|
Plagegeister aller Art und deren Bekämpfung: Browser Startet nicht, sowie jegliche Antiviren Programme, Downloadgeschwindigkeit sehr geringWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
02.06.2014, 15:28 | #16 |
| Browser Startet nicht, sowie jegliche Antiviren Programme, Downloadgeschwindigkeit sehr gering Liebes Trojaner-Board Team! Hier die Ergebnisse der Log File von: HitmanPro: Code:
ATTFilter HitmanPro 3.7.9.216 www.hitmanpro.com Computer name . . . . : LUKAS-PC Windows . . . . . . . : 6.1.1.7601.X86/2 User name . . . . . . : Lukas-PC\Timmy UAC . . . . . . . . . : Enabled License . . . . . . . : Trial (30 days left) Scan date . . . . . . : 2014-06-02 16:15:34 Scan mode . . . . . . : Normal Scan duration . . . . : 4m 27s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : Yes Threats . . . . . . . : 5 Traces . . . . . . . : 30 Objects scanned . . . : 1.054.050 Files scanned . . . . : 36.595 Remnants scanned . . : 431.726 files / 585.729 keys Malware _____________________________________________________________________ C:\Program Files\Sirius MT2\# Sirius MT2.exe -> Deleted Size . . . . . . . : 1.954.816 bytes Age . . . . . . . : 42.0 days (2014-04-21 17:16:01) Entropy . . . . . : 7.9 SHA-256 . . . . . : 6F92CC23C24CF09DF8B44E9BDC36652409B20E8531EACE3590D2B30BC48DA3EC Needs elevation . : Yes Product . . . . . : SiriusPatcher Publisher . . . . : SiriusMT2 Description . . . : SiriusPatcher Version . . . . . : 1.0.0.1 Copyright . . . . : Copyright ©SiriusMT2 2012 > Bitdefender . . . : Trojan.Generic.11262803 Fuzzy . . . . . . : 108.0 References C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sirius MT2\Sirius MT2.lnk C:\Users\Timmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Sirius MT2.lnk C:\Users\Timmy\Desktop\Sirius MT2.lnk C:\Program Files\Sirius MT2\neuer_patcher -> Deleted Size . . . . . . . : 1.954.816 bytes Age . . . . . . . : 42.0 days (2014-04-21 17:16:01) Entropy . . . . . : 7.9 SHA-256 . . . . . : 6F92CC23C24CF09DF8B44E9BDC36652409B20E8531EACE3590D2B30BC48DA3EC Needs elevation . : Yes Product . . . . . : SiriusPatcher Publisher . . . . : SiriusMT2 Description . . . : SiriusPatcher Version . . . . . : 1.0.0.1 Copyright . . . . : Copyright ©SiriusMT2 2012 > Bitdefender . . . : Trojan.Generic.11262803 Fuzzy . . . . . . : 118.0 C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Custom.dll -> Deleted Size . . . . . . . : 93.696 bytes Age . . . . . . . : 1.7 days (2014-05-31 22:15:49) Entropy . . . . . : 6.3 SHA-256 . . . . . : 1BF33578F57D6436E916CC0734E8ADC66A0E3C7CA5DE1290601A73E3E362419D Product . . . . . : SuperbApp Publisher . . . . : SuperbApp Description . . . : Custom DLL for SuperbApp Version . . . . . : 2014.4. Copyright . . . . : Copyright © 2014 S > Kaspersky . . . . : Trojan.Win32.AntiFW.b Fuzzy . . . . . . : 102.0 Forensic Cluster -0.7s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{18EFC9FE-4235-A3E5-8EA1-D0F446646227}\ -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{18EFC9FE-4235-A3E5-8EA1-D0F446646227}\YoutubeAdblocker.2.7.dat -0.6s C:\zoek_backup\restore.txt -0.6s C:\zoek_backup\restore.txt -0.6s C:\zoek_backup\restore.txt -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{1CF67973-C380-3115-A8A6-BA4C958673E1}\ -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{1CF67973-C380-3115-A8A6-BA4C958673E1}\YoutubeAdblocker.2.7.dat -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{396E5F17-26E2-2AEC-C244-7C5E0A47D098}\ -0.5s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{396E5F17-26E2-2AEC-C244-7C5E0A47D098}\HAippy2Savea.2.9.dat -0.5s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{460D08C8-1B07-C60A-64E2-2C684AA107F2}\ -0.5s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{460D08C8-1B07-C60A-64E2-2C684AA107F2}\saeve net.2.7.dat -0.5s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{460D08C8-1B07-C60A-64E2-2C684AA107F2}\saeve net.2.7.dat -0.5s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{9EF49866-DED5-8121-8B45-5CCCDFD52ABC}\ -0.5s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{9EF49866-DED5-8121-8B45-5CCCDFD52ABC}\Search-NewTab.2.7.dat -0.5s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{9EF49866-DED5-8121-8B45-5CCCDFD52ABC}\Search-NewTab.2.7.dat -0.4s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\ -0.4s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\ -0.4s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.4s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.4s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.4s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.4s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{F1D1E649-0A44-F44E-2F0C-4E25E1AD32BC}\ -0.4s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{F1D1E649-0A44-F44E-2F0C-4E25E1AD32BC}\50Coiupoonss.2.9.dat -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\ -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\2a0b23fa8d6e74d491affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\60b6132765a7b0ab91affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\8c84dcdc46445dd691affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\c639ec01ae8d99a991affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\c639ec01ae8d99a991affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\c639ec01ae8d99a991affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\f5cc729cb434385591affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\f5cc729cb434385591affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\f5cc729cb434385591affd05bff6b1a1.ini -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{44E4311D-BA06-FD43-505E-17DC53F4C22F} -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{44E4311D-BA06-FD43-505E-17DC53F4C22F} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{44E4311D-BA06-FD43-505E-17DC53F4C22F}.old -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.old -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.old -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.old -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E}.old -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} -0.3s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}.old -0.2s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{CE94DD89-7404-B4B9-E713-E55CC0AB6C3B} -0.2s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.2s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.2s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.2s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.2s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\OMvNsr8Q.dat -0.2s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\OMvNsr8Q.tlb -0.2s C:\zoek_backup\C_PROGRA~2_ICQ\ -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\ -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\icqtabs.css -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\icqtabs.js -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\newTab.html -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\ -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\bgLarge.gif -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\bgSmall.gif -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\buttonBlue.gif -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\buttonGreen.gif -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\buttonGreen.gif -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\searchLogo.gif -0.1s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\searchLogo.gif -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\ -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\35814D17\ -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\7736030C\ -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\A8B37AF3\ -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\ -0.0s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\20140417145109.log 0.0s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Custom.dll 0.0s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Readme.txt 0.0s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Setup.dat 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Setup.ico 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\TsuDll.dll 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\_Setup.dll 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\ 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\20140506170218.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Custom.dll 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Readme.txt 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.ico 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\TsuDll.dll 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\TsuDll.dll 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\TsuDll.dll 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\_Setup.dll 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.5s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Custom.dll 0.5s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Readme.txt 0.6s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Setup.dat 0.6s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Setup.ico 0.6s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\TsuDll.dll 0.7s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\_Setup.dll 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\ 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\977FD4FC86B65788449055DB21BA0B6BD22FFFAD\ 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\977FD4FC86B65788449055DB21BA0B6BD22FFFAD\Avira.OE.Setup.Prerequisites.exe 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\ 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\ 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\ 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\cab1.cab 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\ 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\state.rsm 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\vcredist_x86.exe 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\vcredist_x86.exe 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\ 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\Avira.OE.Setup.Msi.msi 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\BundledProducts.xml 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.de.mst 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.en.mst 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.es.mst 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.fr.mst 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.it.mst 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.ptbr.mst 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.ptbr.mst 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.ru.mst 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\ 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\ 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\Avira.OE.Setup.Bundle.En-us.exe 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\Avira.OE.Setup.Bundle.En-us.exe 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\Avira.OE.Setup.Bundle.En-us.exe 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\state.rsm 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\state.rsm 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\ 1.1s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\ 1.1s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab 1.1s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab 1.1s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi 1.2s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\ 1.2s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\AppsHat.lnk 1.2s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\Uninstall.lnk 1.2s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\Uninstall.lnk 1.3s C:\zoek_backup\C_Windows_System32_searchplugins\ 1.3s C:\zoek_backup\C_Windows_System32_Extensions\ 1.3s