|
Plagegeister aller Art und deren Bekämpfung: Internet extrem langsam gewordenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
30.12.2013, 23:02 | #1 |
| Internet extrem langsam geworden Hallo, mein Internet ist in letzerzeit extrem langsam geworden ( hoher ping in spielen, internetseiten werden extrem langsam geladen wenn überhaupt). Habe es bereits mit einem router neustart etc versucht jedoch hat das nichts gebracht. Ich habe bereits mit einem Malewarebytes Scan gemacht jedoch nichts gefunden. Bitte um Hilfe |
31.12.2013, 02:25 | #2 |
/// the machine /// TB-Ausbilder | Internet extrem langsam geworden hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
31.12.2013, 13:00 | #3 |
| Internet extrem langsam geworden Hallo,
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-12-2013 01 Ran by Besitzer (administrator) on LAPTOPJULIAN on 31-12-2013 12:55:33 Running from C:\Users\Besitzer\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Spotify Ltd) C:\Users\Besitzer\AppData\Roaming\Spotify\spotify.exe (Spotify Ltd) C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (Overwolf) C:\Program Files (x86)\Overwolf\Overwolf.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNAutoCon.exe () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Overwolf) C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper.exe (Overwolf) C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper64.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.196\deploy\LoLLauncher.exe () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.63\deploy\LolClient.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Farbar) C:\Users\Besitzer\Downloads\FRST64 (1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [589176 2011-12-20] (Alps Electric Co., Ltd.) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp HKLM\...\Run: [LoadFUJ02E3] - C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2012-01-16] (FUJITSU LIMITED) HKLM\...\Run: [PSUTility] - C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [205168 2011-10-03] (FUJITSU LIMITED) HKLM\...\Run: [LoadFujitsuQuickTouch] - C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [158024 2011-09-30] (FUJITSU LIMITED) HKLM\...\Run: [LoadBtnHnd] - C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [23368 2011-09-30] (FUJITSU LIMITED) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [MouseDriver] - C:\Windows\System32\TiltWheelMouse.exe [241152 2012-12-19] (Pixart Imaging Inc) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-06] (Intel Corporation) HKLM-x32\...\Run: [YouCam Service] - C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [255208 2012-03-21] (CyberLink Corp.) HKLM-x32\...\Run: [IndicatorUtility] - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [48752 2010-09-29] (FUJITSU LIMITED) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-02-01] () HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [Spotify] - C:\Users\Besitzer\AppData\Roaming\Spotify\spotify.exe [5951488 2013-12-07] (Spotify Ltd) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-07] (Spotify Ltd) HKCU\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe [456768 2013-10-19] (BillP Studios) HKCU\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe [35768 2013-12-09] (Overwolf) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF71A0D7D9D00CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Chrome: ======= CHR Extension: (Adblock Plus) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0 CHR Extension: (Google Wallet) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1 ==================== Services (Whitelisted) ================= R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [225280 2011-08-05] (DTS, Inc) R2 FUJ02E3Service; C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2012-01-16] (FUJITSU LIMITED) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf) R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [2213376 2011-12-22] (FUJITSU LIMITED) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2013-11-22] () R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63856 2011-10-03] (FUJITSU LIMITED) S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R0 FBIOSDRV; C:\Windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED) R3 FUJ02B1; C:\Windows\System32\DRIVERS\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED) R3 FUJ02E3; C:\Windows\System32\DRIVERS\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [24496 2012-03-09] (Intel Corporation) S3 iaStorS; C:\Windows\system32\drivers\iaStorS.sys [638896 2012-03-09] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 megasas2; C:\Windows\system32\drivers\megasas2.sys [51280 2010-11-02] (LSI Corporation) S3 megasr1; C:\Windows\system32\drivers\megasr1.sys [806696 2012-02-08] (LSI Corporation, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8217064 2012-01-02] (Realtek Semiconductor Corp.) R3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [6144 2012-12-19] () S3 catchme; \??\C:\ComboFix\catchme.sys [x] U4 losvaiin; U4 lrmykkgu; U4 X6va012; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-31 12:52 - 2013-12-31 12:55 - 01931302 _____ (Farbar) C:\Users\Besitzer\Downloads\FRST64 (1).exe 2013-12-30 14:47 - 2013-12-31 12:42 - 00000168 _____ C:\Windows\setupact.log 2013-12-30 14:47 - 2013-12-30 14:47 - 00000000 _____ C:\Windows\setuperr.log 2013-12-30 14:45 - 2013-12-30 14:45 - 01233962 _____ C:\Users\Besitzer\Downloads\adwcleaner (2).exe 2013-12-30 14:34 - 2013-12-30 14:34 - 00096108 _____ C:\Users\Besitzer\Documents\6.reg 2013-12-30 14:33 - 2013-12-30 14:33 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-12-30 14:31 - 2013-12-30 14:32 - 04645232 _____ (Piriform Ltd) C:\Users\Besitzer\Downloads\ccsetup409.exe 2013-12-27 23:08 - 2013-12-27 23:08 - 00000000 ____D C:\Program Files (x86)\LucasArts 2013-12-22 21:20 - 2013-12-22 21:20 - 00000000 ____D C:\Users\Besitzer\Desktop\Spiele 2013-12-14 12:26 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-14 12:26 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-14 12:26 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-14 12:26 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-14 12:24 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-14 12:24 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-14 12:24 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-14 12:24 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-14 12:24 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-14 12:24 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-14 12:24 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-14 12:24 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-14 12:24 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-14 12:24 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-14 12:24 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-14 12:24 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-14 12:24 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-14 12:24 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-14 12:24 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-14 12:24 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-14 12:24 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-14 12:24 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-14 12:24 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-14 12:24 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-14 12:24 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-14 12:24 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-14 12:24 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-14 12:24 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-14 12:24 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-14 12:24 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-14 12:24 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-14 12:24 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-14 12:24 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-14 12:24 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-14 12:24 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-13 23:25 - 2013-12-30 14:21 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2013-12-13 23:25 - 2013-12-13 23:25 - 00000000 ____D C:\Program