|
Log-Analyse und Auswertung: cpu 100% und exe lassen sich nicht öffenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
06.06.2014, 13:53 | #16 |
| cpu 100% und exe lassen sich nicht öffen hallo Jürgen anti-malware lässt sich nicht install "interner fehler:expression error runtime error (at79:177) external exception E06D7363. |
06.06.2014, 13:54 | #17 |
/// TB-Ausbilder /// Anleitungs-Guru | cpu 100% und exe lassen sich nicht öffen Das hattest doch schon drauf oder? Und auch Avira. Deinstalliert?
__________________
__________________ |
06.06.2014, 13:59 | #18 |
| cpu 100% und exe lassen sich nicht öffen Ja lässt sich nicht starten
__________________avira startet auch nicht lässt sich auch nicht deinstall |
06.06.2014, 14:01 | #19 |
/// TB-Ausbilder /// Anleitungs-Guru | cpu 100% und exe lassen sich nicht öffen Schritt 1 Bitte starte FRST erneut, setze den Haken auch bei Addition.txt und drücke auf Scan. Poste mir bitte beide Logs.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
06.06.2014, 14:05 | #20 |
| cpu 100% und exe lassen sich nicht öffenFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:06-06-2014 Ran by Mafia (administrator) on MAFIA-PC on 06-06-2014 15:02:37 Running from C:\Users\Mafia\Desktop Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchService.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\Box\Box Sync\FSEventsReader.exe (Box Inc.) C:\Program Files\Box\Box Sync\SyncUpdaterService.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe (LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe () C:\Program Files\Core Temp\Core Temp.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Google Inc.) C:\Program Files\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe () C:\Program Files\Unlocker\UnlockerAssistant.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Nexon Korea Corp.) C:\Nexon\NexonPlug\NexonPlug.exe (AMD) C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe (Dropbox, Inc.) C:\Users\Mafia\AppData\Roaming\Dropbox\bin\Dropbox.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Nexon Corp.) C:\Nexon\NexonPlug\NMService.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11930696 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [748256 2014-04-17] (Advanced Micro Devices, Inc.) HKLM\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-05-13] (LogMeIn Inc.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.) HKLM\...\Run: [UnlockerAssistant] => C:\Program Files\Unlocker\UnlockerAssistant.exe [17408 2010-07-04] () HKU\.DEFAULT\...\CurrentVersion\Windows: [Load] C:\Windows\system32\Microsoft.com <===== ATTENTION HKU\S-1-5-21-2278640974-4239821988-345242402-1001\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.) HKU\S-1-5-21-2278640974-4239821988-345242402-1001\...\Run: [NexonPlug] => C:\Nexon\NexonPlug\NexonPlug.exe [2115928 2014-04-23] (Nexon Korea Corp.) HKU\S-1-5-21-2278640974-4239821988-345242402-1001\...\Run: [HydraVisionDesktopManager] => C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe [389120 2014-01-31] (AMD) Startup: C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Mafia\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD07716838EA3CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3326569&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SPDC5C3546-B0DD-4CE4-AD10-187D28F005A7&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} BHO: Promt IE Helper - {1F13CE11-4FAC-49A9-8155-D4F3F0F91A33} - C:\Program Files\PRMT10\PRMTIE\prmtie.dll (PROMT Ltd.) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO: ͬ²½Ò»¼ü°²×°Ö§³Ö - {F72C8153-7140-4FEE-8F69-CA4579D71195} - C:\Program Files\Tongbu\Addin\tbIEAddin.dll (同步网络平台) Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM - PROMT Translator - {C7DDDD27-F303-42A5-B979-51559F7DC0F0} - C:\Program Files\PRMT10\PRMTIE\prmtie.dll (PROMT Ltd.) Toolbar: HKCU - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Mafia\AppData\Roaming\Mozilla\Firefox\Profiles\pwny7wno.default-1381859675478 FF DefaultSearchEngine: Trovi search FF SearchEngineOrder.1: Yahoo FF SelectedSearchEngine: Trovi search FF Homepage: https://de.yahoo.com/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @nexon.com/NxGame - C:\ProgramData\Nexon\NGM\npnxgame.dll (Nexon) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: @tongbu.com/tongbu,version=0.1 - C:\Program Files\Tongbu\Addin\npTongbuAddin.dll (同步网络平台) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Acrobat - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Mafia\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll No File FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\testlog.txt FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahootc.xml FF Extension: PROMT - C:\Users\Mafia\AppData\Roaming\Mozilla\Firefox\Profiles\pwny7wno.default-1381859675478\Extensions\promtff9@promt9.ru [2014-05-29] FF Extension: YouTube Unblocker - C:\Users\Mafia\AppData\Roaming\Mozilla\Firefox\Profiles\pwny7wno.default-1381859675478\Extensions\youtubeunblocker@unblocker.yt [2014-04-18] FF Extension: DownloadHelper - C:\Users\Mafia\AppData\Roaming\Mozilla\Firefox\Profiles\pwny7wno.default-1381859675478\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-25] FF Extension: {11574f4a-82a7-4b99-81dc-020c5e316e55} - C:\Users\Mafia\AppData\Roaming\Mozilla\Firefox\Profiles\pwny7wno.default-1381859675478\Extensions\{11574f4a-82a7-4b99-81dc-020c5e316e55}.xpi [2014-04-19] FF Extension: Adblock Plus - C:\Users\Mafia\AppData\Roaming\Mozilla\Firefox\Profiles\pwny7wno.default-1381859675478\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-26] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-05-10] FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-05-16] FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-05-16] Chrome: ======= CHR HomePage: https://www.facebook.com/?ref=logo CHR StartupUrls: "https://www.facebook.com/", "https://www.youtube.com/feed/subscriptions", "hxxp://www.tumblr.com/dashboard", "https://twitter.com/" CHR Extension: (ProxFlow) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2014-05-15] CHR Extension: (Magic Actions for YouTube™) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2014-05-05] CHR Extension: (Google Docs) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-05] CHR Extension: (Google Drive) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-05] CHR Extension: (TV) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2014-05-05] CHR Extension: (YouTube) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-05] CHR Extension: (Adblock Plus) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-05] CHR Extension: (Google-Suche) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-05] CHR Extension: (Love O'Clock) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbcnbegbcdfdlndabgemkabfhfllocma [2014-05-05] CHR Extension: (Adobe Acrobat – PDF-Datei erstellen) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2014-05-05] CHR Extension: (Stylish) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2014-05-05] CHR Extension: (AdBlock) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-05] CHR Extension: (FVD Downloader) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2014-05-05] CHR Extension: (Surfing Day 2012) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjgigjnbamdjoeifabplldbjgbjnacki [2014-05-05] CHR Extension: (Google Wallet) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-05] CHR Extension: (Google Mail) - C:\Users\Mafia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-05] CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-05-08] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= S4 becldr3Service; C:\Program Files\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [225280 2012-08-01] () R2 BoxSyncFSEventsReaderService; C:\Program Files\Box\Box Sync\FSEventsReader.exe [13824 2013-09-09] () R2 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [18432 2013-09-09] (Box Inc.) R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation) R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1682768 2014-05-13] (LogMeIn Inc.) R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [375056 2014-04-15] (LogMeIn, Inc.) S4 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [762192 2013-07-18] (Nero AG) S4 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () S4 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) S2 HPSLPSVC; C:\Users\Mafia\AppData\Local\Temp\7zS49D6\hpslpsvc32.dll [X] S2 TuneUp.UtilitiesSvc; "C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe" [X] ==================== Drivers (Whitelisted) ==================== S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] () R3 DFX11_1; C:\Windows\System32\drivers\dfx11_1.sys [24424 2012-12-13] (Windows (R) Win 7 DDK provider) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG) R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [22560 2013-09-16] (REALiX(tm)) R3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [25712 2013-01-29] (Microsoft Corporation) R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [204432 2012-06-05] (Realtek Semiconductor Corp.) R1 wStLibG; C:\Windows\System32\drivers\wStLibG.sys [52920 2014-04-10] (StdLib) R3 ALSysIO; \??\C:\Users\Mafia\AppData\Local\Temp\ALSysIO.sys [X] S3 athr; system32\DRIVERS\athr.sys [X] S2 avgntflt; system32\DRIVERS\avgntflt.sys [X] S1 avipbb; system32\DRIVERS\avipbb.sys [X] S1 avkmgr; system32\DRIVERS\avkmgr.sys [X] S3 catchme; \??\C:\Users\Mafia\AppData\Local\Temp\catchme.sys [X] S3 dgderdrv; System32\drivers\dgderdrv.sys [X] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [198656 2010-03-31] (Huawei Technologies Co., Ltd.) S1 ssmdrv; system32\DRIVERS\ssmdrv.sys [X] S3 TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesDriver32.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ========================== Drivers MD5 ======================= C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit C:\Windows\system32\drivers\afd.sys 9EBBBA55060F786F0FCAA3893BFA2806 C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit C:\Windows\system32\drivers\djsvs.sys ==> MD5 is legit C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdagp.sys ==> MD5 is legit C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\atikmdag.sys D4EF00B622EBEBEF85AB53C51A509A14 C:\Windows\System32\DRIVERS\atikmpag.sys 0A536B713BF916E62A14D48B0C1739A3 C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit C:\Windows\system32\drivers\amdsata.sys D320BF87125326F996D4904FE24300FC C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit C:\Windows\System32\drivers\amdxata.sys 46387FB17B086D16DEA267D5BE23A2F2 C:\Windows\System32\Drivers\ssadadb.sys DD8D9C597AF7CD2F6B70A3D6A4A1ACEA C:\Windows\system32\drivers\appid.sys ==> MD5 is legit C:\Windows\system32\drivers\arc.sys ==> MD5 is legit C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit C:\Windows\System32\drivers\AtihdW73.sys 636C40DAC5D13F4C354973017AA8ADC2 C:\Windows\system32\drivers\bxvbdx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60x.sys ==> MD5 is legit C:\Windows\system32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bridge.sys 77361D72A04F18809D0EFB6CCEB74D4B C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys ==> MD5 is legit C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys 247B4CE2DAB1160CD422D532D5241E1F C:\Windows\System32\drivers\compbatt.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit C:\Program Files\SystemRequirementsLab\cpudrv.sys D01F685F8B4598D144B0CCE9FF95D8D5 C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit C:\Windows\System32\drivers\csc.sys ==> MD5 is legit C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit C:\Windows\System32\drivers\dfx11_1.sys 30384865C9AF82DB291E5C4F468E1AC6 C:\Windows\System32\DRIVERS\ssudbus.sys 560B0DCE52DFED6623B27C9BAFA6F236 C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\drivers\disk.sys ==> MD5 is legit C:\Windows\system32\drivers\dmvsc.sys 2A958EF85DB1B61FFCA65044FA4BCE9E C:\Windows\System32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\drivers\dxgkrnl.sys 16498EBC04AE9DD07049A8884B205C05 C:\Windows\system32\drivers\evbdx.sys ==> MD5 is legit C:\Windows\System32\Drivers\ElbyCDIO.sys B83BDCCBACB65BAA9E20888DD0083A16 C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit C:\Windows\system32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\system32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legitB C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\system32\Drivers\Fs_Rec.sys 7DAE5EBCC80E45D3253F4923DC424D05 C:\Windows\System32\DRIVERS\fvevol.sys E306A24D9694C724FA2491278BF50FDB C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\GEARAspiWDM.sys 185ADA973B5020655CEE342059A86CBB C:\Windows\System32\DRIVERS\ggflt.sys 93CA4D9A0433BE0EDD0B9F2F26D5E54C C:\Windows\System32\DRIVERS\ggsemc.sys 17E678AAB82CCDFB80E7614504933895 C:\Windows\System32\DRIVERS\hamachi.sys 833051C6C6C42117191935F734CFBD97 C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\System32\drivers\HdAudio.sys A5EF29D5315111C80A5C1ABAD14C8972 C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\Drivers\ANDROIDUSB.sys 950CC1E6AE3A6CD23E0945CDE089B02C C:\Windows\System32\DRIVERS\htcnprot.sys 339ADEFAD60353F960E3CA67CE468C24 C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ewusbmdm.sys 988C0A49F09D75D3341CB419141793C1 C:\Windows\system32\drivers\HWiNFO32.SYS 43E745EFA7D34ADAED455C0AA94C424A C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 is legit C:\Windows\system32\drivers\iaStorV.sys 5CD5F9A5444E6CDCB0AC89BD62D8B76E C:\Windows\System32\DRIVERS\igdkmd32.sys AD626F6964F4D364D226C39E06872DD3 C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit C:\Windows\System32\drivers\RTKVHDA.sys 82EE5914B6AB27BFD23ECA29AEB34DA4 C:\Windows\System32\drivers\intelide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit C:\Windows\system32\drivers\kbdhid.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecdd.sys B7895B4182C0D16F6EFADEB8081E8D36 C:\Windows\System32\Drivers\ksecpkg.sys D30159AC9237519FBC62C6EC247D2D46 C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mrxsmb.sys 5D16C921E3671636C0EBA3BBAAC5FD25 C:\Windows\System32\DRIVERS\mrxsmb10.sys 6D17A4791ACA19328C685D256349FEFC C:\Windows\System32\DRIVERS\mrxsmb20.sys B81F204D146000BE76651A50670A5E9E C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit C:\Windows\system32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\system32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\Windows\System32\drivers\ndis.sys 8C9C922D71F1CD4DEF73F186416B7896 C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\system32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netaapl.sys 9213AA35BCA94EB79D366DA254E4BDF5 C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit C:\Windows\system32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\system32\Drivers\Ntfs.sys 5E43D2B0EE64123D4880DFA6626DEFDE C:\Windows\System32\DRIVERS\NuidFltr.sys A82BB9014BEF0E4986C3DA610B3A25FE C:\Windows\system32\Drivers\Null.sys ==> MD5 is legit C:\Windows\system32\drivers\nvraid.sys B3E25EE28883877076E0E1FF877D02E0 C:\Windows\system32\drivers\nvstor.sys 4380E59A170D88C4F1022EFF6719A8A4 C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys 3F34A1B4C5F6475F320C275E63AFCE9B C:\Windows\System32\DRIVERS\parvdm.sys ==> MD5 is legit C:\Windows\System32\drivers\pci.sys ==> MD5 is legit C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\drivers\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpdr.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpvideominiport.sys ==> MD5 is legit C:\Windows\system32\Drivers\RDPWD.sys F031683E6D1FEA157ABB2FF260B51E61 C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\Drivers\RimUsb.sys 0F6756EF8BDA6DFA7BE50465C83132BB C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\System32\drivers\RtHDMIV.sys 79C8488DFA2AA377441645123CB73845 C:\Windows\System32\DRIVERS\Rt86win7.sys 3983CEA05BB855351D75F5482B6C42CE C:\Windows\system32\drivers\vms3cap.sys ==> MD5 is legit C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\system32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\seehcri.sys E5B56569A9F79B70314FEDE6C953641E C:\Windows\System32\DRIVERS\serenum.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\serial.sys ==> MD5 is legit C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit C:\Windows\system32\drivers\sisagp.sys ==> MD5 is legit C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\system32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\srv.sys E4C2764065D66EA1D2D3EBC28FE99C46 C:\Windows\System32\DRIVERS\srv2.sys 03F0545BD8D4C77FA0AE1CEEDFCC71AB C:\Windows\System32\DRIVERS\srvnet.sys BE6BD660CAA6F291AE06A718A4FA8ABC C:\Windows\System32\DRIVERS\ssadbus.sys 64E44ACD8C238FCBBB78F0BA4BDC4B05 C:\Windows\System32\DRIVERS\ssadmdfl.sys BB2C84A15C765DA89FD832B0E73F26CE C:\Windows\System32\DRIVERS\ssadmdm.sys 6D0D132DDC6F43EDA00DCED6D8B1CA31 C:\Windows\System32\DRIVERS\ssadserd.sys 1A5A397BC459F346AB56492B61EF79F6 C:\Windows\System32\DRIVERS\ssudmdm.sys 585FDB94DB04AC1C56298D1FD1F1389E C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 is legit C:\Windows\system32\drivers\storvsc.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit C:\Windows\system32\drivers\Synth3dVsc.sys F2AD8960812FD111E20E84659EF19D43 C:\Windows\System32\drivers\tcpip.sys 4E8B9BE71B807B3BAEDB7F4243F85E3C C:\Windows\System32\DRIVERS\tcpip.sys 4E8B9BE71B807B3BAEDB7F4243F85E3C C:\Windows\System32\drivers\tcpipreg.sys 3EEBD3BD93DA46A26E89893C7AB2FF3B C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\drivers\tdtcp.sys 2C2C5AFE7EE4F620D69C23C0617651A8 C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit C:\Windows\system32\drivers\terminpt.sys 052306FD76793D5D5AB5D9891FD1ADBB C:\Windows\System32\DRIVERS\tssecsrv.sys B37B08F2E5EEB1A37E448E09BACE1101 C:\Windows\System32\drivers\tsusbflt.sys ==> MD5 is legit C:\Windows\system32\drivers\TsUsbGD.sys 01246F0BAAD7B68EC0F472AA41E33282 C:\Windows\system32\drivers\tsusbhub.sys 045ACB987C650D8186C6B4A692223860 C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit C:\Windows\System32\Drivers\usbaapl.sys 6E421CCC57059B0186C6259CA3B6DFC9 C:\Windows\System32\DRIVERS\usbccgp.sys BD9C55D7023C5DE374507ACC7A14E2AC C:\Windows\system32\drivers\usbcir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbehci.sys F92DE757E4B7CE9C07C5E65423F3AE3B C:\Windows\System32\DRIVERS\usbhub.sys 8DC94AEC6A7E644A06135AE7506DC2E9 C:\Windows\system32\drivers\usbohci.sys E185D44FAC515A18D9DEDDC23C2CDF44 C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbscan.sys 576096CCBC07E7C4EA4F5E6686D6888F C:\Windows\System32\DRIVERS\USBSTOR.SYS F991AB9CC6B908DB552166768176896A C:\Windows\System32\DRIVERS\usbuhci.sys 68DF884CF41CDADA664BEB01DAF67E3D C:\Windows\System32\Drivers\usbvideo.sys 45F4E7BF43DB40A6C6B4D92C76CBC3F2 C:\Windows\System32\DRIVERS\usb8023x.sys AF77716205C97E902E6C5B78DECE2CCA C:\Windows\System32\DRIVERS\VClone.sys DAEF3AC067094497402C77476BBC3540 C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit C:\Windows\system32\drivers\viaagp.sys ==> MD5 is legit C:\Windows\system32\drivers\viac7.sys ==> MD5 is legit C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit C:\Windows\system32\drivers\vmbus.sys ==> MD5 is legit C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwififlt.sys 7090D3436EEB4E7DA3373090A23448F7 C:\Windows\System32\DRIVERS\wacommousefilter.sys 427A8BC96F16C40DF81C2D2F4EDD32DD C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wacomvhid.sys 846B58EA44BF8C92E4B59F4E2252C4C0 C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\system32\drivers\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys A840213F1ACDCC175B4D1D5AAEAC0D7A C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WinUsb.sys A67E5F9A400F3BD1BE3D80613B45F708 C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\drivers\wStLibG.sys 022E6B0F67F3CF1DE63502194E7D8AC7 C:\Windows\System32\drivers\WudfPf.sys 06E6F32C8D0A3F66D956F57B43A2E070 C:\Windows\System32\DRIVERS\WUDFRd.sys 867C301E8B790040AE9CF6486E8041DF C:\Windows\System32\DRIVERS\xusb21.sys C26C68BCBAC1F33F890C226769759209 ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-06 15:02 - 2014-06-06 15:02 - 00000000 ____D () C:\Users\Mafia\Desktop\FRST-OlderVersion 2014-06-06 11:43 - 2014-06-06 11:44 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-06-06 11:43 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-06 11:43 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-05 23:26 - 2014-06-06 15:03 - 00036961 _____ () C:\Users\Mafia\Desktop\FRST.txt 2014-06-05 23:26 - 2014-06-06 15:02 - 00000000 ____D () C:\FRST 2014-06-05 23:18 - 2014-06-06 15:02 - 01063424 _____ (Farbar) C:\Users\Mafia\Desktop\FRST.exe 2014-06-05 23:11 - 2014-06-05 23:26 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-06-05 23:11 - 2014-06-05 23:11 - 00107224 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-05 23:10 - 2014-06-05 23:26 - 00000000 ____D () C:\Users\Mafia\Desktop\mbar 2014-06-05 23:10 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-05 23:09 - 2014-06-05 23:09 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Mafia\Desktop\mbar-1.07.0.1009.exe 2014-06-05 22:52 - 2014-06-05 22:52 - 00030033 _____ () C:\ComboFix.txt 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\noni\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Bea\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Aileen\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Administrator\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\temp 2014-06-05 22:32 - 2014-06-05 22:32 - 00003268 _____ () C:\Users\Mafia\Desktop\prüfung.7z 2014-06-05 22:03 - 2014-06-06 15:03 - 00000000 ____D () C:\Users\Mafia\AppData\Local\temp 2014-06-05 21:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Qoobox 2014-06-05 21:52 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-05 21:52 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-05 21:52 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-05 21:52 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-05 21:52 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-05 21:52 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-05 21:52 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-05 21:52 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-05 21:51 - 2014-06-05 22:08 - 00000000 ____D () C:\Windows\erdnt 2014-06-05 21:45 - 2014-06-05 21:46 - 05205146 _____ (Swearware) C:\Users\Mafia\Downloads\ComboFix(1).exe 2014-06-05 21:44 - 2014-06-05 21:44 - 05205146 ____R (Swearware) C:\Users\Mafia\Downloads\CF.exe 2014-06-05 20:02 - 2014-06-05 20:03 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-06-05 20:01 - 2014-06-05 20:03 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Apple Computer 2014-06-05 20:01 - 2014-06-05 20:01 - 00001422 _____ () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-06-05 20:01 - 2014-06-05 20:01 - 00001016 _____ () C:\Users\Public\Desktop\Windows Media Player.lnk 2014-06-05 20:01 - 2014-06-05 20:01 - 00000020 ___SH () C:\Users\Administrator.Mafia-PC\ntuser.ini 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\Startmenü 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\Netzwerkumgebung 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\Druckumgebung 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\Documents\Eigene Musik 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\Documents\Eigene Bilder 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\AppData\Local\Verlauf 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Windows\Profiles\Default 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Roaming\WTablet 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Adobe 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\LogMeIn Hamachi 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\LogMeIn 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\Google 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\Box Sync 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\Apple Computer 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC 2014-06-05 20:01 - 2013-09-03 17:18 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Macromedia 2014-06-05 20:01 - 2013-08-29 04:27 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\Microsoft Help 2014-06-05 20:01 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-06-05 20:01 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-06-05 20:00 - 2014-05-01 03:36 - 00000000 ____D () C:\Users\Mafia\Downloads\TuneUp.Utilities.2014.v14.0.1000.296.inkl.Keygen.und.Crack.German 2014-06-05 19:51 - 2014-06-05 19:54 - 29094876 _____ () C:\Users\Mafia\Downloads\TUU.v14.0.1000.296.GER.rar 2014-06-05 19:40 - 2014-06-05 19:42 - 00000000 ____D () C:\Program Files\Unlocker 2014-06-05 19:40 - 2014-06-05 19:40 - 01078591 _____ () C:\Users\Mafia\Downloads\Unlocker1.9.2.exe 2014-06-05 19:40 - 2014-06-05 19:40 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker 2014-06-05 19:37 - 2014-06-05 19:37 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Mafia\Downloads\avira_de_av___ws.exe 2014-06-04 21:50 - 2014-06-04 21:50 - 00961360 _____ (Chip Digital GmbH) C:\Users\Mafia\Downloads\AdwCleaner - CHIP-Installer.exe 2014-06-04 21:38 - 2014-06-04 21:45 - 1204690621 _____ () C:\Users\Mafia\Downloads\iPhone3,1_7.1.1_11D201_Restore.ipsw 2014-06-04 21:29 - 2014-06-04 21:29 - 00001754 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-06-04 21:29 - 2014-06-04 21:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-06-04 21:28 - 2014-06-04 21:28 - 00000000 ____D () C:\Program Files\iPod 2014-06-04 20:44 - 2013-08-22 08:13 - 00000407 _____ () C:\Windows\system32\Drivers\etc\networks 2014-06-04 20:43 - 2014-06-04 20:43 - 00000000 ____D () C:\Windows\system32\Drivers\etc\Neuer Ordner2 2014-06-04 20:41 - 2014-06-04 20:41 - 06347938 _____ () C:\Users\Mafia\Downloads\icloud bypass gwcc1.2.6.rar 2014-06-04 20:29 - 2013-08-22 08:13 - 00017463 _____ () C:\Windows\system32\Drivers\etc\services 2014-06-04 20:29 - 2013-08-22 08:13 - 00001358 _____ () C:\Windows\system32\Drivers\etc\protocol 2014-06-04 01:54 - 2014-06-04 01:55 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Mafia\Downloads\mbam-setup-2.0.2.1012(3).exe 2014-06-04 01:53 - 2014-06-04 01:53 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Mafia\Downloads\mbam-setup-2.0.2.1012(2).exe 2014-06-04 01:44 - 2014-06-04 01:44 - 00010826 _____ () C:\Users\Mafia\Desktop\prüfung.txt 2014-06-04 01:42 - 2014-06-04 01:42 - 00010859 _____ () C:\Users\Mafia\Desktop\hijackthis.log 2014-06-04 01:37 - 2014-06-04 01:38 - 00388608 _____ (Trend Micro Inc.) C:\Users\Mafia\Downloads\hijackthis_5833.exe 2014-06-04 01:18 - 2014-06-04 01:19 - 00000980 _____ () C:\DelFix.txt 2014-06-03 14:24 - 2014-06-03 14:24 - 00000044 _____ () C:\Neues Textdokument.txt 2014-06-01 12:34 - 2014-06-01 12:35 - 00000000 ____D () C:\Users\Mafia\Desktop\Neuer Ordner (3) 2014-06-01 06:04 - 2014-06-04 04:29 - 00000000 __SHD () C:\Program Files\Windows Manager 2014-06-01 05:41 - 2014-06-01 05:41 - 17249726 _____ () C:\Users\Mafia\Downloads\Wondershare Dr.Fone 1.0.2.5 iPhone 5 + Reg Key.rar 2014-06-01 05:27 - 2014-06-01 05:28 - 37652255 _____ () C:\Users\Mafia\Downloads\dr_fone_ios[freedownloadsbywali.com].rar 2014-06-01 03:49 - 2014-06-01 04:06 - 1047527424 _____ () C:\Users\Mafia\Downloads\2315648946457894-lolwddogsrelo.part07.rar 2014-06-01 03:40 - 2014-06-01 03:40 - 00000000 _____ () C:\Users\Mafia\AppData\Roaming\p.n 2014-06-01 03:38 - 2014-06-01 06:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare 2014-06-01 03:38 - 2014-06-01 06:10 - 00000000 ____D () C:\Program Files\Wondershare 2014-06-01 03:38 - 2014-06-01 05:42 - 00000000 ___HD () C:\Program Files\Dr.Fone_Temp 2014-06-01 03:38 - 2014-06-01 03:38 - 00000000 ____D () C:\Users\Mafia\AppData\Local\Wondershare 2014-06-01 03:38 - 2014-06-01 03:38 - 00000000 ____D () C:\ProgramData\Wondershare 2014-06-01 03:38 - 2014-06-01 03:38 - 00000000 ____D () C:\Program Files\Common Files\Wondershare 2014-06-01 03:35 - 2014-06-01 03:35 - 00001048 _____ () C:\Users\Mafia\Downloads\relink.us__Wondershare_Dr.Fone_for_iOS_4.1.1.5_d113dbcd7ab4743928810899a9f375.dlc 2014-06-01 03:13 - 2014-06-01 03:30 - 1047527424 _____ () C:\Users\Mafia\Downloads\2315648946457894-lolwddogsrelo.part06.rar 2014-06-01 02:41 - 2014-06-01 02:59 - 1047527424 _____ () C:\Users\Mafia\Downloads\2315648946457894-lolwddogsrelo.part05.rar 2014-06-01 02:40 - 2014-06-01 02:40 - 00005488 _____ () C:\Users\Mafia\Downloads\9a899b3bb764b80ec902323fa9a530e9.dlc 2014-05-31 18:26 - 2014-05-31 18:26 - 00115144 _____ () C:\Users\Mafia\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-31 18:22 - 2014-05-31 18:28 - 03847328 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-05-31 01:47 - 2014-05-31 01:47 - 00029100 _____ () C:\Users\Mafia\Downloads\ipa01367_GameSave(1).zip 2014-05-31 00:12 - 2014-05-31 00:12 - 00025508 _____ () C:\Users\Mafia\Downloads\org.thebigboss.downlock_v0.1-3_iphoneos-arm.deb 2014-05-30 14:33 - 2014-05-30 14:33 - 00599791 _____ () C:\Users\Mafia\Downloads\Fairway Solitaire Blast Hack Tool.rar 2014-05-30 14:29 - 2014-05-30 14:29 - 00029100 _____ () C:\Users\Mafia\Downloads\ipa01367_GameSave.zip 2014-05-30 13:35 - 2014-05-30 13:41 - 76603164 _____ () C:\Users\Mafia\Downloads\476127375.ipa 2014-05-29 10:45 - 2014-05-29 10:45 - 00000000 ____D () C:\Users\Mafia\Desktop\Library 2014-05-29 01:47 - 2014-05-29 01:48 - 11429326 _____ () C:\Users\Mafia\Downloads\Bypass iOS7 By mohammednadhir31.rar 2014-05-29 01:07 - 2014-05-29 01:07 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_29-05-14_01-07-35.log 2014-05-29 01:04 - 2014-05-29 01:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PROMT 2014-05-29 01:03 - 2014-05-29 01:03 - 00000000 ____D () C:\ProgramData\PROMT 2014-05-29 01:03 - 2014-05-29 01:03 - 00000000 ____D () C:\Program Files\BCL Technologies 2014-05-29 01:01 - 2014-04-04 17:05 - 00000000 ____D () C:\Users\Mafia\Downloads\1532 2014-05-29 00:40 - 2014-05-29 00:40 - 00003312 _____ () C:\Users\Mafia\Downloads\d47a0d88eaa5f3f885b32016624c2700.dlc 2014-05-29 00:08 - 2014-05-29 00:08 - 03146623 _____ () C:\Users\Mafia\Downloads\DIR-615_fw_revd_414b02_ALL_de_20130411.zip 