Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Alles rund um Windows (https://www.trojaner-board.de/alles-rund-um-windows/)
-   -   PC meldet sich nach Anmeldung automatisch wieder ab 2014 (https://www.trojaner-board.de/150588-pc-meldet-anmeldung-automatisch-ab-2014-a.html)

Drancer 06.03.2014 20:28

Ich habe die Logs gepostet die auch Viren anzeigen andere Logs stand nur : 0 detected .
Laufen oder nicht in mein USer komm ich aber nicht rein das ist das problem.
Ich meld mich and und gleich steht da abmelden.

Zitat:

Zitat von Undertaker (Beitrag 1263431)
moin,

zwischen dem 26.02.2014 00:33:53 und dem 03.03.2014 17:27:18 liegen auch ein paar Tage.
Kein Wunder dass die Logdateien Unterschiede zeigen.

Dein Rechner scheint doch aber zu laufen, ohne Abschaltung, oder postest du von einer anderen Maschine?

Insofern scheint das Problem doch gelöst zu sein.

Gruß Undertaker

Was soll eigentlich gelöst sein ?
Und ich habe nur einen Rechner.
Und wie meinst du mit ohne Abschaltung ?

Wird mir hier noch geholfen ?

mort 07.03.2014 11:56

Wir helfen hier freiwillig in unserer Freizeit. Falls du innerhalb von 2 Tagen keine Antwort bekommen haben, schreibe mir eine PM.
http://www.trojaner-board.de/69886-a...tml#post412358

Schritt 1

Downloade dir bitte Windows Repair (All In One) von hier.

Drancer 07.03.2014 20:43

Zitat:

Zitat von mort (Beitrag 1264163)
Wir helfen hier freiwillig in unserer Freizeit. Falls du innerhalb von 2 Tagen keine Antwort bekommen haben, schreibe mir eine PM.
http://www.trojaner-board.de/69886-a...tml#post412358

Schritt 1

Downloade dir bitte Windows Repair (All In One) von hier.

Hey Mort
Ich habe es mal mit dem abgesicherten Modus in dem User probiert wo sich immer selber abmeldet und kann mich nun wieder einloggen !
Zwar sind paar eigene Einstellungen wieder auf Standard aber egal kann mich einloggen !
Danke das du dir die Zeit genommen hast und soooo hilfreich warst ! :daumenhoc
MFG

mort 09.03.2014 18:48

Schritt 1

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).


Schritt 2

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Schritt 3

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Schritt 4

Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, werden ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.

Drancer 12.03.2014 03:20

Zitat:

Zitat von mort (Beitrag 1265532)
Schritt 1

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).


Schritt 2

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Schritt 3

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Schritt 4

Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, werden ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.

Sorry für die späte Antwort dieser ESET scanner hat einiges gefunden aber weil kein häckchen gesetzt wurde, ist auch nichts entfernt schätze ich , die logs :

Maleware bytes :
Code:

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 274797
Laufzeit: 7 Minute(n), 55 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 3
C:\Users\PC\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Roaming\OpenCandy\A25657CAEE0A43C180CBE9E2626F9ED4 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Roaming\OpenCandy\OpenCandy_A25657CAEE0A43C180CBE9E2626F9ED4 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 4
C:\Users\Administrator\AppData\Local\Temp\is-04SA5.tmp\OCSetupHlp.dll (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\Downloads\FreeTorrentViewer.exe (PUP.Optional.Spigot.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Installer\de1398.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Roaming\OpenCandy\A25657CAEE0A43C180CBE9E2626F9ED4\pokkiInstaller.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

ESET :
Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=748e7e5009cc094790de2aed9a5f0add
# engine=17406
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-03-12 01:39:11
# local_time=2014-03-12 02:39:11 (+0100, Mitteleuropäische Zeit)
# country="Austria"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 96 8468 165259656 4851 0
# compatibility_mode=5893 16776573 100 94 8719 146218201 0 0
# scanned=255895
# found=9
# cleaned=0
# scan_time=5461
sh=90B5CB407330EF90E085642D8086212A05AF5771 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\ProgramData\Spybot - Search & Destroy\Recovery\SweetIM186.zip"
sh=03E06E979C0C768B3B4A64EC9E6B3C28941C963D ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\ProgramData\Spybot - Search & Destroy\Recovery\SweetIM7.zip"
sh=90B5CB407330EF90E085642D8086212A05AF5771 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\Users\All Users\Spybot - Search & Destroy\Recovery\SweetIM186.zip"
sh=03E06E979C0C768B3B4A64EC9E6B3C28941C963D ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\Users\All Users\Spybot - Search & Destroy\Recovery\SweetIM7.zip"
sh=6B7AA8CBE19B454320D14E4F8D9A12DA67A80048 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\fncnjnlinokgbjhnhcioomcodahmeceb\1.0\V0JCbN.js"
sh=618A050B15EE954BD9EA5637C956AD1EFFE8CCC2 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\extensions\bpax7a@vekpbgey.org\content\bg.js"
sh=22F380C5438BA167DC774B82E4A00262612FDD40 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\extensions\hqjs4vg@kfajdmhuia.net\content\bg.js"
sh=054C85ED5963555FA1B235411876C404DE9E1102 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\extensions\oa9nnk_ifjm@xoeyavoayo.com\content\bg.js"
sh=4B71417ECA70AE1EEFB1ECD8949FFB7EBEEE4C38 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\extensions\oai5cavr@aasvlrcz.net\content\bg.js"


FRST :
FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-03-2014
Ran by Administrator (administrator) on PC-PC on 12-03-2014 03:18:20
Running from C:\Users\Administrator\Desktop\bewerbung
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

() C:\Program Files (x86)\WinArchiver\WAService.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Doctor Web, Ltd.) C:\Program Files (x86)\TrafInsp\plugins\DwAV\Engine\dwengine.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(SMART-SOFT) C:\Program Files (x86)\TrafInsp\TrafInsp.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(SMART-SOFT) C:\Program Files (x86)\TrafInsp\ASP.NET\bin\TIASPNETHostServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7198424 2013-08-28] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-11-09] (RealNetworks, Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime Alternative\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-2263356855-1520679738-450664524-500\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2011-01-12] (AMD)
HKU\S-1-5-21-2263356855-1520679738-450664524-500\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_70_ActiveX.exe [841096 2014-02-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-2263356855-1520679738-450664524-500\...\MountPoints2: {923abee6-67e0-11e1-8edd-806e6f6e6963} - D:\Autorun.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0D7BFBE9F903CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: No Name - {74D271A4-00A7-0F5C-560A-2412C0CFD357} -  No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: No Name - {8984B388-A5BB-4DF7-B274-77B879E179DB} -  No File
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.66.2.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\eddz111h.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mailru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ozonru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\priceru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-slovari.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex.xml
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-11-09]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []

Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchURL: hxxp://www.google.com/search?q={searchTerms}
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-30]
CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-30]
CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-30]
CHR Extension: (Google-Suche) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-30]
CHR Extension: (RealDownloader) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-02-24]
CHR Extension: (Google Wallet) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-30]
CHR Extension: (Google Mail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-30]
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2012-06-21] ()
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG)
R2 DrWebEngine; C:\Program Files (x86)\TrafInsp\plugins\DwAV\Engine\dwengine.exe [1667416 2012-06-28] (Doctor Web, Ltd.)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5148240 2013-07-23] (INCA Internet Co., Ltd.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-31] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 TrafInspSrv; C:\Program Files (x86)\TrafInsp\TrafInsp.exe [4475392 2012-06-08] (SMART-SOFT)
R2 WinArchiver Service; C:\Program Files (x86)\WinArchiver\WAService.exe [202264 2013-11-10] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
S3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [22600 2013-11-18] ()
R1 TICAPDRV; C:\Windows\System32\DRIVERS\ticap.sys [265880 2012-01-20] (SMART-SOFT)
R0 waemu; C:\Windows\System32\Drivers\waemu.sys [140184 2013-11-10] (Power Software Ltd)
S2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S3 cpuz136; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S2 NEWDRIVER; \??\C:\Windows\SysWow64\WinVDEdrv6.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-12 01:15 - 2014-03-12 01:15 - 00000000 __SHD () C:\Windows\ftpcache
2014-03-11 08:30 - 2014-03-11 08:30 - 00001001 _____ () C:\Users\PC\Desktop\My Downloads - Verknüpfung.lnk
2014-03-11 08:24 - 2014-03-11 08:24 - 00014541 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Lekar.Uchen1k.Aviacenna.2014.D.WEB-DLRip.1400Mb_0.torrent
2014-03-11 01:21 - 2014-03-11 01:21 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-11 01:18 - 2014-03-11 01:19 - 02347384 _____ (ESET) C:\Users\Administrator\Downloads\esetsmartinstaller_enu.exe
2014-03-11 01:17 - 2014-03-11 01:17 - 01949184 _____ () C:\Users\Administrator\Downloads\adwcleaner_3.021.exe
2014-03-11 00:23 - 2014-03-11 00:23 - 08065840 _____ (Cheat Engine ) C:\Users\Administrator\Downloads\CheatEngine63.exe
2014-03-11 00:23 - 2014-03-11 00:23 - 00000000 ____D () C:\Program Files (x86)\Cheat Engine 6.3
2014-03-10 17:24 - 2014-03-10 17:25 - 00000000 ____D () C:\FreeTorrentViewer
2014-03-10 17:24 - 2014-03-10 17:24 - 00001075 _____ () C:\Users\PC\Desktop\Free Torrent Viewer.lnk
2014-03-10 17:24 - 2014-03-10 17:24 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeTorrentViewer
2014-03-10 17:24 - 2014-03-10 17:24 - 00000000 ____D () C:\Program Files (x86)\FreeTorrentViewer
2014-03-10 17:22 - 2014-03-10 17:22 - 00000000 ____D () C:\Users\PC\Downloads\We Are Explorers - 3D Printed Video
2014-03-10 17:21 - 2014-03-10 17:21 - 00000845 _____ () C:\Users\PC\Desktop\µTorrent.lnk
2014-03-10 06:58 - 2014-03-11 01:13 - 00000000 ____D () C:\Program Files (x86)\EA GAMES
2014-03-09 18:11 - 2014-03-09 18:11 - 00003156 _____ () C:\Windows\System32\Tasks\{B6ED3387-65BE-4D2B-90AE-0ECABF44F5B3}
2014-03-09 05:09 - 2014-03-12 01:23 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 2
2014-03-09 04:51 - 2014-03-11 01:24 - 00012134 _____ () C:\Windows\PFRO.log
2014-03-09 03:57 - 2014-03-11 01:18 - 00115180 _____ () C:\Windows\DirectX.log
2014-03-08 23:51 - 2014-03-08 23:51 - 00003194 _____ () C:\Windows\System32\Tasks\{7F2CB0BF-4EB1-428B-85A8-2CC9BBF62917}
2014-03-07 23:32 - 2014-03-12 00:15 - 00003350 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-07 23:32 - 2014-03-12 00:15 - 00003232 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-07 21:42 - 2014-03-12 00:21 - 00001288 _____ () C:\Windows\setupact.log
2014-03-07 21:42 - 2014-03-07 21:42 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-07 20:17 - 2014-03-07 20:55 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2014-03-07 19:47 - 2014-03-07 19:47 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-03-07 14:57 - 2014-03-07 15:16 - 782111825 ____R () C:\Users\Administrator\Desktop\2.Guns.2013.HDRip-AVC_By WazZzup.mkv
2014-03-06 14:56 - 2014-03-06 14:56 - 00000000 ____D () C:\Users\Administrator\Desktop\08951603108
2014-03-06 14:51 - 2014-03-06 14:51 - 00000000 ____D () C:\Users\Administrator\Desktop\004989516003101
2014-03-06 13:31 - 2014-03-06 13:31 - 00000000 ____D () C:\Users\Administrator\Desktop\munchen
2014-03-05 23:18 - 2014-03-05 23:18 - 00001513 _____ () C:\Users\Administrator\AppData\Local\recently-used.xbel
2014-03-05 23:16 - 2014-03-05 23:18 - 00000000 ____D () C:\Users\Administrator\AppData\Local\gtk-2.0
2014-03-05 23:14 - 2014-03-05 23:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\gegl-0.2
2014-03-05 18:06 - 2014-03-09 05:09 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-03-05 18:06 - 2014-03-05 18:07 - 00000000 ____D () C:\Users\Administrator\Documents\GTA San Andreas User Files
2014-03-05 02:42 - 2014-03-05 02:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-05 02:12 - 2014-03-05 02:12 - 00000000 ____D () C:\Users\Administrator\Documents\FreemakeVideoConverter
2014-03-04 22:32 - 2014-03-04 22:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\WMTools Downloaded Files
2014-03-04 19:20 - 2014-03-04 19:20 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Adobe
2014-03-04 15:20 - 2014-03-07 14:38 - 00001160 ____H () C:\Users\Administrator\Desktop\$$JetTHM$$.cache
2014-03-04 15:12 - 2014-03-04 15:12 - 00000000 ____D () C:\Users\Administrator\Documents\Freemake
2014-03-04 15:10 - 2014-03-04 15:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\COWON
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2014-03-04 01:57 - 2014-03-04 01:57 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LavasoftStatistics
2014-03-04 01:51 - 2014-03-04 01:51 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-03-03 21:57 - 2014-03-03 21:58 - 00000000 ____D () C:\Users\Administrator\Documents\DVDVideoSoft
2014-03-03 21:57 - 2014-03-03 21:58 - 00000000 ____D () C:\Users\Administrator\Documents\Assassin's Creed Revelations
2014-03-03 21:57 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 3
2014-03-03 20:40 - 2014-03-12 03:18 - 00000000 ____D () C:\FRST
2014-03-02 05:39 - 2014-03-02 05:39 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Auslogics
2014-03-02 02:41 - 2014-03-02 02:41 - 00000000 ____D () C:\Program Files (x86)\SmartTweak Software
2014-03-02 02:11 - 2014-03-02 02:11 - 00002788 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-01 20:21 - 2014-03-01 21:21 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PhotoScape
2014-03-01 20:18 - 2014-03-01 20:18 - 00000000 ____D () C:\Windows\de
2014-03-01 20:17 - 2014-03-01 20:17 - 00000000 ____D () C:\Windows\en
2014-03-01 20:16 - 2014-03-01 20:16 - 00000000 ____D () C:\Windows\ru
2014-03-01 20:12 - 2014-03-06 15:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Windows Live
2014-03-01 20:01 - 2014-03-11 08:30 - 00055296 ___SH () C:\Users\PC\Thumbs.db
2014-03-01 19:45 - 2014-03-02 05:25 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
2014-03-01 13:21 - 2014-03-01 13:21 - 00021008 _____ () C:\Users\PC\Desktop\Mein Film bbbb.wlmp
2014-03-01 07:12 - 2014-03-01 07:19 - 377248555 _____ () C:\Users\PC\Desktop\Mein Film 1.mp4
2014-03-01 06:47 - 2014-03-07 21:42 - 00070520 _____ () C:\Users\PC\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-27 11:13 - 2014-02-27 11:13 - 00000088 _____ () C:\Users\PC\Desktop\Два ствола скачать торрент в хорошем качестве бесплатно dvdrip, hdrip.url
2014-02-27 10:52 - 2014-02-27 10:52 - 00000000 ____D () C:\Users\PC\Desktop\08951603108
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\WinArchiver
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Program Files (x86)\WinArchiver
2014-02-26 19:54 - 2013-11-10 03:53 - 00140184 _____ (Power Software Ltd) C:\Windows\system32\Drivers\waemu.sys
2014-02-26 19:49 - 2014-02-26 19:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-26 19:48 - 2014-02-26 19:48 - 00000000 ____D () C:\Program Files\Java
2014-02-26 19:44 - 2014-02-26 19:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PowerISO
2014-02-26 14:01 - 2014-01-09 03:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-02-26 14:01 - 2014-01-03 23:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-02-26 00:02 - 2014-02-26 00:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes
2014-02-25 18:53 - 2014-03-07 21:18 - 00306000 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-25 13:50 - 2014-03-11 14:44 - 00726191 _____ () C:\Windows\WindowsUpdate.log
2014-02-25 13:48 - 2014-03-11 14:28 - 00003188 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-24 23:55 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-02-24 23:54 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-02-24 23:54 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-02-24 23:54 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-02-24 23:54 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-02-24 23:54 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-02-24 23:54 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-02-24 23:54 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-02-24 23:54 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-02-24 23:54 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-02-24 23:54 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-02-24 23:54 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-02-24 23:54 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-02-24 23:54 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-02-24 23:54 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-02-24 23:54 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-02-24 23:53 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-02-24 23:53 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-02-24 23:53 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2014-02-24 23:53 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-02-24 23:53 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2014-02-24 23:53 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-02-24 23:53 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-02-24 23:52 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-02-24 23:52 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Malwarebytes
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-24 17:03 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-23 23:06 - 2014-02-23 23:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Need for Speed World
2014-02-23 22:53 - 2014-02-23 23:16 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Electronic_Arts_Inc
2014-02-23 01:58 - 2014-02-23 01:58 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Realmware
2014-02-22 23:05 - 2014-03-03 20:25 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PhotoScape
2014-02-22 23:05 - 2014-02-22 23:12 - 00008192 ____H () C:\Users\Administrator\Desktop\photothumb.db
2014-02-22 01:00 - 2014-02-22 01:00 - 00000000 ____D () C:\Users\PC\Desktop\login
2014-02-21 17:45 - 2014-02-21 17:45 - 00000000 ____D () C:\Users\PC\Desktop\httpwww.youtube.comwatchv=OGnIS_a54ak
2014-02-20 00:08 - 2014-02-20 00:08 - 00000000 ____D () C:\Users\Administrator\AppData\Local\EMU
2014-02-19 20:45 - 2014-02-19 20:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Theta
2014-02-19 20:28 - 2014-02-19 20:28 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-02-19 20:10 - 2014-02-19 20:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\BANDISOFT
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-02-19 12:10 - 2014-02-19 12:10 - 00000836 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-02-19 12:09 - 2014-03-12 01:04 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent
2014-02-18 03:23 - 2014-02-18 03:23 - 00000000 ____D () C:\Users\Administrator\Documents\Rockstar Games
2014-02-17 18:28 - 2014-02-18 02:23 - 00000000 ____D () C:\Users\Administrator\Documents\My Games
2014-02-14 03:45 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-14 03:45 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-14 03:44 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-14 03:44 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-14 03:44 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-14 03:44 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-14 03:44 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-14 03:44 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-14 03:44 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-14 03:44 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-14 03:44 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-14 03:44 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-14 03:44 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-14 03:44 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-14 03:44 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-14 03:44 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-14 03:44 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-14 03:44 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-14 03:44 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-14 03:44 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-14 03:44 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-14 03:44 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-14 03:44 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-14 03:44 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-14 03:44 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-14 03:44 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-14 03:44 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-14 03:44 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-14 03:44 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-14 03:44 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-14 03:44 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-14 03:44 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-14 03:44 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-14 03:44 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-14 03:44 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-14 03:44 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-14 03:44 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-14 03:44 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-14 03:44 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-14 03:44 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-14 03:44 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-13 23:19 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-13 23:19 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-13 23:19 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-13 23:19 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-13 23:19 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-13 23:19 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-13 23:19 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-13 23:19 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 23:19 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-13 23:19 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-13 23:19 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-13 23:18 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-13 23:18 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-13 23:18 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-13 23:18 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-13 22:25 - 2014-02-13 22:25 - 00000000 ____D () C:\Users\PC\Documents\Rockstar Games
2014-02-13 22:14 - 2014-02-13 22:14 - 00003178 _____ () C:\Windows\System32\Tasks\{57E8181A-0929-418A-A72C-CE10D919BEE8}
2014-02-13 22:12 - 2014-02-13 22:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-02-13 22:04 - 2014-03-05 18:04 - 00000289 _____ () C:\Windows\SysWOW64\ScriptHook.log
2014-02-13 22:03 - 2014-02-13 22:03 - 00336384 _____ () C:\Windows\SysWOW64\ScriptHook.dll
2014-02-13 03:16 - 2014-02-13 03:16 - 00000000 ____D () C:\Neuer Ordner
2014-02-12 22:16 - 2014-02-12 22:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-12 21:23 - 2014-02-12 21:23 - 00000000 ____D () C:\Program Files\PowerISO
2014-02-12 20:53 - 2013-10-23 15:11 - 00129944 _____ (Power Software Ltd) C:\Windows\system32\Drivers\scdemu.sys
2014-02-12 20:36 - 2014-02-12 20:36 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PowerISO
2014-02-12 20:30 - 2014-02-12 20:30 - 00000000 ____D () C:\Users\PC\AppData\Local\Disc_Soft_Ltd
2014-02-12 20:28 - 2014-02-12 20:28 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DAEMON Tools Ultra
2014-02-11 16:33 - 2014-02-24 16:19 - 00003350 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-11 02:25 - 2014-02-11 02:25 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\New Technology Studio
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenIV
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Local\New Technology Studio
2014-02-11 00:41 - 2014-02-11 00:54 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\www.gtavicecity.ru
2014-02-10 22:05 - 2014-02-10 22:05 - 00000000 ____D () C:\Users\PC\AppData\Local\EMU
2014-02-10 21:12 - 2014-02-10 21:12 - 01199079 _____ () C:\Windows\unins000.exe
2014-02-10 21:11 - 2014-02-10 21:11 - 00000000 ____D () C:\Users\PC\AppData\Local\Chromium
2014-02-10 13:26 - 2014-02-10 13:26 - 00000000 __RHD () C:\Users\PC\AppData\Roaming\SecuROM

