Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Langsamer Boot, Flash Plugin Problem - woran liegts?

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 07.07.2013, 19:56   #1
mKy
 
Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Hallo,

seit einigen Tagen habe ich Probleme mit dem Adobe Flash Player Plugin, Filme, Videos etc lassen sich nur noch langsam laden und es kann definitiv nicht an meiner Hardware oder Internetverbedingung liegen. Das Plugin stürzt dauernd ab, ich habe davon 2 Prozesse im Task-Manager. Ich habe probiert das Problem selbst zu fixen, aber nun dauert mein Boot länger als zuvor und sobald ich auf Windows angekommen bin, werde ich von einem Kaspersky-Programm gefragt, ob ich dieses Ausführen möchte oder nicht - keine Ahnung ob das etwas zu bedeuten hat, jedoch brauche ich eure Hilfe, da ich nicht weiß, wo genau das Problem liegt.


defogger disable
Zitat:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 20:44 on 07/07/2013 (mKy)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-

OTL


OTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 07.07.2013 20:45:25 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\mKy\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,95 Gb Total Physical Memory | 5,86 Gb Available Physical Memory | 73,79% Memory free
15,89 Gb Paging File | 13,65 Gb Available in Paging File | 85,91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,66 Gb Total Space | 210,85 Gb Free Space | 45,28% Space Free | Partition Type: NTFS
 
Computer Name: MKY-PC | User Name: mKy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02BF2812-3025-4354-8E16-C0384CC6A7EF}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{02F5F83B-B966-41F6-A9CB-A8535DC22910}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{1A004169-56F1-4DBA-9DFB-8266F847D467}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{2341EEA4-42D0-4AC2-86F3-E703D5269581}" = rport=138 | protocol=17 | dir=out | app=system | 
"{4207440D-DD7E-41E4-9C96-C3E518737E5D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{5A5D84FC-F01F-4FCB-9C36-B8FF916D450A}" = lport=445 | protocol=6 | dir=in | app=system | 
"{5CE6DC8F-7DFB-4A31-A277-D9C2E5D2462E}" = lport=58346 | protocol=6 | dir=in | name=pando media booster | 
"{5F231F75-8115-497C-A788-F49BE476F0B2}" = rport=139 | protocol=6 | dir=out | app=system | 
"{658642A4-A16B-4A69-8755-34C32D7D9D49}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{6B9DFA97-8AC6-4116-934D-35EDDD6EECCA}" = lport=58346 | protocol=6 | dir=in | name=pando media booster | 
"{73999932-CCD6-4134-83A6-500BF6FE0935}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{7FF2CD87-7081-4D9A-9A59-596BFCC8462F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{8BA9BA61-F321-4285-8BF4-4C6995C27180}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
"{8D777446-0276-4A4C-9B90-FC610F4CC00E}" = lport=139 | protocol=6 | dir=in | app=system | 
"{94EA1BCE-B2B6-48AD-9AA5-336407BE1546}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{9A12D09F-0F06-45DC-A713-797B3B3C257A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{9A3593CA-F46E-41C4-838A-D0305873AC1D}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{A796C1CF-7BCE-4290-8D60-6251A2396E5C}" = lport=137 | protocol=17 | dir=in | app=system | 
"{A9ADDE06-C017-4E4A-A54E-DA284070F528}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{AA354D07-865F-43AD-835A-41B3751A042C}" = rport=445 | protocol=6 | dir=out | app=system | 
"{AD8D8374-839E-4E05-BC65-685B34456100}" = lport=58346 | protocol=17 | dir=in | name=pando media booster | 
"{B09BFEC5-E893-45A4-B299-74F501405005}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{B5F54F16-A2DB-490A-A06F-5C84C5CE6F24}" = rport=137 | protocol=17 | dir=out | app=system | 
"{C4E5A65E-0043-456D-8306-70C7193F4F29}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{C5F4A146-CE30-4512-913F-E8AEBF9D1800}" = lport=58346 | protocol=17 | dir=in | name=pando media booster | 
"{C8A4CBC3-5ECA-4D73-957D-00E8C433F21D}" = lport=138 | protocol=17 | dir=in | app=system | 
"{F573F369-6A7F-4C15-B1D1-2400F54A0C71}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{F9DACB79-EA42-41C1-A93A-0E162A00739F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{FC883D8D-D3D7-4BEB-9549-09CD1703BF65}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0065AB62-3EAE-496B-8DD7-8E176FE7E435}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe | 
"{07EE8AEB-6C3C-4242-9882-8E706D82CF0B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{0E1FA946-C3DB-4401-80EF-7E52BC186FA1}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{105E8219-54BD-4001-BE4A-6A0AB350599F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe | 
"{172ACB66-7355-4E1D-937B-C89FF51C0D7F}" = protocol=6 | dir=in | app=c:\spiele\steam\steam.exe | 
"{172F4832-8ED8-43BD-BCB3-469CE9D9C901}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{17B31E01-5339-4E5F-B264-C6768FCED6B8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe | 
"{190969D8-FABA-418C-8066-5DC584ED5860}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{191C2040-2FFB-4180-81DB-8E882CAE698C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{22114C97-A0DD-4C8E-B754-7CA1515AD875}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{24F49438-94D2-4188-A166-578188F2E2BE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rose online\wplauncher.exe | 
"{2590FDFA-BA75-42E9-A848-BBFAB4EA5362}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 
"{28560045-A8E9-4353-94E9-9BF0E65CB215}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{306116EE-8DB7-4C1E-BBB6-2BA7B8DC4DA9}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{3068775F-5B0E-4EF3-B7FC-1298F035AD77}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{35D3D48C-BDD6-450C-B4AF-88B971BAA8A9}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{36BF908D-4AB7-454E-B374-927AFCB6EFF7}" = dir=in | app=c:\program files\eslwire\wire.exe | 
"{38DB0367-C4A9-4D01-AA44-D31F9C4822C5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{3A4EDF72-2E10-4B95-AE2C-F3D909D58EEE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe | 
"{3AD8FA80-18D9-4E6D-9FFE-23000188755C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe | 
"{42B88948-B014-4DEC-8E3B-F6DA492C5B59}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{4A6C810D-95E3-464A-B467-7BE5A54256D0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe | 
"{5027278A-BFB5-41D1-85A6-C63F29CFAD54}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{57780257-1C6B-4C66-AC62-E49C18808628}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3.exe | 
"{59B66EE0-9603-4020-A120-F5FB27F3C4E1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{5D124B33-AB5D-4A75-B84B-84283C71FB6F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | 
"{5D815110-B0AF-4CA3-85D9-F9E6C6C62104}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\bin\sdklauncher.exe | 
"{5FCD55F4-6F3E-4D8E-8619-9773BFC03133}" = protocol=6 | dir=in | app=c:\users\public\games\runic games\torchlight 2\tl2.runic.launcher.exe | 
"{61BB661F-A64F-4905-9D1E-848EAEEDC1C3}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | 
"{6204ABB0-BF95-450F-B630-802492A0758D}" = protocol=17 | dir=in | app=c:\users\public\games\runic games\torchlight 2\torchlight2.exe | 
"{65667721-E906-4CFE-A39F-47A67BFC9DA7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe | 
"{663E5A66-8B7B-4550-93C8-286E11798993}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{67083C86-BDEF-47F0-A41B-7726F7708418}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{719984BF-DDFA-4981-BB92-61A3F20A9884}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{774F1D86-BC32-4DA0-BB57-05AE4793DEB2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{77700E0C-8DDF-4E45-BA59-BF1FA37A36E6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\bin\sdklauncher.exe | 
"{80418D4E-9B96-4237-AAA9-BA71681BA4A4}" = protocol=6 | dir=out | app=system | 
"{8B76FC3D-F4A6-4903-9556-07A07A8399EF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{8D06EA5A-B6A4-4B54-A41D-C9CB780D0D01}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | 
"{8D73B0AE-2EA9-4A07-8D57-C0F794C290D6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\bin\sdklauncher.exe | 
"{8DE5DC92-C3AA-4AF9-9ECA-494CE4050514}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{9198722A-B8D8-416E-B225-C41EF9B160C4}" = protocol=58 | dir=in | app=system | 
"{941C68D3-77A7-4E51-9374-3CDDB568DE1E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 
"{98CDE2F5-E3BD-49F6-8A7D-7228802EC061}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{9934840B-950C-460C-9DAC-29FF63485E5E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{9B2A9893-8AAE-43D4-BF98-24918E2B4550}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe | 
"{9F326DB7-71A9-4D29-B222-45722400B761}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{A3948AAB-FAAE-4341-BE16-FF3B16FBF785}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{A4B8179F-B0B3-427D-A2CD-FD658DB33155}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{A9473783-80FF-41A6-AE06-B0A05B634FEC}" = protocol=17 | dir=in | app=c:\spiele\world of warcraft\launcher.patch.exe | 
"{ABDA658D-1397-46DC-8C23-22E7C3DBFC93}" = protocol=6 | dir=in | app=c:\spiele\steam\steamapps\mkyrockt\counter-strike source\hl2.exe | 
"{AD188A4D-CA68-45A9-B142-E96AE54E630A}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.7\icq.exe | 
"{B09F1766-7834-47C7-B722-A779C3F03C0A}" = protocol=6 | dir=in | app=c:\users\public\games\runic games\torchlight 2\torchlight2.exe | 
"{B13A4F55-9C7F-4F23-A0C2-0C8BF0EE2A6F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{B19B3109-C913-4F2D-9FDA-AA1537C68D03}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | 
"{B268A16B-D26A-41C6-A9E3-4F1D94A0D51C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\football superstars\patchbootstrap.exe | 
"{B2AB7C83-F0C3-4CA2-80E7-3E2435BB8DD6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{B318C361-4A5B-40F7-8D08-D32FE864702F}" = protocol=17 | dir=in | app=c:\spiele\steam\steamapps\mkyrockt\counter-strike source\hl2.exe | 
"{B3379AF0-DF82-4180-A018-C0DEDB9F4528}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | 
"{B3C79A66-548F-474C-9FCB-06953C7CF2A0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\mkyrockt\counter-strike source\hl2.exe | 
"{B9F5BC71-C28E-4077-8956-08DE27996EB6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | 
"{BC5D82E5-02C5-4177-AD4A-3E521BBDB2C3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{BD347549-0B0F-4C5D-A3B6-181509B55777}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{C09C2F64-00D8-4149-9C61-3FB16F99CA10}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{C0DADAAD-433A-420F-831F-669F05289F3A}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.7\icq.exe | 
"{C3E66B6D-BC91-401F-A66F-6B4FAD7730A2}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{C7305666-9EE8-4686-B84F-A8AE3AC16989}" = protocol=6 | dir=in | app=c:\spiele\world of warcraft\launcher.patch.exe | 
"{C7EDB4C1-78DC-4B0D-A9EF-1BCD6018EC14}" = protocol=17 | dir=in | app=c:\spiele\steam\steam.exe | 
"{C9C8D3A3-B985-4591-AB3B-452489074313}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe | 
"{CBD1D279-A503-433E-A856-62204A96F56F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{CC38E07D-8846-457B-BFAB-6B560342AE69}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{CC6FCE2F-2C93-427E-926C-7D4765F2AACC}" = protocol=17 | dir=in | app=c:\users\public\games\runic games\torchlight 2\tl2.runic.launcher.exe | 
"{CD9F61F1-93BC-43F4-BF46-E20CE8A01944}" = dir=in | app=c:\users\mky\appdata\local\facebook\video\skype\facebookvideocalling.exe | 
"{D09C2B6B-82AB-47BB-A969-2C0CB1BB12A0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DE8C7258-B2FF-452A-8257-1F02F3B0EC05}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\mkyrockt\counter-strike source\hl2.exe | 
"{E11D0A7E-E08B-40DC-B318-CB5B7C546BCB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{E3DFA8A1-07ED-40E1-9828-561CA21AE8AD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | 
"{E49F546E-3077-44CF-9F64-22FE94C84C89}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe | 
"{E624A546-45A2-4744-AF0B-6527949AA7EA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rose online\wplauncher.exe | 
"{ED51FF24-2E5C-4E43-B43D-84B14E123BD4}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{EDC60BB3-F2E1-4A60-B102-9C2848766206}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.7\icq.exe | 
"{F05B0AD3-E21F-439E-932D-CCEBA6BC728E}" = dir=out | app=c:\program files\eslwire\wire.exe | 
"{F69C7F18-5F59-4ABB-997C-7D3741EDDFDB}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.7\icq.exe | 
"{F7D3A3C7-5075-415A-A0E6-A6A3F18A33C1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{F7F0C7F7-7536-49A4-A1D6-0C19803380D6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\football superstars\patchbootstrap.exe | 
"{FAE9A524-6F59-4926-A859-CC12FA21438C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\bin\sdklauncher.exe | 
"{FBB29DC2-17F2-481B-AD26-723F694388A0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3.exe | 
"{FEC7EDE6-4EB2-463D-8739-F5F31676DBCD}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"TCP Query User{19B69521-5620-4764-901B-52C3D3FFFBD8}C:\spiele\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\spiele\world of warcraft\launcher.exe | 
"TCP Query User{304BB03E-C058-4DD0-8BD0-014E336E592C}C:\users\public\games\runic games\torchlight 2\tl2.runic.launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\runic games\torchlight 2\tl2.runic.launcher.exe | 
"TCP Query User{434A499A-33D2-47A3-8EB0-8E958C47CD9A}C:\spiele\electronic arts\bioware\star wars-the old republic\launcher.exe" = protocol=6 | dir=in | app=c:\spiele\electronic arts\bioware\star wars-the old republic\launcher.exe | 
"TCP Query User{56FCA1F7-3DF4-4DD1-83F4-1D87C0F2AA0D}C:\program files (x86)\heroes of newerth\hon.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of newerth\hon.exe | 
"TCP Query User{643C61C4-5089-4CBA-8BDE-0B801EA7E7E9}C:\spiele\electronic arts\bioware\star wars-the old republic\launcher.exe" = protocol=6 | dir=in | app=c:\spiele\electronic arts\bioware\star wars-the old republic\launcher.exe | 
"TCP Query User{732C023D-AC26-4DD0-A659-191C56755B60}C:\users\mky\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\mky\appdata\roaming\spotify\spotify.exe | 
"TCP Query User{7D514DAA-259C-4865-A238-38650A132D20}C:\users\mky\downloads\sro_full_client_downloader_bmt_v7.exe" = protocol=6 | dir=in | app=c:\users\mky\downloads\sro_full_client_downloader_bmt_v7.exe | 
"TCP Query User{93E7CF86-CE23-46E0-AD41-9B63D56D1257}C:\users\mky\downloads\psro_full_client_downloader_v3(1).exe" = protocol=6 | dir=in | app=c:\users\mky\downloads\psro_full_client_downloader_v3(1).exe | 
"TCP Query User{AB3AA105-0F8E-4230-946A-13F586B6E053}C:\users\mky\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\mky\appdata\roaming\spotify\spotify.exe | 
"TCP Query User{B16F071A-0F14-4B30-88EB-1E2E70C92C7B}C:\users\mky\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\mky\appdata\local\akamai\netsession_win.exe | 
"TCP Query User{CD5C2386-B6BB-4105-85A7-8C458B837CEB}C:\spiele\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\spiele\warcraft iii\war3.exe | 
"TCP Query User{CF947D6B-3B3D-4C2D-8D9F-BCCCF5337AC2}C:\spiele\heroes of newerth\hon.exe" = protocol=6 | dir=in | app=c:\spiele\heroes of newerth\hon.exe | 
"TCP Query User{E2B20030-2EC4-4BB6-AA5A-425040828A3D}C:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe | 
"TCP Query User{EABFC875-FEC3-467C-B0BF-4A014CE18C81}C:\users\mky\downloads\psro_full_client_downloader_v3.exe" = protocol=6 | dir=in | app=c:\users\mky\downloads\psro_full_client_downloader_v3.exe | 
"TCP Query User{F075032D-0DCC-4AEF-BE5F-EDF3B2540E00}C:\users\mky\downloads\psror_full_client_downloader_v3(1).exe" = protocol=6 | dir=in | app=c:\users\mky\downloads\psror_full_client_downloader_v3(1).exe | 
"TCP Query User{F2203345-E8DF-49E8-8724-C43197F04CD0}C:\users\mky\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\mky\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{066F79F4-F48F-45AB-9318-AA2B7C0E30C6}C:\users\mky\downloads\psro_full_client_downloader_v3(1).exe" = protocol=17 | dir=in | app=c:\users\mky\downloads\psro_full_client_downloader_v3(1).exe | 
"UDP Query User{0D1562DC-77D9-407F-88C2-BBB34A2DB0AA}C:\users\mky\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\mky\appdata\roaming\spotify\spotify.exe | 
"UDP Query User{271AB538-D5C9-4025-BC67-BD2B791737EE}C:\users\mky\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\mky\appdata\roaming\spotify\spotify.exe | 
"UDP Query User{323134AD-52B4-4302-B4B9-79EE363F0187}C:\users\public\games\runic games\torchlight 2\tl2.runic.launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\runic games\torchlight 2\tl2.runic.launcher.exe | 
"UDP Query User{3284D84F-B4A2-4C6D-8F79-45B1482CE168}C:\program files (x86)\heroes of newerth\hon.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of newerth\hon.exe | 
"UDP Query User{360ED17B-5EC7-4BAA-B5BD-65D42B6F5EC2}C:\users\mky\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\mky\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{61965A92-BC82-42BF-8773-55815A176CB5}C:\spiele\electronic arts\bioware\star wars-the old republic\launcher.exe" = protocol=17 | dir=in | app=c:\spiele\electronic arts\bioware\star wars-the old republic\launcher.exe | 
"UDP Query User{78F733CC-7B71-4BCF-8883-A8BF61513925}C:\users\mky\downloads\psror_full_client_downloader_v3(1).exe" = protocol=17 | dir=in | app=c:\users\mky\downloads\psror_full_client_downloader_v3(1).exe | 
"UDP Query User{8767E5A9-1D49-42EF-A16A-1C431798BE7A}C:\users\mky\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\mky\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{9324D04F-5E29-45E1-B88F-AF09A6414AD6}C:\spiele\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\spiele\world of warcraft\launcher.exe | 
"UDP Query User{942DD162-2D35-4F46-9740-14B0A5B78A1B}C:\users\mky\downloads\psro_full_client_downloader_v3.exe" = protocol=17 | dir=in | app=c:\users\mky\downloads\psro_full_client_downloader_v3.exe | 
"UDP Query User{C0C7B1B4-DB63-4941-98BA-A5DA75DCB978}C:\spiele\electronic arts\bioware\star wars-the old republic\launcher.exe" = protocol=17 | dir=in | app=c:\spiele\electronic arts\bioware\star wars-the old republic\launcher.exe | 
"UDP Query User{C3451945-8502-46AD-B058-2CCCD56E1E00}C:\users\mky\downloads\sro_full_client_downloader_bmt_v7.exe" = protocol=17 | dir=in | app=c:\users\mky\downloads\sro_full_client_downloader_bmt_v7.exe | 
"UDP Query User{DFB1CAFF-8E20-4205-B11C-71BF528726FB}C:\spiele\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\spiele\warcraft iii\war3.exe | 
"UDP Query User{E0940D5C-A540-494A-BA99-1EB0D9951E62}C:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe | 
"UDP Query User{F2CF5973-CDFC-4BE1-B07E-F7D0DDD1A58C}C:\spiele\heroes of newerth\hon.exe" = protocol=17 | dir=in | app=c:\spiele\heroes of newerth\hon.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC4
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{AB7F4312-8037-4EBF-9D0F-5513CDFD534C}" = ATI Catalyst Install Manager
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"ESL Wire_is1" = ESL Wire 1.11.1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
"WinRAR archiver" = WinRAR 4.10 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{049FF5E4-EB02-4c42-8DB0-226E2F7A9E53}" = Torchlight 2
"{0ACC2993-2058-4BE7-9A92-9DCDAA9B3412}" = LogMeIn Hamachi
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 25
"{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE}" = ICQ7.7
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Deutsch
"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C3592426-531E-4110-911D-BFECE2CE284C}" = osu!
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Akamai" = Akamai NetSession Interface
"AudioCS" = Creative-Audiokonsole
"Avira AntiVir Desktop" = Avira Free Antivirus
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"DivX Setup" = DivX-Setup
"ESE Account Manager" = ESE Account Manager 2.0.0.2
"hon" = Heroes of Newerth
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
"Mozilla Firefox 22.0 (x86 de)" = Mozilla Firefox 22.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Notepad++" = Notepad++
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"PunkBusterSvc" = PunkBuster Services
"RaidCall" = RaidCall
"Silkroad" = Silkroad
"SilkroadR" = SilkroadR
"SimpleScreenshot" = SimpleScreenshot 1.40
"Steam App 205790" = Dota 2 Test
"Steam App 219870" = Football Superstars
"Steam App 220240" = Far Cry® 3
"Steam App 240" = Counter-Strike: Source
"Steam App 49520" = Borderlands 2
"Steam App 570" = Dota 2
"Steam App 730" = Counter-Strike: Global Offensive
"Steam App 745" = Counter-Strike: Global Offensive - SDK
"StepMania" = StepMania (remove only)
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Uplay" = Uplay
"VLC media player" = VLC media player 1.1.11
"WinLiveSuite" = Windows Live Essentials
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Spotify" = Spotify
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 02.07.2013 09:13:57 | Computer Name = mKy-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\Steam\steamapps\common\football superstars\DevWidgetsD_msvcrtd.dll". Fehler
 in Manifest- oder Richtliniendatei "c:\program files (x86)\Steam\steamapps\common\football
 superstars\Microsoft.VC90.CRT.MANIFEST" in Zeile  4.  Die im Manifest gefundene Komponenten-ID
 stimmt nicht mit der ID der angeforderten Komponente überein.  Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition:
 Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden
 Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 02.07.2013 09:13:57 | Computer Name = mKy-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\Steam\steamapps\common\football superstars\DevWidgetsR_msvcrt.dll". Fehler
 in Manifest- oder Richtliniendatei "c:\program files (x86)\Steam\steamapps\common\football
 superstars\Microsoft.VC90.CRT.MANIFEST" in Zeile  4.  Die im Manifest gefundene Komponenten-ID
 stimmt nicht mit der ID der angeforderten Komponente überein.  Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition:
 Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden
 Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 02.07.2013 22:58:44 | Computer Name = mKy-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 03.07.2013 05:35:19 | Computer Name = mKy-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 05.07.2013 20:09:00 | Computer Name = mKy-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 05.07.2013 20:11:50 | Computer Name = mKy-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002
Description = Der Textzeichenfolgenwert zur Beschreibung des Leistungsindikators
 in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge
 ist " ". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte
 Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen
 Indexwerte enthalten.
 
