![]() |
|
Plagegeister aller Art und deren Bekämpfung: Einfachklick wird ungewollt zum DoppelklickWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #1 |
| ![]() Einfachklick wird ungewollt zum Doppelklick Hallo, Ich habe seit einigen Tagen das sehr nervtötende Problem, dass häufig wenn ich einfach klicke ein Doppel-oder manchmal sogar Vierfachklick ausgeführt wird. Ich habe hier von ähnlichen Problemen gelesen, die Ihr gelöst habt und da dachte ich mir versuche ich auch mal mein Glück. Ich werde einfach mal eure Checkliste durchgehen und hoffen, dass ihr mir dann helfen könnt. Was habe ich bisher gemacht: -defogger -FRST -GMER log-daten: Frst FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-11-2013 Ran by Maxi (administrator) on MAXI-PC on 27-11-2013 15:09:36 Running from C:\Users\Maxi\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Memeo) C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\N360.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe () C:\Program Files (x86)\watchmi\TvdService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\N360.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Spotify Ltd) C:\Users\Maxi\AppData\Roaming\Spotify\spotify.exe (Spotify Ltd) C:\Users\Maxi\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () D:\Programme\spotimote\spotimote.exe (Samsung) D:\Programme\Kies\Kies.exe (Akamai Technologies, Inc.) C:\Users\Maxi\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Maxi\AppData\Local\Akamai\netsession_win.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Samsung Electronics Co., Ltd.) D:\Programme\Kies\KiesTrayAgent.exe (Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) D:\Programme\iTunes\iTunesHelper.exe () C:\Users\Maxi\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Maxi\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Maxi\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Users\Maxi\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe () C:\Users\Maxi\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Users\Maxi\Downloads\Defogger.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-20] (Realtek Semiconductor) HKCU\...\Run: [Spotify] - C:\Users\Maxi\AppData\Roaming\Spotify\spotify.exe [5955072 2013-11-15] (Spotify Ltd) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Maxi\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-11-15] (Spotify Ltd) HKCU\...\Run: [spotimote] - D:\Programme\spotimote\spotimote.exe [2171952 2013-06-03] () HKCU\...\Run: [KiesPreload] - D:\Programme\Kies\Kies.exe [1564016 2013-07-26] (Samsung) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Maxi\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-02] (Intel Corporation) HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-03] (CyberLink) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-31] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-03-09] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-01-31] () HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [KiesTrayAgent] - D:\Programme\Kies\KiesTrayAgent.exe [311152 2013-07-26] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [iTunesHelper] - D:\Programme\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {8EF8E341-74C2-4294-9786-03F392B8D440} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=360&chn=retail&geo=DE&ver=21&locale=de_DE&gct=kwd&qsrc=2869 BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\IPS\IPSBHO.dll (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (iTunes Application Detector) - D:\Programme\iTunes\Mozilla Plugins\npitunes.dll () CHR Extension: (Google Docs) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Norton Identity Protection) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.0.27_0 CHR Extension: (Google Wallet) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (Gmail) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\Exts\Chrome.crx ==================== Services (Whitelisted) ================= R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-03-28] (Intel Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\N360.exe [264360 2013-10-08] (Symantec Corporation) R2 watchmi; C:\Program Files (x86)\watchmi\TvdService.exe [70144 2012-01-31] () ==================== Drivers (Whitelisted) ==================== R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20131114.001\BHDrvx64.sys [1524824 2013-11-02] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-21] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-21] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20131126.001\IDSvia64.sys [521816 2013-11-18] (Symantec Corporation) R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20131126.016\ENG64.SYS [126040 2013-11-18] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20131126.016\EX64.SYS [2099288 2013-11-18] (Symantec Corporation) R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1501000.012\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1501000.012\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1501000.012\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation) S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] R3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S4 