Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Pc gibt komischen Ton über die Boxen aus

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 22.11.2013, 03:57   #1
Reclaimbux
 
Pc gibt komischen Ton über die Boxen aus - Icon23

Pc gibt komischen Ton über die Boxen aus



Hallo,
Ich habe seit ein paar Tagen das Problem, dass mein Rechner scheinbar willkürlich Sound aus den Boxen wiedergibt.
Eine Art Wobblesound

Dieser Tritt in gewissen Zeitabständen immer wieder auf.
Mal habe ich 3h ruhe und mal kommt er alle 5minuten.

Mein Windows7 (64bit) habe ich erst kürzlich neu aufgesetzt (recovery Partition)
an dem rechner sind insgesamt 2Soundkarten und ein g900 headset (usb wireless mit eigener Soundkarte)

Das Geräusch tritt immer nur beim Standartwiedergabegerät auf

Was ich bisher unternommen habe:
Da ich der Annahme ging, dass dies ein Ton sei, der Abgespielt wird,weil irgendein Programm geupdatet wurde, habe ich verschiedene Programme zeitweilig ausgeschaltet/ deinstalliert.

Wenn meine Beschreibung zu wenig Details hergibt, sagt bescheid
Damit ihr mir Vernünftig helfen könnt



Da dies leider kein erfolg hatte,wende ich mich nun an euch, mir zu helfen dieses Problem zu beseitigen.

Alt 22.11.2013, 07:34   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 22.11.2013, 11:55   #3
Reclaimbux
 
Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Danke für die schnelle antwort
Addition habe ich im anhang gepackt


Die FRST(war zu gross)
Daher mal pastebin
hxxp://pastebin.com/FYbxhMb4
__________________

Alt 22.11.2013, 15:00   #4
Reclaimbux
 
Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Habe gemerkt dass ich mist gepostet habe sorry

Jetzt nochmal richtig ;D
hxxp://pastebin.com/FYbxhMb4
Angehängte Dateien
Dateityp: txt Addition.txt (21,2 KB, 169x aufgerufen)

Alt 22.11.2013, 20:23   #5
Reclaimbux
 
Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Habe auf meinem rechner antimalewarebytes drauf
Und das hat gemeldet, dass irgendetwas versucht hat nach
162.210.192.9 zu kommunizieren
Die ip kommt aus der usa (manassas}
Habe meinen rechner erstmal vom internet getrennt

Würde es evtl was bringen den rechner via recovery partition zurück zu setzen ?


Geändert von Reclaimbux (22.11.2013 um 20:38 Uhr)

Alt 23.11.2013, 07:13   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Das bringt auf jeden Fall was, ist aber unnötig denke ich und deine Daten sind weg.

FRST.txt fehlt, und:



Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.


So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________
--> Pc gibt komischen Ton über die Boxen aus

Alt 23.11.2013, 09:17   #7
Reclaimbux
 
Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Gut dann ist mein Hauptziel

1.was habe ich mir da eingefangen?
2.wie kann ich die wahrscheinlichkeit verringern' dass dies nochmal passiert
(Mit ausßnahme vom ziehen des Netzwerk Kabels :-)

Code:
ATTFilter

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-11-2013
Ran by Booxi (administrator) on BIOHAZARD on 22-11-2013 12:18:33
Running from C:\Users\Booxi\Dropbox\andro
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(Intel Corporation) C:\windows\system32\IProsetMonitor.exe
() C:\Windows\jmesoft\Service.exe
(Lenovo) C:\Program Files\Lenovo\Power Dial\LenovoCOMSvc.exe
(Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Dropbox, Inc.) C:\Users\Booxi\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
(Lenovo) C:\Program Files\Lenovo\Power Dial\LitModeCtrl.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPop3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
() c:\programdata\quickset\sk.enhancer\SK.Enhancer.exe
(Valve Corporation) D:\Games\Steam\Steam.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMovieViewer.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPictureViewer.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDWebCam.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDYT.exe
(TeamSpeak Systems GmbH) C:\Users\Booxi\AppData\Local\TeamSpeak 3 Client\ts3client_win32.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePRCShortCut] - C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [222504 2009-05-14] (CyberLink Corp.)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware  (cleanup)] - rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1127496 2013-04-04] (Malwarebytes Corporation)
HKLM-x32\...\Run: [ZoneAlarm] - C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [73832 2013-10-25] (Check Point Software Technologies LTD)
HKLM-x32\...\Run: [ModeSwitch] - C:\Program Files\Lenovo\Power Dial\LitModeSwitch.exe [163840 2010-09-26] (Lenovo)
HKLM-x32\...\Run: [RUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation)
AppInit_DLLs-x32: c:\progra~2\skc4df~1.enh\psupport.dll [857600 2013-10-06] ()
Startup: C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Booxi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LEND&bmod=LEND
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.searchbomb.info/?l=1&q={searchTerms}&pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42
SearchScopes: HKCU - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.searchbomb.info/?l=1&q={searchTerms}&pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42
SearchScopes: HKCU - {0FBE57CA-2243-4537-842F-F5092BDE3003} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=20b0ed1900000000000000ffbcc382bd&r=366
SearchScopes: HKCU - {191BAC1D-A829-452A-8A33-9A0257613CE3} URL = hxxp://search.zonealarm.com/search?src=sp&tbid=goughGA&Lan=de&q={searchTerms}&gu=452c1b91a22a47f09f071950a28172a3&tu=10G9y00B41C01g0&sku=&tstsId=&ver=&&r=900
SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.searchbomb.info/?l=1&q={searchTerms}&pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42
BHO: YoutubeAdblocker - {080760C8-FE0A-098C-7183-3254957E24C5} - C:\Program Files (x86)\YoutubeAdblocker\e01v5Gfx.x64.dll ()
BHO: SearchNewTab - {41E98610-8710-C589-9CF8-7C241B467713} - C:\Program Files (x86)\SearchNewTab\GTEvONtDLJ.x64.dll ()
BHO: surf Annd keep - {4727D7CC-F9B0-8EA1-53F0-C8CDA77ABBD5} - C:\Program Files (x86)\surf Annd keep\f3gNkxOJUU.x64.dll ()
BHO-x32: YoutubeAdblocker - {080760C8-FE0A-098C-7183-3254957E24C5} - C:\Program Files (x86)\YoutubeAdblocker\e01v5Gfx.dll ()
BHO-x32: SearchNewTab - {41E98610-8710-C589-9CF8-7C241B467713} - C:\Program Files (x86)\SearchNewTab\GTEvONtDLJ.dll ()
BHO-x32: surf Annd keep - {4727D7CC-F9B0-8EA1-53F0-C8CDA77ABBD5} - C:\Program Files (x86)\surf Annd keep\f3gNkxOJUU.dll ()
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Tcpip\..\Interfaces\{E8059CE8-DE59-4EAC-A0F2-261E180BD0C2}: [NameServer]8.8.8.8,8.8.4.4

FireFox:
========
FF ProfilePath: C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default
FF user.js: detected! => C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\user.js
FF DefaultSearchEngine: WebSearch
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.user_pref("browser.search.order.1,S", "WebSearch");: user_pref("browser.search.order.1,S", "WebSearch");
FF SelectedSearchEngine: WebSearch
FF Homepage: hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42
FF Keyword.URL: hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42&l=1&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\searchplugins\softonic.xml
FF SearchPlugin: C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\searchplugins\WebSearch.xml
FF SearchPlugin: C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\searchplugins\zonealarm.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YoutubeAdblocker - C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\Extensions\e00j-twsm@g-ocjhyor-.org
FF Extension: adblockpopups - C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\Extensions\adblockpopups@jessehakanen.net.xpi
FF Extension: Adblock Plus - C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: dta - C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (souRf aand keep) - C:\Users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\acojnmmppiffdkeejoppapoaioplnkcg\2.19
CHR Extension: (Softonic Chrome Toolbar) - C:\Users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0
CHR Extension: (YoutubeAdblocker) - C:\Users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabkcimgibkpnkfmpgnjoepdmclioeep\1.0
CHR Extension: (SearchNewTab) - C:\Users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pifelbofldigncaipacpjhifgfloepec\1.0

==================== Services (Whitelisted) =================

R2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-03-16] ()
R2 LenovoCOMSvc; C:\Program Files\Lenovo\Power Dial\LenovoCOMSvc.exe [49152 2009-09-30] (Lenovo)
R3 LitModeCtrl; C:\Program Files\Lenovo\Power Dial\LitModeCtrl.exe [81920 2010-09-09] (Lenovo)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2445816 2013-10-25] (Check Point Software Technologies LTD)
R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [50704 2013-10-15] (Check Point Software Technologies, Ltd.)
S2 Stereo Service; "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe" [x]

