![]() |
|
Plagegeister aller Art und deren Bekämpfung: PC bereinigen und schneller machenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() PC bereinigen und schneller machen Hallo Leute, mein PC ist zur Zeit sehr langsam. Ich hatte einen defekten Windows Installer und musste eine Reparaturinstallation alias Inplace-Upgrade durchführen. Der Installer funktioniert nun wieder, nur leider ist mein Rechner seitdem sehr langsam. Außerdem habe ich höchstwahrscheinlich einige Dateien/Programme auf dem Rechner, die kein Mensch braucht und würde daher gerne den PC bereinigen. Habe mir bereits FRST 64-Bit runtergeladen und einen Scan durchgeführt. Die Logdateien stehen unten. Hoffe, es kann mir jemand helfen. LG Tweety FRST.txt FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-12-2013 01 Ran by Jacky (administrator) on JACKY-PC on 30-12-2013 16:43:06 Running from C:\Users\Jacky\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe () C:\Windows\System32\dmwu.exe (RealNetworks, Inc.) C:\Program Files (x86)\Online Games Manager\ogmservice.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (GamersFirst) C:\Users\Jacky\AppData\Local\GamersFirst\LIVE!\Live.exe (Windows Net) C:\Users\Jacky\AppData\Roaming\Windows Net Data\net.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe () C:\Windows\SysWOW64\jmdp\stij.exe () C:\Windows\System32\ljkb\stij.exe (Sonic Solutions) C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_170_ActiveX.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup HKLM-x32\...\Run: [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start HKLM-x32\...\Run: [RoxWatchTray] - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [221184 2006-10-27] (Sonic Solutions) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-13] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Policies\Explorer: [DisallowRun] 1 AppInit_DLLs: [ ] () AppInit_DLLs-x32: [ ] () Startup: C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk ShortcutTarget: GamersFirst LIVE!.lnk -> C:\Users\Jacky\AppData\Local\GamersFirst\LIVE!\Live.exe (GamersFirst) Startup: C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Jacky\AppData\Roaming\Windows Net Data\net.exe (Windows Net) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184962 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x27FEC7DD7524CE01 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184962 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184962 URLSearchHook: HKCU - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184963&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184963&type=default&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=362&systemid=406&v=a9396-116&apn_uid=4138502541114806&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184963&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000520AS_5VX2N6AXXXXX5VX2N6AX&ts=1382184963&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=362&systemid=406&v=a9396-116&apn_uid=4138502541114806&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10039&barid={0F0CAE4C-B87A-11E2-A126-8C89A599A6F8} SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_uid=4138502541114806&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=120519&babsrc=SP_ss&mntrId=56B78C89A599A6F8 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_uid=4138502541114806&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/?a=6PR8dQeNuD&loc=skw&search={searchTerms} SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={0F0CAE4C-B87A-11E2-A126-8C89A599A6F8}&crg=3.1010000.10039&st=23 BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Search-Results Toolbar - {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll No File BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: No Name - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM-x32 - Search-Results Toolbar - {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll No File Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default FF user.js: detected! => C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\user.js FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\dokotoolbar.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\iminent.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\MyStart Search.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\Search_Results.xml FF SearchPlugin: C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\searchplugins\SweetIM Search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\qvo6.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Amazon-Icon - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\amazon-icon@giga.de FF Extension: pricealarm - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM FF Extension: dokotoolbar.com - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\ffxtlbr@dokotoolbar.com FF Extension: Spartipps von SparPilot.com - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\sparpilot@sparpilot.com FF Extension: ReloadEvery - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi FF Extension: New Tab - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{C4A4F5A0-4B89-4392-AFAC-D58010E349AF}.xpi FF Extension: BonanzaDeals - C:\Users\Jacky\AppData\Roaming\Mozilla\Firefox\Profiles\0tw6hpe0.default\Extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}.xpi FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR Extension: (Price Alarm) - C:\Users\Jacky\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [ieadcoanfjloocmfafkebdnfefmohngj] - C:\Program Files (x86)\BonanzaDeals\BonanzaDeals.crx CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Jacky\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1833776 2013-12-29] () R2 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [559552 2013-08-08] (RealNetworks, Inc.) ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-09-07] () R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-10-10] (Kaspersky Lab ZAO) S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-19] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-04-24] (Kaspersky Lab ZAO) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-09-07] () S1 RxFilter; C:\Windows\SysWow64\DRIVERS\RxFilter.sys [58880 2006-10-27] (Sonic Solutions) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-30 16:43 - 2013-12-30 16:43 - 00022432 _____ C:\Users\Jacky\Desktop\FRST.txt 2013-12-30 16:42 - 2013-12-30 16:42 - 00000000 ____D C:\FRST 2013-12-30 16:40 - 2013-12-30 16:41 - 01931302 _____ (Farbar) C:\Users\Jacky\Desktop\FRST64.exe 2013-12-30 13:21 - 2013-12-30 13:22 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele Dirk 2013-12-30 13:21 - 2013-12-30 13:22 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele 2013-12-30 09:45 - 2013-12-30 09:45 - 00000000 ____D C:\Windows\PCHEALTH 2013-12-30 09:45 - 2010-02-23 09:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe 2013-12-30 09:44 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2013-12-30 09:44 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2013-12-30 09:44 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2013-12-30 09:44 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2013-12-30 09:44 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2013-12-30 09:44 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2013-12-30 09:43 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2013-12-30 09:43 - 2012-03-01 07:38 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-12-30 09:43 - 2012-03-01 07:33 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-30 09:43 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2013-12-30 09:43 - 2012-03-01 06:37 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-12-30 09:43 - 2012-03-01 06:33 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-30 09:43 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2013-12-30 09:35 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-12-30 09:35 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-12-30 09:35 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-12-30 09:35 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-12-30 09:35 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-12-30 09:35 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2013-12-30 09:35 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2013-12-30 09:34 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-12-30 09:15 - 2011-11-19 15:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2013-12-30 09:15 - 2011-11-19 15:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2013-12-30 05:16 - 2013-12-29 21:19 - 00000000 ____D C:\Windows\Panther 2013-12-30 05:15 - 2013-12-30 05:15 - 00262144 _____ C:\Windows\system32\config\userdiff 2013-12-30 04:55 - 2013-12-29 21:03 - 00000000 ___HD C:\$WINDOWS.