Zurück   Trojaner-Board > Web/PC > Alles rund um Windows

Alles rund um Windows: PC meldet sich nach Anmeldung automatisch wieder ab 2014

Windows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows.

Antwort
Alt 03.03.2014, 22:02   #1
Drancer
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

Problem: PC meldet sich nach Anmeldung automatisch wieder ab 2014





Hallo Community !

Ich hab genau das gleiche problem wie dieser User es hier beschreibt :

http://www.trojaner-board.de/136922-...atisch-ab.html

Wie Schrauber gesagt hat hab ich in abgesichertes modus mal FRST laufen lassen.
Ich würde gerne auch einen FIXLOG kriegen, villeicht gehts dann endlich mal.


FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-03-2014 01
Ran by PC (administrator) on PC-PC on 03-03-2014 21:00:42
Running from C:\Users\PC\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Safe Mode (minimal)

The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool 
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums

==================== Processes (Whitelisted) =================



==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7198424 2013-08-28] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime Alternative\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-11-09] (RealNetworks, Inc.)
HKLM-x32\...\Run: [WAHELPER.EXE] - C:\Program Files (x86)\WinArchiver\WAHELPER.EXE [480792 2013-11-10] (Power Software Ltd)
HKU\S-1-5-21-2263356855-1520679738-450664524-1003\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2263356855-1520679738-450664524-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
GroupPolicyUsers\S-1-5-21-2263356855-1520679738-450664524-1003\User: Group Policy restriction detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: No Name - {74D271A4-00A7-0F5C-560A-2412C0CFD357} -  No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: No Name - {8984B388-A5BB-4DF7-B274-77B879E179DB} -  No File
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.66.2.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\searchplugins\mailru---.xml
FF SearchPlugin: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\searchplugins\webalta-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mailru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ozonru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\priceru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-slovari.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex.xml
FF Extension: Battlefield Play4Free - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\battlefieldplay4free@ea.com [2012-05-18]
FF Extension: SearchNewTab - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\bpax7a@vekpbgey.org [2013-10-04]
FF Extension: SearchNewTab - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\hqjs4vg@kfajdmhuia.net [2013-11-24]
FF Extension: Downloaed keepEr - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\oa9nnk_ifjm@xoeyavoayo.com [2013-10-04]
FF Extension: SearchNewTab - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\oai5cavr@aasvlrcz.net [2013-10-16]
FF Extension: VideoFileDownload - Download YouTube Videos - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\plugin@videofiledownload.com [2012-06-25]
FF Extension: Flash and Video Download - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2014-02-21]
FF Extension: Youtube Downloader - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\youtube_downloader@anishsane.googlepages.com.xpi [2012-08-27]
FF Extension: Easy YouTube Video Downloader - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi [2012-06-27]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-11-09]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2012-06-21] ()
S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-22] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG)
S2 DrWebEngine; C:\Program Files (x86)\TrafInsp\plugins\DwAV\Engine\dwengine.exe [1667416 2012-06-28] (Doctor Web, Ltd.)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5148240 2013-07-23] (INCA Internet Co., Ltd.)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-31] ()
S2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
S2 TrafInspSrv; C:\Program Files (x86)\TrafInsp\TrafInsp.exe [4475392 2012-06-08] (SMART-SOFT)
S2 WinArchiver Service; C:\Program Files (x86)\WinArchiver\WAService.exe [202264 2013-11-10] ()

==================== Drivers (Whitelisted) ====================

S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-22] (Avira Operations GmbH & Co. KG)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-22] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
S1 TICAPDRV; C:\Windows\System32\DRIVERS\ticap.sys [265880 2012-01-20] (SMART-SOFT)
R0 waemu; C:\Windows\System32\Drivers\waemu.sys [140184 2013-11-10] (Power Software Ltd)
S2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S3 cpuz136; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S2 NEWDRIVER; \??\C:\Windows\SysWow64\WinVDEdrv6.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-03 20:40 - 2014-03-03 21:00 - 00000000 ____D () C:\FRST
2014-03-03 20:26 - 2014-03-03 20:57 - 00000336 _____ () C:\Windows\setupact.log
2014-03-03 20:26 - 2014-03-03 20:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-02 02:41 - 2014-03-02 02:41 - 00000000 ____D () C:\Program Files (x86)\SmartTweak Software
2014-03-02 02:11 - 2014-03-02 02:11 - 00002788 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-01 20:18 - 2014-03-01 20:18 - 00000000 ____D () C:\Windows\de
2014-03-01 20:17 - 2014-03-01 20:17 - 00000000 ____D () C:\Windows\en
2014-03-01 20:16 - 2014-03-01 20:16 - 00000000 ____D () C:\Windows\ru
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Program Files (x86)\WinArchiver
2014-02-26 19:54 - 2013-11-10 03:53 - 00140184 _____ (Power Software Ltd) C:\Windows\system32\Drivers\waemu.sys
2014-02-26 19:49 - 2014-02-26 19:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-26 19:48 - 2014-02-26 19:48 - 00000000 ____D () C:\Program Files\Java
2014-02-26 14:01 - 2014-01-09 03:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-02-26 14:01 - 2014-01-03 23:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-02-25 18:55 - 2014-03-03 20:27 - 00003350 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-02-25 18:53 - 2014-02-26 19:50 - 00306000 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-25 13:50 - 2014-03-03 20:47 - 00257882 _____ () C:\Windows\WindowsUpdate.log
2014-02-25 13:48 - 2014-03-01 06:47 - 00003188 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-24 23:55 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-02-24 23:54 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-02-24 23:54 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-02-24 23:54 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-02-24 23:54 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-02-24 23:54 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-02-24 23:54 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-02-24 23:54 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-02-24 23:54 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-02-24 23:54 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-02-24 23:54 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-02-24 23:54 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-02-24 23:54 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-02-24 23:54 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-02-24 23:54 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-02-24 23:54 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-02-24 23:53 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-02-24 23:53 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-02-24 23:53 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2014-02-24 23:53 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-02-24 23:53 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2014-02-24 23:53 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-02-24 23:53 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-02-24 23:52 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-02-24 23:52 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-02-24 17:03 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-22 23:04 - 2014-02-23 00:10 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-02-20 00:00 - 2014-02-20 00:00 - 00000000 ____D () C:\Program Files (x86)\5
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-02-14 03:45 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-14 03:45 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-14 03:44 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-14 03:44 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-14 03:44 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-14 03:44 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-14 03:44 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-14 03:44 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-14 03:44 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-14 03:44 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-14 03:44 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-14 03:44 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-14 03:44 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-14 03:44 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-14 03:44 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-14 03:44 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-14 03:44 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-14 03:44 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-14 03:44 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-14 03:44 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-14 03:44 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-14 03:44 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-14 03:44 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-14 03:44 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-14 03:44 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-14 03:44 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-14 03:44 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-14 03:44 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-14 03:44 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-14 03:44 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-14 03:44 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-14 03:44 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-14 03:44 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-14 03:44 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-14 03:44 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-14 03:44 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-14 03:44 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-14 03:44 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-14 03:44 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-14 03:44 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-14 03:44 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-13 23:19 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-13 23:19 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-13 23:19 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-13 23:19 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-13 23:19 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-13 23:19 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-13 23:19 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-13 23:19 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 23:19 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-13 23:19 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-13 23:19 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-13 23:18 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-13 23:18 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-13 23:18 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-13 23:18 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-13 22:14 - 2014-02-13 22:14 - 00003178 _____ () C:\Windows\System32\Tasks\{57E8181A-0929-418A-A72C-CE10D919BEE8}
2014-02-13 22:12 - 2014-02-13 22:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-02-13 22:04 - 2014-02-26 23:22 - 00009678 _____ () C:\Windows\SysWOW64\ScriptHook.log
2014-02-13 22:03 - 2014-02-13 22:03 - 00336384 _____ () C:\Windows\SysWOW64\ScriptHook.dll
2014-02-13 03:16 - 2014-02-13 03:16 - 00000000 ____D () C:\Neuer Ordner
2014-02-12 22:16 - 2014-02-12 22:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-12 21:23 - 2014-02-12 21:23 - 00000000 ____D () C:\Program Files\PowerISO
2014-02-12 20:53 - 2013-10-23 15:11 - 00129944 _____ (Power Software Ltd) C:\Windows\system32\Drivers\scdemu.sys
2014-02-11 16:33 - 2014-02-24 16:19 - 00003350 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-11 02:25 - 2014-02-11 02:25 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-02-10 21:12 - 2014-02-10 21:12 - 01199079 _____ () C:\Windows\unins000.exe
2014-02-01 15:22 - 2014-03-01 06:47 - 00003328 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003

