Hallo,
hat ein wenig gedauert - aber hier nun die Logs: Code:
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(RealNetworks, Inc.) C:\Program Files\Online Games Manager\ogmservice.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8555040 2010-04-06] (Realtek Semiconductor)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-04-06] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [CLMLServer] - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-02] (CyberLink)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-05] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN)
HKCU\...\Run: [msnmsgr] - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKCU\...\Run: [Spiele Post] - C:\Program Files\OXXOGames\GPlayer\GameCenterNotifier.exe
HKCU\...\Run: [Google Update*] - <===== ATTENTION (ZeroAccess rootkit hidden path)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.youdagames.com?hp=1
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://medion.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.medion.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ru.redirect.wrapper.services.alawar.com/startpage.php?lang=de&wspv=2.0&locale=de&pid=1669&country=DE
URLSearchHook: SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.)
SearchScopes: HKCU - {1991871C-6236-4ADC-99D1-5219501001D0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
SearchScopes: HKCU - {33524C00-63FB-43DB-A6BF-0A4E14B24649} URL = hxxp://www.basicscan.com/?prt=BscscnPB&keywords={searchTerms}
BHO: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU -Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Winsock: Catalog5 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 27 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\sc0rrgm2.default
FF SearchEngineOrder.1: Ask Search
FF SelectedSearchEngine: Ask Search
FF Homepage: hxxp://www.google.de
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @zylom.com/ZylomGamesPlayer - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\sc0rrgm2.default\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\sc0rrgm2.default\searchplugins\SweetIM Search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Yahoo! Toolbar - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\sc0rrgm2.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF Extension: hdvc - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\sc0rrgm2.default\Extensions\hdvc@hdvc.com.xpi
FF Extension: toolbar_AVIRA-V7 - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\sc0rrgm2.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\PepperFlash\pepflashplayer.dll No File
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
CHR HKLM\...\Chrome\Extension: [kpkbnefaikfaeadgidhpoanckoiaheli] - C:\Program Files\HDvidCodec.com\HDvidCodec10.crx
========================== Services (Whitelisted) =================
R2 AntiVirFirewallService; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [655928 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [622648 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
R2 ogmservice; C:\Program Files\Online Games Manager\ogmservice.exe [559552 2013-08-08] (RealNetworks, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] ()
U2 *etadpug; "C:\Program Files\Google\Desktop\Install\{63b5412a-a7d5-46c9-b511-8e92e0195ec0}\ \...\???\{63b5412a-a7d5-46c9-b511-8e92e0195ec0}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
==================== Drivers (Whitelisted) ====================
R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [92448 2013-09-05] (Avira GmbH)
R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [113024 2013-09-05] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-09-05] (Avira Operations GmbH & Co. KG)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-05] (Avira GmbH)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-09 13:01 - 2013-09-09 13:00 - 01082207 _____ (Farbar) C:\Users\XXX\Desktop\FRST.exe
2013-09-08 09:40 - 2013-09-08 19:40 - 96566691 _____ C:\Windows\system32\ಇ觚h
2013-09-05 19:57 - 2013-09-05 19:57 - 96185213 _____ C:\Windows\system32\퓕쟞c
2013-09-05 19:57 - 2013-09-05 19:56 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-09-05 19:16 - 2013-09-05 19:16 - 00000000 ____D C:\Users\XXX\AppData\Local\AskPartnerNetwork
2013-09-05 17:57 - 2013-09-05 17:57 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-09-05 17:57 - 2013-09-05 17:57 - 00000000 ____D C:\Program Files\AskPartnerNetwork
2013-09-05 17:56 - 2013-09-05 17:56 - 00002020 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-09-05 17:56 - 2013-09-05 17:56 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Avira
2013-09-05 17:56 - 2013-09-05 17:56 - 00000000 ____D C:\ProgramData\APN
2013-09-05 17:56 - 2013-09-05 17:56 - 00000000 ____D C:\Program Files\Avira
