|
Log-Analyse und Auswertung: Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) IIWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
24.11.2013, 16:30 | #1 |
| Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Hallo, ich hatte in folgendem Thema vor ein paar Tagen meine Problem geschildert. http://www.trojaner-board.de/144830-...r-youtube.html Am 22.11.2013 war noch alles in Ordnung. Ein Tag später hab ich jetzt wieder exakt die gleichen Symptome. 1. Rechner fährt nicht mehr automatisch in Standby 2. YouTube spinnt ab und zu. defogger Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 16:14 on 24/11/2013 (Christian) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-11-2013 Ran by Christian (administrator) on CHRIS-PC on 24-11-2013 16:16:34 Running from I:\Dateien\Documents\Computer Windows 8.1 Pro (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (FileZilla Project) C:\xampp\FileZillaFTP\FileZillaServer.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe () C:\xampp\mysql\bin\mysqld.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20279_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Microsoft Corporation) I:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Microsoft Corporation) C:\Windows\WinStore\WSHost.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe (LG Electronics) C:\Program Files (x86)\LG Soft India\Screen Split\bin\ScreenSplit.exe (TODO: <Company name>) C:\Program Files (x86)\LG Soft India\Screen Split\bin\ScreenSplitterHook64App.exe (Dropbox, Inc.) C:\Users\Christian\AppData\Roaming\Dropbox\bin\Dropbox.exe () C:\Program Files\WindowsApps\BE5914B3.F1World_1.0.0.3_x64__dqknxmbjx6sd6\F1World.exe (Microsoft Corporation) C:\Windows\Camera\Camera.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_fa1dc1539b4180d8\TiWorker.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [CDAServer] - C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] () HKCU\...\Run: [ScreenSplitter] - C:\Program Files (x86)\LG Soft India\Screen Split\bin\ScreenSplit.exe [392192 2013-01-16] (LG Electronics) HKCU\...\Run: [BrowserChoice] - C:\Windows\BrowserChoice\browserchoice.exe [86816 2013-08-22] (Microsoft Corporation) HKCU\...\Run: [SkyDrive] - C:\Users\Christian\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257136 2013-08-14] (Microsoft Corporation) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Christian\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-11-23] (Spotify Ltd) HKCU\...\Run: [ISUSPM Startup] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [PDFPrint] - I:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] () Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> I:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?PC=BNSR BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\lvqn9hid.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\lvqn9hid.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-04-29] (Advanced Micro Devices, Inc.) R2 Apache2.4; C:\xampp\apache\bin\httpd.exe [22016 2012-08-18] (Apache Software Foundation) R2 FileZillaServer; C:\xampp\filezillaftp\filezillaserver.exe [632320 2012-05-11] (FileZilla Project) S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) R2 mysql; C:\xampp\mysql\bin\mysqld.exe [8186368 2012-07-20] () S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [36352 2010-08-20] () S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-10-08] (Microsoft Corporation) S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] () R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146272 2013-08-22] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-24 16:16 - 2013-11-24 16:16 - 00000000 ____D C:\FRST 2013-11-24 16:14 - 2013-11-24 16:14 - 00000000 _____ C:\Users\Christian\defogger_reenable 2013-11-22 07:49 - 2013-11-22 07:49 - 00000931 _____ C:\Users\Christian\Desktop\DHBW.lnk 2013-11-22 07:47 - 2013-11-22 07:47 - 13321769 _____ C:\Users\Christian\Downloads\PanoramicMountains.deskthemepack 2013-11-21 18:49 - 2013-11-21 18:50 - 00000771 _____ C:\DelFix.txt 2013-11-21 06:48 - 2013-11-21 06:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-19 13:37 - 2013-11-21 18:49 - 00000000 ____D C:\WINDOWS\ERUNT 2013-11-19 13:30 - 2013-11-19 13:32 - 00000000 ____D C:\AdwCleaner 2013-11-16 07:17 - 2013-10-10 12:26 - 02801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2013-11-16 07:17 - 2013-10-10 12:05 - 01019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2013-11-16 07:17 - 2013-10-10 11:34 - 01085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2013-11-16 07:17 - 2013-10-10 11:27 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2013-11-16 07:16 - 2013-11-05 21:21 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2013-11-16 07:16 - 2013-11-05 19:51 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2013-11-16 07:16 - 2013-11-05 17:20 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2013-11-16 07:16 - 2013-11-05 17:11 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2013-11-16 07:16 - 2013-11-05 15:30 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2013-11-16 07:16 - 2013-11-05 15:29 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2013-11-16 07:16 - 2013-10-23 12:29 - 00044936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll 2013-11-16 07:16 - 2013-10-23 12:21 - 00155480 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys 2013-11-16 07:16 - 2013-10-23 12:13 - 00171864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_8086.dll 2013-11-16 07:16 - 2013-10-23 06:27 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-11-16 07:16 - 2013-10-23 06:09 - 04104704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll 2013-11-16 07:16 - 2013-10-23 06:04 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-11-16 07:16 - 2013-10-23 05:55 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2013-11-16 07:16 - 2013-10-23 05:46 - 00700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2013-11-16 07:16 - 2013-10-22 09:18 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2013-11-16 07:16 - 2013-10-22 09:18 - 00096088 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedapplauncher.exe 2013-11-16 07:16 - 2013-10-22 08:55 - 02328872 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2013-11-16 07:16 - 2013-10-22 07:03 - 02065448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2013-11-16 07:16 - 2013-10-22 06:15 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll 2013-11-16 07:16 - 2013-10-22 05:04 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll 2013-11-16 07:16 - 2013-10-22 05:02 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2013-11-16 07:16 - 2013-10-22 04:56 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll 2013-11-16 07:16 - 2013-10-22 04:44 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll 2013-11-16 07:16 - 2013-10-22 03:38 - 01362944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2013-11-16 07:16 - 2013-10-22 03:22 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2013-11-16 07:16 - 2013-10-22 03:13 - 01704448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2013-11-16 07:16 - 2013-10-22 03:07 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2013-11-16 07:16 - 2013-10-22 02:53 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2013-11-16 07:16 - 2013-10-22 02:47 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2013-11-16 07:16 - 2013-10-19 10:13 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2013-11-16 07:16 - 2013-10-19 09:51 - 00481392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2013-11-16 07:16 - 2013-10-19 08:12 - 00380656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2013-11-16 07:16 - 2013-10-19 07:24 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2013-11-16 07:16 - 2013-10-19 05:48 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2013-11-16 07:16 - 2013-10-19 05:03 - 00531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2013-11-16 07:16 - 2013-10-19 04:57 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2013-11-16 07:16 - 2013-10-19 04:28 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2013-11-16 07:16 - 2013-10-19 04:26 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2013-11-16 07:16 - 2013-10-19 04:14 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2013-11-16 07:16 - 2013-10-17 16:42 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2013-11-16 07:16 - 2013-10-17 16:42 - 01373872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2013-11-16 07:16 - 2013-10-17 15:04 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2013-11-16 07:16 - 2013-10-16 10:34 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2013-11-16 07:16 - 2013-10-16 10:33 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2013-11-16 07:16 - 2013-10-13 04:06 - 00258904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys 2013-11-16 07:16 - 2013-10-13 03:43 - 00708616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll 2013-11-16 07:16 - 2013-10-11 16:11 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll 2013-11-16 07:16 - 2013-10-11 15:22 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll 2013-11-16 07:16 - 2013-10-11 14:24 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2013-11-16 07:16 - 2013-10-11 14:04 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 2013-11-16 07:16 - 2013-10-11 14:03 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2013-11-16 07:16 - 2013-10-10 17:44 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll 2013-11-16 07:16 - 2013-10-10 17:26 - 00317616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2013-11-16 07:16 - 2013-10-10 17:26 - 00104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll 2013-11-16 07:16 - 2013-10-10 17:23 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2013-11-16 07:16 - 2013-10-10 15:53 - 00235960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2013-11-16 07:16 - 2013-10-10 15:53 - 00088272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll 2013-11-16 07:16 - 2013-10-10 12:53 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2013-11-16 07:16 - 2013-10-10 12:38 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2013-11-16 07:16 - 2013-10-10 12:21 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2013-11-16 07:16 - 2013-10-10 11:40 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2013-11-16 07:16 - 2013-10-10 11:19 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2013-11-16 07:16 - 2013-10-09 06:40 - 00385528 _____ C:\WINDOWS\system32\ApnDatabase.xml 2013-11-16 07:16 - 2013-10-08 12:07 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 2013-11-16 07:16 - 2013-10-08 11:28 - 00523096 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys 2013-11-16 07:16 - 2013-10-08 11:13 - 02551640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2013-11-16 07:16 - 2013-10-08 07:46 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll 2013-11-16 07:16 - 2013-10-08 06:58 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll 2013-11-16 07:16 - 2013-10-08 06:50 - 00656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 2013-11-16 07:16 - 2013-10-08 06:48 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 2013-11-16 07:16 - 2013-10-08 06:15 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll 2013-11-16 07:16 - 2013-10-08 06:09 - 01160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll 2013-11-16 07:16 - 2013-10-08 05:50 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll 2013-11-16 07:16 - 2013-10-08 05:50 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2013-11-16 07:16 - 2013-10-07 08:21 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2013-11-16 07:16 - 2013-10-07 08:21 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2013-11-16 07:16 - 2013-10-07 03:13 - 03532288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2013-11-16 07:16 - 2013-10-05 16:25 - 00371032 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 2013-11-16 07:16 - 2013-10-05 16:25 - 00057176 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys 2013-11-16 07:16 - 2013-10-05 15:21 - 00699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll 2013-11-16 07:16 - 2013-10-05 13:05 - 00578952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll 2013-11-16 07:16 - 2013-10-05 12:01 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys 2013-11-16 07:16 - 2013-10-05 10:36 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe 2013-11-16 07:16 - 2013-10-05 10:18 - 01011712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2013-11-16 07:16 - 2013-10-05 10:07 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2013-11-16 07:16 - 2013-10-05 09:56 - 01147904 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2013-11-16 07:16 - 2013-10-05 09:55 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\miutils.dll 2013-11-16 07:16 - 2013-10-05 09:40 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll 2013-11-16 07:16 - 2013-10-05 09:24 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miutils.dll 2013-11-16 07:16 - 2013-10-05 09:21 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2013-11-16 07:16 - 2013-10-05 09:15 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll 2013-11-16 07:16 - 2013-10-05 08:43 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll 2013-11-16 07:16 - 2013-10-05 08:39 - 06639616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2013-11-16 07:16 - 2013-10-05 08:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-11-16 07:16 - 2013-10-05 08:32 - 05769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2013-11-16 07:16 - 2013-10-04 09:10 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2013-11-16 07:16 - 2013-09-19 06:04 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll 2013-11-16 07:16 - 2013-09-17 10:06 - 01067080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2013-11-16 07:16 - 2013-09-17 10:06 - 00465960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2013-11-16 07:16 - 2013-09-17 07:31 - 00883184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2013-11-16 07:16 - 2013-09-17 07:31 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2013-11-16 07:16 - 2013-09-17 05:37 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2013-11-16 07:16 - 2013-09-14 15:07 - 02134120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2013-11-16 07:16 - 2013-09-14 15:00 - 00391512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll 2013-11-16 07:16 - 2013-09-14 13:39 - 01799944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2013-11-16 07:16 - 2013-09-14 13:33 - 00345552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll 2013-11-16 07:16 - 2013-09-14 11:05 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe 2013-11-16 07:16 - 2013-09-14 10:11 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll 2013-11-16 07:16 - 2013-09-13 09:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ftp.exe 2013-11-16 07:16 - 2013-09-13 08:47 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ftp.exe 2013-11-16 07:16 - 2013-09-12 09:45 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll 2013-11-16 07:16 - 2013-09-12 09:08 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll 2013-11-16 07:16 - 2013-09-12 09:08 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2013-11-16 07:16 - 2013-09-12 09:02 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll 2013-11-16 07:16 - 2013-09-12 08:44 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll 2013-11-16 07:16 - 2013-09-12 08:37 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll 2013-11-16 07:16 - 2013-09-12 08:37 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll 2013-11-16 07:16 - 2013-09-12 08:21 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll 2013-11-16 07:16 - 2013-09-12 08:16 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll 2013-11-16 07:16 - 2013-09-12 08:01 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll 2013-11-16 07:16 - 2013-09-11 13:46 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2013-11-16 07:16 - 2013-09-10 06:26 - 04599808 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2013-11-16 07:16 - 2013-09-10 05:52 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msched.dll 2013-11-16 07:16 - 2013-09-10 05:34 - 03934208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Roaming\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\AMD 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\ProgramData\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-11-14 14:32 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files\ATI Technologies 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\ProgramData\AMD 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files\ATI 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-11-14 14:04 - 2013-11-14 14:04 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2013-11-14 14:04 - 2013-10-19 09:08 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2013-11-14 14:04 - 2013-10-19 07:37 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2013-11-14 14:04 - 2013-10-19 07:02 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2013-11-14 14:04 - 2013-10-19 06:37 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe 2013-11-14 14:04 - 2013-10-19 06:19 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2013-11-14 14:04 - 2013-10-19 06:10 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2013-11-14 14:04 - 2013-10-19 05:52 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2013-11-14 14:04 - 2013-10-19 05:44 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2013-11-14 14:04 - 2013-10-19 05:37 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2013-11-14 14:04 - 2013-10-19 05:31 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2013-11-14 14:04 - 2013-10-19 04:56 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2013-11-14 14:04 - 2013-10-19 04:55 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2013-11-14 14:04 - 2013-10-19 04:53 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2013-11-14 14:04 - 2013-10-19 04:23 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2013-11-14 14:04 - 2013-10-19 04:09 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2013-11-14 14:04 - 2013-10-19 04:02 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2013-11-14 14:04 - 2013-10-13 03:48 - 00136536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys 2013-11-14 14:04 - 2013-10-12 22:48 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 2013-11-14 14:04 - 2013-10-12 22:34 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2013-11-14 14:04 - 2013-10-05 15:21 - 01341288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2013-11-14 14:04 - 2013-10-05 09:39 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2013-11-14 14:03 - 2013-11-14 14:03 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2013-11-14 14:01 - 2013-10-16 16:58 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2013-11-14 14:01 - 2013-10-16 14:54 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2013-11-10 12:17 - 2013-11-10 12:17 - 00001392 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse-php.lnk 2013-11-10 12:12 - 2013-11-10 12:14 - 00000242 _____ C:\WINDOWS\pear.ini 2013-11-10 11:05 - 2013-11-10 11:05 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Friends 2013-11-10 02:09 - 2013-11-12 20:29 - 00001351 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Git Lacker.lnk 2013-11-01 16:36 - 2013-11-01 16:36 - 00000313 _____ C:\Users\Christian\.JMAppsCfg 2013-11-01 16:23 - 2013-11-01 16:23 - 05218242 _____ (InstallShield Software Corporation) C:\Users\Christian\Downloads\jmf-2_1_1e-windows-i586.exe 2013-11-01 16:23 - 1998-01-23 12:22 - 00304128 _____ (InstallShield Software Corporation) C:\WINDOWS\IsUninst.exe 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Malwarebytes 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-01 10:00 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2013-10-31 14:39 - 2013-10-31 14:39 - 00000000 ____D C:\ProgramData\Oracle 2013-10-31 14:38 - 2013-10-31 14:39 - 00004249 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-29 07:01 - 2013-10-23 12:01 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2013-10-29 07:01 - 2013-10-23 09:59 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll ==================== One Month Modified Files and Folders ======= 2013-11-24 16:16 - 2013-11-24 16:16 - 00000000 ____D C:\FRST 2013-11-24 16:15 - 2013-07-31 15:57 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-11-24 16:14 - 2013-11-24 16:14 - 00000000 _____ C:\Users\Christian\defogger_reenable 2013-11-24 16:14 - 2013-10-21 09:37 - 01917882 _____ C:\WINDOWS\WindowsUpdate.log 2013-11-24 16:14 - 2013-10-21 09:15 - 00000000 ____D C:\Users\Christian 2013-11-24 16:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru 2013-11-24 15:27 - 2013-10-21 09:45 - 00003946 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{61128387-B861-4393-83E1-DF07BADD9687} 2013-11-24 13:49 - 2013-10-22 12:32 - 00005148 _____ C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for CHRIS-PC-Christian Chris-PC 2013-11-24 13:02 - 2013-10-04 10:49 - 00000572 _____ C:\WINDOWS\Tasks\MATLAB R2013b Startup Accelerator.job 2013-11-24 12:19 - 2013-10-07 14:38 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Dropbox 2013-11-24 11:27 - 2013-05-04 16:45 - 00000000 ____D C:\Users\Christian\.VirtualBox 2013-11-24 10:12 - 2013-07-31 15:59 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2496160165-2463586998-2347050423-1001 2013-11-24 09:07 - 2013-01-14 18:06 - 00000000 __RDO C:\Users\Christian\SkyDrive 2013-11-23 20:36 - 2013-08-14 15:18 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Spotify 2013-11-23 20:35 - 2013-08-14 15:18 - 00000000 ____D C:\Users\Christian\AppData\Local\Spotify 2013-11-22 07:49 - 2013-11-22 07:49 - 00000931 _____ C:\Users\Christian\Desktop\DHBW.lnk 2013-11-22 07:47 - 2013-11-22 07:47 - 13321769 _____ C:\Users\Christian\Downloads\PanoramicMountains.deskthemepack 2013-11-21 18:54 - 2013-09-30 05:14 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-11-21 18:54 - 2013-09-30 04:56 - 00764340 _____ C:\WINDOWS\system32\perfh007.dat 2013-11-21 18:54 - 2013-09-30 04:56 - 00159160 _____ C:\WINDOWS\system32\perfc007.dat 2013-11-21 18:50 - 2013-11-21 18:49 - 00000771 _____ C:\DelFix.txt 2013-11-21 18:50 - 2013-09-29 20:04 - 00028796 _____ C:\WINDOWS\PFRO.log 2013-11-21 18:50 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-11-21 18:50 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2013-11-21 18:50 - 2013-07-31 16:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-21 18:49 - 2013-11-19 13:37 - 00000000 ____D C:\WINDOWS\ERUNT 2013-11-21 18:35 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness 2013-11-21 06:48 - 2013-11-21 06:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-19 19:38 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache 2013-11-19 13:34 - 2013-08-22 15:44 - 00411576 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-11-19 13:34 - 2013-07-31 15:54 - 00000000 ___RD C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-19 13:34 - 2013-07-31 15:54 - 00000000 ___RD C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-11-19 13:34 - 2013-01-15 18:39 - 00000000 ___RD C:\Users\Christian\Podcasts 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ___RD C:\WINDOWS\ToastData 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\migwiz 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2013-11-19 13:32 - 2013-11-19 13:30 - 00000000 ____D C:\AdwCleaner 2013-11-19 11:30 - 2013-08-01 16:53 - 00267936 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2013-11-16 09:11 - 2013-07-31 17:06 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-16 07:41 - 2013-02-15 15:55 - 00000000 ____D C:\xampp 2013-11-16 07:29 - 2013-10-21 09:13 - 00013914 _____ C:\WINDOWS\system32\lvcoinst.log 2013-11-15 15:30 - 2013-08-29 21:01 - 00001782 ____H C:\Users\Christian\.gitk 2013-11-14 18:06 - 2013-01-14 17:12 - 00000000 ____D C:\Users\Christian\AppData\Local\Packages 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Roaming\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\AMD 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\ProgramData\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-11-14 14:33 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files\ATI Technologies 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\ProgramData\AMD 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files\ATI 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-11-14 14:11 - 2013-08-07 17:22 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-11-14 14:10 - 2013-08-01 17:03 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2013-11-14 14:04 - 2013-11-14 14:04 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2013-11-14 14:03 - 2013-11-14 14:03 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2013-11-12 20:29 - 2013-11-10 02:09 - 00001351 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Git Lacker.lnk 2013-11-10 12:42 - 2013-10-03 14:58 - 00001332 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse.lnk 2013-11-10 12:42 - 2013-10-03 07:44 - 00000000 ____D C:\Users\Christian\.eclipse 2013-11-10 12:17 - 2013-11-10 12:17 - 00001392 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse-php.lnk 2013-11-10 12:14 - 2013-11-10 12:12 - 00000242 _____ C:\WINDOWS\pear.ini 2013-11-10 11:05 - 2013-11-10 11:05 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Friends 2013-11-10 11:04 - 2013-10-03 08:21 - 00000000 ____D C:\Program Files (x86)\eclipse 2013-11-10 02:18 - 2013-07-24 17:05 - 00000000 ____D C:\Users\Christian\.ssh 2013-11-06 00:31 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2013-11-06 00:31 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-05 21:21 - 2013-11-16 07:16 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2013-11-05 19:51 - 2013-11-16 07:16 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2013-11-05 17:20 - 2013-11-16 07:16 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2013-11-05 17:11 - 2013-11-16 07:16 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2013-11-05 15:30 - 2013-11-16 07:16 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2013-11-05 15:29 - 2013-11-16 07:16 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2013-11-05 08:07 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2013-11-01 16:36 - 2013-11-01 16:36 - 00000313 _____ C:\Users\Christian\.JMAppsCfg 2013-11-01 16:23 - 2013-11-01 16:23 - 05218242 _____ (InstallShield Software Corporation) C:\Users\Christian\Downloads\jmf-2_1_1e-windows-i586.exe 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Malwarebytes 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-31 14:39 - 2013-10-31 14:39 - 00000000 ____D C:\ProgramData\Oracle 2013-10-31 14:39 - 2013-10-31 14:38 - 00004249 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-31 14:39 - 2013-10-03 08:30 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-29 11:33 - 2013-07-31 17:06 - 00000000 ____D C:\Users\Christian\AppData\Local\Microsoft Help Some content of TEMP: ==================== C:\Users\Christian\AppData\Local\Temp\Dragon.exe C:\Users\Christian\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Christian\AppData\Local\Temp\npp.6.5.Installer.exe C:\Users\Christian\AppData\Local\Temp\ose00000.exe C:\Users\Christian\AppData\Local\Temp\Quarantine.exe C:\Users\Christian\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe [2013-11-16 07:16] - [2013-10-22 08:55] - 2328872 ____A (Microsoft Corporation) 63DC38C3E4564B2405D562855643ABA2 C:\Windows\SysWOW64\explorer.exe [2013-11-16 07:16] - [2013-10-22 07:03] - 2065448 ____A (Microsoft Corporation) 1A0BC9598E4A58FC84570FFF5A108E58 C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll [2013-11-16 07:16] - [2013-10-22 03:38] - 1362944 ____A (Microsoft Corporation) C72456BFFE941714CF05B0AA0BEE5B45 C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-21 19:01 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-11-2013 Ran by Christian at 2013-11-24 16:17:02 Running from I:\Dateien\Documents\Computer Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Tools for .Net 3.5 - DEU Lang Pack (x32 Version: 3.11.50727) Tools for .Net 3.5 (x32 Version: 3.11.50727) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) AMD Accelerated Video Transcoding (Version: 12.5.100.30429) AMD APP SDK Runtime (Version: 10.0.937.2) AMD Catalyst Install Manager (Version: 8.0.877.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Fuel (Version: 2013.0429.2313.39747) AMD Media Foundation Decoders (Version: 1.0.80430.0002) AMD VISION Engine Control Center (x32 Version: 2013.0429.2313.39747) Anno 1701 (x32 Version: 1.02) Blend for Visual Studio 2012 (x32 Version: 5.0.30709.0) Blend for Visual Studio 2012 DEU resources (x32 Version: 5.0.30709.0) Blend for Visual Studio Add-in for Adobe FXG Import (x32 Version: 1.0.40218.0) Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0) Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0429.2313.39747) Catalyst Control Center InstallProxy (x32 Version: 2013.0429.2313.39747) Catalyst Control Center Localization All (x32 Version: 2013.0429.2313.39747) CCC Help Chinese Standard (x32 Version: 2013.0429.2312.39747) CCC Help Chinese Traditional (x32 Version: 2013.0429.2312.39747) CCC Help Czech (x32 Version: 2013.0429.2312.39747) CCC Help Danish (x32 Version: 2013.0429.2312.39747) CCC Help Dutch (x32 Version: 2013.0429.2312.39747) CCC Help English (x32 Version: 2013.0429.2312.39747) CCC Help Finnish (x32 Version: 2013.0429.2312.39747) CCC Help French (x32 Version: 2013.0429.2312.39747) CCC Help German (x32 Version: 2013.0429.2312.39747) CCC Help Greek (x32 Version: 2013.0429.2312.39747) CCC Help Hungarian (x32 Version: 2013.0429.2312.39747) CCC Help Italian (x32 Version: 2013.0429.2312.39747) CCC Help Japanese (x32 Version: 2013.0429.2312.39747) CCC Help Korean (x32 Version: 2013.0429.2312.39747) CCC Help Norwegian (x32 Version: 2013.0429.2312.39747) CCC Help Polish (x32 Version: 2013.0429.2312.39747) CCC Help Portuguese (x32 Version: 2013.0429.2312.39747) CCC Help Russian (x32 Version: 2013.0429.2312.39747) CCC Help Spanish (x32 Version: 2013.0429.2312.39747) CCC Help Swedish (x32 Version: 2013.0429.2312.39747) CCC Help Thai (x32 Version: 2013.0429.2312.39747) CCC Help Turkish (x32 Version: 2013.0429.2312.39747) ccc-utility64 (Version: 2013.0429.2313.39747) Common Desktop Agent (Version: 1.62.0) CVE-2013-3893 Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Definition Update for Microsoft Office 2013 (KB2760587) 32-Bit Edition (x32) Devenv-Ressourcen für Microsoft Visual Studio 2012 (x32 Version: 11.0.50727) Dota 2 (x32) Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4521.29298) Dotfuscator and Analytics Community Edition Language Pack (x32 Version: 5.5.4521.29298) Dropbox (HKCU Version: 2.4.2) Entity Framework Designer für Visual Studio 2012 - DEU (x32 Version: 11.1.21009.00) Erforderliche Komponenten für SSDT (x32 Version: 11.0.2100.60) GIMP 2.8.6 (Version: 2.8.6) Git version 1.8.3-preview20130601 (x32 Version: 1.8.3-preview20130601) Greenshot 1.1.5.2643 (Version: 1.1.5.2643) IIS 8.0 Express (Version: 