==================== Drivers (Whitelisted) ====================

R3 automap; C:\Windows\System32\DRIVERS\automap.sys [18776 2012-04-19] (Focusrite Audio Engineering Limited)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 NvnUsbAudio; C:\Windows\System32\DRIVERS\nvnusbaudio.sys [53552 2013-04-30] (Novation DMS Ltd.)
S3 pwdrvio; C:\windows\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\windows\system32\pwdspio.sys [12504 2013-09-30] ()
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [454168 2013-10-23] (Check Point Software Technologies LTD)
R0 WinI2C-DDC; C:\Windows\System32\drivers\DDCDrv.sys [20832 2008-04-08] (Nicomsoft Ltd.)
R0 WinI2C-DDC; C:\Windows\SysWow64\drivers\DDCDrv.sys [15712 2010-03-23] (Nicomsoft Ltd.)
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [x]
S4 NVHDA; system32\drivers\nvhda64v.sys [x]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-22 12:17 - 2013-11-22 12:17 - 00000000 ____D C:\FRST
2013-11-22 04:12 - 2013-11-22 04:12 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Malwarebytes
2013-11-22 04:11 - 2013-11-22 04:11 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-11-22 04:11 - 2013-11-22 04:11 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-22 04:11 - 2013-11-22 04:11 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-22 04:11 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-11-22 01:18 - 2013-11-22 03:37 - 00000000 ____D C:\ProgramData\QuickSet
2013-11-22 01:18 - 2013-11-22 01:18 - 00002694 _____ C:\windows\System32\Tasks\SK.Enhancer-S-161304646
2013-11-22 01:18 - 2013-11-22 01:18 - 00000448 ____H C:\windows\Tasks\SK.Enhancer-S-161304646.job
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Users\Booxi\AppData\Local\Packages
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\ProgramData\YoutubeAdblocker
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\ProgramData\surf Annd keep
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\ProgramData\SearchNewTab
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\ProgramData\42fe8eb7ee241cea
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Program Files (x86)\YoutubeAdblocker
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Program Files (x86)\WebSearch
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Program Files (x86)\surf Annd keep
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Program Files (x86)\Sk.Enhancer
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Program Files (x86)\SearchNewTab
2013-11-22 01:17 - 2013-11-22 03:37 - 00000000 ____D C:\ProgramData\InstallMate
2013-11-21 05:13 - 2013-11-21 05:13 - 01019818 _____ C:\Users\Booxi\Downloads\MMD3.wal
2013-11-21 05:11 - 2013-11-21 05:11 - 00188479 _____ C:\Users\Booxi\Downloads\KalaK_Amp.wsz
2013-11-21 05:08 - 2013-11-21 05:08 - 01305284 _____ C:\Users\Booxi\Downloads\S7Reflex.wal
2013-11-21 05:00 - 2013-11-21 05:00 - 00000109 _____ C:\Users\Booxi\Documents\winamp2.wsp
2013-11-21 04:52 - 2013-11-21 04:54 - 00041095 _____ C:\Users\Booxi\Documents\winamp.wsp
2013-11-21 04:50 - 2013-11-21 04:50 - 00770176 _____ C:\Users\Booxi\Downloads\WebSpider27Setup.exe
2013-11-21 04:50 - 2013-11-21 04:50 - 00000000 ____D C:\Program Files (x86)\Xaldon
2013-11-21 02:34 - 2013-11-21 02:41 - 00000000 ____D C:\Users\Booxi\Documents\Website Ripper Copier
2013-11-21 02:34 - 2013-11-21 02:34 - 00001289 _____ C:\Users\Public\Desktop\Website Ripper Copier.lnk
2013-11-21 02:34 - 2013-11-21 02:34 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Website Ripper Copier
2013-11-21 02:34 - 2013-11-21 02:34 - 00000000 ____D C:\Program Files (x86)\Tensons
2013-11-21 02:33 - 2013-11-21 02:33 - 00759075 _____ C:\Users\Booxi\Desktop\WRCsetup.exe
2013-11-21 02:33 - 2013-11-21 02:33 - 00401768 _____ (Softonic                                        ) C:\Users\Booxi\Downloads\SoftonicDownloader_fuer_website-ripper-copier.exe
2013-11-21 02:28 - 2013-11-21 02:31 - 12996104 _____ (Nullsoft, Inc.) C:\Users\Booxi\Downloads\winamp566_full_de-de.exe
2013-11-21 00:58 - 2013-11-21 00:58 - 00000000 ____D C:\Users\Booxi\Downloads\UGT_C_v1.9.0
2013-11-21 00:55 - 2013-11-21 00:56 - 05094007 _____ C:\Users\Booxi\Downloads\UGT_C_v1.9.0.rar
2013-11-21 00:18 - 2013-11-21 00:18 - 04250232 _____ (HTTrack                                                     ) C:\Users\Booxi\Downloads\httrack_x64-3.47.27.exe
2013-11-21 00:18 - 2013-11-21 00:18 - 00000836 _____ C:\Users\Booxi\Desktop\HTTrack Website Copier.lnk
2013-11-21 00:18 - 2013-11-21 00:18 - 00000000 ____D C:\Program Files\WinHTTrack
2013-11-20 23:43 - 2013-11-20 23:43 - 00014797 _____ C:\Users\Booxi\Desktop\eichhörnchen.htm
2013-11-20 22:43 - 2013-11-20 22:43 - 00000206 _____ C:\Users\Booxi\Desktop\Killing Floor.url
2013-11-20 20:46 - 2013-11-20 20:48 - 00000000 ____D C:\Program Files (x86)\Smart Port Forwarding
2013-11-20 20:46 - 2013-11-20 20:46 - 00153697 _____ C:\Users\Booxi\Downloads\spf.zip
2013-11-20 20:46 - 2013-11-20 20:46 - 00001071 _____ C:\Users\Public\Desktop\Smart Port Forwarding.lnk
2013-11-20 19:35 - 2013-11-20 19:35 - 05010367 _____ C:\Users\Booxi\Downloads\teamspeak3-server_win64-3.0.10.1.zip
2013-11-20 19:35 - 2013-11-20 19:35 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\2C0A
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0C0A
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0C04
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0816
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0804
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0424
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\041F
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\041E
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\041D
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\041B
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0419
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0416
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0415
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0414
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0413
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0412
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0411
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0410
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\040E
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\040D
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\040C
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\040B
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\040A
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0409
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0408
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0406
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0405
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0404
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0401
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\Program Files (x86)\Renesas Electronics
2013-11-20 16:17 - 2013-11-20 16:17 - 26849632 _____ (Lenovo Group                                                ) C:\Users\Booxi\Downloads\ID1IME03WW5.exe
2013-11-20 16:16 - 2013-11-20 16:16 - 07044136 _____ (Lenovo Group Limited                                        ) C:\Users\Booxi\Downloads\h1100136_32.exe
2013-11-20 16:15 - 2013-11-20 16:15 - 02456976 _____ (Lenovo Group                                                ) C:\Users\Booxi\Downloads\ID2CHP07WW5.exe
2013-11-20 16:13 - 2013-10-23 09:20 - 00922912 _____ (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
2013-11-20 16:00 - 2013-11-20 16:00 - 00296955 _____ C:\windows\system32\nvvsvc.rar
2013-11-20 15:48 - 2013-11-20 15:48 - 00002935 _____ C:\Users\Booxi\Desktop\HiJackThis.lnk
2013-11-20 15:48 - 2013-11-20 15:48 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2013-11-20 15:48 - 2013-11-20 15:48 - 00000000 ____D C:\Program Files (x86)\Trend Micro
2013-11-20 15:47 - 2013-11-20 15:47 - 01402880 _____ C:\Users\Booxi\Downloads\HiJackThis.msi
2013-11-20 13:16 - 2013-11-20 13:31 - 00000000 ____D C:\Users\Booxi\Downloads\Minecraft Portable v.1.11.24 by johsty
2013-11-20 13:15 - 2013-11-20 13:16 - 291481529 _____ C:\Users\Booxi\Downloads\Minecraft Portable v.1.11.24 by johsty.zip
2013-11-19 22:50 - 2013-11-19 22:55 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Audacity
2013-11-19 22:50 - 2013-11-19 22:50 - 00001011 _____ C:\Users\Public\Desktop\Audacity.lnk
2013-11-19 22:50 - 2013-11-19 22:50 - 00000000 ____D C:\Program Files (x86)\Audacity
2013-11-19 22:48 - 2013-11-19 22:49 - 22180353 _____ (Audacity Team                                               ) C:\Users\Booxi\Downloads\audacity-win-2.0.5.exe
2013-11-19 22:40 - 2013-11-19 22:40 - 00618912 _____ C:\Users\Booxi\Downloads\Audacity - CHIP-Downloader.exe
2013-11-19 22:34 - 2013-11-19 22:34 - 00000000 ____D C:\Users\Booxi\Downloads\downloads(1)
2013-11-19 22:19 - 2013-11-19 22:22 - 2851739008 _____ C:\Users\Booxi\Downloads\downloads(1).zip
2013-11-19 20:43 - 2013-11-19 20:43 - 00002625 _____ C:\Users\Public\Desktop\LibreOffice 4.1.lnk
2013-11-19 20:43 - 2013-11-19 20:43 - 00000000 ____D C:\Program Files (x86)\LibreOffice 4
2013-11-19 20:42 - 2013-11-19 20:43 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Nico Mak Computing
2013-11-19 20:42 - 2013-11-19 20:42 - 00001202 _____ C:\Users\Booxi\Desktop\Format Factory.lnk
2013-11-19 20:42 - 2013-11-19 20:42 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2013-11-19 20:42 - 2013-11-19 20:42 - 00000000 ____D C:\Program Files (x86)\FreeTime
2013-11-19 20:42 - 2012-02-08 10:29 - 00018760 _____ (WinZip Computing, S.L.(WinZip Computing)) C:\windows\system32\roboot64.exe
2013-11-19 20:39 - 2013-11-20 23:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-11-18 18:58 - 2013-11-18 19:00 - 00000600 _____ C:\Users\Booxi\AppData\Roaming\winscp.rnd
2013-11-18 18:56 - 2013-11-18 18:56 - 00000983 _____ C:\Users\Public\Desktop\WinSCP.lnk
2013-11-18 18:56 - 2013-11-18 18:56 - 00000000 ____D C:\Program Files (x86)\WinSCP
2013-11-17 20:06 - 2013-11-17 20:06 - 00000808 _____ C:\Users\Booxi\Documents\DeadIslandGame_x86_rwdi.CT
2013-11-17 19:33 - 2013-11-17 19:33 - 00001089 _____ C:\Users\Booxi\Desktop\Cheat Engine.lnk
2013-11-17 19:33 - 2013-11-17 19:33 - 00000000 ____D C:\Users\Booxi\Documents\My Cheat Tables
2013-11-17 19:33 - 2013-11-17 19:33 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\OpenCandy
2013-11-17 19:33 - 2013-11-17 19:33 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.3
2013-11-17 19:26 - 2013-11-17 19:26 - 00000000 ____D C:\Users\Booxi\AppData\Local\Chromium
2013-11-17 19:16 - 2013-11-17 19:19 - 00417513 _____ C:\windows\system32\Drivers\vsconfig.xml
2013-11-17 19:16 - 2013-11-17 19:16 - 00000762 _____ C:\Users\Public\Desktop\ZoneAlarm Security.lnk
2013-11-17 19:09 - 2013-11-17 19:16 - 00000000 ____D C:\Program Files (x86)\CheckPoint
2013-11-17 19:08 - 2013-11-17 19:08 - 00000000 ____D C:\ProgramData\CheckPoint
2013-11-17 19:05 - 2013-11-17 19:05 - 00000000 ____D C:\ProgramData\Overwolf
2013-11-17 15:21 - 2013-11-17 15:21 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\WinRAR
2013-11-17 15:21 - 2013-11-17 15:21 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-11-17 15:21 - 2013-11-17 15:21 - 00000000 ____D C:\Program Files\WinRAR
2013-11-17 12:24 - 2013-11-17 12:25 - 00000000 ____D C:\Program Files\Virtual Audio Cable
2013-11-17 12:24 - 2013-11-17 12:24 - 00066728 _____ (Eugene V. Muzychenko) C:\windows\system32\Drivers\vrtaucbl.sys
2013-11-17 10:15 - 2013-11-22 00:54 - 00000000 ___RD C:\Users\Booxi\Dropbox
2013-11-17 10:15 - 2013-11-17 10:15 - 00001001 _____ C:\Users\Booxi\Desktop\Dropbox.lnk
2013-11-17 10:15 - 2013-11-17 10:15 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-11-16 16:22 - 2013-11-22 12:18 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Dropbox
2013-11-16 11:35 - 2013-11-17 07:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-15 17:42 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_7.dll
2013-11-15 17:42 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_7.dll
2013-11-15 17:42 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_7.dll
2013-11-15 17:42 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_7.dll
2013-11-15 17:42 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_5.dll
2013-11-15 17:42 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_5.dll
2013-11-15 17:42 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_43.dll
2013-11-15 17:42 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_43.dll
2013-11-15 17:42 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_43.dll
2013-11-15 17:42 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_43.dll
2013-11-15 17:42 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\windows\system32\d3dcsx_43.dll
2013-11-15 17:42 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dcsx_43.dll
2013-11-15 17:42 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_43.dll
2013-11-15 17:42 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_43.dll
2013-11-15 17:42 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_43.dll
2013-11-15 17:42 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx11_43.dll
2013-11-15 17:42 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_6.dll
2013-11-15 17:42 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_6.dll
2013-11-15 17:42 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_6.dll
2013-11-15 17:42 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_6.dll
2013-11-15 17:42 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_4.dll
2013-11-15 17:42 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_4.dll
2013-11-15 17:42 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_7.dll
2013-11-15 17:42 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_7.dll
2013-11-15 17:42 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_5.dll
2013-11-15 17:42 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_5.dll
2013-11-15 17:42 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_5.dll
2013-11-15 17:42 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_3.dll
2013-11-15 17:42 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\windows\system32\d3dcsx_42.dll
2013-11-15 17:42 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dcsx_42.dll
2013-11-15 17:42 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_42.dll
2013-11-15 17:42 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_42.dll
2013-11-15 17:42 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_42.dll
2013-11-15 17:42 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_42.dll
2013-11-15 17:42 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx11_42.dll
2013-11-15 17:42 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_4.dll
2013-11-15 17:42 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_4.dll
2013-11-15 17:42 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_4.dll
2013-11-15 17:42 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_4.dll
2013-11-15 17:42 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_6.dll
2013-11-15 17:42 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_6.dll
2013-11-15 17:42 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_41.dll
2013-11-15 17:42 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_41.dll
2013-11-15 17:42 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_41.dll
2013-11-15 17:42 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_41.dll
2013-11-15 17:42 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_3.dll
2013-11-15 17:42 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_3.dll
2013-11-15 17:42 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_3.dll
2013-11-15 17:42 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_3.dll
2013-11-15 17:42 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_2.dll
2013-11-15 17:42 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_2.dll
2013-11-15 17:42 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_5.dll
2013-11-15 17:42 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_5.dll
2013-11-15 17:42 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_40.dll
2013-11-15 17:42 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_40.dll
2013-11-15 17:42 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_40.dll
2013-11-15 17:42 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_40.dll
2013-11-15 17:42 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_40.dll
2013-11-15 17:42 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_40.dll
2013-11-15 17:42 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_2.dll
2013-11-15 17:42 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_2.dll
2013-11-15 17:42 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_1.dll
2013-11-15 17:42 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_1.dll
2013-11-15 17:42 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_2.dll
2013-11-15 17:42 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_2.dll
2013-11-15 17:42 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_39.dll
2013-11-15 17:42 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_39.dll
2013-11-15 17:42 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_39.dll
2013-11-15 17:42 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_39.dll
2013-11-15 17:42 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_39.dll
2013-11-15 17:42 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_39.dll
2013-11-15 17:42 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_1.dll
2013-11-15 17:42 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_1.dll
2013-11-15 17:42 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_1.dll
2013-11-15 17:42 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_1.dll
2013-11-15 17:42 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_0.dll
2013-11-15 17:42 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_0.dll
2013-11-15 17:42 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_4.dll
2013-11-15 17:42 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_4.dll
2013-11-15 17:42 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_38.dll
2013-11-15 17:42 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_38.dll
2013-11-15 17:42 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_38.dll
2013-11-15 17:42 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_38.dll
2013-11-15 17:42 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_38.dll
2013-11-15 17:42 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_38.dll
2013-11-15 17:42 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_0.dll
2013-11-15 17:42 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_0.dll
2013-11-15 17:42 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_0.dll
2013-11-15 17:42 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_0.dll
2013-11-15 17:42 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_3.dll
2013-11-15 17:42 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_3.dll
2013-11-15 17:42 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_37.dll
2013-11-15 17:42 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_37.dll
2013-11-15 17:42 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_37.dll
2013-11-15 17:42 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_37.dll
2013-11-15 17:42 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_37.dll
2013-11-15 17:42 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_37.dll
2013-11-15 17:42 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_10.dll
2013-11-15 17:42 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_10.dll
2013-11-15 17:42 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_2.dll
2013-11-15 17:42 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_2.dll
2013-11-15 17:42 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_36.dll
2013-11-15 17:42 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_36.dll
2013-11-15 17:42 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_36.dll
