS-Booster-S-46480778.job 2014-03-01 00:05 - 2014-03-03 21:48 - 00000000 ____D () C:\Program Files (x86)\WS-Booster 2014-03-01 00:05 - 2014-03-01 00:10 - 00002684 _____ () C:\Windows\System32\Tasks\WS-Booster-S-46480778 2014-03-01 00:05 - 2014-03-01 00:10 - 00000000 ____D () C:\ProgramData\websave 2014-03-01 00:05 - 2014-03-01 00:10 - 00000000 ____D () C:\Program Files (x86)\websave 2014-03-01 00:05 - 2014-03-01 00:06 - 00000000 ____D () C:\ProgramData\SafeSoft 2014-03-01 00:05 - 2014-03-01 00:05 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Packages 2014-03-01 00:05 - 2014-03-01 00:05 - 00000000 ____D () C:\ProgramData\YoutubeAdblocker 2014-03-01 00:05 - 2014-03-01 00:05 - 00000000 ____D () C:\Program Files (x86)\YoutubeAdblocker 2014-03-01 00:04 - 2014-03-07 15:14 - 00000000 ____D () C:\ProgramData\d71360f8168276b3 2014-03-01 00:04 - 2014-03-03 21:49 - 00000000 ____D () C:\ProgramData\InstallMate 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Torch 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Comodo 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Gast\AppData\Local\Torch 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Gast 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Administrator 2014-02-28 22:59 - 2014-02-28 22:59 - 00003120 _____ () C:\Windows\System32\Tasks\YourFile DownloaderUpdate 2014-02-28 22:59 - 2014-02-28 22:59 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\YourFileDownloader 2014-02-28 22:37 - 2014-02-28 22:37 - 00000000 _____ () C:\Windows\DXT44AE.tmp 2014-02-28 22:27 - 2014-02-28 22:27 - 00003162 _____ () C:\Windows\System32\Tasks\{E83CB6D7-71ED-4C27-B3D5-6A28CA10FB18} 2014-02-28 22:25 - 2014-02-28 22:25 - 00000000 ____D () C:\Program Files (x86)\directx 2014-02-28 22:25 - 2014-02-28 22:25 - 00000000 _____ () C:\Windows\DXT5A30.tmp 2014-02-28 22:22 - 1998-10-29 16:45 - 00306688 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe 2014-02-27 22:28 - 2014-02-27 22:28 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-02-27 22:27 - 2014-02-28 23:06 - 00000000 ____D () C:\Program Files (x86)\MediaViewV1 2014-02-26 21:02 - 2014-02-26 21:03 - 00000000 ____D () C:\Users\Yannik\Desktop\Chemie 2014-02-26 13:40 - 2014-02-28 23:06 - 00000000 ____D () C:\Program Files (x86)\MediaViewerV1 2014-02-24 20:34 - 2014-02-24 20:34 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\OpenOffice 2014-02-24 20:33 - 2014-02-24 20:34 - 00000000 ___SD () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1 2014-02-24 20:33 - 2014-02-24 20:33 - 00001188 _____ () C:\Users\Yannik\Desktop\OpenOffice 4.0.1.lnk 2014-02-24 20:32 - 2014-02-24 20:33 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-02-24 20:31 - 2014-02-24 20:31 - 00000000 ____D () C:\Users\Yannik\Desktop\OpenOffice 4.0.1 (de) Installation Files 2014-02-24 12:35 - 2014-02-24 12:37 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 2014-02-24 12:35 - 2014-02-24 12:35 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Conduit 2014-02-24 12:35 - 2014-02-24 12:35 - 00000000 ____D () C:\Program Files\Conduit 2014-02-24 12:35 - 2014-02-24 12:35 - 00000000 ____D () C:\Program Files (x86)\Conduit 2014-02-24 12:34 - 2014-02-24 12:36 - 00000000 _____ () C:\END 2014-02-21 16:17 - 2014-02-28 23:05 - 27137357 _____ () C:\Windows\system32\SavingsBullFilterService.log 2014-02-21 16:17 - 2014-02-21 16:17 - 00000000 _____ () C:\Windows\SysWOW64\Service.log 2014-02-21 16:17 - 2014-02-21 16:17 - 00000000 _____ () C:\Windows\system32\Service.log 2014-02-21 15:05 - 2014-02-21 21:15 - 00002973 _____ () C:\Users\Yannik\Desktop\Sims 3 - Late Night.lnk 2014-02-21 14:56 - 2014-02-21 14:56 - 00003208 _____ () C:\Windows\System32\Tasks\{CC3FA791-CB61-435E-BBDA-7C0A330D47DD} 2014-02-21 04:45 - 2014-02-21 18:09 - 00000000 ____D () C:\Users\Yannik\The Sims 3 Ultimate Bundle 2014-02-20 23:57 - 2014-02-21 00:34 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-02-20 23:46 - 2014-02-20 23:51 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Origin 2014-02-20 23:42 - 2014-02-20 23:52 - 00000000 ____D () C:\ProgramData\Origin 2014-02-20 23:14 - 2014-02-21 00:37 - 00000000 ____D () C:\Users\Yannik\Desktop\Sims 3 Alle Cracks 2014-02-20 22:22 - 2014-02-21 00:13 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\BitLord 2014-02-20 22:22 - 2014-02-20 22:22 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Python-Eggs 2014-02-20 22:21 - 2014-02-20 22:23 - 00000000 ____D () C:\Users\Yannik\Documents\BitLord 2014-02-20 22:20 - 2014-02-21 00:53 - 00000000 ____D () C:\Program Files (x86)\BitLord 2 2014-02-20 22:14 - 2014-02-20 22:14 - 00002035 