Error - 05.07.2013 20:40:09 | Computer Name = mKy-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\Steam\steamapps\common\football superstars\DevWidgetsD_msvcrtd.dll". Fehler
 in Manifest- oder Richtliniendatei "c:\program files (x86)\Steam\steamapps\common\football
 superstars\Microsoft.VC90.CRT.MANIFEST" in Zeile  4.  Die im Manifest gefundene Komponenten-ID
 stimmt nicht mit der ID der angeforderten Komponente überein.  Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition:
 Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden
 Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 05.07.2013 20:40:09 | Computer Name = mKy-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\Steam\steamapps\common\football superstars\DevWidgetsR_msvcrt.dll". Fehler
 in Manifest- oder Richtliniendatei "c:\program files (x86)\Steam\steamapps\common\football
 superstars\Microsoft.VC90.CRT.MANIFEST" in Zeile  4.  Die im Manifest gefundene Komponenten-ID
 stimmt nicht mit der ID der angeforderten Komponente überein.  Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition:
 Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden
 Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 07.07.2013 14:33:22 | Computer Name = mKy-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 07.07.2013 14:36:23 | Computer Name = mKy-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002
Description = Der Textzeichenfolgenwert zur Beschreibung des Leistungsindikators
 in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge
 ist " ". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte
 Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen
 Indexwerte enthalten.
 
[ System Events ]
Error - 14.12.2012 00:38:41 | Computer Name = mKy-PC | Source = Microsoft Antimalware | ID = 2001
Description = Beim Aktualisieren der Signaturen wurde von %%860 ein Fehler festgestellt.

	Neue
 Signaturversion:      Vorherige Signaturversion: 1.141.1697.0     Aktualisierungsquelle: 
%%859     Aktualisierungsphase: %%852     Quellpfad: hxxp://www.microsoft.com     Signaturtyp: 
%%800     Aktualisierungstyp: %%803     Benutzer: NT-AUTORITÄT\SYSTEM     Aktuelle Modulversion:
      Vorherige Modulversion: 1.1.9002.0     Fehlercode: 0x8024402c     Fehlerbeschreibung: Unerwartetes
 Problem bei der Überprüfung auf Updates. Informationen zum Installieren von Updates
 oder zur Problembehandlung finden Sie unter "Hilfe und Support". 
 
Error - 14.12.2012 13:48:17 | Computer Name = mKy-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   cdrom
 
Error - 15.12.2012 21:28:54 | Computer Name = mKy-PC | Source = Microsoft Antimalware | ID = 2001
Description = Beim Aktualisieren der Signaturen wurde von %%860 ein Fehler festgestellt.

	Neue
 Signaturversion:      Vorherige Signaturversion: 1.141.1942.0     Aktualisierungsquelle: 
%%859     Aktualisierungsphase: %%852     Quellpfad: hxxp://www.microsoft.com     Signaturtyp: 
%%800     Aktualisierungstyp: %%803     Benutzer: NT-AUTORITÄT\SYSTEM     Aktuelle Modulversion:
      Vorherige Modulversion: 1.1.9002.0     Fehlercode: 0x8024402c     Fehlerbeschreibung: Unerwartetes
 Problem bei der Überprüfung auf Updates. Informationen zum Installieren von Updates
 oder zur Problembehandlung finden Sie unter "Hilfe und Support". 
 
Error - 18.12.2012 18:20:06 | Computer Name = mKy-PC | Source = Service Control Manager | ID = 7030
Description = Der Dienst "LogMeIn Hamachi Tunneling Engine" ist als interaktiver
 Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive
 Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
 
Error - 18.12.2012 18:20:06 | Computer Name = mKy-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 LogMeIn Hamachi Tunneling Engine erreicht.
 
Error - 18.12.2012 18:20:06 | Computer Name = mKy-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "LogMeIn Hamachi Tunneling Engine" wurde aufgrund folgenden
 Fehlers nicht gestartet:   %%1053
 
Error - 18.12.2012 18:20:36 | Computer Name = mKy-PC | Source = Service Control Manager | ID = 7030
Description = Der Dienst "LogMeIn Hamachi Tunneling Engine" ist als interaktiver
 Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive
 Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
 
Error - 18.12.2012 18:20:36 | Computer Name = mKy-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 LogMeIn Hamachi Tunneling Engine erreicht.
 
Error - 18.12.2012 18:20:36 | Computer Name = mKy-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "LogMeIn Hamachi Tunneling Engine" wurde aufgrund folgenden
 Fehlers nicht gestartet:   %%1053
 
Error - 18.12.2012 18:38:56 | Computer Name = mKy-PC | Source = bowser | ID = 8003
Description = 
 
 
< End of report >
         
--- --- ---



OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 07.07.2013 20:45:25 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\mKy\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,95 Gb Total Physical Memory | 5,86 Gb Available Physical Memory | 73,79% Memory free
15,89 Gb Paging File | 13,65 Gb Available in Paging File | 85,91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,66 Gb Total Space | 210,85 Gb Free Space | 45,28% Space Free | Partition Type: NTFS
 
Computer Name: MKY-PC | User Name: mKy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.07.07 20:44:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\mKy\Desktop\OTL.exe
PRC - [2013.07.07 20:33:28 | 004,640,768 | ---- | M] (Spotify Ltd) -- C:\Users\mKy\AppData\Roaming\Spotify\Spotify.exe
PRC - [2013.07.03 04:59:13 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013.06.28 14:02:06 | 002,255,184 | ---- | M] (LogMeIn Inc.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2013.06.05 01:01:52 | 004,489,472 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe
PRC - [2013.01.10 11:05:32 | 003,093,624 | ---- | M] () -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
PRC - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.12.12 23:08:12 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012.10.02 14:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.08.08 20:01:11 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2011.01.17 19:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 19:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010.03.18 20:17:48 | 000,019,456 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\CtHelper.exe
PRC - [2010.02.12 11:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
PRC - [2008.02.09 11:00:30 | 002,255,360 | ---- | M] (Mirko Böer) -- C:\Program Files (x86)\SSS\SimpleScreenshot.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2013.07.07 20:33:22 | 024,985,600 | ---- | M] () -- C:\Users\mKy\AppData\Roaming\Spotify\Data\libcef.dll
MOD - [2013.07.03 04:58:48 | 003,285,912 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013.01.10 11:05:32 | 003,093,624 | ---- | M] () -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
MOD - [2012.03.04 23:55:40 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2011.07.29 01:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013.07.03 04:59:12 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.06.28 14:02:04 | 002,470,736 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2013.05.27 00:30:12 | 005,127,200 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2013.03.15 18:29:10 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.03.01 12:11:32 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.01.27 12:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013.01.27 12:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.12.12 23:08:12 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012.10.03 00:21:00 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.10.02 14:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.01.28 20:34:27 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2012.01.24 14:50:46 | 000,168,864 | ---- | M] () [Auto | Running] -- C:\Programme\Common Files\WireHelpSvc.exe -- (WireHelpSvc)
SRV - [2011.03.28 22:11:06 | 002,292,096 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.12 11:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2013.01.20 16:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012.07.03 17:25:16 | 000,189,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2012.05.02 15:24:12 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012.04.27 10:20:04 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.04.25 00:32:27 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.24 14:50:38 | 000,147,472 | ---- | M] (<Turtle Entertainment>) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\ESLWireACD.sys -- (ESLWireAC)
DRV:64bit: - [2012.01.24 14:50:38 | 000,025,528 | ---- | M] (Turtle Entertainment GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ESLvnic.sys -- (ESLvnic1)
DRV:64bit: - [2011.03.21 15:22:06 | 000,452,200 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.03.04 07:46:20 | 000,078,976 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2011.03.04 07:46:20 | 000,038,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2011.02.24 11:30:50 | 000,389,608 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci)
DRV:64bit: - [2011.02.24 11:30:50 | 000,126,952 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmthub3.sys -- (asmthub3)
DRV:64bit: - [2010.12.16 06:06:46 | 000,047,232 | R--- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2010.11.25 05:27:42 | 000,120,408 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.09.30 21:00:06 | 000,180,736 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010.09.30 21:00:06 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010.03.18 21:52:18 | 000,295,000 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\haP17v2k.sys -- (hap17v2k)
DRV:64bit: - [2010.03.18 21:52:10 | 000,259,672 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\haP16v2k.sys -- (hap16v2k)
DRV:64bit: - [2010.03.18 21:52:02 | 001,360,984 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ha10kx2k.sys -- (ha10kx2k)
DRV:64bit: - [2010.03.18 21:51:50 | 000,147,544 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\emupia2k.sys -- (emupia)
DRV:64bit: - [2010.03.18 21:51:34 | 000,290,392 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV:64bit: - [2010.03.18 21:51:26 | 000,016,984 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV:64bit: - [2010.03.18 21:51:18 | 000,221,272 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctoss2k.sys -- (ossrv)
DRV:64bit: - [2010.03.18 21:50:52 | 000,866,264 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctaud2k.sys -- (ctaud2k)
DRV:64bit: - [2010.03.18 21:50:42 | 000,580,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctac32k.sys -- (ctac32k)
DRV:64bit: - [2010.03.18 21:40:10 | 000,141,912 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTERFXFX.sys -- (CTERFXFX.SYS)
DRV:64bit: - [2010.03.18 21:40:10 | 000,141,912 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTERFXFX.sys -- (CTERFXFX)
DRV:64bit: - [2010.03.18 21:40:02 | 000,681,048 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTSBLFX.sys -- (CTSBLFX.SYS)
DRV:64bit: - [2010.03.18 21:40:02 | 000,681,048 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTSBLFX.sys -- (CTSBLFX)
DRV:64bit: - [2010.03.18 21:39:54 | 000,706,648 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTAUDFX.sys -- (CTAUDFX.SYS)
DRV:64bit: - [2010.03.18 21:39:54 | 000,706,648 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTAUDFX.sys -- (CTAUDFX)
DRV:64bit: - [2010.03.18 21:39:44 | 000,158,808 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\COMMONFX.sys -- (COMMONFX.SYS)
DRV:64bit: - [2010.03.18 21:39:44 | 000,158,808 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\COMMONFX.sys -- (COMMONFX)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2007.04.10 05:17:22 | 000,123,688 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\CTHWIUT.DLL -- (CTHWIUT.DLL)
DRV:64bit: - [2007.04.10 05:17:00 | 000,252,712 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\CT20XUT.DLL -- (CT20XUT.DLL)
DRV:64bit: - [2007.04.10 05:16:20 | 001,571,112 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\CTEXFIFX.DLL -- (CTEXFIFX.DLL)
DRV:64bit: - [2007.04.10 05:15:44 | 000,363,304 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\CTEDSPSY.DLL -- (CTEDSPSY.DLL)
DRV:64bit: - [2007.04.10 05:15:10 | 000,190,248 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\CTEDSPIO.DLL -- (CTEDSPIO.DLL)
DRV:64bit: - [2007.04.10 05:13:38 | 000,321,832 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\CTEDSPFX.DLL -- (CTEDSPFX.DLL)
DRV:64bit: - [2007.04.10 05:13:08 | 000,219,432 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\CTEAPSFX.DLL -- (CTEAPSFX.DLL)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.avira.com/?l=dis&o=APN10395&gct=hp&dc=EU&locale=de_DE
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3C75F07A-7838-4B12-8017-932CA5A8F50F}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=80f45a53-c7f6-45d2-a543-782228bf2a8e&apn_sauid=0B2E63F2-E13A-479C-94A7-F4E2BE1F5E1F
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@raidcall.en/RCplugin: C:\Users\mKy\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\@raidcall.kr/RCplugin: C:\Users\mKy\AppData\Roaming\RCKR\plugins\nprcplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\mKy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.08.05 16:16:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.07.03 04:58:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.07.03 04:58:44 | 000,000,000 | ---D | M]
 
[2012.01.28 20:50:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\mKy\AppData\Roaming\mozilla\Extensions
[2013.07.04 01:01:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\mKy\AppData\Roaming\mozilla\Firefox\Profiles\wbur3zd3.default-1372892069866\extensions
[2013.07.04 01:01:16 | 000,870,680 | ---- | M] () (No name found) -- C:\Users\mKy\AppData\Roaming\mozilla\firefox\profiles\wbur3zd3.default-1372892069866\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.07.03 04:58:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\Extensions
[2013.07.03 04:58:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2013.07.03 04:59:13 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AsioThk32Reg] C:\Windows\SysWow64\ctasio.dll (Creative Technology Ltd)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CTHelper] C:\Windows\SysWow64\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [SimpleScreenshot] C:\PROGRA~2\SSS\SIMPLESCREENSHOT.EXE (Mirko Böer)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent File not found
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [Spotify] C:\Users\mKy\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\mKy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - Startup: C:\Users\mKy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe (ICQ, LLC.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F07C9AEF-E6C0-4ED7-907C-C2CB0AF89D08}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.07.07 20:44:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\mKy\Desktop\OTL.exe
[2013.07.07 19:41:06 | 000,000,000 | ---D | C] -- C:\Users\mKy\Desktop\RK_Quarantine
[2013.07.07 19:38:44 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2013.07.07 19:38:09 | 000,208,216 | ---- | C] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\31978637.sys
[2013.07.06 02:08:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2013.07.06 02:08:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
[2013.07.06 02:08:24 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.07.05 07:52:09 | 000,000,000 | ---D | C] -- C:\Users\mKy\AppData\Local\Programs
[2013.07.04 00:54:32 | 000,000,000 | ---D | C] -- C:\Users\mKy\Desktop\Alte Firefox-Daten
[2013.07.03 04:58:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.06.27 23:25:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Silkroad
[2013.06.27 22:16:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SilkroadR
[2013.06.27 21:13:05 | 005,127,200 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\SysWow64\GameMon.des
[2013.06.27 21:12:47 | 000,004,682 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\SysWow64\npptNT2.sys
[2013.06.27 21:12:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\INCA Shared
[2013.06.27 20:50:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Overwolf
[2013.06.27 20:49:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Overwolf
[2013.06.27 20:49:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Overwolf
[2013.06.27 20:44:47 | 000,000,000 | ---D | C] -- C:\Users\mKy\AppData\Local\Overwolf
[2013.06.27 20:35:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Games-Masters.com
[2012.12.08 18:58:42 | 001,178,624 | ---- | C] (CPUID) -- C:\Users\mKy\AppData\Roaming\siw_sdk.dll
 
========== Files - Modified Within 30 Days ==========
 
[2013.07.07 20:44:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\mKy\Desktop\OTL.exe
[2013.07.07 20:44:08 | 000,000,000 | ---- | M] () -- C:\Users\mKy\defogger_reenable
[2013.07.07 20:42:59 | 000,050,477 | ---- | M] () -- C:\Users\mKy\Desktop\Defogger.exe
[2013.07.07 20:39:15 | 000,035,088 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.07 20:39:15 | 000,035,088 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.07 20:31:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.07 20:31:29 | 2104,512,511 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.07 20:29:20 | 000,034,240 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000007-00000000-00000005-00001102-00000004-20021102}.rfx
[2013.07.07 20:29:20 | 000,034,240 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000007-00000000-00000005-00001102-00000004-20021102}.rfx
[2013.07.07 20:29:20 | 000,030,528 | ---- | M] () -- C:\Windows\SysNative\BMXCtrlState-{00000007-00000000-00000005-00001102-00000004-20021102}.rfx
[2013.07.07 20:29:20 | 000,030,528 | ---- | M] () -- C:\Windows\SysNative\BMXBkpCtrlState-{00000007-00000000-00000005-00001102-00000004-20021102}.rfx
[2013.07.07 20:29:20 | 000,011,564 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000007-00000000-00000005-00001102-00000004-20021102}.rfx
[2013.07.07 19:38:10 | 000,208,216 | ---- | M] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\31978637.sys
[2013.07.07 18:39:01 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000UA.job
[2013.07.07 00:39:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000Core.job
[2013.07.05 07:52:23 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2013.07.01 16:00:10 | 506,566,888 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013.06.30 00:27:09 | 000,301,832 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.06.27 23:28:56 | 000,001,889 | ---- | M] () -- C:\Users\mKy\Desktop\Silkroad.lnk
[2013.06.27 22:20:01 | 000,001,898 | ---- | M] () -- C:\Users\mKy\Desktop\SilkroadR.lnk

 
========== Files Created - No Company Name ==========
 
[2013.07.07 20:44:08 | 000,000,000 | ---- | C] () -- C:\Users\mKy\defogger_reenable
[2013.07.07 20:42:58 | 000,050,477 | ---- | C] () -- C:\Users\mKy\Desktop\Defogger.exe
[2013.06.27 22:20:01 | 000,001,898 | ---- | C] () -- C:\Users\mKy\Desktop\SilkroadR.lnk
[2013.06.27 22:12:25 | 000,001,889 | ---- | C] () -- C:\Users\mKy\Desktop\Silkroad.lnk
[2013.06.27 21:12:47 | 000,005,174 | ---- | C] () -- C:\Windows\SysWow64\nppt9x.vxd
[2012.12.12 23:08:14 | 000,281,688 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.12.12 23:08:12 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.12.03 15:34:58 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.12.03 15:34:58 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2012.02.17 17:35:39 | 1292,652,314 | ---- | C] () -- C:\Users\mKy\SilkroadOnline_GlobalOfficial_v1_346_LEGEND_8.exe
[2012.01.29 20:20:38 | 000,168,864 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe
[2012.01.29 02:59:23 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2012.01.29 02:59:18 | 000,023,866 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2012.01.28 20:33:54 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2012.01.28 20:33:54 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.01.04 12:44:25 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.01.04 10:59:38 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013.05.28 05:09:26 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\Babylon
[2013.05.06 03:28:16 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\Downloaded Installations
[2013.04.02 09:32:06 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\ICQ
[2013.01.26 09:28:18 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\LolClient
[2012.12.12 12:04:43 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\Notepad++
[2013.05.28 05:09:06 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\OpenCandy
[2012.03.04 23:55:57 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\OpenOffice.org
[2013.06.07 01:40:07 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\raidcall
[2012.11.30 15:40:58 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\RCKR
[2013.06.08 09:24:12 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\SimpleScreenshot
[2013.07.07 20:38:30 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\Spotify
[2013.07.04 00:47:04 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\TS3Client
[2012.12.08 19:01:16 | 000,000,000 | ---D | M] -- C:\Users\mKy\AppData\Roaming\TuneUp Software
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 5120 bytes -> C:\Users\Public\Documents\desktop.ini:gs5sys
@Alternate Data Stream - 5120 bytes -> C:\ProgramData:gs5sys
@Alternate Data Stream - 4096 bytes -> C:\Users\mKy\Documents\desktop.ini:gs5sys

< End of report >
         
--- --- ---



Vielen Dank für Ihre Hilfe!

Geändert von mKy (07.07.2013 um 20:03 Uhr)

Alt 07.07.2013, 20:31   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 07.07.2013, 20:56   #3
mKy
 
Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Hey, vielen Dank für die schnelle Antwort. Hier die Logs:


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013
Ran by mKy (administrator) on 07-07-2013 21:47:35
Running from C:\Users\mKy\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files\Common Files\WireHelpSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Akamai Technologies, Inc.) C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CtHelper.exe
(Mirko Böer) C:\Program Files (x86)\SSS\SimpleScreenshot.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Spotify Ltd) C:\Users\mKy\AppData\Roaming\Spotify\Spotify.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11613288 2010-11-19] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-21] (Microsoft Corporation)
HKCU\...\Run: [Akamai NetSession Interface] "C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe" [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [Facebook Update] "C:\Users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-08-01] (Facebook Inc.)
HKCU\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-01-10] ()
HKCU\...\Run: [Spotify Web Helper] "C:\Users\mKy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1104384 2013-07-07] (Spotify Ltd)
HKCU\...\Run: [Spotify] "C:\Users\mKy\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [4640768 2013-07-07] (Spotify Ltd)
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18680424 2013-05-08] (Skype Technologies S.A.)
HKCU\...\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent [x]
HKLM-x32\...\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL [x]
HKLM-x32\...\Run: [CTHelper] CTHELPER.EXE [19456 2010-03-18] (Creative Technology Ltd)
HKLM-x32\...\Run: [SimpleScreenshot] C:\PROGRA~2\SSS\SIMPLESCREENSHOT.EXE [2255360 2008-02-09] (Mirko Böer)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-29] ()
HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [2255184 2013-06-28] (LogMeIn Inc.)
Startup: C:\Users\mKy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Search Free: Avira Search Free powered by Ask.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Dell Official Site - The Power To Do More | Dell
SearchScopes: HKCU - {3C75F07A-7838-4B12-8017-932CA5A8F50F} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=80f45a53-c7f6-45d2-a543-782228bf2a8e&apn_sauid=0B2E63F2-E13A-479C-94A7-F4E2BE1F5E1F
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL = 
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\mKy\AppData\Roaming\Mozilla\Firefox\Profiles\wbur3zd3.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @raidcall.en/RCplugin - C:\Users\mKy\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: @raidcall.kr/RCplugin - C:\Users\mKy\AppData\Roaming\RCKR\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\mKy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-02] (Avira Operations GmbH & Co. KG)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWow64\GameMon.des [5127200 2013-05-27] (INCA Internet Co., Ltd.)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-12-12] ()
R2 WireHelpSvc; C:\Program Files\Common Files\WireHelpSvc.exe [168864 2012-01-24] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-04-25] (Avira GmbH)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-04-27] (Avira GmbH)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2012-05-02] (Avira GmbH)
S3 CT20XUT.DLL; C:\Windows\System32\CT20XUT.DLL [252712 2007-04-10] (Creative Technology Ltd.)
S3 CTEAPSFX.DLL; C:\Windows\System32\CTEAPSFX.DLL [219432 2007-04-10] (Creative Technology Ltd)
S3 CTEDSPFX.DLL; C:\Windows\System32\CTEDSPFX.DLL [321832 2007-04-10] (Creative Technology Ltd)
S3 CTEDSPIO.DLL; C:\Windows\System32\CTEDSPIO.DLL [190248 2007-04-10] (Creative Technology Ltd)
S3 CTEDSPSY.DLL; C:\Windows\System32\CTEDSPSY.DLL [363304 2007-04-10] (Creative Technology Ltd)
S3 CTEXFIFX.DLL; C:\Windows\System32\CTEXFIFX.DLL [1571112 2007-04-10] (Creative Technology Ltd.)
S3 CTHWIUT.DLL; C:\Windows\System32\CTHWIUT.DLL [123688 2007-04-10] (Creative Technology Ltd.)
R3 ESLvnic1; C:\Windows\System32\DRIVERS\ESLvnic.sys [25528 2012-01-24] (Turtle Entertainment GmbH)
R2 ESLWireAC; C:\Windows\system32\drivers\ESLWireACD.sys [147472 2012-01-24] (<Turtle Entertainment>)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 ALSysIO; \??\C:\Users\mKy\AppData\Local\Temp\ALSysIO64.sys [x]
S3 COMMONFX.DLL; system32\COMMONFX.DLL [x]
S3 CTAUDFX.DLL; system32\CTAUDFX.DLL [x]
S3 CTERFXFX.DLL; system32\CTERFXFX.DLL [x]
S3 CTSBLFX.DLL; system32\CTSBLFX.DLL [x]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-07 21:46 - 2013-07-07 21:46 - 00000000 ____D C:\FRST
2013-07-07 21:44 - 2013-07-07 21:45 - 01934636 ____A (Farbar) C:\Users\mKy\Desktop\FRST64.exe
2013-07-07 20:51 - 2013-07-07 20:51 - 00087572 ____A C:\Users\mKy\Desktop\Extras.Txt
2013-07-07 20:50 - 2013-07-07 20:50 - 00083088 ____A C:\Users\mKy\Desktop\OTL.Txt
2013-07-07 20:44 - 2013-07-07 20:44 - 00602112 ____A (OldTimer Tools) C:\Users\mKy\Desktop\OTL.exe
2013-07-07 20:44 - 2013-07-07 20:44 - 00000468 ____A C:\Users\mKy\Desktop\defogger_disable.log
2013-07-07 20:44 - 2013-07-07 20:44 - 00000000 ____A C:\Users\mKy\defogger_reenable
2013-07-07 20:42 - 2013-07-07 20:42 - 00050477 ____A C:\Users\mKy\Desktop\Defogger.exe
2013-07-07 19:45 - 2013-07-07 19:45 - 00003495 ____A C:\AdwCleaner[R1].txt
2013-07-07 19:43 - 2013-07-07 19:43 - 00002094 ____A C:\Users\mKy\Desktop\RKreport[0]_S_07072013_194312.txt
2013-07-07 19:41 - 2013-07-07 19:44 - 00000000 ____D C:\Users\mKy\Desktop\RK_Quarantine
2013-07-07 19:38 - 2013-07-07 19:38 - 00208216 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\31978637.sys
2013-07-07 19:38 - 2013-07-07 19:38 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-07-07 19:34 - 2013-07-07 19:36 - 00019385 ____A C:\Users\mKy\Downloads\Result.txt
2013-07-07 19:33 - 2013-07-07 19:33 - 00915456 ____A C:\Users\mKy\Downloads\RogueKiller.exe
2013-07-07 19:28 - 2013-07-07 19:28 - 00760775 ____A (Farbar) C:\Users\mKy\Downloads\MiniToolBox.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\mKy\Downloads\tdsskiller.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 00650027 ____A C:\Users\mKy\Downloads\AdwCleaner.exe
2013-07-06 02:08 - 2013-07-06 02:08 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-07-04 00:54 - 2013-07-04 00:54 - 00000000 ____D C:\Users\mKy\Desktop\Alte Firefox-Daten
2013-07-03 22:15 - 2013-07-04 00:59 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-03 22:15 - 2013-07-04 00:59 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-03 10:48 - 2013-07-03 10:48 - 00237568 ____A (CompulsiveCode - The Programs I Write) C:\Users\mKy\Downloads\JPEGtoPDF37.exe
2013-07-03 04:58 - 2013-07-03 04:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 01:43 - 2013-07-02 01:44 - 07236481 ____A C:\Users\mKy\Downloads\Ex.iBot-R v1.73.rar
2013-07-01 16:00 - 2013-07-01 16:00 - 00555240 ____A C:\Windows\Minidump\070113-21325-01.dmp
2013-07-01 03:45 - 2013-07-01 04:00 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadR_071
2013-07-01 03:24 - 2013-07-01 03:42 - 1842256513 ____A C:\Users\mKy\Downloads\SilkroadR_071.zip
2013-06-27 23:30 - 2013-06-27 23:30 - 31272077 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_403(for_v1_400_402).exe
2013-06-27 23:25 - 2013-06-27 23:42 - 00000000 ____D C:\Program Files (x86)\Silkroad
2013-06-27 23:23 - 2013-06-27 23:23 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400
2013-06-27 22:20 - 2013-06-27 22:20 - 00001898 ____A C:\Users\mKy\Desktop\SilkroadR.lnk
2013-06-27 22:16 - 2013-06-27 22:28 - 00000000 ____D C:\Program Files (x86)\SilkroadR
2013-06-27 22:14 - 2013-06-27 23:23 - 1361456630 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400.zip
2013-06-27 22:13 - 2013-06-27 22:13 - 01125376 ____A (PlayWhat) C:\Users\mKy\Downloads\528!SilkroadOnline_GlobalOfficial_v1_400.exe.exe.htm
2013-06-27 22:12 - 2013-06-27 23:28 - 00001889 ____A C:\Users\mKy\Desktop\Silkroad.lnk
2013-06-27 21:13 - 2013-05-27 00:30 - 05127200 ____A (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des
2013-06-27 21:12 - 2013-06-27 21:12 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
2013-06-27 21:12 - 2005-01-04 11:43 - 00004682 ____A (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\npptNT2.sys
2013-06-27 21:12 - 2003-07-20 20:17 - 00005174 ____A C:\Windows\SysWOW64\nppt9x.vxd
2013-06-27 20:50 - 2013-06-27 20:50 - 00000000 ____D C:\ProgramData\Overwolf
2013-06-27 20:49 - 2013-06-27 21:24 - 00000000 ____D C:\Program Files (x86)\Overwolf
2013-06-27 20:44 - 2013-06-27 20:51 - 00000000 ____D C:\Users\mKy\AppData\Local\Overwolf
2013-06-27 20:35 - 2013-06-27 20:35 - 00000000 ____D C:\Program Files (x86)\Games-Masters.com
2013-06-27 20:30 - 2013-06-27 22:09 - 00001040 ____A C:\Users\mKy\Downloads\_predownloadpath.dat
2013-06-27 20:26 - 2013-06-27 20:26 - 02607616 ____A C:\Users\mKy\Downloads\PSROR_Full_Client_Downloader_v3(2).exe
2013-06-27 20:07 - 2013-06-27 20:28 - 1260483304 ____A (Games-Masters.com                                           ) C:\Users\mKy\Downloads\CABAL_Online_Europe_Installer.exe
2013-06-20 14:33 - 2013-06-20 14:33 - 00004915 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-20 14:33 - 2013-06-12 21:47 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-20 14:33 - 2013-06-12 21:43 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-20 14:33 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-20 14:33 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-20 14:32 - 2013-06-20 14:32 - 00903592 ____A (Oracle Corporation) C:\Users\mKy\Downloads\jxpiinstall(3).exe
2013-06-07 01:40 - 2013-06-07 01:40 - 00000000 ____D C:\Users\mKy\AppData\Roaming\raidcall
2013-06-07 01:38 - 2013-06-07 01:39 - 05517176 ____A C:\Users\mKy\Downloads\raidcall_v7.2.4.exe

==================== One Month Modified Files and Folders =======

2013-07-07 21:46 - 2013-07-07 21:46 - 00000000 ____D C:\FRST
2013-07-07 21:45 - 2013-07-07 21:44 - 01934636 ____A (Farbar) C:\Users\mKy\Desktop\FRST64.exe
2013-07-07 21:39 - 2012-08-01 00:34 - 00000920 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000UA.job
2013-07-07 21:34 - 2012-01-28 21:20 - 00000000 ____D C:\Users\mKy\AppData\Roaming\Skype
2013-07-07 21:18 - 2012-11-23 08:53 - 00000000 ____D C:\Users\mKy\AppData\Roaming\Spotify
2013-07-07 21:03 - 2013-01-10 11:05 - 00000000 ____D C:\Users\mKy\AppData\Local\PMB Files
2013-07-07 20:51 - 2013-07-07 20:51 - 00087572 ____A C:\Users\mKy\Desktop\Extras.Txt
2013-07-07 20:50 - 2013-07-07 20:50 - 00083088 ____A C:\Users\mKy\Desktop\OTL.Txt
2013-07-07 20:44 - 2013-07-07 20:44 - 00602112 ____A (OldTimer Tools) C:\Users\mKy\Desktop\OTL.exe
2013-07-07 20:44 - 2013-07-07 20:44 - 00000468 ____A C:\Users\mKy\Desktop\defogger_disable.log
2013-07-07 20:44 - 2013-07-07 20:44 - 00000000 ____A C:\Users\mKy\defogger_reenable
2013-07-07 20:44 - 2012-01-29 02:54 - 00000000 ___AD C:\users\mKy
2013-07-07 20:42 - 2013-07-07 20:42 - 00050477 ____A C:\Users\mKy\Desktop\Defogger.exe
2013-07-07 20:39 - 2009-07-14 06:45 - 00035088 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-07 20:39 - 2009-07-14 06:45 - 00035088 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-07 20:36 - 2012-01-29 02:51 - 01943129 ____A C:\Windows\WindowsUpdate.log
2013-07-07 20:33 - 2012-12-19 00:20 - 00000000 ____D C:\Users\mKy\AppData\Local\LogMeIn Hamachi
2013-07-07 20:31 - 2012-01-29 03:18 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-07 20:31 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-07 20:31 - 2009-07-14 06:51 - 00046271 ____A C:\Windows\setupact.log
2013-07-07 19:45 - 2013-07-07 19:45 - 00003495 ____A C:\AdwCleaner[R1].txt
2013-07-07 19:44 - 2013-07-07 19:41 - 00000000 ____D C:\Users\mKy\Desktop\RK_Quarantine
2013-07-07 19:43 - 2013-07-07 19:43 - 00002094 ____A C:\Users\mKy\Desktop\RKreport[0]_S_07072013_194312.txt
2013-07-07 19:38 - 2013-07-07 19:38 - 00208216 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\31978637.sys
2013-07-07 19:38 - 2013-07-07 19:38 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-07-07 19:36 - 2013-07-07 19:34 - 00019385 ____A C:\Users\mKy\Downloads\Result.txt
2013-07-07 19:33 - 2013-07-07 19:33 - 00915456 ____A C:\Users\mKy\Downloads\RogueKiller.exe
2013-07-07 19:28 - 2013-07-07 19:28 - 00760775 ____A (Farbar) C:\Users\mKy\Downloads\MiniToolBox.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\mKy\Downloads\tdsskiller.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 00650027 ____A C:\Users\mKy\Downloads\AdwCleaner.exe
2013-07-07 00:39 - 2012-08-01 00:34 - 00000898 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000Core.job
2013-07-06 02:08 - 2013-07-06 02:08 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-07-06 02:07 - 2012-05-28 11:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-06 02:07 - 2012-04-28 19:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-06 02:07 - 2010-11-21 05:47 - 00142734 ____A C:\Windows\PFRO.log
2013-07-05 07:52 - 2012-05-28 11:39 - 00001113 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-07-04 00:59 - 2013-07-03 22:15 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-04 00:59 - 2013-07-03 22:15 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-04 00:59 - 2012-02-07 17:52 - 00000000 ____D C:\Users\mKy\AppData\Local\Adobe
2013-07-04 00:54 - 2013-07-04 00:54 - 00000000 ____D C:\Users\mKy\Desktop\Alte Firefox-Daten
2013-07-04 00:47 - 2012-01-28 20:52 - 00000000 ____D C:\Users\mKy\AppData\Roaming\TS3Client
2013-07-03 10:48 - 2013-07-03 10:48 - 00237568 ____A (CompulsiveCode - The Programs I Write) C:\Users\mKy\Downloads\JPEGtoPDF37.exe
2013-07-03 04:59 - 2013-07-03 04:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 01:44 - 2013-07-02 01:43 - 07236481 ____A C:\Users\mKy\Downloads\Ex.iBot-R v1.73.rar
2013-07-01 16:02 - 2012-11-23 08:54 - 00000000 ____D C:\Users\mKy\AppData\Local\Spotify
2013-07-01 16:00 - 2013-07-01 16:00 - 00555240 ____A C:\Windows\Minidump\070113-21325-01.dmp
2013-07-01 16:00 - 2012-03-20 14:40 - 506566888 ____A C:\Windows\MEMORY.DMP
2013-07-01 16:00 - 2012-03-20 14:40 - 00000000 ____D C:\Windows\Minidump
2013-07-01 04:00 - 2013-07-01 03:45 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadR_071
2013-07-01 03:42 - 2013-07-01 03:24 - 1842256513 ____A C:\Users\mKy\Downloads\SilkroadR_071.zip
2013-06-30 00:27 - 2009-07-14 06:45 - 00301832 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-28 17:35 - 2012-01-28 20:59 - 00064080 ____A C:\Users\mKy\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-28 15:34 - 2012-05-28 12:34 - 00000000 ____D C:\Program Files (x86)\Heroes of Newerth
2013-06-28 09:27 - 2012-02-04 16:44 - 00000000 ____D C:\Users\mKy\AppData\Local\Akamai
2013-06-27 23:42 - 2013-06-27 23:25 - 00000000 ____D C:\Program Files (x86)\Silkroad
2013-06-27 23:30 - 2013-06-27 23:30 - 31272077 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_403(for_v1_400_402).exe
2013-06-27 23:28 - 2013-06-27 22:12 - 00001889 ____A C:\Users\mKy\Desktop\Silkroad.lnk
2013-06-27 23:23 - 2013-06-27 23:23 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400
2013-06-27 23:23 - 2013-06-27 22:14 - 1361456630 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400.zip
2013-06-27 22:28 - 2013-06-27 22:16 - 00000000 ____D C:\Program Files (x86)\SilkroadR
2013-06-27 22:20 - 2013-06-27 22:20 - 00001898 ____A C:\Users\mKy\Desktop\SilkroadR.lnk
2013-06-27 22:13 - 2013-06-27 22:13 - 01125376 ____A (PlayWhat) C:\Users\mKy\Downloads\528!SilkroadOnline_GlobalOfficial_v1_400.exe.exe.htm
2013-06-27 22:09 - 2013-06-27 20:30 - 00001040 ____A C:\Users\mKy\Downloads\_predownloadpath.dat
2013-06-27 21:24 - 2013-06-27 20:49 - 00000000 ____D C:\Program Files (x86)\Overwolf
2013-06-27 21:12 - 2013-06-27 21:12 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
2013-06-27 20:51 - 2013-06-27 20:44 - 00000000 ____D C:\Users\mKy\AppData\Local\Overwolf
2013-06-27 20:50 - 2013-06-27 20:50 - 00000000 ____D C:\ProgramData\Overwolf
2013-06-27 20:35 - 2013-06-27 20:35 - 00000000 ____D C:\Program Files (x86)\Games-Masters.com
2013-06-27 20:28 - 2013-06-27 20:07 - 1260483304 ____A (Games-Masters.com                                           ) C:\Users\mKy\Downloads\CABAL_Online_Europe_Installer.exe
2013-06-27 20:27 - 2012-01-28 20:40 - 00000000 ____D C:\Spiele
2013-06-27 20:26 - 2013-06-27 20:26 - 02607616 ____A C:\Users\mKy\Downloads\PSROR_Full_Client_Downloader_v3(2).exe
2013-06-27 20:08 - 2012-11-24 09:34 - 00000000 ____D C:\Joymax
2013-06-22 05:37 - 2012-11-29 07:33 - 00000000 ____D C:\Bewerbungen
2013-06-20 14:33 - 2013-06-20 14:33 - 00004915 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-20 14:33 - 2013-05-18 17:05 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-20 14:32 - 2013-06-20 14:32 - 00903592 ____A (Oracle Corporation) C:\Users\mKy\Downloads\jxpiinstall(3).exe
2013-06-17 08:36 - 2013-05-28 05:09 - 00000000 ____D C:\ProgramData\BrowserProtect
2013-06-12 21:48 - 2012-09-21 13:54 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-12 21:48 - 2012-01-30 00:56 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-12 21:47 - 2013-06-20 14:33 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-12 21:43 - 2013-06-20 14:33 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-12 21:43 - 2013-06-20 14:33 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-12 21:43 - 2013-06-20 14:33 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 09:24 - 2012-01-29 20:59 - 00000000 ____D C:\Users\mKy\AppData\Roaming\SimpleScreenshot
2013-06-08 09:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-06-08 09:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-06-07 01:40 - 2013-06-07 01:40 - 00000000 ____D C:\Users\mKy\AppData\Roaming\raidcall
2013-06-07 01:40 - 2012-11-30 15:40 - 00001011 ____A C:\Users\UpdatusUser\Desktop\RaidCall.lnk
2013-06-07 01:40 - 2012-11-30 15:40 - 00001011 ____A C:\Users\mKy\Desktop\RaidCall.lnk
2013-06-07 01:40 - 2012-11-30 15:40 - 00000000 ____D C:\Program Files (x86)\RaidCall
2013-06-07 01:39 - 2013-06-07 01:38 - 05517176 ____A C:\Users\mKy\Downloads\raidcall_v7.2.4.exe

Files to move or delete:
====================
C:\Users\mKy\SilkroadOnline_GlobalOfficial_v1_346_LEGEND_8.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-06 02:37

==================== End Of Log ============================
         
--- --- ---




FRST Additions Logfile:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-07-2013
Ran by mKy at 2013-07-07 21:52:11
Running from C:\Users\mKy\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
Adobe Reader X (10.1.6) - Deutsch (x32 Version: 10.1.6)
Akamai NetSession Interface (HKCU)
Akamai NetSession Interface (x32)
Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: 1.10.0.0)
ATI Catalyst Install Manager (Version: 3.0.812.0)
Avira Free Antivirus (x32 Version: 12.1.9.2400)
Borderlands 2 (x32)
Core Temp 1.0 RC4 (Version: 1.0)
Counter-Strike: Global Offensive - SDK (x32)
Counter-Strike: Global Offensive (x32)
Counter-Strike: Source (x32)
Creative Software AutoUpdate (x32 Version: 1.40)
Creative-Audiokonsole (x32 Version: 1.33)
D3DX10 (x32 Version: 15.4.2368.0902)
DivX-Setup (x32 Version: 2.6.1.9)
Dota 2 (x32)
Dota 2 Test (x32)
ESE Account Manager 2.0.0.2 (x32 Version: 2.0.0.2)
ESL Wire 1.11.1
Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287)
Far Cry® 3 (x32)
Football Superstars (x32)
Heroes of Newerth (x32 Version: 2.3.0)
ICQ7.7 (x32 Version: 7.7)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
JMicron JMB36X Driver (x32 Version: 1.17.62.0)
League of Legends (x32 Version: 1.3)
LogMeIn Hamachi (x32 Version: 2.1.0.374)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Security Client (Version: 4.2.0223.1)
Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0)
Microsoft Security Essentials (Version: 4.2.223.1)
Microsoft Silverlight (x32 Version: 4.1.10329.0)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0)
Mozilla Maintenance Service (x32 Version: 22.0)
MSVCRT (x32 Version: 15.4.2862.0708)
Notepad++ (x32 Version: 6.2.2)
NVIDIA 3D Vision Controller Driver (x32 Version: 280.19)
NVIDIA 3D Vision Controller-Treiber 306.97 (Version: 306.97)
NVIDIA 3D Vision Treiber 306.97 (Version: 306.97)
NVIDIA Grafiktreiber 306.97 (Version: 306.97)
NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0)
NVIDIA Install Application (Version: 2.1002.85.551)
NVIDIA PhysX (x32 Version: 9.12.0604)
NVIDIA PhysX-Systemsoftware 9.12.0604 (Version: 9.12.0604)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.0697)
NVIDIA Systemsteuerung 306.97 (Version: 306.97)
NVIDIA Update 1.10.8 (Version: 1.10.8)
NVIDIA Update Components (Version: 1.10.8)
OpenAL (x32)
OpenOffice.org 3.3 (x32 Version: 3.3.9567)
osu! (x32 Version: 0.0.0.0)
Pando Media Booster (x32 Version: 2.6.0.8)
PunkBuster Services (x32 Version: 0.993)
RaidCall (x32 Version: 7.2.4-1.0.7299.14)
Realtek Ethernet Controller Driver (x32 Version: 7.43.321.2011)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6251)
Silkroad (x32)
SilkroadR (x32)
SimpleScreenshot 1.40 (x32)
Skype™ 6.3 (x32 Version: 6.3.107)
Spotify (HKCU Version: 0.9.1.57.ge7405149)
Steam (x32 Version: 1.0.0.0)
StepMania (remove only) (x32)
TeamSpeak 3 Client (x32)
Torchlight 2 (x32 Version: 1.9.2.1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Uplay (x32 Version: 2.0)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
VLC media player 1.1.11 (x32 Version: 1.1.11)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
WinRAR 4.10 (64-Bit) (Version: 4.10.0)

==================== Restore Points  =========================

02-07-2013 01:00:11 Windows Update
03-07-2013 01:00:11 Windows Update
04-07-2013 01:00:11 Windows Update
05-07-2013 01:00:11 Windows Update
06-07-2013 01:00:11 Windows Update
07-07-2013 01:00:11 Windows Update
07-07-2013 18:29:01 Windows Update

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {461FC41B-CA4B-4385-8009-0BDA6A55D892} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation)
Task: {7104B927-4B9C-4314-B7A6-5E2D0915F86D} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000UA => C:\Users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-01] (Facebook Inc.)
Task: {77BF86F1-704E-48C5-B730-6C4A34861AA3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000Core => C:\Users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-01] (Facebook Inc.)
Task: {C5A035CC-E720-430B-A481-8A37076F26B2} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {E7AF232E-12A3-4465-8966-8B93ACF68C24} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\MpCmdRun.exe [2013-01-27] (Microsoft Corporation)
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000Core.job => C:\Users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000UA.job => C:\Users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe

==================== Faulty Device Manager Devices =============

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/07/2013 09:47:24 PM) (Source: Application Hang) (User: )
Description: Programm FRST64.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1824

Startzeit: 01ce7b4a911e53de

Endzeit: 5

Anwendungspfad: C:\Users\mKy\Desktop\FRST64.exe

Berichts-ID: 08c9357b-e73e-11e2-a854-00ff01000001

Error: (07/07/2013 08:36:23 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Der Textzeichenfolgenwert zur Beschreibung des Leistungsindikators in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten.

