|
Log-Analyse und Auswertung: TR/Drop.Softomat.AN/Windows 7 64 BitWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
05.06.2014, 15:57 | #1 |
| TR/Drop.Softomat.AN/Windows 7 64 Bit Schon wieder ich :-/ Avira und Malwarebytes haben beide 2 Trojaner gefunden. Keine Ahnung wo die schon wieder her kommen Kann mir jemand helfen? Code:
ATTFilter Avira Free Antivirus Erstellungsdatum der Reportdatei: Donnerstag, 5. Juni 2014 16:08 Das Programm läuft als uneingeschränkte Vollversion. Online-Dienste stehen zur Verfügung. Lizenznehmer : Avira Antivirus Free Seriennummer : 0000149996-AVHOE-0000001 Plattform : Windows 7 Professional Windowsversion : (plain) [6.1.7600] Boot Modus : Normal gebootet Benutzername : David Computername : MONGREL Versionsinformationen: BUILD.DAT : 14.0.4.642 57086 Bytes 09.05.2014 11:16:00 AVSCAN.EXE : 14.0.4.632 1030736 Bytes 27.05.2014 09:29:00 AVSCANRC.DLL : 14.0.4.620 62032 Bytes 27.05.2014 09:29:00 LUKE.DLL : 14.0.4.620 57936 Bytes 27.05.2014 09:29:36 AVSCPLR.DLL : 14.0.4.620 89680 Bytes 27.05.2014 09:29:00 AVREG.DLL : 14.0.4.632 261200 Bytes 27.05.2014 09:28:58 avlode.dll : 14.0.4.638 583760 Bytes 27.05.2014 09:28:57 avlode.rdf : 14.0.4.22 64276 Bytes 15.05.2014 17:06:36 VBASE000.VDF : 7.11.70.0 66736640 Bytes 04.04.2013 09:41:06 VBASE001.VDF : 7.11.74.226 2201600 Bytes 30.04.2013 09:41:06 VBASE002.VDF : 7.11.80.60 2751488 Bytes 28.05.2013 09:41:06 VBASE003.VDF : 7.11.85.214 2162688 Bytes 21.06.2013 09:41:06 VBASE004.VDF : 7.11.91.176 3903488 Bytes 23.07.2013 09:41:06 VBASE005.VDF : 7.11.98.186 6822912 Bytes 29.08.2013 09:41:06 VBASE006.VDF : 7.11.139.38 15708672 Bytes 27.03.2014 14:45:48 VBASE007.VDF : 7.11.152.100 4193792 Bytes 02.06.2014 15:58:07 VBASE008.VDF : 7.11.152.101 2048 Bytes 02.06.2014 15:58:07 VBASE009.VDF : 7.11.152.102 2048 Bytes 02.06.2014 15:58:07 VBASE010.VDF : 7.11.152.103 2048 Bytes 02.06.2014 15:58:07 VBASE011.VDF : 7.11.152.104 2048 Bytes 02.06.2014 15:58:07 VBASE012.VDF : 7.11.152.105 2048 Bytes 02.06.2014 15:58:07 VBASE013.VDF : 7.11.152.227 225280 Bytes 04.06.2014 16:34:27 VBASE014.VDF : 7.11.152.228 2048 Bytes 04.06.2014 16:34:27 VBASE015.VDF : 7.11.152.229 2048 Bytes 04.06.2014 16:34:27 VBASE016.VDF : 7.11.152.230 2048 Bytes 04.06.2014 16:34:27 VBASE017.VDF : 7.11.152.231 2048 Bytes 04.06.2014 16:34:28 VBASE018.VDF : 7.11.152.232 2048 Bytes 04.06.2014 16:34:28 VBASE019.VDF : 7.11.152.233 2048 Bytes 04.06.2014 16:34:28 VBASE020.VDF : 7.11.152.234 2048 Bytes 04.06.2014 16:34:28 VBASE021.VDF : 7.11.152.235 2048 Bytes 04.06.2014 16:34:28 VBASE022.VDF : 7.11.152.236 2048 Bytes 04.06.2014 16:34:28 VBASE023.VDF : 7.11.152.237 2048 Bytes 04.06.2014 16:34:28 VBASE024.VDF : 7.11.152.238 2048 Bytes 04.06.2014 16:34:28 VBASE025.VDF : 7.11.152.239 2048 Bytes 04.06.2014 16:34:28 VBASE026.VDF : 7.11.152.240 2048 Bytes 04.06.2014 16:34:28 VBASE027.VDF : 7.11.152.241 2048 Bytes 04.06.2014 16:34:28 VBASE028.VDF : 7.11.152.242 2048 Bytes 04.06.2014 16:34:28 VBASE029.VDF : 7.11.152.243 2048 Bytes 04.06.2014 16:34:29 VBASE030.VDF : 7.11.152.244 2048 Bytes 04.06.2014 16:34:29 VBASE031.VDF : 7.11.153.56 310784 Bytes 05.06.2014 09:42:26 Engineversion : 8.3.20.4 AEVDF.DLL : 8.3.0.4 118976 Bytes 07.05.2014 14:45:47 AESCRIPT.DLL : 8.1.4.206 528584 Bytes 28.05.2014 16:12:25 AESCN.DLL : 8.3.1.2 135360 Bytes 28.05.2014 16:12:25 AESBX.DLL : 8.2.20.24 1409224 Bytes 08.05.2014 16:43:12 AERDL.DLL : 8.2.0.138 704888 Bytes 25.02.2014 09:41:04 AEPACK.DLL : 8.4.0.24 778440 Bytes 13.05.2014 16:11:50 AEOFFICE.DLL : 8.3.0.4 205000 Bytes 07.05.2014 14:45:47 AEHEUR.DLL : 8.1.4.1092 6762696 Bytes 28.05.2014 16:12:25 AEHELP.DLL : 8.3.1.0 278728 Bytes 28.05.2014 16:12:21 AEGEN.DLL : 8.1.7.26 450752 Bytes 07.05.2014 14:45:47 AEEXP.DLL : 8.4.2.2 237760 Bytes 04.06.2014 16:34:25 AEEMU.DLL : 8.1.3.2 393587 Bytes 25.02.2014 09:41:04 AEDROID.DLL : 8.4.2.24 442568 Bytes 04.06.2014 16:34:26 AECORE.DLL : 8.3.1.0 241864 Bytes 28.05.2014 16:12:20 AEBB.DLL : 8.1.1.4 53619 Bytes 25.02.2014 09:41:04 AVWINLL.DLL : 14.0.4.620 24144 Bytes 27.05.2014 09:28:53 AVPREF.DLL : 14.0.4.632 50256 Bytes 27.05.2014 09:28:58 AVREP.DLL : 14.0.4.620 219216 Bytes 27.05.2014 09:28:58 AVARKT.DLL : 14.0.4.632 225872 Bytes 27.05.2014 09:28:54 AVEVTLOG.DLL : 14.0.4.620 182352 Bytes 27.05.2014 09:28:56 SQLITE3.DLL : 14.0.4.620 452176 Bytes 27.05.2014 09:29:40 AVSMTP.DLL : 14.0.4.620 76368 Bytes 27.05.2014 09:29:01 NETNT.DLL : 14.0.4.620 13392 Bytes 27.05.2014 09:29:36 RCIMAGE.DLL : 14.0.4.620 4979280 Bytes 27.05.2014 09:28:53 RCTEXT.DLL : 14.0.4.620 73808 Bytes 27.05.2014 09:28:53 Konfiguration für den aktuellen Suchlauf: Job Name..............................: Vollständige Systemprüfung Konfigurationsdatei...................: C:\Program Files (x86)\Avira\AntiVir Desktop\sysscan.avp Protokollierung.......................: standard Primäre Aktion........................: Interaktiv Sekundäre Aktion......................: Ignorieren Durchsuche Masterbootsektoren.........: ein Durchsuche Bootsektoren...............: ein Bootsektoren..........................: C:, D:, E:, Durchsuche aktive Programme...........: ein Laufende Programme erweitert..........: ein Durchsuche Registrierung..............: ein Suche nach Rootkits...................: ein Integritätsprüfung von Systemdateien..: aus Prüfe alle Dateien....................: Alle Dateien Durchsuche Archive....................: ein Rekursionstiefe einschränken..........: 20 Archiv Smart Extensions...............: ein Makrovirenheuristik...................: ein Dateiheuristik........................: erweitert Beginn des Suchlaufs: Donnerstag, 5. Juni 2014 16:08 Der Suchlauf über die Bootsektoren wird begonnen: Bootsektor 'HDD0(C:, D:, E:)' [INFO] Es wurde kein Virus gefunden! Der Suchlauf nach versteckten Objekten wird begonnen. Der Suchlauf über gestartete Prozesse wird begonnen: Durchsuche Prozess 'svchost.exe' - '52' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '36' Modul(e) wurden durchsucht Durchsuche Prozess 'atiesrxx.exe' - '26' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '94' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '116' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '148' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '76' Modul(e) wurden durchsucht Durchsuche Prozess 'RtkAudioService64.exe' - '32' Modul(e) wurden durchsucht Durchsuche Prozess 'RAVBg64.exe' - '45' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '76' Modul(e) wurden durchsucht Durchsuche Prozess 'atieclxx.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '72' Modul(e) wurden durchsucht Durchsuche Prozess 'spoolsv.exe' - '101' Modul(e) wurden durchsucht Durchsuche Prozess 'sched.exe' - '56' Modul(e) wurden durchsucht Durchsuche Prozess 'armsvc.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'avguard.exe' - '106' Modul(e) wurden durchsucht Durchsuche Prozess 'HWDeviceService64.exe' - '32' Modul(e) wurden durchsucht Durchsuche Prozess 'HeciServer.exe' - '27' Modul(e) wurden durchsucht Durchsuche Prozess 'IProsetMonitor.exe' - '22' Modul(e) wurden durchsucht Durchsuche Prozess 'ouc.exe' - '30' Modul(e) wurden durchsucht Durchsuche Prozess 'mbamscheduler.exe' - '40' Modul(e) wurden durchsucht Durchsuche Prozess 'mbamservice.exe' - '55' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '56' Modul(e) wurden durchsucht Durchsuche Prozess 'Avira.OE.ServiceHost.exe' - '121' Modul(e) wurden durchsucht Durchsuche Prozess 'taskhost.exe' - '58' Modul(e) wurden durchsucht Durchsuche Prozess 'mbam.exe' - '125' Modul(e) wurden durchsucht Durchsuche Prozess 'Dwm.exe' - '35' Modul(e) wurden durchsucht Durchsuche Prozess 'DCSHelper.exe' - '36' Modul(e) wurden durchsucht Durchsuche Prozess 'avshadow.exe' - '29' Modul(e) wurden durchsucht Durchsuche Prozess 'RAVCpl64.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'rundll32.exe' - '57' Modul(e) wurden durchsucht Durchsuche Prozess 'taskeng.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'SearchIndexer.exe' - '59' Modul(e) wurden durchsucht Durchsuche Prozess 'GoogleUpdate.exe' - '51' Modul(e) wurden durchsucht Durchsuche Prozess 'LCore.exe' - '76' Modul(e) wurden durchsucht Durchsuche Prozess 'wmpnetwk.exe' - '116' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '37' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '69' Modul(e) wurden durchsucht Durchsuche Prozess 'RocketDock.exe' - '50' Modul(e) wurden durchsucht Durchsuche Prozess 'netsession_win.exe' - '47' Modul(e) wurden durchsucht Durchsuche Prozess 'ScanToPCActivationApp.exe' - '58' Modul(e) wurden durchsucht Durchsuche Prozess 'netsession_win.exe' - '72' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '55' Modul(e) wurden durchsucht Durchsuche Prozess 'iusb3mon.exe' - '37' Modul(e) wurden durchsucht Durchsuche Prozess 'KoneXTDMonitor.exe' - '54' Modul(e) wurden durchsucht Durchsuche Prozess 'Creative Cloud.exe' - '125' Modul(e) wurden durchsucht Durchsuche Prozess 'avgnt.exe' - '119' Modul(e) wurden durchsucht Durchsuche Prozess 'Avira.OE.Systray.exe' - '130' Modul(e) wurden durchsucht Durchsuche Prozess 'hpwuschd2.exe' - '30' Modul(e) wurden durchsucht Durchsuche Prozess 'MOM.exe' - '69' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiprvse.exe' - '33' Modul(e) wurden durchsucht Durchsuche Prozess 'AdobeIPCBroker.exe' - '29' Modul(e) wurden durchsucht Durchsuche Prozess 'raptr.exe' - '133' Modul(e) wurden durchsucht Durchsuche Prozess 'CCC.exe' - '219' Modul(e) wurden durchsucht Durchsuche Prozess 'IAStorIcon.exe' - '70' Modul(e) wurden durchsucht Durchsuche Prozess 'raptr_im.exe' - '103' Modul(e) wurden durchsucht Durchsuche Prozess 'winamp.exe' - '167' Modul(e) wurden durchsucht Durchsuche Prozess 'raptr_ep64.exe' - '44' Modul(e) wurden durchsucht Durchsuche Prozess 'CoreSync.exe' - '99' Modul(e) wurden durchsucht Durchsuche Prozess 'unsecapp.exe' - '34' Modul(e) wurden durchsucht Durchsuche Prozess 'Adobe CEF Helper.exe' - '54' Modul(e) wurden durchsucht Durchsuche Prozess 'ts3client_win32.exe' - '106' Modul(e) wurden durchsucht Durchsuche Prozess 'IAStorDataMgrSvc.exe' - '92' Modul(e) wurden durchsucht Durchsuche Prozess 'jhi_service.exe' - '34' Modul(e) wurden durchsucht Durchsuche Prozess 'LMS.exe' - '93' Modul(e) wurden durchsucht Durchsuche Prozess 'PrivacyIconClient.exe' - '57' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '131' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '69' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'HPNetworkCommunicator.exe' - '50' Modul(e) wurden durchsucht Durchsuche Prozess 'splwow64.exe' - '37' Modul(e) wurden durchsucht Durchsuche Prozess 'explorer.exe' - '180' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'Skype.exe' - '159' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiprvse.exe' - '48' Modul(e) wurden durchsucht Durchsuche Prozess 'taskhost.exe' - '31' Modul(e) wurden durchsucht Durchsuche Prozess 'avcenter.exe' - '136' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'QuickTimePlayer.exe' - '131' Modul(e) wurden durchsucht Durchsuche Prozess 'avscan.exe' - '122' Modul(e) wurden durchsucht Durchsuche Prozess 'vssvc.exe' - '47' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'SearchProtocolHost.exe' - '29' Modul(e) wurden durchsucht Durchsuche Prozess 'SearchFilterHost.exe' - '27' Modul(e) wurden durchsucht Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '16' Modul(e) wurden durchsucht Durchsuche Prozess 'wininit.exe' - '26' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht Durchsuche Prozess 'services.exe' - '33' Modul(e) wurden durchsucht Durchsuche Prozess 'lsass.exe' - '66' Modul(e) wurden durchsucht Durchsuche Prozess 'lsm.exe' - '16' Modul(e) wurden durchsucht Durchsuche Prozess 'winlogon.exe' - '31' Modul(e) wurden durchsucht Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen: Die Registry wurde durchsucht ( '1245' Dateien ). Der Suchlauf über die ausgewählten Dateien wird begonnen: Beginne mit der Suche in 'C:\' C:\Windows\System32\audiodg.exe [FUND] Ist das Trojanische Pferd TR/Drop.Softomat.AN C:\Windows\winsxs\amd64_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.1.7600.16385_none_d294b5cdfe50c681\audiodg.exe [FUND] Ist das Trojanische Pferd TR/Drop.Softomat.AN Beginne mit der Suche in 'D:\' Beginne mit der Suche in 'E:\' Beginne mit der Desinfektion: C:\Windows\winsxs\amd64_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.1.7600.16385_none_d294b5cdfe50c681\audiodg.exe [FUND] Ist das Trojanische Pferd TR/Drop.Softomat.AN [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4cc2050b.qua' verschoben! C:\Windows\System32\audiodg.exe [FUND] Ist das Trojanische Pferd TR/Drop.Softomat.AN [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '78aa102a.qua' verschoben! Ende des Suchlaufs: Donnerstag, 5. Juni 2014 16:50 Benötigte Zeit: 25:40 Minute(n) Der Suchlauf wurde vollständig durchgeführt. 36967 Verzeichnisse wurden überprüft 530634 Dateien wurden geprüft 2 Viren bzw. unerwünschte Programme wurden gefunden 0 Dateien wurden als verdächtig eingestuft 0 Dateien wurden gelöscht 0 Viren bzw. unerwünschte Programme wurden repariert 2 Dateien wurden in die Quarantäne verschoben 0 Dateien wurden umbenannt 0 Dateien konnten nicht durchsucht werden 530632 Dateien ohne Befall 3306 Archive wurden durchsucht 0 Warnungen 2 Hinweise 593252 Objekte wurden beim Rootkitscan durchsucht 0 Versteckte Objekte wurden gefunden Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 05.06.2014 Suchlauf-Zeit: 15:38:40 Logdatei: v.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.06.05.08 Rootkit Datenbank: v2014.06.02.01 Lizenz: Premium Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 CPU: x64 Dateisystem: NTFS Benutzer: David Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 289157 Verstrichene Zeit: 11 Min, 18 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 Trojan.FakeMS, C:\Windows\System32\audiodg.exe, 1052, Löschen bei Neustart, [4795383cb4c71521977b790dcf3208f8] Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 2 Trojan.FakeMS, C:\Windows\System32\audiodg.exe, Löschen bei Neustart, [4795383cb4c71521977b790dcf3208f8], PUP.Optional.NewTab.A, C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bakijjialdiiboeaknfpmflphhmljfkd_0.localstorage, In Quarantäne, [29b3076db7c460d68d63e60414efe020], Physische Sektoren: 0 (No malicious items detected) (end) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014 Ran by David (administrator) on MONGREL on 05-06-2014 16:55:16 Running from C:\Users\David\Desktop Platform: Windows 7 Professional (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe () D:\Programme\RocketDock\RocketDock.exe (Akamai Technologies, Inc.) C:\Users\David\AppData\Local\Akamai\netsession_win.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe (Akamai Technologies, Inc.) C:\Users\David\AppData\Local\Akamai\netsession_win.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\KoneXTDMonitor.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Raptr, Inc) C:\Program Files (x86)\Raptr\raptr.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Raptr, Inc) C:\Program Files (x86)\Raptr\raptr_im.exe (Nullsoft, Inc.) D:\Programme\Winamp\winamp.exe (Raptr Inc.) C:\Program Files (x86)\Raptr\raptr_ep64.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (TeamSpeak Systems GmbH) D:\Programme\Teamspeak\ts3client_win32.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Apple Inc.) D:\Programme\Quicktime\QuickTimePlayer.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\prevhost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [Cm106Sound] => C:\Windows\Syswow64\cm106.dll [8151040 2009-10-20] (C-Media Corporation) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-09-03] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM-x32\...\Run: [RoccatKoneXTD] => C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\KoneXTDMonitor.EXE [552960 2013-10-25] (ROCCAT GmbH) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2691480 2014-03-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-27] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [182352 2014-05-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] - "C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \mbamdor.exe" "C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware " [54072 2014-05-12] (Malwarebytes Corporation) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [RocketDock] => D:\Programme\RocketDock\RocketDock.exe [495616 2007-09-02] () HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [Akamai NetSession Interface] => C:\Users\David\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55360 2014-05-15] (Raptr, Inc) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [HP Deskjet 3050 J610 series (NET)] => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\MountPoints2: {2b70206c-e4bc-11e3-995e-d050990f215f} - G:\AutoRun.exe HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\MountPoints2: {2b702082-e4bc-11e3-995e-d050990f215f} - G:\AutoRun.exe HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [RocketDock] => D:\Programme\RocketDock\RocketDock.exe [495616 2007-09-02] () HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Akamai NetSession Interface] => C:\Users\David\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55360 2014-05-15] (Raptr, Inc) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HP Deskjet 3050 J610 series (NET)] => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {2b70206c-e4bc-11e3-995e-d050990f215f} - G:\AutoRun.exe HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {2b702082-e4bc-11e3-995e-d050990f215f} - G:\AutoRun.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= SearchScopes: HKCU - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 Tcpip\..