Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   PC friert ein, teilweise nur 10 Sekunden, manchmal komplett (https://www.trojaner-board.de/139641-pc-friert-teilweise-nur-10-sekunden-manchmal-komplett.html)

cottec 11.08.2013 12:21

PC friert ein, teilweise nur 10 Sekunden, manchmal komplett
 
Guten Tag zusammen,
bin ganz frisch hier im Forum und habe direkt ein größeres Problemchen, welches ich selbst nicht gelöst bekomme:

Symptome:
- Sporadisches einfrieren des Systems zu völlig zufälligen Zeiten für einige Sekunde(ca 10)
- Teilweise(selten, bisher 2/3 mal in einem Monat) hilft nur ein Reset, weil garnichts mehr geht
- Soweit ich das beurteilen kann tritt das einfrieren immer erst auf, wenn ich den Firefox benutzt habe
-Anzeigetreiber stürzt manchmal ab (geforce 560 ti, aktuellster treiber via geforce experience)
- kein booten in den abgesicherten modus möglich
- Nach dem ersten Auftreten eines Freezes verändert sich die Farbe und das Symbol des Mauszeigers willkürlich und bleibt dann bis zu einem Neustart bestehen

System:
- Win 7 pro auf einer SSD installiert (alle updates und sp's sind bei mir selbstverständlich)
- java, flash, browser, antivir immer aktuell
- Nie Probleme mit Viren oder Malware gehabt

Was bisher unternommen wurde:
- Spybot Suchlauf gemacht und immunisiert
- Malwarebytes Anti-Malware Schnellsuchlauf gemacht, ohne Befund
- Versucht, in den abgesicherten Modus zu kommen um dort alle nvidia Treiber zu deinstallieren und mit dem nasty file remover alles zu cleanen. Leider geht der abgesicherte Modus nur bis zum Laden der Treiber und dann bootet der PC selbstständig ganz normal ohne abgesicherten Modus, dies lässt schwer auf Malware schließen, wenn ich mich an diese Bundestrojanergeschichten etc erinnere...

Logfiles aus der Ereignisanzeige zu relevaten "Freeze-Zeiten"
Protokollname: Application
Quelle: HHCTRL
Datum: 11.08.2013 12:22:12
Ereignis-ID: 1903
Aufgabenkategorie:Keine
Ebene: Informationen
Schlüsselwörter:Klassisch
Benutzer: Nicht zutreffend
Computer: cottec-PC
Beschreibung:
Die Beschreibung für die Ereignis-ID "1903" aus der Quelle "HHCTRL" wurde nicht gefunden. Entweder ist die Komponente, die dieses Ereignis auslöst, nicht auf dem lokalen Computer installiert, oder die Installation ist beschädigt. Sie können die Komponente auf dem lokalen Computer installieren oder reparieren.

Falls das Ereignis auf einem anderen Computer aufgetreten ist, mussten die Anzeigeinformationen mit dem Ereignis gespeichert werden.

Die folgenden Informationen wurden mit dem Ereignis gespeichert:

hxxp://go.microsoft.com/fwlink?LinkID=45839

Ereignis-XML:
<Event xmlns="hxxp://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="HHCTRL" />
<EventID Qualifiers="0">1903</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2013-08-11T10:22:12.000000000Z" />
<EventRecordID>19242</EventRecordID>
<Channel>Application</Channel>
<Computer>cottec-PC</Computer>
<Security />
</System>
<EventData>
<Data>hxxp://go.microsoft.com/fwlink?LinkID=45839</Data>
</EventData>
</Event>
Die Beschreibung für die Ereignis-ID "1903" aus der Quelle "HHCTRL" wurde nicht gefunden. Entweder ist die Komponente, die dieses Ereignis auslöst, nicht auf dem lokalen Computer installiert, oder die Installation ist beschädigt. Sie können die Komponente auf dem lokalen Computer installieren oder reparieren.






Nächstes:
Protokollname: Security
Quelle: Microsoft-Windows-Security-Auditing
Datum: 11.08.2013 12:22:36
Ereignis-ID: 4624
Aufgabenkategorie:Anmelden
Ebene: Informationen
Schlüsselwörter:Überwachung erfolgreich
Benutzer: Nicht zutreffend
Computer: cottec-PC
Beschreibung:
Ein Konto wurde erfolgreich angemeldet.

Antragsteller:
Sicherheits-ID: SYSTEM
Kontoname: COTTEC-PC$
Kontodomäne: WORKGROUP
Anmelde-ID: 0x3e7

Anmeldetyp: 5

Neue Anmeldung:
Sicherheits-ID: SYSTEM
Kontoname: SYSTEM
Kontodomäne: NT-AUTORITÄT
Anmelde-ID: 0x3e7
Anmelde-GUID: {00000000-0000-0000-0000-000000000000}

Prozessinformationen:
Prozess-ID: 0x2b0
Prozessname: C:\Windows\System32\services.exe

Netzwerkinformationen:
Arbeitsstationsname:
Quellnetzwerkadresse: -
Quellport: -

Detaillierte Authentifizierungsinformationen:
Anmeldeprozess: Advapi
Authentifizierungspaket: Negotiate
Übertragene Dienste: -
Paketname (nur NTLM): -
Schlüssellänge: 0

Dieses Ereignis wird beim Erstellen einer Anmeldesitzung generiert. Es wird auf dem Computer generiert, auf den zugegriffen wurde.

Die Antragstellerfelder geben das Konto auf dem lokalen System an, von dem die Anmeldung angefordert wurde. Dies ist meistens ein Dienst wie der Serverdienst oder ein lokaler Prozess wie "Winlogon.exe" oder "Services.exe".

Das Anmeldetypfeld gibt den jeweiligen Anmeldetyp an. Die häufigsten Typen sind 2 (interaktiv) und 3 (Netzwerk).

Die Felder für die neue Anmeldung geben das Konto an, für das die Anmeldung erstellt wurde, d. h. das angemeldete Konto.

Die Netzwerkfelder geben die Quelle einer Remoteanmeldeanforderung an. der Arbeitsstationsname ist nicht immer verfügbar und kann in manchen Fällen leer bleiben.

Die Felder für die Authentifizierungsinformationen enthalten detaillierte Informationen zu dieser speziellen Anmeldeanforderung.
- Die Anmelde-GUID ist ein eindeutiger Bezeichner, der verwendet werden kann, um dieses Ereignis mit einem KDC-Ereignis zu korrelieren.
- Die übertragenen Dienste geben an, welche Zwischendienste an der Anmeldeanforderung beteiligt waren.
- Der Paketname gibt das in den NTLM-Protokollen verwendete Unterprotokoll an.
- Die Schlüssellänge gibt die Länge des generierten Sitzungsschlüssels an. Wenn kein Sitzungsschlüssel angefordert wurde, ist dieser Wert 0.
Ereignis-XML:
<Event xmlns="hxxp://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4624</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12544</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2013-08-11T10:22:36.770405700Z" />
<EventRecordID>55739</EventRecordID>
<Correlation />
<Execution ProcessID="740" ThreadID="796" />
<Channel>Security</Channel>
<Computer>cottec-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-18</Data>
<Data Name="SubjectUserName">COTTEC-PC$</Data>
<Data Name="SubjectDomainName">WORKGROUP</Data>
<Data Name="SubjectLogonId">0x3e7</Data>
<Data Name="TargetUserSid">S-1-5-18</Data>
<Data Name="TargetUserName">SYSTEM</Data>
<Data Name="TargetDomainName">NT-AUTORITÄT</Data>
<Data Name="TargetLogonId">0x3e7</Data>
<Data Name="LogonType">5</Data>
<Data Name="LogonProcessName">Advapi </Data>
<Data Name="AuthenticationPackageName">Negotiate</Data>
<Data Name="WorkstationName">
</Data>
<Data Name="LogonGuid">{00000000-0000-0000-0000-000000000000}</Data>
<Data Name="TransmittedServices">-</Data>
<Data Name="LmPackageName">-</Data>
<Data Name="KeyLength">0</Data>
<Data Name="ProcessId">0x2b0</Data>
<Data Name="ProcessName">C:\Windows\System32\services.exe</Data>
<Data Name="IpAddress">-</Data>
<Data Name="IpPort">-</Data>
</EventData>
</Event>

Protokollname: Security
Quelle: Microsoft-Windows-Security-Auditing
Datum: 11.08.2013 12:22:36
Ereignis-ID: 4672
Aufgabenkategorie:Spezielle Anmeldung
Ebene: Informationen
Schlüsselwörter:Überwachung erfolgreich
Benutzer: Nicht zutreffend
Computer: cottec-PC
Beschreibung:
Einer neuen Anmeldung wurden besondere Rechte zugewiesen.

Antragsteller:
Sicherheits-ID: SYSTEM
Kontoname: SYSTEM
Kontodomäne: NT-AUTORITÄT
Anmelde-ID: 0x3e7

Berechtigungen: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Ereignis-XML:
<Event xmlns="hxxp://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4672</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12548</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2013-08-11T10:22:36.770405700Z" />
<EventRecordID>55740</EventRecordID>
<Correlation />
<Execution ProcessID="740" ThreadID="796" />
<Channel>Security</Channel>
<Computer>cottec-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-18</Data>
<Data Name="SubjectUserName">SYSTEM</Data>
<Data Name="SubjectDomainName">NT-AUTORITÄT</Data>
<Data Name="SubjectLogonId">0x3e7</Data>
<Data Name="PrivilegeList">SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege</Data>
</EventData>
</Event>





Hier noch nvidia Sachen zu der Zeit:
Protokollname: Application
Quelle: NvStreamSvc
Datum: 11.08.2013 12:36:20
Ereignis-ID: 3
Aufgabenkategorie:Keine
Ebene: Informationen
Schlüsselwörter:Klassisch
Benutzer: Nicht zutreffend
Computer: cottec-PC
Beschreibung:
Die Beschreibung für die Ereignis-ID "3" aus der Quelle "NvStreamSvc" wurde nicht gefunden. Entweder ist die Komponente, die dieses Ereignis auslöst, nicht auf dem lokalen Computer installiert, oder die Installation ist beschädigt. Sie können die Komponente auf dem lokalen Computer installieren oder reparieren.

Falls das Ereignis auf einem anderen Computer aufgetreten ist, mussten die Anzeigeinformationen mit dem Ereignis gespeichert werden.

Die folgenden Informationen wurden mit dem Ereignis gespeichert:

NvStreamSvc
Stream service as user abnormally ended. Re-launching... [0]

Ereignis-XML:
<Event xmlns="hxxp://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="NvStreamSvc" />
<EventID Qualifiers="16386">3</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2013-08-11T10:36:20.000000000Z" />
<EventRecordID>19252</EventRecordID>
<Channel>Application</Channel>
<Computer>cottec-PC</Computer>
<Security />
</System>
<EventData>
<Data>NvStreamSvc</Data>
<Data>Stream service as user abnormally ended. Re-launching... [0]</Data>
</EventData>
</Event>






Ich hoffe jemand hat hier ne Idee was meinem PC fehlt :daumenhoc

Danke schonmal

Gruß Cottec

schrauber 11.08.2013 12:30

hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


cottec 11.08.2013 15:07

hi, danke für deine schnelle antwort :)

eins vorweg, exakt beim versuch des runterladens auf der seite ein kurzer freeze bei dem der anzeigetreiber abgestürzt ist. direkt nach dem scan ein kompletter systemabsturz (konnte nur noch den mauszeiger bewegen, sonst ging nichts mehr ausser reset)


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-08-2013
Ran by cottec (administrator) on 11-08-2013 15:59:34
Running from C:\Users\cottec\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
(StarWind Software) C:\Program Files (x86)\Alcohol 120\StarWind\StarWindServiceAE.exe
(Andreas Sammann) C:\Program Files (x86)\C2DtoG15\SystoG15Svc.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Transaction Software, D 81737 Munich) C:\Programme\BMWgroup\ETKLokal\transbase\tbmux32.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe
(Miranda Fusion Team) C:\Program Files (x86)\MirandaFusion\fusiontools\mfstart.exe
(Dropbox, Inc.) C:\Users\cottec\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(modified by Miranda Fusion Team) C:\Program Files (x86)\MirandaFusion\miranda32.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPNetworkCommunicator.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Andreas Sammann) C:\Program Files (x86)\C2DtoG15\C2DtoG15.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6854800 2012-12-03] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-27] (NVIDIA Corporation)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7477016 2013-04-25] (Logitech Inc.)
HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [x]
HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [x]
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKCU\...\Run: [HP Officejet 6500 E710n-z (NET)] - C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKCU\...\Run: [Miranda Fusion] - C:\Program Files (x86)\MirandaFusion\fusiontools\mfstart.exe [1122241 2012-06-12] (Miranda Fusion Team)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKCU\...\Run: [AlcoholAutomount] - C:\Program Files (x86)\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKCU\...\Policies\system: [DisableLockWorkstation] 0
MountPoints2: {b75da7ac-4d26-11e2-bd17-d43d7e2bf080} - J:\shelexec.exe start.html
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-21] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [507016 2012-12-21] (MSI)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
AppInit_DLLs: C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll [653600 2013-07-27] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll [593696 2013-07-27] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\VR-NetWorld Auftragsprüfung.lnk
ShortcutTarget: VR-NetWorld Auftragsprüfung.lnk -> C:\Program Files (x86)\VR-NetWorld\vrtoolcheckorder.exe (VR-NetWorld Software)
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\C2DtoG15.lnk
ShortcutTarget: C2DtoG15.lnk -> C:\Program Files (x86)\C2DtoG15\C2DtoG15.exe (Andreas Sammann)
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\cottec\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung SSD Magician.lnk
ShortcutTarget: Samsung SSD Magician.lnk -> C:\Program Files (x86)\Samsung SSD Magician\Samsung SSD Magician.exe (Samsung Electronics.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.111.111.1

FireFox:
========
FF ProfilePath: C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default
FF user.js: detected! => C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\user.js
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\cottec\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com
FF Extension: GFACE Experience Plugin - C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\Extensions\cryenginebrowserplugin@crytek.com
FF Extension: No Name - C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Gmail) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG)
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [146984 2012-07-24] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [144008 2012-12-21] (MSI)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-05-23] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
R2 SystoG15Svc; C:\Program Files (x86)\C2DtoG15\SystoG15Svc.exe [64000 2012-12-24] (Andreas Sammann)
R2 Transbase; C:\Programme\BMWgroup\ETKLokal\transbase\tbmux32.exe [385024 2004-08-05] (Transaction Software, D 81737 Munich)

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-28] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-28] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-28] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-04-01] (DT Soft Ltd)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] ()
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] ()
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [27456 2012-07-09] (Intel Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [20968 2012-07-24] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [19944 2012-07-24] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46016 2012-07-24] ()
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [14136 2010-10-22] (MSI)
S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [14136 2010-10-22] (MSI)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7758v160\NTIOLib_X64.sys [11888 2011-01-06] (MSI)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7758v160\NTIOLib_X64.sys [11888 2011-01-06] (MSI)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2012-12-23] (Duplex Secure Ltd.)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation)
R3 WinRing0_1_2_0; C:\Program Files (x86)\C2DtoG15\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
R3 WinRing0_1_2_0; C:\Program Files (x86)\C2DtoG15\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-08-11] ()
U3 ampfwa8k; C:\Windows\System32\Drivers\ampfwa8k.sys [0 ] (Advanced Micro Devices)
U3 ar57nzpe; C:\Windows\System32\Drivers\ar57nzpe.sys [0 ] (Advanced Micro Devices)
S3 MSICDSetup; \??\D:\CDriver64.sys [x]
S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [x]
S3 NTIOLib_1_0_C; \??\C:\MSI\MSI SUITE\NTIOLib_X64.sys [x]
S3 NTIOLib_1_1_S; \??\C:\MSI\MSI SUITE\Super-Charger\NTIOLib_X64.sys [x]
S3 NTIOLib_SuiteFB; \??\C:\MSI\MSI SUITE\FastBoot\NTIOLib_X64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-11 15:59 - 2013-08-11 15:59 - 00000000 ____D C:\FRST
2013-08-11 13:22 - 2013-08-11 13:22 - 00000000 ____D C:\Windows\pss
2013-08-11 12:47 - 2013-08-11 12:47 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-11 12:47 - 2013-08-11 12:47 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Malwarebytes
2013-08-11 12:47 - 2013-08-11 12:47 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-11 12:47 - 2013-08-11 12:47 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-11 12:47 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-11 12:46 - 2013-08-11 12:46 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\cottec\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-11 12:44 - 2013-08-11 12:44 - 00000000 ____D C:\Program Files (x86)\ESET
2013-08-11 12:43 - 2013-08-11 12:43 - 02347384 _____ (ESET) C:\Users\cottec\Desktop\esetsmartinstaller_enu.exe
2013-08-11 12:40 - 2013-08-11 12:40 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-08-11 11:42 - 2013-08-11 11:42 - 00001941 _____ C:\Users\UpdatusUser\Desktop\BMW_EBA.lnk
2013-08-11 11:42 - 2013-08-11 11:42 - 00001941 _____ C:\Users\cottec\Desktop\BMW_EBA.lnk
2013-08-11 11:42 - 2013-08-11 11:42 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BMW
2013-08-11 11:42 - 2013-08-11 11:42 - 00000000 ____D C:\Program Files (x86)\BMW
2013-08-10 14:49 - 2013-08-10 14:49 - 00316616 _____ C:\Windows\Minidump\081013-7238-01.dmp
2013-08-10 14:49 - 2013-08-10 14:49 - 00000000 ____D C:\Windows\Minidump
2013-08-09 22:53 - 2013-08-09 22:53 - 00000000 ____D C:\Users\cottec\Documents\ProcAlyzer Dumps
2013-08-09 18:31 - 2013-08-09 18:24 - 00447824 _____ C:\Windows\system32\Drivers\etc\hosts.20130809-183137.backup
2013-08-09 18:31 - 2013-08-09 18:24 - 00447824 _____ C:\Windows\system32\Drivers\etc\hosts.20130809-183112.backup
2013-08-09 18:24 - 2013-05-25 13:00 - 00000829 _____ C:\Windows\system32\Drivers\etc\hosts.20130809-182410.backup
2013-08-09 18:22 - 2013-05-25 13:00 - 00000829 _____ C:\Windows\system32\Drivers\etc\hosts.20130809-182259.backup
2013-08-09 18:21 - 2013-05-25 13:00 - 00000829 _____ C:\Windows\system32\Drivers\etc\hosts.20130809-182135.backup
2013-08-09 18:16 - 2013-08-09 22:53 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-08-09 18:16 - 2013-08-09 18:29 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-08-09 18:16 - 2013-08-09 18:16 - 00001385 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-08-09 18:16 - 2013-08-09 18:16 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-08-09 18:16 - 2009-01-25 13:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2013-08-09 17:44 - 2013-08-10 09:13 - 00000000 ____D C:\Program Files (x86)\Spyware Terminator
2013-08-09 17:44 - 2013-08-09 17:44 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys
2013-08-07 18:29 - 2013-08-07 21:21 - 00000000 ____D C:\Users\cottec\Desktop\TK
2013-08-05 09:12 - 2013-08-05 09:12 - 00008694 _____ C:\Users\cottec\Documents\cc_20130805_091227.reg
2013-08-05 09:08 - 2013-08-05 09:10 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-08-05 09:08 - 2013-08-05 09:08 - 02365840 _____ C:\Users\cottec\Desktop\SecurityTaskManager_Setup.exe
2013-08-05 09:02 - 2013-08-05 09:02 - 00011880 _____ C:\Users\cottec\Downloads\hijackthis.log
2013-08-05 09:01 - 2013-08-05 09:01 - 00388608 _____ (Trend Micro Inc.) C:\Users\cottec\Downloads\HiJackThis204.exe
2013-08-04 12:10 - 2013-08-04 12:10 - 00008600 _____ C:\Users\cottec\Documents\Mappe1.xlsx
2013-08-02 15:29 - 2013-07-26 08:09 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 22100768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 15701128 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 11262240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-08-02 15:29 - 2013-07-26 08:09 - 09248072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 07695320 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 02968352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 02007328 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432641.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432641.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 01223336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 00387536 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 00326224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-08-02 15:29 - 2013-07-26 08:09 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-08-02 15:27 - 2013-08-02 15:27 - 00000000 ____D C:\NvidiaLogging
2013-08-02 15:27 - 2013-05-14 21:28 - 00039712 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-08-02 15:27 - 2013-05-14 21:27 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2013-08-02 15:27 - 2013-05-14 21:27 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-07-31 22:15 - 2013-07-31 22:16 - 00000000 ____D C:\Windows\system32\MRT
2013-07-25 23:19 - 2013-07-25 23:19 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-07-25 23:07 - 2013-07-24 09:49 - 03481378 _____ C:\Users\cottec\Desktop\ROM Manager Premium v5.5.3.0.apk
2013-07-24 22:40 - 2013-07-24 22:40 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-07-24 22:36 - 2013-07-24 22:36 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-07-24 22:36 - 2013-06-21 02:07 - 00203672 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2013-07-24 22:35 - 2013-07-24 22:35 - 00000000 ____D C:\Program Files (x86)\MarkAny
2013-07-23 20:35 - 2013-07-23 20:35 - 00000000 ____D C:\Users\cottec\Documents\TomTom
2013-07-23 20:35 - 2013-07-23 20:35 - 00000000 ____D C:\Users\cottec\AppData\Roaming\TomTom
2013-07-23 20:35 - 2013-07-23 20:35 - 00000000 ____D C:\Users\cottec\AppData\Local\TomTom
2013-07-23 20:35 - 2013-07-23 20:35 - 00000000 ____D C:\ProgramData\TomTom
2013-07-23 20:34 - 2013-07-23 20:34 - 00000000 ____D C:\Program Files (x86)\TomTom International B.V
2013-07-23 20:34 - 2013-07-23 20:34 - 00000000 ____D C:\Program Files (x86)\TomTom HOME 2
2013-07-22 14:01 - 2013-08-11 12:39 - 00010122 _____ C:\Windows\PFRO.log
2013-07-21 22:15 - 2013-08-11 15:57 - 00021494 _____ C:\Windows\setupact.log
2013-07-21 22:15 - 2013-07-21 22:15 - 00000000 _____ C:\Windows\setuperr.log
2013-07-21 16:19 - 2013-07-21 16:19 - 00144302 _____ C:\Users\cottec\Documents\cc_20130721_161929.reg
2013-07-21 16:13 - 2013-07-21 16:13 - 00002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-07-21 16:13 - 2013-07-21 16:13 - 00000000 ____D C:\Program Files\CCleaner
2013-07-18 22:51 - 2013-07-14 03:17 - 01882912 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432619.dll
2013-07-18 22:51 - 2013-07-14 03:17 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432619.dll
2013-07-18 22:51 - 2013-06-16 14:38 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2013-07-18 22:51 - 2013-06-16 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2013-07-18 18:01 - 2013-07-19 15:27 - 00009132 _____ C:\Users\cottec\Desktop\Mappe1.xlsx
2013-07-15 18:13 - 2013-07-15 18:13 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-07-15 18:12 - 2013-06-21 14:06 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432049.dll
2013-07-15 18:12 - 2013-06-21 14:06 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432049.dll
2013-07-15 18:11 - 2013-07-15 18:11 - 00000000 ____D C:\NVIDIA
2013-07-14 19:01 - 2013-07-14 19:01 - 00000000 ____D C:\Users\cottec\Desktop\TitaniumBackup