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-02-20 22:14 - 2014-02-20 22:14 - 00000000 ____D () C:\ProgramData\McAfee 2014-02-20 22:13 - 2014-02-20 22:13 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-02-20 22:12 - 2014-02-20 22:15 - 00000000 ____D () C:\ProgramData\Adobe 2014-02-19 15:42 - 2014-02-19 15:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-19 00:26 - 2014-02-26 21:14 - 00000000 ____D () C:\ProgramData\WPM 2014-02-19 00:26 - 2014-02-26 21:09 - 00000000 ____D () C:\ProgramData\IePluginService 2014-02-19 00:26 - 2014-02-19 13:56 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\awesomehp 2014-02-19 00:26 - 2014-02-19 00:26 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-02-19 00:25 - 2014-02-19 14:10 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Lollipop 2014-02-19 00:20 - 2014-02-19 00:20 - 00000000 ____D () C:\Users\Yannik\Documents\Electronic Arts 2014-02-19 00:06 - 2014-02-21 14:50 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-02-18 23:49 - 2014-02-21 18:29 - 00000000 ____D () C:\Users\Yannik\Desktop\Sims 3 2014-02-18 23:46 - 2014-02-18 23:46 - 00381440 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2014-02-17 23:00 - 2014-02-17 23:00 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys 2014-02-17 16:36 - 2014-02-17 16:36 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE 2014-02-17 15:51 - 2014-02-17 23:03 - 00000000 ____D () C:\Users\Yannik\Desktop\Iso erstellen und lesen 2014-02-17 15:38 - 2014-02-17 22:39 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ImgBurn 2014-02-17 15:38 - 2014-02-17 15:38 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\ImgBurn 2014-02-17 15:36 - 2014-02-17 22:39 - 00000000 ____D () C:\Program Files (x86)\ImgBurn 2014-02-17 05:23 - 2014-02-17 05:23 - 00000000 ____D () C:\Users\Public\Documents\DAEMON Tools Images 2014-02-17 05:20 - 2014-02-18 23:06 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite 2014-02-17 05:20 - 2014-02-17 23:03 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\DAEMON Tools Lite 2014-02-17 05:20 - 2014-02-17 23:00 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite 2014-02-17 05:11 - 2014-02-17 05:11 - 00003164 _____ () C:\Windows\System32\Tasks\{3C6452EF-D53B-48D5-AA6D-CB017685DF7C} 2014-02-17 01:31 - 2014-02-17 01:31 - 00276992 _____ (IntelleSoft) C:\Windows\SysWOW64\BugTrap.dll 2014-02-17 01:30 - 2013-11-25 14:44 - 00019392 _____ (Dll-Files.com) C:\Windows\system32\roboot64.exe 2014-02-17 01:04 - 2014-03-03 21:34 - 00000000 ____D () C:\Program Files (x86)\Prompt Downloader 2014-02-17 01:04 - 2014-02-22 01:08 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Prompt Downloader 2014-02-16 22:57 - 2014-02-16 22:57 - 00001259 _____ () C:\Users\Yannik\Desktop\Moorhuhn Piraten spielen.lnk 2014-02-16 22:57 - 2014-02-16 22:57 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Moorhuhn Piraten 2014-02-16 22:57 - 2014-02-16 22:57 - 00000000 ____D () C:\Program Files (x86)\phenomedia 2014-02-16 22:57 - 2014-02-16 22:57 - 00000000 ____D () C:\Program Files (x86)\bellaundben 2014-02-16 22:16 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-16 22:16 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-16 22:15 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-16 22:15 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-16 22:15 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-16 22:15 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-16 22:15 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-16 22:15 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-16 22:15 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-16 22:15 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-16 22:15 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-16 22:15 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-16 22:15 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-16 22:15 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-16 22:15 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-16 22:15 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-16 22:15 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-16 22:15 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-16 22:15 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-16 22:15 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-16 22:15 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-16 22:15 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-16 22:15 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-16 22:15 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-16 22:15 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-16 