|
Plagegeister aller Art und deren Bekämpfung: Ereignis div. FehlermeldungenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
10.07.2014, 22:26 | #1 |
| Ereignis div. Fehlermeldungen Hallo, ich habe mal wieder div. Ereignisprotokolle die Fehler aufweisen und ich nicht weiter weiß. Achtung: Zudem bekomme ich seit neusten wieder sehr komische Mails: Bei einem Online-Spiel bekomme ich dauernt die Mail, dass ich Versuche den "Anzeigenamen" zu ändern dort stande auch eine IP dabei. Die IP kam aus Japan und einmal aus der USA. Ich habe das Gefühl das mein PC irgendwie "angeriffen" wird und versucht wird meine Daten zu klauen. E-Mail passwort habe ich schon 2 mal geändert. Die Fehlermeldungen treten erst seit heute komischerweise auf. Auszüge aus den Ereignisprotokollen: 1. "Die Beschreibung für die Ereignis-ID "255" aus der Quelle "Python Service" wurde nicht gefunden. Entweder ist die Komponente, die dieses Ereignis auslöst, nicht auf dem lokalen Computer installiert, oder die Installation ist beschädigt. Sie können die Komponente auf dem lokalen Computer installieren oder reparieren." Was ist Pyhton Service? Wie kann ich es dieinstallieren? 2. "Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: Es wird bereits eine Instanz des Dienstes ausgeführt." 3. Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. 4. Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) 5. Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) 6. Vom Suchdienst wurden beschädigte Datendateien im Index {id=4700} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) 7. Windows (3528) Windows: Fehler -1811 beim Öffnen von Protokolldatei C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00026.log. 8. Windows Search wird gestartet, und der alte Suchindex wird entfernt {Ursache: Indexbeschädigung}. So geht es munter weiter hier ist der FRST-Log Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-07-2014 Ran by Horst at 2014-07-10 23:06:02 Running from C:\Users\Horst\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 4K Stogram 1.6 (HKLM-x32\...\4K Stogram_is1) (Version: 1.6.0.600 - Open Media LLC) Adobe Flash Player 11 ActiveX (HKLM-x32\...\{E94EFAB6-653F-4837-9E8A-F6377CA1EC0D}) (Version: 11.8.800.175 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.125 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Arma 3 (HKLM-x32\...\Steam App 107410) (Version: - Bohemia Interactive) Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.3.2.3825 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.4.0 - EA Digital Illusions CE AB) CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform) CPUID CPU-Z 1.69 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited) Creative Lautsprechereinstellungen (HKLM-x32\...\SPEAKER) (Version: - ) Creative-Audiokonsole (HKLM-x32\...\AudioCS) (Version: 1.33 - Creative Technology Limited) Creative-Grafik-Equalizer (HKLM-x32\...\Equalizer) (Version: - ) DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) DDL und DTS Connect-Lizenzaktivierung (HKLM-x32\...\AcMgrDDL) (Version: - ) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{043645C8-48EC-458F-B9BD-9C8F15CEF6F7}) (Version: - Microsoft) DH Driver Cleaner Professional Edition (HKLM-x32\...\Driver Cleaner Pro) (Version: Version 1.5 - Ruud Ketelaars) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Diablo III Public Test (HKLM-x32\...\Diablo III Public Test) (Version: - Blizzard Entertainment) Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited) Drakensang Online (HKLM-x32\...\Drakensang Online) (Version: - ) Driver Booster (HKLM-x32\...\Driver Booster_is1) (Version: 1.4 - IObit) DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited) Dxtory version 2.0.122 (HKLM-x32\...\Dxtory2.0_is1) (Version: 2.0.122 - Dxtory Software) Emsisoft Anti-Malware (HKLM-x32\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 9.0 - Emsisoft GmbH) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) Full Tilt Poker.Eu (HKLM-x32\...\{127BEFB3-24B2-4B44-8E99-AD22C2A5A8ED}) (Version: 5.14.1.WIN.FullTilt.EU - ) Geeks3D FurMark 1.13.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D) GomezPEER (HKLM-x32\...\GomezPEER) (Version: 3.2 - Gomez Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) herdProtect Anti-Malware Scanner (HKLM-x32\...\herdProtectScan) (Version: 1.0 - Reason Company Software Inc.) Intel Processor Diagnostic Tool 64bit (HKLM\...\{B1E50355-2437-40B0-A016-67B7490FC93E}) (Version: 2.10.0.0 - Intel Corporation) Intel(R) Chipset Device Software (Version: 10.0.13 - Intel Corporation) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Network Connections 19.1.51.0 (HKLM\...\PROSetDX) (Version: 19.1.51.0 - Intel) Intel(R) Network Connections 19.1.51.0 (Version: 19.1.51.0 - Intel) Hidden Intel(R) Update Manager (HKLM-x32\...\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (x32 Version: 10.0.13 - Intel(R) Corporation) Hidden Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden Java 7 Update 55 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417055FF}) (Version: 7.0.550 - Oracle) Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.49.8 - Black Tree Gaming) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.5 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 337.88 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 337.88 - NVIDIA Corporation) NVIDIA GeForce Experience 2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.157.1165 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) NVIDIA ShadowPlay 14.6.22 (Version: 14.6.22 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6514 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 337.88 (Version: 337.88 - NVIDIA Corporation) Hidden NVIDIA Update 14.6.22 (Version: 14.6.22 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 14.6.22 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.23 (Version: 1.2.23 - NVIDIA Corporation) Hidden Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 9.4.6.2792 - Electronic Arts, Inc.) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.76.1.0 - Overwolf Ltd.) PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge) PingPlotter Pro 3.42.3p (HKLM-x32\...\{76BFD10E-1701-43F4-BAF9-57FD51724A7A}) (Version: 3.42.3.5 - Nessoft, LLC) PokerStars.eu (HKLM-x32\...\PokerStars.eu) (Version: - PokerStars.eu) PokerStars.net (HKLM-x32\...\PokerStars.net) (Version: - PokerStars.net) Prison Architect (HKLM-x32\...\Steam App 233450) (Version: - Introversion Software) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Razer DeathAdder(TM) Mouse (HKLM-x32\...\{EB1B8449-CD8F-485B-ADB6-02FBCFE180D3}) (Version: 3.05 - Razer Inc.) Reversion - The Escape (HKLM-x32\...\Steam App 270570) (Version: - 3f Interactive) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden SHIELD Streaming (Version: 2.1.214 - NVIDIA Corporation) Hidden SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: - ) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.) Spyware Terminator 2012 (HKLM-x32\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.82 - Crawler.com) SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) SUPER © v2014.build.60+Recorder (2014/02/18) Version v2014.buil (HKLM-x32\...\{8E2A18E2-96AF-8549-4DE7-5C06B75719A4}_is1) (Version: v2014.build.60+Recorder - eRightSoft) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.7.1018 - SUPERAntiSpyware.com) System Requirements Lab for Intel (HKLM-x32\...\{04C4B49D-45D9-4A28-9ED1-B45CBD99B8C7}) (Version: 4.5.24.0 - Husdawg, LLC) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.28223 - TeamViewer) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Forest (HKLM-x32\...\Steam App 242760) (Version: - Endnight Games Ltd) Thief (HKLM-x32\...\Steam App 239160) (Version: - Eidos-Montréal) Tropico 5 (HKLM-x32\...\Steam App 245620) (Version: - Haemimont Games) Unknown Device Identifier 8.00 (HKLM\...\Unknown Device Identifier_is1) (Version: - Huntersoft) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version: - Microsoft) Update for Microsoft Excel 2010 (KB2837600) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{17815BC8-062D-49BE-B40C-B54149C85CE3}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{84B191B5-5319-463A-A305-8C4D53B1D20A}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{DB0B0CDF-77EC-47B0-94E2-4738573A1E58}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817396) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{1AA82E2E-7DB7-4C70-910C-BBB657A6B3A5}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{6E760BBA-B83F-4C2D-918F-5F91EF6C9861}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUS_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{D1F3B526-7EB2-4701-92DB-0784988D78DE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837606) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{52BEF8AE-9324-40A1-9A92-E5A8FB63A475}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 64-Bit Edition (HKLM\...