~Q 2013-12-30 04:48 - 2013-12-30 04:51 - 00000000 ___HD C:\$INPLACE.~TR 2013-12-29 23:36 - 2013-12-29 23:36 - 00000000 ____D C:\Program Files\Windows XP Mode 2013-12-29 23:25 - 2013-12-29 23:35 - 486678800 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsXPMode_de-de.exe 2013-12-29 23:23 - 2013-12-29 23:23 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(4).exe 2013-12-29 23:11 - 2013-12-30 12:10 - 00000000 ___RD C:\Users\Jacky\Virtual Machines 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\th-TH 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ro-RO 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\he-IL 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ar-SA 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Program Files (x86)\Windows Virtual PC 2013-12-29 23:01 - 2010-11-20 14:34 - 00360832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcvmm.sys 2013-12-29 23:01 - 2010-11-20 14:34 - 00194944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpchbus.sys 2013-12-29 23:01 - 2010-11-20 14:27 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\vpchbuspipe.dll 2013-12-29 23:01 - 2010-11-20 14:25 - 04514816 _____ (Microsoft Corporation) C:\Windows\system32\vpc.exe 2013-12-29 23:01 - 2010-11-20 14:25 - 02264064 _____ (Microsoft Corporation) C:\Windows\system32\VPCWizard.exe 2013-12-29 23:01 - 2010-11-20 14:25 - 01369600 _____ (Microsoft Corporation) C:\Windows\system32\VPCSettings.exe 2013-12-29 23:01 - 2010-11-20 12:37 - 01210368 _____ (Microsoft Corporation) C:\Windows\system32\VMWindow.exe 2013-12-29 23:01 - 2010-11-20 12:37 - 00936448 _____ (Microsoft Corporation) C:\Windows\system32\vmsal.exe 2013-12-29 23:01 - 2010-11-20 12:35 - 00562176 _____ (Microsoft Corporation) C:\Windows\system32\VMCPropertyHandler.dll 2013-12-29 23:01 - 2010-11-20 12:35 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcusb.sys 2013-12-29 23:01 - 2010-11-20 12:35 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcnfltr.sys 2013-12-29 23:01 - 2010-11-20 11:52 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vmsal.exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(3).exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(2).exe 2013-12-29 21:36 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2013-12-29 21:36 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2013-12-29 21:36 - 2012-02-17 05:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2013-12-29 21:36 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2013-12-29 21:33 - 2013-12-29 21:33 - 09566298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-12-29 21:24 - 2013-12-29 21:24 - 00125128 _____ C:\Users\Jacky\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-29 21:22 - 2013-12-29 21:22 - 00001413 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-12-29 21:21 - 2013-12-29 21:22 - 00001447 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-29 21:21 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-12-29 21:21 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-12-29 21:21 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-12-29 21:21 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-12-29 21:20 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-12-29 21:20 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-12-29 21:20 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-12-29 21:19 - 2013-12-29 21:19 - 00000020 ___SH C:\Users\Jacky\ntuser.ini 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-12-29 21:16 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-12-29 21:16 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-12-29 21:13 - 2013-12-30 15:34 - 01964127 _____ C:\Windows\WindowsUpdate.log 2013-12-29 20:59 - 2013-12-29 20:59 - 00022960 _____ C:\Windows\system32\emptyregdb.dat 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-12-29 20:31 - 2013-12-29 23:11 - 00000000 ____D C:\Users\Jacky 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Vorlagen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Startmenü 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Netzwerkumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Lokale Einstellungen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Eigene Dateien 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Druckumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Musik 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Bilder 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Verlauf 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Anwendungsdaten 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Anwendungsdaten 2013-12-29 20:31 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:31 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:30 - 2013-12-29 20:30 - 00001355 _____ C:\Windows\TSSysprep.log 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-12-29 19:25 - 2013-12-29 21:03 - 00006155 _____ C:\Windows\comsetup.log 2013-12-29 18:57 - 2013-12-29 19:04 - 00013897 _____ C:\Windows\diagwrn.xml 2013-12-29 18:57 - 2013-12-29 19:04 - 00001890 _____ C:\Windows\diagerr.xml 2013-12-29 16:17 - 2013-12-29 20:42 - 00000000 ____D C:\Windows\SysWOW64\jmdp 2013-12-29 16:17 - 2013-12-29 20:42 - 00000000 ____D C:\Windows\system32\ljkb 2013-12-29 16:17 - 2013-12-29 20:42 - 00000000 ____D C:\Windows\pss 2013-12-29 15:37 - 2013-12-30 16:37 - 00000290 _____ C:\Windows\Tasks\Bonanza.job 2013-12-29 15:37 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Bonanza 2013-12-29 15:37 - 2013-12-29 15:37 - 00003226 _____ C:\Windows\System32\Tasks\Bonanza 2013-12-29 13:36 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.technic 2013-12-29 13:36 - 2013-12-29 13:36 - 02304092 _____ () C:\Users\Jacky\Downloads\TechnicLauncher.exe 2013-12-29 10:15 - 2013-12-29 10:15 - 02014840 _____ (DriverBoost) C:\Users\Jacky\Downloads\DriverBoostPro_Setup.exe 2013-12-29 10:12 - 2013-12-29 10:12 - 08054042 _____ C:\Users\Jacky\Downloads\windowsinstaller45(1).zip 2013-12-28 21:42 - 2013-12-28 21:44 - 63443792 _____ C:\Users\Jacky\Downloads\thegameoflifedownload.exe 2013-12-26 21:59 - 2013-12-26 22:00 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-12-26 20:37 - 2013-12-26 20:37 - 00401784 _____ (Softonic ) C:\Users\Jacky\Downloads\SoftonicDownloader_fuer_windows-installer-clean-up.exe 2013-12-26 19:39 - 2013-12-26 19:39 - 02585872 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsInstaller-KB893803-v2-x86.exe 2013-12-26 11:19 - 2013-12-29 20:36 - 00000000 ____D C:\Program Files (x86)\directx 2013-12-26 11:19 - 2013-12-26 11:19 - 00000278 _____ C:\Windows\Directx.log 2013-12-25 21:07 - 2013-12-29 20:41 - 00000000 ____D C:\ProgramData\Windows Genuine Advantage 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck.exe 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(1).exe 2013-12-25 20:59 - 2013-12-25 20:59 - 02311827 _____ C:\Users\Jacky\Downloads\sdl3ewin.zip 2013-12-25 20:57 - 2013-12-25 20:57 - 00397154 _____ C:\Users\Jacky\Downloads\SpieldesLebensWin.zip 2013-12-25 20:53 - 2013-12-25 20:53 - 00002890 _____ C:\Windows\System32\Tasks\{E03E12C0-F94B-4CA6-A09A-515468D6FAA3} 2013-12-25 20:46 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Windows Net Data 2013-12-25 20:46 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp3f96eefeb2049202da2178bd45059162 2013-12-25 20:45 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\Downloads\Spiel-des-Lebens 2013-12-25 20:45 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\ChromeExtensions 2013-12-25 20:45 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp6ec2be2b619d18ef522057d14578d2f7 2013-12-25 20:45 - 2013-12-29 20:50 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp52da00fd457103be90f4c5f287980f49 2013-12-25 20:45 - 2013-12-25 20:45 - 00943872 _____ C:\Users\Jacky\Downloads\Spiel-des-Lebens-Setup.exe 2013-12-25 20:41 - 2013-12-25 20:41 - 00003018 _____ C:\Windows\System32\Tasks\{476505DD-F30E-4FF4-8920-CB14D92EB605} 2013-12-25 20:29 - 2013-12-25 20:29 - 00003018 _____ C:\Windows\System32\Tasks\{01014E7C-EF80-4994-94A4-7882BBE1FC4D} 2013-12-25 20:03 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Zylom 