Error: (07/07/2013 08:33:22 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/06/2013 02:40:09 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"2" in Zeile  Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (07/06/2013 02:40:09 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"2" in Zeile  Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (07/06/2013 02:11:50 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Der Textzeichenfolgenwert zur Beschreibung des Leistungsindikators in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten.

Error: (07/06/2013 02:09:00 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/03/2013 11:35:19 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.

Error: (07/03/2013 04:58:44 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.

Error: (07/02/2013 03:13:57 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"2" in Zeile  Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.


System errors:
=============
Error: (07/07/2013 08:34:13 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1069

Error: (07/07/2013 08:34:13 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
%%1330

Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (07/07/2013 08:32:12 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
cdrom

Error: (07/06/2013 02:09:44 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1069

Error: (07/06/2013 02:09:44 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
%%1330

Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (07/06/2013 02:08:54 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "LogMeIn Hamachi Tunneling Engine" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (07/06/2013 02:08:54 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst LogMeIn Hamachi Tunneling Engine erreicht.

Error: (07/06/2013 02:08:48 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "LogMeIn Hamachi Tunneling Engine" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (07/06/2013 02:07:43 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
cdrom

Error: (07/06/2013 02:07:32 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ?06.?07.?2013 um 02:05:52 unerwartet heruntergefahren.


Microsoft Office Sessions:
=========================
Error: (07/07/2013 09:47:24 PM) (Source: Application Hang)(User: )
Description: FRST64.exe3.3.8.1182401ce7b4a911e53de5C:\Users\mKy\Desktop\FRST64.exe08c9357b-e73e-11e2-a854-00ff01000001

Error: (07/07/2013 08:36:23 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: 16000000003D2800003D280000980B0000

Error: (07/07/2013 08:33:22 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/06/2013 02:40:09 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files (x86)\Steam\steamapps\common\football superstars\DevWidgetsR_msvcrt.dllc:\program files (x86)\Steam\steamapps\common\football superstars\Microsoft.VC90.CRT.MANIFEST4

Error: (07/06/2013 02:40:09 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files (x86)\Steam\steamapps\common\football superstars\DevWidgetsD_msvcrtd.dllc:\program files (x86)\Steam\steamapps\common\football superstars\Microsoft.VC90.CRT.MANIFEST4

Error: (07/06/2013 02:11:50 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: 16000000003D2800003D280000980B0000

Error: (07/06/2013 02:09:00 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/03/2013 11:35:19 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.

Error: (07/03/2013 04:58:44 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.

Error: (07/02/2013 03:13:57 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files (x86)\Steam\steamapps\common\football superstars\DevWidgetsR_msvcrt.dllc:\program files (x86)\Steam\steamapps\common\football superstars\Microsoft.VC90.CRT.MANIFEST4


CodeIntegrity Errors:
===================================
  Date: 2012-12-08 17:55:30.200
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\mKy\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2012-12-08 17:55:30.188
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\mKy\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2012-12-08 17:55:30.092
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2012-12-08 17:55:30.071
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info =========================== 

Percentage of memory in use: 27%
Total physical RAM: 8137.36 MB
Available physical RAM: 5876.77 MB
Total Pagefile: 16272.91 MB
Available Pagefile: 13825.17 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:210.81 GB) NTFS (Disk=0 Partition=2)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: F980F980)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
--- --- ---
__________________

Alt 07.07.2013, 20:58   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 07.07.2013, 21:18   #5
mKy
 
Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Zitat:
Combofix Logfile:
Code:
ATTFilter
ComboFix 13-07-08.02 - mKy 07.07.2013  22:09:35.1.6 - x64
Microsoft Windows 7 Professional   6.1.7601.1.1252.49.1031.18.8137.5976 [GMT 2:00]
ausgeführt von:: c:\users\mKy\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\sss
c:\program files (x86)\sss\licence.txt
c:\program files (x86)\sss\ReadMe.txt
c:\program files (x86)\sss\SimpleScreenshot.exe
c:\program files (x86)\sss\upload.php
c:\users\mKy\AppData\Roaming\siw_sdk.dll
c:\users\mKy\SilkroadOnline_GlobalOfficial_v1_346_LEGEND_8.exe
c:\windows\security\Database\tmp.edb
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-06-07 bis 2013-07-07  ))))))))))))))))))))))))))))))
.
.
2013-07-07 20:14 . 2013-07-07 20:14	--------	d-----w-	c:\users\UpdatusUser\AppData\Local\temp
2013-07-07 20:14 . 2013-07-07 20:14	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-07-07 19:46 . 2013-07-07 19:46	--------	d-----w-	C:\FRST
2013-07-07 18:44 . 2013-07-07 18:44	76232	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A704B25C-954A-4824-ACDE-16CD9D11AACC}\offreg.dll
2013-07-07 17:38 . 2013-07-07 17:38	--------	d-----w-	C:\TDSSKiller_Quarantine
2013-07-07 17:38 . 2013-07-07 17:38	208216	----a-w-	c:\windows\system32\drivers\31978637.sys
2013-07-07 06:16 . 2013-06-12 03:08	9552976	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A704B25C-954A-4824-ACDE-16CD9D11AACC}\mpengine.dll
2013-07-06 17:09 . 2013-06-12 03:08	9552976	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-07-06 00:08 . 2013-07-06 00:08	--------	d-----w-	c:\program files (x86)\LogMeIn Hamachi
2013-07-05 05:52 . 2013-07-05 05:52	--------	d-----w-	c:\users\mKy\AppData\Local\Programs
2013-07-03 20:15 . 2013-07-03 22:59	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-03 20:15 . 2013-07-03 22:59	692104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-27 21:25 . 2013-06-27 21:42	--------	d-----w-	c:\program files (x86)\Silkroad
2013-06-27 19:13 . 2013-05-26 22:30	5127200	----a-w-	c:\windows\SysWow64\GameMon.des
2013-06-27 19:12 . 2005-01-04 09:43	4682	----a-w-	c:\windows\SysWow64\npptNT2.sys
2013-06-27 19:12 . 2003-07-20 18:17	5174	----a-w-	c:\windows\SysWow64\nppt9x.vxd
2013-06-27 19:12 . 2013-06-27 19:12	--------	d-----w-	c:\program files\Common Files\INCA Shared
2013-06-27 18:50 . 2013-06-27 18:50	--------	d-----w-	c:\programdata\Overwolf
2013-06-27 18:49 . 2013-06-27 19:24	--------	d-----w-	c:\program files (x86)\Overwolf
2013-06-27 18:49 . 2013-06-27 19:24	--------	d-----w-	c:\program files (x86)\Common Files\Overwolf
2013-06-27 18:44 . 2013-06-27 18:51	--------	d-----w-	c:\users\mKy\AppData\Local\Overwolf
2013-06-27 18:35 . 2013-06-27 18:35	--------	d-----w-	c:\program files (x86)\Games-Masters.com
2013-06-21 12:48 . 2013-06-21 12:48	964552	------w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{046E4C09-FD75-4EE9-91EB-07C0C24947B8}\gapaengine.dll
2013-06-20 12:33 . 2013-06-12 19:47	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 19:48 . 2012-09-21 11:54	867240	----a-w-	c:\windows\SysWow64\npDeployJava1.dll
2013-06-12 19:48 . 2012-01-29 22:56	789416	----a-w-	c:\windows\SysWow64\deployJava1.dll
2013-05-21 11:30 . 2012-02-10 10:20	964552	------w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-05-15 11:19 . 2011-03-28 17:36	22240	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-02 15:29 . 2010-11-21 03:27	278800	------w-	c:\windows\system32\MpSigStub.exe
2012-01-24 12:50 . 2012-01-29 18:20	168864	----a-w-	c:\program files\Common Files\WireHelpSvc.exe
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"Akamai NetSession Interface"="c:\users\mKy\AppData\Local\Akamai\netsession_win.exe" [2013-06-04 4489472]
"Facebook Update"="c:\users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-31 138096]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2013-01-10 3093624]
"Spotify Web Helper"="c:\users\mKy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-07-07 1104384]
"Spotify"="c:\users\mKy\AppData\Roaming\Spotify\Spotify.exe" [2013-07-07 4640768]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-05-08 18680424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AsioThk32Reg"="CTASIO.DLL" [2010-03-18 47104]
"CTHelper"="CTHELPER.EXE" [2010-03-18 19456]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-06-28 2255184]
.
c:\users\mKy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 ALSysIO;ALSysIO;c:\users\mKy\AppData\Local\Temp\ALSysIO64.sys;c:\users\mKy\AppData\Local\Temp\ALSysIO64.sys [x]
R3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS;c:\windows\SYSNATIVE\drivers\COMMONFX.SYS [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS;c:\windows\SYSNATIVE\drivers\CTAUDFX.SYS [x]
R3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\System32\drivers\CTERFXFX.SYS;c:\windows\SYSNATIVE\drivers\CTERFXFX.SYS [x]
R3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS;c:\windows\SYSNATIVE\drivers\CTERFXFX.SYS [x]
R3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS;c:\windows\SYSNATIVE\drivers\CTSBLFX.SYS [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys;c:\windows\SYSNATIVE\drivers\ESLWireACD.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 WireHelpSvc;WireHelpSvc;c:\program files\Common Files\WireHelpSvc.exe;c:\program files\Common Files\WireHelpSvc.exe [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\System32\drivers\COMMONFX.SYS;c:\windows\SYSNATIVE\drivers\COMMONFX.SYS [x]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\System32\drivers\CTAUDFX.SYS;c:\windows\SYSNATIVE\drivers\CTAUDFX.SYS [x]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\System32\drivers\CTSBLFX.SYS;c:\windows\SYSNATIVE\drivers\CTSBLFX.SYS [x]
S3 ESLvnic1;ESLvnic Virtual Network 64 Bit;c:\windows\system32\DRIVERS\ESLvnic.sys;c:\windows\SYSNATIVE\DRIVERS\ESLvnic.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 49687842
*Deregistered* - 49687842
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai	REG_MULTI_SZ   	Akamai
.
Inhalt des "geplante Tasks" Ordners
.
2013-07-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000Core.job
- c:\users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-31 22:34]
.
2013-07-07 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000UA.job
- c:\users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-31 22:34]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-19 11613288]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.avira.com/?l=dis&o=APN10395&gct=hp&dc=EU&locale=de_DE
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\mKy\AppData\Roaming\Mozilla\Firefox\Profiles\wbur3zd3.default-1372892069866\
FF - ExtSQL: 2013-07-04 01:01; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\mKy\AppData\Roaming\Mozilla\Firefox\Profiles\wbur3zd3.default-1372892069866\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-Overwolf - c:\program files (x86)\Overwolf\Overwolf.exe
Wow6432Node-HKLM-Run-SimpleScreenshot - c:\progra~2\SSS\SIMPLESCREENSHOT.EXE
SafeBoot-49687842.sys
AddRemove-hon - c:\spiele\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-07-07  22:16:22
ComboFix-quarantined-files.txt  2013-07-07 20:16
.
Vor Suchlauf: 22 Verzeichnis(se), 242.840.014.848 Bytes frei
Nach Suchlauf: 28 Verzeichnis(se), 243.833.778.176 Bytes frei
.
- - End Of File - - 4F3EF6A35FE211266B1A0C953088C52D
         
--- --- ---
D41D8CD98F00B204E9800998ECF8427E
Ein Neustart wurde von ComboFix jedoch nicht verlangt.


Alt 08.07.2013, 07:52   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
--> Langsamer Boot, Flash Plugin Problem - woran liegts?

Alt 08.07.2013, 12:44   #7
mKy
 
Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Guten Tag,

AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v2.304 - Datei am 08/07/2013 um 13:26:59 erstellt
# Aktualisiert am 03/07/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzer : mKy - MKY-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\mKy\Desktop\adwcleaner(1).exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\BrowserProtect
Ordner Gelöscht : C:\Users\mKy\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_mpfapcdfbbledbojijcbcclmlieaoogk_0
Ordner Gelöscht : C:\Users\mKy\AppData\LocalLow\boost_interprocess
Ordner Gelöscht : C:\Users\mKy\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\mKy\AppData\Roaming\OpenCandy

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\I Want This
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\5a538f8ce53cb840
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Freeze.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\I Want This_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\I Want This_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\5a538f8ce53cb840
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.7601.17514

Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.avira.com/?l=dis&o=APN10395&gct=hp&dc=EU&locale=de_DE --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd --> hxxp://www.google.com

-\\ Mozilla Firefox v22.0 (de)

Datei : C:\Users\mKy\AppData\Roaming\Mozilla\Firefox\Profiles\wbur3zd3.default-1372892069866\prefs.js

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [3495 octets] - [07/07/2013 19:45:01]
AdwCleaner[S1].txt - [2736 octets] - [08/07/2013 13:26:59]

########## EOF - C:\AdwCleaner[S1].txt - [2796 octets] ##########
         
--- --- ---



Zitat:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.7 (07.08.2013:2)
OS: Windows 7 Professional x64
Ran by mKy on 08.07.2013 at 13:31:54,35
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3C75F07A-7838-4B12-8017-932CA5A8F50F}



