|
Plagegeister aller Art und deren Bekämpfung: PC Langsam, Hängt sich auf ...Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
02.09.2013, 00:55 | #1 |
| PC Langsam, Hängt sich auf ... Hi, ich habe jetzt seit ner gute Woche das Problem das mein PC extrem Langsam geworden ist, Spielen ist so gut wie unmöglich geworden schon das aufrufen von Chrome ist ne Qual geworden selbst das Hochfahren dauert extrem lange, Programme hängen sich auch jetzt des öfteren auf ich weiß nun nicht ob es ein Virus ist oder sonstiges und hoffe ihr hier könnt mir etwas weiter Helfen Habe Win7 mfg Kazu |
02.09.2013, 05:18 | #2 |
/// the machine /// TB-Ausbilder | PC Langsam, Hängt sich auf ... hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
02.09.2013, 11:31 | #3 |
| PC Langsam, Hängt sich auf ... FRST.txt
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-09-2013 04 Ran by Sandro (administrator) on SANDRO-PC on 02-09-2013 12:16:28 Running from C:\Users\Sandro\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Spigot, Inc.) C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Nero AG) C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe () C:\Users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStatsUpdater.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe () C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Motorola Mobility Inc.) C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoCast.exe (Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Akamai Technologies, Inc.) C:\Users\Sandro\AppData\Local\Akamai\netsession_win.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (Dropbox, Inc.) C:\Users\Sandro\AppData\Roaming\Dropbox\bin\Dropbox.exe (Akamai Technologies, Inc.) C:\Users\Sandro\AppData\Local\Akamai\netsession_win.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (Crawler, LLC) C:\Program Files (x86)\SiteRanker\SiteRankTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Windows\system32\dmwu.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe () C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Aeria Games & Entertainment) C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe () C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe (Spigot, Inc.) C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot Inc) C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings64.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe () C:\OEM\USBDECTION\USBS3S4Detection.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE () C:\Windows\SysWOW64\jmdp\stij.exe () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-02-01] (Egis Technology Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9955872 2010-01-12] (Realtek Semiconductor) HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation) HKLM\...\Policies\Explorer: [NoActiveDesktop] 1 HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1 HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKCU\...\Run: [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] () HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-10] (Google Inc.) HKCU\...\Run: [MotoCast] - C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk [2059 2012-04-26] () HKCU\...\Run: [KiesHelper] - C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe [954256 2012-03-31] (Samsung) HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-03-31] () HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1811880 2013-08-28] (Valve Corporation) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Sandro\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Run: [Google Update] - C:\Users\Sandro\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-03-31] (Google Inc.) MountPoints2: J - J:\LaunchU3.exe -a MountPoints2: {767737a1-6589-11e0-bf5f-d027880c8f52} - L:\LaunchU3.exe -a MountPoints2: {77df8f11-8fce-11e1-8a99-d027880c8f52} - F:\MotoCastSetup.exe -a MountPoints2: {7d5f6f93-8fdf-11e0-8d6b-d027880c8f52} - I:\Autorun.exe MountPoints2: {f58e7370-f623-11e0-a974-d027880c8f52} - F:\VTP_Manager.exe HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-02-01] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201512 2009-12-25] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [401192 2009-12-25] (Egis Technology Inc.) HKLM-x32\...\Run: [Hotkey Utility] - C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [611872 2010-08-04] () HKLM-x32\...\Run: [MDS_Menu] - C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [ArcadeMovieService] - C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe [124136 2010-02-05] (CyberLink Corp.) HKLM-x32\...\Run: [facemoods] - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe [362200 2011-09-05] (facemoods.com) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3521424 2012-03-31] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [SweetIM] - C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.) HKLM-x32\...\Run: [Sweetpacks Communicator] - C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.) HKLM-x32\...\Run: [SiteRanker] - C:\Program Files (x86)\SiteRanker\SiteRankTray.exe [320000 2012-12-06] (Crawler, LLC) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-01-30] (DivX, LLC) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) HKLM-x32\...\Run: [Aeria Ignite] - C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [SearchSettings] - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe [1345856 2013-08-28] (Spigot, Inc.) HKU\David\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-10] (Google Inc.) HKU\David\...\Run: [Google Update] - C:\Users\David\AppData\Local\Google\Update\GoogleUpdate.exe [135664 2011-03-31] (Google Inc.) HKU\David\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKU\David\...\Run: [Facebook Update] - C:\Users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-11] (Facebook Inc.) HKU\David\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-03-31] () HKU\David\...\Run: [Akamai NetSession Interface] - C:\Users\David\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\DefaultAppPool\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\Katrin\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKU\Katrin\...\Run: [Google Update] - C:\Users\Katrin\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-10-02] (Google Inc.) HKU\Katrin\...\Run: [Facebook Update] - C:\Users\Katrin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.) HKU\Katrin\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-10] (Google Inc.) HKU\UpdatusUser\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Sandro\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== ProxyServer: 94.126.17.68:3128 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://home.sweetim.com/?crg=3.1010000.10025&barid={7542CD5D-49FE-11E2-93EB-D027880C8F52} HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_x3950&r=173603112607pe418v1l5w57j1v802 HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = my.daemon-search.com hxxp://search.conduit.com?searchsource=10&ctid=ct2967869 URLSearchHook: (No Name) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - No File URLSearchHook: (No Name) - {1ce76c93-a797-4ca2-ab3c-f4a6cfba3440} - No File URLSearchHook: (No Name) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - No File SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2967869 SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10025&barid={7542CD5D-49FE-11E2-93EB-D027880C8F52} SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=109958&tt=280612_5_&babsrc=SP_ss&mntrId=1258acb3000000000000d027880c8f52 SearchScopes: HKCU - {0D7562AE-8EF6-416d-A838-AB665251703A} URL = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=109958&tt=280612_5_&babsrc=SP_ss&mntrId=1258acb3000000000000d027880c8f52 SearchScopes: HKCU - {16E21108-4AD7-49CB-844B-26AF3D1B9664} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} SearchScopes: HKCU - {1F096B29-E9DA-4D64-8D63-936BE7762CC5} URL = hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=1258acb3000000000000d027880c8f52&tlver=1.4.19.19&ss=1&affID=17393 SearchScopes: HKCU - {5F970FDE-702B-4ef9-920C-5F2848A5AF26} URL = hxxp://www.astroburn-search.com/search/web?q={searchTerms} SearchScopes: HKCU - {A4DA128C-FB95-455A-B07E-CEE9E929FAB3} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=E08FA42B-877A-408D-A7F1-897C028D941E&apn_sauid=22671F72-DD03-4AFE-A42F-65F9C805CA0D SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/mb155/?search={searchTerms}&loc=IB_DS&a=6R8wCgbVNs&i=26 SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10025&barid={7542CD5D-49FE-11E2-93EB-D027880C8F52} BHO: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - No File BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: No Name - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\PROGRA~2\SITERA~1\SiteRank.dll (Crawler, LLC) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - No File BHO-x32: Winload Toolbar - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.) BHO-x32: CescrtHlpr Object - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll (facemoods.com BHO) BHO-x32: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll (Montera Technologeis LTD) BHO-x32: AppGraffiti - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\PROGRA~2\APPGRA~1\APPGRA~1.DLL (Omega Partners Ltd) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: GhosteryStats - {C331A7D9-4187-464C-BE66-FDBC56C07678} - C:\Users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStats.dll (David Cancel) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Freemake.YoutubeButton - {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) BHO-x32: YTD Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\7.5\ytdToolbarIE.dll (Spigot, Inc.) BHO-x32: PricePeep - {FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} - C:\Program Files (x86)\PricePeep\pricepeep.dll (PricePeep) Toolbar: HKLM - No Name - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll (Montera Technologeis LTD) Toolbar: HKLM-x32 - Winload Toolbar - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.) Toolbar: HKLM-x32 - loadtbs - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\Sandro\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH) Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM-x32 - YTD Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\7.5\ytdToolbarIE.dll (Spigot, Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {1CE76C93-A797-4CA2-AB3C-F4A6CFBA3440} - No File Toolbar: HKCU - No Name - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No File Toolbar: HKCU - No Name - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - No File DPF: HKLM-x32 {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default FF user.js: detected! => C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\user.js FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Ask.com FF Homepage: hxxp://home.sweetim.com/?crg=3.1010000.10025&barid={7542CD5D-49FE-11E2-93EB-D027880C8F52} FF NetworkProxy: "type", 0 FF DefaultSearchEngine: Ask.com FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.132.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.3 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Sandro\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Sandro\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\searchplugins\absearch-search.xml FF SearchPlugin: C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\searchplugins\conduit.xml FF SearchPlugin: C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\searchplugins\MyStart Search.xml FF SearchPlugin: C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\searchplugins\sweetim.xml FF Extension: AppGraffiti - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\AppGraffiti@AppGraffiti.com FF Extension: Babylon - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\ffxtlbr@babylon.com FF Extension: Facemoods - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\ffxtlbr@Facemoods.com FF Extension: incredibar.com - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\ffxtlbr@incredibar.com FF Extension: No Name - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\staged FF Extension: GIGA Deutsch Community Toolbar - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{1ce76c93-a797-4ca2-ab3c-f4a6cfba3440} FF Extension: Winload - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} FF Extension: DownloadHelper - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9} FF Extension: DealPly - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} FF Extension: jid1-kV5U6puWw0Cdvg - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\jid1-kV5U6puWw0Cdvg@jetpack.xpi FF Extension: pricepeep - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\pricepeep@getpricepeep.com.xpi FF Extension: wtxpcom - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\wtxpcom@mybrowserbar.com FF Extension: youtubedownloader - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\youtubedownloader@mybrowserbar.com FF Extension: No Name - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Babylon - C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\Web Assistant\Firefox FF HKLM-x32\...\Firefox\Extensions: [downloader@finalvideotools.com] C:\Program Files (x86)\FinalVideoDownloader\Firefox FF HKLM-x32\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\Web Assistant\Firefox FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ FF HKLM-x32\...\Firefox\Extensions: [siteranker@siteranker.com] C:\Program Files (x86)\SiteRanker\firefox\ FF Extension: SiteRanker - C:\Program Files (x86)\SiteRanker\firefox\ FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 Chrome: ======= CHR HomePage: hxxp://home.sweetim.com/?crg=3.1010000.10025&barid={7542CD5D-49FE-11E2-93EB-D027880C8F52} CHR RestoreOnStartup: "https://www.google.de/" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\29.0.1547.62\pdf.dll () CHR Plugin: (Freemake np-plugin for google chrome) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0\npFreemake.dll () CHR Plugin: (Freemake np-plugin for google chrome) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0\npFreemakeYoutubeDownloader.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (PlayStation(R)Network Downloader Check Plug-in) - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll No File CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (ProxTube) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0 CHR Extension: (AppGraffiti) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl\1.0.1.1_0 CHR Extension: (YouTube) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Montiera Chrome Toolbar) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmbgdmijgopggjaelphhajpjldacbnba\1.0_0 CHR Extension: (Freemake Video Downloader) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0 CHR Extension: (Google Search) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Battlelog) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajcdbgpkfpghffojnlbjkadcobpbaid\1.0.4_0 CHR Extension: (Freemake Video Downloader) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0 CHR Extension: (GhosteryStats) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehmdnmbaomgmfmjiajhdfopgnbmgkcog\2.7.192_0 CHR Extension: (DealPly) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje\3.5.3.0_0 CHR Extension: (AdBlock) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_0 CHR Extension: (Quick Match BF3) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\iacjfjhinfbmljdpedecedhcghgmmdcf\1.1_0 CHR Extension: (Funmoods) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\2.1.0_0 CHR Extension: () - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigfdicgjnpjkhbnngdfgjfffmdaonfg\2_0 CHR Extension: (BattlelogPlus) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\lphojmgkbcmdjpaepolkjeienkacpjpi\1.38_0 CHR Extension: (BrowseToolE0191) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngnjhfpfhadncgafgbneeljaginimmmk\10.19.2.505_0 CHR Extension: (Battlelog: BF 3) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhdecopbclicngfcdmhinokemjlmcihf\0.1.2_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0 CHR Extension: (Gmail) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx CHR HKLM-x32\...\Chrome\Extension: [angobeimajilfhlcpeiccndaifchnppl] - C:\Program Files (x86)\AppGraffiti\Chrome\graff_chr.crx CHR HKLM-x32\...\Chrome\Extension: [bmbgdmijgopggjaelphhajpjldacbnba] - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibar.crx CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [dgldkplledicnbnnliodeffobaiaodaf] - C:\Program Files (x86)\SiteRanker\Chrome\siterank_c.crx CHR HKLM-x32\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx CHR HKLM-x32\...\Chrome\Extension: [ehmdnmbaomgmfmjiajhdfopgnbmgkcog] - C:\Users\Sandro\AppData\LocalLow\GhosteryStats\CHROME\GhosteryStats.crx CHR HKLM-x32\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx CHR HKLM-x32\...\Chrome\Extension: [ihflimipbcaljfnojhhknppphnnciiif] - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoods.crx CHR HKLM-x32\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx CHR HKLM-x32\...\Chrome\Extension: [licjnkifamhpbaefhdpacpmihicfbomb] - C:\Program Files (x86)\PricePeep\pricepeep.crx CHR HKLM-x32\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\Sandro\AppData\Local\CRE\ngnjhfpfhadncgafgbneeljaginimmmk.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx CHR HKLM-x32\...\Chrome\Extension: [ofahndfepeaeelmhdkjiihmofnokhmik] - C:\Users\Sandro\AppData\Local\Temp\tbch.crx CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx CHR StartMenuInternet: Google Chrome - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG) S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101376 2013-02-25] (Freemake) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-02-25] (Ellora Assets Corp.) R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [350720 2012-06-01] (Microsoft Corporation) R2 GhosteryStatsUpdater; C:\Users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStatsUpdater.exe [18432 2012-02-28] () R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1447728 2013-05-21] () S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2012-02-01] () S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-02-01] (Egis Technology Inc.) S3 npggsvc; C:\Windows\SysWow64\GameMon.des [4159984 2010-12-08] (INCA Internet Co., Ltd.) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-04-07] () R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [244904 2010-02-03] () S2 SystemStoreService; C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe [296448 2013-04-30] () R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2026304 2011-06-06] (TuneUp Software) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH) R2 USBS3S4Detection; C:\OEM\USBDECTION\USBS3S4Detection.exe [76320 2009-12-09] () R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation) S3 BRSptSvc; "C:\ProgramData\BitRaider\BRSptSvc.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-25] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-25] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-25] (Avira Operations GmbH & Co. KG) S3 DrvSnSht; C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys [132432 2010-06-01] (R-TT Inc.) S3 DrvSnSht; C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys [132432 2010-06-01] (R-TT Inc.) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-06-06] (DT Soft Ltd) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) S3 NPPTNT2; C:\Windows\SysWow64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) S3 R-ImageDisk; C:\Program Files (x86)\R-Drive Image\R-ImageDisk64.sys [187600 2010-10-16] (R-TT Inc.) S3 R-ImageDisk; C:\Program Files (x86)\R-Drive Image\R-ImageDisk64.sys [187600 2010-10-16] (R-TT Inc.) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [513080 2011-06-06] () S3 ss_bserd; C:\Windows\System32\DRIVERS\ss_bserd.sys [128000 2010-12-21] (MCCI Corporation) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [11856 2010-10-07] (TuneUp Software) U3 asxjenkp; C:\Windows\System32\Drivers\asxjenkp.sys [0 ] (Advanced Micro Devices) S3 BRDriver64; \??\C:\programdata\bitraider\BRDriver64.sys [x] S3 dump_wmimmc; \??\C:\AeriaGames\WolfTeam-DE\GameGuard\dump_wmimmc.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x] S3 X6va005; \??