==================== One Month Modified Files and Folders =======

2014-03-03 21:00 - 2014-03-03 20:40 - 00000000 ____D () C:\FRST
2014-03-03 20:57 - 2014-03-03 20:26 - 00000336 _____ () C:\Windows\setupact.log
2014-03-03 20:57 - 2012-04-02 15:12 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs
2014-03-03 20:57 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-03 20:56 - 2013-11-24 17:04 - 00000442 ____H () C:\Windows\Tasks\SK.Enhancer-S-161304646.job
2014-03-03 20:56 - 2012-04-02 15:23 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-03 20:55 - 2014-01-11 00:00 - 00000000 ____D () C:\AdwCleaner
2014-03-03 20:47 - 2014-02-25 13:50 - 00257882 _____ () C:\Windows\WindowsUpdate.log
2014-03-03 20:39 - 2013-02-23 17:34 - 00000916 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003UA.job
2014-03-03 20:36 - 2012-04-02 15:23 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-03 20:33 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-03 20:33 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-03 20:31 - 2012-03-07 00:47 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-03 20:27 - 2014-02-25 18:55 - 00003350 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-03 20:27 - 2013-10-30 10:53 - 00003232 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-03 20:27 - 2012-04-02 15:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-03 20:26 - 2014-03-03 20:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-03 20:25 - 2013-09-15 14:00 - 00000000 ____D () C:\Program Files (x86)\RusTV Player
2014-03-03 20:25 - 2012-04-11 07:01 - 00000000 ____D () C:\Windows\Minidump
2014-03-03 20:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-03-03 20:24 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-03-02 17:39 - 2013-02-23 17:34 - 00000894 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003Core.job
2014-03-02 05:26 - 2013-06-28 21:37 - 00000000 ____D () C:\Program Files\WinRAR
2014-03-02 05:25 - 2013-10-03 18:31 - 00000000 ____D () C:\Program Files (x86)\Ss.Helper
2014-03-02 02:56 - 2012-04-27 19:42 - 00000069 _____ () C:\Windows\NeroDigital.ini
2014-03-02 02:41 - 2014-03-02 02:41 - 00000000 ____D () C:\Program Files (x86)\SmartTweak Software
2014-03-02 02:11 - 2014-03-02 02:11 - 00002788 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-02 02:11 - 2012-04-03 05:00 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-02 01:56 - 2012-04-02 22:38 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-03-02 01:56 - 2012-04-02 19:19 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-03-02 00:53 - 2012-04-02 19:19 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-03-02 00:10 - 2012-04-15 21:25 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-03-01 20:27 - 2013-11-10 18:01 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-01 20:18 - 2014-03-01 20:18 - 00000000 ____D () C:\Windows\de
2014-03-01 20:17 - 2014-03-01 20:17 - 00000000 ____D () C:\Windows\en
2014-03-01 20:16 - 2014-03-01 20:16 - 00000000 ____D () C:\Windows\ru
2014-03-01 20:15 - 2012-04-02 16:35 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-03-01 06:47 - 2014-02-25 13:48 - 00003188 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-03-01 06:47 - 2014-02-01 15:22 - 00003328 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-28 07:35 - 2013-08-12 15:04 - 00000000 ____D () C:\Program Files\PeerBlock
2014-02-28 06:47 - 2012-03-07 00:03 - 75431936 _____ () C:\Windows\system32\config\RegBack\SOFTWARE
2014-02-28 06:47 - 2012-03-07 00:03 - 38744064 _____ () C:\Windows\system32\config\RegBack\SYSTEM
2014-02-28 06:47 - 2012-03-07 00:03 - 05013504 _____ () C:\Windows\system32\config\RegBack\DEFAULT
2014-02-28 06:47 - 2012-03-07 00:03 - 00131072 _____ () C:\Windows\system32\config\RegBack\SAM
2014-02-28 06:47 - 2012-03-07 00:03 - 00032768 _____ () C:\Windows\system32\config\RegBack\SECURITY
2014-02-27 12:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-26 23:22 - 2014-02-13 22:04 - 00009678 _____ () C:\Windows\SysWOW64\ScriptHook.log
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Program Files (x86)\WinArchiver
2014-02-26 19:50 - 2014-02-25 18:53 - 00306000 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-26 19:49 - 2014-02-26 19:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-26 19:48 - 2014-02-26 19:48 - 00000000 ____D () C:\Program Files\Java
2014-02-25 01:38 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-02-24 23:54 - 2012-04-03 15:38 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-02-24 23:54 - 2012-04-02 15:12 - 00010061 _____ () C:\Windows\system32\lvcoinst.log
2014-02-24 17:17 - 2012-11-25 00:19 - 00000000 ____D () C:\Program Files (x86)\rhv
2014-02-24 16:19 - 2014-02-11 16:33 - 00003350 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-24 16:19 - 2013-12-12 18:48 - 00003210 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-23 02:16 - 2013-12-31 21:25 - 00000000 ____D () C:\Program Files\Realmware
2014-02-23 00:10 - 2014-02-22 23:04 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-02-22 03:34 - 2012-05-03 07:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-21 17:39 - 2014-01-15 18:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-21 07:27 - 2012-04-02 15:23 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-21 07:27 - 2012-04-02 15:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-21 07:27 - 2012-04-02 15:23 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-20 00:00 - 2014-02-20 00:00 - 00000000 ____D () C:\Program Files (x86)\5
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-02-19 12:07 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-02-16 05:04 - 2013-11-24 15:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-16 05:00 - 2012-04-02 15:15 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-13 22:14 - 2014-02-13 22:14 - 00003178 _____ () C:\Windows\System32\Tasks\{57E8181A-0929-418A-A72C-CE10D919BEE8}
2014-02-13 22:12 - 2014-02-13 22:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-02-13 22:03 - 2014-02-13 22:03 - 00336384 _____ () C:\Windows\SysWOW64\ScriptHook.dll
2014-02-13 18:31 - 2012-04-02 15:23 - 00004098 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-13 18:31 - 2012-04-02 15:23 - 00003846 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-13 03:16 - 2014-02-13 03:16 - 00000000 ____D () C:\Neuer Ordner
2014-02-12 22:16 - 2014-02-12 22:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-12 21:23 - 2014-02-12 21:23 - 00000000 ____D () C:\Program Files\PowerISO
2014-02-11 02:25 - 2014-02-11 02:25 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-02-10 21:57 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-10 21:12 - 2014-02-10 21:12 - 01199079 _____ () C:\Windows\unins000.exe
2014-02-10 21:12 - 2014-01-25 21:41 - 00080705 _____ () C:\Windows\unins000.dat
2014-02-06 13:16 - 2014-02-14 03:44 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-14 03:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-14 03:44 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-14 03:44 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-14 03:44 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-14 03:44 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-14 03:44 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-14 03:44 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 11:52 - 2014-02-14 03:44 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 11:49 - 2014-02-14 03:44 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-14 03:44 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 11:48 - 2014-02-14 03:44 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 11:38 - 2014-02-14 03:44 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-14 03:44 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-14 03:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-14 03:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 11:11 - 2014-02-14 03:44 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-14 03:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-14 03:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-14 03:44 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-14 03:44 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-14 03:44 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-14 03:44 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-14 03:44 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:49 - 2014-02-14 03:44 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-06 10:47 - 2014-02-14 03:44 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-14 03:44 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-14 03:44 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 10:25 - 2014-02-14 03:44 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 10:24 - 2014-02-14 03:44 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 10:22 - 2014-02-14 03:44 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-14 03:44 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-14 03:44 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-14 03:44 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-14 03:44 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-14 03:44 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-14 03:44 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-14 03:44 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-14 03:44 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-03 21:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-28 06:47

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---

--- --- ---

]Kann mir denn wirklich niemand helfen ?

Alt 03.03.2014, 23:20   #2
mort
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

PC meldet sich nach Anmeldung automatisch wieder ab 2014 Anleitung / Hilfe





Ich habe dein Thema in Arbeit und melde mich so schnell als möglich mit weiteren Anweisungen.

Ich bedanke mich für deine Geduld
__________________


Alt 04.03.2014, 00:30   #3
Drancer
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

PC meldet sich nach Anmeldung automatisch wieder ab 2014 Details



VIELEN DANK !


Zitat:
Zitat von mort Beitrag anzeigen


Ich habe dein Thema in Arbeit und melde mich so schnell als möglich mit weiteren Anweisungen.

Ich bedanke mich für deine Geduld
Das würd aber nicht eine wocher oder so dauernd oder :/
__________________

Alt 04.03.2014, 01:10   #4
mort
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

Lösung: PC meldet sich nach Anmeldung automatisch wieder ab 2014



Du kriegst in 24 Stunden mindestens eine Antwort von mir.

Alt 04.03.2014, 01:23   #5
Drancer
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

Wie PC meldet sich nach Anmeldung automatisch wieder ab 2014



Ok, und falls etwas wissen willst also zum PC oder ähnliches , frag bitte.


Alt 04.03.2014, 01:28   #6
mort
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

Wo PC meldet sich nach Anmeldung automatisch wieder ab 2014 Lösung!



Du wirst klare Anweisungen von mir bekommen

Alt 04.03.2014, 12:16   #7
mort
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

PC meldet sich nach Anmeldung automatisch wieder ab 2014



Schritt 1

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKU\S-1-5-21-2263356855-1520679738-450664524-1003\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2263356855-1520679738-450664524-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
GroupPolicyUsers\S-1-5-21-2263356855-1520679738-450664524-1003\User: Group Policy restriction detected <======= ATTENTION
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Schritt 2

Falls du dich wieder einloggen kannst, mache den FRST-Scan bitte aus deinem Benutzerkonto. Falls nicht, teile dies mir bitte mit.
Starte noch einmal FRST.

  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, werden ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.

Alt 04.03.2014, 19:07   #8
Drancer
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

PC meldet sich nach Anmeldung automatisch wieder ab 2014



Zitat:
Zitat von mort Beitrag anzeigen
Schritt 1

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKU\S-1-5-21-2263356855-1520679738-450664524-1003\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2263356855-1520679738-450664524-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
GroupPolicyUsers\S-1-5-21-2263356855-1520679738-450664524-1003\User: Group Policy restriction detected <======= ATTENTION
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Schritt 2

Falls du dich wieder einloggen kannst, mache den FRST-Scan bitte aus deinem Benutzerkonto. Falls nicht, teile dies mir bitte mit.
Starte noch einmal FRST.

  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, werden ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.
Hallo mort.

Erstmal danke für die Antwort !
Ich hab mcih mit abgesicherten Modus In mein Admin Account eingeloggt, also das Konto wo sich selbstständig abmeldet wenn man normal einloggt. Ich habe das Programm gestartet (denn fixlist hatte ich natürlich auf dem Desktop) und auf Fix buttom geklickt. Nach einem Neustart jeden meldet es sich erneut ab..

Hier die 2 Logs die erstellt wurden .
Fixlog :

Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-03-2014
Ran by PC at 2014-03-04 18:54:34 Run:3
Running from C:\Users\PC\Desktop
Boot Mode: Safe Mode (minimal)
==============================================

Content of fixlist:
*****************
HKU\S-1-5-21-2263356855-1520679738-450664524-1003\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2263356855-1520679738-450664524-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
GroupPolicyUsers\S-1-5-21-2263356855-1520679738-450664524-1003\User: Group Policy restriction detected <======= ATTENTION
*****************

HKU\S-1-5-21-2263356855-1520679738-450664524-1003\Software\Microsoft\Windows\CurrentVersion\Policies\system\\LogonHoursAction => Value not found.
HKU\S-1-5-21-2263356855-1520679738-450664524-1003\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DontDisplayLogonHoursWarnings => Value not found.
"C:\Windows\system32\GroupPolicyUsers\S-1-5-21-2263356855-1520679738-450664524-1003\User" => File/Directory not found.

==== End of Fixlog ====
         
Dann noch die Addition :
Zitat:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-03-2014 01
Ran by Administrator at 2014-03-03 20:41:55
Running from C:\Users\Administrator\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