2013-11-15 17:42 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_36.dll
2013-11-15 17:42 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_36.dll
2013-11-15 17:42 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_36.dll
2013-11-15 17:42 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_9.dll
2013-11-15 17:42 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_9.dll
2013-11-15 17:42 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_35.dll
2013-11-15 17:42 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_35.dll
2013-11-15 17:42 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_35.dll
2013-11-15 17:42 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_35.dll
2013-11-15 17:42 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_35.dll
2013-11-15 17:42 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_35.dll
2013-11-15 17:42 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_8.dll
2013-11-15 17:42 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_8.dll
2013-11-15 17:42 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_34.dll
2013-11-15 17:42 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_34.dll
2013-11-15 17:42 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_34.dll
2013-11-15 17:42 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_34.dll
2013-11-15 17:42 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_34.dll
2013-11-15 17:42 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_34.dll
2013-11-15 17:42 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_7.dll
2013-11-15 17:42 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_7.dll
2013-11-15 17:42 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\windows\system32\xinput1_3.dll
2013-11-15 17:42 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_3.dll
2013-11-15 17:42 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_33.dll
2013-11-15 17:42 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_33.dll
2013-11-15 17:42 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_33.dll
2013-11-15 17:42 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_33.dll
2013-11-15 17:42 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_33.dll
2013-11-15 17:42 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_33.dll
2013-11-15 17:42 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\windows\system32\x3daudio1_1.dll
2013-11-15 17:42 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\windows\SysWOW64\x3daudio1_1.dll
2013-11-15 17:42 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_6.dll
2013-11-15 17:42 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_6.dll
2013-11-15 17:42 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_5.dll
2013-11-15 17:42 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_5.dll
2013-11-15 17:42 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\windows\system32\d3dx10.dll
2013-11-15 17:42 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10.dll
2013-11-15 17:42 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_31.dll
2013-11-15 17:42 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_4.dll
2013-11-15 17:42 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_4.dll
2013-11-15 17:42 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\windows\system32\xinput1_2.dll
2013-11-15 17:42 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_3.dll
2013-11-15 17:42 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_3.dll
2013-11-15 17:42 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_2.dll
2013-11-15 17:42 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_2.dll
2013-11-15 17:42 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_2.dll
2013-11-15 17:42 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_30.dll
2013-11-15 17:42 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_30.dll
2013-11-15 17:42 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_1.dll
2013-11-15 17:42 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_1.dll
2013-11-15 17:42 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\windows\system32\xinput1_1.dll
2013-11-15 17:42 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_1.dll
2013-11-15 17:42 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_29.dll
2013-11-15 17:42 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_29.dll
2013-11-15 17:42 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_0.dll
2013-11-15 17:42 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_0.dll
2013-11-15 17:42 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\windows\system32\x3daudio1_0.dll
2013-11-15 17:42 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\windows\SysWOW64\x3daudio1_0.dll
2013-11-15 17:42 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_28.dll
2013-11-15 17:42 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_28.dll
2013-11-15 17:42 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_27.dll
2013-11-15 17:42 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_27.dll
2013-11-15 17:42 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_26.dll
2013-11-15 17:42 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_26.dll
2013-11-15 17:42 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_25.dll
2013-11-15 17:42 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_25.dll
2013-11-15 17:42 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_24.dll
2013-11-15 17:42 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_24.dll
2013-11-15 17:05 - 2013-11-15 17:05 - 00000000 ____D C:\ProgramData\Steam
2013-11-15 16:54 - 2013-11-15 16:54 - 00000000 ____D C:\windows\Sun
2013-11-15 16:53 - 2013-11-15 16:53 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-11-15 16:53 - 2013-11-15 16:53 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-11-15 16:53 - 2013-11-15 16:53 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-11-15 16:53 - 2013-11-15 16:53 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-15 16:46 - 2013-09-30 16:26 - 03050808 _____ C:\windows\system32\pwNative.exe
2013-11-15 16:46 - 2013-09-30 16:26 - 00019152 ____N C:\windows\system32\pwdrvio.sys
2013-11-15 16:46 - 2013-09-30 16:26 - 00012504 ____N C:\windows\system32\pwdspio.sys
2013-11-15 16:45 - 2013-11-15 17:27 - 00000000 ____D C:\Program Files (x86)\MiniTool Partition Wizard Home Edition 8.1.1
2013-11-15 16:45 - 2013-11-15 16:45 - 00001253 _____ C:\Users\Public\Desktop\MiniTool Partition Wizard Home Edition.lnk
2013-11-15 13:32 - 2013-11-15 13:32 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\dvdcss
2013-11-15 13:30 - 2013-11-15 13:32 - 00006046 _____ C:\Filmdb.script
2013-11-15 13:30 - 2013-11-15 13:32 - 00000088 _____ C:\Filmdb.properties
2013-11-15 12:59 - 2013-11-15 12:59 - 00000000 ____D C:\Users\Booxi\AppData\Local\Novation
2013-11-15 12:59 - 2013-11-15 12:59 - 00000000 _____ C:\AutomapClients.ini
2013-11-15 12:58 - 2013-11-20 13:13 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\vlc
2013-11-15 12:55 - 2013-11-15 12:57 - 00000000 ____D C:\Program Files (x86)\Winamp
2013-11-15 12:55 - 2013-11-15 12:55 - 00000983 _____ C:\Users\Public\Desktop\Winamp.lnk
2013-11-15 12:55 - 2013-11-15 12:55 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Winamp
2013-11-15 12:55 - 2013-11-15 12:55 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
2013-11-15 12:55 - 2013-11-15 12:55 - 00000000 ____D C:\Program Files (x86)\Winamp Detect
2013-11-15 12:55 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_42.dll
2013-11-15 12:55 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_31.dll
2013-11-15 12:54 - 2013-11-15 12:54 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-11-15 12:54 - 2013-11-15 12:54 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-11-15 12:38 - 2013-11-15 12:38 - 00000207 _____ C:\Users\Booxi\Desktop\F.E.A.R. 3.url
2013-11-15 12:02 - 2013-11-15 12:02 - 00000000 ____D C:\Users\Booxi\AppData\Local\Focusrite_Audio_Engineeri
2013-11-15 12:01 - 2013-11-15 12:01 - 00000000 ____D C:\ProgramData\Propellerhead Software
2013-11-15 12:01 - 2013-11-15 12:01 - 00000000 ____D C:\ProgramData\Apple
2013-11-15 12:00 - 2013-11-15 12:00 - 00000000 ____D C:\Program Files (x86)\Novation
2013-11-15 12:00 - 2012-04-19 12:31 - 00018776 _____ (Focusrite Audio Engineering Limited) C:\windows\system32\Drivers\automap.sys
2013-11-15 11:58 - 2013-11-15 11:58 - 00000000 ____D C:\Program Files\Novation
2013-11-15 11:58 - 2013-04-30 10:52 - 00053552 _____ (Novation DMS Ltd.) C:\windows\system32\Drivers\nvnusbaudio.sys
2013-11-15 11:58 - 2013-04-30 10:52 - 00021808 _____ (Novation DMS Ltd.) C:\windows\system32\nvnusbaudio_coinst.dll
2013-11-15 11:57 - 2013-11-15 11:57 - 00000000 ____D C:\Users\Booxi\Neuer Ordner
2013-11-15 11:56 - 2013-11-15 11:56 - 00000000 ____D C:\Users\Booxi\Documents\Neuer Ordner
2013-11-15 11:45 - 2013-11-20 22:43 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-11-15 11:43 - 2013-11-15 11:44 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Ableton
2013-11-15 11:41 - 2013-11-15 11:41 - 00000503 _____ C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton Live 9 Lite.lnk
2013-11-15 11:16 - 2013-11-15 11:16 - 00001173 _____ C:\Users\Booxi\Desktop\TeamSpeak 3 Client.lnk
2013-11-15 11:16 - 2013-11-15 11:16 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2013-11-15 11:16 - 2013-11-15 11:16 - 00000000 ____D C:\Users\Booxi\AppData\Local\TeamSpeak 3 Client
2013-11-15 11:04 - 2013-11-15 11:04 - 00000020 _____ C:\windows\TóÁ
2013-11-15 11:01 - 2013-11-15 11:01 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Roxio Log Files
2013-11-15 05:40 - 2013-11-21 17:19 - 00003934 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{B965998B-177E-47D9-8A0E-5AAB77E6A5C0}
2013-11-15 05:05 - 2013-11-15 05:05 - 00000000 ____D C:\Users\Booxi\AppData\Local\Macromedia
2013-11-15 05:02 - 2013-11-15 05:02 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-11-15 05:02 - 2013-11-15 05:02 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-15 05:02 - 2013-11-15 05:02 - 00000000 ____D C:\windows\system32\Macromed
2013-11-15 05:01 - 2013-11-15 05:02 - 00000000 ____D C:\Users\Booxi\AppData\Local\Adobe
2013-11-15 04:59 - 2013-11-15 04:59 - 00000000 ____D C:\Users\Booxi\AppData\Local\wb games
2013-11-15 04:35 - 2013-11-15 05:00 - 00000000 _____ C:\windows\SysWOW64\Access.dat
2013-11-15 04:06 - 2013-11-17 19:03 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-11-15 03:53 - 2013-11-22 04:15 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Tunngle
2013-11-15 03:53 - 2013-11-22 04:15 - 00000000 ____D C:\ProgramData\Tunngle
2013-11-15 03:53 - 2013-11-15 03:53 - 00003380 _____ C:\windows\System32\Tasks\SidebarExecute
2013-11-15 03:53 - 2013-11-15 03:53 - 00000995 _____ C:\Users\Public\Desktop\Tunngle beta.lnk
2013-11-15 03:53 - 2013-11-15 03:53 - 00000000 ____D C:\Users\Public\Documents\Tunngle
2013-11-15 03:53 - 2013-11-15 03:53 - 00000000 ____D C:\Users\Booxi\Documents\Tunngle
2013-11-15 03:53 - 2013-11-15 03:53 - 00000000 ____D C:\Program Files (x86)\Tunngle
2013-11-15 03:53 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\windows\system32\Drivers\tap0901t.sys
2013-11-15 03:45 - 2013-11-15 03:45 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\NVIDIA
2013-11-15 03:37 - 2013-11-15 03:37 - 00000614 _____ C:\Users\Public\Desktop\Steam.lnk
2013-11-15 03:34 - 2013-11-15 03:35 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\CyberLink
2013-11-15 03:32 - 2013-11-20 13:39 - 00000000 ____D C:\Users\Booxi\AppData\Local\NVIDIA
2013-11-15 03:31 - 2013-11-15 03:31 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-11-15 03:28 - 2013-10-23 09:20 - 03426956 _____ C:\windows\system32\nvcoproc.bin
2013-11-15 03:27 - 2013-11-15 03:28 - 01588294 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2013-11-15 03:24 - 2013-11-15 03:24 - 00000000 ____D C:\NVIDIA
2013-11-15 03:24 - 2013-10-23 11:30 - 25257248 _____ (NVIDIA Corporation) C:\windows\system32\nvcompiler.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 22933792 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 18199872 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 17560352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcompiler.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 12572960 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2013-11-15 03:24 - 2013-10-23 11:30 - 11426568 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 11374520 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 09524088 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 09480328 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 03131680 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 03124512 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvenc.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 02946848 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 02747168 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvenc.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 01884448 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6433165.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 01511712 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6433165.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 01435504 _____ (NVIDIA Corporation) C:\windows\system32\nvumdshimx.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 01241376 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvumdshim.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 00696096 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 00655136 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 00599840 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 00560416 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 00317472 _____ (NVIDIA Corporation) C:\windows\system32\nvoglshim64.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 00266984 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglshim32.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 00168616 _____ (NVIDIA Corporation) C:\windows\system32\nvinitx.dll
2013-11-15 03:24 - 2013-10-23 11:30 - 00141336 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvinit.dll
2013-11-15 03:20 - 2013-11-22 04:19 - 00018960 _____ (Logitech, Inc.) C:\windows\system32\Drivers\LNonPnP.sys
2013-11-15 03:20 - 2013-11-22 04:19 - 00001548 _____ C:\windows\LkmdfCoInst.log
2013-11-15 03:20 - 2013-11-15 03:20 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Leadertech
2013-11-15 03:20 - 2013-11-15 03:20 - 00000000 ____D C:\Users\Booxi\AppData\Local\Logitech
2013-11-15 03:20 - 2013-11-15 03:20 - 00000000 ____D C:\ProgramData\LogiShrd
2013-11-15 03:20 - 2013-11-15 03:20 - 00000000 ____D C:\Program Files\Logitech Gaming Software
2013-11-15 03:17 - 2013-11-15 03:17 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Logitech
2013-11-15 03:17 - 2013-11-15 03:17 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Logishrd
2013-11-15 03:12 - 2013-11-15 03:12 - 00001268 _____ C:\Users\Booxi\Desktop\Revo Uninstaller.lnk
2013-11-15 03:12 - 2013-11-15 03:12 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-11-15 03:10 - 2013-11-19 16:43 - 00000000 ____D C:\Users\Booxi\AppData\Local\Overwolf
2013-11-15 03:09 - 2013-11-15 16:53 - 00000000 ____D C:\ProgramData\Oracle
2013-11-15 03:09 - 2013-11-15 03:09 - 00000000 ____D C:\ProgramData\Sun
2013-11-15 03:09 - 2013-11-15 03:09 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-15 03:06 - 2013-11-15 03:06 - 00000000 ____D C:\Program Files\Intel
2013-11-15 03:06 - 2010-08-12 15:00 - 00133800 _____ (Intel Corporation) C:\windows\system32\IPROSetMonitor.exe
2013-11-15 02:34 - 2013-11-19 20:29 - 00000000 ____D C:\Users\Booxi\AppData\Local\Thunderbird
2013-11-15 02:34 - 2013-11-15 02:34 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Thunderbird
2013-11-15 02:33 - 2013-11-15 02:33 - 00002090 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2013-11-15 02:17 - 2013-11-15 02:17 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-11-15 02:13 - 2013-11-15 02:16 - 00000095 ____H C:\Users\Booxi\Documents\.~lock.Jürgi server.odt#
2013-11-15 02:08 - 2013-11-21 22:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-15 02:08 - 2013-11-15 15:36 - 00000000 ____D C:\Users\Booxi\AppData\Local\Mozilla
2013-11-15 02:08 - 2013-11-15 02:09 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Mozilla
2013-11-15 02:08 - 2013-11-15 02:08 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-11-15 02:08 - 2013-11-15 02:08 - 00000000 ____D C:\ProgramData\Mozilla
2013-11-15 02:07 - 2013-11-15 03:11 - 00000000 ____D C:\Users\Booxi\AppData\Local\Google
2013-11-15 02:07 - 2013-11-15 02:07 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Macromedia
2013-11-15 02:07 - 2013-11-15 02:07 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Adobe
2013-11-15 02:06 - 2013-11-19 22:40 - 00073160 _____ C:\Users\Booxi\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-15 02:06 - 2013-11-17 10:15 - 00000000 ___RD C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-15 02:06 - 2013-11-17 10:15 - 00000000 ____D C:\Users\Booxi
2013-11-15 02:06 - 2013-11-15 02:06 - 00001443 _____ C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-15 02:06 - 2013-11-15 02:06 - 00001409 _____ C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-11-15 02:06 - 2013-11-15 02:06 - 00000020 ___SH C:\Users\Booxi\ntuser.ini
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Vorlagen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Startmenü
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Netzwerkumgebung
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Lokale Einstellungen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Eigene Dateien
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Druckumgebung
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Documents\Eigene Musik
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Documents\Eigene Bilder
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\AppData\Local\Verlauf
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\AppData\Local\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Programme
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\ProgramData\Vorlagen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\ProgramData\Startmenü
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\ProgramData\Favoriten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\ProgramData\Dokumente
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Dokumente und Einstellungen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 ___RD C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Intel Corporation
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 ____D C:\Users\Booxi\AppData\Local\VirtualStore
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 ____D C:\Users\Booxi\AppData\Local\Power2Go
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 ____D C:\Users\Booxi\AppData\Local\Lenovo
2013-11-15 02:06 - 2011-09-19 21:03 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2013-11-15 02:06 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-15 02:06 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-15 00:51 - 2013-11-15 02:16 - 00018609 _____ C:\Users\Booxi\Documents\Jürgi server.odt
2013-11-14 22:22 - 2013-11-02 00:17 - 00002022 _____ C:\Users\Booxi\Documents\server.cfg
2013-11-09 02:03 - 2013-11-15 11:40 - 00000000 ____D C:\Users\Booxi\Documents\Ubisoft
2013-11-08 12:46 - 2013-11-15 11:40 - 00000000 ____D C:\Users\Booxi\Documents\WBGames
2013-11-07 23:28 - 2013-11-15 11:40 - 00000000 ____D C:\Users\Booxi\Documents\WB Games
2013-10-27 04:45 - 2013-11-15 11:36 - 00000000 ____D C:\Users\Booxi\Documents\How To Survive Saves
2013-10-24 17:05 - 2013-10-24 17:05 - 00773968 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr100.dll
2013-10-24 17:05 - 2013-10-24 17:05 - 00421200 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp100.dll
2013-10-23 11:00 - 2013-10-23 11:00 - 00454168 _____ (Check Point Software Technologies LTD) C:\windows\system32\Drivers\vsdatant.sys