Files (x86)\Overwolf 2013-12-13 23:22 - 2013-12-31 12:47 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Overwolf 2013-12-13 22:00 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-13 22:00 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-13 22:00 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-13 21:59 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-13 21:59 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-13 21:59 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-13 21:59 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-13 21:57 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-13 21:57 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-13 21:56 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-13 21:56 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-13 21:56 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-13 21:56 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-13 21:56 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-13 21:56 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-13 21:56 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-13 21:56 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-13 21:56 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-13 21:56 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-08 16:26 - 2013-12-08 16:25 - 00103736 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-12-07 13:04 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-07 12:59 - 2013-12-07 12:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-07 12:59 - 2013-12-07 12:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-07 12:59 - 2013-12-07 12:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-07 12:59 - 2013-12-07 12:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-07 12:59 - 2013-12-07 12:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-01 13:59 - 2013-12-08 16:53 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Xfire 2013-12-01 13:58 - 2013-12-08 12:22 - 00000000 ____D C:\ProgramData\Xfire 2013-12-01 13:58 - 2013-12-01 13:58 - 00000000 ____D C:\Program Files (x86)\Xfire 2013-12-01 13:56 - 2013-12-01 13:56 - 09714821 _____ C:\Users\Besitzer\Downloads\xfire_installer_46139.exe 2013-12-01 12:11 - 2013-12-01 12:15 - 00000000 ____D C:\ProgramData\InstallMate 2013-12-01 12:11 - 2013-12-01 12:11 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\WinPatrol 2013-12-01 12:11 - 2013-12-01 12:11 - 00000000 ____D C:\Program Files (x86)\BillP Studios 2013-12-01 12:10 - 2013-12-01 12:11 - 00910888 _____ (BillP Studios) C:\Users\Besitzer\Downloads\wpsetup.exe ==================== One Month Modified Files and Folders ======= 2013-12-31 12:56 - 2013-09-28 22:16 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Spotify 2013-12-31 12:56 - 2013-02-01 18:31 - 00000000 ____D C:\Users\Besitzer\AppData\Local\PMB Files 2013-12-31 12:55 - 2013-12-31 12:52 - 01931302 _____ (Farbar) C:\Users\Besitzer\Downloads\FRST64 (1).exe 2013-12-31 12:55 - 2013-11-16 15:17 - 00014029 _____ C:\Users\Besitzer\Downloads\FRST.txt 2013-12-31 12:51 - 2013-05-25 18:25 - 01137284 _____ C:\Windows\WindowsUpdate.log 2013-12-31 12:50 - 2009-07-14 05:45 - 00025872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-31 12:50 - 2009-07-14 05:45 - 00025872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-31 12:49 - 2013-02-01 18:00 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-31 12:49 - 2013-02-01 18:00 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-31 12:49 - 2013-01-28 21:22 - 01397356 _____ C:\Windows\system32\perfh007.dat 2013-12-31 12:49 - 2013-01-28 21:22 - 00368714 _____ C:\Windows\system32\perfc007.dat 2013-12-31 12:49 - 2009-07-14 06:13 - 00005414 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-31 12:47 - 2013-12-13 23:22 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Overwolf 2013-12-31 12:47 - 2013-04-13 16:49 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Skype 2013-12-31 12:47 - 2013-01-28 12:07 - 00000000 ____D C:\Users\Besitzer\Documents\Youcam 2013-12-31 12:43 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-31 12:42 - 2013-12-30 14:47 - 00000168 _____ C:\Windows\setupact.log 2013-12-31 01:23 - 2013-04-04 14:39 - 00000000 ____D C:\Program Files (x86)\Steam 2013-12-31 01:23 - 2013-02-17 17:49 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\TS3Client 2013-12-31 00:00 - 2013-11-01 12:34 - 00021840 ____T C:\Windows\SysWOW64\SIntfNT.dll 2013-12-31 00:00 - 2013-11-01 12:34 - 00017212 ____T C:\Windows\SysWOW64\SIntf32.dll 2013-12-31 00:00 - 2013-11-01 12:34 - 00012067 ____T C:\Windows\SysWOW64\SIntf16.dll 2013-12-30 14:47 - 2013-12-30 14:47 - 00000000 _____ C:\Windows\setuperr.log 2013-12-30 14:46 - 2013-11-17 13:47 - 00000000 ____D C:\AdwCleaner 2013-12-30 14:45 - 2013-12-30 14:45 - 01233962 _____ C:\Users\Besitzer\Downloads\adwcleaner (2).exe 2013-12-30 14:35 - 2013-02-01 18:31 - 00000000 ____D C:\ProgramData\PMB Files 2013-12-30 14:34 - 2013-12-30 14:34 - 00096108 _____ C:\Users\Besitzer\Documents\6.reg 2013-12-30 14:33 - 2013-12-30 14:33 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-12-30 14:33 - 2013-02-01 18:04 - 00000000 ____D C:\Program Files\CCleaner 2013-12-30 14:32 - 2013-12-30 14:31 - 04645232 _____ (Piriform Ltd) C:\Users\Besitzer\Downloads\ccsetup409.exe 2013-12-30 14:21 - 2013-12-13 23:25 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2013-12-30 14:21 - 2013-01-28 11:32 - 00000000 ____D C:\Users\Besitzer 2013-12-30 14:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-30 14:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-30 14:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-12-30 14:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat 2013-12-30 14:20 - 2013-01-28 11:41 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-30 13:58 - 2013-01-28 21:23 - 00000000 ____D C:\Windows\panther 2013-12-29 23:21 - 2013-09-28 22:18 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Spotify 2013-12-27 23:08 - 2013-12-27 23:08 - 00000000 ____D C:\Program Files (x86)\LucasArts 2013-12-26 11:03 - 2013-05-05 12:08 - 00000000 ____D C:\Users\Besitzer\Desktop\Musik 2013-12-24 22:05 - 2013-04-05 20:00 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-24 12:08 - 2013-04-13 16:49 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-12-24 12:08 - 2013-04-13 16:49 - 00000000 ____D C:\ProgramData\Skype 2013-12-22 21:23 - 2013-05-05 12:10 - 00000000 ___RD C:\Users\Besitzer\Desktop\Anwendungen 2013-12-22 21:21 - 2013-05-05 12:08 - 00000000 ____D C:\Users\Besitzer\Desktop\Bilder 2013-12-22 21:21 - 2013-05-05 12:07 - 00000000 ____D C:\Users\Besitzer\Desktop\Dokumente 2013-12-22 21:20 - 2013-12-22 21:20 - 00000000 ____D C:\Users\Besitzer\Desktop\Spiele 2013-12-15 18:26 - 2013-08-16 22:42 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 18:24 - 2013-06-09 15:45 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-15 12:34 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-15 12:24 - 2009-07-14 05:45 - 00292248 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-13 23:25 - 2013-12-13 23:25 - 00000000 ____D C:\Program Files (x86)\Overwolf 2013-12-08 16:53 - 2013-12-01 13:59 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Xfire 2013-12-08 16:25 - 2013-12-08 16:26 - 00103736 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-12-08 12:44 - 2013-02-01 18:00 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-08 12:44 - 2013-02-01 18:00 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-12-08 12:22 - 2013-12-01 13:58 - 00000000 ____D C:\ProgramData\Xfire 2013-12-08 12:20 - 2013-01-28 11:32 - 00001433 _____ C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-07 23:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-07 12:59 - 2013-12-07 12:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-07 12:59 - 2013-12-07 12:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-07 12:59 - 2013-12-07 12:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-07 12:59 - 2013-12-07 12:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-07 12:59 - 2013-12-07 12:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-06 20:46 - 2013-02-01 18:01 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-12-06 20:35 - 2013-01-28 11:32 - 00000000 ____D C:\Users\Besitzer\AppData\Local\VirtualStore 2013-12-01 13:58 - 2013-12-01 13:58 - 00000000 ____D C:\Program Files (x86)\Xfire 2013-12-01 13:56 - 2013-12-01 13:56 - 09714821 _____ C:\Users\Besitzer\Downloads\xfire_installer_46139.exe 2013-12-01 12:15 - 2013-12-01 12:11 - 00000000 ____D C:\ProgramData\InstallMate 2013-12-01 12:11 - 2013-12-01 12:11 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\WinPatrol 2013-12-01 12:11 - 2013-12-01 12:11 - 00000000 ____D C:\Program Files (x86)\BillP Studios 2013-12-01 12:11 - 2013-12-01 12:10 - 00910888 _____ (BillP Studios) C:\Users\Besitzer\Downloads\wpsetup.exe Some content of TEMP: ==================== C:\Users\Besitzer\AppData\Local\Temp\Quarantine.exe C:\Users\Besitzer\AppData\Local\Temp\SIntfNT.