|
Plagegeister aller Art und deren Bekämpfung: Firefox ProblemWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
26.08.2013, 19:07 | #1 |
| Firefox Problem Guten Aben leibese TB Team, ich habe seit längerem ein Probelm mit Firefox, dass ich schon ein paar mal hatte. Es ging dann aber immer weg nachdem ich mit SpyHunter gescannt habe. SpyHunter habe ich schon mit der Hilfe von euch beseitigt. Da noch mal ein dickes Danke an cosinus. Das Problem ist folgendes: Wenn ich auf Yt zB auf 'später ansehen' klicke kommt ein weiser Bildschirm. Ebenfals komme ich nicht auf die vorherige Seite die ich besucht habe. Auch durch wiederholtes drücken des ''zurück Pfeils'' ändert sich die Seite nicht. Sie wird lediglich neugeladen. Wie kann ich sowas wegbekommen? Ich weiß nicht ob das hier im richtigen Thread ist, aber ich denke mal das passt schon. Mit stets freundlichen Grüßen, Minter |
26.08.2013, 19:42 | #2 |
/// the machine /// TB-Ausbilder | Firefox Problem hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
26.08.2013, 19:49 | #3 |
| Firefox ProblemFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-08-2013 Ran by Moritz (administrator) on 26-08-2013 20:46:46 Running from C:\Users\Moritz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Adobe Systems Incorporated) c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Windows\system32\mfevtps.exe (Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe (Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\CCDashServer.exe () C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe () C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe () C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe () C:\Program Files\Plantronics\GameCom780\GameCom780.exe (PC Drivers Headquarters) C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Huawei Technologies Co., Ltd.) C:\Users\Moritz\AppData\Roaming\Telekom Internet Manager\ouc.exe (Akamai Technologies, Inc.) C:\Users\Moritz\AppData\Local\Akamai\netsession_win.exe () C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe (Akamai Technologies, Inc.) C:\Users\Moritz\AppData\Local\Akamai\netsession_win.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (CyberLink Corp.) C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe (cyberlink) C:\Program Files (x86)\Cyberlink\Shared files\brs.exe () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe (Aeria Games & Entertainment) C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe () C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Dell Products, LP.) c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe (McAfee, Inc.) C:\Program Files\McAfee.com\Agent\mcagent.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (McAfee, Inc.) c:\PROGRA~2\mcafee\SITEAD~1\saui.exe () C:\Users\Moritz\Downloads\FRST64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [626552 2012-04-09] (Alps Electric Co., Ltd.) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-02-14] (IDT, Inc.) HKLM\...\Run: [QuickSet] - c:\Program Files\Dell\QuickSet\QuickSet.exe [4365984 2012-03-12] (Dell Inc.) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] () HKLM\...\Run: [IntelMyWiFiDashboard] - C:\Program Files\Intel\WiFi\bin\CCDashServer.exe [4966912 2012-03-30] (Intel® Corporation) HKLM\...\Run: [BLEServicesCtrl] - C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [120592 2012-01-10] () HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2012-01-12] (Intel Corporation) HKLM\...\Run: [DellStage] - C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj [483424 2012-02-01] () HKLM\...\Run: [Stage Remote] - C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe [2022976 2011-06-28] () HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated) HKLM\...\Run: [GamecomSound] - C:\Program Files\Plantronics\GameCom780\GameCom780.exe [777448 2011-12-01] () HKCU\...\Run: [Driver Whiz] - C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [3527608 2012-11-12] (PC Drivers Headquarters) HKCU\...\Run: [HW_OPENEYE_OUC_Telekom Internet Manager] - C:\Program Files (x86)\Telekom\InternetManager_H\UpdateDog\ouc.exe [116064 2010-12-28] (Huawei Technologies Co., Ltd.) HKCU\...\Run: [Driver Detective] - C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [3527608 2012-11-12] (PC Drivers Headquarters) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Moritz\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [Dxtory Update Checker 2.0] - C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software) MountPoints2: {19fc124d-dfcf-11e1-abd9-806e6f6e6963} - E:\setup.exe HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [577024 2012-03-07] (Creative Technology Ltd) HKLM-x32\...\Run: [Dell DataSafe Online] - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.) HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2010-10-01] (CyberLink Corp.) HKLM-x32\...\Run: [PDVD9LanguageShortcut] - C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-09-18] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe [76872 2012-03-27] (cyberlink) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [37960 2013-05-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [NeroLauncher] - C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe [66872 2012-03-11] () HKLM-x32\...\Run: [AccuWeatherWidget] - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj [2835443 2012-02-01] () HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [DataCardMonitor] - C:\Program Files (x86)\Telekom\InternetManager_H\DataCardMonitor.exe [259424 2013-04-10] (Huawei Technologies Co., Ltd.) HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [1532992 2013-03-13] (McAfee, Inc.) HKLM-x32\...\Run: [Aeria Ignite] - C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-15] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: 0 [97280 2009-07-14] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: ProxTube - {0AA2810A-F009-4BD7-A10A-32F140A1B9F3} - C:\Users\Moritz\AppData\LocalLow\ProxTube\IE\ProxTube.dll (Malte Goetz) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\h9173mwg.default FF Homepage: hxxp://www.google.de/ FF NetworkProxy: "http", "www-proxy.t-online.de" FF NetworkProxy: "http_port", 80 FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @mcafee.com/MVT - C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll (McAfee, Inc.) FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: No Name - C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\h9173mwg.default\Extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com FF Extension: info - C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\h9173mwg.default\Extensions\info@maltegoetz.de.xpi FF Extension: om - C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\h9173mwg.default\Extensions\om@offermosquito.com.xpi FF Extension: No Name - C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\h9173mwg.default\Extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) CHR Plugin: (McAfee Virtual Technician) - C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll (McAfee, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () CHR Extension: (Google Docs) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (ProxTube) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\chakodcglgpacmjpjfaoopegbglbollk\1.1.35_0 CHR Extension: (Google Search) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (SiteAdvisor) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0 CHR Extension: (OfferMosquito) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\0.5_0 CHR Extension: (Plus-HD-2.2) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.23.53_0 CHR Extension: (Google Wallet Service) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.9_0 CHR Extension: (SeeSimilar) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pggagllhehfjjfgnfnfkjedjlmbchamf\1.0.0.5_0 CHR Extension: (Gmail) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [chakodcglgpacmjpjfaoopegbglbollk] - C:\Users\Moritz\AppData\LocalLow\ProxTube\CHROME\ProxTube.crx CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx CHR HKLM-x32\...\Chrome\Extension: [pggagllhehfjjfgnfnfkjedjlmbchamf] - C:\Users\Moritz\AppData\Roaming\SeeSimilar\SeeSimilar.crx ==================== Services (Whitelisted) ================= S2 CLKMSVC10_9EC60124; C:\Program Files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe [242448 2012-03-27] (CyberLink) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3128856 2012-02-28] (devolo AG) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [344928 2011-01-28] () R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-03-28] (Intel Corporation) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [384048 2013-02-25] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [241456 2013-02-19] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218760 2013-02-19] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-02-19] (McAfee, Inc.) R2 MOBKbackup; C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe [231224 2010-04-13] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-03-29] () R2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe [132056 2012-07-17] (Symantec Corporation) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-03-29] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-02-19] (McAfee, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.) R3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-03-28] (Intel Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179280 2013-02-19] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [309840 2013-02-19] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [515968 2013-02-19] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [771536 2013-02-19] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106552 2013-02-19] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340216 2013-02-19] (McAfee, Inc.) R1 MOBKFilter; C:\Windows\System32\DRIVERS\MOBK.sys [66040 2010-04-13] (Mozy, Inc.) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2012-01-31] (CACE Technologies) R3 PlantronicsGC; C:\Windows\System32\drivers\PLTGC.sys [1327104 2011-11-05] (C-Media Electronics Inc) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) U3 mfeavfk01; No ImagePath S3 xhunter1; \??\C:\Windows\xhunter1.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-26 19:48 - 2013-08-26 19:48 - 00000000 ____D C:\Program Files (x86)\Dell Digital Delivery 2013-08-25 20:11 - 2013-08-25 20:11 - 01170448 _____ C:\Users\Moritz\Documents\Themen Welt.world 2013-08-25 12:31 - 2013-08-25 12:32 - 03076208 _____ (pepsoft.org) C:\Users\Moritz\worldpainter_64_1.5.5.exe 2013-08-24 21:17 - 2013-08-24 21:17 - 06445065 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta(1).exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 20:18 - 2013-08-23 20:18 - 00903080 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jxpiinstall.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-23 20:11 - 2013-08-23 20:11 - 00000000 ____D C:\Program Files\Java 2013-08-21 19:22 - 2013-08-21 19:22 - 00011688 _____ C:\Users\Moritz\Downloads\stereofunk.zip 2013-08-17 20:44 - 2013-08-17 20:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-16 08:20 - 2013-08-16 08:20 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie - Kopie (2) 2013-08-14 23:02 - 2013-08-14 23:02 - 00000000 ____D C:\Users\Public\Desktop\CC Support 2013-08-14 23:01 - 2013-08-14 23:01 - 04009167 _____ C:\Users\Moritz\Desktop\ServicesRepair.exe 2013-08-14 21:15 - 2013-08-14 21:15 - 00003160 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-14 17:34 - 2013-08-14 17:34 - 00000207 _____ C:\Windows\tweaking.com-regbackup-MORITZ-PC-Microsoft-Windows-7-Home-Premium-(64-Bit).dat 2013-08-14 17:34 - 2013-08-14 17:34 - 00000000 ____D C:\RegBackup 2013-08-14 17:05 - 2013-08-14 21:13 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-08-14 17:04 - 2013-08-14 17:34 - 03263349 _____ C:\Users\Moritz\Downloads\tweaking.com_windows_repair_aio.zip 2013-08-14 16:05 - 2013-08-14 16:05 - 00357085 _____ (Farbar) C:\Users\Moritz\Downloads\FSS.exe 2013-08-14 16:05 - 2013-08-14 16:05 - 00002285 _____ C:\Users\Moritz\Downloads\FSS.txt 2013-08-14 09:57 - 2013-08-14 09:57 - 00001785 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iTunes 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iPod 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-14 09:43 - 2013-08-23 20:11 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-14 09:39 - 2013-08-14 09:42 - 33150376 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jre-7u25-windows-x64.exe 2013-08-14 09:31 - 2013-08-14 09:31 - 01069032 _____ (Solid State Networks) C:\Users\Moritz\Downloads\install_flashplayer11x32_ltr5x64d_awc_aih.exe 2013-08-14 09:22 - 2013-08-14 09:22 - 00001071 _____ C:\Users\Moritz\Desktop\Secunia PSI.lnk 2013-08-14 09:21 - 2013-08-14 09:21 - 03272136 _____ (Secunia) C:\Users\Moritz\Downloads\PSISetup711.exe 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Users\Moritz\AppData\Local\Secunia PSI 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-08-13 15:33 - 2013-08-13 15:33 - 00000000 ____D C:\FRST 2013-08-13 15:04 - 2013-08-13 15:04 - 00000243 _____ C:\Users\Moritz\Downloads\Search.txt 2013-08-13 13:15 - 2013-08-13 13:15 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin 2013-08-13 13:14 - 2013-08-13 13:14 - 03541664 _____ (Aeria Games & Entertainment) C:\Users\Moritz\Downloads\aeria_ignite_install(1).exe 2013-08-13 10:48 - 2013-08-13 10:48 - 00165376 _____ C:\Users\Moritz\Downloads\SystemLook_x64.exe 2013-08-13 10:39 - 2013-08-13 17:04 - 00043246 _____ C:\Users\Moritz\Downloads\SystemLook.txt 2013-08-13 09:45 - 2013-08-13 09:45 - 00000000 ____D C:\Windows\D4EFA08DA1924007987D71BFF23B2F8F.TMP 2013-08-12 17:27 - 2013-08-12 17:27 - 02347384 _____ (ESET) C:\Users\Moritz\Downloads\esetsmartinstaller_enu.exe 2013-08-12 17:08 - 2013-08-12 17:08 - 00002958 _____ C:\Users\Moritz\Documents\....txt 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Malwarebytes 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-12 16:57 - 2013-08-12 16:57 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Moritz\Downloads\mbam-setup-1.75.0.1300.exe 2013-08-12 16:24 - 2013-08-12 16:25 - 00959697 _____ (Oleg N. Scherbakov) C:\Users\Moritz\Downloads\JRT (1).exe 2013-08-12 