8.0.1557) IIS Express Application Compatibility Database for x64 IIS Express Application Compatibility Database for x86 Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) Java SE Development Kit 7 Update 40 (x32 Version: 1.7.0.400) JavaScript Tooling (Version: 11.0.60315) JavaScript Tooling (x32 Version: 11.0.60315) LocalESPC (x32 Version: 8.59.25584) LocalESPCui for de-de (x32 Version: 8.59.25584) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) MATLAB R2013b (Version: 8.2) Microsoft .NET Framework 4 Multi-Targeting Pack (x32 Version: 4.0.30319) Microsoft .NET Framework 4.5 Multi-Targeting Pack (x32 Version: 4.5.50709) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (x32 Version: 4.5.50709) Microsoft .NET Framework 4.5 SDK (x32 Version: 4.5.50709) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft ASP.NET MVC 3 - DEU (x32 Version: 3.0.20105.0) Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update - DEU (x32 Version: 3.0.30710.0) Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update (x32 Version: 3.0.30710.0) Microsoft ASP.NET MVC 3 (x32 Version: 3.0.20105.0) Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools - DEU (x32 Version: 4.1.20219.0) Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools - ENU (x32 Version: 4.1.20219.0) Microsoft ASP.NET MVC 4 Runtime - DEU (x32 Version: 4.0.20710.0) Microsoft ASP.NET MVC 4 Runtime (x32 Version: 4.0.20710.0) Microsoft ASP.NET Web Pages - DEU (x32 Version: 1.0.20105.0) Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools - DEU (x32 Version: 1.0.20710.0) Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools (x32 Version: 1.0.20710.0) Microsoft ASP.NET Web Pages (x32 Version: 1.0.20105.0) Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools - DEU (x32 Version: 4.1.20219.0) Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools - ENU (x32 Version: 4.1.20219.0) Microsoft ASP.NET Web Pages 2 Runtime - DEU (x32 Version: 2.0.20710.0) Microsoft ASP.NET Web Pages 2 Runtime (x32 Version: 2.0.20715.0) Microsoft Expression Blend SDK for .NET 4 (x32 Version: 2.0.20525.0) Microsoft Expression Blend SDK for Silverlight 4 (x32 Version: 2.0.20525.0) Microsoft Help Viewer 2.0 (x32 Version: 2.0.50727) Microsoft Help Viewer 2.0 Language Pack - DEU (x32 Version: 2.0.50727) Microsoft LightSwitch for Visual Studio 2012 Core (x32 Version: 11.0.50727) Microsoft LightSwitch for Visual Studio 2012 v3.0 Core (x32 Version: 11.0.60517) Microsoft LightSwitch for Visual Studio 2012 v3.0 CoreRes - DEU (x32 Version: 11.0.60517) Microsoft LightSwitch für Visual Studio 2012 CoreRes - DEU (x32 Version: 11.0.50727) Microsoft NuGet - Visual Studio 2012 (x32 Version: 2.0.30625.9003) Microsoft Office 64-bit Components 2013 (Version: 15.0.4420.1017) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Korrekturhilfen 2013 - Deutsch (x32 Version: 15.0.4420.1017) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office OSM MUI (German) 2013 (x32 Version: 15.0.4420.1017) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Professional 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proofing (German) 2013 (x32 Version: 15.0.4420.1017) Microsoft Office Proofing Tools 2013 - English (x32 Version: 15.0.4420.1017) Microsoft Office Proofing Tools 2013 - Italiano (x32 Version: 15.0.4420.1017) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Shared 64-bit MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Shared MUI (German) 2013 (x32 Version: 15.0.4420.1017) Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Visio MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft OneNote 2013 (x32 Version: 15.0.4420.1017) Microsoft OneNote MUI (German) 2013 (x32 Version: 15.0.4420.1017) Microsoft Portable Library Multi-Targeting Pack (x32 Version: 11.0.60418.17931) Microsoft Portable Library Multi-Targeting Pack Language Pack - deu (x32 Version: 11.0.50709.17929) Microsoft Report Viewer Add-On for Visual Studio 2012 (x32 Version: 11.1.2802.16) Microsoft Report Viewer Add-On für Visual Studio 2012 (x32 Version: 11.1.2802.16) Microsoft Silverlight 4 SDK - Deutsch (x32 Version: 4.0.60310.0) Microsoft Silverlight 5 SDK - DEU (x32 Version: 5.0.61118.0) Microsoft SkyDrive (HKCU Version: 17.0.2015.0811) Microsoft SQL Server 2012 Command Line Utilities (Version: 11.0.2100.60) Microsoft SQL Server 2012 Data-Tier App Framework (Version: 11.0.2316.0) Microsoft SQL Server 2012 Data-Tier App Framework (x32 Version: 11.0.2316.0) Microsoft SQL Server 2012 Express LocalDB (Version: 11.0.2100.60) Microsoft SQL Server 2012 Management Objects (x32 Version: 11.0.2100.60) Microsoft SQL Server 2012 Management Objects (x64) (Version: 11.0.2100.60) Microsoft SQL Server 2012 Native Client (Version: 11.0.2100.60) Microsoft SQL Server 2012 Transact-SQL Compiler Service (Version: 11.0.2100.60) Microsoft SQL Server 2012 Transact-SQL ScriptDom (Version: 11.0.2100.60) Microsoft SQL Server 2012 T-SQL Language Service (x32 Version: 11.0.2100.60) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (Version: 4.0.8876.1) Microsoft SQL Server Data Tools - DEU (11.1.20627.00) (x32 Version: 11.1.20627.00) Microsoft SQL Server Data Tools Build Utilities - DEU (11.1.20627.00) (x32 Version: 11.1.20627.00) Microsoft SQL Server System CLR Types (x32 Version: 10.50.1600.1) Microsoft SQL Server System CLR Types (x64) (Version: 10.50.1600.1) Microsoft Visio MUI (German) 2013 (x32 Version: 15.0.4420.1017) Microsoft Visio Professional 2013 (x32 Version: 15.0.4420.1017) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 x64 Designtime - 11.0.50727 (Version: 11.0.50727) Microsoft Visual C++ 2012 32bit Compilers - DEU Resources (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 Compilers - DEU Resources (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 Compilers (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 Core Libraries (x32 Version: 11.0.51106) Microsoft Visual C++ 2012 Extended Libraries (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 Microsoft Foundation Class Libraries (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 x86-x64 Compilers (x32 Version: 11.0.60610) Microsoft Visual Studio 2010 Office Developer Tools (x64) (Version: 11.0.50727) Microsoft Visual Studio 2010 Office Developer Tools (x64) Language Pack - DEU (Version: 11.0.50727) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40303) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40308) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU (Version: 10.0.40303) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (Version: 10.0.40303) Microsoft Visual Studio 2012 Devenv (x32 Version: 11.0.50727) Microsoft Visual Studio 2012 IntelliTrace Core amd64 (Version: 11.0.60315) Microsoft Visual Studio 2012 IntelliTrace Core x86 (x32 Version: 11.0.60315) Microsoft Visual Studio 2012 IntelliTrace Front End x86 (x32 Version: 11.0.60315) Microsoft Visual Studio 2012 IntelliTraceFrontEndLoc (x32 Version: 11.0.60315) Microsoft Visual Studio 2012 IntelliTraceLoc (Version: 11.0.60315) Microsoft Visual Studio 2012 IntelliTraceLoc (x32 Version: 11.0.60315) Microsoft Visual Studio 2012 SharePoint Developer Tools (x32 Version: 11.0.50727) Microsoft Visual Studio 2012 SharePoint Developer Tools DEU Language Pack (x32 Version: 11.0.50727) Microsoft Visual Studio 2012 Shell (Minimum) (x32 Version: 11.0.50727) Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies (x32 Version: 11.0.50727) Microsoft Visual Studio 2012 Shell-(Mindest)-Ressourcen (x32 Version: 11.0.50727) Microsoft Visual Studio 2012 Tools für SQL Server Compact 4.0 SP1 DEU (x32 Version: 4.0.8876.1) Microsoft Visual Studio 2012-Leistungserfassungstools - DEU (Version: 11.0.50727) Microsoft Visual Studio 2012-Leistungserfassungstools (Version: 11.0.50727) Microsoft Visual Studio 2012-Vorbereitung (x32 Version: 11.0.50727) Microsoft Visual Studio Premium 2012 - DEU (x32 Version: 11.0.50727) Microsoft Visual Studio Premium 2012 (x32 Version: 11.0.50727) Microsoft Visual Studio Professional 2012 - DEU (x32 Version: 11.0.50727) Microsoft Visual Studio Professional 2012 (x32 Version: 11.0.50727) Microsoft Visual Studio Team Foundation Server 2012 Object Model (Version: 11.0.60610) Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - DEU (Version: 11.0.60610) Microsoft Visual Studio Team Foundation Server 2012 Storyboarding (Version: 11.0.50727) Microsoft Visual Studio Team Foundation Server 2012 Storyboarding Language Pack - DEU (Version: 11.0.50727) Microsoft Visual Studio Team Foundation Server 2012 Team Explorer (x32 Version: 11.0.50727) Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - DEU (x32 Version: 11.0.50727) Microsoft Visual Studio Ultimate 2012 - DEU (x32 Version: 11.0.50727) Microsoft Visual Studio Ultimate 2012 (x32 Version: 11.0.50727) Microsoft Visual Studio Ultimate 2012 (x32 Version: 11.0.50727.1) Microsoft Visual Studio Ultimate 2012 XAML UI Designer Core (x32 Version: 11.0.50727) Microsoft Visual Studio Ultimate 2012 XAML UI Designer deu Resources (x32 Version: 11.0.50727) Microsoft Web Deploy 3.0 (Version: 3.1236.1631) Microsoft Web Deploy dbSqlPackage Provider - DEU (x32 Version: 10.3.20225.0) Microsoft Web Developer Tools 2012.2 - Visual Studio 2012 - deu (x32 Version: 1.2.40308.0) Microsoft Web Developer Tools 2012.2 - Visual Studio 2012 (x32 Version: 1.2.40308.0) Microsoft Web Platform Installer 4.0 (Version: 4.0.1622) Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0) Microsoft-System-CLR-Typen für SQL Server 2012 (x32 Version: 11.0.2100.60) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (Version: 11.0.2100.60) Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1) Mozilla Maintenance Service (x32 Version: 25.0.1) Notepad++ (x32 Version: 6.5) OpenVPN 2.1.3 (x32 Version: 2.1.3) Oracle VM VirtualBox 4.2.18 (Version: 4.2.18) Outils de vérification linguistique 2013 de Microsoft Office*- Français (x32 Version: 15.0.4420.1017) PDF24 Creator 5.7.0 (x32) PreEmptive Analytics Client German Language Pack (x32 Version: 1.0.2180.1) PreEmptive Analytics Visual Studio Components (x32 Version: 1.0.2180.1) Samsung Easy Printer Manager (x32 Version: 1.03.45.01(17.06.2013)) Samsung Scan Assistant (x32 Version: 1.05.07 (20.07.2012)) Screen Split (x32 Version: 4.5) SDFormatter (x32 Version: 4.0.0) Secure Download Manager (x32 Version: 3.1.10) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32) Spotify (HKCU Version: 0.9.4.185.g7545a404) Steam (x32 Version: 1.0.0.0) TeamViewer 8 (x32 Version: 8.0.20202) Update for (KB2504637) (x32 Version: 1) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32) Update for Microsoft Lync 2013 (KB2825630) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2726954) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2726996) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2738038) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2760224) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2760242) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2760257) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2760267) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2760610) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2767845) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2768016) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2817309) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2817311) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2817490) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2817626) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2817640) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2827225) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2827230) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2827239) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2837643) 32-Bit Edition (x32) Update for Microsoft Office 2013 (KB2837649) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32) Update for Microsoft OneNote 2013 (KB2837642) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32) Update for Microsoft Project 2013 (KB2767859) 32-Bit Edition (x32) Update for Microsoft SkyDrive Pro (KB2837652) 32-Bit Edition (x32) Update for Microsoft Visio 2013 (KB2752018) 32-Bit Edition (x32) Update for Microsoft Visio 2013 (KB2810008) 32-Bit Edition (x32) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32) Update for Microsoft Visio Viewer 2013 (KB2768338) 32-Bit Edition (x32) Update for Microsoft Visual Studio 2012 (KB2781514) (x32 Version: 11.0.51219) Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32) Visual Studio 2012 Prerequisites - DEU Language Pack (Version: 11.0.50727) Visual Studio 2012 Prerequisites (Version: 11.0.50727) Visual Studio 2012 Update 3 (KB2707250) (x32 Version: 11.0.60610) Visual Studio Extensions for Windows Library for JavaScript (x32 Version: 1.0.9202.20789) Visual Studio Extensions for Windows Library for JavaScript 1.0.9200.20789 (x32 Version: 1.0.9200.20789) WCF Data Services 5.0 (for OData v3) DEU Language Pack (x32 Version: 5.0.50628.0) WCF Data Services 5.0 (for OData v3) Primary Components (x32 Version: 5.0.50628.0) WCF Data Services Tools for Microsoft Visual Studio 2012 (x32 Version: 5.0.50710.0) WCF Data Services Tools for Visual Studio 11 DEU Language Pack (x32 Version: 5.0.50710.0) WCF RIA Services V1.0 SP2 (x32 Version: 4.1.61829.0) Windows App Certification Kit Native Components (Version: 8.59.29736) Windows App Certification Kit x64 (x32 Version: 8.59.29750) Windows Azure Tools for LightSwitch HTML Client for Visual Studio 2012 (x32 Version: 1.8.60301.1601) Windows Azure Tools für LightSwitch HTML Client für Visual Studio 2012 (DEU) (x32 Version: 1.8.60301.1601) Windows Mobile Device Updater Component (Version: 04.08.2345.00) Windows Runtime Intellisense Content - de-de (x32 Version: 8.59.25584) Windows Software Development Kit (x32 Version: 8.59.25584) Windows Software Development Kit DirectX x64 Remote (Version: 8.59.25584) Windows Software Development Kit DirectX x86 Remote (x32 Version: 8.59.25584) Windows Software Development Kit for Windows Store Apps (x32 Version: 8.59.25584) Windows Software Development Kit for Windows Store Apps DirectX x64 Remote (Version: 8.59.25584) Windows Software Development Kit for Windows Store Apps DirectX x86 Remote (x32 Version: 8.59.25584) Windows XP Targeting with C++ (Version: 11.0.51106) Windows XP Targeting with C++ (x32 Version: 11.0.51106) XAMPP 1.8.1 (x32) Zune (Version: 04.08.2345.00) Zune Language Pack (CHS) (Version: 04.08.2345.00) Zune Language Pack (CHT) (Version: 04.08.2345.00) Zune Language Pack (CSY) (Version: 04.08.2345.00) Zune Language Pack (DAN) (Version: 04.08.2345.00) Zune Language Pack (DEU) (Version: 04.08.2345.00) Zune Language Pack (ELL) (Version: 04.08.2345.00) Zune Language Pack (ESP) (Version: 04.08.2345.00) Zune Language Pack (FIN) (Version: 04.08.2345.00) Zune Language Pack (FRA) (Version: 04.08.2345.00) Zune Language Pack (HUN) (Version: 04.08.2345.00) Zune Language Pack (IND) (Version: 04.08.2345.00) Zune Language Pack (ITA) (Version: 04.08.2345.00) Zune Language Pack (JPN) (Version: 04.08.2345.00) Zune Language Pack (KOR) (Version: 04.08.2345.00) Zune Language Pack (MSL) (Version: 04.08.2345.00) Zune Language Pack (NLD) (Version: 04.08.2345.00) Zune Language Pack (NOR) (Version: 04.08.2345.00) Zune Language Pack (PLK) (Version: 04.08.2345.00) Zune Language Pack (PTB) (Version: 04.08.2345.00) Zune Language Pack (PTG) (Version: 04.08.2345.00) Zune Language Pack (RUS) (Version: 04.08.2345.00) Zune Language Pack (SVE) (Version: 04.08.2345.00) ==================== Restore Points ========================= 