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-25 13:00 ==================== End Of Log ============================ FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-12-2013 01 Ran by Besitzer at 2013-12-31 12:57:45 Running from C:\Users\Besitzer\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Adobe Flash Player ActiveX (x32 Version: 9.0.47.0 - Adobe Systems Incorporated) Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8 - Adobe Systems Incorporated) Adobe Shockwave Player (x32 Version: 10.2.0.22 - Adobe Systems, Inc.) Age of Empires II: HD Edition (x32 Version: - ) ALPS Touch Pad Driver (Version: - ALPS ELECTRIC CO., LTD.) Apple Application Support (x32 Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.) Bonjour (Version: 3.0.0.10 - Apple Inc.) Call of Duty(R) 4 - Modern Warfare(TM) (x32 Version: 1.00.0000 - Activision) CCleaner (Version: 4.09 - Piriform) Counter-Strike: Source (x32 Version: - Valve) CyberLink YouCam 5 (x32 Version: 5.0.1521 - CyberLink Corp.) Day of Defeat: Source (x32 Version: - Valve) Diablo III (x32 Version: - Blizzard Entertainment) EE-ZDE (x32 Version: - ) Empire Earth (x32 Version: - ) ESET Online Scanner v3 (x32 Version: - ) FIFA 08 (x32 Version: 1.0.1.1 - Electronic Arts) FJ Camera (x32 Version: 6.1.7600.137 - Realtek Semiconductor Corp.) Free Video to iPhone Converter version 5.0.28.827 (x32 Version: 5.0.28.827 - DVDVideoSoft Ltd.) Fujitsu Hotkey Utility (x32 Version: 3.70.0.0 - FUJITSU LIMITED) Fujitsu MobilityCenter Extension Utility (Version: 3.01.00.002 - FUJITSU LIMITED) Fujitsu MobilityCenter Extension Utility (x32 Version: 3.01.00.002 - FUJITSU LIMITED) Fujitsu System Extension Utility (Version: 3.4.5.0 - FUJITSU LIMITED) Fujitsu System Extension Utility (x32 Version: 3.4.5.0 - FUJITSU LIMITED) GIMP 2.8.4 (Version: 2.8.4 - The GIMP Team) Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) High-Definition Video Playback (x32 Version: 7.3.10900.8.0 - Nero AG) Intel PROSet Wireless (Version: - ) Intel(R) Management Engine Components (x32 Version: 8.0.0.1351 - Intel Corporation) Intel(R) OpenCL CPU Runtime (x32 Version: - Intel Corporation) Intel(R) Processor Graphics (x32 Version: 8.15.10.2696 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.1.0.0096 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 2.0.0.0086 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.3.214 - Intel Corporation) Intel® PROSet/Wireless WiFi-Software (Version: 15.01.0000.0830 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.23.216.0 - Intel Corporation) iTunes (Version: 11.1.1.11 - Apple Inc.) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) League of Legends (x32 Version: 1.3 - Riot Games) LIFEBOOK Application Panel (Version: 8.3.2.0 - FUJITSU LIMITED) LIFEBOOK Application Panel (x32 Version: 8.3.2.0 - FUJITSU LIMITED) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft Age of Empires II (x32 Version: - ) Microsoft Age of Empires II: The Conquerors Expansion (x32 Version: - ) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Microsoft Office 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Microsoft Security Essentials (Version: 4.4.304.0 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) MinecraftAlpha (x32 Version: - ) MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MSXML4 Parser (x32 Version: 1.0.0 - Microsoft Game Studios) Nero 10 Movie ThemePack Basic (x32 Version: 10.6.10000.1.0 - Nero AG) Nero BurnRights 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Nero Control Center 10 (x32 Version: 10.6.12700.0.7 - Nero AG) Nero ControlCenter 10 Help (CHM) (x32 Version: 10.6.10800 - Nero AG) Nero Core Components 10 (x32 Version: 2.0.20000.9.12 - Nero AG) Nero CoverDesigner 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Nero InfoTool 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Nero Multimedia Suite 10 Essentials (x32 Version: 10.6.10200 - Nero AG) Nero StartSmart 10 (x32 Version: 10.6.10400.2.100 - Nero AG) Nero StartSmart 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Nero Update (x32 Version: 1.0.10900.31.0 - Nero AG) NeroKwikMedia Help (CHM) (x32 Version: 10.6.10900 - Nero AG) Overwolf (x32 Version: 0.47.284 - Overwolf) Pando Media Booster (x32 Version: 2.6.0.8 - Pando Networks Inc.) Plugfree NETWORK (Version: 6.2.0.1 - FUJITSU LIMITED) Plugfree NETWORK (Version: 6.2.001 - FUJITSU LIMITED) Power Saving Utility (x32 Version: 32.01.10.038 - FUJITSU LIMITED) Realtek Ethernet Controller Driver (x32 Version: 7.49.927.2011 - Realtek) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6526 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7601.30129 - Realtek Semiconductor Corp.) Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) Spotify (HKCU Version: 0.9.6.81.gd359a796 - Spotify AB) Steam (x32 Version: 1.0.0.0 - Valve Corporation) TeamSpeak 3 Client (HKCU Version: 3.0.13.1 - TeamSpeak Systems GmbH) Titan Quest (x32 Version: 1.00.0000 - Iron Lore) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Vocup 1.4.3 (x32 Version: 1.4.3 - Florian Amstutz) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5 - Microsoft Corporation) Windows Live Call (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Windows Live Communications Platform (x32 Version: 14.0.8117.416 - Microsoft Corporation) Windows Live Essentials (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Windows Live Essentials (x32 Version: 14.0.8117.416 - Microsoft Corporation) Windows Live Fotogalerie (x32 Version: 14.0.8117.416 - Microsoft Corporation) Windows Live Mail (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Windows Live Messenger (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Windows Live Movie Maker (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Windows Live Sync (x32 Version: 14.0.8117.416 - Microsoft Corporation) Windows Live Writer (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029 - Microsoft Corporation) WinPatrol (Version: 29.0.2013 - BillP Studios) WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0 - win.rar GmbH) Xfire (x32 Version: - ) ==================== Restore Points ========================= 14-12-2013 01:23:41 Windows Update 14-12-2013 11:23:03 Windows Modules Installer 14-12-2013 22:30:48 Windows Update 15-12-2013 17:23:50 Windows Update 20-12-2013 19:58:55 Windows Update 24-12-2013 21:01:39 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 24-12-2013 21:03:00 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 24-12-2013 21:03:32 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 24-12-2013 21:05:06 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 25-12-2013 11:28:24 Windows Update 27-12-2013 22:08:52 Installiert Star Wars Battlefront II 28-12-2013 22:33:27 Windows Update 29-12-2013 21:33:40 Installiert Empire Earth II 30-12-2013 13:17:29 Wiederherstellungsvorgang 30-12-2013 13:32:46 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-06-10 13:00 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {00830F52-A288-462A-9B24-23390498D620} - System32\Tasks\{46B09F65-A855-4701-909C-EE92EB59B1A0} => C:\Sierra\Empire Earth\Empire Earth.exe [2001-10-12] () Task: {07E89195-6B00-4E1B-BC07-A26F86ABEC30} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-01] (Google Inc.) Task: {246E4390-3A51-4591-B3F2-34221176F91C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-01] (Google Inc.) Task: {32E38577-989D-428F-8BA0-1FC66066E9F3} - System32\Tasks\{1E4D2DC2-9A1F-41A0-845A-F52CF6819397} => C:\Sierra\Empire Earth\Empire Earth.exe [2001-10-12] () Task: {53D2CB40-3782-4BDC-8DC5-3FB54A212D67} - System32\Tasks\{68889118-642F-4FD1-BBD0-C7DC526EC8CE} => Chrome.exe Skype auf Ihren Computer herunterladen ? Mac, Windows, Linux*?