C:\zoek_backup\C_PROGRA~2_rebootpending.txt.vir 1.3s C:\zoek_backup\C_PROGRA~2_rebootpending.txt.vir 1.3s C:\zoek_backup\C_PROGRA~2_rebootpending.txt.vir C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Custom.dll -> Deleted Size . . . . . . . : 93.696 bytes Age . . . . . . . : 1.7 days (2014-05-31 22:15:49) Entropy . . . . . : 6.3 SHA-256 . . . . . : 26A322CAB318444A72EA7E4EA13328753D5930C9BEC68191D43CB28E4648CE92 Product . . . . . : AppReady Software Publisher . . . . : AppReady Software Description . . . : Custom DLL for AppReady Version . . . . . : 2014.5. Copyright . . . . : Copyright © 2014 A > Bitdefender . . . : Gen:Variant.Application.Kazy.365295 > Kaspersky . . . . : Trojan.Win32.AntiFW.b Fuzzy . . . . . . : 102.0 Forensic Cluster -0.9s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{18EFC9FE-4235-A3E5-8EA1-D0F446646227}\ -0.8s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{18EFC9FE-4235-A3E5-8EA1-D0F446646227}\YoutubeAdblocker.2.7.dat -0.7s C:\zoek_backup\restore.txt -0.7s C:\zoek_backup\restore.txt -0.7s C:\zoek_backup\restore.txt -0.7s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{1CF67973-C380-3115-A8A6-BA4C958673E1}\ -0.7s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{1CF67973-C380-3115-A8A6-BA4C958673E1}\YoutubeAdblocker.2.7.dat -0.7s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{396E5F17-26E2-2AEC-C244-7C5E0A47D098}\ -0.7s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{396E5F17-26E2-2AEC-C244-7C5E0A47D098}\HAippy2Savea.2.9.dat -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{460D08C8-1B07-C60A-64E2-2C684AA107F2}\ -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{460D08C8-1B07-C60A-64E2-2C684AA107F2}\saeve net.2.7.dat -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{460D08C8-1B07-C60A-64E2-2C684AA107F2}\saeve net.2.7.dat -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{9EF49866-DED5-8121-8B45-5CCCDFD52ABC}\ -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{9EF49866-DED5-8121-8B45-5CCCDFD52ABC}\Search-NewTab.2.7.dat -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{9EF49866-DED5-8121-8B45-5CCCDFD52ABC}\Search-NewTab.2.7.dat -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\ -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\ -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{F1D1E649-0A44-F44E-2F0C-4E25E1AD32BC}\ -0.6s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{F1D1E649-0A44-F44E-2F0C-4E25E1AD32BC}\50Coiupoonss.2.9.dat -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\ -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\2a0b23fa8d6e74d491affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\60b6132765a7b0ab91affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\8c84dcdc46445dd691affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\c639ec01ae8d99a991affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\c639ec01ae8d99a991affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\c639ec01ae8d99a991affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\f5cc729cb434385591affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\f5cc729cb434385591affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\f5cc729cb434385591affd05bff6b1a1.ini -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{44E4311D-BA06-FD43-505E-17DC53F4C22F} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{44E4311D-BA06-FD43-505E-17DC53F4C22F} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{44E4311D-BA06-FD43-505E-17DC53F4C22F}.old -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.old -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.old -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.old -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.5s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E}.old -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}.old -0.4s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{CE94DD89-7404-B4B9-E713-E55CC0AB6C3B} -0.4s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.4s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.4s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.4s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.3s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\OMvNsr8Q.dat -0.3s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\OMvNsr8Q.tlb -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\ -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\icqtabs.css -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\icqtabs.js -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\newTab.html -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\ -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\bgLarge.gif -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\bgSmall.gif -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\buttonBlue.gif -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\buttonGreen.gif -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\buttonGreen.gif -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\searchLogo.gif -0.3s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\searchLogo.gif -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\35814D17\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\7736030C\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\A8B37AF3\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\20140417145109.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Custom.dll -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Readme.txt -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Setup.dat -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Setup.ico -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\TsuDll.dll -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\_Setup.dll -0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\ -0.0s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\20140506170218.log 0.0s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Custom.dll 0.0s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Readme.txt 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.ico 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\TsuDll.dll 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\TsuDll.dll 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\TsuDll.dll 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\_Setup.dll 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.4s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Custom.dll 0.4s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Readme.txt 0.4s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Setup.dat 0.5s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Setup.ico 0.5s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\TsuDll.dll 0.5s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\_Setup.dll 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\977FD4FC86B65788449055DB21BA0B6BD22FFFAD\ 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\977FD4FC86B65788449055DB21BA0B6BD22FFFAD\Avira.OE.Setup.Prerequisites.exe 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\ 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\ 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\ 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\cab1.cab 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\ 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\state.rsm 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\vcredist_x86.exe 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\vcredist_x86.exe 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\ 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\Avira.OE.Setup.Msi.msi 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\BundledProducts.xml 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.de.mst 0.7s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.en.mst 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.es.mst 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.fr.mst 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.it.mst 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.ptbr.mst 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.ptbr.mst 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.ru.mst 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\ 0.8s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\ 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\Avira.OE.Setup.Bundle.En-us.exe 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\Avira.OE.Setup.Bundle.En-us.exe 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\Avira.OE.Setup.Bundle.En-us.exe 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\state.rsm 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\state.rsm 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\ 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\ 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab 0.9s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab 1.0s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi 1.0s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\ 1.0s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\AppsHat.lnk 1.1s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\Uninstall.lnk 1.1s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\Uninstall.lnk 1.1s C:\zoek_backup\C_Windows_System32_searchplugins\ 1.1s C:\zoek_backup\C_Windows_System32_Extensions\ 1.2s C:\zoek_backup\C_PROGRA~2_rebootpending.txt.vir 1.2s C:\zoek_backup\C_PROGRA~2_rebootpending.txt.vir 1.2s C:\zoek_backup\C_PROGRA~2_rebootpending.txt.vir C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Custom.dll -> Deleted Size . . . . . . . : 93.696 bytes Age . . . . . . . : 1.7 days (2014-05-31 22:15:50) Entropy . . . . . : 6.3 SHA-256 . . . . . : A59DCFC80305319700A9390F0E9770C446497B8B6B373C5DFD32BC08B13F47AA Product . . . . . : AllaboutApp Publisher . . . . : AllaboutApp Description . . . : Custom DLL for AllaboutA Version . . . . . : 2014.5. Copyright . . . . : Copyright © 2014 A > Bitdefender . . . : Gen:Variant.Application.Kazy.365295 > Kaspersky . . . . : Trojan.Win32.AntiFW.b Fuzzy . . . . . . : 102.0 Forensic Cluster -1.3s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{18EFC9FE-4235-A3E5-8EA1-D0F446646227}\ -1.1s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{18EFC9FE-4235-A3E5-8EA1-D0F446646227}\YoutubeAdblocker.2.7.dat -1.1s C:\zoek_backup\restore.txt -1.1s C:\zoek_backup\restore.txt -1.1s C:\zoek_backup\restore.txt -1.1s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{1CF67973-C380-3115-A8A6-BA4C958673E1}\ -1.1s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{1CF67973-C380-3115-A8A6-BA4C958673E1}\YoutubeAdblocker.2.7.dat -1.1s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{396E5F17-26E2-2AEC-C244-7C5E0A47D098}\ -1.1s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{396E5F17-26E2-2AEC-C244-7C5E0A47D098}\HAippy2Savea.2.9.dat -1.0s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{460D08C8-1B07-C60A-64E2-2C684AA107F2}\ -1.0s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{460D08C8-1B07-C60A-64E2-2C684AA107F2}\saeve net.2.7.dat -1.0s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{460D08C8-1B07-C60A-64E2-2C684AA107F2}\saeve net.2.7.dat -1.0s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{9EF49866-DED5-8121-8B45-5CCCDFD52ABC}\ -1.0s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{9EF49866-DED5-8121-8B45-5CCCDFD52ABC}\Search-NewTab.2.7.dat -1.0s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{9EF49866-DED5-8121-8B45-5CCCDFD52ABC}\Search-NewTab.2.7.dat -1.0s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\ -1.0s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\ -0.9s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.9s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.9s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.9s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{D93E1A42-3C60-522A-1BD8-C77671C868B6}\DigiCoupOnn.2.7.dat -0.9s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{F1D1E649-0A44-F44E-2F0C-4E25E1AD32BC}\ -0.9s C:\zoek_backup\C_Users_Timmy_AppData_LocalLow_{F1D1E649-0A44-F44E-2F0C-4E25E1AD32BC}\50Coiupoonss.2.9.dat -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\ -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\2a0b23fa8d6e74d491affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\60b6132765a7b0ab91affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\8c84dcdc46445dd691affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\c639ec01ae8d99a991affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\c639ec01ae8d99a991affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\c639ec01ae8d99a991affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\eb6fe1e673371e2e91affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\f5cc729cb434385591affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\f5cc729cb434385591affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\f5cc729cb434385591affd05bff6b1a1.ini -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{44E4311D-BA06-FD43-505E-17DC53F4C22F} -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{44E4311D-BA06-FD43-505E-17DC53F4C22F} -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{44E4311D-BA06-FD43-505E-17DC53F4C22F}.old -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.9s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.old -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.old -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.old -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E} -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{7DD5E91C-3864-77EC-7635-D14910C2A03E}.old -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}.old -0.8s C:\zoek_backup\C_PROGRA~2_16eee1d900693bc\{CE94DD89-7404-B4B9-E713-E55CC0AB6C3B} -0.7s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.7s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.7s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.7s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\ -0.7s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\OMvNsr8Q.dat -0.7s C:\zoek_backup\C_PROGRA~2_HAippy2Savea\OMvNsr8Q.tlb -0.7s C:\zoek_backup\C_PROGRA~2_ICQ\ -0.7s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\ -0.7s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\icqtabs.css -0.7s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\icqtabs.js -0.6s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\newTab.html -0.6s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\ -0.6s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\bgLarge.gif -0.6s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\bgSmall.gif -0.6s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\buttonBlue.gif -0.6s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\buttonGreen.gif -0.6s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\buttonGreen.gif -0.6s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\searchLogo.gif -0.6s C:\zoek_backup\C_PROGRA~2_ICQ\ICQNewTab\img\searchLogo.gif -0.6s C:\zoek_backup\C_PROGRA~2_InstallMate\ -0.6s C:\zoek_backup\C_PROGRA~2_InstallMate\35814D17\ -0.6s C:\zoek_backup\C_PROGRA~2_InstallMate\7736030C\ -0.6s C:\zoek_backup\C_PROGRA~2_InstallMate\A8B37AF3\ -0.6s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\ -0.6s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\20140417145109.log -0.5s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Custom.dll -0.5s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Readme.txt -0.5s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Setup.dat -0.5s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\Setup.ico -0.5s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\TsuDll.dll -0.4s C:\zoek_backup\C_PROGRA~2_InstallMate\{579E7C0C-5E48-4569-A782-166A8C7D5EFA}\_Setup.dll -0.4s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\ -0.4s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\20140506170218.log -0.4s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Custom.dll -0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Readme.txt -0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat -0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat -0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat -0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat -0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.dat -0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\Setup.ico -0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\TsuDll.dll -0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\TsuDll.dll -0.3s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\TsuDll.dll -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CCE445D9-9094-4486-A66D-D8B61707672F}\_Setup.dll -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\ -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log -0.2s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\20140515160004.log 0.0s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Custom.dll 0.0s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Readme.txt 0.0s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Setup.dat 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\Setup.ico 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\TsuDll.dll 0.1s C:\zoek_backup\C_PROGRA~2_InstallMate\{CEC1B8C2-9212-4135-A3DE-DA3015229A34}\_Setup.dll 0.1s C:\zoek_backup\C_PROGRA~2_Package Cache\ 0.2s C:\zoek_backup\C_PROGRA~2_Package Cache\977FD4FC86B65788449055DB21BA0B6BD22FFFAD\ 0.2s C:\zoek_backup\C_PROGRA~2_Package Cache\977FD4FC86B65788449055DB21BA0B6BD22FFFAD\Avira.OE.Setup.Prerequisites.exe 0.2s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\ 0.2s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\ 0.2s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\ 0.2s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\cab1.cab 0.2s C:\zoek_backup\C_PROGRA~2_Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi 0.3s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\ 0.3s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\state.rsm 0.3s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\vcredist_x86.exe 0.3s C:\zoek_backup\C_PROGRA~2_Package Cache\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}\vcredist_x86.exe 0.3s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\ 0.3s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\Avira.OE.Setup.Msi.msi 0.4s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\BundledProducts.xml 0.4s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.de.mst 0.4s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.en.mst 0.4s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.es.mst 0.4s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.fr.mst 0.4s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.it.mst 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.ptbr.mst 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.ptbr.mst 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{5C16076B-DB38-4E0E-9F36-9276010E4F51}v1.1.12.20002\loc.ru.mst 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\Avira.OE.Setup.Bundle.En-us.exe 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\Avira.OE.Setup.Bundle.En-us.exe 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\Avira.OE.Setup.Bundle.En-us.exe 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\state.rsm 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{70a79d1f-686d-4d5c-962b-07aa1294eae0}\state.rsm 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\ 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab 0.5s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab 0.6s C:\zoek_backup\C_PROGRA~2_Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi 0.6s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\ 0.7s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\AppsHat.lnk 0.7s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\Uninstall.lnk 0.7s C:\zoek_backup\C_Users_Timmy_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_AppsHat\Uninstall.lnk 0.7s C:\zoek_backup\C_Windows_System32_searchplugins\ 0.8s C:\zoek_backup\C_Windows_System32_Extensions\ 0.8s C:\zoek_backup\C_PROGRA~2_rebootpending.txt.vir 0.8s C:\zoek_backup\C_PROGRA~2_rebootpending.txt.vir 0.8s C:\zoek_backup\C_PROGRA~2_rebootpending.txt.vir Suspicious files ____________________________________________________________ C:\Program Files\Sirius MT2\MultiHack_Kamer.mix -> Deleted Size . . . . . . . : 413.184 bytes Age . . . . . . . : 25.7 days (2014-05-07 22:34:49) Entropy . . . . . : 7.6 SHA-256 . . . . . : 032EBBCAA78D7001691B73213AC1376AFA2F5EA4BCAF2ADBFF2E570F4398053D Fuzzy . . . . . . : 24.0 Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. File belongs to an identified security risk. The file name extension of this program is not common. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Forensic Cluster -0.1s C:\Program Files\Sirius MT2\dumpfileremoveme 0.0s C:\Program Files\Sirius MT2\MultiHack_Kamer.mix 0.0s C:\Program Files\Sirius MT2\MultiHack_Kamer.mix 0.0s C:\Program Files\Sirius MT2\MultiHack_Kamer.mix 0.0s C:\Program Files\Sirius MT2\MultiHack_Kamer.mix 0.0s C:\Program Files\Sirius MT2\MultiHack_Kamer.mix C:\Windows\system32\GameMon.des -> Deleted Size . . . . . . . : 4.598.456 bytes Age . . . . . . . : 658.6 days (2012-08-13 02:46:43) Entropy . . . . . : 7.9 SHA-256 . . . . . : CC168A7545B8516C0F10E75E3519FCEF3643EA758308342FDE6E47CF85EFFAF7 Product . . . . . : nProtect Game Monitor Publisher . . . . : INCA Internet Co., Ltd. Description . . . : nProtect Game Monitor Rev 1865 Version . . . . . : 2012.5.23.1 Copyright . . . . : Copyright ⓒ 2000-2011 INCA Internet Service . . . . . : npggsvc Fuzzy . . . . . . : 31.0 The file name extension of this program is not common. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Starts automatically as a service during system bootup. The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities. Startup HKLM\SYSTEM\CurrentControlSet\Services\npggsvc\ Potential Unwanted Programs _________________________________________________ HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}\ (FLV Player) -> Deleted HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}\ (FLV Player) -> Deleted HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}\ (FLV Player) -> Deleted HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}\ (FLV Player) -> Deleted HKLM\SOFTWARE\Microsoft\Tracing\PluginService_RASAPI32\ (Qone8) -> Deleted HKLM\SOFTWARE\Microsoft\Tracing\PluginService_RASMANCS\ (Qone8) -> Deleted HKLM\SOFTWARE\Microsoft\Tracing\TBNotifier_RASAPI32\ (AskBar) -> Deleted HKLM\SOFTWARE\Microsoft\Tracing\TBNotifier_RASMANCS\ (AskBar) -> Deleted HKLM\SOFTWARE\Microsoft\Tracing\wprotectmanager_RASAPI32\ (Qone8) -> Deleted HKLM\SOFTWARE\Microsoft\Tracing\wprotectmanager_RASMANCS\ (Qone8) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467\ (FLV Player) -> Deleted HKLM\SYSTEM\ControlSet001\services\eventlog\Application\IePluginService\ (FTDownloader) -> Deleted HKLM\SYSTEM\ControlSet001\services\eventlog\Application\Wpm\ (FTDownloader) -> Deleted HKLM\SYSTEM\ControlSet002\services\eventlog\Application\IePluginService\ (FTDownloader) -> Deleted HKLM\SYSTEM\ControlSet002\services\eventlog\Application\Wpm\ (FTDownloader) -> Deleted HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\IePluginService\ (FTDownloader) -> PendingDelete HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\Wpm\ (FTDownloader) -> PendingDelete HKU\S-1-5-21-24558719-2126205106-1827937244-1004\Software\Microsoft\Internet Explorer\TabbedBrowsing\bProtectNewTabPageShow (22Find) -> Deleted HKU\S-1-5-21-24558719-2126205106-1827937244-1004\Software\Microsoft\Internet Explorer\TabbedBrowsing\bProtectShowTabsWelcome (22Find) -> Deleted Noch dazu: hatte gerade eben einen Bundestrojaner-Virus, habe diesen aber mit der Systemreperatur gelöscht ! mfg Hippel02 |