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0001AF0F-8572-44D7-B8EE-E3D224520549}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{004F9F44-111B-48FB-AC54-3FCA7506D2DC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0143EC2F-6727-4292-A453-632431CAC78D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{019EA60A-F8C6-4C7E-B484-A6B36BE08A24}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{01F4B987-459B-4FD8-97E3-B05D725E6D10}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{02152D35-8D49-43E4-BA57-D8AB6595A3AB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{024B2255-54B4-40C1-8FB5-52C4ABE23C30}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{02B08222-AA22-4380-9CBE-A1C4C8B7F5AA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{02EE1C2C-8FD6-4F57-B5B7-091B8C3304F8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0385069B-A9C2-4469-9209-8E8DB0426D58}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{03DB662D-CB8B-47BC-95BE-E9C6B08D25FE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{03E74F08-4510-41E5-851D-E89BF2A2340F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{04318CB3-CDC5-4791-B1DA-5BAC26116EC9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{046585BE-38E0-4AB5-A4D8-19C3D51459FB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0519C31D-0006-479A-A80B-89042A487E07}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{058C0107-0DB5-485F-A990-71FDC20D4548}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0598A931-6BC1-4293-A53A-1BF92D666712}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{06509D16-651B-48BE-A234-9C1D30E85149}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{06AE0717-87F0-489D-BA46-4F10074146DD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{071FF795-7BB7-4C2B-B43F-C95C6842A76A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{07390912-FA93-45A1-A189-521FA168A5A2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{07502269-088E-474B-B5D7-C2D1D9C4AD43}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{09372D4D-08D6-4ED6-A70D-45B1B5EAA78B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{097A8430-4DC4-4BC9-AFD0-1D727C0A6FA2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{09A1BD86-C242-4FFF-A026-AB9AA511FD1C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{09E5FB54-8368-49A4-AB68-9C19331649A4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0A910976-7686-473F-A897-D2BEF4EF51A0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0B4286C1-DAD0-4E51-933E-D5E4802CB27F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0BB27A2E-5451-4011-AB86-779FC8C0D7A4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0BDB0CE4-C331-4F1A-8AFC-44A7F45ED30B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0C85C035-4E98-483B-842C-48847777232A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0D92F86D-4735-4002-A001-60C03EA17C3C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0DCA7CAE-743A-4C04-BBDF-09F80D02CA32}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0DEBA500-8024-4FB1-9BB6-B780007A46F8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0E193F4D-A820-41EB-B3AF-7C3053B13413}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{0F77D613-7488-4B6C-822A-E30BF8E213F6}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{10052AB3-B30C-4553-A789-4A263A0B7C19}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1014E322-8050-4266-B84F-39883D24A991}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{10867627-80A0-4A67-B1DD-91185C492991}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1127CF04-9570-4B47-97E3-8F53AA8B4738}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{11B9B897-F4CA-4BCC-8BFC-F5F8C20E0105}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1280C51C-E7EC-490E-888E-0ED82A528633}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{13C239D3-D5E5-42C9-A8EE-5095B7E38826}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{142936FB-9C6F-462D-9734-851ADDDB8F70}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1435000F-489E-4551-BD6C-D2E248AC9D3A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1459BC30-86BC-4A8E-80D0-C7C90C5E119A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{14895669-4388-429D-961C-9984BAD2267B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{149693DC-24B1-4A0E-9B82-C8118C4769BD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{15003FD8-1F9D-458F-A0B9-3AB4AF4FD1D1}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{15010DD2-B7E2-48D6-B0BE-2718C24088F2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{15235023-3C75-476A-914D-C8E6C3A0EEF2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{15774296-2223-4E5D-AB8C-04BB296A2CD8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{15A357B2-7F68-4B26-A3A1-A073D68C11B8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{15ABF512-D4C4-4ACF-9EF1-4EE7987996F0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{15E34DB6-6C58-45DE-A7C6-BF30058BB6B4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{15F1FBFA-46CF-46D2-A8E9-746BFC27EE3D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{160382F8-ED5A-49AC-A597-499AFE3852B7}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{16496262-F999-45AE-B955-64BE88CCC3B4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{16585EF8-4D8F-4B5B-B6EE-8A5D366548AD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{170136A2-8E8E-4523-A636-DF7F95B45EAB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1709830A-E7F8-4F11-860D-DD61C755DE91}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{178B897A-D803-4423-9E72-B39438F98174}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{17DDD2DE-7AEB-4577-ABA3-F5FC60D9AAEF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{184483AB-8D99-4071-BD7A-C09AC6D1D066}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{18EFE740-BE11-44F3-B5F4-7D7496444717}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1A6E7624-029C-4DA5-A437-ECE8E8B6EBB8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1B5A9814-02E7-44FD-B867-640A35029627}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1BD7C104-A243-46AE-8BD7-4C43207701DA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1BF92F2B-C211-4265-977B-79E797C327C9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1C07F9EB-FD1A-4548-BEC4-377FF8E5FD91}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1CA43339-8D12-4CB4-ABB6-79988DA2E3CB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1CBD5009-FADD-4021-89BB-7C9548260868}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1CD662D3-B0DB-43EE-B24D-DAF3CC3EF545}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1D050F97-54F9-414A-BDAA-7C411ACF66F1}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1D5E9B1C-1F21-423A-8D56-9F6285203964}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1E7290B3-BDF9-4CBB-BCBD-6DE4B046DAD4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1EE77925-3523-4195-A0FE-36E3A4D924D8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{1FB9C18D-D27D-417D-ADD9-2F291EF9944E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{20303DB9-BBAB-4ABF-B426-046CAA3B47AC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{20C8B7D6-C37A-48DA-9C26-D8EE0545B238}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{210A32E4-6AF9-48B7-BE31-85076B2213E2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{211AE969-CA5B-4A2F-AFF3-6A6F379AA25E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{212464D5-AEBA-4687-A16B-4CE02554F3B3}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{22FBD67B-9F42-41EA-AE62-98504F193A84}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{230A5A05-E6CE-47AA-85DF-919B4C34C891}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{23752393-127D-4EF3-9B70-40D23CFBA322}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{237BD599-341F-49A7-AB44-D93B5BD65D8F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{23841880-A357-45D8-B9B9-0F583F17C339}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{23E5A333-167F-4108-8014-31945937AC5C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{248FDF32-5774-4861-9885-D317BEBADA75}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2520065B-D485-451F-82D6-1C760335AB30}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2586DF92-7B9F-40CE-8C21-223C5B3B412F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{259D2C63-0E4E-4CD3-9BA8-1745A90E4B8E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{25B5F618-CA58-4D8E-B4B7-BE01EAB00C6E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{260027BB-4A29-4DE1-B2AF-7CA0E171F631}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{266FB32D-6B0D-4D48-82B8-2056B2822558}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{267CE3E2-6FAC-4B2A-87A0-2DB1D7D28A0D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2682689E-4A72-49E1-9C7D-881245B1C1F6}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{26BC67DE-F95D-4339-B104-A285A3D15B1A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{26C6B770-4A67-4F4D-A155-EC891C9FCC38}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{26F90C45-D531-4E10-9C7A-9105C23A9478}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{27A3020A-713D-4544-B942-F2B1B7CB6F52}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{28371007-F39F-4B56-AF41-CCDF8489DBFD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{286EF8EE-0E8E-4F44-8D9F-4DC4964319A4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{28BD5B0E-A00C-4BCB-A7F5-17684111E666}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{298DEF32-1BFC-4FC1-9984-1E23B7855A76}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{299A378C-B00B-4BED-9BEA-132D69C7A6FA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{29D56DBE-4421-4DBE-AAA2-6B4C4E19831F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{29D88722-1AC6-417C-B0C4-87B8FA785DC3}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2A54B319-6B57-4CAB-8B0F-816BD62B1BCE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2B3F2ABD-DF3D-495B-B995-AC474614459D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2B77D89E-1534-489F-A74E-8838804D1363}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2BC200EC-C457-4513-A248-C2C0916AA534}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2C6E1AB4-2F98-42F8-8B8E-A4F37B087BB4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2C95FDB5-90FA-405F-A9B0-2BE41464C091}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2D5CB2FB-E4CD-4149-8CDD-F704CE2F2D02}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2D6C6115-6EF8-462A-A7BC-07413940EEE8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2DC2095F-8CDD-4537-A60C-04F0B4506D67}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2DE1A8BB-B00B-4386-B1B2-2C3E89FCE744}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2F4A3AC0-EF0C-4D02-AEE8-484DBFE7BFC3}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2FB8529F-8B68-4BE1-80CD-CB798743B4C0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{2FDFA1BE-72EC-4C6A-AB69-BE6428E056AC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{30E94168-632B-4D3F-880C-46062F9FDE04}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{31C67D09-49AD-44F2-8EAD-6BB23D3743FF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{33326089-029D-4DCA-BC7D-139719778347}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{33AE5AC9-3960-463A-91FA-B72FA79727F0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{33FA7ADC-72A6-4DE4-9D83-E6EDB77CEF72}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{34D00F52-3A96-4515-942C-0AF7C110B79F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{34E8201A-BD53-4CB5-AA04-118DCBB53090}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3545AA78-AD89-4CCF-92F5-399FEF1D5AC4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{36153626-E21E-4BE4-8230-DF836910957F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{36E90196-A631-412B-913A-75FDF9FF5CD5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{373069B0-E69A-429E-BB5B-CAFA86AA5CDB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{378A9007-E390-405B-A46A-A7D41DC1DEA2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{378CD4C8-8643-4D9C-B8B1-3FADF5330681}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{37FB7FA3-9600-4A85-A8A5-6A1015078C64}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{386B0972-E7FC-4A8A-AFAB-EB7655FCBD89}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{394D945A-3A55-453F-8070-99D5C7E00053}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{398EAD02-3CAD-4B96-B023-C67DECC79F8C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3A43FF9D-B10C-411D-8207-57860967D724}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3ABAA5B4-6ACE-41FF-B63B-24E6C39B4E93}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3B1F8EDD-80D7-40BA-A7AB-4B5A4A45EFA8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3BC77FF3-E48B-4077-8FD1-BBA9CA72E939}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3C026789-7358-4800-88F9-68F02F805F6A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3C4CE727-52DE-4E47-B62F-74D313CC9A21}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3CB15F44-7586-4FC1-9261-AA80A881A88A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3CF79239-0D9E-450D-86D1-BF20D2F103E5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3D76D65F-83CB-43AF-A3A0-FEEE01893FB7}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3D88CD92-F20D-49D5-B9DB-3CFDA943345B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3DE1D9C5-2D27-4968-9E4D-DFD04059817C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3DF223FC-ADDD-4194-85BC-670C9C49697F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3E0E2186-0594-41E9-8291-E54F3CB6C1BC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3E276347-8E66-4160-BB37-175CBAB7FE1C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3EA06A83-2ABA-4287-81B2-4D155108AAE1}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3F5B0164-83D7-4616-897A-B7A77643A4A1}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3F836CD0-6C68-45D5-B38C-1A7FBE695755}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{3FF43EA1-58EE-4A6E-B04E-FFFA14817E7C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{40405AF1-D73D-48EB-97C7-DD523D1CE5DD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{407A8484-5C38-4E3E-B523-46B089351EDA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{40B7B50A-BC17-4A50-A4FD-7F05D5658680}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{40B868E2-229F-4E8F-BF55-7E163477A41A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{40ED9653-A606-467D-883C-E8D6C6807FFC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4148B225-8699-45D4-8EEA-6ED4B0F47686}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{41B44791-DBCF-4B41-BD78-B3603A7D28EE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{41C5595C-4402-46D0-B5A5-9939103C3770}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{41C6BCE0-1361-4B32-964E-0D6EBD8C635A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{41DA5BD6-008C-4346-B848-F141EE1C4130}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{42738CEF-94CB-473E-B2E1-F2A0D9896D91}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{431924A9-3D8A-4EDA-AD7A-7250F47BD611}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{43803E8F-04EF-4341-B790-377332AC2C95}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{43B006FD-514F-491F-913F-931839DCD636}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{449B57D2-E4A3-4C74-B6AD-22286D3BB944}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{44A5A2E8-A650-47C4-A261-4E672DC628A7}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{45009E56-3523-4801-AD27-FED52B156883}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{452EF96B-3465-4629-B1DF-58019008106C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{45356309-ADB2-4650-8A22-6929B1C4B57D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{459EF9AC-90CC-4112-A216-11D4AFFBAA57}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4600550C-8E38-4477-8978-A8769CE7A487}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{464087EE-DF64-447F-A25A-7771C359FC5D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{46BE68C3-6F0B-4DB1-9D46-5B1572070CFC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4706D7D2-5407-4A6E-B682-27D8795720FF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{47758C9F-338C-482D-B608-CC55419FEE09}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{478EA9D2-F6D4-4E30-96DD-6B0B5AB21677}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4927E822-EAD7-410A-80F7-E27340E3DEC4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4942FC84-C44C-4CE1-9E64-F3853B79448C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{496EB076-5E59-4326-A2B9-20E877EB332B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{499F69F5-B476-41E7-9305-FB8639B7DA4C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4A5ADD1B-D6A8-4093-8BA3-DAC32BC5CCE9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4A7A323D-0B50-4845-9C9E-FCBBE2C42933}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4B0F0C7E-E3E8-46B6-B07F-DCE84BA60EF2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4BA8E516-165C-4429-8E9A-21EE7FA3811B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4BE8919C-1819-4DF6-8BD7-4C51ACF8A8E0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4CCD1080-C334-4580-8E32-397F05611092}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4D0E0771-6ACD-45A0-931A-AAFDE3CDE17B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4D3BAD1B-713D-4C8B-8107-00260585D4BD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4D82B368-7D4C-4595-817C-75EFFFBB3217}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4E3B95AA-87E4-4714-A35D-17394A75612A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4E48475C-E1C5-47C2-B796-BD3EAA147E89}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4ED59DCB-2E27-4D60-B333-B132B9E5C9BF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4F178535-C22B-4C79-A470-574CF331332F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4F5B39BE-C533-4B6D-8C1F-8C5D478045D0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{4F7E163C-9D2E-4E68-B1FD-99E98AA3B998}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5009B03F-56CC-4753-9DCC-AE0ABF0BEB72}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5155A701-05AA-421D-A8E8-5DA627F0CF8B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{51A782FD-7881-4AD6-9257-66158AD7FB01}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{52C260E4-4DC4-4118-A07B-9583EE0B73D9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{53385146-7AA0-4601-8C20-0002A675F4ED}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{53390128-2E48-4EC1-9FD4-48AF329F5C8B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{53462D38-803D-4213-BC89-212A778D53B4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{53511AB4-CCF0-4028-9A1E-D7CDA262A3F8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5396F939-0ECC-46C9-9EA5-A50F8F57EA27}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{53EB240F-2109-4465-9051-9B6D64B2FBDB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{54E00587-B510-424A-A265-9ADC4A1918F5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5547F1B0-ED11-49DE-9B2A-5EE2E787D1DA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{56156F6E-9822-4DCF-A778-2CC07EA487A5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5724F061-DE4D-43C2-AAC0-C33D720A6E1F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{572D8A2E-3738-45D0-9938-1F1F5C353F26}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{579C8B13-E558-4929-8757-D5C1E7EBC63E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{57C4103D-FAA8-4576-B91C-397687530608}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{589FB6BD-8C95-4D41-85A4-0D7908EB3242}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{597EE9EC-0676-428A-A24B-B2DBC95D2A12}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5A1F010A-9F43-4715-9A53-E68945D4370F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5A39AC65-B795-4774-A8F1-730E17C73888}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5A719082-EC08-4275-B714-FC0A9D1E72AF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5BC12840-CC83-40BA-A040-1501B2265FBA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5C82F321-74E9-48B3-BF37-7FE63E28EB45}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5CD2BC60-17A3-4C02-8C77-5D2CE2D8810C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5CF88299-D8CF-4E67-B5D5-B2B10D6C3F95}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5E645CB4-3E05-4124-AF13-55EF6717D70D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{5F894FA4-F23C-4093-A1BF-8DF94E002B23}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{601A8441-7312-4485-856C-2D60DF362282}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{60AC420F-6D97-4112-BD81-3CEF4FD8A874}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{60BBC9C9-8F73-4CFF-9A78-7D09B85A9C0F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{60E6AAF8-D0C8-43C2-BE0E-F65DEFCB43F8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6132CE49-0234-433A-ACC1-04CCE1A6060F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{613E741D-FC57-433F-B020-514B14F0BBF8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{61B6304C-833B-43BF-B401-95BF6884D988}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{62079D96-BCD2-490F-BDC5-4FFB47A6BBE5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6257B9F5-98FD-442E-886D-F8B9DBEDEC1E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{626CB044-E4CF-4439-8E68-357D3BCC4047}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6278F0B2-6EB5-4F2E-8A87-D990B5743B65}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{630B2F56-55D9-4CE5-8B5C-982E91191F42}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{63ED789D-D25D-49CA-B307-85DCE04C7E73}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{646F682C-92A4-4E93-B2CB-70B56F68176F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{64F298D3-B04C-40D6-95B1-323FADA6E376}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{65336F45-2DC0-4FFF-BC97-038136077518}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{66001E02-80B1-417E-8DD2-A6606AF88A18}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{661FD113-462E-42B4-809E-F41C0134F7C7}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6708ECAD-D869-4698-8155-C789DF7210B9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{67FA2ABF-C45F-4042-9D11-700C9914056A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{69CD332A-E8DC-4A35-891F-FF1F9E7216BC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{69EDF78D-300C-4319-9F9B-760135D9ED3E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{69F4CC33-596A-4865-8F56-99C6C637B8BA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6AACCD90-7B3F-4805-974E-F8C6B139FF39}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6AC33423-A506-4971-AE1D-8B77337226C3}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6ACD53F9-2A2B-41A7-A69C-C232562B6310}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6B01E14F-A292-463A-972F-3BED38B137D5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6B6DF499-E2EC-4A70-96C6-76465D896FFD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6B8A47C2-DF24-4799-AEB4-F6F6C45BE044}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6C653743-B49F-42D7-A25A-212606C4F1CA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6C7B9ADA-609F-48D3-8AEF-EF992A0DF979}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6CB3979D-4621-489B-974D-8D3FDC273C5E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6D6A09D4-45C3-4293-A8F1-CB1631D78EA0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6DEF12DB-40EF-450F-B1E1-8EE66A18ACD1}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6E14BAA1-AE42-4F48-BA33-67F2892BB462}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6F49FE90-0FDA-4A98-A1C0-6641EFA4DD0B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6F4B947D-C2CD-451A-B1A4-7B1FB55A138A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{6F5086ED-F01A-4092-B937-1C16985087FD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7030E89C-EAD5-4B78-AA8F-E55A11D73611}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{70739DA4-311A-49AB-95BB-11DFCA746CE6}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{71192C14-370F-4D3D-B718-15D39D12B199}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{714E25DD-6208-4319-BD47-070F3D3D6541}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{71557135-2811-4F3D-9FB9-1E7438D07D5E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{71600536-D312-4027-BC23-2045727BF6F6}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{71BA72F2-F87B-4E72-B704-FD0CC69CF2F2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{71FD2C2B-4900-4AD7-9523-4D76654871E2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{72346A5E-974F-482F-BBFE-98B48C909CAE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{72350415-BCB5-4A49-A0D7-BD54AC28D145}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7264C1A8-99B7-4B0A-9A6F-6049170BD130}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{72AA7325-D89D-4AA5-A4DE-4FAE58009DC1}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{730F6C14-FAF3-44AE-A3F5-FBB7776536CC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{741DDFC2-9807-42B4-9B13-F5055B066D4D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{742D334E-2651-4B28-839F-67547FB4E7A6}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{748E5385-A979-4813-B0DA-93CC0E2A1FBC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{74CD7EFC-F295-4567-93DD-64E8ABD09F91}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{74D73A47