*Skype Task: {5D3B4AA6-826B-4BBD-97C6-39197B8EED9B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd) Task: {C94088A0-41FE-44BE-995E-71B87725A699} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {CA982104-4B6B-4451-8021-75F22A739476} - \BitGuard No Task File Task: {F8AA8A91-F48E-4AC8-BD05-632EDB44A9B6} - System32\Tasks\{CE8BD713-851B-4392-9C23-E0931C774379} => C:\Sierra\Empire Earth\Empire Earth.exe [2001-10-12] () Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-09 12:08 - 2013-12-09 12:08 - 00045608 _____ () C:\Program Files (x86)\Overwolf\x64\OWExplorer-20125.dll 2012-03-19 08:09 - 2012-03-19 08:09 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-12-09 12:08 - 2013-12-09 12:08 - 00039464 _____ () C:\Program Files (x86)\Overwolf\x64\OWLog.dll 2013-12-09 12:08 - 2013-12-09 12:08 - 00721960 _____ () C:\Program Files (x86)\Overwolf\x64\OWExplorerLauncher.dll 2013-01-28 13:08 - 2013-01-28 13:08 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-01-28 13:08 - 2013-01-28 13:08 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-01-28 11:48 - 2011-12-16 02:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-12-09 12:08 - 2013-12-09 12:08 - 00079400 _____ () C:\Program Files (x86)\Overwolf\OWExplorer-20125.dll 2013-09-28 22:18 - 2013-12-07 12:53 - 36967424 _____ () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\libcef.dll 2013-12-01 12:11 - 2013-07-15 18:29 - 00620718 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll 2013-12-09 12:08 - 2013-12-09 12:08 - 00015288 _____ () C:\Program Files (x86)\Overwolf\ODK.AddIns.V2.HostView.dll 2013-12-09 12:08 - 2013-12-09 12:08 - 00134696 _____ () C:\Program Files (x86)\Overwolf\OWService.dll 2013-12-09 12:08 - 2013-12-09 12:08 - 00970792 _____ () C:\Program Files (x86)\Overwolf\OWServer.dll 2013-12-09 12:08 - 2013-12-09 12:08 - 00038440 _____ () C:\Program Files (x86)\Overwolf\OWLog.dll 2013-12-09 12:08 - 2013-12-09 12:08 - 00025600 _____ () C:\Program Files (x86)\Overwolf\CoreAudioApi.dll 2013-12-09 12:08 - 2013-12-09 12:08 - 00839720 _____ () C:\Program Files (x86)\Overwolf\OWAgent.dll 2013-12-09 12:08 - 2013-12-09 12:08 - 00029224 _____ () C:\Program Files (x86)\Overwolf\OWExplorerLauncher.dll 2013-09-06 20:20 - 2013-12-20 20:51 - 00126816 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.196\deploy\RiotLauncher.dll 2013-07-10 09:25 - 2013-07-10 09:25 - 04774248 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.63\deploy\Adobe AIR\Versions\1.0\Resources\WebKit.dll 2013-12-06 20:46 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-06 20:46 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-06 20:46 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-06 20:46 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-06 20:46 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/31/2013 00:49:44 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (12/31/2013 00:49:44 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (12/31/2013 00:49:44 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (12/31/2013 00:43:13 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 10:04:37 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: League of Legends.exe, Version: 3.15.0.260, Zeitstempel: 0x52b20b88 Name des fehlerhaften Moduls: cgD3D9.dll, Version: 3.0.0.16, Zeitstempel: 0x4d55a06f Ausnahmecode: 0xc0000005 Fehleroffset: 0x000b6539 ID des fehlerhaften Prozesses: 0x171c Startzeit der fehlerhaften Anwendung: 0xLeague of Legends.exe0 Pfad der fehlerhaften Anwendung: League of Legends.exe1 Pfad des fehlerhaften Moduls: League of Legends.exe2 Berichtskennung: League of Legends.exe3 Error: (12/30/2013 09:10:14 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (12/30/2013 09:10:14 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (12/30/2013 09:10:14 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (12/30/2013 09:04:02 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 02:51:42 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. System errors: ============= Error: (12/31/2013 00:43:14 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (12/30/2013 09:04:03 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (12/30/2013 02:47:30 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (12/30/2013 02:22:54 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (12/30/2013 02:13:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (12/30/2013 02:13:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Error: (12/30/2013 02:12:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (12/30/2013 02:07:09 PM) (Source: DCOM) (User: ) Description: 1084wuauserv{E60687F7-01A1-40AA-86AC-DB1CBF673334} Error: (12/30/2013 02:06:07 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (12/30/2013 02:05:51 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= Error: (12/31/2013 00:49:44 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (12/31/2013 00:49:44 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (12/31/2013 00:49:44 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (12/31/2013 00:43:13 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 10:04:37 PM) (Source: Application Error)(User: ) Description: League of Legends.exe3.15.0.26052b20b88cgD3D9.dll3.0.0.164d55a06fc0000005000b6539171c01cf05a2a5926c10C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.1.4\deploy\League of Legends.exeC:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.1.4\deploy\cgD3D9.dllfd97f2ec-7195-11e3-bfca-685d435046e5 Error: (12/30/2013 09:10:14 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (12/30/2013 09:10:14 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (12/30/2013 09:10:14 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (12/30/2013 09:04:02 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 02:51:42 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl8F20300004D070000 CodeIntegrity Errors: =================================== Date: 2013-12-21 22:15:44.684 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-21 14:13:43.995 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-14 12:29:14.182 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-14 02:23:48.929 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-13 21:41:43.666 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 16:42:40.533 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 12:17:44.733 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-07 21:21:48.252 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-07 21:14:12.749 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-07 14:03:39.543 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 55% Total physical RAM: 3956.3 MB Available physical RAM: 1779.99 MB Total Pagefile: 7910.78 MB Available Pagefile: 4988.06 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.99 GB) (Free:190.71 GB) NTFS Drive d: (EEARTH) (CDROM) (Total:0.55 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: BEBC961E) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
01.01.2014, 13:00 | #4 | |
/// the machine /// TB-Ausbilder | Internet extrem langsam gewordenCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.01.2014, 13:32 | #5 |
| Internet extrem langsam geworden hier der logCombofix Logfile: Code:
ATTFilter ComboFix 13-12-31.01 - Besitzer 01.01.2014 13:11:20.3.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3956.2453 [GMT 1:00] ausgeführt von:: c:\users\Besitzer\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . ((((((((((((((((((((((( Dateien erstellt von 2013-12-01 bis 2014-01-01 )))))))))))))))))))))))))))))) . . 2014-01-01 12:17 . 2014-01-01 12:17 -------- d-----w- c:\users\Public\AppData\Local\temp 2014-01-01 12:17 . 2014-01-01 12:17 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-12-30 22:37 . 2013-12-30 22:37 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5FCDFD70-50E6-4D7E-AA79-39BC1A0F8673}\offreg.dll 2013-12-30 13:33 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5FCDFD70-50E6-4D7E-AA79-39BC1A0F8673}\mpengine.dll 2013-12-30 13:22 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-12-27 22:08 . 2013-12-27 22:08 -------- d-----w- c:\program files (x86)\LucasArts 2013-12-14 11:26 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL 2013-12-14 11:26 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2013-12-14 11:26 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe 2013-12-14 11:26 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL 2013-12-14 11:26 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll 2013-12-13 22:25 . 2013-12-13 22:25 -------- d-----w- c:\program files (x86)\Common Files\Overwolf 2013-12-13 22:25 . 2013-12-13 22:25 -------- d-----w- c:\program files (x86)\Overwolf 2013-12-13 22:22 . 2014-01-01 12:03 -------- d-----w- c:\users\Besitzer\AppData\Local\Overwolf 2013-12-13 21:00 . 2013-10-30 02:32 335360 ----a-w- c:\windows\system32\msieftp.dll 2013-12-13 21:00 . 2013-10-30 02:19 301568 ----a-w- c:\windows\SysWow64\msieftp.dll 2013-12-13 21:00 . 2013-10-30 01:24 3155968 ----a-w- c:\windows\system32\win32k.sys 2013-12-13 20:59 . 2013-11-23 18:26 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-12-13 20:59 . 2013-11-23 17:47 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-12-13 20:59 . 2013-10-19 02:18 81408 ----a-w- c:\windows\system32\imagehlp.dll 2013-12-13 20:59 . 2013-10-19 01:36 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll 2013-12-13 20:57 . 2013-11-12 02:23 2048 ----a-w- c:\windows\system32\tzres.dll 2013-12-13 20:57 . 2013-11-12 02:07 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2013-12-13 20:56 . 2013-10-04 02:16 116736 ----a-w- c:\windows\system32\drivers\drmk.sys 2013-12-13 20:56 . 2013-10-04 01:36 230400 ----a-w- c:\windows\system32\drivers\portcls.sys 2013-12-13 20:56 . 2013-10-12 02:32 150016 ----a-w- c:\windows\system32\wshom.ocx 2013-12-13 20:56 . 2013-10-12 02:04 121856 ----a-w- c:\windows\SysWow64\wshom.ocx 2013-12-13 20:56 . 2013-10-12 02:31 202752 ----a-w- c:\windows\system32\scrrun.dll 2013-12-13 20:56 . 2013-10-12 02:03 163840 ----a-w- c:\windows\SysWow64\scrrun.dll 2013-12-13 20:56 . 2013-10-12 01:33 156160 ----a-w- c:\windows\system32\cscript.exe 2013-12-13 20:56 . 2013-10-12 01:33 168960 ----a-w- c:\windows\system32\wscript.exe 2013-12-13 20:56 . 2013-10-12 01:15 141824 ----a-w- c:\windows\SysWow64\wscript.exe 2013-12-13 20:56 . 2013-10-12 01:15 126976 ----a-w- c:\windows\SysWow64\cscript.exe 2013-12-08 15:26 . 2013-12-08 15:25 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-12-07 12:04 . 2013-10-14 17:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE 2013-12-06 19:41 . 2013-10-18 22:20 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4B125B32-AAD7-43CC-BB8F-20F4ADAC88E3}\gapaengine.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-31 15:30 . 2013-11-01 11:34 21840 ----atw- c:\windows\SysWow64\SIntfNT.dll 2013-12-31 15:30 . 2013-11-01 11:34 17212 ----atw- c:\windows\SysWow64\SIntf32.dll 2013-12-31 15:30 . 2013-11-01 11:34 12067 ----atw- c:\windows\SysWow64\SIntf16.dll 2013-12-15 17:24 . 2013-06-09 14:45 90708896 ----a-w- c:\windows\system32\MRT.exe 2013-11-22 20:12 . 2013-11-22 18:16 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe 2013-11-19 10:21 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe 2013-10-18 22:20 . 2013-03-12 19:08 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2013-10-12 15:17 . 2013-10-12 15:17 102 ----a-w- c:\users\Public\sdelevURL.tmp 2013-10-12 02:30 . 2013-11-15 15:55 830464 ----a-w- c:\windows\system32\nshwfp.dll 2013-10-12 02:29 . 2013-11-15 15:55 859648 ----a-w- c:\windows\system32\IKEEXT.DLL 2013-10-12 02:29 . 2013-11-15 15:55 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2013-10-12 02:03 . 2013-11-15 15:55 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll 2013-10-12 02:01 . 2013-11-15 15:55 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL 2013-10-08 06:50 . 2013-10-27 12:42 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-10-05 20:25 . 2013-11-15 15:56 1474048 ----a-w- c:\windows\system32\crypt32.dll 2013-10-05 19:57 . 2013-11-15 15:56 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-10-04 02:28 . 2013-11-15 15:56 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll 2013-10-04 02:25 . 2013-11-15 15:56 197120 ----a-w- c:\windows\system32\credui.dll 2013-10-04 02:24 . 2013-11-15 15:56 1930752 ----a-w- c:\windows\system32\authui.dll 2013-10-04 01:58 . 2013-11-15 15:56 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll 2013-10-04 01:56 . 2013-11-15 15:56 168960 ----a-w- c:\windows\SysWow64\credui.dll 2013-10-04 01:56 . 2013-11-15 15:56 1796096 ----a-w- c:\windows\SysWow64\authui.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2013-02-01 3093624] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-11-14 20584608] "Spotify"="c:\users\Besitzer\AppData\Roaming\Spotify\Spotify.exe" [2013-12-07 5951488] "Spotify Web Helper"="c:\users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-12-07 1168896] "WinPatrol"="c:\program files (x86)\BillP Studios\WinPatrol\winpatrol.exe" [2013-10-19 456768] "Overwolf"="c:\program files (x86)\Overwolf\Overwolf.exe" [2013-12-09 35768] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-06 291608] "YouCam Service"="c:\program files (x86)\CyberLink\YouCam\YouCamService.exe" [2012-03-21 255208] "IndicatorUtility"="c:\program files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2010-09-29 48752] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-10-01 152392] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 iaStorS;iaStorS;c:\windows\system32\drivers\iaStorS.sys;c:\windows\SYSNATIVE\drivers\iaStorS.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 megasas2;megasas2;c:\windows\system32\drivers\megasas2.sys;c:\windows\SYSNATIVE\drivers\megasas2.sys [x] R3 megasr1;megasr1;c:\windows\system32\drivers\megasr1.sys;c:\windows\SYSNATIVE\drivers\megasr1.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x] R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x] R3 OverwolfUpdaterService;Overwolf Updater Service;c:\program files (x86)\Overwolf\OverwolfUpdater.exe;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [x] R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x] R3 tihub3;TI USB3 Hub Service;c:\windows\system32\drivers\tihub3.sys;c:\windows\SYSNATIVE\drivers\tihub3.sys [x] R3 tixhci;TI XHCI Service;c:\windows\system32\drivers\tixhci.sys;c:\windows\SYSNATIVE\drivers\tixhci.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] S0 FBIOSDRV;Fujitsu BIOS Driver;c:\windows\System32\Drivers\FBIOSDRV.sys;c:\windows\SYSNATIVE\Drivers\FBIOSDRV.sys [x] S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys;c:\windows\SYSNATIVE\drivers\iaStorF.sys [x] S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\drivers\iusb3hcs.sys;c:\windows\SYSNATIVE\drivers\iusb3hcs.sys [x] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x] S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x] S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x] S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 DTSAudioSvc;DTSAudioSvc;c:\program files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe;c:\program files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [x] S2 FUJ02E3Service;FUJ02E3Service;c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe;c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x] S2 PFNService;PFNService;c:\program files\Fujitsu\Plugfree NETWORK\PFNService.exe;c:\program files\Fujitsu\Plugfree NETWORK\PFNService.exe [x] S2 PowerSavingUtilityService;PowerSavingUtilityService;c:\program files\Fujitsu\PSUtility\PSUService.exe;c:\program files\Fujitsu\PSUtility\PSUService.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x] S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x] S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x] S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x] S3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\DRIVERS\FUJ02E3.sys;c:\windows\SYSNATIVE\DRIVERS\FUJ02E3.sys [x] S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 rtsuvc;FJ Camera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] S3 t_mouse.sys;HID-compliand device;c:\windows\system32\DRIVERS\t_mouse.sys;c:\windows\SYSNATIVE\DRIVERS\t_mouse.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-12-06 19:44 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-01-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-01 17:00] . 