|
Plagegeister aller Art und deren Bekämpfung: Problem GoogleWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.12.2013, 19:21 | #1 |
| Problem Google Guten Tag, mein Name ist Lenny und ich habe ein Problem, heute kam ich von einem Freund nachhause und wollte mein Projekt fertig stellen, ich öffnete Google Chrome und gab Google.com ein, doch es kam eine Fehlermeldung, die Seite konnte nicht aufgerufen werden. YouTube könnte ich zwar aufrufen aber die Videos funktionierten nicht. Nun Frage ich euch woran das liegen kann. System Infos: -Windows 7, 32Bit. Internetanschluss von 1&1. PS: Ich habe heute 2 Trojaner und eine C99Shell entfernt. |
01.12.2013, 19:51 | #2 |
/// the machine /// TB-Ausbilder | Problem Google hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
01.12.2013, 21:15 | #3 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Problem Google Addition:
__________________
FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-12-2013 Ran by User (administrator) on USER-PC on 01-12-2013 20:55:41 Running from C:\Users\User\Downloads\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Firebird Project) C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe (LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe () C:\xampp\mysql\bin\mysqld.exe () C:\Windows\System32\PnkBstrA.exe (Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe (AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe (Wajam) C:\Program Files\Wajam\Updater\WajamUpdater.exe () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\loggingserver.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgemcx.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Google Inc.) C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe (AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Firebird Project) C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Renesas Electronics Corporation) C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Iminent) C:\Program Files\Iminent\Iminent.exe (Iminent) C:\Program Files\Iminent\Iminent.Messengers.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe (LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe () C:\Program Files\AVG Nation toolbar\vprot.exe (Valve Corporation) C:\Program Files\Steam\Steam.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Overwolf) C:\Program Files\Overwolf\Overwolf.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft) C:\Program Files\Common Files\Overwolf\OverwolfHelper.exe () C:\Program Files\Overwolf\Purplizer\Purplizer.exe () C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation) C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9288296 2010-06-14] (Realtek Semiconductor) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-05-27] (Advanced Micro Devices, Inc.) HKLM\...\Run: [NUSB3MON] - C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation) HKLM\...\Run: [CLMLServer] - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-02] (CyberLink) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [LifeCam] - C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM\...\Run: [Iminent] - C:\Program Files\Iminent\Iminent.exe [1073744 2012-04-27] (Iminent) HKLM\...\Run: [IminentMessenger] - C:\Program Files\Iminent\Iminent.Messengers.exe [884816 2012-04-27] (Iminent) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-06-13] (Adobe Systems Incorporated) HKLM\...\Run: [SwitchBoard] - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM\...\Run: [AdobeCS6ServiceManager] - C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated) HKLM\...\Run: [amd_dc_opt] - C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411952 2013-09-23] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-05-15] (LogMeIn Inc.) HKLM\...\Run: [Adobe Creative Cloud] - C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-09-03] (Adobe Systems Incorporated) HKLM\...\Run: [vProt] - C:\Program Files\AVG Nation toolbar\vprot.exe [2403144 2013-10-02] () HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-05-11] (Google Inc.) HKCU\...\Run: [msnmsgr] - C:\Program Files\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation) HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [Spiele Post] - C:\Program Files\OXXOGames\GPlayer\GameCenterNotifier.exe [480328 2013-04-24] (Intenium) HKCU\...\Run: [Exetender_148] - "C:\Program Files\FreeRide Games\GPlayer.exe" /schedule 300000 HKCU\...\Run: [Overwolf] - C:\Program Files\Overwolf\Overwolf.exe [35256 2013-11-11] (Overwolf) MountPoints2: F - F:\HTC_Sync_Manager_PC.exe MountPoints2: {06a1ef87-9b2b-11e1-bd81-74f06d6ce3f5} - I:\CD_Start.exe MountPoints2: {a1c0b772-ec4b-11e2-93f6-6c626d887930} - F:\HTC_Sync_Manager_PC.exe MountPoints2: {bca08001-db14-11e2-9878-6c626d887930} - F:\HTC_Sync_Manager_PC.exe HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] () HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [ 2009-10-23] () HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] () HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [ 2009-10-23] () HKU\Philipp\...\Run: [Akamai NetSession Interface] - C:\Users\Philipp\AppData\Local\Akamai\netsession_win.exe [ 2013-06-05] (Akamai Technologies, Inc.) HKU\Philipp\...\Run: [msnmsgr] - C:\Program Files\Windows Live\Messenger\msnmsgr.exe [ 2010-04-16] (Microsoft Corporation) HKU\Philipp\...