-BCF9-4AA8-B129-64EFEA52A1CE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{74F0B047-0AD2-47DB-B6C1-7D8B93A4C4C9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{750BC199-EA82-46D0-9960-A0245963829B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{757D88B4-172E-4DA9-82CD-05561046653C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{763E1ABC-4910-4D68-8D31-C24D6D847050}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{76702668-FB10-49D0-8D7A-08DB75F087BA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{767D7542-CD5D-4362-8ACB-F71A45D7818E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{768723F6-1348-4D5F-B091-1A49B211DA49}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{76D9ACD9-D997-4FBB-869A-1CAC2943039B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{77132226-4995-4025-B7C0-6926D09C08CC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{777C2F4F-1E2D-40CA-B43C-C6C33251D85D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{779ED2AB-C327-4497-9700-1F767D2DFAE8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{78D88042-C79E-4297-95F4-094A1165507B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{797BDE29-8AE5-49A8-BAAF-920C4A7F88A3}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7AA74BCF-BFA2-4DE0-8A02-D1B7352882A4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7B1B8D31-20F7-452F-A501-22C7129227EB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7B8BF8DF-F977-4615-8884-41423731685B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7C579D9F-3B6F-49F2-A37B-9544761CCBF3}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7C814307-40C2-4444-88A7-F748142F27B4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7D3F4307-99FC-4BCE-B3D9-8D4790FB7DBB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7D72D0CE-6E49-4399-B168-82AF765E07A6}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7D7640BB-332B-4BCA-BF59-FB38DCB92793}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7D7D090A-8C21-4E9F-A310-3206454B22B1}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{7F973881-B4BC-463F-B449-9C6C2E089D05}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{800E280E-8C0D-4439-8723-9B00EA1E0744}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{80EE2B60-6161-446A-B61E-D98CF35009CA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{81C46F5B-6140-465E-9BEE-25C3D2BBD15E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{82333A33-CE64-4687-8DE0-F7DC3EEA9FB0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{82E30220-9E43-4C84-B58D-A3899926DCCC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{83A8EAAA-DAB7-4775-8CEC-CA987E8A2158}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8474D27E-150F-4672-802C-7708A84C92F7}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{84807B59-0953-49D8-A1FC-D4D76BDDD331}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{84B6EAE5-0264-48D3-9A51-08DD766B47A1}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{84CCE3CA-D35F-4004-8A76-70060C14EC1F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{85420985-4F2F-4908-A65C-243B18571351}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8562AD8F-6AE9-4F23-B6BC-109A6A097478}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{85D955DC-70B0-444D-B98E-C26131453D81}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{868BF3C4-6925-4B18-8F2C-36AFF011AD7B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8879E291-37E4-4EB9-AEE3-60BE263A232D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{88928F89-4FBC-44A3-9F5D-FA9112EDA444}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{889B11DB-B155-4C0A-9802-F1C07644C1D8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{889DB761-1C1D-42D5-947F-3691E000C0AA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{88AC918C-D9F1-43FF-9003-AC5703992BEF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{890A07C1-B51A-45C2-9C46-A34B83AC4100}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{895280B2-24C0-4B30-9B86-C4A0F403DFA3}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8A0A7908-25A7-4396-991A-175088CE631F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8A1133C1-E78F-4FB3-8BDD-D47977709ECD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8A18AD27-8A18-457B-86FA-054888E05F1A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8A598BC3-5ECB-4450-9CAC-504C7EE29694}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8AC194DA-15DD-4345-9BAF-EB76BD6CD382}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8AF0C9B5-1C60-403C-BAAD-A21A7081D753}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8AF1CCED-31A9-4057-9F37-BF6986A611F4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8B4CF4F6-E7E8-4FCE-A4A6-FEA3158844FC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8BD48994-E3F7-4CCA-A400-6E192B0F1D1E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8BE68166-9D7C-4AF6-AC55-72D6D5956DEB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8C5755C4-8620-470A-8580-8C8B1B90A117}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8C6191B6-693F-43B9-B77E-9DB0DB65A22C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8CF53C83-D505-4925-94F7-018842AA8F89}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8D818829-1D01-40D6-AD19-2DFE889CA280}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8E8B5D4E-4E56-4AC6-9AE0-4887368F3EDF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8E993BB7-C7EE-4B40-8814-2ECE5BB1772A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8EC746F0-03BE-4178-B739-5EA4BBA1C657}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{8F4CE52E-B80E-410B-84CB-E7239956B2AC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9036C232-8423-4389-BC65-86CF0EEB54EE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9069A8A9-2EB7-4FCC-AA84-2EB1E89D5EBD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9120F8BF-59A4-4809-98F3-9704CF84F56B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9171B643-2536-49D7-8022-AF0C5A690832}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{91BF99A2-3620-4BE8-A588-C6E68264C7F0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{92131C3A-65B7-4E44-8B95-25B25335A687}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{92723409-C147-43DF-A6B0-90B757565BBF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{92954594-BF98-422E-8B8D-4368AF9570CE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{92957D3D-B4DB-471A-9309-6E0142251F38}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{92CBBE46-61BC-49E6-B78D-D7CD773B0275}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{938DC990-BA32-4AB6-A2C6-6F9778C6BA7C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{93DDC593-E6EA-405F-8F17-230085E69716}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{95AF3546-7BE8-4215-BAB5-D320CE16403F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{95CC2D96-D03C-495E-97E3-D4EEB0C2E8C4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{95F147D0-3F17-4E0E-8D0D-F07297843204}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9637CA08-46D9-4477-87EA-C7781173596D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{964EE27F-83DC-44E3-BC1E-D3A9CFBBC694}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{968A98A7-D121-4744-8FC6-4008F85CF3DC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{96DBE679-B015-4E28-88D0-D34882DCD8C3}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9706FF62-F562-4F8D-AB34-5E97079A065E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{97E348B6-42FB-4FA4-B241-2F8EEE422469}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9881A0FF-CE4D-41EA-8A42-13BBCB1B73EE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{98C3B92B-2B04-44A5-A34B-C179937684EE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{992579B0-4696-4041-94BD-8B92CE26BBD9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{99C2B562-425F-4451-A805-6484040B7D4F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{99E119FD-EFB7-46FD-AD40-AC639D351B66}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9A530756-6880-4DCB-A3EA-B4304CCD66E8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9B342A72-7234-4A87-AA0E-2668EBFE88DF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9B39F697-8637-4511-8F37-2BD005DA7051}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9B7B8071-0989-4448-B675-4B02A7C48ED8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9D0A70B8-CF14-4DDA-98E2-5608832C0140}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9DFB069B-E639-40DF-A1FB-1F2E9F3EA9AD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9E71E3F4-F322-4617-A888-193CEFB8F408}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9E9C8A47-E97E-4EC4-A65D-35D03C6E124A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{9EEDEC5A-8D53-4694-A642-844FC6E161C8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A03EB4D5-6A5B-45B3-ACEF-F85991E90083}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A1469ED5-C2F1-4E97-B20A-3E6CC39299BC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A14774F6-CFEE-4FF3-A8C8-FA771329AE7A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A15F5266-9A1A-4787-BCE0-5579EFEA9448}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A2025904-A4D1-4B3A-9FE9-EDDAC285E155}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A2A638A6-6104-4CFA-8083-5B65CBA1BB45}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A2B8EDA0-7535-42C1-A107-344152197C81}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A2E7547D-02D5-4DD2-987C-C46682B39BF6}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A3A594B5-75FD-45CE-9122-FF7DBAF8AAD2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A3CB33F3-3259-4917-ADBE-E38C5A840158}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A524935E-5172-4BBA-992A-31E60624CC5E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A5DFCE9F-D090-4AE8-A177-3252CA60835E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A64CCF3D-52BC-4B71-8AB1-C5D12BC9B28E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A652C2F4-F668-476E-82BC-A3F1B1E62636}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A65E57EB-A543-497A-97FE-9FBFD435F4E7}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A6F59504-470F-4CCA-988E-5FFDC497B396}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A76F2B20-C56B-46F8-B48B-363ED65C1021}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A78F747A-14E8-45F8-895C-8878DDC715FD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A7ABED3D-DB96-4437-9BDB-547A18813987}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{A7E76556-4E48-46CF-B356-71B84FD89822}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{AA740861-3224-4200-924E-28FCDA795301}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{ABA24A00-2BCB-4044-BC01-768F0CC245DE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{AD48EF76-ED20-49FD-8B98-5D7EB0845781}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{AD8284E0-2EF0-493A-8437-91833A73E900}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{AE0A65BD-90BD-4CBC-B369-6A144C5289E6}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{AE9B18F0-2EA3-4163-9516-4801B137E824}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{AF0D18F0-FCD2-44C0-922A-DB3D624410EB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{AF30BF3A-7AE1-4C42-B4D2-EECE22629DB0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{AF7CEDB2-FA85-4B92-A0AB-268C2F74F294}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{AFA361E3-94D2-470A-B787-310BCB40576C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{AFF735E3-D092-477C-A4F7-69B4C6079887}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B051C630-B98E-4D70-AC8C-D0EE31A34272}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B07BC6B1-B922-4E13-AF92-4BEA6E995C53}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B0EC3B51-40FF-4045-86DB-7BB3BB725544}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B152FA83-CFB4-40D8-AA1F-81D21F8EF5F4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B1A86ACF-B336-4494-BF02-9A73CBA658A2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B29E116C-534D-4531-9F21-18F69D7A89F8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B2BA0D83-CD2A-4EC7-A24C-3EEACF63D520}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B3331C9E-333A-4DF4-8477-5E01245AD257}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B3DD390F-F0B8-4C55-BA03-51198172F73D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B433B4CA-F79D-45EA-8CB0-6B15B4EBDE57}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B451FC50-8DE7-4FFA-8EF4-8A771F1FBA96}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B49676CB-D433-40FE-AFFB-A09C79C96CAE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B52D131C-5986-4F53-B514-663FEA22F758}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B5AA4973-624A-4628-9F36-D77BD19E4715}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B5BA7842-27DB-4493-ADAD-7D6FEE83BC75}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B6BD95B0-9619-4B08-B54E-C1C7CE80F762}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B6D2ACC2-2033-4B51-8DBD-04521A738C39}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B7944906-8641-42B5-9443-E28E8DB8F70F}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B80D1079-7E18-4D3F-8381-4E2BAFF64101}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B9192374-9E25-4120-B3FC-2E62FFD58481}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B9D77813-7B98-4487-9070-403812FBC001}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{B9E85F42-72B5-44A1-950E-03703BDC974E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BAFD48FF-9C3E-40A8-97BF-001624734B9D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BB27E58C-0AE5-419B-A6FA-BF8C3BDE0834}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BB715E92-B17F-4C4F-B579-5CB243D8A659}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BB9821B3-F946-4DAB-8ABF-E199787413C2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BBA2557D-820D-413A-877D-F3CE6BB7E909}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BBE55B8E-0CD2-47C8-92C0-43FC7B7DC2C5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BBFB1381-E69C-432C-BB3B-9B76082374FA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BC64DE72-E2AB-4A46-8ED9-AA5715B97442}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BD190C99-F9D3-4FBF-89E1-212F279CCB51}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BD2405DE-63DE-452F-9A31-66E71FA24AA9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BDA49A89-51AD-4D3E-A69A-B517F92D8989}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BDC2DF1F-E111-40BE-B100-8A78F72632F4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BE1624BB-CA85-44A9-9DF9-626BE561DE89}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BE941E0C-213A-470C-B6AD-38AD6AF22742}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BED011D8-7D35-46CA-AB77-E468C35172B5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BF1D28DA-9611-4655-8F3B-2C43326E9F39}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{BFDADEB0-7034-41EF-BF20-010DA3E06131}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C04B5374-A17A-42D5-8316-DBC125A48CB6}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C124923F-C325-446D-8D0D-3C3312A4F603}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C12495B0-917F-4493-A735-91561D577BE8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C19D7C9E-7EBB-43CF-B870-7DCFBD21BDA9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C1D0D48A-DAA7-459E-9847-19B7CEBA1A22}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C2008F69-09FB-4A60-A91C-84D38B716757}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C208C240-8F29-4837-A694-A2EDC5044B9D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C2475F4A-8AB5-42D4-8AF4-8B6B198EEC85}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C2AB21D9-AF43-4450-B688-77E2CBD4F2D7}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C33A6CA7-6518-414C-8D3B-EFC271F2A030}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C39C3746-3D2C-4473-977B-4E4B9A353B97}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C457E651-EDD9-47E5-B418-BA3DD7448268}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C4C2DFA0-1A6A-416D-8977-EE091B39B167}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C4C913EF-AE6C-440D-BEDF-98DB1BD01789}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C4CA0A4A-E6F9-4E04-A71C-ED051259E474}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C5117695-194E-4FF6-A44D-E474EA794F60}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C5455A3C-A70F-4391-AFF7-197F363AA7DC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C642CE9B-FD4A-4BE7-9394-8B33C6DF8C93}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C67039A6-CC2F-46FC-BC11-42BFCDA45E79}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C75BA187-BF95-4BEA-B7AF-A6F2AEA439B3}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C77BEB8D-3ED3-4EB3-9C2A-E44687D66A5C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C83B2847-5F41-4A3A-AE77-97412AD2A4B5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C83F921E-8EE9-48AF-BB56-8B11440EF54E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C9973315-3E91-4574-BD85-63CDBEA7D51D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C99AD961-3165-43A2-919A-E359430005CD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{C9DB6B6E-708D-49AF-BD44-DCD1930DCB2E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CB09655E-12F1-402C-97A6-674DF1ADBE55}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CB24D2AB-4143-4638-861A-DC4FE31FBF37}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CD781410-3D63-41B4-8495-DC842283BFF9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CDC21E07-0529-43BC-A2F5-4491B5ECEAEE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CDD329D3-47EE-4094-B4DE-8132A89BCCAA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CDF3B980-DF6F-4400-A3CA-7A9CC455E208}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CDFEA1B1-E827-497C-A6B0-0201D76AE186}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CE649420-2B59-4C42-A45F-0840F8431999}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CE96FA95-70F5-4C1A-BDF7-FF7EB22BE482}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CEAD7C0B-5222-4163-BD95-9B427E42CE71}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CEC0F68D-165B-4D9A-AC3B-03E287B5BFA7}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CEE53682-DC13-4A6B-B6E7-E65989487EFA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CF551893-3647-42C2-AA21-EFC764588CC9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CF825719-0194-4B76-AB57-3ACCAA64915D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CFA954A6-C02B-4D13-B61D-315B6D808C0C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CFE84DE6-FBA6-4692-B995-FF7BAA8243AD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{CFF59EE1-46DB-4D7D-AB84-731F901432CE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D0622970-C87E-450D-8187-A1153D558246}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D0E29149-A842-4AD8-A23C-E2904C0D598A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D116AFEB-C838-4085-A777-A36E48189F09}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D13C002C-32E1-4A1D-B3C6-3CDD77303471}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D1A64760-1A6D-4CB3-9578-9A4047B42C71}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D1BD35C6-5D9D-4D76-90E4-DB7EB6F2F4B6}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D1EE84ED-C1E7-4373-AB0A-204518ED8EFB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D23F17CA-3643-419A-933A-33D203416846}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D250AEF8-1251-4D7A-87FD-9D170F7F5F15}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D2D8490A-6006-4956-B118-80F81FA2EFAE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D3156CE9-9B16-4C3A-AB41-EC617F8F6E73}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D36C09E9-EF0C-41CF-8D08-67FBBC430EC2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D3ADCCB1-410C-44F5-B6D5-2F4D10FB6183}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D3BA831D-76C8-42BE-9FC6-2CD75FE0C6D4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D3D14791-762D-4BBA-A0CB-541B50383AEB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D3E43435-5730-46D8-B57D-E0411F37DD04}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D41F302B-4406-40A1-9225-8AB2BFAE5A05}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D4C24C45-A1E6-41A1-A97C-1D8D992D486D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D55B2D62-D337-4311-8DD8-CEF744402D27}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D603BD3E-C5AB-4E6F-AD76-46F0C548A17B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D6C7FDC6-BA1C-49DA-8479-63DC165A8F28}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D7983CE9-DF2B-4147-B27E-D1E8690FB28B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D7B9A832-6ECE-4CB8-9DC7-437E3969C2E9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D8208908-8BE9-4BCD-A7E2-F9C20F36D10E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D8CE6B1C-CE17-4B40-B150-78E9BC6C4C36}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D9485058-B222-497D-8505-66658F0A80E2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{D9E7B649-1AED-4EE1-99F2-11AD6D0835A7}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DA2C7B99-9142-45F7-AF3D-242641018B0B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DB8DC52B-35C6-4099-A3FC-CC24070BBCAB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DC1AD89C-093C-4355-A3CE-F859812B37FD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DC4FE887-A76A-477F-8BB0-01960928C33E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DCD75004-703D-4218-9C3D-BDB2727CF47D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DD25BDC7-B460-4B35-B4E8-2E186AA630C5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DDAC39B1-7EDF-485C-B2D7-357BBB7193F0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DDC99803-D46C-49E5-8CED-AA77B37F8F17}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DE509968-495E-4C68-B41B-7F72DED40E2E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DE581537-DCE6-4F51-91D2-C487C97CE2ED}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DE595531-E696-4EE6-B54B-6201387D1A30}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DECEAB6F-BCF4-458A-87F2-EFD9F92BAE0E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DF585F6E-7C42-4549-A325-070EA9E66141}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{DFCC56AF-0F0D-4B34-AA35-DAFF7A3960CE}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E0C8BF07-47E8-4593-BE0D-1F3D57E704ED}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E0DDB9C6-A868-4065-9440-17ABCE03073E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E0E40FFD-7F97-4CD0-BA92-E4B6E74BF065}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E25C8B90-8720-41F9-99B7-AA4AE5392105}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E32774FC-7702-4738-A1A2-42C3B312D9D2}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E3F98F7D-7019-4612-ACEB-07641FD12FEF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E48A52A1-C03A-4496-8857-FF005EAE14A0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E5A64AE5-5FBD-4326-AB22-E9A5022C3519}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E60C5EAE-D57F-4FE3-8CE2-A58A0EFD2EBC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E6EDB037-77D6-48D9-8CE9-FFA9FF4E62D9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E831D6E1-01C5-4A57-A93B-91115B409567}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E8A41027-B662-4B31-BBBB-1BE8211219EB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{E9227B84-183A-4BF1-8095-7B8E4A14E448}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EA1731E2-B185-4DA8-9839-809A4123186D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EA7C5EA6-4737-4BBB-BFB0-733AC582EB96}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EAD8FE90-C4AB-416D-A24F-618A2ABED1A0}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EB0D710F-C0E0-4B89-A270-E5D4FC60086E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EB5AF16E-3B30-4526-A231-D2C4F7576670}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EB8E0433-8049-4A84-9814-7E6DBA7F4E70}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EBE1773A-EA7E-4ABB-9C95-CDE112AE320B}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EBF96F93-3006-4BBA-B7F4-7674142A6D57}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EC19D877-B042-4AAB-AC2B-78B1E3A9AA80}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{ECE44869-D911-432A-9952-0FC594C672E9}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{ED1D7131-28A6-4077-85E4-475B53DCC239}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{ED2B13BF-2B0D-4C06-9AED-2E2BA17823C8}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EDC5902F-AE61-4F89-AC92-FA60C5245348}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EDCE090B-5610-4D49-9BA2-663EDE6AA4EA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EE7C096E-C8F7-4645-B95D-4BF4E17BE934}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{EE9340C6-BA05-4672-8182-4F6ADD85ADD5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F056E4EC-CB91-4327-AD40-79E72B2B4D00}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F0A88463-C11C-4A5E-8A9A-C468076E57CA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F0BBC889-4324-47B1-85FD-A69F0A12DDEC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F0C65E20-3375-4A4A-A64C-7D36D7B6CF93}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F1477D25-1229-49B1-A992-6129C2BAE0FF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F174E4DD-E1E2-42CC-8216-32199CDB86EF}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F1CEEBED-72BE-4C2C-BCE3-26EE8C8FC4C4}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F2AA4A91-2364-45D5-8768-4F593C464C16}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F31DD207-70C5-42C3-9A44-D41B6D10A4E7}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F35F87E7-C15A-45C9-960B-46C1D56562AC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F3F1AB66-3291-4D92-A90F-54030E37EED5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F4017641-56B6-4729-B704-95A50ADEA1FB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F48E5A2A-29EE-4E7B-89C0-E0AA5BB9CBB3}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F4CE1766-3DFF-43E7-BC36-BCC8A1E23128}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F5AA47DC-0A09-478B-81EA-BCD38B4A4737}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F601E337-B26B-4117-B820-8C148D130B08}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F61F10B6-A346-4E6A-B195-DE6AEE28B1B5}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F65BAAF4-16A7-4647-AB4E-CB6C42DB2984}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F6AE9699-BB39-4350-B19E-04C20610916E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F6C6AE01-5EA2-46C5-931B-6DCF1259258A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F74D4F71-3712-4300-A7F6-98E0C9B25B0C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F7BC1A61-F4E2-402F-BC24-1852B48FE22D}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F8A0761A-D40B-4A97-B0C0-D2A905A4F6DC}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F8BA8CD5-090F-4F5D-9E99-1A5ECB7CBC42}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F8D79AD1-A7BF-4A1B-B2B3-995A4E1E0B81}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{F8E98C71-6676-46A1-B5F2-68A7EB3C4E5A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FA22C7DA-7FC7-4C2D-817F-3044F12674FB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FAC51DB5-3E82-4A9A-AFFB-3F20D6BC8712}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FADF2CAD-2227-4626-AE33-553FC9487DAA}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FB862947-2955-4F29-AE0C-AF1DC8A64CDB}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FBA8F2EB-AE48-4314-A8D1-3C3862F4C14C}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FBC3B9AD-CE27-448E-BFE3-890007821A47}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FD37BC1B-6022-44E6-B2EA-533A08F6DC8E}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FDBD8B0D-982D-4565-B921-8170FDC8D072}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FDBF8FA6-D587-4B99-8865-5BFB7E970C60}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FEA160C3-0EEA-4FD3-8F96-F65B5FC02767}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FF442F87-A775-4E12-AB3B-F1E9790EFDDD}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FFC5C468-13E8-437F-BB2E-26F922DD230A}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FFE80416-1362-479A-850C-AE3AC4860746}