\C:\Users\Sandro\AppData\Local\Temp\0053C7D.tmp [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-02 12:16 - 2013-09-02 12:16 - 00000000 ____D C:\FRST 2013-09-02 12:14 - 2013-09-02 12:14 - 01951950 _____ (Farbar) C:\Users\Sandro\Downloads\FRST64.exe 2013-09-02 02:56 - 2013-09-02 02:56 - 00003088 _____ C:\Windows\System32\Tasks\{F741D114-8004-44D5-96EB-33971BBCD417} 2013-09-01 23:42 - 2013-09-01 23:43 - 60757752 _____ (Gazillion Entertainment ) C:\Users\Sandro\Downloads\marvelheroesinstaller.exe 2013-09-01 23:20 - 2013-09-01 23:21 - 00330518 _____ C:\Users\Sandro\Documents\cc_20130901_232036.reg 2013-09-01 23:11 - 2013-09-01 23:29 - 00000000 ____D C:\Users\Sandro\Downloads\CCEnhancer 2013-09-01 23:10 - 2013-09-01 23:11 - 00176719 _____ C:\Users\Sandro\Downloads\CCEnhancer-3.8-multilanguage.zip 2013-09-01 01:25 - 2013-09-01 01:25 - 00000000 ____D C:\Program Files (x86)\Frogwares 2013-08-31 23:58 - 2013-08-31 23:58 - 00614920 _____ C:\Windows\Minidump\083113-158606-01.dmp 2013-08-31 23:21 - 2013-08-31 23:21 - 00003088 _____ C:\Windows\System32\Tasks\{0D0E4C94-0C9F-48BA-A856-AA025793FD2C} 2013-08-31 11:52 - 2013-08-31 11:52 - 03367611 _____ C:\Users\David\Downloads\easyHalls.exe 2013-08-31 02:32 - 2013-08-31 02:32 - 00003088 _____ C:\Windows\System32\Tasks\{598B6998-980B-477A-B0AE-FA6585404995} 2013-08-30 22:50 - 2013-08-30 22:50 - 00000000 ____D C:\Program Files (x86)\YTD Toolbar 2013-08-30 22:50 - 2013-08-30 22:50 - 00000000 ____D C:\Program Files (x86)\Application Updater 2013-08-30 03:00 - 2013-08-30 03:00 - 00003088 _____ C:\Windows\System32\Tasks\{3E5317FD-A87C-4939-B5D3-EEBC998CEB85} 2013-08-29 02:48 - 2013-08-29 02:48 - 00003088 _____ C:\Windows\System32\Tasks\{FB0B0681-2A62-4A02-89EA-275B2BA27866} 2013-08-28 02:44 - 2013-08-28 02:44 - 00003088 _____ C:\Windows\System32\Tasks\{7DF15D2D-9E9F-46AC-A90F-13A20C4D983D} 2013-08-27 02:23 - 2013-08-27 02:23 - 00003088 _____ C:\Windows\System32\Tasks\{6034F774-F129-4A22-AF1B-08870102A4CF} 2013-08-26 03:39 - 2013-08-26 03:39 - 00003088 _____ C:\Windows\System32\Tasks\{00FE09DB-2041-4FE9-A8C7-6A3183FCB20A} 2013-08-26 03:01 - 2013-08-26 03:01 - 00003088 _____ C:\Windows\System32\Tasks\{C0C1C429-CC94-478F-938D-2A2437CF7F0E} 2013-08-25 12:53 - 2013-08-25 12:53 - 00301504 _____ C:\Users\David\Downloads\repetitperche.zip.exe 2013-08-25 12:51 - 2013-08-25 12:51 - 00705136 _____ C:\Users\David\Downloads\UltimateCodec.exe 2013-08-25 02:35 - 2013-08-25 02:35 - 00003088 _____ C:\Windows\System32\Tasks\{079FF58D-0420-425F-A404-A2C8847198A7} 2013-08-24 19:43 - 2013-08-24 19:43 - 01624064 _____ (Bandoo Media Inc) C:\Users\David\Downloads\iLividSetup-r422-n-bf.exe 2013-08-24 19:28 - 2013-08-24 19:28 - 00714352 _____ C:\Users\David\Downloads\ZipOpenerSetup(1).exe 2013-08-24 19:28 - 2013-08-24 19:28 - 00001146 _____ C:\Users\David\Desktop\Continue Zip Opener Installation.lnk 2013-08-24 12:27 - 2013-08-24 12:27 - 13177488 _____ C:\Users\David\Downloads\RopaNawaroMaus.exe 2013-08-24 12:26 - 2013-08-24 12:26 - 03672231 _____ C:\Users\David\Downloads\MischStation.exe 2013-08-24 02:06 - 2013-08-24 02:06 - 00003088 _____ C:\Windows\System32\Tasks\{7C96B1B9-129B-43D3-92BA-15E58DD13CFC} 2013-08-23 02:28 - 2013-08-23 02:28 - 00003088 _____ C:\Windows\System32\Tasks\{80134A1F-9616-4C20-9393-6B0FBA5B4B83} 2013-08-22 18:10 - 2013-08-22 18:10 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip 2013-08-22 18:09 - 2013-08-22 13:32 - 00120761 _____ C:\Users\Sandro\Downloads\Ausgleich der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip 2013-08-22 18:07 - 2013-08-22 18:07 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip 2013-08-22 04:38 - 2013-08-22 04:38 - 00003088 _____ C:\Windows\System32\Tasks\{BF13EA0A-31B2-410A-9F93-743C5C4082DC} 2013-08-22 03:02 - 2013-08-22 03:02 - 00003088 _____ C:\Windows\System32\Tasks\{2CA1F239-220D-4323-AADE-591302E5262B} 2013-08-21 01:35 - 2013-08-21 01:35 - 00003088 _____ C:\Windows\System32\Tasks\{76511A5A-32F2-4D88-9CC3-2EDD4F267B19} 2013-08-20 23:57 - 2013-08-20 23:57 - 00000000 ____D C:\Users\Sandro\Documents\Electronic Arts 2013-08-20 23:32 - 2013-08-20 23:32 - 00002252 _____ C:\Users\Public\Desktop\Die Sims™ 3 Luxus-Accessoires.lnk 2013-08-20 23:27 - 2013-08-20 23:27 - 00002304 _____ C:\Users\Public\Desktop\Die*Sims™*3.lnk 2013-08-20 16:25 - 2013-08-20 17:38 - 00000000 ____D C:\Users\David\AppData\Local\Mozilla Firefox 2013-08-20 02:10 - 2013-08-20 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{E120DF85-ADC1-4E35-B378-5CB8B450BDBA} 2013-08-19 02:05 - 2013-08-19 02:05 - 00003088 _____ C:\Windows\System32\Tasks\{AB4F94BD-4CCB-4275-810C-0C01764E0439} 2013-08-18 13:15 - 2013-08-18 17:39 - 00000000 ____D C:\Users\Katrin\AppData\Local\Mozilla Firefox 2013-08-18 02:46 - 2013-08-18 02:46 - 00003088 _____ C:\Windows\System32\Tasks\{B00AB3A3-0DA8-4391-B49B-85969C9CA3FD} 2013-08-18 01:21 - 2013-08-18 01:22 - 00004197 _____ C:\Users\Sandro\Desktop\Your Humble Bundle order is ready.html 2013-08-15 13:30 - 2013-08-15 13:31 - 00000000 ____D C:\Windows\rescache 2013-08-15 01:59 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 01:59 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 01:59 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 01:59 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 01:59 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 01:59 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 01:59 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 01:59 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 01:59 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 01:59 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 01:59 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 01:59 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-15 01:53 - 2013-08-15 01:57 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 13:10 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 13:10 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 13:10 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 13:10 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 13:10 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 13:10 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 13:10 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 13:10 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 13:10 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 13:10 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 13:10 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 13:10 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 13:10 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 13:10 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 13:10 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 13:10 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 13:10 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 13:10 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 13:10 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 13:10 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 13:10 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 13:10 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 13:10 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 13:10 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 13:10 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 13:10 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 13:10 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 12:58 - 2013-08-14 12:58 - 00000003 _____ C:\Windows\system32\HRUPPROG.DIE.NOW 2013-08-14 12:57 - 2013-08-31 10:00 - 00000003 _____ C:\Windows\system32\HRUPPROG.TXT 2013-08-14 02:51 - 2013-08-14 02:51 - 00003088 _____ C:\Windows\System32\Tasks\{2210D34F-EBC5-4554-9C19-30F50B90D375} 2013-08-14 01:13 - 2013-08-14 01:13 - 00002032 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-14 01:13 - 2013-08-14 01:13 - 00000000 ____D C:\Program Files (x86)\Aeria Games 2013-08-13 01:59 - 2013-08-13 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{207F6A12-65B2-4433-A50D-5467803ED18D} 2013-08-12 19:07 - 2013-09-01 23:45 - 00002469 _____ C:\Windows\DirectX.log 2013-08-12 17:52 - 2013-08-12 17:52 - 01204902 _____ C:\Users\Sandro\Downloads\Smite Font fix.rar 2013-08-12 17:32 - 2013-08-12 17:32 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish (1).exe 2013-08-12 17:29 - 2013-08-12 17:33 - 00002032 _____ C:\Users\Public\Desktop\Smite.lnk 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\ProgramData\Hi-Rez Studios 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios 2013-08-12 17:25 - 2013-08-12 17:25 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish.exe 2013-08-12 01:42 - 2013-08-12 01:42 - 00003088 _____ C:\Windows\System32\Tasks\{B50AF006-5459-4FB7-B54A-159E237C1B47} 2013-08-11 02:16 - 2013-08-11 02:16 - 00003088 _____ C:\Windows\System32\Tasks\{6523F6E2-6431-4271-A355-983127186566} 2013-08-10 18:44 - 2013-08-10 18:44 - 00003088 _____ C:\Windows\System32\Tasks\{6E810A62-A06C-47FA-A5B4-7EDF8D29D3D4} 2013-08-10 02:10 - 2013-08-10 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{50C71F38-7796-4D0F-8828-09F50A146372} 2013-08-09 07:11 - 2013-08-09 07:11 - 00003088 _____ C:\Windows\System32\Tasks\{C89A309D-5292-4DFD-B2A3-C98965450CA6} 2013-08-09 02:43 - 2013-08-09 02:43 - 00003088 _____ C:\Windows\System32\Tasks\{DC14F991-DAAB-4948-836C-81B304ADDA7F} 2013-08-08 19:00 - 2013-08-08 19:00 - 00000011 _____ C:\Users\Sandro\Desktop\Neues Textdokument.txt 2013-08-08 02:26 - 2013-08-08 02:26 - 00003088 _____ C:\Windows\System32\Tasks\{896182C0-FBCB-4B11-8249-C511298E4013} 2013-08-07 02:30 - 2013-08-07 02:30 - 00003088 _____ C:\Windows\System32\Tasks\{7469A554-0505-4536-98F9-F3E80ECCCBEC} 2013-08-06 21:47 - 2013-08-06 21:47 - 00675988 _____ C:\Users\Sandro\Desktop\Minecraft (2).exe 2013-08-06 01:59 - 2013-08-06 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{945A3915-5477-42D9-867D-11EC9100BFFD} 2013-08-05 21:12 - 2013-08-05 21:12 - 00003632 _____ C:\Users\Sandro\Downloads\142e5e19d17b19f2c5398ec6234eaec0.dlc 2013-08-05 02:10 - 2013-08-05 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{DB410448-2A0E-4A1C-8396-235662B567C2} 2013-08-04 19:33 - 2013-08-04 19:34 - 00000000 ____D C:\Users\Katrin\Desktop\Bilder Urlaub 2013-08-04 02:40 - 2013-08-04 02:40 - 00003088 _____ C:\Windows\System32\Tasks\{3CCBF5D6-F969-444A-8F77-5E93635378D4} 2013-08-03 02:34 - 2013-08-03 02:34 - 00003088 _____ C:\Windows\System32\Tasks\{F9A26D5E-F671-4537-B0BB-058FAD3E2844} ==================== One Month Modified Files and Folders ======= 2013-09-02 12:16 - 2013-09-02 12:16 - 00000000 ____D C:\FRST 2013-09-02 12:16 - 2013-04-24 15:11 - 00000000 ____D C:\Users\DefaultAppPool 2013-09-02 12:14 - 2013-09-02 12:14 - 01951950 _____ (Farbar) C:\Users\Sandro\Downloads\FRST64.exe 2013-09-02 12:05 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-02 12:05 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-02 12:00 - 2007-10-10 18:55 - 01073139 _____ C:\Windows\WindowsUpdate.log 2013-09-02 11:58 - 2011-03-31 17:29 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-02 11:56 - 2013-04-23 18:25 - 00004208 _____ C:\Windows\System32\Tasks\Software Updater 2013-09-02 11:56 - 2013-04-23 18:25 - 00004170 _____ C:\Windows\System32\Tasks\Software Updater Ui 2013-09-02 11:54 - 2012-10-16 02:15 - 00000000 ____D C:\Program Files (x86)\Steam 2013-09-02 11:54 - 2012-04-26 21:20 - 00000000 ____D C:\Users\Sandro\.gstreamer-0.10 2013-09-02 11:54 - 2012-04-26 21:18 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\MotoCast 2013-09-02 11:53 - 2013-02-16 19:02 - 00000000 ____D C:\Program Files (x86)\SiteRanker 2013-09-02 11:53 - 2012-07-12 15:29 - 00000000 ___RD C:\Users\Sandro\Dropbox 2013-09-02 11:53 - 2012-07-12 15:25 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Dropbox 2013-09-02 11:52 - 2013-02-24 20:02 - 00000000 ____D C:\Users\Sandro\AppData\Local\LogMeIn Hamachi 2013-09-02 11:52 - 2011-03-31 17:29 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-02 11:51 - 2013-07-13 19:02 - 00006689 _____ C:\Windows\setupact.log 2013-09-02 11:51 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-02 11:51 - 2007-10-10 18:58 - 00000000 ____D C:\ProgramData\NVIDIA 2013-09-02 02:56 - 2013-09-02 02:56 - 00003088 _____ C:\Windows\System32\Tasks\{F741D114-8004-44D5-96EB-33971BBCD417} 2013-09-02 02:43 - 2012-06-05 17:50 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-02 02:37 - 2011-10-02 18:36 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004UA.job 2013-09-02 02:26 - 2011-04-11 15:12 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003UA.job 2013-09-02 02:26 - 2011-04-11 15:12 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003Core.job 2013-09-02 02:25 - 2011-03-31 16:44 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1001UA.job 2013-09-02 01:56 - 2011-12-11 17:34 - 00001138 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003UA.job 2013-09-02 01:44 - 2011-07-03 20:44 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\TS3Client 2013-09-02 01:25 - 2012-01-29 14:28 - 00001142 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004UA.job 2013-09-01 23:45 - 2013-08-12 19:07 - 00002469 _____ C:\Windows\DirectX.log 2013-09-01 23:43 - 2013-09-01 23:42 - 60757752 _____ (Gazillion Entertainment ) C:\Users\Sandro\Downloads\marvelheroesinstaller.exe 2013-09-01 23:29 - 2013-09-01 23:11 - 00000000 ____D C:\Users\Sandro\Downloads\CCEnhancer 2013-09-01 23:21 - 2013-09-01 23:20 - 00330518 _____ C:\Users\Sandro\Documents\cc_20130901_232036.reg 2013-09-01 23:12 - 2011-07-31 23:12 - 00000000 ____D C:\Program Files\CCleaner 2013-09-01 23:11 - 2013-09-01 23:10 - 00176719 _____ C:\Users\Sandro\Downloads\CCEnhancer-3.8-multilanguage.zip 2013-09-01 22:56 - 2011-12-11 17:34 - 00001116 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003Core.job 2013-09-01 22:52 - 2011-04-01 07:10 - 00000000 ____D C:\Users\Katrin 2013-09-01 22:51 - 2013-07-03 07:24 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-09-01 22:51 - 2013-06-01 02:10 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b ROC Installer deDE 2013-09-01 22:51 - 2013-06-01 01:56 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b TFT Installer deDE 2013-09-01 22:51 - 2013-05-31 04:13 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b TFT Installer enGB 2013-09-01 22:51 - 2013-05-31 03:57 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b ROC Installer enGB 2013-09-01 22:51 - 2013-05-06 01:12 - 00000000 ____D C:\Users\Sandro\AppData\Local\Akamai 2013-09-01 22:51 - 2013-04-07 16:55 - 00000000 ____D C:\Ubisoft 2013-09-01 22:51 - 2013-04-07 16:54 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2013-09-01 22:51 - 2013-03-23 22:41 - 00000000 ____D C:\Users\Public\Sony Online Entertainment 2013-09-01 22:51 - 2012-02-11 18:23 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-09-01 22:51 - 2012-02-11 18:23 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-09-01 22:51 - 2011-06-09 01:01 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-09-01 22:51 - 2011-04-04 19:03 - 00000000 ____D C:\Users\Sandro\Downloads\JD 2013-09-01 22:51 - 2011-04-01 19:53 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-09-01 22:51 - 2011-03-31 17:29 - 00000000 ____D C:\Users\David 2013-09-01 22:51 - 2010-05-10 13:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-09-01 22:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-09-01 20:24 - 2011-03-31 16:44 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1001Core.job 2013-09-01 19:00 - 2011-03-31 16:34 - 00000000 ____D C:\Users\Sandro 2013-09-01 14:37 - 2011-10-02 18:36 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004Core.job 2013-09-01 13:20 - 2011-10-02 18:36 - 00002378 _____ C:\Users\Katrin\Desktop\Google Chrome.lnk 2013-09-01 13:01 - 2009-07-14 07:13 - 00419726 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-01 13:01 - 2007-10-11 04:46 - 00178236 _____ C:\Windows\system32\perfh007.dat 2013-09-01 13:01 - 2007-10-11 04:46 - 00060400 _____ C:\Windows\system32\perfc007.dat 2013-09-01 12:59 - 2013-02-25 08:40 - 00000000 ____D C:\Users\Katrin\AppData\Local\LogMeIn Hamachi 2013-09-01 12:55 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-01 01:51 - 2011-08-23 01:29 - 02507776 ___SH C:\Users\Sandro\Downloads\Thumbs.db 2013-09-01 01:25 - 2013-09-01 01:25 - 00000000 ____D C:\Program Files (x86)\Frogwares 2013-09-01 01:14 - 2011-06-06 03:14 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\DAEMON Tools Lite 2013-09-01 01:14 - 2011-04-21 20:14 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\FileZilla 2013-09-01 01:14 - 2011-03-31 18:17 - 00000000 ____D C:\Users\Sandro\Tracing 2013-09-01 01:05 - 2013-02-27 04:11 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\.minecraft 2013-08-31 23:58 - 2013-08-31 23:58 - 00614920 _____ C:\Windows\Minidump\083113-158606-01.dmp 2013-08-31 23:58 - 2011-07-27 16:00 - 00000000 ____D C:\Windows\Minidump 2013-08-31 23:21 - 2013-08-31 23:21 - 00003088 _____ C:\Windows\System32\Tasks\{0D0E4C94-0C9F-48BA-A856-AA025793FD2C} 2013-08-31 11:52 - 2013-08-31 11:52 - 03367611 _____ C:\Users\David\Downloads\easyHalls.exe 2013-08-31 10:00 - 2013-08-14 12:57 - 00000003 _____ C:\Windows\system32\HRUPPROG.TXT 2013-08-31 09:05 - 2013-02-25 14:59 - 00000000 ____D C:\Users\David\AppData\Local\LogMeIn Hamachi 2013-08-31 02:32 - 2013-08-31 02:32 - 00003088 _____ C:\Windows\System32\Tasks\{598B6998-980B-477A-B0AE-FA6585404995} 2013-08-30 22:50 - 2013-08-30 22:50 - 00000000 ____D C:\Program Files (x86)\YTD Toolbar 2013-08-30 22:50 - 2013-08-30 22:50 - 00000000 ____D C:\Program Files (x86)\Application Updater 2013-08-30 07:25 - 2012-01-29 14:28 - 00001120 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004Core.job 2013-08-30 03:00 - 2013-08-30 03:00 - 00003088 _____ C:\Windows\System32\Tasks\{3E5317FD-A87C-4939-B5D3-EEBC998CEB85} 2013-08-30 01:34 - 2011-03-31 16:44 - 00002378 _____ C:\Users\Sandro\Desktop\Google Chrome.lnk 2013-08-29 17:02 - 2011-04-02 16:37 - 00000000 ____D C:\Users\David\AppData\Local\Google 2013-08-29 16:06 - 2011-04-11 19:48 - 00002373 _____ C:\Users\David\Desktop\Google Chrome.lnk 2013-08-29 02:48 - 2013-08-29 02:48 - 00003088 _____ C:\Windows\System32\Tasks\{FB0B0681-2A62-4A02-89EA-275B2BA27866} 2013-08-28 02:44 - 2013-08-28 02:44 - 00003088 _____ C:\Windows\System32\Tasks\{7DF15D2D-9E9F-46AC-A90F-13A20C4D983D} 2013-08-27 21:16 - 2011-07-25 20:55 - 00000000 ____D C:\Users\David\Desktop\Emergency 4 Deluxe 2013-08-27 19:27 - 2013-07-23 11:52 - 00000000 ____D C:\Program Files (x86)\ERS Berlin 2013-08-27 10:40 - 2011-03-31 17:36 - 00000000 ____D C:\Users\David\Documents\My Games 2013-08-27 02:23 - 2013-08-27 02:23 - 00003088 _____ C:\Windows\System32\Tasks\{6034F774-F129-4A22-AF1B-08870102A4CF} 2013-08-26 03:39 - 2013-08-26 03:39 - 00003088 _____ C:\Windows\System32\Tasks\{00FE09DB-2041-4FE9-A8C7-6A3183FCB20A} 2013-08-26 03:01 - 2013-08-26 03:01 - 00003088 _____ C:\Windows\System32\Tasks\{C0C1C429-CC94-478F-938D-2A2437CF7F0E} 2013-08-25 12:53 - 2013-08-25 12:53 - 00301504 _____ C:\Users\David\Downloads\repetitperche.zip.exe 2013-08-25 12:51 - 2013-08-25 12:51 - 00705136 _____ C:\Users\David\Downloads\UltimateCodec.exe 2013-08-25 02:35 - 2013-08-25 02:35 - 00003088 _____ C:\Windows\System32\Tasks\{079FF58D-0420-425F-A404-A2C8847198A7} 2013-08-24 21:56 - 2011-04-03 16:46 - 00064000 _____ C:\Users\David\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-24 19:43 - 2013-08-24 19:43 - 01624064 _____ (Bandoo Media Inc) C:\Users\David\Downloads\iLividSetup-r422-n-bf.exe 2013-08-24 19:28 - 2013-08-24 19:28 - 00714352 _____ C:\Users\David\Downloads\ZipOpenerSetup(1).exe 2013-08-24 19:28 - 2013-08-24 19:28 - 00001146 _____ C:\Users\David\Desktop\Continue Zip Opener Installation.lnk 2013-08-24 12:27 - 2013-08-24 12:27 - 13177488 _____ C:\Users\David\Downloads\RopaNawaroMaus.exe 2013-08-24 12:26 - 2013-08-24 12:26 - 03672231 _____ C:\Users\David\Downloads\MischStation.exe 2013-08-24 02:06 - 2013-08-24 02:06 - 00003088 _____ C:\Windows\System32\Tasks\{7C96B1B9-129B-43D3-92BA-15E58DD13CFC} 2013-08-23 02:28 - 2013-08-23 02:28 - 00003088 _____ C:\Windows\System32\Tasks\{80134A1F-9616-4C20-9393-6B0FBA5B4B83} 2013-08-22 18:10 - 2013-08-22 18:10 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip 2013-08-22 18:07 - 2013-08-22 18:07 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip 2013-08-22 13:32 - 2013-08-22 18:09 - 00120761 _____ C:\Users\Sandro\Downloads\Ausgleich der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip 2013-08-22 13:05 - 2012-03-27 15:08 - 00000000 ____D C:\Program Files (x86)\Origin 2013-08-22 04:38 - 2013-08-22 04:38 - 00003088 _____ C:\Windows\System32\Tasks\{BF13EA0A-31B2-410A-9F93-743C5C4082DC} 2013-08-22 04:35 - 2011-04-25 22:07 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\SoftGrid Client 2013-08-22 03:06 - 2011-03-31 16:43 - 00000000 ____D C:\Users\Sandro\AppData\Local\Google 2013-08-22 03:02 - 2013-08-22 03:02 - 00003088 _____ C:\Windows\System32\Tasks\{2CA1F239-220D-4323-AADE-591302E5262B} 2013-08-21 14:58 - 2013-02-16 19:02 - 00000000 ____D C:\Program Files (x86)\AppGraffiti 2013-08-21 14:43 - 2012-06-05 17:50 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-21 14:43 - 2012-06-05 17:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-21 14:43 - 2012-06-05 17:50 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-21 13:19 - 2012-10-21 15:22 - 00000000 ____D C:\Users\David\AppData\Local\Origin 2013-08-21 13:19 - 2012-03-28 02:55 - 00000000 ____D C:\Users\David\AppData\Roaming\Origin 2013-08-21 01:35 - 2013-08-21 01:35 - 00003088 _____ C:\Windows\System32\Tasks\{76511A5A-32F2-4D88-9CC3-2EDD4F267B19} 2013-08-20 23:57 - 2013-08-20 23:57 - 00000000 ____D C:\Users\Sandro\Documents\Electronic Arts 2013-08-20 23:32 - 2013-08-20 23:32 - 00002252 _____ C:\Users\Public\Desktop\Die Sims™ 3 Luxus-Accessoires.lnk 2013-08-20 23:29 - 2012-03-27 15:10 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-08-20 23:27 - 2013-08-20 23:27 - 00002304 _____ C:\Users\Public\Desktop\Die*Sims™*3.lnk 2013-08-20 17:38 - 2013-08-20 16:25 - 00000000 ____D C:\Users\David\AppData\Local\Mozilla Firefox 2013-08-20 02:10 - 2013-08-20 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{E120DF85-ADC1-4E35-B378-5CB8B450BDBA} 2013-08-19 02:05 - 2013-08-19 02:05 - 00003088 _____ C:\Windows\System32\Tasks\{AB4F94BD-4CCB-4275-810C-0C01764E0439} 2013-08-18 17:39 - 2013-08-18 13:15 - 00000000 ____D C:\Users\Katrin\AppData\Local\Mozilla Firefox 2013-08-18 02:46 - 2013-08-18 02:46 - 00003088 _____ C:\Windows\System32\Tasks\{B00AB3A3-0DA8-4391-B49B-85969C9CA3FD} 2013-08-18 01:22 - 2013-08-18 01:21 - 00004197 _____ C:\Users\Sandro\Desktop\Your Humble Bundle order is ready.html 2013-08-17 23:31 - 2012-03-27 15:10 - 00000000 ____D C:\Users\Sandro\AppData\Local\Origin 2013-08-17 23:31 - 2012-03-27 15:10 - 00000000 ____D C:\ProgramData\Origin 2013-08-17 23:31 - 2012-03-27 15:09 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Origin 2013-08-15 17:16 - 2011-04-26 23:19 - 00000000 ____D C:\Users\Sandro\Desktop\Zeuch Halt 2013-08-15 13:31 - 2013-08-15 13:30 - 00000000 ____D C:\Windows\rescache 2013-08-15 01:57 - 2013-08-15 01:53 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 01:52 - 2011-04-30 22:28 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-14 12:58 - 2013-08-14 12:58 - 00000003 _____ C:\Windows\system32\HRUPPROG.DIE.NOW 2013-08-14 02:51 - 2013-08-14 02:51 - 00003088 _____ C:\Windows\System32\Tasks\{2210D34F-EBC5-4554-9C19-30F50B90D375} 2013-08-14 01:13 - 2013-08-14 01:13 - 00002032 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-14 01:13 - 2013-08-14 01:13 - 00000000 ____D C:\Program Files (x86)\Aeria Games 2013-08-14 01:13 - 2013-04-01 17:36 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin 2013-08-13 12:26 - 2011-04-25 14:31 - 00064000 _____ C:\Users\Katrin\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-13 12:24 - 2009-07-14 06:45 - 00295696 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-13 01:59 - 2013-08-13 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{207F6A12-65B2-4433-A50D-5467803ED18D} 2013-08-12 19:54 - 2011-03-31 22:06 - 00000000 ____D C:\Users\Sandro\Documents\My Games 2013-08-12 17:53 - 2011-03-31 16:35 - 00064000 _____ C:\Users\Sandro\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-12 17:52 - 2013-08-12 17:52 - 01204902 _____ C:\Users\Sandro\Downloads\Smite Font fix.rar 2013-08-12 17:33 - 2013-08-12 17:29 - 00002032 _____ C:\Users\Public\Desktop\Smite.lnk 2013-08-12 17:32 - 2013-08-12 17:32 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish (1).exe 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\ProgramData\Hi-Rez Studios 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios 2013-08-12 17:25 - 2013-08-12 17:25 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish.exe 2013-08-12 01:42 - 2013-08-12 01:42 - 00003088 _____ C:\Windows\System32\Tasks\{B50AF006-5459-4FB7-B54A-159E237C1B47} 2013-08-11 02:16 - 2013-08-11 02:16 - 00003088 _____ C:\Windows\System32\Tasks\{6523F6E2-6431-4271-A355-983127186566} 2013-08-10 18:44 - 2013-08-10 18:44 - 00003088 _____ C:\Windows\System32\Tasks\{6E810A62-A06C-47FA-A5B4-7EDF8D29D3D4} 2013-08-10 02:10 - 2013-08-10 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{50C71F38-7796-4D0F-8828-09F50A146372} 2013-08-09 07:11 - 2013-08-09 07:11 - 00003088 _____ C:\Windows\System32\Tasks\{C89A309D-5292-4DFD-B2A3-C98965450CA6} 2013-08-09 02:43 - 2013-08-09 02:43 - 00003088 _____ C:\Windows\System32\Tasks\{DC14F991-DAAB-4948-836C-81B304ADDA7F} 2013-08-08 19:00 - 2013-08-08 19:00 - 00000011 _____ C:\Users\Sandro\Desktop\Neues Textdokument.txt 2013-08-08 16:35 - 2011-07-03 20:43 - 00000000 ____D C:\Users\Sandro\AppData\Local\TeamSpeak 3 Client 2013-08-08 02:26 - 2013-08-08 02:26 - 00003088 _____ C:\Windows\System32\Tasks\{896182C0-FBCB-4B11-8249-C511298E4013} 2013-08-07 02:30 - 2013-08-07 02:30 - 00003088 _____ C:\Windows\System32\Tasks\{7469A554-0505-4536-98F9-F3E80ECCCBEC} 2013-08-06 21:47 - 2013-08-06 21:47 - 00675988 _____ C:\Users\Sandro\Desktop\Minecraft (2).exe 2013-08-06 01:59 - 2013-08-06 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{945A3915-5477-42D9-867D-11EC9100BFFD} 2013-08-05 21:16 - 2011-07-13 00:02 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-08-05 21:12 - 2013-08-05 21:12 - 00003632 _____ C:\Users\Sandro\Downloads\142e5e19d17b19f2c5398ec6234eaec0.dlc 2013-08-05 02:10 - 2013-08-05 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{DB410448-2A0E-4A1C-8396-235662B567C2} 2013-08-04 19:34 - 2013-08-04 19:33 - 00000000 ____D C:\Users\Katrin\Desktop\Bilder Urlaub 2013-08-04 02:40 - 2013-08-04 02:40 - 00003088 _____ C:\Windows\System32\Tasks\{3CCBF5D6-F969-444A-8F77-5E93635378D4} 2013-08-03 02:34 - 2013-08-03 02:34 - 00003088 _____ C:\Windows\System32\Tasks\{F9A26D5E-F671-4537-B0BB-058FAD3E2844} Files to move or delete: ==================== C:\Users\David\AppData\Local\Temp\0a50e25a83046228c11dcaa7eeed09bb.exe C:\Users\David\AppData\Local\Temp\AskSLib.dll C:\Users\David\AppData\Local\Temp\contentDATs.exe C:\Users\David\AppData\Local\Temp\drm_dyndata_7350008.dll C:\Users\David\AppData\Local\Temp\firefoxjre_exe.exe C:\Users\David\AppData\Local\Temp\IcqUpdater.exe C:\Users\David\AppData\Local\Temp\ICReinstall_PDFCreatorSetup(3).exe C:\Users\David\AppData\Local\Temp\ICReinstall_PDFCreatorSetup.exe C:\Users\David\AppData\Local\Temp\ICReinstall_ZipOpenerSetup(1).exe C:\Users\David\AppData\Local\Temp\ICReinstall_ZipOpenerSetup.exe C:\Users\David\AppData\Local\Temp\installhelper.dll C:\Users\David\AppData\Local\Temp\iupdate.exe C:\Users\David\AppData\Local\Temp\MyBabylonTB.exe C:\Users\David\AppData\Local\Temp\MyBabylonTB[1].exe C:\Users\David\AppData\Local\Temp\SkypeSetup.exe C:\Users\David\AppData\Local\Temp\SRAssetsHelper.dll C:\Users\David\AppData\Local\Temp\_is4292.exe C:\Users\David\AppData\Local\Temp\{B9C91A51-38A3-4720-BE1B-606B8BAEFBC2}\ICQ7.exe C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\GoogleCrashHandler.exe C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\GoogleUpdate.exe C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdate.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\GoopdateBho.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_ar.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_bg.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_bn.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_ca.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_cs.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_da.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_de.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_el.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_en-GB.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_en.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_es-419.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_es.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_et.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_fa.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_fi.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_fil.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_fr.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_gu.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_hi.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_hr.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_hu.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_id.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_is.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_it.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_iw.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_ja.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_kn.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_ko.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_lt.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_lv.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_ml.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_mr.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_ms.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_nl.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_no.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_or.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_pl.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_pt-BR.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_pt-PT.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_ro.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_ru.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_sk.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_sl.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_sr.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_sv.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_ta.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_te.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_th.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_tr.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_uk.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_ur.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_vi.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_zh-CN.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\goopdateres_zh-TW.dll C:\Users\David\AppData\Local\Temp\{5EEFA2AF-1074-485A-BFBD-060621D77BAA}\npGoogleOneClick8.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\GoogleCrashHandler.exe C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\GoogleUpdate.exe C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdate.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\GoopdateBho.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_ar.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_bg.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_bn.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_ca.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_cs.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_da.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_de.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_el.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_en-GB.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_en.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_es-419.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_es.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_et.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_fa.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_fi.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_fil.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_fr.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_gu.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_hi.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_hr.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_hu.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_id.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_is.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_it.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_iw.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_ja.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_kn.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_ko.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_lt.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_lv.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_ml.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_mr.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_ms.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_nl.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_no.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_or.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_pl.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_pt-BR.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_pt-PT.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_ro.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_ru.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_sk.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_sl.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_sr.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_sv.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_ta.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_te.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_th.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_tr.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_uk.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_ur.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_vi.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_zh-CN.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\goopdateres_zh-TW.dll C:\Users\David\AppData\Local\Temp\{542780A4-14D1-4AE4-99F0-6B8485CD1969}\npGoogleOneClick8.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\GoogleCrashHandler.exe C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\GoogleUpdate.exe C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdate.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\GoopdateBho.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_ar.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_bg.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_bn.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_ca.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_cs.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_da.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_de.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_el.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_en-GB.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_en.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_es-419.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_es.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_et.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_fa.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_fi.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_fil.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_fr.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_gu.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_hi.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_hr.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_hu.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_id.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_is.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_it.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_iw.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_ja.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_kn.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_ko.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_lt.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_lv.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_ml.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_mr.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_ms.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_nl.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_no.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_or.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_pl.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_pt-BR.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_pt-PT.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_ro.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_ru.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_sk.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_sl.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_sr.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_sv.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_ta.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_te.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_th.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_tr.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_uk.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_ur.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_vi.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_zh-CN.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\goopdateres_zh-TW.dll C:\Users\David\AppData\Local\Temp\{4E55D0AA-070A-4386-9280-E0710A409537}\npGoogleOneClick8.dll C:\Users\David\AppData\Local\Temp\{332F45AB-C114-4825-961D-6F23152B08D9}\ISSetup.dll C:\Users\David\AppData\Local\Temp\{332F45AB-C114-4825-961D-6F23152B08D9}\_Setup.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\GoogleCrashHandler.exe C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\GoogleUpdate.exe C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdate.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\GoopdateBho.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_ar.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_bg.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_bn.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_ca.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_cs.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_da.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_de.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_el.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_en-GB.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_en.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_es-419.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_es.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_et.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_fa.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_fi.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_fil.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_fr.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_gu.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_hi.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_hr.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_hu.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_id.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_is.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_it.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_iw.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_ja.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_kn.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_ko.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_lt.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_lv.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_ml.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_mr.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_ms.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_nl.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_no.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_or.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_pl.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_pt-BR.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_pt-PT.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_ro.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_ru.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_sk.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_sl.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_sr.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_sv.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_ta.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_te.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_th.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_tr.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_uk.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_ur.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_vi.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_zh-CN.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\goopdateres_zh-TW.dll C:\Users\David\AppData\Local\Temp\{106EB3B3-DBA8-4D39-8B4D-41FE436DF25F}\npGoogleOneClick8.dll C:\Users\David\AppData\Local\Temp\nsn34A4.tmp\Helper.dll C:\Users\David\AppData\Local\Temp\Messenger_20.0.0001_0\SkypeSetupFull(6.3.73.105)(Trackable457)trackable.exe C:\Users\David\AppData\Local\Temp\is1373634743\DeltaTB.exe C:\Users\David\AppData\Local\Temp\is1373634743\MyBabylonTB.exe C:\Users\David\AppData\Local\Temp\is1373634743\QtraxInstaller.exe C:\Users\David\AppData\Local\Temp\is1373634743\wajam_download.exe C:\Users\David\AppData\Local\Temp\e1b92ea8-f486-4b11-ab33-fd92c14f3047\CliSecureRT.dll C:\Users\David\AppData\Local\Temp\bd7c47bb-f5c0-417c-a180-ec348d87718a\CliSecureRT.dll C:\Users\David\AppData\Local\Temp\b1d65e3e-4e75-4804-a122-36dff0499f12\CliSecureRT.dll C:\Users\David\AppData\Local\Temp\7de36826-06f2-4679-9362-144feb863905\CliSecureRT.dll C:\Users\David\AppData\Local\Temp\2827278562\chromeupdaterfull.exe C:\Users\David\AppData\Local\Temp\1a7d9c19-e921-4f28-aef1-9b362897b06a\CliSecureRT.dll C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\Setup.exe C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\VisualCRT\vc2008redist_x86.exe C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\DSETUP.dll C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\dsetup32.dll C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\DXSETUP.exe C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\data\Star Wars - The Old Republic Uninstaller.exe C:\Users\Katrin\AppData\Local\Temp\AskSLib.dll C:\Users\Katrin\AppData\Local\Temp\contentDATs.exe C:\Users\Katrin\AppData\Local\Temp\Shockwave_Installer_FF-1.exe C:\Users\Katrin\AppData\Local\Temp\Shockwave_Installer_FF.exe C:\Users\Katrin\AppData\Local\Temp\908209415\wssetup.exe C:\Users\Katrin\AppData\Local\Temp\2827278562\chromeupdaterfull.exe C:\Users\Sandro\AppData\Local\Temp\sqlite-3.6.20-sqlitejdbc.dll C:\Users\Sandro\AppData\Local\Temp\{D82D66FD-3516-47C5-95B6-9DD3A9EB0213}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\CSCHECK.DLL C:\Users\Sandro\AppData\Local\Temp\{D82D66FD-3516-47C5-95B6-9DD3A9EB0213}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\isrt.dll C:\Users\Sandro\AppData\Local\Temp\{D82D66FD-3516-47C5-95B6-9DD3A9EB0213}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\wmfdist.exe C:\Users\Sandro\AppData\Local\Temp\{D82D66FD-3516-47C5-95B6-9DD3A9EB0213}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\_IsRes.dll C:\Users\Sandro\AppData\Local\Temp\{D82D66FD-3516-47C5-95B6-9DD3A9EB0213}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\_isUser.dll C:\Users\Sandro\AppData\Local\Temp\{D82D66FD-3516-47C5-95B6-9DD3A9EB0213}\{68eec980-ce2c-4d4d-b86a-78bd77bb0258}\isrt.dll C:\Users\Sandro\AppData\Local\Temp\{D82D66FD-3516-47C5-95B6-9DD3A9EB0213}\{68eec980-ce2c-4d4d-b86a-78bd77bb0258}\_IsRes.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MaAgent.exe C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MAAuthProc.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MACLICX13.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MACLicX15.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MACSMANAGER.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MaCSMgr.exe C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MaCSProHook.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\mapshapi.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\mapwij10.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MaSyncP.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MaWAMP.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MAWebControl.exe C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MaWMP.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MPXBox.exe C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\MtpAccess.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\UserShare.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\XSYNCClt.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAFileUpdate.dll C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAUpdate.exe C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAUpdateBoot.exe C:\Users\Sandro\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MaUpdateClient.exe C:\Users\Sandro\AppData\Local\Temp\isp1268.tmp\_setup.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\vcredist_x64_vs2008sp1.exe C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\vcredist_x86_vs2008sp1.exe C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\SPInstaller.exe C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\SPInstallerEngine.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\SPInstallerUi.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\sqmapi.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\3082\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\2070\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\2052\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1055\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1053\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1049\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1046\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1045\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1044\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1043\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1042\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1041\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1040\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1038\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1037\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1036\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1035\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1033\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1032\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1031\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1030\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1029\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1028\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\MSChart\1025\SPInstallerResources.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\DXRedistCutdown\DSETUP.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\DXRedistCutdown\dsetup32.dll C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\DXRedistCutdown\DXSETUP.exe C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\Binaries\UnSetup.exe C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Redist\AMD\amdcpusetup.exe C:\Users\Sandro\AppData\Local\Temp\Epic-3b7a79e9-a4eb-4568-9750-5b0e87595d4b\Binaries\UnSetup.exe C:\Users\Sandro\AppData\Local\Temp\be29e7f1-71ae-4703-50cb-1d52be512f51\twapi-be29e7f1-71ae-4703-50cb-1d52be512f51.dll C:\Users\Sandro\AppData\Local\Temp\bd7c47bb-f5c0-417c-a180-ec348d87718a\CliSecureRT.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-22 12:17 ==================== End Of Log ============================ --- --- --- Geändert von Kazuharu (02.09.2013 um 11:43 Uhr) |
02.09.2013, 14:21 | #4 | |
/// the machine /// TB-Ausbilder | PC Langsam, Hängt sich auf ...Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.09.2013, 16:06 | #5 |
| PC Langsam, Hängt sich auf ...Code:
ATTFilter ComboFix 13-09-02.02 - Sandro 02.09.2013 16:32:19.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4023.2854 [GMT 2:00] ausgeführt von:: c:\users\Sandro\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\DealPly c:\program files (x86)\DealPly\DealPly.crx c:\program files (x86)\DealPly\icon.ico c:\program files (x86)\DealPly\uninst.exe c:\program files (x86)\facemoods.com c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoods.crx c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoods.png c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsApp.dll c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsEng.dll c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\uninstall.exe c:\program files (x86)\Incredibar.com c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibar.crx c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarApp.dll c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarEng.dll c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarsrv.exe c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\uninstall.exe c:\program files (x86)\PricePeep c:\program files (x86)\PricePeep\installer.ico c:\program files (x86)\PricePeep\pricepeep.crx c:\program files (x86)\PricePeep\pricepeep.dll c:\program files (x86)\PricePeep\uninstall.exe C:\Skype c:\skype\SkypeSetupFull55.exe c:\users\David\videos\iLividSetup.exe c:\users\Sandro\AppData\Local\Temp\bd7c47bb-f5c0-417c-a180-ec348d87718a\CliSecureRT.dll c:\users\Sandro\AppData\Roaming\Microsoft\Windows\Templates\install_flashplayer11x64_mssd_aih_de.exe c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\pthreadVC.dll c:\windows\SysWow64\wpcap.dll . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_NPF -------\Service_npf . . ((((((((((((((((((((((( Dateien erstellt von 2013-08-02 bis 2013-09-02 )))))))))))))))))))))))))))))) . . 2013-09-02 14:49 . 2013-09-02 14:49 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-09-02 14:49 . 2013-09-02 14:49 -------- d-----w- c:\users\Katrin\AppData\Local\temp 2013-09-02 14:49 . 2013-09-02 14:49 -------- d-----w- c:\users\hedev\AppData\Local\temp 2013-09-02 14:49 . 2013-09-02 14:49 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp 2013-09-02 14:49 . 2013-09-02 14:49 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-09-02 14:49 . 2013-09-02 14:49 -------- d-----w- c:\users\David\AppData\Local\temp 2013-09-02 10:34 . 2013-09-02 10:34 -------- d-----w- c:\program files (x86)\7-Zip 2013-09-02 10:16 . 2013-09-02 10:16 -------- d-----w- C:\FRST 2013-08-31 23:25 . 2013-08-31 23:25 -------- d-----w- c:\program files (x86)\Frogwares 2013-08-30 20:50 . 2013-08-30 20:50 -------- d-----w- c:\program files (x86)\YTD Toolbar 2013-08-30 20:50 . 2013-08-30 20:50 -------- d-----w- c:\program files (x86)\Common Files\Spigot 2013-08-30 20:50 . 2013-08-30 20:50 -------- d-----w- c:\program files (x86)\Application Updater 2013-08-20 14:25 . 2013-08-20 15:38 -------- d-----w- c:\users\David\AppData\Local\Mozilla Firefox 2013-08-18 11:15 . 2013-08-18 15:39 -------- d-----w- c:\users\Katrin\AppData\Local\Mozilla Firefox 2013-08-15 11:30 . 2013-08-15 11:31 -------- d-----w- c:\windows\rescache 2013-08-14 23:53 . 2013-08-14 23:57 -------- d-----w- c:\windows\system32\MRT 2013-08-13 23:13 . 2013-08-13 23:13 -------- d-----w- c:\program files (x86)\Aeria Games 2013-08-12 15:29 . 2013-08-12 15:29 -------- d-----w- c:\programdata\Hi-Rez Studios 2013-08-12 15:29 . 2013-08-12 15:29 -------- d-----w- c:\program files (x86)\Hi-Rez Studios . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-09-02 14:34 . 2013-08-31 08:00 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D86D6474-8FB5-4BAA-A2C9-A900077429E5}\offreg.dll 2013-08-21 12:43 . 2012-06-05 15:50 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-08-21 12:43 . 2012-06-05 15:50 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-08-14 23:52 . 2011-04-30 20:28 78161360 ----a-w- c:\windows\system32\MRT.exe 2013-08-06 08:58 . 2013-08-30 08:46 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D86D6474-8FB5-4BAA-A2C9-A900077429E5}\mpengine.dll 2013-07-09 04:45 . 2013-08-14 11:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-06-27 11:28 . 2013-05-07 12:23 83672 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-06-21 01:06 . 2013-06-21 01:06 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-06-21 01:06 . 2013-06-21 01:06 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-06-21 01:06 . 2013-06-21 01:06 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-06-21 01:06 . 2013-06-21 01:06 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-06-21 01:06 . 2013-06-21 01:06 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-06-21 01:06 . 2013-06-21 01:06 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-06-21 01:06 . 2013-06-21 01:06 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-06-21 01:06 . 2013-06-21 01:06 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-06-21 01:06 . 2013-06-21 01:06 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-06-21 01:06 . 2013-06-21 01:06 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-06-21 01:06 . 2013-06-21 01:06 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-06-21 01:06 . 2013-06-21 01:06 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-06-21 01:06 . 2013-06-21 01:06 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-06-21 01:06 . 2013-06-21 01:06 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-06-21 01:06 . 2013-06-21 01:06 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-06-21 01:06 . 2013-06-21 01:06 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-06-21 01:06 . 2013-06-21 01:06 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-06-21 01:06 . 2013-06-21 01:06 81408 ----a-w- c:\windows\system32\icardie.dll 2013-06-21 01:06 . 2013-06-21 01:06 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-06-21 01:06 . 2013-06-21 01:06 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-06-21 01:06 . 2013-06-21 01:06 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-06-21 01:06 . 2013-06-21 01:06 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-06-21 01:06 . 2013-06-21 01:06 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-06-21 01:06 . 2013-06-21 01:06 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-06-21 01:06 . 2013-06-21 01:06 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-06-21 01:06 . 2013-06-21 01:06 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-06-21 01:06 . 2013-06-21 01:06 441856 ----a-w- c:\windows\system32\html.iec 2013-06-21 01:06 . 2013-06-21 01:06 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-06-21 01:06 . 2013-06-21 01:06 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-06-21 01:06 . 2013-06-21 01:06 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-06-21 01:06 . 2013-06-21 01:06 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-06-21 01:06 . 2013-06-21 01:06 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-06-21 01:06 . 2013-06-21 01:06 235008 ----a-w- c:\windows\system32\url.dll 2013-06-21 01:06 . 2013-06-21 01:06 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-06-21 01:06 . 2013-06-21 01:06 216064 ----a-w- c:\windows\system32\msls31.dll 2013-06-21 01:06 . 2013-06-21 01:06 197120 ----a-w- c:\windows\system32\msrating.dll 2013-06-21 01:06 . 2013-06-21 01:06 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-06-21 01:06 . 2013-06-21 01:06 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-06-21 01:06 . 2013-06-21 01:06 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-06-21 01:06 . 2013-06-21 01:06 149504 ----a-w- c:\windows\system32\occache.dll 2013-06-21 01:06 . 2013-06-21 01:06 144896 ----a-w- c:\windows\system32\wextract.exe 2013-06-21 01:06 . 2013-06-21 01:06 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-06-21 01:06 . 2013-06-21 01:06 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-06-21 01:06 . 2013-06-21 01:06 13824 ----a-w- c:\windows\system32\mshta.exe 2013-06-21 01:06 . 2013-06-21 01:06 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-06-21 01:06 . 2013-06-21 01:06 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-06-21 01:06 . 2013-06-21 01:06 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-06-21 01:06 . 2013-06-21 01:06 102912 ----a-w- c:\windows\system32\inseng.dll 2013-06-21 01:06 . 2013-06-21 01:06 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-06-21 01:04 . 2013-06-21 01:04 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-06-21 01:04 . 2013-06-21 01:04 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-06-21 01:04 . 2013-06-21 01:04 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-06-21 01:04 . 2013-06-21 01:04 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-06-21 01:04 . 2013-06-21 01:04 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2013-06-21 01:04 . 2013-06-21 01:04 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-06-21 01:04 . 2013-06-21 01:04 1682432 ----a-w- c:\windows\system32\XpsPrint.dll 2013-06-21 01:04 . 2013-06-21 01:04 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll 2013-06-21 01:04 . 2013-06-21 01:04 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-21 01:04 . 2013-06-21 01:04 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2013-06-21 01:04 . 2013-06-21 01:04 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2013-06-21 01:04 . 2013-06-21 01:04 3928064 ----a-w- c:\windows\system32\d2d1.dll 2013-06-21 01:04 . 2013-06-21 01:04 363008 ----a-w- c:\windows\system32\dxgi.dll 2013-06-21 01:04 . 2013-06-21 01:04 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2013-06-21 01:04 . 2013-06-21 01:04 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-06-21 01:04 . 2013-06-21 01:04 296960 ----a-w- c:\windows\system32\d3d10core.dll 2013-06-21 01:04 . 2013-06-21 01:04 293376 ----a-w- c:\windows\SysWow64\dxgi.dll 2013-06-21 01:04 . 2013-06-21 01:04 2565120 ----a-w- c:\windows\system32\d3d10warp.dll 2013-06-21 01:04 . 2013-06-21 01:04 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2013-06-21 01:04 . 2013-06-21 01:04 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2013-06-21 01:04 . 2013-06-21 01:04 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2013-06-21 01:04 . 2013-06-21 01:04 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll 2013-06-21 01:04 . 2013-06-21 01:04 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll 2013-06-21 01:04 . 2013-06-21 01:04 1988096 ----a-w- c:\windows\SysWow64\d3d10warp.dll 2013-06-21 01:04 . 2013-06-21 01:04 194560 ----a-w- c:\windows\system32\d3d10_1.dll 2013-06-21 01:04 . 2013-06-21 01:04 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll 2013-06-21 01:04 . 2013-06-21 01:04 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files (x86)\Winload\prxtbWinl.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}] 2012-12-06 11:17 343296 ----a-w- c:\progra~2\SITERA~1\SiteRank.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6}] 2013-07-23 00:46 1451680 ----a-w- c:\program files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}] 2011-05-09 09:49 176936 ----a-w- c:\program files (x86)\Winload\prxtbWinl.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C331A7D9-4187-464C-BE66-FDBC56C07678}] 2012-02-28 16:35 269824 ----a-w- c:\users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStats.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{e9e8eb35-ff77-455d-b677-91e5e4fc06c2}] 2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] 2012-07-04 14:03 1310040 ----a-r- c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F3FEE66E-E034-436a-86E4-9690573BEE8A}] 2013-08-28 15:20 1356096 ----a-w- c:\program files (x86)\YTD Toolbar\IE\7.5\ytdToolbarIE.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files (x86)\Winload\prxtbWinl.dll" [2011-05-09 176936] "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2012-07-04 1310040] "{F3FEE66E-E034-436a-86E4-9690573BEE8A}"= "c:\program files (x86)\YTD Toolbar\IE\7.5\ytdToolbarIE.dll" [2013-08-28 1356096] . [HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}] . [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1] [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar] . [HKEY_CLASSES_ROOT\clsid\{f3fee66e-e034-436a-86e4-9690573bee8a}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-02-01 18:03 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "Xvid"="c:\program files (x86)\Xvid\CheckUpdate.exe" [2011-01-17 8192] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-05-10 39408] "MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-04-26 2059] "KiesHelper"="c:\program files (x86)\Samsung\Kies\KiesHelper.exe" [2012-03-31 954256] "KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-03-31 21392] "Steam"="c:\program files (x86)\Steam\steam.exe" [2013-08-28 1811880] "Akamai NetSession Interface"="c:\users\Sandro\AppData\Local\Akamai\netsession_win.exe" [2013-06-04 4489472] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-02-01 337264] "EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2009-12-25 201512] "EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2009-12-25 401192] "Hotkey Utility"="c:\program files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" [2010-08-04 611872] "MDS_Menu"="c:\program files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "ArcadeMovieService"="c:\program files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe" [2010-02-05 124136] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-03-31 3521424] "SweetIM"="c:\program files (x86)\SweetIM\Messenger\SweetIM.exe" [2012-10-04 115032] "Sweetpacks Communicator"="c:\program files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [2012-08-15 231768] "SiteRanker"="c:\program files (x86)\SiteRanker\SiteRankTray.exe" [2012-12-06 320000] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-06-27 345144] "DivXMediaServer"="c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" [2013-01-30 450560] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-06-28 2255184] "Aeria Ignite"="c:\program files (x86)\Aeria Games\Ignite\aeriaignite.exe" [2013-06-06 1925656] "SearchSettings"="c:\program files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe" [2013-08-28 1345856] . c:\users\Sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Sandro\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SystemStoreService;System Store;c:\program files (x86)\SoftwareUpdater\SystemStore.exe -displayname System Store -servicename SystemStoreService;c:\program files (x86)\SoftwareUpdater\SystemStore.exe -displayname System Store -servicename SystemStoreService [x] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [x] R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe [x] R3 BRDriver64;BRDriver64;c:\programdata\bitraider\BRDriver64.sys;c:\programdata\bitraider\BRDriver64.sys [x] R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe;c:\programdata\BitRaider\BRSptSvc.exe [x] R3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\DRIVERS\motfilt.sys;c:\windows\SYSNATIVE\DRIVERS\motfilt.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 DrvSnSht;DrvSnSht;c:\program files (x86)\R-Drive Image\DrvSnSht64.sys;c:\program files (x86)\R-Drive Image\DrvSnSht64.sys [x] R3 dump_wmimmc;dump_wmimmc;c:\aeriagames\WolfTeam-DE\GameGuard\dump_wmimmc.sys;c:\aeriagames\WolfTeam-DE\GameGuard\dump_wmimmc.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x] R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [x] R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys;c:\windows\SYSNATIVE\DRIVERS\motccgp.sys [x] R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys;c:\windows\SYSNATIVE\DRIVERS\motccgpfl.sys [x] R3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\DRIVERS\Motousbnet.sys;c:\windows\SYSNATIVE\DRIVERS\Motousbnet.sys [x] R3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\DRIVERS\motusbdevice.sys;c:\windows\SYSNATIVE\DRIVERS\motusbdevice.sys [x] R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [x] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x] R3 R-ImageDisk;R-ImageDisk;c:\program files (x86)\R-Drive Image\R-ImageDisk64.sys;c:\program files (x86)\R-Drive Image\R-ImageDisk64.sys [x] R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bbus.sys [x] R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bmdfl.sys [x] R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bmdm.sys [x] R3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\DRIVERS\ss_bserd.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bserd.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe;c:\program files (x86)\Tunngle\TnglCtrl.exe [x] R3 X6va005;X6va005;c:\users\Sandro\AppData\Local\Temp\0053C7D.tmp;c:\users\Sandro\AppData\Local\Temp\0053C7D.tmp [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x] S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys;c:\windows\SYSNATIVE\drivers\acedrv11.sys [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 Application Updater;Application Updater;c:\program files (x86)\Application Updater\ApplicationUpdater.exe;c:\program files (x86)\Application Updater\ApplicationUpdater.exe [x] S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 DeviceMonitorService;DeviceMonitorService;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [x] S2 Freemake Improver;Freemake Improver;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [x] S2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files (x86)\Freemake\CaptureLib\CaptureLibService.exe;c:\program files (x86)\Freemake\CaptureLib\CaptureLibService.exe [x] S2 ftpsvc;Microsoft-FTP-Dienst;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 GhosteryStatsUpdater;GhosteryStats Updater;c:\users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStatsUpdater.exe;c:\users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStatsUpdater.exe [x] S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe;c:\program files (x86)\Acer\Registration\GregHSRW.exe [x] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [x] S2 IBUpdaterService;IBUpdaterService;c:\windows\system32\dmwu.exe;c:\windows\SYSNATIVE\dmwu.exe [x] S2 MotoHelper;MotoHelper Service;c:\program files (x86)\Motorola\MotoHelper\MotoHelperService.exe;c:\program files (x86)\Motorola\MotoHelper\MotoHelperService.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [x] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x] S2 USBS3S4Detection;USBS3S4Detection;c:\oem\USBDECTION\USBS3S4Detection.exe;c:\oem\USBDECTION\USBS3S4Detection.exe [x] S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] iissvcs REG_MULTI_SZ w3svc was apphost REG_MULTI_SZ apphostsvc . Inhalt des "geplante Tasks" Ordners . 2013-09-02 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-05 12:43] . 2013-09-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003Core.job - c:\users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-12-11 20:51] . 2013-09-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003UA.job - c:\users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-12-11 20:51] . 2013-08-30 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004Core.job - c:\users\Katrin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-29 05:20] . 2013-09-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004UA.job - c:\users\Katrin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-29 05:20] . 2013-09-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-31 15:29] . 2013-09-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-31 15:29] . 2013-09-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1001Core.job - c:\users\Sandro\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-31 14:44] . 2013-09-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1001UA.job - c:\users\Sandro\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-31 14:44] . 2013-09-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003Core.job - c:\users\David\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-11 15:29] . 2013-09-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003UA.job - c:\users\David\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-11 15:29] . 2013-09-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004Core.job - c:\users\Katrin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-02 16:36] . 2013-09-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004UA.job - c:\users\Katrin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-02 16:36] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-02-01 18:06 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-02-01 349552] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-01-12 9955872] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 660360] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyServer = 94.126.17.68:3128 uInternet Settings,ProxyOverride = 192.168.*.*;<local> mSearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 IE: {{3B54DEAB-C6D4-48a8-8C32-A70558643400} - c:\program files (x86)\FinalVideoDownloader\fvdRunner.html IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe Trusted Zone: aeriagames.com . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{1ce76c93-a797-4ca2-ab3c-f4a6cfba3440} - (no file) BHO-{336D0C35-8A85-403a-B9D2-65C292C39087} - (no file) BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll BHO-{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll BHO-{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} - c:\program files (x86)\PricePeep\pricepeep.dll Toolbar-Locked - (no file) Toolbar-{F9639E4A-801B-4843-AEE3-03D9DA199E77} - c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll Wow6432Node-HKLM-Run-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe Wow6432Node-HKLM-Run-<NO NAME> - (no file) Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) Toolbar-{EFEED92A-A33D-4873-BA8F-32BAA631E54D} - (no file) WebBrowser-{1CE76C93-A797-4CA2-AB3C-F4A6CFBA3440} - (no file) WebBrowser-{EFEED92A-A33D-4873-BA8F-32BAA631E54D} - (no file) AddRemove-BitRaider Web Client - c:\programdata\bitraider\brwc.exe AddRemove-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\uninstall.exe AddRemove-GameWiz32 - c:\windows\system32\GKSUI18.EXE AddRemove-Guild Wars 2 - c:\program files (x86)\Guild Wars 2\Gw2.exe AddRemove-incredibar - c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\uninstall.exe AddRemove-marvelheroes - c:\programdata\BitRaider\brwc.exe AddRemove-PricePeep - c:\program files (x86)\PricePeep\uninstall.exe AddRemove-{AA114FA3-54D7-46D9-8028-AECAC9ABE615}_is1 - c:\program files (x86)\Cossacks Anthology\unins000.exe AddRemove-FileZilla Client - l:\sandro\FileZilla FTP Client\uninstall.exe AddRemove-FoxTab Video To MP3 - c:\program files (x86)\FoxTabVideoToMP3\Uninstall\Uninstall.exe AddRemove-Hoolapp For Android - c:\users\Sandro\AppData\Roaming\HoolappForAndroid\UpdateProc\UpdateTask.exe AddRemove-MediaGet - c:\users\Sandro\AppData\Local\MediaGet2\mediaget-uninstaller.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va005] "ImagePath"="\??\c:\users\Sandro\AppData\Local\Temp\0053C7D.tmp" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-2117280256-1913491061-2286216675-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-2117280256-1913491061-2286216675-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-2117280256-1913491061-2286216675-1001\Software\SecuROM\License information*] "datasecu"=hex:83,70,12,65,2e,91,e7,31,a8,92,9f,ac,13,b0,b5,e0,03,f1,4b,ee,59, b8,f9,2a,f3,97,3e,4c,3d,64,24,50,07,be,82,bd,db,a9,89,ff,03,61,4e,07,bb,cc,\ "rkeysecu"=hex:19,05,13,61,41,b9,be,56,c6,3a,44,e9,de,bd,99,90 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\Cyberlink\Shared files\RichVideo.exe c:\windows\SysWOW64\jmdp\stij.exe . ************************************************************************** . Zeit der Fertigstellung: 2013-09-02 17:02:42 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-09-02 15:02 . Vor Suchlauf: 18 Verzeichnis(se), 59.751.018.496 Bytes frei Nach Suchlauf: 22 Verzeichnis(se), 59.407.400.960 Bytes frei . - - End Of File - - 8F84DADEF2F2C1395103C1EED1246F26 |