22:15 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-16 22:15 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-16 22:15 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-16 22:15 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-16 22:15 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-16 22:15 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-16 22:15 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-16 22:15 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-16 22:15 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-16 22:15 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-16 22:15 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-16 22:15 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-16 22:15 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-16 22:15 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-16 22:15 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-16 22:15 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-16 22:15 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-16 22:15 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-16 22:15 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-16 22:15 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-16 22:14 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-16 22:14 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-16 21:27 - 2014-03-07 23:26 - 00000000 ____D () C:\Windows\pss 2014-02-16 20:07 - 2014-02-16 20:44 - 00000000 ____D () C:\Program Files (x86)\Usenet.nl 2014-02-16 20:07 - 2014-02-16 20:22 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Usenet.nl 2014-02-14 15:19 - 2014-03-08 00:18 - 00000189 _____ () C:\siw_debug.txt 2014-02-14 15:17 - 2014-02-14 15:17 - 00001083 _____ () C:\Users\Yannik\Desktop\SIW Home Edition.lnk 2014-02-14 15:17 - 2014-02-14 15:17 - 00000000 ____D () C:\Users\Yannik\AppData\Local\CrashRpt 2014-02-14 15:17 - 2014-02-14 15:17 - 00000000 ____D () C:\Program Files (x86)\SIW 2013 Home Edition 2014-02-14 12:18 - 2014-02-14 14:26 - 00000000 ____D () C:\2c20cb04415d5ee36daf4cf548 2014-02-12 23:39 - 2014-02-12 23:39 - 00000000 ____D () C:\Users\Yannik\Documents\Eidos 2014-02-12 14:25 - 2014-02-12 19:59 - 00000000 ____D () C:\Users\Yannik\Desktop\Verkauf 2014-02-11 21:29 - 2014-02-14 14:26 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\CrystalSpace 2014-02-11 20:43 - 2014-02-11 20:43 - 00000000 ____D () C:\Program Files (x86)\Wicked Studios 2014-02-11 13:06 - 2014-02-11 13:09 - 00000000 ____D () C:\Program Files (x86)\Mobogenie 2014-02-11 13:01 - 2014-02-11 13:24 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Beamrise 2014-02-11 12:59 - 2014-02-16 21:03 - 00000000 ____D () C:\Program Files (x86)\Iminent 2014-02-11 12:50 - 2014-02-11 12:51 - 00000000 ____D () C:\Users\Yannik\AppData\Local\QuickPar 2014-02-11 12:45 - 2014-02-14 14:26 - 00000000 ____D () C:\Program Files (x86)\QuickPar 2014-02-11 12:45 - 2014-02-11 12:45 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar 2014-02-11 12:25 - 2014-02-14 14:26 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\PTS 2014-02-10 23:43 - 2014-02-16 20:13 - 00000000 ____D () C:\Users\Yannik\Documents\Usenet.nl 2014-02-10 23:15 - 2014-03-08 01:01 - 00000360 _____ () C:\Windows\Tasks\AmiUpdXp.job 2014-02-10 23:15 - 2014-02-14 14:26 - 00000000 ____D () C:\Users\Yannik\AppData\Local\SwvUpdater 2014-02-10 23:15 - 2014-02-10 23:15 - 00003382 _____ () C:\Windows\System32\Tasks\AmiUpdXp 2014-02-10 23:09 - 2014-02-28 23:05 - 00000000 ____D () C:\Program Files\SavingsbullFilter 2014-02-10 23:09 - 2014-02-10 23:09 - 00000000 ____D () C:\Program Files\Level Quality Watcher 2014-02-10 23:00 - 2014-02-14 14:26 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Windows Net Data ==================== One Month Modified Files and Folders ======= 2014-03-08 01:06 - 2014-03-08 01:06 - 00022338 _____ () C:\Users\Yannik\Downloads\FRST.txt 2014-03-08 01:06 - 2014-03-08 01:05 - 00000000 ____D () C:\FRST 2014-03-08 01:05 - 2014-03-08 01:04 - 02156544 _____ (Farbar) C:\Users\Yannik\Downloads\FRST64.exe 2014-03-08 01:05 - 2013-06-01 23:33 - 01101329 _____ () C:\Windows\WindowsUpdate.log 2014-03-08 01:01 - 2014-03-03 21:49 - 00000450 ____H () C:\Windows\Tasks\WS-Booster-S-975730335.job 2014-03-08 01:01 - 2014-03-01 00:05 - 00000438 ____H () C:\Windows\Tasks\WS-Booster-S-46480778.job 2014-03-08 01:01 - 2014-02-10 23:15 - 00000360 _____ () C:\Windows\Tasks\AmiUpdXp.job 2014-03-08 01:01 - 2013-08-07 20:11 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-08 01:01 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-08 01:01 - 2009-07-14 05:51 - 00052407 _____ () C:\Windows\setupact.log 2014-03-08 01:00 - 2014-03-08 01:00 - 00000584 _____ () C:\Users\Yannik\Downloads\defogger_disable.log 2014-03-08 01:00 - 2014-03-08 01:00 - 00000020 _____ () C:\Users\Yannik\defogger_reenable 2014-03-08 01:00 - 2013-06-01 23:50 - 00000000 ____D () C:\Users\Yannik 2014-03-08 00:59 - 2014-03-08 00:59 - 00050477 _____ () C:\Users\Yannik\Downloads\Defogger.exe 2014-03-08 00:45 - 2009-07-14 05:45 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-08 00:45 - 2009-07-14 05:45 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-08 00:18 - 2014-02-14 15:19 - 00000189 _____ () C:\siw_debug.txt 2014-03-08 00:01 - 2013-06-03 15:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-07 23:54 - 2013-06-04 10:48 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-07 23:54 - 2013-06-04 10:48 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-07 23:38 - 2014-03-07 23:38 - 00709421 _____ (Virtuoza ) C:\Users\Yannik\Downloads\msconfig-cleanup-setup.exe 2014-03-07 23:38 - 2014-03-07 23:38 - 00000000 ____D () C:\Program Files (x86)\MSConfig CleanUp 2014-03-07 23:36 - 2013-06-29 20:08 - 00000000 ____D () C:\Windows\PCHEALTH 2014-03-07 23:34 - 2013-08-07 20:11 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-07 23:26 - 2014-02-16 21:27 - 00000000 ____D () C:\Windows\pss 2014-03-07 23:14 - 2013-06-07 20:02 - 00032306 _____ () C:\Windows\PFRO.log 2014-03-07 15:14 - 2014-03-07 15:14 - 00000000 ____D () C:\ProgramData\CoupExteNSion 2014-03-07 15:14 - 2014-03-01 00:04 - 00000000 ____D () C:\ProgramData\d71360f8168276b3 2014-03-05 17:26 - 2014-03-01 00:31 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\BitComet 2014-03-05 16:27 - 2014-03-05 16:27 - 00000000 ____D () C:\Users\Yannik\Desktop\Spiele 2014-03-05 13:36 - 2014-03-04 18:21 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\AutoIt3 2014-03-05 12:00 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-05 03:01 - 2013-06-03 18:16 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-05 03:01 - 2013-06-01 13:44 - 00000000 ____D () C:\ProgramData\Skype 2014-03-05 00:50 - 2014-03-05 00:50 - 00000558 _____ () C:\Users\Yannik\Desktop\Vietcong 2.lnk 2014-03-05 00:47 - 2014-03-05 00:47 - 00098304 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll 2014-03-05 00:47 - 2013-06-07 21:40 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-03-04 18:21 - 2014-03-04 18:21 - 42011090 _____ () C:\Users\Yannik\AppData\Roaming\launcher.exe 2014-03-04 18:21 - 2014-03-04 18:21 - 00933768 _____ (DivX, LLC) C:\Users\Yannik\AppData\Roaming\divx.exe 2014-03-04 18:21 - 2014-03-04 18:21 - 00000000 ____D () C:\ProgramData\DivX 2014-03-04 17:57 - 2013-06-03 18:16 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Skype 2014-03-04 17:49 - 2014-03-03 21:10 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Oxy 2014-03-03 23:09 - 2014-03-03 21:12 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Oxy 2014-03-03 23:09 - 2013-06-01 23:51 - 00000000 ___RD () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-03 22:53 - 2014-03-03 22:53 - 00003520 _____ () C:\Windows\System32\Tasks\RunAsStdUser Task 2014-03-03 22:53 - 2014-01-26 14:42 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Chromium 2014-03-03 21:49 - 2014-03-03 21:49 - 00002696 _____ () C:\Windows\System32\Tasks\WS-Booster-S-975730335 2014-03-03 21:49 - 2014-03-03 21:49 - 00000000 ____D () C:\ProgramData\Right Soft 2014-03-03 21:49 - 2014-03-01 00:04 - 00000000 ____D () C:\ProgramData\InstallMate 2014-03-03 21:48 - 2014-03-03 21:48 - 00000000 ____D () C:\ProgramData\websuave 2014-03-03 21:48 - 2014-03-03 21:48 - 00000000 ____D () C:\Program Files (x86)\websuave 2014-03-03 21:48 - 2014-03-01 00:05 - 00000000 ____D () C:\Program Files (x86)\WS-Booster 2014-03-03 21:34 - 2014-02-17 01:04 - 00000000 ____D () C:\Program Files (x86)\Prompt Downloader 2014-03-01 21:52 - 2014-03-01 03:34 - 00004917 _____ () C:\Users\Yannik\Documents\TombRaider.log 2014-03-01 03:34 - 2014-03-01 03:34 - 00000000 ____D () C:\Users\Yannik\AppData\Local\SKIDROW 2014-03-01 03:04 - 2014-03-01 02:56 - 00000000 ____D () C:\Games 2014-03-01 00:31 - 2014-03-01 00:30 - 00000000 ____D () C:\Program Files (x86)\BitComet 2014-03-01 00:11 - 2014-03-01 00:06 - 00000000 ____D () C:\ProgramData\SNT 2014-03-01 00:11 - 2014-03-01 00:06 - 00000000 ____D () C:\Program Files (x86)\SNT 2014-03-01 00:10 - 2014-03-01 00:05 - 00002684 _____ () C:\Windows\System32\Tasks\WS-Booster-S-46480778 2014-03-01 00:10 - 2014-03-01 00:05 - 00000000 ____D () C:\ProgramData\websave 2014-03-01 00:10 - 2014-03-01 00:05 - 00000000 ____D () C:\Program Files (x86)\websave 