16:22 - 2013-08-12 16:22 - 00003122 _____ C:\Windows\System32\Tasks\{1EA7E4A0-B683-44E3-A658-ECE1ECBF2E94} 2013-08-12 16:22 - 2013-08-12 16:22 - 00000000 ____D C:\Windows\ERUNT 2013-08-12 16:20 - 2013-08-12 16:20 - 00959697 _____ (Oleg N. Scherbakov) C:\Users\Moritz\Downloads\JRT.exe 2013-08-12 16:13 - 2013-08-12 16:13 - 00051945 _____ C:\AdwCleaner[S1].txt 2013-08-11 22:10 - 2013-08-11 22:10 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie 2013-08-11 09:43 - 2013-08-11 09:43 - 00002214 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-08-11 09:37 - 2013-08-26 20:42 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-11 09:37 - 2013-08-26 19:46 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-11 09:37 - 2013-08-11 09:37 - 00785024 _____ (Google Inc.) C:\Users\Moritz\Downloads\googleupdatesetup.exe 2013-08-11 09:37 - 2013-08-11 09:37 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-11 09:37 - 2013-08-11 09:37 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-11 09:20 - 2013-08-11 09:21 - 03880313 _____ C:\Users\Moritz\Downloads\MithPack-TEMPFIX-162.zip 2013-08-11 09:19 - 2013-08-11 09:20 - 04016863 _____ C:\Users\Moritz\Downloads\SteamIslands.zip 2013-08-10 18:49 - 2013-08-10 18:49 - 00002030 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-10 15:59 - 2013-08-24 21:38 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Craften Terminal 2013-08-10 15:54 - 2013-08-10 15:55 - 03784176 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta.exe 2013-08-06 18:45 - 2013-08-13 10:20 - 00000000 ____D C:\Users\Moritz\Documents\German Truck Simulator 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\UpdatusUser\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\Moritz\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\German Truck Simulator 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Program Files (x86)\German Truck Simulator 2013-08-05 22:21 - 2013-08-05 22:21 - 00512406 _____ C:\Users\Moritz\Documents\Fantasia.world 2013-08-04 22:22 - 2013-08-05 12:38 - 01443026 _____ C:\Users\Moritz\Desktop\Fantasia.world 2013-08-04 22:22 - 2013-08-04 22:22 - 01439185 _____ C:\Users\Moritz\Desktop\Fantasia.1.world 2013-08-01 13:54 - 2013-08-25 20:14 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\WorldPainter 2013-08-01 13:54 - 2013-08-01 13:54 - 00001869 _____ C:\Users\Moritz\Desktop\WorldPainter.lnk 2013-08-01 13:53 - 2013-08-25 12:32 - 00000000 ____D C:\Program Files\WorldPainter 2013-08-01 13:53 - 2013-08-01 13:53 - 03060336 _____ (pepsoft.org) C:\Users\Moritz\Downloads\worldpainter_64_1.5.0.exe 2013-07-31 20:57 - 2013-08-01 10:39 - 00000000 ____D C:\Users\Moritz\AppData\Local\Dxtory Software 2013-07-31 20:57 - 2013-07-31 20:57 - 00001184 _____ C:\Users\Moritz\Desktop\Dxtory.lnk 2013-07-31 20:57 - 2013-07-31 20:57 - 00000000 ____D C:\Program Files (x86)\Dxtory Software 2013-07-31 20:57 - 2013-02-15 22:44 - 08300544 _____ (Dxtory Software) C:\Windows\SysWOW64\DxtoryCodec.dll 2013-07-31 20:57 - 2013-02-15 22:44 - 08043008 _____ (Dxtory Software) C:\Windows\system32\DxtoryCodec.dll 2013-07-31 20:56 - 2013-07-31 20:56 - 04135551 _____ (Dxtory Software ) C:\Users\Moritz\Downloads\DxtorySetup2.0.122.exe 2013-07-28 21:47 - 2013-07-28 21:47 - 02995080 _____ C:\Users\Moritz\Downloads\Kanalbild0013.tif 2013-07-28 11:48 - 2013-07-28 11:48 - 03541664 _____ (Aeria Games & Entertainment) C:\Users\Moritz\Downloads\aeria_ignite_install.exe 2013-07-27 13:08 - 2013-07-27 13:09 - 01863508 _____ C:\sh4_service.log 2013-07-27 13:03 - 2010-08-05 18:01 - 00014680 _____ C:\Windows\system32\sh4native.exe 2013-07-27 10:42 - 2013-07-27 10:42 - 00000000 _____ C:\autoexec.bat 2013-07-27 10:36 - 2013-07-27 10:36 - 00292648 _____ C:\Windows\Minidump\072713-10842-01.dmp 2013-07-27 10:34 - 2013-07-27 10:42 - 00000000 ____D C:\Windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP 2013-07-27 09:08 - 2013-08-14 09:51 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-27 09:07 - 2013-07-27 09:07 - 00280368 _____ (Mozilla) C:\Users\Moritz\Downloads\Firefox Setup Stub 22.0 (1).exe 2013-07-27 09:06 - 2013-07-27 09:06 - 00280368 _____ (Mozilla) C:\Users\Moritz\Downloads\Firefox Setup Stub 22.0.exe ==================== One Month Modified Files and Folders ======= 2013-08-26 20:46 - 2013-01-14 04:06 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Skype 2013-08-26 20:45 - 2013-08-26 20:45 - 01577068 _____ (Farbar) C:\Users\Moritz\Desktop\FRST64.exe 2013-08-26 20:43 - 2013-07-17 22:13 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\.minecraft 2013-08-26 20:42 - 2013-08-11 09:37 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-26 20:00 - 2012-08-06 23:07 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-26 19:52 - 2010-11-21 08:50 - 00697322 _____ C:\Windows\system32\perfh007.dat 2013-08-26 19:52 - 2010-11-21 08:50 - 00148328 _____ C:\Windows\system32\perfc007.dat 2013-08-26 19:52 - 2009-07-14 07:13 - 01614036 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-26 19:51 - 2012-08-06 23:31 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup 2013-08-26 19:51 - 2009-07-14 06:45 - 00021072 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-26 19:51 - 2009-07-14 06:45 - 00021072 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-26 19:48 - 2013-08-26 19:48 - 00000000 ____D C:\Program Files (x86)\Dell Digital Delivery 2013-08-26 19:48 - 2012-08-06 23:06 - 01348437 _____ C:\Windows\WindowsUpdate.log 2013-08-26 19:46 - 2013-08-11 09:37 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-26 19:46 - 2013-07-22 19:18 - 00000000 ____D C:\Users\Moritz\AppData\Local\LogMeIn Hamachi 2013-08-26 19:46 - 2009-07-14 06:51 - 00085283 _____ C:\Windows\setupact.log 2013-08-26 19:45 - 2012-08-06 16:02 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-26 19:45 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-25 20:14 - 2013-08-01 13:54 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\WorldPainter 2013-08-25 20:11 - 2013-08-25 20:11 - 01170448 _____ C:\Users\Moritz\Documents\Themen Welt.world 2013-08-25 12:32 - 2013-08-25 12:31 - 03076208 _____ (pepsoft.org) C:\Users\Moritz\worldpainter_64_1.5.5.exe 2013-08-25 12:32 - 2013-08-01 13:53 - 00000000 ____D C:\Program Files\WorldPainter 2013-08-25 12:31 - 2012-10-23 13:58 - 00000000 ____D C:\Users\Moritz 2013-08-24 21:38 - 2013-08-10 15:59 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Craften Terminal 2013-08-24 21:19 - 2013-07-15 19:33 - 00001105 _____ C:\Users\Public\Desktop\Craften Terminal.lnk 2013-08-24 21:19 - 2013-06-14 20:58 - 00000000 ____D C:\Program Files (x86)\Craften Terminal 2013-08-24 21:17 - 2013-08-24 21:17 - 06445065 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta(1).exe 2013-08-24 13:30 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-23 20:20 - 2013-08-23 20:20 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 20:20 - 2012-10-23 19:35 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-08-23 20:18 - 2013-08-23 20:18 - 00903080 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jxpiinstall.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-23 20:11 - 2013-08-23 20:11 - 00000000 ____D C:\Program Files\Java 2013-08-23 20:11 - 2013-08-14 09:43 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-23 20:11 - 2012-11-25 11:37 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-08-21 19:22 - 2013-08-21 19:22 - 00011688 _____ C:\Users\Moritz\Downloads\stereofunk.zip 2013-08-19 20:26 - 2013-01-22 21:40 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\TS3Client 2013-08-18 19:04 - 2013-01-22 20:42 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2013-08-18 19:01 - 2013-04-15 19:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-17 20:44 - 2013-08-17 20:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-16 08:20 - 2013-08-16 08:20 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie - Kopie (2) 2013-08-14 23:02 - 2013-08-14 23:02 - 00000000 ____D C:\Users\Public\Desktop\CC Support 2013-08-14 23:01 - 2013-08-14 23:01 - 04009167 _____ C:\Users\Moritz\Desktop\ServicesRepair.exe 2013-08-14 21:19 - 2012-10-23 13:58 - 00059280 _____ C:\Users\Moritz\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-14 21:19 - 2010-11-21 09:00 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-08-14 21:18 - 2009-07-14 06:45 - 00275512 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-14 21:15 - 2013-08-14 21:15 - 00003160 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-14 21:13 - 2013-08-14 17:05 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-08-14 21:12 - 2009-07-14 04:34 - 00000471 _____ C:\Windows\win.ini 2013-08-14 17:38 - 2009-07-14 01:46 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll 2013-08-14 17:34 - 2013-08-14 17:34 - 00000207 _____ C:\Windows\tweaking.com-regbackup-MORITZ-PC-Microsoft-Windows-7-Home-Premium-(64-Bit).dat 2013-08-14 17:34 - 2013-08-14 17:34 - 00000000 ____D C:\RegBackup 2013-08-14 17:34 - 2013-08-14 17:04 - 03263349 _____ C:\Users\Moritz\Downloads\tweaking.com_windows_repair_aio.zip 2013-08-14 17:15 - 2012-11-25 11:23 - 00002257 _____ C:\Users\Moritz\Desktop\Google Chrome.lnk 2013-08-14 17:15 - 2012-10-23 19:23 - 00000000 ____D C:\Users\Moritz\AppData\Local\Google 2013-08-14 16:05 - 2013-08-14 16:05 - 00357085 _____ (Farbar) C:\Users\Moritz\Downloads\FSS.exe 2013-08-14 16:05 - 2013-08-14 16:05 - 00002285 _____ C:\Users\Moritz\Downloads\FSS.txt 2013-08-14 09:57 - 2013-08-14 09:57 - 00001785 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iTunes 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iPod 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-14 09:52 - 2012-08-06 23:07 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-14 09:52 - 2012-08-06 23:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-14 09:52 - 2012-08-06 23:07 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-14 09:51 - 2013-07-27 09:08 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-14 09:42 - 2013-08-14 09:39 - 33150376 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jre-7u25-windows-x64.exe 2013-08-14 09:34 - 2012-10-23 14:05 - 00000000 ____D C:\Users\Moritz\AppData\Local\Adobe 2013-08-14 09:31 - 2013-08-14 09:31 - 01069032 _____ (Solid State Networks) C:\Users\Moritz\Downloads\install_flashplayer11x32_ltr5x64d_awc_aih.exe 2013-08-14 09:22 - 2013-08-14 09:22 - 00001071 _____ C:\Users\Moritz\Desktop\Secunia PSI.lnk 2013-08-14 09:21 - 2013-08-14 09:21 - 03272136 _____ (Secunia) C:\Users\Moritz\Downloads\PSISetup711.exe 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Users\Moritz\AppData\Local\Secunia PSI 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-08-13 17:04 - 2013-08-13 10:39 - 00043246 _____ C:\Users\Moritz\Downloads\SystemLook.txt 2013-08-13 15:33 - 2013-08-13 15:33 - 00000000 ____D C:\FRST 2013-08-13 15:04 - 2013-08-13 15:04 - 00000243 _____ C:\Users\Moritz\Downloads\Search.txt 2013-08-13 13:15 - 2013-08-13 13:15 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin 2013-08-13 13:14 - 2013-08-13 13:14 - 03541664 _____ (Aeria Games & Entertainment) C:\Users\Moritz\Downloads\aeria_ignite_install(1).exe 2013-08-13 10:48 - 2013-08-13 10:48 - 00165376 _____ C:\Users\Moritz\Downloads\SystemLook_x64.exe 2013-08-13 10:20 - 2013-08-06 18:45 - 00000000 ____D C:\Users\Moritz\Documents\German Truck Simulator 2013-08-13 09:45 - 2013-08-13 09:45 - 00000000 ____D C:\Windows\D4EFA08DA1924007987D71BFF23B2F8F.TMP 2013-08-12 23:02 - 2013-07-25 22:05 - 00000000 ____D C:\Program Files\MAXON 2013-08-12 22:59 - 2013-07-25 09:52 - 00000000 ____D C:\Fraps 2013-08-12 22:01 - 2013-02-10 20:14 - 00000532 _____ C:\Users\Moritz\Desktop\settings.xml 2013-08-12 17:27 - 2013-08-12 17:27 - 02347384 _____ (ESET) C:\Users\Moritz\Downloads\esetsmartinstaller_enu.exe 2013-08-12 17:09 - 2010-11-21 05:47 - 00055328 _____ C:\Windows\PFRO.log 2013-08-12 17:08 - 2013-08-12 17:08 - 00002958 _____ C:\Users\Moritz\Documents\....txt 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Malwarebytes 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-12 16:57 - 2013-08-12 16:57 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Moritz\Downloads\mbam-setup-1.75.0.1300.exe 2013-08-12 16:30 - 2013-05-17 14:22 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Uniblue 2013-08-12 16:30 - 2013-05-17 14:22 - 00000000 ____D C:\Program Files (x86)\Uniblue 2013-08-12 16:25 - 2013-08-12 16:24 - 00959697 _____ (Oleg N. Scherbakov) C:\Users\Moritz\Downloads\JRT (1).exe 2013-08-12 16:22 - 2013-08-12 16:22 - 00003122 _____ C:\Windows\System32\Tasks\{1EA7E4A0-B683-44E3-A658-ECE1ECBF2E94} 2013-08-12 16:22 - 2013-08-12 16:22 - 00000000 ____D C:\Windows\ERUNT 2013-08-12 16:20 - 2013-08-12 16:20 - 00959697 _____ (Oleg N. Scherbakov) C:\Users\Moritz\Downloads\JRT.exe 2013-08-12 16:13 - 2013-08-12 16:13 - 00051945 _____ C:\AdwCleaner[S1].txt 2013-08-12 15:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-12 09:47 - 2009-07-14 04:34 - 62652416 _____ C:\Windows\system32\config\software.esg.bak 2013-08-12 09:47 - 2009-07-14 04:34 - 19136512 _____ C:\Windows\system32\config\system.esg.bak 2013-08-12 09:47 - 2009-07-14 04:34 - 01331200 _____ C:\Windows\system32\config\default.esg.bak 2013-08-12 09:47 - 2009-07-14 04:34 - 00057344 _____ C:\Windows\system32\config\sam.esg.bak 2013-08-11 22:10 - 2013-08-11 22:10 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie 2013-08-11 21:06 - 2009-07-14 04:34 - 23347200 _____ C:\Windows\system32\config\components.esg.bak 2013-08-11 19:55 - 2012-11-10 20:46 - 00000000 ____D C:\Users\Moritz\AppData\Local\Nero 2013-08-11 09:43 - 2013-08-11 09:43 - 00002214 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-08-11 09:37 - 2013-08-11 09:37 - 00785024 _____ (Google Inc.) C:\Users\Moritz\Downloads\googleupdatesetup.exe 2013-08-11 09:37 - 2013-08-11 09:37 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-11 09:37 - 2013-08-11 09:37 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-11 09:21 - 2013-08-11 09:20 - 03880313 _____ C:\Users\Moritz\Downloads\MithPack-TEMPFIX-162.zip 2013-08-11 09:20 - 2013-08-11 09:19 - 04016863 _____ C:\Users\Moritz\Downloads\SteamIslands.zip 2013-08-10 18:49 - 2013-08-10 18:49 - 00002030 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-10 15:55 - 2013-08-10 15:54 - 03784176 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta.exe 