==================== One Month Modified Files and Folders =======

2014-03-12 03:18 - 2014-03-03 20:40 - 00000000 ____D () C:\FRST
2014-03-12 03:18 - 2013-02-16 19:35 - 00000000 ___RD () C:\Users\Administrator\Desktop\bewerbung
2014-03-12 02:39 - 2013-02-23 17:34 - 00000916 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003UA.job
2014-03-12 02:39 - 2012-04-02 22:38 - 00281152 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-03-12 02:39 - 2012-04-02 19:19 - 00281152 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-03-12 02:36 - 2012-04-02 15:23 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-12 02:27 - 2012-04-02 15:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-12 02:10 - 2012-04-02 19:19 - 00281152 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-03-12 01:23 - 2014-03-09 05:09 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 2
2014-03-12 01:15 - 2014-03-12 01:15 - 00000000 __SHD () C:\Windows\ftpcache
2014-03-12 01:04 - 2014-02-19 12:09 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent
2014-03-12 00:21 - 2014-03-07 21:42 - 00001288 _____ () C:\Windows\setupact.log
2014-03-12 00:17 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-12 00:17 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-12 00:15 - 2014-03-07 23:32 - 00003350 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-12 00:15 - 2014-03-07 23:32 - 00003232 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-12 00:15 - 2013-11-24 17:04 - 00000442 ____H () C:\Windows\Tasks\SK.Enhancer-S-161304646.job
2014-03-12 00:15 - 2012-04-02 15:23 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-12 00:12 - 2012-04-02 15:12 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs
2014-03-12 00:12 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-11 14:44 - 2014-02-25 13:50 - 00726191 _____ () C:\Windows\WindowsUpdate.log
2014-03-11 14:28 - 2014-02-25 13:48 - 00003188 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-03-11 14:28 - 2014-02-01 15:22 - 00003328 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-03-11 08:56 - 2013-08-12 15:04 - 00000000 ____D () C:\Program Files\PeerBlock
2014-03-11 08:56 - 2012-04-02 14:43 - 00000000 ____D () C:\Users\PC\AppData\Roaming\uTorrent
2014-03-11 08:30 - 2014-03-11 08:30 - 00001001 _____ () C:\Users\PC\Desktop\My Downloads - Verknüpfung.lnk
2014-03-11 08:30 - 2014-03-01 20:01 - 00055296 ___SH () C:\Users\PC\Thumbs.db
2014-03-11 08:30 - 2012-04-02 14:26 - 00000000 ____D () C:\Users\PC
2014-03-11 08:24 - 2014-03-11 08:24 - 00014541 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Lekar.Uchen1k.Aviacenna.2014.D.WEB-DLRip.1400Mb_0.torrent
2014-03-11 01:24 - 2014-03-09 04:51 - 00012134 _____ () C:\Windows\PFRO.log
2014-03-11 01:23 - 2014-01-11 00:00 - 00000000 ____D () C:\AdwCleaner
2014-03-11 01:21 - 2014-03-11 01:21 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-11 01:19 - 2014-03-11 01:18 - 02347384 _____ (ESET) C:\Users\Administrator\Downloads\esetsmartinstaller_enu.exe
2014-03-11 01:18 - 2014-03-09 03:57 - 00115180 _____ () C:\Windows\DirectX.log
2014-03-11 01:17 - 2014-03-11 01:17 - 01949184 _____ () C:\Users\Administrator\Downloads\adwcleaner_3.021.exe
2014-03-11 01:13 - 2014-03-10 06:58 - 00000000 ____D () C:\Program Files (x86)\EA GAMES
2014-03-11 01:13 - 2012-03-07 00:47 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-11 00:23 - 2014-03-11 00:23 - 08065840 _____ (Cheat Engine ) C:\Users\Administrator\Downloads\CheatEngine63.exe
2014-03-11 00:23 - 2014-03-11 00:23 - 00000000 ____D () C:\Program Files (x86)\Cheat Engine 6.3
2014-03-10 17:39 - 2013-02-23 17:34 - 00000894 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003Core.job
2014-03-10 17:25 - 2014-03-10 17:24 - 00000000 ____D () C:\FreeTorrentViewer
2014-03-10 17:24 - 2014-03-10 17:24 - 00001075 _____ () C:\Users\PC\Desktop\Free Torrent Viewer.lnk
2014-03-10 17:24 - 2014-03-10 17:24 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeTorrentViewer
2014-03-10 17:24 - 2014-03-10 17:24 - 00000000 ____D () C:\Program Files (x86)\FreeTorrentViewer
2014-03-10 17:22 - 2014-03-10 17:22 - 00000000 ____D () C:\Users\PC\Downloads\We Are Explorers - 3D Printed Video
2014-03-10 17:21 - 2014-03-10 17:21 - 00000845 _____ () C:\Users\PC\Desktop\µTorrent.lnk
2014-03-10 17:21 - 2014-02-07 06:28 - 00000825 _____ () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-03-10 00:41 - 2012-04-15 21:26 - 00000000 ____D () C:\ProgramData\Origin
2014-03-09 23:07 - 2013-11-08 20:14 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Origin
2014-03-09 22:31 - 2012-04-15 21:25 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-03-09 19:20 - 2013-10-26 19:40 - 00000000 ____D () C:\Users\Administrator
2014-03-09 18:11 - 2014-03-09 18:11 - 00003156 _____ () C:\Windows\System32\Tasks\{B6ED3387-65BE-4D2B-90AE-0ECABF44F5B3}
2014-03-09 05:09 - 2014-03-05 18:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-03-08 23:51 - 2014-03-08 23:51 - 00003194 _____ () C:\Windows\System32\Tasks\{7F2CB0BF-4EB1-428B-85A8-2CC9BBF62917}
2014-03-08 21:00 - 2012-04-27 19:42 - 00000069 _____ () C:\Windows\NeroDigital.ini
2014-03-08 20:06 - 2012-04-03 07:57 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-03-08 20:06 - 2012-04-03 07:57 - 00000000 ____D () C:\Program Files (x86)\QuickTime Alternative
2014-03-07 23:34 - 2013-10-26 19:42 - 00000000 ___DC () C:\Users\Administrator\Desktop\Neuer Ordner
2014-03-07 22:59 - 2013-11-08 20:08 - 00000000 ____D () C:\Users\Administrator\Desktop\dzhan
2014-03-07 22:50 - 2013-10-26 19:41 - 00070520 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-07 21:42 - 2014-03-07 21:42 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-07 21:42 - 2014-03-01 06:47 - 00070520 _____ () C:\Users\PC\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-07 21:42 - 2012-04-03 05:05 - 00000000 ___RD () C:\Users\PC\Desktop\PROGRAMME
2014-03-07 21:21 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-03-07 21:20 - 2012-04-02 14:27 - 00001339 _____ () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-07 21:20 - 2012-04-02 14:27 - 00000000 ___RD () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-07 21:20 - 2012-04-02 14:27 - 00000000 ___RD () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-07 21:18 - 2014-02-25 18:53 - 00306000 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-07 21:15 - 2009-07-14 03:34 - 00000439 _____ () C:\Windows\win.ini
2014-03-07 20:55 - 2014-03-07 20:17 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2014-03-07 19:47 - 2014-03-07 19:47 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-03-07 15:16 - 2014-03-07 14:57 - 782111825 ____R () C:\Users\Administrator\Desktop\2.Guns.2013.HDRip-AVC_By WazZzup.mkv
2014-03-07 14:38 - 2014-03-04 15:20 - 00001160 ____H () C:\Users\Administrator\Desktop\$$JetTHM$$.cache
2014-03-07 04:04 - 2012-04-02 15:12 - 00010691 _____ () C:\Windows\system32\lvcoinst.log
2014-03-06 15:06 - 2014-03-01 20:12 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Windows Live
2014-03-06 14:56 - 2014-03-06 14:56 - 00000000 ____D () C:\Users\Administrator\Desktop\08951603108
2014-03-06 14:51 - 2014-03-06 14:51 - 00000000 ____D () C:\Users\Administrator\Desktop\004989516003101
2014-03-06 13:31 - 2014-03-06 13:31 - 00000000 ____D () C:\Users\Administrator\Desktop\munchen
2014-03-06 13:24 - 2013-10-30 10:39 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-03-05 23:18 - 2014-03-05 23:18 - 00001513 _____ () C:\Users\Administrator\AppData\Local\recently-used.xbel
2014-03-05 23:18 - 2014-03-05 23:16 - 00000000 ____D () C:\Users\Administrator\AppData\Local\gtk-2.0
2014-03-05 23:14 - 2014-03-05 23:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\gegl-0.2
2014-03-05 22:02 - 2013-11-10 18:01 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-05 22:02 - 2013-11-02 14:14 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\DVDVideoSoft
2014-03-05 18:07 - 2014-03-05 18:06 - 00000000 ____D () C:\Users\Administrator\Documents\GTA San Andreas User Files
2014-03-05 18:04 - 2014-02-13 22:04 - 00000289 _____ () C:\Windows\SysWOW64\ScriptHook.log
2014-03-05 02:42 - 2014-03-05 02:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-05 02:12 - 2014-03-05 02:12 - 00000000 ____D () C:\Users\Administrator\Documents\FreemakeVideoConverter
2014-03-04 22:48 - 2012-04-11 07:01 - 00000000 ____D () C:\Windows\Minidump
2014-03-04 22:32 - 2014-03-04 22:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\WMTools Downloaded Files
2014-03-04 19:38 - 2013-10-26 19:41 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-04 19:20 - 2014-03-04 19:20 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Adobe
2014-03-04 19:20 - 2013-10-26 19:41 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-03-04 18:39 - 2013-10-26 19:40 - 00000008 __RSH () C:\Users\Administrator\ntuser.pol
2014-03-04 18:39 - 2013-06-14 16:23 - 00000322 __RSH () C:\Users\PC\ntuser.pol
2014-03-04 18:38 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-03-04 15:12 - 2014-03-04 15:12 - 00000000 ____D () C:\Users\Administrator\Documents\Freemake
2014-03-04 15:10 - 2014-03-04 15:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\COWON
2014-03-04 15:05 - 2013-11-24 03:03 - 00000000 ____D () C:\Users\PC\Desktop\na more
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2014-03-04 11:40 - 2012-06-27 13:08 - 00002139 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-04 01:57 - 2014-03-04 01:57 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LavasoftStatistics
2014-03-04 01:51 - 2014-03-04 01:51 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-03-03 21:58 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\DVDVideoSoft
2014-03-03 21:58 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Assassin's Creed Revelations
2014-03-03 21:57 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 3
2014-03-03 20:25 - 2014-02-22 23:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PhotoScape
2014-03-03 20:25 - 2013-09-15 14:00 - 00000000 ____D () C:\Program Files (x86)\RusTV Player
2014-03-03 20:25 - 2012-07-04 13:30 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-03 20:25 - 2012-07-04 13:30 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-03 20:25 - 2012-07-04 13:29 - 00000000 ____D () C:\Users\Gast
2014-03-03 20:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-03-03 20:24 - 2013-11-08 20:15 - 00000000 ____D () C:\Users\Administrator\AppData\Local\PunkBuster
2014-03-03 20:24 - 2012-04-03 04:54 - 00000000 ____D () C:\ProgramData\Real
2014-03-03 20:24 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-03-02 05:39 - 2014-03-02 05:39 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Auslogics
2014-03-02 05:26 - 2013-06-28 21:37 - 00000000 ____D () C:\Program Files\WinRAR
2014-03-02 05:25 - 2014-03-01 19:45 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
2014-03-02 05:25 - 2014-01-29 08:54 - 00000000 ____D () C:\Users\PC\Downloads\Neuer Ordner
2014-03-02 05:25 - 2013-10-03 18:31 - 00000000 ____D () C:\Program Files (x86)\Ss.Helper
2014-03-02 02:41 - 2014-03-02 02:41 - 00000000 ____D () C:\Program Files (x86)\SmartTweak Software
2014-03-02 02:11 - 2014-03-02 02:11 - 00002788 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-02 02:11 - 2012-04-03 05:00 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-01 21:21 - 2014-03-01 20:21 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PhotoScape
2014-03-01 20:39 - 2013-08-29 23:53 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DVDVideoSoft
2014-03-01 20:18 - 2014-03-01 20:18 - 00000000 ____D () C:\Windows\de
2014-03-01 20:17 - 2014-03-01 20:17 - 00000000 ____D () C:\Windows\en
2014-03-01 20:16 - 2014-03-01 20:16 - 00000000 ____D () C:\Windows\ru
2014-03-01 20:15 - 2012-04-02 16:35 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-03-01 13:21 - 2014-03-01 13:21 - 00021008 _____ () C:\Users\PC\Desktop\Mein Film bbbb.wlmp
2014-03-01 07:19 - 2014-03-01 07:12 - 377248555 _____ () C:\Users\PC\Desktop\Mein Film 1.mp4
2014-02-27 12:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-27 11:13 - 2014-02-27 11:13 - 00000088 _____ () C:\Users\PC\Desktop\Два ствола скачать торрент в хорошем качестве бесплатно dvdrip, hdrip.url
2014-02-27 10:52 - 2014-02-27 10:52 - 00000000 ____D () C:\Users\PC\Desktop\08951603108
2014-02-26 21:09 - 2013-10-03 23:18 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\WinArchiver
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Program Files (x86)\WinArchiver
2014-02-26 19:49 - 2014-02-26 19:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-26 19:48 - 2014-02-26 19:48 - 00000000 ____D () C:\Program Files\Java
2014-02-26 19:44 - 2014-02-26 19:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PowerISO
2014-02-26 00:02 - 2014-02-26 00:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes
2014-02-25 01:38 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-02-24 23:54 - 2012-04-03 15:38 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-02-24 23:54 - 2012-04-03 15:38 - 00000000 ____D () C:\ProgramData\Skype
2014-02-24 17:17 - 2012-11-25 00:19 - 00000000 ____D () C:\Program Files (x86)\rhv
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Malwarebytes
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-24 16:49 - 2012-04-03 13:33 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-24 16:19 - 2014-02-11 16:33 - 00003350 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-24 16:19 - 2013-12-12 18:48 - 00003210 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-23 23:16 - 2014-02-23 22:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Electronic_Arts_Inc
2014-02-23 23:06 - 2014-02-23 23:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Need for Speed World
2014-02-23 02:16 - 2013-12-31 21:25 - 00000000 ____D () C:\Program Files\Realmware
2014-02-23 01:58 - 2014-02-23 01:58 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Realmware
2014-02-22 23:12 - 2014-02-22 23:05 - 00008192 ____H () C:\Users\Administrator\Desktop\photothumb.db
2014-02-22 03:34 - 2012-05-03 07:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-22 01:08 - 2012-05-26 18:55 - 00000000 ____D () C:\Users\PC\AppData\Local\Electronic_Arts_Inc
2014-02-22 01:00 - 2014-02-22 01:00 - 00000000 ____D () C:\Users\PC\Desktop\login
2014-02-21 21:49 - 2012-04-04 16:15 - 00042496 _____ () C:\Users\PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-21 17:45 - 2014-02-21 17:45 - 00000000 ____D () C:\Users\PC\Desktop\httpwww.youtube.comwatchv=OGnIS_a54ak
2014-02-21 17:39 - 2014-01-15 18:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-21 07:27 - 2012-04-02 15:23 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-21 07:27 - 2012-04-02 15:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-21 07:27 - 2012-04-02 15:23 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-20 00:08 - 2014-02-20 00:08 - 00000000 ____D () C:\Users\Administrator\AppData\Local\EMU
2014-02-19 20:45 - 2014-02-19 20:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Theta
2014-02-19 20:28 - 2014-02-19 20:28 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-02-19 20:10 - 2014-02-19 20:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\BANDISOFT
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-02-19 12:10 - 2014-02-19 12:10 - 00000836 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-02-18 03:23 - 2014-02-18 03:23 - 00000000 ____D () C:\Users\Administrator\Documents\Rockstar Games
2014-02-18 02:23 - 2014-02-17 18:28 - 00000000 ____D () C:\Users\Administrator\Documents\My Games
2014-02-18 02:18 - 2013-07-28 12:00 - 00000000 ____D () C:\Users\PC\Documents\My Games
2014-02-16 05:04 - 2013-11-24 15:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-16 05:00 - 2012-04-02 15:15 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-13 22:25 - 2014-02-13 22:25 - 00000000 ____D () C:\Users\PC\Documents\Rockstar Games
2014-02-13 22:14 - 2014-02-13 22:14 - 00003178 _____ () C:\Windows\System32\Tasks\{57E8181A-0929-418A-A72C-CE10D919BEE8}
2014-02-13 22:12 - 2014-02-13 22:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-02-13 22:03 - 2014-02-13 22:03 - 00336384 _____ () C:\Windows\SysWOW64\ScriptHook.dll
2014-02-13 18:31 - 2012-04-02 15:23 - 00004098 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-13 18:31 - 2012-04-02 15:23 - 00003846 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-13 03:16 - 2014-02-13 03:16 - 00000000 ____D () C:\Neuer Ordner
2014-02-12 22:16 - 2014-02-12 22:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-12 21:23 - 2014-02-12 21:23 - 00000000 ____D () C:\Program Files\PowerISO
2014-02-12 20:36 - 2014-02-12 20:36 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PowerISO
2014-02-12 20:30 - 2014-02-12 20:30 - 00000000 ____D () C:\Users\PC\AppData\Local\Disc_Soft_Ltd
2014-02-12 20:28 - 2014-02-12 20:28 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DAEMON Tools Ultra
2014-02-11 02:25 - 2014-02-11 02:25 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\New Technology Studio
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenIV
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Local\New Technology Studio
2014-02-11 00:54 - 2014-02-11 00:41 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\www.gtavicecity.ru
2014-02-10 22:05 - 2014-02-10 22:05 - 00000000 ____D () C:\Users\PC\AppData\Local\EMU
2014-02-10 21:57 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-10 21:12 - 2014-02-10 21:12 - 01199079 _____ () C:\Windows\unins000.exe
2014-02-10 21:12 - 2014-01-25 21:41 - 00080705 _____ () C:\Windows\unins000.dat
2014-02-10 21:11 - 2014-02-10 21:11 - 00000000 ____D () C:\Users\PC\AppData\Local\Chromium
2014-02-10 19:50 - 2014-01-03 01:25 - 00000000 ____D () C:\Users\PC\Documents\Arma 3 Alpha
2014-02-10 13:26 - 2014-02-10 13:26 - 00000000 __RHD () C:\Users\PC\AppData\Roaming\SecuROM