2014-05-28 23:16 - 2014-05-28 23:16 - 111128912 _____ (Apple Inc.) C:\Users\Mafia\Downloads\itunessetup_16920.exe 2014-05-27 20:36 - 2014-05-27 20:36 - 00021124 _____ () C:\Users\Mafia\Downloads\Game.of.Thrones.S04E07.HDTV.x264-KILLERS.de-SubCentral.rar 2014-05-26 18:35 - 2014-05-30 21:31 - 00000000 ____D () C:\Users\Mafia\Desktop\Neue Musik mit Cover 2014-05-26 17:49 - 2014-05-26 17:53 - 62624584 _____ () C:\Users\Mafia\Desktop\Addicted Instrumental.zip 2014-05-26 17:05 - 2014-05-26 20:30 - 00000000 ____D () C:\Users\Mafia\Desktop\Neuer Ordner (2) 2014-05-25 02:07 - 2014-05-25 02:07 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Mafia\Downloads\mbam-setup-2.0.2.1012(1).exe 2014-05-24 23:00 - 2014-05-24 23:06 - 527018710 _____ () C:\Users\Mafia\Downloads\Lt28h_4.4.2_MaDMaT.zip 2014-05-24 22:58 - 2014-05-24 22:59 - 03058322 _____ () C:\Users\Mafia\Downloads\DooMLoRD_Easy-Rooting-Toolkit_v17_perf-event-exploit(1).zip 2014-05-24 22:53 - 2014-05-24 22:56 - 261566507 _____ () C:\Users\Mafia\Downloads\pac_aoba_4.4.Alpha-1_20140502-185255.zip 2014-05-24 22:25 - 2014-05-24 22:25 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Mafia\Downloads\mbam-setup-2.0.2.1012.exe 2014-05-24 06:12 - 2014-05-24 06:12 - 09092064 _____ (Kingosoft Technology Ltd. ) C:\Users\Mafia\Downloads\sony_bootloader_unlock.exe 2014-05-24 06:11 - 2014-05-24 06:13 - 09023582 _____ () C:\Users\Mafia\Downloads\sony_bootloader_unlock.rar 2014-05-24 05:40 - 2014-05-24 05:40 - 00011712 _____ () C:\Windows\DPINST.LOG 2014-05-24 04:47 - 2014-05-24 04:49 - 00000000 ____D () C:\Fastboot files 2014-05-24 04:47 - 2014-05-24 04:47 - 00825874 _____ () C:\Users\Mafia\Downloads\fastboot.zip 2014-05-24 04:20 - 2014-05-24 04:20 - 00001824 _____ () C:\Users\Mafia\Downloads\vold.fstab 2014-05-24 03:57 - 2014-05-24 03:57 - 03058322 _____ () C:\Users\Mafia\Downloads\DooMLoRD_Easy-Rooting-Toolkit_v17_perf-event-exploit.zip 2014-05-24 02:42 - 2014-05-24 03:02 - 519492673 _____ () C:\Users\Mafia\Downloads\LT28h_6.2.B.0.211_Generic.zip 2014-05-24 02:41 - 2014-05-24 02:57 - 414675530 _____ () C:\Users\Mafia\Downloads\LT28i_6.1.E.3.7-Stock-Rooted.zip 2014-05-24 00:23 - 2014-05-24 00:23 - 00027632 _____ (Sony Ericsson Mobile Communications) C:\Windows\system32\Drivers\seehcri.sys 2014-05-24 00:22 - 2013-01-21 11:11 - 64168776 _____ () C:\Users\Mafia\Downloads\Emma_Setup.exe 2014-05-24 00:21 - 2014-05-24 00:22 - 64656538 _____ () C:\Users\Mafia\Downloads\Flash_tool_for_Xperia_2.zip 2014-05-24 00:21 - 2014-05-24 00:21 - 00961360 _____ (Chip Digital GmbH) C:\Users\Mafia\Downloads\Emma Sony Flash Tool - CHIP-Installer.exe 2014-05-23 14:40 - 2014-05-23 14:41 - 89006156 _____ () C:\Users\Mafia\Downloads\itunes to restore custom ispw BY BESSI.zip 2014-05-23 14:37 - 2014-05-23 14:37 - 00000784 _____ () C:\Users\Mafia\Downloads\hosts.txt 2014-05-22 23:51 - 2012-08-21 13:01 - 00026840 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2014-05-22 23:49 - 2014-05-22 23:50 - 89082704 _____ (Apple Inc.) C:\Users\Mafia\Downloads\iTunesSetup1105.exe 2014-05-22 23:47 - 2014-05-22 23:47 - 11202228 _____ () C:\Users\Mafia\Downloads\itunes 11.05(1).rar 2014-05-22 23:20 - 2014-05-22 23:20 - 02958695 _____ () C:\Users\Mafia\Downloads\Install_ipswDownloader_v201_hf.exe 2014-05-22 23:18 - 2014-05-22 23:19 - 11202228 _____ () C:\Users\Mafia\Downloads\itunes 11.05.rar 2014-05-22 04:36 - 2014-05-22 04:37 - 00000955 _____ () C:\Windows\system32\Drivers\etc\hosts.umbrella 2014-05-22 04:25 - 2014-05-22 04:26 - 00000774 _____ () C:\Windows\KB893803v2.log 2014-05-21 14:39 - 2014-05-21 14:39 - 00007686 _____ () C:\Windows\system32\Drivers\etc.rar 2014-05-21 00:51 - 2014-05-29 09:44 - 00000000 ____D () C:\Langenscheidt T1 7_0 2014-05-21 00:51 - 2014-05-21 00:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LangenscheidtT1 7.0 2014-05-21 00:51 - 2014-05-21 00:51 - 00000000 ____D () C:\Program Files\Langenscheidt T1 7_0 2014-05-21 00:39 - 2013-12-21 20:51 - 00000000 ____D () C:\Users\Mafia\Downloads\Langenscheidt T1 Professional 2014-05-21 00:36 - 2014-05-21 00:36 - 27893796 _____ () C:\Users\Mafia\Downloads\Tu.Up.Utilities.296.m1.rar 2014-05-21 00:22 - 2014-05-21 00:24 - 113652504 _____ () C:\Users\Mafia\Downloads\Langenscheidt_T1_Professional.rar 2014-05-20 23:55 - 2014-05-20 23:55 - 00104336 _____ () C:\Users\Mafia\Downloads\com.magnusdevelopment.gifpaper_v1.0-84_iphoneos-arm.deb 2014-05-20 23:17 - 2014-05-20 23:17 - 00595982 _____ () C:\Users\Mafia\Downloads\com.a3tweaks.auxo2_v1.2_iphoneos-arm-CrAcKeD By RegKiller.deb 2014-05-20 17:02 - 2014-05-20 17:02 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-05-20 11:12 - 2014-05-20 11:12 - 00000000 ____D () C:\Users\Mafia\Documents\iTools 2014-05-20 11:11 - 2014-05-20 11:12 - 02879276 _____ () C:\Users\Mafia\Downloads\iTools0520E_2.rar 2014-05-19 13:13 - 2014-05-19 13:13 - 00021151 _____ () C:\Users\Mafia\Downloads\Game.of.Thrones.S04E07.HDTV.x264-KILLERS.VO.rar 2014-05-19 13:11 - 2014-05-19 13:17 - 327532650 _____ () C:\Users\Mafia\Downloads\gotkills04e07.rar 2014-05-19 03:08 - 2014-05-19 03:08 - 00000000 ____D () C:\Users\Mafia\Documents\PDF Files 2014-05-19 02:58 - 2014-05-19 02:58 - 00000000 ____D () C:\ProgramData\Avanquest Software 2014-05-19 02:56 - 2014-05-19 02:56 - 00000000 ____D () C:\Users\Public\Documents\Avanquest Software 2014-05-19 02:50 - 2014-05-19 02:50 - 00961360 _____ (Chip Digital GmbH) C:\Users\Mafia\Downloads\PDF Experte Ultimate - CHIP-Downloader.exe 2014-05-18 23:47 - 2014-05-18 23:48 - 111121232 _____ (Apple Inc.) C:\Users\Mafia\Downloads\iTunesSetup.exe 2014-05-18 16:58 - 2014-06-06 14:45 - 00009608 _____ () C:\Windows\setupact.log 2014-05-18 16:58 - 2014-05-18 16:58 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-18 16:57 - 2014-06-06 00:04 - 01977166 _____ () C:\Windows\PFRO.log 2014-05-18 11:07 - 2014-05-18 11:07 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\PROMT 2014-05-18 10:38 - 2012-10-15 22:06 - 00000000 ____D () C:\Users\Mafia\Downloads\Dox 2014-05-18 09:56 - 2014-06-04 15:53 - 00013817 _____ () C:\Users\Mafia\Downloads\umbrella.log 2014-05-18 08:41 - 2014-05-22 17:06 - 00000000 ____D () C:\Users\Mafia\Desktop\Neuer Ordner 2014-05-18 01:07 - 2014-05-18 01:07 - 05366773 _____ () C:\Users\Mafia\Downloads\iCloud Activation bypass with redsn0w 0..mp4 2014-05-17 16:22 - 2014-05-17 16:22 - 08535964 _____ () C:\Users\Mafia\Desktop\Hatsune Miku - Strobe Light (ストロボライト) - English-Romaji Sub.ogg 2014-05-17 15:25 - 2014-05-17 15:25 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool 2014-05-17 03:18 - 2014-05-17 03:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression 2014-05-17 03:18 - 2014-05-17 03:18 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 11.0 2014-05-17 03:18 - 2014-05-17 03:18 - 00000000 ____D () C:\Program Files\Microsoft SDKs 2014-05-17 02:34 - 2014-05-17 02:34 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_17-05-14_02-34-44.log 2014-05-17 02:32 - 2014-05-29 01:04 - 00000000 ____D () C:\Program Files\PRMT10 2014-05-17 01:47 - 2014-05-17 01:47 - 00991232 _____ () C:\Users\Mafia\Downloads\MicrosoftFixit50267(1).msi 2014-05-16 23:25 - 2014-05-16 23:25 - 00002829 _____ () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\GadgetWide Cloud Control.lnk 2014-05-16 22:53 - 2014-05-16 22:53 - 00991232 _____ () C:\Users\Mafia\Downloads\MicrosoftFixit50267.msi 2014-05-16 22:53 - 2014-05-16 22:53 - 00001243 _____ () C:\Users\Mafia\Desktop\etc - Verknüpfung.lnk 2014-05-16 22:13 - 2014-05-23 00:57 - 00000000 __SHD () C:\Windows\system32\AI_RecycleBin 2014-05-16 22:13 - 2014-05-16 22:13 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Drivers et Pilotes 2014-05-16 20:47 - 2014-05-16 20:47 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-05-16 20:47 - 2014-05-16 20:47 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-05-16 20:47 - 2014-05-16 20:47 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-05-16 20:47 - 2014-05-16 20:47 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-05-16 20:47 - 2014-05-16 20:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-16 20:47 - 2014-05-16 20:47 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-05-16 20:46 - 2014-05-16 20:46 - 00921512 _____ (Oracle Corporation) C:\Users\Mafia\Downloads\jxpiinstall(1).exe 2014-05-16 20:20 - 2014-05-16 20:20 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_16-05-14_20-20-02.log 2014-05-16 20:16 - 2014-05-17 03:11 - 00000000 ____D () C:\Program Files\PRMT9 2014-05-16 20:10 - 2014-05-16 20:14 - 461998752 _____ (PROMT ) C:\Users\Mafia\Downloads\PROMT9_Freelance_EngGer_EGE_Trial.exe 2014-05-16 19:34 - 2011-12-28 11:01 - 00000000 ____D () C:\Users\Mafia\Downloads\hosts- 2014-05-16 18:56 - 2014-05-16 19:00 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk 2014-05-16 18:56 - 2014-05-16 19:00 - 00002181 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk 2014-05-16 18:56 - 2014-05-16 19:00 - 00002020 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk 2014-05-16 17:24 - 2014-05-16 17:24 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_16-05-14_17-24-13.log 2014-05-16 17:00 - 2014-05-16 17:00 - 00049018 _____ () C:\Users\Mafia\Downloads\coinwidget.com-master.zip 2014-05-15 15:20 - 2014-05-15 15:20 - 00002829 _____ () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\GadgetWide Tool.lnk 2014-05-15 15:19 - 2014-05-12 01:16 - 05438976 _____ () C:\Users\Mafia\Downloads\GadgetWide Cloud Control Service.msi 2014-05-15 15:19 - 2000-05-18 01:00 - 01509632 _____ (Microsoft Corporation) C:\Users\Mafia\Downloads\InstMsiW.exe 2014-05-15 05:41 - 2014-05-15 05:41 - 00000000 ____D () C:\Users\Mafia\AppData\Local\BigFinishGames 2014-05-15 05:40 - 2014-05-15 05:40 - 00000962 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tesla Effect A Tex Murphy Adventure.lnk 2014-05-15 05:40 - 2014-05-15 05:40 - 00000950 _____ () C:\Users\Public\Desktop\Tesla Effect A Tex Murphy Adventure.lnk 2014-05-15 05:25 - 2014-05-15 05:40 - 00000000 ____D () C:\Program Files\Tesla Effect A Tex Murphy Adventure 2014-05-15 05:22 - 2014-05-15 15:02 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\WindowsDDL 2014-05-15 05:22 - 2014-05-15 14:59 - 00000000 __SHD () C:\Users\Mafia\vWc85O 2014-05-15 01:03 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-05-15 00:47 - 2014-05-15 00:47 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-05-14 11:08 - 2014-05-14 11:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-05-14 11:08 - 2014-05-14 11:08 - 00000000 ____D () C:\Program Files\LogMeIn Hamachi 2014-05-13 22:48 - 2014-05-13 22:48 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe 2014-05-13 20:15 - 2014-06-02 22:08 - 00000000 ____D () C:\Users\Mafia\AppData\Local\QuickPar 2014-05-13 20:12 - 2014-05-13 22:47 - 00000000 ____D () C:\Program Files\QuickPar 2014-05-13 20:12 - 2014-05-13 20:12 - 00503439 _____ (Peter B Clements) C:\Users\Mafia\Downloads\QuickPar-0.9.1.0-DEU.exe 2014-05-13 20:12 - 2014-05-13 20:12 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar 2014-05-13 20:12 - 2014-05-13 20:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPar 2014-05-13 19:49 - 2014-06-06 14:46 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\DropboxMaster 2014-05-13 11:37 - 2014-05-21 00:26 - 00000000 ____D () C:\Users\Mafia\AppData\Local\Microsoft_Corporation 2014-05-13 11:11 - 2014-05-15 05:23 - 00000000 ____D () C:\Users\Mafia\Desktop\Tesla Effect A Tex Murphy Adventure - Reloaded - r 2014-05-13 07:05 - 2014-05-13 07:05 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_13-05-14_07-05-17.log 2014-05-13 05:40 - 2014-05-13 05:40 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_13-05-14_05-40-06.log 2014-05-13 00:35 - 2014-05-13 00:42 - 1308208441 _____ () C:\Users\Mafia\Downloads\iPhone4,1_7.1_11D167_Restore.ipsw 2014-05-13 00:10 - 2014-06-04 20:49 - 00000057 _____ () C:\Windows\IMTDCCM.INI 2014-05-13 00:09 - 2014-06-04 20:49 - 00000000 ____D () C:\Program Files\GadgetWide Cloud Control Service 2014-05-12 21:30 - 2014-05-12 21:30 - 00000000 ____D () C:\Users\Mafia\AppData\Local\Promt 2014-05-12 21:11 - 2014-05-12 21:11 - 00006465 _____ () C:\Windows\system32\IssuesFixerLog_12-05-14_21-11-14.log 2014-05-12 19:32 - 2014-05-12 20:43 - 00000000 ____D () C:\Users\Mafia\Downloads\Patch for PROMT Professional 9.5 2014-05-12 19:30 - 2014-06-04 08:05 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Win_3400 2014-05-12 19:29 - 2014-05-29 09:53 - 00000000 ____D () C:\Windows\Lhsp 2014-05-12 19:29 - 2014-05-29 01:07 - 00000000 ____D () C:\Windows\msagent 2014-05-12 19:29 - 2014-05-12 19:29 - 00006292 _____ () C:\Windows\system32\IssuesFixerLog_12-05-14_19-29-53.log 2014-05-12 12:08 - 2014-06-04 08:07 - 00000000 ____D () C:\Users\Mafia\Downloads\iPhone.Backup.Extractor.v4.0.9.0 2014-05-11 18:30 - 2014-05-26 00:25 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Notepad++ 2014-05-11 18:30 - 2014-05-26 00:25 - 00000000 ____D () C:\Program Files\Notepad++ 2014-05-11 18:30 - 2014-05-11 18:30 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ 2014-05-11 18:30 - 2014-05-11 18:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 2014-05-11 18:29 - 2014-05-11 18:29 - 07631728 _____ () C:\Users\Mafia\Downloads\npp.6.6.2.Installer.exe 2014-05-11 18:24 - 2014-05-12 12:11 - 00001246 _____ () C:\Users\Mafia\Desktop\iPhone Backup Extractor.lnk 2014-05-11 18:24 - 2014-05-11 18:26 - 00000107 _____ () C:\Users\Mafia\Desktop\Neues Textdokument.txt 2014-05-10 19:51 - 2014-05-10 19:51 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-08 21:26 - 2014-03-21 22:36 - 00000000 ____D () C:\Users\Mafia\Downloads\Babylon Pro 10 2014-05-08 20:30 - 2014-05-08 20:30 - 00000000 ____D () C:\Users\Mafia\AppData\Local\MaxRecorder 2014-05-08 19:50 - 2014-05-08 19:50 - 00000000 ____D () C:\ProgramData\DFX 2014-05-08 19:49 - 2014-05-08 19:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Max Recorder 2014-05-08 19:49 - 2014-05-08 19:49 - 00000000 ____D () C:\Program Files\Max Recorder 2014-05-08 15:39 - 2014-05-08 15:39 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Logitech 2014-05-08 15:38 - 2014-05-08 15:38 - 00000320 _____ () C:\Users\Mafia\Desktop\MyHarmony.appref-ms 2014-05-08 15:38 - 2014-05-08 15:38 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logitech 2014-05-08 15:37 - 2014-05-08 15:38 - 00409880 _____ (Logitech) C:\Users\Mafia\Downloads\MyHarmony-App.exe 2014-05-08 08:04 - 2014-05-08 13:12 - 00000000 ____D () C:\Users\Mafia\Desktop\Attack on Titan 2014-05-08 02:31 - 2014-05-08 02:31 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UnlockRoot Pro 2014-05-08 02:28 - 2014-05-08 02:31 - 00000000 ____D () C:\Program Files\Unlockroot Pro 2014-05-08 02:27 - 2014-05-08 02:28 - 27874312 _____ (Sony Mobile Communications ) C:\Users\Mafia\Downloads\Sony PC Companion_Web.exe 2014-05-07 19:56 - 2014-03-28 18:19 - 00000000 ____D () C:\Users\Mafia\Downloads\bshdbxst 2014-05-07 11:46 - 2014-05-07 11:46 - 00000924 _____ () C:\Users\Mafia\Downloads\iPhone 4S.txt ==================== One Month Modified Files and Folders ======= 2014-06-06 15:03 - 2014-06-05 23:26 - 