2013-12-25 20:03 - 2013-12-29 09:40 - 00000000 ____D C:\Users\Jacky\AppData\Local\Zylom Games 2013-12-25 16:26 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Das Spiel des Lebens 2013-12-25 16:26 - 2013-12-29 20:36 - 00000000 ____D C:\Program Files (x86)\Das Spiel des Lebens 2013-12-25 16:22 - 2013-12-25 16:22 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p200715036_s2_l2.exe 2013-12-25 16:19 - 2013-12-25 16:19 - 00002890 _____ C:\Windows\System32\Tasks\{D5C4E481-AC90-46F2-A2E0-FC0AF1374D57} 2013-12-21 13:39 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Realore_Whiterra Roads Of Rome 3 2013-12-20 10:03 - 2013-12-29 20:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-15 11:33 - 2013-12-29 20:41 - 00000000 ____D C:\ProgramData\Sony 2013-12-15 11:33 - 2013-12-29 20:39 - 00000000 ____D C:\Program Files (x86)\Sony 2013-12-15 11:33 - 2013-12-15 11:36 - 00181280 _____ C:\Windows\DPINST.LOG 2013-12-15 11:33 - 2013-12-15 11:33 - 00002106 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2013-12-12 00:27 - 2013-11-26 11:18 - 00004096 ____N (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-12 00:27 - 2013-11-26 10:46 - 00048640 ____N (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-12 00:27 - 2013-11-26 10:18 - 00111616 ____N (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-12 00:27 - 2013-11-26 10:16 - 00708608 ____N (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-12 00:27 - 2013-11-26 09:35 - 05769216 ____N (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 00:27 - 2013-11-26 09:28 - 00553472 ____N (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-12 00:27 - 2013-11-26 09:16 - 04243968 ____N (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-30 19:51 - 2013-12-29 20:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Das Koenigreich der Kobolde 2013-11-30 19:51 - 2013-12-29 20:35 - 00000000 ____D C:\Program Files (x86)\Awakening - Das Koenigreich der Kobolde 2013-11-30 19:40 - 2013-11-30 19:40 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p132398476_s2_l2(1).exe 2013-11-30 19:36 - 2013-11-30 19:36 - 00003150 _____ C:\Windows\System32\Tasks\{D9FF8CB0-8D45-4811-B5EE-E5A392CEF7CF} ==================== One Month Modified Files and Folders ======= 2013-12-30 16:43 - 2013-12-30 16:43 - 00022432 _____ C:\Users\Jacky\Desktop\FRST.txt 2013-12-30 16:42 - 2013-12-30 16:42 - 00000000 ____D C:\FRST 2013-12-30 16:41 - 2013-12-30 16:40 - 01931302 _____ (Farbar) C:\Users\Jacky\Desktop\FRST64.exe 2013-12-30 16:37 - 2013-12-29 15:37 - 00000290 _____ C:\Windows\Tasks\Bonanza.job 2013-12-30 15:46 - 2013-03-20 18:27 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-30 15:44 - 2013-05-22 16:18 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-30 15:34 - 2013-12-29 21:13 - 01964127 _____ C:\Windows\WindowsUpdate.log 2013-12-30 14:43 - 2013-03-18 20:52 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-12-30 13:33 - 2009-07-14 05:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-30 13:33 - 2009-07-14 05:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-30 13:26 - 2013-05-22 16:18 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-30 13:25 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-30 13:25 - 2009-07-14 05:51 - 00581851 _____ C:\Windows\setupact.log 2013-12-30 13:22 - 2013-12-30 13:21 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele Dirk 2013-12-30 13:22 - 2013-12-30 13:21 - 00000000 ____D C:\Users\Jacky\Desktop\Spiele 2013-12-30 13:22 - 2013-03-18 20:55 - 00000000 ___RD C:\Users\Jacky\Desktop\Jacky 2013-12-30 13:20 - 2013-08-25 09:18 - 00000000 ____D C:\Users\Jacky\Desktop\Die Sims 3 (Download) 2013-12-30 13:20 - 2013-07-29 18:31 - 00000000 ____D C:\Users\Jacky\Desktop\BigFish 2013-12-30 13:18 - 2013-05-22 16:18 - 00000000 ____D C:\Program Files (x86)\Google 2013-12-30 12:10 - 2013-12-29 23:11 - 00000000 ___RD C:\Users\Jacky\Virtual Machines 2013-12-30 12:06 - 2010-11-21 04:47 - 00015340 _____ C:\Windows\PFRO.log 2013-12-30 10:11 - 2013-03-19 18:33 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-30 09:54 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2013-12-30 09:54 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sl-SI 2013-12-30 09:45 - 2013-12-30 09:45 - 00000000 ____D C:\Windows\PCHEALTH 2013-12-30 08:59 - 2013-10-28 15:50 - 00000000 ____D C:\Program Files (x86)\Steam 2013-12-30 05:16 - 2009-07-14 06:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2013-12-30 05:16 - 2009-07-14 06:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2013-12-30 05:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\oobe 2013-12-30 05:15 - 2013-12-30 05:15 - 00262144 _____ C:\Windows\system32\config\userdiff 2013-12-30 04:51 - 2013-12-30 04:48 - 00000000 ___HD C:\$INPLACE.~TR 2013-12-29 23:36 - 2013-12-29 23:36 - 00000000 ____D C:\Program Files\Windows XP Mode 2013-12-29 23:35 - 2013-12-29 23:25 - 486678800 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsXPMode_de-de.exe 2013-12-29 23:23 - 2013-12-29 23:23 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(4).exe 2013-12-29 23:15 - 2011-05-16 16:16 - 00646378 _____ C:\Windows\system32\perfh01F.dat 2013-12-29 23:15 - 2011-05-16 16:16 - 00137204 _____ C:\Windows\system32\perfc01F.dat 2013-12-29 23:15 - 2011-05-16 16:03 - 00716756 _____ C:\Windows\system32\prfh0816.dat 2013-12-29 23:15 - 2011-05-16 16:03 - 00150122 _____ C:\Windows\system32\prfc0816.dat 2013-12-29 23:15 - 2011-05-16 15:55 - 00727012 _____ C:\Windows\system32\perfh015.dat 2013-12-29 23:15 - 2011-05-16 15:55 - 00151786 _____ C:\Windows\system32\perfc015.dat 2013-12-29 23:15 - 2011-05-16 15:47 - 00729558 _____ C:\Windows\system32\perfh013.dat 2013-12-29 23:15 - 2011-05-16 15:47 - 00149498 _____ C:\Windows\system32\perfc013.dat 2013-12-29 23:15 - 2011-05-16 15:39 - 00727436 _____ C:\Windows\system32\perfh010.dat 2013-12-29 23:15 - 2011-05-16 15:39 - 00143600 _____ C:\Windows\system32\perfc010.dat 2013-12-29 23:15 - 2011-05-16 15:31 - 00670640 _____ C:\Windows\system32\perfh00E.dat 2013-12-29 23:15 - 2011-05-16 15:31 - 00166482 _____ C:\Windows\system32\perfc00E.dat 2013-12-29 23:15 - 2011-05-16 15:25 - 00732362 _____ C:\Windows\system32\perfh00C.dat 2013-12-29 23:15 - 2011-05-16 15:25 - 00146270 _____ C:\Windows\system32\perfc00C.dat 2013-12-29 23:15 - 2011-05-16 15:17 - 00731974 _____ C:\Windows\system32\perfh00A.dat 2013-12-29 23:15 - 2011-05-16 15:17 - 00154536 _____ C:\Windows\system32\perfc00A.dat 2013-12-29 23:15 - 2011-05-16 15:11 - 00591216 _____ C:\Windows\system32\perfh008.dat 2013-12-29 23:15 - 2011-05-16 15:11 - 00106810 _____ C:\Windows\system32\perfc008.dat 2013-12-29 23:15 - 2011-05-16 15:04 - 00698006 _____ C:\Windows\system32\perfh007.dat 2013-12-29 23:15 - 2011-05-16 15:04 - 00148062 _____ C:\Windows\system32\perfc007.dat 2013-12-29 23:15 - 2011-05-16 14:58 - 00498524 _____ C:\Windows\system32\perfh006.dat 2013-12-29 23:15 - 2011-05-16 14:58 - 00095894 _____ C:\Windows\system32\perfc006.dat 2013-12-29 23:15 - 2009-07-14 06:13 - 09772048 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-29 23:11 - 2013-12-29 20:31 - 00000000 ____D C:\Users\Jacky 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\th-TH 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ro-RO 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\he-IL 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Windows\system32\Drivers\ar-SA 2013-12-29 23:06 - 2013-12-29 23:06 - 00000000 ____D C:\Program Files (x86)\Windows Virtual PC 2013-12-29 23:06 - 2011-05-16 16:15 - 00000000 ____D C:\Windows\system32\Drivers\tr-TR 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\th-TH 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\ro-RO 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\he-IL 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\ar-SA 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\th-TH 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ro-RO 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\he-IL 2013-12-29 23:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ar-SA 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(3).exe 2013-12-29 22:57 - 2013-12-29 22:57 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(2).exe 2013-12-29 21:33 - 2013-12-29 21:33 - 09566298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-12-29 21:24 - 2013-12-29 21:24 - 00125128 _____ C:\Users\Jacky\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-29 21:22 - 2013-12-29 21:22 - 00001413 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-12-29 21:22 - 2013-12-29 21:21 - 00001447 _____ C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-29 21:22 - 2013-03-18 19:15 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-29 21:22 - 2013-03-18 19:15 - 00000000 ___RD C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-12-29 21:22 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-29 21:19 - 2013-12-30 05:16 - 00000000 ____D C:\Windows\Panther 2013-12-29 21:19 - 2013-12-29 21:19 - 00000020 ___SH C:\Users\Jacky\ntuser.ini 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-12-29 21:19 - 2013-12-29 21:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-12-29 21:19 - 2012-02-04 14:06 - 00000000 __SHD C:\Recovery 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Recovery 2013-12-29 21:19 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT 2013-12-29 21:18 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-29 21:16 - 2009-07-14 05:51 - 00000261 _____ C:\Windows\setuperr.log 2013-12-29 21:14 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\restore 2013-12-29 21:03 - 2013-12-30 04:55 - 00000000 ___HD C:\$WINDOWS.