Files to move or delete:
====================
C:\Users\Gast\AppData\Roaming\CamLayout.ini
C:\Users\Gast\AppData\Roaming\CamShapes.ini
C:\Users\PC\AppData\Roaming\CamLayout.ini
C:\Users\PC\AppData\Roaming\CamShapes.ini
C:\ProgramData\qjaxlkio.dss


Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\Gast\AppData\Local\Temp\AskSLib.dll
C:\Users\Gast\AppData\Local\Temp\avgnt.exe
C:\Users\Gast\AppData\Local\Temp\install_flashplayer11x32axau_mssa_aaa_aih.exe
C:\Users\Gast\AppData\Local\Temp\kpinstaller.exe
C:\Users\Gast\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\PC\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-10 15:05

==================== End Of Log ============================

--- --- ---

--- --- ---
mfg

mort 12.03.2014 10:48

Wir sollten bald durch sein.

Schritt 1

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: No Name - {74D271A4-00A7-0F5C-560A-2412C0CFD357} -  No File
BHO-x32: No Name - {8984B388-A5BB-4DF7-B274-77B879E179DB} -  No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mailru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ozonru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\priceru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-slovari.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex.xml
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\ProgramData\qjaxlkio.dss


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Drancer 12.03.2014 22:29

Zitat:

Zitat von mort (Beitrag 1266831)
Wir sollten bald durch sein.