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\UpdatusUser\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\Moritz\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\German Truck Simulator 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Program Files (x86)\German Truck Simulator 2013-08-05 22:21 - 2013-08-05 22:21 - 00512406 _____ C:\Users\Moritz\Documents\Fantasia.world 2013-08-05 12:38 - 2013-08-04 22:22 - 01443026 _____ C:\Users\Moritz\Desktop\Fantasia.world 2013-08-04 22:22 - 2013-08-04 22:22 - 01439185 _____ C:\Users\Moritz\Desktop\Fantasia.1.world 2013-08-01 13:54 - 2013-08-01 13:54 - 00001869 _____ C:\Users\Moritz\Desktop\WorldPainter.lnk 2013-08-01 13:53 - 2013-08-01 13:53 - 03060336 _____ (pepsoft.org) C:\Users\Moritz\Downloads\worldpainter_64_1.5.0.exe 2013-08-01 10:39 - 2013-07-31 20:57 - 00000000 ____D C:\Users\Moritz\AppData\Local\Dxtory Software 2013-07-31 20:57 - 2013-07-31 20:57 - 00001184 _____ C:\Users\Moritz\Desktop\Dxtory.lnk 2013-07-31 20:57 - 2013-07-31 20:57 - 00000000 ____D C:\Program Files (x86)\Dxtory Software 2013-07-31 20:56 - 2013-07-31 20:56 - 04135551 _____ (Dxtory Software ) C:\Users\Moritz\Downloads\DxtorySetup2.0.122.exe 2013-07-31 09:49 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-07-30 10:34 - 2012-08-06 23:38 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks 2013-07-30 10:34 - 2012-08-06 23:38 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks 2013-07-28 21:47 - 2013-07-28 21:47 - 02995080 _____ C:\Users\Moritz\Downloads\Kanalbild0013.tif 2013-07-28 11:48 - 2013-07-28 11:48 - 03541664 _____ (Aeria Games & Entertainment) C:\Users\Moritz\Downloads\aeria_ignite_install.exe 2013-07-27 13:09 - 2013-07-27 13:08 - 01863508 _____ C:\sh4_service.log 2013-07-27 13:08 - 2013-07-25 09:52 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Common 2013-07-27 10:46 - 2013-07-25 10:06 - 00003116 _____ C:\Windows\System32\Tasks\Advanced System Protector_startup 2013-07-27 10:42 - 2013-07-27 10:42 - 00000000 _____ C:\autoexec.bat 2013-07-27 10:42 - 2013-07-27 10:34 - 00000000 ____D C:\Windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP 2013-07-27 10:36 - 2013-07-27 10:36 - 00292648 _____ C:\Windows\Minidump\072713-10842-01.dmp 2013-07-27 10:36 - 2012-12-01 11:01 - 558294278 _____ C:\Windows\MEMORY.DMP 2013-07-27 10:36 - 2012-12-01 11:01 - 00000000 ____D C:\Windows\Minidump 2013-07-27 09:30 - 2013-07-25 22:04 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\MAXON 2013-07-27 09:07 - 2013-07-27 09:07 - 00280368 _____ (Mozilla) C:\Users\Moritz\Downloads\Firefox Setup Stub 22.0 (1).exe 2013-07-27 09:06 - 2013-07-27 09:06 - 00280368 _____ (Mozilla) C:\Users\Moritz\Downloads\Firefox Setup Stub 22.0.exe Files to move or delete: ==================== C:\Users\Moritz\worldpainter_64_1.5.5.exe C:\Users\Moritz\AppData\Local\Temp\c9d4f6f9a38404700fcd30991219e2cd.dll C:\Users\Moritz\AppData\Local\Temp\fhxfdye0.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\GoogleCrashHandler.exe C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\GoogleCrashHandler64.exe C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\GoogleUpdate.exe C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\GoogleUpdateBroker.exe C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\GoogleUpdateOnDemand.exe C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\GoogleUpdateSetup.exe C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdate.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_am.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_ar.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_bg.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_bn.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_ca.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_cs.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_da.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_de.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_el.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_en-GB.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_en.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_es-419.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_es.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_et.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_fa.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_fi.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_fil.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_fr.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_gu.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_hi.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_hr.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_hu.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_id.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_is.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_it.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_iw.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_ja.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_kn.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_ko.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_lt.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_lv.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_ml.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_mr.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_ms.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_nl.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_no.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_pl.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_pt-BR.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_pt-PT.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_ro.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_ru.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_sk.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_sl.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_sr.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_sv.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_sw.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_ta.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_te.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_th.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_tr.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_uk.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_ur.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_vi.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_zh-CN.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\goopdateres_zh-TW.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\npGoogleUpdate3.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\psmachine.dll C:\Users\Moritz\AppData\Local\Temp\{E47C94E7-46B3-489B-81A7-219A95D14062}\psuser.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-27 11:24 ==================== End Of Log ============================ Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-08-2013 Ran by Moritz at 2013-08-26 20:47:28 Running from C:\Users\Moritz\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe AIR (x32 Version: 3.8.0.870) Adobe Community Help (x32 Version: 3.2.1) Adobe Community Help (x32 Version: 3.2.1.650) Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Adobe Photoshop Elements 9 (x32 Version: 9.0) Adobe Premiere Elements 9 (x32 Version: 9.0) Adobe Reader X (10.1.7) MUI (x32 Version: 10.1.7) Advanced Audio FX Engine (x32 Version: 1.12.05) Aeria Ignite (x32 Version: 1.13.3296) Akamai NetSession Interface (HKCU) Alliance of Valiant Arms DE (x32) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (x32 Version: 2.1.3.127) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95) Bonjour (Version: 3.0.0.10) Build-a-lot 2 (x32 Version: 2.2.0.95) Cake Mania (x32 Version: 2.2.0.95) Chuzzle Deluxe (x32 Version: 2.2.0.95) Craften Terminal Beta 3.4.4978.30355 (x32 Version: 3.4.4978.30355) CyberLink PowerDVD 9.6 (x32 Version: 9.6.1.5127) D3DX10 (x32 Version: 15.4.2368.0902) DebugMode Wink (x32) Dell DataSafe Local Backup - Support Software (x32 Version: 9.4.67) Dell DataSafe Local Backup (x32 Version: 9.4.67) Dell DataSafe Online (x32 Version: 2.1.19634) Dell Digital Delivery (x32 Version: 2.7.1000.0) Dell Edoc Viewer (Version: 1.0.0) Dell Getting Started Guide (x32 Version: 1.00.0000) Dell MusicStage (x32 Version: 1.6.225.0) Dell PhotoStage (x32 Version: 1.5.0.130) Dell Stage (x32 Version: 1.7.209.0) Dell Stage Remote (x32 Version: 2.0.0.43) Dell Support Center (Version: 3.1.5907.16) Dell Touchpad (Version: 7.1209.101.217) Dell VideoStage (x32 Version: 1.3.0.2513) Dell Webcam Central (x32 Version: 2.01.15) devolo dLAN Cockpit (x32 Version: 3.2.0.0) Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95) dLAN Cockpit (x32 Version: 3.2.28) dLAN Cockpit (x32 Version: 3.23.12) Dora's World Adventure (x32 Version: 2.2.0.95) Driver Whiz (x32 Version: 8.1) Dxtory version 2.0.122 (x32 Version: 2.0.122) eBay (x32 Version: 1.4.0) Elements 9 Organizer (x32 Version: 9.0) Elements STI Installer (x32 Version: 1.0) Escape Whisper Valley (TM) (x32 Version: 2.2.0.95) Farm Frenzy (x32 Version: 2.2.0.95) FATE (x32 Version: 2.2.0.95) Final Drive Fury (x32 Version: 2.2.0.95) Final Drive Nitro (x32 Version: 2.2.0.95) German Truck Simulator 1.00 (x32 Version: 1.00) Google Chrome (x32 Version: 29.0.1547.57) Google Earth (x32 Version: 7.1.1.1888) Google Update Helper (x32 Version: 1.3.21.153) High-Definition Video Playback (x32 Version: 7.3.10000.0.0) Iminent (x32 Version: 5.48.42.0) Intel PROSet Wireless Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Management Engine Components (x32 Version: 8.0.1.1399) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.1.0.0096) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 2.0.0.0113) Intel(R) Rapid Start Technology (x32 Version: 1.0.0.1024) Intel(R) Rapid Storage Technology (x32 Version: 11.1.0.1006) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.4.220) Intel® PROSet/Wireless WiFi-Software (Version: 15.01.1000.0927) Intel® Trusted Connect Service Client (Version: 1.23.219.2) iTunes (Version: 11.0.3.42) Java 7 Update 25 (64-bit) (Version: 7.0.250) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Jewel Quest (x32 Version: 2.2.0.95) Jewel Quest Solitaire 2 (x32 Version: 2.2.0.95) Junk Mail filter update (x32 Version: 15.4.3502.0922) ldPainter 1.5.5 (Version: 1.5.5) LogMeIn Hamachi (x32 Version: 2.1.0.374) Luxor (x32 Version: 2.2.0.95) McAfee Internet Security (x32 Version: 11.6.511) McAfee Online Backup (Version: 1.16.4.0) McAfee Online Backup (x32) McAfee Security Scan Plus (x32 Version: 3.0.318.3) McAfee Virtual Technician (x32 Version: 7.1.0.2483) Mesh Runtime (x32 Version: 15.4.5722.2) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1) Mozilla Maintenance Service (x32 Version: 23.0.1) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) Namco All-Stars PAC-MAN (x32 Version: 2.2.0.95) Nero 10 Movie ThemePack Basic (x32 Version: 10.2.10200.0.0) Nero Control Center 10 (x32 Version: 10.6.12800.0.8) Nero ControlCenter 10 Help (CHM) (x32 Version: 10.2.10800) Nero Core Components 10 (x32 Version: 2.0.20500.9.16) Nero Update (x32 Version: 1.0.0018) Norton PC Checkup (x32 Version: 3.0.2.122.0) NVIDIA 3D Vision Controller-Treiber 295.73 (Version: 295.73) NVIDIA 3D Vision Treiber 296.37 (Version: 296.37) NVIDIA Grafiktreiber 296.37 (Version: 296.37) NVIDIA HD-Audiotreiber 1.3.12.0 (Version: 1.3.12.0) NVIDIA Install Application (Version: 2.1002.62.312) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.9637) NVIDIA Systemsteuerung 296.37 (Version: 296.37) NVIDIA Update 1.7.12 (Version: 1.7.12) NVIDIA Update Components (Version: 1.7.12) OKI Setup Utility for MC160n (x32 Version: 1.04.0000) Penguins! (x32 Version: 2.2.0.95) PiccShare (HKCU Version: 2.0) Plantronics® GameCom 780 Software for Dolby® Headphone (x32 Version: 1.00.0001) Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95) Polar Bowler (x32 Version: 2.2.0.95) Polar Golfer (x32 Version: 2.2.0.95) Quickset64 (Version: 11.1.17) Samantha Swift (x32 Version: 2.2.0.95) Secunia PSI (3.0.0.7011) (x32 Version: 3.0.0.7011) SeeSimilar (x32 Version: 1.0.0.5) Shared C Run-time for x64 (Version: 10.0.0) Skype™ 6.6 (x32 Version: 6.6.106) SmartSound Quicktracks for Premiere Elements 9.0 (x32 Version: 3.12.3090) SyncUP (x32 Version: 1.12.11500.11.105) SyncUP (x32 Version: 10.2.16500) TeamSpeak 3 Client (Version: 3.0.11.1) TeamViewer 8 (x32 Version: 8.0.17396) Telekom Internet Manager (x32 Version: 11.301.05.09.748) Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (Version: 2.1.23.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update Installer for WildTangent Games App (x32) Wedding Dash - Ready, Aim, Love! (x32 Version: 2.2.0.95) WildTangent Games App (Dell Games) (x32 Version: 4.0.5.2) WildTangent-Spiele (x32 Version: 1.0.2.5) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3508.1109) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3508.1109) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Mesh (x32 Version: 15.4.3502.0922) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Live Messenger (x32 Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) WinRAR 4.20 (64-bit) (Version: 4.20.0) Zinio Reader 4 (x32 Version: 4.2.4164) Zuma Deluxe (x32 Version: 2.2.0.95) ==================== Restore Points ========================= 13-08-2013 07:44:42 Removed RegHunter 13-08-2013 11:15:23 Installed Aeria Ignite 14-08-2013 07:24:50 Removed Java(TM) 6 Update 31 (64-bit) 14-08-2013 07:31:46 Installed Adobe Flash Player 11 ActiveX. 14-08-2013 07:34:26 Removed Java 7 Update 25 14-08-2013 07:42:41 Installed Java 7 Update 25 (64-bit) 14-08-2013 07:51:56 Installed Adobe Flash Player 11 Plugin. 