\Interfaces\{A395CEDE-D5A6-48E6-8CC2-506A45065462}: [NameServer] FireFox: ======== FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: adobe.com/AdobeExManCCDetect32 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect32.dll (Adobe Systems) FF Plugin HKCU: adobe.com/AdobeExManCCDetect64 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect64.dll (Adobe Systems) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://google.de/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-01] CHR Extension: (Adblock Plus) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-01] CHR Extension: (Type Scout) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\fedokkaolmkkoeedicihicdeppjjeamj [2014-05-01] CHR Extension: (AdBlock) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-01] CHR Extension: (TabJump - Intelligenter Tab-Navigator) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokofmgcicpnjchllaccgedmmmbbnbmf [2014-05-01] CHR Extension: (Google Mail-Checker) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-05-01] CHR Extension: (WGT Golf Game) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpedbpkelbhcbkdaglillalioeeekbpb [2014-05-01] CHR Extension: (Google Mail) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-01] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2014-05-01] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [124496 2014-05-05] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-05-09] () R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2011-06-17] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-27] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-27] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [495376 2013-05-30] (Intel Corporation) U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.) S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [238080 2012-04-23] (Huawei Technologies Co., Ltd.) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-05] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation) U0 phxc; C:\Windows\System32\drivers\otnfbxsx.sys [79064 2014-06-05] (Malwarebytes Corporation) S3 USBMULCD; C:\Windows\System32\drivers\CM10664.sys [1307648 2009-10-01] (C-Media Electronics Inc) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-05 16:55 - 2014-06-05 16:55 - 00018454 _____ () C:\Users\David\Desktop\FRST.txt 2014-06-05 16:54 - 2014-06-05 16:54 - 02068992 _____ (Farbar) C:\Users\David\Desktop\FRST64.exe 2014-06-05 16:53 - 2014-06-05 16:53 - 00001510 _____ () C:\Users\David\Desktop\v.txt 2014-06-05 15:59 - 2014-06-05 15:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\Apple Computer 2014-06-05 15:59 - 2014-06-05 15:59 - 00000000 ____D () C:\Users\David\AppData\Local\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-06-05 15:58 - 2014-06-05 15:58 - 00001576 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Users\David\AppData\Local\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-06-05 15:54 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-06-05 15:50 - 2014-06-05 15:50 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\otnfbxsx.sys 2014-06-05 15:47 - 2014-06-05 15:48 - 41945432 _____ (Apple Inc.) C:\Users\David\Downloads\QuickTimeInstaller.exe 2014-06-05 15:45 - 2014-06-05 15:46 - 00000000 ____D () C:\Users\David\AppData\Roaming\vlc 2014-06-05 15:40 - 2014-06-05 15:41 - 25531584 _____ () C:\Users\David\Downloads\vlc-2.1.3-win32.exe 2014-06-03 14:47 - 2014-06-03 14:51 - 44199212 _____ () C:\Users\David\Downloads\Pentakill-SmiteandIgnite.zip 2014-06-03 14:17 - 2014-05-21 16:18 - 01193472 _____ () C:\Users\David\Desktop\OBS.exe 2014-06-03 14:15 - 2014-06-03 14:15 - 00000000 ____D () C:\Users\David\AppData\Roaming\OBS 2014-06-03 14:14 - 2014-06-03 14:14 - 00961360 _____ (Chip Digital GmbH) C:\Users\David\Downloads\Open Broadcaster Software - CHIP-Installer.exe 2014-06-02 23:20 - 2014-06-03 14:31 - 16849882 _____ () C:\Users\David\Downloads\Season-4-Overlay-Mega-Pack-by-Temporalcortex.zip 2014-06-02 16:41 - 2014-06-02 16:58 - 00026934 _____ () C:\Users\David\Downloads\debug.log 2014-06-02 16:32 - 2014-06-02 16:32 - 00000796 _____ () C:\Users\Public\Desktop\XSplit Broadcaster.lnk 2014-06-02 16:32 - 2014-06-02 16:32 - 00000000 ____D () C:\Users\David\AppData\Local\SplitMediaLabs 2014-06-02 16:30 - 2014-06-05 16:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-02 16:30 - 2014-06-02 16:30 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-02 16:30 - 2014-06-02 16:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-02 16:30 - 2014-06-02 16:30 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\system32\Macromed 2014-06-02 16:28 - 2014-06-02 16:29 - 42360392 _____ (SplitMediaLabs) C:\Users\David\Downloads\xsplit_bc_installer.exe 2014-06-02 16:21 - 2014-06-02 16:21 - 00000000 ____D () C:\Users\David\AppData\Local\IsolatedStorage 2014-06-02 15:59 - 2014-06-02 16:32 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-06-02 15:59 - 2014-06-02 16:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit 2014-06-02 15:59 - 2014-06-02 15:59 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-06-02 15:58 - 2014-06-02 16:31 - 00000000 ____D () C:\Users\David\AppData\Roaming\SplitmediaLabs 2014-06-02 15:55 - 2014-06-02 15:57 - 46455952 _____ (SplitmediaLabs) C:\Users\David\Downloads\xsplit_gc_installer.exe 2014-05-31 19:39 - 2014-05-31 19:39 - 00111788 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget (1).zip 2014-05-31 19:12 - 2014-05-31 19:12 - 00112213 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget.zip 2014-05-31 15:04 - 2014-06-03 15:23 - 00150528 ___SH () C:\Users\David\Thumbs.db 2014-05-30 15:01 - 2014-06-03 15:23 - 00000132 _____ () C:\Users\David\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen 2014-05-26 18:37 - 2014-05-26 18:37 - 01677440 _____ (Skype Technologies S.A.) C:\Users\David\Downloads\SkypeSetup (1).exe 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_juextctrl_01007.Wdf 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf 2014-05-26 12:07 - 2014-05-26 12:07 - 00001245 _____ () C:\Users\Public\Desktop\Internet Manager.lnk 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Manager 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Internet Manager 2014-05-26 12:07 - 2012-04-26 05:04 - 00450048 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbwwan.sys 2014-05-26 12:07 - 2012-04-23 03:58 - 00238080 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juwwanecm.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00104448 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcacm.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00090112 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00076800 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00030720 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys 2014-05-26 12:07 - 2011-12-31 03:20 - 00225920 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2014-05-26 12:07 - 2011-08-16 10:40 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2014-05-26 12:07 - 2011-08-16 10:40 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01007.dll 2014-05-26 12:07 - 2010-10-08 10:59 - 00032768 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys 2014-05-26 12:07 - 2010-09-26 12:09 - 00022016 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys 2014-05-26 12:07 - 2010-08-06 01:43 - 01001472 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys 2014-05-26 12:07 - 2010-07-27 03:52 - 00117248 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys 2014-05-26 12:07 - 2010-03-20 06:06 - 00013952 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys 2014-05-26 12:06 - 2014-05-26 12:06 - 00000000 ____D () C:\Program Files (x86)\T-Mobile 2014-05-26 12:03 - 2014-05-26 12:08 - 00000000 ____D () C:\ProgramData\DatacardService 2014-05-18 15:41 - 2014-05-18 15:42 - 00000036 _____ () C:\Users\David\Malwarebytes ID.txt 2014-05-12 17:22 - 2014-05-12 17:22 - 00056100 _____ () C:\Windows\SysWOW64\CCCInstall_201405121722165928.log 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\ProgramData\ATI 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-05-12 17:20 - 2014-05-12 17:20 - 00000000 ____D () C:\Program Files\AMD 2014-05-12 17:17 - 2014-05-19 19:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\HpUpdate 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\ProgramData\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\Program Files\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\Program Files (x86)\HP 2014-05-12 17:17 - 2012-10-17 04:31 - 00741480 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPM9311.dll 2014-05-12 17:16 - 2014-05-12 17:18 - 00000000 ____D () C:\Users\David\AppData\Local\HP 2014-05-12 17:16 - 2014-05-12 17:16 - 00000057 _____ () C:\ProgramData\Ament.ini 2014-05-12 17:13 - 2014-05-12 17:15 - 56732448 _____ () C:\Users\David\Downloads\DJ3050_J610_1315.exe 2014-05-12 15:36 - 2014-05-12 15:43 - 269338400 _____ (AMD Inc.) C:\Users\David\Downloads\14-4-win7-win8-win8.1-64-dd-ccc-whql.exe 2014-05-12 00:18 - 2014-05-13 21:27 - 00000000 ____D () C:\Users\David\Documents\dragoon 2014-05-12 00:06 - 2014-06-05 15:38 - 00000000 ____D () C:\Users\David\AppData\Roaming\Raptr 2014-05-12 00:06 - 2014-05-22 19:04 - 00000000 ____D () C:\Program Files (x86)\Raptr 2014-05-12 00:06 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Raptr 2014-05-12 00:06 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\library_dir 2014-05-12 00:02 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-05-12 00:02 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-05-12 00:02 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-05-12 00:02 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-05-12 00:02 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-05-12 00:02 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-05-12 00:00 - 2014-05-12 00:00 - 00000826 _____ () C:\Users\Public\Desktop\Dragon's Prophet.lnk 2014-05-12 00:00 - 2014-05-12 00:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragon's Prophet 2014-05-11 23:55 - 2014-05-12 00:19 - 00000000 ____D () C:\Users\David\Desktop\Neuer Ordner 2014-05-11 23:55 - 2014-05-11 23:55 - 00000000 ____D () C:\Users\David\AppData\Local\Akamai 2014-05-11 23:54 - 2014-05-11 23:54 - 10551808 _____ (Akamai Technologies, Inc.) C:\Users\David\Downloads\my_downloader_installer.exe 2014-05-11 23:44 - 2014-05-16 11:33 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-11 23:44 - 2014-05-11 23:44 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-05-11 18:36 - 2014-05-12 00:21 - 00000000 ____D () C:\ProgramData\Solid State Networks 2014-05-11 18:36 - 2014-05-11 18:36 - 01495552 _____ (Infernum Productions AG) C:\Users\David\Downloads\DragonsProphetDLM.exe 2014-05-11 18:21 - 2014-05-11 18:21 - 00000000 ____D () C:\Windows\ERUNT 2014-05-11 18:12 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-11 18:11 - 2014-05-11 18:17 - 00000000 ____D () C:\AdwCleaner 2014-05-11 13:30 - 2014-05-11 13:30 - 00001440 _____ () C:\Users\Public\Desktop\Free YouTube Download.lnk 2014-05-11 13:28 - 2014-05-11 13:29 - 32355208 _____ (DVDVideoSoft Ltd. ) C:\Users\David\Downloads\FreeYouTubeDownload.exe 2014-05-09 20:04 - 2014-05-09 20:04 - 00000000 ____D () C:\ProgramData\Bohemia Interactive Studio 2014-05-09 20:01 - 2014-05-09 20:01 - 00000000 ____D () C:\Users\David\AppData\Local\ArmA 2 2014-05-09 19:59 - 2014-05-09 22:03 - 00000000 ____D () C:\Users\David\AppData\Local\ArmA 2 OA 2014-05-09 19:59 - 2014-05-09 20:06 - 00000000 ____D () C:\Users\David\Documents\ArmA 2 2014-05-09 19:59 - 2014-05-09 19:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2014-05-09 19:59 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-05-09 19:59 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2014-05-09 19:59 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2014-05-09 19:59 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-05-09 19:59 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-05-09 19:59 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2014-05-09 19:59 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-05-09 19:59 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2014-05-09 19:59 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-05-09 19:59 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2014-05-09 19:59 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2014-05-09 19:59 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-05-09 19:59 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-05-09 19:59 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-05-09 19:59 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-05-09 19:59 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2014-05-09 19:59 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-05-09 19:59 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-05-09 19:59 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-05-09 19:59 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-05-09 19:59 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-05-09 19:59 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-05-09 19:59 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2014-05-09 19:59 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-05-09 19:59 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-05-09 19:59 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-05-09 19:59 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-05-09 19:59 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-05-09 19:59 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-05-09 19:59 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-05-09 19:59 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-05-09 19:59 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-05-09 19:59 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-05-09 19:59 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-05-09 19:59 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-05-08 15:54 - 2014-06-05 16:55 - 00000000 ____D () C:\FRST 2014-05-08 15:36 - 2014-06-05 15:02 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-08 15:36 - 2014-05-31 13:45 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-08 15:36 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-08 15:36 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-08 15:36 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-08 15:36 - 2014-05-08 15:36 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-08 15:35 - 2014-05-08 15:35 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\David\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-07 17:46 - 2014-05-07 17:46 - 00000000 ____D () C:\Users\David\AppData\Roaming\Avira 2014-05-07 16:46 - 2014-05-07 16:45 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-05-07 00:03 - 2014-05-27 11:28 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-07 00:03 - 2014-05-27 11:28 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-07 00:03 - 2014-02-25 11:41 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-05-06 23:46 - 2014-05-12 15:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-06 23:46 - 2014-05-12 15:38 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-06 23:46 - 2014-05-07 00:03 - 00000000 ____D () C:\ProgramData\Avira 2014-05-06 23:42 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-05-06 23:42 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2014-05-06 23:42 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-05-06 23:42 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2014-05-06 23:41 - 2014-05-12 00:02 - 00045035 _____ () C:\Windows\DirectX.log 2014-05-06 23:41 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-05-06 23:41 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-05-06 23:41 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-05-06 23:41 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-05-06 23:41 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-05-06 23:41 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-05-06 23:41 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-05-06 23:41 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-05-06 23:41 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-05-06 23:41 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-05-06 23:41 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-05-06 23:41 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-05-06 23:41 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-05-06 23:41 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-05-06 23:41 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-05-06 23:41 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-05-06 23:41 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-05-06 23:41 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-05-06 23:41 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-05-06 23:41 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-05-06 23:41 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-05-06 23:41 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-05-06 23:41 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-05-06 23:41 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-05-06 23:41 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-05-06 23:41 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-05-06 23:41 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-05-06 23:41 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-05-06 23:41 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-05-06 23:41 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-05-06 23:41 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-05-06 23:41 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-05-06 23:41 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-05-06 23:41 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-05-06 23:41 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-05-06 23:41 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-05-06 23:41 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-05-06 23:41 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-05-06 23:41 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-05-06 23:41 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-05-06 23:41 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-05-06 23:41 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-05-06 23:41 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-05-06 23:41 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2014-05-06 23:41 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-05-06 23:41 