~Q 2013-12-29 21:03 - 2013-12-29 19:25 - 00006155 _____ C:\Windows\comsetup.log 2013-12-29 21:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration 2013-12-29 20:59 - 2013-12-29 20:59 - 00022960 _____ C:\Windows\system32\emptyregdb.dat 2013-12-29 20:55 - 2009-07-14 05:45 - 00468632 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-29 20:53 - 2013-04-26 19:01 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-12-29 20:53 - 2009-07-14 05:46 - 00005157 _____ C:\Windows\DtcInstall.log 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2013-12-29 20:52 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-12-29 20:52 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-12-29 20:51 - 2013-12-25 20:46 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Windows Net Data 2013-12-29 20:51 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\Downloads\Spiel-des-Lebens 2013-12-29 20:51 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\ChromeExtensions 2013-12-29 20:51 - 2013-12-25 20:03 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Zylom 2013-12-29 20:51 - 2013-12-25 16:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Das Spiel des Lebens 2013-12-29 20:51 - 2013-12-21 13:39 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Realore_Whiterra Roads Of Rome 3 2013-12-29 20:51 - 2013-11-30 19:51 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Das Koenigreich der Kobolde 2013-12-29 20:51 - 2013-11-14 19:31 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals 2013-12-29 20:51 - 2013-11-03 10:16 - 00000000 ____D C:\Users\Jacky\Downloads\Konto 2013-12-29 20:51 - 2013-10-29 13:53 - 00000000 ____D C:\Users\Jacky\Documents\My Games 2013-12-29 20:51 - 2013-10-21 10:08 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\PlayFirst 2013-12-29 20:51 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Systweak 2013-12-29 20:51 - 2013-09-28 16:13 - 00000000 ____D C:\Users\Jacky\Downloads\ActiveSync 2013-12-29 20:51 - 2013-09-28 15:40 - 00000000 ____D C:\Users\Jacky\Documents\FalkData 2013-12-29 20:51 - 2013-09-22 19:21 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\PlayFavoriteGames 2013-12-29 20:51 - 2013-08-25 12:53 - 00000000 __RHD C:\Users\Jacky\AppData\Roaming\SecuROM 2013-12-29 20:51 - 2013-08-25 12:52 - 00000000 ____D C:\Users\Jacky\Documents\Electronic Arts 2013-12-29 20:51 - 2013-08-25 12:25 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Origin 2013-12-29 20:51 - 2013-07-29 19:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roads of Rome III 2013-12-29 20:51 - 2013-07-29 19:08 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Christmas Stories - Nussknacker Sammleredition 2013-12-29 20:51 - 2013-07-29 18:45 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Schloss ohne Traeume 2013-12-29 20:51 - 2013-07-29 18:42 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening 2 - Der Mondenwald 2013-12-29 20:51 - 2013-07-29 18:36 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\9 - The Dark Side Sammleredition 2013-12-29 20:51 - 2013-07-15 14:12 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1 Moment of Time - Silentville 2013-12-29 20:51 - 2013-05-25 17:01 - 00000000 ____D C:\Users\Jacky\Documents\BlackMirror2 2013-12-29 20:51 - 2013-05-25 17:01 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\ProtectDisc 2013-12-29 20:51 - 2013-05-09 09:13 - 00000000 ____D C:\Users\Jacky\Documents\My Cheat Tables 2013-12-29 20:51 - 2013-05-09 08:43 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Ubisoft 2013-12-29 20:51 - 2013-05-06 19:37 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\OpenCandy 2013-12-29 20:51 - 2013-05-04 09:25 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2013-12-29 20:51 - 2013-04-26 18:46 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2013-12-29 20:51 - 2013-04-06 15:59 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Roxio 2013-12-29 20:51 - 2013-03-20 20:24 - 00000000 ____D C:\Users\Jacky\Documents\Euro Truck Simulator 2 2013-12-29 20:51 - 2013-03-20 19:31 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mystery of the Ancients - Der Fluch des Schwarzen Wassers Sammleredition 2013-12-29 20:51 - 2013-03-20 19:05 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Party 2013-12-29 20:51 - 2013-03-20 17:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Nero 2013-12-29 20:51 - 2013-03-19 20:06 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Awakening - Das Himmelsschloss Sammleredition 2013-12-29 20:51 - 2013-03-19 19:59 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\WinRAR 2013-12-29 20:51 - 2013-03-19 19:58 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-12-29 20:51 - 2013-03-19 18:45 - 00000000 ____D C:\Users\Jacky\Documents\DVDFab 2013-12-29 20:51 - 2013-03-18 20:21 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Mozilla 2013-12-29 20:50 - 2013-12-29 15:37 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Bonanza 2013-12-29 20:50 - 2013-12-29 13:36 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.technic 2013-12-29 20:50 - 2013-12-25 20:46 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp3f96eefeb2049202da2178bd45059162 2013-12-29 20:50 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp6ec2be2b619d18ef522057d14578d2f7 2013-12-29 20:50 - 2013-12-25 20:45 - 00000000 ____D C:\Users\Jacky\AppData\Local\Temp52da00fd457103be90f4c5f287980f49 2013-12-29 20:50 - 2013-10-29 13:56 - 00000000 ____D C:\Users\Jacky\AppData\Local\Skyrim 2013-12-29 20:50 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\LavFilters 2013-12-29 20:50 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\CDXReader 2013-12-29 20:50 - 2013-10-19 13:15 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\DigitalSite 2013-12-29 20:50 - 2013-10-18 14:32 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Elephant Games 2013-12-29 20:50 - 2013-10-17 19:30 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\AlawarEntertainment 2013-12-29 20:50 - 2013-09-16 16:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Artifex Mundi 2013-12-29 20:50 - 2013-08-25 12:25 - 00000000 ____D C:\Users\Jacky\AppData\Local\Origin 2013-12-29 20:50 - 2013-07-19 14:15 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\2monkeys 2013-12-29 20:50 - 2013-06-01 16:23 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\cerasus.media 2013-12-29 20:50 - 2013-05-09 09:03 - 00000000 ____D C:\Users\Jacky\AppData\Local\Ubisoft Game Launcher 2013-12-29 20:50 - 2013-05-07 14:14 - 00000000 ____D C:\Users\Jacky\AppData\Local\PunkBuster 2013-12-29 20:50 - 2013-04-09 18:38 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Apple Computer 2013-12-29 20:50 - 2013-04-06 16:06 - 00000000 ____D C:\Users\Jacky\AppData\Local\Power2Go8 2013-12-29 20:50 - 2013-04-01 14:41 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\HP 2013-12-29 20:50 - 2013-03-24 19:15 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Babylon 2013-12-29 20:50 - 2013-03-21 20:04 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\.minecraft 2013-12-29 20:50 - 2013-03-20 19:05 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\cef-cache 2013-12-29 20:50 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Macromedia 