|
Log-Analyse und Auswertung: Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im SpielWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
29.01.2014, 00:17 | #1 |
| Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Hallo, in letzter Zeit ist mein Laptop (ASUS N71JQ) ziemlich langsam geworden. Anfangs lief alles problemlos, aber seit einiger Zeit (paar Tage/Wochen) zickt er bei Spielen doch immer mehr rum. Dies äußerst sich durch Laggs und FPS-Einbrüche, sodass es teilweise richtig ruckelt und kaum spielbar ist, was zuvor überhaupt kein Problem war. Ich habe bereits versucht die Grafiktreiber zu aktualisieren, was aber trotz Originaltreiber von Asus oft zu Problemen führt. Meist lassen sich andere, sowohl neue, als auch alte Treiber gar nicht erst richtig installieren, da die Installation direkt geblockt wird, da korrekte Treiber schon vorhanden wären, oder sie lassen sich installieren und das Bild wird und bleibt schwarz, sodass ich erst alles wieder im abgesicherten Modus rückgängig machen muss, obwohl es sich wie erwähnt um die angeblich korrekten Treiber handelt. Bin langsam ratlos und erhoffe mir, dass mir hier jmd. helfen kann, da ich die Vermutung habe, dass irgendwas "zerschossen" ist, oder mir ein Trojaner einen Strich durch die Rechnung macht. beste Grüße, Robert Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-01-2014 02 Ran by Pauly at 2014-01-28 23:58:29 Running from C:\Users\Pauly\Desktop\Scan Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: AVG AntiVirus Free Edition 2014 (Disabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2014 (Disabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (x32 Version: - Microsoft) 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov) Abenteuer auf dem Reiterhof 3 - Das Erbe der Gräfin (x32 Version: 1.00.0000 - Ubisoft) Adobe Flash Media Live Encoder 3.2 (x32 Version: 3.2.0 - Adobe Systems Incorporated) Adobe Flash Player 12 ActiveX (x32 Version: 12.0.0.38 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.43 - Adobe Systems Incorporated) Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8 - Adobe Systems Incorporated) Akamai NetSession Interface (HKCU Version: - Akamai Technologies, Inc) Alcor Micro USB Card Reader (x32 Version: 1.5.17.25482 - Alcor Micro Corp.) Alcor Micro USB Card Reader (x32 Version: 1.5.17.25482 - Alcor Micro Corp.) Hidden AMD Accelerated Video Transcoding (Version: 13.20.100.31206 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.938.1 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.81206.1620 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden Apple Application Support (x32 Version: 2.3.3 - Apple Inc.) Apple Mobile Device Support (Version: 6.1.0.13 - Apple Inc.) Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.) ASUS AI Recovery (x32 Version: 1.0.7 - ASUS) ASUS FancyStart (x32 Version: 1.0.6 - ASUSTeK Computer Inc.) ASUS LifeFrame3 (x32 Version: 3.0.20 - ASUS) ASUS Live Update (x32 Version: 2.5.9 - ASUS) ASUS MultiFrame (x32 Version: 1.0.0019 - ASUS) ASUS Power4Gear Hybrid (Version: 1.1.25 - ASUS) ASUS SmartLogon (x32 Version: 1.0.0007 - ASUS) ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0028 - ASUS) ASUS Virtual Camera (x32 Version: 1.0.19 - asus) ASUS_N_Series_Screensaver (x32 Version: - ) ATK Generic Function Service (x32 Version: 1.00.0008 - ATK) ATK Package (x32 Version: 1.0.0020 - ASUS) AVG 2014 (Version: 14.0.3681 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4259 - AVG Technologies) Hidden AVG 2014 (Version: 2014.0.4259 - AVG Technologies) Battle.net (x32 Version: - Blizzard Entertainment) Bonjour (Version: 3.0.0.10 - Apple Inc.) Carom3D (x32 Version: - ) Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Cinergy T-Stick MKII V9.06.3.01 (x32 Version: 9.06.3.01 - ) ControlDeck (x32 Version: 1.0.5 - ASUS) Core Temp 1.0 RC6 (Version: 1.0 - Alcpu) Counter-Strike (x32 Version: - Valve) Counter-Strike: Global Offensive Beta (x32 Version: - ) Debut Videorekorder (x32 Version: - NCH Software) Diablo III (x32 Version: - Blizzard Entertainment) Die Sims™ 3 (x32 Version: 1.55.4 - Electronic Arts) Die Sims™ 3 Einfach tierisch (x32 Version: 10.0.96 - Electronic Arts) Dota 2 (x32 Version: - Valve ) Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.) DVBViewer TERRATEC Edition (x32 Version: - CM&V) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden ETDWare PS/2-x64 7.0.5.9_WHQL (Version: - ) Express Burn (x32 Version: - NCH Software) Express Gate (x32 Version: 1.2.13.32 - DeviceVM, Inc.) Facebook Video Calling 2.0.0.447 (x32 Version: 2.0.447 - Skype Limited) Fast Boot (Version: 1.0.4 - ASUS) Full Tilt Poker (x32 Version: 4.45.10.WIN.FullTilt.COM - ) Gamers.IRC 6.03 (x32 Version: - ) GamersFirst LIVE! (HKCU Version: - GamersFirst) Google Chrome (HKCU Version: 32.0.1700.76 - Google Inc.) Google Earth Plug-in (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Guitar Pro 6 (x32 Version: - Arobas Music) Hearthstone (x32 Version: - Blizzard Entertainment) Hi-Rez Studios Authenticate and Update Service (x32 Version: 3.0.0.0 - Hi-Rez Studios) HLSW v1.4.0.2 (x32 Version: - Stripf Software) HUAWEI DataCard Driver 4.20.12.00 (x32 Version: 4.20.12.00 - Huawei technologies Co., Ltd.) ICQ7.6 (x32 Version: 7.6 - ICQ) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179 - Intel Corporation) iTunes (Version: 11.0.2.26 - Apple Inc.) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 27 (x32 Version: 6.0.270 - Oracle) Java(TM) 6 Update 29 (64-bit) (Version: 6.0.290 - Oracle) Jungle Timer (x32 Version: 1.0.0 - SitenApp) Jungle Timer (x32 Version: 1.0.0 - SitenApp) Hidden League of Legends (x32 Version: 1.02.0000 - Riot Games) League of Legends (x32 Version: 1.3 - Riot Games) LG PC Suite (x32 Version: 5.1.29.20120718 - LG Electronics) LG United Mobile Drivers (x32 Version: 3.7.2.0 - LG Electronics) Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.50 (Version: 8.50.281 - Logitech Inc.) Logitech SetPoint 6.32 (Version: 6.32.20 - Logitech) LoL-Starter (HKCU Version: 1.3.5.0 - Absolute Legends) Microsoft .NET Framework 4.5 DEU Language Pack Beta (Version: 4.5.50131 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (x32 Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Mobile Connection Manager (x32 Version: - Mobile Connection Manager) Mozilla Firefox 15.0.1 (x86 de) (x32 Version: 15.0.1 - Mozilla) Mozilla Maintenance Service (x32 Version: 15.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) NB Probe (x32 Version: - ) NEC Electronics USB 3.0 Host Controller Driver (x32 Version: 1.0.17.0 - NEC Electronics Corporation) NEC Electronics USB 3.0 Host Controller Driver (x32 Version: 1.0.17.0 - NEC Electronics Corporation) Hidden Net4Switch (x32 Version: 1.00.0020 - ASUS) NVIDIA PhysX (x32 Version: 9.10.0129 - NVIDIA Corporation) OpenAL (x32 Version: - ) OpenTTD 1.2.1 (x32 Version: 1.2.1 - OpenTTD) Origin (x32 Version: 9.0.14.2148 - Electronic Arts, Inc.) osu! (x32 Version: 0.0.0.0 - peppy) Pando Media Booster (x32 Version: 2.6.0.8 - Pando Networks Inc.) PDF-Viewer (Version: 2.5.212.0 - Tracker Software Products Ltd) PhotoScape (x32 Version: - ) PKR (x32 Version: - PKR Ltd) PlayReady PC Runtime amd64 (Version: 1.3.0 - Microsoft Corporation) PokerStars (x32 Version: - PokerStars) PokerStars.net (x32 Version: - PokerStars.net) Prism Videodatei-Konverter (x32 Version: - NCH Software) PunkBuster Services (x32 Version: 0.993 - Even Balance, Inc.) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5995 - Realtek Semiconductor Corp.) Remote Control USB Driver (x32 Version: 2.3.2.317 - ) Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) Smite Closed Beta (x32 Version: 0.1.954.0 - Hi-Rez Studios) Sniper: Ghost Warrior (x32 Version: - City Interactive) Spotify (HKCU Version: 0.9.7.16.g4b197456 - Spotify AB) Spybot - Search & Destroy (x32 Version: 1.6.2 - Safer Networking Limited) SRS Premium Sound Control Panel (Version: 1.8.2600 - SRS Labs, Inc.) Steam (x32 Version: 1.0.0.0 - Valve Corporation) Swift Browse 1.0.0 (Version: 1.0.0 - Swift Browse) TeamSpeak 3 Client (Version: - TeamSpeak Systems GmbH) TeamViewer 8 (x32 Version: 8.0.16642 - TeamViewer) TerraTec Home Cinema (x32 Version: 6.27.7 - ) TerraTec Remote Control (x32 Version: 5.34 - ) TmNationsForever (x32 Version: - Nadeo) Torchlight II (x32 Version: - Runic Games) TuxGuitar (x32 Version: 1.2 - Herac) Unlocker 1.9.1-x64 (Version: 1.9.1 - Cedrick Collomb) Update for 2007 Microsoft Office System (KB967642) (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version: - Microsoft) Veetle TV (x32 Version: 0.9.19 - Veetle, Inc) Ventrilo Client for Windows x64 (Version: 3.0.8.0 - Flagship Industries, Inc.) VideoPad Videobearbeitungs-Software (x32 Version: - NCH Software) Visual Studio 2012 x64 Redistributables (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (x32 Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 2.0.4 (x32 Version: 2.0.4 - VideoLAN) WIDCOMM Bluetooth Software (Version: 6.2.5.500 - Broadcom Corporation) Winamp (x32 Version: 5.622 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1 - Nullsoft, Inc) WinBMA (x32 Version: 2.0.4713.34518 - WinBMA/Andrew Moore) Windows Driver Package - Broadcom Bluetooth (07/17/2009 6.2.0.9403) (Version: 07/17/2009 6.2.0.9403 - Broadcom) Windows Driver Package - Broadcom Bluetooth (07/29/2009 6.1.7100.0) (Version: 07/29/2009 6.1.7100.0 - Broadcom) Windows Driver Package - Broadcom HIDClass (06/11/2009 6.2.0.9500) (Version: 06/11/2009 6.2.0.9500 - Broadcom) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8 - Microsoft Corp) WinFlash (x32 Version: 2.29.0 - ASUS) Wireless Console 3 (x32 Version: 3.0.14 - ASUS) XSplit (x32 Version: 1.0.1204.1301 - SplitMediaLabs) ==================== Restore Points ========================= 17-01-2014 17:49:49 Removed osu! 17-01-2014 17:54:53 Installed osu! 19-01-2014 07:29:04 Windows Update 25-01-2014 10:24:26 Windows Update 28-01-2014 22:34:07 Removed XSplit ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {11FA85C3-DFD9-4B64-B223-F9D3FD2992EB} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000UA => C:\Users\Pauly\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {14B32C34-6AD3-402D-ADDC-6382884B731A} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-05-18] (ASUS) Task: {292E45FB-B6E1-4F0D-9124-996FC085B2BD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {37716B26-A1C4-4619-A547-D91214B68339} - System32\Tasks\Net4Switch => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe [2009-09-23] (ASUS) Task: {4421006A-7C68-4037-96CF-1C6737F6D879} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2009-11-06] (ATK) Task: {471C8DE3-71BE-4103-B6AB-8310AE322703} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000Core => C:\Users\Pauly\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {6D03262B-5594-4F17-B52A-394D8E11E392} - System32\Tasks\P4GIntlCtrl => C:\Program Files\P4G\IntlCtrl.exe [2009-09-22] (TODO: <Company name>) Task: {90A440B6-8BFF-4BEA-9FE4-61743F27DD43} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000Core => C:\Users\Pauly\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-18] (Google Inc.) Task: {922E8849-6F40-4AAB-9CD9-673BCC2224E4} - System32\Tasks\{8CAFE3D3-6232-4C19-B07A-DE7226FD7893} => C:\Program Files\Logitech Gaming Software\LCore.exe [2013-08-01] (Logitech Inc.) Task: {9978403B-FE58-4440-BDF7-035AB6B8E42D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-06-06] (Google Inc.) Task: {A5E51E0E-671B-47F8-9FD3-51C16EAC9BC1} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {A709AD61-E272-459F-9921-8154175490BE} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe [2009-11-24] () Task: {A7A36851-7F35-4567-8D2D-CC94BEE9F2D7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-24] (Adobe Systems Incorporated) Task: {A7BD1A50-8B01-49D4-854A-BCE66EA589EE} - System32\Tasks\WC3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2009-11-12] () Task: {ABE236F8-986B-4616-AD0F-309B2C0C7114} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-06-06] (Google Inc.) Task: {B4164108-CD11-4D30-8981-4A43C416087F} - System32\Tasks\P4G Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21] (Microsoft Corporation) Task: {D2D0AAFD-DFE8-4941-86FB-4640C719DBF9} - System32\Tasks\ATKOSD2 => C:\Programme (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-06-25] (ASUSTek Computer Inc.) Task: {EBFE48AC-77DA-43FC-B0C6-AED0CDB315CC} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK) Task: {F29705D5-C76F-4BDD-8BE1-B3E2B9B601D1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000UA => C:\Users\Pauly\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-18] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000Core.job => C:\Users\Pauly\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000UA.job => C:\Users\Pauly\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000Core.job => C:\Users\Pauly\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000UA.job => C:\Users\Pauly\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2009-10-23 12:40 - 2009-10-23 12:40 - 00041984 _____ () C:\Program Files\P4G\DevMng.dll 2009-09-11 11:27 - 2009-09-11 11:27 - 00029184 _____ () C:\Program Files\P4G\OvrClk.dll 2012-02-20 20:29 - 2012-02-20 20:29 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-02-20 20:28 - 2012-02-20 20:28 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-10-18 18:00 - 2013-10-18 18:00 - 00337920 _____ () C:\Program Files (x86)\Swift Browse\bin\sqlite3.DLL 2014-01-16 19:33 - 2014-01-11 11:28 - 00715544 _____ () C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.76\libglesv2.dll 2014-01-16 19:33 - 2014-01-11 11:28 - 00100120 _____ () C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.76\libegl.dll 2014-01-16 19:33 - 2014-01-11 11:29 - 04055320 _____ () C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.76\pdf.dll 2014-01-16 19:33 - 2014-01-11 11:29 - 00399640 _____ () C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll 2014-01-16 19:33 - 2014-01-11 11:28 - 01634584 _____ () C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.76\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/28/2014 11:34:48 PM) (Source: MsiInstaller) (User: ADIOZ) Description: Product: XSplit -- Error 1721. There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor. Action: AI_UPDATER_UNINSTALL, location: D:\streaming\XSPLIT\xsplit_updater.exe, command: /clean silent Error: (01/28/2014 11:32:28 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/28/2014 10:34:43 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/28/2014 05:21:37 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/27/2014 08:55:26 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/27/2014 08:07:42 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/26/2014 11:33:41 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/26/2014 07:21:08 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/26/2014 11:31:09 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/25/2014 07:40:11 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (01/28/2014 11:35:23 PM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (01/28/2014 11:35:23 PM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (01/28/2014 11:31:46 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 28.01.2014 um 23:29:05 unerwartet heruntergefahren. Error: (01/27/2014 08:54:08 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 27.01.2014 um 20:50:58 unerwartet heruntergefahren. Error: (01/25/2014 09:40:48 PM) (Source: Service Control Manager) (User: ) Description: Dienst "Adobe Acrobat Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (01/25/2014 09:40:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "TeamViewer 8" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 2000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/25/2014 09:40:39 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Apple Mobile Device" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/25/2014 09:55:27 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst AVGIDSAgent konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (01/19/2014 11:00:52 PM) (Source: ACPI) (User: ) Description: ACPI: ACPI-BIOS versucht, in einen ungültigen PCI-Operationsbereich (0x4) zu schreiben. Wenden Sie sich an den Systemhersteller, um technische Unterstützung zu erhalten. Error: (01/19/2014 11:00:52 PM) (Source: ACPI) (User: ) Description: ACPI: ACPI-BIOS versucht, in einen ungültigen PCI-Operationsbereich (0x4) zu schreiben. Wenden Sie sich an den Systemhersteller, um technische Unterstützung zu erhalten. Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-01-14 14:32:49.564 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-14 14:32:49.408 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-14 14:30:46.870 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-14 14:30:46.813 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-07-21 23:41:16.678 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-07-21 23:41:16.616 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-07-21 23:39:00.881 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-07-21 23:39:00.859 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-05-16 03:51:00.526 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-05-16 03:51:00.464 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 4020.52 MB Available physical RAM: 2154.07 MB Total Pagefile: 8039.23 MB Available Pagefile: 5852.36 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:270.35 GB) (Free:197.2 GB) NTFS Drive d: () (Fixed) (Total:465.76 GB) (Free:340.78 GB) NTFS Drive e: () (Fixed) (Total:195.31 GB) (Free:173.09 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: CC15D786) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=270 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=195 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 16AF6DE6) Partition 1: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 23:56 on 28/01/2014 (Pauly) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-01-2014 02 Ran by Pauly (administrator) on ADIOZ on 28-01-2014 23:56:57 Running from C:\Users\Pauly\Desktop\Scan Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgwdsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe () C:\Program Files (x86)\Swift Browse\updateSwiftBrowse.exe () C:\Program Files (x86)\Swift Browse\bin\utilSwiftBrowse.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ATK) C:\Program Files\P4G\BatteryLife.exe () C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe (ASUSTek Computer Inc.) C:\Programme (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Spotify Ltd) C:\Users\Pauly\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ASUSTek Computer Inc.) C:\Programme (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Programme (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgui.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [621440 2009-09-30] (ELAN Microelectronic Corp.) HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-10-21] (NEC Electronics Corporation) HKLM-x32\...\Run: [ATKOSD2] - C:\Programme (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-06-25] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ATKMEDIA] - C:\Programme (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-06-19] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [HControlUser] - C:\Programme (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) MountPoints2: G - G:\AutoRun.exe MountPoints2: {1719a26e-fe52-11e0-a551-001e101f2500} - G:\AutoRun.exe MountPoints2: {56612493-f99c-11e0-98c0-1c4bd616c077} - G:\AutoRun.exe MountPoints2: {566124a1-f99c-11e0-98c0-1c4bd616c077} - G:\AutoRun.exe MountPoints2: {566124b0-f99c-11e0-98c0-1c4bd616c077} - G:\AutoRun.exe MountPoints2: {566124d3-f99c-11e0-98c0-001e101f50a4} - G:\AutoRun.exe MountPoints2: {566124df-f99c-11e0-98c0-001e101f50a4} - G:\AutoRun.exe MountPoints2: {566124eb-f99c-11e0-98c0-001e101f50a4} - G:\AutoRun.exe MountPoints2: {67bc9d93-f9d4-11e0-a9ca-001e101f57d0} - G:\AutoRun.exe MountPoints2: {c12d0844-f674-11e0-a344-806e6f6e6963} - F:\InstAll.exe MountPoints2: {f781f1c9-b361-11e2-98d3-20cf300ba951} - G:\AutoRun.