2013-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-01 17:00] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-25 170264] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-25 398616] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-25 439064] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-13 13374568] "RtHDVBg_DTS"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-11-15 2277992] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2011-12-20 589176] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-12-19 11406608] "LoadFUJ02E3"="c:\program files\Fujitsu\FUJ02E3\fuj02e3.exe" [2012-01-16 76104] "PSUTility"="c:\program files\Fujitsu\PSUtility\TrayManager.exe" [2011-10-03 205168] "LoadFujitsuQuickTouch"="c:\program files\Fujitsu\Application Panel\QuickTouch.exe" [2011-09-30 158024] "LoadBtnHnd"="c:\program files\Fujitsu\Application Panel\BtnHnd.exe" [2011-09-30 23368] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912] "MouseDriver"="TiltWheelMouse.exe" [2012-12-19 241152] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 192.168.178.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-Adobe Shockwave Player - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}] @Denied: (A 2) (Everyone) @="FlashProp Class" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.9" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9d.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9d.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}] @Denied: (A 2) (Everyone) @="IFlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-01-01 13:18:57 ComboFix-quarantined-files.txt 2014-01-01 12:18 . Vor Suchlauf: 17 Verzeichnis(se), 204.820.017.152 Bytes frei Nach Suchlauf: 20 Verzeichnis(se), 204.386.439.168 Bytes frei . - - End Of File - - CEC85E2E0E9DEC1001A2C09AA5024F52 |
02.01.2014, 08:56 | #6 |
/// the machine /// TB-Ausbilder | Internet extrem langsam geworden Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Internet extrem langsam geworden |
02.01.2014, 21:34 | #7 |
| Internet extrem langsam geworden Malwarebytes Anti-Malware 1.75.0.1300 Malwarebytes : Free Anti-Malware Datenbank Version: v2013.12.30.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 Besitzer :: LAPTOPJULIAN [Administrator] 02.01.2014 14:44:48 mbam-log-2014-01-02 (14-44-48).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 216080 Laufzeit: 6 Minute(n), 21 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 02/01/2014 um 15:04:18 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Besitzer - LAPTOPJULIAN # Gestartet von : C:\Users\Besitzer\Downloads\adwcleaner (3).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [2515 octets] - [17/11/2013 13:48:06] AdwCleaner[R1].txt - [2579 octets] - [17/11/2013 13:55:50] AdwCleaner[R2].txt - [994 octets] - [30/12/2013 14:45:33] AdwCleaner[R3].txt - [1114 octets] - [02/01/2014 15:02:18] AdwCleaner[S0].txt - [2369 octets] - [17/11/2013 13:56:52] AdwCleaner[S1].txt - [1054 octets] - [30/12/2013 14:45:57] AdwCleaner[S2].txt - [1036 octets] - [02/01/2014 15:04:18] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1096 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.9 (01.01.2014:1) OS: Windows 7 Professional x64 Ran by Besitzer on 02.01.2014 at 15:28:37,81 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 02.01.2014 at 15:33:29,36 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
03.01.2014, 12:42 | #8 |
/// the machine /// TB-Ausbilder | Internet extrem langsam gewordenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.01.2014, 00:57 | #9 |
| Internet extrem langsam geworden ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=afa2ed7bdd84804988f3b9d4436aeb43 # engine=14047 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-06-11 05:10:54 # local_time=2013-06-11 07:10:54 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 11566108 122600504 0 0 # scanned=100248 # found=0 # cleaned=0 # scan_time=16116 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=afa2ed7bdd84804988f3b9d4436aeb43 # engine=14049 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-06-11 06:48:10 # local_time=2013-06-11 08:48:10 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 11571944 122606340 0 0 # scanned=142381 # found=0 # cleaned=0 # scan_time=5483 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=afa2ed7bdd84804988f3b9d4436aeb43 # engine=16000 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-23 04:39:14 # local_time=2013-11-23 05:39:14 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 11686084 136854604 0 0 # scanned=159582 # found=0 # cleaned=0 # scan_time=17331 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=afa2ed7bdd84804988f3b9d4436aeb43 # engine=16505 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-03 10:19:00 # local_time=2014-01-03 11:19:00 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 15248870 140417390 0 0 # scanned=172179 # found=0 # cleaned=0 # scan_time=14092 Results of screen317's Security Check version 0.99.78 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 45 Adobe Reader 10.1.8 Adobe Reader out of Date! Google Chrome 31.0.1650.57 Google Chrome 31.0.1650.63 ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe WinPatrol winpatrol.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe BillP Studios WinPatrol WinPatrol.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` und zu guter letzt FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-01-2014 Ran by Besitzer (administrator) on LAPTOPJULIAN on 03-01-2014 23:57:14 Running from C:\Users\Besitzer\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Spotify Ltd) C:\Users\Besitzer\AppData\Roaming\Spotify\spotify.exe (Spotify Ltd) C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (Overwolf) C:\Program Files (x86)\Overwolf\Overwolf.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Overwolf) C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper.exe (Overwolf) C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper64.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNAutoCon.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [589176 2011-12-20] (Alps Electric Co., Ltd.) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp HKLM\...\Run: [LoadFUJ02E3] - C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2012-01-16] (FUJITSU LIMITED) HKLM\...\Run: [PSUTility] - C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [205168 2011-10-03] (FUJITSU LIMITED) HKLM\...\Run: [LoadFujitsuQuickTouch] - C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [158024 2011-09-30] (FUJITSU LIMITED) HKLM\...\Run: [LoadBtnHnd] - C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [23368 2011-09-30] (FUJITSU LIMITED) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [MouseDriver] - C:\Windows\System32\TiltWheelMouse.exe [241152 2012-12-19] (Pixart Imaging Inc) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-06] (Intel Corporation) HKLM-x32\...\Run: [YouCam Service] - C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [255208 2012-03-21] (CyberLink Corp.) HKLM-x32\...