\Run: [RocketDock] - "C:\Program Files\RocketDock\RocketDock.exe" HKU\Philipp\...\Run: [AVG-Secure-Search-Update_0913b] - C:\Users\Philipp\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 7a32709e964f47d09a99bd2b2b6c90c3-ce3459d2a217299ab9ef231c670fdbc9aaf836df --CMPID 0913b AppInit_DLLs: c:\progra~2\browse~1\261519~1.190\{c16c1~1\browse~1.dll c:\progra~1\ssde96~1.hel\psupport.dll [ ] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.iminent.com/?appid=621f0543-39d7-4a9b-9678-97a5138c5442 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com HKCU\Software\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = hxxp://search.iminent.com/?appid=621f0543-39d7-4a9b-9678-97a5138c5442 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://my.myplaycity.com/ URLSearchHook: HKLM - (No Name) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No File SearchScopes: HKLM - DefaultScope {48B8DEF1-1E31-45F0-8FE4-3F4EAE05D89A} URL = SearchScopes: HKLM - Backup.Old.DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=DE&userid=4a862d30-b900-4f96-946f-0abc704d6be1&searchtype=ds&q={searchTerms} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://start.funmoods.com/results.php?f=4&q={searchTerms}&a=bf3&chnl=bf3&cd=2XzuyEtN2Y1L1QzuyB0AyBzytDyDyE0EtC0CtCtB0DtA0E0EtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=1235926218 SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=133&systemid=2&sr=0&q={searchTerms} SearchScopes: HKLM - {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://search.iminent.com/?appId=&ref=toolbox&q={searchTerms} SearchScopes: HKCU - DefaultScope {48B8DEF1-1E31-45F0-8FE4-3F4EAE05D89A} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3176921&CUI=UN34220508943161820&UM=2 SearchScopes: HKCU - Backup.Old.DefaultScope {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=DE&userid=4a862d30-b900-4f96-946f-0abc704d6be1&searchtype=ds&q={searchTerms}&installDate=01/01/1970 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A06E6C626D887930&affID=119982&tsp=4952 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {48B8DEF1-1E31-45F0-8FE4-3F4EAE05D89A} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3176921&CUI=UN34220508943161820&UM=2 SearchScopes: HKCU - {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = hxxp://my.myplaycity.com/results.php?category=web&s={searchTerms} BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - No File BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: ADDICT-THING Class - {54D8A4DF-A11D-8CDF-95A0-3D9FC0AD3B81} - C:\ProgramData\ADDICT-THING\bhoclass.dll () BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - No File BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - No File BHO: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent) BHO: Wajam - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: TheSea.TheSeaPlugin - {C585D593-E7F3-4852-A200-561686EE02E4} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Oracle) BHO: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - No File BHO: Yontoo - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC) BHO: BonanzaDeals - {fe063412-bea4-4d76-8ed3-183be6220d17} - C:\Program Files\BonanzaDeals\BonanzaDealsIE.dll No File Toolbar: HKLM - Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - No File Toolbar: HKLM - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - No File Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - No Name - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No File Toolbar: HKLM - Funmoods Toolbar - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - No File Toolbar: HKLM - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - No Name - {C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} - No File DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll (AVG Secure Search) Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default FF user.js: detected! => C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default\user.js FF NewTab: hxxp://www.doko-search.com/?babsrc=NT_ss&mntrId=A06E6C626D887930&affID=125836&tsp=5038 FF DefaultSearchEngine: MyPlayCity FF SearchEngineOrder.1: Delta Search FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: MyPlayCity FF Homepage: hxxp://search.iminent.com/?appId=621f0543-39d7-4a9b-9678-97a5138c5442&lcid=1031&ref=homepage FF Keyword.URL: hxxp://my.myplaycity.com/results.php?category=web&s= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll No File FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12\\npsitesafety.dll (AVG Technologies) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Oracle) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.bdupdater.com/BonanzaDealsLive Update;version=3 - C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll No File FF Plugin: @tools.bdupdater.com/BonanzaDealsLive Update;version=9 - C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll No File FF Plugin: @tools.dpliveupdate.com/DealPlyLive Update;version=3 - C:\Program Files\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll No File FF Plugin: @tools.dpliveupdate.com/DealPlyLive Update;version=9 - C:\Program Files\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll No File FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: @nsroblox.roblox.com/launcher - C:\Users\User\AppData\Local\Roblox\Versions\version-090353e3882541ce\\NPRobloxProxy.dll ( ROBLOX Corporation) FF Plugin HKCU: @soe.sony.com/installer,version=1.0.3 - C:\Users\User\AppData\LocalLow\Sony Online Entertainment\npsoe.dll () FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default\searchplugins\express-files-customized-web-search.xml FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default\searchplugins\myplaycity.xml FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default\searchplugins\SearchTheWeb.xml FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\User\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions FF Extension: OneClickDownloader - C:\Users\User\AppData\Roaming\Mozilla\Firefox\profiles\extensions\OneClickDownload@OneClickDownload.com FF Extension: No Name - C:\Users\User\AppData\Roaming\Mozilla\Firefox\profiles\extensions\user.js FF Extension: DowNload kEeeper - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default\Extensions\ttsoyy.9my@tob-aypbxzi.co.uk FF Extension: DealPly Shopping - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default\Extensions\{906000a4-88d9-4d52-b209-7a772970d91f} FF Extension: BonanzaDeals - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1rx4x1k3.default\Extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca} FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com Chrome: ======= CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\User\AppData\Local\funmoods.crx CHR HKLM\...\Chrome\Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C:\Users\User\AppData\Local\funmoods-speeddial.crx CHR HKLM\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonChrome.crx CHR HKLM\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\User\AppData\Roaming\BabSolution\CR\Delta.crx CHR HKLM\...\Chrome\Extension: [flolnhkojafikhpkpidiphabnpgedplh] - C:\Users\User\AppData\Local\CRE\flolnhkojafikhpkpidiphabnpgedplh.crx CHR HKLM\...\Chrome\Extension: [igdhbblpcellaljokkpfhcjlagemhgjl] - C:\Program Files\Iminent\Iminent.crx CHR HKLM\...\Chrome\Extension: [iibmmjhgclhlahmjniokmhleigemjpbh] - C:\Users\User\AppData\Local\CRE\iibmmjhgclhlahmjniokmhleigemjpbh.crx CHR HKLM\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\User\AppData\Local\Wajam\Chrome\wajam.crx CHR HKLM\...\Chrome\Extension: [leocdeigfnkaojcapikdjcdbedcjmffc] - C:\Users\User\AppData\Local\CRE\leocdeigfnkaojcapikdjcdbedcjmffc.crx CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Nation toolbar\ChromeExt\17.0.1.12\avg.crx CHR HKLM\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Users\User\AppData\Local\Temp\YontooLayers.crx CHR HKLM\...\Chrome\Extension: [nnolphifcgfkbkfdkmmhmlikpgmkblmh] - C:\ProgramData\DownloadnSave\nnolphifcgfkbkfdkmmhmlikpgmkblmh.crx CHR HKLM\...\Chrome\Extension: [pbghnefoidjbbkjgafiimmiaaknpfnpe] - C:\ProgramData\ADDICT-THING\pbghnefoidjbbkjgafiimmiaaknpfnpe.crx CHR HKLM\...\Chrome\Extension: [pmlghpafmmnmmkjdhacccolfgnkiboco] - C:\Program Files\1ClickDownload\oneclickdownloader10.crx ========================== Services (Whitelisted) ================= R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.) R2 Apache2.2; c:\xampp\apache\bin\httpd.exe [18432 2011-09-10] (Apache Software Foundation) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) R2 FirebirdGuardianDefaultInstance; C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe [98304 2010-09-17] (Firebird Project) R3 FirebirdServerDefaultInstance; C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe [3735552 2010-09-17] (Firebird Project) R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1435984 2013-05-15] (LogMeIn Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation) R2 mysql; c:\xampp\mysql\bin\my.ini [5396 2013-08-28] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation) S3 OverwolfUpdaterService; C:\Program Files\Overwolf\OverwolfUpdater.exe [18360 2013-11-11] (Overwolf Ltd) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-05-20] () R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.) R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [1740088 2013-09-23] (AVG) R2 vToolbarUpdater17.0.12; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe [1733448 2013-10-02] (AVG Secure Search) R2 WajamUpdater; C:\Program Files\Wajam\Updater\WajamUpdater.exe [109064 2012-04-24] (Wajam) S2 bonanzadealslive; C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe /svc [x] S3 bonanzadealslivem; C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe /medsvc [x] S3 iPod Service; "C:\Program Files\iPod\bin\iPodService.exe" [x] ==================== Drivers (Whitelisted) ==================== R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-09-05] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-10-02] (AVG Technologies) R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation) R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [64904 2010-04-27] (Renesas Electronics Corporation) R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [146568 2010-04-27] (Renesas Electronics Corporation) R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2013-09-18] (TuneUp Software) S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [x] R1 MpKsl3ba84040; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6FA50BB3-87FE-4DDA-A6ED-20759B8DE30E}\MpKsl3ba84040.sys [x] S3 uxddrv; \??