14-08-2013 15:33:05 Tweaking.com - Windows Repair 14-08-2013 15:33:31 Tweaking.com - Windows Repair 14-08-2013 19:06:26 Tweaking.com - Windows Repair 18-08-2013 17:43:56 Windows-Sicherung 23-08-2013 18:05:15 Installed Java(TM) 6 Update 31 (64-bit) 23-08-2013 18:10:37 Removed Java 7 Update 25 (64-bit) 23-08-2013 18:11:30 Installed Java 7 Update 25 (64-bit) 23-08-2013 18:19:45 Installed Java 7 Update 25 25-08-2013 17:00:10 Windows-Sicherung ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-08-14 21:13 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {05596622-83A8-4AED-8E8B-820F505F8955} - System32\Tasks\Driver Whiz-RTMRules => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [2012-11-12] (PC Drivers Headquarters) Task: {0BA067D9-2648-4957-BE66-31DF45F70513} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-14] (Adobe Systems Incorporated) Task: {1754FCEC-50D6-468E-B6A4-5DF65ACFCB1A} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe No File Task: {21BFBF47-579C-4AF1-BE23-83E6DCF4A1A7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-11] (Google Inc.) Task: {2AA0F9AA-A6E1-4234-85BD-F037FCD60A95} - System32\Tasks\Browser Manager => C:\Windows\system32\sc.exe [2009-07-14] (Microsoft Corporation) Task: {2ADE6BE8-2517-44DA-8E26-F013C9BE50A9} - \SpyHunter4Startup No Task File Task: {393315DA-1416-40F8-8884-4D25ACE00326} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {3C1ADAEE-3336-4D7B-8945-3817359B0728} - System32\Tasks\{D7F095E5-D08C-417B-9138-F1B60BDF9961} => C:\Windows\System32\java.exe [2013-08-23] (Oracle Corporation) Task: {3C8E8BD4-A20B-4B9C-9CDB-A180921F7ECE} - System32\Tasks\Driver Detective-RTMUpdater => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [2012-11-12] (PC Drivers Headquarters) Task: {575B21E8-5D72-4904-9B63-869063451D68} - System32\Tasks\PC Checkup 3 Weekly Scan => C:\Program Files (x86)\Norton PC Checkup 3.0\NLAppLauncher.exe [2012-07-17] (Symantec Corporation) Task: {5B1328E1-7D1C-400F-9C1B-B84C60BD0A0B} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21] (Microsoft Corporation) Task: {6F71A867-EDE2-420C-BF6F-66A125C2A5D6} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-21] (Microsoft Corporation) Task: {7206D9F8-864B-401F-8A64-7AA8F793EF91} - System32\Tasks\Driver Detective-RTMScan => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [2012-11-12] (PC Drivers Headquarters) Task: {72813D0F-418F-4F40-89A4-20202465C05A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-11] (Google Inc.) Task: {72894989-0776-4934-9248-8858C46BDD68} - System32\Tasks\FTdownloader V4.0-updater => C:\Program Files (x86)\FTdownloader V4.0\FTdownloader V4.0-updater.exe No File Task: {79D46503-8463-4C79-96B7-EBB427D9F20E} - System32\Tasks\Driver Whiz-RTMUpdater => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [2012-11-12] (PC Drivers Headquarters) Task: {8BAF83FF-3F84-46FE-8843-5EFA7FDBC828} - \RegClean Pro_UPDATES No Task File Task: {989A710A-94A7-46B5-82E5-9FBC59074891} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {A9D0CFE3-A9EE-4484-B9A3-F90B0347F3F7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {C01CE44C-B492-48A0-8760-6C6E60580C32} - System32\Tasks\FTdownloader V4.0-enabler => C:\Program Files (x86)\FTdownloader V4.0\FTdownloader V4.0-enabler.exe No File Task: {C4A8DE08-1CF5-4304-B5DD-BD37644AE3AF} - System32\Tasks\Intel® Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2012-03-28] (Intel) Task: {CC4C341A-4599-47AD-A80A-F78E65B0FEF3} - System32\Tasks\{FC955929-46CA-465E-877B-EBF3BD92097F} => C:\Windows\System32\java.exe [2013-08-23] (Oracle Corporation) Task: {D04AF408-D8C0-4BDF-8B39-483FBEE79E5E} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe No File Task: {D853F765-4BFF-4892-A80B-69E459C9CD44} - \RegClean Pro_DEFAULT No Task File Task: {D8A24848-58E9-4F4D-B15C-F16419048B89} - System32\Tasks\Driver Detective-RTMRules => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [2012-11-12] (PC Drivers Headquarters) Task: {DA020825-C66D-4563-BB20-92C89E5BBEB6} - System32\Tasks\EPUpdater => C:\Users\Moritz\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe No File Task: {E7B37535-FC07-4795-8257-AA6905D9042B} - System32\Tasks\FTdownloader V4.0-codedownloader => C:\Program Files (x86)\FTdownloader V4.0\FTdownloader V4.0-codedownloader.exe No File Task: {EAB43E2C-12D2-4980-914D-AAF21EDCC554} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {EEA40B23-817A-4D58-9B8F-070BD95720CD} - System32\Tasks\Driver Whiz-RTMScan => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [2012-11-12] (PC Drivers Headquarters) Task: {FCC653CE-2C37-4F77-9049-7DE8FC923546} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {FEF0C41D-4023-4E3C-81A4-ADF3397083A9} - System32\Tasks\IntelBootstrapCCDashServer => C:\Program Files\Intel\WiFi\bin\CCDashServer.exe [2012-03-30] (Intel® Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Driver Whiz-RTMRules.job => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe Task: C:\Windows\Tasks\Driver Whiz-RTMScan.job => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe Task: C:\Windows\Tasks\Driver Whiz-RTMUpdater.job => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/26/2013 07:56:02 PM) (Source: CVHSVC) (User: ) Description: Nur zur Information. (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: In den Microsoft Windows HTTP-Diensten ist ein interner Fehler aufgetreten. Error: (08/26/2013 07:51:43 PM) (Source: DataSafe.exe) (User: ) Description: Recovery Environment incorrect, file 'Y:\dell\Image\Factory.wim' missing Error: (08/26/2013 07:51:34 PM) (Source: DataSafe.exe) (User: ) Description: Recovery Environment incorrect, file 'Y:\dell\Image\Factory.wim' missing Error: (08/26/2013 07:48:05 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {50c576d4-1336-4df0-82f2-1d2fbb71d330} Error: (08/26/2013 07:45:58 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2013 07:08:44 PM) (Source: CVHSVC) (User: ) Description: Nur zur Information. (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: In den Microsoft Windows HTTP-Diensten ist ein interner Fehler aufgetreten. Error: (08/25/2013 07:01:14 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {eaff0b94-471d-4d39-a1b5-96f3628aa0d1} Error: (08/25/2013 06:58:34 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2013 00:26:43 PM) (Source: CVHSVC) (User: ) Description: Nur zur Information. (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: In den Microsoft Windows HTTP-Diensten ist ein interner Fehler aufgetreten. Error: (08/25/2013 00:18:50 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {7bf915e2-e0e6-4a75-9071-979c8fb15315} System errors: ============= Error: (08/26/2013 07:48:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Dell Digital Delivery Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 1000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/26/2013 07:48:07 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde mit folgendem Fehler beendet: %%-2147012892 Error: (08/26/2013 07:48:06 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/26/2013 07:48:06 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/26/2013 07:45:51 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Net.Tcp Listener Adapter" ist vom Dienst "Net.Tcp Port Sharing Service" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/26/2013 07:45:51 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Net.Pipe Listener Adapter" ist von folgendem Dienst abhängig: was. Dieser Dienst ist eventuell nicht installiert. Error: (08/26/2013 07:45:51 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Net.Msmq Listener Adapter" ist von folgendem Dienst abhängig: msmq. Dieser Dienst ist eventuell nicht installiert. Error: (08/25/2013 07:02:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde mit folgendem Fehler beendet: %%-2147012892 Error: (08/25/2013 07:01:15 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/25/2013 07:01:15 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Microsoft Office Sessions: ========================= Error: (08/26/2013 07:56:02 PM) (Source: CVHSVC)(User: ) Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: In den Microsoft Windows HTTP-Diensten ist ein interner Fehler aufgetreten. Error: (08/26/2013 07:51:43 PM) (Source: DataSafe.exe)(User: ) Description: Recovery Environment incorrect, file 'Y:\dell\Image\Factory.wim' missing Error: (08/26/2013 07:51:34 PM) (Source: DataSafe.exe)(User: ) Description: Recovery Environment incorrect, file 'Y:\dell\Image\Factory.wim' missing Error: (08/26/2013 07:48:05 PM) (Source: VSS)(User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {50c576d4-1336-4df0-82f2-1d2fbb71d330} Error: (08/26/2013 07:45:58 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2013 07:08:44 PM) (Source: CVHSVC)(User: ) Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: In den Microsoft Windows HTTP-Diensten ist ein interner Fehler aufgetreten. Error: (08/25/2013 07:01:14 PM) (Source: VSS)(User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {eaff0b94-471d-4d39-a1b5-96f3628aa0d1} Error: (08/25/2013 06:58:34 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2013 00:26:43 PM) (Source: CVHSVC)(User: ) Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: In den Microsoft Windows HTTP-Diensten ist ein interner Fehler aufgetreten. Error: (08/25/2013 00:18:50 PM) (Source: VSS)(User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {7bf915e2-e0e6-4a75-9071-979c8fb15315} CodeIntegrity Errors: =================================== Date: 2013-07-15 11:43:23.396 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\SET8CF4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-15 11:43:23.395 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\SET8CF4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 28% Total physical RAM: 8131.37 MB Available physical RAM: 5779.2 MB Total Pagefile: 16260.92 MB Available Pagefile: 12367.69 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:678.78 GB) (Free:596.11 GB) NTFS Drive d: (DATAPART1) (Fixed) (Total:698.63 GB) (Free:491.65 GB) NTFS Drive e: (Plantronics GameCom 780) (CDROM) (Total:0.04 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 699 GB) (Disk ID: 14A9202A) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Active) - (Size=20 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=679 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 14A92030) Partition 1: (Not Active) - (Size=699 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 8 GB) (Disk ID: 14A920CB) Partition 1: (Not Active) - (Size=8 GB) - (Type=84) ==================== End Of Log ============================ |
27.08.2013, 09:49 | #4 |
/// the machine /// TB-Ausbilder | Firefox Problem Bevor wir tief greifen: Firefox schonmal deinstalliert und neu installiert?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.08.2013, 13:02 | #5 |
| Firefox Problem Nein, aber ich habe bemerkt, dass bei Chrome das selbe ist. Trotzdem mal neuinstallieren? |
27.08.2013, 13:52 | #6 |
/// the machine /// TB-Ausbilder | Firefox Problem Revo Uninstaller Pro - Uninstall Software, Remove Programs easily, Forced Uninstall, Leftovers Uninstaller Damit Firefox, Chrome und Flash Player deinstallieren, alle Reste entfernen. Alles neu installieren. In ein Flash Player Fenster bei YT nen Rechtsklick, Haken raus bei Hardwarebeschleunigung aktivieren. Testen
__________________ --> Firefox Problem |
28.08.2013, 19:45 | #7 |
| Firefox Problem Ok habst gemacht. Bis auf das mit dem Flash Player. Wo kann ich denn da das Häckchen rausmachen? Ansonsten geht alles so weit wieder. wenn das problem nochmal kommt melde ich mich nochmal hier Mir ist soeben aufgefallen, dass wenn ich Chrome öffne 9 Suchanbieter geöffnet werden. Der letzte heißt ftdownloader Search. Ich denke mal das ist nicht gewollt und den ftdownloader hab ich ja schon kennengelernt. Desweiteren ist in CHrome auch diese Werbung die der ftdownloader bringt mit Abnehmen und irgebtwelchen Kräutern für Muskelwachstum die es nicht gibt... Was kann ich dagegen machen? Geändert von Minter (28.08.2013 um 20:09 Uhr) |
29.08.2013, 04:31 | #8 |
/// the machine /// TB-Ausbilder | Firefox Problem Du hast bei Chrome wirklich keine Daten behalten? Chrome deinstallieren. Alles was Du in Programme und ProgramData von Chrome als Ordner findest, löschen, dann TFC laufen lassen. Chrome wieder installieren.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.08.2013, 17:50 | #9 |
| Firefox Problem OK hab Chrome noch mal deinstalliert. Jetzt sind die anderen Suchanbieter auch weg. Noch eine Frage, wenn der ftdownloader bei FRST in der Quarantine ist, kann der dann noch Schaden anrichten? |
30.08.2013, 06:26 | #10 |
/// the machine /// TB-Ausbilder | Firefox Problem Nein, Quarantäne ist Quarantäne Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.08.2013, 08:45 | #11 |
| Firefox Problem Danke für diese tolle und ausführliche Liste. Aber bei Windows Update kommt immer die Fehlermeldung '0x80072ee4: 0x80072ee4 ' wenn ich es starten will. Dadurch werden keine Updates herruntergeladen und mein Virenschutz ist nicht auf dem neusten Stand. |
30.08.2013, 15:32 | #12 |
/// the machine /// TB-Ausbilder | Firefox Problem Downloade dir bitte Farbar Service Scanner
Poste bitte den Inhalt hier. Poste auch mal noch ein frisches FRST log.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.08.2013, 16:15 | #13 |
| Firefox ProblemCode:
ATTFilter Farbar Service Scanner Version: 28-08-2013 Ran by Moritz (administrator) on 30-08-2013 at 17:10:33 Running from "C:\Users\Moritz\Downloads" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ wuauserv Service is not running. Checking service configuration: The start type of wuauserv service is OK. The ImagePath of wuauserv service is OK. The ServiceDll of wuauserv service is OK. Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013 Ran by Moritz (administrator) on 30-08-2013 17:13:05 Running from C:\Users\Moritz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Adobe Systems Incorporated) c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Windows\system32\mfevtps.exe (Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe (Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\CCDashServer.exe () C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe () C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe () C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe () C:\Program Files\Plantronics\GameCom780\GameCom780.exe (PC Drivers Headquarters) C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Akamai Technologies, Inc.) C:\Users\Moritz\AppData\Local\Akamai\netsession_win.exe () C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Akamai Technologies, Inc.) C:\Users\Moritz\AppData\Local\Akamai\netsession_win.exe (Huawei Technologies Co., Ltd.) C:\Users\Moritz\AppData\Roaming\Telekom Internet Manager\ouc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe () C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (CyberLink Corp.) C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe (cyberlink) C:\Program Files (x86)\Cyberlink\Shared files\brs.exe () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe (McAfee, Inc.) C:\Program Files\McAfee.com\Agent\mcagent.exe (Aeria Games & Entertainment) C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (McAfee, Inc.) c:\PROGRA~2\mcafee\SITEAD~1\saui.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Dell Products, LP.) c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Secure Banking) C:\Program Files (x86)\Secure Banking\SecureBanking.exe () C:\Program Files (x86)\Secure Banking\sbservice.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [626552 2012-04-09] (Alps Electric Co., Ltd.) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-02-14] (IDT, Inc.) HKLM\...\Run: [QuickSet] - c:\Program Files\Dell\QuickSet\QuickSet.exe [4365984 2012-03-12] (Dell Inc.) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] () HKLM\...\Run: [IntelMyWiFiDashboard] - C:\Program Files\Intel\WiFi\bin\CCDashServer.exe [4966912 2012-03-30] (Intel® Corporation) HKLM\...\Run: [BLEServicesCtrl] - C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [120592 2012-01-10] () HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2012-01-12] (Intel Corporation) HKLM\...\Run: [DellStage] - C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj [483424 2012-02-01] () HKLM\...\Run: [Stage Remote] - C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe [2022976 2011-06-28] () HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated) HKLM\...\Run: [GamecomSound] - C:\Program Files\Plantronics\GameCom780\GameCom780.exe [777448 2011-12-01] () HKCU\...\Run: [Driver Whiz] - C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [3527608 2012-11-12] (PC Drivers Headquarters) HKCU\...\Run: [HW_OPENEYE_OUC_Telekom Internet Manager] - C:\Program Files (x86)\Telekom\InternetManager_H\UpdateDog\ouc.exe [116064 2010-12-28] (Huawei Technologies Co., Ltd.) HKCU\...\Run: [Driver Detective] - C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [3527608 2012-11-12] (PC Drivers Headquarters) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Moritz\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [Dxtory Update Checker 2.0] - C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software) HKCU\...\Run: [SecureBanking] - C:\Program Files (x86)\Secure Banking\SecureBanking.exe [372736 2012-09-10] (Secure Banking) MountPoints2: {19fc124d-dfcf-11e1-abd9-806e6f6e6963} - E:\setup.exe HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [577024 2012-03-07] (Creative Technology Ltd) HKLM-x32\...\Run: [Dell DataSafe Online] - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.) HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2010-10-01] (CyberLink Corp.) HKLM-x32\...\Run: [PDVD9LanguageShortcut] - C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-09-18] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe [76872 2012-03-27] (cyberlink) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [37960 2013-05-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [NeroLauncher] - C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe [66872 2012-03-11] () HKLM-x32\...\Run: [AccuWeatherWidget] - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj [2835443 2012-02-01] () HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [DataCardMonitor] - C:\Program Files (x86)\Telekom\InternetManager_H\DataCardMonitor.exe [259424 2013-04-10] (Huawei Technologies Co., Ltd.) HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [1532992 2013-03-13] (McAfee, Inc.) HKLM-x32\...\Run: [Aeria Ignite] - C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-15] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: 0 [97280 2009-07-14] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: ProxTube - {0AA2810A-F009-4BD7-A10A-32F140A1B9F3} - C:\Users\Moritz\AppData\LocalLow\ProxTube\IE\ProxTube.dll (Malte Goetz) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\ovrpeuoq.default FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @mcafee.com/MVT - C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll (McAfee, Inc.) FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\ovrpeuoq.default\Extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK Chrome: ======= CHR HomePage: hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={97E8337D-318A-11E2-99C1-685D43F81BF9} CHR RestoreOnStartup: "hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={97E8337D-318A-11E2-99C1-685D43F81BF9}", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=48&cc=", "hxxp://search.iminent.com/?appId=8C23518F-7CF9-4B86-8615-966552B59FA0", "hxxp://search.babylon.com/?affID=115038&tt=201112_1849_4712_1&babsrc=HP_ss_cr&mntrId=141c7b8f000000000000685d43f81bf6", "hxxp://www.searchnu.com/406", "hxxp://search.nation.com/?orig=HP&affid=801&cztbid=233971303", "hxxp://search.conduit.com/?CUI=UN33859423212177427&ctid=CT3241949&SearchSource=48", "hxxp://isearch.babylon.com/?affID=115038&tt=201112_1849_4712_1&babsrc=HP_ss_gr2&mntrId=141c7b8f000000000000685d43f81bf6", "hxxp://search.fbdownloader.com/?channel=sfde203fbdgy21" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Extension: (Google Docs) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR Extension: (Gmail) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 ==================== Services (Whitelisted) ================= S2 CLKMSVC10_9EC60124; C:\Program Files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe [242448 2012-03-27] (CyberLink) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3128856 2012-02-28] (devolo AG) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [344928 2011-01-28] () R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-03-28] (Intel Corporation) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [384048 2013-02-25] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [241456 2013-02-19] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218760 2013-02-19] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-02-19] (McAfee, Inc.) R2 MOBKbackup; C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe [231224 2010-04-13] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-03-29] () R2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe [132056 2012-07-17] (Symantec Corporation) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-03-29] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-02-19] (McAfee, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.) R3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-03-28] (Intel Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179280 2013-02-19] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [309840 2013-02-19] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [515968 2013-02-19] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [771536 2013-02-19] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106552 2013-02-19] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340216 2013-02-19] (McAfee, Inc.) R1 MOBKFilter; C:\Windows\System32\DRIVERS\MOBK.sys [66040 2010-04-13] (Mozy, Inc.) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2012-01-31] (CACE Technologies) S3 PlantronicsGC; C:\Windows\System32\drivers\PLTGC.sys [1327104 2011-11-05] (C-Media Electronics Inc) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) U3 mfeavfk01; No ImagePath S3 xhunter1; \??\C:\Windows\xhunter1.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-30 17:12 - 2013-08-30 17:12 - 00000000 ____D C:\FRST 2013-08-30 17:11 - 2013-08-30 17:11 - 01579080 _____ (Farbar) C:\Users\Moritz\Downloads\FRST64.exe 2013-08-30 17:10 - 2013-08-30 17:10 - 00358571 _____ (Farbar) C:\Users\Moritz\Downloads\FSS.exe 2013-08-30 17:10 - 2013-08-30 17:10 - 00002282 _____ C:\Users\Moritz\Downloads\FSS.txt 2013-08-30 16:08 - 2013-08-30 16:08 - 00001076 _____ C:\Users\Public\Desktop\Secure Banking.lnk 2013-08-30 16:08 - 2013-08-30 16:08 - 00000000 ____D C:\Program Files (x86)\Secure Banking 2013-08-30 09:46 - 2013-08-30 09:46 - 00448512 _____ (OldTimer Tools) C:\Users\Moritz\Downloads\TFC.exe 2013-08-30 09:36 - 2013-08-30 09:36 - 00818944 _____ C:\Users\Moritz\Downloads\adblockplus-2.2.4.xpi.zip 2013-08-30 09:30 - 2013-08-30 09:31 - 00003158 _____ C:\DelFix.txt 2013-08-29 18:45 - 2013-08-29 18:45 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-28 20:38 - 2013-08-30 17:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-28 20:38 - 2013-08-28 20:38 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-28 20:38 - 2013-08-28 20:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-28 20:38 - 2013-08-28 20:38 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-28 20:31 - 2013-08-28 20:32 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Mozilla 2013-08-28 20:31 - 2013-08-28 20:31 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-28 20:31 - 2013-08-28 20:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-28 20:31 - 2013-08-28 20:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-28 20:22 - 2013-08-28 20:22 - 00001039 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\Users\Moritz\AppData\Local\VS Revo Group 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\Program Files\VS Revo Group 2013-08-28 20:22 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys 2013-08-28 20:21 - 2013-08-28 20:21 - 10031224 _____ (VS Revo Group ) C:\Users\Moritz\Downloads\RevoUninProSetup.exe 2013-08-27 20:01 - 2013-08-27 20:01 - 06384214 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta(2).exe 2013-08-26 19:48 - 2013-08-26 19:48 - 00000000 ____D C:\Program Files (x86)\Dell Digital Delivery 2013-08-25 20:11 - 2013-08-25 20:11 - 01170448 _____ C:\Users\Moritz\Documents\Themen Welt.world 2013-08-25 12:31 - 2013-08-25 12:32 - 03076208 _____ (pepsoft.org) C:\Users\Moritz\worldpainter_64_1.5.5.exe 2013-08-24 21:17 - 2013-08-24 21:17 - 06445065 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta(1).exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 20:18 - 2013-08-23 20:18 - 00903080 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jxpiinstall.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-23 20:11 - 2013-08-23 20:11 - 00000000 ____D C:\Program Files\Java 2013-08-21 19:22 - 2013-08-21 19:22 - 00011688 _____ C:\Users\Moritz\Downloads\stereofunk.zip 2013-08-16 08:20 - 2013-08-16 08:20 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie - Kopie (2) 2013-08-14 23:02 - 2013-08-14 23:02 - 00000000 ____D C:\Users\Public\Desktop\CC Support 2013-08-14 21:15 - 2013-08-14 21:15 - 00003160 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-14 17:34 - 2013-08-14 17:34 - 00000207 _____ C:\Windows\tweaking.com-regbackup-MORITZ-PC-Microsoft-Windows-7-Home-Premium-(64-Bit).dat 2013-08-14 17:34 - 2013-08-14 17:34 - 00000000 ____D C:\RegBackup 2013-08-14 17:05 - 2013-08-14 21:13 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-08-14 17:04 - 2013-08-14 17:34 - 03263349 _____ C:\Users\Moritz\Downloads\tweaking.com_windows_repair_aio.zip 2013-08-14 09:57 - 2013-08-14 09:57 - 00001785 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iTunes 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iPod 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-14 09:43 - 2013-08-23 20:11 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-14 09:39 - 2013-08-14 09:42 - 33150376 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jre-7u25-windows-x64.exe 2013-08-14 09:31 - 2013-08-14 09:31 - 01069032 _____ (Solid State Networks) C:\Users\Moritz\Downloads\install_flashplayer11x32_ltr5x64d_awc_aih.exe 2013-08-14 09:22 - 2013-08-14 09:22 - 00001071 _____ C:\Users\Moritz\Desktop\Secunia PSI.lnk 2013-08-14 09:21 - 2013-08-14 09:21 - 03272136 _____ (Secunia) C:\Users\Moritz\Downloads\PSISetup711.exe 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Users\Moritz\AppData\Local\Secunia PSI 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-08-13 13:15 - 2013-08-13 13:15 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin 2013-08-13 13:14 - 2013-08-13 13:14 - 03541664 _____ (Aeria Games & Entertainment) C:\Users\Moritz\Downloads\aeria_ignite_install(1).exe 2013-08-12 17:08 - 2013-08-12 17:08 - 00002958 _____ C:\Users\Moritz\Documents\....txt 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Malwarebytes 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-12 16:57 - 2013-08-12 16:57 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Moritz\Downloads\mbam-setup-1.75.0.1300.exe 2013-08-12 16:22 - 2013-08-30 09:30 - 00000000 ____D C:\Windows\ERUNT 2013-08-12 16:22 - 2013-08-12 16:22 - 00003122 _____ C:\Windows\System32\Tasks\{1EA7E4A0-B683-44E3-A658-ECE1ECBF2E94} 2013-08-11 22:10 - 2013-08-11 22:10 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie 2013-08-11 09:43 - 2013-08-11 09:43 - 00002214 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-08-11 09:37 - 2013-08-30 16:42 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-11 09:37 - 2013-08-30 16:02 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-11 09:37 - 2013-08-11 09:37 - 00785024 _____ (Google Inc.) C:\Users\Moritz\Downloads\googleupdatesetup.exe 2013-08-11 09:37 - 2013-08-11 09:37 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-11 09:37 - 2013-08-11 09:37 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-11 09:20 - 2013-08-11 09:21 - 03880313 _____ C:\Users\Moritz\Downloads\MithPack-TEMPFIX-162.zip 2013-08-11 09:19 - 2013-08-11 09:20 - 04016863 _____ C:\Users\Moritz\Downloads\SteamIslands.zip 2013-08-10 18:49 - 2013-08-10 18:49 - 00002030 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-10 15:59 - 2013-08-28 19:03 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Craften Terminal 2013-08-10 15:54 - 2013-08-10 15:55 - 03784176 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta.exe 2013-08-06 18:45 - 2013-08-13 10:20 - 00000000 ____D C:\Users\Moritz\Documents\German Truck Simulator 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\UpdatusUser\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\Moritz\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\German Truck Simulator 