NVHDA; system32\drivers\nvhda64v.sys [x] S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-27 15:09 - 2013-11-27 15:09 - 01958818 _____ (Farbar) C:\Users\Maxi\Downloads\FRST64.exe 2013-11-27 15:09 - 2013-11-27 15:09 - 00014985 _____ C:\Users\Maxi\Downloads\FRST.txt 2013-11-27 15:09 - 2013-11-27 15:09 - 00000000 ____D C:\FRST 2013-11-27 15:07 - 2013-11-27 15:07 - 00377856 _____ C:\Users\Maxi\Downloads\wzcg4jru.exe 2013-11-27 15:06 - 2013-11-27 15:07 - 00000470 _____ C:\Users\Maxi\Downloads\defogger_disable.log 2013-11-27 15:06 - 2013-11-27 15:06 - 00000000 _____ C:\Users\Maxi\defogger_reenable 2013-11-27 15:05 - 2013-11-27 15:05 - 00050477 _____ C:\Users\Maxi\Downloads\Defogger.exe 2013-11-26 18:26 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-26 18:24 - 2013-11-26 18:24 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-26 18:24 - 2013-11-26 18:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-26 18:24 - 2013-11-26 18:24 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-26 18:24 - 2013-11-26 18:24 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-26 18:24 - 2013-11-26 18:24 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-26 18:24 - 2013-11-26 18:24 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-26 18:24 - 2013-11-26 18:24 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-26 18:24 - 2013-11-26 18:24 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-26 18:24 - 2013-11-26 18:24 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-26 18:24 - 2013-11-26 18:24 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-26 18:24 - 2013-11-26 18:24 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-26 18:23 - 2013-11-26 18:26 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-26 13:38 - 2013-11-26 13:38 - 00000000 ____D C:\ProgramData\Nexon 2013-11-26 13:01 - 2013-11-26 13:42 - 00000000 ____D C:\Users\Maxi\Documents\Vindictus EU 2013-11-26 11:51 - 2013-11-26 11:51 - 00000670 _____ C:\Users\Maxi\Downloads\MatrixColumns.java 2013-11-26 11:50 - 2013-11-26 11:50 - 00000440 _____ C:\Users\Maxi\Downloads\Notensysteme.txt 2013-11-25 15:06 - 2013-11-25 15:06 - 00000183 _____ C:\Users\Public\Desktop\Vindictus EU.url 2013-11-25 15:06 - 2013-11-25 15:06 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1 2013-11-25 14:32 - 2013-11-26 13:01 - 00000000 ____D C:\ProgramData\NexonEU 2013-11-25 14:32 - 2013-11-25 14:32 - 00000000 ____D C:\Users\Maxi\AppData\Local\{A6BA325C-2421-406F-9FD6-40B42FAF5182} 2013-11-25 14:32 - 2013-11-25 14:32 - 00000000 ____D C:\Nexon 2013-11-25 13:56 - 2013-11-25 14:21 - 1972079553 _____ C:\Users\Maxi\Downloads\Vindictus.z02 2013-11-25 13:28 - 2013-11-25 13:56 - 2147350516 _____ C:\Users\Maxi\Downloads\Vindictus.z01 2013-11-25 13:01 - 2013-11-25 13:28 - 2151104311 _____ (Nexon) C:\Users\Maxi\Downloads\Vindictus.exe 2013-11-25 12:38 - 2013-11-25 12:38 - 00000000 ____D C:\Users\Maxi\AppData\Local\Akamai 2013-11-25 12:37 - 2013-11-25 12:37 - 10028912 _____ (Akamai Technologies, Inc.) C:\Users\Maxi\Downloads\NexonEU_Installer.exe 2013-11-24 20:53 - 2013-11-24 20:53 - 00001538 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-11-24 20:53 - 2013-11-24 20:53 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-11-24 20:53 - 2013-11-24 20:53 - 00000000 ____D C:\Program Files\iTunes 2013-11-24 20:53 - 2013-11-24 20:53 - 00000000 ____D C:\Program Files\iPod 2013-11-21 10:49 - 2013-11-21 10:49 - 00001170 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-11-21 10:48 - 2013-11-21 10:48 - 05831344 _____ (TeamViewer GmbH) C:\Users\Maxi\Downloads\TeamViewer_Setup_de-ckc (1).exe 2013-11-21 10:48 - 2013-11-21 10:48 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-11-20 10:45 - 2013-11-20 10:45 - 05831344 _____ (TeamViewer GmbH) C:\Users\Maxi\Downloads\TeamViewer_Setup_de-ckc.exe 2013-11-19 15:48 - 2013-11-19 15:48 - 32411232 _____ C:\Users\Maxi\Downloads\ghc-7.6.3-x86_64-unknown-mingw32.tar.bz2.crdownload 2013-11-19 12:40 - 2013-11-19 12:40 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360 2013-11-19 12:35 - 2013-11-19 12:44 - 742391808 _____ C:\Users\Maxi\Downloads\ubuntu-12.04.3-desktop-amd64.iso 2013-11-19 11:45 - 2013-11-19 11:45 - 00004270 _____ C:\Users\Maxi\Downloads\smime.p7s 2013-11-18 18:21 - 2013-11-18 18:21 - 00020530 _____ C:\ComboFix.txt 2013-11-18 18:15 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-11-18 18:15 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-11-18 18:15 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-11-18 18:15 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-11-18 18:15 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-11-18 18:15 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-11-18 18:15 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-11-18 18:15 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-11-18 18:14 - 2013-11-18 18:21 - 00000000 ____D C:\Qoobox 2013-11-18 18:14 - 2013-11-18 18:20 - 00000000 ____D C:\Windows\erdnt 2013-11-18 18:11 - 2013-11-18 18:11 - 05146764 _____ (Swearware) C:\Users\Maxi\Downloads\ComboFix (1).exe 2013-11-18 18:10 - 2013-11-18 18:11 - 05146764 ____R (Swearware) C:\Users\Maxi\Downloads\ComboFix.exe 2013-11-18 18:01 - 2013-11-18 18:10 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-11-18 18:01 - 2013-11-18 18:01 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Maxi\Downloads\mbar-1.07.0.1007.exe 2013-11-18 18:01 - 2013-11-18 18:01 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-11-18 18:01 - 2013-11-18 18:01 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-18 18:01 - 2013-11-18 18:01 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-18 16:30 - 2013-11-18 16:30 - 00000000 ____D C:\Users\Maxi\AppData\Local\{053E8251-9378-4D3B-89DE-5FA90214F201} 2013-11-15 02:19 - 2013-11-15 02:19 - 00000606 _____ C:\Users\Maxi\Desktop\tremulous - Verknüpfung.lnk 2013-11-14 12:11 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-14 12:11 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-14 12:11 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-14 12:11 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-14 12:11 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-14 12:11 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-14 12:11 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-14 12:11 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-14 12:11 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-14 12:11 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-14 12:11 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-14 12:11 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-14 12:11 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-14 12:11 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-14 12:11 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-14 12:11 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-14 12:11 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-14 12:11 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-14 12:11 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-14 12:11 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-14 12:11 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-14 12:11 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-14 12:11 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-14 12:11 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-14 12:11 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-14 12:11 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-14 12:11 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-14 12:11 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-14 12:11 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-14 12:11 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-03 17:38 - 2013-11-03 17:49 - 00015420 _____ C:\Users\Maxi\Downloads\sarah.odt 2013-11-03 16:35 - 2013-11-03 16:35 - 00014109 _____ C:\Users\Maxi\Documents\untitled_0.odt 2013-11-03 16:35 - 2013-11-03 16:35 - 00013810 _____ C:\Users\Maxi\Documents\richtige%20Gliederung.odt_0.odt 2013-11-03 16:04 - 2013-11-03 16:04 - 00000000 ____D C:\Users\Maxi\AppData\Roaming\OpenOffice 2013-11-03 14:28 - 2013-11-03 14:28 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2013-11-03 14:28 - 2013-11-03 14:28 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-11-02 14:03 - 2013-11-02 14:03 - 00135483 _____ C:\wubildr 2013-11-02 14:03 - 2013-11-02 14:03 - 00008192 _____ C:\wubildr.mbr 2013-11-02 13:45 - 2013-11-02 13:46 - 00000000 ____D C:\Users\Maxi\AppData\Roaming\CyberLink 2013-11-02 13:36 - 2013-11-02 13:36 - 00000699 _____ C:\Users\Maxi\Desktop\TreeSize Free.lnk 2013-11-02 13:36 - 2013-11-02 13:36 - 00000000 ____D C:\Users\Maxi\AppData\Roaming\JAM Software 2013-10-29 15:23 - 2013-10-29 15:23 - 00000747 _____ C:\Users\Public\Desktop\Crysis 3.lnk ==================== One Month Modified Files and Folders ======= 2013-11-27 15:09 - 2013-11-27 15:09 - 01958818 _____ (Farbar) C:\Users\Maxi\Downloads\FRST64.exe 2013-11-27 15:09 - 2013-11-27 15:09 - 00014985 _____ C:\Users\Maxi\Downloads\FRST.txt 2013-11-27 15:09 - 2013-11-27 15:09 - 00000000 ____D C:\FRST 2013-11-27 15:07 - 2013-11-27 15:07 - 00377856 _____ C:\Users\Maxi\Downloads\wzcg4jru.exe 2013-11-27 15:07 - 2013-11-27 15:06 - 00000470 _____ C:\Users\Maxi\Downloads\defogger_disable.log 2013-11-27 15:06 - 2013-11-27 15:06 - 00000000 _____ C:\Users\Maxi\defogger_reenable 2013-11-27 15:06 - 2013-03-30 13:33 - 00000000 ____D C:\Users\Maxi 2013-11-27 15:05 - 2013-11-27 15:05 - 00050477 _____ C:\Users\Maxi\Downloads\Defogger.exe 2013-11-27 15:05 - 2012-08-28 23:58 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2013-11-27 14:35 - 2013-04-07 14:47 - 00000000 ____D C:\Users\Maxi\AppData\Roaming\Spotify 2013-11-27 14:22 - 2013-03-30 13:30 - 01999948 _____ C:\Windows\WindowsUpdate.log 2013-11-27 14:16 - 2013-03-30 16:50 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-27 13:45 - 2009-07-14 05:51 - 00261289 _____ C:\Windows\setupact.log 2013-11-27 12:16 - 2013-03-30 16:50 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-27 11:12 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-27 11:12 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-27 11:09 - 2011-05-16 15:04 - 00654150 _____ C:\Windows\system32\perfh007.dat 2013-11-27 11:09 - 2011-05-16 15:04 - 00130022 _____ C:\Windows\system32\perfc007.dat 2013-11-27 11:09 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-27 11:05 - 2012-08-28 23:58 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2013-11-27 11:05 - 2010-11-21 04:47 - 00261834 _____ C:\Windows\PFRO.log 2013-11-27 11:05 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-26 23:47 - 2013-03-30 13:33 - 00001429 _____ C:\Users\Maxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-26 23:38 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-26 18:26 - 2013-11-26 18:23 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-26 18:24 - 2013-11-26 18:24 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-26 18:24 - 2013-11-26 18:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-26 18:24 - 2013-11-26 18:24 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-26 18:24 - 2013-11-26 18:24 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-26 18:24 - 2013-11-26 18:24 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-26 18:24 - 2013-11-26 18:24 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-26 18:24 - 2013-11-26 18:24 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-26 18:24 - 2013-11-26 18:24 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-26 18:24 - 2013-11-26 18:24 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-26 18:24 - 2013-11-26 18:24 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-26 18:24 - 2013-11-26 18:24 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-26 18:24 - 2013-11-26 18:24 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-26 18:24 - 2013-11-26 18:24 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-26 13:42 - 2013-11-26 13:01 - 00000000 ____D C:\Users\Maxi\Documents\Vindictus EU 2013-11-26 13:38 - 2013-11-26 13:38 - 00000000 ____D C:\ProgramData\Nexon 2013-11-26 13:01 - 2013-11-25 14:32 - 00000000 ____D C:\ProgramData\NexonEU 2013-11-26 11:51 - 2013-11-26 11:51 - 00000670 _____ C:\Users\Maxi\Downloads\MatrixColumns.java 2013-11-26 11:50 - 2013-11-26 11:50 - 00000440 _____ C:\Users\Maxi\Downloads\Notensysteme.txt 2013-11-26 11:32 - 2013-04-07 14:47 - 00000000 ____D C:\Users\Maxi\AppData\Local\Spotify 2013-11-26 01:10 - 2013-03-30 18:07 - 00000000 ____D C:\Users\Maxi\AppData\Roaming\Skype 2013-11-25 15:06 - 2013-11-25 15:06 - 00000183 _____ C:\Users\Public\Desktop\Vindictus EU.url 2013-11-25 15:06 - 2013-11-25 15:06 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1 2013-11-25 14:32 - 2013-11-25 14:32 - 00000000 ____D C:\Users\Maxi\AppData\Local\{A6BA325C-2421-406F-9FD6-40B42FAF5182} 2013-11-25 14:32 - 2013-11-25 14:32 - 00000000 ____D C:\Nexon 2013-11-25 14:21 - 2013-11-25 13:56 - 1972079553 _____ C:\Users\Maxi\Downloads\Vindictus.z02 2013-11-25 13:56 - 2013-11-25 13:28 - 2147350516 _____ C:\Users\Maxi\Downloads\Vindictus.z01 2013-11-25 13:28 - 2013-11-25 13:01 - 2151104311 _____ (Nexon) C:\Users\Maxi\Downloads\Vindictus.exe 2013-11-25 12:38 - 2013-11-25 12:38 - 00000000 ____D C:\Users\Maxi\AppData\Local\Akamai 2013-11-25 12:37 - 2013-11-25 12:37 - 10028912 _____ (Akamai Technologies, Inc.) C:\Users\Maxi\Downloads\NexonEU_Installer.exe 2013-11-24 20:53 - 2013-11-24 20:53 - 00001538 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-11-24 20:53 - 2013-11-24 20:53 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-11-24 20:53 - 2013-11-24 20:53 - 00000000 ____D C:\Program Files\iTunes 2013-11-24 20:53 - 2013-11-24 20:53 - 00000000 ____D C:\Program Files\iPod 2013-11-21 14:35 - 2009-07-14 05:45 - 00325136 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-21 10:49 - 2013-11-21 10:49 - 00001170 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-11-21 10:49 - 2013-10-25 15:19 - 00000000 ____D C:\Users\Maxi\AppData\Roaming\TeamViewer 2013-11-21 10:49 - 2013-03-30 13:33 - 00067992 _____ C:\Users\Maxi\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-21 10:48 - 2013-11-21 10:48 - 05831344 _____ (TeamViewer GmbH) C:\Users\Maxi\Downloads\TeamViewer_Setup_de-ckc (1).exe 2013-11-21 10:48 - 2013-11-21 10:48 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-11-21 03:14 - 2013-04-05 22:17 - 00000000 ____D C:\Users\Maxi\AppData\Local\CrashDumps 2013-11-20 20:33 - 2013-05-02 20:20 - 00000000 ____D C:\Users\Maxi\AppData\Local\Warframe 2013-11-20 20:18 - 2011-07-18 21:49 - 00269994 _____ C:\Windows\DirectX.log 2013-11-20 10:45 - 2013-11-20 10:45 - 05831344 _____ (TeamViewer GmbH) C:\Users\Maxi\Downloads\TeamViewer_Setup_de-ckc.exe 2013-11-19 15:48 - 2013-11-19 15:48 - 32411232 _____ C:\Users\Maxi\Downloads\ghc-7.6.3-x86_64-unknown-mingw32.tar.bz2.crdownload 2013-11-19 12:44 - 2013-11-19 12:35 - 742391808 _____ C:\Users\Maxi\Downloads\ubuntu-12.04.3-desktop-amd64.iso 2013-11-19 12:40 - 2013-11-19 12:40 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360 2013-11-19 12:34 - 2013-04-08 13:45 - 00002323 _____ C:\Users\Public\Desktop\Norton 360.lnk 2013-11-19 12:34 - 2013-03-30 17:19 - 00003206 _____ C:\Windows\System32\Tasks\Norton WSC Integration 2013-11-19 12:34 - 2013-03-30 17:19 - 00000000 ____D C:\Windows\system32\Drivers\N360x64 2013-11-19 11:45 - 2013-11-19 11:45 - 00004270 _____ C:\Users\Maxi\Downloads\smime.p7s 2013-11-19 10:14 - 