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-05-06 23:41 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-05-06 23:41 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-05-06 23:41 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-05-06 23:41 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-05-06 23:41 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-05-06 23:41 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-05-06 23:41 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-05-06 23:41 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-05-06 23:41 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-05-06 23:41 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-05-06 23:41 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-05-06 23:41 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-05-06 23:41 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-05-06 23:41 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-05-06 23:41 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-05-06 23:41 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-05-06 23:41 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-05-06 23:41 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-05-06 23:41 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-05-06 23:41 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-05-06 23:41 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-05-06 23:41 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2014-05-06 23:41 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-05-06 23:41 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-05-06 23:41 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2014-05-06 23:41 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-05-06 23:41 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2014-05-06 23:41 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-05-06 23:41 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2014-05-06 23:41 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-05-06 23:41 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2014-05-06 23:41 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-05-06 23:41 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2014-05-06 23:41 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-05-06 23:41 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2014-05-06 23:41 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-05-06 23:41 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2014-05-06 23:41 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-05-06 23:41 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2014-05-06 23:41 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-05-06 23:41 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2014-05-06 23:41 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-05-06 23:41 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2014-05-06 23:41 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-05-06 23:41 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2014-05-06 23:40 - 2014-05-06 23:40 - 04530864 _____ (Avira Operations GmbH & Co. KG) C:\Users\David\Downloads\avira_de_av___ws.exe ==================== One Month Modified Files and Folders ======= 2014-06-05 16:55 - 2014-06-05 16:55 - 00018454 _____ () C:\Users\David\Desktop\FRST.txt 2014-06-05 16:55 - 2014-05-08 15:54 - 00000000 ____D () C:\FRST 2014-06-05 16:55 - 2014-05-01 16:56 - 00000000 ____D () C:\Users\David\AppData\Local\Temp 2014-06-05 16:54 - 2014-06-05 16:54 - 02068992 _____ (Farbar) C:\Users\David\Desktop\FRST64.exe 2014-06-05 16:53 - 2014-06-05 16:53 - 00001510 _____ () C:\Users\David\Desktop\v.txt 2014-06-05 16:47 - 2014-05-01 17:52 - 00000000 ____D () C:\Users\David\AppData\Roaming\Skype 2014-06-05 16:39 - 2014-05-01 18:39 - 00000292 _____ () C:\Windows\Tasks\Speedial.job 2014-06-05 16:11 - 2014-05-01 16:56 - 01317713 _____ () C:\Windows\WindowsUpdate.log 2014-06-05 16:08 - 2014-05-01 17:03 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-05 16:01 - 2014-06-02 16:30 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-05 15:59 - 2014-06-05 15:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\Apple Computer 2014-06-05 15:59 - 2014-06-05 15:59 - 00000000 ____D () C:\Users\David\AppData\Local\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-06-05 15:58 - 2014-06-05 15:58 - 00001576 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Users\David\AppData\Local\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-06-05 15:58 - 2014-06-05 15:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-06-05 15:50 - 2014-06-05 15:50 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\otnfbxsx.sys 2014-06-05 15:48 - 2014-06-05 15:47 - 41945432 _____ (Apple Inc.) C:\Users\David\Downloads\QuickTimeInstaller.exe 2014-06-05 15:46 - 2014-06-05 15:45 - 00000000 ____D () C:\Users\David\AppData\Roaming\vlc 2014-06-05 15:41 - 2014-06-05 15:40 - 25531584 _____ () C:\Users\David\Downloads\vlc-2.1.3-win32.exe 2014-06-05 15:38 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\Raptr 2014-06-05 15:02 - 2014-05-08 15:36 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-05 13:07 - 2014-05-01 17:52 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-06-05 13:07 - 2014-05-01 17:52 - 00000000 ____D () C:\ProgramData\Skype 2014-06-05 12:26 - 2014-05-01 17:57 - 00000000 ____D () C:\Users\David\AppData\Roaming\TS3Client 2014-06-05 12:08 - 2014-05-01 17:15 - 00000000 ____D () C:\Users\David\AppData\Local\PMB Files 2014-06-05 11:47 - 2014-05-03 18:47 - 00000000 ____D () C:\Users\David\AppData\Local\Adobe 2014-06-05 11:45 - 2009-07-14 06:45 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-05 11:45 - 2009-07-14 06:45 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-05 11:38 - 2014-05-01 17:03 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-05 11:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-05 11:37 - 2009-07-14 06:51 - 00035073 _____ () C:\Windows\setupact.log 2014-06-04 18:35 - 2009-07-14 19:58 - 00699726 _____ () C:\Windows\system32\perfh007.dat 2014-06-04 18:35 - 2009-07-14 19:58 - 00149364 _____ () C:\Windows\system32\perfc007.dat 2014-06-04 18:35 - 2009-07-14 07:13 - 01621742 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-03 22:43 - 2014-05-01 17:15 - 00000000 ____D () C:\ProgramData\PMB Files 2014-06-03 15:23 - 2014-05-31 15:04 - 00150528 ___SH () C:\Users\David\Thumbs.db 2014-06-03 15:23 - 2014-05-30 15:01 - 00000132 _____ () C:\Users\David\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen 2014-06-03 15:23 - 2014-05-01 16:56 - 00000000 ____D () C:\Users\David 2014-06-03 14:51 - 2014-06-03 14:47 - 44199212 _____ () C:\Users\David\Downloads\Pentakill-SmiteandIgnite.zip 2014-06-03 14:31 - 2014-06-02 23:20 - 16849882 _____ () C:\Users\David\Downloads\Season-4-Overlay-Mega-Pack-by-Temporalcortex.zip 2014-06-03 14:15 - 2014-06-03 14:15 - 00000000 ____D () C:\Users\David\AppData\Roaming\OBS 2014-06-03 14:14 - 2014-06-03 14:14 - 00961360 _____ (Chip Digital GmbH) C:\Users\David\Downloads\Open Broadcaster Software - CHIP-Installer.exe 2014-06-02 16:58 - 2014-06-02 16:41 - 00026934 _____ () C:\Users\David\Downloads\debug.log 2014-06-02 16:32 - 2014-06-02 16:32 - 00000796 _____ () C:\Users\Public\Desktop\XSplit Broadcaster.lnk 2014-06-02 16:32 - 2014-06-02 16:32 - 00000000 ____D () C:\Users\David\AppData\Local\SplitMediaLabs 2014-06-02 16:32 - 2014-06-02 15:59 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-06-02 16:32 - 2014-06-02 15:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit 2014-06-02 16:31 - 2014-06-02 15:58 - 00000000 ____D () C:\Users\David\AppData\Roaming\SplitmediaLabs 2014-06-02 16:30 - 2014-06-02 16:30 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-02 16:30 - 2014-06-02 16:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-02 16:30 - 2014-06-02 16:30 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\system32\Macromed 2014-06-02 16:29 - 2014-06-02 16:28 - 42360392 _____ (SplitMediaLabs) C:\Users\David\Downloads\xsplit_bc_installer.exe 2014-06-02 16:21 - 2014-06-02 16:21 - 00000000 ____D () C:\Users\David\AppData\Local\IsolatedStorage 2014-06-02 15:59 - 2014-06-02 15:59 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-06-02 15:57 - 2014-06-02 15:55 - 46455952 _____ (SplitmediaLabs) C:\Users\David\Downloads\xsplit_gc_installer.exe 2014-05-31 19:39 - 2014-05-31 19:39 - 00111788 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget (1).zip 2014-05-31 19:12 - 2014-05-31 19:12 - 00112213 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget.zip 2014-05-31 13:45 - 2014-05-08 15:36 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-27 11:28 - 2014-05-07 00:03 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-27 11:28 - 2014-05-07 00:03 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-26 18:37 - 2014-05-26 18:37 - 01677440 _____ (Skype Technologies S.A.) C:\Users\David\Downloads\SkypeSetup (1).exe 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_juextctrl_01007.Wdf 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf 2014-05-26 12:08 - 2014-05-26 12:03 - 00000000 ____D () C:\ProgramData\DatacardService 2014-05-26 12:07 - 2014-05-26 12:07 - 00001245 _____ () C:\Users\Public\Desktop\Internet Manager.lnk 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Manager 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Internet Manager 2014-05-26 12:06 - 2014-05-26 12:06 - 00000000 ____D () C:\Program Files (x86)\T-Mobile 2014-05-22 19:04 - 2014-05-12 00:06 - 00000000 ____D () C:\Program Files (x86)\Raptr 2014-05-21 16:18 - 2014-06-03 14:17 - 01193472 _____ () C:\Users\David\Desktop\OBS.exe 2014-05-19 19:59 - 2014-05-12 17:17 - 00000000 ____D () C:\Users\David\AppData\Roaming\HpUpdate 2014-05-18 15:42 - 2014-05-18 15:41 - 00000036 _____ () C:\Users\David\Malwarebytes ID.txt 2014-05-16 11:33 - 2014-05-11 23:44 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-13 22:44 - 2014-05-01 17:43 - 00089872 _____ () C:\Windows\PFRO.log 2014-05-13 21:27 - 2014-05-12 00:18 - 00000000 ____D () C:\Users\David\Documents\dragoon 2014-05-12 17:22 - 2014-05-12 17:22 - 00056100 _____ () C:\Windows\SysWOW64\CCCInstall_201405121722165928.log 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\ProgramData\ATI 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-05-12 17:22 - 2014-05-01 17:34 - 00000000 ____D () C:\ProgramData\AMD 2014-05-12 17:21 - 2014-05-01 17:27 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-05-12 17:20 - 2014-05-12 17:20 - 00000000 ____D () C:\Program Files\AMD 2014-05-12 17:19 - 2014-05-01 17:30 - 00000000 ____D () C:\ProgramData\Package Cache 2014-05-12 17:18 - 2014-05-12 17:16 - 00000000 ____D () C:\Users\David\AppData\Local\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\ProgramData\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\Program Files\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\Program Files (x86)\HP 2014-05-12 17:16 - 2014-05-12 17:16 - 00000057 _____ () C:\ProgramData\Ament.ini 2014-05-12 17:15 - 2014-05-12 17:13 - 56732448 _____ () C:\Users\David\Downloads\DJ3050_J610_1315.exe 2014-05-12 17:11 - 2014-05-01 17:33 - 00000000 ____D () C:\AMD 2014-05-12 15:43 - 2014-05-12 15:36 - 269338400 _____ (AMD Inc.) C:\Users\David\Downloads\14-4-win7-win8-win8.1-64-dd-ccc-whql.exe 2014-05-12 15:38 - 2014-05-06 23:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-12 15:38 - 2014-05-06 23:46 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-12 07:26 - 2014-05-08 15:36 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-05-08 15:36 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-05-08 15:36 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-12 00:21 - 2014-05-11 18:36 - 00000000 ____D () C:\ProgramData\Solid State Networks 2014-05-12 00:19 - 2014-05-11 23:55 - 00000000 ____D () C:\Users\David\Desktop\Neuer Ordner 2014-05-12 00:06 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Raptr 2014-05-12 00:06 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\library_dir 2014-05-12 00:02 - 2014-05-06 23:41 - 00045035 _____ () C:\Windows\DirectX.log 2014-05-12 00:00 - 2014-05-12 00:00 - 00000826 _____ () C:\Users\Public\Desktop\Dragon's Prophet.lnk 2014-05-12 00:00 - 2014-05-12 00:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragon's Prophet 2014-05-11 23:55 - 2014-05-11 23:55 - 00000000 ____D () C:\Users\David\AppData\Local\Akamai 2014-05-11 23:54 - 2014-05-11 23:54 - 10551808 _____ (Akamai Technologies, Inc.) C:\Users\David\Downloads\my_downloader_installer.exe 2014-05-11 23:47 - 2014-05-03 18:40 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-11 23:47 - 2014-05-01 19:37 - 00000000 ____D () C:\Users\David\AppData\Roaming\Adobe 2014-05-11 23:44 - 2014-05-11 23:44 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-05-11 23:44 - 2014-05-03 18:52 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-05-11 22:56 - 2014-05-03 20:27 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-05-11 18:36 - 2014-05-11 18:36 - 01495552 _____ (Infernum Productions AG) C:\Users\David\Downloads\DragonsProphetDLM.exe 2014-05-11 18:21 - 2014-05-11 18:21 - 00000000 ____D () C:\Windows\ERUNT 2014-05-11 18:17 - 2014-05-11 18:11 - 00000000 ____D () C:\AdwCleaner 2014-05-11 13:31 - 2014-05-01 18:39 - 00000000 ____D () C:\Users\David\AppData\Roaming\DVDVideoSoft 2014-05-11 13:30 - 2014-05-11 13:30 - 00001440 _____ () C:\Users\Public\Desktop\Free YouTube Download.lnk 2014-05-11 13:30 - 2014-05-01 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2014-05-11 13:30 - 2014-05-01 18:39 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-05-11 13:29 - 2014-05-11 13:28 - 32355208 _____ (DVDVideoSoft Ltd. ) C:\Users\David\Downloads\FreeYouTubeDownload.exe 2014-05-11 12:44 - 2014-05-04 23:44 - 00000000 ___RD () C:\Users\David\Desktop\Games 2014-05-09 22:03 - 2014-05-09 19:59 - 00000000 ____D () C:\Users\David\AppData\Local\ArmA 2 OA 2014-05-09 20:06 - 2014-05-09 19:59 - 00000000 ____D () C:\Users\David\Documents\ArmA 2 2014-05-09 20:04 - 2014-05-09 20:04 - 00000000 ____D () C:\ProgramData\Bohemia Interactive Studio 2014-05-09 20:01 - 2014-05-09 20:01 - 00000000 ____D () C:\Users\David\AppData\Local\ArmA 2 2014-05-09 19:59 - 2014-05-09 19:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2014-05-09 17:48 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\CSC 2014-05-08 15:36 - 2014-05-08 15:36 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-08 15:35 - 2014-05-08 15:35 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\David\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-07 17:46 - 2014-05-07 17:46 - 00000000 ____D () C:\Users\David\AppData\Roaming\Avira 2014-05-07 16:45 - 2014-05-07 16:46 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-05-07 00:03 - 2014-05-06 23:46 - 00000000 ____D () C:\ProgramData\Avira 2014-05-06 23:40 - 2014-05-06 23:40 - 04530864 _____ (Avira Operations GmbH & Co. KG) C:\Users\David\Downloads\avira_de_av___ws.exe Some content of TEMP: ==================== C:\Users\David\AppData\Local\Temp\avgnt.exe C:\Users\David\AppData\Local\Temp\MSIAFTERBURNERSETUP.EXE C:\Users\David\AppData\Local\Temp\Quarantine.exe C:\Users\David\AppData\Local\Temp\SETUP_AFTERBURNER.EXE C:\Users\David\AppData\Local\Temp\swt-win32-3349.dll C:\Users\David\AppData\Local\Temp\uninstall_flash_player.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-31 13:18 ==================== End Of Log ============================ Edit: Kann leider die GMER nicht mehr anhängen aber sobald einer antwortet kommt sie nach Geändert von xXFenrizXx (05.06.2014 um 16:13 Uhr) |
06.06.2014, 12:58 | #3 |