\F:\uxddrv86.sys [x] S3 XDva397; \??\C:\Windows\system32\XDva397.sys [x] S3 XDva398; \??\C:\Windows\system32\XDva398.sys [x] S3 XDva399; \??\C:\Windows\system32\XDva399.sys [x] S3 XDva400; \??\C:\Windows\system32\XDva400.sys [x] S3 XDva401; \??\C:\Windows\system32\XDva401.sys [x] S3 XDva402; \??\C:\Windows\system32\XDva402.sys [x] S3 XDva404; \??\C:\Windows\system32\XDva404.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-01 20:55 - 2013-12-01 20:55 - 00000000 ____D C:\FRST 2013-12-01 20:54 - 2013-12-01 20:55 - 01092187 _____ (Farbar) C:\Users\User\Downloads\FRST.exe 2013-12-01 11:15 - 2013-12-01 11:15 - 00001335 _____ C:\Users\Public\Desktop\Der Fluch von Montezuma.lnk 2013-12-01 10:26 - 2013-12-01 10:30 - 49131544 _____ (INTENIUM GmbH) C:\Users\User\Downloads\DerFluchVonMontezuma.exe 2013-12-01 10:21 - 2013-12-01 10:21 - 00001359 _____ C:\Users\Public\Desktop\Geheimnis von Montezuma 3.lnk 2013-12-01 09:48 - 2013-12-01 09:58 - 143369176 _____ (INTENIUM GmbH) C:\Users\User\Downloads\GeheimnisVonMontezuma3.exe 2013-11-30 15:21 - 2013-11-30 15:22 - 00142801 _____ C:\Users\User\Downloads\Minecraft.jar 2013-11-30 13:22 - 2013-11-30 14:07 - 636786640 _____ (INTENIUM GmbH) C:\Users\User\Downloads\DieChronikenVonShakespeare2.exe 2013-11-30 12:20 - 2013-11-30 12:21 - 00000000 ____D C:\Users\User\AppData\Local\Deadtime Stories 2013-11-30 12:16 - 2013-11-30 12:16 - 00000000 ____D C:\ProgramData\Deadtime Stories 2013-11-30 12:03 - 2013-11-30 12:13 - 119971176 _____ (INTENIUM GmbH) C:\Users\User\Downloads\DeadtimeStories.exe 2013-11-30 11:34 - 2013-11-30 11:47 - 192773048 _____ (INTENIUM GmbH) C:\Users\User\Downloads\NightmareOnThePacific.exe 2013-11-30 10:09 - 2013-11-30 10:24 - 210350064 _____ (INTENIUM GmbH) C:\Users\User\Downloads\SamanthaSwift4.exe 2013-11-29 16:38 - 2013-11-29 16:38 - 00000000 ____D C:\Users\User\AppData\Roaming\mp3DirectCut 2013-11-29 16:35 - 2013-11-29 16:35 - 00000000 ____D C:\Program Files\mpshit 2013-11-28 20:00 - 2013-11-28 20:00 - 00000000 ____D C:\MicroVolts Package 2013-11-28 19:54 - 2013-11-28 19:55 - 01679872 _____ (Rock Hippo Productions) C:\Users\User\Downloads\MicroVolts_Package.exe 2013-11-28 17:51 - 2013-11-28 17:53 - 10009073 _____ C:\Users\User\Downloads\After Effects Intro Template #3 -TFT.rar 2013-11-28 12:04 - 2013-11-28 12:04 - 00000342 _____ C:\Users\User\Downloads\attachments_20131128120403.zip 2013-11-27 19:00 - 2013-11-27 19:00 - 00002576 _____ C:\Users\User\Downloads\help.yml 2013-11-27 19:00 - 2013-11-27 19:00 - 00001252 _____ C:\Users\User\Downloads\spigot.yml 2013-11-27 19:00 - 2013-11-27 19:00 - 00001126 _____ C:\Users\User\Downloads\server.log 2013-11-27 19:00 - 2013-11-27 19:00 - 00001082 _____ C:\Users\User\Downloads\bukkit.yml 2013-11-27 19:00 - 2013-11-27 19:00 - 00000815 _____ C:\Users\User\Downloads\server.log.1 2013-11-27 19:00 - 2013-11-27 19:00 - 00000109 _____ C:\Users\User\Downloads\banned-players.txt 2013-11-27 19:00 - 2013-11-27 19:00 - 00000109 _____ C:\Users\User\Downloads\banned-ips.txt 2013-11-27 19:00 - 2013-11-27 19:00 - 00000000 ____D C:\Users\User\Downloads\plugins 2013-11-27 19:00 - 2013-11-27 19:00 - 00000000 _____ C:\Users\User\Downloads\white-list.txt 2013-11-27 19:00 - 2013-11-27 19:00 - 00000000 _____ C:\Users\User\Downloads\server.log.lck 2013-11-27 19:00 - 2013-11-27 19:00 - 00000000 _____ C:\Users\User\Downloads\server.log.1.lck 2013-11-27 19:00 - 2013-11-27 19:00 - 00000000 _____ C:\Users\User\Downloads\ops.txt 2013-11-27 18:55 - 2013-11-27 18:59 - 19394634 _____ C:\Users\User\Downloads\Server.rar 2013-11-24 16:30 - 2013-11-24 16:30 - 00000000 ____D C:\Users\User\AppData\Roaming\ERS Game Studios 2013-11-24 13:53 - 2013-11-24 13:53 - 00002203 _____ C:\Users\Public\Desktop\Spiel Spirits of Mystery - Der dunkle Minotaurus.lnk 2013-11-24 13:50 - 2013-11-24 13:53 - 00000000 ____D C:\Program Files\Spirits of Mystery - Der dunkle Minotaurus 2013-11-24 13:50 - 2013-11-24 13:50 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spirits of Mystery - Der dunkle Minotaurus 2013-11-24 13:49 - 2013-11-24 13:49 - 00001869 _____ C:\Users\Public\Desktop\Game Manager.lnk 2013-11-24 13:49 - 2013-11-24 13:49 - 00000000 ____D C:\Program Files\bfgclient 2013-11-23 20:43 - 2013-11-23 20:43 - 00000000 ____D C:\Users\User\Documents\Eden Games 2013-11-23 20:37 - 2013-11-23 20:37 - 00000000 ____D C:\Users\User\AppData\Local\CrashRpt 2013-11-23 20:33 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2013-11-23 20:24 - 2013-11-23 20:24 - 00001057 _____ C:\Users\Public\Desktop\Test Drive Unlimited 2.lnk 2013-11-23 20:09 - 2013-11-23 20:09 - 00000000 ____D C:\Program Files\Atari 2013-11-23 15:18 - 2013-11-23 15:18 - 00002211 _____ C:\Users\Public\Desktop\Play More Playrix Games!.lnk 2013-11-23 15:18 - 2013-11-23 15:18 - 00001339 _____ C:\Users\Public\Desktop\The Path of Hercules.lnk 2013-11-23 11:34 - 2013-11-23 11:34 - 00001227 _____ C:\Users\Public\Desktop\World Voyage.lnk 2013-11-20 18:13 - 2013-12-01 20:38 - 00000000 ____D C:\Users\User\AppData\Local\Purplizer 2013-11-20 18:11 - 2013-11-20 18:11 - 00001925 _____ C:\Users\Public\Desktop\Overwolf.lnk 2013-11-20 18:11 - 2013-11-20 18:11 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2013-11-20 18:11 - 2013-11-20 18:11 - 00000000 ____D C:\Program Files\Overwolf 