02.09.2013, 19:09 | #6 |
/// the machine /// TB-Ausbilder | PC Langsam, Hängt sich auf ... Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> PC Langsam, Hängt sich auf ... |
02.09.2013, 22:25 | #7 |
| PC Langsam, Hängt sich auf ...FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-09-2013 05 Ran by Sandro (administrator) on SANDRO-PC on 02-09-2013 23:21:11 Running from C:\Users\Sandro\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Nero AG) C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe () C:\Users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStatsUpdater.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe () C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe () C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe () C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Motorola Mobility Inc.) C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoCast.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Akamai Technologies, Inc.) C:\Users\Sandro\AppData\Local\Akamai\netsession_win.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (Dropbox, Inc.) C:\Users\Sandro\AppData\Roaming\Dropbox\bin\Dropbox.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe (Akamai Technologies, Inc.) C:\Users\Sandro\AppData\Local\Akamai\netsession_win.exe (CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Aeria Games & Entertainment) C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe () C:\OEM\USBDECTION\USBS3S4Detection.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-02-01] (Egis Technology Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9955872 2010-01-12] (Realtek Semiconductor) HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKCU\...\Run: [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] () HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-10] (Google Inc.) HKCU\...\Run: [MotoCast] - C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk [2059 2012-04-26] () HKCU\...\Run: [KiesHelper] - C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe [954256 2012-03-31] (Samsung) HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-03-31] () HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1811880 2013-08-28] (Valve Corporation) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Sandro\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Policies\Explorer: [NoDrives] 0 HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-02-01] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201512 2009-12-25] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [401192 2009-12-25] (Egis Technology Inc.) HKLM-x32\...\Run: [Hotkey Utility] - C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [611872 2010-08-04] () HKLM-x32\...\Run: [MDS_Menu] - C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [ArcadeMovieService] - C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe [124136 2010-02-05] (CyberLink Corp.) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3521424 2012-03-31] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-01-30] (DivX, LLC) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) HKLM-x32\...\Run: [Aeria Ignite] - C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment) HKLM-x32\...\Run: [] - [x] HKU\David\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-10] (Google Inc.) HKU\David\...\Run: [Google Update] - C:\Users\David\AppData\Local\Google\Update\GoogleUpdate.exe [135664 2011-03-31] (Google Inc.) HKU\David\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKU\David\...\Run: [Facebook Update] - C:\Users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-11] (Facebook Inc.) HKU\David\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-03-31] () HKU\David\...\Run: [Akamai NetSession Interface] - C:\Users\David\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\DefaultAppPool\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\Katrin\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKU\Katrin\...\Run: [Google Update] - C:\Users\Katrin\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-10-02] (Google Inc.) HKU\Katrin\...\Run: [Facebook Update] - C:\Users\Katrin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.) HKU\Katrin\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-10] (Google Inc.) HKU\UpdatusUser\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Sandro\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== ProxyServer: 94.126.17.68:3128 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {16E21108-4AD7-49CB-844B-26AF3D1B9664} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: GhosteryStats - {C331A7D9-4187-464C-BE66-FDBC56C07678} - C:\Users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStats.dll (David Cancel) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Freemake.YoutubeButton - {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - No Name - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No File DPF: HKLM-x32 {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Ask.com FF NetworkProxy: "type", 0 FF DefaultSearchEngine: Ask.com FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.132.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.3 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Sandro\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Sandro\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\searchplugins\absearch-search.xml FF Extension: No Name - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\staged FF Extension: DownloadHelper - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9} FF Extension: jid1-kV5U6puWw0Cdvg - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\jid1-kV5U6puWw0Cdvg@jetpack.xpi FF Extension: youtubedownloader - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\youtubedownloader@mybrowserbar.com FF Extension: No Name - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [downloader@finalvideotools.com] C:\Program Files (x86)\FinalVideoDownloader\Firefox FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ FF HKLM-x32\...\Firefox\Extensions: [siteranker@siteranker.com] C:\Program Files (x86)\SiteRanker\firefox\ FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "https://www.google.de/" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\29.0.1547.62\pdf.dll () CHR Plugin: (Freemake np-plugin for google chrome) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0\npFreemake.dll () CHR Plugin: (Freemake np-plugin for google chrome) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0\npFreemakeYoutubeDownloader.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (PlayStation(R)Network Downloader Check Plug-in) - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll No File CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (ProxTube) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0 CHR Extension: (YouTube) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Freemake Video Downloader) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0 CHR Extension: (Google Search) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Battlelog) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajcdbgpkfpghffojnlbjkadcobpbaid\1.0.4_0 CHR Extension: (Freemake Video Downloader) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0 CHR Extension: (GhosteryStats) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehmdnmbaomgmfmjiajhdfopgnbmgkcog\2.7.192_0 CHR Extension: (AdBlock) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_0 CHR Extension: (Quick Match BF3) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\iacjfjhinfbmljdpedecedhcghgmmdcf\1.1_0 CHR Extension: () - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigfdicgjnpjkhbnngdfgjfffmdaonfg\2_0 CHR Extension: (BattlelogPlus) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\lphojmgkbcmdjpaepolkjeienkacpjpi\1.38_0 CHR Extension: (Battlelog: BF 3) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhdecopbclicngfcdmhinokemjlmcihf\0.1.2_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0 CHR Extension: (Gmail) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [dgldkplledicnbnnliodeffobaiaodaf] - C:\Program Files (x86)\SiteRanker\Chrome\siterank_c.crx CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx CHR HKLM-x32\...\Chrome\Extension: [ehmdnmbaomgmfmjiajhdfopgnbmgkcog] - C:\Users\Sandro\AppData\LocalLow\GhosteryStats\CHROME\GhosteryStats.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx CHR HKLM-x32\...\Chrome\Extension: [ofahndfepeaeelmhdkjiihmofnokhmik] - C:\Users\Sandro\AppData\Local\Temp\tbch.crx CHR StartMenuInternet: Google Chrome - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101376 2013-02-25] (Freemake) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-02-25] (Ellora Assets Corp.) R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [350720 2012-06-01] (Microsoft Corporation) R2 GhosteryStatsUpdater; C:\Users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStatsUpdater.exe [18432 2012-02-28] () S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2012-02-01] () S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-02-01] (Egis Technology Inc.) S3 npggsvc; C:\Windows\SysWow64\GameMon.des [4159984 2010-12-08] (INCA Internet Co., Ltd.) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-04-07] () R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [244904 2010-02-03] () S2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2026304 2011-06-06] (TuneUp Software) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH) R2 USBS3S4Detection; C:\OEM\USBDECTION\USBS3S4Detection.exe [76320 2009-12-09] () R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation) S3 BRSptSvc; "C:\ProgramData\BitRaider\BRSptSvc.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-25] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-25] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-25] (Avira Operations GmbH & Co. KG) S3 DrvSnSht; C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys [132432 2010-06-01] (R-TT Inc.) S3 DrvSnSht; C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys [132432 2010-06-01] (R-TT Inc.) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-06-06] (DT Soft Ltd) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) S3 NPPTNT2; C:\Windows\SysWow64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) S3 R-ImageDisk; C:\Program Files (x86)\R-Drive Image\R-ImageDisk64.sys [187600 2010-10-16] (R-TT Inc.) S3 R-ImageDisk; C:\Program Files (x86)\R-Drive Image\R-ImageDisk64.sys [187600 2010-10-16] (R-TT Inc.) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [513080 2011-06-06] () S3 ss_bserd; C:\Windows\System32\DRIVERS\ss_bserd.sys [128000 2010-12-21] (MCCI Corporation) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [11856 2010-10-07] (TuneUp Software) U3 a23e1q28; C:\Windows\System32\Drivers\a23e1q28.sys [0 ] (Microsoft Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 BRDriver64; \??\C:\programdata\bitraider\BRDriver64.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 dump_wmimmc; \??\C:\AeriaGames\WolfTeam-DE\GameGuard\dump_wmimmc.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x] S3 X6va005; \??\C:\Users\Sandro\AppData\Local\Temp\0053C7D.tmp [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-02 23:18 - 2013-09-02 23:18 - 00035012 _____ C:\Users\Sandro\Desktop\Desktop.7z 2013-09-02 23:06 - 2013-09-02 23:06 - 00118766 _____ C:\Users\Sandro\Desktop\JRT.txt 2013-09-02 23:01 - 2013-09-02 23:01 - 00000000 ____D C:\Windows\ERUNT 2013-09-02 22:59 - 2013-09-02 22:59 - 01028757 _____ (Thisisu) C:\Users\Sandro\Downloads\JRT.exe 2013-09-02 22:51 - 2013-09-02 22:54 - 00061439 _____ C:\Users\Sandro\Desktop\AdwCleaner[S0].txt 2013-09-02 22:42 - 2013-09-02 23:13 - 00000000 ____D C:\AdwCleaner 2013-09-02 22:41 - 2013-09-02 22:41 - 01037134 _____ C:\Users\Sandro\Desktop\adwcleaner.exe 2013-09-02 22:02 - 2013-09-02 22:02 - 00001117 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Malwarebytes 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-02 22:02 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-02 22:00 - 2013-09-02 22:01 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Sandro\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-02 17:02 - 2013-09-02 17:02 - 00044132 _____ C:\ComboFix.txt 2013-09-02 16:52 - 2013-09-02 22:27 - 00036046 _____ C:\Windows\PFRO.log 2013-09-02 16:27 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-02 16:27 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-02 16:27 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-02 16:27 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-02 16:27 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-02 16:27 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-02 16:27 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-02 16:27 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-02 16:26 - 2013-09-02 17:02 - 00000000 ____D C:\Qoobox 2013-09-02 16:24 - 2013-09-02 17:00 - 00000000 ____D C:\Windows\erdnt 2013-09-02 16:21 - 2013-09-02 16:22 - 05119472 ____R (Swearware) C:\Users\Sandro\Desktop\ComboFix.exe 2013-09-02 12:42 - 2013-09-02 12:42 - 00038330 _____ C:\Users\Sandro\Downloads\Addition (1).7z 2013-09-02 12:41 - 2013-09-02 12:41 - 00038330 _____ C:\Users\Sandro\Downloads\Addition.7z 2013-09-02 12:34 - 2013-09-02 12:34 - 00000000 ____D C:\Program Files (x86)\7-Zip 2013-09-02 12:33 - 2013-09-02 12:33 - 01110476 _____ C:\Users\Sandro\Downloads\7z920.exe 2013-09-02 12:25 - 2013-09-02 13:18 - 00108166 _____ C:\Users\Sandro\Downloads\FRST.txt 2013-09-02 12:22 - 2013-09-02 12:25 - 00178260 _____ C:\Users\Sandro\Downloads\Addition.txt 2013-09-02 12:16 - 2013-09-02 12:16 - 00000000 ____D C:\FRST 2013-09-02 02:56 - 2013-09-02 02:56 - 00003088 _____ C:\Windows\System32\Tasks\{F741D114-8004-44D5-96EB-33971BBCD417} 2013-09-01 23:42 - 2013-09-01 23:43 - 60757752 _____ (Gazillion Entertainment ) C:\Users\Sandro\Downloads\marvelheroesinstaller.exe 2013-09-01 23:20 - 2013-09-01 23:21 - 00330518 _____ C:\Users\Sandro\Documents\cc_20130901_232036.reg 2013-09-01 23:11 - 2013-09-01 23:29 - 00000000 ____D C:\Users\Sandro\Downloads\CCEnhancer 2013-09-01 23:10 - 2013-09-01 23:11 - 00176719 _____ C:\Users\Sandro\Downloads\CCEnhancer-3.8-multilanguage.zip 2013-09-01 01:25 - 2013-09-01 01:25 - 00000000 ____D C:\Program Files (x86)\Frogwares 2013-08-31 23:58 - 2013-08-31 23:58 - 00614920 _____ C:\Windows\Minidump\083113-158606-01.dmp 2013-08-31 23:21 - 2013-08-31 23:21 - 00003088 _____ C:\Windows\System32\Tasks\{0D0E4C94-0C9F-48BA-A856-AA025793FD2C} 2013-08-31 11:52 - 2013-08-31 11:52 - 03367611 _____ C:\Users\David\Downloads\easyHalls.exe 2013-08-31 02:32 - 2013-08-31 02:32 - 00003088 _____ C:\Windows\System32\Tasks\{598B6998-980B-477A-B0AE-FA6585404995} 2013-08-30 03:00 - 2013-08-30 03:00 - 00003088 _____ C:\Windows\System32\Tasks\{3E5317FD-A87C-4939-B5D3-EEBC998CEB85} 2013-08-29 02:48 - 2013-08-29 02:48 - 00003088 _____ C:\Windows\System32\Tasks\{FB0B0681-2A62-4A02-89EA-275B2BA27866} 2013-08-28 02:44 - 2013-08-28 02:44 - 00003088 _____ C:\Windows\System32\Tasks\{7DF15D2D-9E9F-46AC-A90F-13A20C4D983D} 2013-08-27 02:23 - 2013-08-27 02:23 - 00003088 _____ C:\Windows\System32\Tasks\{6034F774-F129-4A22-AF1B-08870102A4CF} 2013-08-26 03:39 - 2013-08-26 03:39 - 00003088 _____ C:\Windows\System32\Tasks\{00FE09DB-2041-4FE9-A8C7-6A3183FCB20A} 2013-08-26 03:01 - 2013-08-26 03:01 - 00003088 _____ C:\Windows\System32\Tasks\{C0C1C429-CC94-478F-938D-2A2437CF7F0E} 2013-08-25 12:51 - 2013-08-25 12:51 - 00705136 _____ C:\Users\David\Downloads\UltimateCodec.exe 2013-08-25 02:35 - 2013-08-25 02:35 - 00003088 _____ C:\Windows\System32\Tasks\{079FF58D-0420-425F-A404-A2C8847198A7} 2013-08-24 19:28 - 2013-08-24 19:28 - 00001146 _____ C:\Users\David\Desktop\Continue Zip Opener Installation.lnk 2013-08-24 12:27 - 2013-08-24 12:27 - 13177488 _____ C:\Users\David\Downloads\RopaNawaroMaus.exe 2013-08-24 12:26 - 2013-08-24 12:26 - 03672231 _____ C:\Users\David\Downloads\MischStation.exe 2013-08-24 02:06 - 2013-08-24 02:06 - 00003088 _____ C:\Windows\System32\Tasks\{7C96B1B9-129B-43D3-92BA-15E58DD13CFC} 2013-08-23 02:28 - 2013-08-23 02:28 - 00003088 _____ C:\Windows\System32\Tasks\{80134A1F-9616-4C20-9393-6B0FBA5B4B83} 2013-08-22 18:10 - 2013-08-22 18:10 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip 2013-08-22 18:07 - 2013-08-22 18:07 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip 2013-08-22 04:38 - 2013-08-22 04:38 - 00003088 _____ C:\Windows\System32\Tasks\{BF13EA0A-31B2-410A-9F93-743C5C4082DC} 2013-08-22 03:02 - 2013-08-22 03:02 - 00003088 _____ C:\Windows\System32\Tasks\{2CA1F239-220D-4323-AADE-591302E5262B} 2013-08-21 01:35 - 2013-08-21 01:35 - 00003088 _____ C:\Windows\System32\Tasks\{76511A5A-32F2-4D88-9CC3-2EDD4F267B19} 2013-08-20 23:57 - 2013-08-20 23:57 - 00000000 ____D C:\Users\Sandro\Documents\Electronic Arts 2013-08-20 23:32 - 2013-08-20 23:32 - 00002252 _____ C:\Users\Public\Desktop\Die Sims™ 3 Luxus-Accessoires.lnk 2013-08-20 23:27 - 2013-08-20 23:27 - 00002304 _____ C:\Users\Public\Desktop\Die*Sims™*3.lnk 2013-08-20 16:25 - 2013-08-20 17:38 - 00000000 ____D C:\Users\David\AppData\Local\Mozilla Firefox 2013-08-20 02:10 - 2013-08-20 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{E120DF85-ADC1-4E35-B378-5CB8B450BDBA} 2013-08-19 02:05 - 2013-08-19 02:05 - 00003088 _____ C:\Windows\System32\Tasks\{AB4F94BD-4CCB-4275-810C-0C01764E0439} 2013-08-18 13:15 - 2013-08-18 17:39 - 00000000 ____D C:\Users\Katrin\AppData\Local\Mozilla Firefox 2013-08-18 02:46 - 2013-08-18 02:46 - 00003088 _____ C:\Windows\System32\Tasks\{B00AB3A3-0DA8-4391-B49B-85969C9CA3FD} 2013-08-18 01:21 - 2013-08-18 01:22 - 00004197 _____ C:\Users\Sandro\Desktop\Your Humble Bundle order is ready.html 2013-08-15 13:30 - 2013-08-15 13:31 - 00000000 ____D C:\Windows\rescache 2013-08-15 01:59 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 01:59 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 01:59 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 01:59 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 01:59 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 01:59 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 01:59 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 01:59 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 01:59 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 01:59 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 01:59 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 01:59 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-15 01:53 - 2013-08-15 01:57 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 13:10 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 13:10 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 13:10 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 13:10 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 13:10 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 13:10 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 13:10 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 13:10 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 13:10 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 13:10 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 13:10 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 13:10 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 13:10 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 13:10 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 13:10 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 13:10 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 13:10 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 13:10 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 13:10 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 13:10 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 13:10 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 13:10 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 13:10 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 13:10 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 13:10 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 13:10 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 13:10 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 12:58 - 2013-08-14 12:58 - 00000003 _____ C:\Windows\system32\HRUPPROG.DIE.NOW 2013-08-14 12:57 - 2013-08-31 10:00 - 00000003 _____ C:\Windows\system32\HRUPPROG.TXT 2013-08-14 02:51 - 2013-08-14 02:51 - 00003088 _____ C:\Windows\System32\Tasks\{2210D34F-EBC5-4554-9C19-30F50B90D375} 2013-08-14 01:13 - 2013-08-14 01:13 - 00002032 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-14 01:13 - 2013-08-14 01:13 - 00000000 ____D C:\Program Files (x86)\Aeria Games 2013-08-13 01:59 - 2013-08-13 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{207F6A12-65B2-4433-A50D-5467803ED18D} 2013-08-12 19:07 - 2013-09-01 23:45 - 00002469 _____ C:\Windows\DirectX.log 2013-08-12 17:52 - 2013-08-12 17:52 - 01204902 _____ C:\Users\Sandro\Downloads\Smite Font fix.rar 2013-08-12 17:32 - 2013-08-12 17:32 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish (1).exe 2013-08-12 17:29 - 2013-08-12 17:33 - 00002032 _____ C:\Users\Public\Desktop\Smite.lnk 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\ProgramData\Hi-Rez Studios 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios 2013-08-12 17:25 - 2013-08-12 17:25 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish.exe 2013-08-12 01:42 - 2013-08-12 01:42 - 00003088 _____ C:\Windows\System32\Tasks\{B50AF006-5459-4FB7-B54A-159E237C1B47} 2013-08-11 02:16 - 2013-08-11 02:16 - 00003088 _____ C:\Windows\System32\Tasks\{6523F6E2-6431-4271-A355-983127186566} 2013-08-10 18:44 - 2013-08-10 18:44 - 00003088 _____ C:\Windows\System32\Tasks\{6E810A62-A06C-47FA-A5B4-7EDF8D29D3D4} 2013-08-10 02:10 - 2013-08-10 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{50C71F38-7796-4D0F-8828-09F50A146372} 2013-08-09 07:11 - 2013-08-09 07:11 - 00003088 _____ C:\Windows\System32\Tasks\{C89A309D-5292-4DFD-B2A3-C98965450CA6} 2013-08-09 02:43 - 2013-08-09 02:43 - 00003088 _____ C:\Windows\System32\Tasks\{DC14F991-DAAB-4948-836C-81B304ADDA7F} 2013-08-08 19:00 - 2013-08-08 19:00 - 00000011 _____ C:\Users\Sandro\Desktop\Neues Textdokument.txt 2013-08-08 02:26 - 2013-08-08 02:26 - 00003088 _____ C:\Windows\System32\Tasks\{896182C0-FBCB-4B11-8249-C511298E4013} 2013-08-07 02:30 - 2013-08-07 02:30 - 00003088 _____ C:\Windows\System32\Tasks\{7469A554-0505-4536-98F9-F3E80ECCCBEC} 2013-08-06 21:47 - 2013-08-06 21:47 - 00675988 _____ C:\Users\Sandro\Desktop\Minecraft (2).exe 2013-08-06 01:59 - 2013-08-06 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{945A3915-5477-42D9-867D-11EC9100BFFD} 2013-08-05 21:12 - 2013-08-05 21:12 - 00003632 _____ C:\Users\Sandro\Downloads\142e5e19d17b19f2c5398ec6234eaec0.dlc 2013-08-05 02:10 - 2013-08-05 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{DB410448-2A0E-4A1C-8396-235662B567C2} 2013-08-04 19:33 - 2013-08-04 19:34 - 00000000 ____D C:\Users\Katrin\Desktop\Bilder Urlaub 2013-08-04 02:40 - 2013-08-04 02:40 - 00003088 _____ C:\Windows\System32\Tasks\{3CCBF5D6-F969-444A-8F77-5E93635378D4} 2013-08-03 02:34 - 2013-08-03 02:34 - 00003088 _____ C:\Windows\System32\Tasks\{F9A26D5E-F671-4537-B0BB-058FAD3E2844} ==================== One Month Modified Files and Folders ======= 2013-09-02 23:20 - 2013-09-02 23:20 - 01951954 _____ (Farbar) C:\Users\Sandro\Desktop\FRST64.exe 2013-09-02 23:18 - 2013-09-02 23:18 - 00035012 _____ C:\Users\Sandro\Desktop\Desktop.7z 2013-09-02 23:13 - 2013-09-02 22:42 - 00000000 ____D C:\AdwCleaner 2013-09-02 23:06 - 2013-09-02 23:06 - 00118766 _____ C:\Users\Sandro\Desktop\JRT.txt 2013-09-02 23:05 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-02 23:05 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-02 23:01 - 2013-09-02 23:01 - 00000000 ____D C:\Windows\ERUNT 2013-09-02 22:59 - 2013-09-02 22:59 - 01028757 _____ (Thisisu) C:\Users\Sandro\Downloads\JRT.exe 2013-09-02 22:58 - 2012-04-26 21:20 - 00000000 ____D C:\Users\Sandro\.gstreamer-0.10 2013-09-02 22:58 - 2012-04-26 21:18 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\MotoCast 2013-09-02 22:58 - 2011-03-31 17:29 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-02 22:57 - 2013-02-24 20:02 - 00000000 ____D C:\Users\Sandro\AppData\Local\LogMeIn Hamachi 2013-09-02 22:57 - 2012-10-16 02:15 - 00000000 ____D C:\Program Files (x86)\Steam 2013-09-02 22:57 - 2012-07-12 15:29 - 00000000 ___RD C:\Users\Sandro\Dropbox 2013-09-02 22:57 - 2012-07-12 15:25 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Dropbox 2013-09-02 22:56 - 2011-12-11 17:34 - 00001138 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003UA.job 2013-09-02 22:56 - 2011-12-11 17:34 - 00001116 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003Core.job 2013-09-02 22:56 - 2011-03-31 17:29 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-02 22:55 - 2013-07-13 19:02 - 00006857 _____ C:\Windows\setupact.log 2013-09-02 22:55 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-02 22:55 - 2007-10-10 18:58 - 00000000 ____D C:\ProgramData\NVIDIA 2013-09-02 22:54 - 2013-09-02 22:51 - 00061439 _____ C:\Users\Sandro\Desktop\AdwCleaner[S0].txt 2013-09-02 22:54 - 2007-10-10 18:55 - 01122085 _____ C:\Windows\WindowsUpdate.log 2013-09-02 22:53 - 2012-06-30 11:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-02 22:46 - 2011-07-03 20:44 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\TS3Client 2013-09-02 22:43 - 2012-06-05 17:50 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-02 22:41 - 2013-09-02 22:41 - 01037134 _____ C:\Users\Sandro\Desktop\adwcleaner.exe 2013-09-02 22:39 - 2011-03-31 16:44 - 00000000 ____D C:\Users\Sandro\AppData\Local\Apps\2.0 2013-09-02 22:37 - 2011-10-02 18:36 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004UA.job 2013-09-02 22:27 - 2013-09-02 16:52 - 00036046 _____ C:\Windows\PFRO.log 2013-09-02 22:26 - 2011-04-11 15:12 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003UA.job 2013-09-02 22:25 - 2012-01-29 14:28 - 00001142 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004UA.job 2013-09-02 22:25 - 2011-03-31 16:44 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1001UA.job 2013-09-02 22:24 - 2011-03-31 17:29 - 00000000 ____D C:\Users\David 2013-09-02 22:24 - 2011-03-31 16:34 - 00000000 ____D C:\Users\Sandro 2013-09-02 22:10 - 2013-02-27 04:11 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\.minecraft 2013-09-02 22:02 - 2013-09-02 22:02 - 00001117 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Malwarebytes 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-02 22:01 - 2013-09-02 22:00 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Sandro\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-02 20:24 - 2011-03-31 16:44 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1001Core.job 2013-09-02 17:37 - 2013-02-25 08:40 - 00000000 ____D C:\Users\Katrin\AppData\Local\LogMeIn Hamachi 2013-09-02 17:02 - 2013-09-02 17:02 - 00044132 _____ C:\ComboFix.txt 2013-09-02 17:02 - 2013-09-02 16:26 - 00000000 ____D C:\Qoobox 2013-09-02 17:02 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-09-02 17:00 - 2013-09-02 16:24 - 00000000 ____D C:\Windows\erdnt 2013-09-02 16:54 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-09-02 16:22 - 2013-09-02 16:21 - 05119472 ____R (Swearware) C:\Users\Sandro\Desktop\ComboFix.exe 2013-09-02 14:37 - 2011-10-02 18:36 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004Core.job 2013-09-02 13:18 - 2013-09-02 12:25 - 00108166 _____ C:\Users\Sandro\Downloads\FRST.txt 2013-09-02 12:42 - 2013-09-02 12:42 - 00038330 _____ C:\Users\Sandro\Downloads\Addition (1).7z 2013-09-02 12:41 - 2013-09-02 12:41 - 00038330 _____ C:\Users\Sandro\Downloads\Addition.7z 2013-09-02 12:34 - 2013-09-02 12:34 - 00000000 ____D C:\Program Files (x86)\7-Zip 2013-09-02 12:33 - 2013-09-02 12:33 - 01110476 _____ C:\Users\Sandro\Downloads\7z920.exe 2013-09-02 12:25 - 2013-09-02 12:22 - 00178260 _____ C:\Users\Sandro\Downloads\Addition.txt 2013-09-02 12:16 - 2013-09-02 12:16 - 00000000 ____D C:\FRST 2013-09-02 12:16 - 2013-04-24 15:11 - 00000000 ____D C:\Users\DefaultAppPool 2013-09-02 02:56 - 2013-09-02 02:56 - 00003088 _____ C:\Windows\System32\Tasks\{F741D114-8004-44D5-96EB-33971BBCD417} 2013-09-02 02:26 - 2011-04-11 15:12 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003Core.job 2013-09-01 23:45 - 2013-08-12 19:07 - 00002469 _____ C:\Windows\DirectX.log 2013-09-01 23:43 - 2013-09-01 23:42 - 60757752 _____ (Gazillion Entertainment ) C:\Users\Sandro\Downloads\marvelheroesinstaller.exe 2013-09-01 23:29 - 2013-09-01 23:11 - 00000000 ____D C:\Users\Sandro\Downloads\CCEnhancer 2013-09-01 23:21 - 2013-09-01 23:20 - 00330518 _____ C:\Users\Sandro\Documents\cc_20130901_232036.reg 2013-09-01 23:12 - 2011-07-31 23:12 - 00000000 ____D C:\Program Files\CCleaner 2013-09-01 23:11 - 2013-09-01 23:10 - 00176719 _____ C:\Users\Sandro\Downloads\CCEnhancer-3.8-multilanguage.zip 2013-09-01 22:52 - 2011-04-01 07:10 - 00000000 ____D C:\Users\Katrin 2013-09-01 22:51 - 2013-07-03 07:24 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-09-01 22:51 - 2013-06-01 02:10 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b ROC Installer deDE 2013-09-01 22:51 - 2013-06-01 01:56 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b TFT Installer deDE 2013-09-01 22:51 - 2013-05-31 04:13 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b TFT Installer enGB 2013-09-01 22:51 - 2013-05-31 03:57 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b ROC Installer enGB 2013-09-01 22:51 - 2013-05-06 01:12 - 00000000 ____D C:\Users\Sandro\AppData\Local\Akamai 2013-09-01 22:51 - 2013-04-07 16:55 - 00000000 ____D C:\Ubisoft 2013-09-01 22:51 - 2013-04-07 16:54 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2013-09-01 22:51 - 2013-03-23 22:41 - 00000000 ____D C:\Users\Public\Sony Online Entertainment 2013-09-01 22:51 - 2012-02-11 18:23 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-09-01 22:51 - 2012-02-11 18:23 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-09-01 22:51 - 2011-06-09 01:01 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-09-01 22:51 - 2011-04-04 19:03 - 00000000 ____D C:\Users\Sandro\Downloads\JD 2013-09-01 22:51 - 2011-04-01 19:53 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-09-01 22:51 - 2010-05-10 13:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-09-01 22:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-09-01 13:20 - 2011-10-02 18:36 - 00002378 _____ C:\Users\Katrin\Desktop\Google Chrome.lnk 2013-09-01 13:01 - 2009-07-14 07:13 - 00419726 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-01 13:01 - 2007-10-11 04:46 - 00178236 _____ C:\Windows\system32\perfh007.dat 2013-09-01 13:01 - 2007-10-11 04:46 - 00060400 _____ C:\Windows\system32\perfc007.dat 2013-09-01 12:55 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-01 01:51 - 2011-08-23 01:29 - 02507776 ___SH C:\Users\Sandro\Downloads\Thumbs.db 2013-09-01 01:25 - 2013-09-01 01:25 - 00000000 ____D C:\Program Files (x86)\Frogwares 2013-09-01 01:14 - 2011-06-06 03:14 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\DAEMON Tools Lite 2013-09-01 01:14 - 2011-04-21 20:14 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\FileZilla 2013-09-01 01:14 - 2011-03-31 18:17 - 00000000 ____D C:\Users\Sandro\Tracing 2013-08-31 23:58 - 2013-08-31 23:58 - 00614920 _____ C:\Windows\Minidump\083113-158606-01.dmp 2013-08-31 23:58 - 2011-07-27 16:00 - 00000000 ____D C:\Windows\Minidump 2013-08-31 23:21 - 2013-08-31 23:21 - 00003088 _____ C:\Windows\System32\Tasks\{0D0E4C94-0C9F-48BA-A856-AA025793FD2C} 2013-08-31 11:52 - 2013-08-31 11:52 - 03367611 _____ C:\Users\David\Downloads\easyHalls.exe 2013-08-31 10:00 - 2013-08-14 12:57 - 00000003 _____ C:\Windows\system32\HRUPPROG.TXT 2013-08-31 09:05 - 2013-02-25 14:59 - 00000000 ____D C:\Users\David\AppData\Local\LogMeIn Hamachi 2013-08-31 02:32 - 2013-08-31 02:32 - 00003088 _____ C:\Windows\System32\Tasks\{598B6998-980B-477A-B0AE-FA6585404995} 2013-08-30 07:25 - 2012-01-29 14:28 - 00001120 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004Core.job 2013-08-30 03:00 - 2013-08-30 03:00 - 00003088 _____ C:\Windows\System32\Tasks\{3E5317FD-A87C-4939-B5D3-EEBC998CEB85} 2013-08-30 01:34 - 2011-03-31 16:44 - 00002378 _____ C:\Users\Sandro\Desktop\Google Chrome.lnk 2013-08-29 17:02 - 2011-04-02 16:37 - 00000000 ____D C:\Users\David\AppData\Local\Google 2013-08-29 16:06 - 2011-04-11 19:48 - 00002373 _____ C:\Users\David\Desktop\Google Chrome.lnk 2013-08-29 02:48 - 2013-08-29 02:48 - 00003088 _____ C:\Windows\System32\Tasks\{FB0B0681-2A62-4A02-89EA-275B2BA27866} 2013-08-28 02:44 - 2013-08-28 02:44 - 00003088 _____ C:\Windows\System32\Tasks\{7DF15D2D-9E9F-46AC-A90F-13A20C4D983D} 2013-08-27 21:16 - 2011-07-25 20:55 - 00000000 ____D C:\Users\David\Desktop\Emergency 4 Deluxe 2013-08-27 19:27 - 2013-07-23 11:52 - 00000000 ____D C:\Program Files (x86)\ERS Berlin 2013-08-27 10:40 - 2011-03-31 17:36 - 00000000 ____D C:\Users\David\Documents\My Games 2013-08-27 02:23 - 2013-08-27 02:23 - 00003088 _____ C:\Windows\System32\Tasks\{6034F774-F129-4A22-AF1B-08870102A4CF} 2013-08-26 03:39 - 2013-08-26 03:39 - 00003088 _____ C:\Windows\System32\Tasks\{00FE09DB-2041-4FE9-A8C7-6A3183FCB20A} 2013-08-26 03:01 - 2013-08-26 03:01 - 00003088 _____ C:\Windows\System32\Tasks\{C0C1C429-CC94-478F-938D-2A2437CF7F0E} 2013-08-25 12:51 - 2013-08-25 12:51 - 00705136 _____ C:\Users\David\Downloads\UltimateCodec.exe 2013-08-25 02:35 - 2013-08-25 02:35 - 00003088 _____ C:\Windows\System32\Tasks\{079FF58D-0420-425F-A404-A2C8847198A7} 2013-08-24 21:56 - 2011-04-03 16:46 - 00064000 _____ C:\Users\David\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-24 19:28 - 2013-08-24 19:28 - 00001146 _____ C:\Users\David\Desktop\Continue Zip Opener Installation.lnk 2013-08-24 12:27 - 2013-08-24 12:27 - 13177488 _____ C:\Users\David\Downloads\RopaNawaroMaus.exe 2013-08-24 12:26 - 2013-08-24 12:26 - 03672231 _____ C:\Users\David\Downloads\MischStation.exe 2013-08-24 02:06 - 2013-08-24 02:06 - 00003088 _____ C:\Windows\System32\Tasks\{7C96B1B9-129B-43D3-92BA-15E58DD13CFC} 2013-08-23 02:28 - 2013-08-23 02:28 - 00003088 _____ C:\Windows\System32\Tasks\{80134A1F-9616-4C20-9393-6B0FBA5B4B83} 2013-08-22 18:10 - 2013-08-22 18:10 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip 2013-08-22 18:07 - 2013-08-22 18:07 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip 2013-08-22 13:05 - 2012-03-27 15:08 - 00000000 ____D C:\Program Files (x86)\Origin 2013-08-22 04:38 - 2013-08-22 04:38 - 00003088 _____ C:\Windows\System32\Tasks\{BF13EA0A-31B2-410A-9F93-743C5C4082DC} 2013-08-22 04:35 - 2011-04-25 22:07 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\SoftGrid Client 2013-08-22 03:06 - 2011-03-31 16:43 - 00000000 ____D C:\Users\Sandro\AppData\Local\Google 2013-08-22 03:02 - 2013-08-22 03:02 - 00003088 _____ C:\Windows\System32\Tasks\{2CA1F239-220D-4323-AADE-591302E5262B} 2013-08-21 14:43 - 2012-06-05 17:50 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-21 14:43 - 2012-06-05 17:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-21 14:43 - 2012-06-05 17:50 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-21 13:19 - 2012-10-21 15:22 - 00000000 ____D C:\Users\David\AppData\Local\Origin 2013-08-21 13:19 - 2012-03-28 02:55 - 00000000 ____D C:\Users\David\AppData\Roaming\Origin 2013-08-21 01:35 - 2013-08-21 01:35 - 00003088 _____ C:\Windows\System32\Tasks\{76511A5A-32F2-4D88-9CC3-2EDD4F267B19} 2013-08-20 23:57 - 2013-08-20 23:57 - 00000000 ____D C:\Users\Sandro\Documents\Electronic Arts 2013-08-20 23:32 - 2013-08-20 23:32 - 00002252 _____ C:\Users\Public\Desktop\Die Sims™ 3 Luxus-Accessoires.lnk 2013-08-20 23:29 - 2012-03-27 15:10 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-08-20 23:27 - 2013-08-20 23:27 - 00002304 _____ C:\Users\Public\Desktop\Die*Sims™*3.lnk 2013-08-20 17:38 - 2013-08-20 16:25 - 00000000 ____D C:\Users\David\AppData\Local\Mozilla Firefox 2013-08-20 02:10 - 2013-08-20 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{E120DF85-ADC1-4E35-B378-5CB8B450BDBA} 2013-08-19 02:05 - 2013-08-19 02:05 - 00003088 _____ C:\Windows\System32\Tasks\{AB4F94BD-4CCB-4275-810C-0C01764E0439} 2013-08-18 17:39 - 2013-08-18 13:15 - 00000000 ____D C:\Users\Katrin\AppData\Local\Mozilla Firefox 2013-08-18 02:46 - 2013-08-18 02:46 - 00003088 _____ C:\Windows\System32\Tasks\{B00AB3A3-0DA8-4391-B49B-85969C9CA3FD} 2013-08-18 01:22 - 2013-08-18 01:21 - 00004197 _____ C:\Users\Sandro\Desktop\Your Humble Bundle order is ready.html 2013-08-17 23:31 - 2012-03-27 15:10 - 00000000 ____D C:\Users\Sandro\AppData\Local\Origin 2013-08-17 23:31 - 2012-03-27 15:10 - 00000000 ____D C:\ProgramData\Origin 2013-08-17 23:31 - 2012-03-27 15:09 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Origin 2013-08-15 17:16 - 2011-04-26 23:19 - 00000000 ____D C:\Users\Sandro\Desktop\Zeuch Halt 2013-08-15 13:31 - 2013-08-15 13:30 - 00000000 ____D C:\Windows\rescache 2013-08-15 01:57 - 2013-08-15 01:53 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 01:52 - 2011-04-30 22:28 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-14 12:58 - 2013-08-14 12:58 - 00000003 _____ C:\Windows\system32\HRUPPROG.DIE.NOW 2013-08-14 02:51 - 2013-08-14 02:51 - 00003088 _____ C:\Windows\System32\Tasks\{2210D34F-EBC5-4554-9C19-30F50B90D375} 2013-08-14 01:13 - 2013-08-14 01:13 - 00002032 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-14 01:13 - 2013-08-14 01:13 - 00000000 ____D C:\Program Files (x86)\Aeria Games 2013-08-13 12:26 - 2011-04-25 14:31 - 00064000 _____ C:\Users\Katrin\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-13 12:24 - 2009-07-14 06:45 - 00295696 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-13 01:59 - 2013-08-13 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{207F6A12-65B2-4433-A50D-5467803ED18D} 2013-08-12 19:54 - 2011-03-31 22:06 - 00000000 ____D C:\Users\Sandro\Documents\My Games 2013-08-12 17:53 - 2011-03-31 16:35 - 00064000 _____ C:\Users\Sandro\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-12 17:52 - 2013-08-12 17:52 - 01204902 _____ C:\Users\Sandro\Downloads\Smite Font fix.rar 2013-08-12 17:33 - 2013-08-12 17:29 - 00002032 _____ C:\Users\Public\Desktop\Smite.lnk 2013-08-12 17:32 - 2013-08-12 17:32 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish (1).exe 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\ProgramData\Hi-Rez Studios 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios 2013-08-12 17:25 - 2013-08-12 17:25 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish.exe 2013-08-12 01:42 - 2013-08-12 01:42 - 00003088 _____ C:\Windows\System32\Tasks\{B50AF006-5459-4FB7-B54A-159E237C1B47} 2013-08-11 02:16 - 2013-08-11 02:16 - 00003088 _____ C:\Windows\System32\Tasks\{6523F6E2-6431-4271-A355-983127186566} 2013-08-10 18:44 - 2013-08-10 18:44 - 00003088 _____ C:\Windows\System32\Tasks\{6E810A62-A06C-47FA-A5B4-7EDF8D29D3D4} 2013-08-10 02:10 - 2013-08-10 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{50C71F38-7796-4D0F-8828-09F50A146372} 2013-08-09 07:11 - 2013-08-09 07:11 - 00003088 _____ C:\Windows\System32\Tasks\{C89A309D-5292-4DFD-B2A3-C98965450CA6} 2013-08-09 02:43 - 2013-08-09 02:43 - 00003088 _____ C:\Windows\System32\Tasks\{DC14F991-DAAB-4948-836C-81B304ADDA7F} 2013-08-08 19:00 - 2013-08-08 19:00 - 00000011 _____ C:\Users\Sandro\Desktop\Neues Textdokument.txt 2013-08-08 16:35 - 2011-07-03 20:43 - 00000000 ____D C:\Users\Sandro\AppData\Local\TeamSpeak 3 Client 2013-08-08 02:26 - 2013-08-08 02:26 - 00003088 _____ C:\Windows\System32\Tasks\{896182C0-FBCB-4B11-8249-C511298E4013} 2013-08-07 02:30 - 2013-08-07 02:30 - 00003088 _____ C:\Windows\System32\Tasks\{7469A554-0505-4536-98F9-F3E80ECCCBEC} 2013-08-06 21:47 - 2013-08-06 21:47 - 00675988 _____ C:\Users\Sandro\Desktop\Minecraft (2).exe 2013-08-06 01:59 - 2013-08-06 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{945A3915-5477-42D9-867D-11EC9100BFFD} 2013-08-05 21:16 - 2011-07-13 00:02 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-08-05 21:12 - 2013-08-05 21:12 - 00003632 _____ C:\Users\Sandro\Downloads\142e5e19d17b19f2c5398ec6234eaec0.dlc 2013-08-05 02:10 - 2013-08-05 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{DB410448-2A0E-4A1C-8396-235662B567C2} 2013-08-04 19:34 - 2013-08-04 19:33 - 00000000 ____D C:\Users\Katrin\Desktop\Bilder Urlaub 2013-08-04 02:40 - 2013-08-04 02:40 - 00003088 _____ C:\Windows\System32\Tasks\{3CCBF5D6-F969-444A-8F77-5E93635378D4} 2013-08-03 02:34 - 2013-08-03 02:34 - 00003088 _____ C:\Windows\System32\Tasks\{F9A26D5E-F671-4537-B0BB-058FAD3E2844} Files to move or delete: ==================== C:\Users\Sandro\AppData\Local\Temp\Quarantine.exe C:\Users\Sandro\AppData\Local\Temp\sqlite-3.6.20-sqlitejdbc.dll C:\Users\Sandro\AppData\Local\Temp\jrt\erunt\ERUNT.EXE C:\Users\Sandro\AppData\Local\Temp\be29e7f1-71ae-4703-50cb-1d52be512f51\twapi-be29e7f1-71ae-4703-50cb-1d52be512f51.dll C:\Users\Sandro\AppData\Local\Temp\bd7c47bb-f5c0-417c-a180-ec348d87718a\CliSecureRT.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-22 12:17 ==================== End Of Log ============================ |
03.09.2013, 08:10 | #8 |
/// the machine /// TB-Ausbilder | PC Langsam, Hängt sich auf ... Immer alle Logs in den Thread posten. ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.09.2013, 00:06 | #9 |
| PC Langsam, Hängt sich auf ...Code:
ATTFilter Results of screen317's Security Check version 0.99.72 Windows 7 Service Pack 1 x64 Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 TuneUp Utilities 2011 TuneUp Utilities Language Pack (de-DE) Java 7 Update 17 Java version out of Date! Adobe Flash Player 11.8.800.94 Adobe Reader 10.1.0 Adobe Reader out of Date! Google Chrome 29.0.1547.57 Google Chrome 29.0.1547.62 Google Chrome CTB.log.. ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=f85f035caa0ea8478d5c091dd4a516fc # engine=15007 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-09-04 10:13:17 # local_time=2013-09-05 12:13:17 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 96 37447 124099417 30214 0 # compatibility_mode=5893 16776573 100 94 35071 129962647 0 0 # scanned=386152 # found=3 # cleaned=0 # scan_time=34089 sh=270C00220B62FBA723BEF2C07B930B79E57CAB5E ft=0 fh=0000000000000000 vn="Win32/Trustezeb.E trojan" ac=I fn="C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip" sh=270C00220B62FBA723BEF2C07B930B79E57CAB5E ft=0 fh=0000000000000000 vn="Win32/Trustezeb.E trojan" ac=I fn="C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip" sh=5EFD3604F925654F3553E97CA647C52E288E7CBD ft=0 fh=0000000000000000 vn="Win32/Trustezeb.E trojan" ac=I fn="D:\SANDRO-PC\Backup Set 2013-09-01 190014\Backup Files 2013-09-01 190014\Backup files 127.zip" Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-09-2013 Ran by Sandro (administrator) on SANDRO-PC on 05-09-2013 01:02:46 Running from C:\Users\Sandro\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Nero AG) C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe () C:\Users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStatsUpdater.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe () C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe () C:\OEM\USBDECTION\USBS3S4Detection.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe (Accer) C:\OEM\USBDECTION\FixIt.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe () C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Akamai Technologies, Inc.) C:\Users\Sandro\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Sandro\AppData\Local\Akamai\netsession_win.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe () C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Companion\companionuser.exe (Google Inc.) C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-02-01] (Egis Technology Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9955872 2010-01-12] (Realtek Semiconductor) HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKCU\...\Run: [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] () HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-10] (Google Inc.) HKCU\...\Run: [MotoCast] - C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk [2059 2012-04-26] () HKCU\...\Run: [KiesHelper] - C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe [954256 2012-03-31] (Samsung) HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-03-31] () HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1811880 2013-08-28] (Valve Corporation) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Sandro\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Policies\Explorer: [NoDrives] 0 HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-02-01] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201512 2009-12-25] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [401192 2009-12-25] (Egis Technology Inc.) HKLM-x32\...\Run: [Hotkey Utility] - C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [611872 2010-08-04] () HKLM-x32\...\Run: [MDS_Menu] - C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [ArcadeMovieService] - C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe [124136 2010-02-05] (CyberLink Corp.) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3521424 2012-03-31] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-03] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-01-30] (DivX, LLC) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) HKLM-x32\...\Run: [Aeria Ignite] - C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment) HKLM-x32\...\Run: [] - [x] HKU\David\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-10] (Google Inc.) HKU\David\...\Run: [Google Update] - C:\Users\David\AppData\Local\Google\Update\GoogleUpdate.exe [135664 2011-03-31] (Google Inc.) HKU\David\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKU\David\...\Run: [Facebook Update] - C:\Users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-11] (Facebook Inc.) HKU\David\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-03-31] () HKU\David\...\Run: [Akamai NetSession Interface] - C:\Users\David\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\DefaultAppPool\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\Katrin\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKU\Katrin\...\Run: [Google Update] - C:\Users\Katrin\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-10-02] (Google Inc.) HKU\Katrin\...\Run: [Facebook Update] - C:\Users\Katrin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.) HKU\Katrin\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-10] (Google Inc.) HKU\UpdatusUser\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Sandro\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== ProxyServer: 94.126.17.68:3128 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {16E21108-4AD7-49CB-844B-26AF3D1B9664} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: GhosteryStats - {C331A7D9-4187-464C-BE66-FDBC56C07678} - C:\Users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStats.dll (David Cancel) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Freemake.YoutubeButton - {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - No Name - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No File DPF: HKLM-x32 {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Ask.com FF NetworkProxy: "type", 0 FF DefaultSearchEngine: Ask.com FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.132.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.3 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Sandro\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Sandro\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\searchplugins\absearch-search.xml FF Extension: No Name - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\staged FF Extension: DownloadHelper - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9} FF Extension: jid1-kV5U6puWw0Cdvg - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\jid1-kV5U6puWw0Cdvg@jetpack.xpi FF Extension: youtubedownloader - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\youtubedownloader@mybrowserbar.com FF Extension: No Name - C:\Users\Sandro\AppData\Roaming\Mozilla\Firefox\Profiles\hsieo8lk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [downloader@finalvideotools.com] C:\Program Files (x86)\FinalVideoDownloader\Firefox FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ FF HKLM-x32\...\Firefox\Extensions: [siteranker@siteranker.com] C:\Program Files (x86)\SiteRanker\firefox\ FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "https://www.google.de/" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\29.0.1547.62\pdf.dll () CHR Plugin: (Freemake np-plugin for google chrome) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0\npFreemake.dll () CHR Plugin: (Freemake np-plugin for google chrome) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0\npFreemakeYoutubeDownloader.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (PlayStation(R)Network Downloader Check Plug-in) - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll No File CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (ProxTube) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0 CHR Extension: (YouTube) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Freemake Video Downloader) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0 CHR Extension: (Google Search) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Battlelog) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajcdbgpkfpghffojnlbjkadcobpbaid\1.0.4_0 CHR Extension: (Freemake Video Downloader) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0 CHR Extension: (GhosteryStats) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehmdnmbaomgmfmjiajhdfopgnbmgkcog\2.7.192_0 CHR Extension: (AdBlock) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_0 CHR Extension: (Quick Match BF3) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\iacjfjhinfbmljdpedecedhcghgmmdcf\1.1_0 CHR Extension: () - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigfdicgjnpjkhbnngdfgjfffmdaonfg\2_0 CHR Extension: (BattlelogPlus) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\lphojmgkbcmdjpaepolkjeienkacpjpi\1.38_0 CHR Extension: (Battlelog: BF 3) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhdecopbclicngfcdmhinokemjlmcihf\0.1.2_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0 CHR Extension: (Gmail) - C:\Users\Sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [dgldkplledicnbnnliodeffobaiaodaf] - C:\Program Files (x86)\SiteRanker\Chrome\siterank_c.crx CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx CHR HKLM-x32\...\Chrome\Extension: [ehmdnmbaomgmfmjiajhdfopgnbmgkcog] - C:\Users\Sandro\AppData\LocalLow\GhosteryStats\CHROME\GhosteryStats.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx CHR HKLM-x32\...\Chrome\Extension: [ofahndfepeaeelmhdkjiihmofnokhmik] - C:\Users\Sandro\AppData\Local\Temp\tbch.crx CHR StartMenuInternet: Google Chrome - C:\Users\Sandro\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-03] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-03] (Avira Operations GmbH & Co. KG) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101376 2013-02-25] (Freemake) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-02-25] (Ellora Assets Corp.) R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [350720 2012-06-01] (Microsoft Corporation) R2 GhosteryStatsUpdater; C:\Users\Sandro\AppData\LocalLow\GhosteryStats\IE\GhosteryStatsUpdater.exe [18432 2012-02-28] () S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2012-02-01] () S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-02-01] (Egis Technology Inc.) S3 npggsvc; C:\Windows\SysWow64\GameMon.des [4159984 2010-12-08] (INCA Internet Co., Ltd.) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-04-07] () R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [244904 2010-02-03] () S2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2026304 2011-06-06] (TuneUp Software) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH) R2 USBS3S4Detection; C:\OEM\USBDECTION\USBS3S4Detection.exe [76320 2009-12-09] () R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation) S3 BRSptSvc; "C:\ProgramData\BitRaider\BRSptSvc.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-25] (Avira Operations GmbH & Co. KG) S3 DrvSnSht; C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys [132432 2010-06-01] (R-TT Inc.) S3 DrvSnSht; C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys [132432 2010-06-01] (R-TT Inc.) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-06-06] (DT Soft Ltd) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) S3 NPPTNT2; C:\Windows\SysWow64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) S3 R-ImageDisk; C:\Program Files (x86)\R-Drive Image\R-ImageDisk64.sys [187600 2010-10-16] (R-TT Inc.) S3 R-ImageDisk; C:\Program Files (x86)\R-Drive Image\R-ImageDisk64.sys [187600 2010-10-16] (R-TT Inc.) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [513080 2011-06-06] () S3 ss_bserd; C:\Windows\System32\DRIVERS\ss_bserd.sys [128000 2010-12-21] (MCCI Corporation) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [11856 2010-10-07] (TuneUp Software) U3 a9dckv0j; C:\Windows\System32\Drivers\a9dckv0j.sys [0 ] (Microsoft Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 BRDriver64; \??\C:\programdata\bitraider\BRDriver64.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 dump_wmimmc; \??\C:\AeriaGames\WolfTeam-DE\GameGuard\dump_wmimmc.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x] S3 X6va005; \??\C:\Users\Sandro\AppData\Local\Temp\0053C7D.tmp [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-05 01:01 - 2013-09-05 01:02 - 01947160 _____ (Farbar) C:\Users\Sandro\Desktop\FRST64.exe 2013-09-05 00:25 - 2013-09-05 00:26 - 00891115 _____ C:\Users\Sandro\Desktop\SecurityCheck.exe 2013-09-04 16:25 - 2013-09-04 16:25 - 00003088 _____ C:\Windows\System32\Tasks\{3C42D3E8-914C-4801-A7BC-4C76D72D2FAB} 2013-09-04 14:40 - 2013-09-04 14:41 - 02347384 _____ (ESET) C:\Users\Sandro\Desktop\esetsmartinstaller_enu.exe 2013-09-04 07:28 - 2013-09-04 19:49 - 95920262 _____ C:\Windows\SysWOW64\薄⾢ 2013-09-04 02:26 - 2013-09-04 02:26 - 00003088 _____ C:\Windows\System32\Tasks\{53DB35A9-62A7-46E7-8739-06605A0E581F} 2013-09-03 02:21 - 2013-09-03 02:21 - 00003088 _____ C:\Windows\System32\Tasks\{D48A4A15-1357-4295-9367-36C4F88B3261} 2013-09-02 23:18 - 2013-09-02 23:18 - 00035012 _____ C:\Users\Sandro\Desktop\Desktop.7z 2013-09-02 23:06 - 2013-09-02 23:06 - 00118766 _____ C:\Users\Sandro\Desktop\JRT.txt 2013-09-02 23:01 - 2013-09-02 23:01 - 00000000 ____D C:\Windows\ERUNT 2013-09-02 22:59 - 2013-09-02 22:59 - 01028757 _____ (Thisisu) C:\Users\Sandro\Downloads\JRT.exe 2013-09-02 22:51 - 2013-09-02 22:54 - 00061439 _____ C:\Users\Sandro\Desktop\AdwCleaner[S0].txt 2013-09-02 22:42 - 2013-09-02 23:13 - 00000000 ____D C:\AdwCleaner 2013-09-02 22:41 - 2013-09-02 22:41 - 01037134 _____ C:\Users\Sandro\Desktop\adwcleaner.exe 2013-09-02 22:02 - 2013-09-02 22:02 - 00001117 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Malwarebytes 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-02 22:02 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-02 22:00 - 2013-09-02 22:01 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Sandro\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-02 17:02 - 2013-09-02 17:02 - 00044132 _____ C:\ComboFix.txt 2013-09-02 16:52 - 2013-09-02 22:27 - 00036046 _____ C:\Windows\PFRO.log 2013-09-02 16:27 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-02 16:27 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-02 16:27 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-02 16:27 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-02 16:27 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-02 16:27 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-02 16:27 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-02 16:27 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-02 16:26 - 2013-09-02 17:02 - 00000000 ____D C:\Qoobox 2013-09-02 16:24 - 2013-09-02 17:00 - 00000000 ____D C:\Windows\erdnt 2013-09-02 16:21 - 2013-09-02 16:22 - 05119472 ____R (Swearware) C:\Users\Sandro\Desktop\ComboFix.exe 2013-09-02 12:42 - 2013-09-02 12:42 - 00038330 _____ C:\Users\Sandro\Downloads\Addition (1).7z 2013-09-02 12:41 - 2013-09-02 12:41 - 00038330 _____ C:\Users\Sandro\Downloads\Addition.7z 2013-09-02 12:34 - 2013-09-02 12:34 - 00000000 ____D C:\Program Files (x86)\7-Zip 2013-09-02 12:33 - 2013-09-02 12:33 - 01110476 _____ C:\Users\Sandro\Downloads\7z920.exe 2013-09-02 12:25 - 2013-09-02 13:18 - 00108166 _____ C:\Users\Sandro\Downloads\FRST.txt 2013-09-02 12:22 - 2013-09-02 12:25 - 00178260 _____ C:\Users\Sandro\Downloads\Addition.txt 2013-09-02 12:16 - 2013-09-02 12:16 - 00000000 ____D C:\FRST 2013-09-02 02:56 - 2013-09-02 02:56 - 00003088 _____ C:\Windows\System32\Tasks\{F741D114-8004-44D5-96EB-33971BBCD417} 2013-09-01 23:42 - 2013-09-01 23:43 - 60757752 _____ (Gazillion Entertainment ) C:\Users\Sandro\Downloads\marvelheroesinstaller.exe 2013-09-01 23:20 - 2013-09-01 23:21 - 00330518 _____ C:\Users\Sandro\Documents\cc_20130901_232036.reg 2013-09-01 23:11 - 2013-09-01 23:29 - 00000000 ____D C:\Users\Sandro\Downloads\CCEnhancer 2013-09-01 23:10 - 2013-09-01 23:11 - 00176719 _____ C:\Users\Sandro\Downloads\CCEnhancer-3.8-multilanguage.zip 2013-09-01 01:25 - 2013-09-01 01:25 - 00000000 ____D C:\Program Files (x86)\Frogwares 2013-08-31 23:58 - 2013-08-31 23:58 - 00614920 _____ C:\Windows\Minidump\083113-158606-01.dmp 2013-08-31 23:21 - 2013-08-31 23:21 - 00003088 _____ C:\Windows\System32\Tasks\{0D0E4C94-0C9F-48BA-A856-AA025793FD2C} 2013-08-31 11:52 - 2013-08-31 11:52 - 03367611 _____ C:\Users\David\Downloads\easyHalls.exe 2013-08-31 02:32 - 2013-08-31 02:32 - 00003088 _____ C:\Windows\System32\Tasks\{598B6998-980B-477A-B0AE-FA6585404995} 2013-08-30 03:00 - 2013-08-30 03:00 - 00003088 _____ C:\Windows\System32\Tasks\{3E5317FD-A87C-4939-B5D3-EEBC998CEB85} 2013-08-29 02:48 - 2013-08-29 02:48 - 00003088 _____ C:\Windows\System32\Tasks\{FB0B0681-2A62-4A02-89EA-275B2BA27866} 2013-08-28 02:44 - 2013-08-28 02:44 - 00003088 _____ C:\Windows\System32\Tasks\{7DF15D2D-9E9F-46AC-A90F-13A20C4D983D} 2013-08-27 02:23 - 2013-08-27 02:23 - 00003088 _____ C:\Windows\System32\Tasks\{6034F774-F129-4A22-AF1B-08870102A4CF} 2013-08-26 03:39 - 2013-08-26 03:39 - 00003088 _____ C:\Windows\System32\Tasks\{00FE09DB-2041-4FE9-A8C7-6A3183FCB20A} 2013-08-26 03:01 - 2013-08-26 03:01 - 00003088 _____ C:\Windows\System32\Tasks\{C0C1C429-CC94-478F-938D-2A2437CF7F0E} 2013-08-25 12:51 - 2013-08-25 12:51 - 00705136 _____ C:\Users\David\Downloads\UltimateCodec.exe 2013-08-25 02:35 - 2013-08-25 02:35 - 00003088 _____ C:\Windows\System32\Tasks\{079FF58D-0420-425F-A404-A2C8847198A7} 2013-08-24 19:28 - 2013-08-24 19:28 - 00001146 _____ C:\Users\David\Desktop\Continue Zip Opener Installation.lnk 2013-08-24 12:27 - 2013-08-24 12:27 - 13177488 _____ C:\Users\David\Downloads\RopaNawaroMaus.exe 2013-08-24 12:26 - 2013-08-24 12:26 - 03672231 _____ C:\Users\David\Downloads\MischStation.exe 2013-08-24 02:06 - 2013-08-24 02:06 - 00003088 _____ C:\Windows\System32\Tasks\{7C96B1B9-129B-43D3-92BA-15E58DD13CFC} 2013-08-23 02:28 - 2013-08-23 02:28 - 00003088 _____ C:\Windows\System32\Tasks\{80134A1F-9616-4C20-9393-6B0FBA5B4B83} 2013-08-22 18:10 - 2013-08-22 18:10 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip 2013-08-22 18:07 - 2013-08-22 18:07 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip 2013-08-22 04:38 - 2013-08-22 04:38 - 00003088 _____ C:\Windows\System32\Tasks\{BF13EA0A-31B2-410A-9F93-743C5C4082DC} 2013-08-22 03:02 - 2013-08-22 03:02 - 00003088 _____ C:\Windows\System32\Tasks\{2CA1F239-220D-4323-AADE-591302E5262B} 2013-08-21 01:35 - 2013-08-21 01:35 - 00003088 _____ C:\Windows\System32\Tasks\{76511A5A-32F2-4D88-9CC3-2EDD4F267B19} 2013-08-20 23:57 - 2013-08-20 23:57 - 00000000 ____D C:\Users\Sandro\Documents\Electronic Arts 2013-08-20 23:32 - 2013-08-20 23:32 - 00002252 _____ C:\Users\Public\Desktop\Die Sims™ 3 Luxus-Accessoires.lnk 2013-08-20 23:27 - 2013-08-20 23:27 - 00002304 _____ C:\Users\Public\Desktop\Die*Sims™*3.lnk 2013-08-20 16:25 - 2013-08-20 17:38 - 00000000 ____D C:\Users\David\AppData\Local\Mozilla Firefox 2013-08-20 02:10 - 2013-08-20 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{E120DF85-ADC1-4E35-B378-5CB8B450BDBA} 2013-08-19 02:05 - 2013-08-19 02:05 - 00003088 _____ C:\Windows\System32\Tasks\{AB4F94BD-4CCB-4275-810C-0C01764E0439} 2013-08-18 13:15 - 2013-08-18 17:39 - 00000000 ____D C:\Users\Katrin\AppData\Local\Mozilla Firefox 2013-08-18 02:46 - 2013-08-18 02:46 - 00003088 _____ C:\Windows\System32\Tasks\{B00AB3A3-0DA8-4391-B49B-85969C9CA3FD} 2013-08-18 01:21 - 2013-08-18 01:22 - 00004197 _____ C:\Users\Sandro\Desktop\Your Humble Bundle order is ready.html 2013-08-15 13:30 - 2013-08-15 13:31 - 00000000 ____D C:\Windows\rescache 2013-08-15 01:59 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 01:59 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 01:59 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 01:59 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 01:59 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 01:59 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 01:59 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 01:59 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 01:59 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 01:59 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 01:59 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 01:59 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 01:59 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 01:59 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-15 01:53 - 2013-08-15 01:57 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 13:10 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 13:10 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 13:10 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 13:10 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 13:10 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 13:10 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 13:10 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 13:10 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 13:10 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 13:10 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 13:10 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 13:10 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 13:10 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 13:10 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 13:10 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 13:10 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 13:10 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 13:10 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 13:10 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 13:10 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 13:10 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 13:10 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 13:10 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 13:10 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 13:10 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 13:10 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 13:10 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 12:58 - 2013-08-14 12:58 - 00000003 _____ C:\Windows\system32\HRUPPROG.DIE.NOW 2013-08-14 12:57 - 2013-08-31 10:00 - 00000003 _____ C:\Windows\system32\HRUPPROG.TXT 2013-08-14 02:51 - 2013-08-14 02:51 - 00003088 _____ C:\Windows\System32\Tasks\{2210D34F-EBC5-4554-9C19-30F50B90D375} 2013-08-14 01:13 - 2013-08-14 01:13 - 00002032 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-14 01:13 - 2013-08-14 01:13 - 00000000 ____D C:\Program Files (x86)\Aeria Games 2013-08-13 01:59 - 2013-08-13 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{207F6A12-65B2-4433-A50D-5467803ED18D} 2013-08-12 19:07 - 2013-09-01 23:45 - 00002469 _____ C:\Windows\DirectX.log 2013-08-12 17:52 - 2013-08-12 17:52 - 01204902 _____ C:\Users\Sandro\Downloads\Smite Font fix.rar 2013-08-12 17:32 - 2013-08-12 17:32 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish (1).exe 2013-08-12 17:29 - 2013-08-12 17:33 - 00002032 _____ C:\Users\Public\Desktop\Smite.lnk 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\ProgramData\Hi-Rez Studios 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios 2013-08-12 17:25 - 2013-08-12 17:25 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish.exe 2013-08-12 01:42 - 2013-08-12 01:42 - 00003088 _____ C:\Windows\System32\Tasks\{B50AF006-5459-4FB7-B54A-159E237C1B47} 2013-08-11 02:16 - 2013-08-11 02:16 - 00003088 _____ C:\Windows\System32\Tasks\{6523F6E2-6431-4271-A355-983127186566} 2013-08-10 18:44 - 2013-08-10 18:44 - 00003088 _____ C:\Windows\System32\Tasks\{6E810A62-A06C-47FA-A5B4-7EDF8D29D3D4} 2013-08-10 02:10 - 2013-08-10 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{50C71F38-7796-4D0F-8828-09F50A146372} 2013-08-09 07:11 - 2013-08-09 07:11 - 00003088 _____ C:\Windows\System32\Tasks\{C89A309D-5292-4DFD-B2A3-C98965450CA6} 