==================== One Month Modified Files and Folders =======

2013-08-11 15:59 - 2013-08-11 15:59 - 00000000 ____D C:\FRST
2013-08-11 15:59 - 2013-02-17 16:59 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-11 15:57 - 2013-07-21 22:15 - 00021494 _____ C:\Windows\setupact.log
2013-08-11 15:29 - 2013-02-11 20:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-11 13:22 - 2013-08-11 13:22 - 00000000 ____D C:\Windows\pss
2013-08-11 12:47 - 2013-08-11 12:47 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-11 12:47 - 2013-08-11 12:47 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Malwarebytes
2013-08-11 12:47 - 2013-08-11 12:47 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-11 12:47 - 2013-08-11 12:47 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-11 12:47 - 2009-07-14 19:58 - 00699568 _____ C:\Windows\system32\perfh007.dat
2013-08-11 12:47 - 2009-07-14 19:58 - 00149122 _____ C:\Windows\system32\perfc007.dat
2013-08-11 12:47 - 2009-07-14 07:13 - 01615978 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-11 12:47 - 2009-07-14 06:45 - 00013424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-11 12:47 - 2009-07-14 06:45 - 00013424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-11 12:46 - 2013-08-11 12:46 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\cottec\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-11 12:44 - 2013-08-11 12:44 - 00000000 ____D C:\Program Files (x86)\ESET
2013-08-11 12:43 - 2013-08-11 12:43 - 02347384 _____ (ESET) C:\Users\cottec\Desktop\esetsmartinstaller_enu.exe
2013-08-11 12:43 - 2012-12-20 22:01 - 01426681 _____ C:\Windows\WindowsUpdate.log
2013-08-11 12:40 - 2013-08-11 12:40 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-08-11 12:40 - 2013-02-17 16:59 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-11 12:40 - 2013-01-27 19:36 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Dropbox
2013-08-11 12:40 - 2012-12-24 01:51 - 00000000 ____D C:\Program Files (x86)\C2DtoG15
2013-08-11 12:40 - 2012-12-23 19:21 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2013-08-11 12:40 - 2012-12-20 22:32 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-11 12:40 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-11 12:39 - 2013-07-22 14:01 - 00010122 _____ C:\Windows\PFRO.log
2013-08-11 11:48 - 2012-12-20 22:10 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-08-11 11:42 - 2013-08-11 11:42 - 00001941 _____ C:\Users\UpdatusUser\Desktop\BMW_EBA.lnk
2013-08-11 11:42 - 2013-08-11 11:42 - 00001941 _____ C:\Users\cottec\Desktop\BMW_EBA.lnk
2013-08-11 11:42 - 2013-08-11 11:42 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BMW
2013-08-11 11:42 - 2013-08-11 11:42 - 00000000 ____D C:\Program Files (x86)\BMW
2013-08-11 11:40 - 2012-12-23 00:39 - 00000000 ____D C:\Users\cottec\AppData\Roaming\DAEMON Tools Lite
2013-08-10 14:49 - 2013-08-10 14:49 - 00316616 _____ C:\Windows\Minidump\081013-7238-01.dmp
2013-08-10 14:49 - 2013-08-10 14:49 - 00000000 ____D C:\Windows\Minidump
2013-08-10 09:13 - 2013-08-09 17:44 - 00000000 ____D C:\Program Files (x86)\Spyware Terminator
2013-08-09 23:01 - 2013-04-18 15:49 - 00000489 _____ C:\Users\cottec\Documents\ax_files.xml
2013-08-09 22:53 - 2013-08-09 22:53 - 00000000 ____D C:\Users\cottec\Documents\ProcAlyzer Dumps
2013-08-09 22:53 - 2013-08-09 18:16 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-08-09 18:29 - 2013-08-09 18:16 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-08-09 18:24 - 2013-08-09 18:31 - 00447824 _____ C:\Windows\system32\Drivers\etc\hosts.20130809-183137.backup
2013-08-09 18:24 - 2013-08-09 18:31 - 00447824 _____ C:\Windows\system32\Drivers\etc\hosts.20130809-183112.backup
2013-08-09 18:24 - 2009-07-14 04:34 - 00447824 ____R C:\Windows\system32\Drivers\etc\hosts.20130809-183031.backup
2013-08-09 18:16 - 2013-08-09 18:16 - 00001385 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-08-09 18:16 - 2013-08-09 18:16 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-08-09 17:44 - 2013-08-09 17:44 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys
2013-08-07 21:21 - 2013-08-07 18:29 - 00000000 ____D C:\Users\cottec\Desktop\TK
2013-08-05 19:13 - 2012-12-24 11:27 - 00000000 ____D C:\Users\cottec\AppData\Local\CrashDumps
2013-08-05 09:12 - 2013-08-05 09:12 - 00008694 _____ C:\Users\cottec\Documents\cc_20130805_091227.reg
2013-08-05 09:10 - 2013-08-05 09:08 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-08-05 09:08 - 2013-08-05 09:08 - 02365840 _____ C:\Users\cottec\Desktop\SecurityTaskManager_Setup.exe
2013-08-05 09:02 - 2013-08-05 09:02 - 00011880 _____ C:\Users\cottec\Downloads\hijackthis.log
2013-08-05 09:01 - 2013-08-05 09:01 - 00388608 _____ (Trend Micro Inc.) C:\Users\cottec\Downloads\HiJackThis204.exe
2013-08-04 12:10 - 2013-08-04 12:10 - 00008600 _____ C:\Users\cottec\Documents\Mappe1.xlsx
2013-08-02 15:31 - 2012-12-20 22:45 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-08-02 15:27 - 2013-08-02 15:27 - 00000000 ____D C:\NvidiaLogging
2013-08-02 15:27 - 2012-12-20 22:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-08-01 22:00 - 2013-02-17 16:59 - 00000000 ____D C:\Program Files (x86)\Google
2013-07-31 22:16 - 2013-07-31 22:15 - 00000000 ____D C:\Windows\system32\MRT
2013-07-31 08:07 - 2012-12-28 12:50 - 00000000 ____D C:\Users\cottec\AppData\Roaming\vlc
2013-07-31 08:02 - 2012-12-24 18:54 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Winamp
2013-07-26 08:09 - 2013-08-02 15:29 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 22100768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 15701128 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 11262240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-07-26 08:09 - 2013-08-02 15:29 - 09248072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 07695320 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 02968352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 02007328 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432641.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432641.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 01223336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 00387536 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 00326224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-07-26 08:09 - 2013-08-02 15:29 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-07-26 08:09 - 2013-05-27 10:21 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2013-07-26 08:09 - 2013-05-27 10:21 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2013-07-26 08:09 - 2013-05-24 15:03 - 13626160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-07-26 08:09 - 2012-12-20 22:45 - 29335328 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-07-26 08:09 - 2012-12-20 22:45 - 15898352 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-07-26 08:09 - 2012-12-20 22:45 - 12944800 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-07-26 08:09 - 2012-12-20 22:45 - 02986160 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-07-26 08:09 - 2012-12-20 22:45 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-07-26 08:09 - 2012-12-20 22:45 - 01412832 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-07-26 08:09 - 2012-12-20 22:45 - 00022581 _____ C:\Windows\system32\nvinfo.pb
2013-07-26 06:59 - 2013-05-27 10:21 - 06601504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-07-26 06:59 - 2013-05-27 10:21 - 03452704 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-07-26 06:59 - 2013-05-27 10:21 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2013-07-26 06:59 - 2013-05-27 10:21 - 00920864 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-07-26 06:59 - 2013-05-27 10:21 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-07-26 06:59 - 2013-05-27 10:21 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-07-25 23:19 - 2013-07-25 23:19 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-07-24 22:40 - 2013-07-24 22:40 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-07-24 22:36 - 2013-07-24 22:36 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-07-24 22:36 - 2013-06-27 15:14 - 00000000 ____D C:\Program Files (x86)\Kies
2013-07-24 22:36 - 2013-03-07 16:57 - 00000000 ____D C:\Users\cottec\AppData\Local\Downloaded Installations
2013-07-24 22:35 - 2013-07-24 22:35 - 00000000 ____D C:\Program Files (x86)\MarkAny
2013-07-24 22:33 - 2013-06-27 15:21 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Samsung
2013-07-24 09:49 - 2013-07-25 23:07 - 03481378 _____ C:\Users\cottec\Desktop\ROM Manager Premium v5.5.3.0.apk
2013-07-23 20:35 - 2013-07-23 20:35 - 00000000 ____D C:\Users\cottec\Documents\TomTom
2013-07-23 20:35 - 2013-07-23 20:35 - 00000000 ____D C:\Users\cottec\AppData\Roaming\TomTom
2013-07-23 20:35 - 2013-07-23 20:35 - 00000000 ____D C:\Users\cottec\AppData\Local\TomTom
2013-07-23 20:35 - 2013-07-23 20:35 - 00000000 ____D C:\ProgramData\TomTom
2013-07-23 20:34 - 2013-07-23 20:34 - 00000000 ____D C:\Program Files (x86)\TomTom International B.V
2013-07-23 20:34 - 2013-07-23 20:34 - 00000000 ____D C:\Program Files (x86)\TomTom HOME 2
2013-07-22 21:12 - 2013-05-27 10:21 - 03282455 _____ C:\Windows\system32\nvcoproc.bin
2013-07-21 22:22 - 2013-02-17 16:59 - 00000000 ____D C:\Users\cottec\AppData\Local\Google
2013-07-21 22:15 - 2013-07-21 22:15 - 00000000 _____ C:\Windows\setuperr.log
2013-07-21 16:19 - 2013-07-21 16:19 - 00144302 _____ C:\Users\cottec\Documents\cc_20130721_161929.reg
2013-07-21 16:16 - 2013-05-23 19:02 - 00000000 ____D C:\Users\cottec\AppData\Roaming\TS3Client
2013-07-21 16:16 - 2012-12-20 21:58 - 00000000 ____D C:\Windows\Panther
2013-07-21 16:13 - 2013-07-21 16:13 - 00002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-07-21 16:13 - 2013-07-21 16:13 - 00000000 ____D C:\Program Files\CCleaner
2013-07-19 15:27 - 2013-07-18 18:01 - 00009132 _____ C:\Users\cottec\Desktop\Mappe1.xlsx
2013-07-18 17:41 - 2012-12-23 14:32 - 00000000 ____D C:\Users\cottec\AppData\Local\Microsoft Help
2013-07-15 18:13 - 2013-07-15 18:13 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-07-15 18:11 - 2013-07-15 18:11 - 00000000 ____D C:\NVIDIA
2013-07-14 19:01 - 2013-07-14 19:01 - 00000000 ____D C:\Users\cottec\Desktop\TitaniumBackup
2013-07-14 03:17 - 2013-07-18 22:51 - 01882912 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432619.dll
2013-07-14 03:17 - 2013-07-18 22:51 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432619.dll
2013-07-12 19:54 - 2013-02-17 16:59 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-12 19:54 - 2013-02-17 16:59 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-02 22:27

==================== End Of Log ============================

--- --- ---




Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013
Ran by cottec at 2013-08-11 15:59:50
Running from C:\Users\cottec\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

 
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Reader XI - Deutsch (x32 Version: 11.0.00)
ArtMoney SE v7.39.2 (x32 Version: 7.39)
AutoIt v3.3.8.1 (x32)
Avira Free Antivirus (x32 Version: 13.0.0.3885)
AVM FRITZ!fax für FRITZ!Box (x32)
Battlefield 3™ (x32 Version: 1.6.0.0)
Battlelog Web Plugins (x32 Version: 2.1.7)
BMW EBA (x32 Version: 2.1.0)
C2DtoG15 2.0.2.1 (x32)
calibre (x32 Version: 0.9.24)
CLICKBIOSII (x32 Version: 1.0.107)
ControlCenter (x32 Version: 2.5.048)
CrystalDiskInfo 5.2.0 (x32 Version: 5.2.0)
DAEMON Tools Lite (x32 Version: 4.47.1.0333)
Dropbox (HKCU Version: 2.0.22)
eaner (Version: 4.03)
EaseUS Partition Master 9.2.2 (x32)
ElsterFormular (x32 Version: 14.3.20130522)
ESET Online Scanner v3 (x32)
ESN Sonar (x32 Version: 0.70.4)
ETK (Lokal) (x32 Version: 2.00.064)
Far Cry 3 (x32 Version: 1.02)
Google Chrome (x32 Version: 28.0.1500.95)
Google Earth Plug-in (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.153)
Hitman Absolution (x32)
HP Officejet 6500 E710n-z - Grundlegende Software für das Gerät (Version: 28.0.1315.0)
Intel(R) Control Center (x32 Version: 1.2.1.1008)
Intel(R) Management Engine Components (x32 Version: 8.1.0.1252)
Intel(R) Rapid Storage Technology (x32 Version: 11.5.0.1207)
Intel(R) Smart Connect Technology 3.0 x64 (Version: 3.0.30.1526)
Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.5.235)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Live Update 5 (x32 Version: 5.0.098)
Logitech Gaming Software (Version: 8.45.88)
Logitech Gaming Software 5.10 (Version: 5.10.127)
Logitech Gaming Software 8.46 (Version: 8.46.27)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
ManiaPlanet (x32)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0)
Miranda Fusion 3.2.6.0 (x32 Version: 3.2.6.0)
Mobipocket Creator 4.2 (x32 Version: 4.2.41)
Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0)
Mozilla Maintenance Service (x32 Version: 22.0)
Mp3tag v2.54 (x32 Version: v2.54)
MusicBrainz Picard (x32 Version: 1.1)
MyPhoneExplorer (x32 Version: 1.8.4)
NVIDIA 3D Vision Controller-Treiber 326.41 (Version: 326.41)
NVIDIA 3D Vision Treiber 326.41 (Version: 326.41)
NVIDIA GeForce Experience 1.6 (Version: 1.6)
NVIDIA Grafiktreiber 326.41 (Version: 326.41)
NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4)
NVIDIA Install Application (Version: 2.1002.132.865)
NVIDIA PhysX (x32 Version: 9.13.0604)
NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2641)
NVIDIA Systemsteuerung 326.41 (Version: 326.41)
NVIDIA Update 7.2.17 (Version: 7.2.17)
NVIDIA Update Components (Version: 7.2.17)
NVIDIA Virtual Audio 1.2.1 (Version: 1.2.1)
Origin (x32 Version: 9.1.3.2637)
PDF24 Creator 5.4.0 (x32)
Project CARS (x32 Version: 0510)
PunkBuster Services (x32 Version: 0.991)
QuickPar 0.9 (x32 Version: 0.9)
Rainmeter (x32 Version: 2.5 beta r1720)
Realtek Ethernet Controller Driver (x32 Version: 7.53.216.2012)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6793)
Samsung Kies (x32 Version: 2.5.3.13052_10)
Samsung SSD Magician (x32 Version: 3.2)
Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0)
SHIELD Streaming (Version: 1.05.19)
Source SDK Base 2007 (x32)
Spybot - Search & Destroy (x32 Version: 2.1.21)
Steam (x32 Version: 1.0.0.0)
Super-Charger (x32 Version: 1.2.016)
System Requirements Lab for Intel (x32 Version: 4.5.11.0)
Team Fortress 2 (x32)
TeamSpeak 3 Client (Version: 3.0.10)
TeamViewer 8 (x32 Version: 8.0.19045)
TomTom HOME (x32 Version: 2.9.6)
TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2)
TreeSize Free V2.7 (x32 Version: 2.7)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition (x32)
Update für Microsoft Office Excel 2007 Help (KB963678) (x32)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update für Microsoft Office Word 2007 Help (KB963665) (x32)
Uplay (x32 Version: 2.0)
VLC media player 2.0.5 (Version: 2.0.5)
VR-NetWorld (x32)
Winamp (x32 Version: 5.63 )
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1)
Windows XP Mode (Version: 1.3.7600.16422)
WinHTTrack Website Copier 3.47-6 (x64) (Version: 3.47.6)
Winki (x32 Version: 3.2.125)
WinRAR 4.20 (64-Bit) (Version: 4.20.0)

==================== Restore Points  =========================

10-08-2013 13:31:25 Geplanter Prüfpunkt

==================== Hosts content: ==========================

2009-07-14 04:34 - 2013-08-09 18:31 - 00449440 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1        www.007guard.com
127.0.0.1        007guard.com
127.0.0.1        008i.com
127.0.0.1        www.008k.com
127.0.0.1        008k.com
127.0.0.1        www.00hq.com
127.0.0.1        00hq.com
127.0.0.1        010402.com
127.0.0.1        www.032439.com
127.0.0.1        032439.com
127.0.0.1        www.0scan.com
127.0.0.1        0scan.com
127.0.0.1        1000gratisproben.com
127.0.0.1        www.1000gratisproben.com
127.0.0.1        1001namen.com
127.0.0.1        www.1001namen.com
127.0.0.1        100888290cs.com
127.0.0.1        www.100888290cs.com
127.0.0.1        www.100sexlinks.com
127.0.0.1        100sexlinks.com
127.0.0.1        10sek.com
127.0.0.1        www.10sek.com
127.0.0.1        www.1-2005-search.com
127.0.0.1        1-2005-search.com
127.0.0.1        123fporn.info
127.0.0.1        www.123fporn.info
127.0.0.1        123haustiereundmehr.com
127.0.0.1        www.123haustiereundmehr.com
127.0.0.1        123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

Task: {050C409A-505D-4558-ABBB-A3FCE95FB2AD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
Task: {34A40C97-DA4E-4B69-AD0F-74713550220E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.)
Task: {52E3C579-49D3-42A8-B1A6-D991812A5C26} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe No File
Task: {88319E39-E9B5-4222-BF66-4C91BFA72C19} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation)
Task: {B1886FE5-722E-42D7-B5E7-A98F690B3726} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe No File
Task: {D100799E-94C9-4227-A90E-7143AA573FC5} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation)
Task: {E73298AB-85F4-40AD-A720-77D23CD57192} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.)
Task: {EE6E17AB-533D-4D77-B1A2-B351BB4E2240} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-11] (Adobe Systems Incorporated)
Task: {F8A32F2E-B6B5-45A5-BB99-35D934EC7861} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe No File
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/11/2013 02:05:05 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (08/11/2013 00:44:04 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (08/11/2013 00:44:01 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (08/11/2013 00:43:59 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (08/11/2013 00:40:26 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (08/11/2013 00:40:23 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]

Error: (08/11/2013 00:40:21 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD endpoint registered successfully [0]

Error: (08/11/2013 00:38:46 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (08/11/2013 00:38:43 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]

Error: (08/11/2013 00:38:41 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD endpoint registered successfully [0]


System errors:
=============
Error: (08/11/2013 00:40:19 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎11.‎08.‎2013 um 12:39:55 unerwartet heruntergefahren.

Error: (08/11/2013 00:38:39 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎11.‎08.‎2013 um 12:38:16 unerwartet heruntergefahren.

Error: (08/11/2013 00:21:36 PM) (Source: nvlddmkm) (User: )
Description: \Device\Video5!06e6(24f8)

Error: (08/10/2013 02:49:58 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden gelöscht, weil der Schattenkopiespeicher nicht rechtzeitig vergrößert wurde. Sie sollten die E/A-Last auf dem System verringern oder ein Schattenkopie-Speichervolume, von dem keine Schattenkopie erstellt wird, auswählen.

Error: (08/10/2013 02:49:55 PM) (Source: BugCheck) (User: )
Description: 0x00000116 (0xfffffa8006e62140, 0xfffff880085b2024, 0xffffffffc00000b5, 0x000000000000000a)C:\Windows\MEMORY.DMP081013-7238-01

Error: (08/10/2013 02:49:54 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎10.‎08.‎2013 um 14:47:35 unerwartet heruntergefahren.

Error: (08/10/2013 02:42:07 PM) (Source: nvlddmkm) (User: )
Description: \Device\000000b9!06e6(24f8)

Error: (08/09/2013 05:33:31 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎09.‎08.‎2013 um 17:28:05 unerwartet heruntergefahren.

Error: (08/09/2013 05:28:16 PM) (Source: nvlddmkm) (User: )
Description: \Device\000000c2!06e6(24f8)

Error: (08/08/2013 07:51:11 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎08.‎08.‎2013 um 19:44:04 unerwartet heruntergefahren.


Microsoft Office Sessions:
=========================
Error: (07/28/2013 11:02:35 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 45 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (07/18/2013 06:37:37 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (03/06/2013 01:07:38 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 52 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/21/2013 06:03:43 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 01:13:45 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 10:46:31 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 10:20:26 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 49 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2012-12-20 22:14:12.581
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:14:10.454
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:14:10.454
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:43.050
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:43.050
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:28.753
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:26.612
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:26.612
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:05:29.179
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:05:29.179
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 20%
Total physical RAM: 8138.8 MB
Available physical RAM: 6432.26 MB
Total Pagefile: 15872.37 MB
Available Pagefile: 12547.12 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (System) (Fixed) (Total:78.13 GB) (Free:5.57 GB) NTFS (Disk=0 Partition=2)
Drive d: (Daten) (Fixed) (Total:931.51 GB) (Free:170.28 GB) NTFS
Drive e: (Software) (Fixed) (Total:160.24 GB) (Free:24.26 GB) NTFS (Disk=0 Partition=3)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: 5C539950)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=78 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=160 GB) - (Type=OF Extended)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 76AF80D4)
Partition 1: (Not Active) - (Size=932 GB) - (Type=42)

==================== End Of Log ============================


schrauber 11.08.2013 16:43

Revo Uninstaller Pro - Uninstall Software, Remove Programs easily, Forced Uninstall, Leftovers Uninstaller

Damit alles von Nvidia deinstallieren, Reste entfernen lassen, reboot. Neu installieren.

cottec 12.08.2013 18:20

ist erledigt, ich melde mich morgen oder übermorgen wieder, wenn ich lange genug am pc war um feststellen zu können ob der fehler noch da ist...

aber ein massives problem habe ich nach wie vor, ich komme nicht in den abgesicherten modus

schrauber 12.08.2013 20:08

was passiert wenn du es versuchst?

cottec 12.08.2013 20:12

eins vorweg, die freezes sind jetzt schon wieder vorhanden...

er lädt die treiber im abgesicherten, zeigt den willkommen screen an und bootet dann neu

schrauber 13.08.2013 09:01

Win7 DVD zur Hand?

cottec 13.08.2013 19:56

öh, joar hab ich

schrauber 14.08.2013 15:41

Mach das mal:
Windows 7 Reparaturinstallation: Windows 7 Inplace Upgrade

cottec 14.08.2013 17:36

cool, das klingt interessant :)

hast du eine quelle für aktuelle win 7 dvds? (mit manueller keyeingabe)
kenn ich von früher, dass man die so runterladen kann und mit seinem eigenen key benutzen kann.
hab nur eine ohne sp1, aber das muss bei der reparaturinstallation ja vorhanden sein...

schrauber 14.08.2013 20:02

Google, erstes Ergebnis ist ein Download bei Chip.de ;)

cottec 14.08.2013 21:47

viel viel zu leicht :D

schrauber 15.08.2013 12:16

hehe :)

cottec 16.08.2013 15:32

achso eins noch, kann ich das emulieren oder muss die dvd physisch vorhanden sein?

schrauber 16.08.2013 16:55

Da Du das von aussen machst physisch :)

cottec 08.09.2013 21:26

Sooooooo,

ich habe endlich mal die zeit fürs reparieren gefunden :)

ich werde berichten wenn die freezes wieder auftreten oder eben nicht mehr auftreten ;)

danke!

schrauber 09.09.2013 06:25

ok .

cottec 09.09.2013 17:19

gerade leider schon wieder passiert...

diesmal stand das hier in der ereignisanzeige:
Code:

Die Beschreibung für die Ereignis-ID "0" aus der Quelle "APNMCP" wurde nicht gefunden. Entweder ist die Komponente, die dieses Ereignis auslöst, nicht auf dem lokalen Computer installiert, oder die Installation ist beschädigt. Sie können die Komponente auf dem lokalen Computer installieren oder reparieren.

Falls das Ereignis auf einem anderen Computer aufgetreten ist, mussten die Anzeigeinformationen mit dem Ereignis gespeichert werden.

Die folgenden Informationen wurden mit dem Ereignis gespeichert:

Report Service Pass Message recieved the message WM_TIMER

öfters steht auch der drin:
Code:

Die Beschreibung für die Ereignis-ID "3" aus der Quelle "NvStreamSvc" wurde nicht gefunden. Entweder ist die Komponente, die dieses Ereignis auslöst, nicht auf dem lokalen Computer installiert, oder die Installation ist beschädigt. Sie können die Komponente auf dem lokalen Computer installieren oder reparieren.

Falls das Ereignis auf einem anderen Computer aufgetreten ist, mussten die Anzeigeinformationen mit dem Ereignis gespeichert werden.

Die folgenden Informationen wurden mit dem Ereignis gespeichert:

NvStreamSvc
Stream service as user abnormally ended. Re-launching... [0]


diese fehler tauchen öfters rund um freezes auf, immer irgendwelche qullen, die nicht gefunden wurden.
dazu treten sie auch echt oft auf, genau 3 mal pro minute
haben diese fehler in der ereignisanzeige wohl was mit den freezes zu tun oder hab ich nen virus o.ä.?

schrauber 09.09.2013 19:33

Treiber der Grafikkarte erneuern :)

cottec 09.09.2013 21:06

ist aktuell :-/

Syne 09.09.2013 21:19

Bitte manuell downloaden und nochmal drüber installieren (sollte aber eine neuere Version sein, als du hast): Download

Hatte den selben Fehler auch. Habe nun aber endlich den Fehler ausfindig machen können (GeForce Experience).

Mehr Informationen zu dem Fehler:
Zitat:

ACHTUNG die Version GeForce Experience 1.6.0.0 bringt einen virtuellen Treiber "GFExperience.NvStreamSrv" der auf den meisten Systemen > 2 Fehler bleibender Natur verursacht. Ereignis ID 1. Diese treten immer beim Start des Systems auf.
Neuer Treiber bei Nvidia - Seite 5

LG :)

cottec 09.09.2013 21:45

okay, danke für die antwort schonmal ;)

soll ich das experience dann auch runter hauen oder kann das bleiben?


gehört der "APNMCP" quatsch auch dazu? das ist erst seit der upgrade-reparatur aufgetaucht und kommt wirklich jede jede minute 3 mal

edit:der hat sich erledigt, war vom antivir die dämlich tool-leiste (meiner meinung nach mehr spam als hilfe)

Syne 09.09.2013 22:24

Kannst du drauf lassen -> es wird dann geupdatet. Sollte der Fehler danach immer noch vorhanden sein, deinstallier das Programm einfach mal (damit verlierst du dann aber die Automatische Optimierung von Spieleinstellungen und das Automatische Treiberupdate. Das ist aber verschmerzbar :pfeiff:).

LG

cottec 15.09.2013 15:28

gestern ist er mir nochmal eingefroren, diesmal das hier:
Die Beschreibung für die Ereignis-ID "14" aus der Quelle "nvlddmkm" wurde nicht gefunden. Entweder ist die Komponente, die dieses Ereignis auslöst, nicht auf dem lokalen Computer installiert, oder die Installation ist beschädigt. Sie können die Komponente auf dem lokalen Computer installieren oder reparieren.

Falls das Ereignis auf einem anderen Computer aufgetreten ist, mussten die Anzeigeinformationen mit dem Ereignis gespeichert werden.

Die folgenden Informationen wurden mit dem Ereignis gespeichert:

\Device\000000a0
!06e6(24f8)

schrauber 15.09.2013 20:00

Grafikkartentreiber.

cottec 19.09.2013 18:13

udn was mach ich jetzt damit? :D

schrauber 20.09.2013 10:22

Deinstallieren und aktuellen neu installieren. Ebenso evtl vorhandene Software der Grafikkarte.

cottec 25.09.2013 19:33

ist wohl ein nvidia problem mit den 500er karten und tritt am der v314 auf...

danke für eure hilfe hier ;)

schrauber 26.09.2013 08:31

Gern Geschehen :)

cottec 22.10.2013 15:49

darf ich hier nochmal weiter stören? :)

mein abgesicherter modus funktioniert nach wie vor nicht, habt ihr ne idee was das sein könnte?

schrauber 23.10.2013 06:42

Was genau pasiert wenn du da rein willst?

cottec 23.10.2013 08:15

er lädt die treiber, zeigt den willkommen-bildschirm an und rebootet dann sofort

schrauber 23.10.2013 14:50

Dann bitte Frst im normalen Modus öffnen, Haken setzen bei Additional und scannen, poste beide Logfiles.

cottec 31.10.2013 23:27

wird gemacht :)


FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013
Ran by cottec (administrator) on COTTEC-PC on 31-10-2013 23:25:15
Running from D:\Downloads\Software\FRST
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Microsoft Corporation) C:\ProgramData\SolidWorks Electrical\MSSQL11.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Mentor Graphics Corporation) C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\remotesolverdispatcherservice.exe
(Mentor Graphics Corporation) C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\dispatcher.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(StarWind Software) C:\Program Files (x86)\Alcohol 120\StarWind\StarWindServiceAE.exe
(Andreas Sammann) C:\Program Files (x86)\C2DtoG15\SystoG15Svc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Transaction Software, D 81737 Munich) C:\Programme\BMWgroup\ETKLokal\transbase\tbmux32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe
(Miranda Fusion Team) C:\Program Files (x86)\MirandaFusion\fusiontools\mfstart.exe
(Samsung) C:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Samsung) C:\Program Files (x86)\Kies\Kies.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe
(Andreas Sammann) C:\Program Files (x86)\C2DtoG15\C2DtoG15.exe
(Dropbox, Inc.) C:\Users\cottec\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(modified by Miranda Fusion Team) C:\Program Files (x86)\MirandaFusion\miranda32.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPNetworkCommunicator.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Electronic Arts) C:\Spiele\Origin\Origin.exe
(Electronic Arts) C:\Spiele\Origin\OriginClientService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7191768 2013-06-27] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKCU\...\Run: [AlcoholAutomount] - C:\Program Files (x86)\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKCU\...\Run: [HP Officejet 6500 E710n-z (NET)] - C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKCU\...\Run: [Miranda Fusion] - C:\Program Files (x86)\MirandaFusion\fusiontools\mfstart.exe [1122241 2012-06-12] (Miranda Fusion Team)
HKCU\...\Run: [] - C:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-09-04] (Samsung)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Kies\Kies.exe [1564528 2013-09-04] (Samsung)
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [506864 2013-03-08] (MSI)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-08] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ControlCenterCount] - C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [872448 2012-03-26] (MSI CO.,LTD.)
HKLM-x32\...\Run: [ControlCenterII] - \BootStartControlCenter.exe
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\C2DtoG15.lnk
ShortcutTarget: C2DtoG15.lnk -> C:\Program Files (x86)\C2DtoG15\C2DtoG15.exe (Andreas Sammann)
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\cottec\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()

==================== Internet (Whitelisted) ====================

ProxyServer: localhost:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4B157DDCF427CE01
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.111.111.1

FireFox:
========
FF ProfilePath: C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default
FF user.js: detected! => C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\user.js
FF Homepage: hxxp://www.google.de/
FF NetworkProxy: "http", "200.65.127.163"
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: GFACE Experience Plugin - C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\Extensions\cryenginebrowserplugin@crytek.com
FF Extension: Adblock Plus - C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll No File
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (Google Docs) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-08] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-08] (Avira Operations GmbH & Co. KG)
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [146984 2012-07-24] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161264 2013-02-20] (MSI)
R2 MSSQL$TEW_SQLEXPRESS; C:\ProgramData\SolidWorks Electrical\MSSQL11.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe [191064 2012-02-11] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-31] ()
R2 RemoteSolverDispatcher; C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\remotesolverdispatcherservice.exe [235656 2013-09-20] (Mentor Graphics Corporation)
S4 SQLAgent$TEW_SQLEXPRESS; C:\ProgramData\SolidWorks Electrical\MSSQL11.TEW_SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [597080 2012-02-11] (Microsoft Corporation)
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
R2 SystoG15Svc; C:\Program Files (x86)\C2DtoG15\SystoG15Svc.exe [64000 2012-12-24] (Andreas Sammann)
R2 Transbase; C:\Programme\BMWgroup\ETKLokal\transbase\tbmux32.exe [385024 2004-08-05] (Transaction Software, D 81737 Munich)

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-08] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-08] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-09-08] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-09-08] (DT Soft Ltd)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] ()
S3 epmntdrv; C:\Windows\SysWow64\epmntdrv.sys [13896 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\SysWow64\EuGdiDrv.sys [9160 2013-03-07] ()
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [27456 2012-07-09] (Intel Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [20968 2012-07-24] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [19944 2012-07-24] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46016 2012-07-24] ()
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 NTIOLib_1_0_2; C:\Program Files (x86)\MSI\ControlCenter\NTIOLib_X64.sys [13328 2012-02-14] (MSI)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [14136 2010-10-22] (MSI)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7758v190\NTIOLib_X64.sys [11888 2011-01-06] (MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [13368 2012-11-09] (MSI)
S4 RsFx0200; C:\Windows\System32\DRIVERS\RsFx0200.sys [334936 2012-02-11] (Microsoft Corporation)
S3 ssudobex; C:\Windows\System32\DRIVERS\ssudobex.sys [204568 2013-08-20] (DEVGURU Co., LTD.(www.devguru.co.kr))
R3 WinRing0_1_2_0; C:\Program Files (x86)\C2DtoG15\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-10-31] ()