21-11-2013 17:49:54 Ende der Bereinigung ==================== Hosts content: ========================== 2012-07-26 06:26 - 2013-08-20 17:52 - 00000865 ____A C:\WINDOWS\system32\Drivers\etc\hosts 213.23.255.217 amun 192.168.100.15 sv4 ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0D21D59C-D604-47F3-86C0-8406496FA391} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {0F6524F3-35B1-4122-8FB3-EA726BE93D76} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {159D1035-14A2-4403-BB92-009D7B282D47} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe Task: {21A17100-A015-4B15-BB98-74015941C5C3} - System32\Tasks\Microsoft Office 15 Sync Maintenance for CHRIS-PC-Christian Chris-PC => I:\Program Files (x86)\Microsoft Office\Office15\MSOSYNC.EXE [2012-10-01] (Microsoft Corporation) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\System32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {47F698E6-3170-4DD5-A126-EC2EABD3B7CE} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\System32\MRT.exe [2013-11-14] (Microsoft Corporation) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {538E336E-484F-4DA2-9ACB-3474F9C50888} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {767EAFC5-215E-4636-B021-5FE931583ABE} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8C272646-EA11-4D58-BF3A-20DD1B0B6E0F} - System32\Tasks\Microsoft SkyDrive Auto Update Task-S-1-5-21-2496160165-2463586998-2347050423-1001 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => C:\Windows\System32\AppXDeploymentClient.dll [2013-09-30] (Microsoft Corporation) Task: {92619BEF-50F7-47A3-AACC-B056C7986205} - System32\Tasks\MATLAB R2013b Startup Accelerator => I:\Program Files\MATLAB\R2013b\bin\win64\MATLABStartupAccelerator.exe [2013-08-05] () Task: {9AB412B2-E55E-4A32-9DD0-68240BC6EFF8} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {C75F5746-FE2C-44CE-B157-3E37F994DF24} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\MouseKeyboardCenter.exe [2013-05-13] (Microsoft) Task: {CA76E9B6-14B5-4C22-9F39-F2A5B49251B2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E1A86F0E-4C92-4E6B-86B4-9E1B0B6C747E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {E855D973-C5A1-4A56-B5F4-F597436C0B27} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\MATLAB R2013b Startup Accelerator.job => I:\Program Files\MATLAB\R2013b\bin\win64\MATLABStartupAccelerator.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-01 15:23 - 2012-11-28 18:55 - 00065024 _____ () C:\Program Files (x86)\LG Soft India\Screen Split\bin\ScreenSplitterHook64.dll 2013-07-31 17:18 - 2013-06-02 10:30 - 00717230 _____ () C:\Program Files (x86)\Git\git-cheetah\git_shell_ext64.dll 2012-06-18 16:24 - 2012-06-18 16:24 - 00222720 _____ () I:\Program Files (x86)\Notepad++\NppShell_05.dll 2012-03-09 08:58 - 2012-03-09 08:58 - 00057208 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2013-10-22 08:35 - 2013-10-22 08:35 - 01014784 _____ () C:\Users\Christian\AppData\Local\Packages\be5914b3.f1world_dqknxmbjx6sd6\AC\Microsoft\CLR_v4.0\NativeImages\F1World\ab0829aa2b8e813b3c251fed02dd8c46\F1World.ni.exe 2013-10-22 08:35 - 2013-10-22 08:35 - 05179392 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI.Xaml\1a4edd280e2cfb782141cf02237ae00c\Windows.UI.Xaml.ni.dll 2013-10-22 08:35 - 2013-10-22 08:35 - 01782272 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\600862031eb4d4cfdc6f4d2025a7990e\Windows.ApplicationModel.ni.dll 2013-10-22 08:35 - 2013-10-22 08:35 - 00363520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\432868bf54b081b16eaf68729020b30a\Windows.Foundation.ni.dll 2013-10-22 08:35 - 2013-10-22 08:35 - 01459712 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI\0ff25bd7c20be35c2e915bb82db13b72\Windows.UI.ni.dll 2013-10-22 08:35 - 2013-10-22 08:35 - 01278464 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Storage\4c323000d6c8d1d462abb0968333c937\Windows.Storage.ni.dll 2013-10-22 08:35 - 2013-10-22 08:35 - 00521216 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Data\4e1b0dc15d072d992e08612cd74a34db\Windows.Data.ni.dll 2013-03-24 07:01 - 2013-03-24 07:01 - 00005120 _____ () C:\Program Files\WindowsApps\BE5914B3.F1World_1.0.0.3_x64__dqknxmbjx6sd6\LiveClassLibrary.DLL 2012-04-04 17:47 - 2012-04-04 17:47 - 00108032 _____ () C:\xampp\apache\bin\pcre.dll 2012-09-17 11:05 - 2012-09-17 11:05 - 00025088 _____ () C:\xampp\php\php5apache2_4.dll 2013-08-01 15:23 - 2012-11-28 18:55 - 00062976 _____ () C:\Program Files (x86)\LG Soft India\Screen Split\bin\ScreenSplitterHook.dll 2013-08-01 15:23 - 2012-11-04 18:43 - 00004608 _____ () C:\Program Files (x86)\LG Soft India\Screen Split\bin\GerRes.dll 2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Christian\AppData\Roaming\Dropbox\bin\libcef.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Christian\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: TUSB3410 Boot Device Description: TUSB3410 Boot Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (11/24/2013 00:44:46 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: F1World.exe, Version: 1.0.0.0, Zeitstempel: 0x513f017a Name des fehlerhaften Moduls: Windows.UI.Xaml.dll, Version: 6.3.9600.16456, Zeitstempel: 0x52791760 Ausnahmecode: 0xc000027b Fehleroffset: 0x0000000000a4f17a ID des fehlerhaften Prozesses: 0x19a8 Startzeit der fehlerhaften Anwendung: 0xF1World.exe0 Pfad der fehlerhaften Anwendung: F1World.exe1 Pfad des fehlerhaften Moduls: F1World.exe2 Berichtskennung: F1World.exe3 Vollständiger Name des fehlerhaften Pakets: F1World.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: F1World.exe5 Error: (11/21/2013 07:29:39 PM) (Source: WPDMTPDriver) (User: ) Description: MTP WPD Driver0x80070002 Error: (11/21/2013 06:49:55 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (11/21/2013 06:40:47 PM) (Source: Application Hang) (User: ) Description: Programm IEXPLORE.EXE, Version 11.0.9600.16384 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1980 Startzeit: 01cee6e08d3ce433 Endzeit: 31 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: 0bed9a14-52d4-11e3-be87-bcaec51afe5f Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (11/21/2013 06:38:59 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: WMZuneComm.exe, Version: 4.8.2345.0, Zeitstempel: 0x4e3c4567 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.16408, Zeitstempel: 0x523d5305 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000047eb1 ID des fehlerhaften Prozesses: 0x498 Startzeit der fehlerhaften Anwendung: 0xWMZuneComm.exe0 Pfad der fehlerhaften Anwendung: WMZuneComm.exe1 Pfad des fehlerhaften Moduls: WMZuneComm.exe2 Berichtskennung: WMZuneComm.exe3 Vollständiger Name des fehlerhaften Pakets: WMZuneComm.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WMZuneComm.exe5 Error: (11/20/2013 04:34:30 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (11/20/2013 10:51:04 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (11/20/2013 10:41:55 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (11/20/2013 10:41:54 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (11/20/2013 10:41:48 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. System errors: ============= Error: (11/24/2013 00:25:25 PM) (Source: disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (11/24/2013 11:13:10 AM) (Source: disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (11/24/2013 10:00:00 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (11/24/2013 09:22:55 AM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252. Error: (11/24/2013 09:22:55 AM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252. Error: (11/24/2013 09:07:13 AM) (Source: disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden. Error: (11/24/2013 09:07:13 AM) (Source: disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR4 gefunden. Error: (11/24/2013 09:07:13 AM) (Source: disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR5 gefunden. Error: (11/23/2013 09:21:36 PM) (Source: disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden. Error: (11/23/2013 09:21:36 PM) (Source: disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR5 gefunden. Microsoft Office Sessions: ========================= Error: (11/24/2013 00:44:46 PM) (Source: Application Error)(User: ) Description: F1World.exe1.0.0.0513f017aWindows.UI.Xaml.dll6.3.9600.1645652791760c000027b0000000000a4f17a19a801cee90a8552d4e6C:\Program Files\WindowsApps\BE5914B3.F1World_1.0.0.3_x64__dqknxmbjx6sd6\F1World.exeC:\Windows\System32\Windows.UI.Xaml.dlld0e23596-54fd-11e3-be88-bcaec51afe5fBE5914B3.F1World_1.0.0.3_x64__dqknxmbjx6sd6App Error: (11/21/2013 07:29:39 PM) (Source: WPDMTPDriver)(User: ) Description: MTP WPD Driver0x80070002 Error: (11/21/2013 06:49:55 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert Error: (11/21/2013 06:40:47 PM) (Source: Application Hang)(User: ) Description: IEXPLORE.EXE11.0.9600.16384198001cee6e08d3ce43331C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE0bed9a14-52d4-11e3-be87-bcaec51afe5f Error: (11/21/2013 06:38:59 PM) (Source: Application Error)(User: ) Description: WMZuneComm.exe4.8.2345.04e3c4567ntdll.dll6.3.9600.16408523d5305c00000050000000000047eb149801cee6e053e2ee80C:\Program Files\Zune\WMZuneComm.exeC:\WINDOWS\SYSTEM32\ntdll.dllcd3c21ba-52d3-11e3-be87-bcaec51afe5f Error: (11/20/2013 04:34:30 PM) (Source: SideBySide)(User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (11/20/2013 10:51:04 AM) (Source: SideBySide)(User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (11/20/2013 10:41:55 AM) (Source: SideBySide)(User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestI:\Dateien\Documents\Computer\esetsmartinstaller_enu.exe Error: (11/20/2013 10:41:54 AM) (Source: SideBySide)(User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestI:\Dateien\Documents\Computer\esetsmartinstaller_enu.exe Error: (11/20/2013 10:41:48 AM) (Source: SideBySide)(User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestI:\Dateien\Documents\Computer\esetsmartinstaller_enu.exe ==================== Memory info =========================== Percentage of memory in use: 28% Total physical RAM: 7934.18 MB Available physical RAM: 5701.52 MB Total Pagefile: 9214.18 MB Available Pagefile: 6420.6 MB Total Virtual: 131072 MB Available Virtual: 131071.79 MB ==================== Drives ================================ Drive c: (SSD) (Fixed) (Total:111.79 GB) (Free:45.84 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive i: (Data) (Fixed) (Total:931.39 GB) (Free:730.19 GB) NTFS Drive j: (VERBATIM) (Fixed) (Total:931.51 GB) (Free:501.25 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 00000000) Partition: GPT Partition Type ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: A734FEAF) Partition 1: (Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 932 GB) (Disk ID: AC1FBD3A) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-11-24 16:23:31 Windows 6.2.9200 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-2 OCZ-VERTEX3 rev.2.22 111,79GB Running: gmer_2.1.19163.exe; Driver: C:\Users\CHRIST~1\AppData\Local\Temp\kgdcqpod.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff960000e2e00 15 bytes [00, 8F, 0F, 02, 40, F0, 6F, ...] .text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16 fffff960000e2e10 11 bytes [00, DB, FB, FF, 80, C7, D2, ...] ---- User code sections - GMER 2.1 ---- .text C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe[424] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ffad1c1169a 4 bytes [C1, D1, FA, 7F] .text C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe[424] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ffad1c116a2 4 bytes [C1, D1, FA, 7F] .text C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe[424] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ffad1c1181a 4 bytes [C1, D1, FA, 7F] .text C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe[424] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ffad1c11832 4 bytes [C1, D1, FA, 7F] ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [2592:6888] fffff960009014d0 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{B9988453-1FBF-4269-9494-4D2DDE17F60E}\Connection@Name isatap.localdomain Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\RNG@RNGAuxiliarySeed 1934357076 Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{B9988453-1FBF-4269-9494-4D2DDE17F60E}@ReusableType 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{B9988453-1FBF-4269-9494-4D2DDE17F60E}@DefunctTimestamp 0xB2 0xB3 0x91 0x52 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 1585 Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 281 Reg HKLM\SYSTEM\Setup\Upgrade\NsiMigrationRoot\60\0@Rw 0x64 0x62 0x03 0x00 ... Reg HKLM\SYSTEM\Setup\Upgrade\NsiMigrationRoot\60\0@RwMask 0x64 0x62 0x03 0x00 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log\OpenWithList@MRUList cab Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore@Count 2530 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore@Blocked 2530 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{876D9F09-C6D6-4324-A2CC-04DD9A4DE12F}\iexplore@Count 3554 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{876D9F09-C6D6-4324-A2CC-04DD9A4DE12F}\iexplore@Blocked 3554 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore@Count 2033 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore@Blocked 2033 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\iexplore@Count 159 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore@Count 2530 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore@Blocked 2530 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@WindowsBandwidthBucketCounter 6000 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsBandwidthBucketDrainTime 0x1B 0xAD 0xCD 0x3B ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsRequestBucketDrainTime 0xC7 0x93 0x5B 0x9E ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsLargeRequestBucketDrainTime 0xC7 0x93 0x5B 0x9E ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@OtherBandwidthBucketCounter 626356 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@OtherRequestBucketCounter 361 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastOtherRequestBucketDrainTime 0xC7 0x93 0x5B 0x9E ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@GlobalBandwidthBucketCounter 11363748 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@GlobalRequestBucketCounter 361 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastGlobalRequestBucketDrainTime 0xC7 0x93 0x5B 0x9E ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@RoamingSyncToken LM%3d63520901899710%3bID%3d9E7027CD5FC5E786!188%3bLR%3d63520901899943%3bEP%3d4%3bTD%3dTrue Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastUploadTime 0xA8 0x2F 0x04 0x9C ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\RegistrarData@LastRenewCollectionsInterest 0x42 0xEA 0x31 0x61 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData@PendingOperations 43 Reg HKCU\Software\Microsoft\Windows\DWM@ColorizationColor -1664573852 Reg HKCU\Software\Microsoft\Windows\DWM@ColorizationColorBalance 68 Reg HKCU\Software\Microsoft\Windows\DWM@ColorizationAfterglow -1664573852 Reg HKCU\Software\Microsoft\Windows\DWM@ColorizationBlurBalance 22 ---- EOF - GMER 2.1 ---- Mit freundlichen Grüßen Christian |
24.11.2013, 17:13 | #2 |
/// the machine /// TB-Ausbilder | Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II hi,
__________________Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
24.11.2013, 17:46 | #3 |
| Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Hier die neuen Scans.