00036961 _____ () C:\Users\Mafia\Desktop\FRST.txt 2014-06-06 15:03 - 2014-06-05 22:03 - 00000000 ____D () C:\Users\Mafia\AppData\Local\temp 2014-06-06 15:02 - 2014-06-06 15:02 - 00000000 ____D () C:\Users\Mafia\Desktop\FRST-OlderVersion 2014-06-06 15:02 - 2014-06-05 23:26 - 00000000 ____D () C:\FRST 2014-06-06 15:02 - 2014-06-05 23:18 - 01063424 _____ (Farbar) C:\Users\Mafia\Desktop\FRST.exe 2014-06-06 14:58 - 2013-09-30 22:26 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-06 14:55 - 2013-09-01 15:40 - 00000000 ____D () C:\Users\Mafia\AppData\Local\Adobe 2014-06-06 14:50 - 2013-08-28 03:28 - 01669318 _____ () C:\Windows\WindowsUpdate.log 2014-06-06 14:50 - 2009-07-14 06:34 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-06 14:50 - 2009-07-14 06:34 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-06 14:48 - 2013-08-28 03:58 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-06 14:46 - 2014-05-13 19:49 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\DropboxMaster 2014-06-06 14:46 - 2013-08-31 22:37 - 00000000 ___RD () C:\Users\Mafia\Dropbox 2014-06-06 14:46 - 2013-08-31 22:35 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Dropbox 2014-06-06 14:45 - 2014-05-18 16:58 - 00009608 _____ () C:\Windows\setupact.log 2014-06-06 14:45 - 2014-02-03 16:35 - 00000000 ____D () C:\Users\Mafia\AppData\Local\LogMeIn Hamachi 2014-06-06 14:45 - 2013-09-30 22:26 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-06 14:45 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-06 11:44 - 2014-06-06 11:43 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-06-06 00:04 - 2014-05-18 16:57 - 01977166 _____ () C:\Windows\PFRO.log 2014-06-06 00:03 - 2013-09-01 22:42 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\UseNeXT 2014-06-05 23:51 - 2013-09-01 22:42 - 00000000 ____D () C:\Users\Mafia\Documents\UseNeXT 2014-06-05 23:26 - 2014-06-05 23:11 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-06-05 23:26 - 2014-06-05 23:10 - 00000000 ____D () C:\Users\Mafia\Desktop\mbar 2014-06-05 23:11 - 2014-06-05 23:11 - 00107224 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-05 23:09 - 2014-06-05 23:09 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Mafia\Desktop\mbar-1.07.0.1009.exe 2014-06-05 22:52 - 2014-06-05 22:52 - 00030033 _____ () C:\ComboFix.txt 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\noni\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Bea\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Aileen\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Administrator\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 22:52 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\temp 2014-06-05 22:52 - 2014-06-05 21:52 - 00000000 ____D () C:\Qoobox 2014-06-05 22:52 - 2013-09-02 01:49 - 00000000 ____D () C:\Users\Mafia\AppData\Local\Apps\2.0 2014-06-05 22:51 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini 2014-06-05 22:32 - 2014-06-05 22:32 - 00003268 _____ () C:\Users\Mafia\Desktop\prüfung.7z 2014-06-05 22:09 - 2013-10-17 12:37 - 00000000 ____D () C:\Users\noni 2014-06-05 22:09 - 2013-08-25 01:00 - 00000000 ____D () C:\Users\Bea 2014-06-05 22:09 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default 2014-06-05 22:09 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public 2014-06-05 22:08 - 2014-06-05 21:51 - 00000000 ____D () C:\Windows\erdnt 2014-06-05 21:46 - 2014-06-05 21:45 - 05205146 _____ (Swearware) C:\Users\Mafia\Downloads\ComboFix(1).exe 2014-06-05 21:44 - 2014-06-05 21:44 - 05205146 ____R (Swearware) C:\Users\Mafia\Downloads\CF.exe 2014-06-05 20:03 - 2014-06-05 20:02 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-06-05 20:03 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Apple Computer 2014-06-05 20:01 - 2014-06-05 20:01 - 00001422 _____ () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-06-05 20:01 - 2014-06-05 20:01 - 00001016 _____ () C:\Users\Public\Desktop\Windows Media Player.lnk 2014-06-05 20:01 - 2014-06-05 20:01 - 00000020 ___SH () C:\Users\Administrator.Mafia-PC\ntuser.ini 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\Startmenü 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\Netzwerkumgebung 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\Druckumgebung 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\Documents\Eigene Musik 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\Documents\Eigene Bilder 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 _SHDL () C:\Users\Administrator.Mafia-PC\AppData\Local\Verlauf 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Windows\Profiles\Default 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Roaming\WTablet 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Roaming\Adobe 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\LogMeIn Hamachi 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\LogMeIn 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\Google 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\Box Sync 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC\AppData\Local\Apple Computer 2014-06-05 20:01 - 2014-06-05 20:01 - 00000000 ____D () C:\Users\Administrator.Mafia-PC 2014-06-05 20:01 - 2009-07-14 06:46 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-06-05 20:01 - 2009-07-14 04:04 - 00000864 _____ () C:\Windows\win.ini 2014-06-05 20:00 - 2013-09-07 02:10 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-06-05 19:54 - 2014-06-05 19:51 - 29094876 _____ () C:\Users\Mafia\Downloads\TUU.v14.0.1000.296.GER.rar 2014-06-05 19:48 - 2013-10-29 21:34 - 00000000 ____D () C:\Temp 2014-06-05 19:46 - 2013-08-31 12:22 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Skype 2014-06-05 19:42 - 2014-06-05 19:40 - 00000000 ____D () C:\Program Files\Unlocker 2014-06-05 19:40 - 2014-06-05 19:40 - 01078591 _____ () C:\Users\Mafia\Downloads\Unlocker1.9.2.exe 2014-06-05 19:40 - 2014-06-05 19:40 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker 2014-06-05 19:37 - 2014-06-05 19:37 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Mafia\Downloads\avira_de_av___ws.exe 2014-06-05 19:05 - 2010-11-20 23:01 - 01657362 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-04 21:50 - 2014-06-04 21:50 - 00961360 _____ (Chip Digital GmbH) C:\Users\Mafia\Downloads\AdwCleaner - CHIP-Installer.exe 2014-06-04 21:45 - 2014-06-04 21:38 - 1204690621 _____ () C:\Users\Mafia\Downloads\iPhone3,1_7.1.1_11D201_Restore.ipsw 2014-06-04 21:29 - 2014-06-04 21:29 - 00001754 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-06-04 21:29 - 2014-06-04 21:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-06-04 21:29 - 2013-08-28 07:39 - 00000000 ____D () C:\Program Files\iTunes 2014-06-04 21:28 - 2014-06-04 21:28 - 00000000 ____D () C:\Program Files\iPod 2014-06-04 21:28 - 2013-08-28 07:39 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-06-04 20:49 - 2014-05-13 00:10 - 00000057 _____ () C:\Windows\IMTDCCM.INI 2014-06-04 20:49 - 2014-05-13 00:09 - 00000000 ____D () C:\Program Files\GadgetWide Cloud Control Service 2014-06-04 20:43 - 2014-06-04 20:43 - 00000000 ____D () C:\Windows\system32\Drivers\etc\Neuer Ordner2 2014-06-04 20:43 - 2014-04-06 23:53 - 00000000 ____D () C:\Neuer Ordner 2014-06-04 20:41 - 2014-06-04 20:41 - 06347938 _____ () C:\Users\Mafia\Downloads\icloud bypass gwcc1.2.6.rar 2014-06-04 15:53 - 2014-05-18 09:56 - 00013817 _____ () C:\Users\Mafia\Downloads\umbrella.log 2014-06-04 08:07 - 2014-05-12 12:08 - 00000000 ____D () C:\Users\Mafia\Downloads\iPhone.Backup.Extractor.v4.0.9.0 2014-06-04 08:05 - 2014-05-12 19:30 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Win_3400 2014-06-04 04:29 - 2014-06-01 06:04 - 00000000 __SHD () C:\Program Files\Windows Manager 2014-06-04 01:55 - 2014-06-04 01:54 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Mafia\Downloads\mbam-setup-2.0.2.1012(3).exe 2014-06-04 01:53 - 2014-06-04 01:53 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Mafia\Downloads\mbam-setup-2.0.2.1012(2).exe 2014-06-04 01:44 - 2014-06-04 01:44 - 00010826 _____ () C:\Users\Mafia\Desktop\prüfung.txt 2014-06-04 01:42 - 2014-06-04 01:42 - 00010859 _____ () C:\Users\Mafia\Desktop\hijackthis.log 2014-06-04 01:38 - 2014-06-04 01:37 - 00388608 _____ (Trend Micro Inc.) C:\Users\Mafia\Downloads\hijackthis_5833.exe 2014-06-04 01:19 - 2014-06-04 01:18 - 00000980 _____ () C:\DelFix.txt 2014-06-03 19:13 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-06-03 14:24 - 2014-06-03 14:24 - 00000044 _____ () C:\Neues Textdokument.txt 2014-06-02 22:08 - 2014-05-13 20:15 - 00000000 ____D () C:\Users\Mafia\AppData\Local\QuickPar 2014-06-01 19:51 - 2014-04-06 12:47 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\.minecraft 2014-06-01 12:35 - 2014-06-01 12:34 - 00000000 ____D () C:\Users\Mafia\Desktop\Neuer Ordner (3) 2014-06-01 09:42 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-06-01 06:10 - 2014-06-01 03:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare 2014-06-01 06:10 - 2014-06-01 03:38 - 00000000 ____D () C:\Program Files\Wondershare 2014-06-01 05:42 - 2014-06-01 03:38 - 00000000 ___HD () C:\Program Files\Dr.Fone_Temp 2014-06-01 05:41 - 2014-06-01 05:41 - 17249726 _____ () C:\Users\Mafia\Downloads\Wondershare Dr.Fone 1.0.2.5 iPhone 5 + Reg Key.rar 2014-06-01 05:28 - 2014-06-01 05:27 - 37652255 _____ () C:\Users\Mafia\Downloads\dr_fone_ios[freedownloadsbywali.com].rar 2014-06-01 04:06 - 2014-06-01 03:49 - 1047527424 _____ () C:\Users\Mafia\Downloads\2315648946457894-lolwddogsrelo.part07.rar 2014-06-01 04:05 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-06-01 03:40 - 2014-06-01 03:40 - 00000000 _____ () C:\Users\Mafia\AppData\Roaming\p.n 2014-06-01 03:38 - 2014-06-01 03:38 - 00000000 ____D () C:\Users\Mafia\AppData\Local\Wondershare 2014-06-01 03:38 - 2014-06-01 03:38 - 00000000 ____D () C:\ProgramData\Wondershare 2014-06-01 03:38 - 2014-06-01 03:38 - 00000000 ____D () C:\Program Files\Common Files\Wondershare 2014-06-01 03:35 - 2014-06-01 03:35 - 00001048 _____ () C:\Users\Mafia\Downloads\relink.us__Wondershare_Dr.Fone_for_iOS_4.1.1.5_d113dbcd7ab4743928810899a9f375.dlc 2014-06-01 03:30 - 2014-06-01 03:13 - 1047527424 _____ () C:\Users\Mafia\Downloads\2315648946457894-lolwddogsrelo.part06.rar 2014-06-01 02:59 - 2014-06-01 02:41 - 1047527424 _____ () C:\Users\Mafia\Downloads\2315648946457894-lolwddogsrelo.part05.rar 2014-06-01 02:40 - 2014-06-01 02:40 - 00005488 _____ () C:\Users\Mafia\Downloads\9a899b3bb764b80ec902323fa9a530e9.dlc 2014-05-31 18:28 - 2014-05-31 18:22 - 03847328 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-05-31 18:26 - 2014-05-31 18:26 - 00115144 _____ () C:\Users\Mafia\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-31 18:23 - 2013-08-28 03:29 - 00000000 ____D () C:\Users\Mafia 2014-05-31 17:04 - 2009-07-14 04:03 - 69468160 _____ () C:\Windows\system32\config\SOFTWARE_tureg_old 2014-05-31 17:04 - 2009-07-14 04:03 - 27262976 _____ () C:\Windows\system32\config\SYSTEM_tureg_old 2014-05-31 17:04 - 2009-07-14 04:03 - 00262144 _____ () C:\Windows\system32\config\DEFAULT_tureg_old 2014-05-31 17:04 - 2009-07-14 04:03 - 00024576 _____ () C:\Windows\system32\config\SECURITY_tureg_old 2014-05-31 16:59 - 2009-07-14 04:03 - 00069632 _____ () C:\Windows\system32\config\SAM_tureg_old 2014-05-31 02:41 - 2014-02-07 02:05 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\vlc 2014-05-31 01:47 - 2014-05-31 01:47 - 00029100 _____ () C:\Users\Mafia\Downloads\ipa01367_GameSave(1).zip 2014-05-31 00:12 - 2014-05-31 00:12 - 00025508 _____ () C:\Users\Mafia\Downloads\org.thebigboss.downlock_v0.1-3_iphoneos-arm.deb 2014-05-30 21:31 - 2014-05-26 18:35 - 00000000 ____D () C:\Users\Mafia\Desktop\Neue Musik mit Cover 2014-05-30 14:33 - 2014-05-30 14:33 - 00599791 _____ () C:\Users\Mafia\Downloads\Fairway Solitaire Blast Hack Tool.rar 2014-05-30 14:29 - 2014-05-30 14:29 - 00029100 _____ () C:\Users\Mafia\Downloads\ipa01367_GameSave.zip 2014-05-30 13:41 - 2014-05-30 13:35 - 76603164 _____ () C:\Users\Mafia\Downloads\476127375.ipa 2014-05-29 21:25 - 2014-02-08 00:09 - 00000000 ____D () C:\The KMPlayer 2014-05-29 10:49 - 2013-09-13 07:08 - 00000000 ____D () C:\Users\Mafia\Documents\Tongbu 2014-05-29 10:45 - 2014-05-29 10:45 - 00000000 ____D () C:\Users\Mafia\Desktop\Library 2014-05-29 09:53 - 2014-05-12 19:29 - 00000000 ____D () C:\Windows\Lhsp 2014-05-29 09:44 - 2014-05-21 00:51 - 00000000 ____D () C:\Langenscheidt T1 7_0 2014-05-29 01:48 - 2014-05-29 01:47 - 11429326 _____ () C:\Users\Mafia\Downloads\Bypass iOS7 By mohammednadhir31.rar 2014-05-29 01:07 - 2014-05-29 01:07 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_29-05-14_01-07-35.log 2014-05-29 01:07 - 2014-05-12 19:29 - 00000000 ____D () C:\Windows\msagent 2014-05-29 01:07 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Speech 2014-05-29 01:07 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Help 2014-05-29 01:04 - 2014-05-29 01:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PROMT 2014-05-29 01:04 - 2014-05-17 02:32 - 00000000 ____D () C:\Program Files\PRMT10 2014-05-29 01:03 - 2014-05-29 01:03 - 00000000 ____D () C:\ProgramData\PROMT 2014-05-29 01:03 - 2014-05-29 01:03 - 00000000 ____D () C:\Program Files\BCL Technologies 2014-05-29 00:40 - 2014-05-29 00:40 - 00003312 _____ () C:\Users\Mafia\Downloads\d47a0d88eaa5f3f885b32016624c2700.dlc 2014-05-29 00:08 - 2014-05-29 00:08 - 03146623 _____ () C:\Users\Mafia\Downloads\DIR-615_fw_revd_414b02_ALL_de_20130411.zip 2014-05-28 23:16 - 2014-05-28 23:16 - 111128912 _____ (Apple Inc.) C:\Users\Mafia\Downloads\itunessetup_16920.exe 2014-05-27 20:36 - 2014-05-27 20:36 - 00021124 _____ () C:\Users\Mafia\Downloads\Game.of.Thrones.S04E07.HDTV.x264-KILLERS.de-SubCentral.rar 2014-05-27 00:55 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\addins 2014-05-26 20:30 - 2014-05-26 17:05 - 00000000 ____D () C:\Users\Mafia\Desktop\Neuer Ordner (2) 2014-05-26 17:53 - 2014-05-26 17:49 - 62624584 _____ () C:\Users\Mafia\Desktop\Addicted Instrumental.zip 2014-05-26 00:25 - 2014-05-11 18:30 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Notepad++ 2014-05-26 00:25 - 2014-05-11 18:30 - 00000000 ____D () C:\Program Files\Notepad++ 2014-05-25 21:58 - 2014-05-05 18:35 - 00000000 ____D () C:\ProgramData\InstallMate 2014-05-25 02:07 - 2014-05-25 02:07 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Mafia\Downloads\mbam-setup-2.0.2.1012(1).exe 2014-05-24 23:06 - 2014-05-24 23:00 - 527018710 _____ () C:\Users\Mafia\Downloads\Lt28h_4.4.2_MaDMaT.zip 2014-05-24 22:59 - 2014-05-24 22:58 - 03058322 _____ () C:\Users\Mafia\Downloads\DooMLoRD_Easy-Rooting-Toolkit_v17_perf-event-exploit(1).zip 2014-05-24 22:56 - 2014-05-24 22:53 - 261566507 _____ () C:\Users\Mafia\Downloads\pac_aoba_4.4.Alpha-1_20140502-185255.zip 2014-05-24 22:25 - 2014-05-24 22:25 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Mafia\Downloads\mbam-setup-2.0.2.1012.exe 2014-05-24 19:29 - 2013-10-16 16:39 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-05-24 06:13 - 2014-05-24 06:11 - 09023582 _____ () C:\Users\Mafia\Downloads\sony_bootloader_unlock.rar 2014-05-24 06:12 - 2014-05-24 06:12 - 09092064 _____ (Kingosoft Technology Ltd. ) C:\Users\Mafia\Downloads\sony_bootloader_unlock.exe 2014-05-24 05:40 - 2014-05-24 05:40 - 00011712 _____ () C:\Windows\DPINST.LOG 2014-05-24 04:49 - 2014-05-24 04:47 - 00000000 ____D () C:\Fastboot files 2014-05-24 04:47 - 2014-05-24 04:47 - 00825874 _____ () C:\Users\Mafia\Downloads\fastboot.zip 2014-05-24 04:20 - 2014-05-24 04:20 - 00001824 _____ () C:\Users\Mafia\Downloads\vold.fstab 2014-05-24 04:14 - 2014-02-10 21:55 - 00000000 ____D () C:\Flashtool 2014-05-24 03:57 - 2014-05-24 03:57 - 03058322 _____ () C:\Users\Mafia\Downloads\DooMLoRD_Easy-Rooting-Toolkit_v17_perf-event-exploit.zip 2014-05-24 03:02 - 2014-05-24 02:42 - 519492673 _____ () C:\Users\Mafia\Downloads\LT28h_6.2.B.0.211_Generic.zip 2014-05-24 02:57 - 2014-05-24 02:41 - 414675530 _____ () C:\Users\Mafia\Downloads\LT28i_6.1.E.3.7-Stock-Rooted.zip 2014-05-24 00:25 - 2013-12-25 08:57 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony Mobile 2014-05-24 00:23 - 2014-05-24 00:23 - 00027632 _____ (Sony Ericsson Mobile Communications) C:\Windows\system32\Drivers\seehcri.sys 2014-05-24 00:22 - 2014-05-24 00:21 - 64656538 _____ () C:\Users\Mafia\Downloads\Flash_tool_for_Xperia_2.zip 2014-05-24 00:22 - 2013-12-17 13:30 - 00000000 ____D () C:\Program Files\Sony Mobile 2014-05-24 00:21 - 2014-05-24 00:21 - 00961360 _____ (Chip Digital GmbH) C:\Users\Mafia\Downloads\Emma Sony Flash Tool - CHIP-Installer.exe 2014-05-23 21:17 - 2013-12-17 13:30 - 00000000 ____D () C:\ProgramData\Sony Mobile 2014-05-23 15:08 - 2013-08-28 07:41 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\iFunbox_UserCache 2014-05-23 14:41 - 2014-05-23 14:40 - 89006156 _____ () C:\Users\Mafia\Downloads\itunes to restore custom ispw BY BESSI.zip 2014-05-23 14:37 - 2014-05-23 14:37 - 00000784 _____ () C:\Users\Mafia\Downloads\hosts.txt 2014-05-23 00:57 - 2014-05-16 22:13 - 00000000 __SHD () C:\Windows\system32\AI_RecycleBin 2014-05-23 00:54 - 2013-10-18 18:59 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\libimobiledevice 2014-05-22 23:59 - 2014-05-05 18:44 - 00002122 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-05-22 23:50 - 2014-05-22 23:49 - 89082704 _____ (Apple Inc.) C:\Users\Mafia\Downloads\iTunesSetup1105.exe 2014-05-22 23:47 - 2014-05-22 23:47 - 11202228 _____ () C:\Users\Mafia\Downloads\itunes 11.05(1).rar 2014-05-22 23:20 - 2014-05-22 23:20 - 02958695 _____ () C:\Users\Mafia\Downloads\Install_ipswDownloader_v201_hf.exe 2014-05-22 23:19 - 2014-05-22 23:18 - 11202228 _____ () C:\Users\Mafia\Downloads\itunes 11.05.rar 2014-05-22 23:15 - 2014-04-19 15:12 - 00007680 ___SH () C:\Users\Mafia\AppData\Roaming\Thumbs.db 2014-05-22 17:06 - 2014-05-18 08:41 - 00000000 ____D () C:\Users\Mafia\Desktop\Neuer Ordner 2014-05-22 04:37 - 2014-05-22 04:36 - 00000955 _____ () C:\Windows\system32\Drivers\etc\hosts.umbrella 2014-05-22 04:35 - 2014-03-16 21:22 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\DiskAid 2014-05-22 04:26 - 2014-05-22 04:25 - 00000774 _____ () C:\Windows\KB893803v2.log 2014-05-21 19:05 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\Performance 2014-05-21 18:01 - 2014-04-03 19:13 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\redsn0w 2014-05-21 14:39 - 2014-05-21 14:39 - 00007686 _____ () C:\Windows\system32\Drivers\etc.rar 2014-05-21 00:51 - 2014-05-21 00:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LangenscheidtT1 7.0 2014-05-21 00:51 - 2014-05-21 00:51 - 00000000 ____D () C:\Program Files\Langenscheidt T1 7_0 2014-05-21 00:51 - 2013-08-28 04:41 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-05-21 00:50 - 2013-08-28 04:41 - 00000000 ____D () C:\Program Files\Common Files\InstallShield 2014-05-21 00:36 - 2014-05-21 00:36 - 27893796 _____ () C:\Users\Mafia\Downloads\Tu.Up.Utilities.296.m1.rar 2014-05-21 00:26 - 2014-05-13 11:37 - 00000000 ____D () C:\Users\Mafia\AppData\Local\Microsoft_Corporation 2014-05-21 00:24 - 2014-05-21 00:22 - 113652504 _____ () C:\Users\Mafia\Downloads\Langenscheidt_T1_Professional.rar 2014-05-20 23:55 - 2014-05-20 23:55 - 00104336 _____ () C:\Users\Mafia\Downloads\com.magnusdevelopment.gifpaper_v1.0-84_iphoneos-arm.deb 2014-05-20 23:17 - 2014-05-20 23:17 - 00595982 _____ () C:\Users\Mafia\Downloads\com.a3tweaks.auxo2_v1.2_iphoneos-arm-CrAcKeD By RegKiller.deb 2014-05-20 17:02 - 2014-05-20 17:02 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-05-20 17:02 - 2013-08-31 12:22 - 00000000 ___RD () C:\Program Files\Skype 2014-05-20 17:02 - 2013-08-31 12:21 - 00000000 ____D () C:\ProgramData\Skype 2014-05-20 11:12 - 2014-05-20 11:12 - 00000000 ____D () C:\Users\Mafia\Documents\iTools 2014-05-20 11:12 - 2014-05-20 11:11 - 02879276 _____ () C:\Users\Mafia\Downloads\iTools0520E_2.rar 2014-05-20 01:43 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\schemas 2014-05-19 13:17 - 2014-05-19 13:11 - 327532650 _____ () C:\Users\Mafia\Downloads\gotkills04e07.rar 2014-05-19 13:13 - 2014-05-19 13:13 - 00021151 _____ () C:\Users\Mafia\Downloads\Game.of.Thrones.S04E07.HDTV.x264-KILLERS.VO.rar 2014-05-19 03:08 - 2014-05-19 03:08 - 00000000 ____D () C:\Users\Mafia\Documents\PDF Files 2014-05-19 02:58 - 2014-05-19 02:58 - 00000000 ____D () C:\ProgramData\Avanquest Software 2014-05-19 02:56 - 2014-05-19 02:56 - 00000000 ____D () C:\Users\Public\Documents\Avanquest Software 2014-05-19 02:50 - 2014-05-19 02:50 - 00961360 _____ (Chip Digital GmbH) C:\Users\Mafia\Downloads\PDF Experte Ultimate - CHIP-Downloader.exe 2014-05-18 23:56 - 2013-08-28 07:39 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-05-18 23:48 - 2014-05-18 23:47 - 111121232 _____ (Apple Inc.) C:\Users\Mafia\Downloads\iTunesSetup.exe 2014-05-18 16:58 - 2014-05-18 16:58 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-18 11:07 - 2014-05-18 11:07 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\PROMT 2014-05-18 01:07 - 2014-05-18 01:07 - 05366773 _____ () C:\Users\Mafia\Downloads\iCloud Activation bypass with redsn0w 0..mp4 2014-05-17 16:22 - 2014-05-17 16:22 - 08535964 _____ () C:\Users\Mafia\Desktop\Hatsune Miku - Strobe Light (ストロボライト) - English-Romaji Sub.ogg 2014-05-17 15:25 - 2014-05-17 15:25 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool 2014-05-17 05:02 - 2013-08-28 19:26 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Malwarebytes 2014-05-17 05:02 - 2013-08-28 19:26 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-17 03:18 - 2014-05-17 03:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression 2014-05-17 03:18 - 2014-05-17 03:18 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 11.0 2014-05-17 03:18 - 2014-05-17 03:18 - 00000000 ____D () C:\Program Files\Microsoft SDKs 2014-05-17 03:18 - 2013-08-28 03:50 - 00000000 ____D () C:\ProgramData\Package Cache 2014-05-17 03:11 - 2014-05-16 20:16 - 00000000 ____D () C:\Program Files\PRMT9 2014-05-17 02:34 - 2014-05-17 02:34 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_17-05-14_02-34-44.log 2014-05-17 01:47 - 2014-05-17 01:47 - 00991232 _____ () C:\Users\Mafia\Downloads\MicrosoftFixit50267(1).msi 2014-05-16 23:25 - 2014-05-16 23:25 - 00002829 _____ () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\GadgetWide Cloud Control.lnk 2014-05-16 22:53 - 2014-05-16 22:53 - 00991232 _____ () C:\Users\Mafia\Downloads\MicrosoftFixit50267.msi 2014-05-16 22:53 - 2014-05-16 22:53 - 00001243 _____ () C:\Users\Mafia\Desktop\etc - Verknüpfung.lnk 2014-05-16 22:13 - 2014-05-16 22:13 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Drivers et Pilotes 2014-05-16 20:47 - 2014-05-16 20:47 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-05-16 20:47 - 2014-05-16 20:47 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-05-16 20:47 - 2014-05-16 20:47 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-05-16 20:47 - 2014-05-16 20:47 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-05-16 20:47 - 2014-05-16 20:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-16 20:47 - 2014-05-16 20:47 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-05-16 20:47 - 2013-09-13 06:30 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-16 20:46 - 2014-05-16 20:46 - 00921512 _____ (Oracle Corporation) C:\Users\Mafia\Downloads\jxpiinstall(1).exe 2014-05-16 20:20 - 2014-05-16 20:20 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_16-05-14_20-20-02.log 2014-05-16 20:14 - 2014-05-16 20:10 - 461998752 _____ (PROMT ) C:\Users\Mafia\Downloads\PROMT9_Freelance_EngGer_EGE_Trial.exe 2014-05-16 19:00 - 2014-05-16 18:56 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk 2014-05-16 19:00 - 2014-05-16 18:56 - 00002181 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk 2014-05-16 19:00 - 2014-05-16 18:56 - 00002020 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk 2014-05-16 18:58 - 2013-09-01 15:40 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-05-16 18:55 - 2013-09-01 15:38 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-16 17:24 - 2014-05-16 17:24 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_16-05-14_17-24-13.log 2014-05-16 17:12 - 2013-09-13 06:28 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-16 17:00 - 2014-05-16 17:00 - 00049018 _____ () C:\Users\Mafia\Downloads\coinwidget.com-master.zip 2014-05-16 16:35 - 2013-08-28 03:58 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-05-16 16:35 - 2013-08-28 03:58 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-05-15 15:20 - 2014-05-15 15:20 - 00002829 _____ () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\GadgetWide Tool.lnk 2014-05-15 15:02 - 2014-05-15 05:22 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\WindowsDDL 2014-05-15 14:59 - 2014-05-15 05:22 - 00000000 __SHD () C:\Users\Mafia\vWc85O 2014-05-15 05:41 - 2014-05-15 05:41 - 00000000 ____D () C:\Users\Mafia\AppData\Local\BigFinishGames 2014-05-15 05:40 - 2014-05-15 05:40 - 00000962 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tesla Effect A Tex Murphy Adventure.lnk 2014-05-15 05:40 - 2014-05-15 05:40 - 00000950 _____ () C:\Users\Public\Desktop\Tesla Effect A Tex Murphy Adventure.lnk 2014-05-15 05:40 - 2014-05-15 05:25 - 00000000 ____D () C:\Program Files\Tesla Effect A Tex Murphy Adventure 2014-05-15 05:23 - 2014-05-13 11:11 - 00000000 ____D () C:\Users\Mafia\Desktop\Tesla Effect A Tex Murphy Adventure - Reloaded - r 2014-05-15 05:02 - 2013-09-01 15:38 - 00000000 ____D () C:\Program Files\Adobe 2014-05-15 04:55 - 2013-11-24 17:47 - 00000000 ____D () C:\Users\Mafia\AppData\Local\Razer 2014-05-15 04:55 - 2013-11-24 17:46 - 00000000 ____D () C:\ProgramData\Razer 2014-05-15 04:55 - 2013-11-24 17:46 - 00000000 ____D () C:\Program Files\Razer 2014-05-15 01:01 - 2013-08-28 07:56 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-15 00:47 - 2014-05-15 00:47 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-05-15 00:47 - 2013-08-28 04:04 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-15 00:45 - 2012-06-14 12:39 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-14 11:08 - 2014-05-14 11:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-05-14 11:08 - 2014-05-14 11:08 - 00000000 ____D () C:\Program Files\LogMeIn Hamachi 2014-05-14 11:08 - 2014-04-15 11:35 - 00000897 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk 2014-05-13 22:48 - 2014-05-13 22:48 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe 2014-05-13 22:47 - 2014-05-13 20:12 - 00000000 ____D () C:\Program Files\QuickPar 2014-05-13 20:12 - 2014-05-13 20:12 - 00503439 _____ (Peter B Clements) C:\Users\Mafia\Downloads\QuickPar-0.9.1.0-DEU.exe 2014-05-13 20:12 - 2014-05-13 20:12 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar 2014-05-13 20:12 - 2014-05-13 20:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPar 2014-05-13 13:30 - 2013-08-28 03:47 - 00000000 ____D () C:\Program Files\Java 2014-05-13 13:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-13 07:05 - 2014-05-13 07:05 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_13-05-14_07-05-17.log 2014-05-13 05:40 - 2014-05-13 05:40 - 00004144 _____ () C:\Windows\system32\IssuesFixerLog_13-05-14_05-40-06.log 2014-05-13 00:42 - 2014-05-13 00:35 - 1308208441 _____ () C:\Users\Mafia\Downloads\iPhone4,1_7.1_11D167_Restore.ipsw 2014-05-13 00:10 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-05-12 21:30 - 2014-05-12 21:30 - 00000000 ____D () C:\Users\Mafia\AppData\Local\Promt 2014-05-12 21:11 - 2014-05-12 21:11 - 00006465 _____ () C:\Windows\system32\IssuesFixerLog_12-05-14_21-11-14.log 2014-05-12 20:43 - 2014-05-12 19:32 - 00000000 ____D () C:\Users\Mafia\Downloads\Patch for PROMT Professional 9.5 2014-05-12 19:29 - 2014-05-12 19:29 - 00006292 _____ () C:\Windows\system32\IssuesFixerLog_12-05-14_19-29-53.log 2014-05-12 12:11 - 2014-05-11 18:24 - 00001246 _____ () C:\Users\Mafia\Desktop\iPhone Backup Extractor.lnk 2014-05-12 07:26 - 2014-06-06 11:43 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-06-06 11:43 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-12 07:25 - 2014-06-05 23:10 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 01:16 - 2014-05-15 15:19 - 05438976 _____ () C:\Users\Mafia\Downloads\GadgetWide Cloud Control Service.msi 2014-05-11 18:30 - 2014-05-11 18:30 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ 2014-05-11 18:30 - 2014-05-11 18:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 2014-05-11 18:29 - 2014-05-11 18:29 - 07631728 _____ () C:\Users\Mafia\Downloads\npp.6.6.2.Installer.exe 2014-05-11 18:26 - 2014-05-11 18:24 - 00000107 _____ () C:\Users\Mafia\Desktop\Neues Textdokument.txt 2014-05-11 17:58 - 2013-09-02 05:19 - 00000000 ____D () C:\Users\Mafia\AppData\Local\Deployment 2014-05-11 17:40 - 2013-08-28 04:12 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-05-10 19:51 - 2014-05-10 19:51 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-08 20:30 - 2014-05-08 20:30 - 00000000 ____D () C:\Users\Mafia\AppData\Local\MaxRecorder 2014-05-08 19:50 - 2014-05-08 19:50 - 00000000 ____D () C:\ProgramData\DFX 2014-05-08 19:49 - 2014-05-08 19:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Max Recorder 2014-05-08 19:49 - 2014-05-08 19:49 - 00000000 ____D () C:\Program Files\Max Recorder 2014-05-08 19:49 - 2013-08-29 12:27 - 00000000 ____D () C:\Program Files\DFX 2014-05-08 15:39 - 2014-05-08 15:39 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Logitech 2014-05-08 15:38 - 2014-05-08 15:38 - 00000320 _____ () C:\Users\Mafia\Desktop\MyHarmony.appref-ms 2014-05-08 15:38 - 2014-05-08 15:38 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logitech 2014-05-08 15:38 - 2014-05-08 15:37 - 00409880 _____ (Logitech) C:\Users\Mafia\Downloads\MyHarmony-App.exe 2014-05-08 13:12 - 2014-05-08 08:04 - 00000000 ____D () C:\Users\Mafia\Desktop\Attack on Titan 2014-05-08 09:23 - 2014-01-06 23:54 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\AVS4YOU 2014-05-08 02:35 - 2013-10-02 22:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony 2014-05-08 02:31 - 2014-05-08 02:31 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UnlockRoot Pro 2014-05-08 02:31 - 2014-05-08 02:28 - 00000000 ____D () C:\Program Files\Unlockroot Pro 2014-05-08 02:28 - 2014-05-08 02:27 - 27874312 _____ (Sony Mobile Communications ) C:\Users\Mafia\Downloads\Sony PC Companion_Web.exe 2014-05-08 01:31 - 2014-01-06 23:49 - 00000000 ____D () C:\Program Files\AVS4YOU 2014-05-08 01:21 - 2013-12-05 01:56 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\TuneUpMedia 2014-05-08 01:21 - 2013-08-28 04:12 - 00000000 ____D () C:\Users\Mafia\AppData\Roaming\Mozilla 2014-05-07 11:46 - 2014-05-07 11:46 - 00000924 _____ () C:\Users\Mafia\Downloads\iPhone 4S.txt 2014-05-07 00:18 - 2014-04-29 12:56 - 00000000 ____D () C:\Users\Mafia\Desktop\Minecraft-bilder Files to move or delete: ==================== C:\Users\Bea\contacts.dat Some content of TEMP: ==================== C:\Users\Mafia\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkkxore.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION! ==================== BCD ================================ Windows-Start-Manager --------------------- Bezeichner {bootmgr} device partition=\Device\HarddiskVolume1 path \bootmgr description Windows Boot Manager locale de-DE inherit {globalsettings} integrityservices Enable default {current} resumeobject {ec0b5fe5-c457-11e3-a4e7-dd71149e4331} displayorder {ec0b5fe6-c457-11e3-a4e7-dd71149e4331} {61b1399a-24cd-11de-a4c4-ca27f4abce37} {current} toolsdisplayorder {memdiag} timeout 15 Windows-Startladeprogramm ------------------------- Bezeichner {10a77768-b926-11e3-9e2d-f3f7ac4b143e} device ramdisk=[D:]\Recovery\WindowsRE\Winre.wim,{10a77769-b926-11e3-9e2d-f3f7ac4b143e} path \windows\system32\winload.exe description Windows Recovery Environment locale de-DE inherit {bootloadersettings} custom:15000065 3 custom:15000066 3 osdevice ramdisk=[D:]\Recovery\WindowsRE\Winre.wim,{10a77769-b926-11e3-9e2d-f3f7ac4b143e} systemroot \windows nx OptIn custom:250000c2 1 winpe Yes Windows-Startladeprogramm ------------------------- Bezeichner {5eea018c-c458-11e3-a4e7-dd71149e4331} device ramdisk=[D:]\Recovery\WindowsRE\Winre.wim,{5eea018d-c458-11e3-a4e7-dd71149e4331} path \windows\system32\winload.exe description Windows Recovery Environment locale de-DE inherit {bootloadersettings} custom:15000065 3 custom:15000066 3 osdevice ramdisk=[D:]\Recovery\WindowsRE\Winre.wim,{5eea018d-c458-11e3-a4e7-dd71149e4331} systemroot \windows nx OptIn custom:250000c2 1 winpe Yes Windows-Startladeprogramm ------------------------- Bezeichner {ab31a0e4-0f88-11e3-95df-c80cab60adee} device ramdisk=[C:]\Recovery\ab31a0e4-0f88-11e3-95df-c80cab60adee\Winre.wim,{ab31a0e5-0f88-11e3-95df-c80cab60adee} path \windows\system32\winload.exe description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\ab31a0e4-0f88-11e3-95df-c80cab60adee\Winre.wim,{ab31a0e5-0f88-11e3-95df-c80cab60adee} systemroot \windows nx OptIn winpe Yes Windows-Startladeprogramm ------------------------- Bezeichner {current} device partition=C: path \Windows\system32\winload.exe description Windows 7 ohne DDR-RAM Sperre locale de-DE inherit {bootloadersettings} recoverysequence {ab31a0e4-0f88-11e3-95df-c80cab60adee} recoveryenabled Yes testsigning Yes osdevice partition=C: systemroot \Windows kernel ntkrlICE.exe resumeobject {ab31a0e2-0f88-11e3-95df-c80cab60adee} nx OptIn pae ForceEnable numproc 2 usefirmwarepcisettings No Windows-Startladeprogramm ------------------------- Bezeichner {ec0b5fe6-c457-11e3-a4e7-dd71149e4331} device partition=D: path \WINDOWS\system32\winload.exe description Windows 8.1 locale de-DE inherit {bootloadersettings} recoverysequence {5eea018c-c458-11e3-a4e7-dd71149e4331} integrityservices Enable recoveryenabled Yes custom:17000077 352321653 osdevice partition=D: systemroot \WINDOWS resumeobject {ec0b5fe5-c457-11e3-a4e7-dd71149e4331} nx OptIn custom:250000c2 1 Wiederaufnahme aus dem Ruhezustand ---------------------------------- Bezeichner {10a77766-b926-11e3-9e2d-f3f7ac4b143e} device partition=D: path \Windows\system32\winresume.exe description Windows Resume Application locale de-DE inherit {resumeloadersettings} recoverysequence {10a77768-b926-11e3-9e2d-f3f7ac4b143e} recoveryenabled Yes custom:17000077 352321653 filedevice partition=D: filepath \hiberfil.sys custom:25000008 1 pae Yes debugoptionenabled No Wiederaufnahme aus dem Ruhezustand ---------------------------------- Bezeichner {ab31a0e2-0f88-11e3-95df-c80cab60adee} device partition=C: path \Windows\system32\winresume.exe description Windows Resume Application locale de-DE inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys pae Yes debugoptionenabled No Wiederaufnahme aus dem Ruhezustand ---------------------------------- Bezeichner {ec0b5fe5-c457-11e3-a4e7-dd71149e4331} device partition=D: path \WINDOWS\system32\winresume.exe description Windows Resume Application locale de-DE inherit {resumeloadersettings} recoverysequence {5eea018c-c458-11e3-a4e7-dd71149e4331} recoveryenabled Yes custom:17000077 352321653 filedevice partition=D: filepath \hiberfil.sys custom:25000008 1 pae Yes debugoptionenabled No Windows-Speichertestprogramm ---------------------------- Bezeichner {memdiag} device partition=\Device\HarddiskVolume1 path \boot\memtest.exe description Windows-Speicherdiagnose locale de-DE inherit {globalsettings} badmemoryaccess Yes EMS-Einstellungen ----------------- Bezeichner {emssettings} bootems No Debuggereinstellungen --------------------- Bezeichner {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM-Defekte ----------- Bezeichner {badmemory} Globale Einstellungen --------------------- Bezeichner {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Startladeprogramm-Einstellungen ------------------------------- Bezeichner {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisoreinstellungen ------------------- Bezeichner {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Einstellungen zur Ladeprogrammfortsetzung ----------------------------------------- Bezeichner {resumeloadersettings} inherit {globalsettings} Ger„teoptionen -------------- Bezeichner {10a77769-b926-11e3-9e2d-f3f7ac4b143e} description Windows Recovery ramdisksdidevice partition=D: ramdisksdipath \Recovery\WindowsRE\boot.sdi Ger„teoptionen -------------- Bezeichner {10a7776a-b926-11e3-9e2d-f3f7ac4b143e} description Windows Setup ramdisksdidevice partition=D: ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi Ger„teoptionen -------------- Bezeichner {5eea018d-c458-11e3-a4e7-dd71149e4331} description Windows Recovery ramdisksdidevice partition=D: ramdisksdipath \Recovery\WindowsRE\boot.sdi Ger„teoptionen -------------- Bezeichner {ab31a0e5-0f88-11e3-95df-c80cab60adee} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\ab31a0e4-0f88-11e3-95df-c80cab60adee\boot.sdi LastRegBack: 2014-05-29 01:30 ==================== End Of Log ============================ |
06.06.2014, 14:05 | #21 |
| cpu 100% und exe lassen sich nicht öffenCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:06-06-2014 Ran by Mafia at 2014-06-06 15:03:34 Running from C:\Users\Mafia\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) AC3Filter 2.6.0b (HKLM\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky) Adobe Acrobat XI Pro (HKLM\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.07 - Adobe Systems) Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.8.0.1280 - Adobe Systems Incorporated) Adobe AIR (Version: 3.8.0.1280 - Adobe Systems Incorporated) Hidden Adobe Creative Cloud (HKLM\...\Adobe Creative Cloud) (Version: 2.5.1.369 - Adobe Systems Incorporated) Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Professional CS6 (HKLM\...\{BD5669B5-49FF-4490-B956-E9D7CB9B0ADC}) (Version: 12.0 - Adobe Systems Incorporated) Adobe Help Manager (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Help Manager (Version: 4.0.244 - Adobe Systems Incorporated) Hidden Adobe Photoshop CC (HKLM\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\{AA3B06B1-E89A-43C6-A26B-7109DB4BEE7B}) (Version: 12.0.7.148 - Adobe Systems, Inc) Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.0.150 - Adobe Systems, Inc.) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.7 - Sereby Corporation) AMD Accelerated Video Transcoding (Version: 13.30.100.40417 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.1124.2 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Control Center (Version: 2014.0417.2226.38446 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{DC7723BE-A2BB-58A0-4820-5630F9B82198}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.81206.1620 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.10 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.15 - Advanced Micro Devices, Inc.) Hidden Android SDK Tools (HKLM\...\Android SDK Tools) (Version: 1.16 - Google Inc.) Apple Application Support (HKLM\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AVS Video Converter 8.5 (HKLM\...\AVS4YOU Video Converter 7_is1) (Version: 8.5.1.551 - Online Media Technologies Ltd.) Babylon (HKLM\...\{5111D459-D8BD-4C26-BE8B-A15ED1ACBF69}) (Version: 10.00.0111 - Babylon Ltd.) Bamboo (HKLM\...\Pen Tablet Driver) (Version: 5.2.5-3 - Wacom Technology Corp.) Bamboo Dock (HKLM\...\Bamboo Dock) (Version: 4.1 - Wacom Co., Ltd.) Bamboo Dock (Version: 4.1.0 - Wacom Europe GmbH) Hidden Bleed (HKLM\...\Steam App 239800) (Version: - Ian Campbell) Blend for Visual Studio Add-in for Adobe FXG Import (Version: 1.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for .NET 4.5 (Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for Silverlight 5 (Version: 3.0.40218.0 - Microsoft Corporation) Hidden Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Box Sync (HKLM\...\{EA45DACB-0978-420F-AE32-FD5354FEED61}) (Version: 4.0.3100.0 - Box, Inc.) Box Sync (Version: 4.0.3100.0 - Box Inc.) Hidden Broken Sword 5 - the Serpent's Curse - Episode 1 (HKLM\...\GOGPACKBROKENSWORD5EP1_is1) (Version: 2.0.0.3 - GOG.com) calibre (HKLM\...\{BA356893-F9F4-4C84-B10B-6EB2FC3C3B90}) (Version: 1.5.0 - Kovid Goyal) Catalyst Control Center - Branding (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help English (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help French (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help German (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden ccc-utility (Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Core Temp 1.0 RC5 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.0 - Alcpu) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{349F73CA-653A-43A6-AE77-970B07D6EDA0}) (Version: - Microsoft) DFX (HKLM\...\DFX) (Version: 11.113.0.0 - Power Technology) DirectX 9.0c Extra Files (x86, x64) (HKLM\...\{8729E65B-8C12-4A42-B1FE-E4DA7ED52855}_is1) (Version: 1.10.06.0 - Sereby Corporation) DirectX for Managed Code (HKLM\...\{FDF7187F-3960-4BEC-916D-98C9A83E3A68}_is1) (Version: 1.0.0.0 - Sereby Corporation) DiskAid 6.5.6.0 (HKLM\...\DiskAid_is1) (Version: 6.5.6.0 - DigiDNA) DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.1.90 - DivX, LLC) Dracula 5 (HKLM\...\Dracula5_is1) (Version: 1.0 - Anuman) DriverTuner 3.1.0.1 (HKLM\...\{520C1D80-935C-42B9-9340-E883849D804F}_is1) (Version: 3.1.0.1 - LionSea SoftWare) Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.) EasyBCD 2.2 (HKLM\...\EasyBCD) (Version: 2.2 - NeoSmart Technologies) Eleusis (HKLM\...\Eleusis_is1) (Version: - ) ffdshow v1.3.4500 [2013-01-06] (HKLM\...\ffdshow_is1) (Version: 1.3.4500.0 - ) Flashtool (HKLM\...\Flashtool) (Version: 0.9.16.0 - Androxyde) GadgetWide Cloud Control Service (HKLM\...\{6147344A-2A3D-4CE0-9F09-E99CE1C45573}) (Version: 1.2.0.6 - GadgetWide) GadgetWide Cloud Control Service (HKLM\...\{9DF8F96F-821F-458C-AE5A-FC17051BD592}) (Version: 1.2.4.0 - ) Geheimakte Sam Peters (HKLM\...\{F4DE991E-E7DE-4C22-A01C-3AEC85A62FDE}) (Version: 1.00 - Deep Silver) Goodbye Deponia (HKLM\...\R29vZGJ5ZURlcG9uaWE=_is1) (Version: 1 - ) Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.) Google Earth Plug-in (HKLM\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden HWiNFO32 Version 4.24 (HKLM\...\HWiNFO32_is1) (Version: 4.24 - Martin Malík - REALiX) HydraVision (Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden iBackupBot 5.0.6 (HKLM\...\iBackupBot) (Version: 5.0.6 - VOWSoft, Ltd.) iFunbox (v2.7.2386.747), iFunbox DevTeam (HKLM\...\iFunbox_is1) (Version: v2.7.2386.747 - ) ImgBurn (HKLM\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!) iPhone Backup Extractor (HKCU\...\iPhone Backup Extractor) (Version: 4.0.9.0 - Reincubate Ltd) IPTInstaller (HKLM\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC) IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.37 - Irfan Skiljan) iTunes (HKLM\...\{0718A90E-93AA-49AF-A4FE-0165ACD91DF0}) (Version: 11.2.2.3 - Apple Inc.) Java 7 Update 55 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Kai's SuperGOO (HKLM\...\SUPERGOO) (Version: - ) KnightShift (HKLM\...\KnightShift) (Version: 1.2 - ZUXXEZ Entertainment AG) L&H TTS3000 Deutsch (HKLM\...\LHTTSGED) (Version: - ) L&H TTS3000 Español (HKLM\...\LHTTSSPE) (Version: - ) L&H TTS3000 Français (HKLM\...\LHTTSFRF) (Version: - ) L&H TTS3000 Italiano (HKLM\...\LHTTSITI) (Version: - ) L&H TTS3000 Português (Brasil) (HKLM\...\LHTTSPTB) (Version: - ) L&H TTS3000 Russian (HKLM\...\LHTTSRUR) (Version: - ) Langenscheidt T1 7.0 (HKLM\...\{57EB87EF-23DF-4A76-9B90-FD7B53E1C6CE}) (Version: - ) League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (Version: 3.0.1 - Riot Games ) Hidden Lernout & Hauspie TruVoice American English TTS Engine (HKLM\...\tv_enua) (Version: - ) Logitech Harmony Remote Software 7 (HKLM\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech) Logitech Harmony Remote Software 7 (Version: 7.7.0.0 - Logitech) Hidden LogMeIn Hamachi (HKLM\...\LogMeIn Hamachi) (Version: 2.2.0.193 - LogMeIn, Inc.) LogMeIn Hamachi (Version: 2.2.0.193 - LogMeIn, Inc.) Hidden Max Recorder (HKLM\...\Max Recorder) (Version: 1.026.0.0 - Silver Vine, LLC) Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2742597) (HKLM\...\M2742597) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - ) Microsoft .NET Framework 1.1 SP1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 SP1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{4903D172-DCCB-392F-93A3-34CA9D47FE3D}) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Expression Blend SDK for .NET 4 (Version: 2.0.20525.0 - Microsoft Corporation) Hidden Microsoft Expression Blend SDK for Silverlight 4 (Version: 2.0.20525.0 - Microsoft Corporation) Hidden Microsoft Office Access MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Language Pack 2010 - German/Deutsch (HKLM\...\Office14.OMUI.de-de) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office O MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office SharePoint Designer MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office X MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Portable Library Multi-Targeting Pack (Version: 11.0.60418.17931 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{cbf90bef-21fb-400b-935a-5900785071dd}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM\...