2013-09-05 17:56 - 2013-09-05 17:50 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-09-05 17:56 - 2013-09-05 17:50 - 00113024 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwot.sys
2013-09-05 17:56 - 2013-09-05 17:50 - 00092448 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwim.sys
2013-09-05 17:56 - 2013-09-05 17:50 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-09-05 17:56 - 2013-09-05 17:50 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-09-05 17:56 - 2013-09-05 17:50 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2013-09-04 17:45 - 2013-09-04 17:45 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Blue Tea Games
2013-08-28 15:56 - 2013-08-28 15:56 - 00000000 ____D C:\Users\XXX\AppData\Roaming\VendelGAMES
2013-08-28 15:55 - 2013-08-28 15:55 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Love Chronicles - Der Fluch Sammleredition
2013-08-28 15:55 - 2013-08-28 15:55 - 00000000 ____D C:\Program Files\Love Chronicles - Der Fluch Sammleredition
2013-08-25 18:48 - 2013-08-25 18:49 - 00000000 ____D C:\Program Files\Die Spurensucher
2013-08-25 18:48 - 2013-08-25 18:48 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Die Spurensucher
2013-08-17 21:08 - 2013-08-18 10:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-16 03:03 - 2013-08-16 03:06 - 00000000 ____D C:\Windows\system32\MRT
2013-08-16 03:00 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-16 03:00 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-16 03:00 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-16 03:00 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-16 03:00 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-16 03:00 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-16 03:00 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-16 03:00 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-16 03:00 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-16 03:00 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-16 03:00 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-16 03:00 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-16 03:00 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-16 03:00 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-16 03:00 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-16 03:00 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-15 09:46 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-15 09:46 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-15 09:46 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-15 09:46 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-15 09:46 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-15 09:46 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-15 09:46 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-15 09:46 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-15 09:42 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-15 09:38 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-15 09:30 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-15 09:30 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-12 16:56 - 2013-08-12 16:57 - 00000000 ____D C:\Program Files\Adelantado Trilogy - Book Two
2013-08-12 16:56 - 2013-08-12 16:56 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adelantado Trilogy - Book Two
2013-08-12 16:36 - 2013-08-12 16:36 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Liam games
2013-08-12 16:35 - 2013-08-12 16:36 - 00000000 ____D C:\Program Files\Sweet Kingdom - Verhexte Prinzessin
2013-08-12 16:35 - 2013-08-12 16:35 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sweet Kingdom - Verhexte Prinzessin
2013-08-12 11:39 - 2013-08-12 11:39 - 00236536 _____ (Big Fish Games) C:\Users\XXX\Downloads\farmscapes_s2_l2_gF6156T1L2_d2137481916.exe
2013-08-11 13:38 - 2013-08-11 13:38 - 00236536 _____ (Big Fish Games) C:\Users\XXX\Downloads\solars-abenteuer_s2_l2_gF6430T1L2_d2136859503.exe
2013-08-11 13:36 - 2013-08-11 13:36 - 00236536 _____ (Big Fish Games) C:\Users\XXX\Downloads\solars-abenteuer_s2_l2_gF6430T1L2_d2136858862.exe
2013-08-11 13:23 - 2013-08-11 13:23 - 00267072 _____ (Boonty) C:\Users\XXX\Downloads\Adelantado_Trilogy_Book_2_Downloaden{1212431}.exe
2013-08-11 12:46 - 2013-08-11 12:46 - 00000000 ____D C:\Users\XXX\AppData\Roaming\adelantado_2_boonty_de
2013-08-11 12:42 - 2013-08-11 12:42 - 00000000 ____D C:\Program Files\BoontyGames
2013-08-11 12:29 - 2013-08-11 12:29 - 00000000 ____D C:\Boonty
2013-08-11 12:23 - 2013-08-11 12:23 - 00236536 _____ (Big Fish Games) C:\Users\XXX\Downloads\adelantado-trilogy-book-two_s1_l1_gF6435T1L1_d2136823668.exe
2013-08-11 12:00 - 2013-08-11 12:00 - 00000000 ____D C:\GameHouse Games
2013-08-11 11:25 - 2013-08-11 11:25 - 00000000 ____D C:\ProgramData\Youdagames