2013-11-20 18:11 - 2013-11-20 18:11 - 00000000 ____D C:\Program Files\Common Files\Overwolf 2013-11-20 18:06 - 2013-12-01 20:37 - 00000000 ____D C:\Users\User\AppData\Local\Overwolf 2013-11-20 11:27 - 2013-11-20 11:27 - 00000000 ____D C:\Users\User\AppData\Local\Artogon 2013-11-17 19:04 - 2013-11-17 19:04 - 00000000 ____D C:\Users\User\AppData\Roaming\OpenOffice 2013-11-15 08:52 - 2013-11-15 08:53 - 00000000 ____D C:\Users\User\AppData\Local\Chronicles of Albian 2 2013-11-14 15:51 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-14 15:51 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-14 15:51 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-14 15:51 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-14 15:51 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-14 15:51 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-14 15:51 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-14 15:50 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-14 15:50 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-14 15:50 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-14 15:50 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-14 15:50 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-14 15:50 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-14 15:50 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-14 15:50 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-14 15:50 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-14 15:50 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-14 15:50 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-14 13:50 - 2013-11-14 13:51 - 00000438 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-11-12 11:04 - 2013-11-12 11:04 - 17142784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 11220992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 04240384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-12 11:04 - 2013-11-12 11:04 - 02166272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 01926656 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-12 11:04 - 2013-11-12 11:04 - 01818112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-12 11:04 - 2013-11-12 11:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-12 11:04 - 2013-11-12 11:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-12 11:04 - 2013-11-12 11:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-12 11:03 - 2013-11-12 11:07 - 00010464 _____ C:\Windows\IE11_main.log 2013-11-08 20:47 - 2013-11-08 20:52 - 144752885 _____ C:\Users\Philipp\AppData\Local\ACCCx2_2_1_260.zip.aamdownload 2013-11-08 20:47 - 2013-11-08 20:52 - 00001817 _____ C:\Users\Philipp\AppData\Local\ACCCx2_2_1_260.zip.aamdownload.aamd 2013-11-05 18:01 - 2013-11-05 18:36 - 106246287 _____ C:\Users\Philipp\Downloads\Misa ResourcePack 1.6.4 and older (rw edit).zip 2013-11-05 17:59 - 2013-11-05 17:59 - 02161521 _____ C:\Users\Philipp\Downloads\MCpatcher.exe 2013-11-05 17:34 - 2013-11-05 17:46 - 89940403 _____ C:\Users\Philipp\Downloads\LB Photo Realism x256 10.0.0-converted-1374012707213.zip 2013-11-05 10:00 - 2013-11-05 10:00 - 00000000 ____D C:\Users\Public\Documents\intenium_de 2013-11-02 19:11 - 2013-11-02 19:27 - 00000000 ____D C:\Users\User\AppData\Local\fd 2013-11-02 11:45 - 2013-11-02 11:45 - 00000000 ____D C:\Users\User\AppData\Local\Murder on the Titanic 2013-11-01 18:54 - 2013-11-01 18:54 - 00000000 ____D C:\Users\User\AppData\Roaming\GO Games 2013-11-01 17:03 - 2013-11-01 17:03 - 00000000 ____D C:\Users\User\AppData\Roaming\VampireSagaHL ==================== One Month Modified Files and Folders ======= 2013-12-01 20:55 - 2013-12-01 20:55 - 00000000 ____D C:\FRST 2013-12-01 20:55 - 2013-12-01 20:54 - 01092187 _____ (Farbar) C:\Users\User\Downloads\FRST.exe 2013-12-01 20:55 - 2012-05-11 06:39 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-01 20:52 - 2013-10-17 13:47 - 00000910 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job 2013-12-01 20:52 - 2012-05-16 18:12 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype 2013-12-01 20:48 - 2012-05-11 15:25 - 01806393 _____ C:\Windows\WindowsUpdate.log 2013-12-01 20:44 - 2013-07-23 17:44 - 00000286 _____ C:\Windows\Tasks\Dealply.job 2013-12-01 20:44 - 2009-07-14 05:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-01 20:44 - 2009-07-14 05:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-01 20:39 - 2013-07-27 12:28 - 00000000 ____D C:\ProgramData\MFAData 2013-12-01 20:38 - 2013-11-20 18:13 - 00000000 ____D C:\Users\User\AppData\Local\Purplizer 2013-12-01 20:37 - 2013-11-20 18:06 - 00000000 ____D C:\Users\User\AppData\Local\Overwolf 2013-12-01 20:37 - 2012-06-04 17:52 - 00000000 ____D C:\Users\User\Tracing 2013-12-01 20:36 - 2012-12-29 15:34 - 00000000 ____D C:\Program Files\Steam 2013-12-01 20:36 - 2012-05-17 07:53 - 00000000 ____D C:\Users\User\AppData\Local\LogMeIn Hamachi 2013-12-01 20:35 - 2013-10-17 13:47 - 00000906 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job 2013-12-01 20:35 - 2012-07-10 13:19 - 00000000 ____D C:\Program Files\Common Files\Akamai 2013-12-01 20:35 - 2012-05-11 06:39 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-01 20:34 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-01 20:34 - 2009-07-14 05:39 - 00145641 _____ C:\Windows\setupact.log 2013-12-01 17:42 - 