µTorrent (HKCU\...\uTorrent) (Version: 3.4.1.30615 - BitTorrent Inc.)
Activision(R) (x32 Version: 1.0 - Activision) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.2.0.2070 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.2.0.2070 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated)
Adobe Photoshop CS (HKLM-x32\...\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}) (Version: CS - Adobe Systems, Inc.)
Adobe Reader X (10.1.9) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.9 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)
Alcor Micro USB Card Reader Driver (HKLM-x32\...\InstallShield_{838DA1F1-23F8-4C70-B190-AC51CB5A5ECD}) (Version: 3.1.45.72435 - Alcor Micro Corp.)
Alcor Micro USB Card Reader Driver (x32 Version: 3.1.45.72435 - Alcor Micro Corp.) Hidden
AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden
AMD Drag and Drop Transcoding (Version: 2.00.0000 - ATI Technologies Inc.) Hidden
Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo Magical Snap (HKLM-x32\...\Ashampoo Magical Snap) (Version: - ashampoo GmbH & Co. KG)
ATI AVIVO64 Codecs (Version: 11.6.0.10112 - ATI Technologies Inc.) Hidden
Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 3.6 - Auslogics Software Pty Ltd)
Avira APC 0.1.0.1 (HKLM-x32\...\{18948029-33D5-4B93-8275-FE1FC7A43D51}_is1) (Version: 0.1.0.1 - Avira Operations GmbH & Co. KG)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.2.286 - Avira)
Bandicam (HKLM-x32\...\Bandicam) (Version: 1.9.1.419 - Bandisoft.com)
Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandisoft.com)
Battlefield 3™ (HKLM-x32\...\{64BFBE7A-886C-4CA2-A9B4-0C2B5A5942BC}) (Version: 1.6.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.2 - EA Digital Illusions CE AB)
BF3 Settings Editor (HKLM\...\{5866DD36-8055-475B-A5C3-82C04091D14E}) (Version: 2.3 - Realmware)
Brockhaus multimedial 2011 (HKLM-x32\...\{50D69C54-6963-49A6-B762-A9FF8F56AF0F}) (Version: 13.00.0000 - wissenmedia GmbH)
CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform)
CLEO 4.3 (HKLM-x32\...\{A8F37EB0-C741-41D7-8CAB-5B40ECEEF094}_is1) (Version: 4.3 - Seemann, Deji, Alien)
Clock Screen Saver (HKLM-x32\...\QWhaleClockScreenSaver) (Version: - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
Fotogalerie (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Free 3D Photo Maker version 2.0.27.225 (HKLM-x32\...\Free 3D Photo Maker_is1) (Version: 2.0.27.225 - DVDVideoSoft Ltd.)
Free Image Convert and Resize version 2.1.26.225 (HKLM-x32\...\Free Image Convert and Resize_is1) (Version: 2.1.26.225 - DVDVideoSoft Ltd.)
Free MP3 Recorder 1.0 (HKLM-x32\...\{AE84E7FF-4DEC-48EC-BBA9-9A808E48DF8E}_is1) (Version: 1.0 - WordAddin Studio)
Free Video Dub version 2.0.21.822 (HKLM-x32\...\Free Video Dub_is1) (Version: 2.0.21.822 - DVDVideoSoft Ltd.)
Free Video to JPG Converter version 5.0.32.1230 (HKLM-x32\...\Free Video to JPG Converter_is1) (Version: 5.0.32.1230 - DVDVideoSoft Ltd.)
Free WebM Video Converter version 5.0.34.225 (HKLM-x32\...\Free WebM Video Converter_is1) (Version: 5.0.34.225 - DVDVideoSoft Ltd.)
Free YouTube Uploader version 4.0.6.1219 (HKLM-x32\...\Free YouTube Uploader_is1) (Version: 4.0.6.1219 - DVDVideoSoft Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.117 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
HydraVision (x32 Version: 4.2.184.0 - ATI Technologies Inc.) Hidden
Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
jetAudio Basic VX (HKLM-x32\...\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}) (Version: 8.0.16 - COWON)
LPT System Updater Service (HKLM-x32\...\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}) (Version: 1.0.0.0 - LPT) <==== ATTENTION
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850419-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
MotioninJoy ds3 driver version 0.6.0003 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.5.0001 - www.motioninjoy.com)
Movavi Turbo Plugin 1.1 (HKLM-x32\...\Movavi Turbo Plugin) (Version: 1.1 - Movavi)
Movie Maker (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Mozilla Firefox 27.0.1 (x86 ru) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 ru)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
MSI Afterburner 2.1.0 (HKLM-x32\...\Afterburner) (Version: 2.1.0 - MSI Co., LTD)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
muvee autoProducer 6.1 (HKLM-x32\...\{7B312BFD-6C04-4409-AB6F-DD41CCD67463}) (Version: 6.10.000 - muvee Technologies)
muvee Reveal (HKLM-x32\...\{D86CC59E-381B-E4E9-EEDF-CBE4105C784D}) (Version: 8.0.1.17654 - muvee Technologies Pte Ltd)
MySoundStudio (HKLM-x32\...\{20EFE260-2C3A-4821-80B7-639B39EFE67B}) (Version: - )
Ñáîðíèê èêîíîê 17.0 (HKLM-x32\...\Ñáîðíèê èêîíîê 17.0) (Version: - )
Nero 7 Micro v7.9.6.0 (HKLM-x32\...\Nero7Micro_is1) (Version: - jameszero)
NVIDIA PhysX (HKLM-x32\...\{DEA314C4-0929-4250-BC92-98E4C105F28D}) (Version: 9.10.0129 - NVIDIA Corporation)
Office-Bibliothek (HKLM-x32\...\{5C81B189-5456-40C4-9313-7FE6FA6DD64C}) (Version: 5.00.4 - Bibliographisches Institut & F.A. Brockhaus AG)
Origin (HKLM-x32\...\Origin) (Version: 9.3.11.2762 - Electronic Arts, Inc.)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.9 - Pando Networks Inc.)
PeerBlock 1.1+ (r677) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.1.0.677 - PeerBlock, LLC)
Photo Gallery (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
PhotoScape (HKLM-x32\...\PhotoScape) (Version: - )
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PowerISO (HKLM-x32\...\PowerISO) (Version: 5.8 - Power Software Ltd)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
QuickTime Alternative 1.76 (HKLM-x32\...\QuicktimeAlt_is1) (Version: 1.76 - )
RealDownloader (x32 Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.46.610.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7026 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
RusTV Player 2.5 (HKLM-x32\...\RusTV Player 2.5) (Version: - )
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.24.0 - SAMSUNG Electronics Co., Ltd.)
San Andreas Mod Installer (HKLM-x32\...\San Andreas Mod Installer1.0) (Version: - )
San Andreas Mod Installer (HKLM-x32\...\San Andreas Mod Installer1.1) (Version: 1.1 - cpmusick)
Schultraining 11. Klasse bis Abitur (HKLM-x32\...\{18F50E84-4DA1-4D05-BEAF-512CE6DF841B}) (Version: 1.1.0 - Bibliographisches Institut AG)
Schultraining 2. bis 4. Klasse (HKLM-x32\...\{15CAD98F-A94A-4633-AF06-FD522A5EAE1E}) (Version: 1.1.0 - Bibliographisches Institut AG)
Schultraining 5. bis 10. Klasse (HKLM-x32\...\{42F71418-BC0A-4F31-968B-EFDEFB61C723}) (Version: 1.1.0 - Bibliographisches Institut AG)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.19617 - TeamViewer)
Traffic Inspector (HKLM-x32\...\{2E2448C5-1ACC-41F3-A621-3285C23E904A}) (Version: 2.0.1 - Smart-Soft, Copyright © 2003-2012 (2.0.1.724))
Transformers(TM) - War for Cybertron(TM) (HKLM-x32\...\InstallShield_{2A96D655-4FEF-4512-9468-0AABA70CD389}) (Version: 1.0 - Activision)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
Win7codecs (HKLM-x32\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 2.7.3 - Shark007)
WinArchiver (HKLM-x32\...\WinArchiver) (Version: 3.4 - Power Software Ltd)
Windows Live Communications Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
Winki (HKLM-x32\...\{81CF5153-38CF-41e2-AC3C-3D477C987D96}_is1) (Version: 3.2.114 - MSI)
Wissens-Center (HKLM-x32\...\{F887B4C1-F448-4195-AFB7-28A774D2171D}) (Version: 10.1 - inmediaONE] GmbH)
Zello 1.34.0.0 (HKLM-x32\...\Zello) (Version: 1.34.0.0 - Zello Inc)
Zona (HKLM-x32\...\Zona)) (Version: - )
Zvu.com 18.0.1 (x86 ru) (HKLM-x32\...\Zvu.com 18.0.1 (x86 ru)) (Version: 18.0.1 - PentagonIT)
Основные компоненты Windows Live (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Фотоальбом (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Фотографии (общедоступная версия) (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden

==================== Restore Points =========================

02-03-2014 18:00:15 Windows-Sicherung
02-03-2014 23:27:04 Entfernt Battlefield 2(TM)
02-03-2014 23:34:00 Installiert Battlefield 2(TM)
02-03-2014 23:44:36 Installiert Battlefield 2 Patch v1.4
02-03-2014 23:45:27 Installiert Battlefield 2 Patch v1.4
02-03-2014 23:54:01 Installiert Battlefield 2 Patch
03-03-2014 15:22:30 Wiederherstellungsvorgang
03-03-2014 16:15:56 Windows Update
03-03-2014 16:19:36 Windows Update
03-03-2014 19:29:48 Entfernt Battlefield 2(TM)

==================== Hosts content: ==========================

2013-01-18 07:56 - 2014-02-07 07:14 - 00449888 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.123fporn.info
127.0.0.1 123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

Task: {035159FE-6E42-466E-93BA-BF6C958224AC} - \QtraxPlayer No Task File
Task: {0AC6E811-CB97-4FD4-8EBF-03EA8CA48340} - \Software Updater Ui No Task File
Task: {0B7FD22D-DBD9-4A1A-B0AE-8EE516A34BF5} - \DealPlyUpdate No Task File
Task: {0D0F8A57-12FB-46F0-8E96-C9C2A753DCDB} - System32\Tasks\{5054DE2F-8424-4F2A-9EDF-CE4ABABA124E} => C:\Users\PC\Desktop\Need for Speed Rivals™\Need for Speed Rivals\Rivals-64.exe
Task: {12E17FB4-6C37-4349-8A68-F4604D5245A8} - System32\Tasks\{A1F555DF-A097-47A5-BA00-72168A390B29} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/ru/abandoninstall?page=tsProgressBar
Task: {15754B07-4D11-4261-852E-D0678AAE1468} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2263356855-1520679738-450664524-1003
Task: {199D581E-A5EC-40A1-8435-66BE9068CC80} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {2693B4A4-929C-4DB7-AC20-41F47CBE28F4} - \Omiga Plus RunAsStdUser No Task File
Task: {31C700A7-3210-455E-80C1-919E28838F14} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-02] (Google Inc.)
Task: {33F5F282-6B84-4D3B-AF75-232F5B04E8F5} - \DSite No Task File
Task: {3709E8C9-BACE-44A3-A87D-1AB0140AA108} - \Dealply No Task File
Task: {41AB0780-C1A4-4AF5-9F33-7ABFD7702B47} - System32\Tasks\{E1A25111-2145-44F6-95B1-C55AF343DDED} => C:\Users\PC\Desktop\bewerbung\GTA San Andreas modded\gta_sa.exe
Task: {46D7CA6E-BA34-4823-9903-11C6D103EF27} - System32\Tasks\{417B9B5E-A815-462A-B075-07AB3D90BBDB} => C:\Users\PC\Desktop\GTA San Andreas\gta_sa.exe
Task: {4B0C7567-76D6-4C0A-9281-9F03618A46EC} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14] (RealNetworks, Inc.)
Task: {618C8803-85FE-4D5D-BEFA-CB1177B59944} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {7215642F-4C03-43B5-80CA-A206BCFB6569} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {748696AA-C682-4276-9B2B-6A12BB68EF94} - System32\Tasks\Razer_Game_Booster_AutoUpdate => C:\Program Files (x86)\Razer\Razer Game Booster\AutoUpdate.exe
Task: {78ED3C1B-819D-4CE7-BAB4-07D43361DCD7} - \DealPlyLiveUpdateTaskMachineUA No Task File
Task: {7FF6348C-26B7-4E35-ACD7-5EC3B3E2A593} - \FreeDriverScout No Task File
Task: {837309DB-7FFC-4539-A341-99BDA961ECFB} - System32\Tasks\SK.Enhancer-S-161304646 => c:\programdata\quickset\sk.enhancer\SK.Enhancer.exe <==== ATTENTION
Task: {8FFC9C41-AF48-47EC-86A4-B78058CDF4C5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-21] (Adobe Systems Incorporated)
Task: {9427009B-AD84-4A25-95DA-F0F0FFE4AF17} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-02] (Google Inc.)
Task: {943A5343-7A8C-4AE9-AD2A-274942028503} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {993B34EC-E4C4-47A9-A6BA-DFA764F0DAB3} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2263356855-1520679738-450664524-501
Task: {A43B0913-2615-483D-B9F5-95D34A04BFA5} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-500 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {A8CEC3A0-A70E-497C-B95D-2B24B33ED790} - \GoforFilesUpdate No Task File
Task: {B36F5150-3EE6-4A27-9FEE-1079F9E8C018} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003UA => C:\Users\PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {B71EC865-D95B-40B1-9613-17E7CAED6914} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {BA37C2B8-28A3-4DD5-870F-F54123D93AC7} - System32\Tasks\{DF6BB311-5A3F-4622-BC2D-A4EC40282B66} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/ru/abandoninstall?page=tsProgressBar
Task: {BF4EC081-F7F5-4AB7-AED3-5D64C711C69D} - \DealPlyLiveUpdateTaskMachineCore No Task File
Task: {C0BA77C8-9674-4335-BE19-A301F0D47781} - \Your File Updater No Task File
Task: {C53C386F-E603-44FB-8A37-233C83C04441} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {C9252470-FD36-431D-9110-713CDA480C51} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003Core => C:\Users\PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {D1F1CD9B-9F8D-4966-8BD8-92D90B80AB0D} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {DD3B500F-3AC1-4760-A100-451C44B8DC25} - System32\Tasks\{6B9E2275-6016-45E7-96AE-D200C35A20B2} => C:\Users\PC\Desktop\GTA San Andreas\gta_sa.exe
Task: {DE1B7FC0-FDF5-4D85-A582-AC4A43524C98} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {E71AC47F-72E7-42FB-8E9E-951F326EB1C6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {E937A32F-C8B3-455E-A4FB-0FF47F397631} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd)
Task: {F2BF422D-4E9D-4C22-9DCA-8521147AC0C5} - \Desk 365 RunAsStdUser No Task File
Task: {F905D356-0795-40E1-9DBA-7DB5DD9EA8C6} - \Software Updater No Task File
Task: {FFED680F-D090-4170-9CA4-583D6D4A715C} - System32\Tasks\FRAPS => C:\Fraps\fraps.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003Core.job => C:\Users\PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003UA.job => C:\Users\PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SK.Enhancer-S-161304646.job => c:\programdata\quickset\sk.enhancer\SK.Enhancer.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2013-11-10 03:53 - 2013-11-10 03:53 - 00202264 _____ () C:\Program Files (x86)\WinArchiver\WAService.exe
2012-04-02 19:19 - 2013-12-31 00:13 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2012-12-17 07:56 - 2012-09-19 18:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-02-22 17:39 - 2014-02-20 02:02 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\chrome_elf.dll
2014-02-22 17:39 - 2014-02-20 02:02 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\libglesv2.dll
2014-02-22 17:39 - 2014-02-20 02:02 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\libegl.dll
2014-02-22 17:39 - 2014-02-20 02:03 - 04060488 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\pdf.dll
2014-02-22 17:39 - 2014-02-20 02:03 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll
2014-02-22 17:39 - 2014-02-20 02:02 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ffmpegsumo.dll
2014-02-22 17:39 - 2014-02-20 02:03 - 13632840 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:0CE7F3C9
AlternateDataStreams: C:\ProgramData\TEMP:661DFA1C
AlternateDataStreams: C:\Users\PC\Lokale Einstellungen:wa
AlternateDataStreams: C:\Users\PC\AppData\Local:wa
AlternateDataStreams: C:\Users\PC\AppData\Local\Anwendungsdaten:wa