\{90140000-001F-0410-1000-0000000FF1CE}_Office14.PROPLUS_{B2508D75-61CF-4CC0-84C0-CF257219201D}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUS_{8F699D53-05FB-488E-B7D3-E4E47257BE5D}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{324703B5-6765-489D-9B9B-B082D34F882E}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUS_{4B9B2BAF-EE1F-4B60-A4D9-17B7BEEB13A1}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{DDDC32A5-9528-4771-B91A-97A8E1D7957B}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-001A-0407-1000-0000000FF1CE}_Office14.PROPLUS_{6164E0E5-C903-488C-93AF-1B7AF7EBC331}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A20A650C-F820-4CE4-AEA5-EC140192FAFB}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0018-0407-1000-0000000FF1CE}_Office14.PROPLUS_{FD360122-6829-4497-97C1-1BF578EF695B}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F6F342A1-530B-4D48-A468-1E3F70928984}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{C950A55F-82E3-4CC8-8FA2-E8A2A0F651F3}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2880529) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{89FDC8D9-FB84-4EFE-950D-AF4EECC3B64C}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 4.5 - Ubisoft) VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN) Warface (HKLM-x32\...\Steam App 291480) (Version: - Crytek GmbH) Watch_Dogs (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft) WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) Wireshark 1.10.7 (64-bit) (HKLM-x32\...\Wireshark) (Version: 1.10.7 - The Wireshark developer community, hxxp://www.wireshark.org) XSplit Broadcaster (HKLM-x32\...\{3A1F3A32-7E9D-4AD2-A2E2-DFC98BAA9DC7}) (Version: 1.3.1403.1202 - SplitMediaLabs) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {221C3E26-787D-4253-962D-EE6094A72E25} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-30] (Google Inc.) Task: {392E6DDA-B295-4F88-9BFB-82A890F1013D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {4EB270C1-0177-4F5D-A7E8-D2F6EFE18B46} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-30] (Google Inc.) Task: {64B3AC2C-B1FE-4B2E-8485-0D605824F9FA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {6A072FE0-3B98-445A-B489-CB3400F1526F} - System32\Tasks\Driver Booster SkipUAC (Horst) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe <==== ATTENTION Task: {6BEA3F9B-AB38-44A8-A200-921DC2AB3E54} - \Driver Booster Update No Task File <==== ATTENTION Task: {814FC172-DC09-483B-B2EF-91735DEDA030} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {87871CC4-6919-492B-BD61-A1ABCBA8F47C} - \Driver Booster Scan No Task File <==== ATTENTION Task: {A0D0D7A1-EC04-4376-9973-360977291CE1} - System32\Tasks\CCleanerSkipUAC => D:\Tools\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd) Task: {A120AAD3-F486-4ACC-8B94-93B3E4A126C3} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] () Task: {A678D38A-B2D5-4FEF-938A-271869349A4B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] () Task: {FE758165-0C9C-43C6-8C19-4DA112F2BB50} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2014-06-10] (Overwolf LTD) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2012-06-18 17:24 - 2012-06-18 17:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll 2014-03-24 15:11 - 2013-04-15 12:50 - 00198144 _____ () C:\Windows\System32\HP1006LM.DLL 2014-03-24 15:11 - 2013-04-15 12:50 - 00065024 _____ () C:\Windows\system32\spool\PRTPROCS\x64\HP1006PP.dll 2014-06-28 12:41 - 2014-06-28 12:41 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe 2014-03-23 00:51 - 2012-01-14 13:56 - 00248832 _____ () C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe 2014-03-23 00:51 - 2011-12-28 17:29 - 00218112 _____ () C:\Program Files (x86)\Razer\DeathAdder\razertra.exe 2014-03-23 00:51 - 2011-04-14 12:48 - 01758208 _____ () C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe 2014-02-28 11:14 - 2014-02-28 11:14 - 00173568 _____ () D:\Tools\TeamSpeak3\quazip.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 01080832 _____ () D:\Tools\TeamSpeak3\platforms\qwindows.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00833024 _____ () D:\Tools\TeamSpeak3\sqldrivers\qsqlite.dll 2014-02-28 15:07 - 2014-06-28 10:25 - 00102344 _____ () D:\Tools\TeamSpeak3\soundbackends\directsound_win64.dll 2014-02-28 15:07 - 2014-06-28 10:25 - 00108488 _____ () D:\Tools\TeamSpeak3\soundbackends\windowsaudiosession_win64.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00030208 _____ () D:\Tools\TeamSpeak3\imageformats\qgif.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00233984 _____ () D:\Tools\TeamSpeak3\imageformats\qjpeg.dll 2014-02-28 15:10 - 2014-06-28 10:25 - 00563144 _____ () D:\Tools\TeamSpeak3\plugins\clientquery_plugin.dll 2014-02-28 15:10 - 2014-06-28 10:25 - 00577480 _____ () D:\Tools\TeamSpeak3\plugins\teamspeak_control_plugin.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00159232 _____ () D:\Tools\TeamSpeak3\accessible\qtaccessiblewidgets.dll 2014-07-10 22:01 - 2014-06-18 15:50 - 00703800 _____ () C:\Program Files (x86)\Emsisoft Anti-Malware\fw32.dll 2014-07-10 22:03 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2014-07-10 22:03 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2014-07-10 22:03 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2014-07-10 22:03 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2014-07-10 22:03 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:5C321E34 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= MSCONFIG\Services: !SASCORE => 2 MSCONFIG\Services: a2AntiMalware => 2 MSCONFIG\Services: BEService => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: ICCS => 3 MSCONFIG\Services: Intel(R) Capability Licensing Service Interface => 2 MSCONFIG\Services: Intel(R) Capability Licensing Service TCP IP Interface => 3 MSCONFIG\Services: Intel(R) ME Service => 2 MSCONFIG\Services: Intel(R) PROSet Monitoring Service => 2 MSCONFIG\Services: iumsvc => 3 MSCONFIG\Services: jhi_service => 2 MSCONFIG\Services: LMS => 2 MSCONFIG\Services: NvNetworkService => 2 MSCONFIG\Services: NvStreamSvc => 2 MSCONFIG\Services: nvsvc => 2 MSCONFIG\Services: PDF Architect 2 => 3 MSCONFIG\Services: pdfforge CrashHandler => 3 MSCONFIG\Services: TeamViewer9 => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GomezPEER.lnk => C:\Windows\pss\GomezPEER.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^iSCTsysTray.lnk => C:\Windows\pss\iSCTsysTray.lnk.CommonStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: BCSSync => "D:\Tools\Microsoft Office Professional Plus 2010\Office14\BCSSync.exe" /DelayServices MSCONFIG\startupreg: DAEMON Tools Lite => "D:\Tools\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: FlashPlayerUpdate => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_13_0_0_206_Plugin.exe -update plugin MSCONFIG\startupreg: HotKeysCmds => "C:\Windows\system32\hkcmd.exe" MSCONFIG\startupreg: IAStorIcon => "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60 MSCONFIG\startupreg: IMSS => "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" MSCONFIG\startupreg: Overwolf => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent MSCONFIG\startupreg: Persistence => "C:\Windows\system32\igfxpers.exe" MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" MSCONFIG\startupreg: XFastUSB => "C:\Program Files (x86)\XFastUSB\XFastUsb.exe" ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Gigabit PCI Express Network Adapter Description: Gigabit PCI Express Network Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: TP-LINK TECHNOLOGIES CO., LTD Service: tpg64win7 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Creative Game Port Description: Creative Game Port Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318} Manufacturer: Creative Technology Ltd. Service: ctgame Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19) Resolution: A registry problem was detected. This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options: On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver. ==================== Event log errors: ========================= Application errors: ================== Error: (07/10/2014 10:32:48 PM) (Source: Python Service) (EventID: 255) (User: ) Description: Exception : (1058, 'StartService', 'Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Ger\xe4ten verbunden.') Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 7010) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 3058) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 3028) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 9002) (User: ) Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 7042) (User: ) Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 7040) (User: ) Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=4700} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 9000) (User: ) Description: Der Jet-Eigenschaftenspeicher kann von Windows Search nicht geöffnet werden. Details: 0x%08x (0xc0041800 - Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800)) System errors: ============= Error: (07/10/2014 10:28:19 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (07/10/2014 10:27:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/10/2014 10:27:49 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Microsoft Office Sessions: ========================= Error: (07/10/2014 10:32:48 PM) (Source: Python Service) (EventID: 255) (User: ) Description: Exception : (1058, 'StartService', 'Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Ger\xe4ten verbunden.') Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 7010) (User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 3058) (User: ) Description: Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 3028) (User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Search.TripoliIndexer Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Search.JetPropStore Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 9002) (User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 7042) (User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) The catalog is corrupt Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 7040) (User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) 4700 Error: (07/10/2014 10:27:49 PM) (Source: Windows Search Service) (EventID: 9000) (User: ) Description: Details: 0x%08x (0xc0041800 - Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800)) CodeIntegrity Errors: =================================== Date: 2014-05-24 00:06:34.529 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-23 20:40:27.466 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-23 18:40:45.357 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-23 13:43:58.576 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-23 11:02:32.763 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-23 08:51:02.377 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-23 06:54:59.451 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-22 22:33:26.872 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-22 22:31:03.981 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-22 22:29:14.090 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 28% Total physical RAM: 8111.09 MB Available physical RAM: 5823.21 MB Total Pagefile: 16220.36 MB Available Pagefile: 13418.16 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:59.53 GB) (Free:11.84 GB) NTFS Drive d: () (Fixed) (Total:465.75 GB) (Free:145.58 GB) NTFS Drive e: () (Fixed) (Total:465.75 GB) (Free:91.58 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 60 GB) (Disk ID: B4F32661) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=60 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 0EF270DC) Partition 1: (Not Active) - (Size=466 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-07-2014 Ran by Horst (administrator) on HORST-PC on 10-07-2014 23:05:35 Running from C:\Users\Horst\Desktop Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE (Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe () C:\Windows\System32\PnkBstrA.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe () C:\Program Files (x86)\Razer\DeathAdder\razertra.exe (Razer Inc.) C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe () C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Valve Corporation) D:\Spiele\Steam\Steam.exe (TeamSpeak Systems GmbH) D:\Tools\TeamSpeak3\ts3client_win64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1279480 2014-05-30] (NVIDIA Corporation) HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM-x32\...\Run: [DeathAdder] => C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe [248832 2012-01-14] () HKLM-x32\...\Run: [AsioThk32Reg] => REGSVR32.EXE /S CTASIO.DLL HKLM-x32\...\Run: [emsisoft anti-malware] => C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe [4841824 2014-07-09] (Emsisoft GmbH) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2014-03-21] (Microsoft Corporation) HKU\S-1-5-21-1090213475-1755308561-993384641-1000\...\Run: [SUPERAntiSpyware] => D:\Tools\SUPERAntiSpyware\SUPERAntiSpyware.exe [6564120 2014-06-14] (SUPERAntiSpyware) HKU\S-1-5-21-1090213475-1755308561-993384641-1000\...\RunOnce: [AsrOMG_Day1] - 0x00000000 HKU\S-1-5-21-1090213475-1755308561-993384641-1000\...\RunOnce: [AsrOMG_Day2] - 0x00000000 HKU\S-1-5-21-1090213475-1755308561-993384641-1000\...\RunOnce: [AsrOMG_Day3] - 0x00000000 HKU\S-1-5-21-1090213475-1755308561-993384641-1000\...\RunOnce: [AsrOMG_Day4] - 0x00000000 HKU\S-1-5-21-1090213475-1755308561-993384641-1000\...\RunOnce: [AsrOMG_Day5] - 0x00000000 HKU\S-1-5-21-1090213475-1755308561-993384641-1000\...\RunOnce: [AsrOMG_Day6] - 0x00000000 HKU\S-1-5-21-1090213475-1755308561-993384641-1000\...\RunOnce: [AsrOMG_Day0] - 0x00000000 HKU\S-1-5-21-1090213475-1755308561-993384641-1000\...\MountPoints2: {2227a7cc-b149-11e3-a14a-806e6f6e6963} - F:\ASRSetup.exe HKU\S-1-5-21-1090213475-1755308561-993384641-1000\...\MountPoints2: {fb8e5f58-b192-11e3-b62b-d050990eda43} - G:\SETUP.EXE ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 1 (GFS Unread Stub) -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => D:\Tools\Microsoft Office Professional Plus 2010\Office14\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 2 (GFS Stub) -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => D:\Tools\Microsoft Office Professional Plus 2010\Office14\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => D:\Tools\Microsoft Office Professional Plus 2010\Office14\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 3 (GFS Folder) -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => D:\Tools\Microsoft Office Professional Plus 2010\Office14\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 4 (GFS Unread Mark) -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => D:\Tools\Microsoft Office Professional Plus 2010\Office14\GROOVEEX.DLL (Microsoft Corporation) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default FF DefaultSearchEngine: SuchMaschine FF SearchEngineOrder.1: SuchMaschine FF SelectedSearchEngine: SuchMaschine FF Homepage: hxxp://www.google.de/ FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll () FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - D:\Tools\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.4 - D:\Tools\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\Horst\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation) FF SearchPlugin: C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\searchplugins\search_engine.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\ich@maltegoetz.de [2014-03-22] FF Extension: LavaFox V2 - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\info@djzig.com [2014-06-30] FF Extension: exfm - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\jid0-IsXX48jx4obwoZPnzG6RQB0pK9A@jetpack [2014-03-22] FF Extension: NetVideoHunter - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\netvideohunter@netvideohunter.com [2014-03-22] FF Extension: FT DeepDark - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2014-06-03] FF Extension: WOT - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-03-22] FF Extension: HP Detect - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2} [2014-03-22] FF Extension: DownloadHelper - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-07-04] FF Extension: DriverAgent Plugin for Firefox and Opera - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{F8CC37C3-CBEB-4A00-8CBF-26A88693F0C5} [2014-03-22] FF Extension: Bazzacuda Image Saver Plus - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{FF2FA6A4-B3B1-11DD-B910-6C9A55D89593} [2014-04-11] FF Extension: BatchDownload - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\batchdownload@panshisoft.cn.xpi [2014-03-22] FF Extension: SaveFrom.net helper - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\helper@savefrom.net.xpi [2014-03-22] FF Extension: Magic Actions for YouTube™ - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\jid0-UVAeBCfd34Kk5usS8A1CBiobvM8@jetpack.xpi [2014-03-22] FF Extension: rarchive - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\jid1-AusxzKACE9lLYQ@jetpack.xpi [2014-04-20] FF Extension: Deutsch (DE) Language Pack - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\langpack-de@firefox.mozilla.org.xpi [2014-06-09] FF Extension: NASA Night Launch - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\nasanightlaunch@example.com.xpi [2014-03-22] FF Extension: Noia Fox options - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\NoiaFoxoption@davidvincent.tld.xpi [2014-03-22] FF Extension: Toggle Persona - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\togglepersona@davidvincent.tld.xpi [2014-03-22] FF Extension: Stylish - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2014-03-22] FF Extension: ImageGrabber - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{546d2a00-2bbf-11dc-8314-0800200c9a66}.xpi [2014-03-22] FF Extension: Noia Fox - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi [2014-03-22] FF Extension: Soundcloud SUPER +2: Downloader and Recommender - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{988da70d-b78d-44a1-a9c7-ed11832a9e2e}.xpi [2014-03-22] FF Extension: Downloads Window - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{a7213cf2-fa1e-4373-88ff-255d0abd3020}.xpi [2014-03-22] FF Extension: Abduction! - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{b0e1b4a6-2c6f-4e99-94f2-8e625d7ae255}.xpi [2014-03-22] FF Extension: Shine Bright Skin Aero - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{c7b3cf78-9cbc-47b9-ba47-bb84a56069dd}.xpi [2014-03-22] FF Extension: Show my Password - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{cd617372-6743-4ee4-bac4-fbf60f35719e}.xpi [2014-03-22] FF Extension: Adblock Plus - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-22] FF Extension: Greasemonkey - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-03-22] FF Extension: Metal Lion Australis Graphite - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{F6D83238-A31E-451d-8BCB-28F6BAFECF10}.xpi [2014-05-13] FF Extension: Metal Lion Australis Scrollbars II - C:\Users\Horst\AppData\Roaming\Mozilla\Firefox\Profiles\5e1sner9.default\Extensions\{FDBAD97E-A258-4fe3-9CF6-60CF386C4422}.xpi [2014-05-13] Chrome: ======= CHR HomePage: CHR StartupUrls: "hxxp://www.google.de/" CHR Extension: (Google Docs) - C:\Users\Horst\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-30] CHR Extension: (Google Drive) - C:\Users\Horst\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-30] CHR Extension: (YouTube) - C:\Users\Horst\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-30] CHR Extension: (Adblock Plus) - C:\Users\Horst\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-03-30] CHR Extension: (Google-Suche) - C:\Users\Horst\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-30] CHR Extension: (Google Wallet) - C:\Users\Horst\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-30] CHR Extension: (Google Mail) - C:\Users\Horst\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-30] ==================== Services (Whitelisted) ================= S4 !SASCORE; D:\Tools\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-11] (SUPERAntiSpyware.com) R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4741384 2014-07-09] (Emsisoft GmbH) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-06-29] () [File not signed] S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2014-06-29] (Creative Labs) [File not signed] S3 Creative Dolby Digital Live Pack Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\DDLLicensing.exe [79360 2014-06-29] (Creative Labs) [File not signed] R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [File not signed] S4 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed] S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) S4 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-03] (Intel Corporation) S4 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation) S3 Microsoft SharePoint Workspace Audit Service; D:\Tools\Microsoft Office Professional Plus 2010\Office14\GROOVE.EXE [50942144 2013-12-19] (Microsoft Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) S4 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation) S4 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [976672 2014-06-10] (Overwolf LTD) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-06-28] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-08] () S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.) R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com) S4 TeamViewer9; D:\Tools\TeamViewer9\TeamViewer_Service.exe [5024576 2014-04-25] (TeamViewer GmbH) ==================== Drivers (Whitelisted) ==================== R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH) R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH) S3 AsrDrv101; C:\Windows\SysWOW64\Drivers\AsrDrv101.sys [22280 2014-03-22] (ASRock Incorporation) R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH) S3 cpudrv64; C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [17864 2011-06-02] () R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [487704 2014-03-14] (Intel Corporation) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation) S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [4221440 2014-01-25] (Intel Corporation) [File not signed] S3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-03-14] () S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation) S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [33448 2013-11-15] (Razer Inc) S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [30888 2013-11-15] (Razer Inc) R1 SASDIFSV; D:\Tools\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; D:\Tools\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2014-07-10] (Windows (R) Win 7 DDK provider) S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2014-03-22] () S3 tpg64win7; C:\Windows\System32\DRIVERS\tpg64win7.sys [648808 2013-06-21] (TP-LINK TECHNOLOGIES CO., LTD) S3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-03-22] () S3 AsrSetupDrv; \??\C:\Windows\SysWOW64\Drivers\AsrSetupDrv.sys [X] S3 AxtuDrv; \??\C:\Windows\SysWOW64\Drivers\AxtuDrv.sys [X] S3 dpclat_driver; \??\C:\Windows\system32\drivers\dpclat_driver.sys [X] S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-10 23:05 - 2014-07-10 23:05 - 00023348 _____ () C:\Users\Horst\Desktop\FRST.txt 2014-07-10 23:04 - 2014-07-10 23:05 - 00000000 ____D () C:\FRST 2014-07-10 23:03 - 2014-07-10 23:03 - 00002269 _____ () C:\Users\Horst\Desktop\Neues Textdokument (3).txt 2014-07-10 22:50 - 2014-07-10 22:50 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-07-10 22:50 - 2014-07-10 22:50 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-07-10 22:50 - 2014-07-10 22:50 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-07-10 22:50 - 2014-07-10 22:50 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-07-10 22:50 - 2014-07-10 22:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-07-10 22:50 - 2014-07-10 22:50 - 00000000 ____D () C:\Program Files\Java 2014-07-10 22:47 - 2014-07-10 22:47 - 02084864 _____ (Farbar) C:\Users\Horst\Desktop\FRST64.exe 2014-07-10 22:43 - 2014-07-10 22:43 - 00709260 _____ () C:\Users\Horst\Desktop\delfix_10.7.exe 2014-07-10 22:43 - 2014-07-10 22:42 - 03434761 _____ () C:\Users\Horst\Desktop\tweaking.com_windows_repair_aio.zip 2014-07-10 22:42 - 2014-07-10 22:42 - 01016261 _____ (Thisisu) C:\Users\Horst\Desktop\JRT.exe 2014-07-10 22:27 - 2014-07-10 22:27 - 00001064 _____ () C:\Windows\PFRO.log 2014-07-10 22:27 - 2014-07-10 22:27 - 00000056 _____ () C:\Windows\setupact.log 2014-07-10 22:27 - 2014-07-10 22:27 - 00000000 _____ () C:\Windows\setuperr.log 2014-07-10 22:09 - 2014-07-10 22:26 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-07-10 22:09 - 2014-07-10 22:09 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-07-10 22:09 - 2014-07-10 22:09 - 00001038 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk 2014-07-10 22:09 - 2014-07-10 22:09 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Spyware Terminator 2014-07-10 22:09 - 2014-07-10 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012 2014-07-10 22:09 - 2014-07-10 22:09 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-07-10 22:08 - 2014-07-10 22:25 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster 2014-07-10 22:08 - 2014-07-10 22:08 - 00001079 _____ () C:\Users\Public\Desktop\SpywareBlaster.lnk 2014-07-10 22:08 - 2014-07-10 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster 2014-07-10 22:08 - 2014-07-10 22:08 - 00000000 ____D () C:\ProgramData\Licenses 2014-07-10 22:08 - 2009-03-24 12:52 - 00129872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSSTDFMT.DLL 2014-07-10 22:07 - 2014-07-10 22:07 - 00000000 ____D () C:\ProgramData\Emsisoft 2014-07-10 22:04 - 2014-07-10 22:04 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-07-10 22:03 - 2014-07-10 22:08 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-07-10 22:03 - 2014-07-10 22:04 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-07-10 22:03 - 2014-07-10 22:03 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk 2014-07-10 22:03 - 2014-07-10 22:03 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-07-10 22:03 - 2014-07-10 22:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 2014-07-10 22:03 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2014-07-10 22:02 - 2014-07-10 22:02 - 00001091 _____ () C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk 2014-07-10 22:02 - 2014-07-10 22:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware 2014-07-10 21:58 - 2014-07-10 21:59 - 00000000 ____D () C:\Users\Horst\Desktop\pic 2014-07-10 21:57 - 2014-07-10 21:57 - 01348263 _____ () C:\Users\Horst\Desktop\adwcleaner_3.215.exe 2014-07-09 03:57 - 2014-07-09 03:57 - 01566800 _____ () C:\Users\Horst\ts3_recording_14_07_09_3_57_20.wav 2014-07-05 05:29 - 2014-07-05 05:56 - 00000000 ____D () C:\ProgramData\firebird 2014-07-05 05:29 - 2014-07-05 05:29 - 00000000 ____D () C:\Users\Horst\AppData\Local\pokerreader 2014-07-05 05:29 - 2014-07-05 05:29 - 00000000 ____D () C:\ProgramData\boost_interprocess 2014-07-05 05:28 - 2014-07-05 06:08 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sharktoolz 2014-07-05 05:28 - 2014-07-05 05:28 - 00000000 ____D () C:\ProgramData\sharktoolz 2014-07-05 05:25 - 2014-07-05 05:25 - 00000000 ____D () C:\Users\Horst\AppData\Local\Hold'em_Manager 2014-07-05 05:15 - 2014-07-05 06:08 - 00034975 _____ () C:\blitzerr.txt 2014-07-05 05:12 - 2014-07-05 05:12 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\HEM Data 2014-07-05 05:12 - 2014-07-05 05:12 - 00000000 ____D () C:\HM2Archive 2014-07-05 05:11 - 2014-07-05 06:08 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\HoldemManager 2014-07-05 05:11 - 2014-07-05 05:11 - 00000000 ____D () C:\Users\Horst\AppData\Local\IsolatedStorage 2014-07-05 05:11 - 2014-07-05 05:11 - 00000000 ____D () C:\ProgramData\XHEO INC 2014-07-05 05:10 - 2014-07-05 05:10 - 00020520 _____ () C:\Users\Horst\Desktop\install.log 2014-07-05 05:09 - 2014-07-05 05:09 - 00000020 ___SH () C:\Users\postgres\ntuser.ini 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Vorlagen 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Startmenü 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Netzwerkumgebung 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Lokale Einstellungen 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Eigene Dateien 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Druckumgebung 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Documents\Eigene Musik 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Documents\Eigene Bilder 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\AppData\Local\Verlauf 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\AppData\Local\Anwendungsdaten 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Anwendungsdaten 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 ____D () C:\Users\postgres 2014-07-05 05:09 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-07-05 05:09 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-07-05 05:08 - 2014-07-05 06:09 - 00000000 ____D () C:\postgreSQL 2014-07-05 04:34 - 2014-07-05 04:35 - 00000000 ____D () C:\Users\Horst\AppData\Local\Poker Pro Labs 2014-07-05 04:34 - 2014-07-05 04:34 - 00000000 ____D () C:\Users\Horst\Documents\Poker Pro Labs 2014-07-05 04:11 - 2014-07-05 04:11 - 00000000 ____D () C:\Users\Horst\AppData\Local\PokerEdge 2014-07-05 04:08 - 2014-07-08 19:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerEdge 2014-07-04 03:46 - 2014-07-04 03:46 - 00000000 ____D () C:\Users\Horst\dwhelper 2014-07-02 15:14 - 2014-07-02 15:14 - 00000000 ____D () C:\Users\Horst\AppData\Local\CrashRpt 2014-07-01 16:17 - 2014-07-03 11:29 - 00000000 ____D () C:\Users\Horst\AppData\Local\wf-launcher 2014-07-01 16:17 - 2014-07-03 11:17 - 00000000 ____D () C:\ProgramData\GFACE 2014-07-01 15:58 - 2014-07-01 15:58 - 00000209 _____ () C:\Users\Horst\Desktop\Warface.url 2014-06-29 13:43 - 2014-06-29 20:49 - 00001080 _____ () C:\Windows\system32\settingsbkup.sfm 2014-06-29 13:43 - 2014-06-29 20:49 - 00001080 _____ () C:\Windows\system32\settings.sfm 2014-06-29 13:38 - 2014-07-05 21:03 - 04931577 _____ () C:\Windows\{00000005-00000000-00000000-00001102-00000004-20021102}.CDF 2014-06-29 13:36 - 2009-02-09 13:40 - 00006010 ____N () C:\Windows\SysWOW64\CTOPT352.cat 2014-06-29 13:36 - 2009-01-30 15:47 - 00171680 ____N (Creative Technology Ltd) C:\Windows\SysWOW64\CTOPT352.dll 2014-06-29 13:36 - 2008-12-22 20:13 - 00061440 ____N (Creative Technology Ltd) C:\Windows\SysWOW64\CTChkAud.dll 2014-06-29 13:35 - 2014-06-29 13:35 - 00002041 _____ () C:\Users\Horst\Desktop\Creative-Audiokonsole.lnk 2014-06-29 13:35 - 2014-06-29 13:35 - 00000000 ____D () C:\Program Files\Creative 2014-06-29 13:16 - 2014-06-29 13:29 - 67457629 _____ (Igor Pavlov) C:\Users\Horst\Desktop\Audigy_SupportPack_3_8.exe 2014-06-29 13:10 - 2014-06-29 13:13 - 42380584 _____ (Creative Technology Ltd) C:\Users\Horst\Desktop\SBAX_PCDRV_LB_2_18_0017.exe 2014-06-29 02:46 - 2014-06-29 13:37 - 00000159 ___RH () C:\Windows\ctfile.rfc 2014-06-29 02:46 - 2011-12-16 17:18 - 00325120 _____ () C:\Windows\system32\APOMgr64.DLL 2014-06-29 02:46 - 2011-12-16 17:17 - 00246272 _____ () C:\Windows\SysWOW64\APOMngr.DLL 2014-06-29 02:46 - 2011-08-17 15:46 - 00089600 _____ () C:\Windows\system32\CmdRtr64.DLL 2014-06-29 02:46 - 2011-08-17 15:45 - 00074240 _____ () C:\Windows\SysWOW64\CmdRtr.DLL 2014-06-28 22:42 - 2014-07-05 02:59 - 00000000 ____D () C:\Users\Horst\AppData\Local\PokerStars.NET 2014-06-28 22:42 - 2014-06-28 22:42 - 00000703 _____ () C:\Users\Horst\Desktop\PokerStars.net.lnk 2014-06-28 22:42 - 2014-06-28 22:42 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStars.NET 2014-06-28 22:00 - 2014-06-28 22:32 - 00000000 ____D () C:\Users\Horst\AppData\Local\FullTiltPoker.eu 2014-06-28 22:00 - 2014-06-28 22:00 - 00000708 _____ () C:\Users\Public\Desktop\Full Tilt Poker.Eu.lnk 2014-06-28 22:00 - 2014-06-28 22:00 - 00000000 ____D () C:\Users\Horst\AppData\Local\cache 2014-06-28 22:00 - 2014-06-28 22:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Full Tilt Poker.Eu 2014-06-28 21:52 - 2014-07-08 19:35 - 00000000 ____D () C:\Users\Horst\AppData\Local\PokerStars.EU 2014-06-28 21:52 - 2014-06-28 21:52 - 00000679 _____ () C:\Users\Horst\Desktop\PokerStars.eu.lnk 2014-06-28 21:52 - 2014-06-28 21:52 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStars.EU 2014-06-28 12:41 - 2014-06-28 12:41 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe 2014-06-28 12:10 - 2014-07-10 21:22 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\vlc 2014-06-28 12:10 - 2014-06-28 12:10 - 00000699 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-06-28 12:10 - 2014-06-28 12:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2014-06-28 12:08 - 2014-06-28 12:08 - 25055851 _____ () C:\Users\Horst\Desktop\vlc-2.1.4-win64.exe 2014-06-28 10:49 - 2014-06-29 13:37 - 00466520 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-06-28 10:49 - 2014-06-29 13:37 - 00445016 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2014-06-28 10:49 - 2014-06-29 13:37 - 00123480 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-06-28 10:49 - 2014-06-29 13:37 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2014-06-28 10:49 - 2014-06-28 10:49 - 00000000 ____D () C:\Program Files (x86)\OpenAL 2014-06-28 10:46 - 2014-06-28 10:46 - 00003390 _____ () C:\Windows\System32\Tasks\{CD534650-7DF7-403C-AF27-A81007082E87} 2014-06-28 10:45 - 2014-06-28 10:45 - 00000000 ____D () C:\Users\Horst\Desktop\SB_Audigy_Series_Support_Pack_2.5 2014-06-28 10:36 - 2014-06-28 10:36 - 00000029 _____ () C:\Windows\sfbm.INI 2014-06-28 09:47 - 2014-06-28 09:47 - 00000684 _____ () C:\Users\Horst\Desktop\PingPlotter Pro.lnk 2014-06-28 09:46 - 2014-06-28 09:46 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\PingPlotter 2014-06-28 09:46 - 2014-06-28 09:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PingPlotter Pro 2014-06-28 09:45 - 2014-06-28 09:45 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Downloaded Installations 2014-06-28 09:34 - 2014-06-28 09:34 - 04425904 _____ () C:\Users\Horst\Desktop\pngplt_pro.exe 2014-06-27 14:53 - 2014-06-27 14:53 - 00000890 _____ () C:\Users\Public\Desktop\Diablo III Public Test.lnk 2014-06-27 14:52 - 2014-06-27 14:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III Public Test 2014-06-27 14:52 - 2014-06-27 14:52 - 03589024 _____ (Blizzard Entertainment) C:\Users\Horst\Desktop\Diablo-III-Public-Test-Setup-deDE.exe 2014-06-27 14:38 - 2014-06-27 14:38 - 00000000 ____D () C:\Users\Horst\Desktop\TG-3468_V2_120308 2014-06-27 14:15 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-27 14:15 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-27 14:15 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-27 14:15 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-27 14:15 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-27 14:15 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-27 14:15 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-27 14:15 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-27 14:15 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-27 