==================== One Month Modified Files and Folders =======

2013-11-22 12:18 - 2013-11-16 16:22 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Dropbox
2013-11-22 12:17 - 2013-11-22 12:17 - 00000000 ____D C:\FRST
2013-11-22 12:11 - 2011-09-19 21:01 - 00001124 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-22 12:10 - 2009-07-14 05:51 - 00047010 _____ C:\windows\setupact.log
2013-11-22 12:09 - 2011-09-19 20:45 - 00671968 _____ C:\windows\WindowsUpdate.log
2013-11-22 04:19 - 2013-11-15 03:20 - 00018960 _____ (Logitech, Inc.) C:\windows\system32\Drivers\LNonPnP.sys
2013-11-22 04:19 - 2013-11-15 03:20 - 00001548 _____ C:\windows\LkmdfCoInst.log
2013-11-22 04:15 - 2013-11-15 03:53 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Tunngle
2013-11-22 04:15 - 2013-11-15 03:53 - 00000000 ____D C:\ProgramData\Tunngle
2013-11-22 04:12 - 2013-11-22 04:12 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Malwarebytes
2013-11-22 04:11 - 2013-11-22 04:11 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-11-22 04:11 - 2013-11-22 04:11 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-22 04:11 - 2013-11-22 04:11 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-22 03:37 - 2013-11-22 01:18 - 00000000 ____D C:\ProgramData\QuickSet
2013-11-22 03:37 - 2013-11-22 01:17 - 00000000 ____D C:\ProgramData\InstallMate
2013-11-22 02:11 - 2011-09-19 21:01 - 00001120 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-22 01:18 - 2013-11-22 01:18 - 00002694 _____ C:\windows\System32\Tasks\SK.Enhancer-S-161304646
2013-11-22 01:18 - 2013-11-22 01:18 - 00000448 ____H C:\windows\Tasks\SK.Enhancer-S-161304646.job
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Users\Booxi\AppData\Local\Packages
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\ProgramData\YoutubeAdblocker
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\ProgramData\surf Annd keep
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\ProgramData\SearchNewTab
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\ProgramData\42fe8eb7ee241cea
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Program Files (x86)\YoutubeAdblocker
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Program Files (x86)\WebSearch
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Program Files (x86)\surf Annd keep
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Program Files (x86)\Sk.Enhancer
2013-11-22 01:18 - 2013-11-22 01:18 - 00000000 ____D C:\Program Files (x86)\SearchNewTab
2013-11-22 01:01 - 2009-07-14 05:45 - 00020480 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-22 01:01 - 2009-07-14 05:45 - 00020480 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-22 01:00 - 2011-09-19 21:28 - 00696132 _____ C:\windows\system32\perfh007.dat
2013-11-22 01:00 - 2011-09-19 21:28 - 00147428 _____ C:\windows\system32\perfc007.dat
2013-11-22 01:00 - 2009-07-14 06:13 - 01611160 _____ C:\windows\system32\PerfStringBackup.INI
2013-11-22 00:54 - 2013-11-17 10:15 - 00000000 ___RD C:\Users\Booxi\Dropbox
2013-11-22 00:54 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-11-21 22:07 - 2013-11-15 02:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-21 17:19 - 2013-11-15 05:40 - 00003934 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{B965998B-177E-47D9-8A0E-5AAB77E6A5C0}
2013-11-21 05:13 - 2013-11-21 05:13 - 01019818 _____ C:\Users\Booxi\Downloads\MMD3.wal
2013-11-21 05:11 - 2013-11-21 05:11 - 00188479 _____ C:\Users\Booxi\Downloads\KalaK_Amp.wsz
2013-11-21 05:08 - 2013-11-21 05:08 - 01305284 _____ C:\Users\Booxi\Downloads\S7Reflex.wal
2013-11-21 05:00 - 2013-11-21 05:00 - 00000109 _____ C:\Users\Booxi\Documents\winamp2.wsp
2013-11-21 04:54 - 2013-11-21 04:52 - 00041095 _____ C:\Users\Booxi\Documents\winamp.wsp
2013-11-21 04:50 - 2013-11-21 04:50 - 00770176 _____ C:\Users\Booxi\Downloads\WebSpider27Setup.exe
2013-11-21 04:50 - 2013-11-21 04:50 - 00000000 ____D C:\Program Files (x86)\Xaldon
2013-11-21 02:41 - 2013-11-21 02:34 - 00000000 ____D C:\Users\Booxi\Documents\Website Ripper Copier
2013-11-21 02:34 - 2013-11-21 02:34 - 00001289 _____ C:\Users\Public\Desktop\Website Ripper Copier.lnk
2013-11-21 02:34 - 2013-11-21 02:34 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Website Ripper Copier
2013-11-21 02:34 - 2013-11-21 02:34 - 00000000 ____D C:\Program Files (x86)\Tensons
2013-11-21 02:33 - 2013-11-21 02:33 - 00759075 _____ C:\Users\Booxi\Desktop\WRCsetup.exe
2013-11-21 02:33 - 2013-11-21 02:33 - 00401768 _____ (Softonic                                        ) C:\Users\Booxi\Downloads\SoftonicDownloader_fuer_website-ripper-copier.exe
2013-11-21 02:31 - 2013-11-21 02:28 - 12996104 _____ (Nullsoft, Inc.) C:\Users\Booxi\Downloads\winamp566_full_de-de.exe
2013-11-21 00:58 - 2013-11-21 00:58 - 00000000 ____D C:\Users\Booxi\Downloads\UGT_C_v1.9.0
2013-11-21 00:56 - 2013-11-21 00:55 - 05094007 _____ C:\Users\Booxi\Downloads\UGT_C_v1.9.0.rar
2013-11-21 00:18 - 2013-11-21 00:18 - 04250232 _____ (HTTrack                                                     ) C:\Users\Booxi\Downloads\httrack_x64-3.47.27.exe
2013-11-21 00:18 - 2013-11-21 00:18 - 00000836 _____ C:\Users\Booxi\Desktop\HTTrack Website Copier.lnk
2013-11-21 00:18 - 2013-11-21 00:18 - 00000000 ____D C:\Program Files\WinHTTrack
2013-11-20 23:58 - 2013-11-19 20:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-11-20 23:43 - 2013-11-20 23:43 - 00014797 _____ C:\Users\Booxi\Desktop\eichhörnchen.htm
2013-11-20 22:43 - 2013-11-20 22:43 - 00000206 _____ C:\Users\Booxi\Desktop\Killing Floor.url
2013-11-20 22:43 - 2013-11-15 11:45 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-11-20 20:48 - 2013-11-20 20:46 - 00000000 ____D C:\Program Files (x86)\Smart Port Forwarding
2013-11-20 20:46 - 2013-11-20 20:46 - 00153697 _____ C:\Users\Booxi\Downloads\spf.zip
2013-11-20 20:46 - 2013-11-20 20:46 - 00001071 _____ C:\Users\Public\Desktop\Smart Port Forwarding.lnk
2013-11-20 19:35 - 2013-11-20 19:35 - 05010367 _____ C:\Users\Booxi\Downloads\teamspeak3-server_win64-3.0.10.1.zip
2013-11-20 19:35 - 2013-11-20 19:35 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\2C0A
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0C0A
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0C04
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0816
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0804
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0424
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\041F
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\041E
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\041D
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\041B
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0419
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0416
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0415
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0414
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0413
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0412
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0411
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0410
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\040E
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\040D
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\040C
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\040B
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\040A
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0409
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0408
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0406
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0405
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0404
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\windows\system32\0401
2013-11-20 16:18 - 2013-11-20 16:18 - 00000000 ____D C:\Program Files (x86)\Renesas Electronics
2013-11-20 16:18 - 2011-09-19 21:28 - 00000000 ____D C:\windows\system32\0407
2013-11-20 16:18 - 2011-09-19 20:44 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-11-20 16:17 - 2013-11-20 16:17 - 26849632 _____ (Lenovo Group                                                ) C:\Users\Booxi\Downloads\ID1IME03WW5.exe
2013-11-20 16:16 - 2013-11-20 16:16 - 07044136 _____ (Lenovo Group Limited                                        ) C:\Users\Booxi\Downloads\h1100136_32.exe
2013-11-20 16:15 - 2013-11-20 16:15 - 02456976 _____ (Lenovo Group                                                ) C:\Users\Booxi\Downloads\ID2CHP07WW5.exe
2013-11-20 16:13 - 2011-09-19 20:56 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-20 16:13 - 2011-09-19 20:46 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-11-20 16:00 - 2013-11-20 16:00 - 00296955 _____ C:\windows\system32\nvvsvc.rar
2013-11-20 15:48 - 2013-11-20 15:48 - 00002935 _____ C:\Users\Booxi\Desktop\HiJackThis.lnk
2013-11-20 15:48 - 2013-11-20 15:48 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2013-11-20 15:48 - 2013-11-20 15:48 - 00000000 ____D C:\Program Files (x86)\Trend Micro
2013-11-20 15:47 - 2013-11-20 15:47 - 01402880 _____ C:\Users\Booxi\Downloads\HiJackThis.msi
2013-11-20 15:31 - 2010-11-21 04:47 - 00157870 _____ C:\windows\PFRO.log
2013-11-20 15:31 - 2009-07-14 05:45 - 00334688 _____ C:\windows\system32\FNTCACHE.DAT
2013-11-20 13:39 - 2013-11-15 03:32 - 00000000 ____D C:\Users\Booxi\AppData\Local\NVIDIA
2013-11-20 13:39 - 2011-09-19 20:46 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-11-20 13:39 - 2011-09-19 20:46 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-11-20 13:31 - 2013-11-20 13:16 - 00000000 ____D C:\Users\Booxi\Downloads\Minecraft Portable v.1.11.24 by johsty
2013-11-20 13:16 - 2013-11-20 13:15 - 291481529 _____ C:\Users\Booxi\Downloads\Minecraft Portable v.1.11.24 by johsty.zip
2013-11-20 13:13 - 2013-11-15 12:58 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\vlc
2013-11-19 22:55 - 2013-11-19 22:50 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Audacity
2013-11-19 22:50 - 2013-11-19 22:50 - 00001011 _____ C:\Users\Public\Desktop\Audacity.lnk
2013-11-19 22:50 - 2013-11-19 22:50 - 00000000 ____D C:\Program Files (x86)\Audacity
2013-11-19 22:49 - 2013-11-19 22:48 - 22180353 _____ (Audacity Team                                               ) C:\Users\Booxi\Downloads\audacity-win-2.0.5.exe
2013-11-19 22:40 - 2013-11-19 22:40 - 00618912 _____ C:\Users\Booxi\Downloads\Audacity - CHIP-Downloader.exe
2013-11-19 22:40 - 2013-11-15 02:06 - 00073160 _____ C:\Users\Booxi\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-19 22:34 - 2013-11-19 22:34 - 00000000 ____D C:\Users\Booxi\Downloads\downloads(1)
2013-11-19 22:22 - 2013-11-19 22:19 - 2851739008 _____ C:\Users\Booxi\Downloads\downloads(1).zip
2013-11-19 20:43 - 2013-11-19 20:43 - 00002625 _____ C:\Users\Public\Desktop\LibreOffice 4.1.lnk
2013-11-19 20:43 - 2013-11-19 20:43 - 00000000 ____D C:\Program Files (x86)\LibreOffice 4
2013-11-19 20:43 - 2013-11-19 20:42 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Nico Mak Computing
2013-11-19 20:42 - 2013-11-19 20:42 - 00001202 _____ C:\Users\Booxi\Desktop\Format Factory.lnk
2013-11-19 20:42 - 2013-11-19 20:42 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2013-11-19 20:42 - 2013-11-19 20:42 - 00000000 ____D C:\Program Files (x86)\FreeTime
2013-11-19 20:29 - 2013-11-15 02:34 - 00000000 ____D C:\Users\Booxi\AppData\Local\Thunderbird
2013-11-19 16:43 - 2013-11-15 03:10 - 00000000 ____D C:\Users\Booxi\AppData\Local\Overwolf
2013-11-19 16:42 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2013-11-19 00:10 - 2011-02-15 11:41 - 00000000 ____D C:\Program Files\Windows Journal
2013-11-19 00:10 - 2010-11-21 08:06 - 00000000 ____D C:\windows\SysWOW64\winrm
2013-11-19 00:10 - 2010-11-21 08:06 - 00000000 ____D C:\windows\SysWOW64\WCN
2013-11-19 00:10 - 2010-11-21 08:06 - 00000000 ____D C:\windows\SysWOW64\sysprep
2013-11-19 00:10 - 2010-11-21 08:06 - 00000000 ____D C:\windows\SysWOW64\slmgr
2013-11-19 00:10 - 2010-11-21 08:06 - 00000000 ____D C:\windows\SysWOW64\Printing_Admin_Scripts
2013-11-19 00:10 - 2010-11-21 08:06 - 00000000 ____D C:\windows\system32\winrm
2013-11-19 00:10 - 2010-11-21 08:06 - 00000000 ____D C:\windows\system32\WCN
2013-11-19 00:10 - 2010-11-21 08:06 - 00000000 ____D C:\windows\system32\slmgr
2013-11-19 00:10 - 2010-11-21 08:06 - 00000000 ____D C:\windows\system32\Printing_Admin_Scripts
2013-11-19 00:10 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2013-11-19 00:10 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-11-19 00:10 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-11-19 00:10 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker
2013-11-19 00:10 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2013-11-19 00:10 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-11-19 00:10 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\Setup
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\oobe
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\MUI
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\migwiz
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\Dism
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\com
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\sysprep
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\Setup
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\oobe
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\MUI
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\migwiz
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\Dism
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\com
2013-11-19 00:10 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System
2013-11-18 19:00 - 2013-11-18 18:58 - 00000600 _____ C:\Users\Booxi\AppData\Roaming\winscp.rnd
2013-11-18 18:56 - 2013-11-18 18:56 - 00000983 _____ C:\Users\Public\Desktop\WinSCP.lnk
2013-11-18 18:56 - 2013-11-18 18:56 - 00000000 ____D C:\Program Files (x86)\WinSCP
2013-11-17 20:06 - 2013-11-17 20:06 - 00000808 _____ C:\Users\Booxi\Documents\DeadIslandGame_x86_rwdi.CT
2013-11-17 19:33 - 2013-11-17 19:33 - 00001089 _____ C:\Users\Booxi\Desktop\Cheat Engine.lnk
2013-11-17 19:33 - 2013-11-17 19:33 - 00000000 ____D C:\Users\Booxi\Documents\My Cheat Tables
2013-11-17 19:33 - 2013-11-17 19:33 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\OpenCandy
2013-11-17 19:33 - 2013-11-17 19:33 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.3
2013-11-17 19:26 - 2013-11-17 19:26 - 00000000 ____D C:\Users\Booxi\AppData\Local\Chromium
2013-11-17 19:19 - 2013-11-17 19:16 - 00417513 _____ C:\windows\system32\Drivers\vsconfig.xml
2013-11-17 19:16 - 2013-11-17 19:16 - 00000762 _____ C:\Users\Public\Desktop\ZoneAlarm Security.lnk
2013-11-17 19:16 - 2013-11-17 19:09 - 00000000 ____D C:\Program Files (x86)\CheckPoint
2013-11-17 19:08 - 2013-11-17 19:08 - 00000000 ____D C:\ProgramData\CheckPoint
2013-11-17 19:05 - 2013-11-17 19:05 - 00000000 ____D C:\ProgramData\Overwolf
2013-11-17 19:03 - 2013-11-15 04:06 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-11-17 15:21 - 2013-11-17 15:21 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\WinRAR
2013-11-17 15:21 - 2013-11-17 15:21 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-11-17 15:21 - 2013-11-17 15:21 - 00000000 ____D C:\Program Files\WinRAR
2013-11-17 12:25 - 2013-11-17 12:24 - 00000000 ____D C:\Program Files\Virtual Audio Cable
2013-11-17 12:24 - 2013-11-17 12:24 - 00066728 _____ (Eugene V. Muzychenko) C:\windows\system32\Drivers\vrtaucbl.sys
2013-11-17 10:15 - 2013-11-17 10:15 - 00001001 _____ C:\Users\Booxi\Desktop\Dropbox.lnk
2013-11-17 10:15 - 2013-11-17 10:15 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-11-17 10:15 - 2013-11-15 02:06 - 00000000 ___RD C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-17 10:15 - 2013-11-15 02:06 - 00000000 ____D C:\Users\Booxi
2013-11-17 07:33 - 2013-11-16 11:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-15 17:42 - 2011-09-19 21:02 - 00010392 _____ C:\windows\DirectX.log
2013-11-15 17:27 - 2013-11-15 16:45 - 00000000 ____D C:\Program Files (x86)\MiniTool Partition Wizard Home Edition 8.1.1
2013-11-15 17:05 - 2013-11-15 17:05 - 00000000 ____D C:\ProgramData\Steam
2013-11-15 16:54 - 2013-11-15 16:54 - 00000000 ____D C:\windows\Sun
2013-11-15 16:53 - 2013-11-15 16:53 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-11-15 16:53 - 2013-11-15 16:53 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-11-15 16:53 - 2013-11-15 16:53 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-11-15 16:53 - 2013-11-15 16:53 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-15 16:53 - 2013-11-15 03:09 - 00000000 ____D C:\ProgramData\Oracle
2013-11-15 16:45 - 2013-11-15 16:45 - 00001253 _____ C:\Users\Public\Desktop\MiniTool Partition Wizard Home Edition.lnk
2013-11-15 15:36 - 2013-11-15 02:08 - 00000000 ____D C:\Users\Booxi\AppData\Local\Mozilla
2013-11-15 13:32 - 2013-11-15 13:32 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\dvdcss
2013-11-15 13:32 - 2013-11-15 13:30 - 00006046 _____ C:\Filmdb.script
2013-11-15 13:32 - 2013-11-15 13:30 - 00000088 _____ C:\Filmdb.properties
2013-11-15 12:59 - 2013-11-15 12:59 - 00000000 ____D C:\Users\Booxi\AppData\Local\Novation
2013-11-15 12:59 - 2013-11-15 12:59 - 00000000 _____ C:\AutomapClients.ini
2013-11-15 12:57 - 2013-11-15 12:55 - 00000000 ____D C:\Program Files (x86)\Winamp
2013-11-15 12:55 - 2013-11-15 12:55 - 00000983 _____ C:\Users\Public\Desktop\Winamp.lnk
2013-11-15 12:55 - 2013-11-15 12:55 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Winamp
2013-11-15 12:55 - 2013-11-15 12:55 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
2013-11-15 12:55 - 2013-11-15 12:55 - 00000000 ____D C:\Program Files (x86)\Winamp Detect
2013-11-15 12:54 - 2013-11-15 12:54 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-11-15 12:54 - 2013-11-15 12:54 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-11-15 12:38 - 2013-11-15 12:38 - 00000207 _____ C:\Users\Booxi\Desktop\F.E.A.R. 3.url