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============

MSCONFIG\Services: TeamViewer8 => 2
MSCONFIG\startupreg: AppsHat => C:\Users\PC\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe
MSCONFIG\startupreg: KiesPreload => C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: MsgCenterExe => "C:\Program Files (x86)\Real\RealPlayer\update\RealOneMessageCenter.exe" -osboot
MSCONFIG\startupreg: multibar.exe =>
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: TkBellExe => "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
MSCONFIG\startupreg: uTorrent => "C:\Users\Administrator\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
MSCONFIG\startupreg: Zello => "C:\Program Files (x86)\Zello\Zello.exe" /background

==================== Faulty Device Manager Devices =============

Name: AODDriver4.01
Description: AODDriver4.01
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: AODDriver4.01
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/03/2014 08:33:33 PM) (Source: Microsoft-Windows-User Profiles Service) (User: NT-AUTORITÄT)
Description: Die Klassenregistrierungsdatei kann nicht geladen werden.
DETAIL - Das System kann die angegebene Datei nicht finden.

Error: (03/03/2014 08:33:33 PM) (Source: Microsoft-Windows-User Profiles Service) (User: NT-AUTORITÄT)
Description: Die Klassenregistrierungsdatei kann nicht geladen werden.
DETAIL - Das System kann die angegebene Datei nicht finden.

Error: (03/03/2014 08:33:31 PM) (Source: Microsoft-Windows-User Profiles Service) (User: NT-AUTORITÄT)
Description: Die Klassenregistrierungsdatei kann nicht geladen werden.
DETAIL - Das System kann die angegebene Datei nicht finden.

Error: (03/03/2014 08:32:46 PM) (Source: Microsoft-Windows-User Profiles Service) (User: NT-AUTORITÄT)
Description: Die Klassenregistrierungsdatei kann nicht geladen werden.
DETAIL - Das System kann die angegebene Datei nicht finden.

Error: (03/03/2014 08:29:48 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-2263356855-1520679738-450664524-1003.bak)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.


Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt

Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {5ca0046b-f6b3-49cf-90e2-d514341462e3}

Error: (03/03/2014 08:26:36 PM) (Source: Microsoft-Windows-User Profiles Service) (User: NT-AUTORITÄT)
Description: Die Klassenregistrierungsdatei kann nicht geladen werden.
DETAIL - Das System kann die angegebene Datei nicht finden.

Error: (03/03/2014 08:26:23 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/03/2014 08:03:57 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/03/2014 07:50:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/03/2014 07:49:00 PM) (Source: Microsoft-Windows-User Profiles Service) (User: NT-AUTORITÄT)
Description: Die Klassenregistrierungsdatei kann nicht geladen werden.
DETAIL - Das System kann die angegebene Datei nicht finden.


System errors:
=============
Error: (03/03/2014 08:33:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535

Error: (03/03/2014 08:33:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535

Error: (03/03/2014 08:33:33 PM) (Source: PNRPSvc) (User: )
Description: 0x80630801

Error: (03/03/2014 08:33:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535

Error: (03/03/2014 08:33:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535

Error: (03/03/2014 08:33:33 PM) (Source: PNRPSvc) (User: )
Description: 0x80630801

Error: (03/03/2014 08:32:49 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535

Error: (03/03/2014 08:32:49 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535

Error: (03/03/2014 08:32:49 PM) (Source: PNRPSvc) (User: )
Description: 0x80630801

Error: (03/03/2014 08:27:50 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535


Microsoft Office Sessions:
=========================
Error: (03/03/2014 08:33:33 PM) (Source: Microsoft-Windows-User Profiles Service)(User: NT-AUTORITÄT)
Description: Das System kann die angegebene Datei nicht finden.

Error: (03/03/2014 08:33:33 PM) (Source: Microsoft-Windows-User Profiles Service)(User: NT-AUTORITÄT)
Description: Das System kann die angegebene Datei nicht finden.

Error: (03/03/2014 08:33:31 PM) (Source: Microsoft-Windows-User Profiles Service)(User: NT-AUTORITÄT)
Description: Das System kann die angegebene Datei nicht finden.

Error: (03/03/2014 08:32:46 PM) (Source: Microsoft-Windows-User Profiles Service)(User: NT-AUTORITÄT)
Description: Das System kann die angegebene Datei nicht finden.

Error: (03/03/2014 08:29:48 PM) (Source: VSS)(User: )
Description: ConvertStringSidToSid(S-1-5-21-2263356855-1520679738-450664524-1003.bak)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.


Vorgang:
OnIdentify-Ereignis
Generatordaten werden gesammelt

Kontext:
Ausführungskontext: Shadow Copy Optimization Writer
Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Generatorname: Shadow Copy Optimization Writer
Generatorinstanz-ID: {5ca0046b-f6b3-49cf-90e2-d514341462e3}

Error: (03/03/2014 08:26:36 PM) (Source: Microsoft-Windows-User Profiles Service)(User: NT-AUTORITÄT)
Description: Das System kann die angegebene Datei nicht finden.

Error: (03/03/2014 08:26:23 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/03/2014 08:03:57 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/03/2014 07:50:32 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/03/2014 07:49:00 PM) (Source: Microsoft-Windows-User Profiles Service)(User: NT-AUTORITÄT)
Description: Das System kann die angegebene Datei nicht finden.


CodeIntegrity Errors:
===================================
Date: 2013-03-12 14:23:54.408
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2013-03-12 14:23:54.382
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2013-03-12 14:23:51.865
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2013-03-12 14:23:51.844
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2013-03-12 14:23:48.652
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2013-03-12 14:23:48.630
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2013-03-12 14:23:45.387
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2013-03-12 14:23:45.365
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2013-03-12 14:23:42.333
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2013-03-12 14:23:42.312
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Percentage of memory in use: 28%
Total physical RAM: 8191.18 MB
Available physical RAM: 5885.22 MB
Total Pagefile: 16380.54 MB
Available Pagefile: 13839.93 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:46.06 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 9A5E8B2E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

==================== End Of Log ============================
MFG !

Eins noch, ich muss das Programm in dem Konto ausführen wo sich ständig abmeldet oder ?
Hab es auch mit dem Konto probiert wo normal läuft, jedoch erfolglos.

Alt 04.03.2014, 19:32   #9
mort
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

PC meldet sich nach Anmeldung automatisch wieder ab 2014



Zitat:
jedoch erfolglos
Was ist passiert? Gab es irgendwelche Fehler?

Hast du mehrere Nutzer? Kannst du dich in einen einloggen? Welcher User ist betroffen?

Geändert von mort (04.03.2014 um 19:38 Uhr)

Alt 04.03.2014, 19:45   #10
Drancer
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

PC meldet sich nach Anmeldung automatisch wieder ab 2014 [gelöst]



Zitat:
Zitat von mort Beitrag anzeigen
Was ist passiert? Gab es irgendwelche Fehler?

Hast du mehrere Nutzer? Kannst du dich in einen einloggen? Welcher User ist betroffen?
Ja ich habe genau 2 User. Der eine User wo sich ständig abmeldet, Primärer User,Admin user der wichtigste von allem ist betroffen.
Und den wo ich jetzt gerade benutze.

Ich habe einmal im abgesicherten modus in Admin User die Fixlist benutzt. PC neugestartet im normalen modus und es hat mich wieder abgemeldet. Hab auch mit dem User wo ich gerade benutze (also wo in ordnung ist ) auch probiert,resultat dasselbe.
Mir fällt ein das dieser Problem aufgetaucht ist seit ich Malewarebyte benutzt habe und viele Viren in Quarante gesteckt habe, manche sind sogar windows Datein. Mit CCleaner hab ich auch Regristry Fehler gefunden , auch behoben.

Eine wichtige FRAGE, im welchen user muss ich das programm laufen lassen ? ist es egal ?
mfg

Alt 04.03.2014, 19:54   #11
mort
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

PC meldet sich nach Anmeldung automatisch wieder ab 2014 [gelöst]



Könntest du FRST unter dem zweiten User, den du grade nutzt, laufen lassen?

Alt 04.03.2014, 20:10   #12
Drancer
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

PC meldet sich nach Anmeldung automatisch wieder ab 2014 [gelöst]



Ja, Ich poste es gleich

Alt 04.03.2014, 20:16   #13
Drancer
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Beitrag

PC meldet sich nach Anmeldung automatisch wieder ab 2014 [gelöst]



Log vom zweitem Account.

Zitat:
Zitat von mort Beitrag anzeigen
Könntest du FRST unter dem zweiten User, den du grade nutzt, laufen lassen?