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x61B88996D817CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ URLSearchHook: HKCU - (No Name) - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - No File SearchScopes: HKCU - DefaultScope {012AF763-C60F-4CB9-8E4F-F45951BFAB17} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {012AF763-C60F-4CB9-8E4F-F45951BFAB17} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {5533637B-7FE5-43F8-B0D4-B87178C6D8CC} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2765711 BHO: weDownload Manager Pro - {11111111-1111-1111-1111-110411361128} - No File BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No File BHO-x32: weDownload Manager Pro - {11111111-1111-1111-1111-110411361128} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Swift Browse - {808dc83c-d35b-4fba-a5b5-9a52103204df} - C:\Program Files (x86)\Swift Browse\SwiftBrowseBHO.dll (Swift Browse) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - D:\Programme\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH) Toolbar: HKCU - No Name - {F0381DBD-E018-4E07-AE40-D96AB15083F0} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default FF user.js: detected! => C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\user.js FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - d:\Programme\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Programme\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - d:\Programme\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 - d:\Programme\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - d:\Programme\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin-x32: @videolan.org/vlc,version=2.0.4 - d:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - d:\Programme\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Pauly\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Pauly\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Pauly\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: weDownload Manager Pro - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com [2013-11-02] FF Extension: Ghostery - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\firefox@ghostery.com [2013-11-02] FF Extension: WOT - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-02] FF Extension: Swift Browse - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\firefox@swiftbrowse.net.xpi [2013-10-18] FF Extension: WEB.DE MailCheck - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\toolbar@web.de.xpi [2011-12-19] FF Extension: Adblock Plus - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-11-04] Chrome: ======= CHR HomePage: hxxp://search.ominent.com/ws/?source=9f1d0980&tbp=homepage&toolbarid=base&u=cc40d42800000000000072f06d3396e4 CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.76\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.76\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.270.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U27) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Microsoft Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Pauly\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (iTunes Application Detector) - D:\Programme\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Veetle TV Player) - d:\Programme\Veetle\Player\npvlc.dll (Veetle Inc) CHR Plugin: (Veetle TV Core) - d:\Programme\Veetle\plugins\npVeetle.dll (Veetle Inc) CHR Extension: (YouTube Options) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdokagampppgbnjfdlkfpphniapiiifn [2013-10-18] CHR Extension: (YouTube) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-18] CHR Extension: (Adblock Plus) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2012-07-18] CHR Extension: (Google-Suche) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-18] CHR Extension: (Grooveshark Germany unlocker) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac [2013-05-19] CHR Extension: (Hola Besseres Internet) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2013-10-18] CHR Extension: (WEB.DE MailCheck) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo [2013-12-26] CHR Extension: (Google Wallet) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (YouTube Unblocker) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [2013-12-10] CHR Extension: (Google Mail) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-18] CHR HKLM-x32\...\Chrome\Extension: [jgapglgghagmhogfjkdlnnmbdfddeedb] - C:\Program Files (x86)\Swift Browse\jgapglgghagmhogfjkdlnnmbdfddeedb.crx [2013-10-22] CHR StartMenuInternet: Google Chrome - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= S4 ASLDRService; C:\Programme (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [80512 2011-11-21] (ASUS) S2 AVGIDSAgent; D:\Programme\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; D:\Programme\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) S4 HiPatchService; D:\Spiele\Smite\HiPatchService.exe [8704 2012-07-12] (Hi-Rez Studios) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-01-13] () S4 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () S4 TGCM_ImportWiFiSvc; D:\o2\Mobile Connection Manager\ImpWiFiSvc.exe [200624 2010-09-29] (Telefónica I+D) R2 Update Swift Browse; C:\Program Files (x86)\Swift Browse\updateSwiftBrowse.exe [102176 2014-01-25] () R2 Util Swift Browse; C:\Program Files (x86)\Swift Browse\bin\utilSwiftBrowse.exe [102176 2014-01-25] () ==================== Drivers (Whitelisted) ==================== S3 AF9035BDA; C:\Windows\System32\DRIVERS\AF15BDA.sys [513600 2009-11-05] (ITETech ) S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2012-03-07] (Google Inc) S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2012-03-06] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2012-03-06] (LG Electronics Inc.) R2 ASMMAP64; C:\Programme (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [15416 2009-07-02] (ASUS) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S3 LADF_BakerCOnly; C:\Windows\System32\DRIVERS\ladfBakerCamd64.sys [410184 2011-03-18] (Logitech) S3 LADF_BakerROnly; C:\Windows\System32\DRIVERS\ladfBakerRamd64.sys [335688 2011-03-18] (Logitech) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () S3 ALSysIO; \??\C:\Users\Pauly\AppData\Local\Temp\ALSysIO64.sys [x] S3 GPU-Z; \??\C:\Users\Pauly\AppData\Local\Temp\GPU-Z.sys [x] S3 ipswuio; System32\DRIVERS\ipswuio.sys [x] S3 massfilter; system32\drivers\massfilter.sys [x] U5 UnlockerDriver5; d:\Programme\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-28 23:56 - 2014-01-28 23:56 - 00000000 ____D C:\FRST 2014-01-28 23:56 - 2014-01-28 23:56 - 00000000 _____ C:\Users\Pauly\defogger_reenable 2014-01-28 23:53 - 2014-01-28 23:56 - 00000000 ____D C:\Users\Pauly\Desktop\Scan 2014-01-28 23:37 - 2014-01-28 23:37 - 00000879 _____ C:\Users\Pauly\Desktop\Spybot - Search & Destroy.lnk 2014-01-28 23:22 - 2014-01-28 23:22 - 00000000 ____D C:\Program Files\ATI Technologies 2014-01-28 23:21 - 2014-01-28 23:21 - 00054772 _____ C:\Windows\SysWOW64\CCCInstall_201401282321398833.log 2014-01-25 11:49 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-01-25 11:49 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-01-25 11:49 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-01-25 11:49 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-01-25 11:39 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-01-25 11:39 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-01-25 11:39 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2014-01-25 11:39 - 2012-08-23 15:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-01-25 11:39 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-01-25 11:39 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-01-25 11:39 - 2012-08-23 14:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-01-25 11:39 - 2012-08-23 14:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-01-25 11:39 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-01-25 11:39 - 2012-08-23 14:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-01-25 11:39 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-01-25 11:39 - 2012-08-23 14:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-01-25 11:39 - 2012-08-23 14:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-01-25 11:39 - 2012-08-23 13:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-01-25 11:39 - 2012-08-23 12:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-01-25 11:39 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2014-01-25 11:39 - 2012-08-23 12:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-01-25 11:39 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2014-01-25 11:39 - 2012-08-23 11:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-01-25 11:39 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-01-25 11:39 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-01-25 11:39 - 2012-08-23 11:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-01-25 11:39 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-01-25 11:39 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-01-25 11:39 - 2012-08-23 09:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2014-01-25 11:31 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2014-01-25 11:31 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2014-01-25 11:31 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2014-01-25 11:31 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2014-01-25 11:23 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-01-25 11:23 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-01-25 11:23 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2014-01-25 11:23 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-01-25 11:23 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2014-01-25 11:23 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-01-25 11:23 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-01-25 11:23 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-01-25 11:23 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2014-01-25 11:23 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-01-25 11:23 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2014-01-25 11:23 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-01-25 11:23 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-01-25 11:23 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-01-25 11:23 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-01-25 11:23 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2014-01-25 11:23 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2014-01-25 11:23 - 2012-11-30 06:45 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-01-25 11:23 - 2012-11-30 06:45 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-01-25 11:23 - 2012-11-30 06:43 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-01-25 11:23 - 2012-11-30 00:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2014-01-25 11:23 - 2012-11-30 00:15 - 00420064 _____ C:\Windows\system32\locale.nls 2014-01-25 11:23 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2014-01-25 11:23 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2014-01-25 11:23 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2014-01-25 11:23 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2014-01-25 11:23 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2014-01-25 11:23 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-01-25 11:23 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2014-01-25 11:23 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2014-01-25 11:22 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-25 11:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-01-25 11:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-01-25 11:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-01-25 11:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-01-25 11:22 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2014-01-25 11:22 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2014-01-25 11:22 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-01-25 11:22 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2014-01-25 11:22 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-01-25 11:22 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2014-01-25 11:22 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-01-25 11:22 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2014-01-25 11:22 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2014-01-25 11:22 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2014-01-25 11:22 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2014-01-25 11:22 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2014-01-25 11:22 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2014-01-25 11:22 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2014-01-25 11:22 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2014-01-25 11:22 - 2013-04-17 08:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-01-25 11:22 - 2013-04-17 07:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-01-25 11:22 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-01-25 11:22 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2014-01-25 11:22 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2014-01-25 11:22 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2014-01-25 11:22 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2014-01-25 11:22 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2014-01-25 11:22 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2014-01-25 11:22 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2014-01-25 11:22 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2014-01-25 11:22 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2014-01-25 11:22 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2014-01-25 11:22 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2014-01-25 11:22 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2014-01-25 11:22 - 2012-07-06 21:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2014-01-25 11:22 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2014-01-25 11:22 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2014-01-25 11:22 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2014-01-25 11:21 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2014-01-25 11:21 - 2012-11-22 06:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-01-25 11:21 - 2012-11-22 05:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-01-19 08:28 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-19 08:28 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-17 18:55 - 2014-01-17 18:55 - 00000632 _____ C:\Users\Public\Desktop\osu!.lnk 2014-01-16 22:30 - 2014-01-16 22:30 - 00001230 _____ C:\Users\Pauly\Desktop\Calculator.lnk 2014-01-15 16:58 - 2014-01-15 16:58 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard 2014-01-15 16:41 - 2014-01-15 16:41 - 00000755 _____ C:\Users\Public\Desktop\Hearthstone.lnk 2014-01-15 16:39 - 2014-01-26 02:15 - 00000000 ____D C:\Users\Pauly\AppData\Local\Battle.net 2014-01-15 16:39 - 2014-01-15 16:41 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Battle.net 2014-01-15 16:39 - 2014-01-15 16:39 - 00000758 _____ C:\Users\Public\Desktop\Battle.net.lnk 2014-01-15 16:39 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard Entertainment 2014-01-14 16:30 - 2014-01-14 16:30 - 00001426 _____ C:\Users\Pauly\Desktop\APB Reloaded.lnk 2014-01-14 15:59 - 2014-01-14 15:59 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2014-01-14 15:59 - 2014-01-14 15:59 - 00000000 ____D C:\Users\Pauly\AppData\Local\PunkBuster 2014-01-14 14:44 - 2014-01-14 14:44 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201401141444120183.log 2014-01-14 14:43 - 2014-01-14 14:43 - 00016738 _____ C:\Windows\SysWOW64\CCCInstall_201401141443071596.log 2014-01-14 14:41 - 2014-01-14 14:41 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2014-01-14 13:54 - 2014-01-14 13:54 - 00000000 ____D C:\Program Files\AMD 2014-01-14 13:07 - 2014-01-14 13:42 - 00000000 ____D C:\AMD 2014-01-14 00:36 - 2014-01-14 00:36 - 00000000 ____D C:\Windows\SysWOW64\directx 2014-01-13 23:26 - 2014-01-14 14:41 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-13 23:25 - 2014-01-14 16:34 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-13 23:25 - 2014-01-14 15:59 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-13 23:25 - 2014-01-13 23:25 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-13 23:22 - 2014-01-13 23:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\Users\Pauly\AppData\Local\WarThunder 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\ProgramData\WarThunder 2014-01-13 21:14 - 2014-01-28 23:32 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2014-01-13 21:14 - 2014-01-13 22:28 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst LIVE! 2014-01-13 21:14 - 2014-01-13 21:14 - 00001168 _____ C:\Users\Pauly\Desktop\GamersFirst LIVE!.lnk 2014-01-13 21:14 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst 2014-01-09 21:26 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-01-09 21:24 - 2014-01-09 21:24 - 00000209 _____ C:\Users\Pauly\Desktop\Torchlight II.url 2014-01-08 01:10 - 2014-01-08 01:10 - 00000000 ____D C:\Users\Pauly\Documents\Sniper - Ghost Warrior 2014-01-08 00:31 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2014-01-08 00:31 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-01-08 00:31 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2014-01-08 00:31 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-01-08 00:31 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-01-08 00:31 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-01-08 00:31 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-01-08 00:31 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-01-08 00:31 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-01-08 00:31 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-01-08 00:31 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-01-08 00:31 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-01-08 00:31 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-01-08 00:31 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-01-08 00:31 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-01-08 00:31 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-01-08 00:31 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-01-08 00:31 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-01-08 00:31 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-01-08 00:31 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-01-08 00:31 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-01-08 00:31 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-01-08 00:31 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-01-08 00:31 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-01-08 00:31 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-01-08 00:31 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-01-08 00:31 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-01-08 00:31 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-01-08 00:31 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-01-08 00:31 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-01-08 00:31 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-01-08 00:31 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-01-08 00:31 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-01-08 00:31 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-01-08 00:31 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-01-08 00:31 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-01-08 00:31 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-01-08 00:31 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-01-08 00:31 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-01-08 00:31 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-01-08 00:31 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-01-08 00:31 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-01-08 00:31 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-01-08 00:31 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-01-08 00:31 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-01-08 00:31 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-01-08 00:31 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-01-08 00:31 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-01-08 00:31 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-01-08 00:31 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-01-08 00:30 - 2014-01-13 23:25 - 00069590 _____ C:\Windows\DirectX.log 2014-01-07 21:59 - 2014-01-07 21:59 - 00000000 ____D C:\Users\Pauly\Documents\Urlaubsparadies Tycoon 2011 ==================== One Month Modified Files and Folders ======= 2014-01-28 23:56 - 2014-01-28 23:56 - 00000000 ____D C:\FRST 2014-01-28 23:56 - 2014-01-28 23:56 - 00000000 _____ C:\Users\Pauly\defogger_reenable 2014-01-28 23:56 - 2014-01-28 23:53 - 00000000 ____D C:\Users\Pauly\Desktop\Scan 2014-01-28 