2013-11-15 12:02 - 2013-11-15 12:02 - 00000000 ____D C:\Users\Booxi\AppData\Local\Focusrite_Audio_Engineeri
2013-11-15 12:01 - 2013-11-15 12:01 - 00000000 ____D C:\ProgramData\Propellerhead Software
2013-11-15 12:01 - 2013-11-15 12:01 - 00000000 ____D C:\ProgramData\Apple
2013-11-15 12:00 - 2013-11-15 12:00 - 00000000 ____D C:\Program Files (x86)\Novation
2013-11-15 11:58 - 2013-11-15 11:58 - 00000000 ____D C:\Program Files\Novation
2013-11-15 11:57 - 2013-11-15 11:57 - 00000000 ____D C:\Users\Booxi\Neuer Ordner
2013-11-15 11:56 - 2013-11-15 11:56 - 00000000 ____D C:\Users\Booxi\Documents\Neuer Ordner
2013-11-15 11:44 - 2013-11-15 11:43 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Ableton
2013-11-15 11:41 - 2013-11-15 11:41 - 00000503 _____ C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton Live 9 Lite.lnk
2013-11-15 11:40 - 2013-11-09 02:03 - 00000000 ____D C:\Users\Booxi\Documents\Ubisoft
2013-11-15 11:40 - 2013-11-08 12:46 - 00000000 ____D C:\Users\Booxi\Documents\WBGames
2013-11-15 11:40 - 2013-11-07 23:28 - 00000000 ____D C:\Users\Booxi\Documents\WB Games
2013-11-15 11:40 - 2013-08-22 19:55 - 00000000 ____D C:\Users\Booxi\Documents\VirtualDJ
2013-11-15 11:40 - 2013-07-24 11:47 - 00000000 ____D C:\Users\Booxi\Documents\STALKER-SHOC
2013-11-15 11:40 - 2013-02-26 04:31 - 00000000 ___SD C:\Users\Booxi\Documents\Sticky Passwords
2013-11-15 11:40 - 2013-02-19 14:35 - 00000000 ____D C:\Users\Booxi\Documents\Simmchen
2013-11-15 11:40 - 2013-02-03 18:15 - 00000000 ____D C:\Users\Booxi\Documents\Square Enix
2013-11-15 11:40 - 2012-12-21 04:46 - 00000000 ____D C:\Users\Booxi\Documents\yay
2013-11-15 11:40 - 2012-11-01 13:10 - 00000000 ____D C:\Users\Booxi\Documents\WebradioSchweiz
2013-11-15 11:40 - 2012-10-15 18:42 - 00000000 ____D C:\Users\Booxi\Documents\Visual Studio 2010
2013-11-15 11:40 - 2012-10-04 14:36 - 00000000 ____D C:\Users\Booxi\Documents\Syndicate
2013-11-15 11:39 - 2013-09-07 03:26 - 695099392 _____ C:\Users\Booxi\Desktop\Setup.msi
2013-11-15 11:39 - 2013-06-16 10:43 - 00000000 ____D C:\Users\Booxi\Documents\SimCity 4
2013-11-15 11:39 - 2013-05-24 02:43 - 00000000 ____D C:\Users\Booxi\Documents\samsung
2013-11-15 11:39 - 2013-05-01 03:23 - 00000000 ____D C:\Users\Booxi\Documents\red5
2013-11-15 11:39 - 2012-10-14 15:05 - 00000000 ____D C:\Users\Booxi\Documents\Shiner
2013-11-15 11:39 - 2012-10-11 10:36 - 00000000 ____D C:\Users\Booxi\Documents\Rockstar Games
2013-11-15 11:38 - 2013-01-19 17:49 - 00000000 ____D C:\Users\Booxi\Documents\Rebellion
2013-11-15 11:38 - 2012-12-26 02:11 - 00000000 ____D C:\Users\Booxi\Documents\Puddle
2013-11-15 11:38 - 2012-11-16 18:25 - 00000000 ____D C:\Users\Booxi\Documents\RCT3
2013-11-15 11:38 - 2012-10-10 21:59 - 00000000 ____D C:\Users\Booxi\Documents\RADIOandDJ
2013-11-15 11:37 - 2013-04-02 09:16 - 00000000 ____D C:\Users\Booxi\Documents\MAGIX_Music_Maker_Rock_Edition_4
2013-11-15 11:37 - 2013-02-26 04:43 - 00000000 ____D C:\Users\Booxi\Documents\PCSpeedUp
2013-11-15 11:37 - 2012-11-08 23:34 - 00000000 ____D C:\Users\Booxi\Documents\Native Instruments
2013-11-15 11:37 - 2012-11-08 22:16 - 00000000 ____D C:\Users\Booxi\Documents\National Instruments
2013-11-15 11:37 - 2012-11-08 21:33 - 00000000 ____D C:\Users\Booxi\Documents\Plexim
2013-11-15 11:37 - 2012-10-28 12:18 - 00000000 ____D C:\Users\Booxi\Documents\PCSX2
2013-11-15 11:37 - 2012-10-11 19:06 - 00000000 ____D C:\Users\Booxi\Documents\My Games
2013-11-15 11:37 - 2012-10-08 10:03 - 00000000 ____D C:\Users\Booxi\Documents\NetBeansProjects
2013-11-15 11:37 - 2007-11-02 11:07 - 00000000 ____D C:\Users\Booxi\Documents\Max Payne 2 Savegames
2013-11-15 11:36 - 2013-10-27 04:45 - 00000000 ____D C:\Users\Booxi\Documents\How To Survive Saves
2013-11-15 11:36 - 2013-08-30 12:01 - 00000000 ____D C:\Users\Booxi\Documents\Electronic Arts
2013-11-15 11:36 - 2013-08-22 01:36 - 00000000 ____D C:\Users\Booxi\Documents\Battlefield 3
2013-11-15 11:36 - 2013-08-03 11:00 - 00000000 ____D C:\Users\Booxi\Documents\AdobeStockPhotos
2013-11-15 11:36 - 2013-06-05 14:37 - 00000000 ____D C:\Users\Booxi\Documents\Alpha Protocol
2013-11-15 11:36 - 2013-03-28 04:46 - 00000000 ____D C:\Users\Booxi\Documents\AVS4YOU
2013-11-15 11:36 - 2013-03-23 16:18 - 00000000 ____D C:\Users\Booxi\Documents\CAPCOM
2013-11-15 11:36 - 2013-03-22 20:33 - 00000000 ____D C:\Users\Booxi\Documents\Adobe
2013-11-15 11:36 - 2013-03-12 20:05 - 00000000 ____D C:\Users\Booxi\Documents\Hitman Blood Money
2013-11-15 11:36 - 2013-02-11 03:00 - 00000000 ____D C:\Users\Booxi\Documents\FLiNGTrainer
2013-11-15 11:36 - 2013-02-08 08:04 - 00000000 ____D C:\Users\Booxi\Documents\EA Games
2013-11-15 11:36 - 2013-01-18 04:38 - 00000000 ____D C:\Users\Booxi\Documents\BasicGame
2013-11-15 11:36 - 2013-01-18 03:27 - 00000000 ____D C:\Users\Booxi\Documents\GTA IV Savegame Backup Tool
2013-11-15 11:36 - 2013-01-05 13:51 - 00000000 ____D C:\Users\Booxi\Documents\DVDVideoSoft
2013-11-15 11:36 - 2012-12-26 05:49 - 00000000 ____D C:\Users\Booxi\Documents\AutomaticSolution Software
2013-11-15 11:36 - 2012-12-22 14:32 - 00000000 ____D C:\Users\Booxi\Documents\Adobe PDF
2013-11-15 11:36 - 2012-11-12 22:27 - 00000000 ____D C:\Users\Booxi\Documents\LogiShrd
2013-11-15 11:36 - 2012-11-07 09:52 - 00000000 ____D C:\Users\Booxi\Documents\Assassin's Creed Revelations
2013-11-15 11:36 - 2012-11-07 09:09 - 00000000 ____D C:\Users\Booxi\Documents\Ableton
2013-11-15 11:36 - 2012-10-31 11:13 - 00000000 ____D C:\Users\Booxi\Documents\Command & Conquer 3 Tiberium Wars
2013-11-15 11:36 - 2012-10-21 15:51 - 00000000 ____D C:\Users\Booxi\Documents\Battlefield 2
2013-11-15 11:36 - 2012-10-14 14:28 - 00000000 ____D C:\Users\Booxi\Documents\Amiga Files
2013-11-15 11:36 - 2012-10-14 12:19 - 00000000 ____D C:\Users\Booxi\Documents\Eigene Spiele
2013-11-15 11:36 - 2012-10-10 17:31 - 00000000 ____D C:\Users\Booxi\Documents\Cooper's Revenge
2013-11-15 11:36 - 2012-10-09 09:50 - 00000000 ____D C:\Users\Booxi\Documents\Assassin's Creed III
2013-11-15 11:36 - 2012-10-07 15:16 - 00000000 ____D C:\Users\Booxi\Documents\Diablo III
2013-11-15 11:34 - 2012-12-21 04:50 - 00000000 ____D C:\Users\Booxi\Documents\a
2013-11-15 11:34 - 2012-10-14 14:59 - 00000000 ____D C:\Users\Booxi\Documents\4a games
2013-11-15 11:16 - 2013-11-15 11:16 - 00001173 _____ C:\Users\Booxi\Desktop\TeamSpeak 3 Client.lnk
2013-11-15 11:16 - 2013-11-15 11:16 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2013-11-15 11:16 - 2013-11-15 11:16 - 00000000 ____D C:\Users\Booxi\AppData\Local\TeamSpeak 3 Client
2013-11-15 11:05 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-11-15 11:04 - 2013-11-15 11:04 - 00000020 _____ C:\windows\TóÁ
2013-11-15 11:01 - 2013-11-15 11:01 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Roxio Log Files
2013-11-15 05:44 - 2011-09-19 21:03 - 00000000 ____D C:\ProgramData\CyberLink
2013-11-15 05:05 - 2013-11-15 05:05 - 00000000 ____D C:\Users\Booxi\AppData\Local\Macromedia
2013-11-15 05:02 - 2013-11-15 05:02 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-11-15 05:02 - 2013-11-15 05:02 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-15 05:02 - 2013-11-15 05:02 - 00000000 ____D C:\windows\system32\Macromed
2013-11-15 05:02 - 2013-11-15 05:01 - 00000000 ____D C:\Users\Booxi\AppData\Local\Adobe
2013-11-15 05:00 - 2013-11-15 04:35 - 00000000 _____ C:\windows\SysWOW64\Access.dat
2013-11-15 04:59 - 2013-11-15 04:59 - 00000000 ____D C:\Users\Booxi\AppData\Local\wb games
2013-11-15 04:36 - 2011-09-19 21:00 - 00000000 ____D C:\ProgramData\McAfee
2013-11-15 04:36 - 2011-09-19 21:00 - 00000000 ____D C:\Program Files\Common Files\mcafee
2013-11-15 04:36 - 2011-09-19 21:00 - 00000000 ____D C:\Program Files (x86)\McAfee
2013-11-15 03:53 - 2013-11-15 03:53 - 00003380 _____ C:\windows\System32\Tasks\SidebarExecute
2013-11-15 03:53 - 2013-11-15 03:53 - 00000995 _____ C:\Users\Public\Desktop\Tunngle beta.lnk
2013-11-15 03:53 - 2013-11-15 03:53 - 00000000 ____D C:\Users\Public\Documents\Tunngle
2013-11-15 03:53 - 2013-11-15 03:53 - 00000000 ____D C:\Users\Booxi\Documents\Tunngle
2013-11-15 03:53 - 2013-11-15 03:53 - 00000000 ____D C:\Program Files (x86)\Tunngle
2013-11-15 03:45 - 2013-11-15 03:45 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\NVIDIA
2013-11-15 03:39 - 2011-09-19 21:07 - 00000000 ____D C:\ProgramData\Lenovo
2013-11-15 03:37 - 2013-11-15 03:37 - 00000614 _____ C:\Users\Public\Desktop\Steam.lnk
2013-11-15 03:35 - 2013-11-15 03:34 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\CyberLink
2013-11-15 03:31 - 2013-11-15 03:31 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-11-15 03:28 - 2013-11-15 03:27 - 01588294 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2013-11-15 03:24 - 2013-11-15 03:24 - 00000000 ____D C:\NVIDIA
2013-11-15 03:20 - 2013-11-15 03:20 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Leadertech
2013-11-15 03:20 - 2013-11-15 03:20 - 00000000 ____D C:\Users\Booxi\AppData\Local\Logitech
2013-11-15 03:20 - 2013-11-15 03:20 - 00000000 ____D C:\ProgramData\LogiShrd
2013-11-15 03:20 - 2013-11-15 03:20 - 00000000 ____D C:\Program Files\Logitech Gaming Software
2013-11-15 03:17 - 2013-11-15 03:17 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Logitech
2013-11-15 03:17 - 2013-11-15 03:17 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Logishrd
2013-11-15 03:12 - 2013-11-15 03:12 - 00001268 _____ C:\Users\Booxi\Desktop\Revo Uninstaller.lnk
2013-11-15 03:12 - 2013-11-15 03:12 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-11-15 03:11 - 2013-11-15 02:07 - 00000000 ____D C:\Users\Booxi\AppData\Local\Google
2013-11-15 03:09 - 2013-11-15 03:09 - 00000000 ____D C:\ProgramData\Sun
2013-11-15 03:09 - 2013-11-15 03:09 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-15 03:08 - 2011-09-19 20:47 - 00000000 ____D C:\Program Files (x86)\Realtek
2013-11-15 03:07 - 2011-09-19 20:47 - 00000000 ____D C:\Program Files (x86)\REALTEK PCIE Wireless LAN Driver
2013-11-15 03:06 - 2013-11-15 03:06 - 00000000 ____D C:\Program Files\Intel
2013-11-15 03:05 - 2009-07-14 06:32 - 00000000 ____D C:\windows\system32\restore
2013-11-15 02:34 - 2013-11-15 02:34 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Thunderbird
2013-11-15 02:33 - 2013-11-15 02:33 - 00002090 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2013-11-15 02:17 - 2013-11-15 02:17 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-11-15 02:16 - 2013-11-15 02:13 - 00000095 ____H C:\Users\Booxi\Documents\.~lock.Jürgi server.odt#
2013-11-15 02:16 - 2013-11-15 00:51 - 00018609 _____ C:\Users\Booxi\Documents\Jürgi server.odt
2013-11-15 02:09 - 2013-11-15 02:08 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Mozilla
2013-11-15 02:08 - 2013-11-15 02:08 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-11-15 02:08 - 2013-11-15 02:08 - 00000000 ____D C:\ProgramData\Mozilla
2013-11-15 02:07 - 2013-11-15 02:07 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Macromedia
2013-11-15 02:07 - 2013-11-15 02:07 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Adobe
2013-11-15 02:07 - 2011-09-19 21:01 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-15 02:06 - 2013-11-15 02:06 - 00001443 _____ C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-15 02:06 - 2013-11-15 02:06 - 00001409 _____ C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-11-15 02:06 - 2013-11-15 02:06 - 00000020 ___SH C:\Users\Booxi\ntuser.ini
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Vorlagen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Startmenü
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Netzwerkumgebung
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Lokale Einstellungen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Eigene Dateien
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Druckumgebung
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Documents\Eigene Musik
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Documents\Eigene Bilder
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\AppData\Local\Verlauf
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\AppData\Local\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Users\Booxi\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Programme
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\ProgramData\Vorlagen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\ProgramData\Startmenü
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\ProgramData\Favoriten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\ProgramData\Dokumente
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 _SHDL C:\Dokumente und Einstellungen
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 ___RD C:\Users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 ____D C:\Users\Booxi\AppData\Roaming\Intel Corporation
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 ____D C:\Users\Booxi\AppData\Local\VirtualStore
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 ____D C:\Users\Booxi\AppData\Local\Power2Go
2013-11-15 02:06 - 2013-11-15 02:06 - 00000000 ____D C:\Users\Booxi\AppData\Local\Lenovo
2013-11-15 02:06 - 2011-09-19 21:01 - 00004120 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-11-15 02:06 - 2011-09-19 21:01 - 00003868 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-11-15 02:06 - 2011-02-12 20:58 - 00000000 __SHD C:\Recovery
2013-11-15 02:06 - 2009-07-14 04:20 - 00000000 ___HD C:\Users\Default
2013-11-15 02:06 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\Recovery
2013-11-15 02:06 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT
2013-11-02 00:17 - 2013-11-14 22:22 - 00002022 _____ C:\Users\Booxi\Documents\server.cfg
2013-10-24 17:05 - 2013-10-24 17:05 - 00773968 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr100.dll
2013-10-24 17:05 - 2013-10-24 17:05 - 00421200 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp100.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 25257248 _____ (NVIDIA Corporation) C:\windows\system32\nvcompiler.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 22933792 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 18199872 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 17560352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcompiler.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 12572960 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2013-10-23 11:30 - 2013-11-15 03:24 - 11426568 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 11374520 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 09524088 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 09480328 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 03131680 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 03124512 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvenc.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 02946848 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 02747168 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvenc.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 01884448 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6433165.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 01511712 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6433165.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 01435504 _____ (NVIDIA Corporation) C:\windows\system32\nvumdshimx.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 01241376 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvumdshim.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 00696096 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 00655136 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 00599840 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 00560416 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 00317472 _____ (NVIDIA Corporation) C:\windows\system32\nvoglshim64.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 00266984 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglshim32.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 00168616 _____ (NVIDIA Corporation) C:\windows\system32\nvinitx.dll
2013-10-23 11:30 - 2013-11-15 03:24 - 00141336 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvinit.dll
2013-10-23 11:30 - 2011-09-19 20:46 - 30344480 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
2013-10-23 11:30 - 2011-09-19 20:46 - 18286416 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll
2013-10-23 11:30 - 2011-09-19 20:46 - 15855568 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll
2013-10-23 11:30 - 2011-09-19 20:46 - 15212336 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll
2013-10-23 11:30 - 2011-09-19 20:46 - 03067560 _____ (NVIDIA Corporation) C:\windows\system32\nvapi64.dll
2013-10-23 11:30 - 2011-09-19 20:46 - 02695200 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll
2013-10-23 11:30 - 2011-09-19 20:46 - 00023287 _____ C:\windows\system32\nvinfo.pb
2013-10-23 11:00 - 2013-10-23 11:00 - 00454168 _____ (Check Point Software Technologies LTD) C:\windows\system32\Drivers\vsdatant.sys
2013-10-23 09:20 - 2013-11-20 16:13 - 00922912 _____ (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
2013-10-23 09:20 - 2013-11-15 03:28 - 03426956 _____ C:\windows\system32\nvcoproc.bin
2013-10-23 09:20 - 2011-04-08 04:37 - 02559776 _____ (NVIDIA Corporation) C:\windows\system32\nvsvcr.dll
2013-10-23 09:20 - 2011-04-08 04:37 - 00219424 _____ (NVIDIA Corporation) C:\windows\system32\nvmctray.dll
2013-10-23 09:20 - 2011-04-08 04:37 - 00063776 _____ (NVIDIA Corporation) C:\windows\system32\nvshext.dll
2013-10-23 09:20 - 2011-04-08 04:36 - 06669600 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.dll
2013-10-23 09:20 - 2011-04-08 04:35 - 03489568 _____ (NVIDIA Corporation) C:\windows\system32\nvsvc64.dll