========================== Drivers MD5 =======================

C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit
C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit
C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit
C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit
C:\Windows\system32\drivers\afd.sys 314C17917AC8523EC77A710215012A65
C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit
C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49
C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit
C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048
C:\Windows\system32\drivers\appid.sys ==> MD5 is legit
C:\Windows\system32\drivers\arc.sys ==> MD5 is legit
C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
C:\Windows\system32\drivers\atapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\avgntflt.sys 0D5C96FD25D6455D97A5C4D7706DFAB1
C:\Windows\System32\DRIVERS\avipbb.sys E26B3C8E9C3DDE047B32C5719955D715
C:\Windows\System32\DRIVERS\avkmgr.sys 490FA25161BF3E51993EB724ECF0ACEB
C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit
C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit
C:\Windows\System32\CLFS.sys ==> MD5 is legit
C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit
C:\Windows\System32\Drivers\cng.sys AAFCB52FE0037207FB6FBEA070D25EFE
C:\Windows\system32\drivers\compbatt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\csc.sys ==> MD5 is legit
C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ssudbus.sys E428DFFA96FAD07D8CA3C9082563A225
C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
C:\Windows\System32\drivers\disk.sys ==> MD5 is legit
C:\Windows\system32\drivers\dmvsc.sys 5DB085A8A6600BE6401F2B24EECB5415
C:\Windows\System32\drivers\drmkaud.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\dtsoftbus01.sys 46571ED73AE84469DCA53081D33CF3C8
C:\Windows\System32\drivers\dxgkrnl.sys 88612F1CE3BF42256913BF6E61C70D52
C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit
C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit
C:\Windows\system32\epmntdrv.sys 6106653B08F4F72EEAA7F099E7C408A4
C:\Windows\SysWow64\epmntdrv.sys F17F09BA097D8EC3CE2084FA97886B85
C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit
C:\Windows\system32\EuGdiDrv.sys 991C04A31777ED77CB92A4F96F14C2E2
C:\Windows\SysWow64\EuGdiDrv.sys F1DE3EEF501DDA7DDF99F2EDF0C5540E
C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit
C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit
C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit
C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B
C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0
C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit
C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A
C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit
C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit
C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit
C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit
C:\Windows\System32\drivers\iaStorA.sys 0FE66A51D81A25AACEAAE4C26308121D
C:\Windows\System32\drivers\iaStorF.sys A0EA86734FD36A1A047CA24EC6528CBA
C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366
C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ikbevent.sys F2C300C2E56F016B485B88080CD7D2FE
C:\Windows\System32\DRIVERS\imsevent.sys C1A5061D6E5C328AE030C34B8AAC5C5C
C:\Windows\System32\drivers\RTKVHD64.sys E551BB77E7D436380139977124BDFF62
C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit
C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ISCTD64.sys 5AB18D8055A4280C0F377A6262F3157E
C:\Windows\System32\DRIVERS\iusb3hcs.sys 75779002A6084C1A011E195E421A9C75
C:\Windows\System32\DRIVERS\iusb3hub.sys F390B641FE6115F536B8B78AA71B8814
C:\Windows\System32\DRIVERS\iusb3xhc.sys 653B86AA174FF7661D00EE1E524B234F
C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\ksecdd.sys 97A7070AEA4C058B6418519E869A63B4
C:\Windows\System32\Drivers\ksecpkg.sys 7EFB9333E4ECCE6AE4AE9D777D9E553E
C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit
C:\Windows\System32\drivers\LGBusEnum.sys FA529FB35694C24BF98A9EF67C1CD9D0
C:\Windows\System32\DRIVERS\LGSHidFilt.Sys 94AF1384A67B9FCF5651E70BC9D4C526
C:\Windows\System32\drivers\LGVirHid.sys 94B29CE153765E768F004FB3440BE2B0
C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit
C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MBfilt64.sys 8FF2D95CBA49B405C5DE27039FF0BF35
C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit
C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\HECIx64.sys 772A1DEEDFDBC244183B5C805D1B7D85
C:\Windows\System32\drivers\modem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit
C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\mrxdav.sys 1A4F75E63C9FB84B85DFFC6B63FD5404
C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC
C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163
C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C
C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit
C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88
C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit
C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Ntfs.sys B98F8C6E31CD07B2E6F71F7F648E38C0
C:\Program Files (x86)\MSI\ControlCenter\NTIOLib_X64.sys 6D97EE5B3300D0F7FA359F2712834C40
C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys 23CF3DA010497EB2BF39A5C5A57E437C
C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys 1B32C54B95121AB1683C7B83B2DB4B96
C:\Program Files (x86)\Setup Files\Ms7758v190\NTIOLib_X64.sys C02F70960FA934B8DEFA16A03D7F6556
C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys 2DA209DDE8188076A9579BD256DC90D0
C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
C:\Windows\System32\drivers\nvhda64v.sys B4F53BCA4C688FF47F04FA90098F896E
C:\Windows\System32\DRIVERS\nvlddmkm.sys 4EE399576F76D38C04745DB739BBC8C7
C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD
C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A
C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit
C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\parport.sys ==> MD5 is legit
C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C
C:\Windows\System32\drivers\pci.sys ==> MD5 is legit
C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit
C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit
C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
C:\Windows\system32\drivers\processr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpdr.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34
C:\Windows\System32\Drivers\RDPWD.sys E61608AA35E98999AF9AAEEEA6114B0A
C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\revoflt.sys 9C3AC71A9934B884FAC567A8807E9C4D
C:\Windows\System32\DRIVERS\RsFx0200.sys 5AA85332CB1694871B2F0704E0FC9113
C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\Rt64win7.sys 130DD683DCC902F47A4AC35201D07E2F
C:\Windows\system32\drivers\vms3cap.sys ==> MD5 is legit
C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serenum.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serial.sys ==> MD5 is legit
C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit
C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit
C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit
C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
C:\Windows\SysWow64\speedfan.sys 0FFE35F0B0CD5A324BBE22F02569AE3B
C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B
C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28
C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3
C:\Windows\System32\DRIVERS\ssudmdm.sys AAF6F247F1DC370C593B4430974EAD9C
C:\Windows\System32\DRIVERS\ssudobex.sys 9A8D59146B6FC187140179D0F05EB07E
C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit
C:\Windows\system32\drivers\serscan.sys DECACB6921DED1A38642642685D77DAC
C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 is legit
C:\Windows\system32\drivers\storvsc.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit
C:\Windows\System32\drivers\tcpip.sys 40AF23633D197905F03AB5628C558C51
C:\Windows\System32\DRIVERS\tcpip.sys 40AF23633D197905F03AB5628C558C51
C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC
C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8
C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tssecsrv.sys 4CE278FC9671BA81A138D70823FCAA09
C:\Windows\System32\drivers\tsusbflt.sys 17C6B51CBCCDED95B3CC14E22791F85E
C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07
C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\usbccgp.sys ACCEA6BC68D0C9A78EB97EE159028B4E
C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31
C:\Windows\system32\drivers\usbehci.sys 311C1DD1088E55BEAE15954D17F50646
C:\Windows\System32\DRIVERS\usbhub.sys 280E90CBF4B2DDD169F0728CB44D726F
C:\Windows\system32\drivers\usbohci.sys 9406D801042FAF859CF81B2C886413DC
C:\Windows\system32\drivers\usbprint.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6
C:\Windows\system32\drivers\usbuhci.sys A83D0EC9AE4C31704442099D40BA2471
C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit
C:\Windows\system32\drivers\vmbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit
C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit
C:\Windows\System32\drivers\vwifibus.sys ==> MD5 is legit
C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\system32\drivers\wd.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8
C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\SysWow64\drivers\wimmount.sys ==> MD5 is legit
C:\Program Files (x86)\C2DtoG15\WinRing0x64.sys 0C0195C48B6B8582FA6F6373032118DA
C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D
C:\Windows\System32\DRIVERS\wmiacpi.sys ==> MD5 is legit
C:\Windows\System32\drivers\WPRO_41_2001.sys 7CA09731EB7FC99B910C7F239E57720F
C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\WSDPrint.sys 8D918B1DB190A4D9B1753A66FA8C96E8
C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F
C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-31 17:42 - 2013-10-31 17:42 - 104348737 _____ C:\Windows\SysWOW64\Ꮿ‹
2013-10-29 19:32 - 2013-10-30 20:12 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2013-10-29 19:32 - 2013-10-29 19:32 - 00001013 _____ C:\Users\UpdatusUser\Desktop\SpeedFan.lnk
2013-10-29 19:32 - 2013-10-29 19:32 - 00001013 _____ C:\Users\cottec\Desktop\SpeedFan.lnk
2013-10-29 19:32 - 2013-10-29 19:32 - 00000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2013-10-29 19:32 - 2013-10-29 19:32 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
2013-10-29 19:32 - 2013-10-29 19:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-28 17:55 - 2013-10-28 17:55 - 00009328 _____ C:\Users\cottec\Desktop\s3_insel-yf0f1pmqzdud.dlc
2013-10-27 20:05 - 2013-10-27 20:05 - 00290112 _____ C:\Windows\msxml4-KB954430-enu.LOG
2013-10-27 20:05 - 2013-10-27 20:05 - 00284430 _____ C:\Windows\msxml4-KB973688-enu.LOG
2013-10-27 20:05 - 2013-10-27 20:05 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-10-27 20:05 - 2013-10-27 20:05 - 00000000 ____D C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2013-10-26 12:44 - 2013-10-26 12:44 - 00000000 ____D C:\Users\cottec\Desktop\Solidworks
2013-10-26 12:35 - 2013-10-26 12:35 - 00002094 _____ C:\Users\cottec\Desktop\JDownloader 2.lnk
2013-10-26 12:35 - 2013-10-26 12:35 - 00001535 _____ C:\Users\cottec\Desktop\GUI_9KW.lnk
2013-10-26 12:35 - 2013-10-26 12:35 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader
2013-10-26 12:34 - 2013-10-30 21:28 - 00000000 ____D C:\Users\cottec\AppData\Local\JDownloader v2.0
2013-10-26 12:32 - 2013-10-26 12:32 - 00000000 _____ C:\Users\cottec\AppData\Local\Temptable.xml
2013-10-26 12:22 - 2013-10-26 12:22 - 00000000 ____D C:\Users\cottec\AppData\Roaming\SolidWorks 2014
2013-10-26 12:15 - 2013-10-26 12:15 - 00000000 ____D C:\Users\cottec\AppData\Local\TempSWSicherungsverzeichnis
2013-10-26 12:14 - 2013-10-26 12:14 - 00000000 ____D C:\Users\cottec\AppData\Local\SolidWorks
2013-10-26 12:11 - 2013-10-26 12:11 - 00000000 ____D C:\ProgramData\Simpoe
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\Users\cottec\Documents\SolidWorksComposer
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\ProgramData\SolidWorks Flow Simulation
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\ProgramData\COSMOS Applications
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 ____D C:\Users\cottec\AppData\Roaming\help_images_otherUI
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 ____D C:\Program Files (x86)\SolidWorks Corp
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 _____ C:\Windows\eDrawingOfficeAutomator.INI
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\Documents\SolidWorks Visual Studio Tools for Applications
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\AppData\Roaming\DassaultSystemes
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\AppData\Local\DassaultSystemes
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\ProgramData\DassaultSystemes
2013-10-26 11:49 - 2013-10-26 12:11 - 00000000 ____D C:\Program Files\SolidWorks Corp
2013-10-26 11:49 - 2013-10-26 12:07 - 00000000 ____D C:\Program Files\Common Files\SolidWorks Shared
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\ProgramData\SolidWorks
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 8
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
2013-10-26 11:48 - 2013-10-26 11:48 - 00000000 ____D C:\Windows\system32\RsFx
2013-10-26 11:48 - 2013-10-26 11:48 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0
2013-10-26 11:48 - 2012-02-11 09:03 - 00082520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perf-MSSQL$TEW_SQLEXPRESS-sqlctr11.0.2100.60.dll
2013-10-26 11:48 - 2012-02-11 09:02 - 00045656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perf-MSSQL11.TEW_SQLEXPRESS-sqlagtctr.dll
2013-10-26 11:48 - 2012-02-11 07:46 - 00180312 _____ (Microsoft Corporation) C:\Windows\system32\hadrres.dll
2013-10-26 11:48 - 2012-02-11 07:46 - 00082520 _____ (Microsoft Corporation) C:\Windows\system32\fssres.dll
2013-10-26 11:48 - 2012-02-11 07:44 - 00095832 _____ (Microsoft Corporation) C:\Windows\system32\perf-MSSQL$TEW_SQLEXPRESS-sqlctr11.0.2100.60.dll
2013-10-26 11:48 - 2012-02-11 07:44 - 00054360 _____ (Microsoft Corporation) C:\Windows\system32\perf-MSSQL11.TEW_SQLEXPRESS-sqlagtctr.dll
2013-10-26 11:47 - 2013-10-26 11:49 - 00000000 ____D C:\Windows\SysWOW64\1033
2013-10-26 11:47 - 2013-10-26 11:49 - 00000000 ____D C:\Windows\system32\1033
2013-10-26 11:47 - 2013-10-26 11:47 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2013-10-26 11:46 - 2013-10-26 12:09 - 00000000 ____D C:\ProgramData\SolidWorks Electrical
2013-10-26 11:46 - 2013-10-26 11:47 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Users\cottec\Documents\Visual Studio 2005
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\ProgramData\FLEXnet
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\ProgramData\Apple
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files\Bonjour
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files (x86)\Bonjour
2013-10-26 11:45 - 2013-10-26 12:03 - 00000000 ____D C:\SolidWorks Data
2013-10-26 11:39 - 2013-10-26 12:22 - 00000000 ____D C:\Users\cottec\AppData\Roaming\SolidWorks
2013-10-26 11:39 - 2013-10-26 11:45 - 00000000 ____D C:\Windows\SolidWorks
2013-10-25 20:52 - 2013-10-25 20:52 - 00001164 _____ C:\Users\Public\Desktop\CLICKBIOSII.lnk
2013-10-25 20:50 - 2013-10-25 20:50 - 00001188 _____ C:\Users\Public\Desktop\ControlCenter.lnk
2013-10-25 20:49 - 2013-10-25 20:50 - 00000000 ___HD C:\ControlCenterCount
2013-10-25 16:49 - 2013-10-25 16:49 - 00000000 ____D C:\Users\cottec\AppData\Roaming\NVIDIA
2013-10-25 16:48 - 2013-10-25 16:48 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-10-25 16:48 - 2013-09-08 20:34 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-10-25 16:48 - 2013-09-08 20:34 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-10-25 16:48 - 2013-09-08 20:34 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Microsoft Help
2013-10-25 16:48 - 2013-03-15 06:53 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2013-10-25 16:48 - 2013-03-15 06:53 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2013-10-25 16:48 - 2013-03-15 05:16 - 06398240 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-10-25 16:48 - 2013-03-15 05:16 - 03477280 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-10-25 16:48 - 2013-03-15 05:16 - 02555680 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2013-10-25 16:48 - 2013-03-15 05:16 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-10-25 16:48 - 2013-03-15 05:16 - 00237856 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-10-25 16:48 - 2013-03-15 05:16 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-10-25 16:47 - 2013-10-25 16:48 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-10-25 16:47 - 2013-03-15 06:53 - 26956576 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 25256736 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 20542752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 17990800 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 15508512 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 15042928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 13088000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 11048736 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-10-25 16:47 - 2013-03-15 06:53 - 09414456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 07959000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 07573816 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 06271872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 02913056 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 02864144 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 02728736 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 02539128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 02355488 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 01995552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 01807136 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6431422.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 01510176 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6431422.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 01118776 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 00968408 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 00250504 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 00205184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 00017738 _____ C:\Windows\system32\nvinfo.pb
2013-10-25 16:47 - 2012-12-19 06:42 - 00031672 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2013-10-25 16:47 - 2012-12-19 06:41 - 00194488 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2013-10-25 16:47 - 2012-12-18 09:31 - 01510328 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2013-10-24 22:07 - 2013-10-25 16:07 - 102975063 _____ C:\Windows\SysWOW64\丘斆“
2013-10-24 18:14 - 2013-10-31 23:15 - 00000292 _____ C:\Windows\Tasks\FoxTab.job
2013-10-24 18:14 - 2013-10-24 18:14 - 00003236 _____ C:\Windows\System32\Tasks\FoxTab
2013-10-24 18:14 - 2013-10-24 18:14 - 00000000 ____D C:\Users\cottec\AppData\Roaming\FoxTab
2013-10-24 18:09 - 2013-10-28 17:56 - 00000000 ____D C:\Users\cottec\AppData\Local\GUI_9KW
2013-10-24 18:06 - 2013-10-24 18:06 - 00000000 ____D C:\Users\cottec\.java
2013-10-24 17:54 - 2013-10-26 12:11 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-10-24 17:54 - 2013-10-24 17:54 - 00000000 ____D C:\Program Files (x86)\Foxtab
2013-10-24 16:19 - 2013-10-24 16:19 - 00000000 ____D C:\ProgramData\Oracle
2013-10-24 16:18 - 2013-10-24 16:18 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-22 16:00 - 2013-10-25 16:48 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-10-22 15:47 - 2013-10-31 17:41 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-10-22 14:38 - 2013-10-22 14:38 - 102329055 _____ C:\Windows\SysWOW64\퟊
2013-10-17 16:44 - 2013-10-17 16:44 - 101544623 _____ C:\Windows\SysWOW64\葙ꇷM
2013-10-16 16:07 - 2013-10-16 16:07 - 101406750 _____ C:\Windows\SysWOW64\핍柮Œ
2013-10-15 17:27 - 2013-10-15 17:27 - 00000000 ____D C:\Users\cottec\AppData\Roaming\wargaming.net
2013-10-15 17:01 - 2013-10-15 17:01 - 101148298 _____ C:\Windows\SysWOW64\梋녒„
2013-10-14 20:02 - 2013-10-14 20:02 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-10-13 16:13 - 2013-10-13 16:14 - 00000000 ____D C:\Users\cottec\Documents\Battlefield 4 Beta
2013-10-12 14:01 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-11 22:39 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-11 22:39 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-11 22:39 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-11 22:39 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-11 22:39 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-11 22:39 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-11 22:39 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-11 22:39 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-11 22:39 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-11 22:39 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-11 20:03 - 2013-10-11 20:03 - 00000000 ____D C:\Program Files\DivX
2013-10-11 20:02 - 2013-10-11 20:03 - 00000000 ____D C:\Program Files (x86)\DivX
2013-10-11 20:01 - 2013-10-11 20:03 - 00000000 ____D C:\ProgramData\DivX
2013-10-11 18:51 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-11 18:51 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-11 18:51 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-11 18:51 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-11 18:51 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-11 18:51 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-11 18:51 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-11 18:51 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-11 18:51 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-11 18:51 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-11 18:51 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-11 18:51 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-11 18:51 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-11 18:51 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-11 18:51 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-11 18:51 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-11 18:51 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-11 18:51 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-11 18:51 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-11 18:51 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-11 18:51 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-11 18:51 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-11 18:51 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 18:51 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 18:51 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-11 18:51 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-11 18:51 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-11 18:51 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-11 18:51 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-11 18:51 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-11 18:51 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-11 18:51 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-11 18:51 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-11 18:51 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-11 18:51 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-11 18:51 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-11 18:51 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-11 18:51 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-11 18:51 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-11 18:51 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-11 18:51 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-11 18:51 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-11 18:51 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-11 18:51 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-11 18:51 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-10 17:23 - 2013-10-10 17:23 - 100305510 _____ C:\Windows\SysWOW64\㳈ˁu
2013-10-07 17:15 - 2013-10-07 17:15 - 00003074 _____ C:\Windows\System32\Tasks\ScanToPCActivationApp.exe_{AD063CB6-193B-4D04-BB14-1AF681BF23C6}
2013-10-07 17:12 - 2013-10-07 17:12 - 00000000 ____D C:\Users\cottec\Documents\Fax
2013-10-07 16:44 - 2013-10-07 16:44 - 99717279 _____ C:\Windows\SysWOW64\꘽ൡ7
2013-10-06 19:46 - 2013-10-06 19:46 - 99477982 _____ C:\Windows\SysWOW64\⠙ᚅ‘
2013-10-06 13:46 - 2013-10-06 13:46 - 99463930 _____ C:\Windows\SysWOW64\乻¤
2013-10-04 18:28 - 2013-10-04 18:28 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-10-02 16:41 - 2013-10-02 16:41 - 98743931 _____ C:\Windows\SysWOW64\팁뺱¤
2013-10-01 18:03 - 2013-10-01 18:17 - 00000000 ____D C:\Users\cottec\Documents\Battlefield 4
2013-10-01 18:00 - 2013-10-01 18:00 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-01 16:47 - 2013-10-01 16:47 - 98609570 _____ C:\Windows\SysWOW64\Ⲭ攢¤

==================== One Month Modified Files and Folders =======

2013-10-31 23:15 - 2013-10-24 18:14 - 00000292 _____ C:\Windows\Tasks\FoxTab.job
2013-10-31 23:04 - 2013-02-17 15:59 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-31 23:04 - 2013-02-17 15:59 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-31 22:29 - 2013-02-11 19:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-31 22:11 - 2012-12-22 23:49 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-10-31 22:05 - 2013-08-20 18:37 - 00091595 _____ C:\Windows\DirectX.log
2013-10-31 22:05 - 2012-12-26 14:22 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-10-31 22:05 - 2012-12-22 23:49 - 00281872 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-10-31 22:05 - 2012-12-22 23:49 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-10-31 20:13 - 2013-09-08 20:27 - 01641014 _____ C:\Windows\WindowsUpdate.log
2013-10-31 17:48 - 2009-07-14 05:45 - 00018496 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-31 17:48 - 2009-07-14 05:45 - 00018496 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-31 17:47 - 2011-04-12 08:43 - 00784632 _____ C:\Windows\system32\perfh007.dat
2013-10-31 17:47 - 2011-04-12 08:43 - 00183704 _____ C:\Windows\system32\perfc007.dat
2013-10-31 17:47 - 2009-07-14 06:13 - 01865344 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-31 17:42 - 2013-10-31 17:42 - 104348737 _____ C:\Windows\SysWOW64\Ꮿ‹
2013-10-31 17:41 - 2013-10-22 15:47 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-10-31 17:41 - 2013-09-08 20:27 - 00000000 ____D C:\ProgramData\NVIDIA
2013-10-31 17:41 - 2013-01-27 18:36 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Dropbox
2013-10-31 17:41 - 2012-12-24 00:51 - 00000000 ____D C:\Program Files (x86)\C2DtoG15
2013-10-31 17:41 - 2012-12-23 18:21 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2013-10-31 17:41 - 2010-11-21 04:47 - 00051824 _____ C:\Windows\PFRO.log
2013-10-31 17:41 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-31 17:41 - 2009-07-14 05:51 - 10117424 _____ C:\Windows\setupact.log
2013-10-30 21:28 - 2013-10-26 12:34 - 00000000 ____D C:\Users\cottec\AppData\Local\JDownloader v2.0
2013-10-30 20:12 - 2013-10-29 19:32 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2013-10-29 19:36 - 2012-12-20 21:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-29 19:32 - 2013-10-29 19:32 - 00001013 _____ C:\Users\UpdatusUser\Desktop\SpeedFan.lnk
2013-10-29 19:32 - 2013-10-29 19:32 - 00001013 _____ C:\Users\cottec\Desktop\SpeedFan.lnk
2013-10-29 19:32 - 2013-10-29 19:32 - 00000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2013-10-29 19:32 - 2013-10-29 19:32 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
2013-10-29 19:32 - 2013-10-29 19:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-28 17:56 - 2013-10-24 18:09 - 00000000 ____D C:\Users\cottec\AppData\Local\GUI_9KW
2013-10-28 17:55 - 2013-10-28 17:55 - 00009328 _____ C:\Users\cottec\Desktop\s3_insel-yf0f1pmqzdud.dlc
2013-10-27 20:05 - 2013-10-27 20:05 - 00290112 _____ C:\Windows\msxml4-KB954430-enu.LOG
2013-10-27 20:05 - 2013-10-27 20:05 - 00284430 _____ C:\Windows\msxml4-KB973688-enu.LOG
2013-10-27 20:05 - 2013-10-27 20:05 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-10-27 20:05 - 2013-10-27 20:05 - 00000000 ____D C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2013-10-26 12:44 - 2013-10-26 12:44 - 00000000 ____D C:\Users\cottec\Desktop\Solidworks
2013-10-26 12:35 - 2013-10-26 12:35 - 00002094 _____ C:\Users\cottec\Desktop\JDownloader 2.lnk
2013-10-26 12:35 - 2013-10-26 12:35 - 00001535 _____ C:\Users\cottec\Desktop\GUI_9KW.lnk
2013-10-26 12:35 - 2013-10-26 12:35 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader
2013-10-26 12:32 - 2013-10-26 12:32 - 00000000 _____ C:\Users\cottec\AppData\Local\Temptable.xml
2013-10-26 12:22 - 2013-10-26 12:22 - 00000000 ____D C:\Users\cottec\AppData\Roaming\SolidWorks 2014
2013-10-26 12:22 - 2013-10-26 11:39 - 00000000 ____D C:\Users\cottec\AppData\Roaming\SolidWorks
2013-10-26 12:15 - 2013-10-26 12:15 - 00000000 ____D C:\Users\cottec\AppData\Local\TempSWSicherungsverzeichnis
2013-10-26 12:14 - 2013-10-26 12:14 - 00000000 ____D C:\Users\cottec\AppData\Local\SolidWorks
2013-10-26 12:14 - 2009-07-14 05:45 - 00447120 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-26 12:12 - 2013-09-08 20:40 - 00122208 _____ C:\Users\cottec\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-26 12:11 - 2013-10-26 12:11 - 00000000 ____D C:\ProgramData\Simpoe
2013-10-26 12:11 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\SolidWorks Corp
2013-10-26 12:11 - 2013-10-24 17:54 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\Users\cottec\Documents\SolidWorksComposer
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\ProgramData\SolidWorks Flow Simulation
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\ProgramData\COSMOS Applications
2013-10-26 12:09 - 2013-10-26 11:46 - 00000000 ____D C:\ProgramData\SolidWorks Electrical
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 ____D C:\Users\cottec\AppData\Roaming\help_images_otherUI
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 ____D C:\Program Files (x86)\SolidWorks Corp
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 _____ C:\Windows\eDrawingOfficeAutomator.INI
2013-10-26 12:07 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\Common Files\SolidWorks Shared
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\Documents\SolidWorks Visual Studio Tools for Applications
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\AppData\Roaming\DassaultSystemes
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\AppData\Local\DassaultSystemes
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\ProgramData\DassaultSystemes
2013-10-26 12:03 - 2013-10-26 11:45 - 00000000 ____D C:\SolidWorks Data
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\ProgramData\SolidWorks
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 8
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
2013-10-26 11:49 - 2013-10-26 11:47 - 00000000 ____D C:\Windows\SysWOW64\1033
2013-10-26 11:49 - 2013-10-26 11:47 - 00000000 ____D C:\Windows\system32\1033
2013-10-26 11:49 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-10-26 11:48 - 2013-10-26 11:48 - 00000000 ____D C:\Windows\system32\RsFx
2013-10-26 11:48 - 2013-10-26 11:48 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0
2013-10-26 11:47 - 2013-10-26 11:47 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2013-10-26 11:47 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Users\cottec\Documents\Visual Studio 2005
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\ProgramData\FLEXnet
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\ProgramData\Apple
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files\Bonjour
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files (x86)\Bonjour
2013-10-26 11:46 - 2012-12-23 13:32 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-26 11:46 - 2012-12-23 13:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2013-10-26 11:46 - 2012-12-23 13:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-10-26 11:45 - 2013-10-26 11:39 - 00000000 ____D C:\Windows\SolidWorks
2013-10-25 20:52 - 2013-10-25 20:52 - 00001164 _____ C:\Users\Public\Desktop\CLICKBIOSII.lnk
2013-10-25 20:50 - 2013-10-25 20:50 - 00001188 _____ C:\Users\Public\Desktop\ControlCenter.lnk
2013-10-25 20:50 - 2013-10-25 20:49 - 00000000 ___HD C:\ControlCenterCount
2013-10-25 16:49 - 2013-10-25 16:49 - 00000000 ____D C:\Users\cottec\AppData\Roaming\NVIDIA
2013-10-25 16:48 - 2013-10-25 16:48 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-10-25 16:48 - 2013-10-25 16:47 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-10-25 16:48 - 2013-10-22 16:00 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-10-25 16:48 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Help
2013-10-25 16:07 - 2013-10-24 22:07 - 102975063 _____ C:\Windows\SysWOW64\丘斆“
2013-10-24 18:14 - 2013-10-24 18:14 - 00003236 _____ C:\Windows\System32\Tasks\FoxTab
2013-10-24 18:14 - 2013-10-24 18:14 - 00000000 ____D C:\Users\cottec\AppData\Roaming\FoxTab
2013-10-24 18:06 - 2013-10-24 18:06 - 00000000 ____D C:\Users\cottec\.java
2013-10-24 18:06 - 2013-09-08 20:28 - 00000000 ____D C:\Users\cottec
2013-10-24 17:54 - 2013-10-24 17:54 - 00000000 ____D C:\Program Files (x86)\Foxtab
2013-10-24 16:19 - 2013-10-24 16:19 - 00000000 ____D C:\ProgramData\Oracle
2013-10-24 16:18 - 2013-10-24 16:18 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-24 16:18 - 2013-03-07 10:45 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-22 14:38 - 2013-10-22 14:38 - 102329055 _____ C:\Windows\SysWOW64\퟊
2013-10-17 16:44 - 2013-10-17 16:44 - 101544623 _____ C:\Windows\SysWOW64\葙ꇷM
2013-10-16 16:07 - 2013-10-16 16:07 - 101406750 _____ C:\Windows\SysWOW64\핍柮Œ
2013-10-15 17:27 - 2013-10-15 17:27 - 00000000 ____D C:\Users\cottec\AppData\Roaming\wargaming.net
2013-10-15 17:26 - 2012-12-20 21:10 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-15 17:01 - 2013-10-15 17:01 - 101148298 _____ C:\Windows\SysWOW64\梋녒„
2013-10-14 20:02 - 2013-10-14 20:02 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-10-13 16:14 - 2013-10-13 16:13 - 00000000 ____D C:\Users\cottec\Documents\Battlefield 4 Beta
2013-10-13 15:36 - 2012-12-24 21:11 - 00000000 ____D C:\Users\cottec\Documents\Calibre Bibliothek
2013-10-12 13:52 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-10-11 22:38 - 2013-09-08 20:43 - 01592864 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-11 22:38 - 2012-12-23 14:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-11 22:38 - 2012-12-23 14:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-11 22:35 - 2013-07-31 21:15 - 00000000 ____D C:\Windows\system32\MRT
2013-10-11 22:34 - 2013-09-09 18:13 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-11 20:03 - 2013-10-11 20:03 - 00000000 ____D C:\Program Files\DivX
2013-10-11 20:03 - 2013-10-11 20:02 - 00000000 ____D C:\Program Files (x86)\DivX
2013-10-11 20:03 - 2013-10-11 20:01 - 00000000 ____D C:\ProgramData\DivX
2013-10-11 20:02 - 2013-09-15 16:16 - 00000000 _____ C:\END
2013-10-10 17:23 - 2013-10-10 17:23 - 100305510 _____ C:\Windows\SysWOW64\㳈ˁu
2013-10-09 19:29 - 2013-02-11 19:12 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 19:29 - 2012-12-21 17:08 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 19:29 - 2012-12-21 17:08 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-09 19:23 - 2012-12-28 11:50 - 00000000 ____D C:\Users\cottec\AppData\Roaming\vlc
2013-10-08 21:59 - 2013-02-17 15:59 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-08 21:59 - 2013-02-17 15:59 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-08 06:50 - 2013-06-23 17:14 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 06:46 - 2013-06-23 17:14 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-08 06:46 - 2013-06-23 17:14 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-08 06:46 - 2013-06-23 17:14 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-07 17:17 - 2013-01-20 15:50 - 00000000 ____D C:\Users\cottec\AppData\Local\FRITZ!
2013-10-07 17:15 - 2013-10-07 17:15 - 00003074 _____ C:\Windows\System32\Tasks\ScanToPCActivationApp.exe_{AD063CB6-193B-4D04-BB14-1AF681BF23C6}
2013-10-07 17:12 - 2013-10-07 17:12 - 00000000 ____D C:\Users\cottec\Documents\Fax
2013-10-07 16:44 - 2013-10-07 16:44 - 99717279 _____ C:\Windows\SysWOW64\꘽ൡ7
2013-10-06 19:46 - 2013-10-06 19:46 - 99477982 _____ C:\Windows\SysWOW64\⠙ᚅ‘
2013-10-06 13:46 - 2013-10-06 13:46 - 99463930 _____ C:\Windows\SysWOW64\乻¤
2013-10-04 18:28 - 2013-10-04 18:28 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-10-04 18:28 - 2013-06-27 14:14 - 00000000 ____D C:\Program Files (x86)\Kies
2013-10-04 16:48 - 2013-06-27 16:54 - 00000000 ____D C:\Users\cottec\AppData\Roaming\MyPhoneExplorer
2013-10-04 16:41 - 2013-06-27 16:54 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer
2013-10-03 17:32 - 2012-12-24 21:10 - 00000000 ____D C:\Program Files (x86)\Calibre2
2013-10-02 17:17 - 2012-12-23 00:32 - 00000000 ____D C:\Users\cottec\AppData\Local\PunkBuster
2013-10-02 16:41 - 2013-10-02 16:41 - 98743931 _____ C:\Windows\SysWOW64\팁뺱¤
2013-10-01 18:17 - 2013-10-01 18:03 - 00000000 ____D C:\Users\cottec\Documents\Battlefield 4
2013-10-01 18:00 - 2013-10-01 18:00 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-01 17:55 - 2012-12-20 21:29 - 00000000 ____D C:\Users\cottec\AppData\Local\Mozilla
2013-10-01 16:47 - 2013-10-01 16:47 - 98609570 _____ C:\Windows\SysWOW64\Ⲭ攢¤