Successfully deleted: [Empty Folder] C:\Users\mKy\appdata\local\{FFEFF6CF-FCA5-4A6F-888D-B5235B9610FC}



~~~ FireFox

Emptied folder: C:\Users\mKy\AppData\Roaming\mozilla\firefox\profiles\wbur3zd3.default-1372892069866\minidumps [2 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08.07.2013 at 13:35:09,39
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013
Ran by mKy (administrator) on 08-07-2013 13:37:10
Running from C:\Users\mKy\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files\Common Files\WireHelpSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Akamai Technologies, Inc.) C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(Spotify Ltd) C:\Users\mKy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Spotify Ltd) C:\Users\mKy\AppData\Roaming\Spotify\spotify.exe
(Akamai Technologies, Inc.) C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CtHelper.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11613288 2010-11-19] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-21] (Microsoft Corporation)
HKCU\...\Run: [Akamai NetSession Interface] "C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe" [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [Facebook Update] "C:\Users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-08-01] (Facebook Inc.)
HKCU\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-01-10] ()
HKCU\...\Run: [Spotify Web Helper] "C:\Users\mKy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1104384 2013-07-07] (Spotify Ltd)
HKCU\...\Run: [Spotify] "C:\Users\mKy\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [4640768 2013-07-07] (Spotify Ltd)
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18680424 2013-05-08] (Skype Technologies S.A.)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL [x]
HKLM-x32\...\Run: [CTHelper] CTHELPER.EXE [19456 2010-03-18] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-29] ()
HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [2255184 2013-06-28] (LogMeIn Inc.)
Startup: C:\Users\mKy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL = 
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\mKy\AppData\Roaming\Mozilla\Firefox\Profiles\wbur3zd3.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @raidcall.en/RCplugin - C:\Users\mKy\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: @raidcall.kr/RCplugin - C:\Users\mKy\AppData\Roaming\RCKR\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\mKy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-02] (Avira Operations GmbH & Co. KG)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWow64\GameMon.des [5127200 2013-05-27] (INCA Internet Co., Ltd.)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-12-12] ()
R2 WireHelpSvc; C:\Program Files\Common Files\WireHelpSvc.exe [168864 2012-01-24] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-04-25] (Avira GmbH)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-04-27] (Avira GmbH)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2012-05-02] (Avira GmbH)
S3 CT20XUT.DLL; C:\Windows\System32\CT20XUT.DLL [252712 2007-04-10] (Creative Technology Ltd.)
S3 CTEAPSFX.DLL; C:\Windows\System32\CTEAPSFX.DLL [219432 2007-04-10] (Creative Technology Ltd)
S3 CTEDSPFX.DLL; C:\Windows\System32\CTEDSPFX.DLL [321832 2007-04-10] (Creative Technology Ltd)
S3 CTEDSPIO.DLL; C:\Windows\System32\CTEDSPIO.DLL [190248 2007-04-10] (Creative Technology Ltd)
S3 CTEDSPSY.DLL; C:\Windows\System32\CTEDSPSY.DLL [363304 2007-04-10] (Creative Technology Ltd)
S3 CTEXFIFX.DLL; C:\Windows\System32\CTEXFIFX.DLL [1571112 2007-04-10] (Creative Technology Ltd.)
S3 CTHWIUT.DLL; C:\Windows\System32\CTHWIUT.DLL [123688 2007-04-10] (Creative Technology Ltd.)
R3 ESLvnic1; C:\Windows\System32\DRIVERS\ESLvnic.sys [25528 2012-01-24] (Turtle Entertainment GmbH)
R2 ESLWireAC; C:\Windows\system32\drivers\ESLWireACD.sys [147472 2012-01-24] (<Turtle Entertainment>)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 ALSysIO; \??\C:\Users\mKy\AppData\Local\Temp\ALSysIO64.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 COMMONFX.DLL; system32\COMMONFX.DLL [x]
S3 CTAUDFX.DLL; system32\CTAUDFX.DLL [x]
S3 CTERFXFX.DLL; system32\CTERFXFX.DLL [x]
S3 CTSBLFX.DLL; system32\CTSBLFX.DLL [x]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-08 13:35 - 2013-07-08 13:35 - 00063939 ____A C:\Users\mKy\Desktop\JRT.txt
2013-07-08 13:31 - 2013-07-08 13:31 - 00000000 ____D C:\Windows\ERUNT
2013-07-08 13:31 - 2013-07-08 13:31 - 00000000 ____D C:\JRT
2013-07-08 13:26 - 2013-07-08 13:27 - 00002859 ____A C:\AdwCleaner[S1].txt
2013-07-08 13:26 - 2013-07-08 13:26 - 00547139 ____A (Oleg N. Scherbakov) C:\Users\mKy\Desktop\JRT.exe
2013-07-08 13:25 - 2013-07-08 13:25 - 00650027 ____A C:\Users\mKy\Desktop\adwcleaner(1).exe
2013-07-07 22:16 - 2013-07-07 22:16 - 00013567 ____A C:\ComboFix.txt
2013-07-07 22:07 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe
2013-07-07 22:07 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe
2013-07-07 22:07 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-07-07 22:07 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-07-07 22:07 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-07-07 22:07 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe
2013-07-07 22:07 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe
2013-07-07 22:07 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe
2013-07-07 22:05 - 2013-07-07 22:16 - 00000000 ____D C:\Qoobox
2013-07-07 22:05 - 2013-07-07 22:15 - 00000000 ____D C:\Windows\erdnt
2013-07-07 22:03 - 2013-07-07 22:04 - 05087001 ____R (Swearware) C:\Users\mKy\Desktop\ComboFix.exe
2013-07-07 21:52 - 2013-07-07 21:54 - 00021031 ____A C:\Users\mKy\Desktop\Addition.txt
2013-07-07 21:46 - 2013-07-07 21:46 - 00000000 ____D C:\FRST
2013-07-07 21:44 - 2013-07-07 21:45 - 01934636 ____A (Farbar) C:\Users\mKy\Desktop\FRST64.exe
2013-07-07 20:51 - 2013-07-07 20:51 - 00087572 ____A C:\Users\mKy\Desktop\Extras.Txt
2013-07-07 20:50 - 2013-07-07 20:50 - 00083088 ____A C:\Users\mKy\Desktop\OTL.Txt
2013-07-07 20:44 - 2013-07-07 20:44 - 00602112 ____A (OldTimer Tools) C:\Users\mKy\Desktop\OTL.exe
2013-07-07 20:44 - 2013-07-07 20:44 - 00000468 ____A C:\Users\mKy\Desktop\defogger_disable.log
2013-07-07 20:44 - 2013-07-07 20:44 - 00000000 ____A C:\Users\mKy\defogger_reenable
2013-07-07 20:42 - 2013-07-07 20:42 - 00050477 ____A C:\Users\mKy\Desktop\Defogger.exe
2013-07-07 19:45 - 2013-07-07 19:45 - 00003495 ____A C:\AdwCleaner[R1].txt
2013-07-07 19:43 - 2013-07-07 19:43 - 00002094 ____A C:\Users\mKy\Desktop\RKreport[0]_S_07072013_194312.txt
2013-07-07 19:41 - 2013-07-07 19:44 - 00000000 ____D C:\Users\mKy\Desktop\RK_Quarantine
2013-07-07 19:38 - 2013-07-07 19:38 - 00208216 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\31978637.sys
2013-07-07 19:38 - 2013-07-07 19:38 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-07-07 19:34 - 2013-07-07 19:36 - 00019385 ____A C:\Users\mKy\Downloads\Result.txt
2013-07-07 19:33 - 2013-07-07 19:33 - 00915456 ____A C:\Users\mKy\Downloads\RogueKiller.exe
2013-07-07 19:28 - 2013-07-07 19:28 - 00760775 ____A (Farbar) C:\Users\mKy\Downloads\MiniToolBox.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\mKy\Downloads\tdsskiller.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 00650027 ____A C:\Users\mKy\Downloads\AdwCleaner.exe
2013-07-06 02:08 - 2013-07-06 02:08 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-07-04 00:54 - 2013-07-04 00:54 - 00000000 ____D C:\Users\mKy\Desktop\Alte Firefox-Daten
2013-07-03 22:15 - 2013-07-04 00:59 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-03 22:15 - 2013-07-04 00:59 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-03 10:48 - 2013-07-03 10:48 - 00237568 ____A (CompulsiveCode - The Programs I Write) C:\Users\mKy\Downloads\JPEGtoPDF37.exe
2013-07-03 04:58 - 2013-07-03 04:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 01:43 - 2013-07-02 01:44 - 07236481 ____A C:\Users\mKy\Downloads\Ex.iBot-R v1.73.rar
2013-07-01 16:00 - 2013-07-01 16:00 - 00555240 ____A C:\Windows\Minidump\070113-21325-01.dmp
2013-07-01 03:45 - 2013-07-01 04:00 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadR_071
2013-07-01 03:24 - 2013-07-01 03:42 - 1842256513 ____A C:\Users\mKy\Downloads\SilkroadR_071.zip
2013-06-27 23:30 - 2013-06-27 23:30 - 31272077 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_403(for_v1_400_402).exe
2013-06-27 23:25 - 2013-06-27 23:42 - 00000000 ____D C:\Program Files (x86)\Silkroad
2013-06-27 23:23 - 2013-06-27 23:23 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400
2013-06-27 22:20 - 2013-06-27 22:20 - 00001898 ____A C:\Users\mKy\Desktop\SilkroadR.lnk
2013-06-27 22:16 - 2013-06-27 22:28 - 00000000 ____D C:\Program Files (x86)\SilkroadR
2013-06-27 22:14 - 2013-06-27 23:23 - 1361456630 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400.zip
2013-06-27 22:13 - 2013-06-27 22:13 - 01125376 ____A (PlayWhat) C:\Users\mKy\Downloads\528!SilkroadOnline_GlobalOfficial_v1_400.exe.exe.htm
2013-06-27 22:12 - 2013-06-27 23:28 - 00001889 ____A C:\Users\mKy\Desktop\Silkroad.lnk
2013-06-27 21:13 - 2013-05-27 00:30 - 05127200 ____A (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des
2013-06-27 21:12 - 2013-06-27 21:12 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
2013-06-27 21:12 - 2005-01-04 11:43 - 00004682 ____A (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\npptNT2.sys
2013-06-27 21:12 - 2003-07-20 20:17 - 00005174 ____A C:\Windows\SysWOW64\nppt9x.vxd
2013-06-27 20:50 - 2013-06-27 20:50 - 00000000 ____D C:\ProgramData\Overwolf
2013-06-27 20:49 - 2013-06-27 21:24 - 00000000 ____D C:\Program Files (x86)\Overwolf
2013-06-27 20:44 - 2013-06-27 20:51 - 00000000 ____D C:\Users\mKy\AppData\Local\Overwolf
2013-06-27 20:35 - 2013-06-27 20:35 - 00000000 ____D C:\Program Files (x86)\Games-Masters.com
2013-06-27 20:30 - 2013-06-27 22:09 - 00001040 ____A C:\Users\mKy\Downloads\_predownloadpath.dat
2013-06-27 20:26 - 2013-06-27 20:26 - 02607616 ____A C:\Users\mKy\Downloads\PSROR_Full_Client_Downloader_v3(2).exe
2013-06-27 20:07 - 2013-06-27 20:28 - 1260483304 ____A (Games-Masters.com                                           ) C:\Users\mKy\Downloads\CABAL_Online_Europe_Installer.exe
2013-06-20 14:33 - 2013-06-20 14:33 - 00004915 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-20 14:33 - 2013-06-12 21:47 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-20 14:33 - 2013-06-12 21:43 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-20 14:33 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-20 14:33 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-20 14:32 - 2013-06-20 14:32 - 00903592 ____A (Oracle Corporation) C:\Users\mKy\Downloads\jxpiinstall(3).exe

==================== One Month Modified Files and Folders =======

2013-07-08 13:37 - 2013-01-10 11:05 - 00000000 ____D C:\Users\mKy\AppData\Local\PMB Files
2013-07-08 13:35 - 2013-07-08 13:35 - 00063939 ____A C:\Users\mKy\Desktop\JRT.txt
2013-07-08 13:35 - 2009-07-14 06:45 - 00035088 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-08 13:35 - 2009-07-14 06:45 - 00035088 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-08 13:34 - 2012-11-23 08:53 - 00000000 ____D C:\Users\mKy\AppData\Roaming\Spotify
2013-07-08 13:31 - 2013-07-08 13:31 - 00000000 ____D C:\Windows\ERUNT
2013-07-08 13:31 - 2013-07-08 13:31 - 00000000 ____D C:\JRT
2013-07-08 13:30 - 2012-01-28 21:20 - 00000000 ____D C:\Users\mKy\AppData\Roaming\Skype
2013-07-08 13:29 - 2012-12-19 00:20 - 00000000 ____D C:\Users\mKy\AppData\Local\LogMeIn Hamachi
2013-07-08 13:28 - 2012-01-29 03:18 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-08 13:28 - 2010-11-21 05:47 - 00143274 ____A C:\Windows\PFRO.log
2013-07-08 13:28 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-08 13:28 - 2009-07-14 06:51 - 00046327 ____A C:\Windows\setupact.log
2013-07-08 13:27 - 2013-07-08 13:26 - 00002859 ____A C:\AdwCleaner[S1].txt
2013-07-08 13:27 - 2012-01-29 02:51 - 02060586 ____A C:\Windows\WindowsUpdate.log
2013-07-08 13:26 - 2013-07-08 13:26 - 00547139 ____A (Oleg N. Scherbakov) C:\Users\mKy\Desktop\JRT.exe
2013-07-08 13:25 - 2013-07-08 13:25 - 00650027 ____A C:\Users\mKy\Desktop\adwcleaner(1).exe
2013-07-08 12:39 - 2012-08-01 00:34 - 00000920 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000UA.job
2013-07-08 00:39 - 2012-08-01 00:34 - 00000898 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000Core.job
2013-07-07 22:16 - 2013-07-07 22:16 - 00013567 ____A C:\ComboFix.txt
2013-07-07 22:16 - 2013-07-07 22:05 - 00000000 ____D C:\Qoobox
2013-07-07 22:16 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-07-07 22:15 - 2013-07-07 22:05 - 00000000 ____D C:\Windows\erdnt
2013-07-07 22:14 - 2012-01-29 02:54 - 00000000 ___AD C:\users\mKy
2013-07-07 22:14 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini
2013-07-07 22:04 - 2013-07-07 22:03 - 05087001 ____R (Swearware) C:\Users\mKy\Desktop\ComboFix.exe
2013-07-07 21:54 - 2013-07-07 21:52 - 00021031 ____A C:\Users\mKy\Desktop\Addition.txt
2013-07-07 21:46 - 2013-07-07 21:46 - 00000000 ____D C:\FRST
2013-07-07 21:45 - 2013-07-07 21:44 - 01934636 ____A (Farbar) C:\Users\mKy\Desktop\FRST64.exe
2013-07-07 20:51 - 2013-07-07 20:51 - 00087572 ____A C:\Users\mKy\Desktop\Extras.Txt
2013-07-07 20:50 - 2013-07-07 20:50 - 00083088 ____A C:\Users\mKy\Desktop\OTL.Txt
2013-07-07 20:44 - 2013-07-07 20:44 - 00602112 ____A (OldTimer Tools) C:\Users\mKy\Desktop\OTL.exe
2013-07-07 20:44 - 2013-07-07 20:44 - 00000468 ____A C:\Users\mKy\Desktop\defogger_disable.log
2013-07-07 20:44 - 2013-07-07 20:44 - 00000000 ____A C:\Users\mKy\defogger_reenable
2013-07-07 20:42 - 2013-07-07 20:42 - 00050477 ____A C:\Users\mKy\Desktop\Defogger.exe
2013-07-07 19:45 - 2013-07-07 19:45 - 00003495 ____A C:\AdwCleaner[R1].txt
2013-07-07 19:44 - 2013-07-07 19:41 - 00000000 ____D C:\Users\mKy\Desktop\RK_Quarantine
2013-07-07 19:43 - 2013-07-07 19:43 - 00002094 ____A C:\Users\mKy\Desktop\RKreport[0]_S_07072013_194312.txt
2013-07-07 19:38 - 2013-07-07 19:38 - 00208216 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\31978637.sys
2013-07-07 19:38 - 2013-07-07 19:38 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-07-07 19:36 - 2013-07-07 19:34 - 00019385 ____A C:\Users\mKy\Downloads\Result.txt
2013-07-07 19:33 - 2013-07-07 19:33 - 00915456 ____A C:\Users\mKy\Downloads\RogueKiller.exe
2013-07-07 19:28 - 2013-07-07 19:28 - 00760775 ____A (Farbar) C:\Users\mKy\Downloads\MiniToolBox.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\mKy\Downloads\tdsskiller.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 00650027 ____A C:\Users\mKy\Downloads\AdwCleaner.exe
2013-07-06 02:08 - 2013-07-06 02:08 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-07-06 02:07 - 2012-05-28 11:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-06 02:07 - 2012-04-28 19:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-05 07:52 - 2012-05-28 11:39 - 00001113 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-07-04 00:59 - 2013-07-03 22:15 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-04 00:59 - 2013-07-03 22:15 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-04 00:59 - 2012-02-07 17:52 - 00000000 ____D C:\Users\mKy\AppData\Local\Adobe
2013-07-04 00:54 - 2013-07-04 00:54 - 00000000 ____D C:\Users\mKy\Desktop\Alte Firefox-Daten
2013-07-04 00:47 - 2012-01-28 20:52 - 00000000 ____D C:\Users\mKy\AppData\Roaming\TS3Client
2013-07-03 10:48 - 2013-07-03 10:48 - 00237568 ____A (CompulsiveCode - The Programs I Write) C:\Users\mKy\Downloads\JPEGtoPDF37.exe
2013-07-03 04:59 - 2013-07-03 04:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 01:44 - 2013-07-02 01:43 - 07236481 ____A C:\Users\mKy\Downloads\Ex.iBot-R v1.73.rar
2013-07-01 16:02 - 2012-11-23 08:54 - 00000000 ____D C:\Users\mKy\AppData\Local\Spotify
2013-07-01 16:00 - 2013-07-01 16:00 - 00555240 ____A C:\Windows\Minidump\070113-21325-01.dmp
2013-07-01 16:00 - 2012-03-20 14:40 - 506566888 ____A C:\Windows\MEMORY.DMP
2013-07-01 16:00 - 2012-03-20 14:40 - 00000000 ____D C:\Windows\Minidump
2013-07-01 04:00 - 2013-07-01 03:45 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadR_071
2013-07-01 03:42 - 2013-07-01 03:24 - 1842256513 ____A C:\Users\mKy\Downloads\SilkroadR_071.zip
2013-06-30 00:27 - 2009-07-14 06:45 - 00301832 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-28 17:35 - 2012-01-28 20:59 - 00064080 ____A C:\Users\mKy\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-28 15:34 - 2012-05-28 12:34 - 00000000 ____D C:\Program Files (x86)\Heroes of Newerth
2013-06-28 09:27 - 2012-02-04 16:44 - 00000000 ____D C:\Users\mKy\AppData\Local\Akamai
2013-06-27 23:42 - 2013-06-27 23:25 - 00000000 ____D C:\Program Files (x86)\Silkroad
2013-06-27 23:30 - 2013-06-27 23:30 - 31272077 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_403(for_v1_400_402).exe
2013-06-27 23:28 - 2013-06-27 22:12 - 00001889 ____A C:\Users\mKy\Desktop\Silkroad.lnk
2013-06-27 23:23 - 2013-06-27 23:23 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400
2013-06-27 23:23 - 2013-06-27 22:14 - 1361456630 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400.zip
2013-06-27 22:28 - 2013-06-27 22:16 - 00000000 ____D C:\Program Files (x86)\SilkroadR
2013-06-27 22:20 - 2013-06-27 22:20 - 00001898 ____A C:\Users\mKy\Desktop\SilkroadR.lnk
2013-06-27 22:13 - 2013-06-27 22:13 - 01125376 ____A (PlayWhat) C:\Users\mKy\Downloads\528!SilkroadOnline_GlobalOfficial_v1_400.exe.exe.htm
2013-06-27 22:09 - 2013-06-27 20:30 - 00001040 ____A C:\Users\mKy\Downloads\_predownloadpath.dat
2013-06-27 21:24 - 2013-06-27 20:49 - 00000000 ____D C:\Program Files (x86)\Overwolf
2013-06-27 21:12 - 2013-06-27 21:12 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
2013-06-27 20:51 - 2013-06-27 20:44 - 00000000 ____D C:\Users\mKy\AppData\Local\Overwolf
2013-06-27 20:50 - 2013-06-27 20:50 - 00000000 ____D C:\ProgramData\Overwolf
2013-06-27 20:35 - 2013-06-27 20:35 - 00000000 ____D C:\Program Files (x86)\Games-Masters.com
2013-06-27 20:28 - 2013-06-27 20:07 - 1260483304 ____A (Games-Masters.com                                           ) C:\Users\mKy\Downloads\CABAL_Online_Europe_Installer.exe
2013-06-27 20:27 - 2012-01-28 20:40 - 00000000 ____D C:\Spiele
2013-06-27 20:26 - 2013-06-27 20:26 - 02607616 ____A C:\Users\mKy\Downloads\PSROR_Full_Client_Downloader_v3(2).exe
2013-06-27 20:08 - 2012-11-24 09:34 - 00000000 ____D C:\Joymax
2013-06-22 05:37 - 2012-11-29 07:33 - 00000000 ____D C:\Bewerbungen
2013-06-20 14:33 - 2013-06-20 14:33 - 00004915 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-20 14:33 - 2013-05-18 17:05 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-20 14:32 - 2013-06-20 14:32 - 00903592 ____A (Oracle Corporation) C:\Users\mKy\Downloads\jxpiinstall(3).exe
2013-06-12 21:48 - 2012-09-21 13:54 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-12 21:48 - 2012-01-30 00:56 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-12 21:47 - 2013-06-20 14:33 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-12 21:43 - 2013-06-20 14:33 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-12 21:43 - 2013-06-20 14:33 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-12 21:43 - 2013-06-20 14:33 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-08 09:24 - 2012-01-29 20:59 - 00000000 ____D C:\Users\mKy\AppData\Roaming\SimpleScreenshot
2013-06-08 09:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-06-08 09:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-06 02:37

==================== End Of Log ============================
         
--- --- ---

Alt 08.07.2013, 17:54   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST Log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 08.07.2013, 22:45   #9
mKy
 
Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Hey,

anscheinend schaffe ich das heute nicht mehr, kam eben erst von der Arbeit und der ESET Scan dauert nun schon über 1 Stunde und 10 Minuten - und das bei 0 Funden. Ich werde Dir dann morgen früh alles posten.

Aber bisher kommt es mir immernoch sehr langsam vor, zumindest auf den Seiten, wo Flash verwendet werden muss.

Endlich fertig, ist es normal, dass der Scan so lange benötigt? Die anderen Virenprogramme etc waren alle deaktiviert.

Zitat:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=3b8828b4edc6b34b801d48f70cb89cd6
# engine=14322
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-08 10:05:15
# local_time=2013-07-09 12:05:15 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 98 0 238744405 31268 0
# compatibility_mode=5893 16776574 100 94 45342472 124950965 0 0
# scanned=175765
# found=0
# cleaned=0
# scan_time=5904

Beim SecurityCheck kommt leider eine Fehlermeldung.
Zitat:
UNSUPPORTED OPERATING SYSTEM! ABORTED!
Wie soll ich nun weiter vorgehen? Und gab es bisher irgendeine Art bösartiger Programme auf meinem Rechner?

Guten Morgen,

wie bereits erwähnt, habe ich 2 Flash Player Plugins "FlashPlayerPlugin_11_7_700_224" im Task-Manager offen, wenn ich z.B. einen Videostream anschaue, der eine hat eben eine CPU-Auslastung von 17% verursacht und etwa 170.000K Arbeitsspeicher. Der Andere eine CPU-Auslastung von 0% und 5.000K und ich brauchte etwa 3 Minuten um einen Videostream zu laden, der dazu noch unanschaubar durchs Ruckeln war. Doch sobald ich den Prozess beendet habe (den Kleineren) und die Seite neu geladen habe, lief alles flüssig - wie noch vor einigen Wochen. Denkst Du das liegt wirklich an einem Virus oder hast du noch ne andere Idee, was das Problem verursachen könnte?

Grüße
Mike

Geändert von mKy (08.07.2013 um 23:13 Uhr)

Alt 09.07.2013, 07:18   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Alles von Flash bitte deinstallieren, rebooten und Flash nochmal installieren. Dann bitte ein frisches FRST Log anhängen.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2013, 13:28   #11
mKy
 
Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Habe ich gemacht.


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013
Ran by mKy (administrator) on 09-07-2013 14:27:14
Running from C:\Users\mKy\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files\Common Files\WireHelpSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Akamai Technologies, Inc.) C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(Spotify Ltd) C:\Users\mKy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Spotify Ltd) C:\Users\mKy\AppData\Roaming\Spotify\spotify.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Creative Technology Ltd) C:\Windows\SysWOW64\CtHelper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Mirko Böer) C:\Program Files (x86)\SSS\SimpleScreenshot.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11613288 2010-11-19] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-21] (Microsoft Corporation)