Files to move or delete:
====================
C:\ProgramData\flashax10.exe


Some content of TEMP:
====================
C:\Users\Booxi\AppData\Local\Temp\AskPIP_FF_.exe
C:\Users\Booxi\AppData\Local\Temp\DSETUP.dll
C:\Users\Booxi\AppData\Local\Temp\dsetup32.dll
C:\Users\Booxi\AppData\Local\Temp\DXSETUP.exe
C:\Users\Booxi\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Booxi\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Booxi\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Booxi\AppData\Local\Temp\nvStInst.exe
C:\Users\Booxi\AppData\Local\Temp\srrczsre.dll
C:\Users\Booxi\AppData\Local\Temp\TsuC72FABED.dll
C:\Users\Booxi\AppData\Local\Temp\wgr0kh1w.dll
C:\Users\Booxi\AppData\Local\Temp\_is13F3.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-20 00:42

==================== End Of Log ============================
         
--- --- ---

Alt 24.11.2013, 07:13   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Schauen wir mal tiefer.
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 24.11.2013, 16:53   #9
Reclaimbux
 
Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



So hier das logfile

[CODE]

Combofix Logfile:
Code:
ATTFilter
ComboFix 13-11-23.02 - Booxi 24.11.2013  17:45:06.1.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.8173.7004 [GMT 1:00]
ausgef�hrt von:: c:\users\Booxi\Desktop\ComboFix.exe
FW: ZoneAlarm Free Firewall Firewall *Disabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere L�schungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.dat
c:\programdata\SearchNewTab
c:\programdata\SearchNewTab\hOrCWWUBnly.dat
c:\programdata\SearchNewTab\hOrCWWUBnly.exe
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\acojnmmppiffdkeejoppapoaioplnkcg
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\acojnmmppiffdkeejoppapoaioplnkcg\2.19\background.html
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\acojnmmppiffdkeejoppapoaioplnkcg\2.19\content.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\acojnmmppiffdkeejoppapoaioplnkcg\2.19\lsdb.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\acojnmmppiffdkeejoppapoaioplnkcg\2.19\manifest.json
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\acojnmmppiffdkeejoppapoaioplnkcg\2.19\sqlite.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\acojnmmppiffdkeejoppapoaioplnkcg\2.19\yv5vsjjPR_bG.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabkcimgibkpnkfmpgnjoepdmclioeep
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabkcimgibkpnkfmpgnjoepdmclioeep\1.0\background.html
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabkcimgibkpnkfmpgnjoepdmclioeep\1.0\CMyhRan4Kb.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabkcimgibkpnkfmpgnjoepdmclioeep\1.0\content.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabkcimgibkpnkfmpgnjoepdmclioeep\1.0\lsdb.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabkcimgibkpnkfmpgnjoepdmclioeep\1.0\manifest.json
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabkcimgibkpnkfmpgnjoepdmclioeep\1.0\sqlite.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pifelbofldigncaipacpjhifgfloepec
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pifelbofldigncaipacpjhifgfloepec\1.0\background.html
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pifelbofldigncaipacpjhifgfloepec\1.0\content.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pifelbofldigncaipacpjhifgfloepec\1.0\Gj0_ngEaWkre.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pifelbofldigncaipacpjhifgfloepec\1.0\lsdb.js
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pifelbofldigncaipacpjhifgfloepec\1.0\manifest.json
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pifelbofldigncaipacpjhifgfloepec\1.0\newtab.html
c:\users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pifelbofldigncaipacpjhifgfloepec\1.0\sqlite.js
c:\users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\extensions\e00j-twsm@g-ocjhyor-.org
c:\users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\extensions\e00j-twsm@g-ocjhyor-.org\bootstrap.js
c:\users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\extensions\e00j-twsm@g-ocjhyor-.org\chrome.manifest
c:\users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\extensions\e00j-twsm@g-ocjhyor-.org\content\bg.js
c:\users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\extensions\e00j-twsm@g-ocjhyor-.org\install.rdf
c:\windows\SysWow64\FlashPlayerApp.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-10-24 bis 2013-11-24  ))))))))))))))))))))))))))))))
.
.
2013-11-22 11:17 . 2013-11-22 11:17	--------	d-----w-	C:\FRST
2013-11-22 03:11 . 2013-11-22 03:11	--------	d-----w-	c:\programdata\Malwarebytes
2013-11-22 03:11 . 2013-11-22 03:11	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2013-11-22 03:11 . 2013-04-04 13:50	25928	----a-w-	c:\windows\system32\drivers\mbam.sys
2013-11-22 00:18 . 2013-11-22 00:18	--------	d-----w-	c:\program files (x86)\SearchNewTab
2013-11-22 00:18 . 2013-11-22 13:19	--------	d-----w-	c:\program files (x86)\WebSearch
2013-11-22 00:18 . 2013-11-22 02:37	--------	d-----w-	c:\programdata\QuickSet
2013-11-22 00:18 . 2013-11-22 13:19	--------	d-----w-	c:\program files (x86)\Sk.Enhancer
2013-11-22 00:18 . 2013-11-22 00:18	--------	d-----w-	c:\programdata\YoutubeAdblocker
2013-11-22 00:18 . 2013-11-22 00:18	--------	d-----w-	c:\program files (x86)\YoutubeAdblocker
2013-11-22 00:18 . 2013-11-22 00:18	--------	d-----w-	c:\programdata\surf Annd keep
2013-11-22 00:18 . 2013-11-22 00:18	--------	d-----w-	c:\program files (x86)\surf Annd keep
2013-11-22 00:18 . 2013-11-22 00:18	--------	d-----w-	c:\programdata\42fe8eb7ee241cea
2013-11-22 00:17 . 2013-11-22 02:37	--------	d-----w-	c:\programdata\InstallMate
2013-11-21 03:50 . 2013-11-21 03:50	--------	d-----w-	c:\program files (x86)\Xaldon
2013-11-21 01:34 . 2013-11-21 01:34	--------	d-----w-	c:\program files (x86)\Tensons
2013-11-20 19:46 . 2013-11-20 19:48	--------	d-----w-	c:\program files (x86)\Smart Port Forwarding
2013-11-20 18:35 . 2013-11-20 18:35	--------	d-----w-	c:\programdata\boost_interprocess
2013-11-20 15:13 . 2013-10-23 08:20	922912	----a-w-	c:\windows\system32\nvvsvc.exe
2013-11-20 14:48 . 2013-11-20 14:48	--------	d-----w-	c:\program files (x86)\Trend Micro
2013-11-19 21:50 . 2013-11-19 21:50	--------	d-----w-	c:\program files (x86)\Audacity
2013-11-19 19:43 . 2013-11-19 19:43	--------	d-----w-	c:\program files (x86)\LibreOffice 4
2013-11-19 19:42 . 2012-02-08 09:29	18760	----a-w-	c:\windows\system32\roboot64.exe
2013-11-19 19:42 . 2013-11-19 19:42	--------	d-----w-	c:\program files (x86)\FreeTime
2013-11-19 19:39 . 2013-11-20 22:58	--------	d-----w-	c:\program files (x86)\Mozilla Thunderbird
2013-11-18 17:56 . 2013-11-18 17:56	--------	d-----w-	c:\program files (x86)\WinSCP
2013-11-17 18:33 . 2013-11-17 18:33	--------	d-----w-	c:\program files (x86)\Cheat Engine 6.3
2013-11-17 18:09 . 2013-11-17 18:16	--------	d-----w-	c:\program files (x86)\CheckPoint
2013-11-17 18:08 . 2013-11-17 18:08	--------	d-----w-	c:\programdata\CheckPoint
2013-11-17 18:05 . 2013-11-17 18:05	--------	d-----w-	c:\programdata\Overwolf
2013-11-17 11:24 . 2013-11-17 11:24	66728	----a-w-	c:\windows\system32\drivers\vrtaucbl.sys
2013-11-15 16:05 . 2013-11-15 16:05	--------	d-----w-	c:\programdata\Steam
2013-11-15 15:54 . 2013-11-15 15:54	--------	d-----w-	c:\windows\Sun
2013-11-15 15:53 . 2013-11-15 15:53	--------	d-----w-	c:\program files (x86)\Common Files\Java
2013-11-15 15:53 . 2013-11-15 15:53	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-11-15 15:46 . 2013-09-30 15:26	3050808	----a-w-	c:\windows\system32\pwNative.exe
2013-11-15 15:46 . 2013-09-30 15:26	19152	------w-	c:\windows\system32\pwdrvio.sys
2013-11-15 15:46 . 2013-09-30 15:26	12504	------w-	c:\windows\system32\pwdspio.sys
2013-11-15 15:45 . 2013-11-15 16:27	--------	d-----w-	c:\program files (x86)\MiniTool Partition Wizard Home Edition 8.1.1
2013-11-15 11:55 . 2009-09-04 16:29	1892184	----a-w-	c:\windows\SysWow64\D3DX9_42.dll
2013-11-15 11:55 . 2006-09-28 15:05	2414360	----a-w-	c:\windows\SysWow64\d3dx9_31.dll
2013-11-15 11:55 . 2013-11-15 11:55	--------	d-----w-	c:\program files (x86)\Winamp Detect
2013-11-15 11:55 . 2013-11-15 11:55	--------	d-----w-	c:\program files (x86)\Common Files\PX Storage Engine
2013-11-15 11:55 . 2013-11-15 11:57	--------	d-----w-	c:\program files (x86)\Winamp
2013-11-15 11:54 . 2013-11-15 11:54	--------	d-----w-	c:\program files (x86)\VideoLAN
2013-11-15 11:01 . 2013-11-15 11:01	--------	d-----w-	c:\programdata\Apple
2013-11-15 11:01 . 2013-11-15 11:01	--------	d-----w-	c:\programdata\Propellerhead Software
2013-11-15 11:00 . 2013-11-15 11:00	--------	d-----w-	c:\program files (x86)\Novation
2013-11-15 11:00 . 2012-04-19 11:31	18776	----a-w-	c:\windows\system32\drivers\automap.sys
2013-11-15 10:58 . 2013-04-30 09:52	21808	----a-w-	c:\windows\system32\nvnusbaudio_coinst.dll
2013-11-15 10:58 . 2013-04-30 09:52	53552	----a-w-	c:\windows\system32\drivers\nvnusbaudio.sys
2013-11-15 10:52 . 2013-11-15 10:51	712568	----a-w-	c:\program files (x86)\Uninstall Information\{ABAF1232-6213-4062-9D52-04E04A730CEA}\unins000.exe
2013-11-15 10:43 . 2013-11-15 10:43	--------	d-----w-	c:\program files (x86)\Common Files\Propellerhead Software
2013-11-15 04:02 . 2013-11-15 04:02	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-15 04:02 . 2013-11-15 04:02	--------	d-----w-	c:\windows\system32\Macromed
2013-11-15 03:06 . 2013-11-17 18:03	--------	d-----w-	c:\programdata\Kaspersky Lab
2013-11-15 02:53 . 2013-11-22 03:15	--------	d-----w-	c:\programdata\Tunngle
2013-11-15 02:53 . 2009-09-16 06:02	31232	----a-w-	c:\windows\system32\drivers\tap0901t.sys
2013-11-15 02:53 . 2013-11-15 02:53	--------	d-----w-	c:\program files (x86)\Tunngle
2013-11-15 02:41 . 2013-11-20 20:36	--------	d-----w-	c:\program files (x86)\Common Files\Steam
2013-11-15 02:31 . 2013-11-15 02:31	--------	d-----w-	c:\program files (x86)\AGEIA Technologies
2013-11-15 02:28 . 2013-10-23 08:20	3426956	----a-w-	c:\windows\system32\nvcoproc.bin
2013-11-15 02:26 . 2013-11-15 02:26	--------	d-----w-	c:\program files (x86)\Microsoft.NET
2013-11-15 02:20 . 2013-11-15 02:20	--------	d-----w-	c:\programdata\LogiShrd
2013-11-15 02:20 . 2013-11-22 03:19	18960	----a-w-	c:\windows\system32\drivers\LNonPnP.sys
2013-11-15 02:12 . 2013-11-15 02:12	--------	d-----w-	c:\program files (x86)\VS Revo Group
2013-11-15 02:09 . 2013-11-15 15:53	--------	d-----w-	c:\programdata\Oracle
2013-11-15 02:09 . 2013-11-15 02:09	--------	d-----w-	c:\program files (x86)\Java
2013-11-15 02:06 . 2010-08-12 14:00	133800	----a-w-	c:\windows\system32\IPROSetMonitor.exe
2013-11-15 02:04 . 2013-11-20 15:17	--------	d-----w-	C:\Drivers
2013-11-15 01:17 . 2013-11-15 01:17	--------	d-----w-	c:\program files (x86)\7-Zip
2013-11-15 01:08 . 2013-11-21 21:07	--------	d-----w-	c:\program files (x86)\Mozilla Maintenance Service
2013-11-15 01:06 . 2013-11-20 23:18	--------	d-----r-	C:\Program Files
2013-11-15 01:06 . 2013-11-20 12:39	--------	d---a-w-	C:\Users
2013-11-15 01:06 . 2013-11-15 01:06	--------	d-sh--we	C:\Programme
2013-11-15 01:06 . 2013-11-15 01:06	--------	d-sh--we	c:\programdata\Vorlagen
2013-11-15 01:06 . 2013-11-15 01:06	--------	d-sh--we	c:\programdata\Startmen�
2013-11-15 01:06 . 2013-11-15 01:06	--------	d-sh--we	c:\programdata\Favoriten
2013-11-15 01:06 . 2013-11-15 01:06	--------	d-sh--we	c:\programdata\Dokumente
2013-11-15 01:06 . 2013-11-15 01:06	--------	d-sh--we	c:\programdata\Anwendungsdaten
2013-11-15 01:06 . 2013-11-15 01:06	--------	d-sh--we	C:\Dokumente und Einstellungen
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-24 16:05 . 2013-10-24 16:05	773968	----a-w-	c:\windows\SysWow64\msvcr100.dll
2013-10-24 16:05 . 2013-10-24 16:05	421200	----a-w-	c:\windows\SysWow64\msvcp100.dll
2013-10-23 10:30 . 2011-09-19 19:46	3067560	----a-w-	c:\windows\system32\nvapi64.dll
2013-10-23 10:30 . 2011-09-19 19:46	30344480	----a-w-	c:\windows\system32\nvoglv64.dll
2013-10-23 10:30 . 2011-09-19 19:46	2695200	----a-w-	c:\windows\SysWow64\nvapi.dll
2013-10-23 10:30 . 2011-09-19 19:46	18286416	----a-w-	c:\windows\system32\nvwgf2umx.dll
2013-10-23 10:30 . 2011-09-19 19:46	15855568	----a-w-	c:\windows\SysWow64\nvwgf2um.dll