14:15 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-27 14:15 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-27 14:15 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-27 14:15 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-27 14:15 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-27 14:15 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-27 14:15 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-27 14:15 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-27 14:15 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-27 14:15 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-27 14:15 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-27 14:15 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-27 14:15 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-27 14:15 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-27 14:15 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-06-27 14:15 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-27 14:15 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-27 14:15 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-06-27 14:15 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-27 14:15 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-27 14:15 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-27 14:15 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-27 14:15 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-06-27 14:15 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-27 14:15 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-06-27 14:15 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-06-27 14:15 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-27 14:15 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-27 14:15 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-27 14:15 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-27 14:15 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-27 14:15 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-27 14:15 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-27 14:15 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-27 14:15 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-27 14:15 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-27 14:15 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-06-27 14:15 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-27 14:15 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-27 14:15 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-27 14:15 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-27 14:15 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-27 14:15 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-27 14:15 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-27 14:15 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-06-27 14:15 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-06-27 14:15 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-06-27 14:15 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-27 14:15 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-27 14:15 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-27 14:15 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2014-06-27 14:15 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-27 14:15 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-27 14:15 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2014-06-27 14:15 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-06-27 14:15 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-27 14:15 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-27 14:15 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2014-06-27 14:15 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-06-27 14:12 - 2014-06-27 14:12 - 00000000 ____D () C:\Users\Horst\Downloads\LiveSetup 2014-06-27 00:16 - 2014-07-10 02:15 - 00000000 ____D () C:\Users\Horst\Desktop\Neuer Ordner (2) 2014-06-25 17:41 - 2014-06-25 17:42 - 00000000 ____D () C:\Users\Horst\Desktop\diesdas 2014-06-25 16:36 - 2014-06-25 16:36 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\PDF Architect 2 2014-06-24 05:53 - 2014-06-24 05:53 - 00000000 ____D () C:\Users\Horst\Documents\Nexus Mod Manager 2014-06-24 05:53 - 2014-06-24 05:53 - 00000000 ____D () C:\Users\Horst\AppData\Local\Black_Tree_Gaming 2014-06-24 05:52 - 2014-06-24 05:54 - 00000692 _____ () C:\Users\Public\Desktop\Nexus Mod Manager.lnk 2014-06-24 05:52 - 2014-06-24 05:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager 2014-06-23 08:54 - 2014-06-23 08:54 - 00000000 ____D () C:\Users\Horst\Desktop\Photoreal ENB V1_2 MORE REALISTIC COLOURS_ENBLENS OFF-50483-1-3 2014-06-23 08:41 - 2014-06-23 08:41 - 00000000 ____D () C:\Users\Horst\AppData\Local\Skyrim 2014-06-22 05:46 - 2014-06-22 05:46 - 00000098 _____ () C:\Users\Horst\AppData\Roaming\LauncherSettings_live.cfg 2014-06-22 05:33 - 2014-06-22 05:33 - 00000000 ____D () C:\Users\Horst\Documents\theHunter 2014-06-22 05:32 - 2014-06-22 05:34 - 00000041 _____ () C:\Users\Horst\AppData\Roaming\TheHunterSettings_steam_live.cfg 2014-06-22 05:32 - 2014-06-22 05:32 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\theHunter 2014-06-22 05:32 - 2014-06-22 05:32 - 00000000 ____D () C:\Users\Horst\AppData\Local\theHunter 2014-06-22 05:31 - 2014-06-22 05:31 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\theHunterSteam 2014-06-22 05:31 - 2014-06-22 05:31 - 00000000 ____D () C:\ProgramData\Hunter 2014-06-22 05:05 - 2014-06-22 05:05 - 00000209 _____ () C:\Users\Horst\Desktop\Reversion - The Escape.url 2014-06-20 03:22 - 2014-07-10 22:45 - 00915736 _____ () C:\Windows\WindowsUpdate.log 2014-06-20 01:59 - 2014-06-20 01:59 - 00000000 ____D () C:\Users\Horst\Desktop\NoMoreBirdsv1.4 2014-06-19 17:35 - 2014-06-19 17:35 - 00000000 ____D () C:\Users\Horst\AppData\Local\Adobe 2014-06-14 23:33 - 2014-07-09 21:09 - 00000145 _____ () C:\Users\Horst\Desktop\InternetProbs.txt 2014-06-14 02:16 - 2014-06-14 02:16 - 00003728 _____ () C:\Windows\System32\Tasks\Overwolf Updater Task 2014-06-14 02:15 - 2014-07-08 02:39 - 00000000 ____D () C:\Users\Horst\AppData\Local\Overwolf 2014-06-14 02:15 - 2014-06-17 20:16 - 00000000 ____D () C:\Program Files (x86)\Overwolf 2014-06-14 02:15 - 2014-06-14 02:15 - 00001971 _____ () C:\Users\Public\Desktop\Overwolf.lnk 2014-06-14 02:15 - 2014-06-14 02:15 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2014-06-14 02:15 - 2014-06-14 02:15 - 00000000 ____D () C:\ProgramData\Overwolf 2014-06-13 19:57 - 2014-06-13 19:58 - 00000000 ____D () C:\Users\Horst\Desktop\Wetten 2014-06-13 17:00 - 2014-06-13 17:15 - 00002244 ____H () C:\Users\Horst\Documents\Default.rdp 2014-06-13 07:00 - 2014-06-13 07:00 - 00000000 ____D () C:\Users\Horst\AppData\Local\PAYDAY 2 2014-06-13 07:00 - 2014-06-13 07:00 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-06-13 06:40 - 2014-06-13 06:40 - 00000209 _____ () C:\Users\Horst\Desktop\PAYDAY 2.url ==================== One Month Modified Files and Folders ======= 2014-07-10 23:05 - 2014-07-10 23:05 - 00023348 _____ () C:\Users\Horst\Desktop\FRST.txt 2014-07-10 23:05 - 2014-07-10 23:04 - 00000000 ____D () C:\FRST 2014-07-10 23:03 - 2014-07-10 23:03 - 00002269 _____ () C:\Users\Horst\Desktop\Neues Textdokument (3).txt 2014-07-10 22:50 - 2014-07-10 22:50 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-07-10 22:50 - 2014-07-10 22:50 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-07-10 22:50 - 2014-07-10 22:50 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-07-10 22:50 - 2014-07-10 22:50 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-07-10 22:50 - 2014-07-10 22:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-07-10 22:50 - 2014-07-10 22:50 - 00000000 ____D () C:\Program Files\Java 2014-07-10 22:47 - 2014-07-10 22:47 - 02084864 _____ (Farbar) C:\Users\Horst\Desktop\FRST64.exe 2014-07-10 22:45 - 2014-06-20 03:22 - 00915736 _____ () C:\Windows\WindowsUpdate.log 2014-07-10 22:44 - 2014-03-22 10:50 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-10 22:44 - 2014-03-21 19:11 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-10 22:43 - 2014-07-10 22:43 - 00709260 _____ () C:\Users\Horst\Desktop\delfix_10.7.exe 2014-07-10 22:43 - 2014-03-21 19:11 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-10 22:42 - 2014-07-10 22:43 - 03434761 _____ () C:\Users\Horst\Desktop\tweaking.com_windows_repair_aio.zip 2014-07-10 22:42 - 2014-07-10 22:42 - 01016261 _____ (Thisisu) C:\Users\Horst\Desktop\JRT.exe 2014-07-10 22:39 - 2014-03-30 07:07 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-10 22:34 - 2009-07-14 06:45 - 00016944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-10 22:34 - 2009-07-14 06:45 - 00016944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-10 22:32 - 2014-03-22 05:21 - 00000000 ____D () C:\Users\Horst\AppData\Local\Arma 3 2014-07-10 22:31 - 2014-04-12 21:54 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware 2014-07-10 22:27 - 2014-07-10 22:27 - 00001064 _____ () C:\Windows\PFRO.log 2014-07-10 22:27 - 2014-07-10 22:27 - 00000056 _____ () C:\Windows\setupact.log 2014-07-10 22:27 - 2014-07-10 22:27 - 00000000 _____ () C:\Windows\setuperr.log 2014-07-10 22:27 - 2014-05-17 14:18 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\IObit 2014-07-10 22:27 - 2014-05-17 14:18 - 00000000 ____D () C:\ProgramData\IObit 2014-07-10 22:27 - 2014-05-17 14:18 - 00000000 ____D () C:\Program Files (x86)\IObit 2014-07-10 22:27 - 2014-04-08 04:32 - 00000000 ____D () C:\AdwCleaner 2014-07-10 22:27 - 2014-03-30 07:07 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-10 22:27 - 2014-03-22 12:29 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-10 22:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-10 22:26 - 2014-07-10 22:09 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-07-10 22:26 - 2014-05-03 02:37 - 00000000 ____D () C:\ProgramData\Temp 2014-07-10 22:25 - 2014-07-10 22:08 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster 2014-07-10 22:09 - 2014-07-10 22:09 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-07-10 22:09 - 2014-07-10 22:09 - 00001038 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk 2014-07-10 22:09 - 2014-07-10 22:09 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Spyware Terminator 2014-07-10 22:09 - 2014-07-10 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012 2014-07-10 22:09 - 2014-07-10 22:09 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-07-10 22:08 - 2014-07-10 22:08 - 00001079 _____ () C:\Users\Public\Desktop\SpywareBlaster.lnk 2014-07-10 22:08 - 2014-07-10 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster 2014-07-10 22:08 - 2014-07-10 22:08 - 00000000 ____D () C:\ProgramData\Licenses 2014-07-10 22:08 - 2014-07-10 22:03 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-07-10 22:07 - 2014-07-10 22:07 - 00000000 ____D () C:\ProgramData\Emsisoft 2014-07-10 22:04 - 2014-07-10 22:04 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-07-10 22:04 - 2014-07-10 22:03 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-07-10 22:04 - 2014-04-12 21:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-10 22:03 - 2014-07-10 22:03 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk 2014-07-10 22:03 - 2014-07-10 22:03 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-07-10 22:03 - 2014-07-10 22:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 2014-07-10 22:02 - 2014-07-10 22:02 - 00001091 _____ () C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk 2014-07-10 22:02 - 2014-07-10 22:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware 2014-07-10 21:59 - 2014-07-10 21:58 - 00000000 ____D () C:\Users\Horst\Desktop\pic 2014-07-10 21:57 - 2014-07-10 21:57 - 01348263 _____ () C:\Users\Horst\Desktop\adwcleaner_3.215.exe 2014-07-10 21:57 - 2014-03-22 20:10 - 00000000 ____D () C:\Users\Horst\AppData\Local\Battle.net 2014-07-10 21:55 - 2014-04-12 21:54 - 00000000 ____D () C:\Users\Horst\Documents\Anti-Malware 2014-07-10 21:54 - 2014-06-04 00:34 - 00000000 ____D () C:\Users\Horst\AppData\Local\NCSOFT 2014-07-10 21:22 - 2014-06-28 12:10 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\vlc 2014-07-10 14:52 - 2014-04-07 20:21 - 00000000 ____D () C:\ProgramData\Origin 2014-07-10 12:29 - 2014-05-16 20:03 - 00000170 _____ () C:\Users\Horst\Desktop\Neues Textdokument.txt 2014-07-10 02:15 - 2014-06-27 00:16 - 00000000 ____D () C:\Users\Horst\Desktop\Neuer Ordner (2) 2014-07-09 21:09 - 2014-06-14 23:33 - 00000145 _____ () C:\Users\Horst\Desktop\InternetProbs.txt 2014-07-09 03:57 - 2014-07-09 03:57 - 01566800 _____ () C:\Users\Horst\ts3_recording_14_07_09_3_57_20.wav 2014-07-09 03:57 - 2014-03-22 00:38 - 00000000 ____D () C:\Users\Horst 2014-07-09 01:50 - 2014-05-21 18:35 - 00000618 _____ () C:\Users\Horst\Desktop\Neues Textdokument2.txt 2014-07-08 19:37 - 2014-07-05 04:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerEdge 2014-07-08 19:35 - 2014-06-28 21:52 - 00000000 ____D () C:\Users\Horst\AppData\Local\PokerStars.EU 2014-07-08 17:09 - 2014-04-08 04:02 - 00000865 _____ () C:\Users\Public\Desktop\Battlefield 4.lnk 2014-07-08 17:09 - 2014-04-08 04:02 - 00000849 _____ () C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk 2014-07-08 02:39 - 2014-06-14 02:15 - 00000000 ____D () C:\Users\Horst\AppData\Local\Overwolf 2014-07-05 21:03 - 2014-06-29 13:38 - 04931577 _____ () C:\Windows\{00000005-00000000-00000000-00001102-00000004-20021102}.CDF 2014-07-05 06:09 - 2014-07-05 05:08 - 00000000 ____D () C:\postgreSQL 2014-07-05 06:08 - 2014-07-05 05:28 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sharktoolz 2014-07-05 06:08 - 2014-07-05 05:15 - 00034975 _____ () C:\blitzerr.txt 2014-07-05 06:08 - 2014-07-05 05:11 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\HoldemManager 2014-07-05 05:56 - 2014-07-05 05:29 - 00000000 ____D () C:\ProgramData\firebird 2014-07-05 05:29 - 2014-07-05 05:29 - 00000000 ____D () C:\Users\Horst\AppData\Local\pokerreader 2014-07-05 05:29 - 2014-07-05 05:29 - 00000000 ____D () C:\ProgramData\boost_interprocess 2014-07-05 05:28 - 2014-07-05 05:28 - 00000000 ____D () C:\ProgramData\sharktoolz 2014-07-05 05:25 - 2014-07-05 05:25 - 00000000 ____D () C:\Users\Horst\AppData\Local\Hold'em_Manager 2014-07-05 05:12 - 2014-07-05 05:12 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\HEM Data 2014-07-05 05:12 - 2014-07-05 05:12 - 00000000 ____D () C:\HM2Archive 2014-07-05 05:11 - 2014-07-05 05:11 - 00000000 ____D () C:\Users\Horst\AppData\Local\IsolatedStorage 2014-07-05 05:11 - 2014-07-05 05:11 - 00000000 ____D () C:\ProgramData\XHEO INC 2014-07-05 05:10 - 2014-07-05 05:10 - 00020520 _____ () C:\Users\Horst\Desktop\install.log 2014-07-05 05:09 - 2014-07-05 05:09 - 00000020 ___SH () C:\Users\postgres\ntuser.ini 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Vorlagen 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Startmenü 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Netzwerkumgebung 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Lokale Einstellungen 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Eigene Dateien 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Druckumgebung 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Documents\Eigene Musik 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Documents\Eigene Bilder 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\AppData\Local\Verlauf 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\AppData\Local\Anwendungsdaten 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 _SHDL () C:\Users\postgres\Anwendungsdaten 2014-07-05 05:09 - 2014-07-05 05:09 - 00000000 ____D () C:\Users\postgres 2014-07-05 04:35 - 2014-07-05 04:34 - 00000000 ____D () C:\Users\Horst\AppData\Local\Poker Pro Labs 2014-07-05 04:34 - 2014-07-05 04:34 - 00000000 ____D () C:\Users\Horst\Documents\Poker Pro Labs 2014-07-05 04:11 - 2014-07-05 04:11 - 00000000 ____D () C:\Users\Horst\AppData\Local\PokerEdge 2014-07-05 02:59 - 2014-06-28 22:42 - 00000000 ____D () C:\Users\Horst\AppData\Local\PokerStars.NET 2014-07-04 03:46 - 2014-07-04 03:46 - 00000000 ____D () C:\Users\Horst\dwhelper 2014-07-03 12:47 - 2014-04-08 04:02 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-07-03 12:11 - 2014-04-08 04:02 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-07-03 11:29 - 2014-07-01 16:17 - 00000000 ____D () C:\Users\Horst\AppData\Local\wf-launcher 2014-07-03 11:17 - 2014-07-01 16:17 - 00000000 ____D () C:\ProgramData\GFACE 2014-07-02 15:14 - 2014-07-02 15:14 - 00000000 ____D () C:\Users\Horst\AppData\Local\CrashRpt 2014-07-01 15:58 - 2014-07-01 15:58 - 00000209 _____ () C:\Users\Horst\Desktop\Warface.url 2014-06-29 20:49 - 2014-06-29 13:43 - 00001080 _____ () C:\Windows\system32\settingsbkup.sfm 2014-06-29 20:49 - 2014-06-29 13:43 - 00001080 _____ () C:\Windows\system32\settings.sfm 2014-06-29 13:44 - 2014-03-22 17:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative 2014-06-29 13:37 - 2014-06-29 02:46 - 00000159 ___RH () C:\Windows\ctfile.rfc 2014-06-29 13:37 - 2014-06-28 10:49 - 00466520 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-06-29 13:37 - 2014-06-28 10:49 - 00445016 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2014-06-29 13:37 - 2014-06-28 10:49 - 00123480 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-06-29 13:37 - 2014-06-28 10:49 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2014-06-29 13:35 - 2014-06-29 13:35 - 00002041 _____ () C:\Users\Horst\Desktop\Creative-Audiokonsole.lnk 2014-06-29 13:35 - 2014-06-29 13:35 - 00000000 ____D () C:\Program Files\Creative 2014-06-29 13:35 - 2014-03-22 17:16 - 00000000 ____D () C:\Program Files (x86)\Creative 2014-06-29 13:34 - 