2013-08-11 11:25 - 2013-08-11 11:25 - 00000000 ____D C:\Program Files\Youdagames
2013-08-11 09:55 - 2013-08-11 09:55 - 00000000 ____D C:\Users\XXX\AppData\Roaming\adelantado_big_fish_de
2013-08-11 09:54 - 2013-08-11 09:54 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adelantado Trilogy - Book One
2013-08-11 09:54 - 2013-08-11 09:54 - 00000000 ____D C:\Program Files\Adelantado Trilogy - Book One
==================== One Month Modified Files and Folders =======
2013-09-09 13:02 - 2013-09-09 13:02 - 00000000 ____D C:\FRST
2013-09-09 13:00 - 2013-09-09 13:01 - 01082207 _____ (Farbar) C:\Users\XXX\Desktop\FRST.exe
2013-09-09 08:37 - 2009-07-14 06:39 - 00080949 _____ C:\Windows\setupact.log
2013-09-09 08:18 - 2009-07-14 06:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-09 08:18 - 2009-07-14 06:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-09 08:17 - 2010-06-15 12:09 - 01498568 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-08 19:40 - 2013-09-08 09:40 - 96566691 _____ C:\Windows\system32\ಇ觚h
2013-09-07 01:18 - 2011-09-28 22:21 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-07 00:55 - 2012-09-23 12:28 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-06 19:18 - 2011-09-28 22:21 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-06 09:30 - 2011-09-28 22:21 - 00000000 ____D C:\Program Files\Google
2013-09-06 08:04 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-05 20:18 - 2011-09-02 15:30 - 00245930 _____ C:\Windows\PFRO.log
2013-09-05 19:57 - 2013-09-05 19:57 - 96185213 _____ C:\Windows\system32\퓕쟞c
2013-09-05 19:56 - 2013-09-05 19:57 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-09-05 19:16 - 2013-09-05 19:16 - 00000000 ____D C:\Users\XXX\AppData\Local\AskPartnerNetwork
2013-09-05 19:16 - 2011-09-28 22:21 - 00000000 ____D C:\Users\XXX\AppData\Local\Google
2013-09-05 19:16 - 2011-09-28 22:21 - 00000000 ____D C:\ProgramData\Google
2013-09-05 17:58 - 2013-07-01 12:22 - 00000000 ____D C:\Program Files\OXXOGames
2013-09-05 17:57 - 2013-09-05 17:57 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-09-05 17:57 - 2013-09-05 17:57 - 00000000 ____D C:\Program Files\AskPartnerNetwork
2013-09-05 17:56 - 2013-09-05 17:56 - 00002020 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-09-05 17:56 - 2013-09-05 17:56 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Avira
2013-09-05 17:56 - 2013-09-05 17:56 - 00000000 ____D C:\ProgramData\APN
2013-09-05 17:56 - 2013-09-05 17:56 - 00000000 ____D C:\Program Files\Avira
2013-09-05 17:56 - 2012-01-28 13:00 - 00000000 ____D C:\ProgramData\Avira
2013-09-05 17:50 - 2013-09-05 17:56 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-09-05 17:50 - 2013-09-05 17:56 - 00113024 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwot.sys
2013-09-05 17:50 - 2013-09-05 17:56 - 00092448 _____ (Avira GmbH) C:\Windows\system32\Drivers\avfwim.sys
2013-09-05 17:50 - 2013-09-05 17:56 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-09-05 17:50 - 2013-09-05 17:56 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-09-05 17:50 - 2013-09-05 17:56 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2013-09-05 15:19 - 2013-07-02 07:59 - 00000048 _____ C:\Windows\system32\games.stat
2013-09-05 13:27 - 2011-12-09 13:59 - 00000000 ____D C:\Zylom Games
2013-09-05 13:27 - 2011-12-09 13:56 - 00000000 ____D C:\Program Files\RealArcade
2013-09-04 18:46 - 2013-03-18 11:57 - 00000000 ____D C:\Users\XXX\Desktop\Spiele
2013-09-04 17:45 - 2013-09-04 17:45 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Blue Tea Games
2013-08-29 20:34 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2013-08-29 20:04 - 2011-09-02 15:25 - 01401500 _____ C:\Windows\WindowsUpdate.log
2013-08-28 17:43 - 2013-07-14 11:13 - 00000000 ____D C:\BigFishCache
2013-08-28 15:56 - 2013-08-28 15:56 - 00000000 ____D C:\Users\XXX\AppData\Roaming\VendelGAMES
2013-08-28 15:55 - 2013-08-28 15:55 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Love Chronicles - Der Fluch Sammleredition
2013-08-28 15:55 - 2013-08-28 15:55 - 00000000 ____D C:\Program Files\Love Chronicles - Der Fluch Sammleredition
2013-08-25 19:32 - 2013-04-08 20:13 - 00000000 ____D C:\Users\XXX\AppData\Roaming\AlawarEntertainment
2013-08-25 18:49 - 2013-08-25 18:48 - 00000000 ____D C:\Program Files\Die Spurensucher
2013-08-25 18:48 - 2013-08-25 18:48 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Die Spurensucher
2013-08-21 09:57 - 2012-09-23 12:28 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-08-21 09:57 - 2011-09-28 22:21 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-08-19 08:47 - 2012-07-02 15:11 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-18 10:28 - 2013-08-17 21:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-17 22:04 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-08-16 11:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-16 06:15 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-08-16 03:06 - 2013-08-16 03:03 - 00000000 ____D C:\Windows\system32\MRT