Some content of TEMP:
====================
C:\Users\cottec\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\cottec\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\cottec\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\cottec\AppData\Local\Temp\nvStInst.exe
C:\Users\cottec\AppData\Local\Temp\proxy_vole6320029762539422116.dll
C:\Users\cottec\AppData\Local\Temp\sfamcc00001.dll
C:\Users\cottec\AppData\Local\Temp\sfextra.dll
C:\Users\cottec\AppData\Local\Temp\sonarinst.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== BCD ================================

Windows-Start-Manager
---------------------
Bezeichner              {bootmgr}
device                  partition=\Device\HarddiskVolume1
description            Windows Boot Manager
locale                  de-DE
inherit                {globalsettings}
default                {current}
resumeobject            {9b38fee3-4adf-11e2-a713-f87b13426a8a}
displayorder            {current}
toolsdisplayorder      {memdiag}
timeout                10

Windows-Startladeprogramm
-------------------------
Bezeichner              {current}
device                  partition=C:
path                    \Windows\system32\winload.exe
description            Windows 7
locale                  de-DE
inherit                {bootloadersettings}
recoverysequence        {cbd971bf-b7b8-4885-951a-fa03044f5d71}
recoveryenabled        No
osdevice                partition=C:
systemroot              \Windows
resumeobject            {9b38fee3-4adf-11e2-a713-f87b13426a8a}
nx                      OptIn

Wiederaufnahme aus dem Ruhezustand
----------------------------------
Bezeichner              {9b38fee3-4adf-11e2-a713-f87b13426a8a}
device                  partition=C:
path                    \Windows\system32\winresume.exe
description            Windows Resume Application
locale                  de-DE
inherit                {resumeloadersettings}
filedevice              partition=C:
filepath                \hiberfil.sys
debugoptionenabled      No

Windows-Speichertestprogramm
----------------------------
Bezeichner              {memdiag}
device                  partition=\Device\HarddiskVolume1
path                    \boot\memtest.exe
description            Windows-Speicherdiagnose
locale                  de-DE
inherit                {globalsettings}
badmemoryaccess        Yes

EMS-Einstellungen
-----------------
Bezeichner              {emssettings}
bootems                Yes

Debuggereinstellungen
---------------------
Bezeichner              {dbgsettings}
debugtype              Serial
debugport              1
baudrate                115200

RAM-Defekte
-----------
Bezeichner              {badmemory}

Globale Einstellungen
---------------------
Bezeichner              {globalsettings}
inherit                {dbgsettings}
                        {emssettings}
                        {badmemory}

Startladeprogramm-Einstellungen
-------------------------------
Bezeichner              {bootloadersettings}
inherit                {globalsettings}
                        {hypervisorsettings}

Hypervisoreinstellungen
-------------------
Bezeichner              {hypervisorsettings}
hypervisordebugtype    Serial
hypervisordebugport    1
hypervisorbaudrate      115200

Einstellungen zur Ladeprogrammfortsetzung
-----------------------------------------
Bezeichner              {resumeloadersettings}
inherit                {globalsettings}



LastRegBack: 2013-10-31 19:50

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---



Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-10-2013
Ran by cottec at 2013-10-31 23:25:44
Running from D:\Downloads\Software\FRST
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader XI - Deutsch (x32 Version: 11.0.00)
ArtMoney SE v7.39.2 (x32 Version: 7.39)
AutoIt v3.3.8.1 (x32)
Avira Free Antivirus (x32 Version: 13.0.0.4052)
AVM FRITZ!fax für FRITZ!Box (x32)
Battlefield 3™ (x32 Version: 1.6.0.0)
Battlefield 4™ (x32 Version: 1.0.0.0)
Battlefield 4™ Beta (x32 Version: 1.0.0.0)
Battlelog Web Plugins (x32 Version: 2.3.0)
BMW EBA (x32 Version: 2.1.0)
Bonjour (Version: 3.0.0.10)
Burnout(TM) Paradise The Ultimate Box (x32 Version: 1.1.0.0)
C2DtoG15 2.0.2.1 (x32)
calibre (x32 Version: 1.5.0)
CCleaner (Version: 4.03)
CLICKBIOSII (x32 Version: 1.0.119)
ControlCenter (x32 Version: 2.5.060)
CrystalDiskInfo 5.2.0 (x32 Version: 5.2.0)
DAEMON Tools Lite (x32 Version: 4.47.1.0333)
DH Driver Cleaner Professional Edition (x32 Version: Version 1.5)
DivX-Setup (x32 Version: 2.6.1.84)
Dropbox (HKCU Version: 2.0.22)
EaseUS Partition Master 9.2.2 (x32)
ElsterFormular (x32 Version: 14.3.20130522)
ESET Online Scanner v3 (x32)
ESN Sonar (x32 Version: 0.70.4)
ETK (Lokal) (x32 Version: 2.00.064)
Far Cry 3 (x32 Version: 1.02)
Foxtab (x32)
Google Chrome (x32 Version: 30.0.1599.101)
Google Earth Plug-in (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
HP Officejet 6500 E710n-z - Grundlegende Software für das Gerät (Version: 28.0.1315.0)
Intel(R) Control Center (x32 Version: 1.2.1.1008)
Intel(R) Management Engine Components (x32 Version: 8.1.0.1252)
Intel(R) Rapid Storage Technology (x32 Version: 11.5.0.1207)
Intel(R) Smart Connect Technology 3.0 x64 (Version: 3.0.30.1526)
Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.8.251)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
JDownloader 2 (Version: 2.0)
Live Update 5 (x32 Version: 5.0.109)
Logitech Gaming Software (Version: 8.45.88)
Logitech Gaming Software 5.10 (Version: 5.10.127)
Logitech Gaming Software 8.50 (Version: 8.50.281)
ManiaPlanet (x32)
Medal of Honor (TM) (x32 Version: 1.0.0.0)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft Office 2003 Web Components (x32 Version: 12.0.6213.1000)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2008 Native Client (Version: 10.0.1600.22)
Microsoft SQL Server 2008 Setup Support Files  (Version: 10.1.2731.0)
Microsoft SQL Server 2012 (64-bit)
Microsoft SQL Server 2012 Native Client  (Version: 11.0.2100.60)
Microsoft SQL Server 2012 RsFx Driver (Version: 11.0.2100.60)
Microsoft SQL Server 2012 Setup (English) (Version: 11.0.2100.60)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (Version: 11.0.2100.60)
Microsoft Visual Basic for Applications 7.1 (x64) (Version: 7.1.00.00)
Microsoft Visual Basic for Applications 7.1 (x64) English (Version: 7.1.0.0)
Microsoft Visual Basic for Applications 7.1 (x64) German (Version: 7.1.0.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU (Version: 8.0.52572)
Microsoft Visual Studio 2005 Tools for Applications - ENU (x32 Version: 8.0.50727.146)
Microsoft Visual Studio 2005 Tools for Applications - ENU (x32)
Microsoft VSS Writer for SQL Server 2012 (Version: 11.0.2100.60)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0)
Miranda Fusion 3.2.6.0 (x32 Version: 3.2.6.0)
Mobipocket Creator 4.2 (x32 Version: 4.2.41)
Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0)
Mozilla Maintenance Service (x32 Version: 25.0)
Mp3tag v2.54 (x32 Version: v2.54)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MusicBrainz Picard (x32 Version: 1.1)
MyPhoneExplorer (x32 Version: 1.8.5)
Nasty File Remover v0.72 (remove only) (x32)
NVIDIA 3D Vision Controller-Treiber 314.22 (Version: 314.22)
NVIDIA 3D Vision Treiber 314.22 (Version: 314.22)
NVIDIA Grafiktreiber 314.22 (Version: 314.22)
NVIDIA HD-Audiotreiber 1.3.23.1 (Version: 1.3.23.1)
NVIDIA Install Application (Version: 2.1002.115.743)
NVIDIA PhysX (x32 Version: 9.12.1031)
NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1422)
NVIDIA Systemsteuerung 314.22 (Version: 314.22)
NVIDIA Update 1.12.12 (Version: 1.12.12)
NVIDIA Update Components (Version: 1.12.12)
Origin (x32 Version: 9.1.3.2637)
PDF24 Creator 5.4.0 (x32)
Populous (x32 Version: 1.0.0.0)
Project CARS (x32 Version: 0510)
PunkBuster Services (x32 Version: 0.993)
QuickPar 0.9 (x32 Version: 0.9)
Rainmeter (x32 Version: 2.5 beta r1720)
Realtek Ethernet Controller Driver (x32 Version: 7.72.410.2013)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6959)
Revo Uninstaller Pro 3.0.7 (Version: 3.0.7)
Samsung Kies (x32 Version: 2.5.3.13052_10)
Samsung Magician (x32 Version: 4.2.1)
Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0)
SolidWorks 2014 x64 Edition SP0 (Version: 22.100.5018)
SolidWorks 2014 x64 Edition SP0 (x32 Version: 22.0.0.5018)
SolidWorks 2014 x64 German Resources (Version: 22.100.5018)
SolidWorks Composer 2014 SP0 x64 Edition (Version: 22.00.5018)
SolidWorks eDrawings 2014 x64 Edition SP0 (Version: 14.0.5006)
SolidWorks Explorer 2014 SP0 x64 Edition (Version: 22.00.5018)
SolidWorks Flow Simulation 2014 SP0 x64 Edition  (Version: 22.00.5019)
SolidWorks Plastics 2014 SP0 x64 Edition (Version: 22.00.5018)
Source SDK Base 2007 (x32)
SpeedFan (remove only) (x32)
Splinter Cell: Blacklist (x32 Version: 1.01)
SQL Server 2012 Common Files (Version: 11.0.2100.60)
SQL Server 2012 Database Engine Services (Version: 11.0.2100.60)
SQL Server 2012 Database Engine Shared (Version: 11.0.2100.60)
SQL Server Browser for SQL Server 2012 (x32 Version: 11.0.2100.60)
Sql Server Customer Experience Improvement Program (Version: 11.0.2100.60)
Steam (x32 Version: 1.0.0.0)
Super-Charger (x32 Version: 1.2.018)
System Requirements Lab for Intel (x32 Version: 4.5.11.0)
Team Fortress 2 (x32)
TeamSpeak 3 Client (Version: 3.0.10)
TeamViewer 8 (x32 Version: 8.0.19045)
TomTom HOME (x32 Version: 2.9.6)
TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2)
TreeSize Free V2.7 (x32 Version: 2.7)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2827325) 32-Bit Edition (x32)
Update für Microsoft Office Excel 2007 Help (KB963678) (x32)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update für Microsoft Office Word 2007 Help (KB963665) (x32)
Uplay (x32 Version: 3.0)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
VLC media player 2.0.5 (Version: 2.0.5)
VR-NetWorld (x32)
Vuze (x32 Version: 5.1.0.0)
Winamp (x32 Version: 5.63 )
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1)
Windows XP Mode (Version: 1.3.7600.16422)
WinHTTrack Website Copier 3.47-6 (x64) (Version: 3.47.6)
Winki (x32 Version: 3.2.125)
WinRAR 4.20 (64-Bit) (Version: 4.20.0)
WinSCP 5.1.6 (x32 Version: 5.1.6)

==================== Restore Points  =========================

26-10-2013 12:43:55 Windows Update
27-10-2013 18:00:03 Windows-Sicherung
27-10-2013 19:05:22 Windows Update
28-10-2013 17:28:01 Windows Update
31-10-2013 21:04:56 DirectX wurde installiert

==================== Hosts content: ==========================

2009-07-14 03:34 - 2013-08-09 17:31 - 00449440 ___RA C:\Windows\system32\Drivers\etc\hosts
127.0.0.1        www.007guard.com
127.0.0.1        007guard.com
127.0.0.1        008i.com
127.0.0.1        www.008k.com
127.0.0.1        008k.com
127.0.0.1        www.00hq.com
127.0.0.1        00hq.com
127.0.0.1        010402.com
127.0.0.1        www.032439.com
127.0.0.1        032439.com
127.0.0.1        www.0scan.com
127.0.0.1        0scan.com
127.0.0.1        1000gratisproben.com
127.0.0.1        www.1000gratisproben.com
127.0.0.1        1001namen.com
127.0.0.1        www.1001namen.com
127.0.0.1        100888290cs.com
127.0.0.1        www.100888290cs.com
127.0.0.1        www.100sexlinks.com
127.0.0.1        100sexlinks.com
127.0.0.1        10sek.com
127.0.0.1        www.10sek.com
127.0.0.1        www.1-2005-search.com
127.0.0.1        1-2005-search.com
127.0.0.1        123fporn.info
127.0.0.1        www.123fporn.info
127.0.0.1        123haustiereundmehr.com
127.0.0.1        www.123haustiereundmehr.com
127.0.0.1        123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

Task: {050C409A-505D-4558-ABBB-A3FCE95FB2AD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
Task: {21C26F42-B34D-4702-88EB-9CA6B615CF3F} - System32\Tasks\ScanToPCActivationApp.exe_{AD063CB6-193B-4D04-BB14-1AF681BF23C6} => C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {34A40C97-DA4E-4B69-AD0F-74713550220E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.)
Task: {E55A84BF-00A1-464C-8541-913DFA654467} - System32\Tasks\FoxTab => C:\Users\cottec\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] ()
Task: {E73298AB-85F4-40AD-A720-77D23CD57192} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.)
Task: {EE6E17AB-533D-4D77-B1A2-B351BB4E2240} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FoxTab.job => C:\Users\cottec\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-09-21 08:30 - 2013-09-21 08:30 - 00276008 _____ () C:\Program Files\SolidWorks Corp\SolidWorks\sldBodyDiffu.dll
2012-12-16 16:42 - 2012-12-16 16:42 - 00761528 _____ () C:\Program Files\Rainmeter\Rainmeter.dll
2012-12-16 16:41 - 2012-12-16 16:41 - 00011776 _____ () C:\Program Files\Rainmeter\Plugins\PowerPlugin.DLL
2013-09-08 21:16 - 2013-09-08 21:16 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2013-10-31 17:41 - 2013-10-31 17:41 - 00011264 _____ () C:\Users\cottec\AppData\Local\Temp\nsa47E9.tmp\System.dll
2012-12-24 00:51 - 2010-06-11 21:14 - 00004608 _____ () C:\Program Files (x86)\C2DtoG15\LgLcdLibWrapper.dll
2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\cottec\AppData\Roaming\Dropbox\bin\libcef.dll
2013-08-05 04:41 - 2013-08-05 04:41 - 00057432 _____ () C:\Program Files (x86)\MirandaFusion\zlib.dll
2008-05-03 08:59 - 2008-05-03 08:59 - 00094208 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\svc_dbepp.dll
2009-08-04 08:46 - 2009-08-04 08:46 - 00162304 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\actman.dll
2013-08-05 04:40 - 2013-08-05 04:40 - 00203869 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\aim.dll
2009-05-08 22:42 - 2009-05-08 22:42 - 00067072 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\authstate.dll
2010-02-10 19:42 - 2010-02-10 19:42 - 00117760 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\extraicons.dll
2013-03-15 09:27 - 2013-03-15 09:27 - 00322048 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\facebook.dll
2010-09-28 16:59 - 2010-09-28 16:59 - 00498688 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\fingerprint.dll
2012-05-24 19:20 - 2012-05-24 19:20 - 00110592 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\folders.dll
2013-08-05 04:41 - 2013-08-05 04:41 - 00339550 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\icq.dll
2013-08-05 04:40 - 2013-08-05 04:40 - 00379993 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\irc.dll
2011-02-09 22:56 - 2011-02-09 22:56 - 00082021 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\keepstatus.dll
2010-08-26 17:27 - 2010-08-26 17:27 - 00062976 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\menuex.dll
2012-07-18 19:39 - 2012-07-18 19:39 - 00106496 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\metacontacts.dll
2013-01-19 22:14 - 2007-10-05 19:29 - 00323584 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\mirandag15.dll
2011-07-17 18:07 - 2011-07-17 18:07 - 00671232 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\mirotr.dll
2010-04-08 19:33 - 2010-04-08 19:33 - 00240128 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\sendss.dll
2011-09-13 14:59 - 2011-09-13 14:59 - 00094315 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\startupstatus.dll
2012-11-05 21:48 - 2012-11-05 21:48 - 00372736 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\twitter.dll
2010-10-10 10:12 - 2010-10-10 10:12 - 00374272 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\uinfoexw.dll
2009-10-09 08:04 - 2009-10-09 08:04 - 00036864 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\useactions.dll
2011-09-13 14:59 - 2011-09-13 14:59 - 00114688 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\variables.dll
2013-08-29 01:25 - 2013-08-29 01:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2013-09-08 21:47 - 2013-09-08 21:47 - 00017408 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\PSIClient\e54fd507aa171a3a0a7d0cc47266a7ff\PSIClient.ni.dll
2012-12-23 18:25 - 2012-06-25 10:41 - 01198912 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-04-25 18:44 - 2013-10-31 18:21 - 00062976 _____ () C:\Spiele\Origin\tufao.dll
2013-10-29 19:32 - 2013-10-29 19:32 - 03368048 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/31/2013 07:51:43 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (10/31/2013 05:43:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/31/2013 05:41:49 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (10/30/2013 08:12:11 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/30/2013 08:10:28 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (10/29/2013 11:39:06 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/29/2013 11:37:23 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (10/29/2013 08:40:36 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (10/29/2013 07:28:44 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/29/2013 07:27:01 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n


System errors:
=============
Error: (10/28/2013 05:12:31 PM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.

Error: (10/28/2013 05:12:31 PM) (Source: volmgr) (User: )
Description: Das System konnte den Treiber für das Speicherabbild nicht laden.

Error: (10/27/2013 02:56:58 PM) (Source: volmgr) (User: )
Description: Das System konnte den Treiber für das Speicherabbild nicht laden.

Error: (10/27/2013 02:56:55 PM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.

Error: (10/27/2013 02:56:55 PM) (Source: volmgr) (User: )
Description: Das System konnte den Treiber für das Speicherabbild nicht laden.

Error: (10/26/2013 00:14:00 PM) (Source: volmgr) (User: )
Description: Das System konnte den Treiber für das Speicherabbild nicht laden.

Error: (10/26/2013 00:07:31 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "ISCT Always Updated Agent" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (10/26/2013 00:07:22 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SQL Server Browser" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (10/26/2013 00:07:19 PM) (Source: Service Control Manager) (User: )
Description: Dienst "SQL Server VSS Writer" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (10/26/2013 00:07:16 PM) (Source: Service Control Manager) (User: )
Description: Dienst "SQL Server (TEW_SQLEXPRESS)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


Microsoft Office Sessions:
=========================
Error: (07/28/2013 10:02:35 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 45 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (07/18/2013 05:37:37 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (03/06/2013 00:07:38 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 52 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/21/2013 05:03:43 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 00:13:45 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 09:46:31 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 09:20:26 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 49 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2012-12-20 22:14:12.581
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:14:10.454
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:14:10.454
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:43.050
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:43.050
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:28.753
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:26.612
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:26.612
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:05:29.179
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:05:29.179
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 34%
Total physical RAM: 8142.93 MB
Available physical RAM: 5339.57 MB
Total Pagefile: 16284.05 MB
Available Pagefile: 12963.94 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (System) (Fixed) (Total:78.13 GB) (Free:14.43 GB) NTFS
Drive d: (Daten) (Fixed) (Total:931.51 GB) (Free:101.58 GB) NTFS
Drive e: (Software) (Fixed) (Total:160.24 GB) (Free:20.12 GB) NTFS
Drive g: (SolidWorks1) (CDROM) (Total:7.76 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: 5C539950)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=78 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=160 GB) - (Type=OF Extended)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 76AF80D4)
Partition 1: (Not Active) - (Size=932 GB) - (Type=42)

==================== End Of Log ============================



meine hosts datei sieht ja garnicht gut aus :(

edit: drunter steht, dass spybot die eingefügt hat, ist das so ok? spybot ist übrigens nicht mehr installiert

schrauber 01.11.2013 12:25

Ja das ist normal :)

Safe Mode Regfix
Laden uns ausführen, versuch den Safe Mode dann nochmal.

cottec 01.11.2013 14:21

"*SafeMode Repair.reg kann nicht importiert werden: Nicht alle Daten konnten in der Systemregistrierung eingetragen werden. Einige Schlüssel sind vom System oder anderen Prozessen geöffnet"

():-)

schrauber 02.11.2013 11:18

Downloade dir bitte Windows Repair (All In One) von hier.

cottec 02.11.2013 12:34

habe vorher den bei step 1 empfohlene MAMB-Suchlauf gemacht und der hat was gefunden:
Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.11.02.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
cottec :: COTTEC-PC [Administrator]

02.11.2013 12:29:12
MBAM-log-2013-11-02 (12-32-20).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 229179
Laufzeit: 1 Minute(n), 41 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 1
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0J1L2U1C1H1Q0R2X1L1R1P0B1P -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 4
C:\Users\cottec\AppData\Local\Temp\ct2504091 (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\cottec\AppData\Local\Temp\ct3288691 (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\cottec\AppData\Local\Temp\ct3297265 (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\cottec\AppData\Local\Temp\ct3297861 (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.

Infizierte Dateien: 6
C:\Users\cottec\AppData\Local\Temp\ct2504091\ism.exe (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\cottec\AppData\Local\Temp\ct3288691\chromeid.txt (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\cottec\AppData\Local\Temp\ct3288691\setup.ini.txt (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\cottec\AppData\Local\Temp\ct3297265\ism.exe (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\cottec\AppData\Local\Temp\ct3297861\chromeid.txt (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\cottec\AppData\Local\Temp\ct3297861\setup.ini.txt (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.

(Ende)

kann das alles gelöscht werden und liegt da vlt sogar das problem?

schrauber 02.11.2013 19:06

alles löschen :)

cottec 03.11.2013 11:15

soo, beim ersten mal ist der durchlauf hängen geblieben(siehe bild). da ich ne neuere version erwischt habe, habe ich die einstellungen hoffentlich richtig gewählt:
http://img822.imageshack.us/img822/9587/h1bk.jpg

unten abegeschnitten ist das aktivierte Set Windows Services To Default Startup

der abgesicherte geht wieder :dankeschoen:

trotzdem hab ich jetzt folgendes problem:
http://img59.imageshack.us/img59/2039/w88h.jpg

antivir ist aktiviert und akutell, wenn ich auf windows defender eisnchalten klicke, dann öffnet sich der system32 ordner :confused:

schrauber 03.11.2013 17:05

poste bitte ein frisches FRST log.

Downloade dir bitte Farbar Service Scanner Farbar Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.