| TR/Drop.Softomat.AN/Windows 7 64 BitCode:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-06-05 17:05:05 Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\00000062 WDC_____ rev.01.0 931,51GB Running: Gmer-19357.exe; Driver: C:\Users\David\AppData\Local\Temp\kwldypod.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\KERNEL32.dll .text ... * 9 .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\kernel32.dll .text D:\Programme\RocketDock\RocketDock.exe[3352] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\kernel32.dll .text C:\Users\David\AppData\Local\Akamai\netsession_win.exe[4256] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\KERNEL32.dll .text ... * 9 .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4180] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!DispatchMessageW 0000000076227deb 5 bytes JMP 00000001612d05a0 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!DispatchMessageA 0000000076228103 5 bytes JMP 00000001612d0570 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076228b9a 5 bytes JMP 00000001612d0f20 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!CreateWindowExA 000000007622a5e6 5 bytes JMP 00000001612d0df0 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!SetWindowPos 000000007622cdb4 5 bytes JMP 00000001612d0700 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000076230112 5 bytes JMP 00000001612d08c0 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!ShowWindow 0000000076230dbe 5 bytes JMP 00000001612d05d0 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!EndPaint 0000000076230e9a 5 bytes JMP 00000001612d09a0 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000076230eba 5 bytes JMP 00000001612d0940 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!SetForegroundWindow 0000000076231d34 5 bytes JMP 00000001612d0800 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!DestroyWindow 0000000076231e6e 5 bytes JMP 00000001612d06d0 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!UpdateLayeredWindowIndirect 000000007623260a 5 bytes JMP 00000001612d0d70 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!WindowFromPoint 0000000076232ddb 5 bytes JMP 00000001612d00d0 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!SetCapture 0000000076232ed1 5 bytes JMP 00000001612d0840 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!SetCursor 0000000076234076 5 bytes JMP 00000001612d00b0 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!BringWindowToTop 0000000076237ba7 5 bytes JMP 00000001612d0920 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!AnimateWindow 0000000076242b8d 5 bytes JMP 00000001612d0770 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!UpdateLayeredWindow 00000000762430a6 5 bytes JMP 00000001612d0ca0 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\USER32.dll!PeekMessageA 000000007624ed58 5 bytes JMP 00000001612d0860 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\GDI32.dll!BitBlt 0000000076545ea6 5 bytes JMP 00000001612d0100 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\kernel32.dll .text C:\PROGRA~2\Raptr\raptr.exe[3780] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\KERNEL32.dll .text ... * 9 .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5356] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes JMP 75eeeb26 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes JMP 75efb513 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes JMP 75f78609 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes CALL 75ed1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes JMP 75f77efe C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes JMP 75f780d8 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes JMP 75f77df4 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes JMP 75f781c2 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes JMP 75eef088 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes JMP 75efb885 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes JMP 75f786c1 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes JMP 75f78222 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes JMP 75f77db8 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes JMP 75eef121 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes JMP 75efb29f C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes JMP 75f78584 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Quicktime\QuickTimePlayer.exe[7724] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes JMP 75f77d4d C:\Windows\syswow64\kernel32.dll ---- Processes - GMER 2.1 ---- Process C:\ProgramData\DatacardService\HWDeviceService64.exe (*** suspicious ***) @ C:\ProgramData\DatacardService\HWDeviceService64.exe [1936](2011-03-14 15:27:34) 000000013fc20000 Process C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [1368](2014-05-26 10:07:40) 0000000000400000 Library C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [1368](2014-05-26 10:07:40) 000000006fbc0000 Library C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [1368](2014-05-26 10:07:40) 000000006e940000 Library C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [1368](2014-05-26 10:07:40) 000000006a1c0000 Library C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [1368](2014-05-26 10:07:40) 000000006ff00000 Process C:\ProgramData\DatacardService\DCSHelper.exe (*** suspicious ***) @ C:\ProgramData\DatacardService\DCSHelper.exe [2988] (DataCardMonitor MFC Application/Huawei Technologies Co., Ltd.)(2011-03-14 15:27:28) 0000000000400000 Process C:\Users\David\AppData\Local\Akamai\netsession_win.exe (*** suspicious ***) @ C:\Users\David\AppData\Local\Akamai\netsession_win.exe [3900] (Akamai NetSession Client/Akamai Technologies, Inc.)(2014-04-17 19:07:50) 0000000000400000 Process C:\Users\David\AppData\Local\Akamai\netsession_win.exe (*** suspicious ***) @ C:\Users\David\AppData\Local\Akamai\netsession_win.exe [4256] (Akamai NetSession Client/Akamai Technologies, Inc.)(2014-04-17 19:07:50) 0000000000400000 ---- EOF - GMER 2.1 ---- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-06-2014 Ran by David at 2014-06-05 20:25:40 Running from C:\Users\David\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.5.0.367 - Adobe Systems Incorporated) Adobe Dreamweaver CC (HKLM-x32\...\{00E094E1-A852-11E2-803D-ACEA632352B4}) (Version: 13 - Adobe Systems Incorporated) Adobe Extension Manager CC (HKLM-x32\...\{244FD30F-63F1-49B9-9D98-1150FF4FFCB1}) (Version: 7.1.1 - Adobe Systems Incorporated) Adobe Flash Player 11 ActiveX (HKLM-x32\...\{E94EFAB6-653F-4837-9E8A-F6377CA1EC0D}) (Version: 11.8.800.175 - Adobe Systems Incorporated) Adobe Photoshop CC (HKLM-x32\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc) AMD Accelerated Video Transcoding (Version: 13.30.100.40417 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2014.0417.2226.38446 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{6119B3A6-3603-9695-0398-CDF2AF0A13F8}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.80911.2216 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.15 - Advanced Micro Devices, Inc.) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Arma 2 (HKLM-x32\...\Steam App 33900) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead (HKLM-x32\...\Steam App 33930) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead Beta (HKLM-x32\...\Steam App 219540) (Version: - ) Avira (HKLM-x32\...\{70a79d1f-686d-4d5c-962b-07aa1294eae0}) (Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) DayZ Commander (HKLM-x32\...\{B3653588-3AC0-4A1D-950F-D96531E84374}) (Version: 0.92.91 - Dotjosh Studios) Dragon's Prophet (HKLM-x32\...\{C31556D7-F2B9-4787-B223-F7A035067E89}_is1) (Version: 2.0.1349.21 - Infernum Productions AG) Free YouTube Download version 3.2.34.430 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.34.430 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.34.430 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.34.430 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 26.0.1410.40 - Google Inc.) Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden HP Deskjet 3050 J610 series - Grundlegende Software für das Gerät (HKLM\...\{EF3293DE-FCAC-4742-91BF-AD0174143FC3}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Network Connections 18.5.54.0 (HKLM\...\PROSetDX) (Version: 18.5.54.0 - Intel) Intel(R) Network Connections 18.5.54.0 (Version: 18.5.54.0 - Intel) Hidden Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation) Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.18.68.55 - Huawei Technologies Co.,Ltd) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Left 4 Dead (HKLM-x32\...\Steam App 500) (Version: - Valve) Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.154 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Raptr (HKLM-x32\...\Raptr) (Version: - ) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.) ROCCAT Kone XTD Mouse Driver (HKLM-x32\...\{7133137D-DF48-4522-AD88-13C82B7D0A63}) (Version: - Roccat GmbH) RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software) Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.) Speedial (HKLM-x32\...\Speedial) (Version: - Speedial) <==== ATTENTION Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) USB Multi-Channel Audio Device (HKLM\...\C-Media CM106 Like Sound Driver) (Version: - ) VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) XSplit Broadcaster (HKLM-x32\...\{3A1F3A32-7E9D-4AD2-A2E2-DFC98BAA9DC7}) (Version: 1.3.1403.1202 - SplitMediaLabs) XSplit Gamecaster (HKLM-x32\...\{C5E8E927-8182-40D0-8718-ED74E5C0690A}) (Version: 1.7.1405.2114 - SplitmediaLabs) ==================== Restore Points ========================= 26-05-2014 17:15:58 Geplanter Prüfpunkt 02-06-2014 13:58:55 Installed XSplit Gamecaster 02-06-2014 14:30:22 Installed Adobe Flash Player 11 ActiveX. 02-06-2014 14:32:26 Installed XSplit Broadcaster 05-06-2014 13:54:19 Installed QuickTime 7 05-06-2014 13:58:09 Installed QuickTime 7 ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {312E2046-82A0-450F-8497-4FFBC6FEC623} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-01] (Google Inc.) Task: {321826E4-3D5B-4EA4-A7F2-A06FFD4092D3} - System32\Tasks\AdobeAAMUpdater-1.0-Mongrel-David => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated) Task: {743E8047-E9DE-45B1-BF85-54DD421FEC8B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {7FB71025-B02D-4B48-A07D-6BDD38B91116} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-01] (Google Inc.) Task: {B7274294-22D5-4BD5-B85E-291E39DD24CE} - System32\Tasks\Speedial => C:\Users\David\AppData\Roaming\Speedial\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {EC8DE1A6-566C-4753-9372-C5513FBF4946} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-02] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Speedial.job => C:\Users\David\AppData\Roaming\Speedial\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2011-03-14 17:27 - 2011-03-14 17:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2014-05-26 12:07 - 2011-06-17 13:04 - 00224096 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe 2014-02-11 20:21 - 2014-02-11 20:21 - 00860160 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 01043968 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-02-11 20:21 - 2014-02-11 20:21 - 00052736 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 00236032 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-05-01 17:56 - 2007-09-02 13:58 - 00495616 _____ () D:\Programme\RocketDock\RocketDock.exe 2014-03-20 11:24 - 2014-03-20 11:24 - 05288608 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe 2014-03-20 11:24 - 2014-03-20 11:24 - 00667808 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll 2014-05-26 12:07 - 2009-01-10 12:32 - 00011362 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll 2014-05-26 12:07 - 2009-06-22 20:42 - 00043008 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll 2014-05-26 12:07 - 2010-05-05 10:47 - 02415104 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll 2014-05-26 12:07 - 2010-02-10 16:10 - 01148416 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll 2014-05-05 10:37 - 2014-05-05 10:37 - 00138320 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll 2014-05-05 10:37 - 2014-05-05 10:37 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2014-05-01 17:56 - 2007-09-02 13:57 - 00069632 _____ () D:\Programme\RocketDock\RocketDock.dll 2014-05-01 18:40 - 2012-06-17 11:20 - 00061440 _____ () C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\hiddriver.dll 2014-03-18 23:22 - 2014-03-18 23:22 - 32733088 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll 2014-05-07 00:03 - 2014-05-05 10:37 - 00049744 _____ () C:\Users\David\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00087040 _____ () C:\Program Files (x86)\Raptr\_ctypes.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00043008 _____ () C:\Program Files (x86)\Raptr\_socket.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00805376 _____ () C:\Program Files (x86)\Raptr\_ssl.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 05812736 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtGui.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00067584 _____ () C:\Program Files (x86)\Raptr\sip.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 01662464 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtCore.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00494592 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtNetwork.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00096256 _____ () C:\Program Files (x86)\Raptr\win32api.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00110592 _____ () C:\Program Files (x86)\Raptr\pywintypes26.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00324608 _____ () C:\Program Files (x86)\Raptr\PIL._imaging.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00356864 _____ () C:\Program Files (x86)\Raptr\_hashlib.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00036352 _____ () C:\Program Files (x86)\Raptr\win32process.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00111104 _____ () C:\Program Files (x86)\Raptr\win32file.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00124928 _____ () C:\Program Files (x86)\Raptr\_elementtree.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00127488 _____ () C:\Program Files (x86)\Raptr\pyexpat.pyd 2012-02-06 22:28 - 2012-02-06 22:28 - 00031744 _____ () C:\Program Files (x86)\Raptr\Crypto.Cipher.AES.pyd 2012-02-06 22:28 - 2012-02-06 22:28 - 00010752 _____ () C:\Program Files (x86)\Raptr\Crypto.Random.OSRNG.winrandom.pyd 2012-02-06 22:28 - 2012-02-06 22:28 - 00011264 _____ () C:\Program Files (x86)\Raptr\Crypto.Util._counter.pyd 2011-05-10 21:01 - 2011-05-10 21:01 - 00030208 _____ () C:\Program Files (x86)\Raptr\simplejson._speedups.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00313856 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtWebKit.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00044544 _____ () C:\Program Files (x86)\Raptr\_sqlite3.pyd 2011-02-15 20:17 - 2011-02-15 20:17 - 00417501 _____ () C:\Program Files (x86)\Raptr\sqlite3.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00354304 _____ () C:\Program Files (x86)\Raptr\pythoncom26.dll 2010-11-23 00:57 - 2010-11-23 00:57 - 00016384 _____ () C:\Program Files (x86)\Raptr\win32trace.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00167936 _____ () C:\Program Files (x86)\Raptr\win32gui.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00009216 _____ () C:\Program Files (x86)\Raptr\winsound.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00010240 _____ () C:\Program Files (x86)\Raptr\select.pyd 2013-11-21 02:05 - 2013-11-21 02:05 - 00256000 _____ () C:\Program Files (x86)\Raptr\amd_ags.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00583680 _____ () C:\Program Files (x86)\Raptr\unicodedata.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00263168 _____ () C:\Program Files (x86)\Raptr\win32com.shell.shell.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00141312 _____ () C:\Program Files (x86)\Raptr\gobject._gobject.pyd 2012-10-27 09:53 - 2012-10-27 09:53 - 02717595 _____ () C:\Program Files (x86)\Raptr\heliotrope._purple.pyd 2011-02-15 20:17 - 2011-02-15 20:17 - 01213633 _____ () C:\Program Files (x86)\Raptr\libxml2-2.dll 2010-11-23 01:06 - 2010-11-23 01:06 - 00055808 _____ () C:\Program Files (x86)\Raptr\zlib1.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 00495680 _____ () C:\Program Files (x86)\Raptr\plugins\libaim.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 01183699 _____ () C:\Program Files (x86)\Raptr\liboscar.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 00483306 _____ () C:\Program Files (x86)\Raptr\plugins\libicq.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00655356 _____ () C:\Program Files (x86)\Raptr\plugins\libirc.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 01306387 _____ () C:\Program Files (x86)\Raptr\plugins\libmsn.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 00565461 _____ () C:\Program Files (x86)\Raptr\plugins\libxmpp.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 01640221 _____ () C:\Program Files (x86)\Raptr\libjabber.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 00506276 _____ () C:\Program Files (x86)\Raptr\plugins\libyahoo.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 01053730 _____ () C:\Program Files (x86)\Raptr\libymsg.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00497782 _____ () C:\Program Files (x86)\Raptr\plugins\libyahoojp.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00603326 _____ () C:\Program Files (x86)\Raptr\plugins\ssl-nss.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00474199 _____ () C:\Program Files (x86)\Raptr\plugins\ssl.dll 2014-05-01 17:40 - 2013-09-03 16:52 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2013-09-13 19:51 - 2013-09-13 19:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-09-13 19:51 - 2013-09-13 19:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 00598480 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libglesv2.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 00124368 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libegl.dll 2014-05-01 17:03 - 2013-03-20 08:04 - 04050896 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll 2014-05-01 17:03 - 2013-03-20 08:04 - 00390096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 01606096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ffmpegsumo.dll 2014-02-28 15:33 - 2014-02-28 15:33 - 00148480 _____ () D:\Programme\Teamspeak\quazip.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00864768 _____ () D:\Programme\Teamspeak\platforms\qwindows.dll 2014-02-27 15:45 - 2014-02-27 15:45 - 00677376 _____ () D:\Programme\Teamspeak\sqldrivers\qsqlite.dll 2014-02-28 15:41 - 2014-02-28 15:41 - 00092104 _____ () D:\Programme\Teamspeak\soundbackends\directsound_win32.dll 2014-02-28 15:41 - 2014-02-28 15:41 - 00105416 _____ () D:\Programme\Teamspeak\soundbackends\windowsaudiosession_win32.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00025600 _____ () D:\Programme\Teamspeak\imageformats\qgif.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00242688 _____ () D:\Programme\Teamspeak\imageformats\qjpeg.dll 2014-02-28 15:42 - 2014-02-28 15:42 - 00477128 _____ () D:\Programme\Teamspeak\plugins\clientquery_plugin.dll 2014-02-28 15:42 - 2014-02-28 15:42 - 00483784 _____ () D:\Programme\Teamspeak\plugins\teamspeak_control_plugin.