02.06.2014, 19:26 | #17 |
/// TB-Ausbilder | Browser Startet nicht, sowie jegliche Antiviren Programme, Downloadgeschwindigkeit sehr gering Servus,
__________________FRST bitte nochmal als Kontrolle:
|
03.06.2014, 05:59 | #18 |
| Browser Startet nicht, sowie jegliche Antiviren Programme, Downloadgeschwindigkeit sehr gering Liebes Trojaner-Board Team!
__________________Hier die FRST-Log: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-06-2014 Ran by Timmy (administrator) on LUKAS-PC on 03-06-2014 06:57:21 Running from C:\Users\Timmy\Downloads\FRST-OlderVersion Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe () C:\Windows\System32\PnkBstrA.exe (Razer Inc.) C:\Program Files\Razer\Razer Game Booster\RzKLService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-03-02] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [182352 2014-05-05] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-24558719-2126205106-1827937244-1004\...\Policies\Explorer: [NoCDBurning] 0 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{62754FEB-049A-4289-9BDF-793AC7A69E05}: [NameServer]192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Timmy\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Timmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-31] CHR Extension: (Google Drive) - C:\Users\Timmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-31] CHR Extension: (YouTube) - C:\Users\Timmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-31] CHR Extension: (Google-Suche) - C:\Users\Timmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-31] CHR Extension: (Google Wallet) - C:\Users\Timmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-17] CHR Extension: (Google Mail) - C:\Users\Timmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-31] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-03-02] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-03-02] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-03-02] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [124496 2014-05-05] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files\Common Files\BattlEye\BEService.exe [49152 2014-05-19] () R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1682768 2014-05-13] (LogMeIn Inc.) R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [375056 2014-04-15] (LogMeIn, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [66872 2012-12-10] () R2 RzKLService; C:\Program Files\Razer\Razer Game Booster\RzKLService.exe [105448 2014-02-25] (Razer Inc.) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2014-03-02] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2014-03-02] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [69240 2014-03-02] (Avira Operations GmbH & Co. KG) R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [30976 2014-06-02] () R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation) R1 netfilter; C:\Windows\System32\drivers\netfilter.sys [47488 2014-02-13] (NetFilterSDK.com) R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [1277504 2012-12-27] (Ralink Technology Corp.) S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [801896 2012-05-14] (Realtek Semiconductor Corporation ) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-11-25] (Avira GmbH) S3 catchme; \??\C:\Users\Timmy\AppData\Local\Temp\catchme.sys [X] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] U5 GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [26840 2012-08-21] (GEAR Software Inc.) S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-02 16:23 - 2014-06-03 06:53 - 00000112 _____ () C:\Windows\setupact.log 2014-06-02 16:23 - 2014-06-02 16:23 - 00030976 _____ () C:\Windows\system32\Drivers\hitmanpro37.sys 2014-06-02 16:23 - 2014-06-02 16:23 - 00000000 _____ () C:\Windows\setuperr.log 2014-06-02 16:22 - 2014-06-02 16:23 - 00270424 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-02 16:21 - 2014-06-02 16:21 - 00126416 _____ () C:\Users\Timmy\Desktop\HitmanPro_20140602_1621.log 2014-06-02 16:21 - 2014-06-02 16:21 - 00005750 _____ () C:\Windows\system32\.crusader 2014-06-02 16:15 - 2014-06-02 16:15 - 00059184 _____ () C:\Users\Timmy\AppData\Local\GDIPFONTCACHEV1.DAT 2014-06-02 16:12 - 2014-06-02 16:21 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-06-02 16:11 - 2014-06-02 16:12 - 10094400 _____ (SurfRight B.V.) C:\Users\Timmy\Downloads\HitmanPro.exe 2014-06-02 15:15 - 2014-06-02 15:15 - 00000059 _____ () C:\ProgramData\RUNDLL32.EXE-2148-F.txt 2014-06-02 14:56 - 2014-06-02 15:14 - 00010728 _____ () C:\ProgramData\RUNDLL32.EXE-2352-F.txt 2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\ProgramData\8DD15FDB8EADA1264B04FE08F85A2FBF 2014-06-02 06:50 - 2014-06-02 06:50 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\Mozilla 2014-06-01 20:47 - 2014-06-01 20:47 - 00000000 __SHD () C:\Users\Timmy\AppData\Local\EmieUserList 2014-06-01 20:47 - 2014-06-01 20:47 - 00000000 __SHD () C:\Users\Timmy\AppData\Local\EmieSiteList 2014-06-01 16:49 - 2012-08-23 16:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-06-01 16:49 - 2012-08-23 16:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-06-01 16:49 - 2012-08-23 15:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-06-01 16:49 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-06-01 16:49 - 2012-08-23 12:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-06-01 16:48 - 2014-06-01 16:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-06-01 16:48 - 2014-06-01 16:48 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-06-01 16:47 - 2013-10-02 02:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-06-01 16:47 - 2013-10-02 02:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-06-01 16:47 - 2013-10-02 02:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-06-01 16:47 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-06-01 16:47 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-06-01 16:47 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-06-01 16:47 - 2013-10-02 01:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-06-01 16:47 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-06-01 16:47 - 2013-10-02 01:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-06-01 16:47 - 2013-10-02 00:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-06-01 16:47 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-06-01 16:47 - 2013-10-01 22:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 17387008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 11745792 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-01 16:42 - 2014-06-01 16:42 - 02178048 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 01967104 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-01 16:42 - 2014-06-01 16:42 - 01789440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 01143808 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-06-01 16:42 - 2014-06-01 16:42 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-06-01 16:42 - 2014-06-01 16:42 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-06-01 16:42 - 2014-06-01 16:42 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-01 16:37 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-06-01 16:37 - 2013-11-23 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-06-01 16:37 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-06-01 16:37 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-06-01 16:36 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-06-01 16:36 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-06-01 16:16 - 2014-06-01 16:16 - 00854367 _____ () C:\Users\Timmy\Desktop\SecurityCheck.exe 2014-06-01 14:32 - 2014-06-01 14:32 - 00000000 ____D () C:\Program Files\ESET 2014-06-01 14:30 - 2014-06-01 14:32 - 02347384 _____ (ESET) C:\Users\Timmy\Downloads\esetsmartinstaller_deu.exe 2014-06-01 14:25 - 2014-06-01 14:26 - 00139264 _____ () C:\Users\Timmy\Downloads\SystemLook.exe 2014-06-01 14:18 - 2014-06-03 06:57 - 00000000 ____D () C:\Users\Timmy\Downloads\FRST-OlderVersion 2014-06-01 12:11 - 2014-06-01 12:12 - 00000000 ____D () C:\Users\Timmy\Desktop\Steam Games 2014-05-31 22:18 - 2014-06-03 06:57 - 00000000 ____D () C:\Users\Timmy\AppData\Local\Temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\ASPNET\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Administrator\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:06 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-05-31 22:08 - 2014-05-31 22:19 - 00030612 _____ () C:\zoek-results.log 2014-05-31 22:06 - 2014-05-31 22:17 - 00000000 ____D () C:\zoek_backup 2014-05-31 22:06 - 2014-05-31 22:06 - 01285120 _____ () C:\Users\Timmy\Downloads\zoek.exe 2014-05-31 21:50 - 2014-05-31 22:02 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-31 21:50 - 2014-05-31 21:50 - 00001060 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-31 21:50 - 2014-05-31 21:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-31 21:50 - 2014-05-31 21:50 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-31 21:50 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-31 21:50 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-31 21:50 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-31 21:44 - 2014-05-31 21:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Timmy\Downloads\mbam-setup-2.0.2.1012 (3).exe 2014-05-31 21:39 - 2014-05-31 21:39 - 01016261 _____ (Thisisu) C:\Users\Timmy\Downloads\JRT.exe 2014-05-31 21:39 - 2014-05-31 21:39 - 00000000 ____D () C:\Windows\ERUNT 2014-05-31 21:34 - 2014-06-01 16:36 - 00000000 ____D () C:\Users\Timmy\Desktop\Moskitos Auftrag 2014-05-31 21:30 - 2014-05-31 21:31 - 01327971 _____ () C:\Users\Timmy\Downloads\adwcleaner_3.211 (1).exe 2014-05-31 21:16 - 2014-05-31 21:16 - 00017920 _____ () C:\ComboFix.txt 2014-05-31 21:03 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-05-31 21:03 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-05-31 21:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-05-31 21:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-05-31 21:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-05-31 21:03 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-05-31 21:03 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-05-31 21:03 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-05-31 21:02 - 2014-05-31 21:16 - 00000000 ____D () C:\Qoobox 2014-05-31 21:02 - 2014-05-31 21:15 - 00000000 ____D () C:\Windows\erdnt 2014-05-31 21:00 - 2014-05-31 21:01 - 05203398 ____R (Swearware) C:\Users\Timmy\Downloads\ComboFix.exe 2014-05-31 20:36 - 2014-05-31 22:26 - 00025675 _____ () C:\Users\Timmy\Downloads\Addition.txt 2014-05-31 20:33 - 2014-06-03 06:57 - 00000000 ____D () C:\FRST 2014-05-31 20:33 - 2014-06-01 14:18 - 01057792 _____ (Farbar) C:\Users\Timmy\Downloads\FRST.exe 2014-05-31 20:33 - 2014-05-31 22:26 - 00069647 _____ () C:\Users\Timmy\Downloads\FRST.txt 2014-05-31 19:48 - 2014-05-31 19:48 - 02056224 _____ () C:\Users\Timmy\Downloads\cpu-z-1692.zip 2014-05-31 19:36 - 2014-05-31 19:36 - 00000000 ____D () C:\Program Files\GPU-Z 2014-05-31 19:35 - 2014-05-31 19:35 - 01617624 _____ () C:\Users\Timmy\Downloads\GPU-Z.0.7.8.zip 2014-05-31 18:52 - 2014-05-31 18:54 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Timmy\Downloads\mbam-setup-2.0.2.1012 (2).exe 2014-05-31 18:40 - 2014-05-31 18:40 - 00001105 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-05-31 18:37 - 2014-05-31 18:39 - 28852416 _____ (Mozilla) C:\Users\Timmy\Downloads\Firefox_Setup_de29.0.1.exe 2014-05-31 18:30 - 2014-05-31 18:30 - 00001421 _____ () C:\Users\Timmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-31 18:21 - 2014-05-31 18:21 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-05-31 18:16 - 2014-05-31 18:17 - 30091776 _____ (Microsoft Corporation) C:\Users\Timmy\Downloads\IE10-Windows6.1-x86-de-de.exe 2014-05-31 18:10 - 2014-05-31 18:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Timmy\Downloads\mbam-setup-2.0.2.1012 (1).exe 2014-05-31 17:52 - 2014-05-31 17:53 - 25443244 _____ () C:\Users\Timmy\Downloads\DayZ 05.10.2014 - 14.06.59.01_1.mp4 2014-05-31 17:47 - 2014-05-31 17:47 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-31 17:45 - 2014-05-31 17:46 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Timmy\Downloads\mbam-setup-2.0.2.1012.exe 2014-05-31 17:41 - 2014-05-31 17:41 - 01327971 _____ () C:\Users\Timmy\Downloads\adwcleaner_3.211.exe 2014-05-31 17:17 - 2014-05-31 17:17 - 00000000 ____D () C:\Windows\pss 2014-05-31 16:47 - 2014-05-31 16:47 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-05-31 16:47 - 2014-05-31 16:47 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-31 16:45 - 2014-05-31 16:46 - 04748896 _____ (Piriform Ltd) C:\Users\Timmy\Downloads\ccsetup414.exe 2014-05-31 16:42 - 2014-05-31 16:42 - 04981160 _____ (Adobe Systems Inc.) C:\Users\Timmy\Downloads\Shockwave_Installer_Slim.exe 2014-05-26 22:01 - 2014-05-26 22:05 - 90513790 _____ () C:\Users\Timmy\Downloads\DayZ 05.26.2014 - 21.57.15.01.mp4 2014-05-25 08:44 - 2014-05-25 08:44 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-05-21 17:42 - 2014-06-02 21:42 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\TS3Client 2014-05-21 17:42 - 2014-05-21 17:42 - 00001120 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-05-21 17:42 - 2014-05-21 17:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client 2014-05-21 17:42 - 2014-05-21 17:42 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-05-21 17:38 - 2014-05-21 17:39 - 00961360 _____ (Chip Digital GmbH) C:\Users\Timmy\Downloads\TeamSpeak 3 32 Bit - CHIP-Downloader.exe 2014-05-19 06:41 - 2014-05-19 06:41 - 00000000 ____D () C:\Program Files\Common Files\BattlEye 2014-05-19 06:22 - 2014-05-19 07:02 - 00000000 ____D () C:\Users\Timmy\Documents\DayZ 2014-05-18 14:25 - 2014-05-18 14:25 - 00017791 _____ () C:\Users\Timmy\Downloads\Download.htm 2014-05-18 14:25 - 2014-05-18 14:25 - 00017791 _____ () C:\Users\Timmy\Downloads\Download (1).htm 2014-05-17 16:27 - 2014-06-01 12:09 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-05-15 19:46 - 2014-05-15 19:46 - 00000000 ____D () C:\Users\Timmy\Documents\Razer 2014-05-15 19:46 - 2014-05-15 19:46 - 00000000 ____D () C:\Users\Timmy\AppData\Local\Razer_Inc 2014-05-15 19:44 - 2014-05-15 19:44 - 00000000 ____D () C:\Users\Timmy\AppData\Local\Razer 2014-05-15 19:44 - 2014-05-15 19:44 - 00000000 ____D () C:\ProgramData\Razer 2014-05-15 19:44 - 2014-05-15 19:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer 2014-05-15 19:44 - 2014-05-15 19:44 - 00000000 ____D () C:\Program Files\Razer 2014-05-15 19:39 - 2014-05-15 19:43 - 41954352 _____ (Razer Inc. ) C:\Users\Timmy\Downloads\RazerGameBoosterSetup_4.2.45.0.exe 2014-05-15 17:46 - 2014-05-15 17:47 - 00818889 _____ () C:\Users\Timmy\Downloads\OptiFine_1.7.4_HD_U_D1.jar 2014-05-15 17:40 - 2014-05-15 17:40 - 00785243 _____ () C:\Users\Timmy\Downloads\OptiFine_1.7.2_HD_D1.jar 2014-05-15 17:40 - 2014-05-15 17:40 - 00539717 _____ () C:\Users\Timmy\Downloads\optifine_1.7.2.zip 2014-05-15 17:38 - 2014-05-15 17:38 - 00030566 _____ () C:\Users\Timmy\Downloads\§6Paolos §aLagLess §4Shaders §cv03 §1RC7 §eLite.zip 2014-05-15 17:34 - 2014-05-15 17:34 - 00445865 _____ () C:\Users\Timmy\Downloads\voxelmap-1.7.2-1.0.jar 2014-05-15 17:32 - 2014-05-15 17:32 - 00066184 _____ () C:\Users\Timmy\Downloads\yatc_b0.9.1_1.4.6.zip 2014-05-15 16:51 - 2014-05-15 16:51 - 00033217 _____ () C:\Users\Timmy\Downloads\§6Paolos §aLagLess §4Shaders §cv03 §3RC8.zip 2014-05-15 16:50 - 2014-05-15 16:50 - 00026598 _____ () C:\Users\Timmy\Downloads\MrMeep_x3s Shaders v04.0 RC4.zip 2014-05-15 16:34 - 2014-05-15 16:34 - 00811462 _____ () C:\Users\Timmy\Downloads\OptiFine_1.7.2_HD_U_D1.jar 2014-05-15 16:34 - 2014-05-15 16:34 - 00064982 _____ () C:\Users\Timmy\Downloads\seus-v10.1-Preview2.zip 2014-05-15 16:25 - 2014-05-15 16:25 - 02530401 _____ () C:\Users\Timmy\Downloads\forge-1.7.2-10.12.0.997-installer.jar 2014-05-15 16:24 - 2014-05-15 16:24 - 00183946 _____ () C:\Users\Timmy\Downloads\ShadersModCore-v2.3.0-beta-mc1.7.2-f997.jar 2014-05-15 16:21 - 2014-05-15 16:21 - 00177465 _____ () C:\Users\Timmy\Downloads\ShadersModCore-v2.3.13mc1.7.4-zip.zip 2014-05-15 16:12 - 2014-05-15 16:13 - 00202061 _____ () C:\Users\Timmy\Downloads\ShadersModCore-v2.3.12-mc1.7.2-f1040.jar 2014-05-15 16:12 - 2014-05-15 16:13 - 00046267 _____ () C:\Users\Timmy\Downloads\SEUS-v10.1-Ultra.zip 2014-05-15 16:07 - 2014-05-15 16:07 - 02632153 _____ () C:\Users\Timmy\Downloads\forge-1.7.2-10.12.0.1024-installer.jar 2014-05-15 16:02 - 2014-05-15 16:02 - 00000000 ____D () C:\ProgramData\AllaboutApp 2014-05-14 19:02 - 2014-05-14 19:02 - 02630583 _____ () C:\Users\Timmy\Downloads\forge-1.7.2-10.12.0.1040-installer.jar 2014-05-14 18:55 - 2014-05-14 18:55 - 03685975 _____ () C:\Users\Timmy\Downloads\Minecraft Force Op 1.7.9.zip 2014-05-14 18:52 - 2014-05-14 18:52 - 00469713 _____ () C:\Users\Timmy\Downloads\MINECRAFT_FORCEOP_2014.RAR 2014-05-14 13:36 - 2014-05-14 13:37 - 06647543 _____ () C:\Users\Timmy\Downloads\Nodus.zip 2014-05-14 13:29 - 2014-05-09 09:06 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 13:29 - 2014-05-09 09:04 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 13:29 - 2014-04-12 04:15 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 13:29 - 2014-04-12 04:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 13:29 - 2014-04-12 04:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 13:29 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 13:29 - 2014-04-12 04:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 13:29 - 2014-04-12 04:11 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 13:29 - 2014-04-12 04:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 13:29 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2014-05-14 13:29 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 13:29 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 13:29 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 13:29 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 13:28 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-14 13:22 - 2014-05-14 13:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-05-14 13:22 - 2014-05-14 13:22 - 00000000 ____D () C:\Program Files\LogMeIn Hamachi 2014-05-13 18:28 - 2014-06-02 16:31 - 00000000 ____D () C:\Users\Timmy\AppData\Local\DayZ 2014-05-13 18:28 - 2014-05-13 18:28 - 00000000 ____D () C:\Users\Timmy\Documents\BIS Core Engine 2014-05-13 18:27 - 2014-05-13 18:27 - 13987015 _____ () C:\Users\Timmy\Downloads\DayZ SA Multiplayer Crack.zip 2014-05-13 17:18 - 2014-05-13 17:18 - 00254645 _____ () C:\Users\Timmy\Downloads\[1.7.2]ReiMinimap_v3.4_03beta.zip 2014-05-13 17:14 - 2014-05-13 17:15 - 28062081 _____ () C:\Users\Timmy\Downloads\Sphax PureBDcraft 128x MC17.zip 2014-05-13 16:49 - 2014-05-13 16:51 - 19329130 _____ () C:\Users\Timmy\Downloads\DayZ By NotAwim for HunteR26RuS 1.5.2 Modify.zip 2014-05-12 14:54 - 2014-05-12 14:54 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\.firefox 2014-05-12 14:51 - 2014-05-12 14:52 - 06647663 _____ () C:\Users\Timmy\Downloads\Nodus 1.7.9.zip 2014-05-11 17:08 - 2014-05-11 18:03 - 1197047898 _____ () C:\Users\Timmy\Downloads\Hardcore-RELOADED_24_01.rar 2014-05-11 17:07 - 2014-05-11 17:07 - 15568473 _____ () C:\Users\Timmy\Downloads\Hardcore-RELOADED_patcher (1).rar 2014-05-11 17:04 - 2014-05-11 17:07 - 08242902 _____ () C:\Users\Timmy\Downloads\Hardcore-RELOADED_patcher.rar 2014-05-10 22:56 - 2014-05-25 08:44 - 00000000 ___RD () C:\Program Files\Skype 2014-05-10 22:56 - 2014-05-10 22:56 - 00000000 ____D () C:\Users\Timmy\AppData\Local\Skype 2014-05-10 22:56 - 2014-05-10 22:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-05-10 22:55 - 2014-05-10 22:55 - 01678496 _____ (Skype Technologies S.A.) C:\Users\Timmy\Downloads\SkypeSetup (1).exe 2014-05-10 15:57 - 2014-05-10 16:00 - 49268534 _____ () C:\Users\Timmy\Downloads\LIFE 128x (Vers. 81).zip 2014-05-09 20:09 - 2014-05-09 20:09 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-05-09 20:09 - 2014-05-09 20:09 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-05-09 20:09 - 2014-05-09 20:09 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-05-09 20:09 - 2014-05-09 20:09 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-05-09 20:09 - 2014-05-09 20:09 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-09 20:09 - 2014-05-09 20:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-09 20:09 - 2014-05-09 20:09 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-05-09 20:05 - 2014-05-09 20:06 - 00921512 _____ (Oracle Corporation) C:\Users\Timmy\Downloads\chromeinstall-7u55 (1).exe 2014-05-09 19:38 - 2014-05-18 20:51 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\.minecraft 2014-05-09 19:37 - 2014-05-30 13:11 - 01557017 _____ (TeamExtreme) C:\Users\Timmy\Desktop\Minecraft.exe 2014-05-09 19:37 - 2014-05-10 09:24 - 01771520 _____ (TeamExtreme) C:\Users\Timmy\Downloads\Minecraft.exe 2014-05-09 18:18 - 2014-05-09 18:18 - 00000009 _____ () C:\Users\Timmy\Downloads\ad_down.htm 2014-05-09 17:26 - 2014-05-09 17:27 - 00255189 _____ () C:\Users\Timmy\Downloads\Mineshafter-launcher.jar 2014-05-09 17:15 - 2014-05-09 17:15 - 00643272 _____ () C:\Users\Timmy\Downloads\MineCraftSetup.exe 2014-05-08 15:36 - 2014-05-31 16:48 - 00000000 ____D () C:\Windows\Minidump 2014-05-08 15:07 - 2014-05-08 15:09 - 04582789 _____ () C:\Users\Timmy\Downloads\m2k-mod_Pserver.zip 2014-05-07 22:28 - 2014-05-07 22:30 - 03757782 _____ () C:\Users\Timmy\Downloads\Item Creator.zip 2014-05-07 22:09 - 2014-05-07 22:14 - 23488196 _____ () C:\Users\Timmy\Downloads\MultiHack (1).rar 2014-05-07 21:52 - 2014-05-07 21:58 - 23488196 _____ () C:\Users\Timmy\Downloads\MultiHack.rar 2014-05-07 21:44 - 2014-05-07 21:44 - 00000000 ___SD () C:\Users\Timmy\AppData\Roaming\Frutas 2014-05-07 21:43 - 2014-05-07 21:43 - 00000000 ___HD () C:\Users\Timmy\Desktop\TempInstall 2014-05-07 21:42 - 2014-05-07 21:43 - 01151644 _____ () C:\Users\Timmy\Downloads\Bot_Metin2.rar 2014-05-07 21:38 - 2014-05-07 21:38 - 00000000 ____D () C:\Users\Timmy\Documents\My Cheat Tables 2014-05-07 21:34 - 2014-05-07 21:35 - 08065840 _____ (Cheat Engine ) C:\Users\Timmy\Downloads\CheatEngine63.exe 2014-05-07 16:31 - 2014-05-07 16:32 - 03511609 _____ () C:\Users\Timmy\Downloads\Metin 2 Yang Hack.rar 2014-05-07 16:22 - 2014-05-07 16:24 - 08435712 _____ () C:\Users\Timmy\Downloads\archpr454_setup_en.msi 2014-05-07 08:39 - 2014-05-07 08:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2 2014-05-06 17:00 - 2014-05-14 17:21 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-05 15:41 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-05-05 15:36 - 2014-05-31 22:00 - 00000000 ____D () C:\Temp 2014-05-05 13:54 - 2014-05-30 11:55 - 00000000 ____D () C:\Program Files\GameforgeLive 2014-05-05 13:54 - 2014-05-30 11:46 - 00000000 ____D () C:\Users\Timmy\Downloads\Gameforge Live 2014-05-05 13:54 - 2014-05-30 11:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live 2014-05-05 13:54 - 2014-05-05 13:54 - 00000000 ____D () C:\Users\Timmy\AppData\Local\Gameforge4d 2014-05-05 13:53 - 2014-05-05 13:53 - 20155712 _____ (Gameforge ) C:\Users\Timmy\Downloads\Metin2_GameforgeLiveSetup.exe ==================== One Month Modified Files and Folders ======= 2014-06-03 06:57 - 2014-06-01 14:18 - 00000000 ____D () C:\Users\Timmy\Downloads\FRST-OlderVersion 2014-06-03 06:57 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Timmy\AppData\Local\Temp 2014-06-03 06:57 - 2014-05-31 20:33 - 00000000 ____D () C:\FRST 2014-06-03 06:56 - 2011-08-13 15:49 - 01606481 _____ () C:\Windows\WindowsUpdate.log 2014-06-03 06:53 - 2014-06-02 16:23 - 00000112 _____ () C:\Windows\setupact.log 2014-06-03 06:53 - 2014-04-13 15:09 - 00000000 ____D () C:\Users\Timmy\AppData\Local\LogMeIn Hamachi 2014-06-03 06:53 - 2012-02-18 20:18 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-06-03 06:53 - 2011-09-26 18:28 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-03 06:53 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-02 21:42 - 2014-05-21 17:42 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\TS3Client 2014-06-02 21:36 - 2011-09-26 18:28 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-02 20:43 - 2012-08-12 14:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-02 20:31 - 2014-04-15 08:26 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-24558719-2126205106-1827937244-1004UA.job 2014-06-02 18:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-06-02 16:31 - 2014-05-13 18:28 - 00000000 ____D () C:\Users\Timmy\AppData\Local\DayZ 2014-06-02 16:31 - 2014-04-16 15:43 - 00000000 ____D () C:\Program Files\Steam 2014-06-02 16:30 - 2009-07-14 06:34 - 00014192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-02 16:30 - 2009-07-14 06:34 - 00014192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-02 16:29 - 2011-08-13 15:55 - 00006446 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-02 16:23 - 2014-06-02 16:23 - 00030976 _____ () C:\Windows\system32\Drivers\hitmanpro37.sys 2014-06-02 16:23 - 2014-06-02 16:23 - 00000000 _____ () C:\Windows\setuperr.log 2014-06-02 16:23 - 2014-06-02 16:22 - 00270424 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-02 16:23 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\tracing 2014-06-02 16:21 - 2014-06-02 16:21 - 00126416 _____ () C:\Users\Timmy\Desktop\HitmanPro_20140602_1621.log 2014-06-02 16:21 - 2014-06-02 16:21 - 00005750 _____ () C:\Windows\system32\.crusader 2014-06-02 16:21 - 2014-06-02 16:12 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-06-02 16:21 - 2014-04-21 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sirius MT2 2014-06-02 16:21 - 2014-04-21 17:10 - 00000000 ____D () C:\Program Files\Sirius MT2 2014-06-02 16:20 - 2013-11-28 22:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-06-02 16:20 - 2013-11-28 22:26 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-06-02 16:20 - 2013-11-28 22:26 - 00000000 ____D () C:\Program Files\iTunes 2014-06-02 16:20 - 2013-11-28 22:26 - 00000000 ____D () C:\Program Files\iPod 2014-06-02 16:20 - 2011-10-01 23:05 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-06-02 16:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp 2014-06-02 16:19 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration 2014-06-02 16:15 - 2014-06-02 16:15 - 00059184 _____ () C:\Users\Timmy\AppData\Local\GDIPFONTCACHEV1.DAT 2014-06-02 16:12 - 2014-06-02 16:11 - 10094400 _____ (SurfRight B.V.) C:\Users\Timmy\Downloads\HitmanPro.exe 2014-06-02 15:24 - 2011-10-26 14:19 - 00000000 ____D () C:\Program Files\Common Files\Steam 2014-06-02 15:21 - 2013-01-13 21:44 - 00000000 ____D () C:\Users\Timmy 2014-06-02 15:15 - 2014-06-02 15:15 - 00000059 _____ () C:\ProgramData\RUNDLL32.EXE-2148-F.txt 2014-06-02 15:14 - 2014-06-02 14:56 - 00010728 _____ () C:\ProgramData\RUNDLL32.EXE-2352-F.txt 2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\ProgramData\8DD15FDB8EADA1264B04FE08F85A2FBF 2014-06-02 06:50 - 2014-06-02 06:50 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\Mozilla 2014-06-01 22:44 - 2014-04-13 17:02 - 00000000 ____D () C:\Program Files\7DaysToDie-Alpha 2014-06-01 22:43 - 2009-10-14 05:07 - 00000000 ____D () C:\Windows\Panther 2014-06-01 22:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-06-01 20:47 - 2014-06-01 20:47 - 00000000 __SHD () C:\Users\Timmy\AppData\Local\EmieUserList 2014-06-01 20:47 - 2014-06-01 20:47 - 00000000 __SHD () C:\Users\Timmy\AppData\Local\EmieSiteList 2014-06-01 16:53 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-06-01 16:51 - 2009-07-14 10:47 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2014-06-01 16:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-06-01 16:48 - 2014-06-01 16:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-06-01 16:48 - 2014-06-01 16:48 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-06-01 16:42 - 2014-06-01 16:42 - 17387008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 11745792 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-01 16:42 - 2014-06-01 16:42 - 02178048 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 01967104 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-01 16:42 - 2014-06-01 16:42 - 01789440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 01143808 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-06-01 16:42 - 2014-06-01 16:42 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-06-01 16:42 - 2014-06-01 16:42 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-06-01 16:42 - 2014-06-01 16:42 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-06-01 16:42 - 2014-06-01 16:42 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-06-01 16:42 - 2014-06-01 16:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-01 16:36 - 2014-05-31 21:34 - 00000000 ____D () C:\Users\Timmy\Desktop\Moskitos Auftrag 2014-06-01 16:16 - 2014-06-01 16:16 - 00854367 _____ () C:\Users\Timmy\Desktop\SecurityCheck.exe 2014-06-01 14:32 - 2014-06-01 14:32 - 00000000 ____D () C:\Program Files\ESET 2014-06-01 14:32 - 2014-06-01 14:30 - 02347384 _____ (ESET) C:\Users\Timmy\Downloads\esetsmartinstaller_deu.exe 2014-06-01 14:26 - 2014-06-01 14:25 - 00139264 _____ () C:\Users\Timmy\Downloads\SystemLook.exe 2014-06-01 14:18 - 2014-05-31 20:33 - 01057792 _____ (Farbar) C:\Users\Timmy\Downloads\FRST.exe 2014-06-01 12:12 - 2014-06-01 12:11 - 00000000 ____D () C:\Users\Timmy\Desktop\Steam Games 2014-06-01 12:12 - 2014-04-14 18:46 - 00000000 ____D () C:\Users\Timmy\Desktop\Games 2014-06-01 12:09 - 2014-05-17 16:27 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-06-01 10:03 - 2014-04-20 22:42 - 00000000 ____D () C:\Users\Timmy\Desktop\Musik 2014-06-01 09:49 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-31 22:26 - 2014-05-31 20:36 - 00025675 _____ () C:\Users\Timmy\Downloads\Addition.txt 2014-05-31 22:26 - 2014-05-31 20:33 - 00069647 _____ () C:\Users\Timmy\Downloads\FRST.txt 2014-05-31 22:19 - 2014-05-31 22:08 - 00030612 _____ () C:\zoek-results.log 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\ASPNET\AppData\Local\temp 2014-05-31 22:18 - 2014-05-31 22:18 - 00000000 ____D () C:\Users\Administrator\AppData\Local\temp 2014-05-31 22:17 - 2014-05-31 22:06 - 00000000 ____D () C:\zoek_backup 2014-05-31 22:06 - 2014-05-31 22:18 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-05-31 22:06 - 2014-05-31 22:06 - 01285120 _____ () C:\Users\Timmy\Downloads\zoek.exe 2014-05-31 22:02 - 2014-05-31 21:50 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-31 22:01 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\twain_32 2014-05-31 22:00 - 2014-05-05 15:36 - 00000000 ____D () C:\Temp 2014-05-31 21:50 - 2014-05-31 21:50 - 00001060 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-31 21:50 - 2014-05-31 21:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-31 21:50 - 2014-05-31 21:50 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-31 21:48 - 2014-05-31 21:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Timmy\Downloads\mbam-setup-2.0.2.1012 (3).exe 2014-05-31 21:39 - 2014-05-31 21:39 - 01016261 _____ (Thisisu) C:\Users\Timmy\Downloads\JRT.exe 2014-05-31 21:39 - 2014-05-31 21:39 - 00000000 ____D () C:\Windows\ERUNT 2014-05-31 21:32 - 2014-04-18 23:47 - 00000000 ____D () C:\AdwCleaner 2014-05-31 21:31 - 2014-05-31 21:30 - 01327971 _____ () C:\Users\Timmy\Downloads\adwcleaner_3.211 (1).exe 2014-05-31 21:16 - 2014-05-31 21:16 - 00017920 _____ () C:\ComboFix.txt 2014-05-31 21:16 - 2014-05-31 21:02 - 00000000 ____D () C:\Qoobox 2014-05-31 21:16 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default 2014-05-31 21:16 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public 2014-05-31 21:15 - 2014-05-31 21:02 - 00000000 ____D () C:\Windows\erdnt 2014-05-31 21:14 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini 2014-05-31 21:01 - 2014-05-31 21:00 - 05203398 ____R (Swearware) C:\Users\Timmy\Downloads\ComboFix.exe 2014-05-31 19:48 - 2014-05-31 19:48 - 02056224 _____ () C:\Users\Timmy\Downloads\cpu-z-1692.zip 2014-05-31 19:36 - 2014-05-31 19:36 - 00000000 ____D () C:\Program Files\GPU-Z 2014-05-31 19:35 - 2014-05-31 19:35 - 01617624 _____ () C:\Users\Timmy\Downloads\GPU-Z.0.7.8.zip 2014-05-31 18:54 - 2014-05-31 18:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Timmy\Downloads\mbam-setup-2.0.2.1012 (2).exe 2014-05-31 18:40 - 2014-05-31 18:40 - 00001105 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-05-31 18:40 - 2014-04-14 19:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-31 18:39 - 2014-05-31 18:37 - 28852416 _____ (Mozilla) C:\Users\Timmy\Downloads\Firefox_Setup_de29.0.1.exe 2014-05-31 18:30 - 2014-05-31 18:30 - 00001421 _____ () C:\Users\Timmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\zh-TW 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\zh-HK 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\zh-CN 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\tr-TR 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\sv-SE 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ru-RU 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\pt-PT 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\pt-BR 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\pl-PL 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\nl-NL 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\nb-NO 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ko-KR 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ja-JP 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\it-IT 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\hu-HU 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\fr-FR 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\fi-FI 2014-05-31 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\el-GR 2014-05-31 18:21 - 2014-05-31 18:21 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-05-31 18:21 - 2014-05-31 18:21 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-05-31 18:17 - 2014-05-31 18:16 - 30091776 _____ (Microsoft Corporation) C:\Users\Timmy\Downloads\IE10-Windows6.1-x86-de-de.exe 2014-05-31 18:11 - 2014-05-31 18:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Timmy\Downloads\mbam-setup-2.0.2.1012 (1).exe 2014-05-31 17:53 - 2014-05-31 17:52 - 25443244 _____ () C:\Users\Timmy\Downloads\DayZ 05.10.2014 - 14.06.59.01_1.mp4 2014-05-31 17:47 - 2014-05-31 17:47 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-31 17:46 - 2014-05-31 17:45 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Timmy\Downloads\mbam-setup-2.0.2.1012.exe 2014-05-31 17:41 - 2014-05-31 17:41 - 01327971 _____ () C:\Users\Timmy\Downloads\adwcleaner_3.211.exe 2014-05-31 17:17 - 2014-05-31 17:17 - 00000000 ____D () C:\Windows\pss 2014-05-31 16:48 - 2014-05-08 15:36 - 00000000 ____D () C:\Windows\Minidump 2014-05-31 16:47 - 2014-05-31 16:47 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-05-31 16:47 - 2014-05-31 16:47 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-31 16:46 - 2014-05-31 16:45 - 04748896 _____ (Piriform Ltd) C:\Users\Timmy\Downloads\ccsetup414.exe 2014-05-31 16:43 - 2012-08-11 21:30 - 00000000 ____D () C:\Windows\system32\Adobe 2014-05-31 16:42 - 2014-05-31 16:42 - 04981160 _____ (Adobe Systems Inc.) C:\Users\Timmy\Downloads\Shockwave_Installer_Slim.exe 2014-05-31 09:31 - 2013-08-25 11:57 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\Skype 2014-05-30 13:11 - 2014-05-09 19:37 - 01557017 _____ (TeamExtreme) C:\Users\Timmy\Desktop\Minecraft.exe 2014-05-30 11:55 - 2014-05-05 13:54 - 00000000 ____D () C:\Program Files\GameforgeLive 2014-05-30 11:46 - 2014-05-05 13:54 - 00000000 ____D () C:\Users\Timmy\Downloads\Gameforge Live 2014-05-30 11:46 - 2014-05-05 13:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live 2014-05-26 22:05 - 2014-05-26 22:01 - 90513790 _____ () C:\Users\Timmy\Downloads\DayZ 05.26.2014 - 