23:56 - 2011-10-14 16:18 - 00000000 ____D C:\Users\Pauly 2014-01-28 23:55 - 2012-09-06 05:44 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2014-01-28 23:39 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-28 23:39 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-28 23:38 - 2010-11-21 07:50 - 00699508 _____ C:\Windows\system32\perfh007.dat 2014-01-28 23:38 - 2010-11-21 07:50 - 00149660 _____ C:\Windows\system32\perfc007.dat 2014-01-28 23:38 - 2009-07-14 06:13 - 01620380 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-28 23:37 - 2014-01-28 23:37 - 00000879 _____ C:\Users\Pauly\Desktop\Spybot - Search & Destroy.lnk 2014-01-28 23:36 - 2011-10-14 15:59 - 01190807 _____ C:\Windows\WindowsUpdate.log 2014-01-28 23:32 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2014-01-28 23:32 - 2013-10-22 15:37 - 00003100 _____ C:\Windows\System32\Tasks\P4G Sidebar 2014-01-28 23:32 - 2013-09-29 17:23 - 00003164 _____ C:\Windows\System32\Tasks\P4GIntlCtrl 2014-01-28 23:32 - 2012-06-06 14:38 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-28 23:31 - 2013-10-19 13:40 - 00012674 _____ C:\Windows\setupact.log 2014-01-28 23:31 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-28 23:29 - 2012-07-18 05:21 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000UA.job 2014-01-28 23:25 - 2012-06-06 14:38 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-28 23:22 - 2014-01-28 23:22 - 00000000 ____D C:\Program Files\ATI Technologies 2014-01-28 23:21 - 2014-01-28 23:21 - 00054772 _____ C:\Windows\SysWOW64\CCCInstall_201401282321398833.log 2014-01-28 23:21 - 2013-09-27 20:34 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Spotify 2014-01-28 23:19 - 2012-06-11 18:01 - 03659264 _____ (ATI Technologies Inc. ) C:\Windows\system32\atidxx64.dll 2014-01-28 23:19 - 2009-11-18 14:21 - 06171136 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2014-01-28 23:19 - 2009-11-18 13:46 - 00446976 _____ (AMD) C:\Windows\system32\atieclxx.exe 2014-01-28 23:19 - 2009-11-18 13:46 - 00446464 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll 2014-01-28 23:19 - 2009-11-18 13:45 - 00202752 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2014-01-28 23:19 - 2009-11-18 13:44 - 00120320 _____ (AMD) C:\Windows\system32\atitmm64.dll 2014-01-28 23:19 - 2009-11-18 13:43 - 00059392 _____ (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll 2014-01-28 23:19 - 2009-11-18 13:43 - 00043520 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll 2014-01-28 23:19 - 2009-11-18 13:43 - 00012288 _____ (AMD) C:\Windows\system32\atimuixx.dll 2014-01-28 23:19 - 2009-11-18 13:40 - 03053056 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2014-01-28 23:19 - 2009-11-18 13:29 - 17559552 _____ (ATI Technologies Inc.) C:\Windows\system32\atio6axx.dll 2014-01-28 23:19 - 2009-11-18 13:24 - 03609600 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2014-01-28 23:19 - 2009-11-18 13:18 - 04675584 _____ (ATI Technologies Inc. ) C:\Windows\system32\atiumd64.dll 2014-01-28 23:19 - 2009-11-18 13:11 - 13422080 _____ (ATI Technologies Inc.) C:\Windows\SysWOW64\atioglxx.dll 2014-01-28 23:19 - 2009-11-18 13:11 - 02600960 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2014-01-28 23:19 - 2009-11-18 13:09 - 00402016 _____ C:\Windows\system32\atiumd6a.cap 2014-01-28 23:19 - 2009-11-18 13:05 - 02896384 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2014-01-28 23:19 - 2009-11-18 13:05 - 00402016 _____ C:\Windows\SysWOW64\atiumdva.cap 2014-01-28 23:19 - 2009-11-18 12:53 - 00053248 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2014-01-28 23:19 - 2009-11-18 12:53 - 00053248 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2014-01-28 23:19 - 2009-11-18 12:53 - 00052224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2014-01-28 23:19 - 2009-11-18 12:53 - 00052224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2014-01-28 23:19 - 2009-11-18 12:52 - 00311296 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2014-01-28 23:19 - 2009-11-18 12:52 - 00225280 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 04678144 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00053248 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00053248 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00043008 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00039936 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2014-01-28 23:19 - 2009-11-18 12:47 - 03579904 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2014-01-28 23:19 - 2009-11-18 12:37 - 00053248 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2014-01-28 23:19 - 2009-10-30 12:44 - 00019017 _____ C:\Windows\atiogl.xml 2014-01-28 23:19 - 2009-10-22 10:59 - 00196565 _____ C:\Windows\system32\atiicdxx.dat 2014-01-28 23:19 - 2009-02-18 13:55 - 00332288 _____ C:\Windows\system32\ATIODE.exe 2014-01-28 23:19 - 2009-02-03 16:52 - 00051200 _____ C:\Windows\system32\ATIODCLI.exe 2014-01-28 23:17 - 2012-08-03 00:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-28 18:39 - 2012-01-13 19:09 - 00001138 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000UA.job 2014-01-28 17:25 - 2013-10-18 10:39 - 00000000 ____D C:\ProgramData\MFAData 2014-01-26 02:15 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Local\Battle.net 2014-01-26 00:39 - 2012-01-13 19:09 - 00001116 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000Core.job 2014-01-25 14:46 - 2011-11-23 02:51 - 00000000 ____D C:\Windows\pss 2014-01-25 14:46 - 2011-10-14 16:19 - 00000000 ___RD C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-25 14:29 - 2012-07-18 05:21 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000Core.job 2014-01-25 12:03 - 2011-10-14 16:21 - 00109296 _____ C:\Users\Pauly\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-25 11:57 - 2013-12-28 02:29 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Dropbox 2014-01-25 11:55 - 2009-07-14 05:45 - 00413656 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-25 11:53 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2014-01-25 11:45 - 2012-07-20 01:29 - 01594660 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-25 11:42 - 2011-10-15 17:43 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Skype 2014-01-24 17:04 - 2013-09-27 20:35 - 00000000 ____D C:\Users\Pauly\AppData\Local\Spotify 2014-01-24 13:35 - 2011-10-14 16:48 - 00000000 ____D C:\Users\Pauly\AppData\Local\Adobe 2014-01-24 13:24 - 2012-08-03 00:54 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-01-24 13:24 - 2012-04-03 13:33 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-24 13:24 - 2011-10-14 16:55 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-19 08:39 - 2011-10-14 16:28 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-19 08:33 - 2013-07-19 17:40 - 00000000 ____D C:\Windows\system32\MRT 2014-01-19 08:29 - 2011-10-14 17:18 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-18 06:20 - 2011-10-15 16:24 - 00000000 ____D C:\Users\Pauly\AppData\Local\PMB Files 2014-01-18 06:20 - 2011-10-15 16:24 - 00000000 ____D C:\ProgramData\PMB Files 2014-01-17 18:55 - 2014-01-17 18:55 - 00000632 _____ C:\Users\Public\Desktop\osu!.lnk 2014-01-17 16:21 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-17 06:46 - 2013-12-28 02:32 - 00001014 _____ C:\Users\Pauly\Desktop\Dropbox.lnk 2014-01-17 06:46 - 2013-12-28 02:30 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-16 22:30 - 2014-01-16 22:30 - 00001230 _____ C:\Users\Pauly\Desktop\Calculator.lnk 2014-01-15 16:58 - 2014-01-15 16:58 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard 2014-01-15 16:41 - 2014-01-15 16:41 - 00000755 _____ C:\Users\Public\Desktop\Hearthstone.lnk 2014-01-15 16:41 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Battle.net 2014-01-15 16:39 - 2014-01-15 16:39 - 00000758 _____ C:\Users\Public\Desktop\Battle.net.lnk 2014-01-15 16:39 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard Entertainment 2014-01-14 16:34 - 2014-01-13 23:25 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-14 16:30 - 2014-01-14 16:30 - 00001426 _____ C:\Users\Pauly\Desktop\APB Reloaded.lnk 2014-01-14 15:59 - 2014-01-14 15:59 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2014-01-14 15:59 - 2014-01-14 15:59 - 00000000 ____D C:\Users\Pauly\AppData\Local\PunkBuster 2014-01-14 15:59 - 2014-01-13 23:25 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-14 14:44 - 2014-01-14 14:44 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201401141444120183.log 2014-01-14 14:43 - 2014-01-14 14:43 - 00016738 _____ C:\Windows\SysWOW64\CCCInstall_201401141443071596.log 2014-01-14 14:41 - 2014-01-14 14:41 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2014-01-14 14:41 - 2014-01-13 23:26 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-14 14:25 - 2012-03-14 18:00 - 00000000 ____D C:\Windows\Minidump 2014-01-14 14:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2014-01-14 14:07 - 2011-10-15 11:31 - 00000000 ____D C:\ProgramData\P4G 2014-01-14 13:54 - 2014-01-14 13:54 - 00000000 ____D C:\Program Files\AMD 2014-01-14 13:42 - 2014-01-14 13:07 - 00000000 ____D C:\AMD 2014-01-14 13:02 - 2013-10-19 13:40 - 00004300 _____ C:\Windows\PFRO.log 2014-01-14 00:36 - 2014-01-14 00:36 - 00000000 ____D C:\Windows\SysWOW64\directx 2014-01-13 23:25 - 2014-01-13 23:25 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-13 23:25 - 2014-01-08 00:30 - 00069590 _____ C:\Windows\DirectX.log 2014-01-13 23:22 - 2014-01-13 23:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-13 22:28 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst LIVE! 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\Users\Pauly\AppData\Local\WarThunder 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\ProgramData\WarThunder 2014-01-13 21:38 - 2012-07-17 04:07 - 00000000 ____D C:\Users\Pauly\Documents\My Games 2014-01-13 21:14 - 2014-01-13 21:14 - 00001168 _____ C:\Users\Pauly\Desktop\GamersFirst LIVE!.lnk 2014-01-13 21:14 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst 2014-01-09 21:24 - 2014-01-09 21:24 - 00000209 _____ C:\Users\Pauly\Desktop\Torchlight II.url 2014-01-08 01:10 - 2014-01-08 01:10 - 00000000 ____D C:\Users\Pauly\Documents\Sniper - Ghost Warrior 2014-01-07 21:59 - 2014-01-07 21:59 - 00000000 ____D C:\Users\Pauly\Documents\Urlaubsparadies Tycoon 2011 ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-19 09:45 ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19355 - hxxp://www.gmer.net Rootkit scan 2014-01-29 00:09:58 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950042 rev.0006 465,76GB Running: gmer.exe; Driver: C:\Users\Pauly\AppData\Local\Temp\pxldrpog.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800039b9000 45 bytes [00, 00, 00, 00, 00, 00, 00, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff800039b902f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...] ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 00000000732d1a22 2 bytes [2D, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 00000000732d1ad0 2 bytes [2D, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 00000000732d1b08 2 bytes [2D, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 00000000732d1bba 2 bytes [2D, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 00000000732d1bda 2 bytes [2D, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076f11465 2 bytes [F1, 76] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076f114bb 2 bytes [F1, 76] .text ... * 2 ---- Processes - GMER 2.1 ---- Library C:\Users\Pauly\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [2960] 000007fef6a20000 Process C:\Users\Pauly\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (*** suspicious ***) @ C:\Users\Pauly\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [4020] 0000000000400000 Library \\?\C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-20\Indiv02_64.key (*** suspicious ***) @ C:\Program Files\Windows Media Player\wmpnetwk.exe [4384] (Individualized Black Box DLL/Microsoft Corporation SIGNED)(2012-02-29 12:28:14) 000000000ac00000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\1c4bd616c077 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\1c4bd616c077 (not active ControlSet) ---- EOF - GMER 2.1 ---- Geändert von adioz (29.01.2014 um 00:23 Uhr) |
29.01.2014, 08:09 | #2 |
/// the machine /// TB-Ausbilder | Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel hi,
__________________Scan mit Combofix
__________________ |
29.01.2014, 18:42 | #3 |
| Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Hallo,
__________________erst einmal Danke für die schnelle Rückmeldung. Habe mir das Programm heruntergeladen und wie beschrieben gestartet. Als der Scan das erste Mal durch lief, war ich gerade nicht am PC und sah nur, wie mein PC neustartet, als ich zurückkam. Das Programm öffnete sich direkt wieder und zeigte mir an, dass die Logfile erstellt werde und ich kein Programm öffnen solle. Dies dauerte dann über 40 Minuten, ohne dass etwas passierte. Als ich es dann versuchte zu schließen, kam die Meldung, dass es wohl den beschrieben Fehler in der Registry gäbe. Ich habe den PC daraufhin nochmal neugestartet und den Scan erneut laufen lassen. Diesmal startete der PC zwar nicht neu, allerdings passierte nach der Meldung, dass die Logfile erstellt wird wiederum nichts. |
30.01.2014, 16:09 | #4 |
/// the machine /// TB-Ausbilder | Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Schau mal ob du ne C:\Combofix.txt findest. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.01.2014, 16:16 | #5 |
| Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Danke! Tatsache, im Ordner C:\Combofix befand sich die datei combofix.txt, hier der Inhalt: Code:
ATTFilter ComboFix 14-01-29.01 - Pauly 29.01.2014 18:26:33.2.8 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.4021.2766 [GMT 1:00] ausgeführt von:: C:\Users\Pauly\Desktop\Scan\ComboFix.exe AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} SP: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) ---- Vorheriger Suchlauf ------- C:\Program Files (x86)\Common Files\Net4Switch.ico C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome.manifest C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\asyncDB.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\background.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\browserAction.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\contextMenu.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\dbManager.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\dom_bg.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\fileManager.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\firefox.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\firefoxNotifications.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\firefoxOmnibox.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\message.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\pageAction.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\request.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\tabs.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\api\webRequest.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\background.html C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\baseObject.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\browser.xul C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\console.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\consts.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\delegate.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\extensionDataStore.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\folderIOWrapper.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\httpObserver.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\IDBWrapper.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\installer.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\logFile.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\prefs.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\progressListenerObserver.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\registry.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\reloadObserver.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\reports.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\requestObject.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\searchSettings.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\uninstallObserver.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\updateManager.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\utils.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\core\xhr.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\dialog.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\main.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\options.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\options.xul C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\chrome\content\search_dialog.xul C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\defaults\preferences\prefs.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\manifest.xml C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins.json C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\1_base.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\101_cortica_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\102_dealply_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\103_intext_5_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\104_jollywallet_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\105_corticas_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\107_coupish_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\108_icm_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\116_ads_only_5_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\117_coupons_intext_ads_5_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\119_similar_web_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\120_luck_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\123_intext_adv_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\124_superfish_no_search_no_coupons_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\125_arcadi2_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\126_revizer_ws_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\127_revizer_p_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\128_superfish_pricora_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\129_widdit_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\13_CrossriderAppUtils.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\135_arcadi3_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\138_getdeal_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\14_CrossriderUtils.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\141_corticas_ru_m.js.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\142_intext_fa_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\155_ibario_pops_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\158_50onred_ads_only_no_fb_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\159_cortica_rollover_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\16_FFAppAPIWrapper.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\17_jQuery.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\170_icm1_5_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\171_arcadi2_sourceID_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\174_arcadi_serp_dynamic_id_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\175_coolmirage_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\177_crossriderDashboard.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\178_revizer_ws_dynamic_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\179_revizer_p_dynamic_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\182_openUrl.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\183_tabsWrapper.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\184_noproblemppc_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\189_active_sanity.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\191_ciuvo_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\200_foxydeal_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\21_debug.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\22_resources.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\28_initializer.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\4_jquery_1_7_1.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\47_resources_background.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\5_notifications.