Poste bitte den Inhalt hier.



cottec 03.11.2013 18:17

wird gemacht ;)


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013
Ran by cottec (administrator) on COTTEC-PC on 03-11-2013 18:13:55
Running from D:\Downloads\Software\FRST
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Microsoft Corporation) C:\ProgramData\SolidWorks Electrical\MSSQL11.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Mentor Graphics Corporation) C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\remotesolverdispatcherservice.exe
(Mentor Graphics Corporation) C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\dispatcher.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(StarWind Software) C:\Program Files (x86)\Alcohol 120\StarWind\StarWindServiceAE.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Andreas Sammann) C:\Program Files (x86)\C2DtoG15\SystoG15Svc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Transaction Software, D 81737 Munich) C:\Programme\BMWgroup\ETKLokal\transbase\tbmux32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe
(Samsung) C:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Samsung) C:\Program Files (x86)\Kies\Kies.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe
(Andreas Sammann) C:\Program Files (x86)\C2DtoG15\C2DtoG15.exe
(Dropbox, Inc.) C:\Users\cottec\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPNetworkCommunicator.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AppWork GmbH) C:\Users\cottec\AppData\Local\JDownloader v2.0\JDownloader2.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7191768 2013-06-27] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-10-18] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKCU\...\Run: [AlcoholAutomount] - C:\Program Files (x86)\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKCU\...\Run: [HP Officejet 6500 E710n-z (NET)] - C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKCU\...\Run: [Miranda Fusion] - C:\Program Files (x86)\MirandaFusion\fusiontools\mfstart.exe [1122241 2012-06-12] (Miranda Fusion Team)
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [506864 2013-03-08] (MSI)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-08] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ControlCenterCount] - C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [872448 2012-03-26] (MSI CO.,LTD.)
HKLM-x32\...\Run: [ControlCenterII] - \BootStartControlCenter.exe
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\C2DtoG15.lnk
ShortcutTarget: C2DtoG15.lnk -> C:\Program Files (x86)\C2DtoG15\C2DtoG15.exe (Andreas Sammann)
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\cottec\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4B157DDCF427CE01
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.111.111.1

FireFox:
========
FF ProfilePath: C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default
FF user.js: detected! => C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\user.js
FF Homepage: hxxp://www.google.de/
FF NetworkProxy: "http", "200.65.127.163"
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: GFACE Experience Plugin - C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\Extensions\cryenginebrowserplugin@crytek.com
FF Extension: Adblock Plus - C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll No File
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (Google Docs) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-08] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-08] (Avira Operations GmbH & Co. KG)
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [520416 2013-10-15] (Futuremark)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [146984 2012-07-24] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161264 2013-02-20] (MSI)
R2 MSSQL$TEW_SQLEXPRESS; C:\ProgramData\SolidWorks Electrical\MSSQL11.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe [191064 2012-02-11] (Microsoft Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-18] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-31] ()
R2 RemoteSolverDispatcher; C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\remotesolverdispatcherservice.exe [235656 2013-09-20] (Mentor Graphics Corporation)
S4 SQLAgent$TEW_SQLEXPRESS; C:\ProgramData\SolidWorks Electrical\MSSQL11.TEW_SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [597080 2012-02-11] (Microsoft Corporation)
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
R2 SystoG15Svc; C:\Program Files (x86)\C2DtoG15\SystoG15Svc.exe [64000 2012-12-24] (Andreas Sammann)
R2 Transbase; C:\Programme\BMWgroup\ETKLokal\transbase\tbmux32.exe [385024 2004-08-05] (Transaction Software, D 81737 Munich)

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-08] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-08] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-09-08] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-09-08] (DT Soft Ltd)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] ()
S3 epmntdrv; C:\Windows\SysWow64\epmntdrv.sys [13896 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\SysWow64\EuGdiDrv.sys [9160 2013-03-07] ()
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [27456 2012-07-09] (Intel Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [20968 2012-07-24] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [19944 2012-07-24] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46016 2012-07-24] ()
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [14136 2010-10-22] (MSI)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7758v190\NTIOLib_X64.sys [11888 2011-01-06] (MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [13368 2012-11-09] (MSI)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation)
S4 RsFx0200; C:\Windows\System32\DRIVERS\RsFx0200.sys [334936 2012-02-11] (Microsoft Corporation)
S3 ssudobex; C:\Windows\System32\DRIVERS\ssudobex.sys [204568 2013-08-20] (DEVGURU Co., LTD.(www.devguru.co.kr))
R3 WinRing0_1_2_0; C:\Program Files (x86)\C2DtoG15\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-11-03] ()
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [x]

========================== Drivers MD5 =======================

C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit
C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit
C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit
C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit
C:\Windows\system32\drivers\afd.sys 314C17917AC8523EC77A710215012A65
C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit
C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49
C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit
C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048
C:\Windows\system32\drivers\appid.sys ==> MD5 is legit
C:\Windows\system32\drivers\arc.sys ==> MD5 is legit
C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
C:\Windows\system32\drivers\atapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\avgntflt.sys 0D5C96FD25D6455D97A5C4D7706DFAB1
C:\Windows\System32\DRIVERS\avipbb.sys E26B3C8E9C3DDE047B32C5719955D715
C:\Windows\System32\DRIVERS\avkmgr.sys 490FA25161BF3E51993EB724ECF0ACEB
C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit
C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit
C:\Windows\System32\CLFS.sys ==> MD5 is legit
C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit
C:\Windows\System32\Drivers\cng.sys AAFCB52FE0037207FB6FBEA070D25EFE
C:\Windows\system32\drivers\compbatt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\csc.sys ==> MD5 is legit
C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ssudbus.sys E428DFFA96FAD07D8CA3C9082563A225
C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
C:\Windows\System32\drivers\disk.sys ==> MD5 is legit
C:\Windows\system32\drivers\dmvsc.sys 5DB085A8A6600BE6401F2B24EECB5415
C:\Windows\System32\drivers\drmkaud.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\dtsoftbus01.sys 46571ED73AE84469DCA53081D33CF3C8
C:\Windows\System32\drivers\dxgkrnl.sys 88612F1CE3BF42256913BF6E61C70D52
C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit
C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit
C:\Windows\system32\epmntdrv.sys 6106653B08F4F72EEAA7F099E7C408A4
C:\Windows\SysWow64\epmntdrv.sys F17F09BA097D8EC3CE2084FA97886B85
C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit
C:\Windows\system32\EuGdiDrv.sys 991C04A31777ED77CB92A4F96F14C2E2
C:\Windows\SysWow64\EuGdiDrv.sys F1DE3EEF501DDA7DDF99F2EDF0C5540E
C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit
C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit
C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit
C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B
C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0
C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit
C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A
C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit
C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit
C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit
C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit
C:\Windows\System32\drivers\iaStorA.sys 0FE66A51D81A25AACEAAE4C26308121D
C:\Windows\System32\drivers\iaStorF.sys A0EA86734FD36A1A047CA24EC6528CBA
C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366
C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ikbevent.sys F2C300C2E56F016B485B88080CD7D2FE
C:\Windows\System32\DRIVERS\imsevent.sys C1A5061D6E5C328AE030C34B8AAC5C5C
C:\Windows\System32\drivers\RTKVHD64.sys E551BB77E7D436380139977124BDFF62
C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit
C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ISCTD64.sys 5AB18D8055A4280C0F377A6262F3157E
C:\Windows\System32\DRIVERS\iusb3hcs.sys 75779002A6084C1A011E195E421A9C75
C:\Windows\System32\DRIVERS\iusb3hub.sys F390B641FE6115F536B8B78AA71B8814
C:\Windows\System32\DRIVERS\iusb3xhc.sys 653B86AA174FF7661D00EE1E524B234F
C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\ksecdd.sys 97A7070AEA4C058B6418519E869A63B4
C:\Windows\System32\Drivers\ksecpkg.sys 7EFB9333E4ECCE6AE4AE9D777D9E553E
C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit
C:\Windows\System32\drivers\LGBusEnum.sys FA529FB35694C24BF98A9EF67C1CD9D0
C:\Windows\System32\DRIVERS\LGSHidFilt.Sys 94AF1384A67B9FCF5651E70BC9D4C526
C:\Windows\System32\drivers\LGVirHid.sys 94B29CE153765E768F004FB3440BE2B0
C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit
C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MBfilt64.sys 8FF2D95CBA49B405C5DE27039FF0BF35
C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit
C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\HECIx64.sys 772A1DEEDFDBC244183B5C805D1B7D85
C:\Windows\System32\drivers\modem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit
C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\mrxdav.sys 1A4F75E63C9FB84B85DFFC6B63FD5404
C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC
C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163
C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C
C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit
C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88
C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit
C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Ntfs.sys B98F8C6E31CD07B2E6F71F7F648E38C0
C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys 23CF3DA010497EB2BF39A5C5A57E437C
C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys 1B32C54B95121AB1683C7B83B2DB4B96
C:\Program Files (x86)\Setup Files\Ms7758v190\NTIOLib_X64.sys C02F70960FA934B8DEFA16A03D7F6556
C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys 2DA209DDE8188076A9579BD256DC90D0
C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
C:\Windows\System32\drivers\nvhda64v.sys 554964B900AE2954B8B589B6287034AC
C:\Windows\System32\DRIVERS\nvlddmkm.sys E71E299FF15390E585BACF2C18F55078
C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD
C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A
C:\Windows\System32\drivers\nvvad64v.sys 31B16657118E439B77B0A527F7EA66CB
C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit
C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\parport.sys ==> MD5 is legit
C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C
C:\Windows\System32\drivers\pci.sys ==> MD5 is legit
C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit
C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit
C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
C:\Windows\system32\drivers\processr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpdr.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34
C:\Windows\System32\Drivers\RDPWD.sys E61608AA35E98999AF9AAEEEA6114B0A
C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\revoflt.sys 9C3AC71A9934B884FAC567A8807E9C4D
C:\Windows\System32\DRIVERS\RsFx0200.sys 5AA85332CB1694871B2F0704E0FC9113
C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\Rt64win7.sys 130DD683DCC902F47A4AC35201D07E2F
C:\Windows\system32\drivers\vms3cap.sys ==> MD5 is legit
C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serenum.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serial.sys ==> MD5 is legit
C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit
C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit
C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit
C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
C:\Windows\SysWow64\speedfan.sys 0FFE35F0B0CD5A324BBE22F02569AE3B
C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B
C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28
C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3
C:\Windows\System32\DRIVERS\ssudmdm.sys AAF6F247F1DC370C593B4430974EAD9C
C:\Windows\System32\DRIVERS\ssudobex.sys 9A8D59146B6FC187140179D0F05EB07E
C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit
C:\Windows\system32\drivers\serscan.sys DECACB6921DED1A38642642685D77DAC
C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 is legit
C:\Windows\system32\drivers\storvsc.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit
C:\Windows\System32\drivers\tcpip.sys 40AF23633D197905F03AB5628C558C51
C:\Windows\System32\DRIVERS\tcpip.sys 40AF23633D197905F03AB5628C558C51
C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC
C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8
C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tssecsrv.sys 4CE278FC9671BA81A138D70823FCAA09
C:\Windows\System32\drivers\tsusbflt.sys 17C6B51CBCCDED95B3CC14E22791F85E
C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07
C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\usbccgp.sys ACCEA6BC68D0C9A78EB97EE159028B4E
C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31
C:\Windows\system32\drivers\usbehci.sys 311C1DD1088E55BEAE15954D17F50646
C:\Windows\System32\DRIVERS\usbhub.sys 280E90CBF4B2DDD169F0728CB44D726F
C:\Windows\system32\drivers\usbohci.sys 9406D801042FAF859CF81B2C886413DC
C:\Windows\system32\drivers\usbprint.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6
C:\Windows\system32\drivers\usbuhci.sys A83D0EC9AE4C31704442099D40BA2471
C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit
C:\Windows\system32\drivers\vmbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit
C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit
C:\Windows\System32\drivers\vwifibus.sys ==> MD5 is legit
C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\system32\drivers\wd.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8
C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\SysWow64\drivers\wimmount.sys ==> MD5 is legit
C:\Program Files (x86)\C2DtoG15\WinRing0x64.sys 0C0195C48B6B8582FA6F6373032118DA
C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D
C:\Windows\System32\DRIVERS\wmiacpi.sys ==> MD5 is legit
C:\Windows\System32\drivers\WPRO_41_2001.sys 7CA09731EB7FC99B910C7F239E57720F
C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\WSDPrint.sys 8D918B1DB190A4D9B1753A66FA8C96E8
C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F
C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-03 16:12 - 2013-11-03 16:12 - 104760586 _____ C:\Windows\SysWOW64\膰傁C
2013-11-03 11:06 - 2013-11-03 11:06 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-11-03 10:43 - 2013-11-03 11:00 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-11-03 10:38 - 2013-11-03 10:38 - 00000207 _____ C:\Windows\tweaking.com-regbackup-COTTEC-PC-Microsoft-Windows-7-Professional-(64-bit).dat
2013-11-03 10:38 - 2013-11-03 10:38 - 00000000 ____D C:\RegBackup
2013-11-03 10:33 - 2013-11-03 10:33 - 00001996 _____ C:\Users\cottec\Desktop\Repair_Windows.exe - Verknüpfung.lnk
2013-11-01 18:29 - 2013-11-02 12:47 - 00000022 _____ C:\Windows\GPU-Z.INI
2013-11-01 18:19 - 2013-11-01 18:16 - 00002073 _____ C:\Users\cottec\Desktop\3DMark 11.lnk
2013-11-01 18:18 - 2013-11-01 18:29 - 00000000 ____D C:\Users\cottec\Documents\3DMark 11
2013-11-01 18:18 - 2013-11-01 18:18 - 00000000 ____D C:\Users\cottec\AppData\Local\IsolatedStorage
2013-11-01 18:18 - 2013-11-01 18:18 - 00000000 ____D C:\Users\cottec\AppData\Local\Futuremark
2013-11-01 18:16 - 2013-11-01 18:19 - 00000000 ____D C:\Program Files (x86)\Futuremark
2013-11-01 18:15 - 2013-11-01 18:16 - 00002049 _____ C:\Users\Public\Desktop\3DMark 11.lnk
2013-11-01 18:14 - 2013-11-01 18:14 - 00000000 ____D C:\Program Files\Futuremark
2013-11-01 17:57 - 2013-11-01 17:57 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-11-01 17:56 - 2013-10-23 11:30 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-01 17:56 - 2013-10-23 11:30 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-11-01 17:56 - 2013-10-23 11:30 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-11-01 17:56 - 2013-06-16 13:38 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2013-11-01 17:56 - 2013-06-16 13:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2013-11-01 17:56 - 2013-01-29 09:35 - 01510176 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco64.dll
2013-11-01 16:44 - 2013-10-18 02:36 - 01063200 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-11-01 16:44 - 2013-10-18 02:36 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-11-01 16:43 - 2013-11-01 16:43 - 00000000 ____D C:\Users\cottec\AppData\Local\NVIDIA
2013-11-01 16:43 - 2013-09-28 00:01 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-11-01 16:43 - 2013-09-28 00:01 - 00028960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-11-01 16:42 - 2013-09-28 00:01 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2013-11-01 14:19 - 2007-02-19 00:21 - 00027054 _____ C:\Users\cottec\Desktop\SafeMode Repair.reg
2013-10-29 19:32 - 2013-10-30 20:12 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2013-10-29 19:32 - 2013-10-29 19:32 - 00001013 _____ C:\Users\UpdatusUser\Desktop\SpeedFan.lnk
2013-10-29 19:32 - 2013-10-29 19:32 - 00001013 _____ C:\Users\cottec\Desktop\SpeedFan.lnk
2013-10-29 19:32 - 2013-10-29 19:32 - 00000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2013-10-29 19:32 - 2013-10-29 19:32 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
2013-10-29 19:32 - 2013-10-29 19:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-28 17:55 - 2013-10-28 17:55 - 00009328 _____ C:\Users\cottec\Desktop\s3_insel-yf0f1pmqzdud.dlc
2013-10-27 20:05 - 2013-10-27 20:05 - 00290112 _____ C:\Windows\msxml4-KB954430-enu.LOG
2013-10-27 20:05 - 2013-10-27 20:05 - 00284430 _____ C:\Windows\msxml4-KB973688-enu.LOG
2013-10-27 20:05 - 2013-10-27 20:05 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-10-27 20:05 - 2013-10-27 20:05 - 00000000 ____D C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2013-10-26 12:44 - 2013-10-26 12:44 - 00000000 ____D C:\Users\cottec\Desktop\Solidworks
2013-10-26 12:35 - 2013-10-26 12:35 - 00002094 _____ C:\Users\cottec\Desktop\JDownloader 2.lnk
2013-10-26 12:35 - 2013-10-26 12:35 - 00001535 _____ C:\Users\cottec\Desktop\GUI_9KW.lnk
2013-10-26 12:35 - 2013-10-26 12:35 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader
2013-10-26 12:34 - 2013-11-03 17:06 - 00000000 ____D C:\Users\cottec\AppData\Local\JDownloader v2.0
2013-10-26 12:32 - 2013-10-26 12:32 - 00000000 _____ C:\Users\cottec\AppData\Local\Temptable.xml
2013-10-26 12:22 - 2013-10-26 12:22 - 00000000 ____D C:\Users\cottec\AppData\Roaming\SolidWorks 2014
2013-10-26 12:15 - 2013-10-26 12:15 - 00000000 ____D C:\Users\cottec\AppData\Local\TempSWSicherungsverzeichnis
2013-10-26 12:14 - 2013-10-26 12:14 - 00000000 ____D C:\Users\cottec\AppData\Local\SolidWorks
2013-10-26 12:11 - 2013-10-26 12:11 - 00000000 ____D C:\ProgramData\Simpoe
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\Users\cottec\Documents\SolidWorksComposer
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\ProgramData\SolidWorks Flow Simulation
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\ProgramData\COSMOS Applications
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 ____D C:\Users\cottec\AppData\Roaming\help_images_otherUI
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 ____D C:\Program Files (x86)\SolidWorks Corp
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 _____ C:\Windows\eDrawingOfficeAutomator.INI
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\Documents\SolidWorks Visual Studio Tools for Applications
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\AppData\Roaming\DassaultSystemes
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\AppData\Local\DassaultSystemes
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\ProgramData\DassaultSystemes
2013-10-26 11:49 - 2013-10-26 12:11 - 00000000 ____D C:\Program Files\SolidWorks Corp
2013-10-26 11:49 - 2013-10-26 12:07 - 00000000 ____D C:\Program Files\Common Files\SolidWorks Shared
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\ProgramData\SolidWorks
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 8
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
2013-10-26 11:48 - 2013-10-26 11:48 - 00000000 ____D C:\Windows\system32\RsFx
2013-10-26 11:48 - 2013-10-26 11:48 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0
2013-10-26 11:48 - 2012-02-11 09:03 - 00082520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perf-MSSQL$TEW_SQLEXPRESS-sqlctr11.0.2100.60.dll
2013-10-26 11:48 - 2012-02-11 09:02 - 00045656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perf-MSSQL11.TEW_SQLEXPRESS-sqlagtctr.dll
2013-10-26 11:48 - 2012-02-11 07:46 - 00180312 _____ (Microsoft Corporation) C:\Windows\system32\hadrres.dll
2013-10-26 11:48 - 2012-02-11 07:46 - 00082520 _____ (Microsoft Corporation) C:\Windows\system32\fssres.dll
2013-10-26 11:48 - 2012-02-11 07:44 - 00095832 _____ (Microsoft Corporation) C:\Windows\system32\perf-MSSQL$TEW_SQLEXPRESS-sqlctr11.0.2100.60.dll
2013-10-26 11:48 - 2012-02-11 07:44 - 00054360 _____ (Microsoft Corporation) C:\Windows\system32\perf-MSSQL11.TEW_SQLEXPRESS-sqlagtctr.dll
2013-10-26 11:47 - 2013-10-26 11:49 - 00000000 ____D C:\Windows\SysWOW64\1033
2013-10-26 11:47 - 2013-10-26 11:49 - 00000000 ____D C:\Windows\system32\1033
2013-10-26 11:47 - 2013-10-26 11:47 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2013-10-26 11:46 - 2013-10-26 12:09 - 00000000 ____D C:\ProgramData\SolidWorks Electrical
2013-10-26 11:46 - 2013-10-26 11:47 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Users\cottec\Documents\Visual Studio 2005
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\ProgramData\FLEXnet
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\ProgramData\Apple
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files\Bonjour
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files (x86)\Bonjour
2013-10-26 11:45 - 2013-10-26 12:03 - 00000000 ____D C:\SolidWorks Data
2013-10-26 11:39 - 2013-10-26 12:22 - 00000000 ____D C:\Users\cottec\AppData\Roaming\SolidWorks
2013-10-26 11:39 - 2013-10-26 11:45 - 00000000 ____D C:\Windows\SolidWorks
2013-10-25 20:52 - 2013-10-25 20:52 - 00001164 _____ C:\Users\Public\Desktop\CLICKBIOSII.lnk
2013-10-25 20:50 - 2013-10-25 20:50 - 00001188 _____ C:\Users\Public\Desktop\ControlCenter.lnk
2013-10-25 20:49 - 2013-10-25 20:50 - 00000000 ___HD C:\ControlCenterCount
2013-10-25 16:49 - 2013-10-25 16:49 - 00000000 ____D C:\Users\cottec\AppData\Roaming\NVIDIA
2013-10-25 16:48 - 2013-11-01 17:57 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-10-25 16:48 - 2013-10-25 16:48 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten
2013-10-25 16:48 - 2013-10-23 11:30 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2013-10-25 16:48 - 2013-10-23 11:30 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2013-10-25 16:48 - 2013-10-23 09:20 - 06669600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-10-25 16:48 - 2013-10-23 09:20 - 03489568 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-10-25 16:48 - 2013-10-23 09:20 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2013-10-25 16:48 - 2013-10-23 09:20 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-10-25 16:48 - 2013-10-23 09:20 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-10-25 16:48 - 2013-10-23 09:20 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-10-25 16:48 - 2013-09-08 20:34 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-10-25 16:48 - 2013-09-08 20:34 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-10-25 16:48 - 2013-09-08 20:34 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Microsoft Help
2013-10-25 16:47 - 2013-11-01 16:44 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-10-25 16:47 - 2013-10-23 11:30 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-10-25 16:47 - 2013-10-23 11:30 - 18286416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-10-25 16:47 - 2013-10-23 11:30 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-10-25 16:47 - 2013-10-23 11:30 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-10-25 16:47 - 2013-10-23 11:30 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-10-25 16:47 - 2013-10-23 11:30 - 02695200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-10-25 16:47 - 2013-10-23 11:30 - 01435504 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-10-25 16:47 - 2013-10-23 11:30 - 00023287 _____ C:\Windows\system32\nvinfo.pb
2013-10-25 16:47 - 2013-03-15 06:53 - 01807136 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6431422.dll
2013-10-25 16:47 - 2013-03-15 06:53 - 01510176 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6431422.dll
2013-10-25 16:47 - 2012-12-18 09:31 - 01510328 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2013-10-24 22:07 - 2013-10-25 16:07 - 102975063 _____ C:\Windows\SysWOW64\丘斆“
2013-10-24 18:14 - 2013-11-03 18:14 - 00000292 _____ C:\Windows\Tasks\FoxTab.job
2013-10-24 18:14 - 2013-10-24 18:14 - 00003236 _____ C:\Windows\System32\Tasks\FoxTab
2013-10-24 18:14 - 2013-10-24 18:14 - 00000000 ____D C:\Users\cottec\AppData\Roaming\FoxTab
2013-10-24 18:09 - 2013-10-28 17:56 - 00000000 ____D C:\Users\cottec\AppData\Local\GUI_9KW
2013-10-24 18:06 - 2013-10-24 18:06 - 00000000 ____D C:\Users\cottec\.java
2013-10-24 17:54 - 2013-10-26 12:11 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-10-24 17:54 - 2013-10-24 17:54 - 00000000 ____D C:\Program Files (x86)\Foxtab
2013-10-24 16:19 - 2013-10-24 16:19 - 00000000 ____D C:\ProgramData\Oracle
2013-10-24 16:18 - 2013-10-24 16:18 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-23 03:02 - 2013-10-23 03:02 - 00589600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-10-22 16:00 - 2013-11-01 17:57 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-10-22 14:38 - 2013-10-22 14:38 - 102329055 _____ C:\Windows\SysWOW64\퟊
2013-10-17 16:44 - 2013-10-17 16:44 - 101544623 _____ C:\Windows\SysWOW64\葙ꇷM
2013-10-16 16:07 - 2013-10-16 16:07 - 101406750 _____ C:\Windows\SysWOW64\핍柮Œ
2013-10-15 17:27 - 2013-10-15 17:27 - 00000000 ____D C:\Users\cottec\AppData\Roaming\wargaming.net
2013-10-15 17:01 - 2013-10-15 17:01 - 101148298 _____ C:\Windows\SysWOW64\梋녒„
2013-10-14 20:02 - 2013-10-14 20:02 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-10-13 16:13 - 2013-10-13 16:14 - 00000000 ____D C:\Users\cottec\Documents\Battlefield 4 Beta
2013-10-12 14:01 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-12 14:01 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-11 22:39 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-11 22:39 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-11 22:39 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-11 22:39 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-11 22:39 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-11 22:39 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-11 22:39 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-11 22:39 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-11 22:39 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-11 22:39 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-11 22:39 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-11 22:39 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-11 20:03 - 2013-10-11 20:03 - 00000000 ____D C:\Program Files\DivX
2013-10-11 20:02 - 2013-10-11 20:03 - 00000000 ____D C:\Program Files (x86)\DivX
2013-10-11 20:01 - 2013-10-11 20:03 - 00000000 ____D C:\ProgramData\DivX
2013-10-11 18:51 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-11 18:51 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-11 18:51 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-11 18:51 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-11 18:51 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-11 18:51 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-11 18:51 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-11 18:51 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-11 18:51 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-11 18:51 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-11 18:51 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-11 18:51 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-11 18:51 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-11 18:51 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-11 18:51 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-11 18:51 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-11 18:51 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-11 18:51 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-11 18:51 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-11 18:51 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-11 18:51 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-11 18:51 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-11 18:51 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 18:51 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 18:51 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-11 18:51 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-11 18:51 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-11 18:51 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-11 18:51 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-11 18:51 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-11 18:51 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-11 18:51 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-11 18:51 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-11 18:51 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-11 18:51 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-11 18:51 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-11 18:51 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-11 18:51 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-11 18:51 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-11 18:51 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-11 18:51 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-11 18:51 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-11 18:51 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-11 18:51 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-11 18:51 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-10 17:23 - 2013-10-10 17:23 - 100305510 _____ C:\Windows\SysWOW64\㳈ˁu
2013-10-07 17:15 - 2013-10-07 17:15 - 00003074 _____ C:\Windows\System32\Tasks\ScanToPCActivationApp.exe_{AD063CB6-193B-4D04-BB14-1AF681BF23C6}
2013-10-07 17:12 - 2013-10-07 17:12 - 00000000 ____D C:\Users\cottec\Documents\Fax
2013-10-07 16:44 - 2013-10-07 16:44 - 99717279 _____ C:\Windows\SysWOW64\꘽ൡ7
2013-10-06 19:46 - 2013-10-06 19:46 - 99477982 _____ C:\Windows\SysWOW64\⠙ᚅ‘
2013-10-06 13:46 - 2013-10-06 13:46 - 99463930 _____ C:\Windows\SysWOW64\乻¤
2013-10-04 18:28 - 2013-10-04 18:28 - 00000000 ____D C:\Users\Public\Documents\CrashDump