Schritt 1

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: No Name - {74D271A4-00A7-0F5C-560A-2412C0CFD357} -  No File
BHO-x32: No Name - {8984B388-A5BB-4DF7-B274-77B879E179DB} -  No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mailru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ozonru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\priceru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-slovari.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex.xml
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\ProgramData\qjaxlkio.dss


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

Der Log :
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-03-2014
Ran by PC at 2014-03-12 22:27:30 Run:5
Running from C:\Users\PC\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: No Name - {74D271A4-00A7-0F5C-560A-2412C0CFD357} -  No File
BHO-x32: No Name - {8984B388-A5BB-4DF7-B274-77B879E179DB} -  No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mailru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ozonru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\priceru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-slovari.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex.xml
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\ProgramData\qjaxlkio.dss
       
*****************

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74D271A4-00A7-0F5C-560A-2412C0CFD357} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{74D271A4-00A7-0F5C-560A-2412C0CFD357} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8984B388-A5BB-4DF7-B274-77B879E179DB} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{8984B388-A5BB-4DF7-B274-77B879E179DB} => Key not found.
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mailru.xml => Moved successfully.
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ozonru.xml => Moved successfully.
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\priceru.xml => Moved successfully.
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-slovari.xml => Moved successfully.
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex.xml => Moved successfully.
HKLM\SOFTWARE\Policies\Google => Unable to delete key
C:\ProgramData\qjaxlkio.dss => Moved successfully.

==== End of Fixlog ====


mort 13.03.2014 08:38

Schritt 1


Starte noch einmal FRST.

  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, werden ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.

Drancer 14.03.2014 18:43

Zitat:

Zitat von mort (Beitrag 1267266)
Schritt 1


Starte noch einmal FRST.

  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, werden ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.

Sorry nochmal das es manchmal so dauert bis ich poste, ich habe nicht immer viel zeit dafür.


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by PC (administrator) on PC-PC on 14-03-2014 18:40:46
Running from C:\Users\PC\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

() C:\Program Files (x86)\WinArchiver\WAService.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Doctor Web, Ltd.) C:\Program Files (x86)\TrafInsp\plugins\DwAV\Engine\dwengine.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(SMART-SOFT) C:\Program Files (x86)\TrafInsp\TrafInsp.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(SMART-SOFT) C:\Program Files (x86)\TrafInsp\ASP.NET\bin\TIASPNETHostServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7198424 2013-08-28] (Realtek Semiconductor)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-03-13] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-11-09] (RealNetworks, Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime Alternative\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-2263356855-1520679738-450664524-1003\...\Run: [Pokki] - C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform

==================== Internet (Whitelisted) ====================

SearchScopes: HKLM - DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.66.2.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\searchplugins\mailru---.xml
FF SearchPlugin: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\searchplugins\webalta-search.xml
FF Extension: Battlefield Play4Free - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\battlefieldplay4free@ea.com [2012-05-18]
FF Extension: SearchNewTab - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\bpax7a@vekpbgey.org [2013-10-04]
FF Extension: SearchNewTab - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\hqjs4vg@kfajdmhuia.net [2013-11-24]
FF Extension: Downloaed keepEr - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\oa9nnk_ifjm@xoeyavoayo.com [2013-10-04]
FF Extension: SearchNewTab - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\oai5cavr@aasvlrcz.net [2013-10-16]
FF Extension: VideoFileDownload - Download YouTube Videos - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\plugin@videofiledownload.com [2012-06-25]
FF Extension: Flash and Video Download - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2014-02-21]
FF Extension: Youtube Downloader - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\youtube_downloader@anishsane.googlepages.com.xpi [2012-08-27]
FF Extension: Easy YouTube Video Downloader - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi [2012-06-27]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-11-09]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2012-06-21] ()
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-03-13] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-03-13] (Avira Operations GmbH & Co. KG)
R2 DrWebEngine; C:\Program Files (x86)\TrafInsp\plugins\DwAV\Engine\dwengine.exe [1667416 2012-06-28] (Doctor Web, Ltd.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5148240 2013-07-23] (INCA Internet Co., Ltd.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-31] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 TrafInspSrv; C:\Program Files (x86)\TrafInsp\TrafInsp.exe [4475392 2012-06-08] (SMART-SOFT)
R2 WinArchiver Service; C:\Program Files (x86)\WinArchiver\WAService.exe [202264 2013-11-10] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
S3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [22600 2013-11-18] ()
R1 TICAPDRV; C:\Windows\System32\DRIVERS\ticap.sys [265880 2012-01-20] (SMART-SOFT)
R0 waemu; C:\Windows\System32\Drivers\waemu.sys [140184 2013-11-10] (Power Software Ltd)
S2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S3 cpuz136; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S2 NEWDRIVER; \??\C:\Windows\SysWow64\WinVDEdrv6.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-14 18:40 - 2014-03-14 18:40 - 00016525 _____ () C:\Users\PC\Downloads\FRST.txt
2014-03-14 18:39 - 2014-03-14 18:39 - 02157056 _____ (Farbar) C:\Users\PC\Downloads\FRST64.exe
2014-03-14 07:09 - 2014-03-14 07:17 - 00000000 ____D () C:\Users\PC\Downloads\Interny.(10.sezon).2013.WEB-DL.(720p).MediaClub
2014-03-14 06:30 - 2014-03-14 06:30 - 00001142 _____ () C:\Windows\PFRO.log
2014-03-13 06:41 - 2014-03-14 16:46 - 00000000 ____D () C:\Users\PC\Downloads\Druzhba.narodov.2013.WEB-DL.(720p).MediaClub
2014-03-13 06:17 - 2014-03-14 07:00 - 00000000 ____D () C:\Users\PC\Downloads\Getery.majora.Sokolova.2014.SATRip.Files-x
2014-03-13 03:26 - 2014-03-13 03:26 - 03821624 _____ () C:\Users\Administrator\Downloads\battlelog-web-plugins_2.3.2_131.exe
2014-03-12 22:05 - 2014-03-12 22:05 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-03-12 22:05 - 2014-03-12 22:05 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-03-12 22:05 - 2014-03-12 22:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-03-12 22:04 - 2014-03-01 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-12 22:04 - 2014-03-01 06:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 22:04 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 22:04 - 2014-03-01 05:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 22:04 - 2014-03-01 05:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 22:04 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-12 22:04 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-12 22:04 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-12 22:04 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-12 22:04 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-12 22:04 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-12 22:04 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 22:04 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-12 22:04 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-12 22:04 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-12 22:04 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-12 22:04 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-12 22:04 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 22:04 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-12 22:03 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-12 22:03 - 2014-03-01 05:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 22:03 - 2014-03-01 05:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 22:03 - 2014-03-01 05:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 22:03 - 2014-03-01 05:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 22:03 - 2014-03-01 05:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 22:03 - 2014-03-01 05:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 22:03 - 2014-03-01 05:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 22:03 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 22:03 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-12 22:03 - 2014-03-01 05:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 22:03 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 22:03 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-12 22:03 - 2014-03-01 04:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 22:03 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 22:03 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-12 22:03 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-12 22:03 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 22:03 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-12 22:03 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 22:03 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-12 22:03 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 22:03 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-12 22:03 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-12 22:03 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-12 22:01 - 2014-02-04 03:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-12 22:01 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 22:01 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-12 22:01 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-12 21:58 - 2014-03-13 21:54 - 00003350 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-12 18:16 - 2014-03-14 18:37 - 00000560 _____ () C:\Windows\setupact.log
2014-03-12 18:16 - 2014-03-12 22:22 - 00306000 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-12 18:16 - 2014-03-12 18:16 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-12 15:01 - 2014-03-12 15:01 - 00000000 ____D () C:\Freemake
2014-03-12 14:09 - 2014-03-12 14:09 - 00000000 ____D () C:\Users\PC\Downloads\Cosmos.A.SpaceTime.Odyssey.Season.01.HDTV.720p
2014-03-12 14:04 - 2014-03-12 14:05 - 00000000 ____D () C:\Users\PC\Downloads\Genery.majora.Sokolova.2014.SATRip.Files-x
2014-03-12 14:00 - 2014-03-14 07:01 - 00000000 ____D () C:\Users\PC\Downloads\Kuhnja.3.SATRip
2014-03-12 01:15 - 2014-03-12 01:15 - 00000000 __SHD () C:\Windows\ftpcache
2014-03-11 08:30 - 2014-03-11 08:30 - 00001001 _____ () C:\Users\PC\Desktop\My Downloads - Verknüpfung.lnk
2014-03-11 01:21 - 2014-03-11 01:21 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-11 01:17 - 2014-03-11 01:17 - 01949184 _____ () C:\Users\Administrator\Downloads\adwcleaner_3.021.exe
2014-03-11 00:23 - 2014-03-11 00:23 - 00000000 ____D () C:\Program Files (x86)\Cheat Engine 6.3
2014-03-10 17:24 - 2014-03-10 17:25 - 00000000 ____D () C:\FreeTorrentViewer
2014-03-10 17:24 - 2014-03-10 17:24 - 00001075 _____ () C:\Users\PC\Desktop\Free Torrent Viewer.lnk
2014-03-10 17:24 - 2014-03-10 17:24 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeTorrentViewer
2014-03-10 17:24 - 2014-03-10 17:24 - 00000000 ____D () C:\Program Files (x86)\FreeTorrentViewer
2014-03-10 17:22 - 2014-03-10 17:22 - 00000000 ____D () C:\Users\PC\Downloads\We Are Explorers - 3D Printed Video
2014-03-10 17:21 - 2014-03-10 17:21 - 00000845 _____ () C:\Users\PC\Desktop\µTorrent.lnk
2014-03-10 06:58 - 2014-03-11 01:13 - 00000000 ____D () C:\Program Files (x86)\EA GAMES
2014-03-09 18:11 - 2014-03-09 18:11 - 00003156 _____ () C:\Windows\System32\Tasks\{B6ED3387-65BE-4D2B-90AE-0ECABF44F5B3}
2014-03-09 05:09 - 2014-03-12 01:23 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 2
2014-03-08 23:51 - 2014-03-08 23:51 - 00003194 _____ () C:\Windows\System32\Tasks\{7F2CB0BF-4EB1-428B-85A8-2CC9BBF62917}
2014-03-07 23:32 - 2014-03-13 21:54 - 00003232 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-07 20:17 - 2014-03-07 20:55 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2014-03-07 19:47 - 2014-03-07 19:47 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-03-07 14:57 - 2014-03-07 15:16 - 782111825 ____R () C:\Users\Administrator\Desktop\2.Guns.2013.HDRip-AVC_By WazZzup.mkv
2014-03-06 14:56 - 2014-03-06 14:56 - 00000000 ____D () C:\Users\Administrator\Desktop\08951603108
2014-03-06 14:51 - 2014-03-06 14:51 - 00000000 ____D () C:\Users\Administrator\Desktop\004989516003101
2014-03-06 13:31 - 2014-03-06 13:31 - 00000000 ____D () C:\Users\Administrator\Desktop\munchen
2014-03-05 18:06 - 2014-03-09 05:09 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-03-05 18:06 - 2014-03-05 18:07 - 00000000 ____D () C:\Users\Administrator\Documents\GTA San Andreas User Files
2014-03-05 02:42 - 2014-03-05 02:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-05 02:12 - 2014-03-05 02:12 - 00000000 ____D () C:\Users\Administrator\Documents\FreemakeVideoConverter
2014-03-04 15:20 - 2014-03-07 14:38 - 00001160 ____H () C:\Users\Administrator\Desktop\$$JetTHM$$.cache
2014-03-04 15:12 - 2014-03-04 15:12 - 00000000 ____D () C:\Users\Administrator\Documents\Freemake
2014-03-04 15:10 - 2014-03-04 15:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\COWON
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-03-04 01:57 - 2014-03-04 01:57 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LavasoftStatistics
2014-03-04 01:51 - 2014-03-04 01:51 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-03-03 21:57 - 2014-03-03 21:58 - 00000000 ____D () C:\Users\Administrator\Documents\DVDVideoSoft
2014-03-03 21:57 - 2014-03-03 21:58 - 00000000 ____D () C:\Users\Administrator\Documents\Assassin's Creed Revelations
2014-03-03 21:57 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 3
2014-03-03 20:40 - 2014-03-14 18:40 - 00000000 ____D () C:\FRST
2014-03-02 05:39 - 2014-03-02 05:39 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Auslogics
2014-03-02 02:41 - 2014-03-02 02:41 - 00000000 ____D () C:\Program Files (x86)\SmartTweak Software
2014-03-02 02:11 - 2014-03-02 02:11 - 00002788 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-01 20:21 - 2014-03-01 21:21 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PhotoScape
2014-03-01 20:18 - 2014-03-01 20:18 - 00000000 ____D () C:\Windows\de
2014-03-01 20:17 - 2014-03-01 20:17 - 00000000 ____D () C:\Windows\en
2014-03-01 20:16 - 2014-03-01 20:16 - 00000000 ____D () C:\Windows\ru
2014-03-01 20:01 - 2014-03-11 08:30 - 00055296 ___SH () C:\Users\PC\Thumbs.db
2014-03-01 19:45 - 2014-03-02 05:25 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
2014-03-01 13:21 - 2014-03-01 13:21 - 00021008 _____ () C:\Users\PC\Desktop\Mein Film bbbb.wlmp
2014-03-01 07:12 - 2014-03-01 07:19 - 377248555 _____ () C:\Users\PC\Desktop\Mein Film 1.mp4
2014-02-27 11:13 - 2014-02-27 11:13 - 00000088 _____ () C:\Users\PC\Desktop\Два ствола скачать торрент в хорошем качестве бесплатно dvdrip, hdrip.url
2014-02-27 10:52 - 2014-02-27 10:52 - 00000000 ____D () C:\Users\PC\Desktop\08951603108
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\WinArchiver
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Program Files (x86)\WinArchiver
2014-02-26 19:54 - 2013-11-10 03:53 - 00140184 _____ (Power Software Ltd) C:\Windows\system32\Drivers\waemu.sys
2014-02-26 19:49 - 2014-02-26 19:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-26 19:48 - 2014-02-26 19:48 - 00000000 ____D () C:\Program Files\Java
2014-02-26 19:44 - 2014-02-26 19:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PowerISO
2014-02-26 14:01 - 2014-01-09 03:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-02-26 14:01 - 2014-01-03 23:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-02-26 00:02 - 2014-02-26 00:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes
2014-02-25 13:50 - 2014-03-14 08:04 - 01044303 _____ () C:\Windows\WindowsUpdate.log
2014-02-25 13:48 - 2014-03-14 15:12 - 00003188 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-24 23:55 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-02-24 23:54 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-02-24 23:54 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-02-24 23:54 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-02-24 23:54 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-02-24 23:54 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-02-24 23:54 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-02-24 23:54 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-02-24 23:54 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-02-24 23:54 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-02-24 23:54 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-02-24 23:54 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-02-24 23:54 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-02-24 23:54 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-02-24 23:54 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-02-24 23:54 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-02-24 23:53 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-02-24 23:53 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-02-24 23:53 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2014-02-24 23:53 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-02-24 23:53 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2014-02-24 23:53 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-02-24 23:53 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-02-24 23:52 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-02-24 23:52 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Malwarebytes
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-24 17:03 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-23 23:06 - 2014-02-23 23:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Need for Speed World
2014-02-22 23:05 - 2014-03-03 20:25 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PhotoScape
2014-02-22 23:05 - 2014-02-22 23:12 - 00008192 ____H () C:\Users\Administrator\Desktop\photothumb.db
2014-02-22 01:00 - 2014-02-22 01:00 - 00000000 ____D () C:\Users\PC\Desktop\login
2014-02-21 17:45 - 2014-02-21 17:45 - 00000000 ____D () C:\Users\PC\Desktop\httpwww.youtube.comwatchv=OGnIS_a54ak
2014-02-19 20:45 - 2014-02-19 20:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Theta
2014-02-19 20:28 - 2014-02-19 20:28 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-02-19 20:10 - 2014-02-19 20:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\BANDISOFT
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-02-19 12:10 - 2014-02-19 12:10 - 00000836 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-02-19 12:09 - 2014-03-12 01:04 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent
2014-02-18 03:23 - 2014-02-18 03:23 - 00000000 ____D () C:\Users\Administrator\Documents\Rockstar Games
2014-02-17 18:28 - 2014-02-18 02:23 - 00000000 ____D () C:\Users\Administrator\Documents\My Games
2014-02-14 03:45 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-14 03:45 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-13 23:19 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-13 23:19 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-13 23:19 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-13 23:19 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-13 23:19 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-13 23:19 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-13 23:19 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-13 23:19 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 23:19 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-13 23:19 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-13 23:19 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-13 23:18 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-13 23:18 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-13 23:18 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-13 23:18 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-13 22:25 - 2014-02-13 22:25 - 00000000 ____D () C:\Users\PC\Documents\Rockstar Games
2014-02-13 22:14 - 2014-02-13 22:14 - 00003178 _____ () C:\Windows\System32\Tasks\{57E8181A-0929-418A-A72C-CE10D919BEE8}
2014-02-13 22:12 - 2014-02-13 22:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-02-13 22:04 - 2014-03-05 18:04 - 00000289 _____ () C:\Windows\SysWOW64\ScriptHook.log
2014-02-13 22:03 - 2014-02-13 22:03 - 00336384 _____ () C:\Windows\SysWOW64\ScriptHook.dll
2014-02-13 03:16 - 2014-02-13 03:16 - 00000000 ____D () C:\Neuer Ordner
2014-02-12 22:16 - 2014-02-12 22:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-12 21:23 - 2014-02-12 21:23 - 00000000 ____D () C:\Program Files\PowerISO
2014-02-12 20:53 - 2013-10-23 15:11 - 00129944 _____ (Power Software Ltd) C:\Windows\system32\Drivers\scdemu.sys
2014-02-12 20:36 - 2014-02-12 20:36 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PowerISO
2014-02-12 20:28 - 2014-02-12 20:28 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DAEMON Tools Ultra