2013-01-13 15:25 - 00000000 ____D C:\Users\User\AppData\Roaming\TS3Client 2013-12-01 17:18 - 2013-10-02 15:02 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-01 17:12 - 2012-05-15 15:09 - 00000000 ____D C:\Users\User\AppData\Roaming\Adobe 2013-12-01 11:15 - 2013-12-01 11:15 - 00001335 _____ C:\Users\Public\Desktop\Der Fluch von Montezuma.lnk 2013-12-01 11:15 - 2013-09-14 10:19 - 00000000 ____D C:\Program Files\DEUTSCHLAND SPIELT 2013-12-01 11:15 - 2013-08-25 09:37 - 00000000 ____D C:\Users\User\AppData\Roaming\Friday's games 2013-12-01 11:15 - 2013-08-24 19:56 - 00001097 _____ C:\Users\Public\Desktop\GAME CENTER.lnk 2013-12-01 10:30 - 2013-12-01 10:26 - 49131544 _____ (INTENIUM GmbH) C:\Users\User\Downloads\DerFluchVonMontezuma.exe 2013-12-01 10:21 - 2013-12-01 10:21 - 00001359 _____ C:\Users\Public\Desktop\Geheimnis von Montezuma 3.lnk 2013-12-01 09:58 - 2013-12-01 09:48 - 143369176 _____ (INTENIUM GmbH) C:\Users\User\Downloads\GeheimnisVonMontezuma3.exe 2013-12-01 08:54 - 2012-06-20 13:10 - 00000000 ____D C:\Users\User\AppData\Local\Adobe 2013-11-30 19:09 - 2012-12-30 13:54 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-11-30 16:14 - 2012-06-20 14:26 - 00000000 ____D C:\Users\User\AppData\Roaming\.minecraft 2013-11-30 15:22 - 2013-11-30 15:21 - 00142801 _____ C:\Users\User\Downloads\Minecraft.jar 2013-11-30 14:25 - 2012-05-16 18:11 - 00000000 ___RD C:\Program Files\Skype 2013-11-30 14:25 - 2012-05-16 18:11 - 00000000 ____D C:\ProgramData\Skype 2013-11-30 14:07 - 2013-11-30 13:22 - 636786640 _____ (INTENIUM GmbH) C:\Users\User\Downloads\DieChronikenVonShakespeare2.exe 2013-11-30 12:21 - 2013-11-30 12:20 - 00000000 ____D C:\Users\User\AppData\Local\Deadtime Stories 2013-11-30 12:16 - 2013-11-30 12:16 - 00000000 ____D C:\ProgramData\Deadtime Stories 2013-11-30 12:13 - 2013-11-30 12:03 - 119971176 _____ (INTENIUM GmbH) C:\Users\User\Downloads\DeadtimeStories.exe 2013-11-30 11:47 - 2013-11-30 11:34 - 192773048 _____ (INTENIUM GmbH) C:\Users\User\Downloads\NightmareOnThePacific.exe 2013-11-30 10:24 - 2013-11-30 10:09 - 210350064 _____ (INTENIUM GmbH) C:\Users\User\Downloads\SamanthaSwift4.exe 2013-11-29 16:38 - 2013-11-29 16:38 - 00000000 ____D C:\Users\User\AppData\Roaming\mp3DirectCut 2013-11-29 16:35 - 2013-11-29 16:35 - 00000000 ____D C:\Program Files\mpshit 2013-11-29 13:05 - 2013-03-10 19:25 - 00000000 ____D C:\Users\User\AppData\Roaming\ShamanGS 2013-11-29 09:09 - 2013-02-22 10:22 - 00000000 ____D C:\Users\User\AppData\Roaming\AlawarEntertainment 2013-11-28 20:00 - 2013-11-28 20:00 - 00000000 ____D C:\MicroVolts Package 2013-11-28 19:55 - 2013-11-28 19:54 - 01679872 _____ (Rock Hippo Productions) C:\Users\User\Downloads\MicroVolts_Package.exe 2013-11-28 18:10 - 2013-02-02 13:15 - 00000000 ____D C:\Fraps 2013-11-28 17:53 - 2013-11-28 17:51 - 10009073 _____ C:\Users\User\Downloads\After Effects Intro Template #3 -TFT.rar 2013-11-28 17:00 - 2012-09-05 17:05 - 00000000 ____D C:\Users\User\AppData\Local\Paint.NET 2013-11-28 12:04 - 2013-11-28 12:04 - 00000342 _____ C:\Users\User\Downloads\attachments_20131128120403.zip 2013-11-27 19:00 - 2013-11-27 19:00 - 00002576 _____ C:\Users\User\Downloads\help.yml 2013-11-27 19:00 - 2013-11-27 19:00 - 00001252 _____ C:\Users\User\Downloads\spigot.yml 2013-11-27 19:00 - 2013-11-27 19:00 - 00001126 _____ C:\Users\User\Downloads\server.log 2013-11-27 19:00 - 2013-11-27 19:00 - 00001082 _____ C:\Users\User\Downloads\bukkit.yml 2013-11-27 19:00 - 2013-11-27 19:00 - 00000815 _____ C:\Users\User\Downloads\server.log.1 2013-11-27 19:00 - 2013-11-27 19:00 - 00000109 _____ C:\Users\User\Downloads\banned-players.txt 2013-11-27 19:00 - 2013-11-27 19:00 - 00000109 _____ C:\Users\User\Downloads\banned-ips.txt 2013-11-27 19:00 - 2013-11-27 19:00 - 00000000 ____D C:\Users\User\Downloads\plugins 2013-11-27 19:00 - 2013-11-27 19:00 - 00000000 _____ C:\Users\User\Downloads\white-list.txt 2013-11-27 19:00 - 2013-11-27 19:00 - 00000000 _____ C:\Users\User\Downloads\server.log.lck 2013-11-27 19:00 - 2013-11-27 19:00 - 00000000 _____ C:\Users\User\Downloads\server.log.1.lck 2013-11-27 19:00 - 2013-11-27 19:00 - 00000000 _____ C:\Users\User\Downloads\ops.txt 2013-11-27 19:00 - 2013-09-22 14:23 - 00000616 _____ C:\Users\User\Downloads\server.properties 2013-11-27 18:59 - 2013-11-27 18:55 - 19394634 _____ C:\Users\User\Downloads\Server.rar 2013-11-27 16:20 - 2012-08-01 09:27 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\TS3Client 2013-11-27 16:20 - 2012-07-04 14:12 - 00000000 ____D C:\Users\Philipp\AppData\Local\LogMeIn Hamachi 2013-11-27 15:39 - 2012-10-23 14:37 - 00000000 ____D C:\Users\Philipp\Tracing 2013-11-27 15:39 - 2012-07-21 09:16 - 00000000 ____D C:\Users\Philipp\AppData\Local\Adobe 2013-11-26 15:33 - 2010-08-28 01:49 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-24 18:53 - 2013-05-19 09:39 - 00000000 ____D C:\BigFishGamesCache 2013-11-24 16:30 - 2013-11-24 16:30 - 00000000 ____D C:\Users\User\AppData\Roaming\ERS Game Studios 2013-11-24 14:25 - 2012-11-20 18:18 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2013-11-24 13:53 - 2013-11-24 13:53 - 00002203 _____ C:\Users\Public\Desktop\Spiel Spirits of Mystery - Der dunkle Minotaurus.lnk 2013-11-24 13:53 - 2013-11-24 13:50 - 00000000 ____D C:\Program Files\Spirits of Mystery - Der dunkle Minotaurus 