21.57.15.01.mp4 2014-05-25 08:44 - 2014-05-25 08:44 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-05-25 08:44 - 2014-05-10 22:56 - 00000000 ___RD () C:\Program Files\Skype 2014-05-25 08:44 - 2011-09-26 18:24 - 00000000 ____D () C:\ProgramData\Skype 2014-05-21 17:42 - 2014-05-21 17:42 - 00001120 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-05-21 17:42 - 2014-05-21 17:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client 2014-05-21 17:42 - 2014-05-21 17:42 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-05-21 17:39 - 2014-05-21 17:38 - 00961360 _____ (Chip Digital GmbH) C:\Users\Timmy\Downloads\TeamSpeak 3 32 Bit - CHIP-Downloader.exe 2014-05-19 07:02 - 2014-05-19 06:22 - 00000000 ____D () C:\Users\Timmy\Documents\DayZ 2014-05-19 06:41 - 2014-05-19 06:41 - 00000000 ____D () C:\Program Files\Common Files\BattlEye 2014-05-18 20:51 - 2014-05-09 19:38 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\.minecraft 2014-05-18 14:25 - 2014-05-18 14:25 - 00017791 _____ () C:\Users\Timmy\Downloads\Download.htm 2014-05-18 14:25 - 2014-05-18 14:25 - 00017791 _____ () C:\Users\Timmy\Downloads\Download (1).htm 2014-05-18 08:31 - 2014-04-15 08:26 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-24558719-2126205106-1827937244-1004Core.job 2014-05-17 16:28 - 2013-10-14 21:05 - 00000000 ____D () C:\Users\Timmy\Desktop\Alles 2014-05-15 19:46 - 2014-05-15 19:46 - 00000000 ____D () C:\Users\Timmy\Documents\Razer 2014-05-15 19:46 - 2014-05-15 19:46 - 00000000 ____D () C:\Users\Timmy\AppData\Local\Razer_Inc 2014-05-15 19:44 - 2014-05-15 19:44 - 00000000 ____D () C:\Users\Timmy\AppData\Local\Razer 2014-05-15 19:44 - 2014-05-15 19:44 - 00000000 ____D () C:\ProgramData\Razer 2014-05-15 19:44 - 2014-05-15 19:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer 2014-05-15 19:44 - 2014-05-15 19:44 - 00000000 ____D () C:\Program Files\Razer 2014-05-15 19:43 - 2014-05-15 19:39 - 41954352 _____ (Razer Inc. ) C:\Users\Timmy\Downloads\RazerGameBoosterSetup_4.2.45.0.exe 2014-05-15 17:47 - 2014-05-15 17:46 - 00818889 _____ () C:\Users\Timmy\Downloads\OptiFine_1.7.4_HD_U_D1.jar 2014-05-15 17:40 - 2014-05-15 17:40 - 00785243 _____ () C:\Users\Timmy\Downloads\OptiFine_1.7.2_HD_D1.jar 2014-05-15 17:40 - 2014-05-15 17:40 - 00539717 _____ () C:\Users\Timmy\Downloads\optifine_1.7.2.zip 2014-05-15 17:38 - 2014-05-15 17:38 - 00030566 _____ () C:\Users\Timmy\Downloads\§6Paolos §aLagLess §4Shaders §cv03 §1RC7 §eLite.zip 2014-05-15 17:34 - 2014-05-15 17:34 - 00445865 _____ () C:\Users\Timmy\Downloads\voxelmap-1.7.2-1.0.jar 2014-05-15 17:32 - 2014-05-15 17:32 - 00066184 _____ () C:\Users\Timmy\Downloads\yatc_b0.9.1_1.4.6.zip 2014-05-15 16:51 - 2014-05-15 16:51 - 00033217 _____ () C:\Users\Timmy\Downloads\§6Paolos §aLagLess §4Shaders §cv03 §3RC8.zip 2014-05-15 16:50 - 2014-05-15 16:50 - 00026598 _____ () C:\Users\Timmy\Downloads\MrMeep_x3s Shaders v04.0 RC4.zip 2014-05-15 16:34 - 2014-05-15 16:34 - 00811462 _____ () C:\Users\Timmy\Downloads\OptiFine_1.7.2_HD_U_D1.jar 2014-05-15 16:34 - 2014-05-15 16:34 - 00064982 _____ () C:\Users\Timmy\Downloads\seus-v10.1-Preview2.zip 2014-05-15 16:25 - 2014-05-15 16:25 - 02530401 _____ () C:\Users\Timmy\Downloads\forge-1.7.2-10.12.0.997-installer.jar 2014-05-15 16:24 - 2014-05-15 16:24 - 00183946 _____ () C:\Users\Timmy\Downloads\ShadersModCore-v2.3.0-beta-mc1.7.2-f997.jar 2014-05-15 16:21 - 2014-05-15 16:21 - 00177465 _____ () C:\Users\Timmy\Downloads\ShadersModCore-v2.3.13mc1.7.4-zip.zip 2014-05-15 16:13 - 2014-05-15 16:12 - 00202061 _____ () C:\Users\Timmy\Downloads\ShadersModCore-v2.3.12-mc1.7.2-f1040.jar 2014-05-15 16:13 - 2014-05-15 16:12 - 00046267 _____ () C:\Users\Timmy\Downloads\SEUS-v10.1-Ultra.zip 2014-05-15 16:07 - 2014-05-15 16:07 - 02632153 _____ () C:\Users\Timmy\Downloads\forge-1.7.2-10.12.0.1024-installer.jar 2014-05-15 16:02 - 2014-05-15 16:02 - 00000000 ____D () C:\ProgramData\AllaboutApp 2014-05-15 16:02 - 2013-11-25 21:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-15 16:02 - 2013-11-25 21:56 - 00000000 ____D () C:\Program Files\Avira 2014-05-14 20:25 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-05-14 19:02 - 2014-05-14 19:02 - 02630583 _____ () C:\Users\Timmy\Downloads\forge-1.7.2-10.12.0.1040-installer.jar 2014-05-14 18:55 - 2014-05-14 18:55 - 03685975 _____ () C:\Users\Timmy\Downloads\Minecraft Force Op 1.7.9.zip 2014-05-14 18:52 - 2014-05-14 18:52 - 00469713 _____ () C:\Users\Timmy\Downloads\MINECRAFT_FORCEOP_2014.RAR 2014-05-14 17:21 - 2014-05-06 17:00 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-14 17:05 - 2013-07-12 17:00 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-14 17:02 - 2009-11-09 12:03 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-14 13:37 - 2014-05-14 13:36 - 06647543 _____ () C:\Users\Timmy\Downloads\Nodus.zip 2014-05-14 13:22 - 2014-05-14 13:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-05-14 13:22 - 2014-05-14 13:22 - 00000000 ____D () C:\Program Files\LogMeIn Hamachi 2014-05-14 06:43 - 2012-08-12 14:43 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-05-14 06:43 - 2011-09-12 17:02 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-05-13 18:28 - 2014-05-13 18:28 - 00000000 ____D () C:\Users\Timmy\Documents\BIS Core Engine 2014-05-13 18:27 - 2014-05-13 18:27 - 13987015 _____ () C:\Users\Timmy\Downloads\DayZ SA Multiplayer Crack.zip 2014-05-13 17:18 - 2014-05-13 17:18 - 00254645 _____ () C:\Users\Timmy\Downloads\[1.7.2]ReiMinimap_v3.4_03beta.zip 2014-05-13 17:15 - 2014-05-13 17:14 - 28062081 _____ () C:\Users\Timmy\Downloads\Sphax PureBDcraft 128x MC17.zip 2014-05-13 16:51 - 2014-05-13 16:49 - 19329130 _____ () C:\Users\Timmy\Downloads\DayZ By NotAwim for HunteR26RuS 1.5.2 Modify.zip 2014-05-12 14:54 - 2014-05-12 14:54 - 00000000 ____D () C:\Users\Timmy\AppData\Roaming\.firefox 2014-05-12 14:52 - 2014-05-12 14:51 - 06647663 _____ () C:\Users\Timmy\Downloads\Nodus 1.7.9.zip 2014-05-12 07:26 - 2014-05-31 21:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-05-31 21:50 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:25 - 2014-05-31 21:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-11 18:06 - 2014-04-19 16:18 - 00000000 ____D () C:\Users\Timmy\Desktop\Hardcore Reloaded (2) 2014-05-11 18:03 - 2014-05-11 17:08 - 1197047898 _____ () C:\Users\Timmy\Downloads\Hardcore-RELOADED_24_01.rar 2014-05-11 17:07 - 2014-05-11 17:07 - 15568473 _____ () C:\Users\Timmy\Downloads\Hardcore-RELOADED_patcher (1).rar 2014-05-11 17:07 - 2014-05-11 17:04 - 08242902 _____ () C:\Users\Timmy\Downloads\Hardcore-RELOADED_patcher.rar 2014-05-10 22:56 - 2014-05-10 22:56 - 00000000 ____D () C:\Users\Timmy\AppData\Local\Skype 2014-05-10 22:56 - 2014-05-10 22:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-05-10 22:55 - 2014-05-10 22:55 - 01678496 _____ (Skype Technologies S.A.) C:\Users\Timmy\Downloads\SkypeSetup (1).exe 2014-05-10 16:00 - 2014-05-10 15:57 - 49268534 _____ () C:\Users\Timmy\Downloads\LIFE 128x (Vers. 81).zip 2014-05-10 09:24 - 2014-05-09 19:37 - 01771520 _____ (TeamExtreme) C:\Users\Timmy\Downloads\Minecraft.exe 2014-05-09 20:09 - 2014-05-09 20:09 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-05-09 20:09 - 2014-05-09 20:09 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-05-09 20:09 - 2014-05-09 20:09 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-05-09 20:09 - 2014-05-09 20:09 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-05-09 20:09 - 2014-05-09 20:09 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-09 20:09 - 2014-05-09 20:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-09 20:09 - 2014-05-09 20:09 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-05-09 20:06 - 2014-05-09 20:05 - 00921512 _____ (Oracle Corporation) C:\Users\Timmy\Downloads\chromeinstall-7u55 (1).exe 2014-05-09 18:18 - 2014-05-09 18:18 - 00000009 _____ () C:\Users\Timmy\Downloads\ad_down.htm 2014-05-09 17:34 - 2013-01-13 22:05 - 00001265 _____ () C:\Users\Timmy\Desktop\chrome - Verknüpfung.lnk 2014-05-09 17:27 - 2014-05-09 17:26 - 00255189 _____ () C:\Users\Timmy\Downloads\Mineshafter-launcher.jar 2014-05-09 17:15 - 2014-05-09 17:15 - 00643272 _____ () C:\Users\Timmy\Downloads\MineCraftSetup.exe 2014-05-09 09:06 - 2014-05-14 13:29 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 09:04 - 2014-05-14 13:29 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-08 15:09 - 2014-05-08 15:07 - 04582789 _____ () C:\Users\Timmy\Downloads\m2k-mod_Pserver.zip 2014-05-07 22:30 - 2014-05-07 22:28 - 03757782 _____ () C:\Users\Timmy\Downloads\Item Creator.zip 2014-05-07 22:14 - 2014-05-07 22:09 - 23488196 _____ () C:\Users\Timmy\Downloads\MultiHack (1).rar 2014-05-07 21:58 - 2014-05-07 21:52 - 23488196 _____ () C:\Users\Timmy\Downloads\MultiHack.rar 2014-05-07 21:44 - 2014-05-07 21:44 - 00000000 ___SD () C:\Users\Timmy\AppData\Roaming\Frutas 2014-05-07 21:43 - 2014-05-07 21:43 - 00000000 ___HD () C:\Users\Timmy\Desktop\TempInstall 2014-05-07 21:43 - 2014-05-07 21:42 - 01151644 _____ () C:\Users\Timmy\Downloads\Bot_Metin2.rar 2014-05-07 21:38 - 2014-05-07 21:38 - 00000000 ____D () C:\Users\Timmy\Documents\My Cheat Tables 2014-05-07 21:35 - 2014-05-07 21:34 - 08065840 _____ (Cheat Engine ) C:\Users\Timmy\Downloads\CheatEngine63.exe 2014-05-07 16:32 - 2014-05-07 16:31 - 03511609 _____ () C:\Users\Timmy\Downloads\Metin 2 Yang Hack.rar 2014-05-07 16:24 - 2014-05-07 16:22 - 08435712 _____ () C:\Users\Timmy\Downloads\archpr454_setup_en.msi 2014-05-07 08:39 - 2014-05-07 08:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2 2014-05-05 13:54 - 2014-05-05 13:54 - 00000000 ____D () C:\Users\Timmy\AppData\Local\Gameforge4d 2014-05-05 13:53 - 2014-05-05 13:53 - 20155712 _____ (Gameforge ) C:\Users\Timmy\Downloads\Metin2_GameforgeLiveSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-06-01 10:21 ==================== End Of Log ============================ ...und hier die Addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:02-06-2014 Ran by Timmy at 2014-06-03 06:58:29 Running from C:\Users\Timmy\Downloads\FRST-OlderVersion Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader X (10.1.4) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.4 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.) Avira (Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) Belkin 54Mbps Wireless Network Adapter (HKLM\...\{F3759A9F-7AFA-4FB4-8DF1-53F26B979DEE}) (Version: 1.00.01 - Belkin) CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform) Command & Conquer Generals (Version: 0.50.0000 - Electronic Arts) Hidden Cry of Fear (HKLM\...\Steam App 223710) (Version: - Team Psykskallar) DayZ (HKLM\...\Steam App 221100) (Version: - Bohemia Interactive) ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - ) Facebook Messenger 2.1.4651.0 (HKLM\...\{17D26CDD-B87C-412B-92F0-2D5DD4313522}) (Version: 2.1.4651.0 - Facebook) Facebook Messenger 2.1.4814.0 (HKLM\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook) Gameforge Live 2.0.3 (HKLM\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.3 - Gameforge) Google Chrome (HKLM\...\Google Chrome) (Version: 34.0.1847.131 - Google Inc.) Google Update Helper (Version: 1.3.23.9 - Google Inc.) Hidden iCloud (HKLM\...\{20C6FF70-690B-4DF7-8F5D-269DD3A7FD23}) (Version: 3.0.2.163 - Apple Inc.) iTunes (HKLM\...\{C197BC08-3D82-4651-8886-E68C21578A38}) (Version: 11.1.3.8 - Apple Inc.) Java 7 Update 55 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) LogMeIn Hamachi (HKLM\...\LogMeIn Hamachi) (Version: 2.2.0.193 - LogMeIn, Inc.) LogMeIn Hamachi (Version: 2.2.0.193 - LogMeIn, Inc.) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Metin2 (HKLM\...\Metin2_is1) (Version: - Gameforge 4D GmbH) Microsoft .NET Framework 1.1 (HKLM\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.10411.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Mozilla Firefox 29.0.1 (x86 de) (HKLM\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) No More Room in Hell (HKLM\...