__________________Malwarebytes Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.24.07 Windows 8 x64 NTFS Internet Explorer 11.0.9600.16438 Christian :: CHRIS-PC [Administrator] 24.11.2013 17:16:23 mbam-log-2013-11-24 (17-16-23).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 337722 Laufzeit: 3 Minute(n), 22 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v3.012 - Bericht erstellt am 19/11/2013 um 13:32:27 # Updated 11/11/2013 von Xplode # Betriebssystem : Windows 8.1 Pro (64 bits) # Benutzername : Christian - CHRIS-PC # Gestartet von : I:\Dateien\Documents\Computer\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16384 -\\ Mozilla Firefox v24.0 (de) [ Datei : C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\lvqn9hid.default\prefs.js ] ************************* AdwCleaner[R0].txt - [792 octets] - [19/11/2013 13:31:50] AdwCleaner[S0].txt - [714 octets] - [19/11/2013 13:32:27] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [773 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 8.1 Pro x64 Ran by Christian on 24.11.2013 at 17:28:09,47 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 24.11.2013 at 17:31:06,34 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-11-2013 Ran by Christian (administrator) on CHRIS-PC on 24-11-2013 17:43:31 Running from I:\Dateien\Documents\Computer Windows 8.1 Pro (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (FileZilla Project) C:\xampp\FileZillaFTP\FileZillaServer.exe () C:\xampp\mysql\bin\mysqld.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20279_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Microsoft Corporation) I:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Microsoft Corporation) C:\Windows\WinStore\WSHost.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [CDAServer] - C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] () HKCU\...\Run: [ScreenSplitter] - C:\Program Files (x86)\LG Soft India\Screen Split\bin\ScreenSplit.exe [392192 2013-01-16] (LG Electronics) HKCU\...\Run: [BrowserChoice] - C:\Windows\BrowserChoice\browserchoice.exe [86816 2013-08-22] (Microsoft Corporation) HKCU\...\Run: [SkyDrive] - C:\Users\Christian\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257136 2013-08-14] (Microsoft Corporation) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Christian\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-11-23] (Spotify Ltd) HKCU\...\Run: [ISUSPM Startup] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [PDFPrint] - I:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] () Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> I:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?PC=BNSR BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\lvqn9hid.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\lvqn9hid.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-04-29] (Advanced Micro Devices, Inc.) R2 Apache2.4; C:\xampp\apache\bin\httpd.exe [22016 2012-08-18] (Apache Software Foundation) R2 FileZillaServer; C:\xampp\filezillaftp\filezillaserver.exe [632320 2012-05-11] (FileZilla Project) S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) R2 mysql; C:\xampp\mysql\bin\mysqld.exe [8186368 2012-07-20] () S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [36352 2010-08-20] () S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-10-08] (Microsoft Corporation) S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] () R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146272 2013-08-22] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-24 17:27 - 2013-11-24 17:27 - 01034531 _____ (Thisisu) C:\Users\Christian\Downloads\JRT.exe.n0r22gs.partial 2013-11-24 16:16 - 2013-11-24 16:16 - 00000000 ____D C:\FRST 2013-11-24 16:14 - 2013-11-24 16:14 - 00000000 _____ C:\Users\Christian\defogger_reenable 2013-11-22 07:49 - 2013-11-22 07:49 - 00000931 _____ C:\Users\Christian\Desktop\DHBW.lnk 2013-11-22 07:47 - 2013-11-22 07:47 - 13321769 _____ C:\Users\Christian\Downloads\PanoramicMountains.deskthemepack 2013-11-21 18:49 - 2013-11-21 18:50 - 00000771 _____ C:\DelFix.txt 2013-11-21 06:48 - 2013-11-21 06:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-19 13:37 - 2013-11-21 18:49 - 00000000 ____D C:\WINDOWS\ERUNT 2013-11-19 13:30 - 2013-11-24 17:24 - 00000000 ____D C:\AdwCleaner 2013-11-16 07:17 - 2013-10-10 12:26 - 02801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2013-11-16 07:17 - 2013-10-10 12:05 - 01019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2013-11-16 07:17 - 2013-10-10 11:34 - 01085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2013-11-16 07:17 - 2013-10-10 11:27 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2013-11-16 07:16 - 2013-11-05 21:21 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2013-11-16 07:16 - 2013-11-05 19:51 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2013-11-16 07:16 - 2013-11-05 17:20 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2013-11-16 07:16 - 2013-11-05 17:11 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2013-11-16 07:16 - 2013-11-05 15:30 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2013-11-16 07:16 - 2013-11-05 15:29 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2013-11-16 07:16 - 2013-10-23 12:29 - 00044936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll 2013-11-16 07:16 - 2013-10-23 12:21 - 00155480 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys 2013-11-16 07:16 - 2013-10-23 12:13 - 00171864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_8086.dll 2013-11-16 07:16 - 2013-10-23 06:27 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-11-16 07:16 - 2013-10-23 06:09 - 04104704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll 2013-11-16 07:16 - 2013-10-23 06:04 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-11-16 07:16 - 2013-10-23 05:55 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2013-11-16 07:16 - 2013-10-23 05:46 - 00700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2013-11-16 07:16 - 2013-10-22 09:18 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2013-11-16 07:16 - 2013-10-22 09:18 - 00096088 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedapplauncher.exe 2013-11-16 07:16 - 2013-10-22 08:55 - 02328872 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2013-11-16 07:16 - 2013-10-22 07:03 - 02065448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2013-11-16 07:16 - 2013-10-22 06:15 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll 2013-11-16 07:16 - 2013-10-22 05:04 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll 2013-11-16 07:16 - 2013-10-22 05:02 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2013-11-16 07:16 - 2013-10-22 04:56 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll 2013-11-16 07:16 - 2013-10-22 04:44 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll 2013-11-16 07:16 - 2013-10-22 03:38 - 01362944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2013-11-16 07:16 - 2013-10-22 03:22 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2013-11-16 07:16 - 2013-10-22 03:13 - 01704448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2013-11-16 07:16 - 2013-10-22 03:07 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2013-11-16 07:16 - 2013-10-22 02:53 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2013-11-16 07:16 - 2013-10-22 02:47 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2013-11-16 07:16 - 2013-10-19 10:13 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2013-11-16 07:16 - 2013-10-19 09:51 - 00481392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2013-11-16 07:16 - 2013-10-19 08:12 - 00380656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2013-11-16 07:16 - 2013-10-19 07:24 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2013-11-16 07:16 - 2013-10-19 05:48 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2013-11-16 07:16 - 2013-10-19 05:03 - 00531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2013-11-16 07:16 - 2013-10-19 04:57 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2013-11-16 07:16 - 2013-10-19 04:28 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2013-11-16 07:16 - 2013-10-19 04:26 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2013-11-16 07:16 - 2013-10-19 04:14 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2013-11-16 07:16 - 2013-10-17 16:42 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2013-11-16 07:16 - 2013-10-17 16:42 - 01373872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2013-11-16 07:16 - 2013-10-17 15:04 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2013-11-16 07:16 - 2013-10-16 10:34 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2013-11-16 07:16 - 2013-10-16 10:33 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2013-11-16 07:16 - 2013-10-13 04:06 - 00258904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys 2013-11-16 07:16 - 2013-10-13 03:43 - 00708616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll 2013-11-16 07:16 - 2013-10-11 16:11 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll 2013-11-16 07:16 - 2013-10-11 15:22 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll 2013-11-16 07:16 - 2013-10-11 14:24 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2013-11-16 07:16 - 2013-10-11 14:04 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 2013-11-16 07:16 - 2013-10-11 14:03 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2013-11-16 07:16 - 2013-10-10 17:44 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll 2013-11-16 07:16 - 2013-10-10 17:26 - 00317616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2013-11-16 07:16 - 2013-10-10 17:26 - 00104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll 2013-11-16 07:16 - 2013-10-10 17:23 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2013-11-16 07:16 - 2013-10-10 15:53 - 00235960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2013-11-16 07:16 - 2013-10-10 15:53 - 00088272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll 2013-11-16 07:16 - 2013-10-10 12:53 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2013-11-16 07:16 - 2013-10-10 12:38 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2013-11-16 07:16 - 2013-10-10 12:21 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2013-11-16 07:16 - 2013-10-10 11:40 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2013-11-16 07:16 - 2013-10-10 11:19 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2013-11-16 07:16 - 2013-10-09 06:40 - 00385528 _____ C:\WINDOWS\system32\ApnDatabase.xml 2013-11-16 07:16 - 2013-10-08 12:07 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 2013-11-16 07:16 - 2013-10-08 11:28 - 00523096 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys 2013-11-16 07:16 - 2013-10-08 11:13 - 02551640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2013-11-16 07:16 - 2013-10-08 07:46 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll 2013-11-16 07:16 - 2013-10-08 06:58 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll 2013-11-16 07:16 - 2013-10-08 06:50 - 00656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 2013-11-16 07:16 - 2013-10-08 06:48 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 2013-11-16 07:16 - 2013-10-08 06:15 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll 2013-11-16 07:16 - 2013-10-08 06:09 - 01160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll 2013-11-16 07:16 - 2013-10-08 05:50 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll 2013-11-16 07:16 - 2013-10-08 05:50 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2013-11-16 07:16 - 2013-10-07 08:21 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2013-11-16 07:16 - 2013-10-07 08:21 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2013-11-16 07:16 - 2013-10-07 03:13 - 03532288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2013-11-16 07:16 - 2013-10-05 16:25 - 00371032 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 2013-11-16 07:16 - 2013-10-05 16:25 - 00057176 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys 2013-11-16 07:16 - 2013-10-05 15:21 - 00699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll 2013-11-16 07:16 - 2013-10-05 13:05 - 00578952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll 2013-11-16 07:16 - 2013-10-05 12:01 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys 2013-11-16 07:16 - 2013-10-05 10:36 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe 2013-11-16 07:16 - 2013-10-05 10:18 - 01011712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2013-11-16 07:16 - 2013-10-05 10:07 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2013-11-16 07:16 - 2013-10-05 09:56 - 01147904 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2013-11-16 07:16 - 2013-10-05 09:55 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\miutils.dll 2013-11-16 07:16 - 2013-10-05 09:40 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll 2013-11-16 07:16 - 2013-10-05 09:24 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miutils.dll 2013-11-16 07:16 - 2013-10-05 09:21 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2013-11-16 07:16 - 2013-10-05 09:15 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll 2013-11-16 07:16 - 2013-10-05 08:43 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll 2013-11-16 07:16 - 2013-10-05 08:39 - 06639616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2013-11-16 07:16 - 2013-10-05 08:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-11-16 07:16 - 2013-10-05 08:32 - 05769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2013-11-16 07:16 - 2013-10-04 09:10 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2013-11-16 07:16 - 2013-09-19 06:04 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll 2013-11-16 07:16 - 2013-09-17 10:06 - 01067080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2013-11-16 07:16 - 2013-09-17 10:06 - 00465960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2013-11-16 07:16 - 2013-09-17 07:31 - 00883184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2013-11-16 07:16 - 2013-09-17 07:31 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2013-11-16 07:16 - 2013-09-17 05:37 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2013-11-16 07:16 - 2013-09-14 15:07 - 02134120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2013-11-16 07:16 - 2013-09-14 15:00 - 00391512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll 2013-11-16 07:16 - 2013-09-14 13:39 - 01799944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2013-11-16 07:16 - 2013-09-14 13:33 - 00345552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll 2013-11-16 07:16 - 2013-09-14 11:05 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe 2013-11-16 07:16 - 2013-09-14 10:11 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll 2013-11-16 07:16 - 2013-09-13 09:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ftp.exe 2013-11-16 07:16 - 2013-09-13 08:47 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ftp.exe 2013-11-16 07:16 - 2013-09-12 09:45 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll 2013-11-16 07:16 - 2013-09-12 09:08 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll 2013-11-16 07:16 - 2013-09-12 09:08 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2013-11-16 07:16 - 2013-09-12 09:02 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll 2013-11-16 07:16 - 2013-09-12 08:44 