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\64_appApiMessage.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\7_hooks.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\72_appApiValidation.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\78_CrossriderInfo.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\79_CrossriderDailyPing.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\87_ginyas_wrapper.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\9_search_engine_hook.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\91_monetizationLoader.js.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\92_superfish_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\93_superfish_no_coupons_m.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\plugins\98_omniCommands.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\userCode\background.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\extensionData\userCode\extension.js C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\install.rdf C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\locale\en-US\translations.dtd C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\button1.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\button2.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\button3.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\button4.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\button5.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\crossrider_statusbar.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\icon128.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\icon16.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\icon24.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\icon48.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\panelarrow-up.png C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\popup.html C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\skin.css C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com\skin\update.css D:\install.exe ((((((((((((((((((((((( Dateien erstellt von 2013-12-28 bis 2014-01-29 )))))))))))))))))))))))))))))) 2014-01-29 17:33:36 . 2014-01-29 17:33:36 -------- d-----w- C:\Users\Default\AppData\Local\temp 2014-01-28 22:56:51 . 2014-01-28 22:56:51 -------- d-----w- C:\FRST 2014-01-28 22:22:56 . 2014-01-28 22:22:56 -------- d-----w- C:\Program Files\ATI Technologies 2014-01-25 10:49:51 . 2013-05-10 04:30:50 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe 2014-01-25 10:49:51 . 2013-05-10 03:48:09 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe 2014-01-25 10:49:50 . 2013-05-10 05:56:40 12625920 ----a-w- C:\Windows\system32\wmploc.DLL 2014-01-25 10:49:49 . 2013-05-10 04:56:15 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL 2014-01-25 10:49:47 . 2013-05-10 05:56:33 14631424 ----a-w- C:\Windows\system32\wmp.dll 2014-01-25 10:43:33 . 2014-01-25 10:43:33 -------- d-----w- C:\Windows\Migration 2014-01-25 10:41:18 . 2012-07-26 07:46:05 2560 ----a-w- C:\Windows\system32\drivers\de-DE\wdf01000.sys.mui 2014-01-25 10:31:38 . 2012-07-26 02:26:45 87040 ----a-w- C:\Windows\system32\drivers\WUDFPf.sys 2014-01-25 10:31:38 . 2012-07-26 02:26:06 198656 ----a-w- C:\Windows\system32\drivers\WUDFRd.sys 2014-01-25 10:31:37 . 2012-07-26 03:08:53 229888 ----a-w- C:\Windows\system32\WUDFHost.exe 2014-01-25 10:31:37 . 2012-07-26 03:08:14 84992 ----a-w- C:\Windows\system32\WUDFSvc.dll 2014-01-25 10:31:37 . 2012-07-26 03:08:14 744448 ----a-w- C:\Windows\system32\WUDFx.dll 2014-01-25 10:31:37 . 2012-07-26 03:08:14 45056 ----a-w- C:\Windows\system32\WUDFCoinstaller.dll 2014-01-25 10:31:37 . 2012-07-26 03:08:14 194048 ----a-w- C:\Windows\system32\WUDFPlatform.dll 2014-01-25 10:22:54 . 2012-12-07 11:20:03 43520 ----a-w- C:\Windows\system32\csrr.rs 2014-01-25 10:21:53 . 2012-11-22 05:44:23 800768 ----a-w- C:\Windows\system32\usp10.dll 2014-01-25 10:21:53 . 2012-11-22 04:45:03 626688 ----a-w- C:\Windows\SysWow64\usp10.dll 2014-01-25 10:21:52 . 2013-08-05 02:25:45 155584 ----a-w- C:\Windows\system32\drivers\ataport.sys 2014-01-19 07:28:43 . 2013-11-26 10:32:56 3156480 ----a-w- C:\Windows\system32\win32k.sys 2014-01-19 07:28:42 . 2013-11-27 01:41:37 343040 ----a-w- C:\Windows\system32\drivers\usbhub.sys 2014-01-19 07:28:42 . 2013-11-27 01:41:15 99840 ----a-w- C:\Windows\system32\drivers\usbccgp.sys 2014-01-19 07:28:42 . 2013-11-27 01:41:11 53248 ----a-w- C:\Windows\system32\drivers\usbehci.sys 2014-01-19 07:28:42 . 2013-11-27 01:41:11 325120 ----a-w- C:\Windows\system32\drivers\usbport.sys 2014-01-19 07:28:42 . 2013-11-27 01:41:09 25600 ----a-w- C:\Windows\system32\drivers\usbohci.sys 2014-01-19 07:28:42 . 2013-11-27 01:41:06 30720 ----a-w- C:\Windows\system32\drivers\usbuhci.sys 2014-01-19 07:28:42 . 2013-11-27 01:41:03 7808 ----a-w- C:\Windows\system32\drivers\usbd.sys 2014-01-15 15:58:15 . 2014-01-15 15:58:15 -------- d-----w- C:\Users\Pauly\AppData\Local\Blizzard 2014-01-15 15:39:55 . 2014-01-15 15:39:55 -------- d-----w- C:\Users\Pauly\AppData\Local\Blizzard Entertainment 2014-01-15 15:39:54 . 2014-01-26 01:15:41 -------- d-----w- C:\Users\Pauly\AppData\Local\Battle.net 2014-01-15 15:39:54 . 2014-01-15 15:41:20 -------- d-----w- C:\Users\Pauly\AppData\Roaming\Battle.net 2014-01-14 14:59:23 . 2014-01-14 14:59:23 290776 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr 2014-01-14 14:59:19 . 2014-01-14 14:59:19 -------- d-----w- C:\Users\Pauly\AppData\Local\PunkBuster 2014-01-14 13:41:30 . 2014-01-14 13:41:30 -------- d-----w- C:\Program Files\Common Files\ATI Technologies 2014-01-14 12:54:20 . 2014-01-14 12:54:20 -------- d-----w- C:\Program Files\AMD 2014-01-14 12:07:29 . 2014-01-14 12:42:21 -------- d-----w- C:\AMD 2014-01-13 22:26:23 . 2014-01-14 13:41:04 -------- d-----w- C:\ProgramData\Package Cache 2014-01-13 22:25:48 . 2014-01-14 15:34:10 290776 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe 2014-01-13 22:25:48 . 2014-01-14 14:59:23 290776 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0 2014-01-13 22:25:47 . 2014-01-13 22:25:47 76888 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe 2014-01-13 22:22:34 . 2014-01-13 22:22:34 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation 2014-01-13 20:38:38 . 2014-01-13 20:38:38 -------- d-----w- C:\Users\Pauly\AppData\Local\WarThunder 2014-01-13 20:38:38 . 2014-01-13 20:38:38 -------- d-----w- C:\ProgramData\WarThunder 2014-01-13 20:14:34 . 2014-01-13 21:28:53 -------- d-----w- C:\Users\Pauly\AppData\Local\GamersFirst LIVE! 2014-01-13 20:14:22 . 2014-01-13 20:14:22 -------- d-----w- C:\Users\Pauly\AppData\Local\GamersFirst 2014-01-07 23:31:48 . 2010-02-04 09:01:14 78680 ----a-w- C:\Windows\system32\XAPOFX1_4.dll . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) 2014-01-28 22:19:30 . 2009-11-18 12:24:08 3609600 ----a-w- C:\Windows\SysWow64\atiumdag.dll 2014-01-28 22:19:30 . 2009-11-18 12:18:20 4675584 ----a-w- C:\Windows\system32\atiumd64.dll 2014-01-28 22:19:30 . 2009-11-18 12:11:52 2600960 ----a-w- C:\Windows\system32\atiumd6a.dll 2014-01-28 22:19:30 . 2009-11-18 12:05:54 2896384 ----a-w- C:\Windows\SysWow64\atiumdva.dll 2014-01-28 22:19:29 . 2009-11-18 12:44:18 120320 ----a-w- C:\Windows\system32\atitmm64.dll 2014-01-28 22:19:29 . 2009-11-18 12:29:08 17559552 ----a-w- C:\Windows\system32\atio6axx.dll 2014-01-28 22:19:29 . 2009-11-18 12:11:32 13422080 ----a-w- C:\Windows\SysWow64\atioglxx.dll 2014-01-28 22:19:29 . 2009-02-18 12:55:24 332288 ----a-w- C:\Windows\system32\ATIODE.exe 2014-01-28 22:19:29 . 2009-02-03 15:52:08 51200 ----a-w- C:\Windows\system32\ATIODCLI.exe 2014-01-28 22:19:28 . 2012-06-11 17:01:56 3659264 ----a-w- C:\Windows\system32\atidxx64.dll 2014-01-28 22:19:28 . 2009-11-18 13:21:20 6171136 ----a-w- C:\Windows\system32\drivers\atikmdag.sys 2014-01-28 22:19:28 . 2009-11-18 12:46:26 446464 ----a-w- C:\Windows\system32\ATIDEMGX.dll 2014-01-28 22:19:28 . 2009-11-18 12:46:16 446976 ----a-w- C:\Windows\system32\atieclxx.exe 2014-01-28 22:19:28 . 2009-11-18 12:45:40 202752 ----a-w- C:\Windows\system32\atiesrxx.exe 2014-01-28 22:19:28 . 2009-11-18 12:43:30 12288 ----a-w- C:\Windows\system32\atimuixx.dll 2014-01-28 22:19:28 . 2009-11-18 12:43:24 59392 ----a-w- C:\Windows\system32\atiedu64.dll 2014-01-28 22:19:28 . 2009-11-18 12:40:28 3053056 ----a-w- C:\Windows\SysWow64\atidxx32.dll 2014-01-28 22:19:28 . 2009-11-18 11:53:24 53248 ----a-w- C:\Windows\system32\atimpc64.dll 2014-01-28 22:19:28 . 2009-11-18 11:53:24 53248 ----a-w- C:\Windows\system32\amdpcom64.dll 2014-01-28 22:19:28 . 2009-11-18 11:53:18 52224 ----a-w- C:\Windows\SysWow64\atimpc32.dll 2014-01-28 22:19:28 . 2009-11-18 11:53:18 52224 ----a-w- C:\Windows\SysWow64\amdpcom32.dll 2014-01-28 22:19:28 . 2009-11-18 11:48:44 43008 ----a-w- C:\Windows\system32\aticalrt64.dll 2014-01-28 22:19:28 . 2009-11-18 11:48:42 53248 ----a-w- C:\Windows\SysWow64\aticalrt.dll 2014-01-28 22:19:28 . 2009-11-18 11:48:18 4678144 ----a-w- C:\Windows\system32\aticaldd64.dll 2014-01-28 22:19:28 . 2009-11-18 11:47:22 3579904 ----a-w- C:\Windows\SysWow64\aticaldd.dll 2014-01-28 22:19:27 . 2009-11-18 12:43:18 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll 2014-01-28 22:19:27 . 2009-11-18 11:52:52 311296 ----a-w- C:\Windows\system32\atiadlxx.dll 2014-01-28 22:19:27 . 2009-11-18 11:52:46 225280 ----a-w- C:\Windows\SysWow64\atiadlxy.dll 2014-01-28 22:19:27 . 2009-11-18 11:48:32 39936 ----a-w- C:\Windows\system32\aticalcl64.dll 2014-01-28 22:19:27 . 2009-11-18 11:48:30 53248 ----a-w- C:\Windows\SysWow64\aticalcl.dll 2014-01-28 22:19:27 . 2009-11-18 11:37:38 53248 ----a-w- C:\Windows\system32\drivers\ati2erec.dll 2014-01-24 12:24:35 . 2012-04-03 12:33:52 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2014-01-24 12:24:35 . 2011-10-14 15:55:42 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2014-01-19 07:29:38 . 2011-10-14 16:18:20 86054176 ----a-w- C:\Windows\system32\MRT.exe 2013-12-06 21:38:40 . 2013-12-06 21:38:40 1187342 ----a-w- C:\Windows\system32\amdocl_as64.exe 2013-12-06 21:38:40 . 2013-12-06 21:38:40 1061902 ----a-w- C:\Windows\system32\amdocl_ld64.exe 2013-12-06 21:38:38 . 2013-12-06 21:38:38 995342 ----a-w- C:\Windows\SysWow64\amdocl_as32.exe 2013-12-06 21:38:38 . 2013-12-06 21:38:38 798734 ----a-w- C:\Windows\SysWow64\amdocl_ld32.exe 2013-12-06 21:38:34 . 2013-12-06 21:38:34 99840 ----a-w- C:\Windows\system32\OpenVideo64.dll 2013-12-06 21:38:28 . 2013-12-06 21:38:28 83968 ----a-w- C:\Windows\SysWow64\OpenVideo.dll 2013-12-06 21:38:22 . 2013-12-06 21:38:22 86528 ----a-w- C:\Windows\system32\OVDecode64.dll 2013-12-06 21:38:18 . 2013-12-06 21:38:18 73728 ----a-w- C:\Windows\SysWow64\OVDecode.dll 2013-12-06 21:37:58 . 2013-12-06 21:37:58 29382144 ----a-w- C:\Windows\system32\amdocl64.dll 2013-12-06 21:35:36 . 2013-12-06 21:35:36 24860160 ----a-w- C:\Windows\SysWow64\amdocl.dll 2013-12-06 21:33:28 . 2013-12-06 21:33:28 63488 ----a-w- C:\Windows\system32\OpenCL.dll 2013-12-06 21:33:24 . 2013-12-06 21:33:24 57344 ----a-w- C:\Windows\SysWow64\OpenCL.dll 2013-12-06 20:53:18 . 2013-12-06 20:53:18 442368 ----a-w- C:\Windows\system32\atidemgy.dll 2013-12-06 15:49:18 . 2013-12-06 15:49:18 51200 ----a-w- C:\Windows\system32\kdbsdk64.dll 2013-12-06 15:44:26 . 2013-12-06 15:44:26 38912 ----a-w- C:\Windows\SysWow64\kdbsdk32.dll 2013-11-23 20:54:45 . 2011-11-20 18:26:30 18960 ----a-w- C:\Windows\system32\drivers\LNonPnP.sys 2013-11-12 02:23:09 . 2013-12-15 11:35:21 2048 ----a-w- C:\Windows\system32\tzres.dll 2013-11-12 02:07:29 . 2013-12-15 11:35:21 2048 ----a-w- C:\Windows\SysWow64\tzres.dll 2013-11-05 20:55:48 . 2013-11-05 20:55:48 150808 ----a-w- C:\Windows\system32\drivers\avgdiska.sys 2013-11-04 20:52:42 . 2013-11-04 20:52:42 240920 ----a-w- C:\Windows\system32\drivers\avgidsdrivera.sys 2013-10-31 22:00:18 . 2013-10-31 22:00:18 212280 ----a-w- C:\Windows\system32\drivers\avgldx64.sys 2013-10-31 21:49:46 . 2013-10-31 21:49:46 294712 ----a-w- C:\Windows\system32\drivers\avgloga.sys (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{808dc83c-d35b-4fba-a5b5-9a52103204df}] 2013-10-18 17:00:46 249632 ----a-w- C:\Program Files (x86)\Swift Browse\SwiftBrowseBHO.dll [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09:56 131248 ----a-w- C:\Users\Pauly\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09:56 131248 ----a-w- C:\Users\Pauly\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09:56 131248 ----a-w- C:\Users\Pauly\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 16:36:46 30040] "NUSB3MON"="C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-10-21 10:12:50 106496] "ATKOSD2"="C:\Programme (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2012-06-25 13:54:28 322208] "ATKMEDIA"="C:\Programme (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2012-06-19 11:59:04 174752] "HControlUser"="C:\Programme (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 08:29:42 105016] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" R2 AVGIDSAgent;AVGIDSAgent;D:\Programme\AVG2014\avgidsagent.exe;D:\Programme\AVG2014\avgidsagent.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AF9035BDA;Cinergy T-Stick service;C:\Windows\system32\DRIVERS\AF15BDA.sys;C:\Windows\SYSNATIVE\DRIVERS\AF15BDA.sys [x] R3 ALSysIO;ALSysIO;C:\Users\Pauly\AppData\Local\Temp\ALSysIO64.sys;C:\Users\Pauly\AppData\Local\Temp\ALSysIO64.sys [x] R3 andnetadb;ADB Interface DriverNet;C:\Windows\system32\Drivers\lgandnetadb.sys;C:\Windows\SYSNATIVE\Drivers\lgandnetadb.sys [x] R3 AndNetDiag;LGE AndroidNet USB Serial Port;C:\Windows\system32\DRIVERS\lgandnetdiag64.sys;C:\Windows\SYSNATIVE\DRIVERS\lgandnetdiag64.sys [x] R3 ANDNetModem;LGE AndroidNet USB Modem;C:\Windows\system32\DRIVERS\lgandnetmodem64.sys;C:\Windows\SYSNATIVE\DRIVERS\lgandnetmodem64.sys [x] R3 btusbflt;Bluetooth USB Filter;C:\Windows\system32\drivers\btusbflt.sys;C:\Windows\SYSNATIVE\drivers\btusbflt.sys [x] R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys;C:\Windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] R3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys;C:\Windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\system32\DRIVERS\ew_hwusbdev.sys;C:\Windows\SYSNATIVE\DRIVERS\ew_hwusbdev.sys [x] R3 ewusbnet;HUAWEI USB-NDIS miniport;C:\Windows\system32\DRIVERS\ewusbnet.sys;C:\Windows\SYSNATIVE\DRIVERS\ewusbnet.sys [x] R3 GPU-Z;GPU-Z;C:\Users\Pauly\AppData\Local\Temp\GPU-Z.sys;C:\Users\Pauly\AppData\Local\Temp\GPU-Z.sys [x] R3 ipswuio;ipswuio;C:\Windows\system32\DRIVERS\ipswuio.sys;C:\Windows\SYSNATIVE\DRIVERS\ipswuio.sys [x] R3 LADF_BakerCOnly;BakerC Filter Driver;C:\Windows\system32\DRIVERS\ladfBakerCamd64.sys;C:\Windows\SYSNATIVE\DRIVERS\ladfBakerCamd64.sys [x] R3 LADF_BakerROnly;BakerR Filter Driver;C:\Windows\system32\DRIVERS\ladfBakerRamd64.sys;C:\Windows\SYSNATIVE\DRIVERS\ladfBakerRamd64.sys [x] R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;C:\Windows\system32\drivers\LGVirHid.sys;C:\Windows\SYSNATIVE\drivers\LGVirHid.sys [x] R3 massfilter;ZTE Mass Storage Filter Driver;C:\Windows\system32\drivers\massfilter.sys;C:\Windows\SYSNATIVE\drivers\massfilter.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys;C:\Windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\system32\drivers\ScreamingBAudio64.sys;C:\Windows\SYSNATIVE\drivers\ScreamingBAudio64.sys [x] R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys;C:\Windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys;C:\Windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys;C:\Windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R4 AFBAgent;AFBAgent;C:\Windows\system32\FBAgent.exe;C:\Windows\SYSNATIVE\FBAgent.exe [x] R4 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe;C:\Windows\SYSNATIVE\atiesrxx.exe [x] R4 HiPatchService;Hi-Rez Studios Authenticate and Update Service;D:\Spiele\Smite\HiPatchService.exe;D:\Spiele\Smite\HiPatchService.exe [x] R4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe;C:\Program Files (x86)\Skype\Updater\Updater.exe [x] R4 TGCM_ImportWiFiSvc;TGCM_ImportWiFiSvc;D:\o2\Mobile Connection Manager\ImpWiFiSvc.exe;D:\o2\Mobile Connection Manager\ImpWiFiSvc.exe [x] R4 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys;C:\Windows\SYSNATIVE\DRIVERS\avgidsha.sys [x] S0 Avgloga;AVG Logging Driver;C:\Windows\system32\DRIVERS\avgloga.sys;C:\Windows\SYSNATIVE\DRIVERS\avgloga.sys [x] S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys;C:\Windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys;C:\Windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x] S1 Avgdiska;AVG Disk Driver;C:\Windows\system32\DRIVERS\avgdiska.sys;C:\Windows\SYSNATIVE\DRIVERS\avgdiska.sys [x] S1 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys;C:\Windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x] S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys;C:\Windows\SYSNATIVE\DRIVERS\avgldx64.sys [x] S1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys;C:\Windows\SYSNATIVE\DRIVERS\avgtdia.sys [x] S2 ASMMAP64;ASMMAP64;C:\Programme (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;C:\Programme (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 avgwd;AVG WatchDog;D:\Programme\AVG2014\avgwdsvc.exe;D:\Programme\AVG2014\avgwdsvc.exe [x] S2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x] S2 Update Swift Browse;Update Swift Browse;C:\Program Files (x86)\Swift Browse\updateSwiftBrowse.exe;C:\Program Files (x86)\Swift Browse\updateSwiftBrowse.exe [x] S2 Util Swift Browse;Util Swift Browse;C:\Program Files (x86)\Swift Browse\bin\utilSwiftBrowse.exe;C:\Program Files (x86)\Swift Browse\bin\utilSwiftBrowse.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys;C:\Windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys;C:\Windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys;C:\Windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] S3 huawei_enumerator;huawei_enumerator;C:\Windows\system32\DRIVERS\ew_jubusenum.sys;C:\Windows\SYSNATIVE\DRIVERS\ew_jubusenum.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\system32\DRIVERS\L1C62x64.sys;C:\Windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 LADF_CaptureOnly;LADF Capture Filter Driver;C:\Windows\system32\DRIVERS\ladfGSCamd64.sys;C:\Windows\SYSNATIVE\DRIVERS\ladfGSCamd64.sys [x] S3 LADF_RenderOnly;LADF Render Filter Driver;C:\Windows\system32\DRIVERS\ladfGSRamd64.sys;C:\Windows\SYSNATIVE\DRIVERS\ladfGSRamd64.sys [x] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\system32\drivers\LGBusEnum.sys;C:\Windows\SYSNATIVE\drivers\LGBusEnum.sys [x] S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;C:\Windows\system32\DRIVERS\LGSHidFilt.Sys;C:\Windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x] S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys;C:\Windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys;C:\Windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}] start [BU] Inhalt des "geplante Tasks" Ordners 2014-01-29 C:\Windows\Tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 12:33:52 . 2014-01-24 12:24:36] 2014-01-29 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-06-06 13:38:07 . 2012-06-06 13:38:05] 2014-01-29 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-06-06 13:38:07 . 2012-06-06 13:38:05] 2014-01-25 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000Core.job - C:\Users\Pauly\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-18 04:21:54 . 2012-07-18 04:21:54] 2014-01-29 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000UA.job - C:\Users\Pauly\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-18 04:21:54 . 2012-07-18 04:21:54] --------- X64 Entries ----------- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09:56 164016 ----a-w- C:\Users\Pauly\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09:56 164016 ----a-w- C:\Users\Pauly\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09:56 164016 ----a-w- C:\Users\Pauly\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09:56 164016 ----a-w- C:\Users\Pauly\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ETDWare"="C:\Program Files\Elantech\ETDCtrl.exe" [2009-09-30 03:55:26 621440] //Update 1: Malwarebytes ist fündig geworden, alles Gefundene gelöscht, hier der Bericht: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.30.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16750 Pauly :: ADIOZ [Administrator] 30.01.2014 16:19:20 mbam-log-2014-01-30 (16-19-20).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 217779 Laufzeit: 6 Minute(n), 5 Sekunde(n) Infizierte Speicherprozesse: 2 C:\Program Files (x86)\Swift Browse\updateSwiftBrowse.exe (PUP.Optional.SwiftBrowse.A) -> 2300 -> Löschen bei Neustart. C:\Program Files (x86)\Swift Browse\bin\utilSwiftBrowse.exe (PUP.Optional.SwiftBrowse.A) -> 3900 -> Löschen bei Neustart. Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 22 HKCR\CLSID\{808dc83c-d35b-4fba-a5b5-9a52103204df} (PUP.Optional.SwiftBrowse.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{808DC83C-D35B-4FBA-A5B5-9A52103204DF} (PUP.Optional.SwiftBrowse.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{808DC83C-D35B-4FBA-A5B5-9A52103204DF} (PUP.Optional.SwiftBrowse.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{808DC83C-D35B-4FBA-A5B5-9A52103204DF} (PUP.Optional.SwiftBrowse.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\AppID\{9A246976-806F-4B2E-B3B9-A9A58F5685AA} (PUP.Optional.Ominent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{271FF4A7-3AA1-4DA8-B272-B10D2025C9D6} (PUP.Optional.Ominent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CrossriderApp0043628.BHO (PUP.Optional.CrossRider.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CrossriderApp0043628.Sandbox (PUP.Optional.CrossRider.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CrossriderApp0043628.Sandbox.1 (PUP.Optional.CrossRider.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\esrv.ominentESrvc (PUP.Optional.Ominent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\esrv.ominentESrvc.1 (PUP.Optional.Ominent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\ominent.ominentappCore (PUP.Optional.Ominent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\ominent.ominentappCore.1 (PUP.Optional.Ominent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\InstalledBrowserExtensions\weDownload (PUP.Optional.WeDownload.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SYSTEM\CurrentControlSet\Services\Update Swift Browse (PUP.Optional.SwiftBrowse.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SYSTEM\CurrentControlSet\Services\Util Swift Browse (PUP.Optional.SwiftBrowse.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\Software\Google\Chrome\Extensions\jgapglgghagmhogfjkdlnnmbdfddeedb (PUP.Optional.SwiftBrowse.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\Software\Wow6432Node\Swift Browse (PUP.Optional.SwiftBrowse.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411361128} (PUP.Optional.CrossRider.M) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{11111111-1111-1111-1111-110411361128} (PUP.Optional.CrossRider.M) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411361128} (PUP.Optional.CrossRider.M) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411361128} (PUP.Optional.CrossRider.M) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 4 C:\Program Files (x86)\Swift Browse\SwiftBrowseBHO.dll (PUP.Optional.SwiftBrowse.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Pauly\Downloads\PhotoScape_V3.6.5.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Swift Browse\updateSwiftBrowse.exe (PUP.Optional.SwiftBrowse.A) -> Löschen bei Neustart. C:\Program Files (x86)\Swift Browse\bin\utilSwiftBrowse.exe (PUP.Optional.SwiftBrowse.A) -> Löschen bei Neustart. (Ende) //Update 2: AdwCleaner durchlaufen lassen, wieder fündig geworden und entfernt, hier der Bericht: Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 30/01/2014 um 16:33:02 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Pauly - ADIOZ # Gestartet von : C:\Users\Pauly\Desktop\Scan\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\Program Files (x86)\Conduit Ordner Gelöscht : C:\Program Files (x86)\Swift Browse Ordner Gelöscht : C:\Users\Pauly\AppData\LocalLow\Conduit Datei Gelöscht : C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\11-suche.xml Datei Gelöscht : C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455365528} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466366628} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455365528} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466366628} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gelöscht : HKCU\Software\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Swift Browse Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\DeviceVM Schlüssel Gelöscht : HKLM\Software\InstallIQ Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DeviceVM Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Swift Browse ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16750 -\\ Mozilla Firefox v15.0.1 (de) [ Datei : C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\prefs.js ] Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.cookie.CrossriderNotifier_channels.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.cookie.CrossriderNotifier_channels.value", "%7B%22app0%22%3A%22app0%22%2C%22app43628%22%3A%22app43[...] Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.description", "Enhance your search results with direct download links and information for apps and[...] Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_meta.value", "%7B%22extension.css%22%3A%7B%22id%22%3A311159%2C%22ver%22%3A2%2[...] Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_resource_311159.value", "%22.crossrider-nofity-34345-body-theme-white-black%2[...] Zeile gelöscht : user_pref("extensions.crossrider.bic", "1420e93ee99cc926a6620bbd1a65a040"); Zeile gelöscht : user_pref("keyword.keywordURL", "hxxp://search.hotspotshield.com/g/results.php?c=s&q="); -\\ Google Chrome v [ Datei : C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [5392 octets] - [30/01/2014 16:31:28] AdwCleaner[S0].txt - [5017 octets] - [30/01/2014 16:33:02] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5077 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Professional x64 Ran by Pauly on 30.01.2014 at 16:39:43,71 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\caphyon Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220422362228} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220422362228} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5533637B-7FE5-43F8-B0D4-B87178C6D8CC} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Program Files (x86)\websparkle" ~~~ FireFox Successfully deleted the following from C:\Users\Pauly\AppData\Roaming\mozilla\firefox\profiles\y6ebfp5y.default\prefs.js user_pref("extensions.ghostery.uiLog", "{\"type\":\"sub_object_block\",\"ref\":\"zattoo.com/view#dmax\",\"to\":\"hxxp://zattoo.com/static/images/channels/b_50x36/DSF.png?v=1\" Emptied folder: C:\Users\Pauly\AppData\Roaming\mozilla\firefox\profiles\y6ebfp5y.default\minidumps [19 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 30.01.2014 at 16:47:35,84 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Geändert von adioz (30.01.2014 um 16:55 Uhr) |
30.01.2014, 16:55 | #6 |
| Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Hier noch der abschließende FRST-Log (musste einen neuen Beitrag starten, da es zu viele Zeichen gewesen wären) Vielen, vielen Dank bis hierhin erstmal, scheint ja schon einiges gefunden/entfernt zu haben. FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01 Ran by Pauly (administrator) on ADIOZ on 30-01-2014 16:51:19 Running from C:\Users\Pauly\Desktop\Scan Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgwdsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ATK) C:\Program Files\P4G\BatteryLife.exe () C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUSTek Computer Inc.) C:\Programme (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ASUSTek Computer Inc.) C:\Programme (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgui.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [621440 2009-09-30] (ELAN Microelectronic Corp.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9642528 2009-12-03] (Realtek Semiconductor) HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-10-21] (NEC Electronics Corporation) HKLM-x32\...\Run: [ATKOSD2] - C:\Programme (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-06-25] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ATKMEDIA] - C:\Programme (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-06-19] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x61B88996D817CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ URLSearchHook: HKCU - (No Name) - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {012AF763-C60F-4CB9-8E4F-F45951BFAB17} URL = hxxp://www.google.de/search?q={searchTerms} BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - D:\Programme\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH) Toolbar: HKCU - No Name - {F0381DBD-E018-4E07-AE40-D96AB15083F0} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - d:\Programme\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Programme\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - d:\Programme\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 - d:\Programme\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - d:\Programme\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin-x32: @videolan.org/vlc,version=2.0.4 - d:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - d:\Programme\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Pauly\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Pauly\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Pauly\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Ghostery - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\firefox@ghostery.com [2013-11-02] FF Extension: WOT - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-02] FF Extension: Swift Browse - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\firefox@swiftbrowse.net.xpi [2013-10-18] FF Extension: WEB.DE MailCheck - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\toolbar@web.de.xpi [2011-12-19] FF Extension: Adblock Plus - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-11-04] Chrome: ======= CHR HomePage: hxxp://search.ominent.com/ws/?source=9f1d0980&tbp=homepage&toolbarid=base&u=cc40d42800000000000072f06d3396e4 CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.102\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.102\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.102\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.270.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U27) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Microsoft Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Pauly\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (iTunes Application Detector) - D:\Programme\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Veetle TV Player) - d:\Programme\Veetle\Player\npvlc.dll (Veetle Inc) CHR Plugin: (Veetle TV Core) - d:\Programme\Veetle\plugins\npVeetle.dll (Veetle Inc) CHR Extension: (YouTube Options) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdokagampppgbnjfdlkfpphniapiiifn [2013-10-18] CHR Extension: (YouTube) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-18] CHR Extension: (Adblock Plus) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2012-07-18] CHR Extension: (Google-Suche) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-18] CHR Extension: (Grooveshark Germany unlocker) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac [2013-05-19] CHR Extension: (Hola Besseres Internet) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2013-10-18] CHR Extension: (WEB.DE MailCheck) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo [2013-12-26] CHR Extension: (Google Wallet) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (YouTube Unblocker) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [2013-12-10] CHR Extension: (Google Mail) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-18] CHR StartMenuInternet: Google Chrome - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= S4 ASLDRService; C:\Programme (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [80512 2011-11-21] (ASUS) S2 AVGIDSAgent; D:\Programme\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; D:\Programme\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) S4 HiPatchService; D:\Spiele\Smite\HiPatchService.exe [8704 2012-07-12] (Hi-Rez Studios) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-01-13] () S4 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () S4 TGCM_ImportWiFiSvc; D:\o2\Mobile Connection Manager\ImpWiFiSvc.exe [200624 2010-09-29] (Telefónica I+D) ==================== Drivers (Whitelisted) ==================== S3 AF9035BDA; C:\Windows\System32\DRIVERS\AF15BDA.sys [513600 2009-11-05] (ITETech ) S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2012-03-07] (Google Inc) S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2012-03-06] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2012-03-06] (LG Electronics Inc.) R2 ASMMAP64; C:\Programme (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [15416 2009-07-02] (ASUS) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S3 LADF_BakerCOnly; C:\Windows\System32\DRIVERS\ladfBakerCamd64.sys [410184 2011-03-18] (Logitech) S3 LADF_BakerROnly; C:\Windows\System32\DRIVERS\ladfBakerRamd64.sys [335688 2011-03-18] (Logitech) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () S3 ALSysIO; \??\C:\Users\Pauly\AppData\Local\Temp\ALSysIO64.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 GPU-Z; \??\C:\Users\Pauly\AppData\Local\Temp\GPU-Z.sys [x] S3 ipswuio; System32\DRIVERS\ipswuio.sys [x] S3 massfilter; system32\drivers\massfilter.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-30 16:47 - 2014-01-30 16:47 - 00001564 _____ C:\Users\Pauly\Desktop\JRT.txt 2014-01-30 16:39 - 2014-01-30 16:39 - 00000000 ____D C:\Windows\ERUNT 2014-01-30 16:31 - 2014-01-30 16:34 - 00000000 ____D C:\AdwCleaner 2014-01-30 16:17 - 2014-01-30 16:17 - 00000736 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-30 16:17 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-29 22:17 - 2014-01-29 22:17 - 00000146 _____ C:\Users\Pauly\Desktop\Sound - Verknüpfung.lnk 2014-01-29 18:25 - 2014-01-29 18:34 - 00000000 ____D C:\ComboFix 2014-01-29 17:25 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-29 17:25 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-29 17:25 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-29 17:25 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-29 17:25 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-29 17:25 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-29 17:25 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-29 17:25 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-29 17:24 - 2014-01-29 17:32 - 00000000 ____D C:\Qoobox 2014-01-29 17:23 - 2014-01-29 17:37 - 00000000 ____D C:\Windows\erdnt 2014-01-28 23:56 - 2014-01-30 16:51 - 00000000 ____D C:\FRST 2014-01-28 23:56 - 2014-01-28 23:56 - 00000000 _____ C:\Users\Pauly\defogger_reenable 2014-01-28 23:53 - 2014-01-30 16:51 - 00000000 ____D C:\Users\Pauly\Desktop\Scan 2014-01-28 23:37 - 2014-01-28 23:37 - 00000879 _____ C:\Users\Pauly\Desktop\Spybot - Search & Destroy.lnk 2014-01-28 23:22 - 2014-01-28 23:22 - 00000000 ____D C:\Program Files\ATI Technologies 2014-01-28 23:21 - 2014-01-28 23:21 - 00054772 _____ C:\Windows\SysWOW64\CCCInstall_201401282321398833.log 2014-01-25 11:49 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-01-25 11:49 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-01-25 11:49 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-01-25 11:49 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-01-25 11:39 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-01-25 11:39 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-01-25 11:39 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2014-01-25 11:39 - 2012-08-23 15:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-01-25 11:39 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-01-25 11:39 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-01-25 11:39 - 2012-08-23 14:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-01-25 11:39 - 2012-08-23 14:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-01-25 11:39 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-01-25 11:39 - 2012-08-23 14:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-01-25 11:39 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-01-25 11:39 - 2012-08-23 14:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-01-25 11:39 - 2012-08-23 14:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-01-25 11:39 - 2012-08-23 13:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-01-25 11:39 - 2012-08-23 12:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-01-25 11:39 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2014-01-25 11:39 - 2012-08-23 12:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-01-25 11:39 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2014-01-25 11:39 - 2012-08-23 11:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-01-25 11:39 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-01-25 11:39 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-01-25 11:39 - 2012-08-23 11:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-01-25 11:39 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-01-25 11:39 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-01-25 11:39 - 2012-08-23 09:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2014-01-25 11:31 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2014-01-25 11:31 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2014-01-25 11:31 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2014-01-25 11:31 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2014-01-25 11:23 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-01-25 11:23 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-01-25 11:23 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2014-01-25 11:23 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-01-25 11:23 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2014-01-25 11:23 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-01-25 11:23 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-01-25 11:23 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-01-25 11:23 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2014-01-25 11:23 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-01-25 11:23 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2014-01-25 11:23 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-01-25 11:23 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-01-25 11:23 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-01-25 11:23 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-01-25 11:23 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2014-01-25 11:23 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2014-01-25 11:23 - 2012-11-30 06:45 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-01-25 11:23 - 2012-11-30 06:45 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-01-25 11:23 - 2012-11-30 06:43 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-01-25 11:23 - 2012-11-30 00:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2014-01-25 11:23 - 2012-11-30 00:15 - 00420064 _____ C:\Windows\system32\locale.nls 2014-01-25 11:23 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2014-01-25 11:23 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2014-01-25 11:23 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2014-01-25 11:23 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2014-01-25 11:23 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2014-01-25 11:23 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-01-25 11:23 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2014-01-25 11:23 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2014-01-25 11:22 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-25 11:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-01-25 11:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-01-25 11:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-01-25 11:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-01-25 11:22 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2014-01-25 11:22 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2014-01-25 11:22 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-01-25 11:22 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2014-01-25 11:22 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-01-25 11:22 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2014-01-25 11:22 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-01-25 11:22 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2014-01-25 11:22 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2014-01-25 11:22 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2014-01-25 11:22 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2014-01-25 11:22 