Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Coin-miner zieht alle ressourcen! Processor 100% (https://www.trojaner-board.de/136651-coin-miner-zieht-alle-ressourcen-processor-100-a.html)

mamic 15.06.2013 14:29

Coin-miner zieht alle ressourcen! Processor 100%
 
Hallo, ich fürchte ich habe mir einen Virus eingefangen. Seit einer Stunde läuft mein Prozessor mit 100% - der Task Manager zeigt dass ein Programm "Coin-miner (32-bit)" die ganze Last verursacht.
Ich bitte um Hilfe, hoffe ich hab das mit den log files richtig gemacht.
Gruss
mamic

HTML-Code:

OTL Extras logfile created on: 15.06.2013 14:43:15 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = G:\Desktop
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16599)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,91 Gb Total Physical Memory | 5,75 Gb Available Physical Memory | 72,69% Memory free
9,10 Gb Paging File | 6,93 Gb Available in Paging File | 76,13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 74,43 Gb Total Space | 20,50 Gb Free Space | 27,54% Space Free | Partition Type: NTFS
Drive E: | 379,63 Gb Total Space | 11,30 Gb Free Space | 2,98% Space Free | Partition Type: NTFS
Drive G: | 75,19 Gb Total Space | 16,79 Gb Free Space | 22,32% Space Free | Partition Type: NTFS
Drive H: | 9,77 Gb Total Space | 0,80 Gb Free Space | 8,17% Space Free | Partition Type: NTFS
 
Computer Name: YPS | User Name: Santa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== File Associations ==========[/color]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
[color=#E56717]========== Shell Spawning ==========[/color]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
[color=#E56717]========== Security Center Settings ==========[/color]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
[color=#E56717]========== Firewall Settings ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[color=#E56717]========== Authorized Applications List ==========[/color]
 
 
[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00AA2EAD-5274-4D92-9EDD-D49C8061DE85}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0A53D4A1-9579-4BC2-B94A-A70C9A0E055A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{19FBCE80-5F45-4E38-A25A-7E4FCBC90F1A}" = lport=138 | protocol=17 | dir=in | app=system |
"{244C4895-4C76-475A-8613-6FFEC6114CCE}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{34544656-2DAE-49C1-BAC3-54D53767C889}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3A426161-B67B-4454-B706-29AE10C1B108}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4560CD55-5749-404E-A939-5EBC735E61C4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{52DB5E37-0527-4BB7-A20C-7C7CC57B9A0A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5A9ECE9F-4BF2-42D0-9D9A-B9D4F80D60C4}" = rport=139 | protocol=6 | dir=out | app=system |
"{782D33FC-6480-4395-8780-8ADA2333039B}" = lport=445 | protocol=6 | dir=in | app=system |
"{7A8B0523-3C55-4896-A3C8-C0FBF339F5DB}" = lport=139 | protocol=6 | dir=in | app=system |
"{7E6793FA-A50C-4EF9-BB7E-4E1F38E284AB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{85F92CF4-C2D8-47DB-9EF0-71E7CD5FA6E5}" = rport=138 | protocol=17 | dir=out | app=system |
"{9F208396-A77A-44E3-9C6B-1F0BB54FF12A}" = lport=137 | protocol=17 | dir=in | app=system |
"{A0388511-25AA-4D35-9F80-F78ABC20CE71}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AC00F4B2-03A0-4162-B5E9-1359D94AECD7}" = rport=445 | protocol=6 | dir=out | app=system |
"{B1E4266C-F3A2-4A76-BE67-7E2D01642C09}" = rport=137 | protocol=17 | dir=out | app=system |
"{BF853237-B7F5-4A2C-B93D-7F4303032217}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C2EE18AE-FC12-4122-BDC8-177E36D27502}" = lport=10243 | protocol=6 | dir=in | app=system |
"{D6A2F78B-C065-48AE-8912-1DFD00F0A5C9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E72414E9-7784-4A30-B89F-05F5C33783BB}" = rport=10243 | protocol=6 | dir=out | app=system |
 
[color=#E56717]========== Vista Active Application Exception List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{027DB729-8992-4FE4-9DD8-58A7AC6BE651}" = dir=in | name=hp printer control |
"{0C05591A-9238-4A1D-AED6-9A1AFBB11496}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{0CF432F0-4FFE-4F0B-B651-E3465D500302}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0D9D7EF4-DB63-4175-8FF6-D2616FEB69DA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{12A6FBCF-1CCD-48FE-9C56-019F98C1FAA0}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{14777555-956F-47D7-993A-D472AF732C33}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{1EB804B3-94AD-47AF-9CB0-3764F1ABA454}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{20859E39-FAE7-4EB7-98AC-89F754271DD8}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{21DF9161-2A80-4156-A1EB-2A58D562BE36}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{2236FC6B-DC1B-4981-9A96-525EA9CEE2A7}" = dir=out | name=markpad |
"{22971F3B-30F1-4838-8AC7-924A0FDA7B24}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{28BD4296-755B-412D-BAD9-1DC7904E9B2B}" = protocol=6 | dir=in | app=c:\users\santa\appdata\roaming\dropbox\bin\dropbox.exe |
"{2BC61803-8966-4177-ADC2-9F35D6EB708D}" = dir=out | name=@{microsoft.bingsports_1.8.0.51_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{3538CDF3-BDFF-42CB-AF64-E67605FEAAB1}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{3A49E9EB-7A1D-42CF-A343-20D7AF2BED14}" = dir=out | name=@{microsoft.zunemusic_1.1.144.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} |
"{469D8B87-0048-4685-B3A8-303ADE675E51}" = dir=in | name=@{microsoft.reader_6.2.9200.20523_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{4970466E-478E-4B4B-85B5-5B9869855E68}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{4BB6A9DB-485B-4DAA-B0EB-17269824B4A4}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{4C7F2F77-C433-4E3E-8EFB-887820E110E3}" = dir=out | name=microsoft mahjong |
"{4C8F411F-8215-46E9-86A7-89059315C2E2}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4E70F3BA-40A1-4E8E-8772-3CFFCF96055C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4F024861-4F05-4982-BE65-1207B7809425}" = dir=out | name=zattoo live tv |
"{515BF6C9-03CD-41E6-A5CF-097384F10FE7}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{5187ACB3-FF8A-4F15-A69F-CDE17E6571E2}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{546A0FEA-EC1D-4819-B3D5-D03A52577106}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{58C20550-7352-46F3-95C2-A49536858BEE}" = protocol=6 | dir=out | app=system |
"{5C307656-20D2-40C2-AD79-4A4A156DCFE0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{61353486-E23E-48B7-9299-F2C382431FFA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{62E92688-C722-49D4-9F83-543CBC6C2E6F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{68746105-F548-4015-994E-19B030550E14}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{68DE01C1-BC82-488A-88C7-85A9C56BF944}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{712E3597-2DE4-4FFC-909A-27301688F5C4}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{71E9C46B-8A1F-4A02-9EE7-6953B2EB06DF}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{77989DFD-C88A-468A-BB31-2DC0DF9A3C2C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{791D45AE-0DCC-4087-840E-5760D900E96D}" = protocol=17 | dir=in | app=c:\program files (x86)\google\google talk\googletalk.exe |
"{7F279CB9-8C3B-4A34-90DA-1ABB175A6EED}" = dir=out | name=@{microsoft.reader_6.2.9200.20523_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{80089ADB-FE50-428D-9C83-5718E7C56EB8}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{8C0B3F93-04A7-4922-9390-028664EF281F}" = dir=out | name=hp printer control |
"{8D2B8401-5AA2-4DC6-B1FD-950FA6CD51F8}" = dir=out | name=wortsuche |
"{904BE012-DA54-43C3-A0A2-9599278432CA}" = dir=in | name=qool |
"{921A3E3E-C41C-4F81-B016-955468619A84}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{923C623D-633C-4DF3-91CA-16C15DED16E2}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{92B500F6-C137-4544-BD52-D90D2EF9B44A}" = dir=out | name=google search |
"{94C0ED25-AD1F-4955-BCD3-2D1577EAD9FA}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{97B41FB1-87FA-4AB6-BEC4-9E9EF314BA7B}" = dir=out | name=@{microsoft.bingfinance_1.7.0.38_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{9AF7E8C5-E9BF-4768-90BC-1DC3E7087153}" = dir=out | name=@{microsoft.zunevideo_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} |
"{9B6CEEBC-48EE-41D3-B2D5-BC81BE29155A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9C2DD098-75D2-4308-B95A-1B27C0EAE1CF}" = dir=out | name=@{microsoft.bingtravel_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{A31FE256-F40C-4ACA-8CE4-02B48A42C51A}" = dir=out | name=@{microsoft.bingnews_1.7.0.38_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{A47A4837-7445-4066-B16A-4CBCAF74C088}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{AA71A175-43CE-40CE-BE0C-CCDDAEF43AAA}" = dir=out | name=@{microsoft.bingmaps_1.5.1.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{AEE19888-B76D-4E27-AA48-557420B7DDFC}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B7B674D5-BA0D-482B-82D7-0DEC5756C9A3}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B8A76143-4973-4EE3-92CF-11D0A89F09DB}" = dir=out | name=qool |
"{BC3A60DD-BC1C-4FAB-8474-F91001C870D1}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{C3E6E7A3-EA2B-482B-A2D1-3AD58E668163}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{C4E4853F-3746-4426-A321-92B08BF40EED}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C628FA0B-2246-4278-A55B-F5BFF54667CD}" = protocol=6 | dir=in | app=c:\program files (x86)\google\google talk\googletalk.exe |
"{CEB3457F-7E41-405F-96CE-EBE76C6FC8D1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D1C8F549-2F3B-4D32-8E9B-E6B9F6380A8E}" = dir=out | name=@{microsoft.xboxlivegames_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{D411DE5A-CA04-42A1-B098-BF95E9D2EFCB}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{D49C1D8E-BEE3-4083-8FD3-7A82DBA9F43B}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D6798907-2749-47D7-B694-77731C3EAAB3}" = dir=out | name=bubblebreaker |
"{D9887D69-EEB0-4970-8EB3-54AB3A6ADE97}" = dir=out | name=tv-programm |
"{DB21E116-0A65-4759-8076-810ECCAF57FD}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{E62DB4B0-B75A-4A59-951B-DC6A88A05CDC}" = dir=out | name=@{microsoft.bingweather_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E9428011-4376-4A69-B7FD-0BCC6C63906B}" = dir=in | app=c:\program files\intel corporation\intel widi\widiapp.exe |
"{EA738C74-D371-4CC9-BAEC-14BF865DD34F}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{EC4939F6-495F-413F-9F4B-7B7831E7330D}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{ED8578FE-9501-417C-A54D-E75A1AF5D38B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F9498454-EC8F-4A37-90DD-9E5B6A861F67}" = protocol=17 | dir=in | app=c:\users\santa\appdata\roaming\dropbox\bin\dropbox.exe |
"{FEEC421E-B699-4007-BA33-939589DE98D3}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{FF2802A5-FBC9-4D57-A8A6-7AC6180BAAD4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FF2AD749-CCB8-4CCD-83B6-DD79B59D25E2}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"TCP Query User{4DB8D40E-2A9D-4DAF-808E-AE1BA667A6EB}C:\users\santa\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\santa\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{C1FDC4A8-882D-417F-BB9A-4558F902A2AC}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{27A6ECDF-C27B-47E7-8E62-37F87BC64E1B}C:\users\santa\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\santa\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{2835BC31-F622-448F-B293-E7E7B03376E8}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
 
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{088AD1DB-D1D7-469A-AE6C-1EBD766ACB5A}" = Newshosting
"{1593C708-5535-47A4-8C0F-F8D4BE2B4560}" = Intel® PROSet/Wireless WiFi-Software
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417021FF}" = Java 7 Update 21 (64-bit)
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{2FE46568-5754-43AE-A289-0A8A7E5BCEAE}" = calibre 64bit
"{49A09C2C-FFF4-478E-B397-5E0979F67F5D}" = Lenovo Patch Utility 64 bit
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6097158B-0184-4140-BEC3-7885794D2571}" = Intel(R) WiDi
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{76FF0F03-B707-4332-B5D1-A56C8303514E}" = iTunes
"{7B324AC3-57C3-4701-B023-F54D78546BFA}_is1" = Windows Service-Center 2013
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7F34ADBE-77C0-47A0-BBC6-B3DA16CE8E68}" = Classic Shell
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9B3F0A88-790D-3AD9-9F96-B19CF2746452}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}" = Lenovo Bluetooth with Enhanced Data Rate Software
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"BatteryBar" = BatteryBar (remove only)
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"KeyLemon" = KeyLemon
"OnScreenDisplay" = Anzeige am Bildschirm
"Power Management Driver" = Lenovo Power Management Driver
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"TeraCopy_is1" = TeraCopy 2.27
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{1845470B-EB14-4ABC-835B-E36C693DC07D}" = Skype™ 6.3
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21
"{38EE230F-F631-451F-8800-E29F5E5C9E7D}" = iTunes Library Updater
"{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}" = Google Earth
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA5009F6-E65C-4DBD-92B8-988F0ADD1E99}" = SlimDrivers
"{B78203BF-CF9C-4163-B6C3-B70A27A646EE}" = 8GadgetPack
"{DD2FEA6F-5AC2-46B2-0001-C2A0C077FD2C}" = Simply Good Pictures 2
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E8F27ADF-B1ED-41AF-A7EF-D5E71778480C}" = Lenovo Patch Utility
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FE041B02-234C-4AAA-9511-80DF6482A458}" = RICOH_Media_Driver_v2.22.18.01
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.17
"ArchiCrypt Live 6_is1" = ArchiCrypt Live Version 6.9.2.10088
"doubleTwist" = doubleTwist
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"Foxit Reader_is1" = Foxit Reader
"FreeFileSync" = FreeFileSync 5.12
"Freemake Video Converter_is1" = Freemake Video Converter Version 4.0.1
"Glary Utilities_is1" = Glary Utilities 2.56.0.1822
"Google Chrome" = Google Chrome
"HandBrake" = HandBrake 0.9.9.1
"ImgBurn" = ImgBurn
"IrfanView" = IrfanView (remove only)
"ISO Workshop_is1" = ISO Workshop 4.2
"KeePassPasswordSafe2_is1" = KeePass Password Safe 2.22
"Mozilla Firefox 21.0 (x86 de)" = Mozilla Firefox 21.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Network Meter_is1" = Network Meter version 9.1
"Notepad++" = Notepad++
"PdaNet_is1" = PdaNet+ for Android 4.12
"Picasa 3" = Picasa 3
"Q-Dir" = Q-Dir
"Revo Uninstaller" = Revo Uninstaller 1.94
"Secunia PSI" = Secunia PSI (3.0.0.6001)
"TeamViewer 8" = TeamViewer 8
"TrueCrypt" = TrueCrypt
"UseNeXT by Tangysoft_is1" = UseNeXT by Tangysoft
"uTorrent" = µTorrent
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 2.0.6
"Yahoo! Messenger" = Yahoo! Messenger
 
[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"MusicManager" = Music Manager
 
[color=#E56717]========== Last 20 Event Log Errors ==========[/color]
 
[ Application Events ]
Error - 13.06.2013 16:37:15 | Computer Name = YpS | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_7_700_224.exe,
 Version: 11.7.700.224, Zeitstempel: 0x51a67447  Name des fehlerhaften Moduls: unknown,
 Version: 0.0.0.0, Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset:
0x6ea42366  ID des fehlerhaften Prozesses: 0x1f8c  Startzeit der fehlerhaften Anwendung:
 0x01ce6875c9b2723c  Pfad der fehlerhaften Anwendung: C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
Pfad
 des fehlerhaften Moduls: unknown  Berichtskennung: 07fc5b60-d469-11e2-beb4-cc52afe0f613
Vollständiger
 Name des fehlerhaften Pakets:  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:
 
Error - 13.06.2013 16:37:22 | Computer Name = YpS | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_7_700_224.exe,
 Version: 11.7.700.224, Zeitstempel: 0x51a67447  Name des fehlerhaften Moduls: unknown,
 Version: 0.0.0.0, Zeitstempel: 0x00000000  Ausnahmecode: 0xc00001a5  Fehleroffset:
0x00d149b0  ID des fehlerhaften Prozesses: 0x1884  Startzeit der fehlerhaften Anwendung:
 0x01ce6875ce919903  Pfad der fehlerhaften Anwendung: C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
Pfad
 des fehlerhaften Moduls: unknown  Berichtskennung: 0c4a10cf-d469-11e2-beb4-cc52afe0f613
Vollständiger
 Name des fehlerhaften Pakets:  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:
 
Error - 13.06.2013 16:37:23 | Computer Name = YpS | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_7_700_224.exe,
 Version: 11.7.700.224, Zeitstempel: 0x51a67447  Name des fehlerhaften Moduls: unknown,
 Version: 0.0.0.0, Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset:
0x6ea42366  ID des fehlerhaften Prozesses: 0x1884  Startzeit der fehlerhaften Anwendung:
 0x01ce6875ce919903  Pfad der fehlerhaften Anwendung: C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
Pfad
 des fehlerhaften Moduls: unknown  Berichtskennung: 0cd6bd5f-d469-11e2-beb4-cc52afe0f613
Vollständiger
 Name des fehlerhaften Pakets:  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:
 
Error - 13.06.2013 17:04:13 | Computer Name = YpS | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: CxAudMsg64.exe, Version: 1.6.0.0,
 Zeitstempel: 0x4fd1c0c1  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16579,
 Zeitstempel: 0x51637f77  Ausnahmecode: 0xc0000374  Fehleroffset: 0x00000000000ebd59
ID
 des fehlerhaften Prozesses: 0x754  Startzeit der fehlerhaften Anwendung: 0x01ce68480457b5be
Pfad
 der fehlerhaften Anwendung: C:\WINDOWS\system32\CxAudMsg64.exe  Pfad des fehlerhaften
 Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll  Berichtskennung: cc2db026-d46c-11e2-beb4-cc52afe0f613
Vollständiger
 Name des fehlerhaften Pakets:  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:
 
Error - 14.06.2013 15:19:25 | Computer Name = YpS | Source = Microsoft-Windows-LocationProvider | ID = 2006
Description = There was an error with the Windows Location Provider database
 
Error - 15.06.2013 01:51:58 | Computer Name = YpS | Source = VSS | ID = 8194
Description =
 
Error - 15.06.2013 06:48:17 | Computer Name = YpS | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.3.21.103,
 Zeitstempel: 0x4f3c6d6c  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578,
 Zeitstempel: 0x515fac6e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00000032  ID des fehlerhaften
 Prozesses: 0x28b4  Startzeit der fehlerhaften Anwendung: 0x01ce69b5cda18bea  Pfad der
 fehlerhaften Anwendung: C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe
Pfad
 des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll  Berichtskennung: 15eccb3d-d5a9-11e2-beb5-cc52afe0f613
Vollständiger
 Name des fehlerhaften Pakets:  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:
 
Error - 15.06.2013 07:48:30 | Computer Name = YpS | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.3.21.103,
 Zeitstempel: 0x4f3c6d6c  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578,
 Zeitstempel: 0x515fac6e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0000002f  ID des fehlerhaften
 Prozesses: 0x3838  Startzeit der fehlerhaften Anwendung: 0x01ce69be2f66f29e  Pfad der
 fehlerhaften Anwendung: C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe
Pfad
 des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll  Berichtskennung: 7f2c509e-d5b1-11e2-beb5-cc52afe0f613
Vollständiger
 Name des fehlerhaften Pakets:  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:
 
Error - 15.06.2013 08:47:38 | Computer Name = YpS | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: GPhotos.scr, Version: 3.9.136.20,
 Zeitstempel: 0x515ae6ae  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578,
 Zeitstempel: 0x515fac6e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00000048  ID des fehlerhaften
 Prozesses: 0x3220  Startzeit der fehlerhaften Anwendung: 0x01ce69c676d7072f  Pfad der
 fehlerhaften Anwendung: C:\WINDOWS\SysWOW64\GPhotos.scr  Pfad des fehlerhaften Moduls:
 C:\WINDOWS\SYSTEM32\ntdll.dll  Berichtskennung: c1be7245-d5b9-11e2-beb5-cc52afe0f613
Vollständiger
 Name des fehlerhaften Pakets:  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:
 
Error - 15.06.2013 08:48:25 | Computer Name = YpS | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.3.21.103,
 Zeitstempel: 0x4f3c6d6c  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578,
 Zeitstempel: 0x515fac6e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0000002f  ID des fehlerhaften
 Prozesses: 0x1e6c  Startzeit der fehlerhaften Anwendung: 0x01ce69c6912b3725  Pfad der
 fehlerhaften Anwendung: C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe
Pfad
 des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll  Berichtskennung: ddc9ec21-d5b9-11e2-beb5-cc52afe0f613
Vollständiger
 Name des fehlerhaften Pakets:  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:
 
[ System Events ]
Error - 09.06.2013 03:17:38 | Computer Name = YpS | Source = Service Control Manager | ID = 7000
Description = Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
Error - 09.06.2013 04:16:01 | Computer Name = YpS | Source = Service Control Manager | ID = 7034
Description = Dienst "Conexant Audio Message Service" wurde unerwartet beendet.
Dies ist bereits 1 Mal passiert.
 
Error - 09.06.2013 06:44:16 | Computer Name = YpS | Source = DCOM | ID = 10010
Description =
 
Error - 09.06.2013 06:45:01 | Computer Name = YpS | Source = Service Control Manager | ID = 7000
Description = Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
Error - 10.06.2013 12:41:09 | Computer Name = YpS | Source = Service Control Manager | ID = 7000
Description = Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
Error - 11.06.2013 13:08:08 | Computer Name = YpS | Source = Service Control Manager | ID = 7000
Description = Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
Error - 12.06.2013 14:13:45 | Computer Name = YpS | Source = Service Control Manager | ID = 7000
Description = Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
Error - 13.06.2013 11:10:15 | Computer Name = YpS | Source = Service Control Manager | ID = 7000
Description = Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
Error - 13.06.2013 17:04:13 | Computer Name = YpS | Source = Service Control Manager | ID = 7034
Description = Dienst "Conexant Audio Message Service" wurde unerwartet beendet.
Dies ist bereits 1 Mal passiert.
 
Error - 14.06.2013 15:19:08 | Computer Name = YpS | Source = Service Control Manager | ID = 7000
Description = Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
 
< End of report >

HTML-Code:

OTL logfile created on: 15.06.2013 14:43:15 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = G:\Desktop
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16599)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,91 Gb Total Physical Memory | 5,75 Gb Available Physical Memory | 72,69% Memory free
9,10 Gb Paging File | 6,93 Gb Available in Paging File | 76,13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 74,43 Gb Total Space | 20,50 Gb Free Space | 27,54% Space Free | Partition Type: NTFS
Drive E: | 379,63 Gb Total Space | 11,30 Gb Free Space | 2,98% Space Free | Partition Type: NTFS
Drive G: | 75,19 Gb Total Space | 16,79 Gb Free Space | 22,32% Space Free | Partition Type: NTFS
Drive H: | 9,77 Gb Total Space | 0,80 Gb Free Space | 8,17% Space Free | Partition Type: NTFS
 
Computer Name: YPS | User Name: Santa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
[color=#E56717]========== Processes (SafeList) ==========[/color]
 
PRC - [2013.06.15 14:32:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- G:\Desktop\OTL.exe
PRC - [2013.06.15 12:16:53 | 000,055,296 | ---- | M] (Ufasoft) -- C:\Users\Santa\AppData\Roaming\WindowsLogonS\shell.exe
PRC - [2013.06.15 12:16:53 | 000,055,296 | ---- | M] (Ufasoft) -- C:\Users\Santa\AppData\Roaming\WindowsLogonS\macromedia.exe
PRC - [2013.06.07 14:39:25 | 004,150,112 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2013.05.30 01:33:20 | 000,101,888 | ---- | M] (Freemake) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
PRC - [2013.04.12 23:27:48 | 000,068,608 | ---- | M] (IvoSoft) -- C:\Programme\Classic Shell\ClassicShellService.exe
PRC - [2012.11.26 16:09:22 | 001,225,312 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe
PRC - [2012.08.24 19:33:26 | 000,127,072 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\micmute.exe
PRC - [2012.07.26 05:32:50 | 000,385,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WerFault.exe
PRC - [2012.07.26 05:20:44 | 000,349,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe
PRC - [2011.11.10 10:59:36 | 002,594,584 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2011.11.10 10:59:34 | 000,325,912 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2011.09.01 16:23:44 | 000,447,104 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\SysWOW64\SASrv.exe
 
 
[color=#E56717]========== Modules (No Company Name) ==========[/color]
 
MOD - [2012.11.28 15:13:52 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012.11.28 15:13:30 | 001,242,512 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2012.05.25 05:25:00 | 000,921,600 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
 
 
[color=#E56717]========== Services (SafeList) ==========[/color]
 
SRV:[b]64bit:[/b] - [2013.04.09 06:48:42 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2013.03.02 04:45:07 | 000,171,008 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:[b]64bit:[/b] - [2013.03.02 04:45:05 | 000,180,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2013.02.02 10:21:45 | 000,467,456 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2013.01.10 01:23:16 | 001,964,544 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2013.01.10 01:22:35 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2012.12.11 07:22:08 | 000,060,272 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC)
SRV:[b]64bit:[/b] - [2012.11.06 06:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2012.09.20 11:10:47 | 002,367,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:[b]64bit:[/b] - [2012.09.20 08:31:18 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2012.09.20 08:30:41 | 000,179,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2012.07.26 05:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2012.07.26 05:07:42 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2012.07.26 05:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2012.07.26 05:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2012.07.26 05:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2012.07.26 05:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2012.07.26 05:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2012.07.26 05:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2012.07.26 05:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2012.07.26 05:05:28 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2012.07.26 05:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2012.07.26 05:05:12 | 000,331,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BthHFSrv.dll -- (BthHFSrv)
SRV:[b]64bit:[/b] - [2012.07.26 05:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent)
SRV:[b]64bit:[/b] - [2012.07.26 05:05:04 | 000,187,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2012.06.08 18:07:16 | 000,201,376 | ---- | M] (Conexant Systems Inc.) [Auto | Running] -- C:\Windows\SysNative\CxAudMsg64.exe -- (CxAudMsg)
SRV:[b]64bit:[/b] - [2000.01.01 02:00:00 | 002,227,992 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Windows\SysNative\BtwRSupportService.exe -- (BcmBtRSupport)
SRV - [2013.06.11 20:09:17 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.06.07 14:39:25 | 004,150,112 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2013.05.30 16:34:34 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.05.30 01:33:20 | 000,101,888 | ---- | M] (Freemake) [Auto | Running] -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe -- (Freemake Improver)
SRV - [2013.04.12 23:27:48 | 000,068,608 | ---- | M] (IvoSoft) [Auto | Running] -- C:\Programme\Classic Shell\ClassicShellService.exe -- (ClassicShellService)
SRV - [2012.12.18 13:30:54 | 000,127,120 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\tphkload.exe -- (TPHKLOAD)
SRV - [2012.12.14 03:42:10 | 000,277,616 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012.11.26 16:09:22 | 001,225,312 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2012.11.26 16:09:20 | 000,659,040 | ---- | M] (Secunia) [Auto | Stopped] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2012.11.15 15:51:42 | 000,959,256 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Programme\Lenovo\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2012.11.06 06:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2012.09.24 17:03:12 | 001,153,840 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService)
SRV - [2012.09.24 17:02:54 | 000,272,176 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV - [2012.09.24 17:02:42 | 000,617,776 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV - [2012.09.24 17:02:16 | 000,149,296 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV - [2012.08.24 19:33:26 | 000,127,072 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
SRV - [2012.07.26 05:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2011.11.10 10:59:36 | 002,594,584 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011.11.10 10:59:34 | 000,325,912 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011.09.01 16:23:44 | 000,447,104 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\SASrv.exe -- (SAService)
 
 
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
 
DRV:[b]64bit:[/b] - [2013.04.24 01:23:00 | 000,460,528 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2013.04.12 17:20:43 | 000,231,376 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\truecrypt.sys -- (truecrypt)
DRV:[b]64bit:[/b] - [2013.04.09 07:27:43 | 000,284,424 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2013.03.11 02:49:12 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\VClone.sys -- (VClone)
DRV:[b]64bit:[/b] - [2013.03.04 14:24:27 | 000,040,344 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:[b]64bit:[/b] - [2013.03.02 12:57:48 | 000,337,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2013.03.02 12:57:46 | 000,077,544 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2013.03.02 12:45:20 | 000,148,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2013.03.02 12:45:19 | 000,194,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2013.03.02 12:39:38 | 000,069,864 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2013.02.14 01:51:32 | 000,109,016 | ---- | M] (Softwareentwicklung Remus - ArchiCrypt - ) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\ACLE1764.sys -- (ACLE6Live)
DRV:[b]64bit:[/b] - [2013.02.06 08:42:08 | 000,102,936 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\ssudbus.sys -- (dg_ssudbus)
DRV:[b]64bit:[/b] - [2013.02.02 13:19:44 | 000,446,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2013.02.02 09:25:23 | 000,037,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:[b]64bit:[/b] - [2013.02.02 09:24:50 | 000,117,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthA2DP.sys -- (BthA2DP)
DRV:[b]64bit:[/b] - [2013.02.02 09:24:42 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthHfAud.sys -- (BthHFAud)
DRV:[b]64bit:[/b] - [2013.01.29 03:57:05 | 000,035,232 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2013.01.29 01:08:22 | 000,230,904 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2013.01.10 03:53:32 | 000,028,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2012.12.14 03:42:22 | 005,353,888 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2012.12.13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
DRV:[b]64bit:[/b] - [2012.12.11 07:22:08 | 000,042,824 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV:[b]64bit:[/b] - [2012.11.27 05:55:44 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid)
DRV:[b]64bit:[/b] - [2012.11.20 06:54:31 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2012.11.06 05:55:44 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM)
DRV:[b]64bit:[/b] - [2012.10.18 00:19:22 | 000,044,344 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys -- (SmbDrvI)
DRV:[b]64bit:[/b] - [2012.10.12 10:08:01 | 000,027,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2012.10.11 09:25:48 | 000,056,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2012.10.11 09:13:49 | 000,058,088 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2012.10.09 19:48:50 | 000,035,296 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:[b]64bit:[/b] - [2012.10.09 19:48:50 | 000,025,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\iwdbus.sys -- (iwdbus)
DRV:[b]64bit:[/b] - [2012.10.09 19:48:48 | 000,188,896 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\xHCIPort.sys -- (XHCIPort)
DRV:[b]64bit:[/b] - [2012.10.09 19:48:48 | 000,047,072 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\usb3Hub.sys -- (usb3Hub)
DRV:[b]64bit:[/b] - [2012.09.20 09:55:33 | 000,212,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000)
DRV:[b]64bit:[/b] - [2012.09.20 09:55:30 | 000,120,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2012.09.20 09:55:27 | 003,265,256 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2012.09.20 09:55:24 | 000,533,224 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2012.08.21 14:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2012.07.26 07:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2012.07.26 07:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2012.07.26 07:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2012.07.26 06:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2012.07.26 06:54:34 | 000,096,496 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2012.07.26 06:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2012.07.26 05:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2012.07.26 04:30:00 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbser.sys -- (usbser)
DRV:[b]64bit:[/b] - [2012.07.26 04:29:47 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:[b]64bit:[/b] - [2012.07.26 04:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2012.07.26 04:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2012.07.26 04:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2012.07.26 04:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2012.07.26 04:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2012.07.26 04:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2012.07.26 04:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2012.07.26 04:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2012.07.26 04:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2012.07.26 04:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2012.07.26 04:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2012.07.26 04:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2012.07.26 04:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2012.07.26 04:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2012.07.26 04:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2012.07.26 04:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2012.07.26 04:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2012.07.26 04:25:26 | 000,203,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Vid.sys -- (Vid)
DRV:[b]64bit:[/b] - [2012.07.26 04:25:22 | 000,067,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\storvsp.sys -- (storvsp)
DRV:[b]64bit:[/b] - [2012.07.26 04:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr)
DRV:[b]64bit:[/b] - [2012.07.26 04:25:12 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmbusr.sys -- (vmbusr)
DRV:[b]64bit:[/b] - [2012.07.26 04:25:12 | 000,066,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpcivsp.sys -- (vpcivsp)
DRV:[b]64bit:[/b] - [2012.07.26 04:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2012.07.26 04:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2012.07.26 04:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2012.07.04 14:39:00 | 000,105,472 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\risdxc64.sys -- (risdxc)
DRV:[b]64bit:[/b] - [2012.06.22 06:59:50 | 001,586,848 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:[b]64bit:[/b] - [2012.06.02 16:31:56 | 000,589,824 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\Rt630x64.sys -- (RTL8168)
DRV:[b]64bit:[/b] - [2012.06.02 16:31:50 | 008,604,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\NETwNs64.sys -- (NETwNs64)
DRV:[b]64bit:[/b] - [2011.11.25 01:25:52 | 000,015,360 | ---- | M] (June Fabrics Technology Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\pneteth.sys -- (pneteth)
DRV:[b]64bit:[/b] - [2011.09.22 10:49:56 | 000,056,600 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\HECIx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2011.07.27 20:48:14 | 000,014,952 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\iPodDrv.sys -- (iPodDrv)
DRV:[b]64bit:[/b] - [2010.09.01 10:30:58 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\Drivers\psi_mf.sys -- (PSI)
DRV:[b]64bit:[/b] - [2000.01.01 02:00:00 | 000,226,680 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\btwavdt.sys -- (btwavdt)
DRV:[b]64bit:[/b] - [2000.01.01 02:00:00 | 000,186,136 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\btwaudio.sys -- (btwaudio)
DRV:[b]64bit:[/b] - [2000.01.01 02:00:00 | 000,169,240 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\bcbtums.sys -- (bcbtums)
DRV:[b]64bit:[/b] - [2000.01.01 02:00:00 | 000,161,144 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\btwampfl.sys -- (btwampfl)
DRV:[b]64bit:[/b] - [2000.01.01 02:00:00 | 000,040,248 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\btwl2cap.sys -- (btwl2cap)
DRV:[b]64bit:[/b] - [2000.01.01 02:00:00 | 000,020,856 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\btwrchid.sys -- (btwrchid)
 
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== Internet Explorer ==========[/color]
 
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE,de;q=0.8,en-US;q=0.5,en;q=0.3
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 18 7D 4C C7 E0 62 CE 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
[color=#E56717]========== FireFox ==========[/color]
 
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://web.de/|hxxp://www.google.com/ig?hl=de|https://ksab.kroschu.com/webaccess/index.php|hxxp://www.gizmodo.de/|hxxp://www.focus.de/|hxxp://www.myliveshopping.de/"
FF - prefs.js..extensions.enabledAddons: %7BD4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389%7D:0.9.10
FF - prefs.js..extensions.enabledAddons: translator%40zoli.bod:2.1.0.3
FF - prefs.js..extensions.enabledAddons: musicplayer%40firemediaplayer.com:2.2
FF - prefs.js..extensions.enabledAddons: isreaditlater%40ideashower.com:3.0.1
FF - prefs.js..extensions.enabledAddons: amznUWL2%40amazon.com:1.10
FF - prefs.js..extensions.enabledAddons: SkipScreen%40SkipScreen:0.7.0
FF - prefs.js..extensions.enabledAddons: %7Bdc572301-7619-498c-a57d-39143191b318%7D:0.4.1.0
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.15
FF - prefs.js..extensions.enabledAddons: %7B0545b830-f0aa-4d7e-8820-50a4629a56fe%7D:18.8
FF - prefs.js..extensions.enabledAddons: %7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:4.2.9
FF - prefs.js..extensions.enabledAddons: %7B677a8f98-fd64-40b0-a883-b8c95d0cbf17%7D:0.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - user.js - File not found
 
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@doubletwist.com/NPPodcast: C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Santa\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Santa\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{59d42255-7f9c-49e5-8e68-a5fd16d06d76}: C:\Program Files\KeyLemon\extension\{59d42255-7f9c-49e5-8e68-a5fd16d06d76}
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2013.02.03 21:18:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\Extensions
[2013.06.08 21:21:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\Firefox\Profiles\5zat8v2p.default\extensions
[2013.05.30 16:55:07 | 000,000,000 | ---D | M] ("ColorfulTabs") -- C:\Users\Santa\AppData\Roaming\mozilla\Firefox\Profiles\5zat8v2p.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2013.05.30 16:55:07 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Santa\AppData\Roaming\mozilla\Firefox\Profiles\5zat8v2p.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2013.05.30 16:55:07 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Santa\AppData\Roaming\mozilla\Firefox\Profiles\5zat8v2p.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013.02.03 21:53:47 | 000,243,287 | ---- | M] () (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\amznUWL2@amazon.com.xpi
[2013.05.30 16:55:07 | 000,363,920 | ---- | M] () (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\client@anonymox.net.xpi
[2013.02.03 21:53:47 | 000,223,719 | ---- | M] () (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\isreaditlater@ideashower.com.xpi
[2013.02.03 21:53:47 | 000,237,521 | ---- | M] () (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\musicplayer@firemediaplayer.com.xpi
[2013.02.03 21:53:47 | 000,071,037 | ---- | M] () (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\SkipScreen@SkipScreen.xpi
[2013.02.03 21:53:47 | 000,060,290 | ---- | M] () (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\translator@zoli.bod.xpi
[2013.06.08 21:21:34 | 000,020,949 | ---- | M] () (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\{677a8f98-fd64-40b0-a883-b8c95d0cbf17}.xpi
[2013.05.30 16:10:49 | 000,870,680 | ---- | M] () (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.02.03 21:53:47 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2013.04.20 22:00:58 | 000,765,412 | ---- | M] () (No name found) -- C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
[2013.05.30 16:34:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2013.05.30 16:34:36 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
[color=#E56717]========== Chrome  ==========[/color]
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll
CHR - plugin: AmazonMP3DownloaderPlugin (Enabled) = C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll
CHR - plugin: doubletwist Plugin 1, 3, 0, 0 (Enabled) = C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\WINDOWS\SysWOW64\npDeployJava1.dll
CHR - Extension: Google Docs = C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YOUZEEK Free Music = C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjcgpdkighmjfjlplcighhgamlhkimce\2.0.1_0\
CHR - Extension: YouTube = C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Play Music = C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg\5.1_0\
CHR - Extension: Google Mail = C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2012.07.26 07:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Programme\Classic Shell\ClassicExplorer64.dll (IvoSoft)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:[b]64bit:[/b] - BHO: (ClassicIE9BHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Programme\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
O2 - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Programme\Classic Shell\ClassicExplorer32.dll (IvoSoft)
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files (x86)\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (ClassicIE9BHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Programme\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Programme\Classic Shell\ClassicExplorer64.dll (IvoSoft)
O3 - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Programme\Classic Shell\ClassicExplorer32.dll (IvoSoft)
O4:[b]64bit:[/b] - HKLM..\Run: [cAudioFilterAgent] C:\Programme\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [ForteConfig] C:\Programme\CONEXANT\ForteConfig\fmapp.exe ()
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [KeyLemon LemonScreen] C:\Program Files\KeyLemon\KLLockEngine.exe (KeyLemon)
O4:[b]64bit:[/b] - HKLM..\Run: [KeyLemon Updater] C:\Programme\KeyLemon\KLUpdater.exe (KeyLemon)
O4:[b]64bit:[/b] - HKLM..\Run: [LenovoOptMouseUpdate] C:\Programme\Lenovo\HOTKEY\extapsup.exe (Lenovo Group Limited)
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKCU..\Run: [Adobe Flash Updater] C:\ProgramData\svsupdates0\xsytzecrn.exe (Microsoft Corporation)
O4 - HKCU..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [MusicManager] C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)
O4 - HKCU..\Run: [NPowerTray] G:\Downloads\NPowerTray.exe ()
O4 - HKCU..\Run: [ShowBatteryBar] C:\Program Files\BatteryBar\ShowBatteryBar.exe ()
O4 - HKCU..\RunOnce: [Adobe Flash Updater] C:\ProgramData\svsupdates0\xsytzecrn.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk = C:\Users\Santa\AppData\Roaming\WindowsLogonS\usft_ext.exe.vbs ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoNotification = 1
O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 File not found
O8:[b]64bit:[/b] - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Programme\Classic Shell\ClassicIE9_32.exe (IvoSoft)
O9 - Extra 'Tools' menuitem : Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Programme\Classic Shell\ClassicIE9_32.exe (IvoSoft)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A283C47B-98AD-4D34-9552-DCD9CEC0DDA1}: DhcpNameServer = 192.168.178.1
O18:[b]64bit:[/b] - Protocol\Handler\msdaipp - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:[b]64bit:[/b] - Protocol\Filter\text/xml - No CLSID value found
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O27:[b]64bit:[/b] - HKLM IFEO\mbam.exe: Debugger - mefjb_.exe File not found
O27:[b]64bit:[/b] - HKLM IFEO\mbamgui.exe: Debugger - gxwfo_.exe File not found
O27:[b]64bit:[/b] - HKLM IFEO\MSASCui.exe: Debugger - moyml_.exe File not found
O27:[b]64bit:[/b] - HKLM IFEO\MsMpEng.exe: Debugger - ftdim_.exe File not found
O27:[b]64bit:[/b] - HKLM IFEO\msseces.exe: Debugger - xsljq_.exe File not found
O27 - HKLM IFEO\mbam.exe: Debugger - mefjb_.exe File not found
O27 - HKLM IFEO\mbamgui.exe: Debugger - gxwfo_.exe File not found
O27 - HKLM IFEO\MSASCui.exe: Debugger - moyml_.exe File not found
O27 - HKLM IFEO\MsMpEng.exe: Debugger - ftdim_.exe File not found
O27 - HKLM IFEO\msseces.exe: Debugger - xsljq_.exe File not found
O30 - LSA: Security Packages - (livessp) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[2013.06.15 14:39:40 | 000,602,112 | ---- | C] (OldTimer Tools) -- G:\Desktop\OTL.exe
[2013.06.15 12:16:52 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\WindowsLogonS
[2013.06.15 11:46:28 | 000,000,000 | -HSD | C] -- C:\ProgramData\svsupdates0
[2013.06.13 18:32:38 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Local\Newshosting
[2013.06.13 18:32:38 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Local\CrashRpt
[2013.06.13 18:32:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Caphyon
[2013.06.13 18:32:32 | 000,000,000 | ---D | C] -- C:\Program Files\Newshosting
[2013.06.13 18:32:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Newshosting
[2013.06.13 18:32:27 | 000,000,000 | ---D | C] -- C:\Users\Santa\Downloads
[2013.06.13 18:30:24 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\Newshosting
[2013.06.09 12:54:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes Library Updater
[2013.06.09 12:54:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTLU
[2013.06.09 12:28:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013.06.09 12:28:22 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013.06.09 12:28:21 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013.06.09 12:28:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013.06.09 12:28:21 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013.06.09 09:44:04 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music Manager
[2013.06.09 09:40:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013.06.08 22:36:28 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth
[2013.06.08 22:35:16 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Local\Broadcom
[2013.06.08 22:19:32 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\WINDOWS\SysWow64\CSVer.dll
[2013.06.08 22:19:23 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Local\pcwServiceCenter
[2013.06.08 22:16:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
[2013.06.08 22:16:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SlimDrivers
[2013.06.08 22:16:04 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Downloaded Installers
[2013.06.08 22:12:34 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
[2013.06.08 21:02:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013.06.08 21:01:45 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Talk
[2013.06.08 21:01:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Talk
[2013.06.08 20:59:05 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Local\Secunia PSI
[2013.06.08 20:59:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secunia
[2013.06.08 19:54:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
[2013.06.08 19:54:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Auslogics
[2013.06.08 19:48:33 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\Auslogics
[2013.06.08 19:47:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC-WELT-ServiceCenter
[2013.06.08 19:46:51 | 000,000,000 | ---D | C] -- C:\Program Files\PC-WELT-ServiceCenter
[2013.06.08 18:32:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\appmgmt
[2013.06.08 16:46:00 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Local\Engelmann_Media
[2013.06.08 16:40:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Licenses
[2013.06.08 16:34:05 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\SuperEasy Software
[2013.06.08 16:31:13 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\Engelmann Media
[2013.06.08 16:31:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\HDX4
[2013.06.08 16:31:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Engelmann Media
[2013.06.08 16:31:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Engelmann Media
[2013.06.08 16:27:57 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\Q-Dir
[2013.06.08 16:27:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Q-Dir
[2013.06.08 16:27:57 | 000,000,000 | ---D | C] -- G:\Documents\Favorites_Q_Dir
[2013.06.08 16:27:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Q-Dir
[2013.06.06 22:52:08 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\GlarySoft
[2013.06.06 22:50:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities
[2013.06.06 22:50:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Glary Utilities
[2013.06.05 23:50:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
[2013.06.04 20:02:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
[2013.06.04 20:02:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elaborate Bytes
[2013.06.04 19:22:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Bluray Decrypter
[2013.06.04 19:07:29 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake
[2013.06.04 19:07:28 | 000,000,000 | ---D | C] -- C:\Program Files\Handbrake
[2013.06.04 13:51:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
[2013.06.04 13:51:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Lenovo
[2013.06.04 13:51:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Lenovo
[2013.06.04 13:51:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Lenovo
[2013.06.03 17:30:43 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Local\VMLite Workstation
[2013.06.03 17:30:42 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VMLite Workstation
[2013.06.03 17:10:08 | 000,000,000 | ---D | C] -- C:\Users\Santa\VMLites
[2013.06.02 12:38:54 | 000,000,000 | ---D | C] -- C:\Users\Santa\.android
[2013.05.31 22:26:58 | 000,015,360 | ---- | C] (June Fabrics Technology Inc.) -- C:\WINDOWS\SysNative\drivers\pneteth.sys
[2013.05.31 22:26:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PdaNet for Android
[2013.05.31 22:26:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PdaNet for Android
[2013.05.31 22:25:12 | 000,000,000 | ---D | C] -- G:\Desktop\motochopper
[2013.05.31 14:19:48 | 000,000,000 | ---D | C] -- C:\ZOPO
[2013.05.31 12:29:01 | 000,000,000 | ---D | C] -- C:\ProgramData\SP_FT_Logs
[2013.05.30 20:59:08 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Local\FreemakeVideoConverter
[2013.05.30 20:25:26 | 000,000,000 | ---D | C] -- G:\Documents\Freemake
[2013.05.30 20:25:26 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
[2013.05.30 20:25:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
[2013.05.30 20:25:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Freemake
[2013.05.30 20:25:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Freemake
[2013.05.30 19:37:41 | 000,000,000 | ---D | C] -- C:\Users\Santa\AppData\Roaming\HandBrake
[2013.05.30 19:37:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake
[2013.05.30 16:57:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
[2013.05.30 16:57:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Foxit Software
[2013.05.30 16:34:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.05.19 12:54:27 | 000,097,176 | ---- | C] (Elaborate Bytes AG) -- C:\WINDOWS\SysWow64\ElbyCDIO.dll
 
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
 
[2013.06.15 14:44:14 | 000,001,116 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.15 14:41:56 | 000,000,418 | ---- | M] () -- C:\WINDOWS\tasks\SlimDrivers Startup.job
[2013.06.15 14:37:45 | 000,377,856 | ---- | M] () -- G:\Desktop\gmer_2.1.19163.exe
[2013.06.15 14:32:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- G:\Desktop\OTL.exe
[2013.06.15 14:32:03 | 000,050,477 | ---- | M] () -- G:\Desktop\Defogger.exe
[2013.06.15 14:09:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013.06.15 14:00:00 | 000,015,547 | ---- | M] () -- C:\Users\Santa\Network_Meter_Data.js
[2013.06.15 13:48:39 | 000,000,916 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
[2013.06.15 12:16:57 | 000,001,088 | ---- | M] () -- C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk
[2013.06.15 09:48:00 | 000,000,864 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
[2013.06.15 09:44:00 | 000,001,112 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013.06.14 21:27:29 | 001,745,416 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2013.06.14 21:27:29 | 000,753,134 | ---- | M] () -- C:\WINDOWS\SysNative\perfh007.dat
[2013.06.14 21:27:29 | 000,710,244 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2013.06.14 21:27:29 | 000,155,826 | ---- | M] () -- C:\WINDOWS\SysNative\perfc007.dat
[2013.06.14 21:27:29 | 000,132,614 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2013.06.14 21:20:39 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.06.14 21:19:00 | 000,000,334 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2013.06.14 21:18:38 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2013.06.14 21:18:38 | 2502,512,639 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.14 00:40:10 | 000,000,026 | ---- | M] () -- C:\Users\Santa\AppData\Roaming\Network Meter_Usage.ini
[2013.06.13 22:23:58 | 000,000,658 | ---- | M] () -- G:\Documents\Breaking Point (German) (2009) AC3 BDRip.nzb
[2013.06.10 18:43:27 | 000,000,853 | ---- | M] () -- C:\Users\Santa\AppData\Roaming\Drives Meter_Settings.ini
[2013.06.09 12:58:20 | 000,000,748 | ---- | M] () -- G:\Documents\2013-06-09.itlu
[2013.06.08 22:34:42 | 000,000,876 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2013.06.08 22:20:10 | 000,000,334 | ---- | M] () -- C:\WINDOWS\tasks\SuperEasyDriverUpdater_UPDATES.job
[2013.06.08 22:16:04 | 000,002,467 | ---- | M] () -- C:\Users\Public\Desktop\SlimDrivers.lnk
[2013.06.08 20:59:01 | 000,001,109 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2013.06.08 20:56:39 | 000,053,248 | ---- | M] () -- C:\WINDOWS\SysWow64\zlib.dll
[2013.06.08 20:56:39 | 000,000,749 | ---- | M] () -- C:\Users\Public\Desktop\dMaintenanceConfig.zip
[2013.06.08 20:49:03 | 000,024,576 | ---- | M] () -- C:\WINDOWS\SysNative\FoolishEventLogMsgHelper.dll
[2013.06.08 19:47:38 | 000,000,946 | ---- | M] () -- C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
[2013.06.08 16:28:09 | 000,010,458 | ---- | M] () -- C:\WINDOWS\Q-Dir.ini
[2013.06.08 16:27:57 | 000,001,832 | ---- | M] () -- C:\Users\Public\Desktop\Q-Dir.lnk
[2013.06.05 23:44:36 | 000,000,562 | ---- | M] () -- G:\Documents\Menu Settings.xml
[2013.06.04 20:05:22 | 000,000,021 | ---- | M] () -- C:\Users\Santa\AppData\Roaming\ISOWorkshop.ini
[2013.06.04 19:51:10 | 000,036,446 | ---- | M] () -- G:\Documents\cc_20130604_195103.reg
[2013.06.04 19:13:43 | 000,001,198 | ---- | M] () -- C:\Users\Public\Desktop\ISO Workshop.lnk
[2013.06.01 09:27:30 | 000,001,048 | ---- | M] () -- C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.06.01 09:27:24 | 000,000,930 | ---- | M] () -- G:\Desktop\Dropbox.lnk
[2013.05.30 17:19:36 | 000,001,080 | ---- | M] () -- C:\Users\Santa\AppData\Roaming\Network Meter_Settings.ini
[2013.05.30 17:17:46 | 000,310,216 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2013.05.24 15:21:55 | 000,000,572 | R--- | M] () -- C:\WINDOWS\SysWow64\revolution.2012.118.720p-dimension.nfo
[2013.05.19 12:54:27 | 000,097,176 | ---- | M] (Elaborate Bytes AG) -- C:\WINDOWS\SysWow64\ElbyCDIO.dll
 
[color=#E56717]========== Files Created - No Company Name ==========[/color]
 
[2013.06.15 14:37:40 | 000,377,856 | ---- | C] () -- G:\Desktop\gmer_2.1.19163.exe
[2013.06.15 14:31:48 | 000,050,477 | ---- | C] () -- G:\Desktop\Defogger.exe
[2013.06.15 12:16:57 | 000,001,088 | ---- | C] () -- C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk
[2013.06.15 00:21:50 | 000,000,572 | R--- | C] () -- C:\WINDOWS\SysWow64\revolution.2012.118.720p-dimension.nfo
[2013.06.13 22:23:58 | 000,000,658 | ---- | C] () -- G:\Documents\Breaking Point (German) (2009) AC3 BDRip.nzb
[2013.06.09 12:58:19 | 000,000,748 | ---- | C] () -- G:\Documents\2013-06-09.itlu
[2013.06.09 09:43:45 | 000,000,916 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
[2013.06.09 09:43:45 | 000,000,864 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
[2013.06.09 09:39:34 | 000,001,116 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.09 09:39:34 | 000,001,112 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013.06.08 22:34:26 | 000,000,876 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2013.06.08 22:16:04 | 000,002,467 | ---- | C] () -- C:\Users\Public\Desktop\SlimDrivers.lnk
[2013.06.08 22:12:36 | 000,000,418 | ---- | C] () -- C:\WINDOWS\tasks\SlimDrivers Startup.job
[2013.06.08 20:59:01 | 000,001,109 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2013.06.08 20:59:01 | 000,001,072 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2013.06.08 20:56:39 | 000,053,248 | ---- | C] () -- C:\WINDOWS\SysWow64\zlib.dll
[2013.06.08 20:56:39 | 000,000,749 | ---- | C] () -- C:\Users\Public\Desktop\dMaintenanceConfig.zip
[2013.06.08 20:49:03 | 000,024,576 | ---- | C] () -- C:\WINDOWS\SysNative\FoolishEventLogMsgHelper.dll
[2013.06.08 19:47:38 | 000,000,946 | ---- | C] () -- C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
[2013.06.08 16:34:10 | 000,000,334 | ---- | C] () -- C:\WINDOWS\tasks\SuperEasyDriverUpdater_UPDATES.job
[2013.06.08 16:27:57 | 000,001,832 | ---- | C] () -- C:\Users\Public\Desktop\Q-Dir.lnk
[2013.06.08 16:27:46 | 000,010,458 | ---- | C] () -- C:\WINDOWS\Q-Dir.ini
[2013.06.06 22:50:51 | 000,000,334 | ---- | C] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2013.06.05 23:44:36 | 000,000,562 | ---- | C] () -- G:\Documents\Menu Settings.xml
[2013.06.04 19:51:06 | 000,036,446 | ---- | C] () -- G:\Documents\cc_20130604_195103.reg
[2013.06.03 17:30:42 | 000,002,241 | ---- | C] () -- C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (Secure).lnk
[2013.05.30 17:17:43 | 000,310,216 | ---- | C] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2013.05.30 16:03:37 | 000,387,688 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2013.03.31 19:55:28 | 000,006,656 | ---- | C] () -- C:\Users\Santa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.03.31 01:13:10 | 000,000,026 | ---- | C] () -- C:\Users\Santa\AppData\Roaming\Network Meter_Usage.ini
[2013.03.30 17:26:19 | 000,000,368 | ---- | C] () -- C:\Users\Santa\AppData\Roaming\Digital Clock_Settings.ini
[2013.03.30 17:23:06 | 000,015,547 | ---- | C] () -- C:\Users\Santa\Network_Meter_Data.js
[2013.02.10 13:29:17 | 000,057,344 | ---- | C] () -- C:\WINDOWS\SysWow64\ff_vfw.dll
[2013.02.09 16:08:35 | 000,000,021 | ---- | C] () -- C:\Users\Santa\AppData\Roaming\ISOWorkshop.ini
[2013.02.06 00:00:00 | 000,004,853 | ---- | C] () -- C:\ProgramData\Network_Meter_Data.csv
[2013.02.05 23:11:22 | 000,001,080 | ---- | C] () -- C:\Users\Santa\AppData\Roaming\Network Meter_Settings.ini
[2013.02.05 00:41:56 | 000,000,576 | ---- | C] () -- C:\Users\Santa\AppData\Roaming\All CPU MeterV3_Settings.ini
[2013.02.05 00:26:52 | 000,000,853 | ---- | C] () -- C:\Users\Santa\AppData\Roaming\Drives Meter_Settings.ini
[2013.02.05 00:14:24 | 000,727,029 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2013.02.05 00:14:24 | 000,044,083 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2013.02.04 22:33:22 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2013.02.03 21:00:48 | 000,083,968 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2013.02.03 20:59:12 | 000,010,597 | ---- | C] () -- C:\Users\Santa\AppData\Local\Application.xml
[2013.01.30 20:34:47 | 000,000,000 | ---- | C] () -- C:\Users\Santa\defogger_reenable
[2012.12.14 03:42:30 | 000,963,452 | ---- | C] () -- C:\WINDOWS\SysWow64\igcodeckrng600.bin
[2012.12.14 03:42:30 | 000,064,512 | ---- | C] () -- C:\WINDOWS\SysWow64\igdde32.dll
[2012.12.14 03:42:28 | 000,272,928 | ---- | C] () -- C:\WINDOWS\SysWow64\igvpkrng600.bin
[2012.10.29 16:44:56 | 000,315,392 | ---- | C] () -- C:\WINDOWS\SysWow64\EMRegSys.dll
[2012.07.26 10:13:10 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2012.07.26 10:13:09 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2012.07.26 09:21:26 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012.07.26 03:17:42 | 000,043,520 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2012.07.25 22:37:29 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2012.07.25 22:28:31 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2012.06.02 16:31:19 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
 
[color=#E56717]========== ZeroAccess Check ==========[/color]
 
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.03.06 08:31:28 | 019,758,592 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.03.06 07:03:37 | 017,561,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.07.26 05:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012.07.26 05:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.07.26 05:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
[color=#E56717]========== LOP Check ==========[/color]
 
[2013.02.14 01:57:59 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\ACLive5
[2013.02.10 12:14:02 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\Amazon
[2013.06.08 19:48:33 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\Auslogics
[2013.06.06 22:55:51 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\BatteryBar
[2013.02.16 22:43:12 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\calibre
[2013.02.03 22:23:15 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\Canneverbe Limited
[2013.06.14 21:20:05 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\Dropbox
[2013.06.08 16:31:13 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\Engelmann Media
[2013.02.06 22:38:22 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\EurekaLog
[2013.05.30 16:57:23 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\Foxit Software
[2013.02.12 18:36:41 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\FreeFileSync
[2013.06.06 23:09:05 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\GlarySoft
[2013.04.12 17:20:24 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\Greenshot
[2013.06.01 12:38:56 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\HandBrake
[2013.02.06 21:02:49 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\IrfanView
[2013.05.30 17:24:12 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\JAM Software
[2013.06.13 22:09:57 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\KeePass
[2013.06.13 18:30:24 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\Newshosting
[2013.06.02 12:36:20 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\Notepad++
[2013.02.03 22:17:34 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\pdfforge
[2013.06.08 16:28:09 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\Q-Dir
[2013.06.08 16:34:05 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\SuperEasy Software
[2013.06.04 16:20:36 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\TeamViewer
[2013.02.03 22:44:28 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\TeraCopy
[2013.06.13 22:24:06 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\UseNeXT
[2013.06.04 19:49:39 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\uTorrent
[2013.06.15 12:16:53 | 000,000,000 | ---D | M] -- C:\Users\Santa\AppData\Roaming\WindowsLogonS
 
[color=#E56717]========== Purity Check ==========[/color]
 
 

< End of report >


schrauber 15.06.2013 14:37

Hi,

Systemscan mit FRST
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Scan.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

mamic 15.06.2013 15:06

Hallo Schrauber,
die Antwort kam schneller als erwartet! Super. Hier die scan Ergebnisse:
Gruss
mamic


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013
Ran by Santa (administrator) on 15-06-2013 16:01:13
Running from G:\Desktop
Windows 8 Pro with Media Center (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SAsrv.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(AddGadgets) G:\Downloads\Gadgets\PCMeter\PCMeterV0.3.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
() G:\Downloads\NPowerTray.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Google Inc.) C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Dropbox, Inc.) C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\WINDOWS\System32\WScript.exe
(Ufasoft) C:\Users\Santa\AppData\Roaming\WindowsLogonS\shell.exe
(Ufasoft) C:\Users\Santa\AppData\Roaming\WindowsLogonS\macromedia.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\Bluetooth Headset Helper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [KeyLemon LemonScreen] C:\Program Files\KeyLemon\KLLockEngine.exe atstartup [1004984 2012-12-17] (KeyLemon)
HKLM\...\Run: [KeyLemon Updater] C:\Program Files\KeyLemon\KLUpdater.exe [705464 2012-12-17] (KeyLemon)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe /t [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [LenovoOptMouseUpdate] C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-08-31] (Lenovo Group Limited)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1371648 2012-05-19] (Microsoft Corporation)
HKCU\...\Run: [NPowerTray] G:\Downloads\NPowerTray.exe [x]
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18642024 2013-02-28] (Skype Technologies S.A.)
HKCU\...\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show [89600 2013-04-11] ()
HKCU\...\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart [3289088 2007-11-21] (Google)
HKCU\...\Run: [Google Update] "C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2013-06-09] (Google Inc.)
HKCU\...\Run: [MusicManager] "C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [7331840 2013-04-24] (Google Inc.)
HKCU\...\Run: [Adobe Flash Updater] "C:\ProgramData\svsupdates0\xsytzecrn.exe" [745472 2013-06-15] (Microsoft Corporation)
HKLM-x32\...\Run: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload [1960448 2013-04-05] (Dominik Reichl)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Flash Updater] "C:\ProgramData\svsupdates0\xsytzecrn.exe" [745472 2013-06-15] (Microsoft Corporation)
IMEO\hijackthis.exe: [Debugger] kbvh_.exe
IMEO\housecalllauncher.exe: [Debugger] snrm_.exe
IMEO\mbam.exe: [Debugger] mefjb_.exe
IMEO\mbamgui.exe: [Debugger] gxwfo_.exe
IMEO\MSASCui.exe: [Debugger] moyml_.exe
IMEO\MsMpEng.exe: [Debugger] ftdim_.exe
IMEO\msseces.exe: [Debugger] xsljq_.exe
IMEO\rstrui.exe: [Debugger] safp_.exe
IMEO\spybotsd.exe: [Debugger] sina_.exe
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk
ShortcutTarget: Skype.lnk -> C:\Users\Santa\AppData\Roaming\WindowsLogonS\usft_ext.exe.vbs ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: PodcastBHO Class - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files (x86)\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler: msdaipp - No CLSID Value -
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default
FF SelectedSearchEngine: Web Search
FF Homepage: hxxp://web.de/|hxxp://www.google.com/ig?hl=de|https://ksab.kroschu.com/webaccess/index.php|hxxp://www.gizmodo.de/|hxxp://www.focus.de/|hxxp://www.myliveshopping.de/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
FF Extension: Flagfox - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: DownloadHelper - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: amznUWL2 - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\amznUWL2@amazon.com.xpi
FF Extension: client - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\client@anonymox.net.xpi
FF Extension: isreaditlater - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\isreaditlater@ideashower.com.xpi
FF Extension: musicplayer - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\musicplayer@firemediaplayer.com.xpi
FF Extension: SkipScreen - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\SkipScreen@SkipScreen.xpi
FF Extension: translator - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\translator@zoli.bod.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{677a8f98-fd64-40b0-a883-b8c95d0cbf17}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi

Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
CHR Plugin: (doubletwist Plugin 1, 3, 0, 0) - C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
CHR Plugin: (Foxit Reader Plugin for Mozilla) - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YOUZEEK Free Music) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjcgpdkighmjfjlplcighhgamlhkimce\2.0.1_0
CHR Extension: (YouTube) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Play Music) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg\5.1_0
CHR Extension: (Gmail) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2000-01-01] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [331776 2012-07-26] (Microsoft Corporation)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959256 2012-11-15] (Broadcom Corporation.)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-04-12] (IvoSoft)
R2 CxAudMsg; C:\WINDOWS\system32\CxAudMsg64.exe [201376 2012-06-08] (Conexant Systems Inc.)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-05-30] (Freemake)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1225312 2012-11-26] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [659040 2012-11-26] (Secunia)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

R1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
R1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2000-01-01] (Broadcom Corporation.)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [117632 2013-02-02] (Microsoft Corporation)
S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [30720 2013-02-02] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44344 2012-10-18] (Synaptics Incorporated)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2013-06-15] ()
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 WinRing0_1_2_0; \??\C:\Users\Santa\AppData\Local\Temp\tmpA2D7.tmp [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-15 16:01 - 2013-06-15 16:01 - 00000000 ____D C:\FRST
2013-06-15 15:09 - 2013-06-15 15:09 - 862801894 ____A C:\Windows\MEMORY.DMP
2013-06-15 12:16 - 2013-06-15 12:16 - 00000000 ____D C:\Users\Santa\AppData\Roaming\WindowsLogonS
2013-06-15 11:46 - 2013-06-15 11:46 - 00000000 __SHD C:\ProgramData\svsupdates0
2013-06-15 00:21 - 2013-05-24 15:21 - 00000572 ___RA C:\Windows\SysWOW64\revolution.2012.118.720p-dimension.nfo
2013-06-13 19:15 - 2013-05-04 09:45 - 02233600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Program Files\Newshosting
2013-06-13 18:30 - 2013-06-13 18:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-13 18:11 - 2013-04-24 01:13 - 01013248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-13 18:11 - 2013-04-24 01:12 - 01569792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-13 18:11 - 2013-04-24 01:12 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-13 18:11 - 2013-04-24 00:56 - 01255936 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 18:11 - 2013-04-24 00:55 - 01889280 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 18:11 - 2013-04-24 00:55 - 00141312 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 18:11 - 2013-04-24 00:55 - 00068096 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 17:11 - 2013-04-27 07:20 - 00733184 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 22:23 - 2013-04-03 01:37 - 00025088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 22:23 - 2013-04-03 01:12 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 21:51 - 2013-05-16 00:37 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-06-12 21:51 - 2013-05-16 00:36 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 21:51 - 2013-05-16 00:35 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 21:51 - 2013-05-16 00:35 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-06-12 21:51 - 2013-05-14 15:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 21:51 - 2013-05-14 11:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 21:51 - 2013-04-29 00:30 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 21:51 - 2013-04-29 00:27 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 21:51 - 2013-04-29 00:27 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 21:51 - 2013-04-29 00:27 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-11 19:21 - 2013-05-16 00:35 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\tssdisai.dll
2013-06-09 12:54 - 2013-06-09 12:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 09:43 - 2013-06-15 15:48 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-09 09:43 - 2013-06-15 09:48 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-09 09:39 - 2013-06-15 15:44 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-09 09:39 - 2013-06-15 15:10 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-08 22:35 - 2013-06-08 22:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 22:35 - 2000-01-01 02:00 - 00161144 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwampfl.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 02231064 ____A (Broadcom Corporation.) C:\Windows\System32\BcmBtRSupport.dll
2013-06-08 22:34 - 2000-01-01 02:00 - 02227992 ____A (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
2013-06-08 22:34 - 2000-01-01 02:00 - 00226680 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwavdt.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00186136 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwaudio.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00169240 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\bcbtums.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00040248 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwl2cap.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00020856 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwrchid.sys
2013-06-08 22:28 - 2013-06-08 22:34 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 22:28 - 2013-06-08 22:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 22:20 - 2013-06-09 12:44 - 00000838 ____A C:\Windows\PFRO.log
2013-06-08 22:19 - 2013-06-08 22:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 22:19 - 2000-01-01 02:00 - 00053248 ____A (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
2013-06-08 22:16 - 2013-06-08 22:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 22:16 - 2013-06-08 22:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 22:12 - 2013-06-15 15:10 - 00016152 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-08 22:12 - 2013-06-15 15:10 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-08 22:12 - 2013-06-08 22:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 21:02 - 2013-06-08 21:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 21:02 - 2013-06-08 21:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 21:01 - 2013-06-08 21:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 20:59 - 2013-06-15 13:07 - 01083791 ____A C:\Windows\WindowsUpdate.log
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 20:56 - 2013-06-08 20:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 20:56 - 2013-06-08 20:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 20:49 - 2013-06-08 20:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 19:54 - 2013-06-08 19:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 19:48 - 2013-06-08 19:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 19:47 - 2013-06-08 19:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 19:46 - 2013-06-08 19:47 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 18:32 - 2013-06-08 18:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 16:46 - 2013-06-08 16:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 16:40 - 2013-06-08 16:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 16:34 - 2013-06-08 22:20 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 16:34 - 2013-06-08 16:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2013-06-08 16:27 - 2013-06-08 16:28 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 16:27 - 2013-06-08 16:28 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 16:27 - 2013-06-08 16:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 16:27 - 2013-06-08 16:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 22:52 - 2013-06-06 23:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 22:50 - 2013-06-15 15:10 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-06 22:50 - 2013-06-06 22:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-04 20:02 - 2013-06-04 20:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 19:22 - 2013-06-04 19:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 19:07 - 2013-06-04 19:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 13:52 - 2013-05-24 19:05 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-06-04 13:51 - 2013-06-04 13:56 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-03 17:30 - 2013-06-03 17:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-03 17:10 - 2013-06-08 18:29 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-02 12:38 - 2013-06-02 12:38 - 00000000 ____D C:\Users\Santa\.android
2013-05-31 22:26 - 2013-05-31 22:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 22:26 - 2011-11-25 01:25 - 00015360 ____A (June Fabrics Technology Inc.) C:\Windows\System32\Drivers\pneteth.sys
2013-05-31 14:19 - 2013-05-31 14:19 - 00000000 ____D C:\ZOPO
2013-05-30 20:59 - 2013-05-30 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 19:37 - 2013-06-04 19:07 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-05-30 19:37 - 2013-06-01 12:38 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-30 17:17 - 2013-05-30 17:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 17:13 - 2013-06-05 00:09 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-30 17:13 - 2013-06-05 00:09 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-30 16:57 - 2013-05-30 16:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 16:34 - 2013-06-06 22:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-30 16:04 - 2013-04-08 23:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2013-05-30 16:04 - 2013-04-08 23:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll
2013-05-30 16:04 - 2013-03-16 00:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2013-05-30 16:03 - 2013-04-09 07:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2013-05-30 16:03 - 2013-04-09 07:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll
2013-05-30 16:03 - 2013-04-09 07:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll
2013-05-30 16:03 - 2013-04-09 07:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll
2013-05-30 16:03 - 2013-04-09 07:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-05-30 16:03 - 2013-04-09 06:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe
2013-05-30 16:03 - 2013-04-09 06:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-05-30 16:03 - 2013-04-09 06:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl
2013-05-30 16:03 - 2013-04-09 06:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll
2013-05-30 16:03 - 2013-04-09 04:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-05-30 16:03 - 2013-04-09 04:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2013-05-30 16:03 - 2013-04-09 04:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2013-05-30 16:03 - 2013-04-09 04:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2013-05-30 16:03 - 2013-04-09 04:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2013-05-30 16:03 - 2013-04-09 04:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2013-05-30 16:03 - 2013-04-09 01:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2013-05-30 16:03 - 2013-04-09 01:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-05-30 16:03 - 2013-04-09 01:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2013-05-30 16:03 - 2013-04-09 01:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-05-30 16:03 - 2013-04-08 23:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-05-30 16:03 - 2013-04-08 23:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-05-30 16:03 - 2013-04-08 23:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-05-30 16:03 - 2013-04-08 23:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2013-05-30 16:03 - 2013-04-05 01:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll
2013-05-30 16:03 - 2013-04-03 00:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml
2013-05-30 16:03 - 2013-03-30 20:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi
2013-05-30 16:03 - 2013-03-30 20:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe
2013-05-30 16:03 - 2013-03-29 00:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi
2013-05-30 16:03 - 2013-03-29 00:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe
2013-05-30 16:03 - 2013-03-16 00:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll
2013-05-30 16:03 - 2012-12-13 06:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-05-30 16:03 - 2012-12-13 05:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-05-30 16:01 - 2013-04-16 04:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-30 16:01 - 2013-04-11 08:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-05-30 15:59 - 2013-03-22 05:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2013-05-30 15:59 - 2013-03-22 00:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll
2013-05-30 15:59 - 2013-03-15 02:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-05-30 15:59 - 2013-03-06 09:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-30 15:59 - 2013-03-06 08:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-30 15:59 - 2013-03-06 08:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-30 15:59 - 2013-03-06 08:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-30 15:59 - 2013-03-06 07:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-30 15:59 - 2013-03-06 07:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-19 12:54 - 2013-05-19 12:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll

==================== One Month Modified Files and Folders =======

2013-06-15 16:01 - 2013-06-15 16:01 - 00000000 ____D C:\FRST
2013-06-15 16:00 - 2013-03-30 17:23 - 00015614 ____A C:\Users\Santa\Network_Meter_Data.js
2013-06-15 16:00 - 2013-02-03 22:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Skype
2013-06-15 16:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\sru
2013-06-15 15:48 - 2013-06-09 09:43 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-15 15:44 - 2013-06-09 09:39 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-15 15:19 - 2012-07-26 12:27 - 00753134 ____A C:\Windows\System32\perfh007.dat
2013-06-15 15:19 - 2012-07-26 12:27 - 00155826 ____A C:\Windows\System32\perfc007.dat
2013-06-15 15:19 - 2012-07-26 09:28 - 01745416 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-15 15:11 - 2013-02-03 21:35 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Dropbox
2013-06-15 15:10 - 2013-06-09 09:39 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-15 15:10 - 2013-06-08 22:12 - 00016152 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-15 15:10 - 2013-06-08 22:12 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-15 15:10 - 2013-06-06 22:50 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-15 15:10 - 2012-07-26 09:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-15 15:09 - 2013-06-15 15:09 - 862801894 ____A C:\Windows\MEMORY.DMP
2013-06-15 15:09 - 2013-03-28 14:18 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-15 13:07 - 2013-06-08 20:59 - 01083791 ____A C:\Windows\WindowsUpdate.log
2013-06-15 12:16 - 2013-06-15 12:16 - 00000000 ____D C:\Users\Santa\AppData\Roaming\WindowsLogonS
2013-06-15 11:46 - 2013-06-15 11:46 - 00000000 __SHD C:\ProgramData\svsupdates0
2013-06-15 09:48 - 2013-06-09 09:43 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-15 02:29 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2013-06-15 00:18 - 2013-02-09 16:59 - 00000000 ____D C:\Users\Santa\AppData\Roaming\vlc
2013-06-14 00:40 - 2013-03-31 01:13 - 00000026 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Usage.ini
2013-06-14 00:40 - 2012-07-26 07:26 - 00262144 __ASH C:\Windows\System32\config\BBI
2013-06-13 22:24 - 2013-02-03 22:01 - 00000000 ____D C:\Users\Santa\AppData\Roaming\UseNeXT
2013-06-13 22:09 - 2013-02-03 21:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\KeePass
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Program Files\Newshosting
2013-06-13 18:32 - 2013-02-03 20:59 - 00000000 ____D C:\users\Santa
2013-06-13 18:30 - 2013-06-13 18:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-13 17:31 - 2013-02-04 22:44 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 20:19 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-06-12 00:22 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-06-10 18:43 - 2013-02-05 00:26 - 00000853 ____A C:\Users\Santa\AppData\Roaming\Drives Meter_Settings.ini
2013-06-09 12:54 - 2013-06-09 12:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 12:44 - 2013-06-08 22:20 - 00000838 ____A C:\Windows\PFRO.log
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 09:44 - 2013-02-03 22:16 - 00000000 ____D C:\Users\Santa\AppData\Local\Google
2013-06-09 09:39 - 2013-02-03 22:16 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-08 22:35 - 2013-06-08 22:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 22:34 - 2013-06-08 22:28 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 22:34 - 2013-02-11 01:19 - 00000000 ____D C:\Program Files\Lenovo
2013-06-08 22:28 - 2013-06-08 22:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 22:20 - 2013-06-08 16:34 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 22:19 - 2013-06-08 22:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 22:19 - 2013-02-03 21:15 - 00000000 ____D C:\Program Files (x86)\Intel
2013-06-08 22:16 - 2013-06-08 22:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 22:16 - 2013-06-08 22:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 22:12 - 2013-06-08 22:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 21:02 - 2013-06-08 21:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 21:02 - 2013-06-08 21:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 21:02 - 2013-04-12 16:38 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-08 21:02 - 2013-04-12 16:38 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 21:01 - 2013-02-03 22:14 - 01092512 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-06-08 21:01 - 2013-02-03 22:14 - 00971680 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 20:56 - 2013-06-08 20:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 20:56 - 2013-06-08 20:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 20:49 - 2013-06-08 20:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 19:54 - 2013-06-08 19:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 19:48 - 2013-06-08 19:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 19:47 - 2013-06-08 19:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 19:47 - 2013-06-08 19:46 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 18:32 - 2013-06-08 18:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 18:29 - 2013-06-03 17:10 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-08 17:48 - 2013-02-03 21:03 - 00000000 ____D C:\Users\Santa\AppData\Local\VirtualStore
2013-06-08 16:46 - 2013-06-08 16:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 16:40 - 2013-06-08 16:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 16:34 - 2013-06-08 16:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2013-06-08 16:28 - 2013-06-08 16:27 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 16:28 - 2013-06-08 16:27 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 16:27 - 2013-06-08 16:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 16:27 - 2013-06-08 16:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 23:32 - 2013-02-11 01:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-06-06 23:09 - 2013-06-06 22:52 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 22:55 - 2013-05-30 16:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-06 22:55 - 2013-02-05 00:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\BatteryBar
2013-06-06 22:50 - 2013-06-06 22:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-06 18:09 - 2012-01-07 18:24 - 00000000 ____D C:\Users\Santa\dwhelper
2013-06-06 14:16 - 2013-02-05 00:09 - 00000000 ____D C:\Program Files\BatteryBar
2013-06-05 23:50 - 2013-02-03 22:16 - 00000000 ____D C:\Program Files\Classic Shell
2013-06-05 00:09 - 2013-05-30 17:13 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-05 00:09 - 2013-05-30 17:13 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-04 20:05 - 2013-02-09 16:08 - 00000021 ____A C:\Users\Santa\AppData\Roaming\ISOWorkshop.ini
2013-06-04 20:02 - 2013-06-04 20:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 19:49 - 2013-02-03 22:17 - 00000000 ____D C:\Program Files (x86)\PDFCreator
2013-06-04 19:49 - 2013-02-03 22:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\uTorrent
2013-06-04 19:48 - 2013-02-05 00:10 - 00000000 ____D C:\Program Files\CCleaner
2013-06-04 19:22 - 2013-06-04 19:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 19:13 - 2013-02-05 00:37 - 00001198 ____A C:\Users\Public\Desktop\ISO Workshop.lnk
2013-06-04 19:07 - 2013-06-04 19:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 19:07 - 2013-05-30 19:37 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-06-04 16:20 - 2013-02-11 01:20 - 00000000 ____D C:\Users\Santa\AppData\Roaming\TeamViewer
2013-06-04 14:04 - 2013-02-11 01:19 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-06-04 13:56 - 2013-06-04 13:51 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-04 13:51 - 2012-07-26 10:12 - 00000000 __RSD C:\Windows\Media
2013-06-03 19:08 - 2013-02-03 22:15 - 00000000 ____D C:\Program Files (x86)\uTorrent
2013-06-03 17:30 - 2013-06-03 17:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-02 12:38 - 2013-06-02 12:38 - 00000000 ____D C:\Users\Santa\.android
2013-06-02 12:36 - 2013-02-03 22:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Notepad++
2013-06-01 12:38 - 2013-05-30 19:37 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-31 22:26 - 2013-05-31 22:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 14:19 - 2013-05-31 14:19 - 00000000 ____D C:\ZOPO
2013-05-30 20:59 - 2013-05-30 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 17:24 - 2013-02-06 20:07 - 00000000 ____D C:\Users\Santa\AppData\Roaming\JAM Software
2013-05-30 17:19 - 2013-02-05 23:11 - 00001080 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Settings.ini
2013-05-30 17:17 - 2013-05-30 17:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 17:12 - 2013-02-03 21:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-30 17:12 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData
2013-05-30 17:12 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore
2013-05-30 16:57 - 2013-05-30 16:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 16:57 - 2013-02-12 12:51 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Foxit Software
2013-05-24 19:05 - 2013-06-04 13:52 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-05-24 15:21 - 2013-06-15 00:21 - 00000572 ___RA C:\Windows\SysWOW64\revolution.2012.118.720p-dimension.nfo
2013-05-19 12:54 - 2013-05-19 12:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll
2013-05-16 00:37 - 2013-06-12 21:51 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-05-16 00:36 - 2013-06-12 21:51 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-05-16 00:35 - 2013-06-12 21:51 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-16 00:35 - 2013-06-12 21:51 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-05-16 00:35 - 2013-06-11 19:21 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\tssdisai.dll

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-11 20:03

==================== End Of Log ============================

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-06-2013
Ran by Santa at 2013-06-15 16:02:23 Run:
Running from G:\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

µTorrent (Version: 3.3.0.29533)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
8GadgetPack (Version: 5.0.0)
Adobe Flash Player 11 Plugin (Version: 11.7.700.224)
Amazon MP3-Downloader 1.0.17 (Version: 1.0.17)
Anzeige am Bildschirm (Version: 6.67.05)
Apple Application Support (Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (Version: 2.1.3.127)
ArchiCrypt Live Version 6.9.2.10088 (Version: 6.9.2.10088)
Auslogics Disk Defrag (Version: 3.6)
BatteryBar (remove only)
Bonjour (Version: 3.0.0.10)
calibre 64bit (Version: 0.9.27)
CCleaner (Version: 4.02)
CDBurnerXP (Version: 4.5.1.3868)
Classic Shell (Version: 3.6.7)
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
Conexant HD Audio (Version: 8.32.43.50)
doubleTwist (Version: 3.2.1.14961)
Dropbox (Version: 2.0.22)
ffdshow [rev 2527] [2008-12-19] (Version: 1.0)
Foxit Reader (Version: 6.0.3.524)
FreeFileSync 5.12 (Version: 5.12)
Freemake Video Converter Version 4.0.1 (Version: 4.0.1)
Glary Utilities 2.56.0.1822 (Version: 2.56.0.1822)
Google Chrome (Version: 27.0.1453.110)
Google Earth (Version: 7.0.3.8542)
Google Talk (remove only)
Google Update Helper (Version: 1.3.21.145)
HandBrake 0.9.9.1 (Version: 0.9.9.1)
ImgBurn (Version: 2.5.7.0)
Intel PROSet Wireless
Intel(R) Management Engine Components (Version: 7.1.21.1134)
Intel(R) Processor Graphics (Version: 9.17.10.2932)
Intel(R) WiDi (Version: 3.5.40.0)
Intel® PROSet/Wireless WiFi-Software (Version: 15.05.6000.1657)
IrfanView (remove only) (Version: 4.35)
ISO Workshop 4.2
iTunes (Version: 11.0.4.4)
iTunes Library Updater (Version: 1.2.2)
Java 7 Update 21 (64-bit) (Version: 7.0.210)
Java 7 Update 21 (Version: 7.0.210)
KeePass Password Safe 2.22
KeyLemon (Version: 2.7.1)
Lenovo Bluetooth with Enhanced Data Rate Software (Version: 12.0.0.4300)
Lenovo Patch Utility (Version: 1.3.2.6)
Lenovo Patch Utility 64 bit (Version: 1.3.2.6)
Lenovo Power Management Driver (Version: 1.66.00.22)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office Standard Edition 2003 (Version: 11.0.8173.0)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mozilla Firefox 21.0 (x86 de) (Version: 21.0)
Mozilla Maintenance Service (Version: 21.0)
Music Manager
Network Meter version 9.1 (Version: 9.1)
Newshosting (Version: 1.4.0)
Notepad++ (Version: 6.3.2)
Paint.NET v3.5.10 (Version: 3.60.0)
PdaNet+ for Android 4.12
PDFCreator (Version: 1.6.2)
Picasa 3 (Version: 3.9)
Q-Dir
Revo Uninstaller 1.94 (Version: 1.94)
RICOH_Media_Driver_v2.22.18.01 (Version: 2.22.18.01)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.9.0)
Secunia PSI (3.0.0.6001) (Version: 3.0.0.6001)
Simply Good Pictures 2 (Version: 2.0.12.1210)
Skype™ 6.3 (Version: 6.3.105)
SlimDrivers (Version: 2.2.30085)
TeamViewer 8 (Version: 8.0.18930)
TeraCopy 2.27
ThinkPad UltraNav Driver (Version: 16.2.19.7)
TrueCrypt (Version: 7.1a)
UseNeXT by Tangysoft
VirtualCloneDrive
VLC media player 2.0.6 (Version: 2.0.6)
Windows Service-Center 2013
Yahoo! Messenger

==================== Restore Points  =========================

03-06-2013 15:06:36 Installed VMLite Workstation
05-06-2013 21:50:11 Installed Classic Shell
08-06-2013 14:31:03 Installed Simply Good Pictures 2
08-06-2013 20:17:39 SlimDrivers Installing Drivers
08-06-2013 20:32:26 SlimDrivers Installing Drivers
12-06-2013 20:22:52 Windows Update
15-06-2013 05:51:58 Windows Defender Checkpoint

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/15/2013 03:12:02 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.3.21.103, Zeitstempel: 0x4f3c6d6c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000002e
ID des fehlerhaften Prozesses: 0x1064
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3
Vollständiger Name des fehlerhaften Pakets: GoogleUpdate.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: GoogleUpdate.exe5

Error: (06/15/2013 03:11:07 PM) (Source: Perflib) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (06/15/2013 03:03:09 PM) (Source: Picasa3) (User: )
Description: Google Photos Screensaver ist abgestürzt. Eine Dump-Datei wurde generiert: C:\Users\Santa\AppData\Local\Temp\Photos_Screensaver_130615-150144.dmp

Error: (06/15/2013 02:48:25 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.3.21.103, Zeitstempel: 0x4f3c6d6c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000002f
ID des fehlerhaften Prozesses: 0x1e6c
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3
Vollständiger Name des fehlerhaften Pakets: GoogleUpdate.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: GoogleUpdate.exe5

Error: (06/15/2013 02:47:38 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GPhotos.scr, Version: 3.9.136.20, Zeitstempel: 0x515ae6ae
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000048
ID des fehlerhaften Prozesses: 0x3220
Startzeit der fehlerhaften Anwendung: 0xGPhotos.scr0
Pfad der fehlerhaften Anwendung: GPhotos.scr1
Pfad des fehlerhaften Moduls: GPhotos.scr2
Berichtskennung: GPhotos.scr3
Vollständiger Name des fehlerhaften Pakets: GPhotos.scr4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: GPhotos.scr5

Error: (06/15/2013 01:48:30 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.3.21.103, Zeitstempel: 0x4f3c6d6c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000002f
ID des fehlerhaften Prozesses: 0x3838
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3
Vollständiger Name des fehlerhaften Pakets: GoogleUpdate.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: GoogleUpdate.exe5

Error: (06/15/2013 00:48:17 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.3.21.103, Zeitstempel: 0x4f3c6d6c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000032
ID des fehlerhaften Prozesses: 0x28b4
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3
Vollständiger Name des fehlerhaften Pakets: GoogleUpdate.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: GoogleUpdate.exe5

Error: (06/15/2013 07:51:58 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
  Generatordaten werden gesammelt

Kontext:
  Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
  Generatorname: System Writer
  Generatorinstanz-ID: {a8aee6a7-3469-42e0-bc55-75ae02fddfd4}

Error: (06/14/2013 09:19:25 PM) (Source: Microsoft-Windows-LocationProvider) (User: NT-AUTORITÄT)
Description: There was an error with the Windows Location Provider database

Error: (06/13/2013 11:04:13 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: CxAudMsg64.exe, Version: 1.6.0.0, Zeitstempel: 0x4fd1c0c1
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16579, Zeitstempel: 0x51637f77
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000ebd59
ID des fehlerhaften Prozesses: 0x754
Startzeit der fehlerhaften Anwendung: 0xCxAudMsg64.exe0
Pfad der fehlerhaften Anwendung: CxAudMsg64.exe1
Pfad des fehlerhaften Moduls: CxAudMsg64.exe2
Berichtskennung: CxAudMsg64.exe3
Vollständiger Name des fehlerhaften Pakets: CxAudMsg64.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: CxAudMsg64.exe5


System errors:
=============
Error: (06/15/2013 03:10:52 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (06/15/2013 03:10:22 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Heimnetzgruppen-Listener" wurde mit dem folgenden dienstspezifischen Fehler beendet:
%%2147944153

Error: (06/15/2013 03:10:19 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Defender-Dienst" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (06/15/2013 03:10:15 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ?15.?06.?2013 um 14:38:40 unerwartet heruntergefahren.

Error: (06/14/2013 09:19:08 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (06/13/2013 11:04:13 PM) (Source: Service Control Manager) (User: )
Description: Dienst "Conexant Audio Message Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (06/13/2013 05:10:15 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (06/12/2013 08:13:45 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (06/11/2013 07:08:08 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (06/10/2013 06:41:09 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WinRing0_1_2_0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2


Microsoft Office Sessions:
=========================
Error: (06/15/2013 03:12:02 PM) (Source: Application Error)(User: )
Description: GoogleUpdate.exe1.3.21.1034f3c6d6cntdll.dll6.2.9200.16578515fac6ec00000050000002e106401ce69c9d0546b24C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exeC:\WINDOWS\SYSTEM32\ntdll.dll2ab81968-d5bd-11e2-beb7-cc52afe0f613

Error: (06/15/2013 03:11:07 PM) (Source: Perflib)(User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (06/15/2013 03:03:09 PM) (Source: Picasa3)(User: )
Description: Google Photos Screensaver ist abgestürzt. Eine Dump-Datei wurde generiert: C:\Users\Santa\AppData\Local\Temp\Photos_Screensaver_130615-150144.dmp

Error: (06/15/2013 02:48:25 PM) (Source: Application Error)(User: )
Description: GoogleUpdate.exe1.3.21.1034f3c6d6cntdll.dll6.2.9200.16578515fac6ec00000050000002f1e6c01ce69c6912b3725C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exeC:\WINDOWS\SYSTEM32\ntdll.dllddc9ec21-d5b9-11e2-beb5-cc52afe0f613

Error: (06/15/2013 02:47:38 PM) (Source: Application Error)(User: )
Description: GPhotos.scr3.9.136.20515ae6aentdll.dll6.2.9200.16578515fac6ec000000500000048322001ce69c676d7072fC:\WINDOWS\SysWOW64\GPhotos.scrC:\WINDOWS\SYSTEM32\ntdll.dllc1be7245-d5b9-11e2-beb5-cc52afe0f613

Error: (06/15/2013 01:48:30 PM) (Source: Application Error)(User: )
Description: GoogleUpdate.exe1.3.21.1034f3c6d6cntdll.dll6.2.9200.16578515fac6ec00000050000002f383801ce69be2f66f29eC:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exeC:\WINDOWS\SYSTEM32\ntdll.dll7f2c509e-d5b1-11e2-beb5-cc52afe0f613

Error: (06/15/2013 00:48:17 PM) (Source: Application Error)(User: )
Description: GoogleUpdate.exe1.3.21.1034f3c6d6cntdll.dll6.2.9200.16578515fac6ec00000050000003228b401ce69b5cda18beaC:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exeC:\WINDOWS\SYSTEM32\ntdll.dll15eccb3d-d5a9-11e2-beb5-cc52afe0f613

Error: (06/15/2013 07:51:58 AM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert


Vorgang:
  Generatordaten werden gesammelt

Kontext:
  Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
  Generatorname: System Writer
  Generatorinstanz-ID: {a8aee6a7-3469-42e0-bc55-75ae02fddfd4}

Error: (06/14/2013 09:19:25 PM) (Source: Microsoft-Windows-LocationProvider)(User: NT-AUTORITÄT)
Description: -2147024883

Error: (06/13/2013 11:04:13 PM) (Source: Application Error)(User: )
Description: CxAudMsg64.exe1.6.0.04fd1c0c1ntdll.dll6.2.9200.1657951637f77c000037400000000000ebd5975401ce68480457b5beC:\WINDOWS\system32\CxAudMsg64.exeC:\WINDOWS\SYSTEM32\ntdll.dllcc2db026-d46c-11e2-beb4-cc52afe0f613


==================== Memory info ===========================

Percentage of memory in use: 24%
Total physical RAM: 8103.23 MB
Available physical RAM: 6085.42 MB
Total Pagefile: 16295.23 MB
Available Pagefile: 14240.36 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB

==================== Drives ================================

Drive c: (SSD) (Fixed) (Total:74.43 GB) (Free:13.19 GB) NTFS (Disk=1 Partition=2)
Drive e: (Volume) (Fixed) (Total:379.63 GB) (Free:11.3 GB) NTFS (Disk=0 Partition=4)
Drive g: (DATA) (Fixed) (Total:75.19 GB) (Free:16.78 GB) NTFS (Disk=0 Partition=2)
Drive h: (W8_Recovery) (Fixed) (Total:9.77 GB) (Free:0.8 GB) NTFS (Disk=0 Partition=3)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 9D286FA3)
Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=75 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=380 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=10 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: 9F478B1E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=74 GB) - (Type=07 NTFS)

==================== End Of Log ============================


schrauber 15.06.2013 16:07

Fix mit FRST
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

IMEO\hijackthis.exe: [Debugger] kbvh_.exe
IMEO\housecalllauncher.exe: [Debugger] snrm_.exe
IMEO\mbam.exe: [Debugger] mefjb_.exe
IMEO\mbamgui.exe: [Debugger] gxwfo_.exe
IMEO\MSASCui.exe: [Debugger] moyml_.exe
IMEO\MsMpEng.exe: [Debugger] ftdim_.exe
IMEO\msseces.exe: [Debugger] xsljq_.exe
IMEO\rstrui.exe: [Debugger] safp_.exe
IMEO\spybotsd.exe: [Debugger] sina_.exe
R3 WinRing0_1_2_0; \??\C:\Users\Santa\AppData\Local\Temp\tmpA2D7.tmp [x]
2013-06-15 12:16 - 2013-06-15 12:16 - 00000000 ____D C:\Users\Santa\AppData\Roaming\WindowsLogonS
2013-06-15 11:46 - 2013-06-15 11:46 - 00000000 __SHD C:\ProgramData\svsupdates0

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Fix Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

mamic 15.06.2013 16:29

Ausgeführt!
Gruss Manfred

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-06-2013
Ran by Santa at 2013-06-15 17:20:28 Run:1
Running from G:\Desktop
Boot Mode: Normal
==============================================

HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\hijackthis.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\housecalllauncher.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbam.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbamgui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MsMpEng.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\rstrui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\spybotsd.exe => Key deleted successfully.
WinRing0_1_2_0 => Service deleted successfully.

"C:\Users\Santa\AppData\Roaming\WindowsLogonS" directory move:

C:\Users\Santa\AppData\Roaming\WindowsLogonS\coinutil.dll => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\killer.bat => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\macromedia.exe => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\miner.dll => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\openssl.dll => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\phatk.cl => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\phatk.ptx => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\puts.vbs => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\shell.exe => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\usft_ext.dll => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\usft_ext.exe.vbs => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\shel\compile.bat => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\shel\shell.exe_part2 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\shel\shell.exe_part3 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\shel\shell.exe_part4 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\shel\shell.exe_part5 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\shel\shell.exe_part6 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\compile.bat => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part10 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part11 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part12 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part13 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part14 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part15 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part16 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part17 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part18 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part19 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part2 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part20 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part21 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part22 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part23 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part24 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part25 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part26 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part27 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part28 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part29 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part3 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part30 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part31 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part32 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part33 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part34 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part35 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part4 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part5 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part6 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part7 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part8 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\min\miner.dll_part9 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\macro\compile.bat => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\macro\macromedia.exe_part2 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\macro\macromedia.exe_part3 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\macro\macromedia.exe_part4 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\macro\macromedia.exe_part5 => Moved successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS\macro\macromedia.exe_part6 => Moved successfully.
Could not move "C:\Users\Santa\AppData\Roaming\WindowsLogonS" directory. => Scheduled to move on reboot.


"C:\ProgramData\svsupdates0" directory move:

Could not move C:\ProgramData\svsupdates0\xsytzecrn.exe. => Scheduled to move on reboot.
Could not move "C:\ProgramData\svsupdates0" directory. => Scheduled to move on reboot.


=========== Result of Scheduled Files to move ===========
C:\Users\Santa\AppData\Roaming\WindowsLogonS => Moved successfully.
C:\ProgramData\svsupdates0\xsytzecrn.exe => File could not move.
C:\ProgramData\svsupdates0 => Directory could not move.

==== End of Fixlog ====


schrauber 15.06.2013 17:50

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST Log bitte :)

mamic 15.06.2013 18:55

Good evening!
Alles wie angewiesen durchgeführt, hier die log files!
Gruss
Manfred

Code:

# AdwCleaner v2.303 - Datei am 15/06/2013 um 19:39:10 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows 8 Pro with Media Center  (64 bits)
# Benutzer : Santa - YPS
# Bootmodus : Normal
# Ausgeführt unter : G:\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Users\Santa\AppData\Roaming\pdfforge

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\Software\PIP
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}

***** [Internet Browser] *****

-\\ Internet Explorer v10.0.9200.16537

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v21.0 (de)

Datei : C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\prefs.js

Gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
Gelöscht : user_pref("extensions.skipscreen.hostMatchStr", "hxxp://www.4shared.com/(get|audio|file|document|dir[...]

-\\ Google Chrome v27.0.1453.110

Datei : C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S1].txt - [10552 octets] - [15/06/2013 19:39:10]

########## EOF - C:\AdwCleaner[S1].txt - [10613 octets] ##########

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 8 Pro with Media Center x64
Ran by Santa on 15.06.2013 at 19:43:34,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1236658316-3132239065-196456727-1000\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted: [File] "C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\extensions\isreaditlater@ideashower.com.xpi"
Successfully deleted the following from C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\prefs.js

user_pref("extensions.webbooster@iminent.com.install-event-fired", true);
Emptied folder: C:\Users\Santa\AppData\Roaming\mozilla\firefox\profiles\5zat8v2p.default\minidumps [3 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.06.2013 at 19:47:13,78
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013
Ran by Santa (administrator) on 15-06-2013 19:47:42
Running from G:\Desktop
Windows 8 Pro with Media Center (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SAsrv.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(AddGadgets) G:\Downloads\Gadgets\PCMeter\PCMeterV0.3.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\WINDOWS\System32\LocationNotifications.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
(Google Inc.) C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\WINDOWS\System32\WScript.exe
(Ufasoft) C:\FRST\Quarantine\shell.exe
(Ufasoft) C:\FRST\Quarantine\macromedia.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [KeyLemon LemonScreen] C:\Program Files\KeyLemon\KLLockEngine.exe atstartup [1004984 2012-12-17] (KeyLemon)
HKLM\...\Run: [KeyLemon Updater] C:\Program Files\KeyLemon\KLUpdater.exe [705464 2012-12-17] (KeyLemon)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe /t [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [LenovoOptMouseUpdate] C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-08-31] (Lenovo Group Limited)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1371648 2012-05-19] (Microsoft Corporation)
HKCU\...\Run: [NPowerTray] G:\Downloads\NPowerTray.exe [x]
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18642024 2013-02-28] (Skype Technologies S.A.)
HKCU\...\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show [89600 2013-04-11] ()
HKCU\...\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart [3289088 2007-11-21] (Google)
HKCU\...\Run: [Google Update] "C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2013-06-09] (Google Inc.)
HKCU\...\Run: [MusicManager] "C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [7331840 2013-04-24] (Google Inc.)
HKCU\...\Run: [Adobe Flash Updater] "C:\ProgramData\svsupdates0\xsytzecrn.exe" [745472 2013-06-15] (Microsoft Corporation)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload [1960448 2013-04-05] (Dominik Reichl)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Flash Updater] "C:\ProgramData\svsupdates0\xsytzecrn.exe" [745472 2013-06-15] (Microsoft Corporation)
IMEO\hijackthis.exe: [Debugger] iuznf_.exe
IMEO\housecalllauncher.exe: [Debugger] wtdar_.exe
IMEO\rstrui.exe: [Debugger] bjrwz_.exe
IMEO\spybotsd.exe: [Debugger] wfoqk_.exe
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk
ShortcutTarget: Skype.lnk -> C:\FRST\Quarantine\usft_ext.exe.vbs ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: PodcastBHO Class - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files (x86)\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler: msdaipp - No CLSID Value -
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File

FireFox:
========
FF ProfilePath: C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default
FF Homepage: hxxp://web.de/|hxxp://www.google.com/ig?hl=de|https://ksab.kroschu.com/webaccess/index.php|hxxp://www.gizmodo.de/|hxxp://www.focus.de/|hxxp://www.myliveshopping.de/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
FF Extension: Flagfox - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: DownloadHelper - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: amznUWL2 - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\amznUWL2@amazon.com.xpi
FF Extension: client - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\client@anonymox.net.xpi
FF Extension: musicplayer - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\musicplayer@firemediaplayer.com.xpi
FF Extension: SkipScreen - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\SkipScreen@SkipScreen.xpi
FF Extension: translator - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\translator@zoli.bod.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{677a8f98-fd64-40b0-a883-b8c95d0cbf17}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi

Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
CHR Plugin: (doubletwist Plugin 1, 3, 0, 0) - C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
CHR Plugin: (Foxit Reader Plugin for Mozilla) - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YOUZEEK Free Music) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjcgpdkighmjfjlplcighhgamlhkimce\2.0.1_0
CHR Extension: (YouTube) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Play Music) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg\5.1_0
CHR Extension: (Gmail) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2000-01-01] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [331776 2012-07-26] (Microsoft Corporation)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959256 2012-11-15] (Broadcom Corporation.)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-04-12] (IvoSoft)
R2 CxAudMsg; C:\WINDOWS\system32\CxAudMsg64.exe [201376 2012-06-08] (Conexant Systems Inc.)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-05-30] (Freemake)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1225312 2012-11-26] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [659040 2012-11-26] (Secunia)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

R1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
R1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2000-01-01] (Broadcom Corporation.)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [117632 2013-02-02] (Microsoft Corporation)
S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [30720 2013-02-02] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44344 2012-10-18] (Synaptics Incorporated)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 WinRing0_1_2_0; \??\C:\Users\Santa\AppData\Local\Temp\tmp786C.tmp [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-15 19:47 - 2013-06-15 19:47 - 00001842 ____A C:\Users\Santa\Desktop\JRT.txt
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\JRT
2013-06-15 19:39 - 2013-06-15 19:39 - 00010597 ____A C:\AdwCleaner[S1].txt
2013-06-15 16:01 - 2013-06-15 17:21 - 00000000 ____D C:\FRST
2013-06-15 15:09 - 2013-06-15 15:09 - 862801894 ____A C:\Windows\MEMORY.DMP
2013-06-15 11:46 - 2013-06-15 11:46 - 00000000 __SHD C:\ProgramData\svsupdates0
2013-06-15 00:21 - 2013-05-24 15:21 - 00000572 ___RA C:\Windows\SysWOW64\revolution.2012.118.720p-dimension.nfo
2013-06-13 19:15 - 2013-05-04 09:45 - 02233600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Program Files\Newshosting
2013-06-13 18:30 - 2013-06-13 18:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-13 18:11 - 2013-04-24 01:13 - 01013248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-13 18:11 - 2013-04-24 01:12 - 01569792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-13 18:11 - 2013-04-24 01:12 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-13 18:11 - 2013-04-24 00:56 - 01255936 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 18:11 - 2013-04-24 00:55 - 01889280 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 18:11 - 2013-04-24 00:55 - 00141312 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 18:11 - 2013-04-24 00:55 - 00068096 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 17:11 - 2013-04-27 07:20 - 00733184 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 22:23 - 2013-04-03 01:37 - 00025088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 22:23 - 2013-04-03 01:12 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 21:51 - 2013-05-16 00:37 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-06-12 21:51 - 2013-05-16 00:36 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 21:51 - 2013-05-16 00:35 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 21:51 - 2013-05-16 00:35 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-06-12 21:51 - 2013-05-14 15:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 21:51 - 2013-05-14 11:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 21:51 - 2013-04-29 00:30 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 21:51 - 2013-04-29 00:27 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 21:51 - 2013-04-29 00:27 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 21:51 - 2013-04-29 00:27 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-11 19:21 - 2013-05-16 00:35 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\tssdisai.dll
2013-06-09 12:54 - 2013-06-09 12:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 09:43 - 2013-06-15 19:48 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-09 09:43 - 2013-06-15 09:48 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-09 09:39 - 2013-06-15 19:44 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-09 09:39 - 2013-06-15 19:40 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-08 22:35 - 2013-06-08 22:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 22:35 - 2000-01-01 02:00 - 00161144 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwampfl.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 02231064 ____A (Broadcom Corporation.) C:\Windows\System32\BcmBtRSupport.dll
2013-06-08 22:34 - 2000-01-01 02:00 - 02227992 ____A (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
2013-06-08 22:34 - 2000-01-01 02:00 - 00226680 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwavdt.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00186136 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwaudio.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00169240 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\bcbtums.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00040248 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwl2cap.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00020856 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwrchid.sys
2013-06-08 22:28 - 2013-06-08 22:34 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 22:28 - 2013-06-08 22:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 22:20 - 2013-06-15 17:20 - 00001174 ____A C:\Windows\PFRO.log
2013-06-08 22:19 - 2013-06-08 22:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 22:19 - 2000-01-01 02:00 - 00053248 ____A (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
2013-06-08 22:16 - 2013-06-08 22:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 22:16 - 2013-06-08 22:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 22:12 - 2013-06-15 19:42 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-08 22:12 - 2013-06-08 22:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 21:02 - 2013-06-08 21:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 21:02 - 2013-06-08 21:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 21:01 - 2013-06-08 21:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 20:59 - 2013-06-15 13:07 - 01083791 ____A C:\Windows\WindowsUpdate.log
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 20:56 - 2013-06-08 20:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 20:56 - 2013-06-08 20:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 20:49 - 2013-06-08 20:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 19:54 - 2013-06-08 19:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 19:48 - 2013-06-08 19:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 19:47 - 2013-06-08 19:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 19:46 - 2013-06-08 19:47 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 18:32 - 2013-06-08 18:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 16:46 - 2013-06-08 16:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 16:40 - 2013-06-08 16:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 16:34 - 2013-06-08 22:20 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 16:34 - 2013-06-08 16:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2013-06-08 16:27 - 2013-06-08 16:28 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 16:27 - 2013-06-08 16:28 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 16:27 - 2013-06-08 16:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 16:27 - 2013-06-08 16:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 22:52 - 2013-06-06 23:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 22:50 - 2013-06-15 19:40 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-06 22:50 - 2013-06-06 22:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-04 20:02 - 2013-06-04 20:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 19:22 - 2013-06-04 19:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 19:07 - 2013-06-04 19:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 13:52 - 2013-05-24 19:05 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-06-04 13:51 - 2013-06-04 13:56 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-03 17:30 - 2013-06-03 17:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-03 17:10 - 2013-06-08 18:29 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-02 12:38 - 2013-06-02 12:38 - 00000000 ____D C:\Users\Santa\.android
2013-05-31 22:26 - 2013-05-31 22:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 22:26 - 2011-11-25 01:25 - 00015360 ____A (June Fabrics Technology Inc.) C:\Windows\System32\Drivers\pneteth.sys
2013-05-31 14:19 - 2013-05-31 14:19 - 00000000 ____D C:\ZOPO
2013-05-30 20:59 - 2013-05-30 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 19:37 - 2013-06-04 19:07 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-05-30 19:37 - 2013-06-01 12:38 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-30 17:17 - 2013-05-30 17:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 17:13 - 2013-06-05 00:09 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-30 17:13 - 2013-06-05 00:09 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-30 16:57 - 2013-05-30 16:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 16:34 - 2013-06-06 22:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-30 16:04 - 2013-04-08 23:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2013-05-30 16:04 - 2013-04-08 23:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll
2013-05-30 16:04 - 2013-03-16 00:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2013-05-30 16:03 - 2013-04-09 07:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2013-05-30 16:03 - 2013-04-09 07:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll
2013-05-30 16:03 - 2013-04-09 07:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll
2013-05-30 16:03 - 2013-04-09 07:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll
2013-05-30 16:03 - 2013-04-09 07:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-05-30 16:03 - 2013-04-09 06:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe
2013-05-30 16:03 - 2013-04-09 06:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-05-30 16:03 - 2013-04-09 06:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl
2013-05-30 16:03 - 2013-04-09 06:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll
2013-05-30 16:03 - 2013-04-09 04:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-05-30 16:03 - 2013-04-09 04:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2013-05-30 16:03 - 2013-04-09 04:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2013-05-30 16:03 - 2013-04-09 04:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2013-05-30 16:03 - 2013-04-09 04:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2013-05-30 16:03 - 2013-04-09 04:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2013-05-30 16:03 - 2013-04-09 01:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2013-05-30 16:03 - 2013-04-09 01:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-05-30 16:03 - 2013-04-09 01:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2013-05-30 16:03 - 2013-04-09 01:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-05-30 16:03 - 2013-04-08 23:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-05-30 16:03 - 2013-04-08 23:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-05-30 16:03 - 2013-04-08 23:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-05-30 16:03 - 2013-04-08 23:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2013-05-30 16:03 - 2013-04-05 01:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll
2013-05-30 16:03 - 2013-04-03 00:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml
2013-05-30 16:03 - 2013-03-30 20:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi
2013-05-30 16:03 - 2013-03-30 20:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe
2013-05-30 16:03 - 2013-03-29 00:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi
2013-05-30 16:03 - 2013-03-29 00:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe
2013-05-30 16:03 - 2013-03-16 00:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll
2013-05-30 16:03 - 2012-12-13 06:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-05-30 16:03 - 2012-12-13 05:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-05-30 16:01 - 2013-04-16 04:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-30 16:01 - 2013-04-11 08:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-05-30 15:59 - 2013-03-22 05:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2013-05-30 15:59 - 2013-03-22 00:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll
2013-05-30 15:59 - 2013-03-15 02:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-05-30 15:59 - 2013-03-06 09:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-30 15:59 - 2013-03-06 08:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-30 15:59 - 2013-03-06 08:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-30 15:59 - 2013-03-06 08:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-30 15:59 - 2013-03-06 07:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-30 15:59 - 2013-03-06 07:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-19 12:54 - 2013-05-19 12:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll

==================== One Month Modified Files and Folders =======

2013-06-15 19:48 - 2013-06-09 09:43 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-15 19:47 - 2013-06-15 19:47 - 00001842 ____A C:\Users\Santa\Desktop\JRT.txt
2013-06-15 19:44 - 2013-06-09 09:39 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\JRT
2013-06-15 19:42 - 2013-06-08 22:12 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-15 19:41 - 2013-02-03 22:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Skype
2013-06-15 19:41 - 2013-02-03 21:35 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Dropbox
2013-06-15 19:40 - 2013-06-09 09:39 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-15 19:40 - 2013-06-06 22:50 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-15 19:40 - 2012-07-26 09:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-15 19:39 - 2013-06-15 19:39 - 00010597 ____A C:\AdwCleaner[S1].txt
2013-06-15 19:09 - 2013-03-28 14:18 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-15 19:00 - 2013-03-30 17:23 - 00015713 ____A C:\Users\Santa\Network_Meter_Data.js
2013-06-15 19:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\sru
2013-06-15 17:29 - 2012-07-26 12:27 - 00753134 ____A C:\Windows\System32\perfh007.dat
2013-06-15 17:29 - 2012-07-26 12:27 - 00155826 ____A C:\Windows\System32\perfc007.dat
2013-06-15 17:29 - 2012-07-26 09:28 - 01745416 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-15 17:21 - 2013-06-15 16:01 - 00000000 ____D C:\FRST
2013-06-15 17:20 - 2013-06-08 22:20 - 00001174 ____A C:\Windows\PFRO.log
2013-06-15 17:20 - 2013-03-31 01:13 - 00000026 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Usage.ini
2013-06-15 17:20 - 2012-07-26 07:26 - 00262144 __ASH C:\Windows\System32\config\BBI
2013-06-15 15:09 - 2013-06-15 15:09 - 862801894 ____A C:\Windows\MEMORY.DMP
2013-06-15 13:07 - 2013-06-08 20:59 - 01083791 ____A C:\Windows\WindowsUpdate.log
2013-06-15 11:46 - 2013-06-15 11:46 - 00000000 __SHD C:\ProgramData\svsupdates0
2013-06-15 09:48 - 2013-06-09 09:43 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-15 02:29 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2013-06-15 00:18 - 2013-02-09 16:59 - 00000000 ____D C:\Users\Santa\AppData\Roaming\vlc
2013-06-13 22:24 - 2013-02-03 22:01 - 00000000 ____D C:\Users\Santa\AppData\Roaming\UseNeXT
2013-06-13 22:09 - 2013-02-03 21:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\KeePass
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Program Files\Newshosting
2013-06-13 18:32 - 2013-02-03 20:59 - 00000000 ____D C:\users\Santa
2013-06-13 18:30 - 2013-06-13 18:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-13 17:31 - 2013-02-04 22:44 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 20:19 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-06-12 00:22 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-06-10 18:43 - 2013-02-05 00:26 - 00000853 ____A C:\Users\Santa\AppData\Roaming\Drives Meter_Settings.ini
2013-06-09 12:54 - 2013-06-09 12:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 09:44 - 2013-02-03 22:16 - 00000000 ____D C:\Users\Santa\AppData\Local\Google
2013-06-09 09:39 - 2013-02-03 22:16 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-08 22:35 - 2013-06-08 22:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 22:34 - 2013-06-08 22:28 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 22:34 - 2013-02-11 01:19 - 00000000 ____D C:\Program Files\Lenovo
2013-06-08 22:28 - 2013-06-08 22:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 22:20 - 2013-06-08 16:34 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 22:19 - 2013-06-08 22:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 22:19 - 2013-02-03 21:15 - 00000000 ____D C:\Program Files (x86)\Intel
2013-06-08 22:16 - 2013-06-08 22:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 22:16 - 2013-06-08 22:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 22:12 - 2013-06-08 22:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 21:02 - 2013-06-08 21:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 21:02 - 2013-06-08 21:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 21:02 - 2013-04-12 16:38 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-08 21:02 - 2013-04-12 16:38 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 21:01 - 2013-02-03 22:14 - 01092512 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-06-08 21:01 - 2013-02-03 22:14 - 00971680 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 20:56 - 2013-06-08 20:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 20:56 - 2013-06-08 20:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 20:49 - 2013-06-08 20:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 19:54 - 2013-06-08 19:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 19:48 - 2013-06-08 19:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 19:47 - 2013-06-08 19:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 19:47 - 2013-06-08 19:46 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 18:32 - 2013-06-08 18:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 18:29 - 2013-06-03 17:10 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-08 17:48 - 2013-02-03 21:03 - 00000000 ____D C:\Users\Santa\AppData\Local\VirtualStore
2013-06-08 16:46 - 2013-06-08 16:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 16:40 - 2013-06-08 16:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 16:34 - 2013-06-08 16:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2013-06-08 16:28 - 2013-06-08 16:27 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 16:28 - 2013-06-08 16:27 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 16:27 - 2013-06-08 16:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 16:27 - 2013-06-08 16:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 23:32 - 2013-02-11 01:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-06-06 23:09 - 2013-06-06 22:52 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 22:55 - 2013-05-30 16:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-06 22:55 - 2013-02-05 00:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\BatteryBar
2013-06-06 22:50 - 2013-06-06 22:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-06 18:09 - 2012-01-07 18:24 - 00000000 ____D C:\Users\Santa\dwhelper
2013-06-06 14:16 - 2013-02-05 00:09 - 00000000 ____D C:\Program Files\BatteryBar
2013-06-05 23:50 - 2013-02-03 22:16 - 00000000 ____D C:\Program Files\Classic Shell
2013-06-05 00:09 - 2013-05-30 17:13 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-05 00:09 - 2013-05-30 17:13 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-04 20:05 - 2013-02-09 16:08 - 00000021 ____A C:\Users\Santa\AppData\Roaming\ISOWorkshop.ini
2013-06-04 20:02 - 2013-06-04 20:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 19:49 - 2013-02-03 22:17 - 00000000 ____D C:\Program Files (x86)\PDFCreator
2013-06-04 19:49 - 2013-02-03 22:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\uTorrent
2013-06-04 19:48 - 2013-02-05 00:10 - 00000000 ____D C:\Program Files\CCleaner
2013-06-04 19:22 - 2013-06-04 19:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 19:13 - 2013-02-05 00:37 - 00001198 ____A C:\Users\Public\Desktop\ISO Workshop.lnk
2013-06-04 19:07 - 2013-06-04 19:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 19:07 - 2013-05-30 19:37 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-06-04 16:20 - 2013-02-11 01:20 - 00000000 ____D C:\Users\Santa\AppData\Roaming\TeamViewer
2013-06-04 14:04 - 2013-02-11 01:19 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-06-04 13:56 - 2013-06-04 13:51 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-04 13:51 - 2012-07-26 10:12 - 00000000 __RSD C:\Windows\Media
2013-06-03 19:08 - 2013-02-03 22:15 - 00000000 ____D C:\Program Files (x86)\uTorrent
2013-06-03 17:30 - 2013-06-03 17:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-02 12:38 - 2013-06-02 12:38 - 00000000 ____D C:\Users\Santa\.android
2013-06-02 12:36 - 2013-02-03 22:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Notepad++
2013-06-01 12:38 - 2013-05-30 19:37 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-31 22:26 - 2013-05-31 22:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 14:19 - 2013-05-31 14:19 - 00000000 ____D C:\ZOPO
2013-05-30 20:59 - 2013-05-30 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 17:24 - 2013-02-06 20:07 - 00000000 ____D C:\Users\Santa\AppData\Roaming\JAM Software
2013-05-30 17:19 - 2013-02-05 23:11 - 00001080 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Settings.ini
2013-05-30 17:17 - 2013-05-30 17:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 17:12 - 2013-02-03 21:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-30 17:12 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData
2013-05-30 17:12 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore
2013-05-30 16:57 - 2013-05-30 16:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 16:57 - 2013-02-12 12:51 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Foxit Software
2013-05-24 19:05 - 2013-06-04 13:52 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-05-24 15:21 - 2013-06-15 00:21 - 00000572 ___RA C:\Windows\SysWOW64\revolution.2012.118.720p-dimension.nfo
2013-05-19 12:54 - 2013-05-19 12:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll
2013-05-16 00:37 - 2013-06-12 21:51 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-05-16 00:36 - 2013-06-12 21:51 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-05-16 00:35 - 2013-06-12 21:51 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-16 00:35 - 2013-06-12 21:51 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-05-16 00:35 - 2013-06-11 19:21 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\tssdisai.dll

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-11 20:03

==================== End Of Log ============================

--- --- ---

--- --- ---


Hallo Schrauber,
ich musste inzwischen den Laptop neu starten um den Defender wieder zu aktivieren. Vor Neustart war es nicht möglich oder ich hab mich zu dumm angestellt.
Hoffe das verursacht kein weiteres Problem. Prozessor ist noch immer auf 100%

schrauber 15.06.2013 19:30

Supi, noch ein Onlinescan dann sollte es gut sein.


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST Log. noch Probleme? :)

mamic 16.06.2013 08:45

Guten Morgen Schrauber,
deine letzten Worte von Gestern "noch Probleme?"
Ja, und es wird eher schlimmer! Eset scan dauerte Stunden da die Platte voll ist und der Virus den grössten Teil der Ressourcen beansprucht. Ich bin dann um 1 ins Bett und habe heute morgen auf deinstallieren gedrückt. Leider war das log file dann auch weg. Sorry, mein Fehler ich hab mich nicht genau an die ANweisung gehalten. Die Funde hatte ich vorher noch gesichert:
Code:

C:\FRST\Quarantine\puts.vbs        VBS/CoinMiner.O trojan
C:\FRST\Quarantine\usft_ext.exe.vbs        VBS/CoinMiner.O trojan
C:\Users\Santa\AppData\Local\Temp\bjrwzmzisdj.exe        VBS/CoinMiner.O trojan
C:\Users\Santa\AppData\Local\Temp\edvldqbrrua.exe        VBS/CoinMiner.O trojan
C:\Users\Santa\AppData\Roaming\WindowsLogonS\puts.vbs        VBS/CoinMiner.O trojan
C:\Users\Santa\AppData\Roaming\WindowsLogonS\usft_ext.exe.vbs        VBS/CoinMiner.O trojan
E:\TempT\Revolution.2012.S01E18.720p.HDTV.X264-DIMENSION\Revolution.2012.S01E18.720p.HDTV.X264-DIMENSION.part01.exe.1        a variant of Win32/Injector.Autoit.MB trojan
H:\Galaxy S2\2012-05\clockworkmod\backup\2012-04-30-16.59.33\data.ext4.tar        Android/Exploit.Lotoor.AN trojan

Nach diese Mail werde ich den eset scan nochmal starten!
Security check läuft nicht bis zum Ende durch, stoppt bei "Performing System Health Check". egal ob als user oder admin gestartet.
Ich kann den Windows-Securitycenter Dienst nicht mehr aktivieren und wenn ich den Status des Defenders prüfen möchte sagt mir Win dass es die MSASCui.exe nicht finden kann.
Ich hoffe du hast noch ein paar gute Ideen?
Gruss Manfred

schrauber 16.06.2013 08:51

Die meisten Funde sind schon in Quarantäne. Mach auf jeden fall noch ein frisches FRST LOg, ausserdem noch das:

Downloade dir bitte Farbar Service Scanner Farbar Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.

Poste bitte den Inhalt hier.



mamic 16.06.2013 09:25

Hallo Schrauber, du scheinst Tag und Nacht hier zu sein! Vielen Dank!
Als ich am Handy gesehen habe was du geantwortet hast habe ich den Eset abgebrochen und den fss scan gestartet. So wie ich das verstehe läuft inzwischen bei mir gar nix mehr (Firewall, Defender,...)
Code:

Farbar Service Scanner Version: 13-06-2013
Ran by Santa (administrator) on 16-06-2013 at 10:13:01
Running from "G:\Downloads"
Windows 8 Pro with Media Center  (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.
Checking LEGACY_mpsdrv: ATTENTION!=====> Unable to open LEGACY_mpsdrv\0000 registry key. The key does not exist.

MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is set to Disabled. The default start type is Auto.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is set to Disabled. The default start type is Auto.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Disabled. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.

BITS Service is not running. Checking service configuration:
The start type of BITS service is set to Disabled. The default start type is Auto.
The ImagePath of BITS service is OK.
The ServiceDll of BITS service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend: ""%ProgramFiles%\Windows Defender\MsMpEng.exe"".


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2013-06-13 19:15] - [2013-05-04 09:45] - 2233600 ____A (Microsoft Corporation) D750CE2A52F1B95E654CF2904C88EF1F

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll
[2013-05-30 16:03] - [2013-04-09 06:51] - 0099840 ____A (Microsoft Corporation) 012CFE7F0F95266F554EE3B91EE2128A

C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll
[2013-04-12 21:56] - [2013-03-02 04:45] - 3240448 ____A (Microsoft Corporation) 79F95469604B77296346DE7DB463EA2A

C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll
[2013-06-13 18:11] - [2013-04-24 00:55] - 0068096 ____A (Microsoft Corporation) AFA426B0E7975CEB21F8B6711EFA8945

C:\Program Files\Windows Defender\MpSvc.dll
[2013-03-28 14:10] - [2013-01-29 01:08] - 1555920 ____A (Microsoft Corporation) 905601FFF40D8DA9FA82CBE77D1F5EB1

C:\Program Files\Windows Defender\MsMpEng.exe
[2013-03-28 14:10] - [2013-01-29 03:57] - 0014920 ____A (Microsoft Corporation) 473B9548568BA927ACE0B77EC208A561

C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

Und hier noch der frische FRST Log

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013
Ran by Santa (administrator) on 16-06-2013 10:22:59
Running from G:\Desktop
Windows 8 Pro with Media Center (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SAsrv.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(AddGadgets) G:\Downloads\Gadgets\PCMeter\PCMeterV0.3.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
(Google Inc.) C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Dropbox, Inc.) C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe
(Ufasoft) C:\Users\Santa\AppData\Roaming\WindowsLogonS\shell.exe
(Ufasoft) C:\Users\Santa\AppData\Roaming\WindowsLogonS\macromedia.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [KeyLemon LemonScreen] C:\Program Files\KeyLemon\KLLockEngine.exe atstartup [1004984 2012-12-17] (KeyLemon)
HKLM\...\Run: [KeyLemon Updater] C:\Program Files\KeyLemon\KLUpdater.exe [705464 2012-12-17] (KeyLemon)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe /t [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [LenovoOptMouseUpdate] C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-08-31] (Lenovo Group Limited)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1371648 2012-05-19] (Microsoft Corporation)
HKCU\...\Run: [NPowerTray] G:\Downloads\NPowerTray.exe [x]
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18642024 2013-02-28] (Skype Technologies S.A.)
HKCU\...\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show [89600 2013-04-11] ()
HKCU\...\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart [3289088 2007-11-21] (Google)
HKCU\...\Run: [Google Update] "C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2013-06-09] (Google Inc.)
HKCU\...\Run: [MusicManager] "C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [7331840 2013-04-24] (Google Inc.)
HKCU\...\Run: [Adobe Flash Updater] "C:\ProgramData\svsupdates0\xsytzecrn.exe" [745472 2013-06-15] (Microsoft Corporation)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload [1960448 2013-04-05] (Dominik Reichl)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Flash Updater] "C:\ProgramData\svsupdates0\xsytzecrn.exe" [745472 2013-06-15] (Microsoft Corporation)
IMEO\hijackthis.exe: [Debugger] cxyqahc_.exe
IMEO\housecalllauncher.exe: [Debugger] sbvhynp_.exe
IMEO\mbam.exe: [Debugger] qs_.exe
IMEO\mbamgui.exe: [Debugger] vf_.exe
IMEO\MSASCui.exe: [Debugger] qs_.exe
IMEO\MsMpEng.exe: [Debugger] zt_.exe
IMEO\msseces.exe: [Debugger] hw_.exe
IMEO\rstrui.exe: [Debugger] xsytzec_.exe
IMEO\spybotsd.exe: [Debugger] ltoazty_.exe
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk
ShortcutTarget: Skype.lnk -> C:\Users\Santa\AppData\Roaming\WindowsLogonS\usft_ext.exe.vbs ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: PodcastBHO Class - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files (x86)\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler: msdaipp - No CLSID Value -
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default
FF Homepage: hxxp://web.de/|hxxp://www.google.com/ig?hl=de|https://ksab.kroschu.com/webaccess/index.php|hxxp://www.gizmodo.de/|hxxp://www.focus.de/|hxxp://www.myliveshopping.de/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
FF Extension: Flagfox - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: DownloadHelper - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: amznUWL2 - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\amznUWL2@amazon.com.xpi
FF Extension: client - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\client@anonymox.net.xpi
FF Extension: musicplayer - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\musicplayer@firemediaplayer.com.xpi
FF Extension: SkipScreen - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\SkipScreen@SkipScreen.xpi
FF Extension: translator - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\translator@zoli.bod.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{677a8f98-fd64-40b0-a883-b8c95d0cbf17}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi

Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
CHR Plugin: (doubletwist Plugin 1, 3, 0, 0) - C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
CHR Plugin: (Foxit Reader Plugin for Mozilla) - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YOUZEEK Free Music) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjcgpdkighmjfjlplcighhgamlhkimce\2.0.1_0
CHR Extension: (YouTube) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Play Music) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg\5.1_0
CHR Extension: (Gmail) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2000-01-01] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [331776 2012-07-26] (Microsoft Corporation)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959256 2012-11-15] (Broadcom Corporation.)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-04-12] (IvoSoft)
R2 CxAudMsg; C:\WINDOWS\system32\CxAudMsg64.exe [201376 2012-06-08] (Conexant Systems Inc.)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-05-30] (Freemake)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1225312 2012-11-26] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [659040 2012-11-26] (Secunia)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

R1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
R1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2000-01-01] (Broadcom Corporation.)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [117632 2013-02-02] (Microsoft Corporation)
S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [30720 2013-02-02] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44344 2012-10-18] (Synaptics Incorporated)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2013-06-16] ()
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 WinRing0_1_2_0; \??\C:\Users\Santa\AppData\Local\Temp\tmp6282.tmp [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-16 09:49 - 2013-06-16 09:49 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-15 21:47 - 2013-06-16 10:10 - 00000000 ____D C:\Users\Santa\AppData\Roaming\WindowsLogonS
2013-06-15 19:47 - 2013-06-15 19:47 - 00001842 ____A C:\Users\Santa\Desktop\JRT.txt
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\JRT
2013-06-15 19:39 - 2013-06-15 19:39 - 00010597 ____A C:\AdwCleaner[S1].txt
2013-06-15 16:01 - 2013-06-15 17:21 - 00000000 ____D C:\FRST
2013-06-15 15:09 - 2013-06-15 15:09 - 862801894 ____A C:\Windows\MEMORY.DMP
2013-06-15 11:46 - 2013-06-15 11:46 - 00000000 __SHD C:\ProgramData\svsupdates0
2013-06-15 00:21 - 2013-05-24 15:21 - 00000572 ___RA C:\Windows\SysWOW64\revolution.2012.118.720p-dimension.nfo
2013-06-13 19:15 - 2013-05-04 09:45 - 02233600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Program Files\Newshosting
2013-06-13 18:30 - 2013-06-13 18:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-13 18:11 - 2013-04-24 01:13 - 01013248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-13 18:11 - 2013-04-24 01:12 - 01569792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-13 18:11 - 2013-04-24 01:12 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-13 18:11 - 2013-04-24 00:56 - 01255936 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 18:11 - 2013-04-24 00:55 - 01889280 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 18:11 - 2013-04-24 00:55 - 00141312 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 18:11 - 2013-04-24 00:55 - 00068096 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 17:11 - 2013-04-27 07:20 - 00733184 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 22:23 - 2013-04-03 01:37 - 00025088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 22:23 - 2013-04-03 01:12 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 21:51 - 2013-05-16 00:37 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-06-12 21:51 - 2013-05-16 00:36 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 21:51 - 2013-05-16 00:35 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 21:51 - 2013-05-16 00:35 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-06-12 21:51 - 2013-05-14 15:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 21:51 - 2013-05-14 11:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 21:51 - 2013-04-29 00:30 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 21:51 - 2013-04-29 00:27 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 21:51 - 2013-04-29 00:27 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 21:51 - 2013-04-29 00:27 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-11 19:21 - 2013-05-16 00:35 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\tssdisai.dll
2013-06-09 12:54 - 2013-06-09 12:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 09:43 - 2013-06-16 09:48 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-09 09:43 - 2013-06-16 09:48 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-09 09:39 - 2013-06-16 09:44 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-09 09:39 - 2013-06-16 09:44 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-08 22:35 - 2013-06-08 22:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 22:35 - 2000-01-01 02:00 - 00161144 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwampfl.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 02231064 ____A (Broadcom Corporation.) C:\Windows\System32\BcmBtRSupport.dll
2013-06-08 22:34 - 2000-01-01 02:00 - 02227992 ____A (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
2013-06-08 22:34 - 2000-01-01 02:00 - 00226680 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwavdt.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00186136 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwaudio.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00169240 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\bcbtums.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00040248 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwl2cap.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00020856 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwrchid.sys
2013-06-08 22:28 - 2013-06-08 22:34 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 22:28 - 2013-06-08 22:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 22:20 - 2013-06-15 17:20 - 00001174 ____A C:\Windows\PFRO.log
2013-06-08 22:19 - 2013-06-08 22:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 22:19 - 2000-01-01 02:00 - 00053248 ____A (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
2013-06-08 22:16 - 2013-06-08 22:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 22:16 - 2013-06-08 22:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 22:12 - 2013-06-16 09:13 - 00016152 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-08 22:12 - 2013-06-16 09:13 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-08 22:12 - 2013-06-08 22:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 21:02 - 2013-06-08 21:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 21:02 - 2013-06-08 21:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 21:01 - 2013-06-08 21:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 20:59 - 2013-06-15 13:07 - 01083791 ____A C:\Windows\WindowsUpdate.log
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 20:56 - 2013-06-08 20:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 20:56 - 2013-06-08 20:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 20:49 - 2013-06-08 20:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 19:54 - 2013-06-08 19:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 19:48 - 2013-06-08 19:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 19:47 - 2013-06-08 19:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 19:46 - 2013-06-08 19:47 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 18:32 - 2013-06-08 18:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 16:46 - 2013-06-08 16:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 16:40 - 2013-06-08 16:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 16:34 - 2013-06-08 22:20 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 16:34 - 2013-06-08 16:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2013-06-08 16:27 - 2013-06-08 16:28 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 16:27 - 2013-06-08 16:28 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 16:27 - 2013-06-08 16:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 16:27 - 2013-06-08 16:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 22:52 - 2013-06-06 23:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 22:50 - 2013-06-16 09:13 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-06 22:50 - 2013-06-06 22:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-04 20:02 - 2013-06-04 20:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 19:22 - 2013-06-04 19:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 19:07 - 2013-06-04 19:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 13:52 - 2013-05-24 19:05 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-06-04 13:51 - 2013-06-04 13:56 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-03 17:30 - 2013-06-03 17:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-03 17:10 - 2013-06-08 18:29 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-02 12:38 - 2013-06-02 12:38 - 00000000 ____D C:\Users\Santa\.android
2013-05-31 22:26 - 2013-05-31 22:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 22:26 - 2011-11-25 01:25 - 00015360 ____A (June Fabrics Technology Inc.) C:\Windows\System32\Drivers\pneteth.sys
2013-05-31 14:19 - 2013-05-31 14:19 - 00000000 ____D C:\ZOPO
2013-05-30 20:59 - 2013-05-30 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 19:37 - 2013-06-04 19:07 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-05-30 19:37 - 2013-06-01 12:38 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-30 17:17 - 2013-05-30 17:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 17:13 - 2013-06-05 00:09 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-30 17:13 - 2013-06-05 00:09 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-30 16:57 - 2013-05-30 16:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 16:34 - 2013-06-06 22:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-30 16:04 - 2013-04-08 23:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2013-05-30 16:04 - 2013-04-08 23:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll
2013-05-30 16:04 - 2013-03-16 00:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2013-05-30 16:03 - 2013-04-09 07:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2013-05-30 16:03 - 2013-04-09 07:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll
2013-05-30 16:03 - 2013-04-09 07:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll
2013-05-30 16:03 - 2013-04-09 07:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll
2013-05-30 16:03 - 2013-04-09 07:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-05-30 16:03 - 2013-04-09 06:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe
2013-05-30 16:03 - 2013-04-09 06:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-05-30 16:03 - 2013-04-09 06:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl
2013-05-30 16:03 - 2013-04-09 06:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll
2013-05-30 16:03 - 2013-04-09 04:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-05-30 16:03 - 2013-04-09 04:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2013-05-30 16:03 - 2013-04-09 04:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2013-05-30 16:03 - 2013-04-09 04:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2013-05-30 16:03 - 2013-04-09 04:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2013-05-30 16:03 - 2013-04-09 04:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2013-05-30 16:03 - 2013-04-09 01:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2013-05-30 16:03 - 2013-04-09 01:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-05-30 16:03 - 2013-04-09 01:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2013-05-30 16:03 - 2013-04-09 01:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-05-30 16:03 - 2013-04-08 23:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-05-30 16:03 - 2013-04-08 23:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-05-30 16:03 - 2013-04-08 23:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-05-30 16:03 - 2013-04-08 23:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2013-05-30 16:03 - 2013-04-05 01:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll
2013-05-30 16:03 - 2013-04-03 00:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml
2013-05-30 16:03 - 2013-03-30 20:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi
2013-05-30 16:03 - 2013-03-30 20:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe
2013-05-30 16:03 - 2013-03-29 00:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi
2013-05-30 16:03 - 2013-03-29 00:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe
2013-05-30 16:03 - 2013-03-16 00:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll
2013-05-30 16:03 - 2012-12-13 06:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-05-30 16:03 - 2012-12-13 05:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-05-30 16:01 - 2013-04-16 04:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-30 16:01 - 2013-04-11 08:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-05-30 15:59 - 2013-03-22 05:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2013-05-30 15:59 - 2013-03-22 00:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll
2013-05-30 15:59 - 2013-03-15 02:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-05-30 15:59 - 2013-03-06 09:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-30 15:59 - 2013-03-06 08:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-30 15:59 - 2013-03-06 08:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-30 15:59 - 2013-03-06 08:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-30 15:59 - 2013-03-06 07:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-30 15:59 - 2013-03-06 07:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-19 12:54 - 2013-05-19 12:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll

==================== One Month Modified Files and Folders =======

2013-06-16 10:10 - 2013-06-15 21:47 - 00000000 ____D C:\Users\Santa\AppData\Roaming\WindowsLogonS
2013-06-16 10:09 - 2013-03-28 14:18 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-16 10:00 - 2013-03-30 17:23 - 00015975 ____A C:\Users\Santa\Network_Meter_Data.js
2013-06-16 10:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\sru
2013-06-16 09:51 - 2013-02-03 22:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Skype
2013-06-16 09:49 - 2013-06-16 09:49 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-16 09:48 - 2013-06-09 09:43 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-16 09:48 - 2013-06-09 09:43 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-16 09:44 - 2013-06-09 09:39 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-16 09:44 - 2013-06-09 09:39 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-16 09:21 - 2012-07-26 12:27 - 00753134 ____A C:\Windows\System32\perfh007.dat
2013-06-16 09:21 - 2012-07-26 12:27 - 00155826 ____A C:\Windows\System32\perfc007.dat
2013-06-16 09:21 - 2012-07-26 09:28 - 01745416 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-16 09:14 - 2013-02-03 21:35 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Dropbox
2013-06-16 09:13 - 2013-06-08 22:12 - 00016152 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-16 09:13 - 2013-06-08 22:12 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-16 09:13 - 2013-06-06 22:50 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-16 09:13 - 2013-03-31 01:13 - 00000026 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Usage.ini
2013-06-16 09:13 - 2012-07-26 09:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-16 09:13 - 2012-07-26 07:26 - 00262144 __ASH C:\Windows\System32\config\BBI
2013-06-15 19:47 - 2013-06-15 19:47 - 00001842 ____A C:\Users\Santa\Desktop\JRT.txt
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\JRT
2013-06-15 19:39 - 2013-06-15 19:39 - 00010597 ____A C:\AdwCleaner[S1].txt
2013-06-15 17:21 - 2013-06-15 16:01 - 00000000 ____D C:\FRST
2013-06-15 17:20 - 2013-06-08 22:20 - 00001174 ____A C:\Windows\PFRO.log
2013-06-15 15:09 - 2013-06-15 15:09 - 862801894 ____A C:\Windows\MEMORY.DMP
2013-06-15 13:07 - 2013-06-08 20:59 - 01083791 ____A C:\Windows\WindowsUpdate.log
2013-06-15 11:46 - 2013-06-15 11:46 - 00000000 __SHD C:\ProgramData\svsupdates0
2013-06-15 02:29 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2013-06-15 00:18 - 2013-02-09 16:59 - 00000000 ____D C:\Users\Santa\AppData\Roaming\vlc
2013-06-13 22:24 - 2013-02-03 22:01 - 00000000 ____D C:\Users\Santa\AppData\Roaming\UseNeXT
2013-06-13 22:09 - 2013-02-03 21:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\KeePass
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Program Files\Newshosting
2013-06-13 18:32 - 2013-02-03 20:59 - 00000000 ____D C:\users\Santa
2013-06-13 18:30 - 2013-06-13 18:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-13 17:31 - 2013-02-04 22:44 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 20:19 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-06-12 00:22 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-06-10 18:43 - 2013-02-05 00:26 - 00000853 ____A C:\Users\Santa\AppData\Roaming\Drives Meter_Settings.ini
2013-06-09 12:54 - 2013-06-09 12:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 09:44 - 2013-02-03 22:16 - 00000000 ____D C:\Users\Santa\AppData\Local\Google
2013-06-09 09:39 - 2013-02-03 22:16 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-08 22:35 - 2013-06-08 22:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 22:34 - 2013-06-08 22:28 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 22:34 - 2013-02-11 01:19 - 00000000 ____D C:\Program Files\Lenovo
2013-06-08 22:28 - 2013-06-08 22:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 22:20 - 2013-06-08 16:34 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 22:19 - 2013-06-08 22:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 22:19 - 2013-02-03 21:15 - 00000000 ____D C:\Program Files (x86)\Intel
2013-06-08 22:16 - 2013-06-08 22:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 22:16 - 2013-06-08 22:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 22:12 - 2013-06-08 22:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 21:02 - 2013-06-08 21:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 21:02 - 2013-06-08 21:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 21:02 - 2013-04-12 16:38 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-08 21:02 - 2013-04-12 16:38 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 21:01 - 2013-02-03 22:14 - 01092512 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-06-08 21:01 - 2013-02-03 22:14 - 00971680 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 20:56 - 2013-06-08 20:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 20:56 - 2013-06-08 20:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 20:49 - 2013-06-08 20:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 19:54 - 2013-06-08 19:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 19:48 - 2013-06-08 19:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 19:47 - 2013-06-08 19:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 19:47 - 2013-06-08 19:46 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 18:32 - 2013-06-08 18:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 18:29 - 2013-06-03 17:10 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-08 17:48 - 2013-02-03 21:03 - 00000000 ____D C:\Users\Santa\AppData\Local\VirtualStore
2013-06-08 16:46 - 2013-06-08 16:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 16:40 - 2013-06-08 16:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 16:34 - 2013-06-08 16:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2013-06-08 16:28 - 2013-06-08 16:27 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 16:28 - 2013-06-08 16:27 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 16:27 - 2013-06-08 16:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 16:27 - 2013-06-08 16:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 23:32 - 2013-02-11 01:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-06-06 23:09 - 2013-06-06 22:52 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 22:55 - 2013-05-30 16:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-06 22:55 - 2013-02-05 00:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\BatteryBar
2013-06-06 22:50 - 2013-06-06 22:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-06 18:09 - 2012-01-07 18:24 - 00000000 ____D C:\Users\Santa\dwhelper
2013-06-06 14:16 - 2013-02-05 00:09 - 00000000 ____D C:\Program Files\BatteryBar
2013-06-05 23:50 - 2013-02-03 22:16 - 00000000 ____D C:\Program Files\Classic Shell
2013-06-05 00:09 - 2013-05-30 17:13 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-05 00:09 - 2013-05-30 17:13 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-04 20:05 - 2013-02-09 16:08 - 00000021 ____A C:\Users\Santa\AppData\Roaming\ISOWorkshop.ini
2013-06-04 20:02 - 2013-06-04 20:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 19:49 - 2013-02-03 22:17 - 00000000 ____D C:\Program Files (x86)\PDFCreator
2013-06-04 19:49 - 2013-02-03 22:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\uTorrent
2013-06-04 19:48 - 2013-02-05 00:10 - 00000000 ____D C:\Program Files\CCleaner
2013-06-04 19:22 - 2013-06-04 19:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 19:13 - 2013-02-05 00:37 - 00001198 ____A C:\Users\Public\Desktop\ISO Workshop.lnk
2013-06-04 19:07 - 2013-06-04 19:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 19:07 - 2013-05-30 19:37 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-06-04 16:20 - 2013-02-11 01:20 - 00000000 ____D C:\Users\Santa\AppData\Roaming\TeamViewer
2013-06-04 14:04 - 2013-02-11 01:19 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-06-04 13:56 - 2013-06-04 13:51 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-04 13:51 - 2012-07-26 10:12 - 00000000 __RSD C:\Windows\Media
2013-06-03 19:08 - 2013-02-03 22:15 - 00000000 ____D C:\Program Files (x86)\uTorrent
2013-06-03 17:30 - 2013-06-03 17:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-02 12:38 - 2013-06-02 12:38 - 00000000 ____D C:\Users\Santa\.android
2013-06-02 12:36 - 2013-02-03 22:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Notepad++
2013-06-01 12:38 - 2013-05-30 19:37 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-31 22:26 - 2013-05-31 22:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 14:19 - 2013-05-31 14:19 - 00000000 ____D C:\ZOPO
2013-05-30 20:59 - 2013-05-30 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 17:24 - 2013-02-06 20:07 - 00000000 ____D C:\Users\Santa\AppData\Roaming\JAM Software
2013-05-30 17:19 - 2013-02-05 23:11 - 00001080 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Settings.ini
2013-05-30 17:17 - 2013-05-30 17:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 17:12 - 2013-02-03 21:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-30 17:12 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData
2013-05-30 17:12 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore
2013-05-30 16:57 - 2013-05-30 16:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 16:57 - 2013-02-12 12:51 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Foxit Software
2013-05-24 19:05 - 2013-06-04 13:52 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-05-24 15:21 - 2013-06-15 00:21 - 00000572 ___RA C:\Windows\SysWOW64\revolution.2012.118.720p-dimension.nfo
2013-05-19 12:54 - 2013-05-19 12:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-11 20:03

==================== End Of Log ============================

--- --- ---


Gruss Mamic

schrauber 16.06.2013 09:51

Zitat:

Hallo Schrauber, du scheinst Tag und Nacht hier zu sein! Vielen Dank!
ehm....neeee....ich hab auch noch ein Privatleben.....glaub ich zumindest :D

Das nenn ich mal sauber reinfected :)

Das machen wir jetzt von aussen.
[indent]
Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Yes und klicke Scan
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).

mamic 16.06.2013 10:31

Ok, hat geklappt, hier das log: :kaffee:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013
Ran by SYSTEM on 16-06-2013 11:24:54
Running from E:\
Windows 8 Pro with Media Center (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [KeyLemon LemonScreen] C:\Program Files\KeyLemon\KLLockEngine.exe atstartup [1004984 2012-12-17] (KeyLemon)
HKLM\...\Run: [KeyLemon Updater] C:\Program Files\KeyLemon\KLUpdater.exe [705464 2012-12-17] (KeyLemon)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe /t [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [LenovoOptMouseUpdate] C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-08-31] (Lenovo Group Limited)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload [1960448 2013-04-05] (Dominik Reichl)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Flash Updater] "C:\ProgramData\svsupdates0\xsytzecrn.exe" [745472 2013-06-15] (Microsoft Corporation)
HKU\Santa\...\Run: [NPowerTray] G:\Downloads\NPowerTray.exe [x]
HKU\Santa\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18642024 2013-02-28] (Skype Technologies S.A.)
HKU\Santa\...\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show [89600 2013-04-11] ()
HKU\Santa\...\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart [3289088 2007-11-21] (Google)
HKU\Santa\...\Run: [Google Update] "C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2013-06-09] (Google Inc.)
HKU\Santa\...\Run: [MusicManager] "C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [7331840 2013-04-24] (Google Inc.)
HKU\Santa\...\Run: [Adobe Flash Updater] "C:\ProgramData\svsupdates0\xsytzecrn.exe" [745472 2013-06-15] (Microsoft Corporation)
IMEO\hijackthis.exe: [Debugger] cxyqahc_.exe
IMEO\housecalllauncher.exe: [Debugger] sbvhynp_.exe
IMEO\mbam.exe: [Debugger] qs_.exe
IMEO\mbamgui.exe: [Debugger] vf_.exe
IMEO\MSASCui.exe: [Debugger] qs_.exe
IMEO\MsMpEng.exe: [Debugger] zt_.exe
IMEO\msseces.exe: [Debugger] hw_.exe
IMEO\rstrui.exe: [Debugger] xsytzec_.exe
IMEO\spybotsd.exe: [Debugger] ltoazty_.exe
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk ->  (No File)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk
ShortcutTarget: Skype.lnk ->  (No File)

==================== Services (Whitelisted) =================

S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2000-01-01] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [331776 2012-07-26] (Microsoft Corporation)
S2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959256 2012-11-15] (Broadcom Corporation.)
S2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-04-12] (IvoSoft)
S2 CxAudMsg; C:\WINDOWS\system32\CxAudMsg64.exe [201376 2012-06-08] (Conexant Systems Inc.)
S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-05-30] (Freemake)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] ()
S2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1225312 2012-11-26] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [659040 2012-11-26] (Secunia)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

S1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
S1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2000-01-01] (Broadcom Corporation.)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [117632 2013-02-02] (Microsoft Corporation)
S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [30720 2013-02-02] (Microsoft Corporation)
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44344 2012-10-17] (Synaptics Incorporated)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2013-06-16] ()
S3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)
S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)
S3 WinRing0_1_2_0; \??\C:\Users\Santa\AppData\Local\Temp\tmp6282.tmp [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-16 11:22 - 2013-06-16 11:22 - 00000000 ____A C:\Recovery.txt
2013-06-16 08:49 - 2013-06-16 08:49 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-15 20:47 - 2013-06-16 09:10 - 00000000 ____D C:\Users\Santa\AppData\Roaming\WindowsLogonS
2013-06-15 18:47 - 2013-06-15 18:47 - 00001842 ____A C:\Users\Santa\Desktop\JRT.txt
2013-06-15 18:43 - 2013-06-15 18:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 18:43 - 2013-06-15 18:43 - 00000000 ____D C:\JRT
2013-06-15 18:39 - 2013-06-15 18:39 - 00010597 ____A C:\AdwCleaner[S1].txt
2013-06-15 15:01 - 2013-06-15 16:21 - 00000000 ____D C:\FRST
2013-06-15 14:09 - 2013-06-15 14:09 - 862801894 ____A C:\Windows\MEMORY.DMP
2013-06-15 10:46 - 2013-06-15 10:46 - 00000000 __SHD C:\ProgramData\svsupdates0
2013-06-14 23:21 - 2013-05-24 14:21 - 00000572 ___RA C:\Windows\SysWOW64\revolution.2012.118.720p-dimension.nfo
2013-06-13 18:15 - 2013-05-04 08:45 - 02233600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 17:32 - 2013-06-13 17:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 17:32 - 2013-06-13 17:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 17:32 - 2013-06-13 17:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 17:32 - 2013-06-13 17:32 - 00000000 ____D C:\Program Files\Newshosting
2013-06-13 17:30 - 2013-06-13 17:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-13 17:11 - 2013-04-24 00:13 - 01013248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-13 17:11 - 2013-04-24 00:12 - 01569792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-13 17:11 - 2013-04-24 00:12 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-13 17:11 - 2013-04-23 23:56 - 01255936 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 17:11 - 2013-04-23 23:55 - 01889280 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 17:11 - 2013-04-23 23:55 - 00141312 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 17:11 - 2013-04-23 23:55 - 00068096 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 16:11 - 2013-04-27 06:20 - 00733184 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 21:23 - 2013-04-03 00:37 - 00025088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 21:23 - 2013-04-03 00:12 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 20:51 - 2013-05-15 23:37 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-06-12 20:51 - 2013-05-15 23:36 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 20:51 - 2013-05-15 23:35 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 20:51 - 2013-05-15 23:35 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-06-12 20:51 - 2013-05-14 14:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 20:51 - 2013-05-14 10:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 20:51 - 2013-04-28 23:30 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 20:51 - 2013-04-28 23:30 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 20:51 - 2013-04-28 23:30 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 20:51 - 2013-04-28 23:30 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 20:51 - 2013-04-28 23:30 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 20:51 - 2013-04-28 23:30 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 20:51 - 2013-04-28 23:30 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 20:51 - 2013-04-28 23:28 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 20:51 - 2013-04-28 23:28 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 20:51 - 2013-04-28 23:28 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 20:51 - 2013-04-28 23:28 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll
2013-06-12 20:51 - 2013-04-28 23:28 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 20:51 - 2013-04-28 23:28 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 20:51 - 2013-04-28 23:27 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 20:51 - 2013-04-28 23:27 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 20:51 - 2013-04-28 23:27 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-11 18:21 - 2013-05-15 23:35 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\tssdisai.dll
2013-06-09 11:54 - 2013-06-09 11:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 11:28 - 2013-06-09 11:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 11:28 - 2013-06-09 11:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 11:28 - 2013-06-09 11:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 11:28 - 2013-06-09 11:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 08:43 - 2013-06-16 09:48 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-09 08:43 - 2013-06-16 08:48 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-09 08:39 - 2013-06-16 09:44 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-09 08:39 - 2013-06-16 08:44 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-08 21:35 - 2013-06-08 21:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 21:35 - 2000-01-01 01:00 - 00161144 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwampfl.sys
2013-06-08 21:34 - 2000-01-01 01:00 - 02231064 ____A (Broadcom Corporation.) C:\Windows\System32\BcmBtRSupport.dll
2013-06-08 21:34 - 2000-01-01 01:00 - 02227992 ____A (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
2013-06-08 21:34 - 2000-01-01 01:00 - 00226680 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwavdt.sys
2013-06-08 21:34 - 2000-01-01 01:00 - 00186136 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwaudio.sys
2013-06-08 21:34 - 2000-01-01 01:00 - 00169240 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\bcbtums.sys
2013-06-08 21:34 - 2000-01-01 01:00 - 00040248 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwl2cap.sys
2013-06-08 21:34 - 2000-01-01 01:00 - 00020856 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwrchid.sys
2013-06-08 21:28 - 2013-06-08 21:34 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 21:28 - 2013-06-08 21:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 21:20 - 2013-06-15 16:20 - 00001174 ____A C:\Windows\PFRO.log
2013-06-08 21:19 - 2013-06-08 21:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 21:19 - 2000-01-01 01:00 - 00053248 ____A (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
2013-06-08 21:16 - 2013-06-08 21:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 21:16 - 2013-06-08 21:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 21:12 - 2013-06-16 10:18 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-08 21:12 - 2013-06-16 08:13 - 00016152 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-08 21:12 - 2013-06-08 21:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 20:02 - 2013-06-08 20:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 20:02 - 2013-06-08 20:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 20:02 - 2013-06-08 20:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 20:02 - 2013-06-08 20:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 20:02 - 2013-06-08 20:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 20:01 - 2013-06-08 20:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 20:01 - 2013-06-08 20:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 20:01 - 2013-06-08 20:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 20:01 - 2013-06-08 20:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 20:01 - 2013-06-08 20:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 19:59 - 2013-06-15 12:07 - 01083791 ____A C:\Windows\WindowsUpdate.log
2013-06-08 19:59 - 2013-06-08 19:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 19:59 - 2013-06-08 19:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 19:56 - 2013-06-08 19:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 19:56 - 2013-06-08 19:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 19:49 - 2013-06-08 19:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 18:54 - 2013-06-08 18:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 18:48 - 2013-06-08 18:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 18:47 - 2013-06-08 18:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 18:46 - 2013-06-08 18:47 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 17:32 - 2013-06-08 17:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 15:46 - 2013-06-08 15:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 15:40 - 2013-06-08 15:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 15:34 - 2013-06-08 21:20 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 15:34 - 2013-06-08 15:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 15:31 - 2013-06-08 15:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 15:31 - 2013-06-08 15:31 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2013-06-08 15:27 - 2013-06-08 15:28 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 15:27 - 2013-06-08 15:28 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 15:27 - 2013-06-08 15:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 15:27 - 2013-06-08 15:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 21:52 - 2013-06-06 22:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 21:50 - 2013-06-16 08:13 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-06 21:50 - 2013-06-06 21:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-04 19:02 - 2013-06-04 19:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 18:22 - 2013-06-04 18:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 18:07 - 2013-06-04 18:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 12:52 - 2013-05-24 18:05 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-06-04 12:51 - 2013-06-04 12:56 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 12:51 - 2013-06-04 12:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 12:51 - 2013-06-04 12:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-03 16:30 - 2013-06-03 16:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-03 16:10 - 2013-06-08 17:29 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-02 11:38 - 2013-06-02 11:38 - 00000000 ____D C:\Users\Santa\.android
2013-05-31 21:26 - 2013-05-31 21:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 21:26 - 2011-11-25 00:25 - 00015360 ____A (June Fabrics Technology Inc.) C:\Windows\System32\Drivers\pneteth.sys
2013-05-31 13:19 - 2013-05-31 13:19 - 00000000 ____D C:\ZOPO
2013-05-30 19:59 - 2013-05-30 19:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 19:25 - 2013-05-30 19:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 19:25 - 2013-05-30 19:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 18:37 - 2013-06-04 18:07 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-05-30 18:37 - 2013-06-01 11:38 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-30 16:17 - 2013-05-30 16:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 16:13 - 2013-06-04 23:09 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-30 16:13 - 2013-06-04 23:09 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-30 15:57 - 2013-05-30 15:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 15:34 - 2013-06-06 21:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-30 15:04 - 2013-04-08 22:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2013-05-30 15:04 - 2013-04-08 22:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2013-05-30 15:04 - 2013-04-08 22:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2013-05-30 15:04 - 2013-04-08 22:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2013-05-30 15:04 - 2013-04-08 22:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-05-30 15:04 - 2013-04-08 22:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll
2013-05-30 15:04 - 2013-03-15 23:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2013-05-30 15:03 - 2013-04-09 06:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2013-05-30 15:03 - 2013-04-09 06:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2013-05-30 15:03 - 2013-04-09 06:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2013-05-30 15:03 - 2013-04-09 06:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2013-05-30 15:03 - 2013-04-09 06:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll
2013-05-30 15:03 - 2013-04-09 06:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll
2013-05-30 15:03 - 2013-04-09 06:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll
2013-05-30 15:03 - 2013-04-09 06:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-05-30 15:03 - 2013-04-09 05:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2013-05-30 15:03 - 2013-04-09 05:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe
2013-05-30 15:03 - 2013-04-09 05:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2013-05-30 15:03 - 2013-04-09 05:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe
2013-05-30 15:03 - 2013-04-09 05:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe
2013-05-30 15:03 - 2013-04-09 05:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2013-05-30 15:03 - 2013-04-09 05:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2013-05-30 15:03 - 2013-04-09 05:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-05-30 15:03 - 2013-04-09 05:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll
2013-05-30 15:03 - 2013-04-09 05:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll
2013-05-30 15:03 - 2013-04-09 05:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2013-05-30 15:03 - 2013-04-09 05:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll
2013-05-30 15:03 - 2013-04-09 05:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-05-30 15:03 - 2013-04-09 05:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-05-30 15:03 - 2013-04-09 05:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll
2013-05-30 15:03 - 2013-04-09 05:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2013-05-30 15:03 - 2013-04-09 05:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll
2013-05-30 15:03 - 2013-04-09 05:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll
2013-05-30 15:03 - 2013-04-09 05:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll
2013-05-30 15:03 - 2013-04-09 05:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-05-30 15:03 - 2013-04-09 05:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll
2013-05-30 15:03 - 2013-04-09 05:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2013-05-30 15:03 - 2013-04-09 05:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll
2013-05-30 15:03 - 2013-04-09 05:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll
2013-05-30 15:03 - 2013-04-09 05:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll
2013-05-30 15:03 - 2013-04-09 05:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2013-05-30 15:03 - 2013-04-09 05:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2013-05-30 15:03 - 2013-04-09 05:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2013-05-30 15:03 - 2013-04-09 05:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll
2013-05-30 15:03 - 2013-04-09 05:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll
2013-05-30 15:03 - 2013-04-09 05:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll
2013-05-30 15:03 - 2013-04-09 05:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2013-05-30 15:03 - 2013-04-09 05:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll
2013-05-30 15:03 - 2013-04-09 05:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-30 15:03 - 2013-04-09 05:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2013-05-30 15:03 - 2013-04-09 05:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl
2013-05-30 15:03 - 2013-04-09 05:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll
2013-05-30 15:03 - 2013-04-09 03:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-30 15:03 - 2013-04-09 03:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
2013-05-30 15:03 - 2013-04-09 03:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-05-30 15:03 - 2013-04-09 03:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-05-30 15:03 - 2013-04-09 03:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2013-05-30 15:03 - 2013-04-09 03:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2013-05-30 15:03 - 2013-04-09 03:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2013-05-30 15:03 - 2013-04-09 03:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2013-05-30 15:03 - 2013-04-09 03:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2013-05-30 15:03 - 2013-04-09 00:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2013-05-30 15:03 - 2013-04-09 00:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-05-30 15:03 - 2013-04-09 00:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2013-05-30 15:03 - 2013-04-09 00:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-05-30 15:03 - 2013-04-08 22:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-05-30 15:03 - 2013-04-08 22:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-05-30 15:03 - 2013-04-08 22:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-05-30 15:03 - 2013-04-08 22:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-05-30 15:03 - 2013-04-08 22:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-05-30 15:03 - 2013-04-08 22:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-05-30 15:03 - 2013-04-08 22:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2013-05-30 15:03 - 2013-04-08 22:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2013-05-30 15:03 - 2013-04-05 00:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll
2013-05-30 15:03 - 2013-04-02 23:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml
2013-05-30 15:03 - 2013-03-30 19:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi
2013-05-30 15:03 - 2013-03-30 19:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe
2013-05-30 15:03 - 2013-03-28 23:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi
2013-05-30 15:03 - 2013-03-28 23:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe
2013-05-30 15:03 - 2013-03-15 23:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll
2013-05-30 15:03 - 2012-12-13 05:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-05-30 15:03 - 2012-12-13 04:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-05-30 15:01 - 2013-04-16 03:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-30 15:01 - 2013-04-11 07:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-05-30 14:59 - 2013-03-22 04:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2013-05-30 14:59 - 2013-03-21 23:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll
2013-05-30 14:59 - 2013-03-15 01:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-05-30 14:59 - 2013-03-06 08:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-30 14:59 - 2013-03-06 07:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-30 14:59 - 2013-03-06 07:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-30 14:59 - 2013-03-06 07:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-30 14:59 - 2013-03-06 06:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-30 14:59 - 2013-03-06 06:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-19 11:54 - 2013-05-19 11:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll

==================== One Month Modified Files and Folders =======

2013-06-16 11:22 - 2013-06-16 11:22 - 00000000 ____A C:\Recovery.txt
2013-06-16 10:20 - 2012-07-26 06:26 - 00262144 __ASH C:\Windows\System32\config\BBI
2013-06-16 10:19 - 2012-07-26 11:27 - 00753134 ____A C:\Windows\System32\perfh007.dat
2013-06-16 10:19 - 2012-07-26 11:27 - 00155826 ____A C:\Windows\System32\perfc007.dat
2013-06-16 10:19 - 2012-07-26 08:28 - 01745416 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-16 10:18 - 2013-06-08 21:12 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-16 10:18 - 2013-03-31 00:13 - 00000026 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Usage.ini
2013-06-16 10:09 - 2013-03-28 13:18 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-16 10:00 - 2013-03-30 16:23 - 00016009 ____A C:\Users\Santa\Network_Meter_Data.js
2013-06-16 10:00 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\System32\sru
2013-06-16 09:48 - 2013-06-09 08:43 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-16 09:44 - 2013-06-09 08:39 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-16 09:10 - 2013-06-15 20:47 - 00000000 ____D C:\Users\Santa\AppData\Roaming\WindowsLogonS
2013-06-16 08:51 - 2013-02-03 21:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Skype
2013-06-16 08:49 - 2013-06-16 08:49 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-16 08:48 - 2013-06-09 08:43 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-16 08:44 - 2013-06-09 08:39 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-16 08:14 - 2013-02-03 20:35 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Dropbox
2013-06-16 08:13 - 2013-06-08 21:12 - 00016152 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-16 08:13 - 2013-06-06 21:50 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-16 08:13 - 2012-07-26 08:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-15 18:47 - 2013-06-15 18:47 - 00001842 ____A C:\Users\Santa\Desktop\JRT.txt
2013-06-15 18:43 - 2013-06-15 18:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 18:43 - 2013-06-15 18:43 - 00000000 ____D C:\JRT
2013-06-15 18:39 - 2013-06-15 18:39 - 00010597 ____A C:\AdwCleaner[S1].txt
2013-06-15 16:21 - 2013-06-15 15:01 - 00000000 ____D C:\FRST
2013-06-15 16:20 - 2013-06-08 21:20 - 00001174 ____A C:\Windows\PFRO.log
2013-06-15 14:09 - 2013-06-15 14:09 - 862801894 ____A C:\Windows\MEMORY.DMP
2013-06-15 12:07 - 2013-06-08 19:59 - 01083791 ____A C:\Windows\WindowsUpdate.log
2013-06-15 10:46 - 2013-06-15 10:46 - 00000000 __SHD C:\ProgramData\svsupdates0
2013-06-15 01:29 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\rescache
2013-06-14 23:18 - 2013-02-09 15:59 - 00000000 ____D C:\Users\Santa\AppData\Roaming\vlc
2013-06-13 21:24 - 2013-02-03 21:01 - 00000000 ____D C:\Users\Santa\AppData\Roaming\UseNeXT
2013-06-13 21:09 - 2013-02-03 20:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\KeePass
2013-06-13 17:32 - 2013-06-13 17:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 17:32 - 2013-06-13 17:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 17:32 - 2013-06-13 17:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 17:32 - 2013-06-13 17:32 - 00000000 ____D C:\Program Files\Newshosting
2013-06-13 17:32 - 2013-02-03 19:59 - 00000000 ____D C:\users\Santa
2013-06-13 17:30 - 2013-06-13 17:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-13 16:31 - 2013-02-04 21:44 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 19:19 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-06-11 23:22 - 2012-07-26 06:37 - 00000000 ____D C:\Windows\servicing
2013-06-10 17:43 - 2013-02-04 23:26 - 00000853 ____A C:\Users\Santa\AppData\Roaming\Drives Meter_Settings.ini
2013-06-09 11:54 - 2013-06-09 11:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 11:28 - 2013-06-09 11:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 11:28 - 2013-06-09 11:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 11:28 - 2013-06-09 11:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 11:28 - 2013-06-09 11:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 08:44 - 2013-02-03 21:16 - 00000000 ____D C:\Users\Santa\AppData\Local\Google
2013-06-09 08:39 - 2013-02-03 21:16 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-08 21:35 - 2013-06-08 21:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 21:34 - 2013-06-08 21:28 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 21:34 - 2013-02-11 00:19 - 00000000 ____D C:\Program Files\Lenovo
2013-06-08 21:28 - 2013-06-08 21:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 21:20 - 2013-06-08 15:34 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 21:19 - 2013-06-08 21:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 21:19 - 2013-02-03 20:15 - 00000000 ____D C:\Program Files (x86)\Intel
2013-06-08 21:16 - 2013-06-08 21:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 21:16 - 2013-06-08 21:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 21:12 - 2013-06-08 21:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 20:02 - 2013-06-08 20:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 20:02 - 2013-06-08 20:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 20:02 - 2013-06-08 20:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 20:02 - 2013-06-08 20:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 20:02 - 2013-06-08 20:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 20:02 - 2013-04-12 15:38 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-08 20:02 - 2013-04-12 15:38 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-08 20:01 - 2013-06-08 20:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 20:01 - 2013-06-08 20:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 20:01 - 2013-06-08 20:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 20:01 - 2013-06-08 20:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 20:01 - 2013-06-08 20:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 20:01 - 2013-02-03 21:14 - 01092512 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-06-08 20:01 - 2013-02-03 21:14 - 00971680 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-06-08 19:59 - 2013-06-08 19:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 19:59 - 2013-06-08 19:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 19:56 - 2013-06-08 19:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 19:56 - 2013-06-08 19:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 19:49 - 2013-06-08 19:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 18:54 - 2013-06-08 18:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 18:48 - 2013-06-08 18:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 18:47 - 2013-06-08 18:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 18:47 - 2013-06-08 18:46 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 17:32 - 2013-06-08 17:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 17:29 - 2013-06-03 16:10 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-08 16:48 - 2013-02-03 20:03 - 00000000 ____D C:\Users\Santa\AppData\Local\VirtualStore
2013-06-08 15:46 - 2013-06-08 15:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 15:40 - 2013-06-08 15:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 15:34 - 2013-06-08 15:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 15:31 - 2013-06-08 15:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 15:31 - 2013-06-08 15:31 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2013-06-08 15:28 - 2013-06-08 15:27 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 15:28 - 2013-06-08 15:27 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 15:27 - 2013-06-08 15:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 15:27 - 2013-06-08 15:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 22:32 - 2013-02-11 00:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-06-06 22:09 - 2013-06-06 21:52 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 21:55 - 2013-05-30 15:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-06 21:55 - 2013-02-04 23:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\BatteryBar
2013-06-06 21:50 - 2013-06-06 21:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-06 17:09 - 2012-01-07 17:24 - 00000000 ____D C:\Users\Santa\dwhelper
2013-06-06 13:16 - 2013-02-04 23:09 - 00000000 ____D C:\Program Files\BatteryBar
2013-06-05 22:50 - 2013-02-03 21:16 - 00000000 ____D C:\Program Files\Classic Shell
2013-06-04 23:09 - 2013-05-30 16:13 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-04 23:09 - 2013-05-30 16:13 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-04 19:05 - 2013-02-09 15:08 - 00000021 ____A C:\Users\Santa\AppData\Roaming\ISOWorkshop.ini
2013-06-04 19:02 - 2013-06-04 19:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 18:49 - 2013-02-03 21:17 - 00000000 ____D C:\Program Files (x86)\PDFCreator
2013-06-04 18:49 - 2013-02-03 21:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\uTorrent
2013-06-04 18:48 - 2013-02-04 23:10 - 00000000 ____D C:\Program Files\CCleaner
2013-06-04 18:22 - 2013-06-04 18:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 18:13 - 2013-02-04 23:37 - 00001198 ____A C:\Users\Public\Desktop\ISO Workshop.lnk
2013-06-04 18:07 - 2013-06-04 18:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 18:07 - 2013-05-30 18:37 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-06-04 15:20 - 2013-02-11 00:20 - 00000000 ____D C:\Users\Santa\AppData\Roaming\TeamViewer
2013-06-04 13:04 - 2013-02-11 00:19 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-06-04 12:56 - 2013-06-04 12:51 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 12:51 - 2013-06-04 12:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 12:51 - 2013-06-04 12:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-04 12:51 - 2012-07-26 09:12 - 00000000 __RSD C:\Windows\Media
2013-06-03 18:08 - 2013-02-03 21:15 - 00000000 ____D C:\Program Files (x86)\uTorrent
2013-06-03 16:30 - 2013-06-03 16:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-02 11:38 - 2013-06-02 11:38 - 00000000 ____D C:\Users\Santa\.android
2013-06-02 11:36 - 2013-02-03 21:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Notepad++
2013-06-01 11:38 - 2013-05-30 18:37 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-31 21:26 - 2013-05-31 21:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 13:19 - 2013-05-31 13:19 - 00000000 ____D C:\ZOPO
2013-05-30 19:59 - 2013-05-30 19:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 19:25 - 2013-05-30 19:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 19:25 - 2013-05-30 19:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 16:24 - 2013-02-06 19:07 - 00000000 ____D C:\Users\Santa\AppData\Roaming\JAM Software
2013-05-30 16:19 - 2013-02-05 22:11 - 00001080 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Settings.ini
2013-05-30 16:17 - 2013-05-30 16:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 16:12 - 2013-02-03 20:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-30 16:12 - 2012-07-26 09:12 - 00000000 ___RD C:\Windows\ToastData
2013-05-30 16:12 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\WinStore
2013-05-30 15:57 - 2013-05-30 15:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 15:57 - 2013-02-12 11:51 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Foxit Software
2013-05-24 18:05 - 2013-06-04 12:52 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-05-24 14:21 - 2013-06-14 23:21 - 00000572 ___RA C:\Windows\SysWOW64\revolution.2012.118.720p-dimension.nfo
2013-05-19 11:54 - 2013-05-19 11:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll

==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

Restore point made on: 2013-06-03 16:06:42
Restore point made on: 2013-06-05 20:20:13
Restore point made on: 2013-06-05 22:50:16
Restore point made on: 2013-06-08 15:31:09
Restore point made on: 2013-06-08 18:51:01
Restore point made on: 2013-06-08 21:17:44
Restore point made on: 2013-06-08 21:32:32
Restore point made on: 2013-06-12 21:22:58
Restore point made on: 2013-06-15 06:52:02

==================== Memory info ===========================

Percentage of memory in use: 10%
Total physical RAM: 8103.23 MB
Available physical RAM: 7279.2 MB
Total Pagefile: 8103.23 MB
Available Pagefile: 7287.05 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB

==================== Drives ================================

Drive c: (SSD) (Fixed) (Total:74.43 GB) (Free:12.1 GB) NTFS (Disk=1 Partition=2)
Drive d: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS (Disk=1 Partition=1) ==>[System with boot components (obtained from reading drive)]
Drive e: (T_094432277) (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT32 (Disk=2 Partition=1)
Drive f: (Volume) (Fixed) (Total:379.63 GB) (Free:11.3 GB) NTFS (Disk=0 Partition=4)
Drive g: (DATA) (Fixed) (Total:75.19 GB) (Free:16.83 GB) NTFS (Disk=0 Partition=2)
Drive h: (W8_Recovery) (Fixed) (Total:9.77 GB) (Free:0.8 GB) NTFS (Disk=0 Partition=3)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (SYSTEM_DRV) (Fixed) (Total:1.17 GB) (Free:0.82 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 9D286FA3)
Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=75 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=380 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=10 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: 9F478B1E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=74 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: 96BD01E5)
Partition 1: (Active) - (Size=2 GB) - (Type=0B)


LastRegBack: 2013-06-11 19:03

==================== End Of Log ============================

--- --- ---

schrauber 16.06.2013 10:50

Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

HKU\Santa\...\Run: [Adobe Flash Updater] "C:\ProgramData\svsupdates0\xsytzecrn.exe" [745472 2013-06-15] (Microsoft Corporation)
IMEO\hijackthis.exe: [Debugger] cxyqahc_.exe
IMEO\housecalllauncher.exe: [Debugger] sbvhynp_.exe
IMEO\mbam.exe: [Debugger] qs_.exe
IMEO\mbamgui.exe: [Debugger] vf_.exe
IMEO\MSASCui.exe: [Debugger] qs_.exe
IMEO\MsMpEng.exe: [Debugger] zt_.exe
IMEO\msseces.exe: [Debugger] hw_.exe
IMEO\rstrui.exe: [Debugger] xsytzec_.exe
IMEO\spybotsd.exe: [Debugger] ltoazty_.exe
S3 WinRing0_1_2_0; \??\C:\Users\Santa\AppData\Local\Temp\tmp6282.tmp [x]
2013-06-15 20:47 - 2013-06-16 09:10 - 00000000 ____D C:\Users\Santa\AppData\Roaming\WindowsLogonS
2013-06-15 10:46 - 2013-06-15 10:46 - 00000000 __SHD C:\ProgramData\svsupdates0
2013-06-15 10:46 - 2013-06-15 10:46 - 00000000 __SHD C:\ProgramData\svsupdates0

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Fix Button.
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.


Reboot in den normalen Modus und von dort nen frischen FRST Scan bitte.

mamic 16.06.2013 11:10

Hallo Schrauber,
nein, das war's leider noch nicht. :headbang:
Ein paar Sekunden nach dem Hochfahren waren alle Prozessoren wieder auf 100%
Hier die beiden logs:
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-06-2013
Ran by SYSTEM at 2013-06-16 11:57:57 Run:2
Running from E:\
Boot Mode: Recovery
==============================================

HKU\Santa\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Flash Updater => Value deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\hijackthis.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\housecalllauncher.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbam.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbamgui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MsMpEng.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\rstrui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\spybotsd.exe => Key deleted successfully.
WinRing0_1_2_0 => Service deleted successfully.
C:\Users\Santa\AppData\Roaming\WindowsLogonS => Moved successfully.
C:\ProgramData\svsupdates0 => Moved successfully.
C:\ProgramData\svsupdates0 => File/Directory not found.

==== End of Fixlog ====

Und hier das FRST Log nach dem hochfahren:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013
Ran by Santa (administrator) on 16-06-2013 12:00:47
Running from G:\Desktop
Windows 8 Pro with Media Center (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SAsrv.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(AddGadgets) G:\Downloads\Gadgets\PCMeter\PCMeterV0.3.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\WINDOWS\System32\LocationNotifications.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe
(Google Inc.) C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Dropbox, Inc.) C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\WINDOWS\System32\WScript.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Ufasoft) C:\FRST\Quarantine\WindowsLogonS\WindowsLogonS\shell.exe
(Ufasoft) C:\FRST\Quarantine\WindowsLogonS\WindowsLogonS\macromedia.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\Bluetooth Headset Helper.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [KeyLemon LemonScreen] C:\Program Files\KeyLemon\KLLockEngine.exe atstartup [1004984 2012-12-17] (KeyLemon)
HKLM\...\Run: [KeyLemon Updater] C:\Program Files\KeyLemon\KLUpdater.exe [705464 2012-12-17] (KeyLemon)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe /t [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [LenovoOptMouseUpdate] C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-08-31] (Lenovo Group Limited)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1371648 2012-05-19] (Microsoft Corporation)
HKCU\...\Run: [NPowerTray] G:\Downloads\NPowerTray.exe [x]
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18642024 2013-02-28] (Skype Technologies S.A.)
HKCU\...\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show [89600 2013-04-11] ()
HKCU\...\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart [3289088 2007-11-21] (Google)
HKCU\...\Run: [Google Update] "C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2013-06-09] (Google Inc.)
HKCU\...\Run: [MusicManager] "C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [7331840 2013-04-24] (Google Inc.)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload [1960448 2013-04-05] (Dominik Reichl)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Flash Updater] "C:\ProgramData\svsupdates0\xsytzecrn.exe" [x]
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk
ShortcutTarget: Skype.lnk -> C:\FRST\Quarantine\WindowsLogonS\WindowsLogonS\usft_ext.exe.vbs ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: PodcastBHO Class - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files (x86)\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler: msdaipp - No CLSID Value -
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default
FF Homepage: hxxp://web.de/|hxxp://www.google.com/ig?hl=de|https://ksab.kroschu.com/webaccess/index.php|hxxp://www.gizmodo.de/|hxxp://www.focus.de/|hxxp://www.myliveshopping.de/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
FF Extension: Flagfox - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: DownloadHelper - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: amznUWL2 - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\amznUWL2@amazon.com.xpi
FF Extension: client - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\client@anonymox.net.xpi
FF Extension: musicplayer - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\musicplayer@firemediaplayer.com.xpi
FF Extension: SkipScreen - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\SkipScreen@SkipScreen.xpi
FF Extension: translator - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\translator@zoli.bod.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{677a8f98-fd64-40b0-a883-b8c95d0cbf17}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi

Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
CHR Plugin: (doubletwist Plugin 1, 3, 0, 0) - C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
CHR Plugin: (Foxit Reader Plugin for Mozilla) - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YOUZEEK Free Music) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjcgpdkighmjfjlplcighhgamlhkimce\2.0.1_0
CHR Extension: (YouTube) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Play Music) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg\5.1_0
CHR Extension: (Gmail) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2000-01-01] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [331776 2012-07-26] (Microsoft Corporation)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959256 2012-11-15] (Broadcom Corporation.)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-04-12] (IvoSoft)
R2 CxAudMsg; C:\WINDOWS\system32\CxAudMsg64.exe [201376 2012-06-08] (Conexant Systems Inc.)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-05-30] (Freemake)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1225312 2012-11-26] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [659040 2012-11-26] (Secunia)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

R1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
R1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2000-01-01] (Broadcom Corporation.)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [117632 2013-02-02] (Microsoft Corporation)
S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [30720 2013-02-02] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44344 2012-10-18] (Synaptics Incorporated)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2013-06-16] ()
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 WinRing0_1_2_0; \??\C:\Users\Santa\AppData\Local\Temp\tmp568C.tmp [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-16 09:49 - 2013-06-16 09:49 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-15 19:47 - 2013-06-15 19:47 - 00001842 ____A C:\Users\Santa\Desktop\JRT.txt
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\JRT
2013-06-15 19:39 - 2013-06-15 19:39 - 00010597 ____A C:\AdwCleaner[S1].txt
2013-06-15 16:01 - 2013-06-15 17:21 - 00000000 ____D C:\FRST
2013-06-15 15:09 - 2013-06-15 15:09 - 862801894 ____A C:\Windows\MEMORY.DMP
2013-06-15 00:21 - 2013-05-24 15:21 - 00000572 ___RA C:\Windows\SysWOW64\revolution.2012.118.720p-dimension.nfo
2013-06-13 19:15 - 2013-05-04 09:45 - 02233600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Program Files\Newshosting
2013-06-13 18:30 - 2013-06-13 18:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-13 18:11 - 2013-04-24 01:13 - 01013248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-13 18:11 - 2013-04-24 01:12 - 01569792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-13 18:11 - 2013-04-24 01:12 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-13 18:11 - 2013-04-24 00:56 - 01255936 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 18:11 - 2013-04-24 00:55 - 01889280 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 18:11 - 2013-04-24 00:55 - 00141312 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 18:11 - 2013-04-24 00:55 - 00068096 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 17:11 - 2013-04-27 07:20 - 00733184 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 22:23 - 2013-04-03 01:37 - 00025088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 22:23 - 2013-04-03 01:12 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 21:51 - 2013-05-16 00:37 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-06-12 21:51 - 2013-05-16 00:36 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 21:51 - 2013-05-16 00:35 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 21:51 - 2013-05-16 00:35 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-06-12 21:51 - 2013-05-14 15:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 21:51 - 2013-05-14 11:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 21:51 - 2013-04-29 00:30 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 21:51 - 2013-04-29 00:30 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 21:51 - 2013-04-29 00:28 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 21:51 - 2013-04-29 00:27 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 21:51 - 2013-04-29 00:27 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 21:51 - 2013-04-29 00:27 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-11 19:21 - 2013-05-16 00:35 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\tssdisai.dll
2013-06-09 12:54 - 2013-06-09 12:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 09:43 - 2013-06-16 10:48 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-09 09:43 - 2013-06-16 09:48 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-09 09:39 - 2013-06-16 11:59 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-09 09:39 - 2013-06-16 10:44 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-08 22:35 - 2013-06-08 22:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 22:35 - 2000-01-01 02:00 - 00161144 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwampfl.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 02231064 ____A (Broadcom Corporation.) C:\Windows\System32\BcmBtRSupport.dll
2013-06-08 22:34 - 2000-01-01 02:00 - 02227992 ____A (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
2013-06-08 22:34 - 2000-01-01 02:00 - 00226680 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwavdt.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00186136 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwaudio.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00169240 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\bcbtums.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00040248 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwl2cap.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00020856 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwrchid.sys
2013-06-08 22:28 - 2013-06-08 22:34 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 22:28 - 2013-06-08 22:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 22:20 - 2013-06-15 17:20 - 00001174 ____A C:\Windows\PFRO.log
2013-06-08 22:19 - 2013-06-08 22:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 22:19 - 2000-01-01 02:00 - 00053248 ____A (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
2013-06-08 22:16 - 2013-06-08 22:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 22:16 - 2013-06-08 22:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 22:12 - 2013-06-16 11:59 - 00016152 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-08 22:12 - 2013-06-16 11:59 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-08 22:12 - 2013-06-08 22:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 21:02 - 2013-06-08 21:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 21:02 - 2013-06-08 21:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 21:01 - 2013-06-08 21:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 20:59 - 2013-06-15 13:07 - 01083791 ____A C:\Windows\WindowsUpdate.log
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 20:56 - 2013-06-08 20:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 20:56 - 2013-06-08 20:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 20:49 - 2013-06-08 20:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 19:54 - 2013-06-08 19:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 19:48 - 2013-06-08 19:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 19:47 - 2013-06-08 19:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 19:46 - 2013-06-08 19:47 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 18:32 - 2013-06-08 18:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 16:46 - 2013-06-08 16:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 16:40 - 2013-06-08 16:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 16:34 - 2013-06-08 22:20 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 16:34 - 2013-06-08 16:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2013-06-08 16:27 - 2013-06-08 16:28 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 16:27 - 2013-06-08 16:28 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 16:27 - 2013-06-08 16:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 16:27 - 2013-06-08 16:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 22:52 - 2013-06-06 23:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 22:50 - 2013-06-16 11:59 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-06 22:50 - 2013-06-06 22:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-04 20:02 - 2013-06-04 20:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 19:22 - 2013-06-04 19:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 19:07 - 2013-06-04 19:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 13:52 - 2013-05-24 19:05 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-06-04 13:51 - 2013-06-04 13:56 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-03 17:30 - 2013-06-03 17:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-03 17:10 - 2013-06-08 18:29 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-02 12:38 - 2013-06-02 12:38 - 00000000 ____D C:\Users\Santa\.android
2013-05-31 22:26 - 2013-05-31 22:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 22:26 - 2011-11-25 01:25 - 00015360 ____A (June Fabrics Technology Inc.) C:\Windows\System32\Drivers\pneteth.sys
2013-05-31 14:19 - 2013-05-31 14:19 - 00000000 ____D C:\ZOPO
2013-05-30 20:59 - 2013-05-30 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 19:37 - 2013-06-04 19:07 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-05-30 19:37 - 2013-06-01 12:38 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-30 17:17 - 2013-05-30 17:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 17:13 - 2013-06-05 00:09 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-30 17:13 - 2013-06-05 00:09 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-30 16:57 - 2013-05-30 16:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 16:34 - 2013-06-06 22:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-30 16:04 - 2013-04-08 23:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2013-05-30 16:04 - 2013-04-08 23:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll
2013-05-30 16:04 - 2013-03-16 00:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2013-05-30 16:03 - 2013-04-09 07:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2013-05-30 16:03 - 2013-04-09 07:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll
2013-05-30 16:03 - 2013-04-09 07:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll
2013-05-30 16:03 - 2013-04-09 07:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll
2013-05-30 16:03 - 2013-04-09 07:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-05-30 16:03 - 2013-04-09 06:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe
2013-05-30 16:03 - 2013-04-09 06:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-05-30 16:03 - 2013-04-09 06:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl
2013-05-30 16:03 - 2013-04-09 06:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll
2013-05-30 16:03 - 2013-04-09 04:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-05-30 16:03 - 2013-04-09 04:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2013-05-30 16:03 - 2013-04-09 04:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2013-05-30 16:03 - 2013-04-09 04:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2013-05-30 16:03 - 2013-04-09 04:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2013-05-30 16:03 - 2013-04-09 04:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2013-05-30 16:03 - 2013-04-09 01:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2013-05-30 16:03 - 2013-04-09 01:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-05-30 16:03 - 2013-04-09 01:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2013-05-30 16:03 - 2013-04-09 01:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-05-30 16:03 - 2013-04-08 23:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-05-30 16:03 - 2013-04-08 23:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-05-30 16:03 - 2013-04-08 23:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-05-30 16:03 - 2013-04-08 23:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2013-05-30 16:03 - 2013-04-05 01:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll
2013-05-30 16:03 - 2013-04-03 00:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml
2013-05-30 16:03 - 2013-03-30 20:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi
2013-05-30 16:03 - 2013-03-30 20:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe
2013-05-30 16:03 - 2013-03-29 00:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi
2013-05-30 16:03 - 2013-03-29 00:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe
2013-05-30 16:03 - 2013-03-16 00:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll
2013-05-30 16:03 - 2012-12-13 06:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-05-30 16:03 - 2012-12-13 05:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-05-30 16:01 - 2013-04-16 04:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-30 16:01 - 2013-04-11 08:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-05-30 15:59 - 2013-03-22 05:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2013-05-30 15:59 - 2013-03-22 00:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll
2013-05-30 15:59 - 2013-03-15 02:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-05-30 15:59 - 2013-03-06 09:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-30 15:59 - 2013-03-06 08:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-30 15:59 - 2013-03-06 08:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-30 15:59 - 2013-03-06 08:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-30 15:59 - 2013-03-06 07:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-30 15:59 - 2013-03-06 07:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-19 12:54 - 2013-05-19 12:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll

==================== One Month Modified Files and Folders =======

2013-06-16 12:00 - 2013-03-30 17:23 - 00016041 ____A C:\Users\Santa\Network_Meter_Data.js
2013-06-16 12:00 - 2013-02-03 22:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Skype
2013-06-16 12:00 - 2013-02-03 21:35 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Dropbox
2013-06-16 12:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\sru
2013-06-16 11:59 - 2013-06-09 09:39 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-16 11:59 - 2013-06-08 22:12 - 00016152 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-16 11:59 - 2013-06-08 22:12 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-16 11:59 - 2013-06-06 22:50 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-16 11:59 - 2012-07-26 09:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-16 11:20 - 2012-07-26 07:26 - 00262144 __ASH C:\Windows\System32\config\BBI
2013-06-16 11:19 - 2012-07-26 12:27 - 00753134 ____A C:\Windows\System32\perfh007.dat
2013-06-16 11:19 - 2012-07-26 12:27 - 00155826 ____A C:\Windows\System32\perfc007.dat
2013-06-16 11:19 - 2012-07-26 09:28 - 01745416 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-16 11:18 - 2013-03-31 01:13 - 00000026 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Usage.ini
2013-06-16 11:09 - 2013-03-28 14:18 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-16 10:48 - 2013-06-09 09:43 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-16 10:44 - 2013-06-09 09:39 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-16 09:49 - 2013-06-16 09:49 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-16 09:48 - 2013-06-09 09:43 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-15 19:47 - 2013-06-15 19:47 - 00001842 ____A C:\Users\Santa\Desktop\JRT.txt
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\JRT
2013-06-15 19:39 - 2013-06-15 19:39 - 00010597 ____A C:\AdwCleaner[S1].txt
2013-06-15 17:21 - 2013-06-15 16:01 - 00000000 ____D C:\FRST
2013-06-15 17:20 - 2013-06-08 22:20 - 00001174 ____A C:\Windows\PFRO.log
2013-06-15 15:09 - 2013-06-15 15:09 - 862801894 ____A C:\Windows\MEMORY.DMP
2013-06-15 13:07 - 2013-06-08 20:59 - 01083791 ____A C:\Windows\WindowsUpdate.log
2013-06-15 02:29 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2013-06-15 00:18 - 2013-02-09 16:59 - 00000000 ____D C:\Users\Santa\AppData\Roaming\vlc
2013-06-13 22:24 - 2013-02-03 22:01 - 00000000 ____D C:\Users\Santa\AppData\Roaming\UseNeXT
2013-06-13 22:09 - 2013-02-03 21:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\KeePass
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Program Files\Newshosting
2013-06-13 18:32 - 2013-02-03 20:59 - 00000000 ____D C:\users\Santa
2013-06-13 18:30 - 2013-06-13 18:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-13 17:31 - 2013-02-04 22:44 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 20:19 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-06-12 00:22 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-06-10 18:43 - 2013-02-05 00:26 - 00000853 ____A C:\Users\Santa\AppData\Roaming\Drives Meter_Settings.ini
2013-06-09 12:54 - 2013-06-09 12:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 09:44 - 2013-02-03 22:16 - 00000000 ____D C:\Users\Santa\AppData\Local\Google
2013-06-09 09:39 - 2013-02-03 22:16 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-08 22:35 - 2013-06-08 22:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 22:34 - 2013-06-08 22:28 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 22:34 - 2013-02-11 01:19 - 00000000 ____D C:\Program Files\Lenovo
2013-06-08 22:28 - 2013-06-08 22:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 22:20 - 2013-06-08 16:34 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 22:19 - 2013-06-08 22:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 22:19 - 2013-02-03 21:15 - 00000000 ____D C:\Program Files (x86)\Intel
2013-06-08 22:16 - 2013-06-08 22:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 22:16 - 2013-06-08 22:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 22:12 - 2013-06-08 22:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 21:02 - 2013-06-08 21:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 21:02 - 2013-06-08 21:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 21:02 - 2013-04-12 16:38 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-08 21:02 - 2013-04-12 16:38 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 21:01 - 2013-02-03 22:14 - 01092512 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-06-08 21:01 - 2013-02-03 22:14 - 00971680 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 20:56 - 2013-06-08 20:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 20:56 - 2013-06-08 20:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 20:49 - 2013-06-08 20:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 19:54 - 2013-06-08 19:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 19:48 - 2013-06-08 19:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 19:47 - 2013-06-08 19:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 19:47 - 2013-06-08 19:46 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 18:32 - 2013-06-08 18:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 18:29 - 2013-06-03 17:10 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-08 17:48 - 2013-02-03 21:03 - 00000000 ____D C:\Users\Santa\AppData\Local\VirtualStore
2013-06-08 16:46 - 2013-06-08 16:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 16:40 - 2013-06-08 16:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 16:34 - 2013-06-08 16:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2013-06-08 16:28 - 2013-06-08 16:27 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 16:28 - 2013-06-08 16:27 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 16:27 - 2013-06-08 16:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 16:27 - 2013-06-08 16:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 23:32 - 2013-02-11 01:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-06-06 23:09 - 2013-06-06 22:52 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 22:55 - 2013-05-30 16:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-06 22:55 - 2013-02-05 00:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\BatteryBar
2013-06-06 22:50 - 2013-06-06 22:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-06 18:09 - 2012-01-07 18:24 - 00000000 ____D C:\Users\Santa\dwhelper
2013-06-06 14:16 - 2013-02-05 00:09 - 00000000 ____D C:\Program Files\BatteryBar
2013-06-05 23:50 - 2013-02-03 22:16 - 00000000 ____D C:\Program Files\Classic Shell
2013-06-05 00:09 - 2013-05-30 17:13 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-05 00:09 - 2013-05-30 17:13 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-04 20:05 - 2013-02-09 16:08 - 00000021 ____A C:\Users\Santa\AppData\Roaming\ISOWorkshop.ini
2013-06-04 20:02 - 2013-06-04 20:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 19:49 - 2013-02-03 22:17 - 00000000 ____D C:\Program Files (x86)\PDFCreator
2013-06-04 19:49 - 2013-02-03 22:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\uTorrent
2013-06-04 19:48 - 2013-02-05 00:10 - 00000000 ____D C:\Program Files\CCleaner
2013-06-04 19:22 - 2013-06-04 19:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 19:13 - 2013-02-05 00:37 - 00001198 ____A C:\Users\Public\Desktop\ISO Workshop.lnk
2013-06-04 19:07 - 2013-06-04 19:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 19:07 - 2013-05-30 19:37 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-06-04 16:20 - 2013-02-11 01:20 - 00000000 ____D C:\Users\Santa\AppData\Roaming\TeamViewer
2013-06-04 14:04 - 2013-02-11 01:19 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-06-04 13:56 - 2013-06-04 13:51 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-04 13:51 - 2012-07-26 10:12 - 00000000 __RSD C:\Windows\Media
2013-06-03 19:08 - 2013-02-03 22:15 - 00000000 ____D C:\Program Files (x86)\uTorrent
2013-06-03 17:30 - 2013-06-03 17:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-02 12:38 - 2013-06-02 12:38 - 00000000 ____D C:\Users\Santa\.android
2013-06-02 12:36 - 2013-02-03 22:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Notepad++
2013-06-01 12:38 - 2013-05-30 19:37 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-31 22:26 - 2013-05-31 22:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 14:19 - 2013-05-31 14:19 - 00000000 ____D C:\ZOPO
2013-05-30 20:59 - 2013-05-30 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 17:24 - 2013-02-06 20:07 - 00000000 ____D C:\Users\Santa\AppData\Roaming\JAM Software
2013-05-30 17:19 - 2013-02-05 23:11 - 00001080 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Settings.ini
2013-05-30 17:17 - 2013-05-30 17:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 17:12 - 2013-02-03 21:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-30 17:12 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData
2013-05-30 17:12 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore
2013-05-30 16:57 - 2013-05-30 16:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 16:57 - 2013-02-12 12:51 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Foxit Software
2013-05-24 19:05 - 2013-06-04 13:52 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-05-24 15:21 - 2013-06-15 00:21 - 00000572 ___RA C:\Windows\SysWOW64\revolution.2012.118.720p-dimension.nfo
2013-05-19 12:54 - 2013-05-19 12:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-11 20:03

==================== End Of Log ============================

--- --- ---


Gruss
mamic

schrauber 16.06.2013 11:14

Das wird intressant :)

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

mamic 16.06.2013 11:39

Danke dass du dran bleibst!
Hier der erste log: Ich lass den Malewwarebites jetzt gleich laufen.
Code:

12:38:01.0275 5664  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
12:38:01.0415 5664  ============================================================
12:38:01.0415 5664  Current date / time: 2013/06/16 12:38:01.0415
12:38:01.0415 5664  SystemInfo:
12:38:01.0415 5664 
12:38:01.0415 5664  OS Version: 6.2.9200 ServicePack: 0.0
12:38:01.0415 5664  Product type: Workstation
12:38:01.0415 5664  ComputerName: YPS
12:38:01.0415 5664  UserName: Santa
12:38:01.0415 5664  Windows directory: C:\WINDOWS
12:38:01.0415 5664  System windows directory: C:\WINDOWS
12:38:01.0415 5664  Running under WOW64
12:38:01.0415 5664  Processor architecture: Intel x64
12:38:01.0415 5664  Number of processors: 4
12:38:01.0415 5664  Page size: 0x1000
12:38:01.0415 5664  Boot type: Normal boot
12:38:01.0415 5664  ============================================================
12:38:01.0697 5664  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:38:01.0697 5664  Drive \Device\Harddisk1\DR1 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:38:01.0697 5664  ============================================================
12:38:01.0697 5664  \Device\Harddisk0\DR0:
12:38:01.0697 5664  MBR partitions:
12:38:01.0697 5664  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x258000
12:38:01.0697 5664  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x258800, BlocksNum 0x9663800
12:38:01.0697 5664  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x98BC800, BlocksNum 0x2F741000
12:38:01.0697 5664  \Device\Harddisk0\DR0\Partition4: MBR, Type 0x7, StartLBA 0x38FFD800, BlocksNum 0x1388000
12:38:01.0697 5664  \Device\Harddisk1\DR1:
12:38:01.0697 5664  MBR partitions:
12:38:01.0697 5664  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
12:38:01.0697 5664  \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x94DC800
12:38:01.0697 5664  ============================================================
12:38:01.0712 5664  C: <-> \Device\Harddisk1\DR1\Partition2
12:38:01.0712 5664  E: <-> \Device\Harddisk0\DR0\Partition3
12:38:01.0712 5664  G: <-> \Device\Harddisk0\DR0\Partition2
12:38:01.0712 5664  H: <-> \Device\Harddisk0\DR0\Partition4
12:38:01.0712 5664  ============================================================
12:38:01.0712 5664  Initialize success
12:38:01.0712 5664  ============================================================
12:38:11.0653 1908  ============================================================
12:38:11.0653 1908  Scan started
12:38:11.0653 1908  Mode: Manual; SigCheck; TDLFS;
12:38:11.0653 1908  ============================================================
12:38:11.0747 1908  ================ Scan system memory ========================
12:38:11.0747 1908  System memory - ok
12:38:11.0747 1908  ================ Scan services =============================
12:38:11.0778 1908  [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci        C:\WINDOWS\System32\drivers\1394ohci.sys
12:38:11.0825 1908  1394ohci - ok
12:38:11.0841 1908  [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware          C:\WINDOWS\system32\drivers\3ware.sys
12:38:11.0857 1908  3ware - ok
12:38:11.0857 1908  [ 2C4D6B18A15E9DB5C8856B9F9ECD32D9 ] ACLE6Live      C:\WINDOWS\system32\Drivers\ACLE1764.sys
12:38:11.0903 1908  ACLE6Live - ok
12:38:11.0919 1908  [ 975AABEB243B800C23626D6B652C5A9C ] ACPI            C:\WINDOWS\system32\drivers\ACPI.sys
12:38:11.0950 1908  ACPI - ok
12:38:11.0950 1908  [ DC968C37822117E576B933F34A2D130C ] acpiex          C:\WINDOWS\system32\Drivers\acpiex.sys
12:38:11.0966 1908  acpiex - ok
12:38:11.0966 1908  [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr        C:\WINDOWS\System32\drivers\acpipagr.sys
12:38:11.0982 1908  acpipagr - ok
12:38:11.0997 1908  [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi        C:\WINDOWS\System32\drivers\acpipmi.sys
12:38:11.0997 1908  AcpiPmi - ok
12:38:12.0013 1908  [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime        C:\WINDOWS\System32\drivers\acpitime.sys
12:38:12.0028 1908  acpitime - ok
12:38:12.0044 1908  [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
12:38:12.0060 1908  AdobeFlashPlayerUpdateSvc - ok
12:38:12.0075 1908  [ 93C6388592B99925C1D1576E465BC80F ] adp94xx        C:\WINDOWS\system32\drivers\adp94xx.sys
12:38:12.0091 1908  adp94xx - ok
12:38:12.0107 1908  [ D27763E0247292654E7F7D16444C7C72 ] adpahci        C:\WINDOWS\system32\drivers\adpahci.sys
12:38:12.0138 1908  adpahci - ok
12:38:12.0138 1908  [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320        C:\WINDOWS\system32\drivers\adpu320.sys
12:38:12.0153 1908  adpu320 - ok
12:38:12.0169 1908  [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc    C:\WINDOWS\System32\aelupsvc.dll
12:38:12.0185 1908  AeLookupSvc - ok
12:38:12.0200 1908  [ 36D6A3201721558A8AFBCC09C2DA4C2C ] AFD            C:\WINDOWS\system32\drivers\afd.sys
12:38:12.0216 1908  AFD - ok
12:38:12.0232 1908  [ 01590377A5AB19E792528C628A2A68F9 ] agp440          C:\WINDOWS\system32\drivers\agp440.sys
12:38:12.0247 1908  agp440 - ok
12:38:12.0247 1908  [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG            C:\WINDOWS\System32\alg.exe
12:38:12.0263 1908  ALG - ok
12:38:12.0278 1908  [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\WINDOWS\system32\AUInstallAgent.dll
12:38:12.0294 1908  AllUserInstallAgent - ok
12:38:12.0294 1908  [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8          C:\WINDOWS\System32\drivers\amdk8.sys
12:38:12.0310 1908  AmdK8 - ok
12:38:12.0325 1908  [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM          C:\WINDOWS\System32\drivers\amdppm.sys
12:38:12.0325 1908  AmdPPM - ok
12:38:12.0341 1908  [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata        C:\WINDOWS\system32\drivers\amdsata.sys
12:38:12.0357 1908  amdsata - ok
12:38:12.0357 1908  [ 00452671904F5EE94B50BF0219C97164 ] amdsbs          C:\WINDOWS\system32\drivers\amdsbs.sys
12:38:12.0388 1908  amdsbs - ok
12:38:12.0388 1908  [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata        C:\WINDOWS\system32\drivers\amdxata.sys
12:38:12.0403 1908  amdxata - ok
12:38:12.0419 1908  [ 83B3682CE922FB0F415734B26D9D6233 ] AppID          C:\WINDOWS\system32\drivers\appid.sys
12:38:12.0435 1908  AppID - ok
12:38:12.0450 1908  [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc        C:\WINDOWS\System32\appidsvc.dll
12:38:12.0466 1908  AppIDSvc - ok
12:38:12.0466 1908  [ 4F750B7EFCB6520AE01E01D082D7D476 ] Appinfo        C:\WINDOWS\System32\appinfo.dll
12:38:12.0482 1908  Appinfo - ok
12:38:12.0497 1908  [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
12:38:12.0497 1908  Apple Mobile Device - ok
12:38:12.0513 1908  [ 2D14788C5D0836292BEB27BBE109BE56 ] AppMgmt        C:\WINDOWS\System32\appmgmts.dll
12:38:12.0528 1908  AppMgmt - ok
12:38:12.0528 1908  [ E933401B392387F4BE34DE8BAF1722A7 ] arc            C:\WINDOWS\system32\drivers\arc.sys
12:38:12.0544 1908  arc - ok
12:38:12.0560 1908  [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas          C:\WINDOWS\system32\drivers\arcsas.sys
12:38:12.0575 1908  arcsas - ok
12:38:12.0575 1908  [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac        C:\WINDOWS\system32\DRIVERS\asyncmac.sys
12:38:12.0607 1908  AsyncMac - ok
12:38:12.0607 1908  [ A721FF570C2387E383BDDEA9632863C9 ] atapi          C:\WINDOWS\system32\drivers\atapi.sys
12:38:12.0622 1908  atapi - ok
12:38:12.0622 1908  [ BCD7A47EF587DC00DD61D12D9C2D1E44 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
12:38:12.0653 1908  AudioEndpointBuilder - ok
12:38:12.0653 1908  [ 810F30FF8490ED5ED510621DF10DE320 ] Audiosrv        C:\WINDOWS\System32\Audiosrv.dll
12:38:12.0685 1908  Audiosrv - ok
12:38:12.0700 1908  [ 89491EF71D5EA011127832C588002853 ] AxInstSV        C:\WINDOWS\System32\AxInstSV.dll
12:38:12.0716 1908  AxInstSV - ok
12:38:12.0716 1908  [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv        C:\WINDOWS\system32\drivers\bxvbda.sys
12:38:12.0747 1908  b06bdrv - ok
12:38:12.0763 1908  [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay    C:\WINDOWS\System32\drivers\BasicDisplay.sys
12:38:12.0778 1908  BasicDisplay - ok
12:38:12.0778 1908  [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender    C:\WINDOWS\System32\drivers\BasicRender.sys
12:38:12.0794 1908  BasicRender - ok
12:38:12.0810 1908  [ 656B7660FB8FD2D3D015172486A2DB04 ] bcbtums        C:\WINDOWS\system32\drivers\bcbtums.sys
12:38:12.0810 1908  bcbtums - ok
12:38:12.0841 1908  [ 47F0FE026652F601F367ECE2DFFCFC40 ] BcmBtRSupport  C:\WINDOWS\system32\BtwRSupportService.exe
12:38:12.0935 1908  BcmBtRSupport - ok
12:38:12.0935 1908  [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC          C:\WINDOWS\System32\bdesvc.dll
12:38:12.0950 1908  BDESVC - ok
12:38:12.0966 1908  [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
12:38:12.0966 1908  Beep - ok
12:38:12.0982 1908  [ 9E6A544F465C582AB42444A217CF04DC ] BFE            C:\WINDOWS\System32\bfe.dll
12:38:13.0013 1908  BFE - ok
12:38:13.0028 1908  [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS            C:\WINDOWS\System32\qmgr.dll
12:38:13.0060 1908  BITS - ok
12:38:13.0075 1908  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
12:38:13.0091 1908  Bonjour Service - ok
12:38:13.0107 1908  [ B17AC10B47C7FCB44D22A1F06415840E ] bowser          C:\WINDOWS\system32\DRIVERS\bowser.sys
12:38:13.0107 1908  bowser - ok
12:38:13.0122 1908  [ 975398A3D2C1FEA73FC93931978DF354 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
12:38:13.0138 1908  BrokerInfrastructure - ok
12:38:13.0138 1908  [ 310068BDA80B1D55C36580FD8A873FAF ] Browser        C:\WINDOWS\System32\browser.dll
12:38:13.0153 1908  Browser - ok
12:38:13.0169 1908  [ 1487553CE1433AB594427B2E7DA4181C ] BthA2DP        C:\WINDOWS\system32\drivers\BthA2DP.sys
12:38:13.0185 1908  BthA2DP - ok
12:38:13.0185 1908  [ F17DEEAC7D51D44CF1BFF8DD4F0A2B6D ] BthAvrcpTg      C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
12:38:13.0200 1908  BthAvrcpTg - ok
12:38:13.0200 1908  [ A8B20D852B07AE19A13B5D47EC4E4C3B ] BthEnum        C:\WINDOWS\System32\drivers\BthEnum.sys
12:38:13.0216 1908  BthEnum - ok
12:38:13.0232 1908  [ E695E706C9E11DD5201605F1F6B4505C ] BthHFAud        C:\WINDOWS\system32\DRIVERS\BthHfAud.sys
12:38:13.0232 1908  BthHFAud - ok
12:38:13.0247 1908  [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum      C:\WINDOWS\System32\drivers\bthhfenum.sys
12:38:13.0278 1908  BthHFEnum - ok
12:38:13.0294 1908  [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid        C:\WINDOWS\System32\drivers\BthHFHid.sys
12:38:13.0294 1908  bthhfhid - ok
12:38:13.0310 1908  [ 447A41162B74E345C8E80A681867C653 ] BthHFSrv        C:\WINDOWS\System32\BthHFSrv.dll
12:38:13.0357 1908  BthHFSrv - ok
12:38:13.0357 1908  [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM        C:\WINDOWS\System32\drivers\bthmodem.sys
12:38:13.0404 1908  BTHMODEM - ok
12:38:13.0404 1908  [ 091BB978E9504D0AD14586929431A957 ] BthPan          C:\WINDOWS\system32\DRIVERS\bthpan.sys
12:38:13.0419 1908  BthPan - ok
12:38:13.0435 1908  [ 13795CAA34239D97A7211E7F9D96E012 ] BTHPORT        C:\WINDOWS\System32\Drivers\BTHport.sys
12:38:13.0466 1908  BTHPORT - ok
12:38:13.0482 1908  [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv        C:\WINDOWS\system32\bthserv.dll
12:38:13.0497 1908  bthserv - ok
12:38:13.0497 1908  [ 1F715957F5236D30B6020A19A4271F6A ] BTHUSB          C:\WINDOWS\System32\Drivers\BTHUSB.sys
12:38:13.0513 1908  BTHUSB - ok
12:38:13.0513 1908  [ 183E8A570E03F14C357F0948D2F5E2FE ] btwampfl        C:\WINDOWS\system32\drivers\btwampfl.sys
12:38:13.0529 1908  btwampfl - ok
12:38:13.0544 1908  [ 187686608DF41BE0E436FBF3F88986CC ] btwaudio        C:\WINDOWS\system32\drivers\btwaudio.sys
12:38:13.0544 1908  btwaudio - ok
12:38:13.0560 1908  [ B68927792C57BD730308230BB9A5D070 ] btwavdt        C:\WINDOWS\System32\drivers\btwavdt.sys
12:38:13.0575 1908  btwavdt - ok
12:38:13.0591 1908  [ 848250AC2A5E0378A02708C5FFC148B6 ] btwdins        C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
12:38:13.0622 1908  btwdins - ok
12:38:13.0638 1908  [ C3C8974D99F976C927165363855690CD ] btwl2cap        C:\WINDOWS\system32\DRIVERS\btwl2cap.sys
12:38:13.0638 1908  btwl2cap - ok
12:38:13.0654 1908  [ 7BBD1461FBE22E68668C70891512E9AB ] btwrchid        C:\WINDOWS\System32\drivers\btwrchid.sys
12:38:13.0654 1908  btwrchid - ok
12:38:13.0654 1908  [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs            C:\WINDOWS\system32\DRIVERS\cdfs.sys
12:38:13.0669 1908  cdfs - ok
12:38:13.0685 1908  [ 339BFF85D788268752DA8C9644B188EE ] cdrom          C:\WINDOWS\System32\drivers\cdrom.sys
12:38:13.0700 1908  cdrom - ok
12:38:13.0700 1908  [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc    C:\WINDOWS\System32\certprop.dll
12:38:13.0732 1908  CertPropSvc - ok
12:38:13.0732 1908  [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass        C:\WINDOWS\System32\drivers\circlass.sys
12:38:13.0763 1908  circlass - ok
12:38:13.0779 1908  [ 9BCE872B95A6AA65C5B5A0E60703F1E3 ] ClassicShellService C:\Program Files\Classic Shell\ClassicShellService.exe
12:38:13.0794 1908  ClassicShellService ( UnsignedFile.Multi.Generic ) - warning
12:38:13.0794 1908  ClassicShellService - detected UnsignedFile.Multi.Generic (1)
12:38:13.0794 1908  [ 9905168708DB68849B879B5548F68AB3 ] CLFS            C:\WINDOWS\system32\drivers\CLFS.sys
12:38:13.0825 1908  CLFS - ok
12:38:13.0841 1908  [ 2DC8538A2260647484A6C921CA837313 ] CmBatt          C:\WINDOWS\System32\drivers\CmBatt.sys
12:38:13.0857 1908  CmBatt - ok
12:38:13.0857 1908  [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG            C:\WINDOWS\system32\Drivers\cng.sys
12:38:13.0904 1908  CNG - ok
12:38:13.0919 1908  [ BAC2D188758596568FA72D11C3D50087 ] CnxtHdAudService C:\WINDOWS\system32\drivers\CHDRT64.sys
12:38:13.0967 1908  CnxtHdAudService - ok
12:38:13.0967 1908  [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus    C:\WINDOWS\System32\drivers\CompositeBus.sys
12:38:14.0014 1908  CompositeBus - ok
12:38:14.0014 1908  COMSysApp - ok
12:38:14.0014 1908  [ D9CB0782AF819548072AA45B70F8B22D ] condrv          C:\WINDOWS\system32\drivers\condrv.sys
12:38:14.0030 1908  condrv - ok
12:38:14.0045 1908  [ 815F3180B5117E42E422188E9CCC89C6 ] cphs            C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
12:38:14.0061 1908  cphs - ok
12:38:14.0076 1908  [ AFA426B0E7975CEB21F8B6711EFA8945 ] CryptSvc        C:\WINDOWS\system32\cryptsvc.dll
12:38:14.0092 1908  CryptSvc - ok
12:38:14.0092 1908  [ F2C69C3D98249DE14D4B2832516D4FD5 ] CSC            C:\WINDOWS\system32\drivers\csc.sys
12:38:14.0123 1908  CSC - ok
12:38:14.0139 1908  [ 22CCB6AFF617AAC6121DF6CDA5ABF3F4 ] CscService      C:\WINDOWS\System32\cscsvc.dll
12:38:14.0155 1908  CscService - ok
12:38:14.0170 1908  [ 48AED45DF009081AF3F5144F7D624674 ] CxAudMsg        C:\WINDOWS\system32\CxAudMsg64.exe
12:38:14.0170 1908  CxAudMsg - ok
12:38:14.0186 1908  [ C4D01BD86D6B207275FC143EEA951D75 ] dam            C:\WINDOWS\system32\drivers\dam.sys
12:38:14.0201 1908  dam - ok
12:38:14.0217 1908  [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
12:38:14.0248 1908  DcomLaunch - ok
12:38:14.0248 1908  [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc      C:\WINDOWS\System32\defragsvc.dll
12:38:14.0280 1908  defragsvc - ok
12:38:14.0295 1908  [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
12:38:14.0326 1908  DeviceAssociationService - ok
12:38:14.0326 1908  [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall  C:\WINDOWS\system32\umpnpmgr.dll
12:38:14.0358 1908  DeviceInstall - ok
12:38:14.0358 1908  [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc            C:\WINDOWS\system32\Drivers\dfsc.sys
12:38:14.0373 1908  Dfsc - ok
12:38:14.0373 1908  [ 41AC348DBD378F618CB4FDEE54270692 ] dg_ssudbus      C:\WINDOWS\system32\DRIVERS\ssudbus.sys
12:38:14.0389 1908  dg_ssudbus - ok
12:38:14.0389 1908  [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp            C:\WINDOWS\system32\dhcpcore.dll
12:38:14.0420 1908  Dhcp - ok
12:38:14.0420 1908  [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache        C:\WINDOWS\system32\drivers\discache.sys
12:38:14.0451 1908  discache - ok
12:38:14.0451 1908  [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk            C:\WINDOWS\system32\drivers\disk.sys
12:38:14.0467 1908  disk - ok
12:38:14.0483 1908  [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc          C:\WINDOWS\System32\drivers\dmvsc.sys
12:38:14.0498 1908  dmvsc - ok
12:38:14.0498 1908  [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
12:38:14.0514 1908  Dnscache - ok
12:38:14.0530 1908  [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc        C:\WINDOWS\System32\dot3svc.dll
12:38:14.0545 1908  dot3svc - ok
12:38:14.0561 1908  [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS            C:\WINDOWS\system32\dps.dll
12:38:14.0592 1908  DPS - ok
12:38:14.0608 1908  [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud        C:\WINDOWS\system32\drivers\drmkaud.sys
12:38:14.0608 1908  drmkaud - ok
12:38:14.0623 1908  [ BF48F32EE248C3D371DA5DC93BBEADA7 ] DsmSvc          C:\WINDOWS\System32\DeviceSetupManager.dll
12:38:14.0639 1908  DsmSvc - ok
12:38:14.0670 1908  [ 6D1B8A9A2C0BD4851D8AF1AB43E67AD9 ] DXGKrnl        C:\WINDOWS\System32\drivers\dxgkrnl.sys
12:38:14.0733 1908  DXGKrnl - ok
12:38:14.0733 1908  [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost        C:\WINDOWS\System32\eapsvc.dll
12:38:14.0764 1908  Eaphost - ok
12:38:14.0795 1908  [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv          C:\WINDOWS\system32\drivers\evbda.sys
12:38:14.0920 1908  ebdrv - ok
12:38:14.0936 1908  [ F702AB6181513303AB0FC8D59E52708B ] EFS            C:\WINDOWS\System32\lsass.exe
12:38:14.0951 1908  EFS - ok
12:38:14.0967 1908  [ 4B84E647C934EDFF7F28C4B91A5C0864 ] ehRecvr        C:\WINDOWS\ehome\ehRecvr.exe
12:38:14.0983 1908  ehRecvr - ok
12:38:14.0998 1908  [ 72781EC7A97E44B9651550D7A83D1B96 ] ehSched        C:\WINDOWS\ehome\ehsched.exe
12:38:15.0014 1908  ehSched - ok
12:38:15.0014 1908  [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass    C:\WINDOWS\system32\drivers\EhStorClass.sys
12:38:15.0030 1908  EhStorClass - ok
12:38:15.0045 1908  [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv    C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
12:38:15.0061 1908  EhStorTcgDrv - ok
12:38:15.0061 1908  [ BE2902E13CA69383F449B6BF927844FB ] ElbyCDIO        C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
12:38:15.0076 1908  ElbyCDIO - ok
12:38:15.0076 1908  [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev          C:\WINDOWS\System32\drivers\errdev.sys
12:38:15.0092 1908  ErrDev - ok
12:38:15.0108 1908  [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem    C:\WINDOWS\system32\es.dll
12:38:15.0123 1908  EventSystem - ok
12:38:15.0139 1908  [ 933723A47E9B7B22208F79F0F40A249A ] EvtEng          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
12:38:15.0155 1908  EvtEng - ok
12:38:15.0170 1908  [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat          C:\WINDOWS\system32\drivers\exfat.sys
12:38:15.0201 1908  exfat - ok
12:38:15.0201 1908  [ 60996602A7111FD2D086E803F33E4282 ] fastfat        C:\WINDOWS\system32\drivers\fastfat.sys
12:38:15.0233 1908  fastfat - ok
12:38:15.0233 1908  [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax            C:\WINDOWS\system32\fxssvc.exe
12:38:15.0264 1908  Fax - ok
12:38:15.0264 1908  [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc            C:\WINDOWS\System32\drivers\fdc.sys
12:38:15.0280 1908  fdc - ok
12:38:15.0280 1908  [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost        C:\WINDOWS\system32\fdPHost.dll
12:38:15.0311 1908  fdPHost - ok
12:38:15.0311 1908  [ 872506AAB591E8908DF4461475AF92DF ] FDResPub        C:\WINDOWS\system32\fdrespub.dll
12:38:15.0342 1908  FDResPub - ok
12:38:15.0358 1908  [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc          C:\WINDOWS\system32\fhsvc.dll
12:38:15.0373 1908  fhsvc - ok
12:38:15.0373 1908  [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo        C:\WINDOWS\system32\drivers\fileinfo.sys
12:38:15.0389 1908  FileInfo - ok
12:38:15.0389 1908  [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace      C:\WINDOWS\system32\drivers\filetrace.sys
12:38:15.0420 1908  Filetrace - ok
12:38:15.0436 1908  [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk        C:\WINDOWS\System32\drivers\flpydisk.sys
12:38:15.0451 1908  flpydisk - ok
12:38:15.0451 1908  [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr          C:\WINDOWS\system32\drivers\fltmgr.sys
12:38:15.0483 1908  FltMgr - ok
12:38:15.0498 1908  [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache      C:\WINDOWS\system32\FntCache.dll
12:38:15.0530 1908  FontCache - ok
12:38:15.0545 1908  [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:38:15.0561 1908  FontCache3.0.0.0 - ok
12:38:15.0561 1908  [ 0DFEBEA4BB4444488E0032A48524F56A ] Freemake Improver C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
12:38:15.0561 1908  Freemake Improver ( UnsignedFile.Multi.Generic ) - warning
12:38:15.0561 1908  Freemake Improver - detected UnsignedFile.Multi.Generic (1)
12:38:15.0576 1908  [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends      C:\WINDOWS\system32\drivers\FsDepends.sys
12:38:15.0592 1908  FsDepends - ok
12:38:15.0592 1908  [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
12:38:15.0608 1908  Fs_Rec - ok
12:38:15.0623 1908  [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol          C:\WINDOWS\system32\DRIVERS\fvevol.sys
12:38:15.0655 1908  fvevol - ok
12:38:15.0655 1908  [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM          C:\WINDOWS\System32\drivers\fxppm.sys
12:38:15.0670 1908  FxPPM - ok
12:38:15.0686 1908  [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx        C:\WINDOWS\system32\drivers\gagp30kx.sys
12:38:15.0702 1908  gagp30kx - ok
12:38:15.0702 1908  [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM    C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
12:38:15.0702 1908  GEARAspiWDM - ok
12:38:15.0717 1908  [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter      C:\WINDOWS\System32\drivers\vmgencounter.sys
12:38:15.0733 1908  gencounter - ok
12:38:15.0733 1908  [ CA18ECFCFFDD638ECE80799A9056B238 ] GPIOClx0101    C:\WINDOWS\system32\Drivers\msgpioclx.sys
12:38:15.0748 1908  GPIOClx0101 - ok
12:38:15.0764 1908  [ 5358678C6370F2ADC5291849F6503262 ] gpsvc          C:\WINDOWS\System32\gpsvc.dll
12:38:15.0811 1908  gpsvc - ok
12:38:15.0827 1908  [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:38:15.0827 1908  gupdate - ok
12:38:15.0842 1908  [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:38:15.0842 1908  gupdatem - ok
12:38:15.0858 1908  [ C1B577B2169900F4CF7190C39F085794 ] gusvc          C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
12:38:15.0873 1908  gusvc - ok
12:38:15.0873 1908  [ C2504AA983B5D411F7D31402E8B57725 ] HdAudAddService C:\WINDOWS\system32\drivers\HdAudio.sys
12:38:15.0889 1908  HdAudAddService - ok
12:38:15.0905 1908  [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus        C:\WINDOWS\System32\drivers\HDAudBus.sys
12:38:15.0920 1908  HDAudBus - ok
12:38:15.0936 1908  [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt        C:\WINDOWS\System32\drivers\HidBatt.sys
12:38:15.0936 1908  HidBatt - ok
12:38:15.0952 1908  [ 085F150D002B7F0153D3C06DDF33A143 ] HidBth          C:\WINDOWS\System32\drivers\hidbth.sys
12:38:15.0967 1908  HidBth - ok
12:38:15.0967 1908  [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c          C:\WINDOWS\System32\drivers\hidi2c.sys
12:38:15.0983 1908  hidi2c - ok
12:38:15.0983 1908  [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr          C:\WINDOWS\System32\drivers\hidir.sys
12:38:16.0030 1908  HidIr - ok
12:38:16.0030 1908  [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv        C:\WINDOWS\system32\hidserv.dll
12:38:16.0045 1908  hidserv - ok
12:38:16.0061 1908  [ 9E11EE0F2E117B2D5A835B2B91752827 ] HidUsb          C:\WINDOWS\System32\drivers\hidusb.sys
12:38:16.0077 1908  HidUsb - ok
12:38:16.0077 1908  [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc          C:\WINDOWS\system32\kmsvc.dll
12:38:16.0092 1908  hkmsvc - ok
12:38:16.0108 1908  [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
12:38:16.0123 1908  HomeGroupListener - ok
12:38:16.0139 1908  [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
12:38:16.0155 1908  HomeGroupProvider - ok
12:38:16.0155 1908  [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD          C:\WINDOWS\system32\drivers\HpSAMD.sys
12:38:16.0170 1908  HpSAMD - ok
12:38:16.0186 1908  [ F4A91D985EB9D1D2717D538F3424603C ] HTTP            C:\WINDOWS\system32\drivers\HTTP.sys
12:38:16.0217 1908  HTTP - ok
12:38:16.0217 1908  [ 2A98301068801700906C06649860FE94 ] hwpolicy        C:\WINDOWS\system32\drivers\hwpolicy.sys
12:38:16.0233 1908  hwpolicy - ok
12:38:16.0248 1908  [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd        C:\WINDOWS\System32\drivers\hyperkbd.sys
12:38:16.0264 1908  hyperkbd - ok
12:38:16.0264 1908  [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo      C:\WINDOWS\system32\DRIVERS\HyperVideo.sys
12:38:16.0280 1908  HyperVideo - ok
12:38:16.0280 1908  [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt        C:\WINDOWS\System32\drivers\i8042prt.sys
12:38:16.0295 1908  i8042prt - ok
12:38:16.0311 1908  [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV        C:\WINDOWS\system32\drivers\iaStorV.sys
12:38:16.0358 1908  iaStorV - ok
12:38:16.0358 1908  [ B21087E1A64FD474BF3E1A602A714F1F ] IBMPMDRV        C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
12:38:16.0373 1908  IBMPMDRV - ok
12:38:16.0373 1908  [ A3E4DE0F77031061972485EF9BD8E4D0 ] IBMPMSVC        C:\WINDOWS\system32\ibmpmsvc.exe
12:38:16.0389 1908  IBMPMSVC - ok
12:38:16.0452 1908  [ 348214F96642FD4FEF630DE021BA3540 ] igfx            C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
12:38:16.0545 1908  igfx - ok
12:38:16.0545 1908  [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp          C:\WINDOWS\system32\drivers\iirsp.sys
12:38:16.0561 1908  iirsp - ok
12:38:16.0577 1908  [ 531B5A98145DA689741A0AC18F14EA94 ] IKEEXT          C:\WINDOWS\System32\ikeext.dll
12:38:16.0608 1908  IKEEXT - ok
12:38:16.0623 1908  [ FD2032D2EAE8D7F3381EBA5FA3E7FEEA ] intaud_WaveExtensible C:\WINDOWS\system32\drivers\intelaud.sys
12:38:16.0623 1908  intaud_WaveExtensible - ok
12:38:16.0639 1908  [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide        C:\WINDOWS\system32\drivers\intelide.sys
12:38:16.0655 1908  intelide - ok
12:38:16.0655 1908  [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm        C:\WINDOWS\System32\drivers\intelppm.sys
12:38:16.0670 1908  intelppm - ok
12:38:16.0670 1908  [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
12:38:16.0702 1908  IpFilterDriver - ok
12:38:16.0717 1908  [ C217B8D2E58C57A319B16125C3D4B69C ] iphlpsvc        C:\WINDOWS\System32\iphlpsvc.dll
12:38:16.0733 1908  iphlpsvc - ok
12:38:16.0748 1908  [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV        C:\WINDOWS\System32\drivers\IPMIDrv.sys
12:38:16.0764 1908  IPMIDRV - ok
12:38:16.0764 1908  [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT          C:\WINDOWS\system32\drivers\ipnat.sys
12:38:16.0795 1908  IPNAT - ok
12:38:16.0795 1908  [ 0FF335D687C85097725A53458160E81E ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
12:38:16.0827 1908  iPod Service - ok
12:38:16.0842 1908  [ 02DEF37AB75E0032C50724646F708DE8 ] iPodDrv        C:\WINDOWS\system32\drivers\iPodDrv.sys
12:38:16.0842 1908  iPodDrv - ok
12:38:16.0858 1908  [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM          C:\WINDOWS\system32\drivers\irenum.sys
12:38:16.0873 1908  IRENUM - ok
12:38:16.0873 1908  [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp          C:\WINDOWS\system32\drivers\isapnp.sys
12:38:16.0889 1908  isapnp - ok
12:38:16.0889 1908  [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt        C:\WINDOWS\System32\drivers\msiscsi.sys
12:38:16.0920 1908  iScsiPrt - ok
12:38:16.0920 1908  [ C59B9CE2855E667809F9E63C20FC44A5 ] iwdbus          C:\WINDOWS\System32\drivers\iwdbus.sys
12:38:16.0936 1908  iwdbus - ok
12:38:16.0936 1908  [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass        C:\WINDOWS\System32\drivers\kbdclass.sys
12:38:16.0952 1908  kbdclass - ok
12:38:16.0952 1908  [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid          C:\WINDOWS\System32\drivers\kbdhid.sys
12:38:16.0967 1908  kbdhid - ok
12:38:16.0983 1908  [ FB6C185092E18011EF49989425C2AA87 ] kdnic          C:\WINDOWS\system32\DRIVERS\kdnic.sys
12:38:16.0983 1908  kdnic - ok
12:38:16.0998 1908  [ F702AB6181513303AB0FC8D59E52708B ] KeyIso          C:\WINDOWS\system32\lsass.exe
12:38:17.0014 1908  KeyIso - ok
12:38:17.0014 1908  [ DFA480F6DED551464F3A5B959F437800 ] KSecDD          C:\WINDOWS\system32\Drivers\ksecdd.sys
12:38:17.0030 1908  KSecDD - ok
12:38:17.0045 1908  [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg        C:\WINDOWS\system32\Drivers\ksecpkg.sys
12:38:17.0061 1908  KSecPkg - ok
12:38:17.0061 1908  [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk        C:\WINDOWS\system32\drivers\ksthunk.sys
12:38:17.0077 1908  ksthunk - ok
12:38:17.0092 1908  [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm          C:\WINDOWS\system32\msdtckrm.dll
12:38:17.0108 1908  KtmRm - ok
12:38:17.0123 1908  [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer    C:\WINDOWS\system32\srvsvc.dll
12:38:17.0139 1908  LanmanServer - ok
12:38:17.0155 1908  [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
12:38:17.0170 1908  LanmanWorkstation - ok
12:38:17.0186 1908  [ 7CFE36AF06E9C0984021796EDC8AC207 ] LENOVO.MICMUTE  C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
12:38:17.0186 1908  LENOVO.MICMUTE - ok
12:38:17.0202 1908  [ CEEFD29FC551F289810B0B9381B321DC ] lltdio          C:\WINDOWS\system32\DRIVERS\lltdio.sys
12:38:17.0217 1908  lltdio - ok
12:38:17.0233 1908  [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc        C:\WINDOWS\System32\lltdsvc.dll
12:38:17.0248 1908  lltdsvc - ok
12:38:17.0264 1908  [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts        C:\WINDOWS\System32\lmhsvc.dll
12:38:17.0280 1908  lmhosts - ok
12:38:17.0280 1908  [ F28E88AFA2EE1E5A7E4FCAB4D1578C36 ] LMS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
12:38:17.0295 1908  LMS - ok
12:38:17.0311 1908  [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS        C:\WINDOWS\system32\drivers\lsi_sas.sys
12:38:17.0327 1908  LSI_SAS - ok
12:38:17.0327 1908  [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2        C:\WINDOWS\system32\drivers\lsi_sas2.sys
12:38:17.0342 1908  LSI_SAS2 - ok
12:38:17.0358 1908  [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI        C:\WINDOWS\system32\drivers\lsi_scsi.sys
12:38:17.0373 1908  LSI_SCSI - ok
12:38:17.0373 1908  [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS        C:\WINDOWS\system32\drivers\lsi_sss.sys
12:38:17.0389 1908  LSI_SSS - ok
12:38:17.0405 1908  [ A57BA284F5996FFD32DCDBC41A4657DB ] LSM            C:\WINDOWS\System32\lsm.dll
12:38:17.0452 1908  LSM - ok
12:38:17.0452 1908  [ 2BDC5D711FA61307CE6190D47C956368 ] luafv          C:\WINDOWS\system32\drivers\luafv.sys
12:38:17.0483 1908  luafv - ok
12:38:17.0483 1908  [ 4448CCEA974F0B15A00EA33FCEDFC062 ] Mcx2Svc        C:\WINDOWS\system32\Mcx2Svc.dll
12:38:17.0498 1908  Mcx2Svc - ok
12:38:17.0514 1908  [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas        C:\WINDOWS\system32\drivers\megasas.sys
12:38:17.0530 1908  megasas - ok
12:38:17.0530 1908  [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR          C:\WINDOWS\system32\drivers\MegaSR.sys
12:38:17.0561 1908  MegaSR - ok
12:38:17.0561 1908  [ 86614752D2FAE34CCD9E7B2AABA5FBEC ] MEIx64          C:\WINDOWS\System32\drivers\HECIx64.sys
12:38:17.0577 1908  MEIx64 - ok
12:38:17.0577 1908  [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS          C:\WINDOWS\system32\mmcss.dll
12:38:17.0592 1908  MMCSS - ok
12:38:17.0592 1908  [ 780098AD5DA8A4822E2563984C85EF7B ] Modem          C:\WINDOWS\system32\drivers\modem.sys
12:38:17.0623 1908  Modem - ok
12:38:17.0623 1908  [ EA8EAD3F5B762F889CC7F3966625B48B ] monitor        C:\WINDOWS\System32\drivers\monitor.sys
12:38:17.0639 1908  monitor - ok
12:38:17.0639 1908  [ 618446B98C79776654340CE27C73485E ] mouclass        C:\WINDOWS\System32\drivers\mouclass.sys
12:38:17.0655 1908  mouclass - ok
12:38:17.0670 1908  [ C0ADEBED913295803B579ED288936CBB ] mouhid          C:\WINDOWS\System32\drivers\mouhid.sys
12:38:17.0670 1908  mouhid - ok
12:38:17.0686 1908  [ 89D263DBF08119CE16273991C120D6DD ] mountmgr        C:\WINDOWS\system32\drivers\mountmgr.sys
12:38:17.0702 1908  mountmgr - ok
12:38:17.0702 1908  [ 825BF0E46B4470A463AEB641480C5FCA ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
12:38:17.0717 1908  MozillaMaintenance - ok
12:38:17.0717 1908  [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv          C:\WINDOWS\system32\drivers\mpsdrv.sys
12:38:17.0733 1908  mpsdrv - ok
12:38:17.0748 1908  [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc          C:\WINDOWS\system32\mpssvc.dll
12:38:17.0780 1908  MpsSvc - ok
12:38:17.0795 1908  [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV          C:\WINDOWS\system32\drivers\mrxdav.sys
12:38:17.0811 1908  MRxDAV - ok
12:38:17.0827 1908  [ 93179D48066918323628CB016D8C94DC ] mrxsmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
12:38:17.0842 1908  mrxsmb - ok
12:38:17.0842 1908  [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10        C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
12:38:17.0873 1908  mrxsmb10 - ok
12:38:17.0873 1908  [ 5C7DD2E5759FFCCD2C7341C1B90F2B26 ] mrxsmb20        C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
12:38:17.0889 1908  mrxsmb20 - ok
12:38:17.0905 1908  [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge        C:\WINDOWS\system32\DRIVERS\bridge.sys
12:38:17.0920 1908  MsBridge - ok
12:38:17.0920 1908  [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC          C:\WINDOWS\System32\msdtc.exe
12:38:17.0952 1908  MSDTC - ok
12:38:17.0952 1908  [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
12:38:17.0967 1908  Msfs - ok
12:38:17.0983 1908  [ C32A7A39B960A42BA9D4FBE47213CA03 ] msgpiowin32    C:\WINDOWS\System32\drivers\msgpiowin32.sys
12:38:17.0998 1908  msgpiowin32 - ok
12:38:17.0998 1908  [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf      C:\WINDOWS\System32\drivers\mshidkmdf.sys
12:38:18.0014 1908  mshidkmdf - ok
12:38:18.0014 1908  [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf      C:\WINDOWS\System32\drivers\mshidumdf.sys
12:38:18.0030 1908  mshidumdf - ok
12:38:18.0030 1908  [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv        C:\WINDOWS\system32\drivers\msisadrv.sys
12:38:18.0045 1908  msisadrv - ok
12:38:18.0061 1908  [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI        C:\WINDOWS\system32\iscsiexe.dll
12:38:18.0077 1908  MSiSCSI - ok
12:38:18.0077 1908  msiserver - ok
12:38:18.0077 1908  [ 509809566E49F4411055864EA8D437CD ] MSKSSRV        C:\WINDOWS\system32\drivers\MSKSSRV.sys
12:38:18.0092 1908  MSKSSRV - ok
12:38:18.0108 1908  [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp          C:\WINDOWS\system32\DRIVERS\mslldp.sys
12:38:18.0124 1908  MsLldp - ok
12:38:18.0124 1908  [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK        C:\WINDOWS\system32\drivers\MSPCLOCK.sys
12:38:18.0139 1908  MSPCLOCK - ok
12:38:18.0139 1908  [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM          C:\WINDOWS\system32\drivers\MSPQM.sys
12:38:18.0155 1908  MSPQM - ok
12:38:18.0170 1908  [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC          C:\WINDOWS\system32\drivers\MsRPC.sys
12:38:18.0186 1908  MsRPC - ok
12:38:18.0202 1908  [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios        C:\WINDOWS\System32\drivers\mssmbios.sys
12:38:18.0217 1908  mssmbios - ok
12:38:18.0217 1908  [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE          C:\WINDOWS\system32\drivers\MSTEE.sys
12:38:18.0233 1908  MSTEE - ok
12:38:18.0233 1908  [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig        C:\WINDOWS\System32\drivers\MTConfig.sys
12:38:18.0249 1908  MTConfig - ok
12:38:18.0249 1908  [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup            C:\WINDOWS\system32\Drivers\mup.sys
12:38:18.0264 1908  Mup - ok
12:38:18.0280 1908  [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis          C:\WINDOWS\system32\drivers\mvumis.sys
12:38:18.0295 1908  mvumis - ok
12:38:18.0295 1908  [ D8C1FE237762249C879760E7F3ABFC1F ] MyWiFiDHCPDNS  C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
12:38:18.0311 1908  MyWiFiDHCPDNS - ok
12:38:18.0327 1908  [ 4B18840511D720BA118D3017E8165875 ] napagent        C:\WINDOWS\system32\qagentRT.dll
12:38:18.0358 1908  napagent - ok
12:38:18.0358 1908  [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP    C:\WINDOWS\system32\DRIVERS\nwifi.sys
12:38:18.0389 1908  NativeWifiP - ok
12:38:18.0389 1908  [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc          C:\WINDOWS\System32\ncasvc.dll
12:38:18.0405 1908  NcaSvc - ok
12:38:18.0420 1908  [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup    C:\WINDOWS\System32\NcdAutoSetup.dll
12:38:18.0436 1908  NcdAutoSetup - ok
12:38:18.0452 1908  [ 03CFE4108D1DE16D6C59455B5C73319C ] NDIS            C:\WINDOWS\system32\drivers\ndis.sys
12:38:18.0499 1908  NDIS - ok
12:38:18.0499 1908  [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap        C:\WINDOWS\system32\DRIVERS\ndiscap.sys
12:38:18.0514 1908  NdisCap - ok
12:38:18.0530 1908  [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform  C:\WINDOWS\system32\DRIVERS\NdisImPlatform.sys
12:38:18.0545 1908  NdisImPlatform - ok
12:38:18.0545 1908  [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
12:38:18.0561 1908  NdisTapi - ok
12:38:18.0561 1908  [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio        C:\WINDOWS\system32\DRIVERS\ndisuio.sys
12:38:18.0577 1908  Ndisuio - ok
12:38:18.0592 1908  [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan        C:\WINDOWS\system32\DRIVERS\ndiswan.sys
12:38:18.0608 1908  NdisWan - ok
12:38:18.0624 1908  [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY  C:\WINDOWS\system32\DRIVERS\ndiswan.sys
12:38:18.0639 1908  NDISWANLEGACY - ok
12:38:18.0639 1908  [ 3730942D7DB2F8BB5F84542B7FF6F650 ] NDProxy        C:\WINDOWS\system32\drivers\NDProxy.sys
12:38:18.0655 1908  NDProxy - ok
12:38:18.0670 1908  [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu            C:\WINDOWS\system32\drivers\Ndu.sys
12:38:18.0686 1908  Ndu - ok
12:38:18.0686 1908  [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS        C:\WINDOWS\system32\DRIVERS\netbios.sys
12:38:18.0702 1908  NetBIOS - ok
12:38:18.0717 1908  [ 7CEC25C682D319D484630B3952C31A11 ] NetBT          C:\WINDOWS\system32\DRIVERS\netbt.sys
12:38:18.0733 1908  NetBT - ok
12:38:18.0733 1908  [ F702AB6181513303AB0FC8D59E52708B ] Netlogon        C:\WINDOWS\system32\lsass.exe
12:38:18.0749 1908  Netlogon - ok
12:38:18.0764 1908  [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman          C:\WINDOWS\System32\netman.dll
12:38:18.0795 1908  Netman - ok
12:38:18.0795 1908  [ 5FF52E13C72838D87DAF228EC9E92C89 ] netprofm        C:\WINDOWS\System32\netprofmsvc.dll
12:38:18.0827 1908  netprofm - ok
12:38:18.0827 1908  [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:38:18.0842 1908  NetTcpPortSharing - ok
12:38:18.0952 1908  [ 57B9C04D673F236D41FAB03842C8640B ] NETwNs64        C:\WINDOWS\system32\DRIVERS\NETwNs64.sys
12:38:19.0108 1908  NETwNs64 - ok
12:38:19.0124 1908  [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960        C:\WINDOWS\system32\drivers\nfrd960.sys
12:38:19.0139 1908  nfrd960 - ok
12:38:19.0139 1908  [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc          C:\WINDOWS\System32\nlasvc.dll
12:38:19.0170 1908  NlaSvc - ok
12:38:19.0170 1908  [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
12:38:19.0186 1908  Npfs - ok
12:38:19.0186 1908  [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig      C:\WINDOWS\System32\drivers\npsvctrig.sys
12:38:19.0217 1908  npsvctrig - ok
12:38:19.0217 1908  [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi            C:\WINDOWS\system32\nsisvc.dll
12:38:19.0233 1908  nsi - ok
12:38:19.0249 1908  [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy        C:\WINDOWS\system32\drivers\nsiproxy.sys
12:38:19.0264 1908  nsiproxy - ok
12:38:19.0295 1908  [ 76929F4A69E425911A63B407E26C2589 ] Ntfs            C:\WINDOWS\system32\drivers\Ntfs.sys
12:38:19.0374 1908  Ntfs - ok
12:38:19.0374 1908  [ 4163ADE07DB51843AE31F65B94F5398D ] Null            C:\WINDOWS\system32\drivers\Null.sys
12:38:19.0389 1908  Null - ok
12:38:19.0405 1908  [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid          C:\WINDOWS\system32\drivers\nvraid.sys
12:38:19.0420 1908  nvraid - ok
12:38:19.0420 1908  [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor          C:\WINDOWS\system32\drivers\nvstor.sys
12:38:19.0452 1908  nvstor - ok
12:38:19.0452 1908  [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp          C:\WINDOWS\system32\drivers\nv_agp.sys
12:38:19.0467 1908  nv_agp - ok
12:38:19.0467 1908  [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:38:19.0483 1908  ose - ok
12:38:19.0499 1908  [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc        C:\WINDOWS\system32\pnrpsvc.dll
12:38:19.0514 1908  p2pimsvc - ok
12:38:19.0530 1908  [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc          C:\WINDOWS\system32\p2psvc.dll
12:38:19.0545 1908  p2psvc - ok
12:38:19.0561 1908  [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport        C:\WINDOWS\System32\drivers\parport.sys
12:38:19.0577 1908  Parport - ok
12:38:19.0577 1908  [ D6ACCF9F2EEEEA711C14EFD976E573F3 ] partmgr        C:\WINDOWS\system32\drivers\partmgr.sys
12:38:19.0592 1908  partmgr - ok
12:38:19.0608 1908  [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc          C:\WINDOWS\System32\pcasvc.dll
12:38:19.0624 1908  PcaSvc - ok
12:38:19.0624 1908  [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci            C:\WINDOWS\system32\drivers\pci.sys
12:38:19.0655 1908  pci - ok
12:38:19.0655 1908  [ F9908D274D458220F91E89B54D78D837 ] pciide          C:\WINDOWS\system32\drivers\pciide.sys
12:38:19.0670 1908  pciide - ok
12:38:19.0670 1908  [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia          C:\WINDOWS\system32\drivers\pcmcia.sys
12:38:19.0702 1908  pcmcia - ok
12:38:19.0702 1908  [ CEBBAD5391C2644560C55628A40BFD27 ] pcw            C:\WINDOWS\system32\drivers\pcw.sys
12:38:19.0717 1908  pcw - ok
12:38:19.0717 1908  [ 0698DEDEAD6A00AD0D468C687D830FBF ] pdc            C:\WINDOWS\system32\drivers\pdc.sys
12:38:19.0733 1908  pdc - ok
12:38:19.0749 1908  [ 61FE70659CD43E07F94DA4DC31DEC493 ] PEAUTH          C:\WINDOWS\system32\drivers\peauth.sys
12:38:19.0780 1908  PEAUTH - ok
12:38:19.0811 1908  [ DF0D9BDCB600913F40FF125BF8CE1979 ] PeerDistSvc    C:\WINDOWS\system32\peerdistsvc.dll
12:38:19.0874 1908  PeerDistSvc - ok
12:38:19.0889 1908  [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost        C:\WINDOWS\SysWow64\perfhost.exe
12:38:19.0905 1908  PerfHost - ok
12:38:19.0936 1908  [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla            C:\WINDOWS\system32\pla.dll
12:38:19.0983 1908  pla - ok
12:38:19.0999 1908  [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay        C:\WINDOWS\system32\umpnpmgr.dll
12:38:20.0014 1908  PlugPlay - ok
12:38:20.0014 1908  [ A010F13D27C1033A8BE09D5FA9BF348B ] pneteth        C:\WINDOWS\system32\DRIVERS\pneteth.sys
12:38:20.0030 1908  pneteth - ok
12:38:20.0030 1908  [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg    C:\WINDOWS\system32\pnrpauto.dll
12:38:20.0045 1908  PNRPAutoReg - ok
12:38:20.0061 1908  [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc        C:\WINDOWS\system32\pnrpsvc.dll
12:38:20.0077 1908  PNRPsvc - ok
12:38:20.0092 1908  [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent    C:\WINDOWS\System32\ipsecsvc.dll
12:38:20.0124 1908  PolicyAgent - ok
12:38:20.0124 1908  [ F1E067F56373F11EA4B785CAE823740A ] Power          C:\WINDOWS\system32\umpo.dll
12:38:20.0139 1908  Power - ok
12:38:20.0155 1908  [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport    C:\WINDOWS\system32\DRIVERS\raspptp.sys
12:38:20.0170 1908  PptpMiniport - ok
12:38:20.0202 1908  [ C2D3B3D0060619D5E03E696BD56FF59F ] PrintNotify    C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
12:38:20.0264 1908  PrintNotify - ok
12:38:20.0264 1908  [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor      C:\WINDOWS\System32\drivers\processr.sys
12:38:20.0280 1908  Processor - ok
12:38:20.0295 1908  [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc        C:\WINDOWS\system32\profsvc.dll
12:38:20.0311 1908  ProfSvc - ok
12:38:20.0311 1908  [ EB8034147D4820CD31BFCB11A2A652DF ] Psched          C:\WINDOWS\system32\DRIVERS\pacer.sys
12:38:20.0342 1908  Psched - ok
12:38:20.0342 1908  [ FB46E9A827A8799EBD7BFA9128C91F37 ] PSI            C:\WINDOWS\system32\DRIVERS\psi_mf.sys
12:38:20.0342 1908  PSI - ok
12:38:20.0358 1908  [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE          C:\WINDOWS\system32\qwave.dll
12:38:20.0374 1908  QWAVE - ok
12:38:20.0389 1908  [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv        C:\WINDOWS\system32\drivers\qwavedrv.sys
12:38:20.0405 1908  QWAVEdrv - ok
12:38:20.0405 1908  [ 873C60F8178100557740A832FCE10B5F ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
12:38:20.0421 1908  RasAcd - ok
12:38:20.0436 1908  [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn    C:\WINDOWS\system32\DRIVERS\AgileVpn.sys
12:38:20.0467 1908  RasAgileVpn - ok
12:38:20.0467 1908  [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto        C:\WINDOWS\System32\rasauto.dll
12:38:20.0483 1908  RasAuto - ok
12:38:20.0499 1908  [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp        C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
12:38:20.0514 1908  Rasl2tp - ok
12:38:20.0530 1908  [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan          C:\WINDOWS\System32\rasmans.dll
12:38:20.0561 1908  RasMan - ok
12:38:20.0561 1908  [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
12:38:20.0577 1908  RasPppoe - ok
12:38:20.0592 1908  [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp        C:\WINDOWS\system32\DRIVERS\rassstp.sys
12:38:20.0608 1908  RasSstp - ok
12:38:20.0624 1908  [ B72C33DBD5326B3864CF2091AF8B906B ] rdbss          C:\WINDOWS\system32\DRIVERS\rdbss.sys
12:38:20.0639 1908  rdbss - ok
12:38:20.0655 1908  [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus          C:\WINDOWS\System32\drivers\rdpbus.sys
12:38:20.0655 1908  rdpbus - ok
12:38:20.0671 1908  [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR          C:\WINDOWS\system32\drivers\rdpdr.sys
12:38:20.0686 1908  RDPDR - ok
12:38:20.0702 1908  [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
12:38:20.0717 1908  RdpVideoMiniport - ok
12:38:20.0717 1908  [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD          C:\WINDOWS\system32\drivers\RDPWD.sys
12:38:20.0733 1908  RDPWD - ok
12:38:20.0749 1908  [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost        C:\WINDOWS\system32\drivers\rdyboost.sys
12:38:20.0764 1908  rdyboost - ok
12:38:20.0764 1908  [ 695C4AC7D0B5002040C7540364C43940 ] RegSrvc        C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
12:38:20.0780 1908  RegSrvc - ok
12:38:20.0796 1908  [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
12:38:20.0811 1908  RemoteAccess - ok
12:38:20.0811 1908  [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry  C:\WINDOWS\system32\regsvc.dll
12:38:20.0858 1908  RemoteRegistry - ok
12:38:20.0858 1908  [ CCBFCABDFE2BC22F0645CEAADDB36004 ] RFCOMM          C:\WINDOWS\System32\drivers\rfcomm.sys
12:38:20.0874 1908  RFCOMM - ok
12:38:20.0874 1908  [ 6DA53881D918900F85C3D22331EB0CFD ] risdxc          C:\WINDOWS\System32\drivers\risdxc64.sys
12:38:20.0889 1908  risdxc - ok
12:38:20.0905 1908  [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper    C:\WINDOWS\System32\RpcEpMap.dll
12:38:20.0921 1908  RpcEptMapper - ok
12:38:20.0921 1908  [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator      C:\WINDOWS\system32\locator.exe
12:38:20.0936 1908  RpcLocator - ok
12:38:20.0952 1908  [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs          C:\WINDOWS\system32\rpcss.dll
12:38:20.0983 1908  RpcSs - ok
12:38:20.0999 1908  [ E04E770DD198B9399640717145E79EBF ] rspndr          C:\WINDOWS\system32\DRIVERS\rspndr.sys
12:38:21.0014 1908  rspndr - ok
12:38:21.0030 1908  [ 15923AA360F7675D3D43C9669316A0BA ] RTL8168        C:\WINDOWS\system32\DRIVERS\Rt630x64.sys
12:38:21.0046 1908  RTL8168 - ok
12:38:21.0046 1908  [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap          C:\WINDOWS\System32\drivers\vms3cap.sys
12:38:21.0061 1908  s3cap - ok
12:38:21.0077 1908  [ F702AB6181513303AB0FC8D59E52708B ] SamSs          C:\WINDOWS\system32\lsass.exe
12:38:21.0092 1908  SamSs - ok
12:38:21.0092 1908  SAService - ok
12:38:21.0092 1908  [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port        C:\WINDOWS\system32\drivers\sbp2port.sys
12:38:21.0124 1908  sbp2port - ok
12:38:21.0124 1908  [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr        C:\WINDOWS\System32\SCardSvr.dll
12:38:21.0155 1908  SCardSvr - ok
12:38:21.0155 1908  [ 5D7733A12756B267FCA021672B26BC9E ] scfilter        C:\WINDOWS\system32\DRIVERS\scfilter.sys
12:38:21.0171 1908  scfilter - ok
12:38:21.0202 1908  [ ED40ED9A65F3E79A8C43DD50C5FDADBF ] Schedule        C:\WINDOWS\system32\schedsvc.dll
12:38:21.0233 1908  Schedule - ok
12:38:21.0233 1908  [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc    C:\WINDOWS\System32\certprop.dll
12:38:21.0264 1908  SCPolicySvc - ok
12:38:21.0264 1908  [ 047315E75392CEA447ACC86257824C16 ] sdbus          C:\WINDOWS\System32\drivers\sdbus.sys
12:38:21.0296 1908  sdbus - ok
12:38:21.0296 1908  [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC          C:\WINDOWS\System32\SDRSVC.dll
12:38:21.0311 1908  SDRSVC - ok
12:38:21.0327 1908  [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor          C:\WINDOWS\System32\drivers\sdstor.sys
12:38:21.0342 1908  sdstor - ok
12:38:21.0342 1908  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\WINDOWS\system32\drivers\secdrv.sys
12:38:21.0358 1908  secdrv - ok
12:38:21.0358 1908  [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon        C:\WINDOWS\system32\seclogon.dll
12:38:21.0389 1908  seclogon - ok
12:38:21.0405 1908  [ 306F9390976E41063D21AB9AB6D48122 ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe
12:38:21.0436 1908  Secunia PSI Agent - ok
12:38:21.0452 1908  [ 29C852880E9634F8C6BD77A4E68B5B34 ] Secunia Update Agent C:\Program Files (x86)\Secunia\PSI\sua.exe
12:38:21.0483 1908  Secunia Update Agent - ok
12:38:21.0483 1908  [ 9C51620998F0763039DFA6BF68E475ED ] SENS            C:\WINDOWS\System32\sens.dll
12:38:21.0514 1908  SENS - ok
12:38:21.0514 1908  [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc        C:\WINDOWS\system32\sensrsvc.dll
12:38:21.0530 1908  SensrSvc - ok
12:38:21.0546 1908  [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx          C:\WINDOWS\system32\drivers\SerCx.sys
12:38:21.0561 1908  SerCx - ok
12:38:21.0561 1908  [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum        C:\WINDOWS\System32\drivers\serenum.sys
12:38:21.0577 1908  Serenum - ok
12:38:21.0577 1908  [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial          C:\WINDOWS\System32\drivers\serial.sys
12:38:21.0592 1908  Serial - ok
12:38:21.0608 1908  [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse        C:\WINDOWS\System32\drivers\sermouse.sys
12:38:21.0624 1908  sermouse - ok
12:38:21.0639 1908  [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv      C:\WINDOWS\system32\sessenv.dll
12:38:21.0655 1908  SessionEnv - ok
12:38:21.0655 1908  [ 7EE65419B29302C795714FF8073969A1 ] sfloppy        C:\WINDOWS\System32\drivers\sfloppy.sys
12:38:21.0671 1908  sfloppy - ok
12:38:21.0686 1908  [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
12:38:21.0717 1908  SharedAccess - ok
12:38:21.0733 1908  [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
12:38:21.0764 1908  ShellHWDetection - ok
12:38:21.0780 1908  [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2        C:\WINDOWS\system32\drivers\SiSRaid2.sys
12:38:21.0780 1908  SiSRaid2 - ok
12:38:21.0796 1908  [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4        C:\WINDOWS\system32\drivers\sisraid4.sys
12:38:21.0811 1908  SiSRaid4 - ok
12:38:21.0811 1908  [ E11C9E13E92DA6747363924CFFCBD7EF ] SmbDrvI        C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
12:38:21.0827 1908  SmbDrvI - ok
12:38:21.0827 1908  [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP        C:\WINDOWS\System32\snmptrap.exe
12:38:21.0858 1908  SNMPTRAP - ok
12:38:21.0858 1908  [ 872E937681910E2456A054331C7D5A18 ] spaceport      C:\WINDOWS\system32\drivers\spaceport.sys
12:38:21.0889 1908  spaceport - ok
12:38:21.0889 1908  [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx          C:\WINDOWS\system32\drivers\SpbCx.sys
12:38:21.0905 1908  SpbCx - ok
12:38:21.0921 1908  [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler        C:\WINDOWS\System32\spoolsv.exe
12:38:21.0952 1908  Spooler - ok
12:38:22.0017 1908  [ EC84D961501054F87A6878EC5D53388F ] sppsvc          C:\WINDOWS\system32\sppsvc.exe
12:38:22.0111 1908  sppsvc - ok
12:38:22.0111 1908  [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv            C:\WINDOWS\system32\DRIVERS\srv.sys
12:38:22.0142 1908  srv - ok
12:38:22.0158 1908  [ 56218A571ECF8D55E0CDFF8DF2546CF1 ] srv2            C:\WINDOWS\system32\DRIVERS\srv2.sys
12:38:22.0174 1908  srv2 - ok
12:38:22.0189 1908  [ 14FC338B80CFF7E04215133B568D15C4 ] srvnet          C:\WINDOWS\system32\DRIVERS\srvnet.sys
12:38:22.0205 1908  srvnet - ok
12:38:22.0205 1908  [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV        C:\WINDOWS\System32\ssdpsrv.dll
12:38:22.0236 1908  SSDPSRV - ok
12:38:22.0236 1908  [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc        C:\WINDOWS\system32\sstpsvc.dll
12:38:22.0267 1908  SstpSvc - ok
12:38:22.0267 1908  [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor        C:\WINDOWS\system32\drivers\stexstor.sys
12:38:22.0283 1908  stexstor - ok
12:38:22.0299 1908  [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc          C:\WINDOWS\System32\wiaservc.dll
12:38:22.0314 1908  stisvc - ok
12:38:22.0330 1908  [ B240874B2CA0CD02E8CD11E140B14C57 ] storahci        C:\WINDOWS\system32\drivers\storahci.sys
12:38:22.0345 1908  storahci - ok
12:38:22.0345 1908  [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt        C:\WINDOWS\system32\DRIVERS\vmstorfl.sys
12:38:22.0361 1908  storflt - ok
12:38:22.0361 1908  [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc        C:\WINDOWS\system32\storsvc.dll
12:38:22.0377 1908  StorSvc - ok
12:38:22.0377 1908  [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc        C:\WINDOWS\system32\drivers\storvsc.sys
12:38:22.0392 1908  storvsc - ok
12:38:22.0408 1908  [ 1A36AC469140F87CDE62D7F8524E270C ] storvsp        C:\WINDOWS\System32\drivers\storvsp.sys
12:38:22.0424 1908  storvsp - ok
12:38:22.0424 1908  [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc          C:\WINDOWS\system32\svsvc.dll
12:38:22.0455 1908  svsvc - ok
12:38:22.0455 1908  [ EEBBD6E7D1E31F18B1BA5707FD7A04D6 ] SWDUMon        C:\WINDOWS\system32\DRIVERS\SWDUMon.sys
12:38:22.0470 1908  SWDUMon - ok
12:38:22.0470 1908  [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum          C:\WINDOWS\System32\drivers\swenum.sys
12:38:22.0486 1908  swenum - ok
12:38:22.0502 1908  [ 502F9488540051F3E6C39889ECFA76BB ] swprv          C:\WINDOWS\System32\swprv.dll
12:38:22.0533 1908  swprv - ok
12:38:22.0549 1908  [ AEAE48AF681BAF5904608FF5D84E3C9C ] SynTP          C:\WINDOWS\system32\DRIVERS\SynTP.sys
12:38:22.0564 1908  SynTP - ok
12:38:22.0580 1908  [ DC21E1F06343773D7E24362DCEF7944B ] SysMain        C:\WINDOWS\system32\sysmain.dll
12:38:22.0627 1908  SysMain - ok
12:38:22.0627 1908  [ 6FB88606C4A71E1BFAF97D63A676C673 ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
12:38:22.0642 1908  SystemEventsBroker - ok
12:38:22.0658 1908  [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
12:38:22.0674 1908  TabletInputService - ok
12:38:22.0674 1908  [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv        C:\WINDOWS\System32\tapisrv.dll
12:38:22.0705 1908  TapiSrv - ok
12:38:22.0736 1908  [ D750CE2A52F1B95E654CF2904C88EF1F ] Tcpip          C:\WINDOWS\system32\drivers\tcpip.sys
12:38:22.0830 1908  Tcpip - ok
12:38:22.0861 1908  [ D750CE2A52F1B95E654CF2904C88EF1F ] TCPIP6          C:\WINDOWS\system32\DRIVERS\tcpip.sys
12:38:22.0955 1908  TCPIP6 - ok
12:38:22.0955 1908  [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg        C:\WINDOWS\system32\drivers\tcpipreg.sys
12:38:22.0971 1908  tcpipreg - ok
12:38:22.0986 1908  [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx            C:\WINDOWS\system32\DRIVERS\tdx.sys
12:38:23.0002 1908  tdx - ok
12:38:23.0064 1908  [ 879F46329B7DC4D109345AA96F1AB47F ] TeamViewer8    C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
12:38:23.0158 1908  TeamViewer8 - ok
12:38:23.0174 1908  [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt        C:\WINDOWS\System32\drivers\terminpt.sys
12:38:23.0189 1908  terminpt - ok
12:38:23.0205 1908  [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService    C:\WINDOWS\System32\termsrv.dll
12:38:23.0221 1908  TermService - ok
12:38:23.0236 1908  [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes          C:\WINDOWS\system32\themeservice.dll
12:38:23.0267 1908  Themes - ok
12:38:23.0267 1908  [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER    C:\WINDOWS\system32\mmcss.dll
12:38:23.0283 1908  THREADORDER - ok
12:38:23.0283 1908  [ 4515B9E4140F04FB3907692DF89FCA87 ] TimeBroker      C:\WINDOWS\System32\TimeBrokerServer.dll
12:38:23.0314 1908  TimeBroker - ok
12:38:23.0330 1908  [ 373B3EABBE1B07E3CDE98E1452B6D131 ] TPHKLOAD        C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
12:38:23.0330 1908  TPHKLOAD - ok
12:38:23.0346 1908  [ 6F0BFF80EE2A5BC841286A51F893CBAD ] TPM            C:\WINDOWS\system32\drivers\tpm.sys
12:38:23.0361 1908  TPM - ok
12:38:23.0361 1908  [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks          C:\WINDOWS\System32\trkwks.dll
12:38:23.0377 1908  TrkWks - ok
12:38:23.0392 1908  [ 370A6907DDF79532A39319492B1FA38A ] truecrypt      C:\WINDOWS\system32\drivers\truecrypt.sys
12:38:23.0408 1908  truecrypt - ok
12:38:23.0408 1908  [ 8ABBB5CE0C62E0A6D28F32F44B7F865C ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
12:38:23.0424 1908  TrustedInstaller - ok
12:38:23.0439 1908  [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt        C:\WINDOWS\system32\drivers\tsusbflt.sys
12:38:23.0455 1908  TsUsbFlt - ok
12:38:23.0455 1908  [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD        C:\WINDOWS\System32\drivers\TsUsbGD.sys
12:38:23.0471 1908  TsUsbGD - ok
12:38:23.0471 1908  [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel          C:\WINDOWS\system32\DRIVERS\tunnel.sys
12:38:23.0502 1908  tunnel - ok
12:38:23.0502 1908  [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35          C:\WINDOWS\system32\drivers\uagp35.sys
12:38:23.0517 1908  uagp35 - ok
12:38:23.0517 1908  [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor        C:\WINDOWS\System32\drivers\uaspstor.sys
12:38:23.0533 1908  UASPStor - ok
12:38:23.0549 1908  [ 1ED222DFE6C13DA50FE081ABF90CAFE1 ] UCX01000        C:\WINDOWS\System32\drivers\ucx01000.sys
12:38:23.0564 1908  UCX01000 - ok
12:38:23.0580 1908  [ DC5A461591C71AF7F19DC048A81E3F88 ] udfs            C:\WINDOWS\system32\DRIVERS\udfs.sys
12:38:23.0611 1908  udfs - ok
12:38:23.0627 1908  [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect      C:\WINDOWS\system32\UI0Detect.exe
12:38:23.0642 1908  UI0Detect - ok
12:38:23.0658 1908  [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx        C:\WINDOWS\system32\drivers\uliagpkx.sys
12:38:23.0674 1908  uliagpkx - ok
12:38:23.0674 1908  [ 02CEB3FE6152668A7BA420B93B664860 ] umbus          C:\WINDOWS\System32\drivers\umbus.sys
12:38:23.0689 1908  umbus - ok
12:38:23.0689 1908  [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass          C:\WINDOWS\System32\drivers\umpass.sys
12:38:23.0705 1908  UmPass - ok
12:38:23.0705 1908  [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService    C:\WINDOWS\System32\umrdp.dll
12:38:23.0736 1908  UmRdpService - ok
12:38:23.0767 1908  [ 201840BC53DAB0E5780E643221013902 ] UNS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
12:38:23.0830 1908  UNS - ok
12:38:23.0846 1908  [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost        C:\WINDOWS\System32\upnphost.dll
12:38:23.0877 1908  upnphost - ok
12:38:23.0877 1908  [ 8047D8AFA070A4C3B9FCBDBF77A84C45 ] usb3Hub        C:\WINDOWS\System32\drivers\usb3Hub.sys
12:38:23.0892 1908  usb3Hub - ok
12:38:23.0892 1908  [ C9E9D59C0099A9FF51697E9306A44240 ] USBAAPL64      C:\WINDOWS\System32\Drivers\usbaapl64.sys
12:38:23.0908 1908  USBAAPL64 - ok
12:38:23.0908 1908  [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] usbccgp        C:\WINDOWS\System32\drivers\usbccgp.sys
12:38:23.0924 1908  usbccgp - ok
12:38:23.0939 1908  [ B395B62B62F28106218FA6FB17F4C797 ] usbcir          C:\WINDOWS\System32\drivers\usbcir.sys
12:38:23.0971 1908  usbcir - ok
12:38:23.0971 1908  [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] usbehci        C:\WINDOWS\System32\drivers\usbehci.sys
12:38:23.0986 1908  usbehci - ok
12:38:24.0002 1908  [ ADBF89B8E0BB372FEFE2E4B84E1E20AE ] usbhub          C:\WINDOWS\System32\drivers\usbhub.sys
12:38:24.0049 1908  usbhub - ok
12:38:24.0064 1908  [ C5986337DE3BF63ABD9ED4D834D34B89 ] USBHUB3        C:\WINDOWS\System32\drivers\UsbHub3.sys
12:38:24.0080 1908  USBHUB3 - ok
12:38:24.0096 1908  [ 325F6179009B5A7F6118951A5BA422AB ] usbohci        C:\WINDOWS\System32\drivers\usbohci.sys
12:38:24.0111 1908  usbohci - ok
12:38:24.0111 1908  [ BA3ABE0CD1C14B3295BAD0F076B84CAC ] usbprint        C:\WINDOWS\System32\drivers\usbprint.sys
12:38:24.0127 1908  usbprint - ok
12:38:24.0127 1908  [ 72334EC4B3FD4EB270623E32E701B57D ] usbser          C:\WINDOWS\system32\DRIVERS\usbser.sys
12:38:24.0142 1908  usbser - ok
12:38:24.0158 1908  [ F77177F6C95B2116EE7AD23B5EF57007 ] USBSTOR        C:\WINDOWS\System32\drivers\USBSTOR.SYS
12:38:24.0174 1908  USBSTOR - ok
12:38:24.0174 1908  [ D25EF4A6EC244C5DE85D88A05B7C149D ] usbuhci        C:\WINDOWS\System32\drivers\usbuhci.sys
12:38:24.0189 1908  usbuhci - ok
12:38:24.0205 1908  [ 09799E701B4327097E9F63D3FE221083 ] usbvideo        C:\WINDOWS\System32\Drivers\usbvideo.sys
12:38:24.0221 1908  usbvideo - ok
12:38:24.0221 1908  [ 11C0CF143D246E2F0E9BDBF17A0CC70B ] USBXHCI        C:\WINDOWS\System32\drivers\USBXHCI.SYS
12:38:24.0252 1908  USBXHCI - ok
12:38:24.0252 1908  [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc        C:\WINDOWS\system32\lsass.exe
12:38:24.0267 1908  VaultSvc - ok
12:38:24.0283 1908  [ 3EEBF3C348C3DEB4CF6F10F2E6E222CD ] VClone          C:\WINDOWS\system32\DRIVERS\VClone.sys
12:38:24.0283 1908  VClone - ok
12:38:24.0299 1908  [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot        C:\WINDOWS\system32\drivers\vdrvroot.sys
12:38:24.0314 1908  vdrvroot - ok
12:38:24.0314 1908  [ 8A8CDA9E3CF2E0B4C6CC19FBC6FB9A71 ] vds            C:\WINDOWS\System32\vds.exe
12:38:24.0346 1908  vds - ok
12:38:24.0346 1908  [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt    C:\WINDOWS\system32\drivers\VerifierExt.sys
12:38:24.0361 1908  VerifierExt - ok
12:38:24.0377 1908  [ 500BE6B2E49883720D0AE8BB859ED7A3 ] vhdmp          C:\WINDOWS\System32\drivers\vhdmp.sys
12:38:24.0408 1908  vhdmp - ok
12:38:24.0408 1908  [ F5B4A14B00E89250C50982AC762DDD1D ] viaide          C:\WINDOWS\system32\drivers\viaide.sys
12:38:24.0424 1908  viaide - ok
12:38:24.0439 1908  [ 0E43886F01C85B47BA0A3157274BCF59 ] Vid            C:\WINDOWS\System32\drivers\Vid.sys
12:38:24.0455 1908  Vid - ok
12:38:24.0455 1908  [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus          C:\WINDOWS\system32\drivers\vmbus.sys
12:38:24.0471 1908  vmbus - ok
12:38:24.0486 1908  [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID        C:\WINDOWS\System32\drivers\VMBusHID.sys
12:38:24.0502 1908  VMBusHID - ok
12:38:24.0502 1908  [ B4F432A51826FFC66F4DF72A83E8E4B1 ] vmbusr          C:\WINDOWS\System32\drivers\vmbusr.sys
12:38:24.0517 1908  vmbusr - ok
12:38:24.0533 1908  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat  C:\WINDOWS\System32\ICSvc.dll
12:38:24.0549 1908  vmicheartbeat - ok
12:38:24.0564 1908  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll
12:38:24.0580 1908  vmickvpexchange - ok
12:38:24.0580 1908  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv        C:\WINDOWS\System32\ICSvc.dll
12:38:24.0611 1908  vmicrdv - ok
12:38:24.0611 1908  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown    C:\WINDOWS\System32\ICSvc.dll
12:38:24.0627 1908  vmicshutdown - ok
12:38:24.0642 1908  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync    C:\WINDOWS\System32\ICSvc.dll
12:38:24.0658 1908  vmictimesync - ok
12:38:24.0674 1908  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss        C:\WINDOWS\System32\ICSvc.dll
12:38:24.0689 1908  vmicvss - ok
12:38:24.0689 1908  [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr          C:\WINDOWS\system32\drivers\volmgr.sys
12:38:24.0705 1908  volmgr - ok
12:38:24.0721 1908  [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx        C:\WINDOWS\system32\drivers\volmgrx.sys
12:38:24.0736 1908  volmgrx - ok
12:38:24.0752 1908  [ 2FB3CDFD5EAF4CD9D4AFAF96877D13AE ] volsnap        C:\WINDOWS\system32\drivers\volsnap.sys
12:38:24.0767 1908  volsnap - ok
12:38:24.0783 1908  [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci            C:\WINDOWS\System32\drivers\vpci.sys
12:38:24.0799 1908  vpci - ok
12:38:24.0799 1908  [ 0190AFFF28F600461C0164353CC7EE27 ] vpcivsp        C:\WINDOWS\System32\drivers\vpcivsp.sys
12:38:24.0814 1908  vpcivsp - ok
12:38:24.0830 1908  [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid        C:\WINDOWS\system32\drivers\vsmraid.sys
12:38:24.0846 1908  vsmraid - ok
12:38:24.0861 1908  [ EA658570314042C914964FC72AB50E6B ] VSS            C:\WINDOWS\system32\vssvc.exe
12:38:24.0908 1908  VSS - ok
12:38:24.0924 1908  [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID        C:\WINDOWS\system32\drivers\vstxraid.sys
12:38:24.0955 1908  VSTXRAID - ok
12:38:24.0955 1908  [ 62460A45435A26A334907E3F2EA45611 ] vwifibus        C:\WINDOWS\System32\drivers\vwifibus.sys
12:38:24.0971 1908  vwifibus - ok
12:38:24.0971 1908  [ 095E943D27025E4D588AF0A72CC2318F ] vwififlt        C:\WINDOWS\system32\DRIVERS\vwififlt.sys
12:38:24.0986 1908  vwififlt - ok
12:38:25.0002 1908  [ 73FA1A41A97A5C34ADC03B3577FF1A86 ] vwifimp        C:\WINDOWS\system32\DRIVERS\vwifimp.sys
12:38:25.0018 1908  vwifimp - ok
12:38:25.0018 1908  [ F690B6EEAA94576727B24376D7ED3601 ] W32Time        C:\WINDOWS\system32\w32time.dll
12:38:25.0049 1908  W32Time - ok
12:38:25.0049 1908  [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen        C:\WINDOWS\System32\drivers\wacompen.sys
12:38:25.0064 1908  WacomPen - ok
12:38:25.0080 1908  [ 61F6972FF9AC9A8D0B4D62076DC30051 ] Wanarp          C:\WINDOWS\system32\DRIVERS\wanarp.sys
12:38:25.0096 1908  Wanarp - ok
12:38:25.0096 1908  [ 61F6972FF9AC9A8D0B4D62076DC30051 ] Wanarpv6        C:\WINDOWS\system32\DRIVERS\wanarp.sys
12:38:25.0111 1908  Wanarpv6 - ok
12:38:25.0127 1908  [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine        C:\WINDOWS\system32\wbengine.exe
12:38:25.0174 1908  wbengine - ok
12:38:25.0174 1908  [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc        C:\WINDOWS\System32\wbiosrvc.dll
12:38:25.0205 1908  WbioSrvc - ok
12:38:25.0205 1908  [ D9C1E82651BF19C6FF69CEC6FD400124 ] Wcmsvc          C:\WINDOWS\System32\wcmsvc.dll
12:38:25.0236 1908  Wcmsvc - ok
12:38:25.0236 1908  [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc        C:\WINDOWS\System32\wcncsvc.dll
12:38:25.0268 1908  wcncsvc - ok
12:38:25.0268 1908  [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll
12:38:25.0283 1908  WcsPlugInService - ok
12:38:25.0283 1908  [ B3A4D918DAB90505B6BC7B70632913CB ] Wd              C:\WINDOWS\system32\drivers\wd.sys
12:38:25.0299 1908  Wd - ok
12:38:25.0314 1908  [ 6F4B5DDDC3B86091E94BC47347A78AF7 ] WdBoot          C:\WINDOWS\system32\drivers\WdBoot.sys
12:38:25.0330 1908  WdBoot - ok
12:38:25.0330 1908  [ 2ADC985B85A71BD7D99712EC0C24358B ] Wdf01000        C:\WINDOWS\system32\drivers\Wdf01000.sys
12:38:25.0361 1908  Wdf01000 - ok
12:38:25.0377 1908  [ 99D404A9A0AFC4734E014EBEBAC13F8F ] WdFilter        C:\WINDOWS\system32\drivers\WdFilter.sys
12:38:25.0393 1908  WdFilter - ok
12:38:25.0408 1908  [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost  C:\WINDOWS\system32\wdi.dll
12:38:25.0439 1908  WdiServiceHost - ok
12:38:25.0439 1908  [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost  C:\WINDOWS\system32\wdi.dll
12:38:25.0471 1908  WdiSystemHost - ok
12:38:25.0471 1908  [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient      C:\WINDOWS\System32\webclnt.dll
12:38:25.0502 1908  WebClient - ok
12:38:25.0502 1908  [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc          C:\WINDOWS\system32\wecsvc.dll
12:38:25.0533 1908  Wecsvc - ok
12:38:25.0533 1908  [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport  C:\WINDOWS\System32\wercplsupport.dll
12:38:25.0580 1908  wercplsupport - ok
12:38:25.0596 1908  [ 5F70EBFC1F75B487DE79501E3CCBDB54 ] WerSvc          C:\WINDOWS\System32\WerSvc.dll
12:38:25.0627 1908  WerSvc - ok
12:38:25.0627 1908  [ FE762D3498719C3A23471BBA62F747B4 ] WFPLWFS        C:\WINDOWS\system32\DRIVERS\wfplwfs.sys
12:38:25.0643 1908  WFPLWFS - ok
12:38:25.0643 1908  [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc          C:\WINDOWS\System32\wiarpc.dll
12:38:25.0658 1908  WiaRpc - ok
12:38:25.0674 1908  [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount        C:\WINDOWS\system32\drivers\wimmount.sys
12:38:25.0689 1908  WIMMount - ok
12:38:25.0689 1908  WinDefend - ok
12:38:25.0705 1908  [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
12:38:25.0736 1908  WinHttpAutoProxySvc - ok
12:38:25.0736 1908  [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt        C:\WINDOWS\system32\wbem\WMIsvc.dll
12:38:25.0768 1908  Winmgmt - ok
12:38:25.0768 1908  WinRing0_1_2_0 - ok
12:38:25.0799 1908  [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM          C:\WINDOWS\system32\WsmSvc.dll
12:38:25.0861 1908  WinRM - ok
12:38:25.0877 1908  [ BB20956C424531003F7FA6CD36F11D5D ] WinUsb          C:\WINDOWS\system32\DRIVERS\WinUsb.sys
12:38:25.0908 1908  WinUsb - ok
12:38:25.0939 1908  [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc        C:\WINDOWS\System32\wlansvc.dll
12:38:25.0971 1908  WlanSvc - ok
12:38:26.0002 1908  [ B330CE47FB74A6BE9A3FFFF4B3F64D9B ] wlidsvc        C:\WINDOWS\system32\wlidsvc.dll
12:38:26.0049 1908  wlidsvc - ok
12:38:26.0049 1908  [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi        C:\WINDOWS\System32\drivers\wmiacpi.sys
12:38:26.0064 1908  WmiAcpi - ok
12:38:26.0064 1908  [ D113499052C5E541906B727779F0F959 ] wmiApSrv        C:\WINDOWS\system32\wbem\WmiApSrv.exe
12:38:26.0096 1908  wmiApSrv - ok
12:38:26.0096 1908  WMPNetworkSvc - ok
12:38:26.0111 1908  [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr        C:\WINDOWS\system32\DRIVERS\wpcfltr.sys
12:38:26.0111 1908  wpcfltr - ok
12:38:26.0127 1908  [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc          C:\WINDOWS\System32\wpcsvc.dll
12:38:26.0143 1908  WPCSvc - ok
12:38:26.0143 1908  [ 3013658A4D327854BEEC4A08D9655194 ] WPDBusEnum      C:\WINDOWS\system32\wpdbusenum.dll
12:38:26.0158 1908  WPDBusEnum - ok
12:38:26.0158 1908  [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr      C:\WINDOWS\system32\drivers\WpdUpFltr.sys
12:38:26.0174 1908  WpdUpFltr - ok
12:38:26.0189 1908  [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl        C:\WINDOWS\system32\drivers\ws2ifsl.sys
12:38:26.0189 1908  ws2ifsl - ok
12:38:26.0205 1908  [ 012CFE7F0F95266F554EE3B91EE2128A ] wscsvc          C:\WINDOWS\System32\wscsvc.dll
12:38:26.0221 1908  wscsvc - ok
12:38:26.0221 1908  [ 74EFDA0526862C3D8D01A776182798EA ] WSDPrintDevice  C:\WINDOWS\System32\drivers\WSDPrint.sys
12:38:26.0236 1908  WSDPrintDevice - ok
12:38:26.0236 1908  WSearch - ok
12:38:26.0283 1908  [ C10BFFEE7E0D7A1366E84F251796C51D ] WSService      C:\WINDOWS\System32\WSService.dll
12:38:26.0377 1908  WSService - ok
12:38:26.0424 1908  [ 79F95469604B77296346DE7DB463EA2A ] wuauserv        C:\WINDOWS\system32\wuaueng.dll
12:38:26.0486 1908  wuauserv - ok
12:38:26.0486 1908  [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf          C:\WINDOWS\system32\drivers\WudfPf.sys
12:38:26.0502 1908  WudfPf - ok
12:38:26.0518 1908  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd          C:\WINDOWS\System32\drivers\WUDFRd.sys
12:38:26.0533 1908  WUDFRd - ok
12:38:26.0533 1908  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFSensorLP    C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
12:38:26.0549 1908  WUDFSensorLP - ok
12:38:26.0564 1908  [ B20F051B03A966392364C83F009F7D17 ] wudfsvc        C:\WINDOWS\System32\WUDFSvc.dll
12:38:26.0580 1908  wudfsvc - ok
12:38:26.0580 1908  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs      C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
12:38:26.0611 1908  WUDFWpdFs - ok
12:38:26.0611 1908  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdMtp      C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
12:38:26.0627 1908  WUDFWpdMtp - ok
12:38:26.0643 1908  [ F9D8D2E6ECE08B278621D5BF3A7240A6 ] WwanSvc        C:\WINDOWS\System32\wwansvc.dll
12:38:26.0658 1908  WwanSvc - ok
12:38:26.0674 1908  [ 24E57041608ED6A9D7FDAD0D9EC214E2 ] XHCIPort        C:\WINDOWS\System32\drivers\XHCIPort.sys
12:38:26.0674 1908  XHCIPort - ok
12:38:26.0705 1908  [ 7055B389BD0DA0B19236BF43CDDF0E1A ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
12:38:26.0736 1908  ZeroConfigService - ok
12:38:26.0752 1908  ================ Scan global ===============================
12:38:26.0752 1908  [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\WINDOWS\system32\basesrv.dll
12:38:26.0768 1908  [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\WINDOWS\system32\winsrv.dll
12:38:26.0768 1908  [ BD7C6949984D19AAA609896B675E7357 ] C:\WINDOWS\system32\sxssrv.dll
12:38:26.0783 1908  [ 8F226143046435C75C033B0C52E90FFE ] C:\WINDOWS\system32\services.exe
12:38:26.0783 1908  [Global] - ok
12:38:26.0783 1908  ================ Scan MBR ==================================
12:38:26.0783 1908  [ 92D254C369228CDF8AAD5B39E303B14E ] \Device\Harddisk0\DR0
12:38:27.0330 1908  \Device\Harddisk0\DR0 - ok
12:38:27.0330 1908  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
12:38:27.0408 1908  \Device\Harddisk1\DR1 - ok
12:38:27.0408 1908  ================ Scan VBR ==================================
12:38:27.0424 1908  [ 3045DED65FE6DF338ED6E28059E42AEF ] \Device\Harddisk0\DR0\Partition1
12:38:27.0424 1908  \Device\Harddisk0\DR0\Partition1 - ok
12:38:27.0440 1908  [ 6EBF0B0550FF56CD5FABE99FA1CF29EE ] \Device\Harddisk0\DR0\Partition2
12:38:27.0440 1908  \Device\Harddisk0\DR0\Partition2 - ok
12:38:27.0440 1908  [ 258079E114874F817B231FAA4702C22A ] \Device\Harddisk0\DR0\Partition3
12:38:27.0440 1908  \Device\Harddisk0\DR0\Partition3 - ok
12:38:27.0471 1908  [ CF834247AB28C620E46465A65B19F0E4 ] \Device\Harddisk0\DR0\Partition4
12:38:27.0471 1908  \Device\Harddisk0\DR0\Partition4 - ok
12:38:27.0486 1908  [ 7BA75A63A3BF0B6E0BF0CB7F7C486918 ] \Device\Harddisk1\DR1\Partition1
12:38:27.0486 1908  \Device\Harddisk1\DR1\Partition1 - ok
12:38:27.0486 1908  [ A68FC5B28BA3C90CFADB714605B00866 ] \Device\Harddisk1\DR1\Partition2
12:38:27.0486 1908  \Device\Harddisk1\DR1\Partition2 - ok
12:38:27.0486 1908  ============================================================
12:38:27.0486 1908  Scan finished
12:38:27.0486 1908  ============================================================
12:38:27.0502 0052  Detected object count: 2
12:38:27.0502 0052  Actual detected object count: 2
12:38:30.0768 0052  ClassicShellService ( UnsignedFile.Multi.Generic ) - skipped by user
12:38:30.0768 0052  ClassicShellService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:38:30.0768 0052  Freemake Improver ( UnsignedFile.Multi.Generic ) - skipped by user
12:38:30.0768 0052  Freemake Improver ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:38:43.0098 5576  Deinitialize success