2013-10-23 10:30 . 2011-09-19 19:46	15212336	----a-w-	c:\windows\SysWow64\nvd3dum.dll
2013-10-23 10:00 . 2013-10-23 10:00	454168	----a-w-	c:\windows\system32\drivers\vsdatant.sys
2013-10-23 08:20 . 2011-04-08 03:36	6669600	----a-w-	c:\windows\system32\nvcpl.dll
2013-10-23 08:20 . 2011-04-08 03:35	3489568	----a-w-	c:\windows\system32\nvsvc64.dll
2013-10-23 08:20 . 2011-04-08 03:37	63776	----a-w-	c:\windows\system32\nvshext.dll
2013-10-23 08:20 . 2011-04-08 03:37	2559776	----a-w-	c:\windows\system32\nvsvcr.dll
2013-10-23 08:20 . 2011-04-08 03:37	219424	----a-w-	c:\windows\system32\nvmctray.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Eintr�ge & legitime Standardeintr�ge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{080760C8-FE0A-098C-7183-3254957E24C5}]
2012-11-22 00:18	425984	----a-w-	c:\program files (x86)\YoutubeAdblocker\e01v5Gfx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41E98610-8710-C589-9CF8-7C241B467713}]
2013-11-22 00:18	425984	----a-w-	c:\program files (x86)\SearchNewTab\GTEvONtDLJ.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{4727D7CC-F9B0-8EA1-53F0-C8CDA77ABBD5}]
2012-11-22 00:18	425984	----a-w-	c:\program files (x86)\surf Annd keep\f3gNkxOJUU.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	131248	----a-w-	c:\users\Booxi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	131248	----a-w-	c:\users\Booxi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	131248	----a-w-	c:\users\Booxi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	131248	----a-w-	c:\users\Booxi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm"="c:\program files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2013-10-25 73832]
"ModeSwitch"="c:\program files\Lenovo\Power Dial\LitModeSwitch.exe" [2010-09-26 163840]
"RUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe" [2011-09-20 115048]
.
c:\users\Booxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Booxi\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-11-9 29770248]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 JME Keyboard;JME Keyboard Driver;c:\windows\jmesoft\Service.exe;c:\windows\jmesoft\Service.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 NvnUsbAudio;Novation USB Audio Driver;c:\windows\system32\DRIVERS\nvnusbaudio.sys;c:\windows\SYSNATIVE\DRIVERS\nvnusbaudio.sys [x]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys;c:\windows\SYSNATIVE\pwdrvio.sys [x]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys;c:\windows\SYSNATIVE\pwdspio.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe;c:\program files (x86)\Tunngle\TnglCtrl.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
R4 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S0 WinI2C-DDC;WinI2C-DDC Kernel Mode Driver;c:\windows\system32\drivers\DDCDrv.sys;c:\windows\SYSNATIVE\drivers\DDCDrv.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel� PROSet Monitoring Service;Intel� PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x]
S2 LenovoCOMSvc;LenovoCOMService;c:\program files\Lenovo\Power Dial\LenovoCOMSvc.exe;c:\program files\Lenovo\Power Dial\LenovoCOMSvc.exe [x]
S2 ZAPrivacyService;ZoneAlarm Privacy Service;c:\program files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe;c:\program files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [x]
S3 automap;Automap MIDI Driver;c:\windows\system32\DRIVERS\automap.sys;c:\windows\SYSNATIVE\DRIVERS\automap.sys [x]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x]
S3 LADF_CaptureOnly;LADF Capture Filter Driver;c:\windows\system32\DRIVERS\ladfGSCamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSCamd64.sys [x]
S3 LADF_RenderOnly;LADF Render Filter Driver;c:\windows\system32\DRIVERS\ladfGSRamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSRamd64.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 LitModeCtrl;LitModeCtrl;c:\program files\Lenovo\Power Dial\LitModeCtrl.exe;c:\program files\Lenovo\Power Dial\LitModeCtrl.exe [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192Ce.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-19 20:01]
.
2013-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-19 20:01]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{080760C8-FE0A-098C-7183-3254957E24C5}]
2013-11-22 00:18	474624	----a-w-	c:\program files (x86)\YoutubeAdblocker\e01v5Gfx.x64.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41E98610-8710-C589-9CF8-7C241B467713}]
2013-11-22 00:18	474624	----a-w-	c:\program files (x86)\SearchNewTab\GTEvONtDLJ.x64.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4727D7CC-F9B0-8EA1-53F0-C8CDA77ABBD5}]
2012-11-22 00:18	474624	----a-w-	c:\program files (x86)\surf Annd keep\f3gNkxOJUU.x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	164016	----a-w-	c:\users\Booxi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	164016	----a-w-	c:\users\Booxi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	164016	----a-w-	c:\users\Booxi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	164016	----a-w-	c:\users\Booxi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-08-01 8290584]
.
------- Zus�tzlicher Suchlauf -------
.
uStart Page = hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
TCP: Interfaces\{E8059CE8-DE59-4EAC-A0F2-261E180BD0C2}: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\
FF - prefs.js: browser.search.defaulturl - hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42&l=1&q=
FF - prefs.js: browser.startup.homepage - hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42
FF - prefs.js: keyword.URL - hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42&l=1&q=
FF - ExtSQL: 2013-11-15 02:16; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-11-15 03:23; adblockpopups@jessehakanen.net; c:\users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\extensions\adblockpopups@jessehakanen.net.xpi
FF - ExtSQL: 2013-11-21 05:36; {DDC359D1-844A-42a7-9AA1-88A850A938A8}; c:\users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
FF - ExtSQL: 2013-11-22 01:18; e00j-twsm@g-ocjhyor-.org; c:\users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\extensions\e00j-twsm@g-ocjhyor-.org
FF - user.js: extensions.zonealarm.hpOld0 - 
FF - user.js: extensions.zonealarm.tlbrSrchUrl - hxxp://search.zonealarm.com/search?src=tb&tbid=goughGA&Lan={dfltLng}&gu=452c1b91a22a47f09f071950a28172a3&tu=10G9y00B41C01g0&sku=&tstsId=&ver=&&q=
FF - user.js: extensions.zonealarm.id - 20b0ed1900000000000000ffbcc382bd
FF - user.js: extensions.zonealarm.appId - {C56C48A0-DA4E-46F6-9859-1553DC865F84}
FF - user.js: extensions.zonealarm.instlDay - 16026
FF - user.js: extensions.zonealarm.vrsn - 1.8.22.0
FF - user.js: extensions.zonealarm.vrsni - 1.8.22.0
FF - user.js: extensions.zonealarm.vrsnTs - 1.8.22.019:09
FF - user.js: extensions.zonealarm.prtnrId - checkpoint
FF - user.js: extensions.zonealarm.prdct - zonealarm
FF - user.js: extensions.zonealarm.aflt - 1001
FF - user.js: extensions.zonealarm.smplGrp - none
FF - user.js: extensions.zonealarm.tlbrId - goughGA
FF - user.js: extensions.zonealarm.instlRef - ZLN120638738563127-1001
FF - user.js: extensions.zonealarm.dfltLng - de
FF - user.js: extensions.zonealarm.excTlbr - false
FF - user.js: extensions.zonealarm.ffxUnstlRst - false
FF - user.js: extensions.zonealarm.admin - false
FF - user.js: extensions.zonealarm.autoRvrt - false
FF - user.js: extensions.zonealarm.rvrt - false
FF - user.js: extensions.zonealarm.hmpg - true
FF - user.js: extensions.zonealarm.hmpgUrl - hxxp://search.zonealarm.com/?src=hp&tbid=goughGA&Lan=de&gu=452c1b91a22a47f09f071950a28172a3&tu=10G9y00B41C01g0&sku=&tstsId=&ver=&
FF - user.js: extensions.zonealarm.dfltSrch - true
FF - user.js: extensions.zonealarm.srchPrvdr - Search By ZoneAlarm
FF - user.js: extensions.zonealarm.kw_url - hxxp://search.zonealarm.com/search?src=sp&tbid=goughGA&Lan=de&gu=452c1b91a22a47f09f071950a28172a3&tu=10G9y00B41C01g0&sku=&tstsId=&ver=&&q=
FF - user.js: extensions.zonealarm.dnsErr - true
FF - user.js: extensions.zonealarm.newTab - true
FF - user.js: extensions.zonealarm.newTabUrl - hxxp://search.zonealarm.com/?src=nt&tbid=goughGA&Lan=de&gu=452c1b91a22a47f09f071950a28172a3&tu=10G9y00B41C01g0&sku=&tstsId=&ver=&
FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=20b0ed1900000000000000ffbcc382bd&q=
FF - user.js: extensions.Softonic.id - 20b0ed1900000000000000ffbcc382bd
FF - user.js: extensions.Softonic.appId - {7ABBFE1C-E485-44AA-8F36-353751B4124D}
FF - user.js: extensions.Softonic.instlDay - 16026
FF - user.js: extensions.Softonic.vrsn - 1.8.21.14
FF - user.js: extensions.Softonic.vrsni - 1.8.21.14
FF - user.js: extensions.Softonic.vrsnTs - 1.8.21.1419:33
FF - user.js: extensions.Softonic.prtnrId - softonic
FF - user.js: extensions.Softonic.prdct - Softonic
FF - user.js: extensions.Softonic.aflt - OC
FF - user.js: extensions.Softonic.smplGrp - none
FF - user.js: extensions.Softonic.tlbrId - opencandy2013
FF - user.js: extensions.Softonic.instlRef - MOY00621
FF - user.js: extensions.Softonic.dfltLng - de
FF - user.js: extensions.Softonic.excTlbr - false
FF - user.js: extensions.Softonic.ffxUnstlRst - false
FF - user.js: extensions.Softonic.admin - false
FF - user.js: extensions.Softonic.autoRvrt - false
FF - user.js: extensions.Softonic.rvrt - false
FF - user.js: extensions.Softonic.hmpg - true
FF - user.js: extensions.Softonic.hmpgUrl - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=20b0ed1900000000000000ffbcc382bd
FF - user.js: extensions.Softonic.dfltSrch - true
FF - user.js: extensions.Softonic.srchPrvdr - Search the web (Softonic)
FF - user.js: extensions.Softonic.dnsErr - true
FF - user.js: extensions.Softonic.newTab - true
FF - user.js: extensions.Softonic.newTabUrl - hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=20b0ed1900000000000000ffbcc382bd
.
- - - - Entfernte verwaiste Registrierungseintr�ge - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
AddRemove-{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} - c:\programdata\SearchNewTab\hOrCWWUBnly.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-11-24  17:48:13
ComboFix-quarantined-files.txt  2013-11-24 16:48
.
Vor Suchlauf: 11 Verzeichnis(se), 13.423.951.872 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 19.050.680.320 Bytes frei
.
- - End Of File - - 39D5B96FFB2E51D38642A9BFFE1133E6
         
--- --- ---

Alt 25.11.2013, 07:23   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 25.11.2013, 13:53   #11
Reclaimbux
 
Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Nach dem durchführen der schritte, dauert es bis zu20 sek das bis das kontextmenu ,beim rechtsklicken auf dem desktop erscheint

Code:
ATTFilter

�� Malwarebytes Anti-Malware  (Test) 1.75.0.1300

www.malwarebytes.org



Datenbank Version: v2013.11.24.11



Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

Booxi :: BIOHAZARD [Administrator]



Schutz: Aktiviert



25.11.2013 13:06:17

malwarebytes log.txt



Art des Suchlaufs: Vollst�ndiger Suchlauf (C:\|D:\|)

Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM

Deaktivierte Suchlaufeinstellungen: P2P

Durchsuchte Objekte: 682023

Laufzeit: 1 Stunde(n), 5 Minute(n), 50 Sekunde(n)



Infizierte Speicherprozesse: 0

(Keine b�sartigen Objekte gefunden)



Infizierte Speichermodule: 0

(Keine b�sartigen Objekte gefunden)



Infizierte Registrierungsschl�ssel: 12

HKCR\CLSID\{080760C8-FE0A-098C-7183-3254957E24C5} (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{080760C8-FE0A-098C-7183-3254957E24C5} (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{080760C8-FE0A-098C-7183-3254957E24C5} (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{080760C8-FE0A-098C-7183-3254957E24C5} (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{080760C8-FE0A-098C-7183-3254957E24C5} (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

HKCR\CLSID\{41E98610-8710-C589-9CF8-7C241B467713} (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41E98610-8710-C589-9CF8-7C241B467713} (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{41E98610-8710-C589-9CF8-7C241B467713} (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{41E98610-8710-C589-9CF8-7C241B467713} (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{41E98610-8710-C589-9CF8-7C241B467713} (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A) -> Keine Aktion durchgef�hrt.