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-03-2014
Ran by Administrator (administrator) on PC-PC on 04-03-2014 20:10:11
Running from C:\Users\Administrator\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

() C:\Program Files (x86)\WinArchiver\WAService.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Doctor Web, Ltd.) C:\Program Files (x86)\TrafInsp\plugins\DwAV\Engine\dwengine.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(SMART-SOFT) C:\Program Files (x86)\TrafInsp\TrafInsp.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AMD) C:\Windows\system32\atieclxx.exe
(SMART-SOFT) C:\Program Files (x86)\TrafInsp\ASP.NET\bin\TIASPNETHostServer.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Power Software Ltd) C:\Program Files (x86)\WinArchiver\WAHELPER.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\updrgui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7198424 2013-08-28] (Realtek Semiconductor)
HKLM\...\Run: [] - [X]
HKLM\...\Run: [AdAwareTray] - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe [4114264 2014-01-23] ()
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime Alternative\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-11-09] (RealNetworks, Inc.)
HKLM-x32\...\Run: [WAHELPER.EXE] - C:\Program Files (x86)\WinArchiver\WAHELPER.EXE [480792 2013-11-10] (Power Software Ltd)
HKU\S-1-5-21-2263356855-1520679738-450664524-500\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2011-01-12] (AMD)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0D7BFBE9F903CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: No Name - {74D271A4-00A7-0F5C-560A-2412C0CFD357} -  No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: No Name - {8984B388-A5BB-4DF7-B274-77B879E179DB} -  No File
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.66.2.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\eddz111h.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mailru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ozonru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\priceru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-slovari.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex.xml
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-11-09]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []

Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchURL: hxxp://www.google.com/search?q={searchTerms}
CHR DefaultNewTabURL: 
CHR Extension: (Google Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-30]
CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-30]
CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-30]
CHR Extension: (Google-Suche) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-30]
CHR Extension: (RealDownloader) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-02-24]
CHR Extension: (Google Wallet) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-30]
CHR Extension: (Google Mail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-30]
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2012-06-21] ()
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG)
R2 DrWebEngine; C:\Program Files (x86)\TrafInsp\plugins\DwAV\Engine\dwengine.exe [1667416 2012-06-28] (Doctor Web, Ltd.)
R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe [702744 2014-01-23] ()
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5148240 2013-07-23] (INCA Internet Co., Ltd.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-31] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 TrafInspSrv; C:\Program Files (x86)\TrafInsp\TrafInsp.exe [4475392 2012-06-08] (SMART-SOFT)
R2 WinArchiver Service; C:\Program Files (x86)\WinArchiver\WAService.exe [202264 2013-11-10] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
R1 TICAPDRV; C:\Windows\System32\DRIVERS\ticap.sys [265880 2012-01-20] (SMART-SOFT)
R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [329800 2013-07-17] (BitDefender S.R.L.)
R0 waemu; C:\Windows\System32\Drivers\waemu.sys [140184 2013-11-10] (Power Software Ltd)
S2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S3 cpuz136; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S2 NEWDRIVER; \??\C:\Windows\SysWow64\WinVDEdrv6.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-04 20:10 - 2014-03-04 20:12 - 00017148 _____ () C:\Users\Administrator\Desktop\FRST.txt
2014-03-04 19:31 - 2014-03-04 19:31 - 00000000 ____D () C:\Users\Administrator\Desktop\GTAA
2014-03-04 19:28 - 2014-03-04 19:38 - 00000000 ___RD () C:\Users\Administrator\Desktop\GTA San Andreas
2014-03-04 19:20 - 2014-03-04 19:33 - 00000000 ___RD () C:\Users\Administrator\Dropbox
2014-03-04 19:20 - 2014-03-04 19:20 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Adobe
2014-03-04 19:18 - 2014-03-04 19:39 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Dropbox
2014-03-04 19:14 - 2014-03-04 19:16 - 37660568 _____ (Dropbox, Inc.) C:\Users\Administrator\Downloads\Dropbox 2.6.2.exe
2014-03-04 18:44 - 2014-03-04 18:44 - 00262144 ____N () C:\Windows\Minidump\030414-21403-01.dmp
2014-03-04 18:37 - 2014-03-04 18:37 - 02156544 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe
2014-03-04 15:20 - 2014-03-04 15:20 - 00001160 ____H () C:\Users\Administrator\Desktop\$$JetTHM$$.cache
2014-03-04 15:12 - 2014-03-04 15:12 - 00000000 ____D () C:\Users\Administrator\Documents\Freemake
2014-03-04 15:10 - 2014-03-04 15:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\COWON
2014-03-04 15:08 - 2014-03-04 15:16 - 562072450 ____R () C:\Users\Administrator\Desktop\Noviy.Comedy.Club.(efir.28.02.2014).WEBRip.avi
2014-03-04 14:29 - 2014-03-04 15:24 - 1582391058 ____R () C:\Users\Administrator\Desktop\KVN.2014.1.igra.hdtvrip.avi
2014-03-04 14:09 - 2014-03-04 14:09 - 00013068 _____ () C:\Users\Administrator\Downloads\[rutor.org]Новый_Comedy_Club.torrent
2014-03-04 14:07 - 2014-03-04 14:07 - 00011261 _____ () C:\Users\Administrator\Downloads\[rutor.org]Noviy.Comedy.Club.(efir.28.02.2014).WEBRip.avi_.torrent
2014-03-04 14:06 - 2014-03-04 14:06 - 00015603 _____ () C:\Users\Administrator\Downloads\[rutor.org]KVN.2014.1.igra.hdtvrip.avi.torrent
2014-03-04 14:05 - 2014-03-04 14:05 - 00017937 _____ () C:\Users\Administrator\Downloads\[rutor.org]Splin-Rezonans,_chast_1.torrent
2014-03-04 14:05 - 2014-03-04 14:05 - 00013062 _____ () C:\Users\Administrator\Downloads\[rutor.org]Ляпис_Трубецкой-Матрёшка.torrent
2014-03-04 14:03 - 2014-03-04 15:11 - 00000000 ____D () C:\Users\Administrator\Desktop\Top Gear 21х01-04.720p
2014-03-04 14:03 - 2014-03-04 14:03 - 00012263 _____ () C:\Users\Administrator\Downloads\[rutor.org]Kuhnja.3.01.TVRip.avi.torrent
2014-03-04 14:03 - 2014-03-04 14:03 - 00011783 _____ () C:\Users\Administrator\Downloads\[rutor.org]Kuhnja.3.02.TVRip.avi.torrent
2014-03-04 14:02 - 2014-03-04 14:02 - 00019388 _____ () C:\Users\Administrator\Downloads\[rutor.org]Top_Gear_21х01-04.720p.torrent
2014-03-04 14:02 - 2014-03-04 14:02 - 00000000 ____D () C:\Users\Administrator\Desktop\Discovery_Aliens mummies (2012) SATRip
2014-03-04 14:01 - 2014-03-04 14:01 - 00012821 _____ () C:\Users\Administrator\Downloads\[rutor.org]Discovery_Aliens_mummies_(2012)_SATRip.torrent
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2014-03-04 13:55 - 2014-03-04 16:07 - 1467863040 ____R () C:\Users\Administrator\Desktop\The.Hungover.Games.Unrated Edition.2014.D.WEB-DLRip.1400Mb.avi
2014-03-04 13:55 - 2014-03-04 13:55 - 00014538 _____ () C:\Users\Administrator\Downloads\[filmitorrent.org]The.Hungover.Games.Unrated_Edition.2014.D.WEB-D_0.torrent
2014-03-04 01:57 - 2014-03-04 01:57 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LavasoftStatistics
2014-03-04 01:54 - 2014-03-04 01:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Lavasoft
2014-03-04 01:53 - 2014-03-04 18:56 - 00002305 _____ () C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2014-03-04 01:53 - 2014-03-04 01:53 - 00000000 ____D () C:\Program Files\Lavasoft
2014-03-04 01:52 - 2014-03-04 01:52 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-03-04 01:51 - 2014-03-04 01:51 - 01727624 _____ () C:\Users\Administrator\Downloads\Adaware_Installer.exe
2014-03-04 01:51 - 2014-03-04 01:51 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-03-03 21:57 - 2014-03-03 21:58 - 00000000 ____D () C:\Users\Administrator\Documents\DVDVideoSoft
2014-03-03 21:57 - 2014-03-03 21:58 - 00000000 ____D () C:\Users\Administrator\Documents\Assassin's Creed Revelations
2014-03-03 21:57 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 3
2014-03-03 21:05 - 2014-03-04 18:57 - 00003350 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-03 21:05 - 2014-03-04 18:57 - 00003232 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-03 20:40 - 2014-03-04 20:10 - 00000000 ____D () C:\FRST
2014-03-03 20:26 - 2014-03-04 18:55 - 00000672 _____ () C:\Windows\setupact.log
2014-03-03 20:26 - 2014-03-03 20:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-03 00:18 - 2014-03-03 00:18 - 00714207 _____ () C:\Users\Administrator\Downloads\pbsetup.zip
2014-03-02 05:39 - 2014-03-02 05:39 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Auslogics
2014-03-02 02:43 - 2014-03-02 02:44 - 01244192 _____ () C:\Users\Administrator\Downloads\adwcleaner_3.0.2.0.exe
2014-03-02 02:41 - 2014-03-02 02:41 - 00000000 ____D () C:\Program Files (x86)\SmartTweak Software
2014-03-02 02:11 - 2014-03-02 02:11 - 00002788 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-01 20:21 - 2014-03-01 21:21 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PhotoScape
2014-03-01 20:18 - 2014-03-01 20:18 - 00000000 ____D () C:\Windows\de
2014-03-01 20:17 - 2014-03-01 20:17 - 00000000 ____D () C:\Windows\en
2014-03-01 20:16 - 2014-03-01 20:16 - 00000000 ____D () C:\Windows\ru
2014-03-01 20:12 - 2014-03-02 19:27 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Windows Live
2014-03-01 20:01 - 2014-03-01 20:01 - 00016384 ___SH () C:\Users\PC\Thumbs.db
2014-03-01 19:45 - 2014-03-02 05:25 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
2014-03-01 13:21 - 2014-03-01 13:21 - 00021008 _____ () C:\Users\PC\Desktop\Mein Film bbbb.wlmp
2014-03-01 07:12 - 2014-03-01 07:19 - 377248555 _____ () C:\Users\PC\Desktop\Mein Film 1.mp4
2014-03-01 06:47 - 2014-03-01 06:47 - 00070520 _____ () C:\Users\PC\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-28 07:10 - 2014-02-28 07:10 - 00015349 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Red.2.2013_HDRip__[scarabey.org].torrent
2014-02-27 14:12 - 2014-02-27 14:12 - 00015648 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Bilet.na.Vegas.2012.O.BDRip.745MB_[Youtracker]_.torrent
2014-02-27 14:11 - 2014-02-27 14:11 - 00015441 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Dubler.2013.O.BDRip.745MB_by_Yarmak23.avi.torrent
2014-02-27 14:07 - 2014-02-27 14:07 - 00014550 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Elki.3.2013.O.DVDRip.700MB.avi.torrent
2014-02-27 11:13 - 2014-02-27 11:13 - 00000088 _____ () C:\Users\PC\Desktop\Два ствола скачать торрент в хорошем качестве бесплатно dvdrip, hdrip.url
2014-02-27 10:52 - 2014-02-27 10:52 - 00000000 ____D () C:\Users\PC\Desktop\08951603108
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\WinArchiver
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Program Files (x86)\WinArchiver
2014-02-26 19:54 - 2013-11-10 03:53 - 00140184 _____ (Power Software Ltd) C:\Windows\system32\Drivers\waemu.sys
2014-02-26 19:49 - 2014-02-26 19:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-26 19:48 - 2014-02-26 19:48 - 00000000 ____D () C:\Program Files\Java
2014-02-26 19:44 - 2014-02-26 19:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PowerISO
2014-02-26 14:01 - 2014-01-09 03:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-02-26 14:01 - 2014-01-03 23:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-02-26 00:02 - 2014-02-26 00:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes
2014-02-25 18:53 - 2014-02-26 19:50 - 00306000 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-25 13:50 - 2014-03-04 18:42 - 00304531 _____ () C:\Windows\WindowsUpdate.log
2014-02-25 13:48 - 2014-03-01 06:47 - 00003188 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-24 23:55 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-02-24 23:54 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-02-24 23:54 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-02-24 23:54 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-02-24 23:54 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-02-24 23:54 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-02-24 23:54 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-02-24 23:54 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-02-24 23:54 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-02-24 23:54 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-02-24 23:54 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-02-24 23:54 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-02-24 23:54 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-02-24 23:54 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-02-24 23:54 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-02-24 23:54 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-02-24 23:53 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-02-24 23:53 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-02-24 23:53 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2014-02-24 23:53 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-02-24 23:53 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2014-02-24 23:53 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-02-24 23:53 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-02-24 23:52 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-02-24 23:52 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Malwarebytes
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-24 17:03 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-23 23:06 - 2014-02-23 23:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Need for Speed World
2014-02-23 22:53 - 2014-02-23 23:16 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Electronic_Arts_Inc
2014-02-23 01:58 - 2014-02-23 01:58 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Realmware
2014-02-22 23:05 - 2014-03-03 20:25 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PhotoScape
2014-02-22 23:05 - 2014-02-22 23:12 - 00008192 ____H () C:\Users\Administrator\Desktop\photothumb.db
2014-02-22 23:04 - 2014-02-23 00:10 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-02-22 01:00 - 2014-02-22 01:00 - 00000000 ____D () C:\Users\PC\Desktop\login
2014-02-21 17:45 - 2014-02-21 17:45 - 00000000 ____D () C:\Users\PC\Desktop\httpwww.youtube.com
2014-02-21 15:51 - 2014-02-21 15:59 - 402748888 _____ () C:\Users\PC\Downloads\Горцы от ума - 4 . Полный фильм - Derbent.tv - Видео Дагестана, новости, приколы, клипы, концерты,свадьбы.flv
2014-02-21 07:39 - 2014-02-21 07:53 - 613726208 ____R () C:\Users\PC\Downloads\ТРИ РУБЛЯ (Дом Кино).mpg
2014-02-21 07:36 - 2014-02-21 07:53 - 616548352 ____R () C:\Users\PC\Downloads\Субботний вечер (Дом Кино).mpg
2014-02-20 00:08 - 2014-02-20 00:08 - 00000000 ____D () C:\Users\Administrator\AppData\Local\EMU
2014-02-20 00:00 - 2014-02-20 00:00 - 00000000 ____D () C:\Program Files (x86)\5
2014-02-19 20:45 - 2014-02-19 20:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Theta
2014-02-19 20:28 - 2014-02-19 20:28 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Ubisoft Game Launcher
2014-02-19 20:28 - 2014-02-19 20:28 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-02-19 20:10 - 2014-02-19 20:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\BANDISOFT
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-02-19 12:10 - 2014-02-19 12:10 - 00000836 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-02-19 12:09 - 2014-03-04 16:08 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent
2014-02-18 03:23 - 2014-02-18 03:23 - 00000000 ____D () C:\Users\Administrator\Documents\Rockstar Games
2014-02-18 03:21 - 2014-02-18 03:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Rockstar Games
2014-02-18 03:01 - 2014-02-18 03:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\SKIDROW
2014-02-18 03:01 - 2014-02-18 03:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Arma 3 Alpha
2014-02-17 18:28 - 2014-02-18 02:23 - 00000000 ____D () C:\Users\Administrator\Documents\My Games
2014-02-17 14:53 - 2014-02-25 14:27 - 00000000 ____D () C:\Users\PC\Downloads\Top Gear S21 E01-02
2014-02-14 03:45 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-14 03:45 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-14 03:44 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-14 03:44 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-14 03:44 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-14 03:44 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-14 03:44 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-14 03:44 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-14 03:44 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-14 03:44 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-14 03:44 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-14 03:44 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-14 03:44 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-14 03:44 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-14 03:44 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-14 03:44 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-14 03:44 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-14 03:44 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-14 03:44 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-14 03:44 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-14 03:44 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-14 03:44 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-14 03:44 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-14 03:44 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-14 03:44 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-14 03:44 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-14 03:44 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-14 03:44 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-14 03:44 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-14 03:44 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-14 03:44 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-14 03:44 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-14 03:44 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-14 03:44 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-14 03:44 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-14 03:44 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-14 03:44 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-14 03:44 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-14 03:44 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-14 03:44 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-14 03:44 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-13 23:19 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-13 23:19 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-13 23:19 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-13 23:19 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-13 23:19 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-13 23:19 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-13 23:19 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-13 23:19 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 23:19 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-13 23:19 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-13 23:19 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-13 23:18 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-13 23:18 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-13 23:18 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-13 23:18 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-13 22:25 - 2014-02-13 22:25 - 00000000 ____D () C:\Users\PC\Documents\Rockstar Games
2014-02-13 22:14 - 2014-02-13 22:14 - 00003178 _____ () C:\Windows\System32\Tasks\{57E8181A-0929-418A-A72C-CE10D919BEE8}
2014-02-13 22:12 - 2014-02-13 22:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-02-13 22:04 - 2014-02-26 23:22 - 00009678 _____ () C:\Windows\SysWOW64\ScriptHook.log
2014-02-13 22:03 - 2014-02-13 22:03 - 00336384 _____ () C:\Windows\SysWOW64\ScriptHook.dll
2014-02-13 03:16 - 2014-02-13 03:16 - 00000000 ____D () C:\Neuer Ordner
2014-02-12 22:16 - 2014-02-12 22:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-12 21:23 - 2014-02-12 21:23 - 00000000 ____D () C:\Program Files\PowerISO
2014-02-12 20:53 - 2013-10-23 15:11 - 00129944 _____ (Power Software Ltd) C:\Windows\system32\Drivers\scdemu.sys
2014-02-12 20:36 - 2014-02-12 20:36 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PowerISO
2014-02-12 20:30 - 2014-02-12 20:30 - 00000000 ____D () C:\Users\PC\AppData\Local\Disc_Soft_Ltd
2014-02-12 20:28 - 2014-02-12 20:28 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DAEMON Tools Ultra
2014-02-11 16:33 - 2014-02-24 16:19 - 00003350 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-11 02:25 - 2014-02-11 02:25 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\New Technology Studio
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenIV
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Local\New Technology Studio
2014-02-11 00:41 - 2014-02-11 00:54 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\www.gtavicecity.ru
2014-02-10 22:05 - 2014-02-10 22:05 - 00000000 ____D () C:\Users\PC\AppData\Local\EMU
2014-02-10 21:12 - 2014-02-10 21:12 - 01199079 _____ () C:\Windows\unins000.exe
2014-02-10 21:11 - 2014-02-10 21:11 - 00000000 ____D () C:\Users\PC\AppData\Local\Chromium
2014-02-10 13:26 - 2014-02-10 13:26 - 00000000 __RHD () C:\Users\PC\AppData\Roaming\SecuROM
2014-02-08 16:15 - 2014-02-08 17:27 - 00000000 ____D () C:\Users\PC\AppData\Local\Mato_Technologies
2014-02-07 06:41 - 2014-02-08 15:53 - 00001782 _____ () C:\Users\PC\Desktop\PeerBlock.lnk
2014-02-07 06:28 - 2014-02-09 23:29 - 00000825 _____ () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk

==================== One Month Modified Files and Folders =======

2014-03-04 20:12 - 2014-03-04 20:10 - 00017148 _____ () C:\Users\Administrator\Desktop\FRST.txt
2014-03-04 20:10 - 2014-03-03 20:40 - 00000000 ____D () C:\FRST
2014-03-04 19:39 - 2014-03-04 19:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Dropbox
2014-03-04 19:38 - 2014-03-04 19:28 - 00000000 ___RD () C:\Users\Administrator\Desktop\GTA San Andreas
2014-03-04 19:38 - 2013-10-26 19:41 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-04 19:36 - 2012-04-02 15:23 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-04 19:33 - 2014-03-04 19:20 - 00000000 ___RD () C:\Users\Administrator\Dropbox
2014-03-04 19:31 - 2014-03-04 19:31 - 00000000 ____D () C:\Users\Administrator\Desktop\GTAA
2014-03-04 19:27 - 2012-04-02 15:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-04 19:20 - 2014-03-04 19:20 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Adobe
2014-03-04 19:20 - 2013-10-26 19:41 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-03-04 19:20 - 2013-10-26 19:40 - 00000000 ____D () C:\Users\Administrator
2014-03-04 19:16 - 2014-03-04 19:14 - 37660568 _____ (Dropbox, Inc.) C:\Users\Administrator\Downloads\Dropbox 2.6.2.exe
2014-03-04 19:04 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-04 19:04 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-04 18:57 - 2014-03-03 21:05 - 00003350 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-04 18:57 - 2014-03-03 21:05 - 00003232 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-04 18:57 - 2012-04-02 15:23 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-04 18:56 - 2014-03-04 01:53 - 00002305 _____ () C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2014-03-04 18:56 - 2013-11-24 17:04 - 00000442 ____H () C:\Windows\Tasks\SK.Enhancer-S-161304646.job
2014-03-04 18:55 - 2014-03-03 20:26 - 00000672 _____ () C:\Windows\setupact.log
2014-03-04 18:55 - 2012-04-02 15:12 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs
2014-03-04 18:55 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-04 18:45 - 2012-04-11 07:01 - 00000000 ____D () C:\Windows\Minidump
2014-03-04 18:44 - 2014-03-04 18:44 - 00262144 ____N () C:\Windows\Minidump\030414-21403-01.dmp
2014-03-04 18:42 - 2014-02-25 13:50 - 00304531 _____ () C:\Windows\WindowsUpdate.log
2014-03-04 18:39 - 2013-10-26 19:40 - 00000008 __RSH () C:\Users\Administrator\ntuser.pol
2014-03-04 18:39 - 2013-06-14 16:23 - 00000322 __RSH () C:\Users\PC\ntuser.pol
2014-03-04 18:39 - 2012-04-02 14:26 - 00000000 ____D () C:\Users\PC
2014-03-04 18:38 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-03-04 18:37 - 2014-03-04 18:37 - 02156544 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe
2014-03-04 18:33 - 2013-02-16 19:35 - 00000000 ___RD () C:\Users\Administrator\Desktop\bewerbung
2014-03-04 17:19 - 2013-08-12 15:04 - 00000000 ____D () C:\Program Files\PeerBlock
2014-03-04 17:13 - 2012-04-27 19:42 - 00000069 _____ () C:\Windows\NeroDigital.ini
2014-03-04 16:41 - 2012-04-03 05:05 - 00000000 ___RD () C:\Users\PC\Desktop\PROGRAMME
2014-03-04 16:08 - 2014-02-19 12:09 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent
2014-03-04 16:07 - 2014-03-04 13:55 - 1467863040 ____R () C:\Users\Administrator\Desktop\The.Hungover.Games.Unrated Edition.2014.D.WEB-DLRip.1400Mb.avi
2014-03-04 15:24 - 2014-03-04 14:29 - 1582391058 ____R () C:\Users\Administrator\Desktop\KVN.2014.1.igra.hdtvrip.avi
2014-03-04 15:20 - 2014-03-04 15:20 - 00001160 ____H () C:\Users\Administrator\Desktop\$$JetTHM$$.cache
2014-03-04 15:16 - 2014-03-04 15:08 - 562072450 ____R () C:\Users\Administrator\Desktop\Noviy.Comedy.Club.(efir.28.02.2014).WEBRip.avi
2014-03-04 15:12 - 2014-03-04 15:12 - 00000000 ____D () C:\Users\Administrator\Documents\Freemake
2014-03-04 15:11 - 2014-03-04 14:03 - 00000000 ____D () C:\Users\Administrator\Desktop\Top Gear 21х01-04.720p
2014-03-04 15:10 - 2014-03-04 15:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\COWON
2014-03-04 15:05 - 2013-11-24 03:03 - 00000000 ____D () C:\Users\PC\Desktop\na more
2014-03-04 14:39 - 2013-02-23 17:34 - 00000916 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003UA.job
2014-03-04 14:09 - 2014-03-04 14:09 - 00013068 _____ () C:\Users\Administrator\Downloads\[rutor.org]Новый_Comedy_Club.torrent
2014-03-04 14:07 - 2014-03-04 14:07 - 00011261 _____ () C:\Users\Administrator\Downloads\[rutor.org]Noviy.Comedy.Club.(efir.28.02.2014).WEBRip.avi_.torrent
2014-03-04 14:06 - 2014-03-04 14:06 - 00015603 _____ () C:\Users\Administrator\Downloads\[rutor.org]KVN.2014.1.igra.hdtvrip.avi.torrent
2014-03-04 14:05 - 2014-03-04 14:05 - 00017937 _____ () C:\Users\Administrator\Downloads\[rutor.org]Splin-Rezonans,_chast_1.torrent
2014-03-04 14:05 - 2014-03-04 14:05 - 00013062 _____ () C:\Users\Administrator\Downloads\[rutor.org]Ляпис_Трубецкой-Матрёшка.torrent
2014-03-04 14:03 - 2014-03-04 14:03 - 00012263 _____ () C:\Users\Administrator\Downloads\[rutor.org]Kuhnja.3.01.TVRip.avi.torrent
2014-03-04 14:03 - 2014-03-04 14:03 - 00011783 _____ () C:\Users\Administrator\Downloads\[rutor.org]Kuhnja.3.02.TVRip.avi.torrent
2014-03-04 14:02 - 2014-03-04 14:02 - 00019388 _____ () C:\Users\Administrator\Downloads\[rutor.org]Top_Gear_21х01-04.720p.torrent
2014-03-04 14:02 - 2014-03-04 14:02 - 00000000 ____D () C:\Users\Administrator\Desktop\Discovery_Aliens mummies (2012) SATRip
2014-03-04 14:01 - 2014-03-04 14:01 - 00012821 _____ () C:\Users\Administrator\Downloads\[rutor.org]Discovery_Aliens_mummies_(2012)_SATRip.torrent
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2014-03-04 13:55 - 2014-03-04 13:55 - 00014538 _____ () C:\Users\Administrator\Downloads\[filmitorrent.org]The.Hungover.Games.Unrated_Edition.2014.D.WEB-D_0.torrent
2014-03-04 11:40 - 2012-06-27 13:08 - 00002139 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-04 03:40 - 2012-04-15 21:26 - 00000000 ____D () C:\ProgramData\Origin
2014-03-04 03:10 - 2012-04-02 22:38 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-03-04 03:10 - 2012-04-02 19:19 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-03-04 03:08 - 2012-04-02 19:19 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-03-04 02:44 - 2012-04-15 21:25 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-03-04 02:34 - 2014-01-11 00:00 - 00000000 ____D () C:\AdwCleaner
2014-03-04 01:57 - 2014-03-04 01:57 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LavasoftStatistics
2014-03-04 01:54 - 2014-03-04 01:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Lavasoft
2014-03-04 01:53 - 2014-03-04 01:53 - 00000000 ____D () C:\Program Files\Lavasoft
2014-03-04 01:52 - 2014-03-04 01:52 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-03-04 01:51 - 2014-03-04 01:51 - 01727624 _____ () C:\Users\Administrator\Downloads\Adaware_Installer.exe
2014-03-04 01:51 - 2014-03-04 01:51 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-03-03 21:58 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\DVDVideoSoft
2014-03-03 21:58 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Assassin's Creed Revelations
2014-03-03 21:57 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 3
2014-03-03 20:31 - 2012-03-07 00:47 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-03 20:26 - 2014-03-03 20:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-03 20:25 - 2014-02-22 23:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PhotoScape
2014-03-03 20:25 - 2013-09-15 14:00 - 00000000 ____D () C:\Program Files (x86)\RusTV Player
2014-03-03 20:25 - 2012-07-04 13:30 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-03 20:25 - 2012-07-04 13:30 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-03 20:25 - 2012-07-04 13:29 - 00000000 ____D () C:\Users\Gast
2014-03-03 20:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-03-03 20:24 - 2013-11-24 17:35 - 00000000 ____D () C:\Users\Administrator\Desktop\YGO PRO V5
2014-03-03 20:24 - 2013-11-08 20:15 - 00000000 ____D () C:\Users\Administrator\AppData\Local\PunkBuster
2014-03-03 20:24 - 2012-04-03 04:54 - 00000000 ____D () C:\ProgramData\Real
2014-03-03 20:24 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-03-03 04:39 - 2013-11-08 20:08 - 00000000 ____D () C:\Users\Administrator\Desktop\Häslon seine sachen
2014-03-03 00:18 - 2014-03-03 00:18 - 00714207 _____ () C:\Users\Administrator\Downloads\pbsetup.zip
2014-03-02 19:27 - 2014-03-01 20:12 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Windows Live
2014-03-02 17:39 - 2013-02-23 17:34 - 00000894 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003Core.job
2014-03-02 05:39 - 2014-03-02 05:39 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Auslogics
2014-03-02 05:26 - 2013-06-28 21:37 - 00000000 ____D () C:\Program Files\WinRAR
2014-03-02 05:25 - 2014-03-01 19:45 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
2014-03-02 05:25 - 2014-01-29 08:54 - 00000000 ____D () C:\Users\PC\Downloads\Neuer Ordner
2014-03-02 05:25 - 2013-10-03 18:31 - 00000000 ____D () C:\Program Files (x86)\Ss.Helper
2014-03-02 02:44 - 2014-03-02 02:43 - 01244192 _____ () C:\Users\Administrator\Downloads\adwcleaner_3.0.2.0.exe
2014-03-02 02:41 - 2014-03-02 02:41 - 00000000 ____D () C:\Program Files (x86)\SmartTweak Software
2014-03-02 02:11 - 2014-03-02 02:11 - 00002788 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-02 02:11 - 2012-04-03 05:00 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-01 23:41 - 2013-10-26 19:42 - 00000000 ___DC () C:\Users\Administrator\Desktop\Neuer Ordner
2014-03-01 21:21 - 2014-03-01 20:21 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PhotoScape
2014-03-01 20:39 - 2013-08-29 23:53 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DVDVideoSoft
2014-03-01 20:27 - 2013-11-10 18:01 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-01 20:27 - 2013-11-02 14:14 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\DVDVideoSoft
2014-03-01 20:18 - 2014-03-01 20:18 - 00000000 ____D () C:\Windows\de
2014-03-01 20:17 - 2014-03-01 20:17 - 00000000 ____D () C:\Windows\en
2014-03-01 20:16 - 2014-03-01 20:16 - 00000000 ____D () C:\Windows\ru
2014-03-01 20:15 - 2012-04-02 16:35 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-03-01 20:01 - 2014-03-01 20:01 - 00016384 ___SH () C:\Users\PC\Thumbs.db
2014-03-01 13:21 - 2014-03-01 13:21 - 00021008 _____ () C:\Users\PC\Desktop\Mein Film bbbb.wlmp
2014-03-01 07:19 - 2014-03-01 07:12 - 377248555 _____ () C:\Users\PC\Desktop\Mein Film 1.mp4
2014-03-01 06:49 - 2012-04-02 14:43 - 00000000 ____D () C:\Users\PC\AppData\Roaming\uTorrent
2014-03-01 06:47 - 2014-03-01 06:47 - 00070520 _____ () C:\Users\PC\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-01 06:47 - 2014-02-25 13:48 - 00003188 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-03-01 06:47 - 2014-02-01 15:22 - 00003328 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-28 07:10 - 2014-02-28 07:10 - 00015349 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Red.2.2013_HDRip__[scarabey.org].torrent
2014-02-27 14:12 - 2014-02-27 14:12 - 00015648 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Bilet.na.Vegas.2012.O.BDRip.745MB_[Youtracker]_.torrent