2014-03-01 00:08 - 2014-03-01 00:08 - 00052987 _____ () C:\tomb-raider-2013-pc-game-full-version.html 2014-03-01 00:07 - 2014-03-01 00:07 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\EZDownloader 2014-03-01 00:06 - 2014-03-01 00:05 - 00000000 ____D () C:\ProgramData\SafeSoft 2014-03-01 00:05 - 2014-03-01 00:05 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Packages 2014-03-01 00:05 - 2014-03-01 00:05 - 00000000 ____D () C:\ProgramData\YoutubeAdblocker 2014-03-01 00:05 - 2014-03-01 00:05 - 00000000 ____D () C:\Program Files (x86)\YoutubeAdblocker 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Torch 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Comodo 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Gast\AppData\Local\Torch 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Gast 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-03-01 00:04 - 2014-03-01 00:04 - 00000000 ____D () C:\Users\Administrator 2014-03-01 00:04 - 2013-08-07 20:11 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Google 2014-02-28 23:06 - 2014-02-27 22:27 - 00000000 ____D () C:\Program Files (x86)\MediaViewV1 2014-02-28 23:06 - 2014-02-26 13:40 - 00000000 ____D () C:\Program Files (x86)\MediaViewerV1 2014-02-28 23:05 - 2014-02-21 16:17 - 27137357 _____ () C:\Windows\system32\SavingsBullFilterService.log 2014-02-28 23:05 - 2014-02-10 23:09 - 00000000 ____D () C:\Program Files\SavingsbullFilter 2014-02-28 22:59 - 2014-02-28 22:59 - 00003120 _____ () C:\Windows\System32\Tasks\YourFile DownloaderUpdate 2014-02-28 22:59 - 2014-02-28 22:59 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\YourFileDownloader 2014-02-28 22:37 - 2014-02-28 22:37 - 00000000 _____ () C:\Windows\DXT44AE.tmp 2014-02-28 22:37 - 2013-07-18 23:27 - 00001617 _____ () C:\Windows\DirectX.log 2014-02-28 22:27 - 2014-02-28 22:27 - 00003162 _____ () C:\Windows\System32\Tasks\{E83CB6D7-71ED-4C27-B3D5-6A28CA10FB18} 2014-02-28 22:25 - 2014-02-28 22:25 - 00000000 ____D () C:\Program Files (x86)\directx 2014-02-28 22:25 - 2014-02-28 22:25 - 00000000 _____ () C:\Windows\DXT5A30.tmp 2014-02-27 22:28 - 2014-02-27 22:28 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-02-27 22:28 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-02-27 22:28 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-02-26 21:14 - 2014-02-19 00:26 - 00000000 ____D () C:\ProgramData\WPM 2014-02-26 21:10 - 2013-06-03 15:23 - 00000000 ____D () C:\Users\Yannik\AppData\Local\LogMeIn Hamachi 2014-02-26 21:09 - 2014-02-19 00:26 - 00000000 ____D () C:\ProgramData\IePluginService 2014-02-26 21:08 - 2009-07-14 18:58 - 00698784 _____ () C:\Windows\system32\perfh007.dat 2014-02-26 21:08 - 2009-07-14 18:58 - 00149088 _____ () C:\Windows\system32\perfc007.dat 2014-02-26 21:08 - 2009-07-14 06:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-26 21:03 - 2014-02-26 21:02 - 00000000 ____D () C:\Users\Yannik\Desktop\Chemie 2014-02-25 08:01 - 2009-07-14 05:45 - 00345872 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-24 20:36 - 2013-06-03 14:56 - 00077184 _____ () C:\Users\Yannik\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-24 20:34 - 2014-02-24 20:34 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\OpenOffice 2014-02-24 20:34 - 2014-02-24 20:33 - 00000000 ___SD () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1 2014-02-24 20:33 - 2014-02-24 20:33 - 00001188 _____ () C:\Users\Yannik\Desktop\OpenOffice 4.0.1.lnk 2014-02-24 20:33 - 2014-02-24 20:32 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-02-24 20:31 - 2014-02-24 20:31 - 00000000 ____D () C:\Users\Yannik\Desktop\OpenOffice 4.0.1 (de) Installation Files 2014-02-24 12:37 - 2014-02-24 12:35 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 2014-02-24 12:36 - 2014-02-24 12:34 - 00000000 _____ () C:\END 2014-02-24 12:35 - 2014-02-24 12:35 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Conduit 2014-02-24 12:35 - 2014-02-24 12:35 - 00000000 ____D () C:\Program Files\Conduit 2014-02-24 12:35 - 2014-02-24 12:35 - 00000000 ____D () C:\Program Files (x86)\Conduit 2014-02-22 01:08 - 2014-02-17 01:04 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Prompt Downloader 2014-02-21 21:15 - 2014-02-21 15:05 - 00002973 _____ () C:\Users\Yannik\Desktop\Sims 3 - Late Night.lnk 2014-02-21 18:29 - 2014-02-18 23:49 - 00000000 ____D () C:\Users\Yannik\Desktop\Sims 3 2014-02-21 18:09 - 2014-02-21 04:45 - 00000000 ____D () C:\Users\Yannik\The Sims 3 Ultimate Bundle 2014-02-21 16:17 - 2014-02-21 16:17 - 00000000 _____ () C:\Windows\SysWOW64\Service.log 2014-02-21 16:17 - 2014-02-21 16:17 - 00000000 _____ () C:\Windows\system32\Service.log 