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00123904 _____ () D:\Programme\Teamspeak\accessible\qtaccessiblewidgets.dll 2014-05-01 17:03 - 2013-03-20 08:04 - 12662224 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/05/2014 08:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (632)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/05/2014 08:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (632)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/05/2014 08:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (632)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/05/2014 08:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (632)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/05/2014 07:40:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (632)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/05/2014 07:40:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (632)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/05/2014 07:40:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (632)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/05/2014 07:40:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (632)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/05/2014 07:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (632)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/05/2014 07:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (632)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. System errors: ============= Error: (06/05/2014 11:39:09 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (06/05/2014 11:38:06 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst RtkAudioService erreicht. Error: (06/05/2014 11:37:22 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/05/2014 11:37:22 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Error: (06/04/2014 06:30:28 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (06/04/2014 06:29:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/04/2014 06:29:21 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Error: (06/03/2014 00:51:34 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (06/03/2014 00:49:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/03/2014 00:49:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Microsoft Office Sessions: ========================= Error: (06/05/2014 08:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll632SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/05/2014 08:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll632SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/05/2014 08:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll632SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/05/2014 08:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll632SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/05/2014 07:40:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll632SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/05/2014 07:40:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll632SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/05/2014 07:40:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll632SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/05/2014 07:40:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll632SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/05/2014 07:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll632SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/05/2014 07:10:56 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll632SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 ==================== Memory info =========================== Percentage of memory in use: 43% Total physical RAM: 8111.09 MB Available physical RAM: 4592.41 MB Total Pagefile: 16220.33 MB Available Pagefile: 12151.43 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:195.31 GB) (Free:148.25 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:292.87 GB) (Free:286.33 GB) NTFS Drive e: () (Fixed) (Total:443.23 GB) (Free:386.16 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: DA688F2A) Partition 1: (Active) - (Size=195 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=443 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Edit: Mist nachdem ich gestern den Virus TR/Drop.Softomat.AN der die Datei audiodg.exe befallen hat gelöscht habe geht der sound nicht mehr. Ich weiß war dumm. Hab nun mit cmd.exe und sfc/scannow die datei wiederhergestellt aber der Virus ist auch wieder da und liegt jetzt in der Quarantäne Edit 2: So Ton ist wieder da nachdem ich die audiodg.exe vom laptop kopiert habe mache gleich nochmal in Malwarebytes LOG |
07.06.2014, 05:54 | #4 |
/// the machine /// TB-Ausbilder | TR/Drop.Softomat.AN/Windows 7 64 Bit bite nichts mehr auf eigene Faust machen. Adware & Co. deinstallieren
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter: Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.06.2014, 12:08 | #5 |
| TR/Drop.Softomat.AN/Windows 7 64 Bit Hey Schritt 1: Speedial war das einzige Programm mit Attention. Es kam aber eine Fehlermeldung das es nicht gelöscht weden kann Schritt 2: Code:
ATTFilter ComboFix 14-06-04.01 - David 07.06.2014 12:59:51.1.4 - x64 Microsoft Windows 7 Professional 6.1.7600.0.1252.49.1031.18.8111.4859 [GMT 2:00] ausgeführt von:: c:\users\David\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\David\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll c:\users\David\AppData\Local\Temp\WDE167C.tmp\auth.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\burnlib.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\dsp_sc.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\dsp_sps.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\enc_fhgaac.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\enc_flac.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\enc_lame.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\enc_vorbis.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\enc_wav.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\enc_wma.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_classicart.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_crasher.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_ff.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_hotkeys.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_jumpex.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_ml.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_nopro.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_skinmanager.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_timerestore.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_tray.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_undo.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\gen_yar.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_avi.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_cdda.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_dshow.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_flac.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_flv.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_linein.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_midi.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_mkv.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_mod.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_mp3.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_mp4.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_nsv.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_swf.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_vorbis.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_wav.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_wave.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_wm.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\in_wv.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_autotag.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_bookmarks.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_devices.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_disc.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_downloads.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_enqplay.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_history.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_impex.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_local.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_nowplaying.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_online.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_playlists.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_plg.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_pmp.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_rg.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_transcode.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ml_wire.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\ombrowser.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\out_disk.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\out_ds.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\out_wave.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\playlist.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\pmp_activesync.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\pmp_android.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\pmp_ipod.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\pmp_njb.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\pmp_p4s.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\pmp_usb.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\pmp_wifi.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\tagz.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\vis_avs.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\vis_milk2.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\vis_nsfs.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\winamp.lng c:\users\David\AppData\Local\Temp\WDE167C.tmp\winampa.lng . . ((((((((((((((((((((((( Dateien erstellt von 2014-05-07 bis 2014-06-07 )))))))))))))))))))))))))))))) . . 2014-06-07 10:47 . 2014-06-07 10:47 -------- d-----w- c:\program files (x86)\VS Revo Group 2014-06-06 11:54 . 2010-11-20 12:16 100864 ----a-w- c:\windows\system32\audiodg.exe 2014-06-06 11:33 . 2014-06-06 11:38 126464 ----a-w- c:\windows\SysWow64\audiodg.exe 2014-06-05 13:59 . 2014-06-05 13:59 -------- d-----w- c:\users\David\AppData\Local\Apple Computer 2014-06-05 13:59 . 2014-06-06 10:53 -------- d-----w- c:\users\David\AppData\Roaming\Apple Computer 2014-06-05 13:58 . 2014-06-05 13:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2014-06-05 13:58 . 2014-06-05 13:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2014-06-05 13:58 . 2014-06-05 13:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2014-06-05 13:58 . 2014-06-05 13:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2014-06-05 13:58 . 2014-06-05 13:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2014-06-05 13:58 . 2014-06-05 13:58 -------- d-----w- c:\programdata\Apple Computer 2014-06-05 13:58 . 2014-06-05 13:58 -------- d-----w- c:\program files (x86)\Common Files\Apple 2014-06-05 13:58 . 2014-06-05 13:58 -------- d-----w- c:\users\David\AppData\Local\Apple 2014-06-05 13:58 . 2014-06-05 13:58 -------- d-----w- c:\programdata\Apple 2014-06-05 13:58 . 2014-06-05 13:58 -------- d-----w- c:\program files (x86)\Apple Software Update 2014-06-05 13:45 . 2014-06-05 13:46 -------- d-----w- c:\users\David\AppData\Roaming\vlc 2014-06-05 11:07 . 2014-06-05 11:07 -------- d-----w- c:\program files (x86)\Common Files\Skype 2014-06-03 12:15 . 2014-06-03 12:15 -------- d-----w- c:\users\David\AppData\Roaming\OBS 2014-06-02 14:32 . 2014-06-02 14:32 -------- d-----w- c:\users\David\AppData\Local\SplitMediaLabs 2014-06-02 14:30 . 2014-06-02 14:30 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-06-02 14:30 . 2014-06-02 14:30 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-06-02 14:30 . 2014-06-02 14:30 -------- d-----w- c:\windows\SysWow64\Macromed 2014-06-02 14:30 . 2014-06-02 14:30 -------- d-----w- c:\windows\system32\Macromed 2014-06-02 14:21 . 2014-06-02 14:21 -------- d-----w- c:\users\David\AppData\Local\IsolatedStorage 2014-06-02 13:59 . 2014-06-02 14:32 -------- d-sh--w- c:\windows\SysWow64\AI_RecycleBin 2014-06-02 13:59 . 2014-06-02 13:59 -------- d-----w- c:\programdata\SplitMediaLabs 2014-06-02 13:58 . 2014-06-02 14:31 -------- d-----w- c:\users\David\AppData\Roaming\SplitmediaLabs 2014-05-26 10:06 . 2014-05-26 10:06 -------- d-----w- c:\program files (x86)\T-Mobile 2014-05-26 10:03 . 2014-05-26 10:08 -------- d-----w- c:\programdata\DatacardService 2014-05-12 15:22 . 2014-05-12 15:22 -------- d-----w- c:\programdata\ATI 2014-05-12 15:22 . 2014-05-12 15:22 -------- d-----w- c:\program files (x86)\AMD AVT 2014-05-12 15:20 . 2014-05-12 15:20 -------- d-----w- c:\program files\AMD 2014-05-12 15:17 . 2014-05-19 17:59 -------- d-----w- c:\users\David\AppData\Roaming\HpUpdate 2014-05-12 15:17 . 2012-10-17 02:31 741480 ------w- c:\windows\system32\HPDiscoPM9311.dll 2014-05-12 15:17 . 2014-05-12 15:17 -------- d-----w- c:\program files (x86)\HP 2014-05-12 15:17 . 2014-05-12 15:17 -------- d-----w- c:\programdata\HP 2014-05-12 15:17 . 2014-05-12 15:17 -------- d-----w- c:\program files\HP 2014-05-12 15:16 . 2014-05-12 15:18 -------- d-----w- c:\users\David\AppData\Local\HP 2014-05-11 22:06 . 2014-05-11 22:06 -------- d-----w- c:\users\David\AppData\Roaming\library_dir 2014-05-11 22:06 . 2014-06-07 10:33 -------- d-----w- c:\users\David\AppData\Roaming\Raptr 2014-05-11 22:06 . 2014-05-22 17:04 -------- d-----w- c:\program files (x86)\Raptr 2014-05-11 21:55 . 2014-05-11 21:55 -------- d-----w- c:\users\David\AppData\Local\Akamai 2014-05-11 16:36 . 2014-05-11 22:21 -------- d-----w- c:\programdata\Solid State Networks 2014-05-11 16:21 . 2014-05-11 16:21 -------- d-----w- c:\windows\ERUNT 2014-05-11 16:12 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll 2014-05-11 16:11 . 2014-05-11 16:17 -------- d-----w- C:\AdwCleaner 2014-05-09 18:07 . 2014-05-09 18:07 -------- d-----w- c:\program files (x86)\Common Files\BattlEye 2014-05-09 18:04 . 2014-05-09 18:04 -------- d-----w- c:\programdata\Bohemia Interactive Studio 2014-05-09 18:01 . 2014-05-09 18:01 -------- d-----w- c:\users\David\AppData\Local\ArmA 2 2014-05-08 13:54 . 2014-06-05 18:25 -------- d-----w- C:\FRST 2014-05-08 13:36 . 2014-06-07 11:04 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-05-08 13:36 . 2014-05-31 11:45 -------- d-----w- c:\program files (x86)\ Malwarebytes Anti-Malware 2014-05-08 13:36 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-05-08 13:36 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-05-08 13:36 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-05-08 13:36 . 2014-05-08 13:36 -------- d-----w- c:\programdata\Malwarebytes . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-05-27 09:28 . 2014-05-06 22:03 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-05-27 09:28 . 2014-05-06 22:03 112080 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-05-07 14:45 . 2014-05-07 14:46 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2014-04-18 02:43 . 2014-04-18 02:43 127872 ----a-w- c:\windows\system32\amdhcp64.dll 2014-04-18 02:43 . 2014-04-18 02:43 78432 ----a-w- c:\windows\system32\atimpc64.dll 2014-04-18 02:43 . 2014-04-18 02:43 78432 ----a-w- c:\windows\system32\amdpcom64.dll 2014-04-18 02:43 . 2014-04-18 02:43 117560 ----a-w- c:\windows\SysWow64\amdhcp32.dll 2014-04-18 02:43 . 2014-04-18 02:43 71704 ----a-w- c:\windows\SysWow64\atimpc32.dll 2014-04-18 02:43 . 2014-04-18 02:43 71704 ----a-w- c:\windows\SysWow64\amdpcom32.dll 2014-04-18 02:43 . 2013-09-12 02:42 143304 ----a-w- c:\windows\system32\atiuxp64.dll 2014-04-18 02:42 . 2014-04-18 02:42 126336 ----a-w- c:\windows\SysWow64\atiuxpag.dll 2014-04-18 02:42 . 2013-09-12 02:42 117584 ----a-w- c:\windows\system32\atiu9p64.dll 2014-04-18 02:42 . 2013-09-12 02:42 99520 ----a-w- c:\windows\SysWow64\atiu9pag.dll 2014-04-18 02:42 . 2013-09-12 02:42 1343272 ----a-w- c:\windows\system32\aticfx64.dll 2014-04-18 02:42 . 2013-09-12 02:42 1117184 ----a-w- c:\windows\SysWow64\aticfx32.dll 2014-04-18 02:42 . 2013-09-12 02:42 10335208 ----a-w- c:\windows\system32\atidxx64.dll 2014-04-18 02:42 . 2014-04-18 02:42 8866928 ----a-w- c:\windows\SysWow64\atidxx32.dll 2014-04-18 02:42 . 2013-09-12 02:41 6796592 ----a-w- c:\windows\SysWow64\atiumdva.dll 2014-04-18 02:42 . 2013-09-12 02:41 6799688 ----a-w- c:\windows\SysWow64\atiumdag.dll 2014-04-18 02:42 . 2013-09-12 02:41 7520200 ----a-w- c:\windows\system32\atiumd6a.dll 2014-04-18 02:42 . 2013-09-12 02:41 8010968 ----a-w- c:\windows\system32\atiumd64.dll 2014-04-18 02:39 . 2014-04-18 02:39 274656 ----a-w- c:\windows\system32\drivers\amdacpksd.sys 2014-04-18 02:36 . 2014-04-18 02:36 15376384 ----a-w- c:\windows\system32\drivers\atikmdag.sys 2014-04-18 02:23 . 2014-04-18 02:23 231424 ----a-w- c:\windows\system32\clinfo.exe 2014-04-18 02:22 . 2014-04-18 02:22 98816 ----a-w- c:\windows\system32\OpenVideo64.dll 2014-04-18 02:22 . 2014-04-18 02:22 83456 ----a-w- c:\windows\SysWow64\OpenVideo.dll 2014-04-18 02:22 . 2014-04-18 02:22 86528 ----a-w- c:\windows\system32\OVDecode64.dll 2014-04-18 02:22 . 2014-04-18 02:22 73216 ----a-w- c:\windows\SysWow64\OVDecode.dll 2014-04-18 02:22 . 2014-04-18 02:22 28685824 ----a-w- c:\windows\system32\amdocl64.dll 2014-04-18 02:19 . 2014-04-18 02:19 24107520 ----a-w- c:\windows\SysWow64\amdocl.dll 2014-04-18 02:17 . 2014-04-18 02:17 65024 ----a-w- c:\windows\system32\OpenCL.dll 2014-04-18 02:17 . 2014-04-18 02:17 58880 ----a-w- c:\windows\SysWow64\OpenCL.dll 2014-04-18 02:13 . 2014-04-18 02:13 127488 ----a-w- c:\windows\system32\mantle64.dll 2014-04-18 02:13 . 2014-04-18 02:13 113664 ----a-w- c:\windows\SysWow64\mantle32.dll 2014-04-18 02:12 . 2014-04-18 02:12 27907584 ----a-w- c:\windows\system32\atio6axx.dll 2014-04-18 02:12 . 2014-04-18 02:12 5442048 ----a-w- c:\windows\system32\amdmantle64.dll 2014-04-18 01:58 . 2014-04-18 01:58 4358656 ----a-w- c:\windows\SysWow64\amdmantle32.dll 2014-04-18 01:51 . 2014-04-18 01:51 23409152 ----a-w- c:\windows\SysWow64\atioglxx.dll 2014-04-18 01:46 . 2014-04-18 01:46 368128 ----a-w- c:\windows\system32\atiapfxx.exe 2014-04-18 01:46 . 2014-04-18 01:46 62464 ----a-w- c:\windows\system32\aticalrt64.dll 2014-04-18 01:46 . 2014-04-18 01:46 52224 ----a-w- c:\windows\SysWow64\aticalrt.dll 2014-04-18 01:46 . 2014-04-18 01:46 55808 ----a-w- c:\windows\system32\aticalcl64.dll 2014-04-18 01:46 . 2014-04-18 01:46 49152 ----a-w- c:\windows\SysWow64\aticalcl.dll 2014-04-18 01:46 . 2014-04-18 01:46 15716352 ----a-w- c:\windows\system32\aticaldd64.dll 2014-04-18 01:45 . 2014-04-18 01:45 91136 ----a-w- c:\windows\system32\mantleaxl64.dll 2014-04-18 01:45 . 2014-04-18 01:45 85504 ----a-w- c:\windows\SysWow64\mantleaxl32.dll 2014-04-18 01:42 . 2014-04-18 01:42 14302208 ----a-w- c:\windows\SysWow64\aticaldd.dll 2014-04-18 01:33 . 2014-04-18 01:33 48128 ----a-w- c:\windows\system32\amdmmcl6.dll 2014-04-18 01:33 . 2014-04-18 01:33 37888 ----a-w- c:\windows\SysWow64\amdmmcl.dll 2014-04-18 01:30 . 2014-05-01 15:33 442368 ----a-w- c:\windows\system32\atidemgy.dll 2014-04-18 01:30 . 