==================== One Month Modified Files and Folders =======

2014-03-14 18:41 - 2014-03-14 18:40 - 00016525 _____ () C:\Users\PC\Downloads\FRST.txt
2014-03-14 18:40 - 2014-03-03 20:40 - 00000000 ____D () C:\FRST
2014-03-14 18:39 - 2014-03-14 18:39 - 02157056 _____ (Farbar) C:\Users\PC\Downloads\FRST64.exe
2014-03-14 18:37 - 2014-03-12 18:16 - 00000560 _____ () C:\Windows\setupact.log
2014-03-14 18:36 - 2012-04-02 15:23 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-14 18:36 - 2012-04-02 15:23 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-14 18:27 - 2012-04-02 15:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-14 18:00 - 2014-02-25 13:50 - 01044303 _____ () C:\Windows\WindowsUpdate.log
2014-03-14 17:39 - 2013-02-23 17:34 - 00000916 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003UA.job
2014-03-14 17:39 - 2013-02-23 17:34 - 00000894 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003Core.job
2014-03-14 16:46 - 2014-03-13 06:41 - 00000000 ____D () C:\Users\PC\Downloads\Druzhba.narodov.2013.WEB-DL.(720p).MediaClub
2014-03-14 15:12 - 2014-02-25 13:48 - 00003188 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-03-14 15:12 - 2014-02-01 15:22 - 00003328 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-03-14 13:57 - 2012-04-27 19:42 - 00000069 _____ () C:\Windows\NeroDigital.ini
2014-03-14 13:57 - 2012-04-02 14:43 - 00000000 ____D () C:\Users\PC\AppData\Roaming\uTorrent
2014-03-14 07:17 - 2014-03-14 07:09 - 00000000 ____D () C:\Users\PC\Downloads\Interny.(10.sezon).2013.WEB-DL.(720p).MediaClub
2014-03-14 07:01 - 2014-03-12 14:00 - 00000000 ____D () C:\Users\PC\Downloads\Kuhnja.3.SATRip
2014-03-14 07:00 - 2014-03-13 06:17 - 00000000 ____D () C:\Users\PC\Downloads\Getery.majora.Sokolova.2014.SATRip.Files-x
2014-03-14 06:57 - 2013-11-24 17:04 - 00000442 ____H () C:\Windows\Tasks\SK.Enhancer-S-161304646.job
2014-03-14 06:36 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-14 06:36 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-14 06:30 - 2014-03-14 06:30 - 00001142 _____ () C:\Windows\PFRO.log
2014-03-14 06:30 - 2012-04-02 15:12 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs
2014-03-14 06:30 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-14 03:42 - 2012-04-02 22:38 - 00281152 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-03-14 03:42 - 2012-04-02 19:19 - 00281152 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-03-14 03:28 - 2012-04-02 19:19 - 00281152 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-03-14 02:07 - 2013-02-16 19:35 - 00000000 ___RD () C:\Users\Administrator\Desktop\bewerbung
2014-03-14 02:05 - 2014-01-11 00:00 - 00000000 ____D () C:\AdwCleaner
2014-03-13 21:54 - 2014-03-12 21:58 - 00003350 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-13 21:54 - 2014-03-07 23:32 - 00003232 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-13 13:25 - 2014-02-11 16:33 - 00003350 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-03-13 13:25 - 2013-12-12 18:48 - 00003210 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-03-13 03:26 - 2014-03-13 03:26 - 03821624 _____ () C:\Users\Administrator\Downloads\battlelog-web-plugins_2.3.2_131.exe
2014-03-13 03:26 - 2012-04-16 09:36 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-03-12 22:24 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-03-12 22:22 - 2014-03-12 18:16 - 00306000 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-12 22:22 - 2012-05-18 17:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-12 22:22 - 2012-05-18 17:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-12 22:20 - 2013-10-26 19:42 - 00000000 ___DC () C:\Users\Administrator\Desktop\Neuer Ordner
2014-03-12 22:09 - 2012-04-02 15:12 - 00011325 _____ () C:\Windows\system32\lvcoinst.log
2014-03-12 22:08 - 2013-11-24 15:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-12 22:07 - 2012-04-02 15:15 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-12 22:05 - 2014-03-12 22:05 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-03-12 22:05 - 2014-03-12 22:05 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-03-12 22:05 - 2014-03-12 22:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-03-12 18:16 - 2014-03-12 18:16 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-12 15:27 - 2012-04-02 15:23 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 15:27 - 2012-04-02 15:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-12 15:27 - 2012-04-02 15:23 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-12 15:01 - 2014-03-12 15:01 - 00000000 ____D () C:\Freemake
2014-03-12 14:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenIV
2014-03-12 14:10 - 2014-01-03 23:08 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-03-12 14:09 - 2014-03-12 14:09 - 00000000 ____D () C:\Users\PC\Downloads\Cosmos.A.SpaceTime.Odyssey.Season.01.HDTV.720p
2014-03-12 14:05 - 2014-03-12 14:04 - 00000000 ____D () C:\Users\PC\Downloads\Genery.majora.Sokolova.2014.SATRip.Files-x
2014-03-12 01:23 - 2014-03-09 05:09 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 2
2014-03-12 01:15 - 2014-03-12 01:15 - 00000000 __SHD () C:\Windows\ftpcache
2014-03-12 01:04 - 2014-02-19 12:09 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent
2014-03-11 08:56 - 2013-08-12 15:04 - 00000000 ____D () C:\Program Files\PeerBlock
2014-03-11 08:30 - 2014-03-11 08:30 - 00001001 _____ () C:\Users\PC\Desktop\My Downloads - Verknüpfung.lnk
2014-03-11 08:30 - 2014-03-01 20:01 - 00055296 ___SH () C:\Users\PC\Thumbs.db
2014-03-11 08:30 - 2012-04-02 14:26 - 00000000 ____D () C:\Users\PC
2014-03-11 01:21 - 2014-03-11 01:21 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-11 01:17 - 2014-03-11 01:17 - 01949184 _____ () C:\Users\Administrator\Downloads\adwcleaner_3.021.exe
2014-03-11 01:13 - 2014-03-10 06:58 - 00000000 ____D () C:\Program Files (x86)\EA GAMES
2014-03-11 01:13 - 2012-03-07 00:47 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-11 00:23 - 2014-03-11 00:23 - 00000000 ____D () C:\Program Files (x86)\Cheat Engine 6.3
2014-03-10 17:25 - 2014-03-10 17:24 - 00000000 ____D () C:\FreeTorrentViewer
2014-03-10 17:24 - 2014-03-10 17:24 - 00001075 _____ () C:\Users\PC\Desktop\Free Torrent Viewer.lnk
2014-03-10 17:24 - 2014-03-10 17:24 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeTorrentViewer
2014-03-10 17:24 - 2014-03-10 17:24 - 00000000 ____D () C:\Program Files (x86)\FreeTorrentViewer
2014-03-10 17:22 - 2014-03-10 17:22 - 00000000 ____D () C:\Users\PC\Downloads\We Are Explorers - 3D Printed Video
2014-03-10 17:21 - 2014-03-10 17:21 - 00000845 _____ () C:\Users\PC\Desktop\µTorrent.lnk
2014-03-10 17:21 - 2014-02-07 06:28 - 00000825 _____ () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-03-10 00:41 - 2012-04-15 21:26 - 00000000 ____D () C:\ProgramData\Origin
2014-03-09 23:07 - 2013-11-08 20:14 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Origin
2014-03-09 22:31 - 2012-04-15 21:25 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-03-09 19:20 - 2013-10-26 19:40 - 00000000 ____D () C:\Users\Administrator
2014-03-09 18:11 - 2014-03-09 18:11 - 00003156 _____ () C:\Windows\System32\Tasks\{B6ED3387-65BE-4D2B-90AE-0ECABF44F5B3}
2014-03-09 05:09 - 2014-03-05 18:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-03-08 23:51 - 2014-03-08 23:51 - 00003194 _____ () C:\Windows\System32\Tasks\{7F2CB0BF-4EB1-428B-85A8-2CC9BBF62917}
2014-03-08 20:06 - 2012-04-03 07:57 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-03-08 20:06 - 2012-04-03 07:57 - 00000000 ____D () C:\Program Files (x86)\QuickTime Alternative
2014-03-07 22:59 - 2013-11-08 20:08 - 00000000 ____D () C:\Users\Administrator\Desktop\dzhan
2014-03-07 21:42 - 2012-04-03 05:05 - 00000000 ___RD () C:\Users\PC\Desktop\PROGRAMME
2014-03-07 21:20 - 2012-04-02 14:27 - 00001339 _____ () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-07 21:20 - 2012-04-02 14:27 - 00000000 ___RD () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-07 21:20 - 2012-04-02 14:27 - 00000000 ___RD () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-07 21:15 - 2009-07-14 03:34 - 00000439 _____ () C:\Windows\win.ini
2014-03-07 20:55 - 2014-03-07 20:17 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2014-03-07 19:47 - 2014-03-07 19:47 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-03-07 15:16 - 2014-03-07 14:57 - 782111825 ____R () C:\Users\Administrator\Desktop\2.Guns.2013.HDRip-AVC_By WazZzup.mkv
2014-03-07 14:38 - 2014-03-04 15:20 - 00001160 ____H () C:\Users\Administrator\Desktop\$$JetTHM$$.cache
2014-03-06 14:56 - 2014-03-06 14:56 - 00000000 ____D () C:\Users\Administrator\Desktop\08951603108
2014-03-06 14:51 - 2014-03-06 14:51 - 00000000 ____D () C:\Users\Administrator\Desktop\004989516003101
2014-03-06 13:31 - 2014-03-06 13:31 - 00000000 ____D () C:\Users\Administrator\Desktop\munchen
2014-03-05 22:02 - 2013-11-10 18:01 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-05 22:02 - 2013-11-02 14:14 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\DVDVideoSoft
2014-03-05 18:07 - 2014-03-05 18:06 - 00000000 ____D () C:\Users\Administrator\Documents\GTA San Andreas User Files
2014-03-05 18:04 - 2014-02-13 22:04 - 00000289 _____ () C:\Windows\SysWOW64\ScriptHook.log
2014-03-05 02:42 - 2014-03-05 02:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-05 02:12 - 2014-03-05 02:12 - 00000000 ____D () C:\Users\Administrator\Documents\FreemakeVideoConverter
2014-03-04 22:48 - 2012-04-11 07:01 - 00000000 ____D () C:\Windows\Minidump
2014-03-04 19:38 - 2013-10-26 19:41 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-04 19:20 - 2013-10-26 19:41 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-03-04 18:39 - 2013-10-26 19:40 - 00000008 __RSH () C:\Users\Administrator\ntuser.pol
2014-03-04 18:39 - 2013-06-14 16:23 - 00000322 __RSH () C:\Users\PC\ntuser.pol