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Program Files (x86)\German Truck Simulator 2013-08-05 22:21 - 2013-08-05 22:21 - 00512406 _____ C:\Users\Moritz\Documents\Fantasia.world 2013-08-04 22:22 - 2013-08-05 12:38 - 01443026 _____ C:\Users\Moritz\Desktop\Fantasia.world 2013-08-04 22:22 - 2013-08-04 22:22 - 01439185 _____ C:\Users\Moritz\Desktop\Fantasia.1.world 2013-08-01 13:54 - 2013-08-25 20:14 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\WorldPainter 2013-08-01 13:54 - 2013-08-01 13:54 - 00001869 _____ C:\Users\Moritz\Desktop\WorldPainter.lnk 2013-08-01 13:53 - 2013-08-25 12:32 - 00000000 ____D C:\Program Files\WorldPainter 2013-08-01 13:53 - 2013-08-01 13:53 - 03060336 _____ (pepsoft.org) C:\Users\Moritz\Downloads\worldpainter_64_1.5.0.exe 2013-07-31 20:57 - 2013-08-01 10:39 - 00000000 ____D C:\Users\Moritz\AppData\Local\Dxtory Software 2013-07-31 20:57 - 2013-07-31 20:57 - 00001184 _____ C:\Users\Moritz\Desktop\Dxtory.lnk 2013-07-31 20:57 - 2013-07-31 20:57 - 00000000 ____D C:\Program Files (x86)\Dxtory Software 2013-07-31 20:57 - 2013-02-15 22:44 - 08300544 _____ (Dxtory Software) C:\Windows\SysWOW64\DxtoryCodec.dll 2013-07-31 20:57 - 2013-02-15 22:44 - 08043008 _____ (Dxtory Software) C:\Windows\system32\DxtoryCodec.dll 2013-07-31 20:56 - 2013-07-31 20:56 - 04135551 _____ (Dxtory Software ) C:\Users\Moritz\Downloads\DxtorySetup2.0.122.exe ==================== One Month Modified Files and Folders ======= 2013-08-30 17:12 - 2013-08-30 17:12 - 00028691 _____ C:\Users\Moritz\Downloads\Addition.txt 2013-08-30 17:12 - 2013-08-30 17:12 - 00000000 ____D C:\FRST 2013-08-30 17:12 - 2013-08-28 20:38 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-30 17:11 - 2013-08-30 17:11 - 01579080 _____ (Farbar) C:\Users\Moritz\Downloads\FRST64.exe 2013-08-30 17:10 - 2013-08-30 17:10 - 00358571 _____ (Farbar) C:\Users\Moritz\Downloads\FSS.exe 2013-08-30 17:10 - 2013-08-30 17:10 - 00002282 _____ C:\Users\Moritz\Downloads\FSS.txt 2013-08-30 17:09 - 2013-07-17 22:13 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\.minecraft 2013-08-30 17:02 - 2013-01-14 04:06 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Skype 2013-08-30 16:42 - 2013-08-11 09:37 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-30 16:08 - 2013-08-30 16:08 - 00001076 _____ C:\Users\Public\Desktop\Secure Banking.lnk 2013-08-30 16:08 - 2013-08-30 16:08 - 00000000 ____D C:\Program Files (x86)\Secure Banking 2013-08-30 16:08 - 2009-07-14 06:45 - 00021072 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-30 16:08 - 2009-07-14 06:45 - 00021072 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-30 16:06 - 2010-11-21 08:50 - 00697322 _____ C:\Windows\system32\perfh007.dat 2013-08-30 16:06 - 2010-11-21 08:50 - 00148328 _____ C:\Windows\system32\perfc007.dat 2013-08-30 16:06 - 2009-07-14 07:13 - 01614036 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-30 16:04 - 2012-08-06 23:06 - 01372054 _____ C:\Windows\WindowsUpdate.log 2013-08-30 16:02 - 2013-08-11 09:37 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-30 16:02 - 2013-07-22 19:18 - 00000000 ____D C:\Users\Moritz\AppData\Local\LogMeIn Hamachi 2013-08-30 16:02 - 2012-08-06 23:31 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup 2013-08-30 16:02 - 2012-08-06 16:02 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-30 16:02 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-30 16:02 - 2009-07-14 06:51 - 00086170 _____ C:\Windows\setupact.log 2013-08-30 09:46 - 2013-08-30 09:46 - 00448512 _____ (OldTimer Tools) C:\Users\Moritz\Downloads\TFC.exe 2013-08-30 09:36 - 2013-08-30 09:36 - 00818944 _____ C:\Users\Moritz\Downloads\adblockplus-2.2.4.xpi.zip 2013-08-30 09:31 - 2013-08-30 09:30 - 00003158 _____ C:\DelFix.txt 2013-08-30 09:30 - 2013-08-12 16:22 - 00000000 ____D C:\Windows\ERUNT 2013-08-30 09:26 - 2010-11-21 05:47 - 00057038 _____ C:\Windows\PFRO.log 2013-08-29 22:16 - 2013-01-22 21:40 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\TS3Client 2013-08-29 18:45 - 2013-08-29 18:45 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-29 18:45 - 2012-10-23 19:23 - 00000000 ____D C:\Users\Moritz\AppData\Local\Google 2013-08-29 18:45 - 2012-10-23 19:23 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-28 20:38 - 2013-08-28 20:38 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-28 20:38 - 2013-08-28 20:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-28 20:38 - 2013-08-28 20:38 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-28 20:38 - 2012-10-23 14:05 - 00000000 ____D C:\Users\Moritz\AppData\Local\Adobe 2013-08-28 20:32 - 2013-08-28 20:31 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Mozilla 2013-08-28 20:31 - 2013-08-28 20:31 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-28 20:31 - 2013-08-28 20:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-28 20:31 - 2013-08-28 20:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-28 20:29 - 2012-10-23 19:23 - 00000000 ____D C:\Users\Moritz\AppData\Local\Deployment 2013-08-28 20:22 - 2013-08-28 20:22 - 00001039 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\Users\Moritz\AppData\Local\VS Revo Group 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\Program Files\VS Revo Group 2013-08-28 20:21 - 2013-08-28 20:21 - 10031224 _____ (VS Revo Group ) C:\Users\Moritz\Downloads\RevoUninProSetup.exe 2013-08-28 19:03 - 2013-08-10 15:59 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Craften Terminal 2013-08-27 20:01 - 2013-08-27 20:01 - 06384214 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta(2).exe 2013-08-27 20:01 - 2013-07-15 19:33 - 00001105 _____ C:\Users\Public\Desktop\Craften Terminal.lnk 2013-08-27 20:01 - 2013-06-14 20:58 - 00000000 ____D C:\Program Files (x86)\Craften Terminal 2013-08-26 19:48 - 2013-08-26 19:48 - 00000000 ____D C:\Program Files (x86)\Dell Digital Delivery 2013-08-25 20:14 - 2013-08-01 13:54 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\WorldPainter 2013-08-25 20:11 - 2013-08-25 20:11 - 01170448 _____ C:\Users\Moritz\Documents\Themen Welt.world 2013-08-25 12:32 - 2013-08-25 12:31 - 03076208 _____ (pepsoft.org) C:\Users\Moritz\worldpainter_64_1.5.5.exe 2013-08-25 12:32 - 2013-08-01 13:53 - 00000000 ____D C:\Program Files\WorldPainter 2013-08-25 12:31 - 2012-10-23 13:58 - 00000000 ____D C:\Users\Moritz 2013-08-24 21:17 - 2013-08-24 21:17 - 06445065 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta(1).exe 2013-08-24 13:30 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-23 20:20 - 2013-08-23 20:20 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 20:20 - 2012-10-23 19:35 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-08-23 20:18 - 2013-08-23 20:18 - 00903080 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jxpiinstall.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-23 20:11 - 2013-08-23 20:11 - 00000000 ____D C:\Program Files\Java 2013-08-23 20:11 - 2013-08-14 09:43 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-23 20:11 - 2012-11-25 11:37 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-08-21 19:22 - 2013-08-21 19:22 - 00011688 _____ C:\Users\Moritz\Downloads\stereofunk.zip 2013-08-18 19:04 - 2013-01-22 20:42 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2013-08-16 08:20 - 2013-08-16 08:20 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie - Kopie (2) 2013-08-14 23:02 - 2013-08-14 23:02 - 00000000 ____D C:\Users\Public\Desktop\CC Support 2013-08-14 21:19 - 2012-10-23 13:58 - 00059280 _____ C:\Users\Moritz\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-14 21:19 - 2010-11-21 09:00 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-08-14 21:18 - 2009-07-14 06:45 - 00275512 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-14 21:15 - 2013-08-14 21:15 - 00003160 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-14 21:13 - 2013-08-14 17:05 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-08-14 21:12 - 2009-07-14 04:34 - 00000471 _____ C:\Windows\win.ini 2013-08-14 17:38 - 2009-07-14 01:46 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll 2013-08-14 17:34 - 2013-08-14 17:34 - 00000207 _____ C:\Windows\tweaking.com-regbackup-MORITZ-PC-Microsoft-Windows-7-Home-Premium-(64-Bit).dat 2013-08-14 17:34 - 2013-08-14 17:34 - 00000000 ____D C:\RegBackup 2013-08-14 17:34 - 2013-08-14 17:04 - 03263349 _____ C:\Users\Moritz\Downloads\tweaking.com_windows_repair_aio.zip 2013-08-14 09:57 - 2013-08-14 09:57 - 00001785 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iTunes 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iPod 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-14 09:42 - 2013-08-14 09:39 - 33150376 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jre-7u25-windows-x64.exe 2013-08-14 09:31 - 2013-08-14 09:31 - 01069032 _____ (Solid State Networks) C:\Users\Moritz\Downloads\install_flashplayer11x32_ltr5x64d_awc_aih.exe 2013-08-14 09:22 - 2013-08-14 09:22 - 00001071 _____ C:\Users\Moritz\Desktop\Secunia PSI.lnk 2013-08-14 09:21 - 2013-08-14 09:21 - 03272136 _____ (Secunia) C:\Users\Moritz\Downloads\PSISetup711.exe 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Users\Moritz\AppData\Local\Secunia PSI 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-08-13 13:15 - 2013-08-13 13:15 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin 2013-08-13 13:14 - 2013-08-13 13:14 - 03541664 _____ (Aeria Games & Entertainment) C:\Users\Moritz\Downloads\aeria_ignite_install(1).exe 2013-08-13 10:20 - 2013-08-06 18:45 - 00000000 ____D C:\Users\Moritz\Documents\German Truck Simulator 2013-08-12 23:02 - 2013-07-25 22:05 - 00000000 ____D C:\Program Files\MAXON 2013-08-12 22:59 - 2013-07-25 09:52 - 00000000 ____D C:\Fraps 2013-08-12 22:01 - 2013-02-10 20:14 - 00000532 _____ C:\Users\Moritz\Desktop\settings.xml 2013-08-12 17:08 - 2013-08-12 17:08 - 00002958 _____ C:\Users\Moritz\Documents\....txt 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Malwarebytes 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-12 16:57 - 2013-08-12 16:57 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Moritz\Downloads\mbam-setup-1.75.0.1300.exe 2013-08-12 16:30 - 2013-05-17 14:22 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Uniblue 2013-08-12 16:30 - 2013-05-17 14:22 - 00000000 ____D C:\Program Files (x86)\Uniblue 2013-08-12 16:22 - 2013-08-12 16:22 - 00003122 _____ C:\Windows\System32\Tasks\{1EA7E4A0-B683-44E3-A658-ECE1ECBF2E94} 2013-08-12 15:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-12 09:47 - 2009-07-14 04:34 - 62652416 _____ C:\Windows\system32\config\software.esg.bak 2013-08-12 09:47 - 2009-07-14 04:34 - 19136512 _____ C:\Windows\system32\config\system.esg.bak 2013-08-12 09:47 - 2009-07-14 04:34 - 01331200 _____ C:\Windows\system32\config\default.esg.bak 2013-08-12 09:47 - 2009-07-14 04:34 - 00057344 _____ C:\Windows\system32\config\sam.esg.bak 2013-08-11 22:10 - 2013-08-11 22:10 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie 2013-08-11 21:06 - 2009-07-14 04:34 - 23347200 _____ C:\Windows\system32\config\components.esg.bak 2013-08-11 19:55 - 2012-11-10 20:46 - 00000000 ____D C:\Users\Moritz\AppData\Local\Nero 2013-08-11 09:43 - 2013-08-11 09:43 - 00002214 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-08-11 09:37 - 2013-08-11 09:37 - 00785024 _____ (Google Inc.) C:\Users\Moritz\Downloads\googleupdatesetup.exe 2013-08-11 09:37 - 2013-08-11 09:37 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-11 09:37 - 2013-08-11 09:37 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-11 09:21 - 2013-08-11 09:20 - 03880313 _____ C:\Users\Moritz\Downloads\MithPack-TEMPFIX-162.zip 2013-08-11 09:20 - 2013-08-11 09:19 - 04016863 _____ C:\Users\Moritz\Downloads\SteamIslands.zip 2013-08-10 18:49 - 2013-08-10 18:49 - 00002030 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-10 15:55 - 2013-08-10 15:54 - 03784176 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta.exe 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\UpdatusUser\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\Moritz\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\German Truck Simulator 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Program Files (x86)\German Truck Simulator 2013-08-05 22:21 - 2013-08-05 22:21 - 00512406 _____ C:\Users\Moritz\Documents\Fantasia.world 2013-08-05 12:38 - 2013-08-04 22:22 - 01443026 _____ C:\Users\Moritz\Desktop\Fantasia.world 2013-08-04 22:22 - 2013-08-04 22:22 - 01439185 _____ C:\Users\Moritz\Desktop\Fantasia.1.world 2013-08-01 13:54 - 2013-08-01 13:54 - 00001869 _____ C:\Users\Moritz\Desktop\WorldPainter.lnk 2013-08-01 13:53 - 2013-08-01 13:53 - 03060336 _____ (pepsoft.org) C:\Users\Moritz\Downloads\worldpainter_64_1.5.0.exe 2013-08-01 10:39 - 2013-07-31 20:57 - 00000000 ____D C:\Users\Moritz\AppData\Local\Dxtory Software 2013-07-31 20:57 - 2013-07-31 20:57 - 00001184 _____ C:\Users\Moritz\Desktop\Dxtory.lnk 2013-07-31 20:57 - 2013-07-31 20:57 - 00000000 ____D C:\Program Files (x86)\Dxtory Software 2013-07-31 20:56 - 2013-07-31 20:56 - 04135551 _____ (Dxtory Software ) C:\Users\Moritz\Downloads\DxtorySetup2.0.122.exe 2013-07-31 09:49 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD Files to move or delete: ==================== C:\Users\Moritz\worldpainter_64_1.5.5.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-27 11:24 ==================== End Of Log ============================ |
30.08.2013, 20:38 | #14 |
/// the machine /// TB-Ausbilder | Firefox Problem http://download.bleepingcomputer.com...7/wuauserv.reg laden und ausführen, erlauben. reboot, frisches FSS und FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.08.2013, 12:12 | #15 |