2014-04-18 01:30 31232 ----a-w- c:\windows\system32\atimuixx.dll 2014-04-18 01:29 . 2014-04-18 01:29 586240 ----a-w- c:\windows\system32\atieclxx.exe 2014-04-18 01:29 . 2014-04-18 01:29 239616 ----a-w- c:\windows\system32\atiesrxx.exe 2014-04-18 01:28 . 2014-04-18 01:28 190976 ----a-w- c:\windows\system32\atitmm64.dll 2014-04-18 01:21 . 2014-04-18 01:21 806912 ----a-w- c:\windows\system32\coinst_14.100.dll 2014-04-18 01:09 . 2013-09-12 01:15 1177600 ----a-w- c:\windows\system32\atiadlxx.dll 2014-04-18 01:09 . 2014-04-18 01:09 848896 ----a-w- c:\windows\SysWow64\atiadlxy.dll 2014-04-18 01:08 . 2014-04-18 01:08 95744 ----a-w- c:\windows\system32\amdave64.dll 2014-04-18 01:08 . 2014-04-18 01:08 90112 ----a-w- c:\windows\SysWow64\amdave32.dll 2014-04-18 01:08 . 2014-04-18 01:08 89088 ----a-w- c:\windows\system32\atisamu64.dll 2014-04-18 01:08 . 2014-04-18 01:08 80896 ----a-w- c:\windows\SysWow64\atisamu32.dll 2014-04-18 01:07 . 2014-04-18 01:07 75264 ----a-w- c:\windows\system32\atig6pxx.dll 2014-04-18 01:07 . 2014-04-18 01:07 69632 ----a-w- c:\windows\SysWow64\atiglpxx.dll 2014-04-18 01:07 . 2014-04-18 01:07 69632 ----a-w- c:\windows\system32\atiglpxx.dll 2014-04-18 01:07 . 2014-04-18 01:07 146944 ----a-w- c:\windows\system32\atig6txx.dll 2014-04-18 01:07 . 2014-04-18 01:07 133632 ----a-w- c:\windows\SysWow64\atigktxx.dll 2014-04-18 01:07 . 2014-04-18 01:07 638976 ----a-w- c:\windows\system32\drivers\atikmpag.sys 2014-04-18 01:04 . 2014-04-18 01:04 43520 ----a-w- c:\windows\system32\drivers\ati2erec.dll 2014-04-17 20:33 . 2014-04-17 20:33 51200 ----a-w- c:\windows\system32\kdbsdk64.dll 2014-04-17 20:28 . 2014-04-17 20:28 38912 ----a-w- c:\windows\SysWow64\kdbsdk32.dll 2014-04-17 03:31 . 2014-05-01 15:16 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BD9933D9-95F2-43C1-92CE-DD9B4FE17A75}\mpengine.dll 2014-03-31 07:35 . 2014-05-01 15:16 270496 ------w- c:\windows\system32\MpSigStub.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RocketDock"="d:\programme\RocketDock\RocketDock.exe" [2007-09-02 495616] "Akamai NetSession Interface"="c:\users\David\AppData\Local\Akamai\netsession_win.exe" [2014-04-17 4672920] "Raptr"="c:\progra~2\Raptr\raptrstub.exe" [2014-05-14 55360] "HP Deskjet 3050 J610 series (NET)"="c:\program files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe" [2012-10-17 2573416] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2013-09-03 134616] "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-04-26 292848] "RoccatKoneXTD"="c:\program files (x86)\ROCCAT\Kone XTD Mouse\KoneXTDMonitor.EXE" [2013-10-25 552960] "Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2014-03-21 2691480] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-05-27 737872] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-12-21 959904] "Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2014-05-05 182352] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-04-17 767200] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . 2;2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 Internet Manager. RunOuc;Internet Manager. OUC;c:\program files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe;c:\program files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [x] R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x] R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys;c:\windows\SYSNATIVE\DRIVERS\ew_usbenumfilter.sys [x] R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jucdcacm.sys [x] R3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\DRIVERS\ew_juextctrl.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juextctrl.sys [x] R3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\DRIVERS\ew_juwwanecm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juwwanecm.sys [x] R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x] R3 USBMULCD;Muse Pocket LT3 Interface;c:\windows\system32\drivers\CM10664.sys;c:\windows\SYSNATIVE\drivers\CM10664.sys [x] S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x] S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x] S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x] S2 HWDeviceService64.exe;HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [x] S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 e1dexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver D;c:\windows\system32\DRIVERS\e1d62x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1d62x64.sys [x] S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jubusenum.sys [x] S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] S3 LADF_CaptureOnly;LADF Capture Filter Driver;c:\windows\system32\DRIVERS\ladfGSCamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSCamd64.sys [x] S3 LADF_RenderOnly;LADF Render Filter Driver;c:\windows\system32\DRIVERS\ladfGSRamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSRamd64.sys [x] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x] S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x] S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - MBAMSWISSARMY *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-05-01 15:03 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.40\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-06-07 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-02 14:30] . 2014-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-05-01 15:03] . 2014-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-05-01 15:03] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2014-03-20 09:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2014-03-20 09:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2014-03-20 09:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-07-26 13636824] "IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2013-08-07 36352] "Cm106Sound"="c:\windows\Syswow64\cm106.dll" [2009-10-20 8151040] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-04-15 10396440] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2014-02-27 558496] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = www.google.com mStart Page = www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = <local> IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm TCP: DhcpNameServer = 192.168.2.1 192.168.2.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKLM-Run-<NO NAME> - (no file) AddRemove-Open Broadcaster Software - c:\program files (x86)\OBS\uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\system32\AUDIODG.EXE c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\programdata\Internet Manager\OnlineUpdate\ouc.exe c:\program files (x86)\ Malwarebytes Anti-Malware \mbam.exe c:\windows\SysWOW64\rundll32.exe c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe c:\progra~2\Raptr\raptr.exe c:\progra~2\Raptr\raptr_im.exe c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe c:\program files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-06-07 13:07:06 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-06-07 11:07 . Vor Suchlauf: 10 Verzeichnis(se), 158.640.586.752 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 159.952.453.632 Bytes frei . - - End Of File - - 877F8DDF0E704A962BB7C0747D9B91DD A36C5E4F47E84449FF07ED3517B43A31 Neuer Avira Scan Code:
ATTFilter Avira Free Antivirus Erstellungsdatum der Reportdatei: Samstag, 7. Juni 2014 13:13 Das Programm läuft als uneingeschränkte Vollversion. Online-Dienste stehen zur Verfügung. Lizenznehmer : Avira Antivirus Free Seriennummer : 0000149996-AVHOE-0000001 Plattform : Windows 7 Professional Windowsversion : (plain) [6.1.7600] Boot Modus : Normal gebootet Benutzername : David Computername : MONGREL Versionsinformationen: BUILD.DAT : 14.0.4.642 57086 Bytes 09.05.2014 11:16:00 AVSCAN.EXE : 14.0.4.632 1030736 Bytes 27.05.2014 09:29:00 AVSCANRC.DLL : 14.0.4.620 62032 Bytes 27.05.2014 09:29:00 LUKE.DLL : 14.0.4.620 57936 Bytes 27.05.2014 09:29:36 AVSCPLR.DLL : 14.0.4.620 89680 Bytes 27.05.2014 09:29:00 AVREG.DLL : 14.0.4.632 261200 Bytes 27.05.2014 09:28:58 avlode.dll : 14.0.4.638 583760 Bytes 27.05.2014 09:28:57 avlode.rdf : 14.0.4.22 64276 Bytes 15.05.2014 17:06:36 VBASE000.VDF : 7.11.70.0 66736640 Bytes 04.04.2013 09:41:06 VBASE001.VDF : 7.11.74.226 2201600 Bytes 30.04.2013 09:41:06 VBASE002.VDF : 7.11.80.60 2751488 Bytes 28.05.2013 09:41:06 VBASE003.VDF : 7.11.85.214 2162688 Bytes 21.06.2013 09:41:06 VBASE004.VDF : 7.11.91.176 3903488 Bytes 23.07.2013 09:41:06 VBASE005.VDF : 7.11.98.186 6822912 Bytes 29.08.2013 09:41:06 VBASE006.VDF : 7.11.139.38 15708672 Bytes 27.03.2014 14:45:48 VBASE007.VDF : 7.11.152.100 4193792 Bytes 02.06.2014 15:58:07 VBASE008.VDF : 7.11.152.101 2048 Bytes 02.06.2014 15:58:07 VBASE009.VDF : 7.11.152.102 2048 Bytes 02.06.2014 15:58:07 VBASE010.VDF : 7.11.152.103 2048 Bytes 02.06.2014 15:58:07 VBASE011.VDF : 7.11.152.104 2048 Bytes 02.06.2014 15:58:07 VBASE012.VDF : 7.11.152.105 2048 Bytes 02.06.2014 15:58:07 VBASE013.VDF : 7.11.152.227 225280 Bytes 04.06.2014 16:34:27 VBASE014.VDF : 7.11.153.81 191488 Bytes 06.06.2014 10:57:37 VBASE015.VDF : 7.11.153.159 197120 Bytes 06.06.2014 10:37:35 VBASE016.VDF : 7.11.153.160 2048 Bytes 06.06.2014 10:37:35 VBASE017.VDF : 7.11.153.161 2048 Bytes 06.06.2014 10:37:35 VBASE018.VDF : 7.11.153.162 2048 Bytes 06.06.2014 10:37:35 VBASE019.VDF : 7.11.153.163 2048 Bytes 06.06.2014 10:37:35 VBASE020.VDF : 7.11.153.164 2048 Bytes 06.06.2014 10:37:35 VBASE021.VDF : 7.11.153.165 2048 Bytes 06.06.2014 10:37:35 VBASE022.VDF : 7.11.153.166 2048 Bytes 06.06.2014 10:37:35 VBASE023.VDF : 7.11.153.167 2048 Bytes 06.06.2014 10:37:35 VBASE024.VDF : 7.11.153.168 2048 Bytes 06.06.2014 10:37:35 VBASE025.VDF : 7.11.153.169 2048 Bytes 06.06.2014 10:37:35 VBASE026.VDF : 7.11.153.170 2048 Bytes 06.06.2014 10:37:35 VBASE027.VDF : 7.11.153.171 2048 Bytes 06.06.2014 10:37:35 VBASE028.VDF : 7.11.153.172 2048 Bytes 06.06.2014 10:37:36 VBASE029.VDF : 7.11.153.173 2048 Bytes 06.06.2014 10:37:36 VBASE030.VDF : 7.11.153.174 2048 Bytes 06.06.2014 10:37:36 VBASE031.VDF : 7.11.153.214 265728 Bytes 07.06.2014 10:37:36 Engineversion : 8.3.20.8 AEVDF.DLL : 8.3.0.4 118976 Bytes 07.05.2014 14:45:47 AESCRIPT.DLL : 8.1.4.210 528584 Bytes 06.06.2014 10:57:36 AESCN.DLL : 8.3.1.2 135360 Bytes 28.05.2014 16:12:25 AESBX.DLL : 8.2.20.24 1409224 Bytes 08.05.2014 16:43:12 AERDL.DLL : 8.2.0.138 704888 Bytes 25.02.2014 09:41:04 AEPACK.DLL : 8.4.0.24 778440 Bytes 13.05.2014 16:11:50 AEOFFICE.DLL : 8.3.0.4 205000 Bytes 07.05.2014 14:45:47 AEHEUR.DLL : 8.1.4.1106 6754504 Bytes 06.06.2014 10:57:35 AEHELP.DLL : 8.3.1.0 278728 Bytes 28.05.2014 16:12:21 AEGEN.DLL : 8.1.7.28 450752 Bytes 06.06.2014 10:57:28 AEEXP.DLL : 8.4.2.2 237760 Bytes 04.06.2014 16:34:25 AEEMU.DLL : 8.1.3.2 393587 Bytes 25.02.2014 09:41:04 AEDROID.DLL : 8.4.2.24 442568 Bytes 04.06.2014 16:34:26 AECORE.DLL : 8.3.1.4 241864 Bytes 06.06.2014 10:57:27 AEBB.DLL : 8.1.1.4 53619 Bytes 25.02.2014 09:41:04 AVWINLL.DLL : 14.0.4.620 24144 Bytes 27.05.2014 09:28:53 AVPREF.DLL : 14.0.4.632 50256 Bytes 27.05.2014 09:28:58 AVREP.DLL : 14.0.4.620 219216 Bytes 27.05.2014 09:28:58 AVARKT.DLL : 14.0.4.632 225872 Bytes 27.05.2014 09:28:54 AVEVTLOG.DLL : 14.0.4.620 182352 Bytes 27.05.2014 09:28:56 SQLITE3.DLL : 14.0.4.620 452176 Bytes 27.05.2014 09:29:40 AVSMTP.DLL : 14.0.4.620 76368 Bytes 27.05.2014 09:29:01 NETNT.DLL : 14.0.4.620 13392 Bytes 27.05.2014 09:29:36 RCIMAGE.DLL : 14.0.4.620 4979280 Bytes 27.05.2014 09:28:53 RCTEXT.DLL : 14.0.4.620 73808 Bytes 27.05.2014 09:28:53 Konfiguration für den aktuellen Suchlauf: Job Name..............................: Vollständige Systemprüfung Konfigurationsdatei...................: C:\Program Files (x86)\Avira\AntiVir Desktop\sysscan.avp Protokollierung.......................: standard Primäre Aktion........................: Interaktiv Sekundäre Aktion......................: Ignorieren Durchsuche Masterbootsektoren.........: ein Durchsuche Bootsektoren...............: ein Bootsektoren..........................: C:, D:, E:, Durchsuche aktive Programme...........: ein Laufende Programme erweitert..........: ein Durchsuche Registrierung..............: ein Suche nach Rootkits...................: ein Integritätsprüfung von Systemdateien..: aus Prüfe alle Dateien....................: Alle Dateien Durchsuche Archive....................: ein Rekursionstiefe einschränken..........: 20 Archiv Smart Extensions...............: ein Makrovirenheuristik...................: ein Dateiheuristik........................: erweitert Beginn des Suchlaufs: Samstag, 7. Juni 2014 13:13 Der Suchlauf über die Bootsektoren wird begonnen: Bootsektor 'HDD0(C:, D:, E:)' [INFO] Es wurde kein Virus gefunden! Der Suchlauf nach versteckten Objekten wird begonnen. Der Suchlauf über gestartete Prozesse wird begonnen: Durchsuche Prozess 'svchost.exe' - '52' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '34' Modul(e) wurden durchsucht Durchsuche Prozess 'atiesrxx.exe' - '26' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '94' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '116' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '150' Modul(e) wurden durchsucht Durchsuche Prozess 'AUDIODG.EXE' - '43' Modul(e) wurden durchsucht Modul ist infiziert -> <C:\Windows\SysWOW64\AUDIODG.EXE> [FUND] Ist das Trojanische Pferd TR/Drop.Softomat.AN [WARNUNG] Die Datei wurde ignoriert. Durchsuche Prozess 'svchost.exe' - '79' Modul(e) wurden durchsucht Durchsuche Prozess 'RtkAudioService64.exe' - '32' Modul(e) wurden durchsucht Durchsuche Prozess 'RAVBg64.exe' - '45' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '85' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '72' Modul(e) wurden durchsucht Durchsuche Prozess 'atieclxx.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'spoolsv.exe' - '87' Modul(e) wurden durchsucht Durchsuche Prozess 'sched.exe' - '56' Modul(e) wurden durchsucht Durchsuche Prozess 'armsvc.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'avguard.exe' - '106' Modul(e) wurden durchsucht Durchsuche Prozess 'HWDeviceService64.exe' - '32' Modul(e) wurden durchsucht Durchsuche Prozess 'HeciServer.exe' - '27' Modul(e) wurden durchsucht Durchsuche Prozess 'IProsetMonitor.exe' - '22' Modul(e) wurden durchsucht Durchsuche Prozess 'ouc.exe' - '30' Modul(e) wurden durchsucht Durchsuche Prozess 'mbamscheduler.exe' - '39' Modul(e) wurden durchsucht Durchsuche Prozess 'mbamservice.exe' - '52' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '53' Modul(e) wurden durchsucht Durchsuche Prozess 'Avira.OE.ServiceHost.exe' - '121' Modul(e) wurden durchsucht Durchsuche Prozess 'taskhost.exe' - '58' Modul(e) wurden durchsucht Durchsuche Prozess 'mbam.exe' - '75' Modul(e) wurden durchsucht Durchsuche Prozess 'Dwm.exe' - '35' Modul(e) wurden durchsucht Durchsuche Prozess 'avshadow.exe' - '29' Modul(e) wurden durchsucht Durchsuche Prozess 'taskeng.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'GoogleUpdate.exe' - '50' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '37' Modul(e) wurden durchsucht Durchsuche Prozess 'RAVCpl64.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'rundll32.exe' - '53' Modul(e) wurden durchsucht Durchsuche Prozess 'SearchIndexer.exe' - '53' Modul(e) wurden durchsucht Durchsuche Prozess 'LCore.exe' - '76' Modul(e) wurden durchsucht Durchsuche Prozess 'RocketDock.exe' - '50' Modul(e) wurden durchsucht Durchsuche Prozess 'netsession_win.exe' - '47' Modul(e) wurden durchsucht Durchsuche Prozess 'ScanToPCActivationApp.exe' - '56' Modul(e) wurden durchsucht Durchsuche Prozess 'iusb3mon.exe' - '37' Modul(e) wurden durchsucht Durchsuche Prozess 'KoneXTDMonitor.exe' - '54' Modul(e) wurden durchsucht Durchsuche Prozess 'Creative Cloud.exe' - '125' Modul(e) wurden durchsucht Durchsuche Prozess 'avgnt.exe' - '119' Modul(e) wurden durchsucht Durchsuche Prozess 'Avira.OE.Systray.exe' - '121' Modul(e) wurden durchsucht Durchsuche Prozess 'hpwuschd2.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'netsession_win.exe' - '72' Modul(e) wurden durchsucht Durchsuche Prozess 'AdobeIPCBroker.exe' - '29' Modul(e) wurden durchsucht Durchsuche Prozess 'raptr.exe' - '133' Modul(e) wurden durchsucht Durchsuche Prozess 'raptr_im.exe' - '103' Modul(e) wurden durchsucht Durchsuche Prozess 'wmpnetwk.exe' - '112' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '69' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '55' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiprvse.exe' - '33' Modul(e) wurden durchsucht Durchsuche Prozess 'raptr_ep64.exe' - '44' Modul(e) wurden durchsucht Durchsuche Prozess 'CoreSync.exe' - '106' Modul(e) wurden durchsucht Durchsuche Prozess 'IAStorIcon.exe' - '70' Modul(e) wurden durchsucht Durchsuche Prozess 'unsecapp.exe' - '34' Modul(e) wurden durchsucht Durchsuche Prozess 'Adobe CEF Helper.exe' - '54' Modul(e) wurden durchsucht Durchsuche Prozess 'IAStorDataMgrSvc.exe' - '92' Modul(e) wurden durchsucht Durchsuche Prozess 'jhi_service.exe' - '34' Modul(e) wurden durchsucht Durchsuche Prozess 'LMS.exe' - '87' Modul(e) wurden durchsucht Durchsuche Prozess 'explorer.exe' - '185' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '103' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '69' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'chrome.exe' - '43' Modul(e) wurden durchsucht Durchsuche Prozess 'avcenter.exe' - '133' Modul(e) wurden durchsucht Durchsuche Prozess 'avscan.exe' - '122' Modul(e) wurden durchsucht Durchsuche Prozess 'vssvc.exe' - '47' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'rads_user_kernel.exe' - '54' Modul(e) wurden durchsucht Durchsuche Prozess 'PMB.exe' - '82' Modul(e) wurden durchsucht Durchsuche Prozess 'LoLLauncher.exe' - '83' Modul(e) wurden durchsucht Durchsuche Prozess 'LolClient.exe' - '114' Modul(e) wurden durchsucht Durchsuche Prozess 'ts3client_win32.exe' - '90' Modul(e) wurden durchsucht Durchsuche Prozess 'winamp.exe' - '165' Modul(e) wurden durchsucht Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '16' Modul(e) wurden durchsucht Durchsuche Prozess 'wininit.exe' - '26' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '16' Modul(e) wurden durchsucht Durchsuche Prozess 'services.exe' - '33' Modul(e) wurden durchsucht Durchsuche Prozess 'lsass.exe' - '64' Modul(e) wurden durchsucht Durchsuche Prozess 'lsm.exe' - '16' Modul(e) wurden durchsucht Durchsuche Prozess 'winlogon.exe' - '31' Modul(e) wurden durchsucht Ende des Suchlaufs: Samstag, 7. Juni 2014 13:16 Benötigte Zeit: 02:42 Minute(n) Der Suchlauf wurde vollständig durchgeführt. 0 Verzeichnisse wurden überprüft 6684 Dateien wurden geprüft 1 Viren bzw. unerwünschte Programme wurden gefunden 0 Dateien wurden als verdächtig eingestuft 0 Dateien wurden gelöscht 0 Viren bzw. unerwünschte Programme wurden repariert 0 Dateien wurden in die Quarantäne verschoben 0 Dateien wurden umbenannt 0 Dateien konnten nicht durchsucht werden 6683 Dateien ohne Befall 25 Archive wurden durchsucht 1 Warnungen 0 Hinweise 577808 Objekte wurden beim Rootkitscan durchsucht 0 Versteckte Objekte wurden gefunden Geändert von xXFenrizXx (07.06.2014 um 12:17 Uhr) |