2013-08-16 03:03 - 2010-06-15 12:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-12 16:57 - 2013-08-12 16:56 - 00000000 ____D C:\Program Files\Adelantado Trilogy - Book Two
2013-08-12 16:56 - 2013-08-12 16:56 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adelantado Trilogy - Book Two
2013-08-12 16:36 - 2013-08-12 16:36 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Liam games
2013-08-12 16:36 - 2013-08-12 16:35 - 00000000 ____D C:\Program Files\Sweet Kingdom - Verhexte Prinzessin
2013-08-12 16:35 - 2013-08-12 16:35 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sweet Kingdom - Verhexte Prinzessin
2013-08-12 11:39 - 2013-08-12 11:39 - 00236536 _____ (Big Fish Games) C:\Users\XXX\Downloads\farmscapes_s2_l2_gF6156T1L2_d2137481916.exe
2013-08-11 13:38 - 2013-08-11 13:38 - 00236536 _____ (Big Fish Games) C:\Users\XXX\Downloads\solars-abenteuer_s2_l2_gF6430T1L2_d2136859503.exe
2013-08-11 13:36 - 2013-08-11 13:36 - 00236536 _____ (Big Fish Games) C:\Users\XXX\Downloads\solars-abenteuer_s2_l2_gF6430T1L2_d2136858862.exe
2013-08-11 13:23 - 2013-08-11 13:23 - 00267072 _____ (Boonty) C:\Users\XXX\Downloads\Adelantado_Trilogy_Book_2_Downloaden{1212431}.exe
2013-08-11 12:46 - 2013-08-11 12:46 - 00000000 ____D C:\Users\XXX\AppData\Roaming\adelantado_2_boonty_de
2013-08-11 12:42 - 2013-08-11 12:42 - 00000000 ____D C:\Program Files\BoontyGames
2013-08-11 12:29 - 2013-08-11 12:29 - 00000000 ____D C:\Boonty
2013-08-11 12:23 - 2013-08-11 12:23 - 00236536 _____ (Big Fish Games) C:\Users\XXX\Downloads\adelantado-trilogy-book-two_s1_l1_gF6435T1L1_d2136823668.exe
2013-08-11 12:00 - 2013-08-11 12:00 - 00000000 ____D C:\GameHouse Games
2013-08-11 11:25 - 2013-08-11 11:25 - 00000000 ____D C:\ProgramData\Youdagames
2013-08-11 11:25 - 2013-08-11 11:25 - 00000000 ____D C:\Program Files\Youdagames
2013-08-11 11:25 - 2011-12-09 14:12 - 00000000 ____D C:\Users\XXX\AppData\Roaming\YoudaGames
2013-08-11 11:25 - 2011-09-02 15:29 - 00000000 ____D C:\Users\XXX
2013-08-11 09:55 - 2013-08-11 09:55 - 00000000 ____D C:\Users\XXX\AppData\Roaming\adelantado_big_fish_de
2013-08-11 09:54 - 2013-08-11 09:54 - 00000000 ____D C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adelantado Trilogy - Book One
2013-08-11 09:54 - 2013-08-11 09:54 - 00000000 ____D C:\Program Files\Adelantado Trilogy - Book One
2013-08-10 20:08 - 2013-04-17 13:32 - 00000000 ____D C:\Users\XXX\Desktop\Zylom
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
Files to move or delete:
====================
ZeroAccess:
C:\Users\XXX\AppData\Local\Google\Desktop\Install\{63b5412a-a7d5-46c9-b511-8e92e0195ec0}
ZeroAccess:
C:\Program Files\Google\Desktop\Install\{63b5412a-a7d5-46c9-b511-8e92e0195ec0}
C:\Users\XXX\AppData\Local\Temp\bfguni.exe
C:\Users\XXX\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\XXX\AppData\Local\Temp\GenericUninstall.exe
C:\Users\XXX\AppData\Local\Temp\GoogleToolbarInstaller_en32_signed.exe
C:\Users\XXX\AppData\Local\Temp\mgsqlite3.dll
C:\Users\XXX\AppData\Local\Temp\Uninstaller-1876.exe
C:\Users\XXX\AppData\Local\Temp\uninstaller.exe
C:\Users\XXX\AppData\Local\Temp\WSSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
C:\Program Files\Windows Defender\mpsvc.dll => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
LastRegBack: 2013-09-01 16:22
==================== End Of Log ============================ Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 09-09-2013
Ran by XXX at 2013-09-09 13:03:38
Running from C:\Users\XXX\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
A Gnome's Home: Der Kristall des Lebens
Adelantado Trilogy - Book One
Adelantado Trilogy - Book Two
Adelantado Trilogy Book Two de (Version: de)
Adelantado Trilogy: Book One
Adelantado Trilogy: Book Two
Adobe Flash Player 11 ActiveX (Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (Version: 11.8.800.94)
Adobe Reader XI (11.0.03) - Deutsch (Version: 11.0.03)
AION Free-To-Play (Version: 2.70.0000)
Alchemy
Alice Greenfingers 2
Apothecarium - The Renaissance of Evil Premium Edition
ATI Catalyst Install Manager (Version: 3.0.769.0)
Avira Internet Security (Version: 13.0.0.4052)
Avira SearchFree Toolbar plus Web Protection (Version: 12.2.2.663)
Barn Yarn Premium Edition
Bau der Großen Mauer in China
Big City Adventure(TM) - Paris Classic
Big Fish: Game Manager (Version: 3.2.0.4)
Bing Bar (Version: 7.1.391.0)
Brink of Consciousness - The Lonely Hearts Murders
Catalyst Control Center Core Implementation (Version: 2010.0406.2133.36843)
Catalyst Control Center Graphics Full Existing (Version: 2010.0406.2133.36843)