2013-04-08 13:45 - 00177752 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-11-19 10:14 - 2013-04-08 13:45 - 00008222 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-11-19 10:14 - 2013-04-08 13:45 - 00000000 ____D C:\Program Files (x86)\Norton 360 2013-11-19 10:14 - 2013-03-30 17:17 - 00000000 ____D C:\ProgramData\Norton 2013-11-19 10:11 - 2013-04-08 13:43 - 00000000 ____D C:\Users\Public\Downloads\Norton 2013-11-18 18:21 - 2013-11-18 18:21 - 00020530 _____ C:\ComboFix.txt 2013-11-18 18:21 - 2013-11-18 18:14 - 00000000 ____D C:\Qoobox 2013-11-18 18:20 - 2013-11-18 18:14 - 00000000 ____D C:\Windows\erdnt 2013-11-18 18:20 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2013-11-18 18:11 - 2013-11-18 18:11 - 05146764 _____ (Swearware) C:\Users\Maxi\Downloads\ComboFix (1).exe 2013-11-18 18:11 - 2013-11-18 18:10 - 05146764 ____R (Swearware) C:\Users\Maxi\Downloads\ComboFix.exe 2013-11-18 18:10 - 2013-11-18 18:01 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-11-18 18:01 - 2013-11-18 18:01 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Maxi\Downloads\mbar-1.07.0.1007.exe 2013-11-18 18:01 - 2013-11-18 18:01 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-11-18 18:01 - 2013-11-18 18:01 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-18 18:01 - 2013-11-18 18:01 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-18 16:30 - 2013-11-18 16:30 - 00000000 ____D C:\Users\Maxi\AppData\Local\{053E8251-9378-4D3B-89DE-5FA90214F201} 2013-11-15 02:19 - 2013-11-15 02:19 - 00000606 _____ C:\Users\Maxi\Desktop\tremulous - Verknüpfung.lnk 2013-11-15 02:18 - 2013-10-03 10:36 - 00000000 ____D C:\Users\Maxi\AppData\Roaming\Tremulous 2013-11-14 22:21 - 2013-03-30 16:51 - 00002179 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-14 18:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-14 12:54 - 2013-08-18 17:11 - 00000000 ____D C:\Windows\system32\MRT 2013-11-14 12:53 - 2011-07-18 21:31 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-06 10:28 - 2013-10-17 14:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-05 22:49 - 2013-10-17 14:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-11-03 17:49 - 2013-11-03 17:38 - 00015420 _____ C:\Users\Maxi\Downloads\sarah.odt 2013-11-03 16:35 - 2013-11-03 16:35 - 00014109 _____ C:\Users\Maxi\Documents\untitled_0.odt 2013-11-03 16:35 - 2013-11-03 16:35 - 00013810 _____ C:\Users\Maxi\Documents\richtige%20Gliederung.odt_0.odt 2013-11-03 16:04 - 2013-11-03 16:04 - 00000000 ____D C:\Users\Maxi\AppData\Roaming\OpenOffice 2013-11-03 14:28 - 2013-11-03 14:28 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2013-11-03 14:28 - 2013-11-03 14:28 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-11-03 13:36 - 2013-10-17 14:45 - 00000000 ____D C:\Users\Maxi\AppData\Local\Thunderbird 2013-11-02 14:03 - 2013-11-02 14:03 - 00135483 _____ C:\wubildr 2013-11-02 14:03 - 2013-11-02 14:03 - 00008192 _____ C:\wubildr.mbr 2013-11-02 13:46 - 2013-11-02 13:45 - 00000000 ____D C:\Users\Maxi\AppData\Roaming\CyberLink 2013-11-02 13:45 - 2012-08-29 16:24 - 00000000 ____D C:\Users\Public\CyberLink 2013-11-02 13:45 - 2012-08-29 15:57 - 00000000 ____D C:\ProgramData\CyberLink 2013-11-02 13:36 - 2013-11-02 13:36 - 00000699 _____ C:\Users\Maxi\Desktop\TreeSize Free.lnk 2013-11-02 13:36 - 2013-11-02 13:36 - 00000000 ____D C:\Users\Maxi\AppData\Roaming\JAM Software 2013-10-29 15:23 - 2013-10-29 15:23 - 00000747 _____ C:\Users\Public\Desktop\Crysis 3.lnk Some content of TEMP: ==================== C:\Users\Maxi\AppData\Local\Temp\bdfilters.dll C:\Users\Maxi\AppData\Local\Temp\NGMDll.dll C:\Users\Maxi\AppData\Local\Temp\NGMResource.dll C:\Users\Maxi\AppData\Local\Temp\NGMSetup.exe C:\Users\Maxi\AppData\Local\Temp\unicows.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 02:14 ==================== End Of Log ============================ --- --- --- FRST-addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-11-2013 Ran by Maxi at 2013-11-27 15:09:55 Running from C:\Users\Maxi\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Norton 360 (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton 360 (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton 360 (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== µTorrent (HKCU Version: 3.3.1.30017) Adobe AIR (x32 Version: 3.3.0.3670) Adobe Flash Player 11 ActiveX (x32 Version: 11.3.300.265) Adobe Reader X (10.1.8) MUI (x32 Version: 10.1.8) Akamai NetSession Interface (HKCU) AMD Accelerated Video Transcoding (Version: 2.00.0002) AMD APP SDK Runtime (Version: 10.0.898.1) AMD AVIVO64 Codecs (Version: 12.3.103.20309) AMD Catalyst Install Manager (Version: 3.0.868.