2013-11-24 13:50 - 2013-11-24 13:50 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spirits of Mystery - Der dunkle Minotaurus 2013-11-24 13:49 - 2013-11-24 13:49 - 00001869 _____ C:\Users\Public\Desktop\Game Manager.lnk 2013-11-24 13:49 - 2013-11-24 13:49 - 00000000 ____D C:\Program Files\bfgclient 2013-11-23 20:43 - 2013-11-23 20:43 - 00000000 ____D C:\Users\User\Documents\Eden Games 2013-11-23 20:37 - 2013-11-23 20:37 - 00000000 ____D C:\Users\User\AppData\Local\CrashRpt 2013-11-23 20:24 - 2013-11-23 20:24 - 00001057 _____ C:\Users\Public\Desktop\Test Drive Unlimited 2.lnk 2013-11-23 20:09 - 2013-11-23 20:09 - 00000000 ____D C:\Program Files\Atari 2013-11-23 15:18 - 2013-11-23 15:18 - 00002211 _____ C:\Users\Public\Desktop\Play More Playrix Games!.lnk 2013-11-23 15:18 - 2013-11-23 15:18 - 00001339 _____ C:\Users\Public\Desktop\The Path of Hercules.lnk 2013-11-23 15:17 - 2013-05-11 17:49 - 00000000 ____D C:\Program Files\Playrix Entertainment 2013-11-23 14:58 - 2012-09-09 12:21 - 00000000 ____D C:\ProgramData\Solidshield 2013-11-23 11:34 - 2013-11-23 11:34 - 00001227 _____ C:\Users\Public\Desktop\World Voyage.lnk 2013-11-23 11:34 - 2013-08-02 11:09 - 00000000 ____D C:\Users\User\AppData\Roaming\Sahmon Games 2013-11-22 21:38 - 2013-03-01 18:15 - 00000000 ____D C:\Users\User\AppData\Roaming\YoudaGames 2013-11-22 18:02 - 2012-09-16 08:59 - 00002004 ____H C:\Users\User\Documents\Default.rdp 2013-11-22 17:58 - 2013-09-17 13:36 - 00000000 ____D C:\ProgramData\Big Fish 2013-11-22 17:58 - 2013-09-17 13:32 - 00000000 ____D C:\BigFishCache 2013-11-22 17:10 - 2012-07-04 14:17 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Skype 2013-11-20 18:11 - 2013-11-20 18:11 - 00001925 _____ C:\Users\Public\Desktop\Overwolf.lnk 2013-11-20 18:11 - 2013-11-20 18:11 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2013-11-20 18:11 - 2013-11-20 18:11 - 00000000 ____D C:\Program Files\Overwolf 2013-11-20 18:11 - 2013-11-20 18:11 - 00000000 ____D C:\Program Files\Common Files\Overwolf 2013-11-20 11:27 - 2013-11-20 11:27 - 00000000 ____D C:\Users\User\AppData\Local\Artogon 2013-11-19 21:09 - 2012-05-17 16:40 - 00001912 _____ C:\Windows\epplauncher.mif 2013-11-19 21:09 - 2012-05-17 16:39 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-11-19 19:01 - 2013-09-04 16:19 - 00000185 _____ C:\Users\User\Downloads\conf1.txt 2013-11-19 19:01 - 2013-09-04 16:19 - 00000060 _____ C:\Users\User\Downloads\conf4.txt 2013-11-19 19:01 - 2013-09-04 16:19 - 00000060 _____ C:\Users\User\Downloads\conf3.txt 2013-11-19 19:01 - 2013-09-04 16:19 - 00000060 _____ C:\Users\User\Downloads\conf2.txt 2013-11-19 19:01 - 2013-09-04 16:19 - 00000003 _____ C:\Users\User\Downloads\lastactivemap.txt 2013-11-19 13:19 - 2013-10-08 10:15 - 00000000 ____D C:\Users\User\AppData\Roaming\quickclick 2013-11-19 11:21 - 2010-08-30 17:46 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-19 10:50 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2013-11-18 10:46 - 2013-09-13 13:37 - 00000000 ____D C:\Users\User\AppData\Roaming\MagicIndie 2013-11-18 07:57 - 2010-08-30 10:48 - 00064004 _____ C:\Windows\PFRO.log 2013-11-17 19:23 - 2013-10-30 12:41 - 00000000 ____D C:\Users\User\AppData\Roaming\Playrix Entertainment 2013-11-17 19:04 - 2013-11-17 19:04 - 00000000 ____D C:\Users\User\AppData\Roaming\OpenOffice 2013-11-17 19:01 - 2013-08-07 08:20 - 00000000 ____D C:\Program Files\MyPlayCity.com 2013-11-17 19:00 - 2012-06-30 16:37 - 00000000 ____D C:\Program Files\Lokas 2013-11-17 18:58 - 2012-05-24 17:07 - 00000000 ____D C:\Users\User\AppData\Roaming\Solveig Multimedia 2013-11-17 18:57 - 2012-07-15 12:31 - 00000000 ____D C:\Users\User\AppData\Local\Conduit 2013-11-17 18:52 - 2012-06-04 17:52 - 00000000 ____D C:\Program Files\IMinent Toolbar 2013-11-17 18:44 - 2012-08-09 17:05 - 00000000 ____D C:\Program Files\alaplaya 2013-11-17 18:42 - 2013-09-29 13:42 - 00000000 ____D C:\Program Files\AVG Nation toolbar 2013-11-17 08:20 - 2009-07-14 05:33 - 03768608 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-15 14:37 - 2013-06-17 10:51 - 00000000 ____D C:\Users\User\AppData\Roaming\Deep Shadows 2013-11-15 08:53 - 2013-11-15 08:52 - 00000000 ____D C:\Users\User\AppData\Local\Chronicles of Albian 2 2013-11-15 07:54 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-11-14 21:20 - 2013-08-14 10:26 - 00000000 ____D C:\Windows\system32\MRT 2013-11-14 21:16 - 2010-08-30 17:47 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-14 13:51 - 2013-11-14 13:50 - 00000438 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-11-14 13:50 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF 2013-11-14 13:47 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Public\Libraries 2013-11-14 13:40 - 2012-07-10 13:22 - 00000000 ____D C:\Users\Philipp\AppData\Local\Akamai 2013-11-13 16:32 - 2013-08-01 15:36 - 00000066 _____ C:\Users\Philipp\Downloads\conf1.txt 2013-11-13 16:32 - 2013-08-01 15:36 - 00000060 _____ C:\Users\Philipp\Downloads\conf4.txt 2013-11-13 16:32 - 2013-08-01 15:36 - 00000060 _____ C:\Users\Philipp\Downloads\conf3.txt 2013-11-13 16:32 - 2013-08-01 15:36 - 00000060 _____ C:\Users\Philipp\Downloads\conf2.txt 2013-11-13 16:32 - 2013-08-01 15:36 - 00000003 _____ C:\Users\Philipp\Downloads\lastactivemap.txt 2013-11-13 13:33 - 2013-02-21 14:47 - 00000000 ____D