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2014-01-25 11:22 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2014-01-25 11:22 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2014-01-25 11:22 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2014-01-25 11:22 - 2013-04-17 08:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-01-25 11:22 - 2013-04-17 07:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-01-25 11:22 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-01-25 11:22 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2014-01-25 11:22 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2014-01-25 11:22 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2014-01-25 11:22 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2014-01-25 11:22 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2014-01-25 11:22 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2014-01-25 11:22 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2014-01-25 11:22 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2014-01-25 11:22 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2014-01-25 11:22 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2014-01-25 11:22 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2014-01-25 11:22 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2014-01-25 11:22 - 2012-07-06 21:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2014-01-25 11:22 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2014-01-25 11:22 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2014-01-25 11:22 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2014-01-25 11:21 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2014-01-25 11:21 - 2012-11-22 06:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-01-25 11:21 - 2012-11-22 05:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-01-19 08:28 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-19 08:28 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-17 18:55 - 2014-01-17 18:55 - 00000632 _____ C:\Users\Public\Desktop\osu!.lnk 2014-01-16 22:30 - 2014-01-16 22:30 - 00001230 _____ C:\Users\Pauly\Desktop\Calculator.lnk 2014-01-15 16:58 - 2014-01-15 16:58 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard 2014-01-15 16:41 - 2014-01-15 16:41 - 00000755 _____ C:\Users\Public\Desktop\Hearthstone.lnk 2014-01-15 16:39 - 2014-01-26 02:15 - 00000000 ____D C:\Users\Pauly\AppData\Local\Battle.net 2014-01-15 16:39 - 2014-01-15 16:41 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Battle.net 2014-01-15 16:39 - 2014-01-15 16:39 - 00000758 _____ C:\Users\Public\Desktop\Battle.net.lnk 2014-01-15 16:39 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard Entertainment 2014-01-14 15:59 - 2014-01-14 15:59 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2014-01-14 15:59 - 2014-01-14 15:59 - 00000000 ____D C:\Users\Pauly\AppData\Local\PunkBuster 2014-01-14 14:44 - 2014-01-14 14:44 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201401141444120183.log 2014-01-14 14:43 - 2014-01-14 14:43 - 00016738 _____ C:\Windows\SysWOW64\CCCInstall_201401141443071596.log 2014-01-14 14:41 - 2014-01-14 14:41 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2014-01-14 13:54 - 2014-01-14 13:54 - 00000000 ____D C:\Program Files\AMD 2014-01-14 13:07 - 2014-01-14 13:42 - 00000000 ____D C:\AMD 2014-01-14 00:36 - 2014-01-14 00:36 - 00000000 ____D C:\Windows\SysWOW64\directx 2014-01-13 23:26 - 2014-01-14 14:41 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-13 23:25 - 2014-01-14 16:34 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-13 23:25 - 2014-01-14 15:59 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-13 23:25 - 2014-01-13 23:25 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-13 23:22 - 2014-01-13 23:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\Users\Pauly\AppData\Local\WarThunder 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\ProgramData\WarThunder 2014-01-13 21:14 - 2014-01-28 23:32 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2014-01-13 21:14 - 2014-01-13 22:28 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst LIVE! 2014-01-13 21:14 - 2014-01-13 21:14 - 00001168 _____ C:\Users\Pauly\Desktop\GamersFirst LIVE!.lnk 2014-01-13 21:14 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst 2014-01-09 21:26 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-01-09 21:24 - 2014-01-09 21:24 - 00000209 _____ C:\Users\Pauly\Desktop\Torchlight II.url 2014-01-08 01:10 - 2014-01-08 01:10 - 00000000 ____D C:\Users\Pauly\Documents\Sniper - Ghost Warrior 2014-01-08 00:31 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2014-01-08 00:31 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-01-08 00:31 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2014-01-08 00:31 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-01-08 00:31 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-01-08 00:31 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-01-08 00:31 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-01-08 00:31 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-01-08 00:31 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-01-08 00:31 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-01-08 00:31 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-01-08 00:31 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-01-08 00:31 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-01-08 00:31 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-01-08 00:31 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-01-08 00:31 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-01-08 00:31 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-01-08 00:31 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-01-08 00:31 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-01-08 00:31 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-01-08 00:31 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-01-08 00:31 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-01-08 00:31 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-01-08 00:31 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-01-08 00:31 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-01-08 00:31 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-01-08 00:31 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-01-08 00:31 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-01-08 00:31 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-01-08 00:31 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-01-08 00:31 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-01-08 00:31 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-01-08 00:31 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-01-08 00:31 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-01-08 00:31 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-01-08 00:31 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-01-08 00:31 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-01-08 00:31 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-01-08 00:31 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-01-08 00:31 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-01-08 00:31 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-01-08 00:31 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-01-08 00:31 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-01-08 00:31 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-01-08 00:31 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-01-08 00:31 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-01-08 00:31 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-01-08 00:31 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-01-08 00:31 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-01-08 00:31 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-01-08 00:30 - 2014-01-13 23:25 - 00069590 _____ C:\Windows\DirectX.log 2014-01-07 21:59 - 2014-01-07 21:59 - 00000000 ____D C:\Users\Pauly\Documents\Urlaubsparadies Tycoon 2011 ==================== One Month Modified Files and Folders ======= 2014-01-30 16:51 - 2014-01-28 23:56 - 00000000 ____D C:\FRST 2014-01-30 16:51 - 2014-01-28 23:53 - 00000000 ____D C:\Users\Pauly\Desktop\Scan 2014-01-30 16:47 - 2014-01-30 16:47 - 00001564 _____ C:\Users\Pauly\Desktop\JRT.txt 2014-01-30 16:43 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-30 16:43 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-30 16:39 - 2014-01-30 16:39 - 00000000 ____D C:\Windows\ERUNT 2014-01-30 16:36 - 2013-10-22 15:37 - 00003100 _____ C:\Windows\System32\Tasks\P4G Sidebar 2014-01-30 16:36 - 2013-10-19 13:40 - 00013010 _____ C:\Windows\setupact.log 2014-01-30 16:36 - 2013-09-29 17:23 - 00003164 _____ C:\Windows\System32\Tasks\P4GIntlCtrl 2014-01-30 16:36 - 2012-06-06 14:38 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-30 16:36 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-30 16:34 - 2014-01-30 16:31 - 00000000 ____D C:\AdwCleaner 2014-01-30 16:34 - 2011-10-14 15:59 - 01258501 _____ C:\Windows\WindowsUpdate.log 2014-01-30 16:29 - 2013-10-19 13:40 - 00006570 _____ C:\Windows\PFRO.log 2014-01-30 16:25 - 2012-06-06 14:38 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-30 16:17 - 2014-01-30 16:17 - 00000736 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-30 16:17 - 2012-08-03 00:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-30 16:14 - 2013-10-18 10:39 - 00000000 ____D C:\ProgramData\MFAData 2014-01-30 16:14 - 2010-11-21 07:50 - 00699508 _____ C:\Windows\system32\perfh007.dat 2014-01-30 16:14 - 2010-11-21 07:50 - 00149660 _____ C:\Windows\system32\perfc007.dat 2014-01-30 16:14 - 2009-07-14 06:13 - 01620380 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-30 00:29 - 2012-07-18 05:21 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000UA.job 2014-01-29 22:17 - 2014-01-29 22:17 - 00000146 _____ C:\Users\Pauly\Desktop\Sound - Verknüpfung.lnk 2014-01-29 18:34 - 2014-01-29 18:25 - 00000000 ____D C:\ComboFix 2014-01-29 18:33 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-29 17:37 - 2014-01-29 17:23 - 00000000 ____D C:\Windows\erdnt 2014-01-29 17:32 - 2014-01-29 17:24 - 00000000 ____D C:\Qoobox 2014-01-28 23:56 - 2014-01-28 23:56 - 00000000 _____ C:\Users\Pauly\defogger_reenable 2014-01-28 23:56 - 2011-10-14 16:18 - 00000000 ____D C:\Users\Pauly 2014-01-28 23:55 - 2012-09-06 05:44 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2014-01-28 23:37 - 2014-01-28 23:37 - 00000879 _____ C:\Users\Pauly\Desktop\Spybot - Search & Destroy.lnk 2014-01-28 23:32 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2014-01-28 23:22 - 2014-01-28 23:22 - 00000000 ____D C:\Program Files\ATI Technologies 2014-01-28 23:21 - 2014-01-28 23:21 - 00054772 _____ C:\Windows\SysWOW64\CCCInstall_201401282321398833.log 2014-01-28 23:21 - 2013-09-27 20:34 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Spotify 2014-01-28 23:19 - 2012-06-11 18:01 - 03659264 _____ (ATI Technologies Inc. ) C:\Windows\system32\atidxx64.dll 2014-01-28 23:19 - 2009-11-18 14:21 - 06171136 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2014-01-28 23:19 - 2009-11-18 13:46 - 00446976 _____ (AMD) C:\Windows\system32\atieclxx.exe 2014-01-28 23:19 - 2009-11-18 13:46 - 00446464 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll 2014-01-28 23:19 - 2009-11-18 13:45 - 00202752 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2014-01-28 23:19 - 2009-11-18 13:44 - 00120320 _____ (AMD) C:\Windows\system32\atitmm64.dll 2014-01-28 23:19 - 2009-11-18 13:43 - 00059392 _____ (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll 2014-01-28 23:19 - 2009-11-18 13:43 - 00043520 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll 2014-01-28 23:19 - 2009-11-18 13:43 - 00012288 _____ (AMD) C:\Windows\system32\atimuixx.dll 2014-01-28 23:19 - 2009-11-18 13:40 - 03053056 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2014-01-28 23:19 - 2009-11-18 13:29 - 17559552 _____ (ATI Technologies Inc.) C:\Windows\system32\atio6axx.dll 2014-01-28 23:19 - 2009-11-18 13:24 - 03609600 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2014-01-28 23:19 - 2009-11-18 13:18 - 04675584 _____ (ATI Technologies Inc. ) C:\Windows\system32\atiumd64.dll 2014-01-28 23:19 - 2009-11-18 13:11 - 13422080 _____ (ATI Technologies Inc.) C:\Windows\SysWOW64\atioglxx.dll 2014-01-28 23:19 - 2009-11-18 13:11 - 02600960 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2014-01-28 23:19 - 2009-11-18 13:09 - 00402016 _____ C:\Windows\system32\atiumd6a.cap 2014-01-28 23:19 - 2009-11-18 13:05 - 02896384 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2014-01-28 23:19 - 2009-11-18 13:05 - 00402016 _____ C:\Windows\SysWOW64\atiumdva.cap 2014-01-28 23:19 - 2009-11-18 12:53 - 00053248 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2014-01-28 23:19 - 2009-11-18 12:53 - 00053248 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2014-01-28 23:19 - 2009-11-18 12:53 - 00052224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2014-01-28 23:19 - 2009-11-18 12:53 - 00052224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2014-01-28 23:19 - 2009-11-18 12:52 - 00311296 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2014-01-28 23:19 - 2009-11-18 12:52 - 00225280 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 04678144 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00053248 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00053248 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00043008 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00039936 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2014-01-28 23:19 - 2009-11-18 12:47 - 03579904 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2014-01-28 23:19 - 2009-11-18 12:37 - 00053248 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2014-01-28 23:19 - 2009-10-30 12:44 - 00019017 _____ C:\Windows\atiogl.xml 2014-01-28 23:19 - 2009-10-22 10:59 - 00196565 _____ C:\Windows\system32\atiicdxx.dat 2014-01-28 23:19 - 2009-02-18 13:55 - 00332288 _____ C:\Windows\system32\ATIODE.exe 2014-01-28 23:19 - 2009-02-03 16:52 - 00051200 _____ C:\Windows\system32\ATIODCLI.exe 2014-01-26 02:15 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Local\Battle.net 2014-01-25 14:46 - 2011-11-23 02:51 - 00000000 ____D C:\Windows\pss 2014-01-25 14:46 - 2011-10-14 16:19 - 00000000 ___RD C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-25 14:29 - 2012-07-18 05:21 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000Core.job 2014-01-25 12:03 - 2011-10-14 16:21 - 00109296 _____ C:\Users\Pauly\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-25 11:57 - 2013-12-28 02:29 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Dropbox 2014-01-25 11:55 - 2009-07-14 05:45 - 00413656 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-25 11:53 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2014-01-25 11:45 - 2012-07-20 01:29 - 01594660 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-25 11:42 - 2011-10-15 17:43 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Skype 2014-01-24 17:04 - 2013-09-27 20:35 - 00000000 ____D C:\Users\Pauly\AppData\Local\Spotify 2014-01-24 13:35 - 2011-10-14 16:48 - 00000000 ____D C:\Users\Pauly\AppData\Local\Adobe 2014-01-24 13:24 - 2012-08-03 00:54 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-01-24 13:24 - 2012-04-03 13:33 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-24 13:24 - 2011-10-14 16:55 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-19 08:39 - 2011-10-14 16:28 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-19 08:33 - 2013-07-19 17:40 - 00000000 ____D C:\Windows\system32\MRT 2014-01-19 08:29 - 2011-10-14 17:18 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-18 06:20 - 2011-10-15 16:24 - 00000000 ____D C:\Users\Pauly\AppData\Local\PMB Files 2014-01-18 06:20 - 2011-10-15 16:24 - 00000000 ____D C:\ProgramData\PMB Files 2014-01-17 18:55 - 2014-01-17 18:55 - 00000632 _____ C:\Users\Public\Desktop\osu!.lnk 2014-01-17 16:21 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-17 06:46 - 2013-12-28 02:32 - 00001014 _____ C:\Users\Pauly\Desktop\Dropbox.lnk 2014-01-17 06:46 - 2013-12-28 02:30 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-16 22:30 - 2014-01-16 22:30 - 00001230 _____ C:\Users\Pauly\Desktop\Calculator.lnk 2014-01-15 16:58 - 2014-01-15 16:58 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard 2014-01-15 16:41 - 2014-01-15 16:41 - 00000755 _____ C:\Users\Public\Desktop\Hearthstone.lnk 2014-01-15 16:41 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Battle.net 2014-01-15 16:39 - 2014-01-15 16:39 - 00000758 _____ C:\Users\Public\Desktop\Battle.net.lnk 2014-01-15 16:39 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard Entertainment 2014-01-14 16:34 - 2014-01-13 23:25 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-14 15:59 - 2014-01-14 15:59 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2014-01-14 15:59 - 2014-01-14 15:59 - 00000000 ____D C:\Users\Pauly\AppData\Local\PunkBuster 2014-01-14 15:59 - 2014-01-13 23:25 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-14 14:44 - 2014-01-14 14:44 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201401141444120183.log 2014-01-14 14:43 - 2014-01-14 14:43 - 00016738 _____ C:\Windows\SysWOW64\CCCInstall_201401141443071596.log 2014-01-14 14:41 - 2014-01-14 14:41 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2014-01-14 14:41 - 2014-01-13 23:26 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-14 14:25 - 2012-03-14 18:00 - 00000000 ____D C:\Windows\Minidump 2014-01-14 14:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2014-01-14 14:07 - 2011-10-15 11:31 - 00000000 ____D C:\ProgramData\P4G 2014-01-14 13:54 - 2014-01-14 13:54 - 00000000 ____D C:\Program Files\AMD 2014-01-14 13:42 - 2014-01-14 13:07 - 00000000 ____D C:\AMD 2014-01-14 00:36 - 2014-01-14 00:36 - 00000000 ____D C:\Windows\SysWOW64\directx 2014-01-13 23:25 - 2014-01-13 23:25 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-13 23:25 - 2014-01-08 00:30 - 00069590 _____ C:\Windows\DirectX.log 2014-01-13 23:22 - 2014-01-13 23:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-13 22:28 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst LIVE! 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\Users\Pauly\AppData\Local\WarThunder 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\ProgramData\WarThunder 2014-01-13 21:38 - 2012-07-17 04:07 - 00000000 ____D C:\Users\Pauly\Documents\My Games 2014-01-13 21:14 - 2014-01-13 21:14 - 00001168 _____ C:\Users\Pauly\Desktop\GamersFirst LIVE!.lnk 2014-01-13 21:14 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst 2014-01-09 21:24 - 2014-01-09 21:24 - 00000209 _____ C:\Users\Pauly\Desktop\Torchlight II.url 2014-01-08 01:10 - 2014-01-08 01:10 - 00000000 ____D C:\Users\Pauly\Documents\Sniper - Ghost Warrior 2014-01-07 21:59 - 2014-01-07 21:59 - 00000000 ____D C:\Users\Pauly\Documents\Urlaubsparadies Tycoon 2011 Some content of TEMP: ==================== C:\Users\Pauly\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-30 00:26 ==================== End Of Log ============================ --- --- --- --- --- --- |
31.01.2014, 09:25 | #7 |
/// the machine /// TB-Ausbilder | Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im SpielESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.01.2014, 17:22 | #8 |
| Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Onlinescan, scheinbar wieder was gefunden: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=7ded636b0628d148bccc62da14d2fec7 # engine=16880 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-31 03:32:28 # local_time=2014-01-31 04:32:28 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 9092757 142812198 0 0 # scanned=299185 # found=16 # cleaned=0 # scan_time=9241 sh=2E84F89E522777BF4C699D282C8E9BC615ADE352 ft=1 fh=1252f47403c8ae30 vn="Win32/AdWare.1ClickDownload.AQ application" ac=I fn="C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000000" sh=414EC2288BED4C2D457177B270910725CB316180 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2011-3544.DE trojan" ac=I fn="C:\Users\Pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\7c17f690-18405d56" sh=E5185E099E16324AB80A621B42A5C979B253A23A ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2011-3544.DE trojan" ac=I fn="C:\Users\Pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\e311594-3d7a1f21" sh=ADCE69196F393A856402B98AEBA631F755D1D86F ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2012-4681.CT trojan" ac=I fn="C:\Users\Pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\78706fd9-29459d3e" sh=ADCE69196F393A856402B98AEBA631F755D1D86F ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2012-4681.CT trojan" ac=I fn="C:\Users\Pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\78706fd9-3053b43b" sh=63F7FFDB99534D2C5DA628F68240CC1CE40558D9 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-2423.L trojan" ac=I fn="C:\Users\Pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\12d8aec3-40a75441" sh=63F7FFDB99534D2C5DA628F68240CC1CE40558D9 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-2423.L trojan" ac=I fn="C:\Users\Pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\12d8aec3-69f4ca26" sh=C9BE7ACD12DC1A978C253D1267D4D19D9283DDBC ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-2423.L trojan" ac=I fn="C:\Users\Pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\49d3eca4-20a3a060" sh=C9BE7ACD12DC1A978C253D1267D4D19D9283DDBC ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-2423.L trojan" ac=I fn="C:\Users\Pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\49d3eca4-48f7e049" sh=CF7734ED47E21AC32C298D941B63164DF5309E57 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2012-4681.CU trojan" ac=I fn="C:\Users\Pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\4ece4eaa-1eba1c81" sh=CF7734ED47E21AC32C298D941B63164DF5309E57 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2012-4681.CU trojan" ac=I fn="C:\Users\Pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\4ece4eaa-3899e4e4" sh=F8F35DF25726B45EFAC5B0BC1B2EFCB3940C2DD5 ft=0 fh=0000000000000000 vn="Win32/Fynloski.AA trojan" ac=I fn="D:\Programme\Fraps\3.5.9.rar" sh=FAB6C74021793ABFFB76BAF3683D82C9A82039A4 ft=1 fh=3ca65237bb9bf27f vn="Win32/Fynloski.AA trojan" ac=I fn="E:\backup pauly\AppData\Local\Temp\48C6.tmp\crack.exe" sh=37EFB7467DE14EA0E6C608ED68E30EB2E7A23C9B ft=1 fh=b5267f5d42b67b3b vn="Win32/Webprefix.B trojan" ac=I fn="E:\backup pauly\AppData\Local\Temp\InstallShare7698\gutscheinfilter_q.exe" sh=CFCB3363C8800DD290F4AD94D5685C514C57CF58 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.NEO trojan" ac=I fn="E:\backup pauly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\5fef98f5-23e8146a" sh=FAB6C74021793ABFFB76BAF3683D82C9A82039A4 ft=1 fh=3ca65237bb9bf27f vn="Win32/Fynloski.AA trojan" ac=I fn="E:\backup pauly\AppData\Roaming\Microsoft\twunk_16.exe" Security Checklog: Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` AVG AntiVirus Free Edition 2014 Antivirus out of date! `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy Malwarebytes Anti-Malware Version 1.75.0.1300 Java(TM) 6 Update 27 Java 7 Update 45 Java version out of Date! Adobe Flash Player 12.0.0.43 Flash Player out of Date! Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox 15.0.1 Firefox out of Date! Google Chrome 32.0.1700.102 Google Chrome 32.0.1700.76 ````````Process Check: objlist.exe by Laurent```````` AVG avgwdsvc.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Mozilla benutze ich eig. gar nicht mehr und AVG hab ich direkt nochmal geupdatet, obwohl das heute schon einmal der Fall war. Neuer FRST-Log: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01 Ran by Pauly (administrator) on ADIOZ on 31-01-2014 17:30:48 Running from C:\Users\Pauly\Desktop\Scan Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgwdsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ATK) C:\Program Files\P4G\BatteryLife.exe () C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ASUSTek Computer Inc.) C:\Programme (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ASUSTek Computer Inc.) C:\Programme (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgui.exe () E:\LoL\League of Legends\RADS\system\rads_user_kernel.exe () E:\LoL\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.198\deploy\LoLLauncher.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgemca.exe (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) D:\Programme\AVG2014\avgcsrva.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [621440 2009-09-30] (ELAN Microelectronic Corp.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9642528 2009-12-03] (Realtek Semiconductor) HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-10-21] (NEC Electronics Corporation) HKLM-x32\...\Run: [ATKOSD2] - C:\Programme (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-06-25] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ATKMEDIA] - C:\Programme (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-06-19] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x61B88996D817CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ URLSearchHook: HKCU - (No Name) - {f0381dbd-e018-4e07-ae40-d96ab15083f0} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {012AF763-C60F-4CB9-8E4F-F45951BFAB17} URL = hxxp://www.google.de/search?q={searchTerms} BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - D:\Programme\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH) Toolbar: HKCU - No Name - {F0381DBD-E018-4E07-AE40-D96AB15083F0} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - d:\Programme\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Programme\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - d:\Programme\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 - d:\Programme\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - d:\Programme\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin-x32: @videolan.org/vlc,version=2.0.4 - d:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - d:\Programme\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Pauly\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Pauly\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Pauly\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Ghostery - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\firefox@ghostery.com [2013-11-02] FF Extension: WOT - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-02] FF Extension: Swift Browse - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\firefox@swiftbrowse.net.xpi [2013-10-18] FF Extension: WEB.DE MailCheck - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\toolbar@web.de.xpi [2011-12-19] FF Extension: Adblock Plus - C:\Users\Pauly\AppData\Roaming\Mozilla\Firefox\Profiles\y6ebfp5y.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-11-04] Chrome: ======= CHR HomePage: hxxp://search.ominent.com/ws/?source=9f1d0980&tbp=homepage&toolbarid=base&u=cc40d42800000000000072f06d3396e4 CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.102\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.102\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\32.0.1700.102\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.270.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U27) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Microsoft Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Pauly\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (iTunes Application Detector) - D:\Programme\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Veetle TV Player) - d:\Programme\Veetle\Player\npvlc.dll (Veetle Inc) CHR Plugin: (Veetle TV Core) - d:\Programme\Veetle\plugins\npVeetle.dll (Veetle Inc) CHR Extension: (YouTube Options) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdokagampppgbnjfdlkfpphniapiiifn [2013-10-18] CHR Extension: (YouTube) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-18] CHR Extension: (Adblock Plus) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2012-07-18] CHR Extension: (Google-Suche) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-18] CHR Extension: (Grooveshark Germany unlocker) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac [2013-05-19] CHR Extension: (Hola Besseres Internet) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2013-10-18] CHR Extension: (WEB.DE MailCheck) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo [2013-12-26] CHR Extension: (Google Wallet) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (YouTube Unblocker) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [2013-12-10] CHR Extension: (Google Mail) - C:\Users\Pauly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-18] CHR StartMenuInternet: Google Chrome - C:\Users\Pauly\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= S4 ASLDRService; C:\Programme (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [80512 2011-11-21] (ASUS) R2 AVGIDSAgent; D:\Programme\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; D:\Programme\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) S4 HiPatchService; D:\Spiele\Smite\HiPatchService.exe [8704 2012-07-12] (Hi-Rez Studios) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-01-13] () S4 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () S4 TGCM_ImportWiFiSvc; D:\o2\Mobile Connection Manager\ImpWiFiSvc.exe [200624 2010-09-29] (Telefónica I+D) ==================== Drivers (Whitelisted) ==================== S3 AF9035BDA; C:\Windows\System32\DRIVERS\AF15BDA.sys [513600 2009-11-05] (ITETech ) S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2012-03-07] (Google Inc) S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2012-03-06] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2012-03-06] (LG Electronics Inc.) R2 ASMMAP64; C:\Programme (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [15416 2009-07-02] (ASUS) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S3 LADF_BakerCOnly; C:\Windows\System32\DRIVERS\ladfBakerCamd64.sys [410184 2011-03-18] (Logitech) S3 LADF_BakerROnly; C:\Windows\System32\DRIVERS\ladfBakerRamd64.sys [335688 2011-03-18] (Logitech) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () S3 ALSysIO; \??\C:\Users\Pauly\AppData\Local\Temp\ALSysIO64.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 GPU-Z; \??\C:\Users\Pauly\AppData\Local\Temp\GPU-Z.sys [x] S3 ipswuio; System32\DRIVERS\ipswuio.sys [x] S3 massfilter; system32\drivers\massfilter.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-31 14:27 - 2014-01-31 14:27 - 00001119 _____ C:\Users\Pauly\Desktop\ElophantClient.exe - Verknüpfung.lnk 2014-01-31 13:57 - 2014-01-31 13:57 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-30 16:47 - 2014-01-30 16:47 - 00001564 _____ C:\Users\Pauly\Desktop\JRT.txt 2014-01-30 16:39 - 2014-01-30 16:39 - 00000000 ____D C:\Windows\ERUNT 2014-01-30 16:31 - 2014-01-30 16:34 - 00000000 ____D C:\AdwCleaner 2014-01-30 16:17 - 2014-01-30 16:17 - 00000736 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-30 16:17 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-29 22:17 - 2014-01-29 22:17 - 00000146 _____ C:\Users\Pauly\Desktop\Sound - Verknüpfung.lnk 2014-01-29 18:25 - 2014-01-29 18:34 - 00000000 ____D C:\ComboFix 2014-01-29 17:25 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-29 17:25 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-29 17:25 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-29 17:25 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-29 17:25 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-29 17:25 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-29 17:25 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-29 17:25 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-29 17:24 - 2014-01-29 17:32 - 00000000 ____D C:\Qoobox 2014-01-29 17:23 - 2014-01-29 17:37 - 00000000 ____D C:\Windows\erdnt 2014-01-28 23:56 - 2014-01-31 17:30 - 00000000 ____D C:\FRST 2014-01-28 23:56 - 2014-01-28 23:56 - 00000000 _____ C:\Users\Pauly\defogger_reenable 2014-01-28 23:53 - 2014-01-31 17:30 - 00000000 ____D C:\Users\Pauly\Desktop\Scan 2014-01-28 23:37 - 2014-01-28 23:37 - 00000879 _____ C:\Users\Pauly\Desktop\Spybot - Search & Destroy.lnk 2014-01-28 23:22 - 2014-01-28 23:22 - 00000000 ____D C:\Program Files\ATI Technologies 2014-01-28 23:21 - 2014-01-28 23:21 - 00054772 _____ C:\Windows\SysWOW64\CCCInstall_201401282321398833.log 2014-01-25 11:49 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-01-25 11:49 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-01-25 11:49 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-01-25 11:49 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-01-25 11:39 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-01-25 11:39 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-01-25 11:39 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2014-01-25 11:39 - 2012-08-23 15:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-01-25 11:39 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-01-25 11:39 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-01-25 11:39 - 2012-08-23 14:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-01-25 11:39 - 2012-08-23 14:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-01-25 11:39 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-01-25 11:39 - 2012-08-23 14:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-01-25 11:39 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-01-25 11:39 - 2012-08-23 14:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-01-25 11:39 - 2012-08-23 14:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-01-25 11:39 - 2012-08-23 13:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-01-25 11:39 - 2012-08-23 12:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-01-25 11:39 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2014-01-25 11:39 - 2012-08-23 12:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-01-25 11:39 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2014-01-25 11:39 - 2012-08-23 11:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-01-25 11:39 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-01-25 11:39 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-01-25 11:39 - 2012-08-23 11:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-01-25 11:39 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-01-25 11:39 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-01-25 11:39 - 2012-08-23 09:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2014-01-25 11:31 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2014-01-25 11:31 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2014-01-25 11:31 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2014-01-25 11:31 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2014-01-25 11:31 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2014-01-25 11:23 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-01-25 11:23 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-01-25 11:23 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2014-01-25 11:23 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-01-25 11:23 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2014-01-25 11:23 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-01-25 11:23 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-01-25 11:23 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-01-25 11:23 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2014-01-25 11:23 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-01-25 11:23 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2014-01-25 11:23 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-01-25 11:23 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-01-25 11:23 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-01-25 11:23 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-01-25 11:23 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2014-01-25 11:23 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2014-01-25 11:23 - 2012-11-30 06:45 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-01-25 11:23 - 2012-11-30 06:45 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-01-25 11:23 - 2012-11-30 06:43 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-01-25 11:23 - 2012-11-30 00:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2014-01-25 11:23 - 2012-11-30 00:15 - 00420064 _____ C:\Windows\system32\locale.nls 2014-01-25 11:23 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2014-01-25 11:23 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2014-01-25 11:23 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2014-01-25 11:23 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2014-01-25 11:23 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2014-01-25 11:23 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2014-01-25 11:23 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-01-25 11:23 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2014-01-25 11:23 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2014-01-25 11:22 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-25 11:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-01-25 11:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-01-25 11:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-01-25 11:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-01-25 11:22 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2014-01-25 11:22 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2014-01-25 11:22 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-01-25 11:22 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2014-01-25 11:22 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-01-25 11:22 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2014-01-25 11:22 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-01-25 11:22 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2014-01-25 11:22 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2014-01-25 11:22 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2014-01-25 11:22 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2014-01-25 11:22 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2014-01-25 11:22 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2014-01-25 11:22 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2014-01-25 11:22 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2014-01-25 11:22 - 2013-04-17 08:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-01-25 11:22 - 2013-04-17 07:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-01-25 11:22 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-01-25 11:22 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2014-01-25 11:22 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2014-01-25 11:22 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2014-01-25 11:22 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2014-01-25 11:22 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2014-01-25 11:22 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2014-01-25 11:22 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2014-01-25 11:22 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2014-01-25 11:22 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2014-01-25 11:22 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2014-01-25 11:22 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2014-01-25 11:22 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2014-01-25 11:22 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2014-01-25 11:22 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2014-01-25 11:22 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2014-01-25 11:22 - 2012-07-06 21:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2014-01-25 11:22 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2014-01-25 11:22 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2014-01-25 11:22 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2014-01-25 11:21 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2014-01-25 11:21 - 2012-11-22 06:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-01-25 11:21 - 2012-11-22 05:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-01-19 08:28 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-19 08:28 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-19 08:28 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-17 18:55 - 2014-01-17 18:55 - 00000632 _____ C:\Users\Public\Desktop\osu!.lnk 2014-01-16 22:30 - 2014-01-16 22:30 - 00001230 _____ C:\Users\Pauly\Desktop\Calculator.lnk 2014-01-15 16:58 - 2014-01-15 16:58 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard 2014-01-15 16:41 - 2014-01-15 16:41 - 00000755 _____ C:\Users\Public\Desktop\Hearthstone.lnk 2014-01-15 16:39 - 2014-01-26 02:15 - 00000000 ____D C:\Users\Pauly\AppData\Local\Battle.net 2014-01-15 16:39 - 2014-01-15 16:41 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Battle.net 2014-01-15 16:39 - 2014-01-15 16:39 - 00000758 _____ C:\Users\Public\Desktop\Battle.net.lnk 2014-01-15 16:39 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard Entertainment 2014-01-14 15:59 - 2014-01-14 15:59 