Catalyst Control Center Graphics Full New (Version: 2010.0406.2133.36843)
Catalyst Control Center Graphics Light (Version: 2010.0406.2133.36843)
Catalyst Control Center Graphics Previews Vista (Version: 2010.0406.2133.36843)
Catalyst Control Center InstallProxy (Version: 2010.0406.2133.36843)
Catalyst Control Center Localization All (Version: 2010.0406.2133.36843)
CCC Help Danish (Version: 2010.0406.2132.36843)
CCC Help Dutch (Version: 2010.0406.2132.36843)
CCC Help English (Version: 2010.0406.2132.36843)
CCC Help Finnish (Version: 2010.0406.2132.36843)
CCC Help French (Version: 2010.0406.2132.36843)
CCC Help German (Version: 2010.0406.2132.36843)
CCC Help Italian (Version: 2010.0406.2132.36843)
CCC Help Japanese (Version: 2010.0406.2132.36843)
CCC Help Norwegian (Version: 2010.0406.2132.36843)
CCC Help Spanish (Version: 2010.0406.2132.36843)
CCC Help Swedish (Version: 2010.0406.2132.36843)
ccc-core-static (Version: 2010.0406.2133.36843)
ccc-utility (Version: 2010.0406.2133.36843)
Cursed Fates: Der kopflose Reiter Sammleredition
CyberLink LabelPrint (Version: 2.5.2515)
CyberLink Power2Go (Version: 6.1.3602c)
CyberLink PowerDVD Copy (Version: 1.5.1306)
Dark Parables: Der Orden der Rotkäppchen
Dark Parables: Dornröschens Fluch Sammleredition
Delicious - Emily's Holiday Season
Delicious - Emily's True Love Deluxe
Delicious - Emily's Wonder Wedding Premium Edition
Delicious 2 Deluxe
Detective Quest: Der gläserne Schuh Sammleredition
Die Spurensucher
Double Pack Farm Craft Deluxe
Dreamscapes - The Sandman Premium Edition
Eternal Journey - New Atlantis
Farm Fables
Farmington Tales
Gameforge Live 1.0 "Legend" (Version: 1.1.1724)
Gardens Inc. - From Rakes to Riches
Gardenscapes - Mansion Makeover Premium Edition
Go! Go! Rescue Squad!
Google Update Helper (Version: 1.3.21.153)
Hidden Wonders of the Depths 3: Das Abenteuer Atlantis
House of 1,000 Doors - The Palm of Zoroaster
Im Land der Wikinger
Intel(R) Control Center (Version: 1.2.1.1007)
Intel(R) Rapid Storage Technology (Version: 9.6.0.1014)
Jack of All Tribes
Jane`s Hotel: Family Hero
Jane's Hotel
Jane's Hotel Mania
Java Auto Updater (Version: 2.0.2.1)
Java(TM) 6 Update 20 (Version: 6.0.200)
Jojo's Fashion Show 2
Jojos Fashion Show World Tour
Jo's Dream - Organic Coffee
Junk Mail filter update (Version: 14.0.8117.416)
Love Chronicles: Der Fluch Sammleredition
Mahjong Fortuna 2
Medion Home Cinema (Version: 6.0.0000)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Office 2010 (Version: 14.0.4763.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [DEU] (Version: 3.1.0000)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0)
Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft XNA Framework Redistributable 3.1 (Version: 3.1.10527.0)
MOAI: Erschaffe deinen Traum
Mozilla Firefox 23.0.1 (x86 de) (Version: 23.0.1)
Mozilla Maintenance Service (Version: 23.0.1)
MSVCRT (Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Mystery P.I. - The Lottery Ticket
NC Launcher (GameForge)
Northern Tale
Online Games Manager v1.21 (Version: 1.21.2)
Otherworld: Frühling der Schatten Sammleredition
PlayReady PC Runtime x86 (Version: 1.3.0)
Rainforest Adventure
Realtek High Definition Audio Driver (Version: 6.0.1.6083)
Rescue Team
Sally's Spa
SCRABBLE
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
Spirit Walkers - Curse of the Cypress Witch
Stray Souls - Dollhouse Story
Sweet Kingdom: Verhexte Prinzessin
TeamSpeak 3 Client
Temple of Life - The Legend of Four Elements
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Virtual Villagers: Eine neue Heimat
Virtual Villagers: The Secret City
Web of Deceit: Die Schwarze Witwe
Windows Live Call (Version: 14.0.8117.0416)
Windows Live Communications Platform (Version: 14.0.8117.416)
Windows Live Essentials (Version: 14.0.8117.0416)
Windows Live Essentials (Version: 14.0.8117.416)
Windows Live Fotogalerie (Version: 14.0.8117.416)
Windows Live Mail (Version: 14.0.8117.0416)
Windows Live Messenger (Version: 14.0.8117.0416)
Windows Live Movie Maker (Version: 14.0.8117.0416)
Windows Live Sync (Version: 14.0.8117.416)
Windows Live Writer (Version: 14.0.8117.0416)
Windows Live-Uploadtool (Version: 14.0.8014.1029)
Youda Camper
Youda Marina
Zylom Games Player Plugin
==================== Restore Points =========================
25-08-2013 17:00:15 Windows-Sicherung
27-08-2013 07:02:31 Windows Update
29-08-2013 18:19:58 Windows Defender Checkpoint
01-09-2013 17:00:14 Windows-Sicherung
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {021B449A-E7E1-4E39-90DC-C3D78AFA0226} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation)
Task: {0D9B5D92-3A22-486D-A887-3AA21597CF27} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started
Task: {10CB5600-0123-4232-8438-9AA399E04448} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-28] (Google Inc.)