\Run: [IndicatorUtility] - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [48752 2010-09-29] (FUJITSU LIMITED) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-02-01] () HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [Spotify] - C:\Users\Besitzer\AppData\Roaming\Spotify\spotify.exe [5951488 2013-12-07] (Spotify Ltd) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Besitzer\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-07] (Spotify Ltd) HKCU\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe [456768 2013-10-19] (BillP Studios) HKCU\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe [35768 2013-12-09] (Overwolf) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF71A0D7D9D00CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Chrome: ======= CHR Extension: (Adblock Plus) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0 CHR Extension: (Google Wallet) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 ==================== Services (Whitelisted) ================= R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [225280 2011-08-05] (DTS, Inc) R2 FUJ02E3Service; C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2012-01-16] (FUJITSU LIMITED) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf) R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [2213376 2011-12-22] (FUJITSU LIMITED) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2013-11-22] () R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63856 2011-10-03] (FUJITSU LIMITED) S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R0 FBIOSDRV; C:\Windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED) R3 FUJ02B1; C:\Windows\System32\DRIVERS\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED) R3 FUJ02E3; C:\Windows\System32\DRIVERS\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [24496 2012-03-09] (Intel Corporation) S3 iaStorS; C:\Windows\system32\drivers\iaStorS.sys [638896 2012-03-09] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 megasas2; C:\Windows\system32\drivers\megasas2.sys [51280 2010-11-02] (LSI Corporation) S3 megasr1; C:\Windows\system32\drivers\megasr1.sys [806696 2012-02-08] (LSI Corporation, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8217064 2012-01-02] (Realtek Semiconductor Corp.) R3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [6144 2012-12-19] () S3 catchme; \??\C:\ComboFix\catchme.sys [x] U4 losvaiin; U4 lrmykkgu; U4 X6va012; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-03 23:56 - 2014-01-03 23:56 - 01931750 _____ (Farbar) C:\Users\Besitzer\Downloads\FRST64.exe 2014-01-03 23:47 - 2014-01-03 23:47 - 00987410 _____ C:\Users\Besitzer\Downloads\SecurityCheck (1).exe 2014-01-03 18:53 - 2014-01-03 18:53 - 02347384 _____ (ESET) C:\Users\Besitzer\Downloads\esetsmartinstaller_enu (2).exe 2014-01-02 23:00 - 2014-01-02 23:00 - 00002138 _____ C:\Users\Public\Desktop\Rise Of Nations.lnk 2014-01-02 15:33 - 2014-01-02 15:33 - 00000628 _____ C:\Users\Besitzer\Desktop\JRT.txt 2014-01-02 15:27 - 2014-01-02 15:27 - 01036305 _____ (Thisisu) C:\Users\Besitzer\Downloads\JRT (1).exe 2014-01-02 15:09 - 2014-01-02 15:09 - 00000000 __SHD C:\found.000 2014-01-02 15:01 - 2014-01-02 15:01 - 01233962 _____ C:\Users\Besitzer\Downloads\adwcleaner (3).exe 2014-01-02 14:41 - 2014-01-02 14:42 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Besitzer\Downloads\mbam-setup-1.75.0.1300 (1).exe 2014-01-01 13:28 - 2014-01-01 13:28 - 00000546 _____ C:\Windows\PFRO.log 2014-01-01 13:18 - 2014-01-01 13:18 - 00023546 _____ C:\ComboFix.txt 2014-01-01 13:09 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-01 13:09 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-01 13:09 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-01 13:09 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-01 13:09 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-01 13:09 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-01 13:09 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-01 13:09 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-01 13:08 - 2014-01-01 13:18 - 00000000 ____D C:\Qoobox 2014-01-01 13:06 - 2014-01-01 13:07 - 05160176 ____R (Swearware) C:\Users\Besitzer\Downloads\ComboFix.exe 2013-12-30 14:47 - 2014-01-03 13:52 - 00000560 _____ C:\Windows\setupact.log 2013-12-30 14:47 - 2013-12-30 14:47 - 00000000 _____ C:\Windows\setuperr.log 2013-12-30 14:45 - 2013-12-30 14:45 - 01233962 _____ C:\Users\Besitzer\Downloads\adwcleaner (2).exe 2013-12-30 14:34 - 2013-12-30 14:34 - 00096108 _____ C:\Users\Besitzer\Documents\6.reg 2013-12-30 14:33 - 2013-12-30 14:33 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-12-30 14:31 - 2013-12-30 14:32 - 04645232 _____ (Piriform Ltd) C:\Users\Besitzer\Downloads\ccsetup409.exe 2013-12-27 23:08 - 2013-12-27 23:08 - 00000000 ____D C:\Program Files (x86)\LucasArts 2013-12-22 21:20 - 2013-12-22 21:20 - 00000000 ____D C:\Users\Besitzer\Desktop\Spiele 2013-12-14 12:26 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-14 12:26 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-14 12:26 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-14 12:26 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-14 12:24 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-14 12:24 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-14 12:24 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-14 12:24 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-14 12:24 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-14 12:24 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-14 12:24 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-14 12:24 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-14 12:24 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-14 12:24 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-14 12:24 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-14 12:24 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-14 12:24 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-14 12:24 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-14 12:24 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-14 12:24 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-14 12:24 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-14 12:24 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-14 12:24 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-14 12:24 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-14 12:24 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-14 12:24 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-14 12:24 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-14 12:24 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-14 12:24 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-14 12:24 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-14 12:24 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-14 12:24 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-14 12:24 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-14 12:24 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-14 12:24 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-13 23:25 - 2013-12-30 14:21 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2013-12-13 23:25 - 2013-12-13 23:25 - 00000000 ____D C:\Program Files (x86)\Overwolf 2013-12-13 23:22 - 2014-01-03 18:50 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Overwolf 2013-12-13 22:00 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-13 22:00 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-13 22:00 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-13 21:59 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-13 21:59 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-13 21:59 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-13 21:59 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-13 21:57 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-13 21:57 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-13 21:56 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-13 21:56 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-13 21:56 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-13 21:56 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-13 21:56 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-13 21:56 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-13 21:56 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-13 21:56 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-13 21:56 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-13 21:56 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-08 16:26 - 2013-12-08 16:25 - 00103736 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-12-07 13:04 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-07 12:59 - 2013-12-07 12:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-07 12:59 - 2013-12-07 12:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-07 12:59 - 2013-12-07 12:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-07 12:59 - 2013-12-07 12:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-07 12:59 - 2013-12-07 12:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe ==================== One Month Modified Files and Folders ======= 2014-01-03 23:57 - 2013-11-16 15:17 - 00013559 _____ C:\Users\Besitzer\Downloads\FRST.txt 2014-01-03 23:56 - 2014-01-03 23:56 - 01931750 _____ (Farbar) C:\Users\Besitzer\Downloads\FRST64.exe 