HKCU\...\Run: [Akamai NetSession Interface] "C:\Users\mKy\AppData\Local\Akamai\netsession_win.exe" [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [Facebook Update] "C:\Users\mKy\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-08-01] (Facebook Inc.)
HKCU\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-01-10] ()
HKCU\...\Run: [Spotify Web Helper] "C:\Users\mKy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1104384 2013-07-07] (Spotify Ltd)
HKCU\...\Run: [Spotify] "C:\Users\mKy\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [4640768 2013-07-07] (Spotify Ltd)
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18680424 2013-05-08] (Skype Technologies S.A.)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL [x]
HKLM-x32\...\Run: [CTHelper] CTHELPER.EXE [19456 2010-03-18] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-29] ()
HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [2255184 2013-06-28] (LogMeIn Inc.)
HKLM-x32\...\Run: [SimpleScreenshot] C:\PROGRA~2\SSS\SIMPLESCREENSHOT.EXE [2255360 2008-02-09] (Mirko Böer)
Startup: C:\Users\mKy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL = 
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\mKy\AppData\Roaming\Mozilla\Firefox\Profiles\wbur3zd3.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @raidcall.en/RCplugin - C:\Users\mKy\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: @raidcall.kr/RCplugin - C:\Users\mKy\AppData\Roaming\RCKR\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\mKy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-02] (Avira Operations GmbH & Co. KG)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWow64\GameMon.des [5127200 2013-05-27] (INCA Internet Co., Ltd.)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-12-12] ()
R2 WireHelpSvc; C:\Program Files\Common Files\WireHelpSvc.exe [168864 2012-01-24] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-04-25] (Avira GmbH)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-04-27] (Avira GmbH)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2012-05-02] (Avira GmbH)
S3 CT20XUT.DLL; C:\Windows\System32\CT20XUT.DLL [252712 2007-04-10] (Creative Technology Ltd.)
S3 CTEAPSFX.DLL; C:\Windows\System32\CTEAPSFX.DLL [219432 2007-04-10] (Creative Technology Ltd)
S3 CTEDSPFX.DLL; C:\Windows\System32\CTEDSPFX.DLL [321832 2007-04-10] (Creative Technology Ltd)
S3 CTEDSPIO.DLL; C:\Windows\System32\CTEDSPIO.DLL [190248 2007-04-10] (Creative Technology Ltd)
S3 CTEDSPSY.DLL; C:\Windows\System32\CTEDSPSY.DLL [363304 2007-04-10] (Creative Technology Ltd)
S3 CTEXFIFX.DLL; C:\Windows\System32\CTEXFIFX.DLL [1571112 2007-04-10] (Creative Technology Ltd.)
S3 CTHWIUT.DLL; C:\Windows\System32\CTHWIUT.DLL [123688 2007-04-10] (Creative Technology Ltd.)
R3 ESLvnic1; C:\Windows\System32\DRIVERS\ESLvnic.sys [25528 2012-01-24] (Turtle Entertainment GmbH)
R2 ESLWireAC; C:\Windows\system32\drivers\ESLWireACD.sys [147472 2012-01-24] (<Turtle Entertainment>)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 ALSysIO; \??\C:\Users\mKy\AppData\Local\Temp\ALSysIO64.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 COMMONFX.DLL; system32\COMMONFX.DLL [x]
S3 CTAUDFX.DLL; system32\CTAUDFX.DLL [x]
S3 CTERFXFX.DLL; system32\CTERFXFX.DLL [x]
S3 CTSBLFX.DLL; system32\CTSBLFX.DLL [x]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-09 14:24 - 2013-07-09 14:24 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-09 14:24 - 2013-07-09 14:24 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-09 14:18 - 2013-07-09 14:18 - 00815496 ____A (Adobe Systems Incorporated) C:\Users\mKy\Desktop\uninstall_flash_player.exe
2013-07-09 10:57 - 2013-07-09 10:57 - 01227218 ____A C:\Users\mKy\Downloads\ssshot14(1).zip
2013-07-09 10:57 - 2013-07-09 10:57 - 00001456 ____R C:\Windows\SimpleScreenshot0_Uninstall.in
2013-07-09 10:57 - 2013-07-09 10:57 - 00000956 ____A C:\Users\mKy\Desktop\SimpleScreenshot.lnk
2013-07-09 10:57 - 2013-07-09 10:57 - 00000000 ____D C:\Users\mKy\Downloads\ssshot14(1)
2013-07-09 10:57 - 2013-07-09 10:57 - 00000000 ____D C:\Program Files (x86)\SSS
2013-07-09 10:57 - 2008-01-28 15:51 - 00330336 ____A (Mirko Böer) C:\Windows\SSSUn0.exe
2013-07-09 08:09 - 2013-07-09 08:09 - 00000000 ____D C:\Users\mKy\Downloads\The Chainsmokers 25k Bootie Edit Giveaway
2013-07-09 08:07 - 2013-07-09 08:08 - 49000624 ____A C:\Users\mKy\Downloads\The Chainsmokers 25k Bootie Edit Giveaway.zip
2013-07-09 07:59 - 2013-07-09 08:00 - 44418144 ____A C:\Users\mKy\Downloads\Ariane ep.wav
2013-07-09 07:38 - 2013-07-09 07:38 - 00357181 ____A C:\Users\mKy\Downloads\proxmate_unblock_the_internet-2.2.5-fx.zip
2013-07-09 07:38 - 2013-07-09 07:38 - 00000000 ____D C:\Users\mKy\Downloads\proxmate_unblock_the_internet-2.2.5-fx
2013-07-09 07:25 - 2013-07-09 14:24 - 00000000 ____D C:\Users\mKy\AppData\Roaming\DVDVideoSoft
2013-07-09 07:25 - 2013-07-09 07:25 - 00001402 ____A C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-07-09 07:25 - 2013-07-09 07:25 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-07-09 07:24 - 2013-07-09 07:24 - 25328416 ____A (DVDVideoSoft Ltd.                                           ) C:\Users\mKy\Downloads\FreeYouTubeToMP3Converter5628.exe
2013-07-09 06:59 - 2013-07-09 06:59 - 04566616 ____A C:\Users\mKy\Downloads\Joywave - _Tongues_ feat. KOPPS (off 88888 Mixtape).mp4
2013-07-08 22:24 - 2013-07-08 22:24 - 00890988 ____A C:\Users\mKy\Desktop\SecurityCheck.exe
2013-07-08 22:23 - 2013-07-08 22:23 - 02347384 ____A (ESET) C:\Users\mKy\Desktop\esetsmartinstaller_enu(2).exe
2013-07-08 13:35 - 2013-07-08 13:35 - 00063939 ____A C:\Users\mKy\Desktop\JRT.txt
2013-07-08 13:31 - 2013-07-08 13:31 - 00000000 ____D C:\Windows\ERUNT
2013-07-08 13:31 - 2013-07-08 13:31 - 00000000 ____D C:\JRT
2013-07-08 13:26 - 2013-07-08 13:27 - 00002859 ____A C:\AdwCleaner[S1].txt
2013-07-08 13:26 - 2013-07-08 13:26 - 00547139 ____A (Oleg N. Scherbakov) C:\Users\mKy\Desktop\JRT.exe
2013-07-08 13:25 - 2013-07-08 13:25 - 00650027 ____A C:\Users\mKy\Desktop\adwcleaner(1).exe
2013-07-07 22:16 - 2013-07-07 22:16 - 00013567 ____A C:\ComboFix.txt
2013-07-07 22:07 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe
2013-07-07 22:07 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe
2013-07-07 22:07 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-07-07 22:07 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-07-07 22:07 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-07-07 22:07 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe
2013-07-07 22:07 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe
2013-07-07 22:07 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe
2013-07-07 22:05 - 2013-07-07 22:16 - 00000000 ____D C:\Qoobox
2013-07-07 22:05 - 2013-07-07 22:15 - 00000000 ____D C:\Windows\erdnt
2013-07-07 22:03 - 2013-07-07 22:04 - 05087001 ____R (Swearware) C:\Users\mKy\Desktop\ComboFix.exe
2013-07-07 21:52 - 2013-07-07 21:54 - 00021031 ____A C:\Users\mKy\Desktop\Addition.txt
2013-07-07 21:46 - 2013-07-07 21:46 - 00000000 ____D C:\FRST
2013-07-07 21:44 - 2013-07-07 21:45 - 01934636 ____A (Farbar) C:\Users\mKy\Desktop\FRST64.exe
2013-07-07 20:51 - 2013-07-07 20:51 - 00087572 ____A C:\Users\mKy\Desktop\Extras.Txt
2013-07-07 20:50 - 2013-07-07 20:50 - 00083088 ____A C:\Users\mKy\Desktop\OTL.Txt
2013-07-07 20:44 - 2013-07-07 20:44 - 00602112 ____A (OldTimer Tools) C:\Users\mKy\Desktop\OTL.exe
2013-07-07 20:44 - 2013-07-07 20:44 - 00000468 ____A C:\Users\mKy\Desktop\defogger_disable.log
2013-07-07 20:44 - 2013-07-07 20:44 - 00000000 ____A C:\Users\mKy\defogger_reenable
2013-07-07 20:42 - 2013-07-07 20:42 - 00050477 ____A C:\Users\mKy\Desktop\Defogger.exe
2013-07-07 19:45 - 2013-07-07 19:45 - 00003495 ____A C:\AdwCleaner[R1].txt
2013-07-07 19:43 - 2013-07-07 19:43 - 00002094 ____A C:\Users\mKy\Desktop\RKreport[0]_S_07072013_194312.txt
2013-07-07 19:41 - 2013-07-07 19:44 - 00000000 ____D C:\Users\mKy\Desktop\RK_Quarantine
2013-07-07 19:38 - 2013-07-07 19:38 - 00208216 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\31978637.sys
2013-07-07 19:38 - 2013-07-07 19:38 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-07-07 19:34 - 2013-07-07 19:36 - 00019385 ____A C:\Users\mKy\Downloads\Result.txt
2013-07-07 19:33 - 2013-07-07 19:33 - 00915456 ____A C:\Users\mKy\Downloads\RogueKiller.exe
2013-07-07 19:28 - 2013-07-07 19:28 - 00760775 ____A (Farbar) C:\Users\mKy\Downloads\MiniToolBox.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\mKy\Downloads\tdsskiller.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 00650027 ____A C:\Users\mKy\Downloads\AdwCleaner.exe
2013-07-06 02:08 - 2013-07-06 02:08 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-07-04 00:54 - 2013-07-04 00:54 - 00000000 ____D C:\Users\mKy\Desktop\Alte Firefox-Daten
2013-07-03 10:48 - 2013-07-03 10:48 - 00237568 ____A (CompulsiveCode - The Programs I Write) C:\Users\mKy\Downloads\JPEGtoPDF37.exe
2013-07-03 04:58 - 2013-07-03 04:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 01:43 - 2013-07-02 01:44 - 07236481 ____A C:\Users\mKy\Downloads\Ex.iBot-R v1.73.rar
2013-07-01 16:00 - 2013-07-01 16:00 - 00555240 ____A C:\Windows\Minidump\070113-21325-01.dmp
2013-07-01 03:45 - 2013-07-01 04:00 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadR_071
2013-07-01 03:24 - 2013-07-01 03:42 - 1842256513 ____A C:\Users\mKy\Downloads\SilkroadR_071.zip
2013-06-27 23:30 - 2013-06-27 23:30 - 31272077 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_403(for_v1_400_402).exe
2013-06-27 23:25 - 2013-06-27 23:42 - 00000000 ____D C:\Program Files (x86)\Silkroad
2013-06-27 23:23 - 2013-06-27 23:23 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400
2013-06-27 22:20 - 2013-06-27 22:20 - 00001898 ____A C:\Users\mKy\Desktop\SilkroadR.lnk
2013-06-27 22:16 - 2013-06-27 22:28 - 00000000 ____D C:\Program Files (x86)\SilkroadR
2013-06-27 22:14 - 2013-06-27 23:23 - 1361456630 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400.zip
2013-06-27 22:13 - 2013-06-27 22:13 - 01125376 ____A (PlayWhat) C:\Users\mKy\Downloads\528!SilkroadOnline_GlobalOfficial_v1_400.exe.exe.htm
2013-06-27 22:12 - 2013-06-27 23:28 - 00001889 ____A C:\Users\mKy\Desktop\Silkroad.lnk
2013-06-27 21:13 - 2013-05-27 00:30 - 05127200 ____A (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des
2013-06-27 21:12 - 2013-06-27 21:12 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
2013-06-27 21:12 - 2005-01-04 11:43 - 00004682 ____A (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\npptNT2.sys
2013-06-27 21:12 - 2003-07-20 20:17 - 00005174 ____A C:\Windows\SysWOW64\nppt9x.vxd
2013-06-27 20:50 - 2013-06-27 20:50 - 00000000 ____D C:\ProgramData\Overwolf
2013-06-27 20:49 - 2013-06-27 21:24 - 00000000 ____D C:\Program Files (x86)\Overwolf
2013-06-27 20:44 - 2013-06-27 20:51 - 00000000 ____D C:\Users\mKy\AppData\Local\Overwolf
2013-06-27 20:35 - 2013-06-27 20:35 - 00000000 ____D C:\Program Files (x86)\Games-Masters.com
2013-06-27 20:30 - 2013-06-27 22:09 - 00001040 ____A C:\Users\mKy\Downloads\_predownloadpath.dat
2013-06-27 20:26 - 2013-06-27 20:26 - 02607616 ____A C:\Users\mKy\Downloads\PSROR_Full_Client_Downloader_v3(2).exe
2013-06-27 20:07 - 2013-06-27 20:28 - 1260483304 ____A (Games-Masters.com                                           ) C:\Users\mKy\Downloads\CABAL_Online_Europe_Installer.exe
2013-06-20 14:33 - 2013-06-20 14:33 - 00004915 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-20 14:33 - 2013-06-12 21:47 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-20 14:33 - 2013-06-12 21:43 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-20 14:33 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-20 14:33 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-20 14:32 - 2013-06-20 14:32 - 00903592 ____A (Oracle Corporation) C:\Users\mKy\Downloads\jxpiinstall(3).exe

==================== One Month Modified Files and Folders =======

2013-07-09 14:27 - 2013-01-10 11:05 - 00000000 ____D C:\Users\mKy\AppData\Local\PMB Files
2013-07-09 14:25 - 2012-11-23 08:53 - 00000000 ____D C:\Users\mKy\AppData\Roaming\Spotify
2013-07-09 14:24 - 2013-07-09 14:24 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-09 14:24 - 2013-07-09 14:24 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-09 14:24 - 2013-07-09 07:25 - 00000000 ____D C:\Users\mKy\AppData\Roaming\DVDVideoSoft
2013-07-09 14:24 - 2012-02-07 17:52 - 00000000 ____D C:\Users\mKy\AppData\Local\Adobe
2013-07-09 14:22 - 2012-01-28 21:20 - 00000000 ____D C:\Users\mKy\AppData\Roaming\Skype
2013-07-09 14:20 - 2012-12-19 00:20 - 00000000 ____D C:\Users\mKy\AppData\Local\LogMeIn Hamachi
2013-07-09 14:20 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-09 14:20 - 2009-07-14 06:51 - 00046439 ____A C:\Windows\setupact.log
2013-07-09 14:19 - 2012-01-29 03:18 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-09 14:19 - 2012-01-29 02:51 - 01279435 ____A C:\Windows\WindowsUpdate.log
2013-07-09 14:19 - 2010-11-21 05:47 - 00144676 ____A C:\Windows\PFRO.log
2013-07-09 14:18 - 2013-07-09 14:18 - 00815496 ____A (Adobe Systems Incorporated) C:\Users\mKy\Desktop\uninstall_flash_player.exe
2013-07-09 13:47 - 2012-05-28 12:34 - 00000000 ____D C:\Program Files (x86)\Heroes of Newerth
2013-07-09 12:39 - 2012-08-01 00:34 - 00000920 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000UA.job
2013-07-09 10:57 - 2013-07-09 10:57 - 01227218 ____A C:\Users\mKy\Downloads\ssshot14(1).zip
2013-07-09 10:57 - 2013-07-09 10:57 - 00001456 ____R C:\Windows\SimpleScreenshot0_Uninstall.in
2013-07-09 10:57 - 2013-07-09 10:57 - 00000956 ____A C:\Users\mKy\Desktop\SimpleScreenshot.lnk
2013-07-09 10:57 - 2013-07-09 10:57 - 00000000 ____D C:\Users\mKy\Downloads\ssshot14(1)
2013-07-09 10:57 - 2013-07-09 10:57 - 00000000 ____D C:\Program Files (x86)\SSS
2013-07-09 08:09 - 2013-07-09 08:09 - 00000000 ____D C:\Users\mKy\Downloads\The Chainsmokers 25k Bootie Edit Giveaway
2013-07-09 08:08 - 2013-07-09 08:07 - 49000624 ____A C:\Users\mKy\Downloads\The Chainsmokers 25k Bootie Edit Giveaway.zip
2013-07-09 08:00 - 2013-07-09 07:59 - 44418144 ____A C:\Users\mKy\Downloads\Ariane ep.wav
2013-07-09 07:38 - 2013-07-09 07:38 - 00357181 ____A C:\Users\mKy\Downloads\proxmate_unblock_the_internet-2.2.5-fx.zip
2013-07-09 07:38 - 2013-07-09 07:38 - 00000000 ____D C:\Users\mKy\Downloads\proxmate_unblock_the_internet-2.2.5-fx
2013-07-09 07:25 - 2013-07-09 07:25 - 00001402 ____A C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-07-09 07:25 - 2013-07-09 07:25 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-07-09 07:24 - 2013-07-09 07:24 - 25328416 ____A (DVDVideoSoft Ltd.                                           ) C:\Users\mKy\Downloads\FreeYouTubeToMP3Converter5628.exe
2013-07-09 06:59 - 2013-07-09 06:59 - 04566616 ____A C:\Users\mKy\Downloads\Joywave - _Tongues_ feat. KOPPS (off 88888 Mixtape).mp4
2013-07-09 00:39 - 2012-08-01 00:34 - 00000898 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1268233647-2086190670-3795427419-1000Core.job
2013-07-09 00:22 - 2009-07-14 06:45 - 00035088 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-09 00:22 - 2009-07-14 06:45 - 00035088 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-09 00:15 - 2012-11-23 08:54 - 00000000 ____D C:\Users\mKy\AppData\Local\Spotify
2013-07-08 22:24 - 2013-07-08 22:24 - 00890988 ____A C:\Users\mKy\Desktop\SecurityCheck.exe
2013-07-08 22:23 - 2013-07-08 22:23 - 02347384 ____A (ESET) C:\Users\mKy\Desktop\esetsmartinstaller_enu(2).exe
2013-07-08 13:35 - 2013-07-08 13:35 - 00063939 ____A C:\Users\mKy\Desktop\JRT.txt
2013-07-08 13:31 - 2013-07-08 13:31 - 00000000 ____D C:\Windows\ERUNT
2013-07-08 13:31 - 2013-07-08 13:31 - 00000000 ____D C:\JRT
2013-07-08 13:27 - 2013-07-08 13:26 - 00002859 ____A C:\AdwCleaner[S1].txt
2013-07-08 13:26 - 2013-07-08 13:26 - 00547139 ____A (Oleg N. Scherbakov) C:\Users\mKy\Desktop\JRT.exe
2013-07-08 13:25 - 2013-07-08 13:25 - 00650027 ____A C:\Users\mKy\Desktop\adwcleaner(1).exe
2013-07-07 22:16 - 2013-07-07 22:16 - 00013567 ____A C:\ComboFix.txt
2013-07-07 22:16 - 2013-07-07 22:05 - 00000000 ____D C:\Qoobox
2013-07-07 22:16 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-07-07 22:15 - 2013-07-07 22:05 - 00000000 ____D C:\Windows\erdnt
2013-07-07 22:14 - 2012-01-29 02:54 - 00000000 ___AD C:\users\mKy
2013-07-07 22:14 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini
2013-07-07 22:04 - 2013-07-07 22:03 - 05087001 ____R (Swearware) C:\Users\mKy\Desktop\ComboFix.exe
2013-07-07 21:54 - 2013-07-07 21:52 - 00021031 ____A C:\Users\mKy\Desktop\Addition.txt
2013-07-07 21:46 - 2013-07-07 21:46 - 00000000 ____D C:\FRST
2013-07-07 21:45 - 2013-07-07 21:44 - 01934636 ____A (Farbar) C:\Users\mKy\Desktop\FRST64.exe
2013-07-07 20:51 - 2013-07-07 20:51 - 00087572 ____A C:\Users\mKy\Desktop\Extras.Txt
2013-07-07 20:50 - 2013-07-07 20:50 - 00083088 ____A C:\Users\mKy\Desktop\OTL.Txt
2013-07-07 20:44 - 2013-07-07 20:44 - 00602112 ____A (OldTimer Tools) C:\Users\mKy\Desktop\OTL.exe
2013-07-07 20:44 - 2013-07-07 20:44 - 00000468 ____A C:\Users\mKy\Desktop\defogger_disable.log
2013-07-07 20:44 - 2013-07-07 20:44 - 00000000 ____A C:\Users\mKy\defogger_reenable
2013-07-07 20:42 - 2013-07-07 20:42 - 00050477 ____A C:\Users\mKy\Desktop\Defogger.exe
2013-07-07 19:45 - 2013-07-07 19:45 - 00003495 ____A C:\AdwCleaner[R1].txt
2013-07-07 19:44 - 2013-07-07 19:41 - 00000000 ____D C:\Users\mKy\Desktop\RK_Quarantine
2013-07-07 19:43 - 2013-07-07 19:43 - 00002094 ____A C:\Users\mKy\Desktop\RKreport[0]_S_07072013_194312.txt
2013-07-07 19:38 - 2013-07-07 19:38 - 00208216 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\31978637.sys
2013-07-07 19:38 - 2013-07-07 19:38 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-07-07 19:36 - 2013-07-07 19:34 - 00019385 ____A C:\Users\mKy\Downloads\Result.txt
2013-07-07 19:33 - 2013-07-07 19:33 - 00915456 ____A C:\Users\mKy\Downloads\RogueKiller.exe
2013-07-07 19:28 - 2013-07-07 19:28 - 00760775 ____A (Farbar) C:\Users\mKy\Downloads\MiniToolBox.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\mKy\Downloads\tdsskiller.exe
2013-07-07 19:27 - 2013-07-07 19:27 - 00650027 ____A C:\Users\mKy\Downloads\AdwCleaner.exe
2013-07-06 02:08 - 2013-07-06 02:08 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-07-06 02:07 - 2012-05-28 11:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-06 02:07 - 2012-04-28 19:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-05 07:52 - 2012-05-28 11:39 - 00001113 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-07-04 00:54 - 2013-07-04 00:54 - 00000000 ____D C:\Users\mKy\Desktop\Alte Firefox-Daten
2013-07-04 00:47 - 2012-01-28 20:52 - 00000000 ____D C:\Users\mKy\AppData\Roaming\TS3Client
2013-07-03 10:48 - 2013-07-03 10:48 - 00237568 ____A (CompulsiveCode - The Programs I Write) C:\Users\mKy\Downloads\JPEGtoPDF37.exe
2013-07-03 04:59 - 2013-07-03 04:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 01:44 - 2013-07-02 01:43 - 07236481 ____A C:\Users\mKy\Downloads\Ex.iBot-R v1.73.rar
2013-07-01 16:00 - 2013-07-01 16:00 - 00555240 ____A C:\Windows\Minidump\070113-21325-01.dmp
2013-07-01 16:00 - 2012-03-20 14:40 - 506566888 ____A C:\Windows\MEMORY.DMP
2013-07-01 16:00 - 2012-03-20 14:40 - 00000000 ____D C:\Windows\Minidump
2013-07-01 04:00 - 2013-07-01 03:45 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadR_071
2013-07-01 03:42 - 2013-07-01 03:24 - 1842256513 ____A C:\Users\mKy\Downloads\SilkroadR_071.zip
2013-06-30 00:27 - 2009-07-14 06:45 - 00301832 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-28 17:35 - 2012-01-28 20:59 - 00064080 ____A C:\Users\mKy\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-28 09:27 - 2012-02-04 16:44 - 00000000 ____D C:\Users\mKy\AppData\Local\Akamai
2013-06-27 23:42 - 2013-06-27 23:25 - 00000000 ____D C:\Program Files (x86)\Silkroad
2013-06-27 23:30 - 2013-06-27 23:30 - 31272077 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_403(for_v1_400_402).exe
2013-06-27 23:28 - 2013-06-27 22:12 - 00001889 ____A C:\Users\mKy\Desktop\Silkroad.lnk
2013-06-27 23:23 - 2013-06-27 23:23 - 00000000 ____D C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400
2013-06-27 23:23 - 2013-06-27 22:14 - 1361456630 ____A C:\Users\mKy\Downloads\SilkroadOnline_GlobalOfficial_v1_400.zip
2013-06-27 22:28 - 2013-06-27 22:16 - 00000000 ____D C:\Program Files (x86)\SilkroadR
2013-06-27 22:20 - 2013-06-27 22:20 - 00001898 ____A C:\Users\mKy\Desktop\SilkroadR.lnk
2013-06-27 22:13 - 2013-06-27 22:13 - 01125376 ____A (PlayWhat) C:\Users\mKy\Downloads\528!SilkroadOnline_GlobalOfficial_v1_400.exe.exe.htm
2013-06-27 22:09 - 2013-06-27 20:30 - 00001040 ____A C:\Users\mKy\Downloads\_predownloadpath.dat
2013-06-27 21:24 - 2013-06-27 20:49 - 00000000 ____D C:\Program Files (x86)\Overwolf
2013-06-27 21:12 - 2013-06-27 21:12 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
2013-06-27 20:51 - 2013-06-27 20:44 - 00000000 ____D C:\Users\mKy\AppData\Local\Overwolf
2013-06-27 20:50 - 2013-06-27 20:50 - 00000000 ____D C:\ProgramData\Overwolf
2013-06-27 20:35 - 2013-06-27 20:35 - 00000000 ____D C:\Program Files (x86)\Games-Masters.com
2013-06-27 20:28 - 2013-06-27 20:07 - 1260483304 ____A (Games-Masters.com                                           ) C:\Users\mKy\Downloads\CABAL_Online_Europe_Installer.exe
2013-06-27 20:27 - 2012-01-28 20:40 - 00000000 ____D C:\Spiele
2013-06-27 20:26 - 2013-06-27 20:26 - 02607616 ____A C:\Users\mKy\Downloads\PSROR_Full_Client_Downloader_v3(2).exe
2013-06-27 20:08 - 2012-11-24 09:34 - 00000000 ____D C:\Joymax
2013-06-22 05:37 - 2012-11-29 07:33 - 00000000 ____D C:\Bewerbungen
2013-06-20 14:33 - 2013-06-20 14:33 - 00004915 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-20 14:33 - 2013-05-18 17:05 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-20 14:32 - 2013-06-20 14:32 - 00903592 ____A (Oracle Corporation) C:\Users\mKy\Downloads\jxpiinstall(3).exe
2013-06-12 21:48 - 2012-09-21 13:54 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-12 21:48 - 2012-01-30 00:56 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-12 21:47 - 2013-06-20 14:33 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-12 21:43 - 2013-06-20 14:33 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-12 21:43 - 2013-06-20 14:33 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-12 21:43 - 2013-06-20 14:33 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-06 02:37

==================== End Of Log ============================
         
--- --- ---

Alt 09.07.2013, 13:29   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2013, 21:31   #13
mKy
 
Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



Oh, habe die zweite Seite nicht gesehen und dachte mein vorheriger Post wäre nicht abgeschickt worden :P

Bisher nicht, ich teste es mal ein bisschen und melde mich nochmal falls irgendwelche Probleme auftreten.

Vielen Dank soweit erstmal

Alt 10.07.2013, 08:32   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Langsamer Boot, Flash Plugin Problem - woran liegts? - Standard

Langsamer Boot, Flash Plugin Problem - woran liegts?



ok
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Langsamer Boot, Flash Plugin Problem - woran liegts?
akamai, autorun, avira, bho, browser, downloader, error, fehler, flash player, format, install.exe, langsam, logfile, mozilla, nicht möglich, plug-in, problem, prozesse, realtek, registry, richtlinie, rundll, scan, security, software, spotify web helper, svchost.exe, tcp, teamspeak, uplay, windows




Ähnliche Themen: Langsamer Boot, Flash Plugin Problem - woran liegts?


  1. Windows 10 bootet nicht (Reboot and select proper boot device or insert boot media in selected boot device and press a key)
    Alles rund um Windows - 18.10.2015 (4)
  2. Problem mit dem USB-Mikrofon - Liegts an einem Treiber oder an Schadsoftware?
    Alles rund um Windows - 25.09.2015 (1)
  3. Flash Plugin stürzt ständig ab! Internetverbindung bei Windows 7 schwankt. Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 04.08.2015 (21)
  4. Problem mit dem VLC web player plugin unter firefox
    Diskussionsforum - 20.12.2014 (5)
  5. Windows 7 Professional: alles langsamer, flash player, Word etc. hängen sich auf
    Log-Analyse und Auswertung - 02.10.2014 (13)
  6. Shockwave Flash Plugin ist abgestürzt
    Diskussionsforum - 11.03.2014 (12)
  7. Windows 8 wird nach einiger Zeit immer langsamer. Problem mit Flash-Player oder Virus?
    Log-Analyse und Auswertung - 05.09.2013 (9)
  8. Flash-Plugin stürzt ab, Filehippo-Website öffnet nicht mehr, Super Antispyware nicht installierbar
    Log-Analyse und Auswertung - 28.06.2013 (3)
  9. Startfenster.com nach Flash / Shockwave Update, Flash Plugin stürzt dauernd ab
    Log-Analyse und Auswertung - 26.09.2012 (41)
  10. Firefox / plugin-container.exe - Absturz/ adobe flash player --> Problem
    Plagegeister aller Art und deren Bekämpfung - 24.02.2012 (8)
  11. Boot Problem
    Log-Analyse und Auswertung - 15.05.2009 (10)
  12. Boot Problem
    Alles rund um Windows - 26.03.2009 (2)
  13. pc extrem langsamer boot
    Log-Analyse und Auswertung - 20.01.2009 (0)
  14. extrem langsamer boot
    Log-Analyse und Auswertung - 11.12.2008 (1)
  15. boot problem
    Netzwerk und Hardware - 18.12.2007 (7)
  16. maus spinnt... liegts an nem virus???
    Plagegeister aller Art und deren Bekämpfung - 19.05.2007 (3)
  17. Internet liegts an Mainboard?
    Netzwerk und Hardware - 20.06.2006 (5)

Zum Thema Langsamer Boot, Flash Plugin Problem - woran liegts? - Hallo, seit einigen Tagen habe ich Probleme mit dem Adobe Flash Player Plugin, Filme, Videos etc lassen sich nur noch langsam laden und es kann definitiv nicht an meiner Hardware - Langsamer Boot, Flash Plugin Problem - woran liegts?...
Archiv
Du betrachtest: Langsamer Boot, Flash Plugin Problem - woran liegts? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.