2013-12-29 20:50 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Adobe 2013-12-29 20:50 - 2013-03-20 17:52 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\CyberLink 2013-12-29 20:50 - 2013-03-20 16:40 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\Boomzap 2013-12-29 20:50 - 2013-03-19 18:26 - 00000000 ____D C:\Users\Jacky\AppData\Roaming\ATI 2013-12-29 20:50 - 2013-03-18 20:21 - 00000000 ____D C:\Users\Jacky\AppData\Local\Mozilla 2013-12-29 20:50 - 2013-03-18 19:15 - 00000000 ____D C:\Users\Jacky\AppData\Local\VirtualStore 2013-12-29 20:49 - 2013-10-19 13:16 - 00000000 ____D C:\Users\Jacky\AppData\Local\BonanzaDealsLive 2013-12-29 20:49 - 2013-07-15 14:00 - 00000000 ____D C:\Users\Jacky\AppData\Local\Big Fish 2013-12-29 20:49 - 2013-05-22 16:18 - 00000000 ____D C:\Users\Jacky\AppData\Local\Google 2013-12-29 20:49 - 2013-05-04 09:30 - 00000000 ____D C:\Users\Jacky\AppData\Local\GamersFirst LIVE! 2013-12-29 20:49 - 2013-05-04 09:25 - 00000000 ____D C:\Users\Jacky\AppData\Local\GamersFirst 2013-12-29 20:49 - 2013-04-09 18:38 - 00000000 ____D C:\Users\Jacky\AppData\Local\Apple Computer 2013-12-29 20:49 - 2013-04-09 18:37 - 00000000 ____D C:\Users\Jacky\AppData\Local\Apple 2013-12-29 20:49 - 2013-04-01 14:35 - 00000000 ____D C:\Users\Jacky\AppData\Local\HP 2013-12-29 20:49 - 2013-04-01 14:13 - 00000000 ____D C:\Users\Jacky\AppData\Local\Adobe 2013-12-29 20:49 - 2013-03-20 18:28 - 00000000 ____D C:\Users\Jacky\AppData\Local\Macromedia 2013-12-29 20:49 - 2013-03-19 18:26 - 00000000 ____D C:\Users\Jacky\AppData\Local\ATI 2013-12-29 20:42 - 2013-12-29 16:17 - 00000000 ____D C:\Windows\SysWOW64\jmdp 2013-12-29 20:42 - 2013-12-29 16:17 - 00000000 ____D C:\Windows\system32\ljkb 2013-12-29 20:42 - 2013-12-29 16:17 - 00000000 ____D C:\Windows\pss 2013-12-29 20:42 - 2013-09-28 14:51 - 00000000 ____D C:\Windows\WindowsMobile 2013-12-29 20:42 - 2013-05-09 08:28 - 00000000 ____D C:\Windows\SysWOW64\WNLT 2013-12-29 20:42 - 2013-05-09 08:28 - 00000000 ____D C:\Windows\SysWOW64\ARFC 2013-12-29 20:42 - 2013-04-01 14:33 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-12-29 20:42 - 2013-03-20 18:27 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-12-29 20:42 - 2013-03-20 18:27 - 00000000 ____D C:\Windows\system32\Macromed 2013-12-29 20:42 - 2011-04-12 09:28 - 00000000 ____D C:\Windows\ShellNew 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-12-29 20:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-29 20:41 - 2013-12-25 21:07 - 00000000 ____D C:\ProgramData\Windows Genuine Advantage 2013-12-29 20:41 - 2013-12-15 11:33 - 00000000 ____D C:\ProgramData\Sony 2013-12-29 20:41 - 2013-11-15 15:30 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2013-12-29 20:41 - 2013-11-14 19:32 - 00000000 ____D C:\ProgramData\Systweak 2013-12-29 20:41 - 2013-10-21 10:08 - 00000000 ____D C:\ProgramData\PlayFirst 2013-12-29 20:41 - 2013-08-25 12:24 - 00000000 ____D C:\ProgramData\Origin 2013-12-29 20:41 - 2013-07-23 07:43 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-12-29 20:41 - 2013-05-26 08:50 - 00000000 ____D C:\ProgramData\Trymedia 2013-12-29 20:41 - 2013-05-09 09:02 - 00000000 ____D C:\ProgramData\Solidshield 2013-12-29 20:41 - 2013-05-09 08:29 - 00000000 ____D C:\ProgramData\SweetIM 2013-12-29 20:41 - 2013-05-06 22:33 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-29 20:41 - 2013-04-06 15:58 - 00000000 ____D C:\ProgramData\Sonic 2013-12-29 20:41 - 2013-04-06 15:57 - 00000000 ____D C:\ProgramData\Roxio 2013-12-29 20:41 - 2013-04-01 14:41 - 00000000 ____D C:\ProgramData\WEBREG 2013-12-29 20:41 - 2013-03-20 18:31 - 00000000 ____D C:\ProgramData\Sun 2013-12-29 20:41 - 2013-03-20 18:13 - 00000000 ____D C:\ProgramData\vsosdk 2013-12-29 20:41 - 2013-03-20 17:52 - 00000000 ____D C:\Users\Public\CyberLink 2013-12-29 20:41 - 2013-03-20 17:24 - 00000000 ____D C:\ProgramData\Nero 2013-12-29 20:41 - 2013-03-18 20:52 - 00000000 ____D C:\Windows\ELAMBKUP 2013-12-29 20:41 - 2013-03-18 20:21 - 00000000 ____D C:\ProgramData\Mozilla 2013-12-29 20:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports 2013-12-29 20:40 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\Xvid 2013-12-29 20:40 - 2013-10-23 13:06 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-12-29 20:40 - 2013-10-19 13:16 - 00000000 ____D C:\ProgramData\DivX 2013-12-29 20:40 - 2013-10-19 13:16 - 00000000 ____D C:\ProgramData\BonanzaDealsLive 2013-12-29 20:40 - 2013-10-18 14:32 - 00000000 ____D C:\ProgramData\Elephant Games 2013-12-29 20:40 - 2013-08-25 13:06 - 00000000 ____D C:\ProgramData\EA Core 2013-12-29 20:40 - 2013-08-25 12:24 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-12-29 20:40 - 2013-07-29 18:10 - 00000000 ____D C:\ProgramData\Big Fish 2013-12-29 20:40 - 2013-05-26 08:58 - 00000000 ____D C:\ProgramData\GameHouse 2013-12-29 20:40 - 2013-05-09 08:29 - 00000000 ____D C:\Program Files (x86)\SweetIM 2013-12-29 20:40 - 2013-05-09 08:22 - 00000000 ____D C:\Program Files (x86)\Ubisoft 2013-12-29 20:40 - 2013-04-11 17:54 - 00000000 ____D C:\ProgramData\McAfee 2013-12-29 20:40 - 2013-04-09 18:38 - 00000000 ____D C:\ProgramData\Apple Computer 2013-12-29 20:40 - 2013-04-09 18:36 - 00000000 ____D C:\ProgramData\Apple 2013-12-29 20:40 - 2013-04-06 15:59 - 00000000 ____D C:\ProgramData\InstallShield 2013-12-29 20:40 - 2013-04-01 14:33 - 00000000 ____D C:\ProgramData\HP Product Assistant 2013-12-29 20:40 - 2013-04-01 14:29 - 00000000 ____D C:\ProgramData\HP 2013-12-29 20:40 - 2013-03-27 07:08 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2013-12-29 20:40 - 2013-03-20 18:26 - 00000000 ____D C:\ProgramData\Adobe 2013-12-29 20:40 - 2013-03-20 17:51 - 00000000 ____D C:\ProgramData\CyberLink 2013-12-29 20:40 - 2013-03-20 17:48 - 00000000 ____D C:\ProgramData\install_clap 2013-12-29 20:40 - 2013-03-19 18:45 - 00000000 ____D C:\ProgramData\dvdfab 2013-12-29 20:40 - 2013-03-19 18:26 - 00000000 ____D C:\ProgramData\ATI 2013-12-29 20:39 - 2013-12-15 11:33 - 00000000 ____D C:\Program Files (x86)\Sony 2013-12-29 20:39 - 2013-08-25 12:41 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-12-29 20:39 - 2013-08-25 12:24 - 00000000 ____D C:\Program Files (x86)\Origin 2013-12-29 20:39 - 2013-07-29 19:16 - 00000000 ____D C:\Program Files (x86)\Roads of Rome III 2013-12-29 20:39 - 2013-05-26 08:50 - 00000000 ____D C:\Program Files (x86)\Online Games Manager 2013-12-29 20:39 - 2013-05-26 08:49 - 00000000 ____D C:\Program Files (x86)\RealArcade 2013-12-29 20:39 - 2013-05-06 22:25 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-12-29 20:39 - 2013-04-06 15:57 - 00000000 ____D C:\Program Files (x86)\Roxio 2013-12-29 20:39 - 2013-03-20 19:31 - 00000000 ____D C:\Program Files (x86)\Mystery of the Ancients - Der Fluch des Schwarzen Wassers Sammleredition 2013-12-29 20:39 - 2013-03-20 17:25 - 00000000 ____D C:\Program Files (x86)\Nero 2013-12-29 20:39 - 2013-03-18 20:14 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-12-29 20:38 - 2013-12-20 10:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-29 20:38 - 2013-10-22 19:21 - 00000000 ____D C:\Program Files (x86)\Java 2013-12-29 20:38 - 2013-10-19 13:18 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-12-29 20:38 - 2013-10-19 13:16 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-12-29 20:38 - 2013-10-09 10:27 - 00000000 ____D C:\Program Files (x86)\MAESTIA 2013-12-29 20:38 - 2013-09-17 08:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-12-29 20:38 - 2013-04-26 18:50 - 00000000 ____D C:\Program Files (x86)\LucasArts 2013-12-29 20:38 - 2013-04-01 14:30 - 00000000 ____D C:\Program Files (x86)\HP 2013-12-29 20:38 - 2013-03-19 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Works 2013-12-29 20:38 - 2013-03-19 18:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 2013-12-29 20:38 - 2013-03-19 18:34 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8 2013-12-29 20:38 - 2013-03-19 18:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-12-29 20:38 - 2013-03-18 20:52 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2013-12-29 20:38 - 2013-03-18 20:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-29 20:38 - 2013-03-18 20:14 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-29 20:38 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\MSBuild 2013-12-29 20:37 - 2013-04-26 18:46 - 00000000 ____D C:\Program Files (x86)\GameSpy Arcade 2013-12-29 20:36 - 2013-12-26 11:19 - 00000000 ____D C:\Program Files (x86)\directx 