Task: {32F34F71-D8C3-4CCD-9AEA-91784432012A} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation)
Task: {7D31B9C4-C25B-40F9-8672-04F686C7B527} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-21] (Adobe Systems Incorporated)
Task: {A0378ADB-028E-4568-999F-01ED3EB8C8E3} - System32\Tasks\RunAsStdUser Task => C:\Users\Marei\AppData\Local\teeveewatchSA\bin\1.0.2.0\TeeveeWatchSA.exe
Task: {A9E60491-D3E1-4B83-B992-45240C7872D7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-28] (Google Inc.)
Task: {D20AE8FA-E59F-4C54-AF70-A0EA4E255CEE} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\System32\sdengin2.dll [2010-11-20] (Microsoft Corporation)
Task: {FA053E9E-22A8-4310-9FA2-756CCB753971} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-08-16 11:15 - 2013-08-16 11:15 - 00452608 _____ (Intel Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\0149e914e4cfbde7da65d4558af19ce0\IAStorUtil.ni.dll
2009-11-02 14:20 - 2009-11-02 14:20 - 00619816 ____N () C:\Program Files\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 14:23 - 2009-11-02 14:23 - 00013096 ____N () C:\Program Files\CyberLink\Power2Go\CLMLSvcPS.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00106496 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3748.36923__90ba9c70f846762e\MOM.Implementation.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00032768 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3748.36815__90ba9c70f846762e\LOG.Foundation.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00036864 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3748.36818__90ba9c70f846762e\LOG.Foundation.Private.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00065536 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3748.36921__90ba9c70f846762e\LOG.Foundation.Implementation.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00005632 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3748.36819__90ba9c70f846762e\MOM.Foundation.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00020480 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3748.36819__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00019456 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3748.36923__90ba9c70f846762e\CCC.Implementation.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00015360 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3748.36816__90ba9c70f846762e\NEWAEM.Foundation.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00098304 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3748.36816__90ba9c70f846762e\CLI.Foundation.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00057344 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3748.36825__90ba9c70f846762e\CLI.Component.SkinFactory.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00028672 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3748.36923__90ba9c70f846762e\CLI.Foundation.XManifest.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00061440 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3748.36824__90ba9c70f846762e\CLI.Component.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3748.36821__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00040960 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3748.36820__90ba9c70f846762e\CLI.Foundation.Private.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00005632 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3748.36820__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00032768 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00045056 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.3748.36822__90ba9c70f846762e\AEM.Server.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00006144 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3748.36822__90ba9c70f846762e\AEM.Server.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00045056 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3748.36936__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00006656 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3748.36928__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00007168 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3748.36817__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00006144 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3748.36821__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00045056 _____ (ATI Technologies Inc.) C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00016384 _____ (ATI Technologies Inc.) C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00006656 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3748.36825__90ba9c70f846762e\DEM.Graphics.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00380928 _____ (Advanced Mirco Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3748.36826__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00151552 _____ (Advanced Mirco Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3748.36819__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00005632 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3748.36826__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00008192 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3748.36820__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00007168 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3748.36824__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00020480 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3748.36837__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00020480 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3748.36825__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00040960 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3748.36855__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00077824 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3748.36907__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00008704 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3748.36849__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00028672 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3748.36837__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00069632 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3748.36886__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00045056 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3748.36877__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00036864 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3748.36884__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00032768 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3748.36837__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00065536 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3748.36876__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00065536 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3748.36891__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00057344 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3748.36891__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00102400 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3748.36877__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00040960 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3748.36886__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00053248 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3748.36847__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00065536 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3748.36867__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00028672 