\Steam App 224260) (Version: - No More Room in Hell Team) PAYDAY 2 (HKLM\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.) Razer Game Booster (HKLM\...\Razer Game Booster_is1) (Version: 4.2.45.0 - Razer Inc.) San Andreas Mod Installer (HKLM\...\San Andreas Mod Installer1.0) (Version: - ) San Andreas Mod Installer (HKLM\...\San Andreas Mod Installer1.1) (Version: 1.1 - cpmusick) Sirius MT2 Version 20.13 (HKLM\...\{831D4B74-7A92-4363-869D-524876C480B1}_is1) (Version: 20.13 - Sirius MT2) Skype™ 6.16 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.) Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TechPowerUp GPU-Z (HKLM\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) TP-LINK TL-WDN3200 Driver (HKLM\...\{C0C6BCBC-0884-4C66-B5EF-0B7668FE2B10}) (Version: 1.3.1 - TP-LINK) TP-LINK TL-WN821N Driver (HKLM\...\{26B52E5B-1620-4676-9B46-B6C56B8105CE}) (Version: 1.2.1 - TP-LINK) WinRAR 5.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Restore Points ========================= 19-05-2014 04:21:05 DirectX wurde installiert 27-05-2014 16:50:07 Geplanter Prüfpunkt 31-05-2014 16:18:49 Windows Modules Installer 31-05-2014 19:35:37 Windows Update 31-05-2014 20:08:16 zoek.exe restore point 01-06-2014 14:40:02 Windows Update 01-06-2014 20:44:57 Removed Advanced Archive Password Recovery 01-06-2014 20:45:45 Removed Apple Application Support 01-06-2014 20:46:22 Removed Apple Mobile Device Support 01-06-2014 20:46:58 Removed Apple Software Update 01-06-2014 20:47:31 Removed iTunes ==================== Hosts content: ========================== 2009-07-14 04:04 - 2014-05-31 21:14 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0A334AE4-C5ED-48D8-8A2A-F7C61B869309} - System32\Tasks\{27DC7C2A-217A-4DB3-960B-A7AB2D37AECD} => Firefox.exe hxxp://ui.skype.com/ui/0/6.0.0.126/de/abandoninstall?page=tsProgressBar Task: {10293B7D-2158-417E-BFC7-712E3A9078B9} - System32\Tasks\{BACF188D-C607-455E-8456-54AAEF610087} => C:\Users\Lukas\Desktop\Games\Left 4 Dead 2\l4d2loader.exe Task: {1F8B9C92-45B5-49CF-B181-72DED67D399A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-24558719-2126205106-1827937244-1004Core => C:\Users\Timmy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-04-15] (Facebook Inc.) Task: {2B69F114-6933-4CEF-824E-6B91E9A6D2A3} - System32\Tasks\{55501A5A-588F-4DA2-A4EB-101B0EAB3333} => Firefox.exe hxxp://ui.skype.com/ui/0/6.9.0.106/de/abandoninstall?page=tsProgressBar Task: {3566B02B-7C8E-47CF-87A2-EDD1D8874A0E} - System32\Tasks\{E7B42520-65B0-4C3D-95A2-7FFD252476B5} => C:\Users\Lukas\Desktop\Games\Left 4 Dead 2\left4dead2.exe Task: {49CC7660-60A6-432E-A727-D77B82396F81} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-24558719-2126205106-1827937244-1004UA => C:\Users\Timmy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-04-15] (Facebook Inc.) Task: {58B6B4AE-4336-416C-945C-7161BF4FA0A0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-26] (Google Inc.) Task: {6DDA0401-A004-4B2F-99AA-1C9E38709FF5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-26] (Google Inc.) Task: {9C649579-95C3-471D-A6F2-649C29AAB8C5} - System32\Tasks\Apple Diagnostics => C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe [2013-09-14] (Apple Inc.) Task: {AB09EA26-2657-4198-995A-AFB4139CF1A7} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {B7AAA789-EC59-4E9E-AB01-226DC5499190} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd) Task: {C542E156-B5EB-4FEB-B911-8C2B5A061457} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated) Task: {F4CFF5D1-F170-4802-817E-201C3408E5FF} - System32\Tasks\{353B5FF4-FD13-45F6-B58C-312F8537F08F} => C:\Users\Lukas\Desktop\Games\Left 4 Dead 2\left4dead2.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-24558719-2126205106-1827937244-1004Core.job => C:\Users\Timmy\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-24558719-2126205106-1827937244-1004UA.job => C:\Users\Timmy\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-12-10 14:13 - 2012-12-10 14:13 - 00066872 _____ () C:\Windows\system32\PnkBstrA.exe 2014-05-05 10:37 - 2014-05-05 10:37 - 00138320 _____ () C:\Program Files\Avira\My Avira\Avira.OE.NativeCore.dll 2014-05-05 10:37 - 2014-05-05 10:37 - 00065616 _____ () C:\Program Files\Avira\My Avira\Avira.OE.AvConnectorNative.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^Users^Timmy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk => C:\Windows\pss\Facebook Messenger.lnk.Startup MSCONFIG\startupfolder: C:^Users^Timmy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^SleepTimer.lnk => C:\Windows\pss\SleepTimer.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: Facebook Update => "C:\Users\Timmy\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver MSCONFIG\startupreg: Firewall => "C:\Program Files\Java\jre7\bin\javaw.exe" -jar "C:\Users\Timmy\AppData\Roaming\Frutas\servidorcito.jar" MSCONFIG\startupreg: GoogleChromeAutoLaunch_EEB5F8AA0ED462375287D8C91BC9B185 => "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window MSCONFIG\startupreg: iCloudServices => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start MSCONFIG\startupreg: RazerGameBooster => C:\Program Files\Razer\Razer Game Booster\RazerGameBooster.exe -autorun MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Steam => "C:\Program Files\Steam\steam.exe" -silent MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: HL-DT-ST DVDRAM GH41N ATA Device Description: CD-ROM-Laufwerk Class Guid: {4d36e965-e325-11ce-bfc1-08002be10318} Manufacturer: (Standard-CD-ROM-Laufwerke) Service: cdrom Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19) Resolution: A registry problem was detected. This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options: On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver. ==================== Event log errors: ========================= Application errors: ================== Error: (06/02/2014 04:29:01 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (06/02/2014 04:29:01 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (06/02/2014 04:29:01 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 7010) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 3058) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 3028) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 9002) (User: ) Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 7042) (User: ) Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (06/03/2014 06:53:28 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (06/03/2014 06:53:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Avira Browser-Schutz" ist vom Dienst "Avira Echtzeit-Scanner" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1053 Error: (06/03/2014 06:53:21 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Avira Echtzeit-Scanner" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/03/2014 06:53:21 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Avira Echtzeit-Scanner erreicht. Error: (06/03/2014 06:53:20 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Avira Planer" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/03/2014 06:53:20 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Avira Planer erreicht. Error: (06/03/2014 06:53:11 AM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/03/2014 06:53:11 AM) (Source: atikmdag) (EventID: 19468) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (06/02/2014 04:59:17 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (06/02/2014 04:23:15 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office Sessions: ========================= Error: (06/02/2014 04:29:01 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (06/02/2014 04:29:01 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (06/02/2014 04:29:01 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 7010) (User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 3058) (User: ) Description: Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 3028) (User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Search.TripoliIndexer Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Search.JetPropStore Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 9002) (User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (06/02/2014 04:23:15 PM) (Source: Windows Search Service) (EventID: 7042) (User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) The catalog is corrupt ==================== Memory info =========================== Percentage of memory in use: 30% Total physical RAM: 3071.23 MB Available physical RAM: 2132.96 MB Total Pagefile: 6140.76 MB Available Pagefile: 5157.1 MB Total Virtual: 2047.88 MB Available Virtual: 1930.35 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:683.44 GB) (Free:550.13 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:0.2 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: DB52735D) Partition 1: (Not Active) - (Size=15 GB) - (Type=27) Partition 2: (Not Active) - (Size=200 MB) - (Type=07 NTFS) Partition 3: (Active) - (Size=683 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
03.06.2014, 18:20 | #19 |
/// TB-Ausbilder | Browser Startet nicht, sowie jegliche Antiviren Programme, Downloadgeschwindigkeit sehr gering Avira nochmal installieren, dann über die Systemsteuerung deinstallieren. Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit) | SystemLook (64 bit)
|
05.06.2014, 05:31 | #20 |
| Browser Startet nicht, sowie jegliche Antiviren Programme, Downloadgeschwindigkeit sehr gering Liebes Trojaner-Board Team Hier die SystemLook.txt Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff Log created at 06:30 on 05/06/2014 by Timmy Administrator - Elevation successful ========== dir ========== C:\ProgramData\8DD15FDB8EADA1264B04FE08F85A2FBF - Parameters: "/s" ---Files--- None found. No folders found. -= EOF =- |
05.06.2014, 14:58 | #21 |
/// TB-Ausbilder | Browser Startet nicht, sowie jegliche Antiviren Programme, Downloadgeschwindigkeit sehr gering Reste entfernen Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start C:\ProgramData\8DD15FDB8EADA1264B04FE08F85A2FBF CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HapPy2Savea.HapPy2Savea" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HapPy2Savea.HapPy2Savea.2.5" /f Reboot: end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1 Du verwendest veraltete Software auf deinem Rechner, was ein Sicherheitsrisiko darstellt. Daher solltest du veraltete Software deinstallieren und anschließend die aktuellste Version installieren. Folge dem Pfad Start > Systemsteuerung > Sofware / Programme deinstallieren. Deinstalliere die folgenden Programme von deinem Rechner:
Downloade und installiere dir bitte nun:Starte deinen Rechner nach der Installation neu auf. Schritt 2 Die Reihenfolge ist hier entscheidend.
Schritt 3 Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Performance
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
09.06.2014, 10:47 | #22 |
/// TB-Ausbilder | Browser Startet nicht, sowie jegliche Antiviren Programme, Downloadgeschwindigkeit sehr gering Ich bin froh, dass wir helfen konnten In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest: Lob, Kritik und Wünsche Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank! Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |
Themen zu Browser Startet nicht, sowie jegliche Antiviren Programme, Downloadgeschwindigkeit sehr gering |
downloadgeschwindigkeit, pup.optional.4shared, pup.optional.adpeak.a, pup.optional.amonetize, pup.optional.amonetize.a, pup.optional.appready, pup.optional.bechiro, pup.optional.coupondownloader.a, pup.optional.domalq, pup.optional.feven.a, pup.optional.installerex, pup.optional.multiplug.a, pup.optional.outbrowse, pup.optional.searchcertifiedtb.a, pup.optional.snboost.a, pup.optional.snbooster.a, pup.optional.softonic, pup.optional.softonic.a, pup.optional.somoto, pup.optional.somoto.a, pup.optional.superfish.a, pup.optional.tarma.a, spyware.msil, trojan.ardamax, trojan.keylogger.msil, trojan.sprotector |