2014-03-04 18:38 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-03-04 15:12 - 2014-03-04 15:12 - 00000000 ____D () C:\Users\Administrator\Documents\Freemake
2014-03-04 15:10 - 2014-03-04 15:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\COWON
2014-03-04 15:05 - 2013-11-24 03:03 - 00000000 ____D () C:\Users\PC\Desktop\na more
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-03-04 11:40 - 2012-06-27 13:08 - 00002139 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-04 01:57 - 2014-03-04 01:57 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LavasoftStatistics
2014-03-04 01:51 - 2014-03-04 01:51 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-03-03 21:58 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\DVDVideoSoft
2014-03-03 21:58 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Assassin's Creed Revelations
2014-03-03 21:57 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 3
2014-03-03 20:25 - 2014-02-22 23:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PhotoScape
2014-03-03 20:25 - 2013-09-15 14:00 - 00000000 ____D () C:\Program Files (x86)\RusTV Player
2014-03-03 20:25 - 2012-07-04 13:30 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-03 20:25 - 2012-07-04 13:30 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-03 20:25 - 2012-07-04 13:29 - 00000000 ____D () C:\Users\Gast
2014-03-03 20:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-03-03 20:24 - 2012-04-03 04:54 - 00000000 ____D () C:\ProgramData\Real
2014-03-03 20:24 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-03-02 05:39 - 2014-03-02 05:39 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Auslogics
2014-03-02 05:26 - 2013-06-28 21:37 - 00000000 ____D () C:\Program Files\WinRAR
2014-03-02 05:25 - 2014-03-01 19:45 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
2014-03-02 05:25 - 2014-01-29 08:54 - 00000000 ____D () C:\Users\PC\Downloads\Neuer Ordner
2014-03-02 05:25 - 2013-10-03 18:31 - 00000000 ____D () C:\Program Files (x86)\Ss.Helper
2014-03-02 02:41 - 2014-03-02 02:41 - 00000000 ____D () C:\Program Files (x86)\SmartTweak Software
2014-03-02 02:11 - 2014-03-02 02:11 - 00002788 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-02 02:11 - 2012-04-03 05:00 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-01 21:21 - 2014-03-01 20:21 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PhotoScape
2014-03-01 20:39 - 2013-08-29 23:53 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DVDVideoSoft
2014-03-01 20:18 - 2014-03-01 20:18 - 00000000 ____D () C:\Windows\de
2014-03-01 20:17 - 2014-03-01 20:17 - 00000000 ____D () C:\Windows\en
2014-03-01 20:16 - 2014-03-01 20:16 - 00000000 ____D () C:\Windows\ru
2014-03-01 20:15 - 2012-04-02 16:35 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-03-01 13:21 - 2014-03-01 13:21 - 00021008 _____ () C:\Users\PC\Desktop\Mein Film bbbb.wlmp
2014-03-01 07:19 - 2014-03-01 07:12 - 377248555 _____ () C:\Users\PC\Desktop\Mein Film 1.mp4
2014-03-01 07:05 - 2014-03-12 22:03 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 06:17 - 2014-03-12 22:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 06:16 - 2014-03-12 22:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 05:58 - 2014-03-12 22:04 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 05:52 - 2014-03-12 22:03 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 05:51 - 2014-03-12 22:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 05:42 - 2014-03-12 22:03 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 05:40 - 2014-03-12 22:04 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 05:37 - 2014-03-12 22:03 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 05:33 - 2014-03-12 22:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 05:33 - 2014-03-12 22:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 05:32 - 2014-03-12 22:03 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 05:30 - 2014-03-12 22:04 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-01 05:23 - 2014-03-12 22:03 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 05:17 - 2014-03-12 22:03 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 05:11 - 2014-03-12 22:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-01 05:02 - 2014-03-12 22:03 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 04:54 - 2014-03-12 22:03 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 04:52 - 2014-03-12 22:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-01 04:51 - 2014-03-12 22:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-01 04:47 - 2014-03-12 22:04 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-01 04:43 - 2014-03-12 22:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-01 04:43 - 2014-03-12 22:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-01 04:42 - 2014-03-12 22:04 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 04:40 - 2014-03-12 22:04 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-01 04:38 - 2014-03-12 22:03 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-01 04:37 - 2014-03-12 22:04 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-01 04:35 - 2014-03-12 22:03 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 04:18 - 2014-03-12 22:03 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 04:16 - 2014-03-12 22:03 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-01 04:14 - 2014-03-12 22:03 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-01 04:10 - 2014-03-12 22:03 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 04:03 - 2014-03-12 22:04 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-01 04:00 - 2014-03-12 22:04 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-01 03:57 - 2014-03-12 22:04 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-01 03:38 - 2014-03-12 22:04 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 03:32 - 2014-03-12 22:03 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-01 03:27 - 2014-03-12 22:04 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-01 03:25 - 2014-03-12 22:03 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-01 03:25 - 2014-03-12 22:03 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-27 12:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-27 11:13 - 2014-02-27 11:13 - 00000088 _____ () C:\Users\PC\Desktop\Два ствола скачать торрент в хорошем качестве бесплатно dvdrip, hdrip.url
2014-02-27 10:52 - 2014-02-27 10:52 - 00000000 ____D () C:\Users\PC\Desktop\08951603108
2014-02-26 21:09 - 2013-10-03 23:18 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\WinArchiver
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Program Files (x86)\WinArchiver
2014-02-26 19:49 - 2014-02-26 19:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-26 19:48 - 2014-02-26 19:48 - 00000000 ____D () C:\Program Files\Java
2014-02-26 19:44 - 2014-02-26 19:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PowerISO
2014-02-26 00:02 - 2014-02-26 00:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes
2014-02-25 01:38 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-02-24 23:54 - 2012-04-03 15:38 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-02-24 23:54 - 2012-04-03 15:38 - 00000000 ____D () C:\ProgramData\Skype
2014-02-24 17:17 - 2012-11-25 00:19 - 00000000 ____D () C:\Program Files (x86)\rhv
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Malwarebytes
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-24 16:49 - 2012-04-03 13:33 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-23 23:06 - 2014-02-23 23:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Need for Speed World
2014-02-23 02:16 - 2013-12-31 21:25 - 00000000 ____D () C:\Program Files\Realmware
2014-02-22 23:12 - 2014-02-22 23:05 - 00008192 ____H () C:\Users\Administrator\Desktop\photothumb.db
2014-02-22 03:34 - 2012-05-03 07:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-22 01:00 - 2014-02-22 01:00 - 00000000 ____D () C:\Users\PC\Desktop\login
2014-02-21 17:45 - 2014-02-21 17:45 - 00000000 ____D () C:\Users\PC\Desktop\httpwww.youtube.comwatchv=OGnIS_a54ak
2014-02-21 17:39 - 2014-01-15 18:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-19 20:45 - 2014-02-19 20:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Theta
2014-02-19 20:28 - 2014-02-19 20:28 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-02-19 20:10 - 2014-02-19 20:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\BANDISOFT
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-02-19 12:10 - 2014-02-19 12:10 - 00000836 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-02-18 03:23 - 2014-02-18 03:23 - 00000000 ____D () C:\Users\Administrator\Documents\Rockstar Games
2014-02-18 02:23 - 2014-02-17 18:28 - 00000000 ____D () C:\Users\Administrator\Documents\My Games
2014-02-18 02:18 - 2013-07-28 12:00 - 00000000 ____D () C:\Users\PC\Documents\My Games
2014-02-13 22:25 - 2014-02-13 22:25 - 00000000 ____D () C:\Users\PC\Documents\Rockstar Games
2014-02-13 22:14 - 2014-02-13 22:14 - 00003178 _____ () C:\Windows\System32\Tasks\{57E8181A-0929-418A-A72C-CE10D919BEE8}
2014-02-13 22:12 - 2014-02-13 22:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-02-13 22:03 - 2014-02-13 22:03 - 00336384 _____ () C:\Windows\SysWOW64\ScriptHook.dll
2014-02-13 18:31 - 2012-04-02 15:23 - 00004098 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-13 18:31 - 2012-04-02 15:23 - 00003846 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-13 03:16 - 2014-02-13 03:16 - 00000000 ____D () C:\Neuer Ordner
2014-02-12 22:16 - 2014-02-12 22:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-12 21:23 - 2014-02-12 21:23 - 00000000 ____D () C:\Program Files\PowerISO
2014-02-12 20:36 - 2014-02-12 20:36 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PowerISO
2014-02-12 20:28 - 2014-02-12 20:28 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DAEMON Tools Ultra