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3748.36847__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00013824 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Runtime\2.0.3748.36965__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00013312 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Runtime\2.0.3748.36963__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00065536 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3748.36907__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00053248 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3748.36876__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00045056 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3748.36929__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00016384 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00009728 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Shared\2.0.3748.36929__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3748.36837__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00040960 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3748.36883__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00024576 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3748.36882__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00053248 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3748.36875__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00007168 _____ ( ) C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00061440 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\APM.Server\2.0.3748.36823__90ba9c70f846762e\APM.Server.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00020480 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.3748.36817__90ba9c70f846762e\APM.Foundation.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00007168 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3748.36822__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00005632 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3748.36936__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00005632 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3748.36821__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00577536 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3748.36917__90ba9c70f846762e\CLI.Component.Systemtray.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00040960 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3748.36830__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00405504 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3748.36843__90ba9c70f846762e\CLI.Component.Wizard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00007680 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3748.36817__90ba9c70f846762e\CLI.Component.Client.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00020480 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3748.36818__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00011776 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3748.36842__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00040960 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3748.36843__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00016384 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3748.36843__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00094208 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3748.36892__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00409600 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3748.36900__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 01708032 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager2.Graphics.Wizard\2.0.3748.36963__90ba9c70f846762e\CLI.Aspect.DisplaysManager2.Graphics.Wizard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00204800 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3748.36850__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00741376 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Implementation\2.0.3748.36957__90ba9c70f846762e\ResourceManagement.Foundation.Implementation.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 01220608 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3748.36832__90ba9c70f846762e\CLI.Component.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00024576 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3748.36818__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00010240 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3748.36831__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00073728 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3748.36836__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00016384 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3748.36836__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00065536 _____ (Advanced Mirco Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3748.36931__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00196608 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3748.36850__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 01294336 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager2.Graphics.Dashboard\2.0.3748.36959__90ba9c70f846762e\CLI.Aspect.DisplaysManager2.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00094208 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3748.36883__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00397312 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3748.36876__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00376832 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3748.36871__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00356352 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3748.36892__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00573440 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3748.36851__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00856064 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3748.36878__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
2010-06-15 13:07 - 2010-06-15 13:07 - 00184320 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Dashboard\2.0.3748.36965__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Dashboard.dll
2013-08-17 21:08 - 2013-08-17 21:08 - 03551640 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2011-09-30 19:06 - 2010-11-20 14:19 - 00232448 _____ (Microsoft Corporation) \\.\globalroot\systemroot\system32\mswsock.dll
2013-07-16 08:17 - 2013-07-16 08:17 - 16166280 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll
==================== Alternate Data Streams (whitelisted) ==========
AlternateDataStreams: C:\ProgramData:gs5sys
AlternateDataStreams: C:\Users\All Users:gs5sys
AlternateDataStreams: C:\Users\XXX:gs5sys
AlternateDataStreams: C:\ProgramData\Anwendungsdaten:gs5sys
AlternateDataStreams: C:\ProgramData\Application Data:gs5sys
AlternateDataStreams: C:\ProgramData\Temp:01690B01
AlternateDataStreams: C:\ProgramData\Temp:097FF903
AlternateDataStreams: C:\ProgramData\Temp:12A012A1
AlternateDataStreams: C:\ProgramData\Temp:12D21A9A
AlternateDataStreams: C:\ProgramData\Temp:1A8FDBA3
AlternateDataStreams: C:\ProgramData\Temp:2701CA70
AlternateDataStreams: C:\ProgramData\Temp:2CB9631F
AlternateDataStreams: C:\ProgramData\Temp:2F384CF4
AlternateDataStreams: C:\ProgramData\Temp:2F5A06FD
AlternateDataStreams: C:\ProgramData\Temp:3651A580
AlternateDataStreams: C:\ProgramData\Temp:4E6B8D68
AlternateDataStreams: C:\ProgramData\Temp:4EE323A4
AlternateDataStreams: C:\ProgramData\Temp:54531C7D