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll 2013-11-16 07:16 - 2013-09-12 08:37 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll 2013-11-16 07:16 - 2013-09-12 08:37 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll 2013-11-16 07:16 - 2013-09-12 08:21 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll 2013-11-16 07:16 - 2013-09-12 08:16 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll 2013-11-16 07:16 - 2013-09-12 08:01 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll 2013-11-16 07:16 - 2013-09-11 13:46 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2013-11-16 07:16 - 2013-09-10 06:26 - 04599808 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2013-11-16 07:16 - 2013-09-10 05:52 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msched.dll 2013-11-16 07:16 - 2013-09-10 05:34 - 03934208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Roaming\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\AMD 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\ProgramData\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-11-14 14:32 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files\ATI Technologies 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\ProgramData\AMD 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files\ATI 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-11-14 14:04 - 2013-11-14 14:04 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2013-11-14 14:04 - 2013-10-19 09:08 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2013-11-14 14:04 - 2013-10-19 07:37 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2013-11-14 14:04 - 2013-10-19 07:02 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2013-11-14 14:04 - 2013-10-19 06:37 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe 2013-11-14 14:04 - 2013-10-19 06:19 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2013-11-14 14:04 - 2013-10-19 06:10 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2013-11-14 14:04 - 2013-10-19 05:52 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2013-11-14 14:04 - 2013-10-19 05:44 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2013-11-14 14:04 - 2013-10-19 05:37 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2013-11-14 14:04 - 2013-10-19 05:31 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2013-11-14 14:04 - 2013-10-19 04:56 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2013-11-14 14:04 - 2013-10-19 04:55 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2013-11-14 14:04 - 2013-10-19 04:53 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2013-11-14 14:04 - 2013-10-19 04:23 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2013-11-14 14:04 - 2013-10-19 04:09 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2013-11-14 14:04 - 2013-10-19 04:02 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2013-11-14 14:04 - 2013-10-13 03:48 - 00136536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys 2013-11-14 14:04 - 2013-10-12 22:48 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 2013-11-14 14:04 - 2013-10-12 22:34 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2013-11-14 14:04 - 2013-10-05 15:21 - 01341288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2013-11-14 14:04 - 2013-10-05 09:39 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2013-11-14 14:03 - 2013-11-14 14:03 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2013-11-14 14:01 - 2013-10-16 16:58 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2013-11-14 14:01 - 2013-10-16 14:54 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2013-11-10 12:17 - 2013-11-10 12:17 - 00001392 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse-php.lnk 2013-11-10 12:12 - 2013-11-10 12:14 - 00000242 _____ C:\WINDOWS\pear.ini 2013-11-10 11:05 - 2013-11-10 11:05 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Friends 2013-11-10 02:09 - 2013-11-12 20:29 - 00001351 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Git Lacker.lnk 2013-11-01 16:36 - 2013-11-01 16:36 - 00000313 _____ C:\Users\Christian\.JMAppsCfg 2013-11-01 16:23 - 2013-11-01 16:23 - 05218242 _____ (InstallShield Software Corporation) C:\Users\Christian\Downloads\jmf-2_1_1e-windows-i586.exe 2013-11-01 16:23 - 1998-01-23 12:22 - 00304128 _____ (InstallShield Software Corporation) C:\WINDOWS\IsUninst.exe 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Malwarebytes 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-01 10:00 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2013-10-31 14:39 - 2013-10-31 14:39 - 00000000 ____D C:\ProgramData\Oracle 2013-10-31 14:38 - 2013-10-31 14:39 - 00004249 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-29 07:01 - 2013-10-23 12:01 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2013-10-29 07:01 - 2013-10-23 09:59 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll ==================== One Month Modified Files and Folders ======= 2013-11-24 17:41 - 2013-10-21 09:37 - 01944357 _____ C:\WINDOWS\WindowsUpdate.log 2013-11-24 17:35 - 2013-10-22 12:32 - 00005148 _____ C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for CHRIS-PC-Christian Chris-PC 2013-11-24 17:31 - 2013-09-30 05:14 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-11-24 17:31 - 2013-09-30 04:56 - 00764340 _____ C:\WINDOWS\system32\perfh007.dat 2013-11-24 17:31 - 2013-09-30 04:56 - 00159160 _____ C:\WINDOWS\system32\perfc007.dat 2013-11-24 17:27 - 2013-11-24 17:27 - 01034531 _____ (Thisisu) C:\Users\Christian\Downloads\JRT.exe.n0r22gs.partial 2013-11-24 17:26 - 2013-10-04 10:49 - 00000572 _____ C:\WINDOWS\Tasks\MATLAB R2013b Startup Accelerator.job 2013-11-24 17:25 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-11-24 17:25 - 2013-01-14 18:06 - 00000000 __RDO C:\Users\Christian\SkyDrive 2013-11-24 17:24 - 2013-11-19 13:30 - 00000000 ____D C:\AdwCleaner 2013-11-24 17:24 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2013-11-24 17:15 - 2013-07-31 15:57 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-11-24 17:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru 2013-11-24 16:16 - 2013-11-24 16:16 - 00000000 ____D C:\FRST 2013-11-24 16:14 - 2013-11-24 16:14 - 00000000 _____ C:\Users\Christian\defogger_reenable 2013-11-24 16:14 - 2013-10-21 09:15 - 00000000 ____D C:\Users\Christian 2013-11-24 15:27 - 2013-10-21 09:45 - 00003946 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{61128387-B861-4393-83E1-DF07BADD9687} 2013-11-24 12:19 - 2013-10-07 14:38 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Dropbox 2013-11-24 11:27 - 2013-05-04 16:45 - 00000000 ____D C:\Users\Christian\.VirtualBox 2013-11-24 10:12 - 2013-07-31 15:59 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2496160165-2463586998-2347050423-1001 2013-11-23 20:36 - 2013-08-14 15:18 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Spotify 2013-11-23 20:35 - 2013-08-14 15:18 - 00000000 ____D C:\Users\Christian\AppData\Local\Spotify 2013-11-22 07:49 - 2013-11-22 07:49 - 00000931 _____ C:\Users\Christian\Desktop\DHBW.lnk 2013-11-22 07:47 - 2013-11-22 07:47 - 13321769 _____ C:\Users\Christian\Downloads\PanoramicMountains.deskthemepack 2013-11-21 18:50 - 2013-11-21 18:49 - 00000771 _____ C:\DelFix.txt 2013-11-21 18:50 - 2013-09-29 20:04 - 00028796 _____ C:\WINDOWS\PFRO.log 2013-11-21 18:50 - 2013-07-31 16:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-21 18:49 - 2013-11-19 13:37 - 00000000 ____D C:\WINDOWS\ERUNT 2013-11-21 18:35 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness 2013-11-21 06:48 - 2013-11-21 06:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-19 19:38 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache 2013-11-19 13:34 - 2013-08-22 15:44 - 00411576 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-11-19 13:34 - 2013-07-31 15:54 - 00000000 ___RD C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-19 13:34 - 2013-07-31 15:54 - 00000000 ___RD C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-11-19 13:34 - 2013-01-15 18:39 - 00000000 ___RD C:\Users\Christian\Podcasts 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ___RD C:\WINDOWS\ToastData 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\migwiz 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2013-11-19 11:30 - 2013-08-01 16:53 - 00267936 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2013-11-16 09:11 - 2013-07-31 17:06 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-16 07:41 - 2013-02-15 15:55 - 00000000 ____D C:\xampp 2013-11-16 07:29 - 2013-10-21 09:13 - 00013914 _____ C:\WINDOWS\system32\lvcoinst.log 2013-11-15 15:30 - 2013-08-29 21:01 - 00001782 ____H C:\Users\Christian\.gitk 2013-11-14 18:06 - 2013-01-14 17:12 - 00000000 ____D C:\Users\Christian\AppData\Local\Packages 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Roaming\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\AMD 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\ProgramData\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-11-14 14:33 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files\ATI Technologies 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\ProgramData\AMD 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files\ATI 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-11-14 14:11 - 2013-08-07 17:22 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-11-14 14:10 - 2013-08-01 17:03 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2013-11-14 14:04 - 2013-11-14 14:04 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2013-11-14 14:03 - 2013-11-14 14:03 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2013-11-12 20:29 - 2013-11-10 02:09 - 00001351 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Git Lacker.lnk 2013-11-10 12:42 - 2013-10-03 14:58 - 00001332 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse.lnk 2013-11-10 12:42 - 2013-10-03 07:44 - 00000000 ____D C:\Users\Christian\.eclipse 2013-11-10 12:17 - 2013-11-10 12:17 - 00001392 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse-php.lnk 2013-11-10 12:14 - 2013-11-10 12:12 - 00000242 _____ C:\WINDOWS\pear.ini 2013-11-10 11:05 - 2013-11-10 11:05 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Friends 2013-11-10 11:04 - 2013-10-03 08:21 - 00000000 ____D C:\Program Files (x86)\eclipse 2013-11-10 02:18 - 2013-07-24 17:05 - 00000000 ____D C:\Users\Christian\.ssh 2013-11-06 00:31 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2013-11-06 00:31 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-05 21:21 - 2013-11-16 07:16 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2013-11-05 19:51 - 2013-11-16 07:16 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2013-11-05 17:20 - 2013-11-16 07:16 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2013-11-05 17:11 - 2013-11-16 07:16 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2013-11-05 15:30 - 2013-11-16 07:16 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2013-11-05 15:29 - 2013-11-16 07:16 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2013-11-05 08:07 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2013-11-01 16:36 - 2013-11-01 16:36 - 00000313 _____ C:\Users\Christian\.JMAppsCfg 2013-11-01 16:23 - 2013-11-01 16:23 - 05218242 _____ (InstallShield Software Corporation) C:\Users\Christian\Downloads\jmf-2_1_1e-windows-i586.exe 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Malwarebytes 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-31 14:39 - 2013-10-31 14:39 - 00000000 ____D C:\ProgramData\Oracle 2013-10-31 14:39 - 2013-10-31 14:38 - 00004249 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-31 14:39 - 2013-10-03 08:30 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-29 11:33 - 2013-07-31 17:06 - 00000000 ____D C:\Users\Christian\AppData\Local\Microsoft Help Some content of TEMP: ==================== C:\Users\Christian\AppData\Local\Temp\Dragon.exe C:\Users\Christian\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Christian\AppData\Local\Temp\npp.6.5.Installer.exe C:\Users\Christian\AppData\Local\Temp\ose00000.exe C:\Users\Christian\AppData\Local\Temp\Quarantine.exe C:\Users\Christian\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe [2013-11-16 07:16] - [2013-10-22 08:55] - 2328872 ____A (Microsoft Corporation) 63DC38C3E4564B2405D562855643ABA2 C:\Windows\SysWOW64\explorer.exe [2013-11-16 07:16] - [2013-10-22 07:03] - 2065448 ____A (Microsoft Corporation) 1A0BC9598E4A58FC84570FFF5A108E58 C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll [2013-11-16 07:16] - [2013-10-22 03:38] - 1362944 ____A (Microsoft Corporation) C72456BFFE941714CF05B0AA0BEE5B45 C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-24 17:36 ==================== End Of Log ============================ |
25.11.2013, 08:23 | #4 |
/// the machine /// TB-Ausbilder | Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) IIESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.11.2013, 18:19 | #5 |
| Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=f4108c4358fe2e41907361a85ebfbef2 # engine=16015 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-25 05:14:36 # local_time=2013-11-25 06:14:36 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.2.9200 NT # compatibility_mode=5893 16776573 100 94 36967 8233378 0 0 # scanned=890688 # found=0 # cleaned=0 # scan_time=18061 Code:
ATTFilter Results of screen317's Security Check version 0.99.76 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Visual Studio Extensions for Windows Library for JavaScript Java 7 Update 45 Java SE Development Kit 7 Update 40 Visual Studio Extensions for Windows Library for JavaScript 1.0.9200.20789 JavaScript Tooling Visual Studio Extensions for Windows Library for JavaScript Adobe Flash Player 11.9.900.117 Adobe Reader XI Mozilla Firefox (25.0.1) ````````Process Check: objlist.exe by Laurent```````` Windows Defender MSMpEng.exe Windows Defender MSASCui.exe Windows Defender MSASCui.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-11-2013 Ran by Christian (administrator) on CHRIS-PC on 25-11-2013 18:16:57 Running from I:\Dateien\Documents\Computer Windows 8.1 Pro (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (FileZilla Project) C:\xampp\FileZillaFTP\FileZillaServer.exe () C:\xampp\mysql\bin\mysqld.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20279_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe () C:\Program Files\WindowsApps\Facebook.Facebook_1.1.0.27_x64__8xx8rvfyw5nnt\Facebook.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Microsoft Corporation) I:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Microsoft Corporation) C:\Windows\WinStore\WSHost.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [CDAServer] - C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] () HKCU\...\Run: [ScreenSplitter] - C:\Program Files (x86)\LG Soft India\Screen Split\bin\ScreenSplit.exe [392192 2013-01-16] (LG Electronics) HKCU\...\Run: [BrowserChoice] - C:\Windows\BrowserChoice\browserchoice.exe [86816 2013-08-22] (Microsoft Corporation) HKCU\...\Run: [SkyDrive] - C:\Users\Christian\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257136 2013-08-14] (Microsoft Corporation) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Christian\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-11-23] (Spotify Ltd) HKCU\...\Run: [ISUSPM Startup] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [PDFPrint] - I:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] () Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> I:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?PC=BNSR BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\lvqn9hid.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\lvqn9hid.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-04-29] (Advanced Micro Devices, Inc.) R2 Apache2.4; C:\xampp\apache\bin\httpd.exe [22016 2012-08-18] (Apache Software Foundation) R2 FileZillaServer; C:\xampp\filezillaftp\filezillaserver.exe [632320 2012-05-11] (FileZilla Project) S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) R2 mysql; C:\xampp\mysql\bin\mysqld.exe [8186368 2012-07-20] () S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [36352 2010-08-20] () S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-10-08] (Microsoft Corporation) S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] () R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146272 2013-08-22] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-25 18:16 - 2013-11-25 18:16 - 00891184 _____ C:\Users\Christian\Desktop\SecurityCheck.exe 2013-11-25 13:11 - 2013-11-25 13:11 - 02347384 _____ (ESET) C:\Users\Christian\Downloads\esetsmartinstaller_enu.exe 2013-11-25 13:11 - 2013-11-25 13:11 - 00000000 ____D C:\Program Files (x86)\ESET 2013-11-25 07:31 - 2013-11-25 07:31 - 00000000 ____D C:\ProgramData\NuGet 2013-11-25 07:31 - 2013-11-25 07:31 - 00000000 ____D C:\Program Files (x86)\NuGet 2013-11-24 17:27 - 2013-11-24 17:27 - 01034531 _____ (Thisisu) C:\Users\Christian\Downloads\JRT.exe.n0r22gs.partial 2013-11-24 16:16 - 2013-11-24 16:16 - 00000000 ____D C:\FRST 2013-11-24 16:14 - 2013-11-24 16:14 - 00000000 _____ C:\Users\Christian\defogger_reenable 2013-11-22 07:49 - 2013-11-22 07:49 - 00000931 _____ C:\Users\Christian\Desktop\DHBW.lnk 2013-11-22 07:47 - 2013-11-22 07:47 - 13321769 _____ C:\Users\Christian\Downloads\PanoramicMountains.deskthemepack 2013-11-21 18:49 - 2013-11-21 18:50 - 00000771 _____ C:\DelFix.txt 2013-11-21 06:48 - 2013-11-21 06:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-19 13:37 - 2013-11-21 18:49 - 00000000 ____D C:\WINDOWS\ERUNT 2013-11-19 13:30 - 2013-11-24 17:24 - 00000000 ____D C:\AdwCleaner 2013-11-16 07:17 - 2013-10-10 12:26 - 02801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2013-11-16 07:17 - 2013-10-10 12:05 - 01019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2013-11-16 07:17 - 2013-10-10 11:34 - 01085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2013-11-16 07:17 - 2013-10-10 11:27 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2013-11-16 07:16 - 2013-11-05 21:21 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2013-11-16 07:16 - 2013-11-05 19:51 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2013-11-16 07:16 - 2013-11-05 17:20 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2013-11-16 07:16 - 2013-11-05 17:11 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2013-11-16 07:16 - 2013-11-05 15:30 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2013-11-16 07:16 - 2013-11-05 15:29 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2013-11-16 07:16 - 2013-10-23 12:29 - 00044936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll 2013-11-16 07:16 - 2013-10-23 12:21 - 00155480 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys 2013-11-16 07:16 - 2013-10-23 12:13 - 00171864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_8086.dll 2013-11-16 07:16 - 2013-10-23 06:27 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-11-16 07:16 - 2013-10-23 06:09 - 04104704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll 2013-11-16 07:16 - 2013-10-23 06:04 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-11-16 07:16 - 2013-10-23 05:55 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2013-11-16 07:16 - 2013-10-23 05:46 - 00700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2013-11-16 07:16 - 2013-10-22 09:18 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2013-11-16 07:16 - 2013-10-22 09:18 - 00096088 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedapplauncher.exe 2013-11-16 07:16 - 2013-10-22 08:55 - 02328872 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2013-11-16 07:16 - 2013-10-22 07:03 - 02065448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2013-11-16 07:16 - 2013-10-22 06:15 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll 2013-11-16 07:16 - 2013-10-22 05:04 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll 2013-11-16 07:16 - 2013-10-22 05:02 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2013-11-16 07:16 - 2013-10-22 04:56 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll 2013-11-16 07:16 - 2013-10-22 04:44 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll 2013-11-16 07:16 - 2013-10-22 03:38 - 01362944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2013-11-16 07:16 - 2013-10-22 03:22 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2013-11-16 07:16 - 2013-10-22 03:13 - 01704448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2013-11-16 07:16 - 2013-10-22 03:07 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2013-11-16 07:16 - 2013-10-22 02:53 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2013-11-16 07:16 - 2013-10-22 02:47 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2013-11-16 07:16 - 2013-10-19 10:13 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2013-11-16 07:16 - 2013-10-19 09:51 - 00481392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2013-11-16 07:16 - 2013-10-19 08:12 - 00380656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2013-11-16 07:16 - 2013-10-19 07:24 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2013-11-16 07:16 - 2013-10-19 05:48 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2013-11-16 07:16 - 2013-10-19 05:03 - 00531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2013-11-16 07:16 - 2013-10-19 04:57 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2013-11-16 07:16 - 2013-10-19 04:28 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2013-11-16 07:16 - 2013-10-19 04:26 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2013-11-16 07:16 - 2013-10-19 04:14 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2013-11-16 07:16 - 2013-10-17 16:42 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2013-11-16 07:16 - 2013-10-17 16:42 - 01373872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2013-11-16 07:16 - 2013-10-17 15:04 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2013-11-16 07:16 - 2013-10-16 10:34 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2013-11-16 07:16 - 2013-10-16 10:33 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2013-11-16 07:16 - 2013-10-13 04:06 - 00258904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys 2013-11-16 07:16 - 2013-10-13 03:43 - 00708616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll 2013-11-16 07:16 - 2013-10-11 16:11 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll 2013-11-16 07:16 - 2013-10-11 15:22 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll 2013-11-16 07:16 - 2013-10-11 14:24 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2013-11-16 07:16 - 2013-10-11 14:04 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 2013-11-16 07:16 - 2013-10-11 14:03 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2013-11-16 07:16 - 2013-10-10 17:44 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll 2013-11-16 07:16 - 2013-10-10 17:26 - 00317616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2013-11-16 07:16 - 2013-10-10 17:26 - 00104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll 2013-11-16 07:16 - 2013-10-10 17:23 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2013-11-16 07:16 - 2013-10-10 15:53 - 00235960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2013-11-16 07:16 - 2013-10-10 15:53 - 00088272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll 2013-11-16 07:16 - 2013-10-10 12:53 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2013-11-16 07:16 - 2013-10-10 12:38 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2013-11-16 07:16 - 2013-10-10 12:21 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2013-11-16 07:16 - 2013-10-10 11:40 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2013-11-16 07:16 - 2013-10-10 11:19 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2013-11-16 07:16 - 2013-10-09 06:40 - 00385528 _____ C:\WINDOWS\system32\ApnDatabase.xml 2013-11-16 07:16 - 2013-10-08 12:07 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 2013-11-16 07:16 - 2013-10-08 11:28 - 00523096 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys 2013-11-16 07:16 - 2013-10-08 11:13 - 02551640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2013-11-16 07:16 - 2013-10-08 07:46 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll 2013-11-16 07:16 - 2013-10-08 06:58 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll 2013-11-16 07:16 - 2013-10-08 06:50 - 00656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 2013-11-16 07:16 - 2013-10-08 06:48 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 2013-11-16 07:16 - 2013-10-08 06:15 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll 2013-11-16 07:16 - 2013-10-08 06:09 - 01160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll 2013-11-16 07:16 - 2013-10-08 05:50 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll 2013-11-16 07:16 - 2013-10-08 05:50 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2013-11-16 07:16 - 2013-10-07 08:21 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2013-11-16 07:16 - 2013-10-07 08:21 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2013-11-16 07:16 - 2013-10-07 03:13 - 03532288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2013-11-16 07:16 - 2013-10-05 16:25 - 00371032 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 2013-11-16 07:16 - 2013-10-05 16:25 - 00057176 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys 2013-11-16 07:16 - 2013-10-05 15:21 - 00699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll 2013-11-16 07:16 - 2013-10-05 13:05 - 00578952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll 2013-11-16 07:16 - 2013-10-05 12:01 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys 2013-11-16 07:16 - 2013-10-05 10:36 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe 2013-11-16 07:16 - 2013-10-05 10:18 - 01011712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2013-11-16 07:16 - 2013-10-05 10:07 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2013-11-16 07:16 - 2013-10-05 09:56 - 01147904 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2013-11-16 07:16 - 2013-10-05 09:55 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\miutils.dll 2013-11-16 07:16 - 2013-10-05 09:40 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll 2013-11-16 07:16 - 2013-10-05 09:24 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miutils.dll 2013-11-16 07:16 - 2013-10-05 09:21 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2013-11-16 07:16 - 2013-10-05 09:15 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll 2013-11-16 07:16 - 2013-10-05 08:43 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll 2013-11-16 07:16 - 2013-10-05 08:39 - 06639616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2013-11-16 07:16 - 2013-10-05 08:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-11-16 07:16 - 2013-10-05 08:32 - 05769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2013-11-16 07:16 - 2013-10-04 09:10 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2013-11-16 07:16 - 2013-09-19 06:04 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll 2013-11-16 07:16 - 2013-09-17 10:06 - 01067080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2013-11-16 07:16 - 2013-09-17 10:06 - 00465960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2013-11-16 07:16 - 2013-09-17 07:31 - 00883184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2013-11-16 07:16 - 2013-09-17 07:31 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2013-11-16 07:16 - 2013-09-17 05:37 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2013-11-16 07:16 - 2013-09-14 15:07 - 02134120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2013-11-16 07:16 - 2013-09-14 15:00 - 00391512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll 2013-11-16 07:16 - 2013-09-14 13:39 - 01799944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2013-11-16 07:16 - 2013-09-14 13:33 - 00345552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll 2013-11-16 07:16 - 2013-09-14 11:05 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe 2013-11-16 07:16 - 2013-09-14 10:11 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll 2013-11-16 07:16 - 2013-09-13 09:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ftp.exe 2013-11-16 07:16 - 2013-09-13 08:47 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ftp.exe 2013-11-16 07:16 - 2013-09-12 09:45 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll 2013-11-16 07:16 - 2013-09-12 09:08 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll 2013-11-16 07:16 - 2013-09-12 09:08 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2013-11-16 07:16 - 2013-09-12 09:02 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll 2013-11-16 07:16 - 2013-09-12 08:44 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll 2013-11-16 07:16 - 2013-09-12 08:37 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll 2013-11-16 07:16 - 2013-09-12 08:37 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll 2013-11-16 07:16 - 2013-09-12 08:21 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll 2013-11-16 07:16 - 2013-09-12 08:16 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll 2013-11-16 07:16 - 2013-09-12 08:01 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll 2013-11-16 07:16 - 2013-09-11 13:46 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2013-11-16 07:16 - 2013-09-10 06:26 - 04599808 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2013-11-16 07:16 - 2013-09-10 05:52 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msched.dll 2013-11-16 07:16 - 2013-09-10 05:34 - 03934208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Roaming\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\AMD 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\ProgramData\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-11-14 14:32 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files\ATI Technologies 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\ProgramData\AMD 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files\ATI 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-11-14 14:04 - 2013-11-14 14:04 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2013-11-14 14:04 - 2013-10-19 09:08 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2013-11-14 14:04 - 2013-10-19 07:37 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2013-11-14 14:04 - 2013-10-19 07:02 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2013-11-14 14:04 - 2013-10-19 06:37 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe 2013-11-14 14:04 - 2013-10-19 06:19 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2013-11-14 14:04 - 2013-10-19 06:10 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2013-11-14 14:04 - 2013-10-19 05:52 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2013-11-14 14:04 - 2013-10-19 05:44 