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.70309.0018) Apple Application Support (x32 Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (x32 Version: 2.1.3.127) Ashampoo Snap 4 v.4.3.0 (x32 Version: 4.3.0) Assassin's Creed (x32 Version: 1.02) Assassin's Creed II (x32 Version: 1.01) Bandisoft MPEG-1 Decoder (x32) Battle Realms (x32 Version: 0.10.000) Bonjour (Version: 3.0.0.10) Catalyst Control Center (x32 Version: 2012.0309.43.976) Catalyst Control Center InstallProxy (x32 Version: 2012.0309.43.976) Catalyst Control Center Localization All (x32 Version: 2012.0309.43.976) CCC Help Danish (x32 Version: 2012.0309.0042.976) CCC Help Dutch (x32 Version: 2012.0309.0042.976) CCC Help English (x32 Version: 2012.0309.0042.976) CCC Help Finnish (x32 Version: 2012.0309.0042.976) CCC Help French (x32 Version: 2012.0309.0042.976) CCC Help German (x32 Version: 2012.0309.0042.976) CCC Help Italian (x32 Version: 2012.0309.0042.976) CCC Help Japanese (x32 Version: 2012.0309.0042.976) CCC Help Norwegian (x32 Version: 2012.0309.0042.976) CCC Help Spanish (x32 Version: 2012.0309.0042.976) CCC Help Swedish (x32 Version: 2012.0309.0042.976) ccc-utility64 (Version: 2012.0309.43.976) COMPUTERBILD Vorteil-Center (x32 Version: 1.1.23) Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2) Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2) Crysis®3 (x32 Version: 1.0.0.0) CyberLink LabelPrint (x32 Version: 2.5.3624) CyberLink Power2Go (x32 Version: 7.0.0.1327) CyberLink PowerDVD Copy (x32 Version: 1.5.1306) CyberLink PowerRecover (x32 Version: 5.5.5310) CyberLink WaveEditor (x32 Version: 1.0.1.2821) D3DX10 (x32 Version: 15.4.2368.0902) ElsterFormular (x32 Version: 14.1.20130301) Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (x32 Version: 15.4.5722.2) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922) Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922) Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922) Galerie de photos Windows Live (x32 Version: 15.4.3502.0922) Google Chrome (x32 Version: 31.0.1650.57) Google Update Helper (x32 Version: 1.3.21.165) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.36279) Intel(R) Management Engine Components (x32 Version: 8.0.10.1464) Intel(R) Rapid Storage Technology (x32 Version: 11.1.0.1006) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.5.235) Intel® Trusted Connect Service Client (Version: 1.23.943.1) iTunes (Version: 11.1.3.8) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) Java(TM) 7 Update 5 (64-bit) (Version: 7.0.50) Junk Mail filter update (x32 Version: 15.4.3502.0922) Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (x32 Version: 15.4.5722.2) League of Legends (x32 Version: 1.3) Medion Home Cinema (x32 Version: 8.0.3216) Memeo Instant Backup (x32 Version: 4.60.0.7943) Mesh Runtime (x32 Version: 15.4.5722.2) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office (x32 Version: 14.0.6120.5004) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Maintenance Service (x32 Version: 24.1.0) Mozilla Thunderbird 24.1.0 (x86 de) (x32 Version: 24.1.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) Norton 360 (x32 Version: 21.1.0.18) OpenOffice 4.0.1 (x32 Version: 4.01.9714) Origin (x32 Version: 9.3.10.4710) PlayReady PC Runtime amd64 (Version: 1.3.0) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922) Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922) Pošta Windows Live (x32 Version: 15.4.3502.0922) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922) Realtek Ethernet Controller Driver (x32 Version: 7.53.216.2012) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6710) Samsung Kies (x32 Version: 2.6.0.13064_2) Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0) Shutdown Timer (x32 Version: 3.3.4) Silkroad (x32) Skype™ 6.3 (x32 Version: 6.3.105) Spelling Dictionaries Support For Adobe Reader X (x32 Version: 10.0.0) Spotify (HKCU Version: 0.9.6.72.ge389c074) spotimote (x32) Star Wars: The Old Republic (x32 Version: 1.00) StarCraft II (x32) Stronghold Crusader HD (x32 Version: 1.30.0001) TeamSpeak 3 Client (x32 Version: 3.0.10) TeamViewer 8 (x32 Version: 8.0.22298) TreeSize Free V2.7 (x32 Version: 2.7) Tremulous 1.1.0 (x32) Ubisoft Game Launcher (x32 Version: 1.0.0.0) Ubuntu (x32 Version: 12.04.1-rev273) Unreal Tournament 2003 (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (x32 Version: 15.4.5722.2) Vindictus EU (x32) VirtualCloneDrive (x32 Version: 5.4.7.0) Warframe (x32 Version: 1.0.0) watchmi (x32 Version: 3.0.0) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3538.0513) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922) Windows Live Fotótár (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3538.0513) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2) Windows Live Mesh (x32 Version: 15.4.3502.0922) Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (x32 Version: 15.4.5722.2) Windows Live Messenger (x32 Version: 15.4.3538.0513) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (x32 Version: 15.4.5722.2) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-11-18 18:19 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {2D6CC583-EC92-48BB-8951-090BD8538F14} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\symerr.exe [2013-08-01] (Symantec Corporation) Task: {3F2B7A10-0824-439F-B487-8137D42499D6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {77011E39-329D-4DC3-9221-D87EC5441F13} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-03-27] (Intel Corporation) Task: {815545C2-9137-4145-BE72-A818FEFE3B61} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\WSCStub.exe [2013-10-08] (Symantec Corporation) Task: {970C9AE5-3AE7-405B-A49E-B08E8EFA5EF1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-30] (Google Inc.) Task: {D4DA7C48-8D06-44C1-9409-DB7F0182438A} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\symerr.exe [2013-08-01] (Symantec Corporation) Task: {DD75457D-FF80-457B-97C1-9B2470EABE64} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-30] (Google Inc.) Task: {E4A17C9F-86F0-48CA-AC33-52F350D3A582} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-03-27] (Intel Corporation) Task: {E4EA323C-C0C1-45DD-AB0C-27407A300FB4} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============= 2012-03-09 09:36 - 2012-03-09 09:36 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2013-01-28 12:08 - 2013-01-28 12:08 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-01-28 12:08 - 2013-01-28 12:08 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-04-07 14:47 - 2013-11-15 01:22 - 36967424 _____ () C:\Users\Maxi\AppData\Roaming\Spotify\Data\libcef.dll 2013-06-03 23:23 - 2013-06-03 23:23 - 00084528 _____ () D:\Programme\spotimote\msgdll.dll 2013-05-03 22:31 - 2013-05-03 22:31 - 01477840 _____ () D:\Programme\spotimote\libspotify.dll 2010-08-03 23:39 - 2010-08-03 23:39 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2010-08-03 23:39 - 2010-08-03 23:39 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2013-09-30 05:48 - 2013-11-15 01:22 - 00887808 _____ () C:\Users\Maxi\AppData\Roaming\Spotify\Data\libglesv2.dll 2013-09-30 05:48 - 2013-11-15 01:22 - 00109568 _____ () C:\Users\Maxi\AppData\Roaming\Spotify\Data\libegl.dll 2013-11-14 22:21 - 2013-11-14 12:28 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libglesv2.dll 2013-11-14 22:21 - 2013-11-14 12:28 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libegl.dll 2013-11-14 22:21 - 2013-11-14 12:29 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll 2013-11-14 22:21 - 2013-11-14 12:29 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll 2013-11-14 22:21 - 2013-11-14 12:28 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll 2013-08-18 22:37 - 2013-08-18 22:37 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\67f2d87ba056e1075fce76a8c50bb57e\IsdiInterop.ni.dll 2012-08-28 23:59 - 2012-02-02 00:25 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2012-08-28 23:58 - 2012-03-28 15:18 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-11-14 22:21 - 2013-11-14 12:29 - 13582800 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/27/2013 11:05:22 AM) (Source: MemeoBackgroundService) (User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (11/26/2013 11:38:31 PM) (Source: MemeoBackgroundService) (User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (11/26/2013 11:32:48 AM) (Source: MemeoBackgroundService) (User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (11/25/2013 09:46:11 AM) (Source: MemeoBackgroundService) (User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (11/24/2013 03:56:25 PM) (Source: MemeoBackgroundService) (User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (11/24/2013 01:57:50 PM) (Source: Application Hang) (User: ) Description: Programm crysis3.exe, Version 1.3.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: b44 Startzeit: 01cee90c458cb33c Endzeit: 544 Anwendungspfad: D:\Program Files (x86)\Origin Games\Crysis 3\Bin32\crysis3.exe Berichts-ID: Error: (11/23/2013 07:22:57 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7020 Error: (11/23/2013 07:22:57 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 7020 Error: (11/23/2013 07:22:57 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (11/23/2013 07:22:56 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6022 System errors: ============= Error: (11/27/2013 11:06:23 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/26/2013 11:59:47 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (11/26/2013 11:39:33 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/26/2013 00:35:23 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (11/26/2013 11:33:49 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/25/2013 07:56:06 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (11/25/2013 10:34:53 AM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (11/25/2013 09:47:12 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 03:57:26 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 00:49:25 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Microsoft Office Sessions: ========================= Error: (11/27/2013 11:05:22 AM) (Source: MemeoBackgroundService)(User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (11/26/2013 11:38:31 PM) (Source: MemeoBackgroundService)(User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (11/26/2013 11:32:48 AM) (Source: MemeoBackgroundService)(User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (11/25/2013 09:46:11 AM) (Source: MemeoBackgroundService)(User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (11/24/2013 03:56:25 PM) (Source: MemeoBackgroundService)(User: ) Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden. bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data) bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor) bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider) --- Ende