2014-02-27 14:11 - 2014-02-27 14:11 - 00015441 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Dubler.2013.O.BDRip.745MB_by_Yarmak23.avi.torrent
2014-02-27 14:07 - 2014-02-27 14:07 - 00014550 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Elki.3.2013.O.DVDRip.700MB.avi.torrent
2014-02-27 12:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-27 11:13 - 2014-02-27 11:13 - 00000088 _____ () C:\Users\PC\Desktop\Два ствола скачать торрент в хорошем качестве бесплатно dvdrip, hdrip.url
2014-02-27 10:52 - 2014-02-27 10:52 - 00000000 ____D () C:\Users\PC\Desktop\08951603108
2014-02-26 23:22 - 2014-02-13 22:04 - 00009678 _____ () C:\Windows\SysWOW64\ScriptHook.log
2014-02-26 21:09 - 2013-10-03 23:18 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\WinArchiver
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Program Files (x86)\WinArchiver
2014-02-26 19:53 - 2013-10-26 19:41 - 00070520 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-26 19:50 - 2014-02-25 18:53 - 00306000 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-26 19:49 - 2014-02-26 19:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-26 19:48 - 2014-02-26 19:48 - 00000000 ____D () C:\Program Files\Java
2014-02-26 19:44 - 2014-02-26 19:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PowerISO
2014-02-26 00:02 - 2014-02-26 00:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes
2014-02-25 14:27 - 2014-02-17 14:53 - 00000000 ____D () C:\Users\PC\Downloads\Top Gear S21 E01-02
2014-02-25 01:38 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-02-24 23:54 - 2012-04-03 15:38 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-02-24 23:54 - 2012-04-03 15:38 - 00000000 ____D () C:\ProgramData\Skype
2014-02-24 23:54 - 2012-04-02 15:12 - 00010061 _____ () C:\Windows\system32\lvcoinst.log
2014-02-24 17:17 - 2012-11-25 00:19 - 00000000 ____D () C:\Program Files (x86)\rhv
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Malwarebytes
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-24 16:49 - 2012-04-03 13:33 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-24 16:19 - 2014-02-11 16:33 - 00003350 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-24 16:19 - 2013-12-12 18:48 - 00003210 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-23 23:16 - 2014-02-23 22:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Electronic_Arts_Inc
2014-02-23 23:06 - 2014-02-23 23:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Need for Speed World
2014-02-23 02:16 - 2013-12-31 21:25 - 00000000 ____D () C:\Program Files\Realmware
2014-02-23 01:58 - 2014-02-23 01:58 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Realmware
2014-02-23 00:10 - 2014-02-22 23:04 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-02-22 23:12 - 2014-02-22 23:05 - 00008192 ____H () C:\Users\Administrator\Desktop\photothumb.db
2014-02-22 03:34 - 2012-05-03 07:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-22 01:08 - 2012-05-26 18:55 - 00000000 ____D () C:\Users\PC\AppData\Local\Electronic_Arts_Inc
2014-02-22 01:00 - 2014-02-22 01:00 - 00000000 ____D () C:\Users\PC\Desktop\login
2014-02-21 21:49 - 2012-04-04 16:15 - 00042496 _____ () C:\Users\PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-21 17:45 - 2014-02-21 17:45 - 00000000 ____D () C:\Users\PC\Desktop\httpwww.youtube.comwatchv=OGnIS_a54ak
2014-02-21 17:39 - 2014-01-15 18:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-21 15:59 - 2014-02-21 15:51 - 402748888 _____ () C:\Users\PC\Downloads\Горцы от ума - 4 . Полный фильм - Derbent.tv - Видео Дагестана, новости, приколы, клипы, концерты,свадьбы.flv
2014-02-21 07:53 - 2014-02-21 07:39 - 613726208 ____R () C:\Users\PC\Downloads\ТРИ РУБЛЯ (Дом Кино).mpg
2014-02-21 07:53 - 2014-02-21 07:36 - 616548352 ____R () C:\Users\PC\Downloads\Субботний вечер (Дом Кино).mpg
2014-02-21 07:27 - 2012-04-02 15:23 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-21 07:27 - 2012-04-02 15:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-21 07:27 - 2012-04-02 15:23 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-20 00:08 - 2014-02-20 00:08 - 00000000 ____D () C:\Users\Administrator\AppData\Local\EMU
2014-02-20 00:00 - 2014-02-20 00:00 - 00000000 ____D () C:\Program Files (x86)\5
2014-02-19 20:45 - 2014-02-19 20:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Theta
2014-02-19 20:28 - 2014-02-19 20:28 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Ubisoft Game Launcher
2014-02-19 20:28 - 2014-02-19 20:28 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-02-19 20:10 - 2014-02-19 20:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\BANDISOFT
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-02-19 12:10 - 2014-02-19 12:10 - 00000836 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-02-19 12:07 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-02-18 03:23 - 2014-02-18 03:23 - 00000000 ____D () C:\Users\Administrator\Documents\Rockstar Games
2014-02-18 03:21 - 2014-02-18 03:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Rockstar Games
2014-02-18 03:01 - 2014-02-18 03:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\SKIDROW
2014-02-18 03:01 - 2014-02-18 03:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Arma 3 Alpha
2014-02-18 02:23 - 2014-02-17 18:28 - 00000000 ____D () C:\Users\Administrator\Documents\My Games
2014-02-18 02:18 - 2013-07-28 12:00 - 00000000 ____D () C:\Users\PC\Documents\My Games
2014-02-16 05:04 - 2013-11-24 15:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-16 05:00 - 2012-04-02 15:15 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-13 22:25 - 2014-02-13 22:25 - 00000000 ____D () C:\Users\PC\Documents\Rockstar Games
2014-02-13 22:14 - 2014-02-13 22:14 - 00003178 _____ () C:\Windows\System32\Tasks\{57E8181A-0929-418A-A72C-CE10D919BEE8}
2014-02-13 22:12 - 2014-02-13 22:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-02-13 22:03 - 2014-02-13 22:03 - 00336384 _____ () C:\Windows\SysWOW64\ScriptHook.dll
2014-02-13 18:31 - 2012-04-02 15:23 - 00004098 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-13 18:31 - 2012-04-02 15:23 - 00003846 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-13 03:16 - 2014-02-13 03:16 - 00000000 ____D () C:\Neuer Ordner
2014-02-12 22:16 - 2014-02-12 22:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-12 21:23 - 2014-02-12 21:23 - 00000000 ____D () C:\Program Files\PowerISO
2014-02-12 20:36 - 2014-02-12 20:36 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PowerISO
2014-02-12 20:30 - 2014-02-12 20:30 - 00000000 ____D () C:\Users\PC\AppData\Local\Disc_Soft_Ltd
2014-02-12 20:28 - 2014-02-12 20:28 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DAEMON Tools Ultra
2014-02-11 02:25 - 2014-02-11 02:25 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-02-11 02:07 - 2014-01-03 01:25 - 00000000 ____D () C:\Users\PC\AppData\Local\SKIDROW
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\New Technology Studio
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenIV
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Local\New Technology Studio
2014-02-11 00:54 - 2014-02-11 00:41 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\www.gtavicecity.ru
2014-02-10 22:05 - 2014-02-10 22:05 - 00000000 ____D () C:\Users\PC\AppData\Local\EMU
2014-02-10 21:57 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-10 21:12 - 2014-02-10 21:12 - 01199079 _____ () C:\Windows\unins000.exe
2014-02-10 21:12 - 2014-01-25 21:41 - 00080705 _____ () C:\Windows\unins000.dat
2014-02-10 21:11 - 2014-02-10 21:11 - 00000000 ____D () C:\Users\PC\AppData\Local\Chromium
2014-02-10 19:50 - 2014-01-03 01:25 - 00000000 ____D () C:\Users\PC\Documents\Arma 3 Alpha
2014-02-10 13:26 - 2014-02-10 13:26 - 00000000 __RHD () C:\Users\PC\AppData\Roaming\SecuROM
2014-02-09 23:29 - 2014-02-07 06:28 - 00000825 _____ () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-02-08 17:27 - 2014-02-08 16:15 - 00000000 ____D () C:\Users\PC\AppData\Local\Mato_Technologies
2014-02-08 15:53 - 2014-02-07 06:41 - 00001782 _____ () C:\Users\PC\Desktop\PeerBlock.lnk
2014-02-06 14:24 - 2012-04-03 15:39 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Skype
2014-02-06 13:16 - 2014-02-14 03:44 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-14 03:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-14 03:44 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-14 03:44 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-14 03:44 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-14 03:44 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-14 03:44 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-14 03:44 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 11:52 - 2014-02-14 03:44 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 11:49 - 2014-02-14 03:44 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-14 03:44 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 11:48 - 2014-02-14 03:44 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 11:38 - 2014-02-14 03:44 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-14 03:44 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-14 03:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-14 03:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 11:11 - 2014-02-14 03:44 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-14 03:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-14 03:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-14 03:44 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-14 03:44 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-14 03:44 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-14 03:44 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-14 03:44 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:49 - 2014-02-14 03:44 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-06 10:47 - 2014-02-14 03:44 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-14 03:44 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-14 03:44 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 10:25 - 2014-02-14 03:44 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 10:24 - 2014-02-14 03:44 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 10:22 - 2014-02-14 03:44 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-14 03:44 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-14 03:44 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-14 03:44 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-14 03:44 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-14 03:44 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-14 03:44 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-14 03:44 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-14 03:44 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-03 22:01 - 2014-01-31 22:15 - 00000000 ____D () C:\Users\PC\Documents\GTA San Andreas User Files
2014-02-03 21:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-02-03 19:09 - 2013-10-26 19:41 - 00001421 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