2013-12-29 20:36 - 2013-12-25 16:26 - 00000000 ____D C:\Program Files (x86)\Das Spiel des Lebens 2013-12-29 20:36 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\ffdshow 2013-12-29 20:36 - 2013-11-14 19:31 - 00000000 ____D C:\Program Files (x86)\DirectVobSub 2013-12-29 20:36 - 2013-10-19 13:16 - 00000000 ____D C:\Program Files (x86)\DSP-worx 2013-12-29 20:36 - 2013-09-28 16:13 - 00000000 ____D C:\Program Files (x86)\Falk 2013-12-29 20:36 - 2013-08-25 12:15 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-12-29 20:36 - 2013-06-01 15:57 - 00000000 ____D C:\Program Files (x86)\Dark Mysteries - Der Seelensammler 2013-12-29 20:36 - 2013-05-26 09:02 - 00000000 ____D C:\Program Files (x86)\dtp 2013-12-29 20:36 - 2013-05-06 19:37 - 00000000 ____D C:\Program Files (x86)\GamersFirst 2013-12-29 20:36 - 2013-04-06 15:57 - 00000000 ____D C:\Program Files (x86)\DivX 2013-12-29 20:36 - 2013-03-20 20:22 - 00000000 ____D C:\Program Files (x86)\Euro Truck Simulator 2 2013-12-29 20:36 - 2013-03-19 18:45 - 00000000 ____D C:\Program Files (x86)\DVDFab 8 Qt 2013-12-29 20:35 - 2013-11-30 19:51 - 00000000 ____D C:\Program Files (x86)\Awakening - Das Koenigreich der Kobolde 2013-12-29 20:35 - 2013-11-15 15:31 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-12-29 20:35 - 2013-11-15 15:20 - 00000000 ____D C:\Program Files\SmartPCFixer 2013-12-29 20:35 - 2013-11-14 19:32 - 00000000 ____D C:\Program Files (x86)\Advanced System Protector 2013-12-29 20:35 - 2013-10-29 17:39 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories 2013-12-29 20:35 - 2013-10-23 13:06 - 00000000 ____D C:\Program Files\iTunes 2013-12-29 20:35 - 2013-10-23 13:06 - 00000000 ____D C:\Program Files\iPod 2013-12-29 20:35 - 2013-10-19 13:18 - 00000000 ____D C:\Program Files\DivX 2013-12-29 20:35 - 2013-10-19 13:16 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive 2013-12-29 20:35 - 2013-10-19 13:15 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals 2013-12-29 20:35 - 2013-09-17 08:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-12-29 20:35 - 2013-09-07 19:09 - 00000000 ____D C:\Program Files (x86)\Anno 1701 2013-12-29 20:35 - 2013-07-29 19:08 - 00000000 ____D C:\Program Files (x86)\Christmas Stories - Nussknacker Sammleredition 2013-12-29 20:35 - 2013-07-29 18:45 - 00000000 ____D C:\Program Files (x86)\Awakening - Schloss ohne Traeume 2013-12-29 20:35 - 2013-07-29 18:42 - 00000000 ____D C:\Program Files (x86)\Awakening 2 - Der Mondenwald 2013-12-29 20:35 - 2013-07-29 18:36 - 00000000 ____D C:\Program Files (x86)\9 - The Dark Side Sammleredition 2013-12-29 20:35 - 2013-07-15 14:12 - 00000000 ____D C:\Program Files (x86)\1 Moment of Time - Silentville 2013-12-29 20:35 - 2013-05-23 17:44 - 00000000 ____D C:\Program Files (x86)\Black Mirror 2 2013-12-29 20:35 - 2013-05-09 08:29 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.2 2013-12-29 20:35 - 2013-04-06 15:59 - 00000000 ____D C:\Program Files\Roxio 2013-12-29 20:35 - 2013-04-01 14:10 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-12-29 20:35 - 2013-03-19 20:06 - 00000000 ____D C:\Program Files (x86)\Awakening - Das Himmelsschloss Sammleredition 2013-12-29 20:35 - 2013-03-19 19:58 - 00000000 ____D C:\Program Files\WinRAR 2013-12-29 20:35 - 2013-03-19 19:53 - 00000000 ____D C:\Program Files (x86)\bfgclient 2013-12-29 20:35 - 2013-03-19 18:34 - 00000000 ____D C:\Program Files\Microsoft Office 2013-12-29 20:35 - 2013-03-19 18:23 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-12-29 20:35 - 2013-03-19 18:22 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:21 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:20 - 00000000 ____D C:\Program Files\ATI Technologies 2013-12-29 20:35 - 2013-03-19 18:20 - 00000000 ____D C:\Program Files\ATI 2013-12-29 20:35 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Vorlagen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Startmenü 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Netzwerkumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Lokale Einstellungen 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Eigene Dateien 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Druckumgebung 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Musik 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Documents\Eigene Bilder 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Verlauf 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\AppData\Local\Anwendungsdaten 2013-12-29 20:31 - 2013-12-29 20:31 - 00000000 _SHDL C:\Users\Jacky\Anwendungsdaten 2013-12-29 20:30 - 2013-12-29 20:30 - 00001355 _____ C:\Windows\TSSysprep.log 2013-12-29 20:30 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2013-12-29 20:29 - 2013-12-29 20:29 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-12-29 19:44 - 2013-03-18 18:53 - 01852960 _____ C:\Windows\WindowsUpdate (1).log 2013-12-29 19:04 - 2013-12-29 18:57 - 00013897 _____ C:\Windows\diagwrn.xml 2013-12-29 19:04 - 2013-12-29 18:57 - 00001890 _____ C:\Windows\diagerr.xml 2013-12-29 15:37 - 2013-12-29 15:37 - 00003226 _____ C:\Windows\System32\Tasks\Bonanza 2013-12-29 13:36 - 2013-12-29 13:36 - 02304092 _____ () C:\Users\Jacky\Downloads\TechnicLauncher.exe 2013-12-29 11:12 - 2013-05-09 08:28 - 01833776 _____ C:\Windows\system32\dmwu.exe 2013-12-29 11:08 - 2013-05-09 08:28 - 00033792 _____ (IncrediMail, Ltd.) C:\Windows\system32\ImHttpComm.dll 2013-12-29 10:15 - 2013-12-29 10:15 - 02014840 _____ (DriverBoost) C:\Users\Jacky\Downloads\DriverBoostPro_Setup.exe 2013-12-29 10:12 - 2013-12-29 10:12 - 08054042 _____ C:\Users\Jacky\Downloads\windowsinstaller45(1).zip 2013-12-29 09:40 - 2013-12-25 20:03 - 00000000 ____D C:\Users\Jacky\AppData\Local\Zylom Games 2013-12-28 21:44 - 2013-12-28 21:42 - 63443792 _____ C:\Users\Jacky\Downloads\thegameoflifedownload.exe 2013-12-26 22:00 - 2013-12-26 21:59 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-12-26 20:37 - 2013-12-26 20:37 - 00401784 _____ (Softonic ) C:\Users\Jacky\Downloads\SoftonicDownloader_fuer_windows-installer-clean-up.exe 2013-12-26 19:39 - 2013-12-26 19:39 - 02585872 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\WindowsInstaller-KB893803-v2-x86.exe 2013-12-26 17:00 - 2013-07-15 14:00 - 00000000 ____D C:\BigFishCache 2013-12-26 11:19 - 2013-12-26 11:19 - 00000278 _____ C:\Windows\Directx.log 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck.exe 2013-12-25 21:07 - 2013-12-25 21:07 - 01528184 _____ (Microsoft Corporation) C:\Users\Jacky\Downloads\GenuineCheck(1).exe 2013-12-25 20:59 - 2013-12-25 20:59 - 02311827 _____ C:\Users\Jacky\Downloads\sdl3ewin.zip 2013-12-25 20:57 - 2013-12-25 20:57 - 00397154 _____ C:\Users\Jacky\Downloads\SpieldesLebensWin.zip 2013-12-25 20:53 - 2013-12-25 20:53 - 00002890 _____ C:\Windows\System32\Tasks\{E03E12C0-F94B-4CA6-A09A-515468D6FAA3} 2013-12-25 20:45 - 2013-12-25 20:45 - 00943872 _____ C:\Users\Jacky\Downloads\Spiel-des-Lebens-Setup.exe 2013-12-25 20:41 - 2013-12-25 20:41 - 00003018 _____ C:\Windows\System32\Tasks\{476505DD-F30E-4FF4-8920-CB14D92EB605} 2013-12-25 20:29 - 2013-12-25 20:29 - 00003018 _____ C:\Windows\System32\Tasks\{01014E7C-EF80-4994-94A4-7882BBE1FC4D} 2013-12-25 16:22 - 2013-12-25 16:22 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p200715036_s2_l2.exe 2013-12-25 16:19 - 2013-12-25 16:19 - 00002890 _____ C:\Windows\System32\Tasks\{D5C4E481-AC90-46F2-A2E0-FC0AF1374D57} 2013-12-25 09:03 - 2011-02-19 22:51 - 00608080 _____ (Microsoft Corporation) C:\Windows\system32\msvcp100.dll 2013-12-25 09:03 - 2011-02-19 00:52 - 00829264 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100.dll 2013-12-19 08:27 - 2013-03-20 19:09 - 00001525 _____ C:\Users\Jacky\Desktop\PartyCasino.lnk 2013-12-19 08:24 - 2013-03-20 19:05 - 00001531 _____ C:\Users\Jacky\Desktop\partypoker.lnk 2013-12-16 05:59 - 2013-08-14 07:15 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 11:36 - 2013-12-15 11:33 - 00181280 _____ C:\Windows\DPINST.LOG 2013-12-15 11:33 - 2013-12-15 11:33 - 00002106 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2013-12-11 18:46 - 2013-03-20 18:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 18:46 - 2013-03-20 18:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-11 18:46 - 2013-03-20 18:27 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-11 08:58 - 2012-08-02 15:09 - 00029792 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys 2013-12-11 08:58 - 2012-06-19 17:28 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2013-12-07 19:39 - 2013-05-22 16:18 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-07 19:39 - 2013-05-22 16:18 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-11-30 19:40 - 2013-11-30 19:40 - 00236648 _____ (Big Fish Games) C:\Users\Jacky\Downloads\bigfishgames_p132398476_s2_l2(1).exe 2013-11-30 19:36 - 2013-11-30 19:36 - 00003150 _____ C:\Windows\System32\Tasks\{D9FF8CB0-8D45-4811-B5EE-E5A392CEF7CF} Files to move or delete: ==================== C:\Users\Jacky\Firefox Setup 19.0.2.exe Some content of TEMP: ==================== C:\Users\Jacky\AppData\Local\Temp\eauninstall.exe C:\Users\Jacky\AppData\Local\Temp\SimCity 4 Deluxe_uninst.