2014-02-21 14:56 - 2014-02-21 14:56 - 00003208 _____ () C:\Windows\System32\Tasks\{CC3FA791-CB61-435E-BBDA-7C0A330D47DD} 2014-02-21 14:50 - 2014-02-19 00:06 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-02-21 14:50 - 2013-06-03 14:46 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-02-21 02:01 - 2013-06-03 15:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-21 02:01 - 2013-06-03 14:52 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-21 02:01 - 2013-06-03 14:52 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-21 00:53 - 2014-02-20 22:20 - 00000000 ____D () C:\Program Files (x86)\BitLord 2 2014-02-21 00:37 - 2014-02-20 23:14 - 00000000 ____D () C:\Users\Yannik\Desktop\Sims 3 Alle Cracks 2014-02-21 00:34 - 2014-02-20 23:57 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-02-21 00:13 - 2014-02-20 22:22 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\BitLord 2014-02-20 23:52 - 2014-02-20 23:42 - 00000000 ____D () C:\ProgramData\Origin 2014-02-20 23:51 - 2014-02-20 23:46 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Origin 2014-02-20 22:23 - 2014-02-20 22:21 - 00000000 ____D () C:\Users\Yannik\Documents\BitLord 2014-02-20 22:22 - 2014-02-20 22:22 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Python-Eggs 2014-02-20 22:15 - 2014-02-20 22:12 - 00000000 ____D () C:\ProgramData\Adobe 2014-02-20 22:15 - 2013-06-03 14:53 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Adobe 2014-02-20 22:15 - 2013-06-03 14:52 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Adobe 2014-02-20 22:14 - 2014-02-20 22:14 - 00002035 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-02-20 22:14 - 2014-02-20 22:14 - 00000000 ____D () C:\ProgramData\McAfee 2014-02-20 22:13 - 2014-02-20 22:13 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-02-20 20:01 - 2014-01-22 23:48 - 00000000 ____D () C:\Gamigo 2014-02-20 12:10 - 2013-06-03 15:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-19 15:42 - 2014-02-19 15:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-19 14:12 - 2013-07-15 00:24 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line 2014-02-19 14:11 - 2014-01-26 14:03 - 00000000 ____D () C:\ProgramData\HappyCloud 2014-02-19 14:11 - 2013-07-15 00:24 - 00000000 ____D () C:\Program Files\Image-Line 2014-02-19 14:11 - 2013-07-15 00:20 - 00000000 ____D () C:\Program Files (x86)\Image-Line 2014-02-19 14:10 - 2014-02-19 00:25 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Lollipop 2014-02-19 13:56 - 2014-02-19 00:26 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\awesomehp 2014-02-19 13:56 - 2013-06-01 23:51 - 00001437 _____ () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-19 00:26 - 2014-02-19 00:26 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-02-19 00:20 - 2014-02-19 00:20 - 00000000 ____D () C:\Users\Yannik\Documents\Electronic Arts 2014-02-18 23:46 - 2014-02-18 23:46 - 00381440 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2014-02-18 23:06 - 2014-02-17 05:20 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite 2014-02-18 23:06 - 2013-05-31 17:40 - 00000000 ____D () C:\Users\XeVizZ.Yannik-PC 2014-02-18 23:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-02-17 23:29 - 2013-08-07 20:11 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-17 23:29 - 2013-08-07 20:11 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-17 23:03 - 2014-02-17 15:51 - 00000000 ____D () C:\Users\Yannik\Desktop\Iso erstellen und lesen 2014-02-17 23:03 - 2014-02-17 05:20 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\DAEMON Tools Lite 2014-02-17 23:00 - 2014-02-17 23:00 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys 2014-02-17 23:00 - 2014-02-17 05:20 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite 2014-02-17 22:39 - 2014-02-17 15:38 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ImgBurn 2014-02-17 22:39 - 2014-02-17 15:36 - 00000000 ____D () C:\Program Files (x86)\ImgBurn 2014-02-17 16:36 - 2014-02-17 16:36 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE 2014-02-17 15:38 - 2014-02-17 15:38 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\ImgBurn 2014-02-17 05:23 - 2014-02-17 05:23 - 00000000 ____D () C:\Users\Public\Documents\DAEMON Tools Images 2014-02-17 05:11 - 2014-02-17 05:11 - 00003164 _____ () C:\Windows\System32\Tasks\{3C6452EF-D53B-48D5-AA6D-CB017685DF7C} 2014-02-17 01:31 - 2014-02-17 01:31 - 00276992 _____ (IntelleSoft) C:\Windows\SysWOW64\BugTrap.dll 2014-02-16 22:57 - 2014-02-16 22:57 - 00001259 _____ () C:\Users\Yannik\Desktop\Moorhuhn Piraten spielen.lnk 2014-02-16 22:57 - 2014-02-16 22:57 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Moorhuhn