Files to move or delete:
====================
C:\Users\Gast\AppData\Roaming\CamLayout.ini
C:\Users\Gast\AppData\Roaming\CamShapes.ini
C:\Users\PC\AppData\Roaming\CamLayout.ini
C:\Users\PC\AppData\Roaming\CamShapes.ini


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-10 15:05

==================== End Of Log ============================

--- --- ---

mort 15.03.2014 12:16

Schritt 1

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

FF SearchPlugin: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\searchplugins\mailru---.xml
FF SearchPlugin: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\searchplugins\webalta-search.xml
FF Extension: SearchNewTab - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\bpax7a@vekpbgey.org [2013-10-04]
FF Extension: SearchNewTab - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\hqjs4vg@kfajdmhuia.net [2013-11-24]
FF Extension: Downloaed keepEr - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\oa9nnk_ifjm@xoeyavoayo.com [2013-10-04]
FF Extension: SearchNewTab - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\gzkboud8.default\Extensions\oai5cavr@aasvlrcz.net [2013-10-16]


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Ich sehe in deinen Logs nichts gefährliches mehr. :)

Cleanup

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


Tipps

Welches Antiviren-Programm soll ich nehmen?

Es gibt kein Antiviren-Programm, dass alle schädlinge findet. Du kannst dich nicht 100%-ig auf das Programm verlassen, es hängt immernoch von deinem Verhalten ab. Mit dem richtigen Verhalten schützt du dich am besten davor, dass du überhaupt infiziert wirst.
  • Klicke nicht auf alles blinkende oder das dich auffordert etwas herunterzuladen.
  • Lasse die finger weg von illegalen Programmen. Sie sind der Hauptgrund für infizierte Computer.
  • Öffne Email-Anhänge nur von bekannten Absendern.
  • Halte Java, Adobe Flash Player und andere Programme immer aktuell.

Nutze immer nur ein Antiviren Programm, da mehrere sich gegenseitig blockieren werden und es somit mehr schadet, als es nutzt. Falls du mehr als einen installiert hast, entscheide dich für einen von denen und deinstalliere die anderen. Halte ausserdem dein Antiviren-Programm immer aktuell, denn durch eine veraltete Datenbank kann das das Programm die neuen Infektionen nicht finden.
Du kannst auch regelmäßig einen On-Demand Scanner laufen lassen um dir eine zweite Meinung zu holen. Ein On-Demand Scanner läuft im gegensatz zu einem normalem Antiviren-Programm nicht ständig mit sondern nur wenn du ihm sagst, dass er das System scannen soll.
Für Firefox würde ich dir empfehlen das Addon NoScript herunterzuladen. Dieses kostenlose Addon blockiert JavaScript, Java und Flash. Sie werden nur ausgeführt, wenn du es erlaubst.

Ich empfehle dir auch das Addon WoT (Web of Trust) zu installieren. Es warnt dich davor eine als gefährlich bewertete Seit zu betreten.
Was sollte ich vor dem Runterladen beachten?
  • Lade dir Programme direkt vom Hersteller runter. Bei Programmen aus einer anderen Quelle wie Softonic und anderen Seiten die dir einen Downloader anbieten, werden unerwünschte Toolbars und anderer Müll mitinstalliert. Führe außerdem immer eine benutzerdefinierte Installation durch und entferne die Haken optionalen Programmen.
  • Lass die Finger von Registry-Cleanern. Sie versprechen dir eine große Beschleunigung deines Sytems obwohl das enfternen von verwaisten Registry-Schlüsseln nur wenig Perfomancegewinng bringt, wenn überhaupt etwas. Falls das Programm aber mal etwas wichtiges löscht, kannst du damit die Registry zerstören. Zerstörst du die Registry, zerstörst du Windows!
Sonstige Tipps
  • Halte dein System und die Programme darauf immer aktuell. Alte Software enthält Sicherheitslücken, die dein System angreifbar machen.
  • Nutze mehrere Passwörter. Falls jemand das Passwort eines Accounts von dir herausfindet hätte er Zugriff auf alle anderen Accounts.
  • Öffne keine Emails von dir unbekannten Absendern. Diese Emails sind meistens Spammails die dich unter anderem auch dazu bringen wollen bestimmt Seiten zu besuchen oder Dateien bzw. Anhänge herunterzuladen.
  • Achte auf die Dateiendung. In den Anhängen von Spammails wird gerne der Trick genutzt, ausfürbare Dateien als harmlose Datei darzustellen, in dem sie eine Datei z.B. Rechnung.pdf.exe nennen. (Dateiendungen anzeigen lassen)
  • Deaktivere die Autorun Funktion. Damit kann Malware sich automatisch von einem USB-Stick starten, wenn man einen infizierten USB-Stick einsteckt hat. (Autorun deaktivieren)


Wenn du das Trojaner-Board untersützten willst, kannst du gerne Spenden.
Ich wünsche dir noch eine schöne Zeit.
:)

Drancer 15.03.2014 15:46

Vielen Dank nochmal für alles !!!
Mein PC läuft sogar noch schneller:Boogie:
MFG


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:00 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130