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2014-01-14 15:59 - 2014-01-14 15:59 - 00000000 ____D C:\Users\Pauly\AppData\Local\PunkBuster 2014-01-14 14:44 - 2014-01-14 14:44 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201401141444120183.log 2014-01-14 14:43 - 2014-01-14 14:43 - 00016738 _____ C:\Windows\SysWOW64\CCCInstall_201401141443071596.log 2014-01-14 14:41 - 2014-01-14 14:41 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2014-01-14 13:54 - 2014-01-14 13:54 - 00000000 ____D C:\Program Files\AMD 2014-01-14 13:07 - 2014-01-14 13:42 - 00000000 ____D C:\AMD 2014-01-14 00:36 - 2014-01-14 00:36 - 00000000 ____D C:\Windows\SysWOW64\directx 2014-01-13 23:26 - 2014-01-14 14:41 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-13 23:25 - 2014-01-14 16:34 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-13 23:25 - 2014-01-14 15:59 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-13 23:25 - 2014-01-13 23:25 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-13 23:22 - 2014-01-13 23:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\Users\Pauly\AppData\Local\WarThunder 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\ProgramData\WarThunder 2014-01-13 21:14 - 2014-01-28 23:32 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2014-01-13 21:14 - 2014-01-13 22:28 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst LIVE! 2014-01-13 21:14 - 2014-01-13 21:14 - 00001168 _____ C:\Users\Pauly\Desktop\GamersFirst LIVE!.lnk 2014-01-13 21:14 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst 2014-01-09 21:26 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-01-09 21:26 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-01-09 21:26 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-01-09 21:24 - 2014-01-09 21:24 - 00000209 _____ C:\Users\Pauly\Desktop\Torchlight II.url 2014-01-08 01:10 - 2014-01-08 01:10 - 00000000 ____D C:\Users\Pauly\Documents\Sniper - Ghost Warrior 2014-01-08 00:31 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-01-08 00:31 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-01-08 00:31 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-01-08 00:31 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-01-08 00:31 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-01-08 00:31 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-01-08 00:31 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-01-08 00:31 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-01-08 00:31 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2014-01-08 00:31 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-01-08 00:31 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2014-01-08 00:31 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-01-08 00:31 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-01-08 00:31 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-01-08 00:31 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-01-08 00:31 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-01-08 00:31 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-01-08 00:31 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-01-08 00:31 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-01-08 00:31 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-01-08 00:31 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-01-08 00:31 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-01-08 00:31 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-01-08 00:31 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-01-08 00:31 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-01-08 00:31 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-01-08 00:31 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-01-08 00:31 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-01-08 00:31 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-01-08 00:31 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-01-08 00:31 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-01-08 00:31 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-01-08 00:31 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-01-08 00:31 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-01-08 00:31 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-01-08 00:31 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-01-08 00:31 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-01-08 00:31 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-01-08 00:31 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-01-08 00:31 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-01-08 00:31 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-01-08 00:31 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-01-08 00:31 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-01-08 00:31 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-01-08 00:31 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-01-08 00:31 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-01-08 00:31 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-01-08 00:31 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-01-08 00:31 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-01-08 00:31 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-01-08 00:31 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-01-08 00:31 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-01-08 00:31 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-01-08 00:31 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-01-08 00:31 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-01-08 00:31 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-01-08 00:31 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-01-08 00:31 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-01-08 00:31 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-01-08 00:31 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-01-08 00:31 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-01-08 00:31 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-01-08 00:31 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-01-08 00:31 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-01-08 00:31 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-01-08 00:30 - 2014-01-13 23:25 - 00069590 _____ C:\Windows\DirectX.log 2014-01-07 21:59 - 2014-01-07 21:59 - 00000000 ____D C:\Users\Pauly\Documents\Urlaubsparadies Tycoon 2011 ==================== One Month Modified Files and Folders ======= 2014-01-31 17:30 - 2014-01-28 23:56 - 00000000 ____D C:\FRST 2014-01-31 17:30 - 2014-01-28 23:53 - 00000000 ____D C:\Users\Pauly\Desktop\Scan 2014-01-31 17:29 - 2013-10-18 10:39 - 00000000 ____D C:\ProgramData\MFAData 2014-01-31 17:29 - 2012-07-18 05:21 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000UA.job 2014-01-31 17:25 - 2012-06-06 14:38 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-31 17:23 - 2011-10-14 15:59 - 01278083 _____ C:\Windows\WindowsUpdate.log 2014-01-31 17:17 - 2012-08-03 00:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-31 14:29 - 2012-07-18 05:21 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499407621-459809178-2675428275-1000Core.job 2014-01-31 14:27 - 2014-01-31 14:27 - 00001119 _____ C:\Users\Pauly\Desktop\ElophantClient.exe - Verknüpfung.lnk 2014-01-31 13:57 - 2014-01-31 13:57 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-31 13:56 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-31 13:56 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-31 13:49 - 2013-10-22 15:37 - 00003100 _____ C:\Windows\System32\Tasks\P4G Sidebar 2014-01-31 13:49 - 2013-10-19 13:40 - 00013122 _____ C:\Windows\setupact.log 2014-01-31 13:49 - 2013-09-29 17:23 - 00003164 _____ C:\Windows\System32\Tasks\P4GIntlCtrl 2014-01-31 13:49 - 2012-06-06 14:38 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-31 13:49 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-31 00:48 - 2013-09-27 20:34 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Spotify 2014-01-30 22:03 - 2011-10-15 16:24 - 00000000 ____D C:\Users\Pauly\AppData\Local\PMB Files 2014-01-30 22:03 - 2011-10-15 16:24 - 00000000 ____D C:\ProgramData\PMB Files 2014-01-30 20:02 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2014-01-30 16:47 - 2014-01-30 16:47 - 00001564 _____ C:\Users\Pauly\Desktop\JRT.txt 2014-01-30 16:39 - 2014-01-30 16:39 - 00000000 ____D C:\Windows\ERUNT 2014-01-30 16:34 - 2014-01-30 16:31 - 00000000 ____D C:\AdwCleaner 2014-01-30 16:29 - 2013-10-19 13:40 - 00006570 _____ C:\Windows\PFRO.log 2014-01-30 16:17 - 2014-01-30 16:17 - 00000736 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-30 16:14 - 2010-11-21 07:50 - 00699508 _____ C:\Windows\system32\perfh007.dat 2014-01-30 16:14 - 2010-11-21 07:50 - 00149660 _____ C:\Windows\system32\perfc007.dat 2014-01-30 16:14 - 2009-07-14 06:13 - 01620380 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-29 22:17 - 2014-01-29 22:17 - 00000146 _____ C:\Users\Pauly\Desktop\Sound - Verknüpfung.lnk 2014-01-29 18:34 - 2014-01-29 18:25 - 00000000 ____D C:\ComboFix 2014-01-29 18:33 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-29 17:37 - 2014-01-29 17:23 - 00000000 ____D C:\Windows\erdnt 2014-01-29 17:32 - 2014-01-29 17:24 - 00000000 ____D C:\Qoobox 2014-01-28 23:56 - 2014-01-28 23:56 - 00000000 _____ C:\Users\Pauly\defogger_reenable 2014-01-28 23:56 - 2011-10-14 16:18 - 00000000 ____D C:\Users\Pauly 2014-01-28 23:55 - 2012-09-06 05:44 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2014-01-28 23:37 - 2014-01-28 23:37 - 00000879 _____ C:\Users\Pauly\Desktop\Spybot - Search & Destroy.lnk 2014-01-28 23:32 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2014-01-28 23:22 - 2014-01-28 23:22 - 00000000 ____D C:\Program Files\ATI Technologies 2014-01-28 23:21 - 2014-01-28 23:21 - 00054772 _____ C:\Windows\SysWOW64\CCCInstall_201401282321398833.log 2014-01-28 23:19 - 2012-06-11 18:01 - 03659264 _____ (ATI Technologies Inc. ) C:\Windows\system32\atidxx64.dll 2014-01-28 23:19 - 2009-11-18 14:21 - 06171136 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2014-01-28 23:19 - 2009-11-18 13:46 - 00446976 _____ (AMD) C:\Windows\system32\atieclxx.exe 2014-01-28 23:19 - 2009-11-18 13:46 - 00446464 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll 2014-01-28 23:19 - 2009-11-18 13:45 - 00202752 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2014-01-28 23:19 - 2009-11-18 13:44 - 00120320 _____ (AMD) C:\Windows\system32\atitmm64.dll 2014-01-28 23:19 - 2009-11-18 13:43 - 00059392 _____ (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll 2014-01-28 23:19 - 2009-11-18 13:43 - 00043520 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll 2014-01-28 23:19 - 2009-11-18 13:43 - 00012288 _____ (AMD) C:\Windows\system32\atimuixx.dll 2014-01-28 23:19 - 2009-11-18 13:40 - 03053056 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2014-01-28 23:19 - 2009-11-18 13:29 - 17559552 _____ (ATI Technologies Inc.) C:\Windows\system32\atio6axx.dll 2014-01-28 23:19 - 2009-11-18 13:24 - 03609600 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2014-01-28 23:19 - 2009-11-18 13:18 - 04675584 _____ (ATI Technologies Inc. ) C:\Windows\system32\atiumd64.dll 2014-01-28 23:19 - 2009-11-18 13:11 - 13422080 _____ (ATI Technologies Inc.) C:\Windows\SysWOW64\atioglxx.dll 2014-01-28 23:19 - 2009-11-18 13:11 - 02600960 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2014-01-28 23:19 - 2009-11-18 13:09 - 00402016 _____ C:\Windows\system32\atiumd6a.cap 2014-01-28 23:19 - 2009-11-18 13:05 - 02896384 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2014-01-28 23:19 - 2009-11-18 13:05 - 00402016 _____ C:\Windows\SysWOW64\atiumdva.cap 2014-01-28 23:19 - 2009-11-18 12:53 - 00053248 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2014-01-28 23:19 - 2009-11-18 12:53 - 00053248 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2014-01-28 23:19 - 2009-11-18 12:53 - 00052224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2014-01-28 23:19 - 2009-11-18 12:53 - 00052224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2014-01-28 23:19 - 2009-11-18 12:52 - 00311296 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2014-01-28 23:19 - 2009-11-18 12:52 - 00225280 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 04678144 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00053248 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00053248 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00043008 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2014-01-28 23:19 - 2009-11-18 12:48 - 00039936 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2014-01-28 23:19 - 2009-11-18 12:47 - 03579904 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2014-01-28 23:19 - 2009-11-18 12:37 - 00053248 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2014-01-28 23:19 - 2009-10-30 12:44 - 00019017 _____ C:\Windows\atiogl.xml 2014-01-28 23:19 - 2009-10-22 10:59 - 00196565 _____ C:\Windows\system32\atiicdxx.dat 2014-01-28 23:19 - 2009-02-18 13:55 - 00332288 _____ C:\Windows\system32\ATIODE.exe 2014-01-28 23:19 - 2009-02-03 16:52 - 00051200 _____ C:\Windows\system32\ATIODCLI.exe 2014-01-26 02:15 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Local\Battle.net 2014-01-25 14:46 - 2011-11-23 02:51 - 00000000 ____D C:\Windows\pss 2014-01-25 14:46 - 2011-10-14 16:19 - 00000000 ___RD C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-25 12:03 - 2011-10-14 16:21 - 00109296 _____ C:\Users\Pauly\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-25 11:57 - 2013-12-28 02:29 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Dropbox 2014-01-25 11:55 - 2009-07-14 05:45 - 00413656 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-25 11:53 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2014-01-25 11:45 - 2012-07-20 01:29 - 01594660 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-25 11:42 - 2011-10-15 17:43 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Skype 2014-01-24 17:04 - 2013-09-27 20:35 - 00000000 ____D C:\Users\Pauly\AppData\Local\Spotify 2014-01-24 13:35 - 2011-10-14 16:48 - 00000000 ____D C:\Users\Pauly\AppData\Local\Adobe 2014-01-24 13:24 - 2012-08-03 00:54 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-01-24 13:24 - 2012-04-03 13:33 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-24 13:24 - 2011-10-14 16:55 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-19 08:39 - 2011-10-14 16:28 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-19 08:33 - 2013-07-19 17:40 - 00000000 ____D C:\Windows\system32\MRT 2014-01-19 08:29 - 2011-10-14 17:18 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-17 18:55 - 2014-01-17 18:55 - 00000632 _____ C:\Users\Public\Desktop\osu!.lnk 2014-01-17 16:21 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-17 06:46 - 2013-12-28 02:32 - 00001014 _____ C:\Users\Pauly\Desktop\Dropbox.lnk 2014-01-17 06:46 - 2013-12-28 02:30 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-16 22:30 - 2014-01-16 22:30 - 00001230 _____ C:\Users\Pauly\Desktop\Calculator.lnk 2014-01-15 16:58 - 2014-01-15 16:58 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard 2014-01-15 16:41 - 2014-01-15 16:41 - 00000755 _____ C:\Users\Public\Desktop\Hearthstone.lnk 2014-01-15 16:41 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Roaming\Battle.net 2014-01-15 16:39 - 2014-01-15 16:39 - 00000758 _____ C:\Users\Public\Desktop\Battle.net.lnk 2014-01-15 16:39 - 2014-01-15 16:39 - 00000000 ____D C:\Users\Pauly\AppData\Local\Blizzard Entertainment 2014-01-14 16:34 - 2014-01-13 23:25 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-14 15:59 - 2014-01-14 15:59 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2014-01-14 15:59 - 2014-01-14 15:59 - 00000000 ____D C:\Users\Pauly\AppData\Local\PunkBuster 2014-01-14 15:59 - 2014-01-13 23:25 - 00290776 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-14 14:44 - 2014-01-14 14:44 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201401141444120183.log 2014-01-14 14:43 - 2014-01-14 14:43 - 00016738 _____ C:\Windows\SysWOW64\CCCInstall_201401141443071596.log 2014-01-14 14:41 - 2014-01-14 14:41 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2014-01-14 14:41 - 2014-01-13 23:26 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-14 14:25 - 2012-03-14 18:00 - 00000000 ____D C:\Windows\Minidump 2014-01-14 14:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2014-01-14 14:07 - 2011-10-15 11:31 - 00000000 ____D C:\ProgramData\P4G 2014-01-14 13:54 - 2014-01-14 13:54 - 00000000 ____D C:\Program Files\AMD 2014-01-14 13:42 - 2014-01-14 13:07 - 00000000 ____D C:\AMD 2014-01-14 00:36 - 2014-01-14 00:36 - 00000000 ____D C:\Windows\SysWOW64\directx 2014-01-13 23:25 - 2014-01-13 23:25 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-13 23:25 - 2014-01-08 00:30 - 00069590 _____ C:\Windows\DirectX.log 2014-01-13 23:22 - 2014-01-13 23:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-13 22:28 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst LIVE! 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\Users\Pauly\AppData\Local\WarThunder 2014-01-13 21:38 - 2014-01-13 21:38 - 00000000 ____D C:\ProgramData\WarThunder 2014-01-13 21:38 - 2012-07-17 04:07 - 00000000 ____D C:\Users\Pauly\Documents\My Games 2014-01-13 21:14 - 2014-01-13 21:14 - 00001168 _____ C:\Users\Pauly\Desktop\GamersFirst LIVE!.lnk 2014-01-13 21:14 - 2014-01-13 21:14 - 00000000 ____D C:\Users\Pauly\AppData\Local\GamersFirst 2014-01-09 21:24 - 2014-01-09 21:24 - 00000209 _____ C:\Users\Pauly\Desktop\Torchlight II.url 2014-01-08 01:10 - 2014-01-08 01:10 - 00000000 ____D C:\Users\Pauly\Documents\Sniper - Ghost Warrior 2014-01-07 21:59 - 2014-01-07 21:59 - 00000000 ____D C:\Users\Pauly\Documents\Urlaubsparadies Tycoon 2011 Some content of TEMP: ==================== C:\Users\Pauly\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-30 00:26 ==================== End Of Log ============================ Geändert von adioz (31.01.2014 um 17:33 Uhr) |
01.02.2014, 11:26 | #9 |
/// the machine /// TB-Ausbilder | Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Java, Flash und ADobe updaten. Backup auf E löschen. Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Chrome komplett deinstallieren, keine Daten behalten, neu installieren. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.02.2014, 17:59 | #10 |
| Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Alles wieder in Ordnung! Tausend Dank dafür, war schon kurz davor win7 neu zu installieren. =) Echt ein SUPER Service, weiter so... Klasse Sache dieses Forum. |
03.02.2014, 16:17 | #11 |
/// the machine /// TB-Ausbilder | Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Fertig Falls Du Lob oder Kritik loswerden möchtest kannst Du das hier tun Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.02.2014, 13:42 | #12 |
| Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Hallo, entschuldige die "leichte" Verzögerung. Hab jetzt alles gemacht und sieht soweit auch gut aus. Kannst du mir generell auch Hilfestellung für andere Programme geben, welche nicht funktionieren? Besitze beispielsweise von Logitech das G930 Headset, allerdings lässt sich die dazugehörige Software zwar installieren, aber sie startet einfach nicht, mehrere Versionen und Neuinstallationen probiert. |
08.02.2014, 11:24 | #13 |
/// the machine /// TB-Ausbilder | Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Kommt ne Fehlermeldung wenn Du starten willst?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.02.2014, 14:15 | #14 |
| Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Leider nicht, es passiert einfach gar nichts. Ist jetzt auch nicht unbedingt wichtig, aber hätte ja sein können, dass es da ne bekannte Lösung für gibt oder etwas, was nicht allzu aufwändig ist |
09.02.2014, 09:05 | #15 |
/// the machine /// TB-Ausbilder | Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel Keinen Schimmer, sorry
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7 - PC in letzter Zeit langsam geworden, FPS-Einbrüche im Spiel |
abgesicherten, acrobat update, adblock, alte treiber, avg antivirus, hotspot, java/exploit.agent.neo, java/exploit.cve-2011-3544.de, java/exploit.cve-2012-4681.ct, java/exploit.cve-2012-4681.cu, java/exploit.cve-2013-2423.l, langsam, modus, msiinstaller, pup.optional.crossrider.a, pup.optional.crossrider.m, pup.optional.ominent.a, pup.optional.opencandy, pup.optional.swiftbrowse.a, pup.optional.wedownload.a, required, rückgängig, safer networking, spiele, spielen, tracker, trojaner, win32/adware.1clickdownload.aq, win32/fynloski.aa, win32/webprefix.b, windows, windows 7 |