==================== One Month Modified Files and Folders =======

2013-11-03 18:14 - 2013-10-24 18:14 - 00000292 _____ C:\Windows\Tasks\FoxTab.job
2013-11-03 18:04 - 2013-02-17 15:59 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-03 17:29 - 2013-02-11 19:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-03 17:06 - 2013-10-26 12:34 - 00000000 ____D C:\Users\cottec\AppData\Local\JDownloader v2.0
2013-11-03 16:12 - 2013-11-03 16:12 - 104760586 _____ C:\Windows\SysWOW64\膰傁C
2013-11-03 12:19 - 2013-09-08 20:27 - 01731835 _____ C:\Windows\WindowsUpdate.log
2013-11-03 11:33 - 2009-07-14 05:45 - 00018496 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-03 11:33 - 2009-07-14 05:45 - 00018496 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-03 11:10 - 2011-04-12 08:43 - 00770770 _____ C:\Windows\system32\perfh007.dat
2013-11-03 11:10 - 2011-04-12 08:43 - 00179534 _____ C:\Windows\system32\perfc007.dat
2013-11-03 11:10 - 2009-07-14 06:13 - 01865344 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-03 11:08 - 2013-08-11 12:22 - 00000000 ____D C:\Windows\pss
2013-11-03 11:06 - 2013-11-03 11:06 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-11-03 11:06 - 2013-09-08 20:27 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-03 11:06 - 2013-02-17 15:59 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-03 11:06 - 2013-01-27 18:36 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Dropbox
2013-11-03 11:06 - 2012-12-24 00:51 - 00000000 ____D C:\Program Files (x86)\C2DtoG15
2013-11-03 11:06 - 2012-12-23 18:21 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2013-11-03 11:06 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-03 11:06 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-03 11:06 - 2009-07-14 05:51 - 10973418 _____ C:\Windows\setupact.log
2013-11-03 11:05 - 2010-11-21 04:47 - 00058806 _____ C:\Windows\PFRO.log
2013-11-03 11:02 - 2011-04-12 08:54 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-03 11:01 - 2009-07-14 05:45 - 00447120 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-03 11:00 - 2013-11-03 10:43 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-11-03 10:59 - 2009-07-14 03:34 - 00000514 _____ C:\Windows\win.ini
2013-11-03 10:57 - 2013-09-08 20:40 - 00122208 _____ C:\Users\cottec\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-03 10:38 - 2013-11-03 10:38 - 00000207 _____ C:\Windows\tweaking.com-regbackup-COTTEC-PC-Microsoft-Windows-7-Professional-(64-bit).dat
2013-11-03 10:38 - 2013-11-03 10:38 - 00000000 ____D C:\RegBackup
2013-11-03 10:33 - 2013-11-03 10:33 - 00001996 _____ C:\Users\cottec\Desktop\Repair_Windows.exe - Verknüpfung.lnk
2013-11-02 15:16 - 2012-12-22 23:49 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-11-02 12:47 - 2013-11-01 18:29 - 00000022 _____ C:\Windows\GPU-Z.INI
2013-11-01 18:29 - 2013-11-01 18:18 - 00000000 ____D C:\Users\cottec\Documents\3DMark 11
2013-11-01 18:19 - 2013-11-01 18:16 - 00000000 ____D C:\Program Files (x86)\Futuremark
2013-11-01 18:18 - 2013-11-01 18:18 - 00000000 ____D C:\Users\cottec\AppData\Local\IsolatedStorage
2013-11-01 18:18 - 2013-11-01 18:18 - 00000000 ____D C:\Users\cottec\AppData\Local\Futuremark
2013-11-01 18:16 - 2013-11-01 18:19 - 00002073 _____ C:\Users\cottec\Desktop\3DMark 11.lnk
2013-11-01 18:16 - 2013-11-01 18:15 - 00002049 _____ C:\Users\Public\Desktop\3DMark 11.lnk
2013-11-01 18:16 - 2013-08-20 18:37 - 00091956 _____ C:\Windows\DirectX.log
2013-11-01 18:16 - 2012-12-20 21:10 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-11-01 18:14 - 2013-11-01 18:14 - 00000000 ____D C:\Program Files\Futuremark
2013-11-01 17:57 - 2013-11-01 17:57 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-11-01 17:57 - 2013-10-25 16:48 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-11-01 17:57 - 2013-10-22 16:00 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-11-01 17:14 - 2012-12-22 23:49 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-11-01 16:44 - 2013-10-25 16:47 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-11-01 16:43 - 2013-11-01 16:43 - 00000000 ____D C:\Users\cottec\AppData\Local\NVIDIA
2013-10-31 22:05 - 2012-12-26 14:22 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-10-31 22:05 - 2012-12-22 23:49 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-10-30 20:12 - 2013-10-29 19:32 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2013-10-29 19:36 - 2012-12-20 21:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-29 19:32 - 2013-10-29 19:32 - 00001013 _____ C:\Users\UpdatusUser\Desktop\SpeedFan.lnk
2013-10-29 19:32 - 2013-10-29 19:32 - 00001013 _____ C:\Users\cottec\Desktop\SpeedFan.lnk
2013-10-29 19:32 - 2013-10-29 19:32 - 00000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2013-10-29 19:32 - 2013-10-29 19:32 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
2013-10-29 19:32 - 2013-10-29 19:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-28 17:56 - 2013-10-24 18:09 - 00000000 ____D C:\Users\cottec\AppData\Local\GUI_9KW
2013-10-28 17:55 - 2013-10-28 17:55 - 00009328 _____ C:\Users\cottec\Desktop\s3_insel-yf0f1pmqzdud.dlc
2013-10-27 20:05 - 2013-10-27 20:05 - 00290112 _____ C:\Windows\msxml4-KB954430-enu.LOG
2013-10-27 20:05 - 2013-10-27 20:05 - 00284430 _____ C:\Windows\msxml4-KB973688-enu.LOG
2013-10-27 20:05 - 2013-10-27 20:05 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-10-27 20:05 - 2013-10-27 20:05 - 00000000 ____D C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2013-10-26 12:44 - 2013-10-26 12:44 - 00000000 ____D C:\Users\cottec\Desktop\Solidworks
2013-10-26 12:35 - 2013-10-26 12:35 - 00002094 _____ C:\Users\cottec\Desktop\JDownloader 2.lnk
2013-10-26 12:35 - 2013-10-26 12:35 - 00001535 _____ C:\Users\cottec\Desktop\GUI_9KW.lnk
2013-10-26 12:35 - 2013-10-26 12:35 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader
2013-10-26 12:32 - 2013-10-26 12:32 - 00000000 _____ C:\Users\cottec\AppData\Local\Temptable.xml
2013-10-26 12:22 - 2013-10-26 12:22 - 00000000 ____D C:\Users\cottec\AppData\Roaming\SolidWorks 2014
2013-10-26 12:22 - 2013-10-26 11:39 - 00000000 ____D C:\Users\cottec\AppData\Roaming\SolidWorks
2013-10-26 12:15 - 2013-10-26 12:15 - 00000000 ____D C:\Users\cottec\AppData\Local\TempSWSicherungsverzeichnis
2013-10-26 12:14 - 2013-10-26 12:14 - 00000000 ____D C:\Users\cottec\AppData\Local\SolidWorks
2013-10-26 12:11 - 2013-10-26 12:11 - 00000000 ____D C:\ProgramData\Simpoe
2013-10-26 12:11 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\SolidWorks Corp
2013-10-26 12:11 - 2013-10-24 17:54 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\Users\cottec\Documents\SolidWorksComposer
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\ProgramData\SolidWorks Flow Simulation
2013-10-26 12:10 - 2013-10-26 12:10 - 00000000 ____D C:\ProgramData\COSMOS Applications
2013-10-26 12:09 - 2013-10-26 11:46 - 00000000 ____D C:\ProgramData\SolidWorks Electrical
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 ____D C:\Users\cottec\AppData\Roaming\help_images_otherUI
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 ____D C:\Program Files (x86)\SolidWorks Corp
2013-10-26 12:07 - 2013-10-26 12:07 - 00000000 _____ C:\Windows\eDrawingOfficeAutomator.INI
2013-10-26 12:07 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\Common Files\SolidWorks Shared
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\Documents\SolidWorks Visual Studio Tools for Applications
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\AppData\Roaming\DassaultSystemes
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\AppData\Local\DassaultSystemes
2013-10-26 12:05 - 2013-10-26 12:05 - 00000000 ____D C:\ProgramData\DassaultSystemes
2013-10-26 12:03 - 2013-10-26 11:45 - 00000000 ____D C:\SolidWorks Data
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\ProgramData\SolidWorks
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 8
2013-10-26 11:49 - 2013-10-26 11:49 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
2013-10-26 11:49 - 2013-10-26 11:47 - 00000000 ____D C:\Windows\SysWOW64\1033
2013-10-26 11:49 - 2013-10-26 11:47 - 00000000 ____D C:\Windows\system32\1033
2013-10-26 11:49 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-10-26 11:48 - 2013-10-26 11:48 - 00000000 ____D C:\Windows\system32\RsFx
2013-10-26 11:48 - 2013-10-26 11:48 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0
2013-10-26 11:47 - 2013-10-26 11:47 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2013-10-26 11:47 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Users\cottec\Documents\Visual Studio 2005
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\ProgramData\FLEXnet
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\ProgramData\Apple
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files\Bonjour
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-10-26 11:46 - 2013-10-26 11:46 - 00000000 ____D C:\Program Files (x86)\Bonjour
2013-10-26 11:46 - 2012-12-23 13:32 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-26 11:46 - 2012-12-23 13:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2013-10-26 11:46 - 2012-12-23 13:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-10-26 11:45 - 2013-10-26 11:39 - 00000000 ____D C:\Windows\SolidWorks
2013-10-25 20:52 - 2013-10-25 20:52 - 00001164 _____ C:\Users\Public\Desktop\CLICKBIOSII.lnk
2013-10-25 20:50 - 2013-10-25 20:50 - 00001188 _____ C:\Users\Public\Desktop\ControlCenter.lnk
2013-10-25 20:50 - 2013-10-25 20:49 - 00000000 ___HD C:\ControlCenterCount
2013-10-25 16:49 - 2013-10-25 16:49 - 00000000 ____D C:\Users\cottec\AppData\Roaming\NVIDIA
2013-10-25 16:48 - 2013-10-25 16:48 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten
2013-10-25 16:48 - 2013-10-25 16:48 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten
2013-10-25 16:48 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Help
2013-10-25 16:07 - 2013-10-24 22:07 - 102975063 _____ C:\Windows\SysWOW64\丘斆“
2013-10-24 18:14 - 2013-10-24 18:14 - 00003236 _____ C:\Windows\System32\Tasks\FoxTab
2013-10-24 18:14 - 2013-10-24 18:14 - 00000000 ____D C:\Users\cottec\AppData\Roaming\FoxTab
2013-10-24 18:06 - 2013-10-24 18:06 - 00000000 ____D C:\Users\cottec\.java
2013-10-24 18:06 - 2013-09-08 20:28 - 00000000 ____D C:\Users\cottec
2013-10-24 17:54 - 2013-10-24 17:54 - 00000000 ____D C:\Program Files (x86)\Foxtab
2013-10-24 16:19 - 2013-10-24 16:19 - 00000000 ____D C:\ProgramData\Oracle
2013-10-24 16:18 - 2013-10-24 16:18 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-24 16:18 - 2013-03-07 10:45 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-23 11:30 - 2013-11-01 17:56 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-10-23 11:30 - 2013-11-01 17:56 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-10-23 11:30 - 2013-11-01 17:56 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-10-23 11:30 - 2013-10-25 16:48 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2013-10-23 11:30 - 2013-10-25 16:48 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2013-10-23 11:30 - 2013-10-25 16:47 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-10-23 11:30 - 2013-10-25 16:47 - 18286416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-10-23 11:30 - 2013-10-25 16:47 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-10-23 11:30 - 2013-10-25 16:47 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-10-23 11:30 - 2013-10-25 16:47 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-10-23 11:30 - 2013-10-25 16:47 - 02695200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-10-23 11:30 - 2013-10-25 16:47 - 01435504 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-10-23 11:30 - 2013-10-25 16:47 - 00023287 _____ C:\Windows\system32\nvinfo.pb
2013-10-23 09:20 - 2013-10-25 16:48 - 06669600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-10-23 09:20 - 2013-10-25 16:48 - 03489568 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-10-23 09:20 - 2013-10-25 16:48 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2013-10-23 09:20 - 2013-10-25 16:48 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-10-23 09:20 - 2013-10-25 16:48 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-10-23 09:20 - 2013-10-25 16:48 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-10-23 09:20 - 2013-09-08 20:27 - 03426956 _____ C:\Windows\system32\nvcoproc.bin
2013-10-23 03:02 - 2013-10-23 03:02 - 00589600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-10-22 14:38 - 2013-10-22 14:38 - 102329055 _____ C:\Windows\SysWOW64\퟊
2013-10-18 02:36 - 2013-11-01 16:44 - 01063200 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-10-18 02:36 - 2013-11-01 16:44 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-10-17 16:44 - 2013-10-17 16:44 - 101544623 _____ C:\Windows\SysWOW64\葙ꇷM
2013-10-16 16:07 - 2013-10-16 16:07 - 101406750 _____ C:\Windows\SysWOW64\핍柮Œ
2013-10-15 17:27 - 2013-10-15 17:27 - 00000000 ____D C:\Users\cottec\AppData\Roaming\wargaming.net
2013-10-15 17:01 - 2013-10-15 17:01 - 101148298 _____ C:\Windows\SysWOW64\梋녒„
2013-10-14 20:02 - 2013-10-14 20:02 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-10-13 16:14 - 2013-10-13 16:13 - 00000000 ____D C:\Users\cottec\Documents\Battlefield 4 Beta
2013-10-13 15:36 - 2012-12-24 21:11 - 00000000 ____D C:\Users\cottec\Documents\Calibre Bibliothek
2013-10-12 13:52 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-10-11 22:38 - 2013-09-08 20:43 - 01592864 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-11 22:38 - 2012-12-23 14:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-11 22:38 - 2012-12-23 14:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-11 22:35 - 2013-07-31 21:15 - 00000000 ____D C:\Windows\system32\MRT
2013-10-11 22:34 - 2013-09-09 18:13 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-11 20:03 - 2013-10-11 20:03 - 00000000 ____D C:\Program Files\DivX
2013-10-11 20:03 - 2013-10-11 20:02 - 00000000 ____D C:\Program Files (x86)\DivX
2013-10-11 20:03 - 2013-10-11 20:01 - 00000000 ____D C:\ProgramData\DivX
2013-10-11 20:02 - 2013-09-15 16:16 - 00000000 _____ C:\END
2013-10-10 17:23 - 2013-10-10 17:23 - 100305510 _____ C:\Windows\SysWOW64\㳈ˁu
2013-10-09 19:29 - 2013-02-11 19:12 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 19:29 - 2012-12-21 17:08 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 19:29 - 2012-12-21 17:08 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-09 19:23 - 2012-12-28 11:50 - 00000000 ____D C:\Users\cottec\AppData\Roaming\vlc
2013-10-08 21:59 - 2013-02-17 15:59 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-08 21:59 - 2013-02-17 15:59 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-08 06:50 - 2013-06-23 17:14 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 06:46 - 2013-06-23 17:14 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-08 06:46 - 2013-06-23 17:14 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-08 06:46 - 2013-06-23 17:14 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-07 17:17 - 2013-01-20 15:50 - 00000000 ____D C:\Users\cottec\AppData\Local\FRITZ!
2013-10-07 17:15 - 2013-10-07 17:15 - 00003074 _____ C:\Windows\System32\Tasks\ScanToPCActivationApp.exe_{AD063CB6-193B-4D04-BB14-1AF681BF23C6}
2013-10-07 17:12 - 2013-10-07 17:12 - 00000000 ____D C:\Users\cottec\Documents\Fax
2013-10-07 16:44 - 2013-10-07 16:44 - 99717279 _____ C:\Windows\SysWOW64\꘽ൡ7
2013-10-06 19:46 - 2013-10-06 19:46 - 99477982 _____ C:\Windows\SysWOW64\⠙ᚅ‘
2013-10-06 13:46 - 2013-10-06 13:46 - 99463930 _____ C:\Windows\SysWOW64\乻¤
2013-10-04 18:28 - 2013-10-04 18:28 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-10-04 18:28 - 2013-06-27 14:14 - 00000000 ____D C:\Program Files (x86)\Kies
2013-10-04 16:48 - 2013-06-27 16:54 - 00000000 ____D C:\Users\cottec\AppData\Roaming\MyPhoneExplorer
2013-10-04 16:41 - 2013-06-27 16:54 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer

Some content of TEMP:
====================
C:\Users\cottec\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\cottec\AppData\Local\Temp\mbam-setup.exe
C:\Users\cottec\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\cottec\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\cottec\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\cottec\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\cottec\AppData\Local\Temp\nvStInst.exe
C:\Users\cottec\AppData\Local\Temp\proxy_vole6320029762539422116.dll
C:\Users\cottec\AppData\Local\Temp\sfamcc00001.dll
C:\Users\cottec\AppData\Local\Temp\sfextra.dll
C:\Users\cottec\AppData\Local\Temp\sonarinst.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== BCD ================================

Windows-Start-Manager
---------------------
Bezeichner              {bootmgr}
device                  partition=\Device\HarddiskVolume1
description            Windows Boot Manager
locale                  de-DE
inherit                {globalsettings}
default                {current}
resumeobject            {9b38fee3-4adf-11e2-a713-f87b13426a8a}
displayorder            {current}
toolsdisplayorder      {memdiag}
timeout                10

Windows-Startladeprogramm
-------------------------
Bezeichner              {current}
device                  partition=C:
path                    \Windows\system32\winload.exe
description            Windows 7
locale                  de-DE
inherit                {bootloadersettings}
recoverysequence        {cbd971bf-b7b8-4885-951a-fa03044f5d71}
recoveryenabled        No
osdevice                partition=C:
systemroot              \Windows
resumeobject            {9b38fee3-4adf-11e2-a713-f87b13426a8a}
nx                      OptIn

Wiederaufnahme aus dem Ruhezustand
----------------------------------
Bezeichner              {9b38fee3-4adf-11e2-a713-f87b13426a8a}
device                  partition=C:
path                    \Windows\system32\winresume.exe
description            Windows Resume Application
locale                  de-DE
inherit                {resumeloadersettings}
filedevice              partition=C:
filepath                \hiberfil.sys
debugoptionenabled      No

Windows-Speichertestprogramm
----------------------------
Bezeichner              {memdiag}
device                  partition=\Device\HarddiskVolume1
path                    \boot\memtest.exe
description            Windows-Speicherdiagnose
locale                  de-DE
inherit                {globalsettings}
badmemoryaccess        Yes

EMS-Einstellungen
-----------------
Bezeichner              {emssettings}
bootems                Yes

Debuggereinstellungen
---------------------
Bezeichner              {dbgsettings}
debugtype              Serial
debugport              1
baudrate                115200

RAM-Defekte
-----------
Bezeichner              {badmemory}

Globale Einstellungen
---------------------
Bezeichner              {globalsettings}
inherit                {dbgsettings}
                        {emssettings}
                        {badmemory}

Startladeprogramm-Einstellungen
-------------------------------
Bezeichner              {bootloadersettings}
inherit                {globalsettings}
                        {hypervisorsettings}

Hypervisoreinstellungen
-------------------
Bezeichner              {hypervisorsettings}
hypervisordebugtype    Serial
hypervisordebugport    1
hypervisorbaudrate      115200

Einstellungen zur Ladeprogrammfortsetzung
-----------------------------------------
Bezeichner              {resumeloadersettings}
inherit                {globalsettings}



LastRegBack: 2013-10-31 19:50

==================== End Of Log ============================

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-10-2013
Ran by cottec at 2013-11-03 18:14:24
Running from D:\Downloads\Software\FRST
Boot Mode: Normal
==========================================================


==================== Security Center ========================


==================== Installed Programs ======================

3DMark 11 (x32 Version: 1.0.5)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader XI - Deutsch (x32 Version: 11.0.00)
ArtMoney SE v7.39.2 (x32 Version: 7.39)
AutoIt v3.3.8.1 (x32)
Avira Free Antivirus (x32 Version: 13.0.0.4052)
AVM FRITZ!fax für FRITZ!Box (x32)
Battlefield 3™ (x32 Version: 1.6.0.0)
Battlefield 4™ (x32 Version: 1.0.0.0)
Battlelog Web Plugins (x32 Version: 2.3.0)
BMW EBA (x32 Version: 2.1.0)
Bonjour (Version: 3.0.0.10)
Burnout(TM) Paradise The Ultimate Box (x32 Version: 1.1.0.0)
C2DtoG15 2.0.2.1 (x32)
calibre (x32 Version: 1.5.0)
CCleaner (Version: 4.03)
CLICKBIOSII (x32 Version: 1.0.119)
ControlCenter (x32 Version: 2.5.060)
CrystalDiskInfo 5.2.0 (x32 Version: 5.2.0)
DAEMON Tools Lite (x32 Version: 4.47.1.0333)
DH Driver Cleaner Professional Edition (x32 Version: Version 1.5)
DivX-Setup (x32 Version: 2.6.1.84)
Dropbox (HKCU Version: 2.0.22)
EaseUS Partition Master 9.2.2 (x32)
ElsterFormular (x32 Version: 14.3.20130522)
ESET Online Scanner v3 (x32)
ESN Sonar (x32 Version: 0.70.4)
ETK (Lokal) (x32 Version: 2.00.064)
Far Cry 3 (x32 Version: 1.02)
Foxtab (x32)
Futuremark SystemInfo (x32 Version: 4.22.211)
GeForce Experience NvStream Client Components (Version: 1.6.28)
Google Chrome (x32 Version: 30.0.1599.101)
Google Earth Plug-in (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
HP Officejet 6500 E710n-z - Grundlegende Software für das Gerät (Version: 28.0.1315.0)
Intel(R) Control Center (x32 Version: 1.2.1.1008)
Intel(R) Management Engine Components (x32 Version: 8.1.0.1252)
Intel(R) Rapid Storage Technology (x32 Version: 11.5.0.1207)
Intel(R) Smart Connect Technology 3.0 x64 (Version: 3.0.30.1526)
Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.8.251)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
JDownloader 2 (Version: 2.0)
Live Update 5 (x32 Version: 5.0.109)
Logitech Gaming Software (Version: 8.45.88)
Logitech Gaming Software 5.10 (Version: 5.10.127)
Logitech Gaming Software 8.50 (Version: 8.50.281)
ManiaPlanet (x32)
Medal of Honor (TM) (x32 Version: 1.0.0.0)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft Office 2003 Web Components (x32 Version: 12.0.6213.1000)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2008 Native Client (Version: 10.0.1600.22)
Microsoft SQL Server 2008 Setup Support Files  (Version: 10.1.2731.0)
Microsoft SQL Server 2012 (64-bit)
Microsoft SQL Server 2012 Native Client  (Version: 11.0.2100.60)
Microsoft SQL Server 2012 RsFx Driver (Version: 11.0.2100.60)
Microsoft SQL Server 2012 Setup (English) (Version: 11.0.2100.60)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (Version: 11.0.2100.60)
Microsoft Visual Basic for Applications 7.1 (x64) (Version: 7.1.00.00)
Microsoft Visual Basic for Applications 7.1 (x64) English (Version: 7.1.0.0)
Microsoft Visual Basic for Applications 7.1 (x64) German (Version: 7.1.0.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU (Version: 8.0.52572)
Microsoft Visual Studio 2005 Tools for Applications - ENU (x32 Version: 8.0.50727.146)
Microsoft Visual Studio 2005 Tools for Applications - ENU (x32)
Microsoft VSS Writer for SQL Server 2012 (Version: 11.0.2100.60)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0)
Miranda Fusion 3.2.6.0 (x32 Version: 3.2.6.0)
Mobipocket Creator 4.2 (x32 Version: 4.2.41)
Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0)
Mozilla Maintenance Service (x32 Version: 25.0)
Mp3tag v2.54 (x32 Version: v2.54)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MusicBrainz Picard (x32 Version: 1.1)
MyPhoneExplorer (x32 Version: 1.8.5)
Nasty File Remover v0.72 (remove only) (x32)
NVIDIA 3D Vision Controller-Treiber 331.65 (Version: 331.65)
NVIDIA 3D Vision Treiber 331.65 (Version: 331.65)
NVIDIA GeForce Experience 1.7 (Version: 1.7)
NVIDIA Grafiktreiber 331.65 (Version: 331.65)
NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4)
NVIDIA Install Application (Version: 2.1002.140.952)
NVIDIA LED Visualizer 1.0 (Version: 1.0)
NVIDIA PhysX (x32 Version: 9.13.0725)
NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725)
NVIDIA ShadowPlay 9.3.16 (Version: 9.3.16)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165)
NVIDIA Systemsteuerung 331.65 (Version: 331.65)
NVIDIA Update 9.3.16 (Version: 9.3.16)
NVIDIA Update Components (Version: 9.3.16)
NVIDIA Virtual Audio 1.2.9 (Version: 1.2.9)
Origin (x32 Version: 9.1.3.2637)
PDF24 Creator 5.4.0 (x32)
Populous (x32 Version: 1.0.0.0)
Project CARS (x32 Version: 0510)
PunkBuster Services (x32 Version: 0.993)
QuickPar 0.9 (x32 Version: 0.9)
Rainmeter (x32 Version: 2.5 beta r1720)
Realtek Ethernet Controller Driver (x32 Version: 7.72.410.2013)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6959)
Revo Uninstaller Pro 3.0.7 (Version: 3.0.7)
Samsung Kies (x32 Version: 2.5.3.13052_10)
Samsung Magician (x32 Version: 4.2.1)
Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0)
SHIELD Streaming (Version: 1.6.34)
SolidWorks 2014 x64 Edition SP0 (Version: 22.100.5018)
SolidWorks 2014 x64 Edition SP0 (x32 Version: 22.0.0.5018)
SolidWorks 2014 x64 German Resources (Version: 22.100.5018)
SolidWorks Composer 2014 SP0 x64 Edition (Version: 22.00.5018)
SolidWorks eDrawings 2014 x64 Edition SP0 (Version: 14.0.5006)
SolidWorks Explorer 2014 SP0 x64 Edition (Version: 22.00.5018)
SolidWorks Flow Simulation 2014 SP0 x64 Edition  (Version: 22.00.5019)
SolidWorks Plastics 2014 SP0 x64 Edition (Version: 22.00.5018)
Source SDK Base 2007 (x32)
SpeedFan (remove only) (x32)
Splinter Cell: Blacklist (x32 Version: 1.01)
SQL Server 2012 Common Files (Version: 11.0.2100.60)
SQL Server 2012 Database Engine Services (Version: 11.0.2100.60)
SQL Server 2012 Database Engine Shared (Version: 11.0.2100.60)
SQL Server Browser for SQL Server 2012 (x32 Version: 11.0.2100.60)
Sql Server Customer Experience Improvement Program (Version: 11.0.2100.60)
Steam (x32 Version: 1.0.0.0)
Super-Charger (x32 Version: 1.2.018)
System Requirements Lab for Intel (x32 Version: 4.5.11.0)
Team Fortress 2 (x32)
TeamSpeak 3 Client (Version: 3.0.10)
TeamViewer 8 (x32 Version: 8.0.19045)
TomTom HOME (x32 Version: 2.9.6)
TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2)
TreeSize Free V2.7 (x32 Version: 2.7)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2827325) 32-Bit Edition (x32)
Update für Microsoft Office Excel 2007 Help (KB963678) (x32)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update für Microsoft Office Word 2007 Help (KB963665) (x32)
Uplay (x32 Version: 3.0)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
VLC media player 2.0.5 (Version: 2.0.5)
VR-NetWorld (x32)
Vuze (x32 Version: 5.1.0.0)
Winamp (x32 Version: 5.63 )
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1)
Windows XP Mode (Version: 1.3.7600.16422)
WinHTTrack Website Copier 3.47-6 (x64) (Version: 3.47.6)
Winki (x32 Version: 3.2.125)
WinRAR 4.20 (64-Bit) (Version: 4.20.0)
WinSCP 5.1.6 (x32 Version: 5.1.6)

==================== Restore Points  =========================

26-10-2013 12:43:55 Windows Update
27-10-2013 18:00:03 Windows-Sicherung
27-10-2013 19:05:22 Windows Update
28-10-2013 17:28:01 Windows Update
31-10-2013 21:04:56 DirectX wurde installiert
01-11-2013 17:14:52 Installiert 3DMark 11
01-11-2013 17:19:01 Installed Futuremark SystemInfo
03-11-2013 09:38:32 Tweaking.com - Windows Repair

==================== Hosts content: ==========================

2009-07-14 03:34 - 2013-08-09 17:31 - 00449440 ___RA C:\Windows\system32\Drivers\etc\hosts
127.0.0.1        www.007guard.com
127.0.0.1        007guard.com
127.0.0.1        008i.com
127.0.0.1        www.008k.com
127.0.0.1        008k.com
127.0.0.1        www.00hq.com
127.0.0.1        00hq.com
127.0.0.1        010402.com
127.0.0.1        www.032439.com
127.0.0.1        032439.com
127.0.0.1        www.0scan.com
127.0.0.1        0scan.com
127.0.0.1        1000gratisproben.com
127.0.0.1        www.1000gratisproben.com
127.0.0.1        1001namen.com
127.0.0.1        www.1001namen.com
127.0.0.1        100888290cs.com
127.0.0.1        www.100888290cs.com
127.0.0.1        www.100sexlinks.com
127.0.0.1        100sexlinks.com
127.0.0.1        10sek.com
127.0.0.1        www.10sek.com
127.0.0.1        www.1-2005-search.com
127.0.0.1        1-2005-search.com
127.0.0.1        123fporn.info
127.0.0.1        www.123fporn.info
127.0.0.1        123haustiereundmehr.com
127.0.0.1        www.123haustiereundmehr.com
127.0.0.1        123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

Task: {050C409A-505D-4558-ABBB-A3FCE95FB2AD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
Task: {21C26F42-B34D-4702-88EB-9CA6B615CF3F} - System32\Tasks\ScanToPCActivationApp.exe_{AD063CB6-193B-4D04-BB14-1AF681BF23C6} => C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {34A40C97-DA4E-4B69-AD0F-74713550220E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.)
Task: {E55A84BF-00A1-464C-8541-913DFA654467} - System32\Tasks\FoxTab => C:\Users\cottec\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] ()
Task: {E73298AB-85F4-40AD-A720-77D23CD57192} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.)
Task: {EE6E17AB-533D-4D77-B1A2-B351BB4E2240} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FoxTab.job => C:\Users\cottec\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-09-21 08:30 - 2013-09-21 08:30 - 00276008 _____ () C:\Program Files\SolidWorks Corp\SolidWorks\sldBodyDiffu.dll
2012-12-16 16:42 - 2012-12-16 16:42 - 00761528 _____ () C:\Program Files\Rainmeter\Rainmeter.dll
2012-12-16 16:41 - 2012-12-16 16:41 - 00011776 _____ () C:\Program Files\Rainmeter\Plugins\PowerPlugin.DLL
2013-11-03 17:06 - 2013-11-03 17:06 - 00566439 _____ () C:\Users\cottec\AppData\Local\JDownloader v2.0\tmp\7zip\SevenZipJBinding-FKPz9\libgcc_s_sjlj-1.dll
2013-11-03 17:06 - 2013-11-03 17:06 - 04078962 _____ () C:\Users\cottec\AppData\Local\JDownloader v2.0\tmp\7zip\SevenZipJBinding-FKPz9\lib7-Zip-JBinding.dll
2013-09-08 21:16 - 2013-09-08 21:16 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2012-12-24 00:51 - 2010-06-11 21:14 - 00004608 _____ () C:\Program Files (x86)\C2DtoG15\LgLcdLibWrapper.dll
2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\cottec\AppData\Roaming\Dropbox\bin\libcef.dll
2013-08-29 01:25 - 2013-08-29 01:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2013-09-08 21:47 - 2013-09-08 21:47 - 00017408 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\PSIClient\e54fd507aa171a3a0a7d0cc47266a7ff\PSIClient.ni.dll
2012-12-23 18:25 - 2012-06-25 10:41 - 01198912 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-10-29 19:32 - 2013-10-29 19:32 - 03368048 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-10-17 17:08 - 2013-10-09 01:01 - 00698832 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libglesv2.dll
2013-10-17 17:08 - 2013-10-09 01:01 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libegl.dll
2013-10-17 17:08 - 2013-10-09 01:02 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll
2013-10-17 17:08 - 2013-10-09 01:02 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll
2013-10-17 17:08 - 2013-10-09 01:01 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/03/2013 00:34:10 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (11/03/2013 11:06:18 AM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (11/03/2013 11:03:52 AM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (11/03/2013 11:02:06 AM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (11/03/2013 10:58:28 AM) (Source: WinMgmt) (User: )
Description: 0x8004100aC:\PROGRAM FILES (X86)\MICROSOFT SQL SERVER\110\SHARED\SQLMGMPROVIDERXPSP2UP.MOF

Error: (11/03/2013 10:34:16 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/03/2013 10:32:33 AM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (11/03/2013 10:32:26 AM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]

Error: (11/03/2013 10:32:26 AM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]

Error: (11/03/2013 10:32:26 AM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD endpoint registration failed [0]


System errors:
=============
Error: (11/03/2013 11:06:50 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Superfetch" wurde mit folgendem Fehler beendet:
%%2

Error: (11/03/2013 11:06:18 AM) (Source: WMPNetworkSvc) (User: )
Description: Dienst "WMPNetworkSvc" konnte nicht ordnungsgemäß gestartet werden, da ein Fehler "0x80070420" in "CoCreateInstance(CLSID_UPnPDeviceFinder)" aufgetreten ist. Überprüfen Sie, ob der Dienst "UPnPHost" ausgeführt wird und ob die Windows-Komponente "UPnPHost" richtig installiert ist.