2014-03-22 00:44 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-06-29 13:29 - 2014-06-29 13:16 - 67457629 _____ (Igor Pavlov) C:\Users\Horst\Desktop\Audigy_SupportPack_3_8.exe 2014-06-29 13:13 - 2014-06-29 13:10 - 42380584 _____ (Creative Technology Ltd) C:\Users\Horst\Desktop\SBAX_PCDRV_LB_2_18_0017.exe 2014-06-28 22:42 - 2014-06-28 22:42 - 00000703 _____ () C:\Users\Horst\Desktop\PokerStars.net.lnk 2014-06-28 22:42 - 2014-06-28 22:42 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStars.NET 2014-06-28 22:32 - 2014-06-28 22:00 - 00000000 ____D () C:\Users\Horst\AppData\Local\FullTiltPoker.eu 2014-06-28 22:00 - 2014-06-28 22:00 - 00000708 _____ () C:\Users\Public\Desktop\Full Tilt Poker.Eu.lnk 2014-06-28 22:00 - 2014-06-28 22:00 - 00000000 ____D () C:\Users\Horst\AppData\Local\cache 2014-06-28 22:00 - 2014-06-28 22:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Full Tilt Poker.Eu 2014-06-28 21:52 - 2014-06-28 21:52 - 00000679 _____ () C:\Users\Horst\Desktop\PokerStars.eu.lnk 2014-06-28 21:52 - 2014-06-28 21:52 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStars.EU 2014-06-28 12:41 - 2014-06-28 12:41 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe 2014-06-28 12:27 - 2014-04-08 04:02 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-06-28 12:10 - 2014-06-28 12:10 - 00000699 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-06-28 12:10 - 2014-06-28 12:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2014-06-28 12:08 - 2014-06-28 12:08 - 25055851 _____ () C:\Users\Horst\Desktop\vlc-2.1.4-win64.exe 2014-06-28 10:54 - 2014-03-22 17:23 - 00000000 ____D () C:\ProgramData\Creative 2014-06-28 10:49 - 2014-06-28 10:49 - 00000000 ____D () C:\Program Files (x86)\OpenAL 2014-06-28 10:46 - 2014-06-28 10:46 - 00003390 _____ () C:\Windows\System32\Tasks\{CD534650-7DF7-403C-AF27-A81007082E87} 2014-06-28 10:45 - 2014-06-28 10:45 - 00000000 ____D () C:\Users\Horst\Desktop\SB_Audigy_Series_Support_Pack_2.5 2014-06-28 10:36 - 2014-06-28 10:36 - 00000029 _____ () C:\Windows\sfbm.INI 2014-06-28 10:01 - 2014-04-07 20:23 - 00000000 ____D () C:\Users\Horst\AppData\Local\Origin 2014-06-28 09:47 - 2014-06-28 09:47 - 00000684 _____ () C:\Users\Horst\Desktop\PingPlotter Pro.lnk 2014-06-28 09:46 - 2014-06-28 09:46 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\PingPlotter 2014-06-28 09:46 - 2014-06-28 09:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PingPlotter Pro 2014-06-28 09:46 - 2014-05-11 11:02 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-06-28 09:45 - 2014-06-28 09:45 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Downloaded Installations 2014-06-28 09:34 - 2014-06-28 09:34 - 04425904 _____ () C:\Users\Horst\Desktop\pngplt_pro.exe 2014-06-27 16:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-06-27 15:08 - 2014-03-22 20:24 - 00000000 ____D () C:\Users\Horst\Documents\Diablo III 2014-06-27 14:53 - 2014-06-27 14:53 - 00000890 _____ () C:\Users\Public\Desktop\Diablo III Public Test.lnk 2014-06-27 14:53 - 2014-06-27 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III Public Test 2014-06-27 14:52 - 2014-06-27 14:52 - 03589024 _____ (Blizzard Entertainment) C:\Users\Horst\Desktop\Diablo-III-Public-Test-Setup-deDE.exe 2014-06-27 14:38 - 2014-06-27 14:38 - 00000000 ____D () C:\Users\Horst\Desktop\TG-3468_V2_120308 2014-06-27 14:16 - 2014-05-03 20:50 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-27 14:12 - 2014-06-27 14:12 - 00000000 ____D () C:\Users\Horst\Downloads\LiveSetup 2014-06-27 13:20 - 2014-05-22 22:34 - 00000000 ____D () C:\Program Files\cFosSpeed 2014-06-26 00:51 - 2014-03-29 15:01 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-06-25 17:42 - 2014-06-25 17:41 - 00000000 ____D () C:\Users\Horst\Desktop\diesdas 2014-06-25 16:36 - 2014-06-25 16:36 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\PDF Architect 2 2014-06-24 05:54 - 2014-06-24 05:52 - 00000692 _____ () C:\Users\Public\Desktop\Nexus Mod Manager.lnk 2014-06-24 05:54 - 2014-06-24 05:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager 2014-06-24 05:53 - 2014-06-24 05:53 - 00000000 ____D () C:\Users\Horst\Documents\Nexus Mod Manager 2014-06-24 05:53 - 2014-06-24 05:53 - 00000000 ____D () C:\Users\Horst\AppData\Local\Black_Tree_Gaming 2014-06-23 08:54 - 2014-06-23 08:54 - 00000000 ____D () C:\Users\Horst\Desktop\Photoreal ENB V1_2 MORE REALISTIC COLOURS_ENBLENS OFF-50483-1-3 2014-06-23 08:41 - 2014-06-23 08:41 - 00000000 ____D () C:\Users\Horst\AppData\Local\Skyrim 2014-06-23 08:40 - 2014-05-27 00:41 - 00000000 ____D () C:\Users\Horst\Documents\My Games 2014-06-23 08:21 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-22 11:34 - 2014-03-30 07:07 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-22 11:34 - 2014-03-30 07:07 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-22 11:15 - 2014-04-24 19:35 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\.minecraft 2014-06-22 05:46 - 2014-06-22 05:46 - 00000098 _____ () C:\Users\Horst\AppData\Roaming\LauncherSettings_live.cfg 2014-06-22 05:34 - 2014-06-22 05:32 - 00000041 _____ () C:\Users\Horst\AppData\Roaming\TheHunterSettings_steam_live.cfg 2014-06-22 05:33 - 2014-06-22 05:33 - 00000000 ____D () C:\Users\Horst\Documents\theHunter 2014-06-22 05:32 - 2014-06-22 05:32 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\theHunter 2014-06-22 05:32 - 2014-06-22 05:32 - 00000000 ____D () C:\Users\Horst\AppData\Local\theHunter 2014-06-22 05:31 - 2014-06-22 05:31 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\theHunterSteam 2014-06-22 05:31 - 2014-06-22 05:31 - 00000000 ____D () C:\ProgramData\Hunter 2014-06-22 05:05 - 2014-06-22 05:05 - 00000209 _____ () C:\Users\Horst\Desktop\Reversion - The Escape.url 2014-06-21 10:34 - 2009-07-14 19:58 - 00699988 _____ () C:\Windows\system32\perfh007.dat 2014-06-21 10:34 - 2009-07-14 19:58 - 00149626 _____ () C:\Windows\system32\perfc007.dat 2014-06-21 10:34 - 2009-07-14 07:13 - 01622126 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-21 09:13 - 2014-04-12 16:58 - 01719292 _____ () C:\Users\Horst\Desktop\Original_Wettmanager_2.02.xlsx 2014-06-20 03:22 - 2014-03-22 10:37 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\DAEMON Tools Lite 2014-06-20 01:59 - 2014-06-20 01:59 - 00000000 ____D () C:\Users\Horst\Desktop\NoMoreBirdsv1.4 2014-06-19 17:35 - 2014-06-19 17:35 - 00000000 ____D () C:\Users\Horst\AppData\Local\Adobe 2014-06-17 20:16 - 2014-06-14 02:15 - 00000000 ____D () C:\Program Files (x86)\Overwolf 2014-06-15 06:33 - 2014-04-06 02:09 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-15 06:33 - 2014-04-06 02:09 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-14 02:16 - 2014-06-14 02:16 - 00003728 _____ () C:\Windows\System32\Tasks\Overwolf Updater Task 2014-06-14 02:15 - 2014-06-14 02:15 - 00001971 _____ () C:\Users\Public\Desktop\Overwolf.lnk 2014-06-14 02:15 - 2014-06-14 02:15 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2014-06-14 02:15 - 2014-06-14 02:15 - 00000000 ____D () C:\ProgramData\Overwolf 2014-06-13 20:18 - 2014-05-27 04:08 - 00000218 _____ () C:\Users\Horst\Desktop\Watch_Dogs.url 2014-06-13 20:02 - 2014-06-09 08:31 - 00000000 ____D () C:\Users\Horst\AppData\Roaming\Audacity 2014-06-13 19:58 - 2014-06-13 19:57 - 00000000 ____D () C:\Users\Horst\Desktop\Wetten 2014-06-13 17:15 - 2014-06-13 17:00 - 00002244 ____H () C:\Users\Horst\Documents\Default.rdp 2014-06-13 07:00 - 2014-06-13 07:00 - 00000000 ____D () C:\Users\Horst\AppData\Local\PAYDAY 2 2014-06-13 07:00 - 2014-06-13 07:00 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-06-13 07:00 - 2014-03-21 19:08 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-06-13 06:40 - 2014-06-13 06:40 - 00000209 _____ () C:\Users\Horst\Desktop\PAYDAY 2.url 2014-06-11 03:25 - 2014-03-22 05:29 - 00000000 ____D () C:\ProgramData\Oracle 2014-06-11 03:22 - 2014-05-17 20:58 - 00000000 ____D () C:\Program Files (x86)\Gomez 2014-06-10 11:53 - 2014-06-09 15:20 - 00000000 ____D () C:\Program Files (x86)\PDFCreator 2014-06-10 04:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Cursors Some content of TEMP: ==================== C:\Users\Horst\AppData\Local\Temp\java-installer.exe C:\Users\Horst\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-08 20:33 ==================== End Of Log ============================ --- --- --- --- --- --- Ich hoffe ihr könnt mir helfen. Danke schonmal im Voraus Uptate: Ich wollte die Laufwerke mal mit chkdsk überprüfen. Wenn ich aber auf ein Lauferwerk mit der rechten Maustaste klicke steht da: "Windows-Explorer funktioniert nicht mehr". Linksklick funktioniert jedoch Rechtsklick nicht mehr. Irgendwas scheint hier kaputt zu sein Geändert von hehejo (10.07.2014 um 22:19 Uhr) |
11.07.2014, 07:10 | #2 |
/// the machine /// TB-Ausbilder | Ereignis div. Fehlermeldungen hi,
__________________Scan mit Combofix
__________________ |