2014-01-03 23:50 - 2013-04-13 16:49 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Skype 2014-01-03 23:49 - 2013-02-01 18:00 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-03 23:47 - 2014-01-03 23:47 - 00987410 _____ C:\Users\Besitzer\Downloads\SecurityCheck (1).exe 2014-01-03 23:33 - 2013-09-28 22:16 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Spotify 2014-01-03 22:53 - 2009-07-14 05:45 - 00025872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-03 22:53 - 2009-07-14 05:45 - 00025872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-03 22:49 - 2013-05-25 18:25 - 01355624 _____ C:\Windows\WindowsUpdate.log 2014-01-03 19:16 - 2013-02-01 18:31 - 00000000 ____D C:\Users\Besitzer\AppData\Local\PMB Files 2014-01-03 19:15 - 2013-02-01 18:31 - 00000000 ____D C:\ProgramData\PMB Files 2014-01-03 18:53 - 2014-01-03 18:53 - 02347384 _____ (ESET) C:\Users\Besitzer\Downloads\esetsmartinstaller_enu (2).exe 2014-01-03 18:51 - 2013-01-28 12:07 - 00000000 ____D C:\Users\Besitzer\Documents\Youcam 2014-01-03 18:50 - 2013-12-13 23:22 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Overwolf 2014-01-03 18:50 - 2013-09-28 22:18 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Spotify 2014-01-03 18:50 - 2013-02-01 18:00 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-03 18:50 - 2013-01-28 11:57 - 00062864 _____ C:\Users\Besitzer\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-03 13:57 - 2013-01-28 21:22 - 01515692 _____ C:\Windows\system32\perfh007.dat 2014-01-03 13:57 - 2013-01-28 21:22 - 00406602 _____ C:\Windows\system32\perfc007.dat 2014-01-03 13:57 - 2009-07-14 06:13 - 00005414 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-03 13:52 - 2013-12-30 14:47 - 00000560 _____ C:\Windows\setupact.log 2014-01-03 13:52 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-03 13:52 - 2009-07-14 05:45 - 00292360 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-02 23:00 - 2014-01-02 23:00 - 00002138 _____ C:\Users\Public\Desktop\Rise Of Nations.lnk 2014-01-02 22:56 - 2013-04-04 23:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Games 2014-01-02 15:45 - 2013-02-17 17:49 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\TS3Client 2014-01-02 15:33 - 2014-01-02 15:33 - 00000628 _____ C:\Users\Besitzer\Desktop\JRT.txt 2014-01-02 15:27 - 2014-01-02 15:27 - 01036305 _____ (Thisisu) C:\Users\Besitzer\Downloads\JRT (1).exe 2014-01-02 15:09 - 2014-01-02 15:09 - 00000000 __SHD C:\found.000 2014-01-02 15:04 - 2013-11-17 13:47 - 00000000 ____D C:\AdwCleaner 2014-01-02 15:01 - 2014-01-02 15:01 - 01233962 _____ C:\Users\Besitzer\Downloads\adwcleaner (3).exe 2014-01-02 14:42 - 2014-01-02 14:41 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Besitzer\Downloads\mbam-setup-1.75.0.1300 (1).exe 2014-01-01 13:28 - 2014-01-01 13:28 - 00000546 _____ C:\Windows\PFRO.log 2014-01-01 13:18 - 2014-01-01 13:18 - 00023546 _____ C:\ComboFix.txt 2014-01-01 13:18 - 2014-01-01 13:08 - 00000000 ____D C:\Qoobox 2014-01-01 13:17 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-01 13:07 - 2014-01-01 13:06 - 05160176 ____R (Swearware) C:\Users\Besitzer\Downloads\ComboFix.exe 2014-01-01 13:07 - 2013-06-10 12:47 - 00000000 ____D C:\Windows\erdnt 2013-12-31 20:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-31 20:10 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-31 18:22 - 2013-11-16 15:18 - 00027785 _____ C:\Users\Besitzer\Downloads\Addition.txt 2013-12-31 16:30 - 2013-11-01 12:34 - 00021840 ____T C:\Windows\SysWOW64\SIntfNT.dll 2013-12-31 16:30 - 2013-11-01 12:34 - 00017212 ____T C:\Windows\SysWOW64\SIntf32.dll 2013-12-31 16:30 - 2013-11-01 12:34 - 00012067 ____T C:\Windows\SysWOW64\SIntf16.dll 2013-12-31 01:23 - 2013-04-04 14:39 - 00000000 ____D C:\Program Files (x86)\Steam 2013-12-30 14:47 - 2013-12-30 14:47 - 00000000 _____ C:\Windows\setuperr.log 2013-12-30 14:45 - 2013-12-30 14:45 - 01233962 _____ C:\Users\Besitzer\Downloads\adwcleaner (2).exe 2013-12-30 14:34 - 2013-12-30 14:34 - 00096108 _____ C:\Users\Besitzer\Documents\6.reg 2013-12-30 14:33 - 2013-12-30 14:33 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-12-30 14:33 - 2013-02-01 18:04 - 00000000 ____D C:\Program Files\CCleaner 2013-12-30 14:32 - 2013-12-30 14:31 - 04645232 _____ (Piriform Ltd) C:\Users\Besitzer\Downloads\ccsetup409.exe 2013-12-30 14:21 - 2013-12-13 23:25 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2013-12-30 14:21 - 2013-01-28 11:32 - 00000000 ____D C:\Users\Besitzer 2013-12-30 14:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-12-30 14:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat 2013-12-30 14:20 - 2013-01-28 11:41 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-30 13:58 - 2013-01-28 21:23 - 00000000 ____D C:\Windows\panther 2013-12-27 23:08 - 2013-12-27 23:08 - 00000000 ____D C:\Program Files (x86)\LucasArts 2013-12-26 11:03 - 2013-05-05 12:08 - 00000000 ____D C:\Users\Besitzer\Desktop\Musik 2013-12-24 22:05 - 2013-04-05 20:00 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-24 12:08 - 2013-04-13 16:49 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-12-24 12:08 - 2013-04-13 16:49 - 00000000 ____D C:\ProgramData\Skype 2013-12-22 21:23 - 2013-05-05 12:10 - 00000000 ___RD C:\Users\Besitzer\Desktop\Anwendungen 2013-12-22 21:21 - 2013-05-05 12:08 - 00000000 ____D C:\Users\Besitzer\Desktop\Bilder 2013-12-22 21:21 - 2013-05-05 12:07 - 00000000 ____D C:\Users\Besitzer\Desktop\Dokumente 2013-12-22 21:20 - 2013-12-22 21:20 - 00000000 ____D C:\Users\Besitzer\Desktop\Spiele 2013-12-15 18:26 - 2013-08-16 22:42 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 18:24 - 2013-06-09 15:45 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-15 12:34 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-13 23:25 - 2013-12-13 23:25 - 00000000 ____D C:\Program Files (x86)\Overwolf 2013-12-08 16:53 - 2013-12-01 13:59 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Xfire 2013-12-08 16:25 - 2013-12-08 16:26 - 00103736 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-12-08 12:44 - 2013-02-01 18:00 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-08 12:44 - 2013-02-01 18:00 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-12-08 12:22 - 2013-12-01 13:58 - 00000000 ____D C:\ProgramData\Xfire 2013-12-08 12:20 - 2013-01-28 11:32 - 00001433 _____ C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-07 23:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-07 12:59 - 2013-12-07 12:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-07 12:59 - 2013-12-07 12:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-07 12:59 - 2013-12-07 12:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-07 12:59 - 2013-12-07 12:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-07 12:59 - 2013-12-07 12:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-07 12:59 - 2013-12-07 12:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-07 12:59 - 2013-12-07 12:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-07 12:59 - 2013-12-07 12:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-07 12:59 - 2013-12-07 12:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-06 20:46 - 2013-02-01 18:01 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-12-06 20:35 - 2013-01-28 11:32 - 00000000 ____D C:\Users\Besitzer\AppData\Local\VirtualStore Some content of TEMP: ==================== C:\Users\Besitzer\AppData\Local\Temp\EBU20CB.DLL C:\Users\Besitzer\AppData\Local\Temp\EBU703.EXE C:\Users\Besitzer\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-31 20:03 ==================== End Of Log ============================ --- --- --- --- --- --- Ja leider habe ich immer noch die gleichen Probleme wie oben beschrieben |
04.01.2014, 15:55 | #10 |
/// the machine /// TB-Ausbilder | Internet extrem langsam geworden Trenn den Router 30 min vom Strom, testen. Bringt das nix, Router komplett auf Werkseinstellungen zurücksetzen und nochmal testen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Internet extrem langsam geworden |
bereits, bitte um hilfe, extrem, extrem langsam, gefunde, geladen, hoher, hoher ping, inter, interne, internet, internetseite, internetseiten, langsam, malewarebytes, neustart, nichts, router, scan, seite, seiten, spiele, spielen, versuch, versucht, überhaupt |