Error: (11/03/2013 11:05:45 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (11/03/2013 11:05:45 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (11/03/2013 11:05:45 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (11/03/2013 11:05:39 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (11/03/2013 11:05:39 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (11/03/2013 11:05:39 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (11/03/2013 11:05:35 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068

Error: (11/03/2013 11:05:35 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068


Microsoft Office Sessions:
=========================
Error: (07/28/2013 10:02:35 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 45 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (07/18/2013 05:37:37 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (03/06/2013 00:07:38 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 52 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/21/2013 05:03:43 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 00:13:45 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 09:46:31 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 09:20:26 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 49 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2012-12-20 22:14:12.581
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:14:10.454
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:14:10.454
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:43.050
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:43.050
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:28.753
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:26.612
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:26.612
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:05:29.179
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:05:29.179
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 40%
Total physical RAM: 8142.93 MB
Available physical RAM: 4815.71 MB
Total Pagefile: 16284.05 MB
Available Pagefile: 11907.16 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB

==================== Drives ================================

Drive c: (System) (Fixed) (Total:78.13 GB) (Free:9.54 GB) NTFS
Drive d: (Daten) (Fixed) (Total:931.51 GB) (Free:98.35 GB) NTFS
Drive e: (Software) (Fixed) (Total:160.24 GB) (Free:25.65 GB) NTFS
Drive g: (SolidWorks1) (CDROM) (Total:7.76 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: 5C539950)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=78 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=160 GB) - (Type=OF Extended)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 76AF80D4)
Partition 1: (Not Active) - (Size=932 GB) - (Type=42)

==================== End Of Log ============================


cottec 03.11.2013 18:19

Code:

Farbar Service Scanner Version: 24-10-2013
Ran by cottec (administrator) on 03-11-2013 at 18:18:06
Running from "D:\Downloads\Software\FRST"
Microsoft Windows 7 Professional  Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys
[2013-10-11 18:51] - [2013-09-14 02:10] - 0497152 ____A (Microsoft Corporation) 314C17917AC8523EC77A710215012A65

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2013-10-11 18:51] - [2013-09-08 03:30] - 1903552 ____A (Microsoft Corporation) 40AF23633D197905F03AB5628C558C51

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****


schrauber 04.11.2013 10:09

http://download.bleepingcomputer.com.../WinDefend.reg

laden und ausführen, erlauben, reboot. Dann bitte ein frisches FSS Logfile.

cottec 04.11.2013 17:27

Code:

Farbar Service Scanner Version: 24-10-2013
Ran by cottec (administrator) on 04-11-2013 at 17:27:25
Running from "D:\Downloads\Software\FRST"
Microsoft Windows 7 Professional  Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is OK.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend: "%ProgramFiles(x86)%\Windows Defender\mpsvc.dll".


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys
[2013-10-11 18:51] - [2013-09-14 02:10] - 0497152 ____A (Microsoft Corporation) 314C17917AC8523EC77A710215012A65

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2013-10-11 18:51] - [2013-09-08 03:30] - 1903552 ____A (Microsoft Corporation) 40AF23633D197905F03AB5628C558C51

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

beides immer noch deaktiviert

schrauber 05.11.2013 12:43

Deinstalliere bitte Avira, dann Defender testen.

cottec 05.11.2013 17:28

soo, jetzt geht der defender immer noch nicht, aber es wird keine meldung mehr angezeigt (nach neuinstallation von antivir)

hier der defender dienst, wenn ich ihn manuell starte
http://img577.imageshack.us/img577/6889/vh97.jpg

Uploaded with ImageShack.us

schrauber 06.11.2013 11:49

Wer hat denn gesagt Du sollst Antivir nochmal installieren? :)

Deinstallieren, dann die Reg-Datei von Oben nochmal ausführen, dann Defender testen und frisches FSS log bitte.

cottec 24.01.2014 00:34

sorry für die späte rückmeldung, aber ich bin leider immer noch nicht durch mit dem thema.

der defender geht immer noch nicht
Code:

Farbar Service Scanner Version: 24-10-2013
Ran by cottec (administrator) on 24-01-2014 at 00:31:18
Running from "D:\Downloads\Software\FRST"
Microsoft Windows 7 Professional  Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys
[2013-11-13 14:09] - [2013-09-28 02:09] - 0497152 ____A (Microsoft Corporation) 79059559E89D06E8B80CE2944BE20228

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2013-10-11 18:51] - [2013-09-08 03:30] - 1903552 ____A (Microsoft Corporation) 40AF23633D197905F03AB5628C558C51

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

dazu die meldung beim manuellen starten des defender dienstes
Dienst "Windows Defender" wurde auf Lokaler Computer gestartet und dann angehalten. Einige Dienste werden automatisch angehalten, wenn sie nicht von anderen Diensten oder Programmen verwendet werden.

schrauber 24.01.2014 14:41

Poste mal bitte noch ein frisches FRST log.

cottec 24.01.2014 16:25

gerne

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2014
Ran by cottec (administrator) on COTTEC-PC on 24-01-2014 16:24:22
Running from D:\Downloads\Software\FRST
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Dassault Systemes) C:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Microsoft Corporation) C:\ProgramData\SolidWorks Electrical\MSSQL11.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Steganos Software GmbH) C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Mentor Graphics Corporation) C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\remotesolverdispatcherservice.exe
(Mentor Graphics Corporation) C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\dispatcher.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(StarWind Software) C:\Program Files (x86)\Alcohol 120\StarWind\StarWindServiceAE.exe
(Andreas Sammann) C:\Program Files (x86)\C2DtoG15\SystoG15Svc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Transaction Software, D 81737 Munich) C:\Programme\BMWgroup\ETKLokal\transbase\tbmux32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe
(Miranda Fusion Team) C:\Program Files (x86)\MirandaFusion\fusiontools\mfstart.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe
(Andreas Sammann) C:\Program Files (x86)\C2DtoG15\C2DtoG15.exe
(Dropbox, Inc.) C:\Users\cottec\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(modified by Miranda Fusion Team) C:\Program Files (x86)\MirandaFusion\miranda32.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPNetworkCommunicator.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Corporation) C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7191768 2013-06-27] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-10-18] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1063200 2013-10-18] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [506864 2013-03-08] (MSI)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ControlCenterCount] - C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [872448 2012-03-26] (MSI CO.,LTD.)
HKLM-x32\...\Run: [ControlCenterII] - \BootStartControlCenter.exe
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
HKCU\...\Run: [AlcoholAutomount] - C:\Program Files (x86)\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKCU\...\Run: [HP Officejet 6500 E710n-z (NET)] - C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKCU\...\Run: [Miranda Fusion] - C:\Program Files (x86)\MirandaFusion\fusiontools\mfstart.exe [1122241 2012-06-12] (Miranda Fusion Team)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKCU\...\Policies\system: [DisableLockWorkstation] 0
MountPoints2: {48c57620-18be-11e3-927f-d43d7e2bf080} - G:\setup.exe
MountPoints2: {8d9c12a6-6494-11e3-b6e5-d43d7e2bf080} - G:\setup.exe
MountPoints2: {b75da7ac-4d26-11e2-bd17-d43d7e2bf080} - J:\shelexec.exe start.html
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\C2DtoG15.lnk
ShortcutTarget: C2DtoG15.lnk -> C:\Program Files (x86)\C2DtoG15\C2DtoG15.exe (Andreas Sammann)
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\cottec\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4B157DDCF427CE01
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.111.111.1

FireFox:
========
FF ProfilePath: C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default
FF user.js: detected! => C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\user.js
FF Homepage: hxxp://www.google.de/
FF NetworkProxy: "http", "200.65.127.163"
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: GFACE Experience Plugin - C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\Extensions\cryenginebrowserplugin@crytek.com [2013-11-07]
FF Extension: Adblock Plus - C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-12-23]
FF Extension: OkayFreedom - C:\Users\cottec\AppData\Roaming\Mozilla\Firefox\Profiles\i18isqwg.default\Extensions\{DB981CCA-088E-4731-A4A2-2FE218703C0E}.xpi [2014-01-20]

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll No File
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (Google Docs) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-21]
CHR Extension: (Google Drive) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-07-21]
CHR Extension: (OkayFreedom) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\bckipplcmnfhblnpibpbehenelnkpecd [2014-01-21]
CHR Extension: (YouTube) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-21]
CHR Extension: (Google-Suche) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-21]
CHR Extension: (Google Wallet) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Google Mail) - C:\Users\cottec\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-07-21]
CHR HKCU\...\Chrome\Extension: [bckipplcmnfhblnpibpbehenelnkpecd] - C:\Program Files (x86)\OkayFreedom\okayfreedom.crx [2013-12-05]

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 BBDemon; C:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe [46592 2011-01-08] (Dassault Systemes)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [520416 2013-10-15] (Futuremark)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [146984 2012-07-24] ()
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161264 2013-02-20] (MSI)
R2 MSSQL$TEW_SQLEXPRESS; C:\ProgramData\SolidWorks Electrical\MSSQL11.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe [192000 2012-12-29] (Microsoft Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-18] (NVIDIA Corporation)
R2 OkayFreedom VPN Starter Service; C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe [317792 2013-12-10] (Steganos Software GmbH)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-31] ()
R2 RemoteSolverDispatcher; C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\remotesolverdispatcherservice.exe [235656 2013-09-20] (Mentor Graphics Corporation)
S4 SQLAgent$TEW_SQLEXPRESS; C:\ProgramData\SolidWorks Electrical\MSSQL11.TEW_SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [612864 2012-12-29] (Microsoft Corporation)
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
R2 SystoG15Svc; C:\Program Files (x86)\C2DtoG15\SystoG15Svc.exe [64000 2012-12-24] (Andreas Sammann)
R2 Transbase; C:\Programme\BMWgroup\ETKLokal\transbase\tbmux32.exe [385024 2004-08-05] (Transaction Software, D 81737 Munich)
R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [18384 2013-09-04] (Intel(R) Corporation)

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-14] (Disc Soft Ltd)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] ()
S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [13896 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] ()
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [27456 2012-07-09] (Intel Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [20968 2012-07-24] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [19944 2012-07-24] ()
R2 iocbios2; C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [26328 2013-07-23] (Intel Corporation)
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46016 2012-07-24] ()
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R1 LUMDriver; C:\Windows\system32\drivers\LUMDriver.sys [24848 2008-01-02] (IBM)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-07-26] (Intel Corporation)
S3 NTIOLib_1_0_1; C:\Program Files (x86)\MSI\CLICKBIOSII\NTIOLib_X64.sys [14136 2009-10-05] (MSI)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [14136 2010-10-22] (MSI)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7758v190\NTIOLib_X64.sys [11888 2011-01-06] (MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [13368 2012-11-09] (MSI)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation)
S4 RsFx0201; C:\Windows\System32\DRIVERS\RsFx0201.sys [336880 2012-10-20] (Microsoft Corporation)
S3 ssudobex; C:\Windows\System32\DRIVERS\ssudobex.sys [204568 2013-08-20] (DEVGURU Co., LTD.(www.devguru.co.kr))
R3 WinRing0_1_2_0; C:\Program Files (x86)\C2DtoG15\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-01-24] ()
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [x]

========================== Drivers MD5 =======================

C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit
C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit
C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit
C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit
C:\Windows\system32\drivers\afd.sys 79059559E89D06E8B80CE2944BE20228
C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit
C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49
C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit
C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048
C:\Windows\system32\drivers\appid.sys ==> MD5 is legit
C:\Windows\system32\drivers\arc.sys ==> MD5 is legit
C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
C:\Windows\system32\drivers\atapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\avgntflt.sys 7806BFCD1D7FA5EC23F7324D4EAFD25B
C:\Windows\System32\DRIVERS\avipbb.sys C3A58DBD18786C338126D30BF8C33D72
C:\Windows\System32\DRIVERS\avkmgr.sys 390184FAD8FCC1B6DA25AEBAE928C3B6
C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit
C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit
C:\Windows\System32\CLFS.sys ==> MD5 is legit
C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit
C:\Windows\System32\Drivers\cng.sys EBF28856F69CF094A902F884CF989706
C:\Windows\system32\drivers\compbatt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\csc.sys ==> MD5 is legit
C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ssudbus.sys E428DFFA96FAD07D8CA3C9082563A225
C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
C:\Windows\System32\drivers\disk.sys ==> MD5 is legit
C:\Windows\system32\drivers\dmvsc.sys 5DB085A8A6600BE6401F2B24EECB5415
C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\dtsoftbus01.sys 6A0E850DDCB136AA3D2FB7234382DF12
C:\Windows\System32\drivers\dxgkrnl.sys 88612F1CE3BF42256913BF6E61C70D52
C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit
C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit
C:\Windows\system32\epmntdrv.sys 6106653B08F4F72EEAA7F099E7C408A4
C:\Windows\SysWOW64\epmntdrv.sys F17F09BA097D8EC3CE2084FA97886B85
C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit
C:\Windows\system32\EuGdiDrv.sys 991C04A31777ED77CB92A4F96F14C2E2
C:\Windows\SysWOW64\EuGdiDrv.sys F1DE3EEF501DDA7DDF99F2EDF0C5540E
C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit
C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit
C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit
C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B
C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0
C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit
C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A
C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit
C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit
C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit
C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit
C:\Windows\System32\drivers\iaStorA.sys 0FE66A51D81A25AACEAAE4C26308121D
C:\Windows\System32\drivers\iaStorF.sys A0EA86734FD36A1A047CA24EC6528CBA
C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366
C:\Windows\System32\DRIVERS\ICCWDT.sys 55004F2386405B28471E09C2373ED0E0
C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ikbevent.sys F2C300C2E56F016B485B88080CD7D2FE
C:\Windows\System32\DRIVERS\imsevent.sys C1A5061D6E5C328AE030C34B8AAC5C5C
C:\Windows\System32\drivers\RTKVHD64.sys E551BB77E7D436380139977124BDFF62
C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys C7F1ED5179349ED83CDD999E1B02DD10
C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit
C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ISCTD64.sys 5AB18D8055A4280C0F377A6262F3157E
C:\Windows\System32\DRIVERS\iusb3hcs.sys 75779002A6084C1A011E195E421A9C75
C:\Windows\System32\DRIVERS\iusb3hub.sys F390B641FE6115F536B8B78AA71B8814
C:\Windows\System32\DRIVERS\iusb3xhc.sys 653B86AA174FF7661D00EE1E524B234F
C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\ksecdd.sys 8F489706472F7E9A06BAAA198703FA64
C:\Windows\System32\Drivers\ksecpkg.sys 868A2CAAB12EFC7A021682BCA0EEC54C
C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit
C:\Windows\System32\drivers\LGBusEnum.sys FA529FB35694C24BF98A9EF67C1CD9D0
C:\Windows\System32\DRIVERS\LGSHidFilt.Sys 94AF1384A67B9FCF5651E70BC9D4C526
C:\Windows\System32\drivers\LGVirHid.sys 94B29CE153765E768F004FB3440BE2B0
C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit
C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
C:\Windows\system32\drivers\LUMDriver.sys 701223C663019B62029FAB1A2385EE81
C:\Windows\System32\drivers\MBfilt64.sys 8FF2D95CBA49B405C5DE27039FF0BF35
C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit
C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\TeeDriverx64.sys 18B9AD128EC84E8D16A83F70CF36594F
C:\Windows\System32\drivers\modem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit
C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\mrxdav.sys 1A4F75E63C9FB84B85DFFC6B63FD5404
C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC
C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163
C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C
C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit
C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88
C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit
C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Ntfs.sys B98F8C6E31CD07B2E6F71F7F648E38C0
C:\Program Files (x86)\MSI\CLICKBIOSII\NTIOLib_X64.sys C3FEA895FE95EA7A57D9F4D7ABED5E71
C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys 23CF3DA010497EB2BF39A5C5A57E437C
C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys 1B32C54B95121AB1683C7B83B2DB4B96
C:\Program Files (x86)\Setup Files\Ms7758v190\NTIOLib_X64.sys C02F70960FA934B8DEFA16A03D7F6556
C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys 2DA209DDE8188076A9579BD256DC90D0
C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
C:\Windows\System32\drivers\nvhda64v.sys 554964B900AE2954B8B589B6287034AC
C:\Windows\System32\DRIVERS\nvlddmkm.sys E71E299FF15390E585BACF2C18F55078
C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD
C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A
C:\Windows\System32\drivers\nvvad64v.sys 31B16657118E439B77B0A527F7EA66CB
C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit
C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\parport.sys ==> MD5 is legit
C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C
C:\Windows\System32\drivers\pci.sys ==> MD5 is legit
C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit
C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit
C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
C:\Windows\system32\drivers\processr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpdr.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34
C:\Windows\System32\Drivers\RDPWD.sys E61608AA35E98999AF9AAEEEA6114B0A
C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\revoflt.sys 9C3AC71A9934B884FAC567A8807E9C4D
C:\Windows\System32\DRIVERS\RsFx0201.sys 964E8376B0B3FE1354B19907E1A4A692
C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\Rt64win7.sys 130DD683DCC902F47A4AC35201D07E2F
C:\Windows\system32\drivers\vms3cap.sys ==> MD5 is legit
C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serenum.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serial.sys ==> MD5 is legit
C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit
C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit
C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit
C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
C:\Windows\SysWow64\speedfan.sys 0FFE35F0B0CD5A324BBE22F02569AE3B
C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B
C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28
C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3
C:\Windows\System32\DRIVERS\ssudmdm.sys AAF6F247F1DC370C593B4430974EAD9C
C:\Windows\System32\DRIVERS\ssudobex.sys 9A8D59146B6FC187140179D0F05EB07E
C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit
C:\Windows\system32\drivers\serscan.sys DECACB6921DED1A38642642685D77DAC
C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 is legit
C:\Windows\system32\drivers\storvsc.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tap0901.sys 3C32FF010F869BC184DF71290477384E
C:\Windows\System32\drivers\tcpip.sys 40AF23633D197905F03AB5628C558C51
C:\Windows\System32\DRIVERS\tcpip.sys 40AF23633D197905F03AB5628C558C51
C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC
C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8
C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tssecsrv.sys 4CE278FC9671BA81A138D70823FCAA09
C:\Windows\System32\drivers\tsusbflt.sys E9981ECE8D894CEF7038FD1D040EB426
C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07
C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\usbccgp.sys DCA68B0943D6FA415F0C56C92158A83A
C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31
C:\Windows\system32\drivers\usbehci.sys 18A85013A3E0F7E1755365D287443965
C:\Windows\System32\DRIVERS\usbhub.sys 8D1196CFBB223621F2C67D45710F25BA
C:\Windows\system32\drivers\usbohci.sys 765A92D428A8DB88B960DA5A8D6089DC
C:\Windows\system32\drivers\usbprint.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6
C:\Windows\system32\drivers\usbuhci.sys DD253AFC3BC6CBA412342DE60C3647F3
C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit
C:\Windows\system32\drivers\vmbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit
C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit
C:\Windows\System32\drivers\vwifibus.sys ==> MD5 is legit
C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\system32\drivers\wd.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8
C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit
C:\Program Files (x86)\C2DtoG15\WinRing0x64.sys 0C0195C48B6B8582FA6F6373032118DA
C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D
C:\Windows\System32\drivers\WmFilter.sys 14C35BA8189C6F65D839163AA285E954
C:\Windows\System32\DRIVERS\wmiacpi.sys ==> MD5 is legit
C:\Windows\System32\drivers\WPRO_41_2001.sys 7CA09731EB7FC99B910C7F239E57720F
C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\WSDPrint.sys 8D918B1DB190A4D9B1753A66FA8C96E8
C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F
C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-24 00:30 - 2014-01-24 00:30 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Avira
2014-01-24 00:29 - 2014-01-24 00:29 - 00002072 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2014-01-24 00:29 - 2013-12-18 09:32 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-01-24 00:29 - 2013-12-18 09:32 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-01-24 00:29 - 2013-12-18 09:32 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-01-24 00:28 - 2014-01-24 00:28 - 00000000 ____D C:\Program Files (x86)\Avira
2014-01-24 00:12 - 2014-01-24 00:24 - 130658432 _____ C:\Users\cottec\Desktop\avira_free_antivirus_de.exe
2014-01-20 23:38 - 2014-01-20 23:38 - 00001079 _____ C:\Users\Public\Desktop\OkayFreedom.lnk
2014-01-20 23:38 - 2014-01-20 23:38 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Steganos VPN
2014-01-20 23:37 - 2014-01-20 23:38 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Steganos
2014-01-20 23:37 - 2014-01-20 23:38 - 00000000 ____D C:\Program Files (x86)\OkayFreedom
2014-01-20 23:37 - 2014-01-20 23:37 - 15523640 _____ (Steganos Software GmbH) C:\Users\cottec\Desktop\okayfreedom.exe
2014-01-20 23:37 - 2014-01-20 23:37 - 02756408 _____ (Steganos Software GmbH) C:\Users\cottec\Desktop\okayfreedomintdle11.exe
2014-01-15 20:18 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 20:18 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 20:18 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 20:18 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 20:18 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 20:18 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 20:18 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 20:18 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 20:18 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-14 23:11 - 2014-01-14 23:11 - 00000000 ____D C:\Users\cottec\AppData\Local\3dmouse
2014-01-14 22:57 - 2014-01-14 22:57 - 00002441 _____ C:\Users\Public\Desktop\CATIA V5R21.lnk
2014-01-14 22:54 - 2014-01-14 22:54 - 00000000 ____D C:\Program Files\Dassault Systemes
2014-01-12 15:13 - 2014-01-12 15:12 - 00001775 _____ C:\Users\Public\Documents\klima.txt
2013-12-31 11:23 - 2014-01-12 15:12 - 00001775 _____ C:\Users\cottec\Desktop\klima.txt
2013-12-28 09:54 - 2013-12-28 11:07 - 00000000 ____D C:\Users\cottec\Desktop\Frei.Wild Still Grenzenlos Deluxe Edition
2013-12-27 12:22 - 2014-01-14 17:43 - 00009588 _____ C:\Users\cottec\Desktop\silvester.xlsx

==================== One Month Modified Files and Folders =======

2014-01-24 16:14 - 2013-10-24 18:14 - 00000292 _____ C:\Windows\Tasks\FoxTab.job
2014-01-24 16:13 - 2009-07-14 05:45 - 00018496 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-24 16:13 - 2009-07-14 05:45 - 00018496 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-24 16:12 - 2013-09-08 20:27 - 01361605 _____ C:\Windows\WindowsUpdate.log
2014-01-24 16:12 - 2011-04-12 08:43 - 00770770 _____ C:\Windows\system32\perfh007.dat
2014-01-24 16:12 - 2011-04-12 08:43 - 00179534 _____ C:\Windows\system32\perfc007.dat
2014-01-24 16:12 - 2009-07-14 06:13 - 01865344 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-24 16:10 - 2013-02-17 15:59 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-24 16:10 - 2013-02-17 15:59 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-24 16:08 - 2013-11-27 07:21 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2014-01-24 16:08 - 2013-09-08 20:27 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-24 16:08 - 2013-01-27 18:36 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Dropbox
2014-01-24 16:08 - 2012-12-24 00:51 - 00000000 ____D C:\Program Files (x86)\C2DtoG15
2014-01-24 16:08 - 2012-12-23 18:21 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2014-01-24 16:08 - 2010-11-21 04:47 - 00297538 _____ C:\Windows\PFRO.log
2014-01-24 16:08 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-24 16:08 - 2009-07-14 05:51 - 17985231 _____ C:\Windows\setupact.log
2014-01-24 00:30 - 2014-01-24 00:30 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Avira
2014-01-24 00:29 - 2014-01-24 00:29 - 00002072 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2014-01-24 00:29 - 2013-02-11 19:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-24 00:28 - 2014-01-24 00:28 - 00000000 ____D C:\Program Files (x86)\Avira
2014-01-24 00:28 - 2013-09-08 21:16 - 00000000 ____D C:\ProgramData\Avira
2014-01-24 00:24 - 2014-01-24 00:12 - 130658432 _____ C:\Users\cottec\Desktop\avira_free_antivirus_de.exe
2014-01-24 00:23 - 2013-11-27 18:50 - 00007599 _____ C:\Users\cottec\AppData\Local\Resmon.ResmonCfg
2014-01-24 00:08 - 2013-11-04 17:22 - 00007586 _____ C:\Users\cottec\Desktop\WinDefend.reg
2014-01-23 18:14 - 2013-12-18 20:14 - 00000106 _____ C:\Users\cottec\AppData\Roaming\WB.CFG
2014-01-21 19:26 - 2012-12-28 11:50 - 00000000 ____D C:\Users\cottec\AppData\Roaming\vlc
2014-01-21 19:23 - 2012-12-23 13:32 - 00000000 ____D C:\Users\cottec\AppData\Local\Microsoft Help
2014-01-20 23:38 - 2014-01-20 23:38 - 00001079 _____ C:\Users\Public\Desktop\OkayFreedom.lnk
2014-01-20 23:38 - 2014-01-20 23:38 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Steganos VPN
2014-01-20 23:38 - 2014-01-20 23:37 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Steganos
2014-01-20 23:38 - 2014-01-20 23:37 - 00000000 ____D C:\Program Files (x86)\OkayFreedom
2014-01-20 23:37 - 2014-01-20 23:37 - 15523640 _____ (Steganos Software GmbH) C:\Users\cottec\Desktop\okayfreedom.exe
2014-01-20 23:37 - 2014-01-20 23:37 - 02756408 _____ (Steganos Software GmbH) C:\Users\cottec\Desktop\okayfreedomintdle11.exe
2014-01-18 08:33 - 2013-01-27 18:36 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-18 08:33 - 2012-12-20 21:02 - 00000000 ___RD C:\Users\cottec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-16 17:25 - 2013-02-11 19:12 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-01-16 17:25 - 2012-12-21 17:08 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-16 17:25 - 2012-12-21 17:08 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-16 17:25 - 2012-12-21 16:49 - 00000000 ____D C:\Users\cottec\AppData\Local\Adobe
2014-01-16 17:21 - 2009-07-14 05:45 - 00464640 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-15 23:07 - 2013-07-31 21:15 - 00000000 ____D C:\Windows\system32\MRT
2014-01-15 23:07 - 2012-12-23 13:32 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-15 23:05 - 2013-09-09 18:13 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-14 23:11 - 2014-01-14 23:11 - 00000000 ____D C:\Users\cottec\AppData\Local\3dmouse
2014-01-14 23:11 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\AppData\Local\DassaultSystemes
2014-01-14 23:02 - 2013-09-08 20:40 - 00126824 _____ C:\Users\cottec\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-14 22:57 - 2014-01-14 22:57 - 00002441 _____ C:\Users\Public\Desktop\CATIA V5R21.lnk
2014-01-14 22:57 - 2009-07-14 03:34 - 00017708 _____ C:\Windows\system32\Drivers\etc\services
2014-01-14 22:54 - 2014-01-14 22:54 - 00000000 ____D C:\Program Files\Dassault Systemes
2014-01-14 22:54 - 2013-10-26 12:05 - 00000000 ____D C:\ProgramData\DassaultSystemes
2014-01-14 22:54 - 2012-12-23 13:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2014-01-14 22:51 - 2013-10-26 12:05 - 00000000 ____D C:\Users\cottec\AppData\Roaming\DassaultSystemes
2014-01-14 22:49 - 2013-10-26 12:34 - 00000000 ____D C:\Users\cottec\AppData\Local\JDownloader v2.0
2014-01-14 17:43 - 2013-12-27 12:22 - 00009588 _____ C:\Users\cottec\Desktop\silvester.xlsx
2014-01-12 15:12 - 2014-01-12 15:13 - 00001775 _____ C:\Users\Public\Documents\klima.txt
2014-01-12 15:12 - 2013-12-31 11:23 - 00001775 _____ C:\Users\cottec\Desktop\klima.txt
2014-01-08 19:32 - 2013-09-15 16:17 - 00000000 ____D C:\Users\cottec\AppData\Roaming\Azureus
2014-01-08 17:16 - 2013-09-15 16:17 - 00000000 ____D C:\Program Files (x86)\Vuze
2014-01-08 17:15 - 2013-09-15 16:16 - 00000000 _____ C:\END
2013-12-28 11:07 - 2013-12-28 09:54 - 00000000 ____D C:\Users\cottec\Desktop\Frei.Wild Still Grenzenlos Deluxe Edition