Das ist ein besonders hartnäckiger! Malewarebites hat NIX gefunden!
Ich lass es gleich nochmal laufen aber hier schon mal das log file:
Gruss mamic
Code:

Malwarebytes Anti-Rootkit BETA 1.06.0.1003
www.malwarebytes.org

Database version: v2013.06.16.01

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16599
Santa :: YPS [administrator]

16.06.2013 12:43:05
mbar-log-2013-06-16 (12-43-05).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: Deep Anti-Rootkit Scan | PUP
Objects scanned: 258119
Time elapsed: 8 minute(s), 22 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

Beim 2. Mal kam auch nix anderes raus. "No Maleware found!" Damit komme ich erst gar nicht zum Clean Up!
Aber die Prozessoren laufen nach wie vor auf 100% und der Task manager zeigt mir dass Coin-Miner mit knapp 68% und WMI Provider Host mit etwa 22% zusammen 99,5% meiner ressourcen fressen!
Was können wir noch tun? Gruss mamic

mamic 16.06.2013 16:58

Hallo Schrauber, ich glaube ich habe es geschafft!
Ich habe den Rechner mit Hilfe eines Wiederherstellungspunktes zurückgesetzt.
Ich bitte um Entschuldigung, ich hätte das schon machen sollen bevor ich diesen Thread eröffnet habe! Ich hab das irgendwie im Eifer des Gefechtes verschwitzt - bitte nicht böse sein.
Vorher hatte ich noch Firefox und Chrome deinstalliert und die Benutzerdaten gelöscht sowie alle Fundstellen des Trojaners.
Jetzt sieht es so aus als sei alles i.O. aber ich bin mir halt leider nicht sicher.
Deshalb hier nocheinmal ein FRST Log. Was kann ich sonst noch tun damit ich sicher bin dass der Trojaner weg ist? Sind der Defender und Firewall von Windows genug Schutz? -der Fall deutet eher auf "Nein".
Danke für die Zeit und Geduld! Gruss mamic

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013
Ran by Santa (administrator) on 16-06-2013 17:42:33
Running from G:\Desktop
Windows 8 Pro with Media Center (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SAsrv.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(AddGadgets) G:\Downloads\Gadgets\PCMeter\PCMeterV0.3.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Google) C:\Program Files (x86)\Google\Google Talk\googletalk.exe
(Google Inc.) C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Dropbox, Inc.) C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\WINDOWS\System32\LocationNotifications.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\Bluetooth Headset Helper.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Adobe Systems, Inc.) C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [KeyLemon LemonScreen] C:\Program Files\KeyLemon\KLLockEngine.exe atstartup [1004984 2012-12-17] (KeyLemon)
HKLM\...\Run: [KeyLemon Updater] C:\Program Files\KeyLemon\KLUpdater.exe [705464 2012-12-17] (KeyLemon)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe /t [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [LenovoOptMouseUpdate] C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-08-31] (Lenovo Group Limited)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM\...\Run: [Greenshot] C:\Program Files\Greenshot\Greenshot.exe [499712 2013-05-20] (Greenshot)
HKCU\...\Run: [NPowerTray] G:\Downloads\NPowerTray.exe [x]
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18642024 2013-02-28] (Skype Technologies S.A.)
HKCU\...\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show [89600 2013-04-11] ()
HKCU\...\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart [3289088 2007-11-21] (Google)
HKCU\...\Run: [Google Update] "C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2013-06-09] (Google Inc.)
HKCU\...\Run: [MusicManager] "C:\Users\Santa\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [7331840 2013-04-24] (Google Inc.)
HKLM-x32\...\Run: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload [1960448 2013-04-05] (Dominik Reichl)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Santa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Santa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar.lnk
ShortcutTarget: Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: PodcastBHO Class - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files (x86)\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler: msdaipp - No CLSID Value -
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default
FF SelectedSearchEngine: Web Search
FF Homepage: hxxp://web.de/|hxxp://www.google.com/ig?hl=de|https://ksab.kroschu.com/webaccess/index.php|hxxp://www.gizmodo.de/|hxxp://www.focus.de/|hxxp://www.myliveshopping.de/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
FF Extension: Flagfox - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: DownloadHelper - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: amznUWL2 - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\amznUWL2@amazon.com.xpi
FF Extension: client - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\client@anonymox.net.xpi
FF Extension: musicplayer - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\musicplayer@firemediaplayer.com.xpi
FF Extension: SkipScreen - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\SkipScreen@SkipScreen.xpi
FF Extension: translator - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\translator@zoli.bod.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{677a8f98-fd64-40b0-a883-b8c95d0cbf17}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF Extension: No Name - C:\Users\Santa\AppData\Roaming\Mozilla\Firefox\Profiles\5zat8v2p.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi

Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll No File
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
CHR Plugin: (doubletwist Plugin 1, 3, 0, 0) - C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
CHR Plugin: (Foxit Reader Plugin for Mozilla) - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YOUZEEK Free Music) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjcgpdkighmjfjlplcighhgamlhkimce\2.0.1_0
CHR Extension: (YouTube) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Play Music) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg\5.1_0
CHR Extension: (Gmail) - C:\Users\Santa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2000-01-01] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [331776 2012-07-26] (Microsoft Corporation)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959256 2012-11-15] (Broadcom Corporation.)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-04-12] (IvoSoft)
R2 CxAudMsg; C:\WINDOWS\system32\CxAudMsg64.exe [201376 2012-06-08] (Conexant Systems Inc.)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-05-30] (Freemake)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1225312 2012-11-26] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [659040 2012-11-26] (Secunia)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

R1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
R1 ACLE6Live; C:\WINDOWS\system32\Drivers\ACLE1764.sys [109016 2013-02-14] (Softwareentwicklung Remus - ArchiCrypt - )
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2000-01-01] (Broadcom Corporation.)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [117632 2013-02-02] (Microsoft Corporation)
S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [30720 2013-02-02] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44344 2012-10-18] (Synaptics Incorporated)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2013-06-16] ()
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)
R3 WinRing0_1_2_0; \??\C:\Users\Santa\AppData\Local\Temp\tmp4DF1.tmp [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-16 17:13 - 2013-06-16 17:13 - 00000000 ____D C:\Users\Santa\AppData\Roaming\pdfforge
2013-06-16 17:13 - 2013-04-09 15:13 - 00110264 ____A (pdfforge GmbH) C:\Windows\System32\pdfcmon.dll
2013-06-16 17:12 - 2013-06-16 17:12 - 00000000 ____D C:\Program Files\Greenshot
2013-06-16 17:12 - 2013-06-16 17:12 - 00000000 ____D C:\Program Files (x86)\uTorrent
2013-06-16 17:12 - 2013-06-16 17:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-16 17:00 - 2013-05-04 09:45 - 02233600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-16 17:00 - 2013-04-27 07:20 - 00733184 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-16 17:00 - 2013-04-24 01:13 - 01013248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-16 17:00 - 2013-04-24 01:12 - 01569792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-16 17:00 - 2013-04-24 01:12 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-16 17:00 - 2013-04-24 00:56 - 01255936 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-16 17:00 - 2013-04-24 00:55 - 01889280 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-16 17:00 - 2013-04-24 00:55 - 00141312 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-16 17:00 - 2013-04-24 00:55 - 00068096 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-16 17:00 - 2013-04-03 01:37 - 00025088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-16 17:00 - 2013-04-03 01:12 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-16 16:59 - 2013-05-16 00:37 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-06-16 16:59 - 2013-05-16 00:36 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-16 16:59 - 2013-05-16 00:35 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-16 16:59 - 2013-05-16 00:35 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-06-16 16:59 - 2013-05-14 15:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-16 16:59 - 2013-05-14 11:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-16 16:59 - 2013-04-29 00:30 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-16 16:59 - 2013-04-29 00:30 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-16 16:59 - 2013-04-29 00:30 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-16 16:59 - 2013-04-29 00:30 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-16 16:59 - 2013-04-29 00:30 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-16 16:59 - 2013-04-29 00:30 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-16 16:59 - 2013-04-29 00:30 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-16 16:59 - 2013-04-29 00:28 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-16 16:59 - 2013-04-29 00:28 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-16 16:59 - 2013-04-29 00:28 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-16 16:59 - 2013-04-29 00:28 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll
2013-06-16 16:59 - 2013-04-29 00:28 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-16 16:59 - 2013-04-29 00:28 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-16 16:59 - 2013-04-29 00:27 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-16 16:59 - 2013-04-29 00:27 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-16 16:59 - 2013-04-29 00:27 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-16 12:42 - 2013-06-16 12:56 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-16 12:42 - 2013-06-16 12:42 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-15 19:47 - 2013-06-15 19:47 - 00001842 ____A C:\Users\Santa\Desktop\JRT.txt
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\JRT
2013-06-15 19:39 - 2013-06-15 19:39 - 00010597 ____A C:\AdwCleaner[S1].txt
2013-06-15 16:01 - 2013-06-15 17:21 - 00000000 ____D C:\FRST
2013-06-13 18:32 - 2013-06-16 17:49 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 18:30 - 2013-06-13 18:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-11 19:21 - 2013-05-16 00:35 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\tssdisai.dll
2013-06-09 12:54 - 2013-06-09 12:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 09:43 - 2013-06-12 21:48 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-09 09:43 - 2013-06-09 09:48 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-08 22:35 - 2013-06-08 22:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 22:35 - 2000-01-01 02:00 - 00161144 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwampfl.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 02231064 ____A (Broadcom Corporation.) C:\Windows\System32\BcmBtRSupport.dll
2013-06-08 22:34 - 2000-01-01 02:00 - 02227992 ____A (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
2013-06-08 22:34 - 2000-01-01 02:00 - 00226680 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwavdt.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00186136 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwaudio.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00169240 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\bcbtums.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00040248 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwl2cap.sys
2013-06-08 22:34 - 2000-01-01 02:00 - 00020856 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwrchid.sys
2013-06-08 22:28 - 2013-06-08 22:34 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 22:28 - 2013-06-08 22:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 22:20 - 2013-06-16 17:06 - 00002196 ____A C:\Windows\PFRO.log
2013-06-08 22:19 - 2013-06-08 22:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 22:19 - 2000-01-01 02:00 - 00053248 ____A (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
2013-06-08 22:16 - 2013-06-08 22:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 22:16 - 2013-06-08 22:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 22:12 - 2013-06-16 17:36 - 00016152 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-08 22:12 - 2013-06-16 17:36 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-08 22:12 - 2013-06-08 22:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 21:02 - 2013-06-08 21:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 21:02 - 2013-06-08 21:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 21:01 - 2013-06-08 21:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 20:59 - 2013-06-16 17:05 - 01870087 ____A C:\Windows\WindowsUpdate.log
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 20:56 - 2013-06-08 20:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 20:56 - 2013-06-08 20:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 20:49 - 2013-06-08 20:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 19:54 - 2013-06-08 19:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 19:48 - 2013-06-08 19:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 19:47 - 2013-06-08 19:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 19:46 - 2013-06-08 19:47 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 18:32 - 2013-06-08 18:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 16:46 - 2013-06-08 16:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 16:40 - 2013-06-08 16:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 16:34 - 2013-06-08 22:20 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 16:34 - 2013-06-08 16:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 16:27 - 2013-06-08 16:28 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 16:27 - 2013-06-08 16:28 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 16:27 - 2013-06-08 16:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 16:27 - 2013-06-08 16:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 22:52 - 2013-06-06 23:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 22:50 - 2013-06-16 17:49 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-06 22:50 - 2013-06-16 17:36 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-04 20:02 - 2013-06-04 20:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 19:22 - 2013-06-04 19:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 19:07 - 2013-06-04 19:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 13:52 - 2013-05-24 19:05 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-06-04 13:51 - 2013-06-04 13:56 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-03 17:30 - 2013-06-03 17:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-03 17:10 - 2013-06-08 18:29 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-02 12:38 - 2013-06-02 12:38 - 00000000 ____D C:\Users\Santa\.android
2013-05-31 22:26 - 2013-05-31 22:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 22:26 - 2011-11-25 01:25 - 00015360 ____A (June Fabrics Technology Inc.) C:\Windows\System32\Drivers\pneteth.sys
2013-05-31 14:19 - 2013-05-31 14:19 - 00000000 ____D C:\ZOPO
2013-05-30 20:59 - 2013-05-30 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 19:37 - 2013-06-04 19:07 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-05-30 19:37 - 2013-06-01 12:38 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-30 17:17 - 2013-05-30 17:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 17:13 - 2013-06-05 00:09 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-30 17:13 - 2013-06-05 00:09 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-30 16:57 - 2013-05-30 16:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 16:34 - 2013-06-16 17:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-30 16:04 - 2013-04-08 23:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2013-05-30 16:04 - 2013-04-08 23:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-05-30 16:04 - 2013-04-08 23:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll
2013-05-30 16:04 - 2013-03-16 00:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2013-05-30 16:03 - 2013-04-09 07:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2013-05-30 16:03 - 2013-04-09 07:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2013-05-30 16:03 - 2013-04-09 07:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll
2013-05-30 16:03 - 2013-04-09 07:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll
2013-05-30 16:03 - 2013-04-09 07:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll
2013-05-30 16:03 - 2013-04-09 07:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-05-30 16:03 - 2013-04-09 06:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe
2013-05-30 16:03 - 2013-04-09 06:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe
2013-05-30 16:03 - 2013-04-09 06:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-05-30 16:03 - 2013-04-09 06:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-05-30 16:03 - 2013-04-09 06:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll
2013-05-30 16:03 - 2013-04-09 06:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2013-05-30 16:03 - 2013-04-09 06:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2013-05-30 16:03 - 2013-04-09 06:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl
2013-05-30 16:03 - 2013-04-09 06:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll
2013-05-30 16:03 - 2013-04-09 04:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-05-30 16:03 - 2013-04-09 04:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-05-30 16:03 - 2013-04-09 04:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2013-05-30 16:03 - 2013-04-09 04:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2013-05-30 16:03 - 2013-04-09 04:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2013-05-30 16:03 - 2013-04-09 04:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2013-05-30 16:03 - 2013-04-09 04:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2013-05-30 16:03 - 2013-04-09 01:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2013-05-30 16:03 - 2013-04-09 01:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-05-30 16:03 - 2013-04-09 01:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2013-05-30 16:03 - 2013-04-09 01:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-05-30 16:03 - 2013-04-08 23:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-05-30 16:03 - 2013-04-08 23:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-05-30 16:03 - 2013-04-08 23:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-05-30 16:03 - 2013-04-08 23:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-05-30 16:03 - 2013-04-08 23:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2013-05-30 16:03 - 2013-04-08 23:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2013-05-30 16:03 - 2013-04-05 01:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll
2013-05-30 16:03 - 2013-04-03 00:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml
2013-05-30 16:03 - 2013-03-30 20:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi
2013-05-30 16:03 - 2013-03-30 20:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe
2013-05-30 16:03 - 2013-03-29 00:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi
2013-05-30 16:03 - 2013-03-29 00:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe
2013-05-30 16:03 - 2013-03-16 00:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll
2013-05-30 16:03 - 2012-12-13 06:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-05-30 16:03 - 2012-12-13 05:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-05-30 16:01 - 2013-04-16 04:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-30 16:01 - 2013-04-11 08:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-05-30 15:59 - 2013-03-22 05:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2013-05-30 15:59 - 2013-03-22 00:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll
2013-05-30 15:59 - 2013-03-15 02:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-05-30 15:59 - 2013-03-06 09:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-30 15:59 - 2013-03-06 08:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-30 15:59 - 2013-03-06 08:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-30 15:59 - 2013-03-06 08:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-30 15:59 - 2013-03-06 07:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-30 15:59 - 2013-03-06 07:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-19 12:54 - 2013-05-19 12:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll

==================== One Month Modified Files and Folders =======

2013-06-16 17:49 - 2013-06-13 18:32 - 00000000 ____D C:\ProgramData\Caphyon
2013-06-16 17:49 - 2013-06-06 22:50 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-06-16 17:49 - 2013-02-09 16:59 - 00000000 ____D C:\Users\Santa\AppData\Roaming\vlc
2013-06-16 17:49 - 2013-02-03 22:43 - 00000000 ____D C:\Users\Santa\AppData\Roaming\TeraCopy
2013-06-16 17:49 - 2013-02-03 20:59 - 00000000 ____D C:\users\DefaultAppPool
2013-06-16 17:49 - 2012-07-26 10:12 - 00000000 __RHD C:\Users\Public\Libraries
2013-06-16 17:49 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2013-06-16 17:49 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\registration
2013-06-16 17:49 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\System32\Sysprep
2013-06-16 17:41 - 2012-07-26 12:27 - 00753134 ____A C:\Windows\System32\perfh007.dat
2013-06-16 17:41 - 2012-07-26 12:27 - 00155826 ____A C:\Windows\System32\perfc007.dat
2013-06-16 17:41 - 2012-07-26 09:28 - 01745416 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-16 17:37 - 2013-02-03 22:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Skype
2013-06-16 17:37 - 2013-02-03 21:35 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Dropbox
2013-06-16 17:36 - 2013-06-08 22:12 - 00016152 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-16 17:36 - 2013-06-08 22:12 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job
2013-06-16 17:36 - 2013-06-06 22:50 - 00000334 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-16 17:36 - 2013-03-31 01:13 - 00000026 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Usage.ini
2013-06-16 17:36 - 2012-07-26 09:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-16 17:15 - 2013-02-03 22:16 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-16 17:14 - 2013-02-03 22:23 - 00000000 ____D C:\Program Files\CDBurnerXP
2013-06-16 17:13 - 2013-06-16 17:13 - 00000000 ____D C:\Users\Santa\AppData\Roaming\pdfforge
2013-06-16 17:13 - 2013-02-03 22:18 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-06-16 17:13 - 2013-02-03 22:17 - 00000000 ____D C:\Program Files (x86)\PDFCreator
2013-06-16 17:12 - 2013-06-16 17:12 - 00000000 ____D C:\Program Files\Greenshot
2013-06-16 17:12 - 2013-06-16 17:12 - 00000000 ____D C:\Program Files (x86)\uTorrent
2013-06-16 17:12 - 2013-06-16 17:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-16 17:12 - 2013-05-30 16:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-16 17:12 - 2013-02-03 22:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\uTorrent
2013-06-16 17:09 - 2013-03-30 17:23 - 00014644 ____A C:\Users\Santa\Network_Meter_Data.js
2013-06-16 17:09 - 2013-03-28 14:18 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-16 17:09 - 2012-07-26 10:12 - 00000000 ___SD C:\Program Files\Windows Sidebar
2013-06-16 17:09 - 2012-07-26 10:12 - 00000000 ___SD C:\Program Files (x86)\Windows Sidebar
2013-06-16 17:06 - 2013-06-08 22:20 - 00002196 ____A C:\Windows\PFRO.log
2013-06-16 17:05 - 2013-06-08 20:59 - 01870087 ____A C:\Windows\WindowsUpdate.log
2013-06-16 17:05 - 2012-07-26 07:26 - 00262144 __ASH C:\Windows\System32\config\BBI
2013-06-16 17:01 - 2013-02-04 22:44 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-16 17:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\sru
2013-06-16 16:58 - 2013-02-03 22:16 - 00000000 ____D C:\Users\Santa\AppData\Local\Google
2013-06-16 16:49 - 2013-02-03 20:59 - 00000000 ____D C:\users\Santa
2013-06-16 12:56 - 2013-06-16 12:42 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-16 12:42 - 2013-06-16 12:42 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-15 19:47 - 2013-06-15 19:47 - 00001842 ____A C:\Users\Santa\Desktop\JRT.txt
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-15 19:43 - 2013-06-15 19:43 - 00000000 ____D C:\JRT
2013-06-15 19:39 - 2013-06-15 19:39 - 00010597 ____A C:\AdwCleaner[S1].txt
2013-06-15 17:21 - 2013-06-15 16:01 - 00000000 ____D C:\FRST
2013-06-13 22:24 - 2013-02-03 22:01 - 00000000 ____D C:\Users\Santa\AppData\Roaming\UseNeXT
2013-06-13 22:09 - 2013-02-03 21:45 - 00000000 ____D C:\Users\Santa\AppData\Roaming\KeePass
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\Newshosting
2013-06-13 18:32 - 2013-06-13 18:32 - 00000000 ____D C:\Users\Santa\AppData\Local\CrashRpt
2013-06-13 18:30 - 2013-06-13 18:30 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Newshosting
2013-06-12 21:48 - 2013-06-09 09:43 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000UA.job
2013-06-12 20:19 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-06-12 00:22 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-06-10 18:43 - 2013-02-05 00:26 - 00000853 ____A C:\Users\Santa\AppData\Roaming\Drives Meter_Settings.ini
2013-06-09 12:54 - 2013-06-09 12:54 - 00000000 ____D C:\Program Files (x86)\iTunes Library Updater
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files\iPod
2013-06-09 12:28 - 2013-06-09 12:28 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 09:48 - 2013-06-09 09:43 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1236658316-3132239065-196456727-1000Core.job
2013-06-08 22:35 - 2013-06-08 22:35 - 00000000 ____D C:\Users\Santa\AppData\Local\Broadcom
2013-06-08 22:34 - 2013-06-08 22:28 - 00000433 ____A C:\Windows\setupact.log
2013-06-08 22:34 - 2013-02-11 01:19 - 00000000 ____D C:\Program Files\Lenovo
2013-06-08 22:28 - 2013-06-08 22:28 - 00000000 ____A C:\Windows\setuperr.log
2013-06-08 22:20 - 2013-06-08 16:34 - 00000334 ____A C:\Windows\Tasks\SuperEasyDriverUpdater_UPDATES.job
2013-06-08 22:19 - 2013-06-08 22:19 - 00000000 ____D C:\Users\Santa\AppData\Local\pcwServiceCenter
2013-06-08 22:19 - 2013-02-03 21:15 - 00000000 ____D C:\Program Files (x86)\Intel
2013-06-08 22:16 - 2013-06-08 22:16 - 00002467 ____A C:\Users\Public\Desktop\SlimDrivers.lnk
2013-06-08 22:16 - 2013-06-08 22:16 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-06-08 22:12 - 2013-06-08 22:12 - 00000000 ____D C:\Users\Santa\AppData\Local\SlimWare Utilities Inc
2013-06-08 21:02 - 2013-06-08 21:02 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 21:02 - 2013-06-08 21:02 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-08 21:02 - 2013-06-08 21:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 21:02 - 2013-04-12 16:38 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-08 21:02 - 2013-04-12 16:38 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-08 21:01 - 2013-06-08 21:01 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 21:01 - 2013-06-08 21:01 - 00001168 ____A C:\Users\Santa\Desktop\Google Talk.lnk
2013-06-08 21:01 - 2013-02-03 22:14 - 01092512 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-06-08 21:01 - 2013-02-03 22:14 - 00971680 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\Secunia PSI
2013-06-08 20:59 - 2013-06-08 20:59 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-06-08 20:56 - 2013-06-08 20:56 - 00053248 ____A C:\Windows\SysWOW64\zlib.dll
2013-06-08 20:56 - 2013-06-08 20:56 - 00000749 ____A C:\Users\Public\Desktop\dMaintenanceConfig.zip
2013-06-08 20:49 - 2013-06-08 20:49 - 00024576 ____A C:\Windows\System32\FoolishEventLogMsgHelper.dll
2013-06-08 19:54 - 2013-06-08 19:54 - 00000000 ____D C:\Program Files (x86)\Auslogics
2013-06-08 19:48 - 2013-06-08 19:48 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Auslogics
2013-06-08 19:47 - 2013-06-08 19:47 - 00000946 ____A C:\Users\Public\Desktop\PC-WELT-ServiceCenter.lnk
2013-06-08 19:47 - 2013-06-08 19:46 - 00000000 ____D C:\Program Files\PC-WELT-ServiceCenter
2013-06-08 18:32 - 2013-06-08 18:32 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-08 18:29 - 2013-06-03 17:10 - 00000000 ____D C:\Users\Santa\VMLites
2013-06-08 17:48 - 2013-02-03 21:03 - 00000000 ____D C:\Users\Santa\AppData\Local\VirtualStore
2013-06-08 16:46 - 2013-06-08 16:46 - 00000000 ____D C:\Users\Santa\AppData\Local\Engelmann_Media
2013-06-08 16:40 - 2013-06-08 16:40 - 00000000 ____D C:\ProgramData\Licenses
2013-06-08 16:34 - 2013-06-08 16:34 - 00000000 ____D C:\Users\Santa\AppData\Roaming\SuperEasy Software
2013-06-08 16:31 - 2013-06-08 16:31 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Engelmann Media
2013-06-08 16:28 - 2013-06-08 16:27 - 00010458 ____A C:\Windows\Q-Dir.ini
2013-06-08 16:28 - 2013-06-08 16:27 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Q-Dir
2013-06-08 16:27 - 2013-06-08 16:27 - 00001832 ____A C:\Users\Public\Desktop\Q-Dir.lnk
2013-06-08 16:27 - 2013-06-08 16:27 - 00000000 ____D C:\Program Files (x86)\Q-Dir
2013-06-06 23:32 - 2013-02-11 01:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-06-06 23:09 - 2013-06-06 22:52 - 00000000 ____D C:\Users\Santa\AppData\Roaming\GlarySoft
2013-06-06 22:55 - 2013-02-05 00:09 - 00000000 ____D C:\Users\Santa\AppData\Roaming\BatteryBar
2013-06-06 18:09 - 2012-01-07 18:24 - 00000000 ____D C:\Users\Santa\dwhelper
2013-06-06 14:16 - 2013-02-05 00:09 - 00000000 ____D C:\Program Files\BatteryBar
2013-06-05 23:50 - 2013-02-03 22:16 - 00000000 ____D C:\Program Files\Classic Shell
2013-06-05 00:09 - 2013-05-30 17:13 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-05 00:09 - 2013-05-30 17:13 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-04 20:05 - 2013-02-09 16:08 - 00000021 ____A C:\Users\Santa\AppData\Roaming\ISOWorkshop.ini
2013-06-04 20:02 - 2013-06-04 20:02 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-06-04 19:48 - 2013-02-05 00:10 - 00000000 ____D C:\Program Files\CCleaner
2013-06-04 19:22 - 2013-06-04 19:22 - 00000000 ____D C:\ProgramData\Bluray Decrypter
2013-06-04 19:13 - 2013-02-05 00:37 - 00001198 ____A C:\Users\Public\Desktop\ISO Workshop.lnk
2013-06-04 19:07 - 2013-06-04 19:07 - 00000000 ____D C:\Program Files\Handbrake
2013-06-04 19:07 - 2013-05-30 19:37 - 00000827 ____A C:\Users\Santa\Desktop\Handbrake.lnk
2013-06-04 16:20 - 2013-02-11 01:20 - 00000000 ____D C:\Users\Santa\AppData\Roaming\TeamViewer
2013-06-04 14:04 - 2013-02-11 01:19 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-06-04 13:56 - 2013-06-04 13:51 - 00000000 ____D C:\ProgramData\Lenovo
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Windows\Downloaded Installations
2013-06-04 13:51 - 2013-06-04 13:51 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-06-04 13:51 - 2012-07-26 10:12 - 00000000 __RSD C:\Windows\Media
2013-06-03 17:30 - 2013-06-03 17:30 - 00000000 ____D C:\Users\Santa\AppData\Local\VMLite Workstation
2013-06-02 12:38 - 2013-06-02 12:38 - 00000000 ____D C:\Users\Santa\.android
2013-06-02 12:36 - 2013-02-03 22:15 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Notepad++
2013-06-01 12:38 - 2013-05-30 19:37 - 00000000 ____D C:\Users\Santa\AppData\Roaming\HandBrake
2013-05-31 22:26 - 2013-05-31 22:26 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2013-05-31 14:19 - 2013-05-31 14:19 - 00000000 ____D C:\ZOPO
2013-05-30 20:59 - 2013-05-30 20:59 - 00000000 ____D C:\Users\Santa\AppData\Local\FreemakeVideoConverter
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\ProgramData\Freemake
2013-05-30 20:25 - 2013-05-30 20:25 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-05-30 17:24 - 2013-02-06 20:07 - 00000000 ____D C:\Users\Santa\AppData\Roaming\JAM Software
2013-05-30 17:19 - 2013-02-05 23:11 - 00001080 ____A C:\Users\Santa\AppData\Roaming\Network Meter_Settings.ini
2013-05-30 17:17 - 2013-05-30 17:17 - 00310216 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-30 17:12 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData
2013-05-30 17:12 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore
2013-05-30 16:57 - 2013-05-30 16:57 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-05-30 16:57 - 2013-02-12 12:51 - 00000000 ____D C:\Users\Santa\AppData\Roaming\Foxit Software
2013-05-24 19:05 - 2013-06-04 13:52 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-05-19 12:54 - 2013-05-19 12:54 - 00097176 ____A (Elaborate Bytes AG) C:\Windows\SysWOW64\ElbyCDIO.dll

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-11 20:03

==================== End Of Log ============================

--- --- ---

schrauber 16.06.2013 18:46

Sieht besser aus. Beobachte das mal nen Tag oder zwei und meld dich wieder :)

mamic 16.06.2013 19:18

Hallo Schrauber, :daumenhoch:

werde ich machen. Erst mal vielen Dank für die Mühe und Zeit.
Ich melde mich spätestens nächstes Wochenende nochmal!
:dankeschoen:
mamic

schrauber 17.06.2013 08:14

Alles klar :)

mamic 18.06.2013 17:14

Hallo Schrauber,
so weit, so gut! Computer läuft jetzt mehr als 48h normal, das eine oder andere Programm hab ich deinstalliert und neu installiert weil anscheinend "etwas beschädigt" war. :singsing:
Bin zu dem Schluss gekommen dass das Schutzpaket von Win 8 wohl doch nicht ausreicht -
Ich habe ESET installiert und Malewarebites laufen lassen - keine Meldungen. :taenzer:
Ich verspreche ich werde in Zukunft noch gründlicher checken bevor ich etwas klicke!
Dieses Mall war es eine "jjojsdfjläsddjfoweerllnsadhsif.rar.exe" deren Name genau so lang war dass ".exe" nicht mehr zu sehen war. Meine Töchter denen ich normalerweise helfen kann haben sich darüber amüsiert dass es diesmal mich erwischt hatte!
Ich sage jedenfalls recht schön Danke für deine Geduld und Hilfe :dankeschoen:
Ich hoffe trotzdem dass ich euch so bald nicht wieder brauche!
Liebe Grüsse
mamic

schrauber 18.06.2013 18:31

Gern geschehen :)

Dann räumen wir mal auf, falls noch was da ist:

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

mamic 18.06.2013 20:25

Hallo Schrauber,
alles erledigt, Software deinstalliert bzw gelöscht.
Nochmal schönen Dank
Gruss
mamic

schrauber 19.06.2013 07:12

Gern Geschehn :)


Alle Zeitangaben in WEZ +1. Es ist jetzt 08:30 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19