\{7CBA9009-7EA4-338B-893D-9607CD829ADF}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual J# 2.0 Redistributable Package - SE (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE) (Version: - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (Version: 2.0.50728 - Microsoft Corporation) Hidden Microsoft Visual Studio 2005 Tools for Office Runtime (Version: 8.0.60816.0 - Microsoft Corporation) Hidden Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_CRT_x86 (Version: 1.00.0000 - Adobe) Hidden Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.145.0 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (Version: 2.3.145.0 - Microsoft Corporation) Hidden Minimal ADB and Fastboot version 1.1.3 (HKLM\...\{DE46417A-9E9E-4BCD-BBDD-DA21943193BB}_is1) (Version: 1.1.3 - ) Mozilla Firefox 29.0.1 (x86 de) (HKLM\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) My Game Long Name (HKLM\...\UDK-a1f395dd-4409-482e-99fc-b5681c730f76) (Version: - Epic Games, Inc.) My Game Long Name (HKLM\...\UDK-cbe5321e-9a5d-4826-aa08-d03b68b18551) (Version: - Epic Games, Inc.) MyHarmony (HKCU\...\036a0e4fc6a247ec) (Version: 1.0.1.241 - Logitech) Nero Burning Core (Version: 15.0.24000 - Nero AG) Hidden Nero Burning ROM (Version: 15.0.24000 - Nero AG) Hidden Nero Burning ROM 2014 (HKLM\...\{28FCF48D-1BB2-4D6B-89F9-9499663122D6}) (Version: 15.0.02800 - Nero AG) Nero Burning ROM Help (CHM) (Version: 15.0.00018 - Nero AG) Hidden Nero ControlCenter (Version: 11.0.16700 - Nero AG) Hidden Nero ControlCenter Help (CHM) (Version: 15.0.00015 - Nero AG) Hidden Nero Core Components (Version: 11.0.22900 - Nero AG) Hidden Nero SharedVideoCodecs (Version: 1.0.15003 - Nero AG) Hidden Nero Update (Version: 11.0.13300.42.0 - Nero AG) Hidden Nexon Game Manager (HKLM\...\{415ADF7E-6DB8-4481-86C0-1CEC0163CC7B}) (Version: - ) Notepad++ (HKLM\...\Notepad++) (Version: 6.6.3 - Notepad++ Team) NVIDIA PhysX (HKLM\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) PDF Settings CC (Version: 12.0 - Adobe Systems Incorporated) Hidden PDF Settings CS6 (Version: 11.0 - Adobe Systems Incorporated) Hidden plist Editor for Windows 1.0.2 (HKLM\...\plist Editor for Windows) (Version: 1.0.2 - VOWSoft,Ltd.) PPÖúÊÖ PC°æ 1.0.8.0 (HKLM\...\PPÖúÊÖ PC°æ) (Version: 1.0.8.0 - ¹ãÖÝÌúÈËÍøÂç¿Æ¼¼ÓÐÏÞ¹«Ë¾) Prerequisite installer (Version: 15.0.0005 - Nero AG) Hidden PROMT Professional 10 Multilingual Try-Buy (HKLM\...\{9841E95C-4F87-4142-85A1-71D33B395763}) (Version: 10.0.00027 - PROMT Ltd.) psynetic® Gif-X 3.00 (HKLM\...\psynetic® Gif-X) (Version: 3.00 - Robert Mundt) QuickPar 0.9 (HKLM\...\QuickPar) (Version: 0.9 - Peter B. Clements) QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Raptr (HKLM\...\Raptr) (Version: - ) Rayman 3 (HKLM\...\{15F52B39-04CB-4EDB-9A8C-496C4A5588E2}) (Version: 1.00.000 - ) Realtek HDMI Audio Driver for ATI (HKLM\...\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6650 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.) Remote Control USB Driver (HKLM\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - ) Safari (HKLM\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM\...\{90140000-0100-0407-0000-0000000FF1CE}_Office14.OMUI.de-de_{F3E80B62-3C51-4940-A434-A1F517AB8D6A}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (Version: - Microsoft) Hidden Shark007 Standard Codecs (HKLM\...\{898E81AD-6DB9-4750-866B-B8958C5DC7AA}) (Version: 1.6.8 - Shark007) Skype Click to Call (HKLM\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.2.15747.10003 - Microsoft Corporation) Skype™ 6.16 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.) Sony Mobile Emma (HKLM\...\Emma) (Version: 2.13.1.38 - Sony Mobile Communications AB) Sony Mobile Update Engine (HKLM\...\Update Engine) (Version: 2.14.7.201405202226 - Sony Mobile Communications AB) Sony Mobile Update Service (HKLM\...\Update Service) (Version: 2.13.14.201312091927 - Sony Mobile Communications AB) Sony PC Companion 2.10.197 (HKLM\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.197 - Sony) SpongeBob Schwammkopf - Der Film (HKLM\...\{E81A7285-8CA6-4430-B6C0-5F719E4D40D9}) (Version: 1.0 - ) Steam (HKLM\...\Steam) (Version: - Valve Corporation) Subtitle Edit 3.3.8 (HKLM\...\SubtitleEdit_is1) (Version: 3.3.8.2047 - Nikse) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden System Requirements Lab for Intel (HKLM\...\{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}) (Version: 4.5.22.0 - Husdawg, LLC) Tesla Effect: A Tex Murphy Adventure (HKLM\...\VGVzbGFFZmZlY3RBVGV4TXVycGh5QWR2ZW50dXJl_is1) (Version: 1 - ) The KMPlayer (remove only) (HKLM\...\The KMPlayer) (Version: 3.8.0.119 - PandoraTV) Tongbu Assistant 2.0.7.1 (HKLM\...\Tongbu2) (Version: 2.0.7.1 - Xiamen Tongbu Network Ltd.) TransMac version 10.4 (HKLM\...\TransMac_is1) (Version: 10.4 - Acute Systems) TuneUp Utilities Language Pack (de-DE) (Version: 13.0.3020.2 - TuneUp Software) Hidden Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) UnLock Root Pro 4.10 (HKLM\...\UnLock Root Pro) (Version: 4.10 - Unlcokroot) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{90140000-0100-0407-0000-0000000FF1CE}_Office14.OMUI.de-de_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.OMUI.de-de_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.OMUI.de-de_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.OMUI.de-de_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{DCE104A1-1875-4469-A83D-A5BFA6C4640F}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.OMUI.de-de_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{334AA0A1-2BB1-4D74-B66A-2B2C4D9C2C87}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft) UseNeXT by Tangysoft (HKLM\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden VirtualCloneDrive (HKLM\...\VirtualCloneDrive) (Version: 5.4.7.0 - Elaborate Bytes) Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation) Visual Studio 2012 Update 4 (KB2707250) (HKLM\...\{312d9252-c71c-4c84-b171-f4ad46e22098}) (Version: 11.0.61030 - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (HKLM\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (Version: 9.0.21022 - Microsoft Corporation) Hidden VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN) WBFS Manager 3.0 (HKLM\...\WBFS Manager 3.0) (Version: 3.0 - AlexDP) WBFS to ISO (HKLM\...\{55F0E086-2E1C-4478-B52E-DA6025A46434}_is1) (Version: - wbfstoiso.com) Windows 7 USB/DVD Download Tool (HKLM\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) Windows Automated Installation Kit (HKLM\...\{31E8F586-4EF7-4500-844D-BA8756474FF1}) (Version: 2.0.0.0 - Microsoft Corporation) Windows-Treiberpaket - Intel System (10/05/2012 9.1.9.1002) (HKLM\...\8A2EF7D7A858B40014EB296EFBEA8CA1CB929923) (Version: 10/05/2012 9.1.9.1002 - Intel) WinRAR 5.00 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) Wondershare Dr.Fone(Build 1.0.2.5) (HKLM\...\{BE467978-8B6E-43D4-8E12-1ED9AFF303F7}_is1) (Version: 1.0.2.5 - Wondershare Software Co.,Ltd.) XBMC (HKCU\...\XBMC) (Version: - Team XBMC) 넥슨플러그 (HKLM\...\NexonPlug) (Version: - ) 엘소드 (HKLM\...\ElSword) (Version: - ) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2014-06-04 20:29 - 2014-06-05 22:05 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0475C0E8-6FD9-4A0B-8BA5-77FA8D3C77A7} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-09-04] (Microsoft Corporation) Task: {06AA28D9-BD5F-428E-875E-F1AE96F4EEE4} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-09-04] (Microsoft Corporation) Task: {129FEFBB-2CBF-4314-AE84-52EE97F42B70} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {1C2541C4-530E-4831-A498-7F9DC5D2D993} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2013-08-28] () Task: {3B21E08C-03AE-479A-A5EF-80BB33ED5879} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-09-04] (Microsoft Corporation) Task: {4BAD7FC9-F9C6-4108-98F2-8CCE2973E4FD} - System32\Tasks\AdobeAAMUpdater-1.0-Mafia-PC-Mafia => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated) Task: {5107B6DA-E500-43F5-A9DC-574FE5B994E2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-16] (Adobe Systems Incorporated) Task: {5A5EB51E-0E2B-47D7-8B81-FBCA5E2E477C} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe Task: {695060B0-E4AF-484E-942E-0F140D400F21} - System32\Tasks\{07001983-0DCD-45FE-9661-9FB5B16F8331} => C:\Program Files\Microsoft Mouse and Keyboard Center\MouseKeyboardCenter.exe [2013-09-04] (Microsoft) Task: {6EDB4E9C-9E4E-4C91-8DFE-2C27D2CFA9AE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {9FEEBCC1-789E-4B1C-B926-EF4973EC0CB3} - System32\Tasks\KMS Activation for Office => C:\Windows\KMSAct.exe Task: {A0070F61-B9A3-4E07-9882-8F07007AF242} - System32\Tasks\{E4DF9104-1E13-49E3-94F2-2069E79ED790} => C:\Program Files\PRMT9\PROMT Professional\PROMT Professional 9.0.exe Task: {A6B93D48-32C5-4D9D-AD7A-59D425F3FD63} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-09-30] (Google Inc.) Task: {AB10449B-88B3-4364-86C1-5E13261F5D86} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-09-30] (Google Inc.) Task: {AE546B48-3289-43CE-8B0D-F69442D246A2} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-09-04] (Microsoft Corporation) Task: {B738FB0D-7366-4329-B78F-8588912B9F4C} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: {B90B8E5A-F52F-4654-9C68-F43E5914DFCA} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-09-04] (Microsoft) Task: {B988CDF7-BDBA-425C-8534-E8629DB7A931} - System32\Tasks\Core Temp Autostart Mafia => C:\Program Files\Core Temp\Core Temp.exe [2013-03-01] () Task: {EC77AA74-7CD3-48A2-A584-8E862F91B227} - System32\Tasks\DivX-Online-Aktualisierungsprogramm => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2013-02-13] () Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-09-09 10:35 - 2013-09-09 10:35 - 00013824 _____ () C:\Program Files\Box\Box Sync\FSEventsReader.exe 2013-09-03 17:16 - 2011-07-06 00:01 - 00962936 _____ () C:\Program Files\Tablet\Pen\libxml2.dll 2010-07-04 23:32 - 2010-07-04 23:32 - 00004608 _____ () C:\Program Files\Unlocker\UnlockerHook.dll 2014-03-20 11:23 - 2014-03-20 11:23 - 00691360 _____ () C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x86.dll 2013-09-09 10:35 - 2013-09-09 10:35 - 00080896 _____ () C:\Program Files\Box\Box Sync\SystemWrapper.dll 2010-07-04 23:32 - 2010-07-04 23:32 - 00010752 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll 2014-05-12 11:49 - 2014-05-12 11:49 - 00260608 _____ () C:\Program Files\Notepad++\NppShell_06.dll 2013-08-28 07:00 - 2013-03-01 17:44 - 00763856 _____ () C:\Program Files\Core Temp\Core Temp.exe 2013-08-28 07:27 - 2011-07-17 22:48 - 00008192 _____ () C:\Program Files\Core Temp\plugins\CoreTempRemoteServer\SystemInfo.dll 2010-07-04 21:51 - 2010-07-04 21:51 - 00017408 _____ () C:\Program Files\Unlocker\UnlockerAssistant.exe 2013-08-28 07:00 - 2013-08-28 07:00 - 00006144 _____ () C:\Users\Mafia\AppData\Local\Microsoft\Windows Sidebar\Gadgets\CoreTempGadget2.7.gadget\CoreTempReader.dll 2013-08-28 07:00 - 2013-08-28 07:00 - 00008704 _____ () C:\Users\Mafia\AppData\Local\Microsoft\Windows Sidebar\Gadgets\CoreTempGadget2.7.gadget\GetCoreTempInfoNET.dll 2013-08-28 07:00 - 2013-08-28 07:00 - 00007680 _____ () C:\Users\Mafia\AppData\Local\Microsoft\Windows Sidebar\Gadgets\CoreTempGadget2.7.gadget\SystemInfo.dll 2006-12-12 04:27 - 2006-12-12 04:27 - 00387072 _____ () C:\Nexon\NexonPlug\mss32.dll 2006-12-12 04:27 - 2006-12-12 04:27 - 00150528 _____ () C:\Nexon\NexonPlug\mssmp3.asi 2014-06-06 14:45 - 2014-06-06 14:45 - 00043008 _____ () c:\users\mafia\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkkxore.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Mafia\AppData\Roaming\Dropbox\bin\libcef.dll 2014-05-10 19:51 - 2014-05-10 19:51 - 03839088 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Bea\pass.1.jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\Bea\pass.1.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Bea\Pass.jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\Bea\Pass.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Bea\Scan leben.jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\Bea\Scan leben.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\noni\NONI.jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\noni\NONI.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: avipbb Description: avipbb Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: avipbb Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: avkmgr Description: avkmgr Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: avkmgr Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: ssmdrv Description: ssmdrv Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: ssmdrv Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: seehcri Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/06/2014 03:03:36 PM) (Source: VSS) (EventID: 12292) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. ] ist ein Fehler aufgetreten. Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen Schattenkopien abfragen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshotkontext: 13 Snapshotkontext: 13 Ausführungskontext: Coordinator Error: (06/06/2014 03:03:36 PM) (Source: VSS) (EventID: 13) (User: ) Description: Volumenschattenkopie-Dienst-Informationen: Der COM-Server mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} und dem Namen "SW_PROV" kann nicht gestartet werden. [0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. ] Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen Schattenkopien abfragen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshotkontext: 13 Snapshotkontext: 13 Ausführungskontext: Coordinator Error: (06/06/2014 02:50:14 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x80042302). Error: (06/06/2014 02:50:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "GetProviderMgmtInterface" ist ein unerwarteter Fehler aufgetreten. hr = 0x8004230f, Unerwarteter Fehler beim Schattenkopieanbieter bei dem Versuch, den angegebenen Vorgang zu verarbeiten. . Error: (06/06/2014 02:50:14 PM) (Source: VSS) (EventID: 12292) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. ] ist ein Fehler aufgetreten. Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Anbieterverwaltungsschnittstelle wird abgerufen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {00000000-0000-0000-0000-000000000000} Snapshotkontext: -1 Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Error: (06/06/2014 02:50:14 PM) (Source: VSS) (EventID: 13) (User: ) Description: Volumenschattenkopie-Dienst-Informationen: Der COM-Server mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} und dem Namen "SW_PROV" kann nicht gestartet werden. [0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. ] Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Anbieterverwaltungsschnittstelle wird abgerufen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {00000000-0000-0000-0000-000000000000} Snapshotkontext: -1 Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Error: (06/06/2014 02:47:04 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/06/2014 11:42:54 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/05/2014 11:30:52 PM) (Source: VSS) (EventID: 12292) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. ] ist ein Fehler aufgetreten. Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen Schattenkopien abfragen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshotkontext: 13 Snapshotkontext: 13 Ausführungskontext: Coordinator Error: (06/05/2014 11:30:52 PM) (Source: VSS) (EventID: 13) (User: ) Description: Volumenschattenkopie-Dienst-Informationen: Der COM-Server mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} und dem Namen "SW_PROV" kann nicht gestartet werden. [0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. ] Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen Schattenkopien abfragen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshotkontext: 13 Snapshotkontext: 13 Ausführungskontext: Coordinator System errors: ============= Error: (06/06/2014 02:47:36 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "HP Network Devices Support" wurde mit folgendem Fehler beendet: %%126 Error: (06/06/2014 02:45:56 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80070422 Error: (06/06/2014 02:45:52 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (06/06/2014 02:45:35 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: avipbb avkmgr ssmdrv Error: (06/06/2014 02:45:30 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUp Utilities Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/06/2014 02:45:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "avgntflt" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/06/2014 11:42:07 AM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1084MSIServer{000C101C-0000-0000-C000-000000000046} Error: (06/06/2014 11:41:34 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (06/06/2014 11:41:34 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (06/06/2014 11:41:34 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= Error: (06/06/2014 03:03:36 PM) (Source: VSS) (EventID: 12292) (User: ) Description: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen Schattenkopien abfragen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshotkontext: 13 Snapshotkontext: 13 Ausführungskontext: Coordinator Error: (06/06/2014 03:03:36 PM) (Source: VSS) (EventID: 13) (User: ) Description: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}SW_PROV0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen Schattenkopien abfragen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshotkontext: 13 Snapshotkontext: 13 Ausführungskontext: Coordinator Error: (06/06/2014 02:50:14 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: C:\Windows\system32\svchost.exe -k netsvcsWindows Update0x80042302 Error: (06/06/2014 02:50:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: GetProviderMgmtInterface0x8004230f, Unerwarteter Fehler beim Schattenkopieanbieter bei dem Versuch, den angegebenen Vorgang zu verarbeiten. Error: (06/06/2014 02:50:14 PM) (Source: VSS) (EventID: 12292) (User: ) Description: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Anbieterverwaltungsschnittstelle wird abgerufen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {00000000-0000-0000-0000-000000000000} Snapshotkontext: -1 Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Error: (06/06/2014 02:50:14 PM) (Source: VSS) (EventID: 13) (User: ) Description: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}SW_PROV0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Anbieterverwaltungsschnittstelle wird abgerufen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {00000000-0000-0000-0000-000000000000} Snapshotkontext: -1 Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Error: (06/06/2014 02:47:04 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/06/2014 11:42:54 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/05/2014 11:30:52 PM) (Source: VSS) (EventID: 12292) (User: ) Description: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen Schattenkopien abfragen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshotkontext: 13 Snapshotkontext: 13 Ausführungskontext: Coordinator Error: (06/05/2014 11:30:52 PM) (Source: VSS) (EventID: 13) (User: ) Description: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}SW_PROV0x80070422, Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden. Vorgang: Für diesen Anbieter eine aufrufbare Schnittstelle abrufen Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen Schattenkopien abfragen Kontext: Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshotkontext: 13 Snapshotkontext: 13 Ausführungskontext: Coordinator CodeIntegrity Errors: =================================== Date: 2014-05-07 09:41:29.811 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Windows Defender\MpUXSrv.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-06 13:31:40.826 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ImmersiveControlPanel\SystemSettings.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-06 13:31:40.823 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ImmersiveControlPanel\SystemSettings.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-06 13:31:40.336 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\explorer.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-06 13:31:40.300 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\explorer.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-06 13:31:40.257 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\explorer.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-06 13:31:40.212 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\BrowserChoice\browserchoice.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-06 13:31:40.207 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\BrowserChoice\browserchoice.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-06 13:31:40.203 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\explorer.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-06 13:31:40.162 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\explorer.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 39% Total physical RAM: 4094.49 MB Available physical RAM: 2458.36 MB Total Pagefile: 8187.25 MB Available Pagefile: 6369.06 MB Total Virtual: 2047.88 MB Available Virtual: 1883.52 MB ==================== Drives ================================ Drive c: ( ) (Fixed) (Total:931.41 GB) (Free:277.51 GB) NTFS Drive d: ( ) (Fixed) (Total:931.51 GB) (Free:848.72 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 30131FA8) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 3558A12E) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
06.06.2014, 14:12 | #22 |
/// TB-Ausbilder /// Anleitungs-Guru | cpu 100% und exe lassen sich nicht öffen
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
06.06.2014, 14:19 | #23 |
| cpu 100% und exe lassen sich nicht öffen fehler 183: eine datei kann nicht erstellt werden wenn sie bereits vorhanden ist |
06.06.2014, 14:26 | #24 |
/// TB-Ausbilder /// Anleitungs-Guru | cpu 100% und exe lassen sich nicht öffen Ok. Dann bitte mal das auf den Desktop runterladen. Download Alle Anwendungen beenden. Datei ausführen. Nach dem Neustart versuchen MBAM 2.0.2 erneut zu installieren.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
06.06.2014, 14:34 | #25 |
| cpu 100% und exe lassen sich nicht öffen run-time error ´13´: type mismatch |
06.06.2014, 14:37 | #26 |
/// TB-Ausbilder /// Anleitungs-Guru | cpu 100% und exe lassen sich nicht öffen Downloade Dir HitmanProauf Deinen Desktop: HitmanPro - 32 Bit HitmanPro - 64 Bit
Poste bitte den Inhalt der HitmanPro_<Datum_Uhrzeit>.txt mit Deiner nächsten Antwort.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
06.06.2014, 14:44 | #27 |
| cpu 100% und exe lassen sich nicht öffenCode:
ATTFilter
|
06.06.2014, 14:49 | #28 |
/// TB-Ausbilder /// Anleitungs-Guru | cpu 100% und exe lassen sich nicht öffen OK, Schritt 1 ESET Online Scanner
Schritt 2 Bitte starte FRST erneut und drücke auf Scan. Bitte poste die Logs von ESET und FRST.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
07.06.2014, 00:11 | #29 |
| cpu 100% und exe lassen sich nicht öffenCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=32f8624a5225db4b89b36b5305874373 # engine=18594 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-06-06 04:25:12 # local_time=2014-06-06 06:25:12 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7600 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 12579 153703103 0 0 # scanned=387813 # found=35 # cleaned=0 # scan_time=5032 sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\$RECYCLE.BIN\S-1-5-21-2003490431-1003139620-1941303677-500\$RN5PE51\Quarantine\C\Users\Mafia\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=04C4825F430B685CA0EA9DED5491C33F576D5806 ft=1 fh=f155009c0f237a2a vn="Variante von Win32/Packed.VProtect.C evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\Unlockroot Pro\unlockrootpro.exe" sh=95AE9706FF5E3B4396948CCBB54DEE305BD09793 ft=1 fh=4573e272ff6777ef vn="Variante von Win32/Packed.VMProtect.ABD Trojaner" ac=I fn="C:\Users\Mafia\Documents\UseNeXT\wizard\Uploader.Presents-Watch.Dogs.Digital.Deluxe.Editio\DOGS_DDE_M2.exe" sh=04E8F8028ED9EC35DB67AF3AEB7E6C2CB6C63D14 ft=1 fh=fb14e8b18daf2e75 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Mafia\Downloads\7 Zip 32 Bit - CHIP-Downloader.exe" sh=C19C930D957A808B02BBC544B3C462603A01B010 ft=1 fh=83268a46bbb05640 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Mafia\Downloads\AdwCleaner - CHIP-Installer.exe" sh=CA6A7826154B8B28B2CF35B7C9479BEA5E6BF87C ft=1 fh=dc225fa9a3192e4a vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Mafia\Downloads\Emma Sony Flash Tool - CHIP-Installer.exe" sh=D0DD893859D062D6BB83162230C04DBE05AB1574 ft=1 fh=7b20d19408a18e22 vn="Win32/OutBrowse.N evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Mafia\Downloads\GadgetWide iCloud Manager Installer.exe" sh=D3B13F31A2277D7AF16506A6CB6053A9D729A890 ft=1 fh=78cace3e93567d5c vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Mafia\Downloads\Install_ipswDownloader_v201_hf.exe" sh=2718B3810797F065922AB45075F1B0B0C807D4D0 ft=1 fh=5e4175fa06b0e95c vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Mafia\Downloads\LogMeIn Hamachi - CHIP-Downloader.exe" sh=3CDCD10CF0ECC168F33E4BF006D4E61DEFDAA1EE ft=1 fh=257e1da52ff191c4 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Mafia\Downloads\PDF Experte Ultimate - CHIP-Downloader.exe" sh=F1EFF6451CED129C0E5C0A510955F234A01158A0 ft=1 fh=332b4278a72373e2 vn="Variante von Win32/Toolbar.Babylon.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Mafia\Downloads\Unlocker1.9.2.exe" sh=F149D412C0F1A75F079960BCCDC78D210F6DA2DE ft=0 fh=0000000000000000 vn="VBS/Starter.NAQ Trojaner" ac=I fn="C:\Users\Mafia\sixfs\5377792.vbe" sh=6DC42E4D9A29B55D9D7EC955C50F936FB4932F8F ft=0 fh=0000000000000000 vn="BAT/Starter.NBI Trojaner" ac=I fn="C:\Users\Mafia\sixfs\start.cmd" sh=1FA3C04839207847206361F77D61025561A5B04B ft=1 fh=1706ee3dac8262db vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="D:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\Main\bin\CltMngSvc.exe.vir" sh=FD5121BC2F11862D3324AE86F2116ED013103F99 ft=1 fh=df1bd3512b7ec240 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="D:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\Main\bin\SPTool.dll.vir" sh=596CFF4528856C198441A006377675FAF3309761 ft=1 fh=5ac51af7cef04fb3 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="D:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\Main\bin\uninstall.exe.vir" sh=C71DCD09B102C292CED61577E35CFF68EC47F9A2 ft=1 fh=3a0ae25475ae5132 vn="Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung" ac=I fn="D:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe.vir" sh=D107BE4B0F4D358844142012699DDC6339819FCF ft=1 fh=b4c8c0c36e324fbb vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="D:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\SPVC32.dll.vir" sh=5CC0E91536E4B1CBC57E83E054F5C326A31F975A ft=1 fh=4906369e873dd708 vn="Variante von Win64/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="D:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\SPVC64Loader.dll.vir" sh=675E1D9758C13A878EB3D7CE54C9606C1966AB3C ft=1 fh=ab22d280f9ebad86 vn="Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung" ac=I fn="D:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\UI\bin\cltmngui.exe.vir" sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="D:\AdwCleaner\Quarantine\C\Users\stefan\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=8871E6FA32DFAA68F84F8E87D81C3222996D41A9 ft=1 fh=9527eda5fc81439a vn="Variante von Win32/Packed.VMProtect.ABD Trojaner" ac=I fn="D:\Program Files (x86)\Watch Dogs Digital Deluxe Edition\bin\Watch_Dogs_3dm.exe" sh=1FBCCE3ECEBD5955F90E91C6B6B74EE06783CD66 ft=1 fh=cdd42cd0b2145c18 vn="Variante von Win32/Conduit.SearchProtect.N evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\AppData\Local\Microsoft\Windows\INetCache\IE\1MQLW2AZ\spstub[1].exe" sh=0CE78CDB7AE8C457229124E383DA64FBDE7AE471 ft=1 fh=fd716b0c5f46d82e vn="Win32/OutBrowse.R evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\AppData\Local\Microsoft\Windows\INetCache\IE\YPVXDBAB\SearchProtectGeneric4Setup[1].exe" sh=0FF9DA392F4DC200E28078ADBC73FF8B53C1EC5B ft=1 fh=c71c00117aa9bf9d vn="Variante von Win32/OutBrowse.D evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\AppData\Local\Temp\ins.exe" sh=F2C3DE7EB064050E7107C5EB48FC5C839E8718BD ft=1 fh=6ce3192e088410d8 vn="Variante von Win32/AdGazelle.A evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\AppData\Local\Temp\qms.exe" sh=FF95989BB863D8AAF97644A00D90100FF4CC71C4 ft=1 fh=8edd0c34d00f1aee vn="Variante von Win32/ELEX.AJ evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\AppData\Local\Temp\smt_qone8.exe" sh=73BD134304E06614DFA40C9E66ECCCB9695BE1BD ft=1 fh=3c78bb21378aa491 vn="Variante von Win32/DealPly.M evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\AppData\Local\Temp\is1597349865\1352239_stp.EXE" sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\AppData\Local\Temp\Neuer Ordner\OCS\ocs_v71b.exe" sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\AppData\Local\Temp\OCS\ocs_v71b.exe" sh=95AE9706FF5E3B4396948CCBB54DEE305BD09793 ft=1 fh=4573e272ff6777ef vn="Variante von Win32/Packed.VMProtect.ABD Trojaner" ac=I fn="D:\Users\stefan\Desktop\alt.binaries.b4e.erotica\DOGS_DDE_M2.exe" sh=9277C68272B7B31E36739F8AB70324A1BD26B7A8 ft=1 fh=a76bc2c4dbb2046e vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\Downloads\AdwCleaner - CHIP-Installer.exe" sh=E731F8D2632DA11060C6F3A8DDDE5FF133673FE0 ft=1 fh=5b93964dcb84ed76 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\Downloads\iPhone Backup Extractor - CHIP-Installer.exe" sh=0C08A38710BFD864B08E17BDCA33BA83E2C1C7BD ft=1 fh=b5e0a9ef53c41549 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="D:\Users\stefan\Downloads\Java Runtime Environment 32 Bit - CHIP-Installer.exe" sh=8871E6FA32DFAA68F84F8E87D81C3222996D41A9 ft=1 fh=9527eda5fc81439a vn="Variante von Win32/Packed.VMProtect.ABD Trojaner" ac=I fn="D:\Users\stefan\Downloads\Crack\Watch_Dogs_3dm.exe" |
07.06.2014, 00:14 | #30 | |
/// TB-Ausbilder /// Anleitungs-Guru | cpu 100% und exe lassen sich nicht öffenZitat:
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |