|
Plagegeister aller Art und deren Bekämpfung: dllhost belegt kompletten Arbeitsspeicher, Virus?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.09.2013, 11:53 | #1 |
| dllhost belegt kompletten Arbeitsspeicher, Virus? Hallo, alle zusammen. Wie im Titel bereits beschrieben, entscheidet sich meine dllhost-Datei dazu, immer mal wieder den ganzen Arbeitsspeicher zu belegen. Antiviren-programme sind schon durchgeloffen und haben bisher nix gefunden. Habe auch nicht wirklich eine Ahnung, warum die das macht. Ich hätte noch ein Hijackthis-Log, vielleicht kann ja jemand damit mir helfen: Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 12:41:21, on 09.09.2013 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16660) FIREFOX: 23.0.1 (de) Boot mode: Normal Running processes: C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Steam\Steam.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Program Files (x86)\Steam\GameOverlayUI.exe C:\Users\GriMoiReX\Downloads\HijackThis.exe C:\Program Files (x86)\Windows Media Player\wmplayer.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www1.delta-search.com/?affID=121845&tt=gc_&babsrc=HP_ss&mntrId=68A01C6F653805D7/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user') O4 - Global Startup: theHunter.url O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted IP range: hxxp://127.0.0.1 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: Avira Planer (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira Echtzeit-Scanner (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe O23 - Service: Avira Browser-Schutz (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - I:\SteamLibrary\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Google Update-Dienst (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Marvell RAID Event Agent (Marvell RAID) - Unknown owner - C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: MRU Web Service (MRUWebService) - Apache Software Foundation - C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 9719 bytes Andere Logfiles können auf Nachfrage nachgereicht werden. Bin für jede Hilfe dankbar. |
09.09.2013, 14:29 | #2 |
/// the machine /// TB-Ausbilder | dllhost belegt kompletten Arbeitsspeicher, Virus? hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
09.09.2013, 14:56 | #3 |
| dllhost belegt kompletten Arbeitsspeicher, Virus? Hier das FRST-Log -->
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-09-2013 Ran by GriMoiReX (administrator) on GRIMOIREX-PC on 09-09-2013 12:57:01 Running from C:\Users\GriMoiReX\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Apache Software Foundation) C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe (Apache Software Foundation) C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\SysWOW64\PnkBstrA.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe (Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\system32\taskmgr.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (TeamViewer GmbH) c:\program files (x86)\teamviewer\version8\TeamViewer_Desktop.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10134560 2010-03-23] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM\...\Policies\Explorer: [NoActiveDesktop] 1 HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1 HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-03] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-07-23] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\theHunter.url () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www1.delta-search.com/?affID=121845&tt=gc_&babsrc=HP_ss&mntrId=68A01C6F653805D7/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp URLSearchHook: (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&affID=121845&tt=gc_&babsrc=SP_ss&mntrId=68A01C6F653805D7 SearchScopes: HKCU - {9CDEE213-6D00-48E6-A175-F0A6F7E410A0} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10267&src=crm&q={searchTerms}&locale=de_NL&apn_ptnrs=^AGY&apn_dtid=^YYYYYY^YY^NL&apn_uid=e15404d3-8be8-489f-a23f-f2d089dc2ef9&apn_sauid=DE2D941D-D5D3-4598-A681-156F026B1B86 BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\GriMoiReX\AppData\Roaming\Mozilla\Firefox\Profiles\gc9av357.default FF user.js: detected! => C:\Users\GriMoiReX\AppData\Roaming\Mozilla\Firefox\Profiles\gc9av357.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @idsoftware.com/QuakeLive - C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Users\GriMoiReX\AppData\Roaming\Mozilla\Firefox\Profiles\gc9av357.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\GriMoiReX\AppData\Roaming\Mozilla\Firefox\Profiles\gc9av357.default\searchplugins\delta.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\GriMoiReX\AppData\Roaming\Mozilla\Firefox\Profiles\gc9av357.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (QUAKE LIVE) - C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Delta Toolbar) - C:\Users\GRIMOI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.4_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\GRIMOI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\GriMoiReX\AppData\Roaming\BabSolution\CR\delta1.crx ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-03] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-03] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-03] (Avira Operations GmbH & Co. KG) S3 DAUpdaterSvc; I:\SteamLibrary\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [25832 2012-12-24] (BioWare) R2 Marvell RAID; C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe [235560 2010-03-08] () R2 MRUWebService; C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe [24635 2008-06-12] (Apache Software Foundation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-09-07] () R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-05-29] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-06] (Avira Operations GmbH & Co. KG) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-03-29] (TuneUp Software) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 GPU-Z; \??\C:\Users\GRIMOI~1\AppData\Local\Temp\GPU-Z.sys [x] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-09 12:56 - 2013-09-09 12:56 - 00000000 ____D C:\FRST 2013-09-09 12:55 - 2013-09-09 12:55 - 00000480 _____ C:\Users\GriMoiReX\Desktop\defogger_disable.log 2013-09-09 12:55 - 2013-09-09 12:55 - 00000000 _____ C:\Users\GriMoiReX\defogger_reenable 2013-09-09 12:54 - 2013-09-09 12:54 - 00050477 _____ C:\Users\GriMoiReX\Desktop\Defogger.exe 2013-09-09 12:43 - 2013-09-09 12:43 - 00009720 _____ C:\Users\GriMoiReX\Desktop\hijackthis.log 2013-09-09 12:42 - 2013-09-09 12:42 - 00009079 _____ C:\Users\GriMoiReX\Desktop\blablabla.txt 2013-09-09 11:20 - 2013-09-09 11:20 - 96601965 _____ C:\Windows\SysWOW64\坉룽蹬ˆ 2013-09-07 20:08 - 2013-09-08 22:29 - 00000000 ____D C:\Users\GriMoiReX\Documents\CAPCOM 2013-09-07 15:50 - 2013-09-07 15:50 - 00001944 _____ C:\Users\Public\Desktop\Metin2.lnk 2013-09-07 15:40 - 2013-09-07 15:41 - 00000000 ____D C:\Users\GriMoiReX\Downloads\Gameforge Live 2013-09-07 15:40 - 2013-09-07 15:40 - 00001067 _____ C:\Users\Public\Desktop\Gameforge Live.lnk 2013-09-07 15:40 - 2013-09-07 15:40 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-09-07 15:39 - 2013-09-07 15:39 - 19328912 _____ (Gameforge ) C:\Users\GriMoiReX\Downloads\Metin2_GameforgeLiveSetup.exe 2013-09-06 16:11 - 2013-09-06 16:11 - 00001825 _____ C:\Users\GriMoiReX\Desktop\Viscera Cleanup Detail - Alpha.lnk 2013-09-06 16:10 - 2013-09-06 16:11 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VisceraCleanupDetail-Alpha 2013-09-06 16:10 - 2013-09-06 16:10 - 00000000 ____D C:\Games 2013-09-06 15:48 - 2013-09-06 16:04 - 402126484 _____ C:\Users\GriMoiReX\Downloads\viscera_alpha_v0.14.exe 2013-09-04 11:22 - 2013-09-04 11:22 - 95812354 _____ C:\Windows\SysWOW64\얛ᆕ蹬¡ 2013-09-03 22:47 - 2013-09-04 03:50 - 00000039 _____ C:\Users\GriMoiReX\AppData\Roaming\TheHunterSettings_live.cfg 2013-09-03 11:37 - 2013-09-09 11:35 - 00000000 ____D C:\Program Files (x86)\theHunter 2013-09-03 11:37 - 2013-09-03 11:37 - 00000132 _____ C:\Users\GriMoiReX\Desktop\theHunter.url 2013-09-03 11:35 - 2013-09-03 11:35 - 14050680 _____ (Expansive Worlds ) C:\Users\GriMoiReX\Downloads\theHunterLauncherSetup(1).exe 2013-09-03 06:46 - 2013-09-03 06:46 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\RotMG.Production 2013-09-03 02:04 - 2013-09-03 02:06 - 59280006 _____ C:\Users\GriMoiReX\Downloads\starmade-build_20130827_083114.zip 2013-09-03 01:58 - 2013-09-03 01:59 - 59290255 _____ C:\Users\GriMoiReX\Downloads\starmade-build_20130902_181250.zip 2013-09-02 12:05 - 2013-09-02 12:05 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2013-09-02 12:05 - 2013-09-02 12:05 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2013-09-02 12:05 - 2013-09-02 12:05 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2013-09-02 12:05 - 2013-09-02 12:05 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2013-09-02 12:05 - 2013-09-02 12:05 - 00000000 ____D C:\Program Files (x86)\OpenAL 2013-09-02 01:38 - 2013-09-02 01:41 - 207963836 _____ C:\Users\GriMoiReX\Downloads\Beatmap Pack #232.rar 2013-09-02 01:11 - 2013-09-02 01:11 - 00000000 ____D C:\Users\GriMoiReX\Desktop\17670 Helblinde - Ritsuen!! 2013-09-01 08:18 - 2013-09-01 08:20 - 20380503 _____ C:\Users\GriMoiReX\Documents\Für Feenfleisch 1.MP4 2013-09-01 08:18 - 2013-09-01 08:20 - 15371240 _____ C:\Users\GriMoiReX\Documents\Für Feenfleisch 2.MP4 2013-09-01 06:45 - 2013-09-01 06:45 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\MercurySteam 2013-08-31 09:47 - 2013-08-31 09:47 - 00007920 _____ C:\Users\GriMoiReX\Documents\DAO Ultimate Addins Updater.log 2013-08-31 09:47 - 2013-08-31 09:47 - 00000000 ____D C:\Users\GriMoiReX\Documents\BioWare 2013-08-30 08:12 - 2013-08-30 08:12 - 03820480 _____ C:\Users\GriMoiReX\Downloads\battlelog-web-plugins_2.1.7_115.exe 2013-08-30 08:12 - 2013-08-30 08:12 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\ESN 2013-08-30 08:12 - 2013-08-30 08:12 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-08-30 08:11 - 2013-08-30 08:11 - 00000000 ____D C:\ProgramData\EA Core 2013-08-30 08:10 - 2013-08-30 08:10 - 00000000 ____D C:\Users\GriMoiReX\Documents\Battlefield 3 2013-08-30 04:40 - 2013-08-30 04:40 - 00000858 _____ C:\Users\Public\Desktop\Battlefield 3.lnk 2013-08-27 18:28 - 2013-08-27 18:29 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\Apple Computer 2013-08-27 18:28 - 2013-08-27 18:28 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-27 18:28 - 2013-08-27 18:28 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\Apple Computer 2013-08-27 18:28 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2013-08-27 18:27 - 2013-08-27 18:28 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-27 18:27 - 2013-08-27 18:28 - 00000000 ____D C:\Program Files\iTunes 2013-08-27 18:27 - 2013-08-27 18:28 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-27 18:27 - 2013-08-27 18:27 - 00000000 ____D C:\Windows\System32\Tasks\Apple 2013-08-27 18:27 - 2013-08-27 18:27 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\Apple 2013-08-27 18:27 - 2013-08-27 18:27 - 00000000 ____D C:\ProgramData\Apple Computer 2013-08-27 18:27 - 2013-08-27 18:27 - 00000000 ____D C:\Program Files\iPod 2013-08-27 18:27 - 2013-08-27 18:27 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2013-08-27 18:26 - 2013-08-27 18:26 - 00000000 ____D C:\ProgramData\Apple 2013-08-27 18:26 - 2013-08-27 18:26 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-08-27 18:26 - 2013-08-27 18:26 - 00000000 ____D C:\Program Files\Bonjour 2013-08-27 18:26 - 2013-08-27 18:26 - 00000000 ____D C:\Program Files (x86)\Bonjour 2013-08-27 18:25 - 2013-08-27 18:25 - 90889040 _____ (Apple Inc.) C:\Users\GriMoiReX\Downloads\iTunes64Setup.exe 2013-08-24 14:08 - 2013-08-24 14:14 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\NationRed 2013-08-24 14:01 - 2013-08-24 14:04 - 00000000 ____D C:\Users\GriMoiReX\Documents\DeadHorde 2013-08-24 10:05 - 2013-08-24 10:07 - 355853027 _____ C:\Users\GriMoiReX\Downloads\[YKS]Uta no Prince-sama - Maji Love 2000% - 08[Troll_Version][Hi10P][5D6A6C7B].mkv 2013-08-21 06:59 - 2013-08-21 06:59 - 00751654 _____ C:\Users\GriMoiReX\Downloads\JoyToKey_en_5.2.1.zip 2013-08-21 06:59 - 2013-08-21 06:59 - 00751654 _____ C:\Users\GriMoiReX\Downloads\JoyToKey_en_5.2.1(1).zip 2013-08-21 06:56 - 2013-08-21 06:56 - 01009664 _____ C:\Users\GriMoiReX\Downloads\Xpadder.exe 2013-08-21 05:36 - 2013-06-22 05:36 - 00000032 ____R C:\ProgramData\hash.dat 2013-08-20 22:15 - 2013-08-20 22:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-19 01:38 - 2013-08-19 01:38 - 00000000 ____D C:\Users\GriMoiReX\Documents\streumon 2013-08-15 07:17 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 07:17 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 07:17 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 07:17 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 07:17 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 07:17 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 07:17 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 07:17 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 07:17 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 07:17 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 07:17 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 07:17 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 07:17 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 07:17 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 07:17 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 07:17 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 07:17 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 07:17 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 07:17 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 07:17 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 07:17 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 07:17 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 07:17 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 07:17 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 07:17 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 07:17 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 07:17 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 07:17 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 07:17 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 07:17 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 07:17 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-15 04:52 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-15 04:52 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-15 04:52 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-15 04:52 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-15 04:52 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-15 04:52 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-15 04:52 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-15 04:52 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-15 04:47 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-15 04:47 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-15 04:47 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-15 04:47 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-15 04:47 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-15 04:47 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-15 04:46 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-15 04:46 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-15 04:46 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-15 04:46 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-15 04:45 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-15 04:45 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-15 04:45 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-15 04:45 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-15 04:45 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-15 04:45 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-15 04:45 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-15 04:45 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-15 04:45 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 00:15 - 2013-08-14 00:15 - 00000000 ____D C:\ProgramData\id Software 2013-08-14 00:13 - 2013-08-14 00:14 - 02095104 _____ C:\Users\GriMoiReX\Downloads\QuakeLiveNP_520.msi 2013-08-13 20:56 - 2013-08-13 20:56 - 00000000 ____D C:\Users\GriMoiReX\Documents\SoftTH 2013-08-13 20:55 - 2013-08-13 20:55 - 00219818 _____ C:\Users\GriMoiReX\Downloads\SoftTH208balpha.zip 2013-08-13 20:55 - 2011-12-28 17:47 - 00017486 ____N C:\Users\GriMoiReX\Desktop\readme_SoftTH2.txt 2013-08-13 20:55 - 2011-12-28 17:45 - 00393216 ____N (Kegetys, hxxp://www.kegetys.net) C:\Users\GriMoiReX\Desktop\d3d9.dll 2013-08-13 16:13 - 2012-01-02 08:33 - 00733652 _____ C:\Users\GriMoiReX\Desktop\failsound.wav 2013-08-13 14:49 - 2013-08-13 14:49 - 00000000 ____D C:\ProgramData\vsosdk 2013-08-13 14:28 - 2013-08-13 14:28 - 00000995 _____ C:\Users\GriMoiReX\Desktop\DVDFab 9.lnk 2013-08-13 14:28 - 2013-08-13 14:28 - 00000000 ____D C:\Users\GriMoiReX\Documents\DVDFab9 2013-08-13 14:28 - 2013-08-13 14:28 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\DVDFab9 2013-08-13 14:28 - 2013-08-13 14:28 - 00000000 ____D C:\Program Files (x86)\DVDFab 9 2013-08-11 03:29 - 2013-08-11 03:29 - 00000000 ____D C:\Users\GriMoiReX\Documents\Hitman Blood Money 2013-08-11 03:13 - 2013-08-14 00:26 - 00000000 ____D C:\Users\GriMoiReX\Documents\Dungeon Siege 2013-08-11 02:40 - 2013-08-11 02:44 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\Two Worlds II 2013-08-10 11:41 - 2013-08-10 11:41 - 00000411 _____ C:\Users\GriMoiReX\Documents\ee.txt 2013-08-10 01:34 - 2013-08-10 01:34 - 00000000 ____D C:\gravity 2013-08-10 01:33 - 2013-08-10 01:33 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies ==================== One Month Modified Files and Folders ======= 2013-09-09 12:56 - 2013-09-09 12:56 - 01948948 _____ (Farbar) C:\Users\GriMoiReX\Desktop\FRST64.exe 2013-09-09 12:56 - 2013-09-09 12:56 - 00000000 ____D C:\FRST 2013-09-09 12:55 - 2013-09-09 12:55 - 00000480 _____ C:\Users\GriMoiReX\Desktop\defogger_disable.log 2013-09-09 12:55 - 2013-09-09 12:55 - 00000000 _____ C:\Users\GriMoiReX\defogger_reenable 2013-09-09 12:55 - 2013-05-07 15:34 - 00000000 ____D C:\Users\GriMoiReX 2013-09-09 12:54 - 2013-09-09 12:54 - 00050477 _____ C:\Users\GriMoiReX\Desktop\Defogger.exe 2013-09-09 12:52 - 2013-05-07 22:40 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\Skype 2013-09-09 12:48 - 2013-05-08 07:23 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-09 12:47 - 2013-05-09 20:22 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\Warframe 2013-09-09 12:43 - 2013-09-09 12:43 - 00009720 _____ C:\Users\GriMoiReX\Desktop\hijackthis.log 2013-09-09 12:42 - 2013-09-09 12:42 - 00009079 _____ C:\Users\GriMoiReX\Desktop\blablabla.txt 2013-09-09 12:41 - 2013-07-30 15:11 - 00009720 _____ C:\Users\GriMoiReX\Downloads\hijackthis.log 2013-09-09 12:34 - 2013-05-07 23:11 - 00000000 ____D C:\Program Files (x86)\Steam 2013-09-09 12:26 - 2013-07-09 13:16 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-09 12:17 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\tracing 2013-09-09 11:35 - 2013-09-03 11:37 - 00000000 ____D C:\Program Files (x86)\theHunter 2013-09-09 11:33 - 2013-07-09 13:16 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-09 11:27 - 2009-07-14 06:45 - 00014336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-09 11:27 - 2009-07-14 06:45 - 00014336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-09 11:23 - 2013-05-07 15:28 - 01254259 _____ C:\Windows\WindowsUpdate.log 2013-09-09 11:20 - 2013-09-09 11:20 - 96601965 _____ C:\Windows\SysWOW64\坉룽蹬ˆ 2013-09-09 11:20 - 2013-05-07 21:06 - 00000008 _____ C:\Windows\mvraidver.dat 2013-09-09 11:19 - 2013-08-05 20:02 - 00000000 ____D C:\ProgramData\NVIDIA 2013-09-09 11:19 - 2013-07-31 12:21 - 00009456 _____ C:\Windows\setupact.log 2013-09-09 11:19 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-08 22:41 - 2013-05-12 04:29 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\vlc 2013-09-08 22:29 - 2013-09-07 20:08 - 00000000 ____D C:\Users\GriMoiReX\Documents\CAPCOM 2013-09-08 22:29 - 2013-08-02 10:49 - 00438283 _____ C:\Windows\DirectX.log 2013-09-08 08:36 - 2013-07-31 12:21 - 00154480 _____ C:\Windows\PFRO.log 2013-09-07 19:05 - 2012-05-13 23:22 - 00000000 ____D C:\Users\GriMoiReX\Documents\Alles mögliche 2013-09-07 18:39 - 2013-05-07 23:33 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-09-07 15:50 - 2013-09-07 15:50 - 00001944 _____ C:\Users\Public\Desktop\Metin2.lnk 2013-09-07 15:41 - 2013-09-07 15:40 - 00000000 ____D C:\Users\GriMoiReX\Downloads\Gameforge Live 2013-09-07 15:40 - 2013-09-07 15:40 - 00001067 _____ C:\Users\Public\Desktop\Gameforge Live.lnk 2013-09-07 15:40 - 2013-09-07 15:40 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-09-07 15:39 - 2013-09-07 15:39 - 19328912 _____ (Gameforge ) C:\Users\GriMoiReX\Downloads\Metin2_GameforgeLiveSetup.exe 2013-09-07 11:14 - 2013-06-08 01:04 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-09-07 11:14 - 2013-06-08 00:39 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-09-07 11:11 - 2013-06-08 00:39 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-09-07 11:10 - 2013-06-08 00:38 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-09-06 22:05 - 2013-07-19 15:27 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\LogMeIn Hamachi 2013-09-06 16:11 - 2013-09-06 16:11 - 00001825 _____ C:\Users\GriMoiReX\Desktop\Viscera Cleanup Detail - Alpha.lnk 2013-09-06 16:11 - 2013-09-06 16:10 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VisceraCleanupDetail-Alpha 2013-09-06 16:10 - 2013-09-06 16:10 - 00000000 ____D C:\Games 2013-09-06 16:04 - 2013-09-06 15:48 - 402126484 _____ C:\Users\GriMoiReX\Downloads\viscera_alpha_v0.14.exe 2013-09-06 01:37 - 2013-05-09 22:37 - 00000000 ____D C:\Program Files (x86)\OBS 2013-09-05 22:20 - 2013-05-09 16:25 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\OBS 2013-09-05 21:58 - 2013-06-04 20:22 - 00000000 ____D C:\Users\GriMoiReX\Documents\my games 2013-09-05 12:07 - 2013-06-21 01:28 - 00014868 _____ C:\Users\GriMoiReX\AppData\Roaming\TheHunterSettings_live.bin 2013-09-04 11:22 - 2013-09-04 11:22 - 95812354 _____ C:\Windows\SysWOW64\얛ᆕ蹬¡ 2013-09-04 03:50 - 2013-09-03 22:47 - 00000039 _____ C:\Users\GriMoiReX\AppData\Roaming\TheHunterSettings_live.cfg 2013-09-03 12:53 - 2013-05-07 22:37 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-09-03 12:53 - 2013-05-07 22:35 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-09-03 12:53 - 2013-05-07 22:35 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-03 11:37 - 2013-09-03 11:37 - 00000132 _____ C:\Users\GriMoiReX\Desktop\theHunter.url 2013-09-03 11:37 - 2013-06-20 22:57 - 00000000 ___HD C:\Windows\msdownld.tmp 2013-09-03 11:37 - 2013-06-14 19:40 - 00000000 ____D C:\Windows\SysWOW64\directx 2013-09-03 11:35 - 2013-09-03 11:35 - 14050680 _____ (Expansive Worlds ) C:\Users\GriMoiReX\Downloads\theHunterLauncherSetup(1).exe 2013-09-03 06:46 - 2013-09-03 06:46 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\RotMG.Production 2013-09-03 04:02 - 2013-07-07 21:58 - 00000000 ____D C:\Users\GriMoiReX\Downloads\StarMade 2013-09-03 02:06 - 2013-09-03 02:04 - 59280006 _____ C:\Users\GriMoiReX\Downloads\starmade-build_20130827_083114.zip 2013-09-03 01:59 - 2013-09-03 01:58 - 59290255 _____ C:\Users\GriMoiReX\Downloads\starmade-build_20130902_181250.zip 2013-09-02 13:14 - 2013-06-23 17:19 - 00000000 ____D C:\Users\GriMoiReX\Documents\dreamss-APBr-Shader-Crosshair-3cbfeea 2013-09-02 12:05 - 2013-09-02 12:05 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2013-09-02 12:05 - 2013-09-02 12:05 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2013-09-02 12:05 - 2013-09-02 12:05 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2013-09-02 12:05 - 2013-09-02 12:05 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2013-09-02 12:05 - 2013-09-02 12:05 - 00000000 ____D C:\Program Files (x86)\OpenAL 2013-09-02 01:41 - 2013-09-02 01:38 - 207963836 _____ C:\Users\GriMoiReX\Downloads\Beatmap Pack #232.rar 2013-09-02 01:11 - 2013-09-02 01:11 - 00000000 ____D C:\Users\GriMoiReX\Desktop\17670 Helblinde - Ritsuen!! 2013-09-01 08:20 - 2013-09-01 08:18 - 20380503 _____ C:\Users\GriMoiReX\Documents\Für Feenfleisch 1.MP4 2013-09-01 08:20 - 2013-09-01 08:18 - 15371240 _____ C:\Users\GriMoiReX\Documents\Für Feenfleisch 2.MP4 2013-09-01 06:45 - 2013-09-01 06:45 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\MercurySteam 2013-08-31 21:22 - 2013-07-05 01:09 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\.minecraft 2013-08-31 09:47 - 2013-08-31 09:47 - 00007920 _____ C:\Users\GriMoiReX\Documents\DAO Ultimate Addins Updater.log 2013-08-31 09:47 - 2013-08-31 09:47 - 00000000 ____D C:\Users\GriMoiReX\Documents\BioWare 2013-08-31 07:56 - 2013-08-09 20:03 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-30 08:12 - 2013-08-30 08:12 - 03820480 _____ C:\Users\GriMoiReX\Downloads\battlelog-web-plugins_2.1.7_115.exe 2013-08-30 08:12 - 2013-08-30 08:12 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\ESN 2013-08-30 08:12 - 2013-08-30 08:12 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-08-30 08:11 - 2013-08-30 08:11 - 00000000 ____D C:\ProgramData\EA Core 2013-08-30 08:11 - 2013-05-08 07:27 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-08-30 08:10 - 2013-08-30 08:10 - 00000000 ____D C:\Users\GriMoiReX\Documents\Battlefield 3 2013-08-30 08:10 - 2013-05-08 07:30 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\Origin 2013-08-30 04:40 - 2013-08-30 04:40 - 00000858 _____ C:\Users\Public\Desktop\Battlefield 3.lnk 2013-08-30 01:26 - 2013-05-08 07:27 - 00000000 ____D C:\ProgramData\Origin 2013-08-28 21:48 - 2013-05-28 15:52 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\PMB Files 2013-08-28 21:48 - 2013-05-28 15:52 - 00000000 ____D C:\ProgramData\PMB Files 2013-08-27 23:53 - 2013-07-22 03:32 - 00000000 ____D C:\Users\GriMoiReX\Documents\nana 2013-08-27 18:29 - 2013-08-27 18:28 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\Apple Computer 2013-08-27 18:28 - 2013-08-27 18:28 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-27 18:28 - 2013-08-27 18:28 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\Apple Computer 2013-08-27 18:28 - 2013-08-27 18:27 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-27 18:28 - 2013-08-27 18:27 - 00000000 ____D C:\Program Files\iTunes 2013-08-27 18:28 - 2013-08-27 18:27 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-27 18:27 - 2013-08-27 18:27 - 00000000 ____D C:\Windows\System32\Tasks\Apple 2013-08-27 18:27 - 2013-08-27 18:27 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\Apple 2013-08-27 18:27 - 2013-08-27 18:27 - 00000000 ____D C:\ProgramData\Apple Computer 2013-08-27 18:27 - 2013-08-27 18:27 - 00000000 ____D C:\Program Files\iPod 2013-08-27 18:27 - 2013-08-27 18:27 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2013-08-27 18:26 - 2013-08-27 18:26 - 00000000 ____D C:\ProgramData\Apple 2013-08-27 18:26 - 2013-08-27 18:26 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-08-27 18:26 - 2013-08-27 18:26 - 00000000 ____D C:\Program Files\Bonjour 2013-08-27 18:26 - 2013-08-27 18:26 - 00000000 ____D C:\Program Files (x86)\Bonjour 2013-08-27 18:25 - 2013-08-27 18:25 - 90889040 _____ (Apple Inc.) C:\Users\GriMoiReX\Downloads\iTunes64Setup.exe 2013-08-27 18:21 - 2013-05-07 22:36 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\DoNotTrackPlus 2013-08-27 02:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-24 14:14 - 2013-08-24 14:08 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\NationRed 2013-08-24 14:04 - 2013-08-24 14:01 - 00000000 ____D C:\Users\GriMoiReX\Documents\DeadHorde 2013-08-24 11:38 - 2013-05-07 16:00 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\Microsoft Games 2013-08-24 10:07 - 2013-08-24 10:05 - 355853027 _____ C:\Users\GriMoiReX\Downloads\[YKS]Uta no Prince-sama - Maji Love 2000% - 08[Troll_Version][Hi10P][5D6A6C7B].mkv 2013-08-21 10:03 - 2009-07-14 19:58 - 00699416 _____ C:\Windows\system32\perfh007.dat 2013-08-21 10:03 - 2009-07-14 19:58 - 00149556 _____ C:\Windows\system32\perfc007.dat 2013-08-21 10:03 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-21 06:59 - 2013-08-21 06:59 - 00751654 _____ C:\Users\GriMoiReX\Downloads\JoyToKey_en_5.2.1.zip 2013-08-21 06:59 - 2013-08-21 06:59 - 00751654 _____ C:\Users\GriMoiReX\Downloads\JoyToKey_en_5.2.1(1).zip 2013-08-21 06:56 - 2013-08-21 06:56 - 01009664 _____ C:\Users\GriMoiReX\Downloads\Xpadder.exe 2013-08-21 03:45 - 2013-05-14 12:55 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-08-21 00:51 - 2013-05-08 07:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-20 22:15 - 2013-08-20 22:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-19 01:38 - 2013-08-19 01:38 - 00000000 ____D C:\Users\GriMoiReX\Documents\streumon 2013-08-18 16:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-15 13:00 - 2013-05-07 16:24 - 00000000 ____D C:\Windows\Panther 2013-08-15 07:15 - 2013-07-20 04:53 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 07:14 - 2013-07-06 01:25 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-14 00:36 - 2013-08-07 01:14 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\NVIDIA 2013-08-14 00:26 - 2013-08-11 03:13 - 00000000 ____D C:\Users\GriMoiReX\Documents\Dungeon Siege 2013-08-14 00:15 - 2013-08-14 00:15 - 00000000 ____D C:\ProgramData\id Software 2013-08-14 00:14 - 2013-08-14 00:13 - 02095104 _____ C:\Users\GriMoiReX\Downloads\QuakeLiveNP_520.msi 2013-08-13 20:56 - 2013-08-13 20:56 - 00000000 ____D C:\Users\GriMoiReX\Documents\SoftTH 2013-08-13 20:55 - 2013-08-13 20:55 - 00219818 _____ C:\Users\GriMoiReX\Downloads\SoftTH208balpha.zip 2013-08-13 15:20 - 2013-05-22 21:24 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\dvdcss 2013-08-13 14:49 - 2013-08-13 14:49 - 00000000 ____D C:\ProgramData\vsosdk 2013-08-13 14:28 - 2013-08-13 14:28 - 00000995 _____ C:\Users\GriMoiReX\Desktop\DVDFab 9.lnk 2013-08-13 14:28 - 2013-08-13 14:28 - 00000000 ____D C:\Users\GriMoiReX\Documents\DVDFab9 2013-08-13 14:28 - 2013-08-13 14:28 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\DVDFab9 2013-08-13 14:28 - 2013-08-13 14:28 - 00000000 ____D C:\Program Files (x86)\DVDFab 9 2013-08-13 14:26 - 2013-02-02 02:33 - 00000000 ____D C:\Users\GriMoiReX\Desktop\EGOIST (Inori) 2013-08-11 03:29 - 2013-08-11 03:29 - 00000000 ____D C:\Users\GriMoiReX\Documents\Hitman Blood Money 2013-08-11 03:28 - 2013-05-25 02:50 - 00000000 ____D C:\Users\GriMoiReX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-08-11 02:44 - 2013-08-11 02:40 - 00000000 ____D C:\Users\GRIMOI~1\AppData\Local\Two Worlds II 2013-08-10 11:41 - 2013-08-10 11:41 - 00000411 _____ C:\Users\GriMoiReX\Documents\ee.txt 2013-08-10 01:34 - 2013-08-10 01:34 - 00000000 ____D C:\gravity 2013-08-10 01:33 - 2013-08-10 01:33 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-08-10 01:33 - 2013-08-02 20:18 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation Files to move or delete: ==================== C:\ProgramData\hash.dat ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-07 16:28 ==================== End Of Log ============================ --- --- --- Und hier das Addition-Log --> Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-09-2013 Ran by GriMoiReX at 2013-09-09 12:58:08 Running from C:\Users\GriMoiReX\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Alien Swarm (x32) AMD Accelerated Video Transcoding (Version: 13.20.100.30723) AMD Catalyst Control Center (x32 Version: 2013.0723.1944.33607) AMD Catalyst Install Manager (Version: 8.0.915.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.80723.2017) AMD Wireless Display v3.0 (Version: 1.0.0.10) AMD Wireless Display v3.0 (Version: 1.0.0.13) APB Reloaded (x32) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (x32 Version: 2.1.3.127) Application Profiles (x32 Version: 2.0.4888.34279) Ask Toolbar (x32 Version: 1.15.24.0) Avira Free Antivirus (x32 Version: 13.0.0.4052) Avira SearchFree Toolbar plus Web Protection Updater (HKCU Version: 1.2.5.42066) Battlefield 3™ (x32 Version: 1.6.0.0) Battlelog Web Plugins (x32 Version: 2.1.7) Bonjour (Version: 3.0.0.10) Bundled software uninstaller (x32) Castlevania: Lords of Shadow - Ultimate Edition (x32) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0723.1944.33607) Catalyst Control Center InstallProxy (x32 Version: 2013.0723.1944.33607) Catalyst Control Center Localization All (x32 Version: 2013.0723.1944.33607) CCC Help Chinese Standard (x32 Version: 2013.0723.1943.33607) CCC Help Chinese Traditional (x32 Version: 2013.0723.1943.33607) CCC Help Czech (x32 Version: 2013.0723.1943.33607) CCC Help Danish (x32 Version: 2013.0723.1943.33607) CCC Help Dutch (x32 Version: 2013.0723.1943.33607) CCC Help English (x32 Version: 2013.0723.1943.33607) CCC Help Finnish (x32 Version: 2013.0723.1943.33607) CCC Help French (x32 Version: 2013.0723.1943.33607) CCC Help German (x32 Version: 2013.0723.1943.33607) CCC Help Greek (x32 Version: 2013.0723.1943.33607) CCC Help Hungarian (x32 Version: 2013.0723.1943.33607) CCC Help Italian (x32 Version: 2013.0723.1943.33607) CCC Help Japanese (x32 Version: 2013.0723.1943.33607) CCC Help Korean (x32 Version: 2013.0723.1943.33607) CCC Help Norwegian (x32 Version: 2013.0723.1943.33607) CCC Help Polish (x32 Version: 2013.0723.1943.33607) CCC Help Portuguese (x32 Version: 2013.0723.1943.33607) CCC Help Russian (x32 Version: 2013.0723.1943.33607) CCC Help Spanish (x32 Version: 2013.0723.1943.33607) CCC Help Swedish (x32 Version: 2013.0723.1943.33607) CCC Help Thai (x32 Version: 2013.0723.1943.33607) CCC Help Turkish (x32 Version: 2013.0723.1943.33607) ccc-utility64 (Version: 2013.0723.1944.33607) Cheat Engine 6.2 (x32) Chivalry: Medieval Warfare (x32) Delta Chrome Toolbar (x32) Dishonored (x32 Version: 1.0) DVDFab 9.0.5.5 (26/07/2013) (x32) E.Y.E: Divine Cybermancy (x32) ESN Sonar (x32 Version: 0.70.4) FilesFrog Update Checker (x32) Gameforge Live 1.7.0 "Legend" (x32 Version: 1.7.0) Google Chrome (x32 Version: 29.0.1547.66) Google Update Helper (x32 Version: 1.3.21.153) Hammerwatch (x32) Hitman: Blood Money (x32) iTunes (Version: 11.0.5.5) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) JDownloader 0.9 (x32 Version: 0.9) Killing Floor (x32) League of Legends (x32 Version: 1.3) LogMeIn Hamachi (x32 Version: 2.1.0.374) LOLReplay (x32 Version: 0.8.2.1) Marvell MRU V4 (x32 Version: 4.1.0.1700) Metin2 (x32) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4.5 (Version: 4.5.50709) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0) Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (x32 Version: 11.0.50727.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (x32 Version: 11.0.50727.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106) Microsoft XNA Framework Redistributable 3.1 (x32 Version: 3.1.10527.0) Microsoft XNA Framework Redistributable 4.0 (x32 Version: 4.0.20823.0) Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1) Mozilla Maintenance Service (x32 Version: 23.0.1) Nation Red (x32) NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49) NVIDIA 3D Vision Treiber 320.49 (Version: 320.49) NVIDIA GeForce Experience 1.5 (Version: 1.5) NVIDIA Grafiktreiber 320.49 (Version: 320.49) NVIDIA HD-Audiotreiber 1.3.24.2 (Version: 1.3.24.2) NVIDIA Install Application (Version: 2.1002.124.810) NVIDIA PhysX (x32 Version: 9.12.1031) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2049) NVIDIA Systemsteuerung 320.49 (Version: 320.49) NVIDIA Update 4.11.9 (Version: 4.11.9) NVIDIA Update Components (Version: 4.11.9) Open Broadcaster Software (x32) OpenAL (x32) Origin (x32 Version: 9.1.15.109) Outlast (x32) Overlord II (x32) Pando Media Booster (x32 Version: 2.6.0.9) PunkBuster Services (x32 Version: 0.991) Quake Live Mozilla Plugin (x32 Version: 1.0.520) Realtek Ethernet Controller Driver (x32 Version: 7.49.927.2011) Realtek Ethernet Diagnostic Utility (x32 Version: 1.006) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6074) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.30.0) Resident Evil 5 (x32) Resident Evil 6 / Biohazard 6 (x32) rosoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Sanctum 2 (x32) Sequence (x32) Skullgirls (x32) Skype™ 6.6 (x32 Version: 6.6.106) Sleeping Dogs™ (x32) Spiral Knights (x32) Steam (x32 Version: 1.0.0.0) Still Life (x32) Still Life 2 (x32) TeamSpeak 3 Client (x32 Version: 3.0.10) TeamViewer 8 (x32 Version: 8.0.19617) TechPowerUp GPU-Z (x32) Terraria (x32) The Secret World (x32 Version: 1.0.0) theHunter Launcher (x32 Version: 617) Trine 2 (x32) TuneUp Utilities 2012 (x32 Version: 12.0.3600.73) TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.73) Two Worlds II (x32) Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1) Viscera Cleanup Detail - ALPHA VLC media player 2.0.6 (Version: 2.0.6) Warframe (x32) Warhammer® 40,000™: Dawn of War® II (x32) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 03-09-2013 09:37:57 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 06-09-2013 14:09:47 DirectX wurde installiert 07-09-2013 16:30:16 DirectX wurde installiert 08-09-2013 20:28:11 DirectX wurde installiert ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started Task: {1DA357EF-7F6B-4F40-B7F7-7163BDB5BE13} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated) Task: {1F8E772A-47CB-4593-ABCB-E504650D0819} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {3649AE4F-494B-4725-9A67-1B35A58AE0D9} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2013-04-01] () Task: {4C0FE4D0-46F2-4D66-952E-13DD806CAD6B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-09] (Google Inc.) Task: {825C84CE-2588-485F-A128-A988FD7004A9} - System32\Tasks\AdobeFlashPlayerUpdate => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated) Task: {9107B4B9-B579-4443-BF8C-E52966FDDF8F} - System32\Tasks\EPUpdater => C:\Users\GriMoiReX\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () Task: {992145BD-F5A9-4276-B0E3-CCCAC6F2FD7C} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation) Task: {9C556118-BCFC-41C7-8CA0-18E21C9CF88E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-09] (Google Inc.) Task: {C85C75E9-73F0-4461-845B-E3F6B21F485A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated) Task: {C93D94C1-AE0C-4655-8954-D65AFBF10B49} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {D8DB80B5-F5C6-4C76-8F66-7AA8DD4693D4} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-05-29] (TuneUp Software) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-05-09 15:54 - 2013-07-08 12:59 - 00114528 _____ (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.dll 2013-08-05 13:10 - 2013-08-05 13:10 - 00019968 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\MOM\b38de2c9143c4136266c90d991c5078d\MOM.ni.exe 2013-08-05 13:10 - 2013-08-05 13:10 - 00410112 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\MOM.Implementation\b3bdd77828a7e2ee6bb16a0e16a8d4e1\MOM.Implementation.ni.dll 2013-08-16 09:02 - 2013-08-16 09:02 - 00137216 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\LOG.Foundation\9b98b63620b9cd7512be5d676b77b5c9\LOG.Foundation.ni.dll 2013-08-16 09:02 - 2013-08-16 09:02 - 00159232 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\LOG.Foundat5023f8e7#\8bc6570f6dea157946e24e8d69193c55\LOG.Foundation.Private.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00327680 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\LOG.Foundat03490438#\252cb743071128bea5a27f13a70843a1\LOG.Foundation.Implementation.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 00014336 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\MOM.Foundation\8bb04987b0a8a34afaa2db7823a25175\MOM.Foundation.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 00090624 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\LOG.Foundatcaafa75b#\4b3bb660ec8fa8ad9bdb4182807429cd\LOG.Foundation.Implementation.Private.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 00227840 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CCC.Implementation\1aef5e2a215f6dce0c3173d48bff3612\CCC.Implementation.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\NEWAEM.Foundation\0d97f62262df679430c35511a8b9c041\NEWAEM.Foundation.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 00022016 _____ (ATI Technologies Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CCC\bb98c6904380f940a447255789c48bc7\CCC.ni.exe 2013-08-16 09:03 - 2013-08-16 09:03 - 00320512 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Foundation\ee23f58082aed7d83467fbb36a7b23e6\CLI.Foundation.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00068608 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Foundat60cdf5df#\5acef3b55a89f20243efdfdbc5f072a9\CLI.Foundation.XManifest.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00248832 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Compone6692ca50#\efbaba9251b807d8db1bc0d092c59ba3\CLI.Component.Runtime.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00169472 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Compone59f353b4#\1d690b4ef80630b504516b6cca950071\CLI.Component.Runtime.Shared.Private.ni.dll 2013-08-16 09:03 - 2013-08-16 09:03 - 00099328 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Foundat3d5d3945#\836cc10e6bcb7597672cb159dc520754\CLI.Foundation.Private.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00014336 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Compone1b4a8c97#\bfaee30fe5b0629b0b26de1e249ffcaf\CLI.Component.Runtime.Shared.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00134144 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\ATICCCom\222b4dc10e359f7ba12558592ba41776\ATICCCom.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00847872 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\ADL.Foundation\9c2531107a9f9df3e31b36600868618b\ADL.Foundation.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 00286208 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\AEM.Server\ac4f65d72a9f9c82a19eac99fcd48f24\AEM.Server.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00015360 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\AEM.Server.Shared\bdff999fb509c2ce32ec854e7e1c04db\AEM.Server.Shared.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00301568 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.5d945b6b#\7b89068795d93bef764dcc12e0ac7cd1\AEM.Plugin.Source.Kit.Server.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00099840 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Foundat619559bd#\7923fc5e4a0d03fb5d66808b38d54d5c\CLI.Foundation.CoreAudioAPI.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00019456 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.2b6a6775#\4723f6f876bf8a6e051b77030463bda9\AEM.Plugin.Hotkeys.Shared.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00017408 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.674d2b8a#\df807f6187fc5e11a86a9d723eb68eb2\AEM.Plugin.WinMessages.Shared.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00121344 _____ (ATI Technologies Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0601\9b108d28ad21d983921422621afde31d\DEM.Graphics.I0601.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00018432 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\DEM.Graphics\84876ac2c85156be527a05c5aed0db55\DEM.Graphics.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00027136 _____ (ATI Technologies Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\DEM.Foundation\11cf271cc8a7918c71a74368cb80b5d6\DEM.Foundation.ni.dll 2013-08-05 13:09 - 2013-08-05 13:09 - 00041984 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I1010\5eaf649393dc814c03161b9d2eaf111e\DEM.Graphics.I1010.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00014336 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.88aba5d2#\b41129eaffa9a63bd8b658ac39df4608\AEM.Plugin.REG.Shared.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 03129344 _____ (Advanced Mirco Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.G962aa464#\342cdbf4be065c942b7c8a8297bd1523\CLI.Caste.Graphics.Runtime.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 02656768 _____ (Advanced Mirco Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.G60a7b4d1#\c3c1d07635630cf43361c7d1bb6c7914\CLI.Caste.Graphics.Shared.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00013824 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.GD.Shared\f87f3b6739931fa576369f54b2583c3c\AEM.Plugin.GD.Shared.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00023552 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\AEM.Actions5dc83b46#\43b246081519f743c7ab46e4fd2edc1c\AEM.Actions.CCAA.Shared.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00027136 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\ResourceManf163905a#\8bbd2cca48624347cdddd913b68cbfac\ResourceManagement.Foundation.Private.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 00088576 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0709\28f181a8d038b1ce868161dddab3317a\DEM.Graphics.I0709.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 00019968 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0804\23c2f4e74b68ac62f81420c2be1ac213\DEM.Graphics.I0804.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00053760 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.ef3eaa4d#\2e7ed76ec4c0127d3ed516e00645b82d\CLI.Aspect.TransCode.Graphics.Runtime.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00041984 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.G60338cc0#\0a39c72ab661716918f7fd3626f823a8\CLI.Caste.Graphics.Runtime.Shared.Private.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00115200 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.3a6f1658#\47241efb4a84771162c83f191bcc64f0\CLI.Aspect.TransCode.Graphics.Shared.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00030720 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.37d3d968#\a13941df354a12d8a2dce727d24d5eb9\CLI.Aspect.AMDHome.Graphics.Shared.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 00019456 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.c854b457#\55c8e3601b82cbd113718c65a1308bda\CLI.Aspect.HotkeysHandling.Graphics.Shared.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00352256 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.F36b07a2b#\c722221ad416d5f1254e1b2f81554293\CLI.Caste.Fuel.Runtime.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00051200 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.F24de14fe#\11214298f96d5ea9ee98682defc092b9\CLI.Caste.Fuel.Shared.ni.dll 2013-08-05 13:09 - 2013-08-05 13:09 - 00041984 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\Fuel.Foundation\4b8c240d3f1621d5a2e4f7ce52068e56\Fuel.Foundation.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00052736 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Pdb36d56e#\22ab3f6c52496c37d299a766fc2a96c8\CLI.Caste.Platform.Runtime.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00034304 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Pac40511b#\ab81dc88c751b04ac9fa86ff08b9777d\CLI.Caste.Platform.Shared.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00049664 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.382a3def#\671cf6cb8da839ad441716bb44b0c5af\CLI.Aspect.AMDOverDrive.Platform.Shared.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00349184 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.c7aaa0f8#\a601c54415dd3e20ee75cfcee5d81a51\CLI.Aspect.OverDrive5.Graphics.Shared.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00054272 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.H18c99613#\313555b591d3c953346b0c7317454ea4\CLI.Caste.HydraVision.Runtime.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00034304 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.H92ba4e46#\67134d2c7b59a3cdcec61ef810fef656\CLI.Caste.HydraVision.Shared.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00075264 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.A4.Runtime\01e6b1b57c4577a055bdb2e71516f271\CLI.Caste.A4.Runtime.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00051200 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.A4.Shared\1e4805c84b53b517c5c56a1ce6cd7972\CLI.Caste.A4.Shared.ni.dll 2013-08-05 13:06 - 2013-08-05 13:06 - 00035840 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\A4.Foundation\1e8d9985fb55102ea95b1512159af022\A4.Foundation.ni.dll 2013-08-16 09:03 - 2013-08-16 09:03 - 00287232 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\APM.Server\2edbbb64fbb6009476bcb23382941f71\APM.Server.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 00061440 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\APM.Foundation\a0290fd4245f2a9fe30f1dff20c4a0d7\APM.Foundation.ni.dll 2013-08-05 13:09 - 2013-08-05 13:09 - 00020480 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Componeb4d0485c#\309b3f0341d77df0b50b60a62f6227ae\CLI.Component.Runtime.Extension.EEU.ni.dll 2013-08-05 13:07 - 2013-08-05 13:07 - 00014848 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.0a1309f7#\16f6b2cb38011333a42aef7644c15acc\AEM.Plugin.EEU.Shared.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00947712 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Compone6bf88b08#\5b1a667af5b03ea39293a5481c7bc2fe\CLI.Component.Dashboard.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00149504 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Compone168638d1#\55596ae23413409c04109c62252c5124\CLI.Component.Client.Shared.Private.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00022528 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Componef1fd67b2#\71356905db36b53ad0f3be135f9ca844\CLI.Component.Client.Shared.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 00092672 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Componef4cf054f#\b21aa6f9ca81211068ed75a9d9c1deb2\CLI.Component.Dashboard.Shared.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 01618432 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Componec89c3bec#\818290901aa3e9595616f1638ac71f1d\CLI.Component.Dashboard.Shared.Private.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00945152 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Compone26c9c557#\2445640d58a5c40fa9a451e248691822\CLI.Component.Systemtray.ni.dll 2013-08-16 09:06 - 2013-08-16 09:06 - 00251904 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\ResourceMan446ca0e5#\0beeeb4e4a4db4788ae07d39097e48ea\ResourceManagement.Foundation.Implementation.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00294912 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.73911eb5#\92b8ce30529a4380a8d39390f65e96e7\CLI.Aspect.WirelessDisplay.Graphics.Shared.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00138752 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.3399d0ec#\39c7c21905677af35c184f32bd64dca2\CLI.Aspect.CustomFormats.Graphics.Shared.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00315904 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.7ec2db45#\062330f96ee90ab1842a7b4c3de56b22\CLI.Aspect.DeviceDFP.Graphics.Shared.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00496640 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.acb9d930#\ae241c61cd1ee5fde37947405c124492\CLI.Aspect.DeviceProperty.Graphics.Shared.ni.dll 2013-08-05 13:08 - 2013-08-05 13:08 - 01026560 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\Localizatio01dbc1c0#\b0d0c5d63bde55ec5a757dfa8bbe2ec7\Localization.Foundation.Private.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00484864 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Gee7d2dbc#\345a382336470e1c7b5a50ca061059ca\CLI.Caste.Graphics.Dashboard.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 01591296 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Gd9d9b43b#\7450076197a8c9681c7956afd18141fa\CLI.Caste.Graphics.Dashboard.Shared.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00092160 _____ (Advanced Mirco Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.ec8786e5#\f06514b8bd1beb73706e9d6afa331f2e\CLI.Aspect.AMDHome.Graphics.Dashboard.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00288256 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.e8635fc7#\8de0526626cfea270efb8525d3ad97c6\CLI.Aspect.InfoCentre.Graphics.Dashboard.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 02692096 _____ (Advanced Micro Devices, Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Combine0616f305#\0d557e720de05b16b1b1a0a3c3d1f975\CLI.Combined.Graphics.Aspects1.Dashboard.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00464896 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.8e996306#\160baf0f1f94c78f2b9124b2e1dcccf5\CLI.Aspect.CrossDisplay.Graphics.Dashboard.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00075776 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.b0a7c1fb#\0b852e9fcdea13e6d41ba2ee982d93ac\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00074752 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.4bbb0755#\dc2fca7a0cf017d05089a398113d1f00\CLI.Aspect.TransCode.Graphics.Dashboard.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00032256 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Ff3085433#\d7d312aa322580e9325bab1988026b5d\CLI.Caste.Fuel.Dashboard.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00028672 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Pfeefa2b6#\b85ef55c13a3349fa385d5dcaf3688ce\CLI.Caste.Platform.Dashboard.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00031232 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Hbb906c0b#\cc11cbfad55d11cf54d98f90014372ce\CLI.Caste.HydraVision.Dashboard.ni.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00032256 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Af820fedc#\e60e89eff5f663d3962134e7cfe16ae3\CLI.Caste.A4.Dashboard.ni.dll 2013-08-16 09:04 - 2013-08-16 09:04 - 00955904 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Foundatd3771151#\22a619f99c8c4d605c320fbe3a5249a5\CLI.Foundation.Client.ni.dll 2013-08-05 20:00 - 2013-06-21 14:06 - 15144928 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-08-16 09:05 - 2013-08-16 09:05 - 00181248 _____ (Advanced Micro Devices Inc.) C:\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Compone29e547cc#\57cde3008449c3eb932022e56b14881e\CLI.Component.Dashboard.ProfileManager2.ni.dll 2013-08-05 20:00 - 2013-06-21 14:06 - 02936208 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-08-05 20:01 - 2013-06-21 12:23 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-05-21 15:11 - 2012-06-09 19:20 - 00196096 _____ (Alexander Roshal) C:\Program Files\WinRAR\rarext.dll 2012-05-29 13:09 - 2012-05-29 13:09 - 00028512 _____ (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\SDShelEx-x64.dll 2012-05-29 13:09 - 2012-05-29 13:09 - 00023904 _____ (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\DseShExt-x64.dll 2013-05-09 15:54 - 2013-07-08 12:59 - 00095584 _____ (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.dll 2013-05-07 22:35 - 2013-09-03 12:52 - 00055352 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\cfglib.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00349752 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccguard.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00029240 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccgrdrc.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00229432 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccgrdw.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00218168 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\gpipc.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00419384 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccwgrd.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00027192 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccwgrdrc.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00127544 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccwgrdw.dll 2013-05-07 22:35 - 2013-09-03 12:52 - 00807992 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccgen.dll 2013-05-07 22:35 - 2013-09-03 12:52 - 00049720 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccgenrc.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00220216 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccupdate.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00028728 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccupdrc.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00083000 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\cclic.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00009784 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\cclicrc.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00237624 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccmsg.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00010296 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccmsgrc.dll 2013-05-07 22:35 - 2013-09-03 12:53 - 00014392 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccmainrc.dll 2013-05-07 23:11 - 2013-08-28 23:47 - 00288680 _____ (Valve Corporation) C:\Program Files (x86)\Steam\crashhandler.dll 2013-05-02 16:29 - 2013-07-16 00:32 - 02895272 _____ (Valve Corporation) C:\Program Files (x86)\Steam\steam.dll 2013-05-03 15:35 - 2013-08-28 23:47 - 10654632 _____ (Valve Corporation) C:\Program Files (x86)\Steam\steamui.dll 2013-04-23 18:30 - 2013-08-22 00:18 - 00687104 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2013-05-03 15:35 - 2013-08-28 23:47 - 00263080 _____ (Valve Corporation) C:\Program Files (x86)\Steam\tier0_s.dll 2013-05-03 15:35 - 2013-08-28 23:47 - 00236456 _____ (Valve Corporation) C:\Program Files (x86)\Steam\vstdlib_s.dll 2010-03-10 09:08 - 2013-06-15 01:49 - 00122864 _____ (Valve) C:\Program Files (x86)\Steam\CSERHelper.dll 2013-05-03 15:35 - 2013-08-28 23:47 - 00169384 _____ (Valve Corporation) C:\Program Files (x86)\Steam\bin\filesystem_stdio.DLL 2013-05-03 15:35 - 2013-08-28 23:47 - 00694696 _____ (Valve Corporation) C:\Program Files (x86)\Steam\bin\vgui2_s.DLL 2013-05-03 15:35 - 2013-08-28 23:47 - 01120680 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2013-03-26 16:16 - 2013-08-07 21:31 - 20625832 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2012-09-07 15:37 - 2013-06-15 01:49 - 09955112 _____ (The ICU Project) C:\Program Files (x86)\Steam\bin\icudt.dll 2012-12-11 09:51 - 2013-06-15 01:49 - 01100800 _____ () C:\Program Files (x86)\Steam\bin\avcodec-53.dll 2012-12-11 09:51 - 2013-06-15 01:49 - 00124416 _____ () C:\Program Files (x86)\Steam\bin\avutil-51.dll 2012-12-11 09:51 - 2013-06-15 01:49 - 00192000 _____ () C:\Program Files (x86)\Steam\bin\avformat-53.dll 2013-05-03 15:35 - 2013-08-28 23:47 - 07745960 _____ (Valve Corporation) C:\Program Files (x86)\Steam\steamclient.dll 2013-05-03 15:35 - 2013-08-28 23:47 - 02449832 _____ (Valve Corporation) c:\program files (x86)\steam\bin\friendsui.DLL 2013-05-03 15:35 - 2013-08-28 23:47 - 01804712 _____ (Valve Corporation) c:\program files (x86)\steam\bin\serverbrowser.DLL 2013-06-21 09:53 - 2013-06-21 09:53 - 00088680 ____R (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.dll 2013-06-12 01:48 - 2013-06-12 01:48 - 16096136 ____R (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_7_700_224.ocx 2013-05-09 15:54 - 2013-07-08 13:09 - 00350048 _____ (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Resource_de.dll 2013-05-09 15:54 - 2013-07-08 13:09 - 03006304 _____ (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_StaticRes.dll 2013-08-20 22:15 - 2013-08-20 22:15 - 03551640 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (09/09/2013 00:48:02 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18205, Zeitstempel: 0x51db9710 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e243 ID des fehlerhaften Prozesses: 0xe34 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1 Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2 Berichtskennung: FlashPlayerUpdateService.exe3 Error: (09/09/2013 11:48:02 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18205, Zeitstempel: 0x51db9710 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e243 ID des fehlerhaften Prozesses: 0xf98 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1 Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2 Berichtskennung: FlashPlayerUpdateService.exe3 Error: (09/09/2013 11:44:11 AM) (Source: Application Hang) (User: ) Description: Programm launcher.exe, Version 1.0.0.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1014 Startzeit: 01cead3ff6dacb97 Endzeit: 2652 Anwendungspfad: C:\Program Files (x86)\theHunter\launcher\launcher.exe Berichts-ID: 5dbd2424-1934-11e3-a9d1-1c6f653805d7 Error: (09/09/2013 11:20:32 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: A3FB.tmp, Version: 0.0.0.0, Zeitstempel: 0x52236ca0 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b83c8a Ausnahmecode: 0xe06d7363 Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x8fc Startzeit der fehlerhaften Anwendung: 0xA3FB.tmp0 Pfad der fehlerhaften Anwendung: A3FB.tmp1 Pfad des fehlerhaften Moduls: A3FB.tmp2 Berichtskennung: A3FB.tmp3 Error: (09/09/2013 00:48:02 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18205, Zeitstempel: 0x51db9710 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e243 ID des fehlerhaften Prozesses: 0x2f4 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1 Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2 Berichtskennung: FlashPlayerUpdateService.exe3 Error: (09/08/2013 11:55:32 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: RE5DX10.exe, Version: 1.0.0.129, Zeitstempel: 0x4a531c50 Name des fehlerhaften Moduls: d3d11.dll, Version: 6.2.9200.16570, Zeitstempel: 0x5153774d Ausnahmecode: 0xc0000005 Fehleroffset: 0x000a5176 ID des fehlerhaften Prozesses: 0x15c0 Startzeit der fehlerhaften Anwendung: 0xRE5DX10.exe0 Pfad der fehlerhaften Anwendung: RE5DX10.exe1 Pfad des fehlerhaften Moduls: RE5DX10.exe2 Berichtskennung: RE5DX10.exe3 Error: (09/08/2013 11:48:02 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18205, Zeitstempel: 0x51db9710 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e243 ID des fehlerhaften Prozesses: 0x14c0 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1 Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2 Berichtskennung: FlashPlayerUpdateService.exe3 Error: (09/08/2013 11:12:28 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: RE5DX10.exe, Version: 1.0.0.129, Zeitstempel: 0x4a531c50 Name des fehlerhaften Moduls: d3d11.dll, Version: 6.2.9200.16570, Zeitstempel: 0x5153774d Ausnahmecode: 0xc0000005 Fehleroffset: 0x000a5176 ID des fehlerhaften Prozesses: 0x6f0 Startzeit der fehlerhaften Anwendung: 0xRE5DX10.exe0 Pfad der fehlerhaften Anwendung: RE5DX10.exe1 Pfad des fehlerhaften Moduls: RE5DX10.exe2 Berichtskennung: RE5DX10.exe3 Error: (09/08/2013 11:10:48 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: RE5DX10.exe, Version: 1.0.0.129, Zeitstempel: 0x4a531c50 Name des fehlerhaften Moduls: d3d11.dll, Version: 6.2.9200.16570, Zeitstempel: 0x5153774d Ausnahmecode: 0xc0000005 Fehleroffset: 0x000a5173 ID des fehlerhaften Prozesses: 0x680 Startzeit der fehlerhaften Anwendung: 0xRE5DX10.exe0 Pfad der fehlerhaften Anwendung: RE5DX10.exe1 Pfad des fehlerhaften Moduls: RE5DX10.exe2 Berichtskennung: RE5DX10.exe3 Error: (09/08/2013 10:48:02 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerUpdateService.exe, Version: 11.6.602.180, Zeitstempel: 0x51a4ab8c Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18205, Zeitstempel: 0x51db9710 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e243 ID des fehlerhaften Prozesses: 0x5c0 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerUpdateService.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerUpdateService.exe1 Pfad des fehlerhaften Moduls: FlashPlayerUpdateService.exe2 Berichtskennung: FlashPlayerUpdateService.exe3 System errors: ============= Error: (09/08/2013 04:03:12 PM) (Source: Service Control Manager) (User: ) Description: Dienst "Avira Browser-Schutz" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error: (09/08/2013 00:26:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Browser-Schutz" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/08/2013 10:21:47 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Browser-Schutz" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/08/2013 10:17:35 AM) (Source: nvlddmkm) (User: ) Description: \Device\Video5!06d7(2648) Error: (09/08/2013 10:14:34 AM) (Source: nvlddmkm) (User: ) Description: \Device\Video5!06d7(2648) Error: (09/08/2013 10:12:47 AM) (Source: nvlddmkm) (User: ) Description: \Device\Video5!06d7(2648) Error: (09/08/2013 09:40:40 AM) (Source: nvlddmkm) (User: ) Description: \Device\Video5!06d7(2648) Error: (09/07/2013 07:43:39 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Browser-Schutz" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/05/2013 07:35:56 AM) (Source: nvlddmkm) (User: ) Description: \Device\Video5CMDre 00000001 00000080 00000000 00000005 0000000b Error: (09/05/2013 07:35:43 AM) (Source: nvlddmkm) (User: ) Description: \Device\Video5CMDre 00000001 00000080 00000000 00000005 0000000b Microsoft Office Sessions: ========================= Error: (09/09/2013 00:48:02 PM) (Source: Application Error)(User: ) Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.1820551db9710c00000050002e243e3401cead4a0d37c596C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dll4c374ae6-193d-11e3-a9d1-1c6f653805d7 Error: (09/09/2013 11:48:02 AM) (Source: Application Error)(User: ) Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.1820551db9710c00000050002e243f9801cead41ab752937C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dllea5e4b1b-1934-11e3-a9d1-1c6f653805d7 Error: (09/09/2013 11:44:11 AM) (Source: Application Hang)(User: ) Description: launcher.exe1.0.0.1101401cead3ff6dacb972652C:\Program Files (x86)\theHunter\launcher\launcher.exe5dbd2424-1934-11e3-a9d1-1c6f653805d7 Error: (09/09/2013 11:20:32 AM) (Source: Application Error)(User: ) Description: A3FB.tmp0.0.0.052236ca0KERNELBASE.dll6.1.7601.1801550b83c8ae06d73630000c41f8fc01cead3dc67dfc59C:\Windows\TEMP\A3FB.tmpC:\Windows\syswow64\KERNELBASE.dll12e50aeb-1931-11e3-a9d1-1c6f653805d7 Error: (09/09/2013 00:48:02 AM) (Source: Application Error)(User: ) Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.1820551db9710c00000050002e2432f401ceace57801b45aC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dllb6d43591-18d8-11e3-a761-1c6f653805d7 Error: (09/08/2013 11:55:32 PM) (Source: Application Error)(User: ) Description: RE5DX10.exe1.0.0.1294a531c50d3d11.dll6.2.9200.165705153774dc0000005000a517615c001ceacd82916d8f6C:\Program Files (x86)\Steam\steamapps\common\Resident Evil 5\RE5DX10.exeC:\Windows\system32\d3d11.dll6148c922-18d1-11e3-a761-1c6f653805d7 Error: (09/08/2013 11:48:02 PM) (Source: Application Error)(User: ) Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.1820551db9710c00000050002e24314c001ceacdd163e1343C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dll55172442-18d0-11e3-a761-1c6f653805d7 Error: (09/08/2013 11:12:28 PM) (Source: Application Error)(User: ) Description: RE5DX10.exe1.0.0.1294a531c50d3d11.dll6.2.9200.165705153774dc0000005000a51766f001ceacd7f457b9aeC:\Program Files (x86)\Steam\steamapps\common\Resident Evil 5\RE5DX10.exeC:\Windows\system32\d3d11.dll5d996e45-18cb-11e3-a761-1c6f653805d7 Error: (09/08/2013 11:10:48 PM) (Source: Application Error)(User: ) Description: RE5DX10.exe1.0.0.1294a531c50d3d11.dll6.2.9200.165705153774dc0000005000a517368001ceacd460b2fdc1C:\Program Files (x86)\Steam\steamapps\common\Resident Evil 5\RE5DX10.exeC:\Windows\system32\d3d11.dll2185d3f4-18cb-11e3-a761-1c6f653805d7 Error: (09/08/2013 10:48:02 PM) (Source: Application Error)(User: ) Description: FlashPlayerUpdateService.exe11.6.602.18051a4ab8cntdll.dll6.1.7601.1820551db9710c00000050002e2435c001ceacd4b47939a7C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeC:\Windows\SysWOW64\ntdll.dllf354bbb0-18c7-11e3-a761-1c6f653805d7 ==================== Memory info =========================== Percentage of memory in use: 31% Total physical RAM: 6142.49 MB Available physical RAM: 4193.61 MB Total Pagefile: 12283.17 MB Available Pagefile: 9401.23 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:463.4 GB) (Free:233.83 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (.:BACK UPS:.) (Fixed) (Total:48.83 GB) (Free:42.15 GB) NTFS Drive e: (.:DLC:.) (Fixed) (Total:214.21 GB) (Free:57.08 GB) NTFS Drive f: (.:ANWENDUNGEN:.) (Fixed) (Total:146.48 GB) (Free:145.96 GB) NTFS Drive g: (.:MUSIK:.) (Fixed) (Total:146.48 GB) (Free:93.61 GB) NTFS Drive h: (.:FAMILIEN BILDER:.) (Fixed) (Total:123.96 GB) (Free:20.98 GB) NTFS Drive i: (.:GAMES:.) (Fixed) (Total:244.14 GB) (Free:40.1 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: C9E50A11) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=463 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=214 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=244 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 60866086) Partition 1: (Active) - (Size=49 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=417 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
09.09.2013, 17:34 | #4 | |
/// the machine /// TB-Ausbilder | dllhost belegt kompletten Arbeitsspeicher, Virus?Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu dllhost belegt kompletten Arbeitsspeicher, Virus? |
adobe, adobe flash player, arbeitsspeicher, avg, avira, avira searchfree toolbar, bho, bonjour, desktop, dllhost, explorer, flash player, google, helper, hijack, hkus\s-1-5-18, internet, internet explorer, logfiles, lsass.exe, microsoft, mozilla, nvidia, object, opera, plug-in, software, virus, virus?, warum, windows |