| Firefox Problem FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-08-2013 01 Ran by Moritz (administrator) on MORITZ-PC on 31-08-2013 11:51:44 Running from C:\Users\Moritz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Adobe Systems Incorporated) c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Windows\system32\mfevtps.exe (Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe (Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\CCDashServer.exe () C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe () C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe () C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe () C:\Program Files\Plantronics\GameCom780\GameCom780.exe (PC Drivers Headquarters) C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Huawei Technologies Co., Ltd.) C:\Users\Moritz\AppData\Roaming\Telekom Internet Manager\ouc.exe (Akamai Technologies, Inc.) C:\Users\Moritz\AppData\Local\Akamai\netsession_win.exe () C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe (Akamai Technologies, Inc.) C:\Users\Moritz\AppData\Local\Akamai\netsession_win.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe () C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe (Secure Banking) C:\Program Files (x86)\Secure Banking\SecureBanking.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe () C:\Program Files (x86)\Secure Banking\sbservice.exe (CyberLink Corp.) C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe (cyberlink) C:\Program Files (x86)\Cyberlink\Shared files\brs.exe () C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe (McAfee, Inc.) C:\Program Files\McAfee.com\Agent\mcagent.exe (Aeria Games & Entertainment) C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (McAfee, Inc.) c:\PROGRA~2\mcafee\SITEAD~1\saui.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Dell Products, LP.) c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [626552 2012-04-09] (Alps Electric Co., Ltd.) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-02-14] (IDT, Inc.) HKLM\...\Run: [QuickSet] - c:\Program Files\Dell\QuickSet\QuickSet.exe [4365984 2012-03-12] (Dell Inc.) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] () HKLM\...\Run: [IntelMyWiFiDashboard] - C:\Program Files\Intel\WiFi\bin\CCDashServer.exe [4966912 2012-03-30] (Intel® Corporation) HKLM\...\Run: [BLEServicesCtrl] - C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [120592 2012-01-10] () HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2012-01-12] (Intel Corporation) HKLM\...\Run: [DellStage] - C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj [483424 2012-02-01] () HKLM\...\Run: [Stage Remote] - C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe [2022976 2011-06-28] () HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated) HKLM\...\Run: [GamecomSound] - C:\Program Files\Plantronics\GameCom780\GameCom780.exe [777448 2011-12-01] () HKLM\...\Policies\Explorer: [NoRun] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKCU\...\Run: [Driver Whiz] - C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [3527608 2012-11-12] (PC Drivers Headquarters) HKCU\...\Run: [HW_OPENEYE_OUC_Telekom Internet Manager] - C:\Program Files (x86)\Telekom\InternetManager_H\UpdateDog\ouc.exe [116064 2010-12-28] (Huawei Technologies Co., Ltd.) HKCU\...\Run: [Driver Detective] - C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe [3527608 2012-11-12] (PC Drivers Headquarters) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Moritz\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [Dxtory Update Checker 2.0] - C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software) HKCU\...\Run: [SecureBanking] - C:\Program Files (x86)\Secure Banking\SecureBanking.exe [372736 2012-09-10] (Secure Banking) HKCU\...\Policies\Explorer: [NoSaveSettings] 1 MountPoints2: {19fc124d-dfcf-11e1-abd9-806e6f6e6963} - E:\setup.exe HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [577024 2012-03-07] (Creative Technology Ltd) HKLM-x32\...\Run: [Dell DataSafe Online] - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.) HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2010-10-01] (CyberLink Corp.) HKLM-x32\...\Run: [PDVD9LanguageShortcut] - C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-09-18] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe [76872 2012-03-27] (cyberlink) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [37960 2013-05-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [NeroLauncher] - C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe [66872 2012-03-11] () HKLM-x32\...\Run: [AccuWeatherWidget] - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj [2835443 2012-02-01] () HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [DataCardMonitor] - C:\Program Files (x86)\Telekom\InternetManager_H\DataCardMonitor.exe [259424 2013-04-10] (Huawei Technologies Co., Ltd.) HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [1532992 2013-03-13] (McAfee, Inc.) HKLM-x32\...\Run: [Aeria Ignite] - C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-15] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: 0 [97280 2009-07-14] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: ProxTube - {0AA2810A-F009-4BD7-A10A-32F140A1B9F3} - C:\Users\Moritz\AppData\LocalLow\ProxTube\IE\ProxTube.dll (Malte Goetz) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\ovrpeuoq.default FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @mcafee.com/MVT - C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll (McAfee, Inc.) FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\ovrpeuoq.default\Extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}.xpi FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK Chrome: ======= CHR HomePage: hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={97E8337D-318A-11E2-99C1-685D43F81BF9} CHR RestoreOnStartup: "hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={97E8337D-318A-11E2-99C1-685D43F81BF9}", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=48&cc=", "hxxp://search.iminent.com/?appId=8C23518F-7CF9-4B86-8615-966552B59FA0", "hxxp://search.babylon.com/?affID=115038&tt=201112_1849_4712_1&babsrc=HP_ss_cr&mntrId=141c7b8f000000000000685d43f81bf6", "hxxp://www.searchnu.com/406", "hxxp://search.nation.com/?orig=HP&affid=801&cztbid=233971303", "hxxp://search.conduit.com/?CUI=UN33859423212177427&ctid=CT3241949&SearchSource=48", "hxxp://isearch.babylon.com/?affID=115038&tt=201112_1849_4712_1&babsrc=HP_ss_gr2&mntrId=141c7b8f000000000000685d43f81bf6", "hxxp://search.fbdownloader.com/?channel=sfde203fbdgy21" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Extension: (Google Docs) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR Extension: (Gmail) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 ==================== Services (Whitelisted) ================= S2 CLKMSVC10_9EC60124; C:\Program Files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe [242448 2012-03-27] (CyberLink) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3128856 2012-02-28] (devolo AG) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [344928 2011-01-28] () R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-03-28] (Intel Corporation) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [384048 2013-02-25] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [241456 2013-02-19] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218760 2013-02-19] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-02-19] (McAfee, Inc.) R2 MOBKbackup; C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe [231224 2010-04-13] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-03-29] () R2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe [132056 2012-07-17] (Symantec Corporation) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-03-29] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-02-19] (McAfee, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.) R3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-03-28] (Intel Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179280 2013-02-19] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [309840 2013-02-19] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [515968 2013-02-19] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [771536 2013-02-19] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106552 2013-02-19] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340216 2013-02-19] (McAfee, Inc.) R1 MOBKFilter; C:\Windows\System32\DRIVERS\MOBK.sys [66040 2010-04-13] (Mozy, Inc.) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2012-01-31] (CACE Technologies) S3 PlantronicsGC; C:\Windows\System32\drivers\PLTGC.sys [1327104 2011-11-05] (C-Media Electronics Inc) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) U3 mfeavfk01; No ImagePath S3 xhunter1; \??\C:\Windows\xhunter1.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-31 11:49 - 2013-08-31 11:49 - 00006176 _____ C:\Users\Moritz\Downloads\wuauserv.reg 2013-08-30 17:12 - 2013-08-30 17:12 - 00028691 _____ C:\Users\Moritz\Downloads\Addition.txt 2013-08-30 17:12 - 2013-08-30 17:12 - 00000000 ____D C:\FRST 2013-08-30 17:10 - 2013-08-31 11:50 - 00002282 _____ C:\Users\Moritz\Downloads\FSS.txt 2013-08-30 17:10 - 2013-08-30 17:10 - 00358571 _____ (Farbar) C:\Users\Moritz\Downloads\FSS.exe 2013-08-30 16:08 - 2013-08-30 16:08 - 00001076 _____ C:\Users\Public\Desktop\Secure Banking.lnk 2013-08-30 16:08 - 2013-08-30 16:08 - 00000000 ____D C:\Program Files (x86)\Secure Banking 2013-08-30 09:46 - 2013-08-30 09:46 - 00448512 _____ (OldTimer Tools) C:\Users\Moritz\Downloads\TFC.exe 2013-08-30 09:36 - 2013-08-30 09:36 - 00818944 _____ C:\Users\Moritz\Downloads\adblockplus-2.2.4.xpi.zip 2013-08-30 09:30 - 2013-08-30 09:31 - 00003158 _____ C:\DelFix.txt 2013-08-29 18:45 - 2013-08-29 18:45 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-28 20:38 - 2013-08-30 17:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-28 20:38 - 2013-08-28 20:38 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-28 20:38 - 2013-08-28 20:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-28 20:38 - 2013-08-28 20:38 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-28 20:31 - 2013-08-28 20:32 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Mozilla 2013-08-28 20:31 - 2013-08-28 20:31 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-28 20:31 - 2013-08-28 20:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-28 20:31 - 2013-08-28 20:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-28 20:22 - 2013-08-28 20:22 - 00001039 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\Users\Moritz\AppData\Local\VS Revo Group 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\Program Files\VS Revo Group 2013-08-28 20:22 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys 2013-08-28 20:21 - 2013-08-28 20:21 - 10031224 _____ (VS Revo Group ) C:\Users\Moritz\Downloads\RevoUninProSetup.exe 2013-08-27 20:01 - 2013-08-27 20:01 - 06384214 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta(2).exe 2013-08-26 19:48 - 2013-08-26 19:48 - 00000000 ____D C:\Program Files (x86)\Dell Digital Delivery 2013-08-25 20:11 - 2013-08-25 20:11 - 01170448 _____ C:\Users\Moritz\Documents\Themen Welt.world 2013-08-25 12:31 - 2013-08-25 12:32 - 03076208 _____ (pepsoft.org) C:\Users\Moritz\worldpainter_64_1.5.5.exe 2013-08-24 21:17 - 2013-08-24 21:17 - 06445065 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta(1).exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 20:18 - 2013-08-23 20:18 - 00903080 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jxpiinstall.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-23 20:11 - 2013-08-23 20:11 - 00000000 ____D C:\Program Files\Java 2013-08-21 19:22 - 2013-08-21 19:22 - 00011688 _____ C:\Users\Moritz\Downloads\stereofunk.zip 2013-08-16 08:20 - 2013-08-16 08:20 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie - Kopie (2) 2013-08-14 23:02 - 2013-08-14 23:02 - 00000000 ____D C:\Users\Public\Desktop\CC Support 2013-08-14 21:15 - 2013-08-14 21:15 - 00003160 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-14 17:34 - 2013-08-14 17:34 - 00000207 _____ C:\Windows\tweaking.com-regbackup-MORITZ-PC-Microsoft-Windows-7-Home-Premium-(64-Bit).dat 2013-08-14 17:34 - 2013-08-14 17:34 - 00000000 ____D C:\RegBackup 2013-08-14 17:05 - 2013-08-14 21:13 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-08-14 17:04 - 2013-08-14 17:34 - 03263349 _____ C:\Users\Moritz\Downloads\tweaking.com_windows_repair_aio.zip 2013-08-14 09:57 - 2013-08-14 09:57 - 00001785 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iTunes 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iPod 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-14 09:43 - 2013-08-23 20:11 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-14 09:39 - 2013-08-14 09:42 - 33150376 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jre-7u25-windows-x64.exe 2013-08-14 09:31 - 2013-08-14 09:31 - 01069032 _____ (Solid State Networks) C:\Users\Moritz\Downloads\install_flashplayer11x32_ltr5x64d_awc_aih.exe 2013-08-14 09:22 - 2013-08-14 09:22 - 00001071 _____ C:\Users\Moritz\Desktop\Secunia PSI.lnk 2013-08-14 09:21 - 2013-08-14 09:21 - 03272136 _____ (Secunia) C:\Users\Moritz\Downloads\PSISetup711.exe 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Users\Moritz\AppData\Local\Secunia PSI 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-08-13 13:15 - 2013-08-13 13:15 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin 2013-08-13 13:14 - 2013-08-13 13:14 - 03541664 _____ (Aeria Games & Entertainment) C:\Users\Moritz\Downloads\aeria_ignite_install(1).exe 2013-08-12 17:08 - 2013-08-12 17:08 - 00002958 _____ C:\Users\Moritz\Documents\....txt 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Malwarebytes 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-12 16:57 - 2013-08-12 16:57 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Moritz\Downloads\mbam-setup-1.75.0.1300.exe 2013-08-12 16:22 - 2013-08-30 09:30 - 00000000 ____D C:\Windows\ERUNT 2013-08-12 16:22 - 2013-08-12 16:22 - 00003122 _____ C:\Windows\System32\Tasks\{1EA7E4A0-B683-44E3-A658-ECE1ECBF2E94} 2013-08-11 22:10 - 2013-08-11 22:10 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie 2013-08-11 09:43 - 2013-08-11 09:43 - 00002214 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-08-11 09:37 - 2013-08-31 11:48 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-11 09:37 - 2013-08-30 16:42 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-11 09:37 - 2013-08-11 09:37 - 00785024 _____ (Google Inc.) C:\Users\Moritz\Downloads\googleupdatesetup.exe 2013-08-11 09:37 - 2013-08-11 09:37 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-11 09:37 - 2013-08-11 09:37 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-11 09:20 - 2013-08-11 09:21 - 03880313 _____ C:\Users\Moritz\Downloads\MithPack-TEMPFIX-162.zip 2013-08-11 09:19 - 2013-08-11 09:20 - 04016863 _____ C:\Users\Moritz\Downloads\SteamIslands.zip 2013-08-10 18:49 - 2013-08-10 18:49 - 00002030 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-10 15:59 - 2013-08-28 19:03 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Craften Terminal 2013-08-10 15:54 - 2013-08-10 15:55 - 03784176 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta.exe 2013-08-06 18:45 - 2013-08-13 10:20 - 00000000 ____D C:\Users\Moritz\Documents\German Truck Simulator 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\UpdatusUser\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\Moritz\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\German Truck Simulator 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Program Files (x86)\German Truck Simulator 2013-08-05 22:21 - 2013-08-05 22:21 - 00512406 _____ C:\Users\Moritz\Documents\Fantasia.world 2013-08-04 22:22 - 2013-08-05 12:38 - 01443026 _____ C:\Users\Moritz\Desktop\Fantasia.world 2013-08-04 22:22 - 2013-08-04 22:22 - 01439185 _____ C:\Users\Moritz\Desktop\Fantasia.1.world 2013-08-01 13:54 - 2013-08-25 20:14 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\WorldPainter 2013-08-01 13:54 - 2013-08-01 13:54 - 00001869 _____ C:\Users\Moritz\Desktop\WorldPainter.lnk 2013-08-01 13:53 - 2013-08-25 12:32 - 00000000 ____D C:\Program Files\WorldPainter 2013-08-01 13:53 - 2013-08-01 13:53 - 03060336 _____ (pepsoft.org) C:\Users\Moritz\Downloads\worldpainter_64_1.5.0.exe ==================== One Month Modified Files and Folders ======= 2013-08-31 11:51 - 2013-08-31 11:51 - 01587214 _____ (Farbar) C:\Users\Moritz\Downloads\FRST64.exe 2013-08-31 11:50 - 2013-08-30 17:10 - 00002282 _____ C:\Users\Moritz\Downloads\FSS.txt 2013-08-31 11:50 - 2012-08-06 23:06 - 01373132 _____ C:\Windows\WindowsUpdate.log 2013-08-31 11:49 - 2013-08-31 11:49 - 00006176 _____ C:\Users\Moritz\Downloads\wuauserv.reg 2013-08-31 11:48 - 2013-08-11 09:37 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-31 11:48 - 2013-07-22 19:18 - 00000000 ____D C:\Users\Moritz\AppData\Local\LogMeIn Hamachi 2013-08-31 11:48 - 2013-01-14 04:06 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Skype 2013-08-31 11:48 - 2012-08-06 23:31 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup 2013-08-31 11:47 - 2012-08-06 16:02 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-31 11:47 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-31 11:47 - 2009-07-14 06:51 - 00086226 _____ C:\Windows\setupact.log 2013-08-30 17:12 - 2013-08-30 17:12 - 00028691 _____ C:\Users\Moritz\Downloads\Addition.txt 2013-08-30 17:12 - 2013-08-30 17:12 - 00000000 ____D C:\FRST 2013-08-30 17:12 - 2013-08-28 20:38 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-30 17:10 - 2013-08-30 17:10 - 00358571 _____ (Farbar) C:\Users\Moritz\Downloads\FSS.exe 2013-08-30 17:09 - 2013-07-17 22:13 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\.minecraft 2013-08-30 16:42 - 2013-08-11 09:37 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-30 16:08 - 2013-08-30 16:08 - 00001076 _____ C:\Users\Public\Desktop\Secure Banking.lnk 2013-08-30 16:08 - 2013-08-30 16:08 - 00000000 ____D C:\Program Files (x86)\Secure Banking 2013-08-30 16:08 - 2009-07-14 06:45 - 00021072 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-30 16:08 - 2009-07-14 06:45 - 00021072 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-30 16:06 - 2010-11-21 08:50 - 00697322 _____ C:\Windows\system32\perfh007.dat 2013-08-30 16:06 - 2010-11-21 08:50 - 00148328 _____ C:\Windows\system32\perfc007.dat 2013-08-30 16:06 - 2009-07-14 07:13 - 01614036 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-30 09:46 - 2013-08-30 09:46 - 00448512 _____ (OldTimer Tools) C:\Users\Moritz\Downloads\TFC.exe 2013-08-30 09:36 - 2013-08-30 09:36 - 00818944 _____ C:\Users\Moritz\Downloads\adblockplus-2.2.4.xpi.zip 2013-08-30 09:31 - 2013-08-30 09:30 - 00003158 _____ C:\DelFix.txt 2013-08-30 09:30 - 2013-08-12 16:22 - 00000000 ____D C:\Windows\ERUNT 2013-08-30 09:26 - 2010-11-21 05:47 - 00057038 _____ C:\Windows\PFRO.log 2013-08-29 22:16 - 2013-01-22 21:40 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\TS3Client 2013-08-29 18:45 - 2013-08-29 18:45 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-29 18:45 - 2012-10-23 19:23 - 00000000 ____D C:\Users\Moritz\AppData\Local\Google 2013-08-29 18:45 - 2012-10-23 19:23 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-28 20:38 - 2013-08-28 20:38 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-28 20:38 - 2013-08-28 20:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-28 20:38 - 2013-08-28 20:38 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-28 20:38 - 2012-10-23 14:05 - 00000000 ____D C:\Users\Moritz\AppData\Local\Adobe 2013-08-28 20:32 - 2013-08-28 20:31 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Mozilla 2013-08-28 20:31 - 2013-08-28 20:31 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-28 20:31 - 2013-08-28 20:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-28 20:31 - 2013-08-28 20:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-28 20:29 - 2012-10-23 19:23 - 00000000 ____D C:\Users\Moritz\AppData\Local\Deployment 2013-08-28 20:22 - 2013-08-28 20:22 - 00001039 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\Users\Moritz\AppData\Local\VS Revo Group 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-08-28 20:22 - 2013-08-28 20:22 - 00000000 ____D C:\Program Files\VS Revo Group 2013-08-28 20:21 - 2013-08-28 20:21 - 10031224 _____ (VS Revo Group ) C:\Users\Moritz\Downloads\RevoUninProSetup.exe 2013-08-28 19:03 - 2013-08-10 15:59 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Craften Terminal 2013-08-27 20:01 - 2013-08-27 20:01 - 06384214 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta(2).exe 2013-08-27 20:01 - 2013-07-15 19:33 - 00001105 _____ C:\Users\Public\Desktop\Craften Terminal.lnk 2013-08-27 20:01 - 2013-06-14 20:58 - 00000000 ____D C:\Program Files (x86)\Craften Terminal 2013-08-26 19:48 - 2013-08-26 19:48 - 00000000 ____D C:\Program Files (x86)\Dell Digital Delivery 2013-08-25 20:14 - 2013-08-01 13:54 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\WorldPainter 2013-08-25 20:11 - 2013-08-25 20:11 - 01170448 _____ C:\Users\Moritz\Documents\Themen Welt.world 2013-08-25 12:32 - 2013-08-25 12:31 - 03076208 _____ (pepsoft.org) C:\Users\Moritz\worldpainter_64_1.5.5.exe 2013-08-25 12:32 - 2013-08-01 13:53 - 00000000 ____D C:\Program Files\WorldPainter 2013-08-25 12:31 - 2012-10-23 13:58 - 00000000 ____D C:\Users\Moritz 2013-08-24 21:17 - 2013-08-24 21:17 - 06445065 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta(1).exe 2013-08-24 13:30 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-23 20:20 - 2013-08-23 20:20 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 20:20 - 2013-08-23 20:20 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 20:20 - 2012-10-23 19:35 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-08-23 20:18 - 2013-08-23 20:18 - 00903080 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jxpiinstall.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-08-23 20:11 - 2013-08-23 20:11 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-23 20:11 - 2013-08-23 20:11 - 00000000 ____D C:\Program Files\Java 2013-08-23 20:11 - 2013-08-14 09:43 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-23 20:11 - 2012-11-25 11:37 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-08-21 19:22 - 2013-08-21 19:22 - 00011688 _____ C:\Users\Moritz\Downloads\stereofunk.zip 2013-08-18 19:04 - 2013-01-22 20:42 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2013-08-16 08:20 - 2013-08-16 08:20 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie - Kopie (2) 2013-08-14 23:02 - 2013-08-14 23:02 - 00000000 ____D C:\Users\Public\Desktop\CC Support 2013-08-14 21:19 - 2012-10-23 13:58 - 00059280 _____ C:\Users\Moritz\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-14 21:19 - 2010-11-21 09:00 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-08-14 21:18 - 2009-07-14 06:45 - 00275512 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-14 21:15 - 2013-08-14 21:15 - 00003160 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-14 21:13 - 2013-08-14 17:05 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-08-14 21:12 - 2009-07-14 04:34 - 00000471 _____ C:\Windows\win.ini 2013-08-14 17:38 - 2009-07-14 01:46 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll 2013-08-14 17:34 - 2013-08-14 17:34 - 00000207 _____ C:\Windows\tweaking.com-regbackup-MORITZ-PC-Microsoft-Windows-7-Home-Premium-(64-Bit).dat 2013-08-14 17:34 - 2013-08-14 17:34 - 00000000 ____D C:\RegBackup 2013-08-14 17:34 - 2013-08-14 17:04 - 03263349 _____ C:\Users\Moritz\Downloads\tweaking.com_windows_repair_aio.zip 2013-08-14 09:57 - 2013-08-14 09:57 - 00001785 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iTunes 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files\iPod 2013-08-14 09:57 - 2013-08-14 09:57 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-14 09:42 - 2013-08-14 09:39 - 33150376 _____ (Oracle Corporation) C:\Users\Moritz\Downloads\jre-7u25-windows-x64.exe 2013-08-14 09:31 - 2013-08-14 09:31 - 01069032 _____ (Solid State Networks) C:\Users\Moritz\Downloads\install_flashplayer11x32_ltr5x64d_awc_aih.exe 2013-08-14 09:22 - 2013-08-14 09:22 - 00001071 _____ C:\Users\Moritz\Desktop\Secunia PSI.lnk 2013-08-14 09:21 - 2013-08-14 09:21 - 03272136 _____ (Secunia) C:\Users\Moritz\Downloads\PSISetup711.exe 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Users\Moritz\AppData\Local\Secunia PSI 2013-08-14 09:21 - 2013-08-14 09:21 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-08-13 13:15 - 2013-08-13 13:15 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin 2013-08-13 13:14 - 2013-08-13 13:14 - 03541664 _____ (Aeria Games & Entertainment) C:\Users\Moritz\Downloads\aeria_ignite_install(1).exe 2013-08-13 10:20 - 2013-08-06 18:45 - 00000000 ____D C:\Users\Moritz\Documents\German Truck Simulator 2013-08-12 23:02 - 2013-07-25 22:05 - 00000000 ____D C:\Program Files\MAXON 2013-08-12 22:59 - 2013-07-25 09:52 - 00000000 ____D C:\Fraps 2013-08-12 22:01 - 2013-02-10 20:14 - 00000532 _____ C:\Users\Moritz\Desktop\settings.xml 2013-08-12 17:08 - 2013-08-12 17:08 - 00002958 _____ C:\Users\Moritz\Documents\....txt 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Malwarebytes 2013-08-12 16:58 - 2013-08-12 16:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-12 16:57 - 2013-08-12 16:57 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Moritz\Downloads\mbam-setup-1.75.0.1300.exe 2013-08-12 16:30 - 2013-05-17 14:22 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Uniblue 2013-08-12 16:30 - 2013-05-17 14:22 - 00000000 ____D C:\Program Files (x86)\Uniblue 2013-08-12 16:22 - 2013-08-12 16:22 - 00003122 _____ C:\Windows\System32\Tasks\{1EA7E4A0-B683-44E3-A658-ECE1ECBF2E94} 2013-08-12 15:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-12 09:47 - 2009-07-14 04:34 - 62652416 _____ C:\Windows\system32\config\software.esg.bak 2013-08-12 09:47 - 2009-07-14 04:34 - 19136512 _____ C:\Windows\system32\config\system.esg.bak 2013-08-12 09:47 - 2009-07-14 04:34 - 01331200 _____ C:\Windows\system32\config\default.esg.bak 2013-08-12 09:47 - 2009-07-14 04:34 - 00057344 _____ C:\Windows\system32\config\sam.esg.bak 2013-08-11 22:10 - 2013-08-11 22:10 - 00000000 ____D C:\Users\Moritz\Desktop\Fantasia - Kopie - Kopie 2013-08-11 21:06 - 2009-07-14 04:34 - 23347200 _____ C:\Windows\system32\config\components.esg.bak 2013-08-11 19:55 - 2012-11-10 20:46 - 00000000 ____D C:\Users\Moritz\AppData\Local\Nero 2013-08-11 09:43 - 2013-08-11 09:43 - 00002214 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-08-11 09:37 - 2013-08-11 09:37 - 00785024 _____ (Google Inc.) C:\Users\Moritz\Downloads\googleupdatesetup.exe 2013-08-11 09:37 - 2013-08-11 09:37 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-11 09:37 - 2013-08-11 09:37 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-11 09:21 - 2013-08-11 09:20 - 03880313 _____ C:\Users\Moritz\Downloads\MithPack-TEMPFIX-162.zip 2013-08-11 09:20 - 2013-08-11 09:19 - 04016863 _____ C:\Users\Moritz\Downloads\SteamIslands.zip 2013-08-10 18:49 - 2013-08-10 18:49 - 00002030 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-10 15:55 - 2013-08-10 15:54 - 03784176 _____ (Craften Dev Team ) C:\Users\Moritz\Downloads\craftenterminal-beta.exe 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\UpdatusUser\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00001377 _____ C:\Users\Moritz\Desktop\German Truck Simulator.lnk 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\German Truck Simulator 2013-08-06 18:44 - 2013-08-06 18:44 - 00000000 ____D C:\Program Files (x86)\German Truck Simulator 2013-08-05 22:21 - 2013-08-05 22:21 - 00512406 _____ C:\Users\Moritz\Documents\Fantasia.world 2013-08-05 12:38 - 2013-08-04 22:22 - 01443026 _____ C:\Users\Moritz\Desktop\Fantasia.world 2013-08-04 22:22 - 2013-08-04 22:22 - 01439185 _____ C:\Users\Moritz\Desktop\Fantasia.1.world 2013-08-01 13:54 - 2013-08-01 13:54 - 00001869 _____ C:\Users\Moritz\Desktop\WorldPainter.lnk 2013-08-01 13:53 - 2013-08-01 13:53 - 03060336 _____ (pepsoft.org) C:\Users\Moritz\Downloads\worldpainter_64_1.5.0.exe 2013-08-01 10:39 - 2013-07-31 20:57 - 00000000 ____D C:\Users\Moritz\AppData\Local\Dxtory Software Files to move or delete: ==================== C:\Users\Moritz\worldpainter_64_1.5.5.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-27 11:24 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Farbar Service Scanner Version: 28-08-2013 Ran by Moritz (administrator) on 31-08-2013 at 11:53:31 Running from "C:\Users\Moritz\Downloads" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ wuauserv Service is not running. Checking service configuration: The start type of wuauserv service is OK. The ImagePath of wuauserv service is OK. The ServiceDll of wuauserv service is OK. Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** |
Themen zu Firefox Problem |
ansehen, besuch, besucht, dickes, drücke, firefox, firefox problem, folge, folgendes, gescannt, guten, hilfe, klicke, längerem, probelm, proble, problem, seite, spyhunter, später ansehen, stets, thread, wegbekomme, zurück gehen nicht möglich, ändert |