der internen Ausnahmestapelüberwachung --- bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType) bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes) bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity) bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity) bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args) Error: (11/24/2013 01:57:50 PM) (Source: Application Hang)(User: ) Description: crysis3.exe1.3.0.0b4401cee90c458cb33c544D:\Program Files (x86)\Origin Games\Crysis 3\Bin32\crysis3.exe Error: (11/23/2013 07:22:57 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7020 Error: (11/23/2013 07:22:57 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 7020 Error: (11/23/2013 07:22:57 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (11/23/2013 07:22:56 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6022 CodeIntegrity Errors: =================================== Date: 2013-11-18 18:19:47.583 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-11-18 18:19:47.552 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 36% Total physical RAM: 8154.02 MB Available physical RAM: 5205.89 MB Total Pagefile: 16306.21 MB Available Pagefile: 12578.77 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:58.52 GB) (Free:8.37 GB) NTFS Drive d: () (Fixed) (Total:1813.01 GB) (Free:1663.15 GB) NTFS Drive e: (Recover) (Fixed) (Total:50 GB) (Free:35.67 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 60 GB) (Disk ID: D635E028) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=59 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=1 GB) - (Type=12) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 895AAD48) Partition 1: (Not Active) - (Size=-252313600000) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=50 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-11-27 15:21:36 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 C400-MTF rev.000F 59,63GB Running: gmer_2.1.19163.exe; Driver: C:\Users\Maxi\AppData\Local\Temp\pwldypod.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80003ff6000 64 bytes [C8, 4F, 29, 0F, 80, FA, FF, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 594 fffff80003ff6042 4 bytes [00, 00, 00, 00] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1944] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077011465 2 bytes [01, 77] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1944] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770114bb 2 bytes [01, 77] .text ... * 2 .text D:\Programme\Kies\Kies.exe[4068] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077011465 2 bytes [01, 77] .text D:\Programme\Kies\Kies.exe[4068] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770114bb 2 bytes [01, 77] .text ... * 2 .text C:\Users\Maxi\AppData\Local\Akamai\netsession_win.exe[4076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077011465 2 bytes [01, 77] .text C:\Users\Maxi\AppData\Local\Akamai\netsession_win.exe[4076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770114bb 2 bytes [01, 77] .text ... * 2 .text C:\Users\Maxi\AppData\Local\Akamai\netsession_win.exe[1492] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077011465 2 bytes [01, 77] .text C:\Users\Maxi\AppData\Local\Akamai\netsession_win.exe[1492] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770114bb 2 bytes [01, 77] .text ... * 2 .text D:\Programme\Kies\KiesTrayAgent.exe[4136] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077011465 2 bytes [01, 77] .text D:\Programme\Kies\KiesTrayAgent.exe[4136] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770114bb 2 bytes [01, 77] .text ... * 2 .text C:\Users\Maxi\Downloads\Defogger.exe[7788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077011465 2 bytes [01, 77] .text C:\Users\Maxi\Downloads\Defogger.exe[7788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770114bb 2 bytes [01, 77] .text ... * 2 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- Geändert von mrmaxify (27.11.2013 um 15:30 Uhr) |
![]() | #2 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Einfachklick wird ungewollt zum Doppelklick Hi,
__________________mal ne janz bescheidene Frage zu Beginn: Was für ne Maus? Schon mal ne andere versucht?
__________________ |
![]() | #3 |
| ![]() Einfachklick wird ungewollt zum Doppelklick Bescheidene, aber gute Frage
__________________![]() Habe gerade eine andere Maus ausprobiert und es funktioniert einwandfrei. Dabei hab ich bei alter Maus sogar schon Treibersoftware aktualisiert etc. Scheint also wirklich an der Maus zu liegen, was mich bei einer Hama uRage allerdings wundert... Trotzdem vielen Dank! |
![]() | #4 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Einfachklick wird ungewollt zum Doppelklick Gern Geschehen ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
Themen zu Einfachklick wird ungewollt zum Doppelklick |
adobe, akamai, bonjour, checkliste, combofix, defender, desktop, doppelklick, einfachklick, error, flash player, google, home, iexplore.exe, mozilla, object, plug-in, problem, realtek, registry, scan, secur, security, services.exe, software, spotify web helper, svchost.exe, symantec, system, usb |