AlternateDataStreams: C:\ProgramData\Temp:56F368C9
AlternateDataStreams: C:\ProgramData\Temp:57B2B96C
AlternateDataStreams: C:\ProgramData\Temp:57EE48CA
AlternateDataStreams: C:\ProgramData\Temp:60C897F3
AlternateDataStreams: C:\ProgramData\Temp:6BEADDC0
AlternateDataStreams: C:\ProgramData\Temp:73461BFA
AlternateDataStreams: C:\ProgramData\Temp:7920E530
AlternateDataStreams: C:\ProgramData\Temp:79C6A9CE
AlternateDataStreams: C:\ProgramData\Temp:7BB584AA
AlternateDataStreams: C:\ProgramData\Temp:81653DC8
AlternateDataStreams: C:\ProgramData\Temp:819394CC
AlternateDataStreams: C:\ProgramData\Temp:84FA02E7
AlternateDataStreams: C:\ProgramData\Temp:8967C154
AlternateDataStreams: C:\ProgramData\Temp:89FC8EEB
AlternateDataStreams: C:\ProgramData\Temp:8B3C3098
AlternateDataStreams: C:\ProgramData\Temp:9524D821
AlternateDataStreams: C:\ProgramData\Temp:961B4D58
AlternateDataStreams: C:\ProgramData\Temp:AE289451
AlternateDataStreams: C:\ProgramData\Temp:C69BA1D0
AlternateDataStreams: C:\ProgramData\Temp:D01ACC06
AlternateDataStreams: C:\ProgramData\Temp:D3A8AA31
AlternateDataStreams: C:\ProgramData\Temp:DCB27118
AlternateDataStreams: C:\ProgramData\Temp:E153075C
AlternateDataStreams: C:\ProgramData\Temp:E4BC4A41
AlternateDataStreams: C:\ProgramData\Temp:E6708F08
AlternateDataStreams: C:\ProgramData\Temp:EC0279DC
AlternateDataStreams: C:\ProgramData\Templates:gs5sys
AlternateDataStreams: C:\ProgramData\Vorlagen:gs5sys
AlternateDataStreams: C:\Users\XXX\Anwendungsdaten:gs5sys
AlternateDataStreams: C:\Users\XXX\Cookies:gs5sys
AlternateDataStreams: C:\Users\XXX\Lokale Einstellungen:gs5sys
AlternateDataStreams: C:\Users\XXX\Vorlagen:gs5sys
AlternateDataStreams: C:\Users\XXX\Desktop\desktop.ini:gs5sys
AlternateDataStreams: C:\Users\XXX\AppData\Local:gs5sys
AlternateDataStreams: C:\Users\XXX\AppData\Roaming:gs5sys
AlternateDataStreams: C:\Users\XXX\AppData\Local\Anwendungsdaten:gs5sys
AlternateDataStreams: C:\Users\XXX\AppData\Local\Verlauf:gs5sys
AlternateDataStreams: C:\Users\XXX\Documents\desktop.ini:gs5sys
AlternateDataStreams: C:\Users\Public\Documents\desktop.ini:gs5sys
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/07/2013 04:47:19 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0xbe8
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (09/07/2013 04:46:19 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0x5f8
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (09/07/2013 04:45:19 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0xbd0
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (09/07/2013 04:44:19 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0xcb8
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (09/07/2013 04:43:19 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0x16d0
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (09/07/2013 04:42:19 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0x4f4
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (09/07/2013 04:41:18 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0xce4
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (09/07/2013 04:40:18 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0x11d4
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (09/07/2013 04:39:18 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0x15fc
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (09/07/2013 04:38:18 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0x678
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
System errors:
=============
Error: (09/09/2013 08:13:57 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet:
%%5
Error: (09/08/2013 09:41:50 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet:
%%5
Error: (09/07/2013 09:49:31 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet:
%%5
Error: (09/06/2013 08:06:37 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet:
%%5
Error: (09/05/2013 08:21:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet:
%%5
Error: (09/05/2013 08:17:16 PM) (Source: DCOM) (User: )
Description: {FCC74B77-EC3E-4DD8-A80B-008A702075A9}
Error: (09/05/2013 07:16:38 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira FireWall" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (09/05/2013 06:01:06 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet:
%%5
Error: (09/05/2013 07:51:30 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet:
%%5
Error: (09/04/2013 06:35:19 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet:
%%5
Microsoft Office Sessions:
=========================
Error: (09/07/2013 04:47:19 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc100unknown0.0.0.000000000c000000500000000be801ceabd9274e52ddC:\Windows\System32\svchost.exeunknown6506c49f-17cc-11e3-944a-6c626d569544
Error: (09/07/2013 04:46:19 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc100unknown0.0.0.000000000c0000005000000005f801ceabd9037abcdeC:\Windows\System32\svchost.exeunknown412e6bdf-17cc-11e3-944a-6c626d569544
Error: (09/07/2013 04:45:19 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc100unknown0.0.0.000000000c000000500000000bd001ceabd8dfa4c57eC:\Windows\System32\svchost.exeunknown1d58747f-17cc-11e3-944a-6c626d569544
Error: (09/07/2013 04:44:19 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc100unknown0.0.0.000000000c000000500000000cb801ceabd8bbcece1eC:\Windows\System32\svchost.exeunknownf9827d1f-17cb-11e3-944a-6c626d569544
Error: (09/07/2013 04:43:19 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc100unknown0.0.0.000000000c00000050000000016d001ceabd897f8d6beC:\Windows\System32\svchost.exeunknownd5ac85bf-17cb-11e3-944a-6c626d569544
Error: (09/07/2013 04:42:19 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc100unknown0.0.0.000000000c0000005000000004f401ceabd874207dfeC:\Windows\System32\svchost.exeunknownb1d68e5f-17cb-11e3-944a-6c626d569544
Error: (09/07/2013 04:41:18 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc100unknown0.0.0.000000000c000000500000000ce401ceabd85048253dC:\Windows\System32\svchost.exeunknown8dfe359f-17cb-11e3-944a-6c626d569544
Error: (09/07/2013 04:40:18 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc100unknown0.0.0.000000000c00000050000000011d401ceabd82c722dddC:\Windows\System32\svchost.exeunknown6a25dcde-17cb-11e3-944a-6c626d569544
Error: (09/07/2013 04:39:18 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc100unknown0.0.0.000000000c00000050000000015fc01ceabd80899d51dC:\Windows\System32\svchost.exeunknown464d841e-17cb-11e3-944a-6c626d569544
Error: (09/07/2013 04:38:18 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc100unknown0.0.0.000000000c00000050000000067801ceabd7e4c3ddbdC:\Windows\System32\svchost.exeunknown22778cbe-17cb-11e3-944a-6c626d569544
==================== Memory info ===========================
Percentage of memory in use: 44%
Total physical RAM: 3063.11 MB
Available physical RAM: 1702.25 MB
Total Pagefile: 6124.52 MB
Available Pagefile: 4303.22 MB
Total Virtual: 2047.88 MB
Available Virtual: 1892.85 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:900.41 GB) (Free:810.54 GB) NTFS
Drive d: (Recover) (Fixed) (Total:30 GB) (Free:7.32 GB) NTFS
Drive g: () (Removable) (Total:0.96 GB) (Free:0.94 GB) FAT
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=900 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=30 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
========================================================
Disk: 2 (Size: 984 MB) (Disk ID: 00F69425)
Partition 1: (Active) - (Size=984 MB) - (Type=0E)
==================== End Of Log ============================ |