Piraten 2014-02-16 22:57 - 2014-02-16 22:57 - 00000000 ____D () C:\Program Files (x86)\phenomedia 2014-02-16 22:57 - 2014-02-16 22:57 - 00000000 ____D () C:\Program Files (x86)\bellaundben 2014-02-16 22:23 - 2013-07-18 23:25 - 01595182 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-16 21:03 - 2014-02-11 12:59 - 00000000 ____D () C:\Program Files (x86)\Iminent 2014-02-16 20:44 - 2014-02-16 20:07 - 00000000 ____D () C:\Program Files (x86)\Usenet.nl 2014-02-16 20:22 - 2014-02-16 20:07 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Usenet.nl 2014-02-16 20:13 - 2014-02-10 23:43 - 00000000 ____D () C:\Users\Yannik\Documents\Usenet.nl 2014-02-14 15:17 - 2014-02-14 15:17 - 00001083 _____ () C:\Users\Yannik\Desktop\SIW Home Edition.lnk 2014-02-14 15:17 - 2014-02-14 15:17 - 00000000 ____D () C:\Users\Yannik\AppData\Local\CrashRpt 2014-02-14 15:17 - 2014-02-14 15:17 - 00000000 ____D () C:\Program Files (x86)\SIW 2013 Home Edition 2014-02-14 14:26 - 2014-02-14 12:18 - 00000000 ____D () C:\2c20cb04415d5ee36daf4cf548 2014-02-14 14:26 - 2014-02-11 21:29 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\CrystalSpace 2014-02-14 14:26 - 2014-02-11 12:45 - 00000000 ____D () C:\Program Files (x86)\QuickPar 2014-02-14 14:26 - 2014-02-11 12:25 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\PTS 2014-02-14 14:26 - 2014-02-10 23:15 - 00000000 ____D () C:\Users\Yannik\AppData\Local\SwvUpdater 2014-02-14 14:26 - 2014-02-10 23:00 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Windows Net Data 2014-02-13 16:34 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-02-13 16:33 - 2014-01-26 14:17 - 00000000 ____D () C:\Users\Yannik\Documents\The Lord of the Rings Online 2014-02-13 16:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2014-02-13 00:43 - 2014-01-26 14:04 - 00000000 ____D () C:\ProgramData\Turbine 2014-02-12 23:39 - 2014-02-12 23:39 - 00000000 ____D () C:\Users\Yannik\Documents\Eidos 2014-02-12 19:59 - 2014-02-12 14:25 - 00000000 ____D () C:\Users\Yannik\Desktop\Verkauf 2014-02-11 20:43 - 2014-02-11 20:43 - 00000000 ____D () C:\Program Files (x86)\Wicked Studios 2014-02-11 13:24 - 2014-02-11 13:01 - 00000000 ____D () C:\Users\Yannik\AppData\Local\Beamrise 2014-02-11 13:09 - 2014-02-11 13:06 - 00000000 ____D () C:\Program Files (x86)\Mobogenie 2014-02-11 12:51 - 2014-02-11 12:50 - 00000000 ____D () C:\Users\Yannik\AppData\Local\QuickPar 2014-02-11 12:45 - 2014-02-11 12:45 - 00000000 ____D () C:\Users\Yannik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar 2014-02-10 23:19 - 2013-09-25 15:06 - 00003078 _____ () C:\Windows\System32\Tasks\GoforFilesUpdate 2014-02-10 23:15 - 2014-02-10 23:15 - 00003382 _____ () C:\Windows\System32\Tasks\AmiUpdXp 2014-02-10 23:09 - 2014-02-10 23:09 - 00000000 ____D () C:\Program Files\Level Quality Watcher 2014-02-06 13:16 - 2014-02-16 22:15 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-16 22:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-16 22:15 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-16 22:15 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-16 22:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-16 22:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-16 22:15 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-16 22:15 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-16 22:15 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-16 22:15 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-16 22:15 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-16 22:15 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-16 22:15 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-16 22:15 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-16 22:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-16 22:15 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-16 22:15 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-16 22:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-16 22:15 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-16 22:15 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-16 22:15 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-16 22:15 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-16 22:15 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-16 22:15 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-16 22:15 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-16 22:15 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-16 22:15 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-16 22:15 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-16 22:15 