C:\ProgramData\Cateia Games 2013-11-13 13:10 - 2013-01-31 14:25 - 00000000 _____ C:\END 2013-11-12 11:07 - 2013-11-12 11:03 - 00010464 _____ C:\Windows\IE11_main.log 2013-11-12 11:04 - 2013-11-12 11:04 - 17142784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 11220992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 04240384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-12 11:04 - 2013-11-12 11:04 - 02166272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 01926656 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-12 11:04 - 2013-11-12 11:04 - 01818112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-12 11:04 - 2013-11-12 11:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-12 11:04 - 2013-11-12 11:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-12 11:04 - 2013-11-12 11:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-12 11:04 - 2013-11-12 11:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-12 11:04 - 2013-11-12 11:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-12 10:29 - 2013-04-12 17:24 - 00000000 ____D C:\ProgramData\Meridian93 2013-11-12 10:28 - 2013-02-23 13:48 - 00000000 ____D C:\Users\User\AppData\Roaming\Meridian93 2013-11-11 15:54 - 2013-07-05 11:07 - 00000000 ____D C:\Users\User\AppData\Roaming\JoyBits 2013-11-10 12:58 - 2013-10-30 14:08 - 00000000 ____D C:\Users\User\AppData\Roaming\Artifex Mundi 2013-11-08 20:52 - 2013-11-08 20:47 - 144752885 _____ C:\Users\Philipp\AppData\Local\ACCCx2_2_1_260.zip.aamdownload 2013-11-08 20:52 - 2013-11-08 20:47 - 00001817 _____ C:\Users\Philipp\AppData\Local\ACCCx2_2_1_260.zip.aamdownload.aamd 2013-11-08 14:32 - 2013-09-15 11:59 - 00000000 ____D C:\Users\User\AppData\Roaming\Gogii Games 2013-11-07 14:10 - 2013-02-17 15:28 - 00000000 ____D C:\ProgramData\Playrix Entertainment 2013-11-06 18:21 - 2012-07-04 14:46 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\.minecraft 2013-11-06 16:20 - 2012-09-15 20:26 - 00002006 ____H C:\Users\Philipp\Documents\Default.rdp 2013-11-05 18:36 - 2013-11-05 18:01 - 106246287 _____ C:\Users\Philipp\Downloads\Misa ResourcePack 1.6.4 and older (rw edit).zip 2013-11-05 17:59 - 2013-11-05 17:59 - 02161521 _____ C:\Users\Philipp\Downloads\MCpatcher.exe 2013-11-05 17:46 - 2013-11-05 17:34 - 89940403 _____ C:\Users\Philipp\Downloads\LB Photo Realism x256 10.0.0-converted-1374012707213.zip 2013-11-05 11:44 - 2013-10-29 13:24 - 00000000 ____D C:\Users\Public\Documents\intenium 2013-11-05 10:00 - 2013-11-05 10:00 - 00000000 ____D C:\Users\Public\Documents\intenium_de 2013-11-05 08:25 - 2013-02-17 15:28 - 00000000 ____D C:\ProgramData\Intenium 2013-11-04 13:41 - 2013-07-24 07:53 - 00000000 ____D C:\Users\User\AppData\Roaming\Freeze Tag 2013-11-04 10:59 - 2013-10-29 12:11 - 00000000 ____D C:\Users\User\AppData\Roaming\Daedalic Entertainment 2013-11-04 08:46 - 2013-06-24 12:57 - 00000000 ____D C:\Users\User\AppData\Roaming\Gogii 2013-11-02 19:27 - 2013-11-02 19:11 - 00000000 ____D C:\Users\User\AppData\Local\fd 2013-11-02 11:45 - 2013-11-02 11:45 - 00000000 ____D C:\Users\User\AppData\Local\Murder on the Titanic 2013-11-01 18:54 - 2013-11-01 18:54 - 00000000 ____D C:\Users\User\AppData\Roaming\GO Games 2013-11-01 17:03 - 2013-11-01 17:03 - 00000000 ____D C:\Users\User\AppData\Roaming\VampireSagaHL 2013-11-01 10:56 - 2013-06-26 18:19 - 00000000 ____D C:\Users\User\AppData\Roaming\ElementalsTheMagicKey 2013-11-01 09:45 - 2013-06-21 20:45 - 00000000 ____D C:\Users\User\AppData\Roaming\4 Friends Games 2013-11-01 08:44 - 2012-12-29 15:34 - 00000000 ____D C:\Program Files\Common Files\Steam Some content of TEMP: ==================== C:\Users\Philipp\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\Philipp\AppData\Local\Temp\CreativeCloudSet-Up.exe C:\Users\Philipp\AppData\Local\Temp\i4jdel0.exe C:\Users\Philipp\AppData\Local\Temp\i4jdel1.exe C:\Users\Philipp\AppData\Local\Temp\ICReinstall_ImageEditorSetup.exe C:\Users\Philipp\AppData\Local\Temp\jansi-32-git-Bukkit-1.3.1-R1.0-b2320jnks.dll C:\Users\Philipp\AppData\Local\Temp\jansi-32-git-Bukkit-1.5.2-R0.1-1-g53734d2-b2779jnks.dll C:\Users\Philipp\AppData\Local\Temp\jline_git-Bukkit-1_2_4-R1_0-b2126jnks.dll C:\Users\Philipp\AppData\Local\Temp\setup.exe C:\Users\Philipp\AppData\Local\Temp\SkypeSetup.exe C:\Users\Philipp\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll C:\Users\User\AppData\Local\Temp\BackupSetup.exe C:\Users\User\AppData\Local\Temp\i4jdel0.exe C:\Users\User\AppData\Local\Temp\jansi-32-git-Spigot-10.dll C:\Users\User\AppData\Local\Temp\tbexp0.dll C:\Users\User\AppData\Local\Temp\tempmessage.bfg ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 14:26 ==================== End Of Log ============================ |
02.12.2013, 11:42 | #4 | |
/// the machine /// TB-Ausbilder | Problem GoogleSo funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.12.2013, 17:15 | #5 |
| Problem Google Das Problem ist gestern von selbst weg gegangen. Trozdem danke |
03.12.2013, 10:15 | #6 |
/// the machine /// TB-Ausbilder | Problem Google ok
__________________ --> Problem Google |
Themen zu Problem Google |
anschluss, aufrufen, chrome, entfern, entfernt, fehlermeldung, fertig, frage, freund, funktionier, google, guten, heute, infos, konnte, problem, projekt, seite, shell, stelle, troja, trojaner, videos, woran, youtube |