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2013-11-14 14:04 - 2013-10-19 05:37 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2013-11-14 14:04 - 2013-10-19 05:31 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2013-11-14 14:04 - 2013-10-19 04:56 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2013-11-14 14:04 - 2013-10-19 04:55 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2013-11-14 14:04 - 2013-10-19 04:53 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2013-11-14 14:04 - 2013-10-19 04:23 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2013-11-14 14:04 - 2013-10-19 04:09 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2013-11-14 14:04 - 2013-10-19 04:02 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2013-11-14 14:04 - 2013-10-13 03:48 - 00136536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys 2013-11-14 14:04 - 2013-10-12 22:48 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 2013-11-14 14:04 - 2013-10-12 22:34 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2013-11-14 14:04 - 2013-10-05 15:21 - 01341288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2013-11-14 14:04 - 2013-10-05 09:39 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2013-11-14 14:03 - 2013-11-14 14:03 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2013-11-14 14:01 - 2013-10-16 16:58 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2013-11-14 14:01 - 2013-10-16 14:54 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2013-11-10 12:17 - 2013-11-10 12:17 - 00001392 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse-php.lnk 2013-11-10 12:12 - 2013-11-10 12:14 - 00000242 _____ C:\WINDOWS\pear.ini 2013-11-10 11:05 - 2013-11-10 11:05 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Friends 2013-11-10 02:09 - 2013-11-12 20:29 - 00001351 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Git Lacker.lnk 2013-11-01 16:36 - 2013-11-01 16:36 - 00000313 _____ C:\Users\Christian\.JMAppsCfg 2013-11-01 16:23 - 2013-11-01 16:23 - 05218242 _____ (InstallShield Software Corporation) C:\Users\Christian\Downloads\jmf-2_1_1e-windows-i586.exe 2013-11-01 16:23 - 1998-01-23 12:22 - 00304128 _____ (InstallShield Software Corporation) C:\WINDOWS\IsUninst.exe 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Malwarebytes 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-01 10:00 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2013-10-31 14:39 - 2013-10-31 14:39 - 00000000 ____D C:\ProgramData\Oracle 2013-10-31 14:38 - 2013-10-31 14:39 - 00004249 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-30 00:28 - 2013-10-30 00:28 - 02279104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsHelper.dll 2013-10-29 07:01 - 2013-10-23 12:01 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2013-10-29 07:01 - 2013-10-23 09:59 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll ==================== One Month Modified Files and Folders ======= 2013-11-25 18:16 - 2013-11-25 18:16 - 00891184 _____ C:\Users\Christian\Desktop\SecurityCheck.exe 2013-11-25 18:15 - 2013-07-31 15:59 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2496160165-2463586998-2347050423-1001 2013-11-25 18:15 - 2013-07-31 15:57 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-11-25 18:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru 2013-11-25 15:36 - 2013-10-21 09:37 - 02025712 _____ C:\WINDOWS\WindowsUpdate.log 2013-11-25 14:00 - 2013-10-22 12:32 - 00005148 _____ C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for CHRIS-PC-Christian Chris-PC 2013-11-25 13:11 - 2013-11-25 13:11 - 02347384 _____ (ESET) C:\Users\Christian\Downloads\esetsmartinstaller_enu.exe 2013-11-25 13:11 - 2013-11-25 13:11 - 00000000 ____D C:\Program Files (x86)\ESET 2013-11-25 13:11 - 2013-09-30 05:14 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-11-25 13:11 - 2013-09-30 04:56 - 00764340 _____ C:\WINDOWS\system32\perfh007.dat 2013-11-25 13:11 - 2013-09-30 04:56 - 00159160 _____ C:\WINDOWS\system32\perfc007.dat 2013-11-25 13:10 - 2013-10-21 09:45 - 00003946 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{61128387-B861-4393-83E1-DF07BADD9687} 2013-11-25 13:08 - 2013-10-04 10:49 - 00000572 _____ C:\WINDOWS\Tasks\MATLAB R2013b Startup Accelerator.job 2013-11-25 13:07 - 2013-01-14 18:06 - 00000000 __RDO C:\Users\Christian\SkyDrive 2013-11-25 07:32 - 2013-07-31 16:04 - 00000000 ____D C:\ProgramData\Package Cache 2013-11-25 07:31 - 2013-11-25 07:31 - 00000000 ____D C:\ProgramData\NuGet 2013-11-25 07:31 - 2013-11-25 07:31 - 00000000 ____D C:\Program Files (x86)\NuGet 2013-11-24 17:50 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-11-24 17:50 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2013-11-24 17:27 - 2013-11-24 17:27 - 01034531 _____ (Thisisu) C:\Users\Christian\Downloads\JRT.exe.n0r22gs.partial 2013-11-24 17:24 - 2013-11-19 13:30 - 00000000 ____D C:\AdwCleaner 2013-11-24 16:16 - 2013-11-24 16:16 - 00000000 ____D C:\FRST 2013-11-24 16:14 - 2013-11-24 16:14 - 00000000 _____ C:\Users\Christian\defogger_reenable 2013-11-24 16:14 - 2013-10-21 09:15 - 00000000 ____D C:\Users\Christian 2013-11-24 12:19 - 2013-10-07 14:38 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Dropbox 2013-11-24 11:27 - 2013-05-04 16:45 - 00000000 ____D C:\Users\Christian\.VirtualBox 2013-11-23 20:36 - 2013-08-14 15:18 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Spotify 2013-11-23 20:35 - 2013-08-14 15:18 - 00000000 ____D C:\Users\Christian\AppData\Local\Spotify 2013-11-22 07:49 - 2013-11-22 07:49 - 00000931 _____ C:\Users\Christian\Desktop\DHBW.lnk 2013-11-22 07:47 - 2013-11-22 07:47 - 13321769 _____ C:\Users\Christian\Downloads\PanoramicMountains.deskthemepack 2013-11-21 18:50 - 2013-11-21 18:49 - 00000771 _____ C:\DelFix.txt 2013-11-21 18:50 - 2013-09-29 20:04 - 00028796 _____ C:\WINDOWS\PFRO.log 2013-11-21 18:50 - 2013-07-31 16:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-21 18:49 - 2013-11-19 13:37 - 00000000 ____D C:\WINDOWS\ERUNT 2013-11-21 18:35 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness 2013-11-21 06:48 - 2013-11-21 06:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-19 19:38 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache 2013-11-19 13:34 - 2013-08-22 15:44 - 00411576 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-11-19 13:34 - 2013-07-31 15:54 - 00000000 ___RD C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-19 13:34 - 2013-07-31 15:54 - 00000000 ___RD C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-11-19 13:34 - 2013-01-15 18:39 - 00000000 ___RD C:\Users\Christian\Podcasts 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ___RD C:\WINDOWS\ToastData 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\migwiz 2013-11-19 13:33 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2013-11-19 11:30 - 2013-08-01 16:53 - 00267936 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2013-11-16 09:11 - 2013-07-31 17:06 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-16 07:41 - 2013-02-15 15:55 - 00000000 ____D C:\xampp 2013-11-16 07:29 - 2013-10-21 09:13 - 00013914 _____ C:\WINDOWS\system32\lvcoinst.log 2013-11-15 15:30 - 2013-08-29 21:01 - 00001782 ____H C:\Users\Christian\.gitk 2013-11-14 18:06 - 2013-01-14 17:12 - 00000000 ____D C:\Users\Christian\AppData\Local\Packages 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Roaming\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Users\Christian\AppData\Local\AMD 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\ProgramData\ATI 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-11-14 14:33 - 2013-11-14 14:33 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-11-14 14:33 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files\ATI Technologies 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\ProgramData\AMD 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files\ATI 2013-11-14 14:32 - 2013-11-14 14:32 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-11-14 14:11 - 2013-08-07 17:22 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-11-14 14:10 - 2013-08-01 17:03 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2013-11-14 14:04 - 2013-11-14 14:04 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2013-11-14 14:03 - 2013-11-14 14:03 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2013-11-12 20:29 - 2013-11-10 02:09 - 00001351 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Git Lacker.lnk 2013-11-10 12:42 - 2013-10-03 14:58 - 00001332 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse.lnk 2013-11-10 12:42 - 2013-10-03 07:44 - 00000000 ____D C:\Users\Christian\.eclipse 2013-11-10 12:17 - 2013-11-10 12:17 - 00001392 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse-php.lnk 2013-11-10 12:14 - 2013-11-10 12:12 - 00000242 _____ C:\WINDOWS\pear.ini 2013-11-10 11:05 - 2013-11-10 11:05 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Friends 2013-11-10 11:04 - 2013-10-03 08:21 - 00000000 ____D C:\Program Files (x86)\eclipse 2013-11-10 02:18 - 2013-07-24 17:05 - 00000000 ____D C:\Users\Christian\.ssh 2013-11-06 00:31 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2013-11-06 00:31 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-05 21:21 - 2013-11-16 07:16 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2013-11-05 19:51 - 2013-11-16 07:16 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2013-11-05 17:20 - 2013-11-16 07:16 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2013-11-05 17:11 - 2013-11-16 07:16 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2013-11-05 15:30 - 2013-11-16 07:16 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2013-11-05 15:29 - 2013-11-16 07:16 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2013-11-05 08:07 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2013-11-01 16:36 - 2013-11-01 16:36 - 00000313 _____ C:\Users\Christian\.JMAppsCfg 2013-11-01 16:23 - 2013-11-01 16:23 - 05218242 _____ (InstallShield Software Corporation) C:\Users\Christian\Downloads\jmf-2_1_1e-windows-i586.exe 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Malwarebytes 2013-11-01 10:00 - 2013-11-01 10:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-31 14:39 - 2013-10-31 14:39 - 00000000 ____D C:\ProgramData\Oracle 2013-10-31 14:39 - 2013-10-31 14:38 - 00004249 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-31 14:39 - 2013-10-03 08:30 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-30 00:28 - 2013-10-30 00:28 - 02279104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsHelper.dll 2013-10-29 11:33 - 2013-07-31 17:06 - 00000000 ____D C:\Users\Christian\AppData\Local\Microsoft Help Some content of TEMP: ==================== C:\Users\Christian\AppData\Local\Temp\Dragon.exe C:\Users\Christian\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Christian\AppData\Local\Temp\npp.6.5.Installer.exe C:\Users\Christian\AppData\Local\Temp\ose00000.exe C:\Users\Christian\AppData\Local\Temp\Quarantine.exe C:\Users\Christian\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe [2013-11-16 07:16] - [2013-10-22 08:55] - 2328872 ____A (Microsoft Corporation) 63DC38C3E4564B2405D562855643ABA2 C:\Windows\SysWOW64\explorer.exe [2013-11-16 07:16] - [2013-10-22 07:03] - 2065448 ____A (Microsoft Corporation) 1A0BC9598E4A58FC84570FFF5A108E58 C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll [2013-11-16 07:16] - [2013-10-22 03:38] - 1362944 ____A (Microsoft Corporation) C72456BFFE941714CF05B0AA0BEE5B45 C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-24 18:01 ==================== End Of Log ============================ Hier die neuen Logs |
26.11.2013, 10:42 | #6 |
/// the machine /// TB-Ausbilder | Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II |
26.11.2013, 19:42 | #7 |
| Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Hallo, also ich hab immer noch das Symptom, dass mein Rechner nicht automatisch in Standby fährt. Gestern ist er mal automatisch in Standby gefahren, aber heute schon wieder nicht mehr. Grüße Christian Edit:YouTube hat gerade eben auch wieder den gleichen Fehler gehabt. |
27.11.2013, 11:47 | #8 |
/// the machine /// TB-Ausbilder | Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Deswegen stelle ich immer die Frage "Noch Probleme" die immer ignoriert wird was bedeutet nicht autoamtisch in Standby? Du lässt ihn also einfach offen stehen, ohnwas dran zu machen, und dann soll er nach einer Zeit X in Standby fahren, tut es aber nicht? Youtube, was genau, in welchem Browser, auch in anderen Browsern?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.11.2013, 13:03 | #9 |
| Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Automatisch in Standby bedeutet genau das für mich. Ich mach 30 Minuten nichts am Rechner und er geht dann automatisch in Standby. Das einzige was funktioniert, ist das der Bildschirm nach 10 Minuten aus geht. Ich verwende den Internet Explorer. Bei YouTube ist es so, dass irgendwann das Video stehen bleibt und ich dann nicht mehr über den Play-Button das Video weiter spielen lassen kann. Erst wenn ich Doppelklick auf das Video und es in Vollbild geht, dann geht es weiter. Das bedeutet dann aber nicht, dass das Video nicht wieder 10 Sekunden später stehen bleibt. Ich teste es gerade mit Firefox. Hier scheint es keine Probleme zu geben. Ich würde aber sehr gerne den IE weiter verwenden. Liebe Grüße Christian |
28.11.2013, 09:16 | #10 |
/// the machine /// TB-Ausbilder | Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Deinstalliere mal den Flash Player komplett und installiere ihn neu. zu dem Standby: Bitte mal auf dein Batteriesymbol klicken und die Energieoptionen checken, vielleicht hat sich da was verstellt.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.11.2013, 19:27 | #11 |
| Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Ich habe den Flash Player jetzt mal deinstalliert. Bei meinen Energieoptionen ist alles richtig eingestellt... Leider muss ich fast schon sagen. |
29.11.2013, 15:28 | #12 |
/// the machine /// TB-Ausbilder | Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Bedenke dass Du 2 Energieoptionen hast, Akku und Ladekabel, und es gibt noch erweiterte Einstellungen, die würde ich auch mal checken. Ansonsten wäre ich nämlich am Ende mit meinem Rat
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.11.2013, 15:32 | #13 |
| Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Ich hab ein Desktop-Rechner . Also kein Akku vorhanden! Die Deinstallation vom Flash-Player hat leider nicht gebracht. Ich hab gemerkt, dass nachdem ich die Scans und Tools laufen lassen habe, die Probleme weg waren. Sie sind nur wieder gekommen, falls das was hilft. |
30.11.2013, 16:46 | #14 | |
/// the machine /// TB-Ausbilder | Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) IIZitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.11.2013, 17:48 | #15 |
| Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II Ich meine nach dem Junkware Removal Tool. |
Themen zu Windows 8: Probleme mit Standby-Modus und Internet Explorer (YouTube) II |
4d36e972-e325-11ce-bfc1-08002be10318, adblock, administrator, adobe, branding, defender, desktop, error, excel, explorer, flash player, helper, internet, internet explorer, mozilla, ntdll.dll, office 2013, performance, plug-in, problem, programm, registry, richtlinie, scan, security, software, spotify web helper, svchost.exe, system, temp, warnung, win64, windows, windowsapps, winlogon.exe |