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-16 22:15 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-16 22:15 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-16 22:15 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-16 22:15 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-16 22:15 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-16 22:15 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-16 22:15 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-16 22:15 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-16 22:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-16 22:15 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Files to move or delete: ==================== C:\Users\Yannik\Minecraft.exe Some content of TEMP: ==================== C:\Users\XeVizZ.Yannik-PC\AppData\Local\Temp\msxml6-KB927977-enu-amd64.exe C:\Users\XeVizZ.Yannik-PC\AppData\Local\Temp\msxml6-KB927977-enu-x86.exe C:\Users\XeVizZ.Yannik-PC\AppData\Local\Temp\swt-win32-3740.dll C:\Users\Yannik\AppData\Local\Temp\6_Offer_12.exe C:\Users\Yannik\AppData\Local\Temp\amazonicon_v4.exe C:\Users\Yannik\AppData\Local\Temp\BackupSetup.exe C:\Users\Yannik\AppData\Local\Temp\bitool.dll C:\Users\Yannik\AppData\Local\Temp\CheatEngine63Clean.exe C:\Users\Yannik\AppData\Local\Temp\DeltaTB.exe C:\Users\Yannik\AppData\Local\Temp\dlLogic.exe C:\Users\Yannik\AppData\Local\Temp\down.4476.ext_setup.exe C:\Users\Yannik\AppData\Local\Temp\downloader.dll C:\Users\Yannik\AppData\Local\Temp\DownloadManager.exe C:\Users\Yannik\AppData\Local\Temp\drm_dialogs.dll C:\Users\Yannik\AppData\Local\Temp\DSETUP.dll C:\Users\Yannik\AppData\Local\Temp\dsetup32.dll C:\Users\Yannik\AppData\Local\Temp\DXSETUP.exe C:\Users\Yannik\AppData\Local\Temp\EnableExtDll.dll C:\Users\Yannik\AppData\Local\Temp\FileSystemView.dll C:\Users\Yannik\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Yannik\AppData\Local\Temp\hcuninstaller_20140213_004205_3512.exe C:\Users\Yannik\AppData\Local\Temp\htmlayout.dll C:\Users\Yannik\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Yannik\AppData\Local\Temp\nsa937C.exe C:\Users\Yannik\AppData\Local\Temp\nsj2D2.exe C:\Users\Yannik\AppData\Local\Temp\nsjF7D9.exe C:\Users\Yannik\AppData\Local\Temp\nsk8DCA.exe C:\Users\Yannik\AppData\Local\Temp\nskE837.exe C:\Users\Yannik\AppData\Local\Temp\nsr2921.exe C:\Users\Yannik\AppData\Local\Temp\nsu3407.exe C:\Users\Yannik\AppData\Local\Temp\nsu888B.exe C:\Users\Yannik\AppData\Local\Temp\nsuAB0.exe C:\Users\Yannik\AppData\Local\Temp\nsuE20E.exe C:\Users\Yannik\AppData\Local\Temp\nsuF062.exe C:\Users\Yannik\AppData\Local\Temp\nsz3A3F.exe C:\Users\Yannik\AppData\Local\Temp\nsz3ED2.exe C:\Users\Yannik\AppData\Local\Temp\nsz810B.exe C:\Users\Yannik\AppData\Local\Temp\OptimizerPro_20140120.exe C:\Users\Yannik\AppData\Local\Temp\pricepeep_130001_0101.exe C:\Users\Yannik\AppData\Local\Temp\pyl496F.tmp.exe C:\Users\Yannik\AppData\Local\Temp\sdanircmdc.exe C:\Users\Yannik\AppData\Local\Temp\sdapskill.exe C:\Users\Yannik\AppData\Local\Temp\sdaspwn.exe C:\Users\Yannik\AppData\Local\Temp\setup.exe C:\Users\Yannik\AppData\Local\Temp\setup_80.exe C:\Users\Yannik\AppData\Local\Temp\setup_ra.exe C:\Users\Yannik\AppData\Local\Temp\SkypeSetup.exe C:\Users\Yannik\AppData\Local\Temp\Theme Park Manager__3515_i348065212_il4266426.exe C:\Users\Yannik\AppData\Local\Temp\tmp194A.exe C:\Users\Yannik\AppData\Local\Temp\tmp1DA4.exe C:\Users\Yannik\AppData\Local\Temp\tmp8CBD.exe C:\Users\Yannik\AppData\Local\Temp\tmpAEED.exe C:\Users\Yannik\AppData\Local\Temp\tmpC5A9.exe C:\Users\Yannik\AppData\Local\Temp\tmpDB6D.exe C:\Users\Yannik\AppData\Local\Temp\tmpE662.exe C:\Users\Yannik\AppData\Local\Temp\tmpF114.exe C:\Users\Yannik\AppData\Local\Temp\tmpF30.exe C:\Users\Yannik\AppData\Local\Temp\tmpFB99.exe C:\Users\Yannik\AppData\Local\Temp\tmpFC6.exe C:\Users\Yannik\AppData\Local\Temp\toolbar19041731.exe C:\Users\Yannik\AppData\Local\Temp\toolbar4434734.exe C:\Users\Yannik\AppData\Local\Temp\toolbar5902266.exe C:\Users\Yannik\AppData\Local\Temp\Tsu06739597.dll C:\Users\Yannik\AppData\Local\Temp\un2334.exe C:\Users\Yannik\AppData\Local\Temp\un32307.exe C:\Users\Yannik\AppData\Local\Temp\un32405.exe C:\Users\Yannik\AppData\Local\Temp\un633.exe C:\Users\Yannik\AppData\Local\Temp\uninstall19108390.exe C:\Users\Yannik\AppData\Local\Temp\uninstall19118546.exe C:\Users\Yannik\AppData\Local\Temp\uninstall19118562.exe C:\Users\Yannik\AppData\Local\Temp\uninstall4551438.exe C:\Users\Yannik\AppData\Local\Temp\UninstallEADM.dll C:\Users\Yannik\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-04 01:19 ==================== End Of Log ============================ |