2013-08-09 02:43 - 2013-08-09 02:43 - 00003088 _____ C:\Windows\System32\Tasks\{DC14F991-DAAB-4948-836C-81B304ADDA7F} 2013-08-08 19:00 - 2013-08-08 19:00 - 00000011 _____ C:\Users\Sandro\Desktop\Neues Textdokument.txt 2013-08-08 02:26 - 2013-08-08 02:26 - 00003088 _____ C:\Windows\System32\Tasks\{896182C0-FBCB-4B11-8249-C511298E4013} 2013-08-07 02:30 - 2013-08-07 02:30 - 00003088 _____ C:\Windows\System32\Tasks\{7469A554-0505-4536-98F9-F3E80ECCCBEC} 2013-08-06 21:47 - 2013-08-06 21:47 - 00675988 _____ C:\Users\Sandro\Desktop\Minecraft (2).exe 2013-08-06 01:59 - 2013-08-06 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{945A3915-5477-42D9-867D-11EC9100BFFD} ==================== One Month Modified Files and Folders ======= 2013-09-05 01:03 - 2013-04-24 15:11 - 00000000 ____D C:\Users\DefaultAppPool 2013-09-05 01:02 - 2013-09-05 01:01 - 01947160 _____ (Farbar) C:\Users\Sandro\Desktop\FRST64.exe 2013-09-05 00:58 - 2011-03-31 17:29 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-05 00:43 - 2012-06-05 17:50 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-05 00:37 - 2011-10-02 18:36 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004UA.job 2013-09-05 00:26 - 2013-09-05 00:25 - 00891115 _____ C:\Users\Sandro\Desktop\SecurityCheck.exe 2013-09-05 00:26 - 2011-04-11 15:12 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003UA.job 2013-09-05 00:25 - 2011-03-31 16:44 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1001UA.job 2013-09-04 23:45 - 2007-10-10 18:55 - 01270133 _____ C:\Windows\WindowsUpdate.log 2013-09-04 23:21 - 2011-07-03 20:44 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\TS3Client 2013-09-04 23:19 - 2013-02-27 04:11 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\.minecraft 2013-09-04 22:56 - 2011-12-11 17:34 - 00001138 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003UA.job 2013-09-04 22:56 - 2011-12-11 17:34 - 00001116 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003Core.job 2013-09-04 22:25 - 2012-01-29 14:28 - 00001142 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004UA.job 2013-09-04 20:58 - 2011-03-31 17:29 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-04 20:24 - 2011-03-31 16:44 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1001Core.job 2013-09-04 19:49 - 2013-09-04 07:28 - 95920262 _____ C:\Windows\SysWOW64\薄⾢ 2013-09-04 16:25 - 2013-09-04 16:25 - 00003088 _____ C:\Windows\System32\Tasks\{3C42D3E8-914C-4801-A7BC-4C76D72D2FAB} 2013-09-04 14:41 - 2013-09-04 14:40 - 02347384 _____ (ESET) C:\Users\Sandro\Desktop\esetsmartinstaller_enu.exe 2013-09-04 14:38 - 2012-04-26 21:20 - 00000000 ____D C:\Users\Sandro\.gstreamer-0.10 2013-09-04 14:38 - 2012-04-26 21:18 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\MotoCast 2013-09-04 14:37 - 2012-10-16 02:15 - 00000000 ____D C:\Program Files (x86)\Steam 2013-09-04 14:37 - 2011-10-02 18:36 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004Core.job 2013-09-04 14:36 - 2012-07-12 15:29 - 00000000 ___RD C:\Users\Sandro\Dropbox 2013-09-04 14:36 - 2012-07-12 15:25 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Dropbox 2013-09-04 14:35 - 2013-02-24 20:02 - 00000000 ____D C:\Users\Sandro\AppData\Local\LogMeIn Hamachi 2013-09-04 07:37 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-04 07:37 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-04 07:26 - 2013-02-25 08:40 - 00000000 ____D C:\Users\Katrin\AppData\Local\LogMeIn Hamachi 2013-09-04 07:25 - 2013-07-13 19:02 - 00007137 _____ C:\Windows\setupact.log 2013-09-04 07:25 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-04 07:25 - 2007-10-10 18:58 - 00000000 ____D C:\ProgramData\NVIDIA 2013-09-04 02:26 - 2013-09-04 02:26 - 00003088 _____ C:\Windows\System32\Tasks\{53DB35A9-62A7-46E7-8739-06605A0E581F} 2013-09-04 02:26 - 2011-04-11 15:12 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1003Core.job 2013-09-03 13:29 - 2013-05-07 14:23 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-09-03 13:29 - 2013-03-25 15:22 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-09-03 13:29 - 2013-03-25 15:22 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-03 07:25 - 2012-01-29 14:28 - 00001120 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2117280256-1913491061-2286216675-1004Core.job 2013-09-03 02:21 - 2013-09-03 02:21 - 00003088 _____ C:\Windows\System32\Tasks\{D48A4A15-1357-4295-9367-36C4F88B3261} 2013-09-02 23:18 - 2013-09-02 23:18 - 00035012 _____ C:\Users\Sandro\Desktop\Desktop.7z 2013-09-02 23:13 - 2013-09-02 22:42 - 00000000 ____D C:\AdwCleaner 2013-09-02 23:06 - 2013-09-02 23:06 - 00118766 _____ C:\Users\Sandro\Desktop\JRT.txt 2013-09-02 23:01 - 2013-09-02 23:01 - 00000000 ____D C:\Windows\ERUNT 2013-09-02 22:59 - 2013-09-02 22:59 - 01028757 _____ (Thisisu) C:\Users\Sandro\Downloads\JRT.exe 2013-09-02 22:54 - 2013-09-02 22:51 - 00061439 _____ C:\Users\Sandro\Desktop\AdwCleaner[S0].txt 2013-09-02 22:53 - 2012-06-30 11:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-02 22:41 - 2013-09-02 22:41 - 01037134 _____ C:\Users\Sandro\Desktop\adwcleaner.exe 2013-09-02 22:39 - 2011-03-31 16:44 - 00000000 ____D C:\Users\Sandro\AppData\Local\Apps\2.0 2013-09-02 22:27 - 2013-09-02 16:52 - 00036046 _____ C:\Windows\PFRO.log 2013-09-02 22:24 - 2011-03-31 17:29 - 00000000 ____D C:\Users\David 2013-09-02 22:24 - 2011-03-31 16:34 - 00000000 ____D C:\Users\Sandro 2013-09-02 22:02 - 2013-09-02 22:02 - 00001117 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Malwarebytes 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-02 22:02 - 2013-09-02 22:02 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-02 22:01 - 2013-09-02 22:00 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Sandro\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-02 17:02 - 2013-09-02 17:02 - 00044132 _____ C:\ComboFix.txt 2013-09-02 17:02 - 2013-09-02 16:26 - 00000000 ____D C:\Qoobox 2013-09-02 17:02 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-09-02 17:00 - 2013-09-02 16:24 - 00000000 ____D C:\Windows\erdnt 2013-09-02 16:54 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-09-02 16:22 - 2013-09-02 16:21 - 05119472 ____R (Swearware) C:\Users\Sandro\Desktop\ComboFix.exe 2013-09-02 13:18 - 2013-09-02 12:25 - 00108166 _____ C:\Users\Sandro\Downloads\FRST.txt 2013-09-02 12:42 - 2013-09-02 12:42 - 00038330 _____ C:\Users\Sandro\Downloads\Addition (1).7z 2013-09-02 12:41 - 2013-09-02 12:41 - 00038330 _____ C:\Users\Sandro\Downloads\Addition.7z 2013-09-02 12:34 - 2013-09-02 12:34 - 00000000 ____D C:\Program Files (x86)\7-Zip 2013-09-02 12:33 - 2013-09-02 12:33 - 01110476 _____ C:\Users\Sandro\Downloads\7z920.exe 2013-09-02 12:25 - 2013-09-02 12:22 - 00178260 _____ C:\Users\Sandro\Downloads\Addition.txt 2013-09-02 12:16 - 2013-09-02 12:16 - 00000000 ____D C:\FRST 2013-09-02 02:56 - 2013-09-02 02:56 - 00003088 _____ C:\Windows\System32\Tasks\{F741D114-8004-44D5-96EB-33971BBCD417} 2013-09-01 23:45 - 2013-08-12 19:07 - 00002469 _____ C:\Windows\DirectX.log 2013-09-01 23:43 - 2013-09-01 23:42 - 60757752 _____ (Gazillion Entertainment ) C:\Users\Sandro\Downloads\marvelheroesinstaller.exe 2013-09-01 23:29 - 2013-09-01 23:11 - 00000000 ____D C:\Users\Sandro\Downloads\CCEnhancer 2013-09-01 23:21 - 2013-09-01 23:20 - 00330518 _____ C:\Users\Sandro\Documents\cc_20130901_232036.reg 2013-09-01 23:12 - 2011-07-31 23:12 - 00000000 ____D C:\Program Files\CCleaner 2013-09-01 23:11 - 2013-09-01 23:10 - 00176719 _____ C:\Users\Sandro\Downloads\CCEnhancer-3.8-multilanguage.zip 2013-09-01 22:52 - 2011-04-01 07:10 - 00000000 ____D C:\Users\Katrin 2013-09-01 22:51 - 2013-07-03 07:24 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-09-01 22:51 - 2013-06-01 02:10 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b ROC Installer deDE 2013-09-01 22:51 - 2013-06-01 01:56 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b TFT Installer deDE 2013-09-01 22:51 - 2013-05-31 04:13 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b TFT Installer enGB 2013-09-01 22:51 - 2013-05-31 03:57 - 00000000 ____D C:\Users\Sandro\Warcraft III 1.21b ROC Installer enGB 2013-09-01 22:51 - 2013-05-06 01:12 - 00000000 ____D C:\Users\Sandro\AppData\Local\Akamai 2013-09-01 22:51 - 2013-04-07 16:55 - 00000000 ____D C:\Ubisoft 2013-09-01 22:51 - 2013-04-07 16:54 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2013-09-01 22:51 - 2013-03-23 22:41 - 00000000 ____D C:\Users\Public\Sony Online Entertainment 2013-09-01 22:51 - 2012-02-11 18:23 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-09-01 22:51 - 2012-02-11 18:23 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-09-01 22:51 - 2011-06-09 01:01 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-09-01 22:51 - 2011-04-04 19:03 - 00000000 ____D C:\Users\Sandro\Downloads\JD 2013-09-01 22:51 - 2011-04-01 19:53 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-09-01 22:51 - 2010-05-10 13:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-09-01 22:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-09-01 13:20 - 2011-10-02 18:36 - 00002378 _____ C:\Users\Katrin\Desktop\Google Chrome.lnk 2013-09-01 13:01 - 2009-07-14 07:13 - 00419726 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-01 13:01 - 2007-10-11 04:46 - 00178236 _____ C:\Windows\system32\perfh007.dat 2013-09-01 13:01 - 2007-10-11 04:46 - 00060400 _____ C:\Windows\system32\perfc007.dat 2013-09-01 12:55 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-01 01:51 - 2011-08-23 01:29 - 02507776 ___SH C:\Users\Sandro\Downloads\Thumbs.db 2013-09-01 01:25 - 2013-09-01 01:25 - 00000000 ____D C:\Program Files (x86)\Frogwares 2013-09-01 01:14 - 2011-06-06 03:14 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\DAEMON Tools Lite 2013-09-01 01:14 - 2011-04-21 20:14 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\FileZilla 2013-09-01 01:14 - 2011-03-31 18:17 - 00000000 ____D C:\Users\Sandro\Tracing 2013-08-31 23:58 - 2013-08-31 23:58 - 00614920 _____ C:\Windows\Minidump\083113-158606-01.dmp 2013-08-31 23:58 - 2011-07-27 16:00 - 00000000 ____D C:\Windows\Minidump 2013-08-31 23:21 - 2013-08-31 23:21 - 00003088 _____ C:\Windows\System32\Tasks\{0D0E4C94-0C9F-48BA-A856-AA025793FD2C} 2013-08-31 11:52 - 2013-08-31 11:52 - 03367611 _____ C:\Users\David\Downloads\easyHalls.exe 2013-08-31 10:00 - 2013-08-14 12:57 - 00000003 _____ C:\Windows\system32\HRUPPROG.TXT 2013-08-31 09:05 - 2013-02-25 14:59 - 00000000 ____D C:\Users\David\AppData\Local\LogMeIn Hamachi 2013-08-31 02:32 - 2013-08-31 02:32 - 00003088 _____ C:\Windows\System32\Tasks\{598B6998-980B-477A-B0AE-FA6585404995} 2013-08-30 03:00 - 2013-08-30 03:00 - 00003088 _____ C:\Windows\System32\Tasks\{3E5317FD-A87C-4939-B5D3-EEBC998CEB85} 2013-08-30 01:34 - 2011-03-31 16:44 - 00002378 _____ C:\Users\Sandro\Desktop\Google Chrome.lnk 2013-08-29 17:02 - 2011-04-02 16:37 - 00000000 ____D C:\Users\David\AppData\Local\Google 2013-08-29 16:06 - 2011-04-11 19:48 - 00002373 _____ C:\Users\David\Desktop\Google Chrome.lnk 2013-08-29 02:48 - 2013-08-29 02:48 - 00003088 _____ C:\Windows\System32\Tasks\{FB0B0681-2A62-4A02-89EA-275B2BA27866} 2013-08-28 02:44 - 2013-08-28 02:44 - 00003088 _____ C:\Windows\System32\Tasks\{7DF15D2D-9E9F-46AC-A90F-13A20C4D983D} 2013-08-27 21:16 - 2011-07-25 20:55 - 00000000 ____D C:\Users\David\Desktop\Emergency 4 Deluxe 2013-08-27 19:27 - 2013-07-23 11:52 - 00000000 ____D C:\Program Files (x86)\ERS Berlin 2013-08-27 10:40 - 2011-03-31 17:36 - 00000000 ____D C:\Users\David\Documents\My Games 2013-08-27 02:23 - 2013-08-27 02:23 - 00003088 _____ C:\Windows\System32\Tasks\{6034F774-F129-4A22-AF1B-08870102A4CF} 2013-08-26 03:39 - 2013-08-26 03:39 - 00003088 _____ C:\Windows\System32\Tasks\{00FE09DB-2041-4FE9-A8C7-6A3183FCB20A} 2013-08-26 03:01 - 2013-08-26 03:01 - 00003088 _____ C:\Windows\System32\Tasks\{C0C1C429-CC94-478F-938D-2A2437CF7F0E} 2013-08-25 12:51 - 2013-08-25 12:51 - 00705136 _____ C:\Users\David\Downloads\UltimateCodec.exe 2013-08-25 02:35 - 2013-08-25 02:35 - 00003088 _____ C:\Windows\System32\Tasks\{079FF58D-0420-425F-A404-A2C8847198A7} 2013-08-24 21:56 - 2011-04-03 16:46 - 00064000 _____ C:\Users\David\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-24 19:28 - 2013-08-24 19:28 - 00001146 _____ C:\Users\David\Desktop\Continue Zip Opener Installation.lnk 2013-08-24 12:27 - 2013-08-24 12:27 - 13177488 _____ C:\Users\David\Downloads\RopaNawaroMaus.exe 2013-08-24 12:26 - 2013-08-24 12:26 - 03672231 _____ C:\Users\David\Downloads\MischStation.exe 2013-08-24 02:06 - 2013-08-24 02:06 - 00003088 _____ C:\Windows\System32\Tasks\{7C96B1B9-129B-43D3-92BA-15E58DD13CFC} 2013-08-23 02:28 - 2013-08-23 02:28 - 00003088 _____ C:\Windows\System32\Tasks\{80134A1F-9616-4C20-9393-6B0FBA5B4B83} 2013-08-22 18:10 - 2013-08-22 18:10 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip 2013-08-22 18:07 - 2013-08-22 18:07 - 00120989 _____ C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip 2013-08-22 13:05 - 2012-03-27 15:08 - 00000000 ____D C:\Program Files (x86)\Origin 2013-08-22 04:38 - 2013-08-22 04:38 - 00003088 _____ C:\Windows\System32\Tasks\{BF13EA0A-31B2-410A-9F93-743C5C4082DC} 2013-08-22 04:35 - 2011-04-25 22:07 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\SoftGrid Client 2013-08-22 03:06 - 2011-03-31 16:43 - 00000000 ____D C:\Users\Sandro\AppData\Local\Google 2013-08-22 03:02 - 2013-08-22 03:02 - 00003088 _____ C:\Windows\System32\Tasks\{2CA1F239-220D-4323-AADE-591302E5262B} 2013-08-21 14:43 - 2012-06-05 17:50 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-21 14:43 - 2012-06-05 17:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-21 14:43 - 2012-06-05 17:50 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-21 13:19 - 2012-10-21 15:22 - 00000000 ____D C:\Users\David\AppData\Local\Origin 2013-08-21 13:19 - 2012-03-28 02:55 - 00000000 ____D C:\Users\David\AppData\Roaming\Origin 2013-08-21 01:35 - 2013-08-21 01:35 - 00003088 _____ C:\Windows\System32\Tasks\{76511A5A-32F2-4D88-9CC3-2EDD4F267B19} 2013-08-20 23:57 - 2013-08-20 23:57 - 00000000 ____D C:\Users\Sandro\Documents\Electronic Arts 2013-08-20 23:32 - 2013-08-20 23:32 - 00002252 _____ C:\Users\Public\Desktop\Die Sims™ 3 Luxus-Accessoires.lnk 2013-08-20 23:29 - 2012-03-27 15:10 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-08-20 23:27 - 2013-08-20 23:27 - 00002304 _____ C:\Users\Public\Desktop\Die*Sims™*3.lnk 2013-08-20 17:38 - 2013-08-20 16:25 - 00000000 ____D C:\Users\David\AppData\Local\Mozilla Firefox 2013-08-20 02:10 - 2013-08-20 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{E120DF85-ADC1-4E35-B378-5CB8B450BDBA} 2013-08-19 02:05 - 2013-08-19 02:05 - 00003088 _____ C:\Windows\System32\Tasks\{AB4F94BD-4CCB-4275-810C-0C01764E0439} 2013-08-18 17:39 - 2013-08-18 13:15 - 00000000 ____D C:\Users\Katrin\AppData\Local\Mozilla Firefox 2013-08-18 02:46 - 2013-08-18 02:46 - 00003088 _____ C:\Windows\System32\Tasks\{B00AB3A3-0DA8-4391-B49B-85969C9CA3FD} 2013-08-18 01:22 - 2013-08-18 01:21 - 00004197 _____ C:\Users\Sandro\Desktop\Your Humble Bundle order is ready.html 2013-08-17 23:31 - 2012-03-27 15:10 - 00000000 ____D C:\Users\Sandro\AppData\Local\Origin 2013-08-17 23:31 - 2012-03-27 15:10 - 00000000 ____D C:\ProgramData\Origin 2013-08-17 23:31 - 2012-03-27 15:09 - 00000000 ____D C:\Users\Sandro\AppData\Roaming\Origin 2013-08-15 17:16 - 2011-04-26 23:19 - 00000000 ____D C:\Users\Sandro\Desktop\Zeuch Halt 2013-08-15 13:31 - 2013-08-15 13:30 - 00000000 ____D C:\Windows\rescache 2013-08-15 01:57 - 2013-08-15 01:53 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 01:52 - 2011-04-30 22:28 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-14 12:58 - 2013-08-14 12:58 - 00000003 _____ C:\Windows\system32\HRUPPROG.DIE.NOW 2013-08-14 02:51 - 2013-08-14 02:51 - 00003088 _____ C:\Windows\System32\Tasks\{2210D34F-EBC5-4554-9C19-30F50B90D375} 2013-08-14 01:13 - 2013-08-14 01:13 - 00002032 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk 2013-08-14 01:13 - 2013-08-14 01:13 - 00000000 ____D C:\Program Files (x86)\Aeria Games 2013-08-13 12:26 - 2011-04-25 14:31 - 00064000 _____ C:\Users\Katrin\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-13 12:24 - 2009-07-14 06:45 - 00295696 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-13 01:59 - 2013-08-13 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{207F6A12-65B2-4433-A50D-5467803ED18D} 2013-08-12 19:54 - 2011-03-31 22:06 - 00000000 ____D C:\Users\Sandro\Documents\My Games 2013-08-12 17:53 - 2011-03-31 16:35 - 00064000 _____ C:\Users\Sandro\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-12 17:52 - 2013-08-12 17:52 - 01204902 _____ C:\Users\Sandro\Downloads\Smite Font fix.rar 2013-08-12 17:33 - 2013-08-12 17:29 - 00002032 _____ C:\Users\Public\Desktop\Smite.lnk 2013-08-12 17:32 - 2013-08-12 17:32 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish (1).exe 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\ProgramData\Hi-Rez Studios 2013-08-12 17:29 - 2013-08-12 17:29 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios 2013-08-12 17:25 - 2013-08-12 17:25 - 37160376 _____ (Hi-Rez Studios) C:\Users\Sandro\Downloads\InstallHiRezGamesEnglish.exe 2013-08-12 01:42 - 2013-08-12 01:42 - 00003088 _____ C:\Windows\System32\Tasks\{B50AF006-5459-4FB7-B54A-159E237C1B47} 2013-08-11 02:16 - 2013-08-11 02:16 - 00003088 _____ C:\Windows\System32\Tasks\{6523F6E2-6431-4271-A355-983127186566} 2013-08-10 18:44 - 2013-08-10 18:44 - 00003088 _____ C:\Windows\System32\Tasks\{6E810A62-A06C-47FA-A5B4-7EDF8D29D3D4} 2013-08-10 02:10 - 2013-08-10 02:10 - 00003088 _____ C:\Windows\System32\Tasks\{50C71F38-7796-4D0F-8828-09F50A146372} 2013-08-09 07:11 - 2013-08-09 07:11 - 00003088 _____ C:\Windows\System32\Tasks\{C89A309D-5292-4DFD-B2A3-C98965450CA6} 2013-08-09 02:43 - 2013-08-09 02:43 - 00003088 _____ C:\Windows\System32\Tasks\{DC14F991-DAAB-4948-836C-81B304ADDA7F} 2013-08-08 19:00 - 2013-08-08 19:00 - 00000011 _____ C:\Users\Sandro\Desktop\Neues Textdokument.txt 2013-08-08 16:35 - 2011-07-03 20:43 - 00000000 ____D C:\Users\Sandro\AppData\Local\TeamSpeak 3 Client 2013-08-08 02:26 - 2013-08-08 02:26 - 00003088 _____ C:\Windows\System32\Tasks\{896182C0-FBCB-4B11-8249-C511298E4013} 2013-08-07 02:30 - 2013-08-07 02:30 - 00003088 _____ C:\Windows\System32\Tasks\{7469A554-0505-4536-98F9-F3E80ECCCBEC} 2013-08-06 21:47 - 2013-08-06 21:47 - 00675988 _____ C:\Users\Sandro\Desktop\Minecraft (2).exe 2013-08-06 01:59 - 2013-08-06 01:59 - 00003088 _____ C:\Windows\System32\Tasks\{945A3915-5477-42D9-867D-11EC9100BFFD} Files to move or delete: ==================== C:\Users\Sandro\AppData\Local\Temp\Quarantine.exe C:\Users\Sandro\AppData\Local\Temp\sqlite-3.6.20-sqlitejdbc.dll C:\Users\Sandro\AppData\Local\Temp\RarSFX0\SecurityCheck\Objlist.exe C:\Users\Sandro\AppData\Local\Temp\RarSFX0\SecurityCheck\runprocesses.exe C:\Users\Sandro\AppData\Local\Temp\RarSFX0\SecurityCheck\uninstalllist.exe C:\Users\Sandro\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\cmdinfo.exe C:\Users\Sandro\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\nircmdc.exe C:\Users\Sandro\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\sed.exe C:\Users\Sandro\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\swreg.exe C:\Users\Sandro\AppData\Local\Temp\jrt\erunt\ERUNT.EXE C:\Users\Sandro\AppData\Local\Temp\be29e7f1-71ae-4703-50cb-1d52be512f51\twapi-be29e7f1-71ae-4703-50cb-1d52be512f51.dll C:\Users\Sandro\AppData\Local\Temp\bd7c47bb-f5c0-417c-a180-ec348d87718a\CliSecureRT.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-03 12:14 ==================== End Of Log ============================ |
05.09.2013, 10:34 | #10 |
/// the machine /// TB-Ausbilder | PC Langsam, Hängt sich auf ... Java und Adobe updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip D:\SANDRO-PC\Backup Set 2013-09-01 190014\Backup Files 2013-09-01 190014\Backup files 127.zip HKCU\...\Run: [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] () ProxyServer: 94.126.17.68:3128 S3 X6va005; \??\C:\Users\Sandro\AppData\Local\Temp\0053C7D.tmp [x] Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.09.2013, 15:38 | #11 |
| PC Langsam, Hängt sich auf ...Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-09-2013 Ran by Sandro at 2013-09-05 16:37:24 Run:1 Running from C:\Users\Sandro\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip D:\SANDRO-PC\Backup Set 2013-09-01 190014\Backup Files 2013-09-01 190014\Backup files 127.zip HKCU\...\Run: [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] () ProxyServer: 94.126.17.68:3128 S3 X6va005; \??\C:\Users\Sandro\AppData\Local\Temp\0053C7D.tmp [x] ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip D:\SANDRO-PC\Backup Set 2013-09-01 190014\Backup Files 2013-09-01 190014\Backup files 127.zip Xvid => Value not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully. "C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip D:\SANDRO-PC\Backup Set 2013-09-01 190014\Backup Files 2013-09-01 190014\Backup files 127.zip HKCU\...\Run: [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] () ProxyServer: 94.126.17.68:3128 S3 X6va005; \??\C:\Users\Sandro\AppData\Local\Temp\0053C7D.tmp [x]" => File/Directory not found. C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013 (1).zip C:\Users\Sandro\Downloads\Forderung der stornierten Zahlung Ihrer Bestellung 22.08.2013.zip D:\SANDRO-PC\Backup Set 2013-09-01 190014\Backup Files 2013-09-01 190014\Backup files 127.zip HKCU\...\Run: [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] () ProxyServer: 94.126.17.68:3128 X6va005 => Service not found. ==== End of Fixlog ==== |
05.09.2013, 20:03 | #12 |
/// the machine /// TB-Ausbilder | PC Langsam, Hängt sich auf ... Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.09.2013, 22:43 | #13 |
| PC Langsam, Hängt sich auf ... Vielen dank für deine Hilfe hat aber leider rein Gar nichts gebracht ist immernoch sehr langsam und spielen ist immernoch unmöglich und er hört weiterhin nicht auf auf hochturen zu laden ohne das wirklich was dabei rauskommt |
07.09.2013, 07:54 | #14 | |
/// the machine /// TB-Ausbilder | PC Langsam, Hängt sich auf ...Zitat:
Und das ist nur Online so?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.09.2013, 22:06 | #15 |
| PC Langsam, Hängt sich auf ... naja gar nichts ist doch etwas übertrieben ^^ ja online da laagt fängt sehr spät zu laden an und sowas gar nicht mehr spielbar oder halt internet seiten brauchen lange zum öffnen |
Themen zu PC Langsam, Hängt sich auf ... |
aufrufe, aufrufen, chrome, dauert, extrem, extrem langsam, gen, hochfahren, hoffe, hänge, hängen, hängt, hängt sich auf, lange, langsam, pc extrem langsam, pc langsam, problem, sonstiges, spiele, spielen, unmöglich, virus, win, woche |