Some content of TEMP:
====================
C:\Users\cottec\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== BCD ================================

Windows-Start-Manager
---------------------
Bezeichner              {bootmgr}
device                  partition=\Device\HarddiskVolume1
description            Windows Boot Manager
locale                  de-DE
inherit                {globalsettings}
default                {current}
resumeobject            {9b38fee3-4adf-11e2-a713-f87b13426a8a}
displayorder            {current}
toolsdisplayorder      {memdiag}
timeout                10

Windows-Startladeprogramm
-------------------------
Bezeichner              {current}
device                  partition=C:
path                    \Windows\system32\winload.exe
description            Windows 7
locale                  de-DE
inherit                {bootloadersettings}
recoverysequence        {cbd971bf-b7b8-4885-951a-fa03044f5d71}
recoveryenabled        No
osdevice                partition=C:
systemroot              \Windows
resumeobject            {9b38fee3-4adf-11e2-a713-f87b13426a8a}
nx                      OptIn

Wiederaufnahme aus dem Ruhezustand
----------------------------------
Bezeichner              {9b38fee3-4adf-11e2-a713-f87b13426a8a}
device                  partition=C:
path                    \Windows\system32\winresume.exe
description            Windows Resume Application
locale                  de-DE
inherit                {resumeloadersettings}
filedevice              partition=C:
filepath                \hiberfil.sys
debugoptionenabled      No

Windows-Speichertestprogramm
----------------------------
Bezeichner              {memdiag}
device                  partition=\Device\HarddiskVolume1
path                    \boot\memtest.exe
description            Windows-Speicherdiagnose
locale                  de-DE
inherit                {globalsettings}
badmemoryaccess        Yes

EMS-Einstellungen
-----------------
Bezeichner              {emssettings}
bootems                Yes

Debuggereinstellungen
---------------------
Bezeichner              {dbgsettings}
debugtype              Serial
debugport              1
baudrate                115200

RAM-Defekte
-----------
Bezeichner              {badmemory}

Globale Einstellungen
---------------------
Bezeichner              {globalsettings}
inherit                {dbgsettings}
                        {emssettings}
                        {badmemory}

Startladeprogramm-Einstellungen
-------------------------------
Bezeichner              {bootloadersettings}
inherit                {globalsettings}
                        {hypervisorsettings}

Hypervisoreinstellungen
-------------------
Bezeichner              {hypervisorsettings}
hypervisordebugtype    Serial
hypervisordebugport    1
hypervisorbaudrate      115200

Einstellungen zur Ladeprogrammfortsetzung
-----------------------------------------
Bezeichner              {resumeloadersettings}
inherit                {globalsettings}



LastRegBack: 2014-01-19 01:55

==================== End Of Log ============================

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-01-2014
Ran by cottec at 2014-01-24 16:24:41
Running from D:\Downloads\Software\FRST
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}

==================== Installed Programs ======================

3DMark 11 (x32 Version: 1.0.5 - Futuremark Corporation)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.43 - Adobe Systems Incorporated)
Adobe Reader XI - Deutsch (x32 Version: 11.0.00 - Adobe Systems Incorporated)
ArtMoney SE v7.39.2 (x32 Version: 7.39 - System SoftLab)
Auto Gordian Knot 2.55 (x32 Version: 2.55 - len0x)
AutoIt v3.3.8.1 (x32 Version:  - AutoIt Team)
Avira Free Antivirus (x32 Version: 14.0.2.344 - Avira)
AviSynth 2.5 (x32 Version:  - )
AVM FRITZ!fax für FRITZ!Box (x32 Version:  - AVM Berlin)
Battlefield 4™ (x32 Version: 1.0.0.1 - Electronic Arts)
Battlelog Web Plugins (x32 Version: 2.3.2 - EA Digital Illusions CE AB)
BMW EBA (x32 Version: 2.1.0 - BMW)
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Burnout(TM) Paradise The Ultimate Box (x32 Version: 1.1.0.0 - Electronic Arts)
C2DtoG15 2.0.2.1 (x32 Version:  - )
calibre (x32 Version: 1.5.0 - Kovid Goyal)
CCleaner (Version: 4.03 - Piriform)
CLICKBIOSII (x32 Version: 1.0.119 - MSI)
ControlCenter (x32 Version: 2.5.060 - MSI)
CrystalDiskInfo 5.2.0 (x32 Version: 5.2.0 - Crystal Dew World)
DAEMON Tools Lite (x32 Version: 4.48.1.0347 - Disc Soft Ltd)
Dassault Systemes Software B21 (Version:  - )
Dassault Systemes Software Prerequisites x86-x64 (Version: 8.1.3 - Dassault Systemes)
DH Driver Cleaner Professional Edition (x32 Version: Version 1.5 - Ruud Ketelaars)
DivX-Setup (x32 Version: 2.6.1.84 - DivX, LLC)
Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.)
EaseUS Partition Master 9.2.2 (x32 Version:  - EaseUS)
EBA (x32 Version: 2.1.0 - BMW) Hidden
ElsterFormular (x32 Version: 14.3.20130522 - Landesfinanzdirektion Thüringen)
ESET Online Scanner v3 (x32 Version:  - )
ESN Sonar (x32 Version: 0.70.4 - ESN Social Software AB)
ETK (Lokal) (x32 Version: 2.00.064 - BMW AG)
Far Cry 3 (x32 Version: 1.02 - Ubisoft)
Foxtab (x32 Version:  - FoxTab) <==== ATTENTION
Futuremark SystemInfo (x32 Version: 4.22.211 - Futuremark)
GDR 3128 für SQL Server 2012 (KB2793634) (64-bit) (Version: 11.1.3128.0 - Microsoft Corporation)
GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
Google Chrome (x32 Version: 32.0.1700.76 - Google Inc.)
Google Earth Plug-in (x32 Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
HP Officejet 6500 E710n-z - Grundlegende Software für das Gerät (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Intel Extreme Tuning Utility (x32 Version: 4.2.0.8 - Intel Corporation)
Intel Extreme Tuning Utility (x32 Version: 4.2.0.8 - Intel Corporation) Hidden
Intel(R) Control Center (x32 Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Management Engine Components (x32 Version: 9.5.10.1658 - Intel Corporation)
Intel(R) Rapid Storage Technology (x32 Version: 11.5.0.1207 - Intel Corporation)
Intel(R) Smart Connect Technology 3.0 x64 (Version: 3.0.30.1526 - Intel)
Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.8.251 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
Intel® Watchdog Timer Driver (Intel® WDT) (x32 Version:  - Intel Corporation)
Java 7 Update 45 (x32 Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
JDownloader 2 (Version: 2.0 - AppWork GmbH)
LEGO MARVEL Super Heroes (x32 Version:  - Warner Bros. Games)
Live Update 5 (x32 Version: 5.0.109 - MSI)
Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden
Logitech Gaming Software 5.10 (Version: 5.10.127 - Logitech)
Logitech Gaming Software 8.50 (Version: 8.50.281 - Logitech Inc.)
ManiaPlanet (x32 Version:  - Nadeo)
Medal of Honor (TM) (x32 Version: 1.0.0.0 - Electronic Arts)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft Office 2003 Web Components (x32 Version: 12.0.6213.1000 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Native Client (Version: 10.2.4000.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (Version: 10.2.4000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 (64-bit) (Version:  - ) Hidden
Microsoft SQL Server 2012 (64-bit) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 RsFx Driver (Version: 11.1.3000.0 - Microsoft Corporation) Hidden
Microsoft SQL Server 2012 Setup (English) (Version: 11.1.3128.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (x32 Version: 3.5.8080.0 - Microsoft Corporation) Hidden
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (Version: 3.5.8080.0 - Microsoft Corporation) Hidden
Microsoft Visual Basic for Applications 7.1 (x64) (Version: 7.1.00.00 - Microsoft Corporation) Hidden
Microsoft Visual Basic for Applications 7.1 (x64) English (Version: 7.1.0.0 - Microsoft Corporation) Hidden
Microsoft Visual Basic for Applications 7.1 (x64) German (Version: 7.1.0.0 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU (Version:  - Microsoft Corporation)
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU (Version: 8.0.52572 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2005 Tools for Applications - ENU (x32 Version:  - Microsoft Corporation)
Microsoft Visual Studio 2005 Tools for Applications - ENU (x32 Version: 8.0.50727.146 - Microsoft Corporation) Hidden
Microsoft VSS Writer for SQL Server 2012 (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0 - Microsoft Corp.)
Miranda Fusion 3.2.6.0 (x32 Version: 3.2.6.0 - Miranda Fusion Team)
Mobipocket Creator 4.2 (x32 Version: 4.2.41 - Mobipocket.com)
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 25.0 - Mozilla)
Mp3tag v2.54 (x32 Version: v2.54 - Florian Heidenreich)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation)
MusicBrainz Picard (x32 Version: 1.1 - MusicBrainz)
MyPhoneExplorer (x32 Version: 1.8.5 - F.J. Wechselberger)
Nasty File Remover v0.72 (remove only) (x32 Version:  - )
NVIDIA 3D Vision Controller-Treiber 331.65 (Version: 331.65 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 331.65 (Version: 331.65 - NVIDIA Corporation)
NVIDIA GeForce Experience 1.7 (Version: 1.7 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.65 (Version: 331.65 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.140.952 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA ShadowPlay 9.3.16 (Version: 9.3.16 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden
NVIDIA Update 9.3.16 (Version: 9.3.16 - NVIDIA Corporation) Hidden
NVIDIA Update Components (Version: 9.3.16 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.9 (Version: 1.2.9 - NVIDIA Corporation)
OkayFreedom (x32 Version: 1.2 - Steganos Software GmbH)
Origin (x32 Version: 9.1.3.2637 - Electronic Arts, Inc.)
PDF24 Creator 5.4.0 (x32 Version:  - PDF24.org)
Populous (x32 Version: 1.0.0.0 - Electronic Arts)
Project CARS (x32 Version: 0510 - WMD)
PunkBuster Services (x32 Version: 0.993 - Even Balance, Inc.)
QuickPar 0.9 (x32 Version: 0.9 - Peter B. Clements)
Rainmeter (x32 Version: 2.5 beta r1720 - )
Realtek Ethernet Controller Driver (x32 Version: 7.72.410.2013 - Realtek)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6959 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.0.7 (Version: 3.0.7 - VS Revo Group, Ltd.)
Samsung Kies (x32 Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.) Hidden
Samsung Magician (x32 Version: 4.2.1 - Samsung Electronics)
Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.)
Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0 - SAMSUNG Electronics Co., Ltd.)
Service Pack 1 für SQL Server 2012 (KB2674319) (64-bit) (Version: 11.1.3000.0 - Microsoft Corporation)
Service Pack 2 für SQL Server 2008 (KB 2285068) (64-bit) (Version: 10.2.4000.0 - Microsoft Corporation)
SHIELD Streaming (Version: 1.6.34 - NVIDIA Corporation) Hidden
SolidWorks 2014 x64 Edition SP0 (Version: 22.100.5018 - SolidWorks) Hidden
SolidWorks 2014 x64 Edition SP0 (x32 Version: 22.0.0.5018 - SolidWorks Corporation)
SolidWorks 2014 x64 German Resources (Version: 22.100.5018 - SolidWorks Corporation) Hidden
SolidWorks Composer 2014 SP0 x64 Edition (Version: 22.00.5018 - Dassault Systemes SolidWorks) Hidden
SolidWorks eDrawings 2014 x64 Edition SP0 (Version: 14.0.5006 - Dassault Systèmes SolidWorks Corp) Hidden
SolidWorks Explorer 2014 SP0 x64 Edition (Version: 22.00.5018 - SolidWorks Corporation) Hidden
SolidWorks Flow Simulation 2014 SP0 x64 Edition  (Version: 22.00.5019 - SolidWorks Corporation) Hidden
SolidWorks Plastics 2014 SP0 x64 Edition (Version: 22.00.5018 - SolidWorks Corporation) Hidden
Source SDK Base 2007 (x32 Version:  - Valve)
SpeedFan (remove only) (x32 Version:  - )
Splinter Cell: Blacklist (x32 Version: 1.01 - Ubisoft)
SQL Server 2012 Common Files (Version: 11.1.3000.0 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Services (Version: 11.1.3000.0 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Shared (Version: 11.1.3000.0 - Microsoft Corporation) Hidden
SQL Server Browser for SQL Server 2012 (x32 Version: 11.1.3000.0 - Microsoft Corporation)
Sql Server Customer Experience Improvement Program (Version: 11.1.3000.0 - Microsoft Corporation) Hidden
Steam (x32 Version: 1.0.0.0 - Valve Corporation)
Super-Charger (x32 Version: 1.2.018 - MSI)
System Requirements Lab for Intel (x32 Version: 4.5.11.0 - Husdawg, LLC)
Team Fortress 2 (x32 Version:  - Valve)
TeamSpeak 3 Client (Version: 3.0.10 - TeamSpeak Systems GmbH)
TeamViewer 8 (x32 Version: 8.0.19045 - TeamViewer)
TomTom HOME (x32 Version: 2.9.7 - Ihr Firmenname)
TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2 - TomTom International B.V.)
TreeSize Free V2.7 (x32 Version: 2.7 - JAM Software)
Update for 2007 Microsoft Office System (KB967642) (x32 Version:  - Microsoft)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (x32 Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32 Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (x32 Version:  - Microsoft)
Uplay (x32 Version: 3.0 - Ubisoft)
VBA (3821b) (x32 Version: 6.01.00.1234 - Microsoft Corporation) Hidden
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Visual Basic for Applications (R) Core - English (x32 Version: 6.5.10.32 - Microsoft Corporation) Hidden
Visual Basic for Applications (R) Core (x32 Version: 6.5.10.53 - Microsoft Corporation) Hidden
VLC media player 2.0.5 (Version: 2.0.5 - VideoLAN)
VobSub v2.23 (Remove Only) (x32 Version:  - )
VR-NetWorld (x32 Version:  - )
Vuze (x32 Version: 5.2.0.0 - Azureus Software, Inc.)
Winamp (x32 Version: 5.63  - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1 - Nullsoft, Inc)
Windows XP Mode (Version: 1.3.7600.16422 - Microsoft Corporation)
WinHTTrack Website Copier 3.47-6 (x64) (Version: 3.47.6 - HTTrack)
Winki (x32 Version: 3.2.125 - MSI)
WinRAR 4.20 (64-Bit) (Version: 4.20.0 - win.rar GmbH)
WinSCP 5.1.6 (x32 Version: 5.1.6 - Martin Prikryl)
XviD MPEG4 Video Codec (remove only) (x32 Version:  - )

==================== Restore Points  =========================

15-01-2014 22:05:46 Windows Update
19-01-2014 19:12:09 Windows-Sicherung
20-01-2014 22:38:02 Gerätetreiber-Paketinstallation: TAP-Windows Provider V9 Netzwerkadapter

==================== Hosts content: ==========================

2009-07-14 03:34 - 2013-08-09 17:31 - 00449440 ___RA C:\Windows\system32\Drivers\etc\hosts
127.0.0.1        www.007guard.com
127.0.0.1        007guard.com
127.0.0.1        008i.com
127.0.0.1        www.008k.com
127.0.0.1        008k.com
127.0.0.1        www.00hq.com
127.0.0.1        00hq.com
127.0.0.1        010402.com
127.0.0.1        www.032439.com
127.0.0.1        032439.com
127.0.0.1        www.0scan.com
127.0.0.1        0scan.com
127.0.0.1        1000gratisproben.com
127.0.0.1        www.1000gratisproben.com
127.0.0.1        1001namen.com
127.0.0.1        www.1001namen.com
127.0.0.1        100888290cs.com
127.0.0.1        www.100888290cs.com
127.0.0.1        www.100sexlinks.com
127.0.0.1        100sexlinks.com
127.0.0.1        10sek.com
127.0.0.1        www.10sek.com
127.0.0.1        www.1-2005-search.com
127.0.0.1        1-2005-search.com
127.0.0.1        123fporn.info
127.0.0.1        www.123fporn.info
127.0.0.1        123haustiereundmehr.com
127.0.0.1        www.123haustiereundmehr.com
127.0.0.1        123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

Task: {050C409A-505D-4558-ABBB-A3FCE95FB2AD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
Task: {21C26F42-B34D-4702-88EB-9CA6B615CF3F} - System32\Tasks\ScanToPCActivationApp.exe_{AD063CB6-193B-4D04-BB14-1AF681BF23C6} => C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {34A40C97-DA4E-4B69-AD0F-74713550220E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.)
Task: {D100799E-94C9-4227-A90E-7143AA573FC5} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {E55A84BF-00A1-464C-8541-913DFA654467} - System32\Tasks\FoxTab => C:\Users\cottec\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {E73298AB-85F4-40AD-A720-77D23CD57192} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.)
Task: {EE6E17AB-533D-4D77-B1A2-B351BB4E2240} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-16] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FoxTab.job => C:\Users\cottec\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-09-21 08:30 - 2013-09-21 08:30 - 00276008 _____ () C:\Program Files\SolidWorks Corp\SolidWorks\sldBodyDiffu.dll
2012-12-16 16:42 - 2012-12-16 16:42 - 00761528 _____ () C:\Program Files\Rainmeter\Rainmeter.dll
2012-12-16 16:41 - 2012-12-16 16:41 - 00011776 _____ () C:\Program Files\Rainmeter\Plugins\PowerPlugin.DLL
2014-01-24 00:29 - 2013-12-18 09:32 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-01-24 16:08 - 2014-01-24 16:08 - 00011264 _____ () C:\Users\cottec\AppData\Local\Temp\nsf5A02.tmp\System.dll
2012-12-24 00:51 - 2010-06-11 21:14 - 00004608 _____ () C:\Program Files (x86)\C2DtoG15\LgLcdLibWrapper.dll
2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\cottec\AppData\Roaming\Dropbox\bin\libcef.dll
2013-08-05 04:41 - 2013-08-05 04:41 - 00057432 _____ () C:\Program Files (x86)\MirandaFusion\zlib.dll
2008-05-03 08:59 - 2008-05-03 08:59 - 00094208 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\svc_dbepp.dll
2009-08-04 08:46 - 2009-08-04 08:46 - 00162304 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\actman.dll
2013-08-05 04:40 - 2013-08-05 04:40 - 00203869 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\aim.dll
2009-05-08 22:42 - 2009-05-08 22:42 - 00067072 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\authstate.dll
2010-02-10 19:42 - 2010-02-10 19:42 - 00117760 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\extraicons.dll
2013-03-15 09:27 - 2013-03-15 09:27 - 00322048 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\facebook.dll
2010-09-28 16:59 - 2010-09-28 16:59 - 00498688 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\fingerprint.dll
2012-05-24 19:20 - 2012-05-24 19:20 - 00110592 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\folders.dll
2013-08-05 04:41 - 2013-08-05 04:41 - 00339550 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\icq.dll
2013-08-05 04:40 - 2013-08-05 04:40 - 00379993 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\irc.dll
2011-02-09 22:56 - 2011-02-09 22:56 - 00082021 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\keepstatus.dll
2010-08-26 17:27 - 2010-08-26 17:27 - 00062976 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\menuex.dll
2012-07-18 19:39 - 2012-07-18 19:39 - 00106496 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\metacontacts.dll
2013-01-19 22:14 - 2007-10-05 19:29 - 00323584 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\mirandag15.dll
2011-07-17 18:07 - 2011-07-17 18:07 - 00671232 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\mirotr.dll
2010-04-08 19:33 - 2010-04-08 19:33 - 00240128 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\sendss.dll
2011-09-13 14:59 - 2011-09-13 14:59 - 00094315 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\startupstatus.dll
2012-11-05 21:48 - 2012-11-05 21:48 - 00372736 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\twitter.dll
2010-10-10 10:12 - 2010-10-10 10:12 - 00374272 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\uinfoexw.dll
2009-10-09 08:04 - 2009-10-09 08:04 - 00036864 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\useactions.dll
2011-09-13 14:59 - 2011-09-13 14:59 - 00114688 _____ () C:\Program Files (x86)\MirandaFusion\Plugins\variables.dll
2013-09-08 21:47 - 2013-09-08 21:47 - 00017408 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\PSIClient\e54fd507aa171a3a0a7d0cc47266a7ff\PSIClient.ni.dll
2012-12-23 18:25 - 2012-06-25 10:41 - 01198912 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-12-20 16:31 - 2013-12-20 16:31 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-01-16 17:25 - 2014-01-16 17:25 - 16287624 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/24/2014 04:08:39 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (01/24/2014 00:26:01 AM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (01/23/2014 05:25:21 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (01/22/2014 08:22:55 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (01/22/2014 07:20:56 AM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (01/21/2014 05:12:03 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (01/20/2014 11:30:20 PM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (01/19/2014 11:03:29 AM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (01/18/2014 08:32:11 AM) (Source: ISCTAgent) (User: )
Description: netDetect::AOACNetDetect::Initialize  Net Detect:  Error Loading PROSet Library Error=0x2\n

Error: (01/18/2014 08:32:00 AM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]


System errors:
=============
Error: (01/24/2014 04:09:06 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Superfetch" wurde mit folgendem Fehler beendet:
%%2

Error: (01/24/2014 04:08:51 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535

Error: (01/24/2014 04:08:51 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535

Error: (01/24/2014 04:08:51 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535

Error: (01/24/2014 04:08:51 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535

Error: (01/24/2014 04:08:51 PM) (Source: PNRPSvc) (User: )
Description: 0x80630801

Error: (01/24/2014 04:08:51 PM) (Source: PNRPSvc) (User: )
Description: 0x80630801

Error: (01/24/2014 04:08:40 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535

Error: (01/24/2014 04:08:40 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535

Error: (01/24/2014 04:08:40 PM) (Source: PNRPSvc) (User: )
Description: 0x80630801


Microsoft Office Sessions:
=========================
Error: (07/28/2013 10:02:35 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 45 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (07/18/2013 05:37:37 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (03/06/2013 00:07:38 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 52 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/21/2013 05:03:43 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 00:13:45 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 09:46:31 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 0 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/11/2013 09:20:26 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 49 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2012-12-20 22:14:12.581
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:14:10.454
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:14:10.454
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:43.050
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:43.050
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:28.753
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:26.612
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:10:26.612
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:05:29.179
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-12-20 22:05:29.179
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\MBWrp64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 32%
Total physical RAM: 8142.93 MB
Available physical RAM: 5471.67 MB
Total Pagefile: 16284.05 MB
Available Pagefile: 13213.35 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: (System) (Fixed) (Total:78.13 GB) (Free:8.57 GB) NTFS
Drive d: (Daten) (Fixed) (Total:931.51 GB) (Free:44.24 GB) NTFS
Drive e: (Software) (Fixed) (Total:160.24 GB) (Free:26.41 GB) NTFS
Drive g: (LEGO MARVEL Super Heroes) (CDROM) (Total:6.17 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: 5C539950)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=78 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=160 GB) - (Type=OF Extended)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 76AF80D4)
Partition 1: (Not Active) - (Size=932 GB) - (Type=42)

==================== End Of Log ============================


schrauber 25.01.2014 12:45

Windows DVD zur Hand?

cottec 26.01.2014 02:44

jap

schrauber 26.01.2014 08:30

"In Place Upgrade"

Bitte mal ein Inplace Upgrade machen.

cottec 26.01.2014 10:47

hm, das hab ich doch erst gemacht und danach war doch der defender erst hinüber :(

schrauber 27.01.2014 08:03

Ich les nit immer nochmal alle 60 Posts in einem Thread, sorry. Ist aber sehr merkwürdig.


Downloade dir bitte Farbar Service Scanner Farbar Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.

Poste bitte den Inhalt hier.



cottec 27.01.2014 08:32

sorry, verlangt auch niemand :)

frisches fss log ist in post #50

schrauber 27.01.2014 16:25

Windows Taste+R, schreibe cmd und drücke Enter. Schreibe nun

sc config WinDefend start =auto
sc start WinDefend

Nach jeder Zeile Enter drücken. geht er jetzt?

cottec 27.01.2014 17:11

Code:

C:\Users\cottec>sc config WinDefend start =auto
BESCHREIBUNG:
        Ändert einen Diensteintrag in der Registrierung und der Dienstdatenbank
SYNTAX:
        sc <Server> config [Dienstname] <Option1> <Option2>...

OPTIONEN:
HINWEIS: Der Optionsname enthält das Gleichheitszeichen.
        Zwischen dem Gleichheitszeichen und dem Wert muss ein Leerzeichen
        eingefügt werden.
 type= <own|share|interact|kernel|filesys|rec|adapt>
 start= <boot|system|auto|demand|disabled|delayed-auto>
 error= <normal|severe|critical|ignore>
 binPath= <Binärpfadname>
 group= <LoadOrderGroup>
 tag= <yes|no>
 depend= <Abhängigkeiten(getrennt durch / (Schrägstrich))>
 obj= <AccountName|ObjectName>
 DisplayName= <Anzeigename>
 password= <Kennwort>

Code:

C:\Users\cottec>sc start WinDefend

SERVICE_NAME: WinDefend
        TYPE              : 20  WIN32_SHARE_PROCESS
        STATE              : 2  START_PENDING
                                (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
        WIN32_EXIT_CODE    : 0  (0x0)
        SERVICE_EXIT_CODE  : 0  (0x0)
        CHECKPOINT        : 0x0
        WAIT_HINT          : 0x7d0
        PID                : 1632
        FLAGS              :


schrauber 28.01.2014 12:16

Zitat:

sc config WinDefend start =auto
den bitte nochmal, diesmal

sc config WinDefend start = auto

ein Leerzeichen hinter dem = :)

cottec 28.01.2014 17:15

geht auch nicht :D

schrauber 29.01.2014 10:56

Also ich würde jetzt das Inplace Upgrade nochmal machen, danach muss der Defender gehen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:50 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131