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} (PUP.Optional.WebSearchInfo) -> Keine Aktion durchgef�hrt.



Infizierte Registrierungswerte: 0

(Keine b�sartigen Objekte gefunden)



Infizierte Dateiobjekte der Registrierung: 2

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.WebSearchInfo) -> B�sartig: (hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42) Gut: (hxxp://www.google.com) -> Keine Aktion durchgef�hrt.

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.WebSearchInfo) -> B�sartig: (hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42) Gut: (hxxp://www.google.com) -> Keine Aktion durchgef�hrt.



Infizierte Verzeichnisse: 7

C:\Users\Booxi\Documents\Optimizer Pro (PUP.Optional.OptimizerPro.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\Documents\PCSpeedUp (PUP.Optional.PCSpeedUp.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\Documents\PCSpeedUp\RestorePoints (PUP.Optional.PCSpeedUp.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\Documents\PCSpeedUp\ScanResults (PUP.Optional.PCSpeedUp.A) -> Keine Aktion durchgef�hrt.

C:\Program Files (x86)\SearchNewTab (PUP.Optional.SearchNewTab.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\AppData\Roaming\OpenCandy\C6B5C80EF6974FBEBF4F945892E75690 (PUP.Optional.OpenCandy) -> Keine Aktion durchgef�hrt.



Infizierte Dateien: 19

C:\Program Files (x86)\YoutubeAdblocker\e01v5Gfx.dll (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

C:\Program Files (x86)\SearchNewTab\GTEvONtDLJ.dll (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-saudi-forf.exe (PUP.Optional.Hao123.A) -> Keine Aktion durchgef�hrt.

C:\Program Files (x86)\SearchNewTab\GTEvONtDLJ.x64.dll (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

C:\Program Files (x86)\YoutubeAdblocker\e01v5Gfx.x64.dll (PUP.Optional.MultiPlug.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FTAKZX96\minibar-core[1].exe (PUP.Optional.MiniBar.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\AppData\Local\Temp\appshat-distribution.exe (PUP.Optional.Somoto.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\AppData\Local\Temp\OptimizerPro.exe (PUP.Optional.OptimizerPro.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\AppData\Local\Temp\UpdateCheckerSetup.exe (PUP.Optional.Somoto) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\Downloads\SoftonicDownloader_fuer_website-ripper-copier.exe (PUP.Optional.Softonic.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\Downloads\UnlockRoot_downloader_by_UnlockRoot.exe (PUP.Optional.Somoto) -> Keine Aktion durchgef�hrt.

D:\usb\Mugen\Ableton Install\AbLS.v8.3.Win\Ableton.Live.Suite.v8.3.Win\ableton.suite.8.3-osx_win-patches\win\ableton.suite.8.3-patch.exe (PUP.RiskwareTool.CK) -> Keine Aktion durchgef�hrt.

D:\usb\Mugen\Addons\VST\Hosts\DarkWave-Studio-Web-Setup.exe (PUP.Optional.Somoto) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\Documents\Optimizer Pro\CookiesException.txt (PUP.Optional.OptimizerPro.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\Documents\PCSpeedUp\App.log (PUP.Optional.PCSpeedUp.A) -> Keine Aktion durchgef�hrt.

C:\Program Files (x86)\SearchNewTab\GTEvONtDLJ.tlb (PUP.Optional.SearchNewTab.A) -> Keine Aktion durchgef�hrt.

C:\Program Files (x86)\SearchNewTab\GTEvONtDLJ.dat (PUP.Optional.SearchNewTab.A) -> Keine Aktion durchgef�hrt.

C:\Users\Booxi\AppData\Roaming\OpenCandy\C6B5C80EF6974FBEBF4F945892E75690\Setupsft_chr_p1v7.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgef�hrt.



(Ende)
         
Log adw cleaner
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v3.013 - Bericht erstellt am 25/11/2013 um 14:30:09
# Updated 24/11/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Booxi - BIOHAZARD
# Gestartet von : C:\Users\Booxi\Downloads\adwcleaner313.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\boost_interprocess
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\QuickSet
Ordner Gelöscht : C:\ProgramData\YoutubeAdblocker
Ordner Gelöscht : C:\Program Files (x86)\YoutubeAdblocker
Ordner Gelöscht : C:\Users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf
Ordner Gelöscht : C:\Users\Booxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpcknfcdcgpffjddjeceioobdelceffo
Datei Gelöscht : C:\windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\searchplugins\softonic.xml
Datei Gelöscht : C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\searchplugins\WebSearch.xml
Datei Gelöscht : C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\searchplugins\zonealarm.xml
Datei Gelöscht : C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\user.js

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskPIP_FF__RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskPIP_FF__RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_website-ripper-copier_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_website-ripper-copier_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\SP Global
Schlüssel Gelöscht : HKLM\Software\SProtector

***** [ Browser ] *****

-\\ Internet Explorer v9.0.8112.16421


-\\ Mozilla Firefox v25.0.1 (de)

[ Datei : C:\Users\Booxi\AppData\Roaming\Mozilla\Firefox\Profiles\l8inr44o.default\prefs.js ]

Zeile gelöscht : user_pref("aol_toolbar.default.homepage.check", false);
Zeile gelöscht : user_pref("aol_toolbar.default.search.check", false);
Zeile gelöscht : user_pref("browser.download.lastDir", "Z:\\winamp own\\skins");
Zeile gelöscht : user_pref("browser.search.defaultenginename,S", "WebSearch");
Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42&l=1&q=");
Zeile gelöscht : user_pref("browser.search.order.1", "WebSearch");
Zeile gelöscht : user_pref("browser.search.order.1,S", "WebSearch");
Zeile gelöscht : user_pref("browser.search.selectedEngine,S", "WebSearch");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Zeile gelöscht : user_pref("extensions.Softonic.admin", false);
Zeile gelöscht : user_pref("extensions.Softonic.aflt", "OC");
Zeile gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");
Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.Softonic.dfltSrch", true);
Zeile gelöscht : user_pref("extensions.Softonic.dnsErr", true);
Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false);
Zeile gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false);
Zeile gelöscht : user_pref("extensions.Softonic.hmpg", true);
Zeile gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=20b0ed1900000000000000ffbcc382bd");
Zeile gelöscht : user_pref("extensions.Softonic.id", "20b0ed1900000000000000ffbcc382bd");
Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "16026");
Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00621");
Zeile gelöscht : user_pref("extensions.Softonic.newTab", true);
Zeile gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=20b0ed1900000000000000ffbcc382bd");
Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic");
Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic");
Zeile gelöscht : user_pref("extensions.Softonic.rvrt", "false");
Zeile gelöscht : user_pref("extensions.Softonic.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "opencandy2013");
Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=20b0ed1900000000000000ffbcc382bd&q=");
Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.21.14");
Zeile gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.21.1419:33:38");
Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.21.14");
Zeile gelöscht : user_pref("extensions.dta.directory", "[\"Z:\\\\winamp own\\\\test\\\\\"]");
Zeile gelöscht : user_pref("extensions.kango.storage.m2_k1", "0");
Zeile gelöscht : user_pref("extensions.kango.storage.m2_k2", "0");
Zeile gelöscht : user_pref("extensions.kango.storage.m2_k3", "0");
Zeile gelöscht : user_pref("extensions.kango.storage.m2_k4", "1385483006197");
Zeile gelöscht : user_pref("extensions.kango.storage.m2_k5", "1385340915601");
Zeile gelöscht : user_pref("extensions.kango.storage.minibar.config", "{\"name\":\"Apps Hat\",\"description\":\"Apps Hat\",\"button\":{\"tooltip\":\"Visit AppsHat.com\",\"icon\":\"hxxp://www.bigspeedpro.com/button/%af[...]
Zeile gelöscht : user_pref("extensions.kango.storage.nero_options", "\"{\\\"m1\\\":{\\\"ads\\\":{\\\"n1\\\":{\\\"url\\\":\\\"//ulayout.com/nero/hatter/google_post_results_728x90.html?aff_slug=appshat\\\",\\\"width\\\"[...]
Zeile gelöscht : user_pref("extensions.kango.storage.ui.button.iconCache", "\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABMAAAATCAYAAAByUDbMAAADlElEQVQ4jb3S3U9adxwG8F/BuooQAQscXj0cOIC8nANUPYjoHDClvqAoZ04gpqsZKmrUV[...]
Zeile gelöscht : user_pref("keyword.URL", "hxxp://websearch.searchbomb.info/?pid=377&r=2013/11/22&hid=1877117274471378197&lg=EN&cc=DE&unqvl=42&l=1&q=");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.enable", "");

*************************

AdwCleaner[R0].txt - [9303 octets] - [25/11/2013 14:29:14]
AdwCleaner[S0].txt - [9092 octets] - [25/11/2013 14:30:09]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9152 octets] ##########
         
--- --- ---

Log jrt

JRT Logfile:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by Booxi on 25.11.2013 at 14:40:23,67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\appshat-distribution_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\appshat-distribution_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\Softonic_chr_1_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\Softonic_chr_1_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0FBE57CA-2243-4537-842F-F5092BDE3003}



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted the following from C:\Users\Booxi\AppData\Roaming\mozilla\firefox\profiles\l8inr44o.default\prefs.js

user_pref("extensions.qaqeMjcQo2.url", "hxxp://getjpit.info/sync2/?q=hfZ9ofV9CShEAen0rHC6tMqLDe49CNU0mwkMCMlNhd9FrHwFrTsErdw5rjaMBzqUojwHrjwGrTaErjY9qSh7hfs0pihPBMn0rjr5pjn5rH
Emptied folder: C:\Users\Booxi\AppData\Roaming\mozilla\firefox\profiles\l8inr44o.default\minidumps [6 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.11.2013 at 14:42:54,78
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
--- --- ---

Alt 26.11.2013, 09:08   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 26.11.2013, 19:14   #13
Reclaimbux
 
Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Sorry doppelpost

Alt 27.11.2013, 10:58   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Doppelpost?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 28.11.2013, 13:45   #15
Reclaimbux
 
Pc gibt komischen Ton über die Boxen aus - Standard

Pc gibt komischen Ton über die Boxen aus



Ja schreibe die ganze zeit über mein tablet.... Und es war mir entgangen, dass es bereits eine zweite seite gibt, und da hatte ich nochmals die logs reingeschrieben.....

Habe ich rechtzeitig erkannt. Und nu wegeditiert logs kommen auch sobals ich wieder am rechner sitze

Antwort

Themen zu Pc gibt komischen Ton über die Boxen aus
64bit, beseitigen, boxen, eigener, geräusch, gewisse, headset, komische, minute, neu, partition, problem, programm, programme, rechner, recovery, schei, sound, soundkarte, soundkarten, usb, vernünftig, verschiedene, windows, wireless



Ähnliche Themen: Pc gibt komischen Ton über die Boxen aus


  1. Computer gibt bei Internetverbindung komisches Geräusch über die Lautsprecher aus
    Plagegeister aller Art und deren Bekämpfung - 07.10.2014 (6)
  2. Geräusche im Hintergrund aus den Boxen bei eingeschalteten PC
    Plagegeister aller Art und deren Bekämpfung - 15.03.2014 (29)
  3. bilder mit komischen dateinamen
    Log-Analyse und Auswertung - 19.09.2012 (1)
  4. Knistern/rauschen in den pc boxen
    Alles rund um Windows - 07.04.2010 (3)
  5. ICQ Virus über Account den es nicht gibt ?
    Plagegeister aller Art und deren Bekämpfung - 12.02.2010 (2)
  6. Google gibt Kunden Auskunft über ihre Daten
    Nachrichten - 05.11.2009 (0)
  7. Boxen für iPod
    Netzwerk und Hardware - 07.09.2009 (5)
  8. boxen machen immer ein piep geräusch
    Plagegeister aller Art und deren Bekämpfung - 08.08.2008 (16)
  9. Pc hängt und piepen über boxen
    Netzwerk und Hardware - 02.06.2008 (9)
  10. Lachen in den Boxen
    Plagegeister aller Art und deren Bekämpfung - 03.01.2007 (5)
  11. Sound, obwohl Boxen ausgeschaltet sind
    Alles rund um Windows - 25.07.2006 (4)
  12. Schüsse aus den PC-Boxen ???
    Plagegeister aller Art und deren Bekämpfung - 09.03.2006 (3)
  13. es knackt in den boxen nach dem booten
    Plagegeister aller Art und deren Bekämpfung - 15.02.2006 (4)
  14. Problem mit easy-search und Message Boxen
    Log-Analyse und Auswertung - 18.04.2005 (3)
  15. Hilfe, komischen Sachen!!!
    Log-Analyse und Auswertung - 19.11.2004 (1)
  16. [B]Festplatte über Trojaner Festplatte gekapert? Gibt´s denn sowas?[/B]
    Plagegeister aller Art und deren Bekämpfung - 27.09.2004 (3)
  17. über ein Prog das es scheinbar nicht gibt aber ins Netz will ???????
    Archiv - 22.01.2003 (6)

Zum Thema Pc gibt komischen Ton über die Boxen aus - Hallo, Ich habe seit ein paar Tagen das Problem, dass mein Rechner scheinbar willkürlich Sound aus den Boxen wiedergibt. Eine Art Wobblesound Dieser Tritt in gewissen Zeitabständen immer wieder auf. - Pc gibt komischen Ton über die Boxen aus...
Archiv
Du betrachtest: Pc gibt komischen Ton über die Boxen aus auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.