Files to move or delete:
====================
C:\Users\Gast\AppData\Roaming\CamLayout.ini
C:\Users\Gast\AppData\Roaming\CamShapes.ini
C:\Users\PC\AppData\Roaming\CamLayout.ini
C:\Users\PC\AppData\Roaming\CamShapes.ini
C:\ProgramData\qjaxlkio.dss


Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\Administrator\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpotc8qp.dll
C:\Users\Gast\AppData\Local\Temp\AskSLib.dll
C:\Users\Gast\AppData\Local\Temp\avgnt.exe
C:\Users\Gast\AppData\Local\Temp\install_flashplayer11x32axau_mssa_aaa_aih.exe
C:\Users\Gast\AppData\Local\Temp\kpinstaller.exe
C:\Users\Gast\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\PC\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-28 06:47

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---

Alt 04.03.2014, 20:56   #14
mort
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

PC meldet sich nach Anmeldung automatisch wieder ab 2014 [gelöst]



edit

Geändert von mort (04.03.2014 um 21:02 Uhr)

Alt 04.03.2014, 21:09   #15
Drancer
 
PC meldet sich nach Anmeldung automatisch wieder ab  2014 - Standard

PC meldet sich nach Anmeldung automatisch wieder ab 2014 [gelöst]



wie meinen ?

Antwort

Themen zu PC meldet sich nach Anmeldung automatisch wieder ab 2014
administrator, adobe, adobe flash player, antivir, avg, avira, computer, detected, download, explorer, fixlog, flash player, home, installation, microsoft, mozilla, nvidia, opera, problem, realtek, registry, safer networking, services.exe, software, svchost.exe, temp, winlogon.exe



Ähnliche Themen: PC meldet sich nach Anmeldung automatisch wieder ab 2014


  1. AVG 2014 lässt sich nach (2) Virenfunden nicht mehr starten
    Log-Analyse und Auswertung - 23.06.2014 (11)
  2. weißer Bildschirm nach Anmeldung, im abges. Modus sofortiger Neustart nach Anmeldung
    Plagegeister aller Art und deren Bekämpfung - 22.11.2013 (12)
  3. PC meldet sich nach Anmeldung automatisch wieder ab
    Log-Analyse und Auswertung - 21.06.2013 (7)
  4. MSN Virus - Bot meldet sich automatisch an - Spamlinks
    Log-Analyse und Auswertung - 15.03.2012 (11)
  5. Norton schaltet sich automatisch ab und lässt sich nicht wieder neu starten!
    Log-Analyse und Auswertung - 06.03.2012 (1)
  6. XP meldet sich sofort nach Anmeldung wieder ab!
    Plagegeister aller Art und deren Bekämpfung - 04.12.2011 (0)
  7. werde bei win 7 nach anmeldung direkt wieder abgemeldet
    Alles rund um Windows - 07.11.2011 (1)
  8. Laptop fährst sofort nach Anmeldung wieder runter
    Plagegeister aller Art und deren Bekämpfung - 27.10.2011 (71)
  9. PC meldet sich nach hochfahren gleich wieder ab!
    Plagegeister aller Art und deren Bekämpfung - 14.04.2011 (5)
  10. Pc fährt nach Anmeldung wieder herunter (drwtsn32.exe , dwwin.exe Fehler in der Anwendung)
    Plagegeister aller Art und deren Bekämpfung - 22.02.2011 (9)
  11. Win XP meldet sich nach Anmeldung sofort wieder ab- endlosschleife... Wie Daten sichern?
    Alles rund um Windows - 26.01.2011 (8)
  12. google leitet automatisch um/Antivir meldet immer wieder Funde
    Antiviren-, Firewall- und andere Schutzprogramme - 10.11.2010 (35)
  13. Windows meldet sich nach anmeldung selbstständig ab
    Log-Analyse und Auswertung - 12.10.2010 (5)
  14. MSN meldet sich seit einiger zeit automatisch ab
    Alles rund um Windows - 07.09.2010 (5)
  15. Windows XP Meldet sich nach Anmeldung automatisch ab
    Plagegeister aller Art und deren Bekämpfung - 23.03.2009 (12)
  16. Windows XP Meldet sich nach Anmeldung automatisch ab
    Plagegeister aller Art und deren Bekämpfung - 13.03.2009 (0)
  17. Pc meldet sich automatisch ab
    Log-Analyse und Auswertung - 16.12.2008 (1)

Zum Thema PC meldet sich nach Anmeldung automatisch wieder ab 2014 - Hallo Community ! Ich hab genau das gleiche problem wie dieser User es hier beschreibt : http://www.trojaner-board.de/136922-...atisch-ab.html Wie Schrauber gesagt hat hab ich in abgesichertes modus mal FRST laufen lassen. - PC meldet sich nach Anmeldung automatisch wieder ab 2014...
Archiv
Du betrachtest: PC meldet sich nach Anmeldung automatisch wieder ab 2014 auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.