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-29 20:17 ==================== End Of Log ============================ --- --- --- --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-12-2013 01 Ran by Jacky at 2013-12-30 16:43:43 Running from C:\Users\Jacky\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5} AS: Kaspersky Internet Security (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E} ==================== Installed Programs ====================== 1 Moment of Time: Silentville (x32 Version: - ) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) 9: The Dark Side Sammleredition (x32 Version: - ) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated) AIO_CDA_ProductContext (x32 Version: 130.0.365.000 - Hewlett-Packard) AIO_CDA_Software (x32 Version: 130.0.365.000 - Hewlett-Packard) AIO_Scan (x32 Version: 130.0.365.000 - Hewlett-Packard) AMD APP SDK Runtime (Version: 2.5.793.1 - Advanced Micro Devices Inc.) AMD AVIVO64 Codecs (Version: 11.7.0.11013 - Advanced Micro Devices, Inc.) AMD Catalyst Install Manager (Version: 3.0.851.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) AMD Media Foundation Decoders (Version: 1.0.61013.1636 - Advanced Micro Devices, Inc.) Anno 1701 (x32 Version: 1.04 - Sunflowers) APB Reloaded (x32 Version: 1.6.1.607756 - ) Awakening 2: Der Mondenwald (x32 Version: - ) Awakening: Das Himmelsschloss Sammleredition (x32 Version: - ) Awakening: Das Königreich der Kobolde (x32 Version: - ) Awakening: Schloss ohne Träume (x32 Version: - ) Big Fish: Game Manager (x32 Version: 3.2.0.7 - ) Black Mirror 1.2 (x32 Version: - Digital Tainment Pool) Black Mirror 2 (x32 Version: - dtp) BrowserProtect (x32 Version: - Bit89 Inc) <==== ATTENTION BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) C3100 (x32 Version: 130.0.365.000 - Hewlett-Packard) c3100_Help (x32 Version: 82.0.256.000 - Hewlett-Packard) Catalyst Control Center (x32 Version: 2011.1013.1702.28713 - Ihr Firmenname) Catalyst Control Center InstallProxy (x32 Version: 2011.1013.1702.28713 - Advanced Micro Devices, Inc.) Catalyst Control Center Localization All (x32 Version: 2011.1013.1702.28713 - Advanced Micro Devices, Inc.) CCC Help Danish (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Dutch (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help English (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Finnish (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help French (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help German (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Italian (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Japanese (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Norwegian (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Spanish (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) CCC Help Swedish (x32 Version: 2011.1013.1701.28713 - Advanced Micro Devices, Inc.) ccc-utility64 (Version: 2011.1013.1702.28713 - Advanced Micro Devices, Inc.) Cheat Engine 6.2 (x32 Version: - Dark Byte) Christmas Stories: Nussknacker Sammleredition (x32 Version: - ) Copy (x32 Version: 130.0.428.000 - Hewlett-Packard) Dark Mysteries - Der Seelensammler (x32 Version: - cerasus.media GmbH) Das Spiel des Lebens (x32 Version: - ) Delicious - Emily's Tea Garden (x32 Version: - Zylom) Delicious Promo (x32 Version: - Zylom) Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Die Sims™ 3 (x32 Version: 1.63.4 - Electronic Arts) Die Sims™ 3 Einfach tierisch (x32 Version: 10.0.96 - Electronic Arts) Die Sims™ 3 Late Night (x32 Version: 6.0.81 - Electronic Arts) DivX-Setup (x32 Version: 2.6.1.8 - DivX, LLC) DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) DomaIQ (x32 Version: - Tuguu SLU) Dream Chronicles(R) - The Book of Air(TM) (x32 Version: - Zylom) DVDFab 8.1.5.8 (18/01/2012) Qt (x32 Version: - Fengtao Software Inc.) Euro Truck Simulator 2 (x32 Version: 1.1.1 - SCS Software) Falk Navi-Manager classic (x32 Version: 2.11.0 - United Navigation GmbH) Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) GamersFirst LIVE! (HKCU Version: - GamersFirst) GameSpy Arcade (x32 Version: - ) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) HP Customer Participation Program 13.0 (Version: 13.0 - HP) HP Imaging Device Functions 13.0 (Version: 13.0 - HP) HP Photosmart All-In-One Driver Software 13.0 Rel. A (Version: 13.0 - HP) HP Photosmart Essential 3.5 (Version: 3.5 - HP) HP Smart Web Printing 4.51 (Version: 4.51 - HP) HP Solution Center 13.0 (Version: 13.0 - HP) HP Update (x32 Version: 4.000.011.006 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Internet Explorer Toolbar 4.8 by SweetPacks (x32 Version: 4.8.0000 - SweetIM Technologies Ltd.) <==== ATTENTION iTunes (Version: 11.1.2.31 - Apple Inc.) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190 - Kaspersky Lab) LAME v3.99.3 (for Windows) (x32 Version: - ) MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Microsoft .NET Framework 4 Client Profile (Version: - ) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: - ) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: - ) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Groove Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (Version: 1.20.146.0 - Microsoft) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) Mystery of the Ancients: Der Fluch des Schwarzen Wassers Sammleredition (x32 Version: - ) Nero Burning ROM (x32 Version: 12.5.6000 - Nero AG) Nero Burning ROM Help (CHM) (x32 Version: 12.0.3000 - Nero AG) Nero BurningROM 12 (x32 Version: 12.5.00900 - Nero AG) Nero ControlCenter (x32 Version: 11.0.15600 - Nero AG) Nero ControlCenter Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Nero Core Components (x32 Version: 11.0.20900 - Nero AG) Nero SharedVideoCodecs (x32 Version: 1.0.12100.2.0 - Nero AG) Nero Update (x32 Version: 11.0.11800.31.0 - Nero AG) Network64 (Version: 130.0.572.000 - Hewlett-Packard) Network64 (Version: 140.0.221.000 - Hewlett-Packard) Nightmares from the Deep - The Cursed Heart Premium Edition (x32 Version: - Zylom) NVIDIA PhysX (x32 Version: 9.10.0129 - NVIDIA Corporation) OCR Software by I.R.I.S. 13.0 (Version: 13.0 - HP) Online Games Manager v1.21 (x32 Version: 1.21.2 - Real Networks, Inc.) Origin (x32 Version: 9.0.14.2148 - Electronic Arts, Inc.) PartyCasino (x32 Version: - PartyGaming) partypoker (x32 Version: - PartyGaming) Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) ProtectDisc Driver, Version 11 (x32 Version: 11.0.0.12 - ProtectDisc Software GmbH) PunkBuster Services (x32 Version: 0.993 - Even Balance, Inc.) Realtek Ethernet Controller Driver (x32 Version: 7.46.610.2011 - Realtek) Roads of Rome III (x32 Version: - ) Roxio WinOnCD 9 (x32 Version: 9.0.136 - Roxio, Inc.) Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Shop for HP Supplies (Version: 13.0 - HP) SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Sony PC Companion 2.10.181 (x32 Version: 2.10.181 - Sony) Star Wars Battlefront II (x32 Version: 1.0 - LucasArts) Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Steam (x32 Version: 1.0.0.0 - Valve Corporation) SweetIM Bundle by SweetPacks (x32 Version: 1.0.0.0 - SweetPacks LTD) <==== ATTENTION SweetIM for Messenger 3.7 (x32 Version: 3.7.0007 - SweetIM Technologies Ltd.) <==== ATTENTION SweetPacks Updater (x32 Version: 5.0.1.7 - ) <==== ATTENTION The Elder Scrolls V: Skyrim (x32 Version: - Bethesda Game Studios) Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Ubisoft Game Launcher (x32 Version: 1.0.0.0 - UBISOFT) UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Update for 2007 Microsoft Office System (KB967642) (x32 Version: - Microsoft) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft Office 2007 Help for Common Features (KB963673) (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Access 2007 Help (KB963663) (x32 Version: - Microsoft) Update for Microsoft Office Excel 2007 Help (KB963678) (x32 Version: - Microsoft) Update for Microsoft Office Infopath 2007 Help (KB963662) (x32 Version: - Microsoft) Update for Microsoft Office OneNote 2007 Help (KB963670) (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 Help (KB963677) (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version: - Microsoft) Update for Microsoft Office Publisher 2007 Help (KB963667) (x32 Version: - Microsoft) Update for Microsoft Office Script Editor Help (KB963671) (x32 Version: - Microsoft) Update for Microsoft Office Word 2007 Help (KB963665) (x32 Version: - Microsoft) Update_for_BonanzaDeals (HKCU Version: - Update_for_BonanzaDeals) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) VD64Inst (Version: 1.00.0000 - Roxio, Inc.) WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8 - Microsoft Corp) Windows Mobile-Gerätecenter (Version: 6.1.6965.0 - Microsoft Corporation) Windows Utils (x32 Version: - ) Windows XP Mode (Version: 1.3.7600.16422 - Microsoft Corporation) WinRAR 4.00 (64-bit) (Version: 4.00.0 - win.rar GmbH) Zuma Deluxe (x32 Version: - Zylom) ==================== Restore Points ========================= 29-12-2013 20:19:46 Windows Update 29-12-2013 20:24:46 Windows Update 29-12-2013 20:36:36 Windows Update 29-12-2013 21:32:10 Windows XP Mode wird installiert 29-12-2013 21:55:17 Windows XP Mode wird entfernt 29-12-2013 22:00:48 Windows Update 29-12-2013 22:12:51 Windows XP Mode wird installiert 29-12-2013 22:21:44 Windows XP Mode wird entfernt 29-12-2013 22:35:39 Windows XP Mode wird installiert 30-12-2013 08:40:01 Windows Update 30-12-2013 09:00:40 Removed Apple Application Support 30-12-2013 09:02:37 Removed Apple Mobile Device Support 30-12-2013 09:04:58 Removed Apple Software Update 30-12-2013 09:09:01 Windows Update 30-12-2013 12:15:44 Removed Bonjour 30-12-2013 12:17:19 Removed Google Earth. ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {139C862C-D1B9-4F0A-9C9A-073303D913EA} - System32\Tasks\{476505DD-F30E-4FF4-8920-CB14D92EB605} => C:\Users\Jacky\AppData\Local\Zylom Games\The Game of Life Deluxe\wrapper.exe Task: {14AB91D8-2263-44A9-9980-D459C2771FB5} - System32\Tasks\{D5C4E481-AC90-46F2-A2E0-FC0AF1374D57} => E:\SETUP.EXE Task: {359F6510-FCB7-4DDA-84B5-9D1285191442} - System32\Tasks\DigitalSite => C:\Users\Jacky\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {5D250DC8-F1DA-43F4-973B-F79C6E6D1007} - System32\Tasks\{E03E12C0-F94B-4CA6-A09A-515468D6FAA3} => E:\SETUP.EXE Task: {7DC5A4E5-DD7F-45A7-A9E2-4EE1E6528AF6} - \SidebarExecute No Task File Task: {9063E202-5ED9-4719-A733-5522E0B2A5A8} - System32\Tasks\Bonanza => C:\Users\Jacky\AppData\Roaming\Bonanza\UpdateProc\UpdateTask.exe [2013-04-30] () Task: {B586DBAA-DA3A-45E8-9DA9-D8805E14F874} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {C5BED6B3-6533-4EF5-912F-E79A5B6739DF} - System32\Tasks\{01014E7C-EF80-4994-94A4-7882BBE1FC4D} => C:\Users\Jacky\AppData\Local\Zylom Games\The Game of Life Deluxe\wrapper.exe Task: {CB5F5DE8-F364-4626-A773-6BE90832BBE3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-22] (Google Inc.) Task: {E66B1016-488B-49AA-A86F-07465CCFA953} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {E6BCC1F9-4A86-485A-95CB-B8ACDA1B47F3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-22] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Bonanza.job => C:\Users\Jacky\AppData\Roaming\Bonanza\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\Jacky\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-03-19 19:58 - 2011-03-02 12:40 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll 2013-12-29 11:12 - 2013-12-29 11:12 - 01429296 _____ () C:\Windows\System32\ljkb\lmrn.dll 2011-10-13 17:01 - 2011-10-13 17:01 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2012-12-14 13:45 - 2012-12-14 13:45 - 01310136 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kpcengine.2.2.dll 2006-10-27 07:13 - 2006-10-27 07:13 - 04587520 ____R () C:\Program Files (x86)\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll 2012-04-26 23:38 - 2012-04-26 23:38 - 20758016 _____ () C:\Users\Jacky\AppData\Local\GamersFirst\LIVE!\libcef.dll 2012-08-17 21:38 - 2012-08-17 21:38 - 00479160 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll 2013-08-29 01:25 - 2013-08-29 01:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2006-10-27 07:17 - 2006-10-27 07:17 - 00516096 _____ () C:\Program Files (x86)\Common Files\Roxio Shared\9.0\DLLShared\LayoutDll9.dll 2013-12-29 11:12 - 2013-12-29 11:12 - 01150256 _____ () C:\Windows\SysWOW64\jmdp\lmrn.dll 2013-12-20 10:03 - 2013-12-20 10:03 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-12-11 18:46 - 2013-12-11 18:46 - 16242056 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: USB (Universal Serial Bus)-Controller Description: USB (Universal Serial Bus)-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: SM-Bus-Controller Description: SM-Bus-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Kaspersky Anti-Virus NDIS 6 Filter Description: Kaspersky Anti-Virus NDIS 6 Filter Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: KLIM6 Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (12/30/2013 04:41:13 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (12/30/2013 01:26:04 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 01:20:37 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 26.0.0.5087, Zeitstempel: 0x52a0d273 Name des fehlerhaften Moduls: xul.dll, Version: 26.0.0.5087, Zeitstempel: 0x52a0d20a Ausnahmecode: 0xc0000005 Fehleroffset: 0x0014e1a8 ID des fehlerhaften Prozesses: 0x1628 Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Error: (12/30/2013 00:31:11 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:30:31 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:30:29 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:30:29 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:30:28 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:29:28 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (12/30/2013 00:08:36 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "hpqcxs08" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst hpqcxs08 erreicht. Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "hpqcxs08" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst hpqcxs08 erreicht. Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "hpqcxs08" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/30/2013 01:26:01 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst hpqcxs08 erreicht. Error: (12/30/2013 01:26:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "hpqcxs08" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/30/2013 01:26:00 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst hpqcxs08 erreicht. Error: (12/30/2013 01:25:52 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "hpqcxs08" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/30/2013 01:25:52 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst hpqcxs08 erreicht. Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-12-30 13:24:50.776 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 13:24:50.652 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 12:06:58.987 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 12:06:58.909 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:55:38.993 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:55:38.915 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:54:08.898 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:54:08.820 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:27:10.482 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-30 09:27:10.419 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\RxFilter.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 70% Total physical RAM: 4077.64 MB Available physical RAM: 1207.27 MB Total Pagefile: 8153.48 MB Available Pagefile: 4410.09 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:880.41 GB) (Free:621.5 GB) NTFS Drive d: (Recover) (Fixed) (Total:50 GB) (Free:15.62 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: C2D23E51) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=880 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ==================== End Of Log ============================ Geändert von Tweety741 (30.12.2013 um 17:51 Uhr) |