08.06.2014, 09:29 | #6 |
/// the machine /// TB-Ausbilder | TR/Drop.Softomat.AN/Windows 7 64 Bit Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> TR/Drop.Softomat.AN/Windows 7 64 Bit |
10.06.2014, 13:14 | #7 |
| TR/Drop.Softomat.AN/Windows 7 64 Bit Sorry war paar Tage nicht da Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 10.06.2014 Suchlauf-Zeit: 13:49:53 Logdatei: Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.06.10.03 Rootkit Datenbank: v2014.06.02.01 Lizenz: Premium Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 CPU: x64 Dateisystem: NTFS Benutzer: David Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 268904 Verstrichene Zeit: 6 Min, 42 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.207 - Bericht erstellt am 11/05/2014 um 18:17:23 # Aktualisiert 05/05/2014 von Xplode # Betriebssystem : Windows 7 Professional (64 bits) # Benutzername : David - MONGREL # Gestartet von : C:\Users\David\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** [!] Ordner Gelöscht : C:\Windows\SysWOW64\AI_RecycleBin ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C} Schlüssel Gelöscht : HKLM\Software\InstallCore ***** [ Browser ] ***** -\\ Internet Explorer v8.0.7600.16385 -\\ Google Chrome v26.0.1410.40 [ Datei : C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms} Gelöscht [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo Gelöscht [Extension] : hphibigbodkkohoglgfkddblldpfohjl Gelöscht [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej Gelöscht [Extension] : kincjchfokkeneeofpeefomkikfkiedl Gelöscht [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc ************************* AdwCleaner[R0].txt - [2670 octets] - [11/05/2014 18:12:04] AdwCleaner[S0].txt - [2587 octets] - [11/05/2014 18:17:23] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2647 octets] ########## AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.212 - Bericht erstellt am 10/06/2014 um 14:16:14 # Aktualisiert 05/06/2014 von Xplode # Betriebssystem : Windows 7 Professional (64 bits) # Benutzername : David - MONGREL # Gestartet von : C:\Users\David\Downloads\adwcleaner_3.212.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SpeeDial_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SpeeDial_RASMANCS Schlüssel Gelöscht : HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v8.0.7600.16385 -\\ Google Chrome v26.0.1410.40 [ Datei : C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms} Gelöscht [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc ************************* AdwCleaner[R0].txt - [3900 octets] - [11/05/2014 18:12:04] AdwCleaner[R1].txt - [1359 octets] - [10/06/2014 14:15:44] AdwCleaner[S0].txt - [3909 octets] - [11/05/2014 18:17:23] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3969 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Professional x64 Ran by David on 10.06.2014 at 14:21:04,84 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 10.06.2014 at 14:24:47,33 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-06-2014 Ran by David (administrator) on MONGREL on 10-06-2014 14:28:10 Running from C:\Users\David\Desktop Platform: Windows 7 Professional (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe () C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe () D:\Programme\RocketDock\RocketDock.exe (Akamai Technologies, Inc.) C:\Users\David\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\David\AppData\Local\Akamai\netsession_win.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\KoneXTDMonitor.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Windows\system\cm106eye.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Raptr, Inc) C:\Program Files (x86)\Raptr\raptr.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Raptr, Inc) C:\Program Files (x86)\Raptr\raptr_im.exe (Raptr Inc.) C:\Program Files (x86)\Raptr\raptr_ep64.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [Cm106Sound] => C:\Windows\Syswow64\cm106.dll [8151040 2009-10-20] (C-Media Corporation) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-09-03] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM-x32\...\Run: [RoccatKoneXTD] => C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\KoneXTDMonitor.EXE [552960 2013-10-25] (ROCCAT GmbH) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2691480 2014-03-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-27] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [182352 2014-05-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [RocketDock] => D:\Programme\RocketDock\RocketDock.exe [495616 2007-09-02] () HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [Akamai NetSession Interface] => C:\Users\David\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55360 2014-05-15] (Raptr, Inc) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [HP Deskjet 3050 J610 series (NET)] => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= SearchScopes: HKCU - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 Tcpip\..\Interfaces\{A395CEDE-D5A6-48E6-8CC2-506A45065462}: [NameServer] FireFox: ======== FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: adobe.com/AdobeExManCCDetect32 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect32.dll (Adobe Systems) FF Plugin HKCU: adobe.com/AdobeExManCCDetect64 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect64.dll (Adobe Systems) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://google.de/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-01] CHR Extension: (Adblock Plus) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-01] CHR Extension: (Type Scout) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\fedokkaolmkkoeedicihicdeppjjeamj [2014-05-01] CHR Extension: (AdBlock) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-01] CHR Extension: (TabJump - Intelligenter Tab-Navigator) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokofmgcicpnjchllaccgedmmmbbnbmf [2014-05-01] CHR Extension: (Google Mail-Checker) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-05-01] CHR Extension: (WGT Golf Game) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpedbpkelbhcbkdaglillalioeeekbpb [2014-05-01] CHR Extension: (Google Mail) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-01] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [124496 2014-05-05] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-05-09] () [File not signed] R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2011-06-17] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-27] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-27] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [495376 2013-05-30] (Intel Corporation) U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.) S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [238080 2012-04-23] (Huawei Technologies Co., Ltd.) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-10] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation) R3 USBMULCD; C:\Windows\System32\drivers\CM10664.sys [1307648 2009-10-01] (C-Media Electronics Inc) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-10 14:28 - 2014-06-10 14:28 - 00000000 ____D () C:\Users\David\Desktop\FRST-OlderVersion 2014-06-10 14:24 - 2014-06-10 14:24 - 00000695 _____ () C:\Users\David\Desktop\JRT.txt 2014-06-10 13:55 - 2014-06-10 13:55 - 01016261 _____ (Thisisu) C:\Users\David\Desktop\JRT.exe 2014-06-10 13:50 - 2014-06-10 13:51 - 01333465 _____ () C:\Users\David\Downloads\adwcleaner_3.212.exe 2014-06-07 13:13 - 2014-06-07 13:13 - 00001633 _____ () C:\Users\David\Desktop\avcenter.lnk 2014-06-07 13:07 - 2014-06-07 13:07 - 00034127 _____ () C:\ComboFix.txt 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-07 12:59 - 2014-06-07 13:07 - 00000000 ____D () C:\Qoobox 2014-06-07 12:59 - 2014-06-07 13:06 - 00000000 ____D () C:\Windows\erdnt 2014-06-07 12:59 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-07 12:59 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-07 12:59 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-07 12:59 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-07 12:59 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-07 12:59 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-07 12:59 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-07 12:59 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-07 12:56 - 2014-06-07 12:57 - 05205146 ____R (Swearware) C:\Users\David\Desktop\ComboFix.exe 2014-06-07 12:47 - 2014-06-07 12:47 - 00001268 _____ () C:\Users\David\Desktop\Revo Uninstaller.lnk 2014-06-07 12:47 - 2014-06-07 12:47 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-06-07 12:46 - 2014-06-07 12:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\David\Downloads\revosetup95.exe 2014-06-06 21:16 - 2014-06-07 15:57 - 00001019 _____ () C:\Users\David\Desktop\Werbung.txt 2014-06-06 13:54 - 2010-11-20 14:16 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2014-06-06 13:33 - 2014-06-06 13:38 - 00126464 _____ () C:\Windows\SysWOW64\audiodg.exe 2014-06-05 20:25 - 2014-06-05 20:25 - 00032537 _____ () C:\Users\David\Desktop\Addition.txt 2014-06-05 17:05 - 2014-06-05 17:05 - 00076918 _____ () C:\Users\David\Desktop\GMER.txt 2014-06-05 16:56 - 2014-06-05 16:56 - 00380416 _____ () C:\Users\David\Desktop\Gmer-19357.exe 2014-06-05 16:55 - 2014-06-10 14:28 - 00016479 _____ () C:\Users\David\Desktop\FRST.txt 2014-06-05 16:54 - 2014-06-10 14:28 - 02080768 _____ (Farbar) C:\Users\David\Desktop\FRST64.exe 2014-06-05 16:53 - 2014-06-05 16:53 - 00001510 _____ () C:\Users\David\Desktop\Malwarebytes.txt 2014-06-05 15:59 - 2014-06-06 12:53 - 00000000 ____D () C:\Users\David\AppData\Roaming\Apple Computer 2014-06-05 15:59 - 2014-06-05 15:59 - 00000000 ____D () C:\Users\David\AppData\Local\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Users\David\AppData\Local\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-06-05 15:54 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-06-05 15:47 - 2014-06-05 15:48 - 41945432 _____ (Apple Inc.) C:\Users\David\Downloads\QuickTimeInstaller.exe 2014-06-05 15:45 - 2014-06-05 15:46 - 00000000 ____D () C:\Users\David\AppData\Roaming\vlc 2014-06-05 15:40 - 2014-06-05 15:41 - 25531584 _____ () C:\Users\David\Downloads\vlc-2.1.3-win32.exe 2014-06-03 14:47 - 2014-06-03 14:51 - 44199212 _____ () C:\Users\David\Downloads\Pentakill-SmiteandIgnite.zip 2014-06-03 14:15 - 2014-06-03 14:15 - 00000000 ____D () C:\Users\David\AppData\Roaming\OBS 2014-06-03 14:14 - 2014-06-03 14:14 - 00961360 _____ (Chip Digital GmbH) C:\Users\David\Downloads\Open Broadcaster Software - CHIP-Installer.exe 2014-06-02 23:20 - 2014-06-03 14:31 - 16849882 _____ () C:\Users\David\Downloads\Season-4-Overlay-Mega-Pack-by-Temporalcortex.zip 2014-06-02 16:41 - 2014-06-02 16:58 - 00026934 _____ () C:\Users\David\Downloads\debug.log 2014-06-02 16:32 - 2014-06-02 16:32 - 00000796 _____ () C:\Users\Public\Desktop\XSplit Broadcaster.lnk 2014-06-02 16:32 - 2014-06-02 16:32 - 00000000 ____D () C:\Users\David\AppData\Local\SplitMediaLabs 2014-06-02 16:30 - 2014-06-10 14:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-02 16:30 - 2014-06-02 16:30 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-02 16:30 - 2014-06-02 16:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-02 16:30 - 2014-06-02 16:30 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\system32\Macromed 2014-06-02 16:28 - 2014-06-02 16:29 - 42360392 _____ (SplitMediaLabs) C:\Users\David\Downloads\xsplit_bc_installer.exe 2014-06-02 16:21 - 2014-06-02 16:21 - 00000000 ____D () C:\Users\David\AppData\Local\IsolatedStorage 2014-06-02 15:59 - 2014-06-02 16:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit 2014-06-02 15:59 - 2014-06-02 15:59 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-06-02 15:58 - 2014-06-02 16:31 - 00000000 ____D () C:\Users\David\AppData\Roaming\SplitmediaLabs 2014-06-02 15:55 - 2014-06-02 15:57 - 46455952 _____ (SplitmediaLabs) C:\Users\David\Downloads\xsplit_gc_installer.exe 2014-05-31 19:39 - 2014-05-31 19:39 - 00111788 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget (1).zip 2014-05-31 19:12 - 2014-05-31 19:12 - 00112213 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget.zip 2014-05-31 15:04 - 2014-06-03 15:23 - 00150528 ___SH () C:\Users\David\Thumbs.db 2014-05-30 15:01 - 2014-06-03 15:23 - 00000132 _____ () C:\Users\David\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen 2014-05-26 18:37 - 2014-05-26 18:37 - 01677440 _____ (Skype Technologies S.A.) C:\Users\David\Downloads\SkypeSetup (1).exe 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_juextctrl_01007.Wdf 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf 2014-05-26 12:07 - 2014-05-26 12:07 - 00001245 _____ () C:\Users\Public\Desktop\Internet Manager.lnk 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Manager 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Internet Manager 2014-05-26 12:07 - 2012-04-26 05:04 - 00450048 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbwwan.sys 2014-05-26 12:07 - 2012-04-23 03:58 - 00238080 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juwwanecm.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00104448 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcacm.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00090112 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00076800 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00030720 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys 2014-05-26 12:07 - 2011-12-31 03:20 - 00225920 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2014-05-26 12:07 - 2011-08-16 10:40 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2014-05-26 12:07 - 2011-08-16 10:40 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01007.dll 2014-05-26 12:07 - 2010-10-08 10:59 - 00032768 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys 2014-05-26 12:07 - 2010-09-26 12:09 - 00022016 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys 2014-05-26 12:07 - 2010-08-06 01:43 - 01001472 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys 2014-05-26 12:07 - 2010-07-27 03:52 - 00117248 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys 2014-05-26 12:07 - 2010-03-20 06:06 - 00013952 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys 2014-05-26 12:06 - 2014-05-26 12:06 - 00000000 ____D () C:\Program Files (x86)\T-Mobile 2014-05-26 12:03 - 2014-05-26 12:08 - 00000000 ____D () C:\ProgramData\DatacardService 2014-05-18 15:41 - 2014-05-18 15:42 - 00000036 _____ () C:\Users\David\Malwarebytes ID.txt 2014-05-12 17:22 - 2014-05-12 17:22 - 00056100 _____ () C:\Windows\SysWOW64\CCCInstall_201405121722165928.log 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\ProgramData\ATI 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-05-12 17:20 - 2014-05-12 17:20 - 00000000 ____D () C:\Program Files\AMD 2014-05-12 17:17 - 2014-05-19 19:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\HpUpdate 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\ProgramData\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\Program Files\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\Program Files (x86)\HP 2014-05-12 17:17 - 2012-10-17 04:31 - 00741480 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPM9311.dll 2014-05-12 17:16 - 2014-05-12 17:18 - 00000000 ____D () C:\Users\David\AppData\Local\HP 2014-05-12 17:16 - 2014-05-12 17:16 - 00000057 _____ () C:\ProgramData\Ament.ini 2014-05-12 17:13 - 2014-05-12 17:15 - 56732448 _____ () C:\Users\David\Downloads\DJ3050_J610_1315.exe 2014-05-12 15:36 - 2014-05-12 15:43 - 269338400 _____ (AMD Inc.) C:\Users\David\Downloads\14-4-win7-win8-win8.1-64-dd-ccc-whql.exe 2014-05-12 00:18 - 2014-05-13 21:27 - 00000000 ____D () C:\Users\David\Documents\dragoon 2014-05-12 00:06 - 2014-06-10 14:18 - 00000000 ____D () C:\Users\David\AppData\Roaming\Raptr 2014-05-12 00:06 - 2014-05-22 19:04 - 00000000 ____D () C:\Program Files (x86)\Raptr 2014-05-12 00:06 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Raptr 2014-05-12 00:06 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\library_dir 2014-05-12 00:02 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-05-12 00:02 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-05-12 00:02 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-05-12 00:02 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-05-12 00:02 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-05-12 00:02 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-05-12 00:02 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-05-12 00:00 - 2014-05-12 00:00 - 00000826 _____ () C:\Users\Public\Desktop\Dragon's Prophet.lnk 2014-05-12 00:00 - 2014-05-12 00:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragon's Prophet 2014-05-11 23:55 - 2014-05-12 00:19 - 00000000 ____D () C:\Users\David\Desktop\Neuer Ordner 2014-05-11 23:55 - 2014-05-11 23:55 - 00000000 ____D () C:\Users\David\AppData\Local\Akamai 2014-05-11 23:54 - 2014-05-11 23:54 - 10551808 _____ (Akamai Technologies, Inc.) C:\Users\David\Downloads\my_downloader_installer.exe 2014-05-11 23:44 - 2014-05-16 11:33 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-11 23:44 - 2014-05-11 23:44 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-05-11 18:36 - 2014-05-12 00:21 - 00000000 ____D () C:\ProgramData\Solid State Networks 2014-05-11 18:36 - 2014-05-11 18:36 - 01495552 _____ (Infernum Productions AG) C:\Users\David\Downloads\DragonsProphetDLM.exe 2014-05-11 18:21 - 2014-05-11 18:21 - 00000000 ____D () C:\Windows\ERUNT 2014-05-11 18:12 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-11 18:11 - 2014-06-10 14:16 - 00000000 ____D () C:\AdwCleaner 2014-05-11 13:30 - 2014-05-11 13:30 - 00001440 _____ () C:\Users\Public\Desktop\Free YouTube Download.lnk 2014-05-11 13:28 - 2014-05-11 13:29 - 32355208 _____ (DVDVideoSoft Ltd. ) C:\Users\David\Downloads\FreeYouTubeDownload.exe ==================== One Month Modified Files and Folders ======= 2014-06-10 14:28 - 2014-06-10 14:28 - 00000000 ____D () C:\Users\David\Desktop\FRST-OlderVersion 2014-06-10 14:28 - 2014-06-05 16:55 - 00016479 _____ () C:\Users\David\Desktop\FRST.txt 2014-06-10 14:28 - 2014-06-05 16:54 - 02080768 _____ (Farbar) C:\Users\David\Desktop\FRST64.exe 2014-06-10 14:28 - 2014-05-08 15:54 - 00000000 ____D () C:\FRST 2014-06-10 14:28 - 2014-05-01 16:56 - 00000000 ____D () C:\Users\David\AppData\Local\Temp 2014-06-10 14:24 - 2014-06-10 14:24 - 00000695 _____ () C:\Users\David\Desktop\JRT.txt 2014-06-10 14:24 - 2009-07-14 06:45 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-10 14:24 - 2009-07-14 06:45 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-10 14:20 - 2014-05-01 16:56 - 01469286 _____ () C:\Windows\WindowsUpdate.log 2014-06-10 14:18 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\Raptr 2014-06-10 14:17 - 2014-05-08 15:36 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-10 14:17 - 2014-05-01 17:03 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-10 14:17 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-10 14:17 - 2009-07-14 06:51 - 00035745 _____ () C:\Windows\setupact.log 2014-06-10 14:16 - 2014-05-11 18:11 - 00000000 ____D () C:\AdwCleaner 2014-06-10 14:16 - 2014-05-01 17:43 - 00091794 _____ () C:\Windows\PFRO.log 2014-06-10 14:15 - 2014-05-01 17:15 - 00000000 ____D () C:\Users\David\AppData\Local\PMB Files 2014-06-10 14:15 - 2014-05-01 17:15 - 00000000 ____D () C:\ProgramData\PMB Files 2014-06-10 14:08 - 2014-05-01 17:03 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-10 14:01 - 2014-06-02 16:30 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-10 13:55 - 2014-06-10 13:55 - 01016261 _____ (Thisisu) C:\Users\David\Desktop\JRT.exe 2014-06-10 13:54 - 2014-05-03 18:47 - 00000000 ____D () C:\Users\David\AppData\Local\Adobe 2014-06-10 13:51 - 2014-06-10 13:50 - 01333465 _____ () C:\Users\David\Downloads\adwcleaner_3.212.exe 2014-06-08 13:14 - 2014-05-01 17:57 - 00000000 ____D () C:\Users\David\AppData\Roaming\TS3Client 2014-06-07 15:57 - 2014-06-06 21:16 - 00001019 _____ () C:\Users\David\Desktop\Werbung.txt 2014-06-07 14:55 - 2014-05-01 17:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-06-07 14:52 - 2014-05-01 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2014-06-07 13:13 - 2014-06-07 13:13 - 00001633 _____ () C:\Users\David\Desktop\avcenter.lnk 2014-06-07 13:07 - 2014-06-07 13:07 - 00034127 _____ () C:\ComboFix.txt 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-07 13:07 - 2014-06-07 12:59 - 00000000 ____D () C:\Qoobox 2014-06-07 13:07 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-06-07 13:06 - 2014-06-07 12:59 - 00000000 ____D () C:\Windows\erdnt 2014-06-07 13:04 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-06-07 12:57 - 2014-06-07 12:56 - 05205146 ____R (Swearware) C:\Users\David\Desktop\ComboFix.exe 2014-06-07 12:47 - 2014-06-07 12:47 - 00001268 _____ () C:\Users\David\Desktop\Revo Uninstaller.lnk 2014-06-07 12:47 - 2014-06-07 12:47 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-06-07 12:47 - 2014-06-07 12:46 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\David\Downloads\revosetup95.exe 2014-06-06 13:38 - 2014-06-06 13:33 - 00126464 _____ () C:\Windows\SysWOW64\audiodg.exe 2014-06-06 12:53 - 2014-06-05 15:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\Apple Computer 2014-06-05 20:25 - 2014-06-05 20:25 - 00032537 _____ () C:\Users\David\Desktop\Addition.txt 2014-06-05 17:05 - 2014-06-05 17:05 - 00076918 _____ () C:\Users\David\Desktop\GMER.txt 2014-06-05 16:58 - 2014-05-01 17:52 - 00000000 ____D () C:\Users\David\AppData\Roaming\Skype 2014-06-05 16:56 - 2014-06-05 16:56 - 00380416 _____ () C:\Users\David\Desktop\Gmer-19357.exe 2014-06-05 16:53 - 2014-06-05 16:53 - 00001510 _____ () C:\Users\David\Desktop\Malwarebytes.txt 2014-06-05 15:59 - 2014-06-05 15:59 - 00000000 ____D () C:\Users\David\AppData\Local\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Users\David\AppData\Local\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-06-05 15:58 - 2014-06-05 15:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-06-05 15:48 - 2014-06-05 15:47 - 41945432 _____ (Apple Inc.) C:\Users\David\Downloads\QuickTimeInstaller.exe 2014-06-05 15:46 - 2014-06-05 15:45 - 00000000 ____D () C:\Users\David\AppData\Roaming\vlc 2014-06-05 15:41 - 2014-06-05 15:40 - 25531584 _____ () C:\Users\David\Downloads\vlc-2.1.3-win32.exe 2014-06-05 13:07 - 2014-05-01 17:52 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-06-05 13:07 - 2014-05-01 17:52 - 00000000 ____D () C:\ProgramData\Skype 2014-06-04 18:35 - 2009-07-14 19:58 - 00699726 _____ () C:\Windows\system32\perfh007.dat 2014-06-04 18:35 - 2009-07-14 19:58 - 00149364 _____ () C:\Windows\system32\perfc007.dat 2014-06-04 18:35 - 2009-07-14 07:13 - 01621742 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-03 15:23 - 2014-05-31 15:04 - 00150528 ___SH () C:\Users\David\Thumbs.db 2014-06-03 15:23 - 2014-05-30 15:01 - 00000132 _____ () C:\Users\David\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen 2014-06-03 15:23 - 2014-05-01 16:56 - 00000000 ____D () C:\Users\David 2014-06-03 14:51 - 2014-06-03 14:47 - 44199212 _____ () C:\Users\David\Downloads\Pentakill-SmiteandIgnite.zip 2014-06-03 14:31 - 2014-06-02 23:20 - 16849882 _____ () C:\Users\David\Downloads\Season-4-Overlay-Mega-Pack-by-Temporalcortex.zip 2014-06-03 14:15 - 2014-06-03 14:15 - 00000000 ____D () C:\Users\David\AppData\Roaming\OBS 2014-06-03 14:14 - 2014-06-03 14:14 - 00961360 _____ (Chip Digital GmbH) C:\Users\David\Downloads\Open Broadcaster Software - CHIP-Installer.exe 2014-06-02 16:58 - 2014-06-02 16:41 - 00026934 _____ () C:\Users\David\Downloads\debug.log 2014-06-02 16:32 - 2014-06-02 16:32 - 00000796 _____ () C:\Users\Public\Desktop\XSplit Broadcaster.lnk 2014-06-02 16:32 - 2014-06-02 16:32 - 00000000 ____D () C:\Users\David\AppData\Local\SplitMediaLabs 2014-06-02 16:32 - 2014-06-02 15:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit 2014-06-02 16:31 - 2014-06-02 15:58 - 00000000 ____D () C:\Users\David\AppData\Roaming\SplitmediaLabs 2014-06-02 16:30 - 2014-06-02 16:30 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-02 16:30 - 2014-06-02 16:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-02 16:30 - 2014-06-02 16:30 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\system32\Macromed 2014-06-02 16:29 - 2014-06-02 16:28 - 42360392 _____ (SplitMediaLabs) C:\Users\David\Downloads\xsplit_bc_installer.exe 2014-06-02 16:21 - 2014-06-02 16:21 - 00000000 ____D () C:\Users\David\AppData\Local\IsolatedStorage 2014-06-02 15:59 - 2014-06-02 15:59 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-06-02 15:57 - 2014-06-02 15:55 - 46455952 _____ (SplitmediaLabs) C:\Users\David\Downloads\xsplit_gc_installer.exe 2014-05-31 19:39 - 2014-05-31 19:39 - 00111788 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget (1).zip 2014-05-31 19:12 - 2014-05-31 19:12 - 00112213 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget.zip 2014-05-31 13:45 - 2014-05-08 15:36 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-27 11:28 - 2014-05-07 00:03 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-27 11:28 - 2014-05-07 00:03 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-26 18:37 - 2014-05-26 18:37 - 01677440 _____ (Skype Technologies S.A.) C:\Users\David\Downloads\SkypeSetup (1).exe 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_juextctrl_01007.Wdf 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf 2014-05-26 12:08 - 2014-05-26 12:03 - 00000000 ____D () C:\ProgramData\DatacardService 2014-05-26 12:07 - 2014-05-26 12:07 - 00001245 _____ () C:\Users\Public\Desktop\Internet Manager.lnk 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Manager 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Internet Manager 2014-05-26 12:06 - 2014-05-26 12:06 - 00000000 ____D () C:\Program Files (x86)\T-Mobile 2014-05-22 19:04 - 2014-05-12 00:06 - 00000000 ____D () C:\Program Files (x86)\Raptr 2014-05-19 19:59 - 2014-05-12 17:17 - 00000000 ____D () C:\Users\David\AppData\Roaming\HpUpdate 2014-05-18 15:42 - 2014-05-18 15:41 - 00000036 _____ () C:\Users\David\Malwarebytes ID.txt 2014-05-16 11:33 - 2014-05-11 23:44 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-13 21:27 - 2014-05-12 00:18 - 00000000 ____D () C:\Users\David\Documents\dragoon 2014-05-12 17:22 - 2014-05-12 17:22 - 00056100 _____ () C:\Windows\SysWOW64\CCCInstall_201405121722165928.log 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\ProgramData\ATI 2014-05-12 17:22 - 2014-05-12 17:22 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-05-12 17:22 - 2014-05-01 17:34 - 00000000 ____D () C:\ProgramData\AMD 2014-05-12 17:21 - 2014-05-01 17:27 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-05-12 17:20 - 2014-05-12 17:20 - 00000000 ____D () C:\Program Files\AMD 2014-05-12 17:19 - 2014-05-01 17:30 - 00000000 ____D () C:\ProgramData\Package Cache 2014-05-12 17:18 - 2014-05-12 17:16 - 00000000 ____D () C:\Users\David\AppData\Local\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\ProgramData\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\Program Files\HP 2014-05-12 17:17 - 2014-05-12 17:17 - 00000000 ____D () C:\Program Files (x86)\HP 2014-05-12 17:16 - 2014-05-12 17:16 - 00000057 _____ () C:\ProgramData\Ament.ini 2014-05-12 17:15 - 2014-05-12 17:13 - 56732448 _____ () C:\Users\David\Downloads\DJ3050_J610_1315.exe 2014-05-12 17:11 - 2014-05-01 17:33 - 00000000 ____D () C:\AMD 2014-05-12 15:43 - 2014-05-12 15:36 - 269338400 _____ (AMD Inc.) C:\Users\David\Downloads\14-4-win7-win8-win8.1-64-dd-ccc-whql.exe 2014-05-12 15:38 - 2014-05-06 23:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-12 15:38 - 2014-05-06 23:46 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-12 07:26 - 2014-05-08 15:36 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-05-08 15:36 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-05-08 15:36 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-12 00:21 - 2014-05-11 18:36 - 00000000 ____D () C:\ProgramData\Solid State Networks 2014-05-12 00:19 - 2014-05-11 23:55 - 00000000 ____D () C:\Users\David\Desktop\Neuer Ordner 2014-05-12 00:06 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Raptr 2014-05-12 00:06 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\library_dir 2014-05-12 00:02 - 2014-05-06 23:41 - 00045035 _____ () C:\Windows\DirectX.log 2014-05-12 00:00 - 2014-05-12 00:00 - 00000826 _____ () C:\Users\Public\Desktop\Dragon's Prophet.lnk 2014-05-12 00:00 - 2014-05-12 00:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragon's Prophet 2014-05-11 23:55 - 2014-05-11 23:55 - 00000000 ____D () C:\Users\David\AppData\Local\Akamai 2014-05-11 23:54 - 2014-05-11 23:54 - 10551808 _____ (Akamai Technologies, Inc.) C:\Users\David\Downloads\my_downloader_installer.exe 2014-05-11 23:47 - 2014-05-03 18:40 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-11 23:47 - 2014-05-01 19:37 - 00000000 ____D () C:\Users\David\AppData\Roaming\Adobe 2014-05-11 23:44 - 2014-05-11 23:44 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-05-11 23:44 - 2014-05-03 18:52 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-05-11 22:56 - 2014-05-03 20:27 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-05-11 18:36 - 2014-05-11 18:36 - 01495552 _____ (Infernum Productions AG) C:\Users\David\Downloads\DragonsProphetDLM.exe 2014-05-11 18:21 - 2014-05-11 18:21 - 00000000 ____D () C:\Windows\ERUNT 2014-05-11 13:31 - 2014-05-01 18:39 - 00000000 ____D () C:\Users\David\AppData\Roaming\DVDVideoSoft 2014-05-11 13:30 - 2014-05-11 13:30 - 00001440 _____ () C:\Users\Public\Desktop\Free YouTube Download.lnk 2014-05-11 13:30 - 2014-05-01 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2014-05-11 13:30 - 2014-05-01 18:39 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-05-11 13:29 - 2014-05-11 13:28 - 32355208 _____ (DVDVideoSoft Ltd. ) C:\Users\David\Downloads\FreeYouTubeDownload.exe 2014-05-11 12:44 - 2014-05-04 23:44 - 00000000 ___RD () C:\Users\David\Desktop\Games Some content of TEMP: ==================== C:\Users\David\AppData\Local\Temp\avgnt.exe C:\Users\David\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-05-31 13:18 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-06-2014 Ran by David at 2014-06-10 14:28:27 Running from C:\Users\David\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.5.0.367 - Adobe Systems Incorporated) Adobe Dreamweaver CC (HKLM-x32\...\{00E094E1-A852-11E2-803D-ACEA632352B4}) (Version: 13 - Adobe Systems Incorporated) Adobe Extension Manager CC (HKLM-x32\...\{244FD30F-63F1-49B9-9D98-1150FF4FFCB1}) (Version: 7.1.1 - Adobe Systems Incorporated) Adobe Flash Player 11 ActiveX (HKLM-x32\...\{E94EFAB6-653F-4837-9E8A-F6377CA1EC0D}) (Version: 11.8.800.175 - Adobe Systems Incorporated) Adobe Photoshop CC (HKLM-x32\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc) AMD Accelerated Video Transcoding (Version: 13.30.100.40417 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2014.0417.2226.38446 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{6119B3A6-3603-9695-0398-CDF2AF0A13F8}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.80911.2216 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.15 - Advanced Micro Devices, Inc.) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Arma 2 (HKLM-x32\...\Steam App 33900) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead (HKLM-x32\...\Steam App 33930) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead Beta (HKLM-x32\...\Steam App 219540) (Version: - ) Avira (HKLM-x32\...\{70a79d1f-686d-4d5c-962b-07aa1294eae0}) (Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) DayZ Commander (HKLM-x32\...\{B3653588-3AC0-4A1D-950F-D96531E84374}) (Version: 0.92.91 - Dotjosh Studios) Dragon's Prophet (HKLM-x32\...\{C31556D7-F2B9-4787-B223-F7A035067E89}_is1) (Version: 2.0.1349.21 - Infernum Productions AG) Free YouTube Download version 3.2.34.430 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.34.430 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.34.430 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.34.430 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 26.0.1410.40 - Google Inc.) Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden HP Deskjet 3050 J610 series - Grundlegende Software für das Gerät (HKLM\...\{EF3293DE-FCAC-4742-91BF-AD0174143FC3}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Network Connections 18.5.54.0 (HKLM\...\PROSetDX) (Version: 18.5.54.0 - Intel) Intel(R) Network Connections 18.5.54.0 (Version: 18.5.54.0 - Intel) Hidden Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation) Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.18.68.55 - Huawei Technologies Co.,Ltd) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Left 4 Dead (HKLM-x32\...\Steam App 500) (Version: - Valve) Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.154 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Raptr (HKLM-x32\...\Raptr) (Version: - ) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) ROCCAT Kone XTD Mouse Driver (HKLM-x32\...\{7133137D-DF48-4522-AD88-13C82B7D0A63}) (Version: - Roccat GmbH) RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software) Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) USB Multi-Channel Audio Device (HKLM\...\C-Media CM106 Like Sound Driver) (Version: - ) VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) XSplit Broadcaster (HKLM-x32\...\{3A1F3A32-7E9D-4AD2-A2E2-DFC98BAA9DC7}) (Version: 1.3.1403.1202 - SplitMediaLabs) XSplit Gamecaster (HKLM-x32\...\{C5E8E927-8182-40D0-8718-ED74E5C0690A}) (Version: 1.7.1405.2114 - SplitmediaLabs) ==================== Restore Points ========================= 26-05-2014 17:15:58 Geplanter Prüfpunkt 02-06-2014 13:58:55 Installed XSplit Gamecaster 02-06-2014 14:30:22 Installed Adobe Flash Player 11 ActiveX. 02-06-2014 14:32:26 Installed XSplit Broadcaster 05-06-2014 13:54:19 Installed QuickTime 7 05-06-2014 13:58:09 Installed QuickTime 7 07-06-2014 10:54:24 Revo Uninstaller's restore point - Speedial ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-06-07 13:02 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {312E2046-82A0-450F-8497-4FFBC6FEC623} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-01] (Google Inc.) Task: {321826E4-3D5B-4EA4-A7F2-A06FFD4092D3} - System32\Tasks\AdobeAAMUpdater-1.0-Mongrel-David => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated) Task: {743E8047-E9DE-45B1-BF85-54DD421FEC8B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {7FB71025-B02D-4B48-A07D-6BDD38B91116} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-01] (Google Inc.) Task: {EC8DE1A6-566C-4753-9372-C5513FBF4946} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-02] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-14 17:27 - 2011-03-14 17:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2014-05-26 12:07 - 2011-06-17 13:04 - 00224096 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe 2014-06-10 13:44 - 2011-06-17 13:04 - 01434464 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe 2014-02-11 20:21 - 2014-02-11 20:21 - 00860160 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 01043968 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-02-11 20:21 - 2014-02-11 20:21 - 00052736 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 00236032 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-05-01 17:56 - 2007-09-02 13:58 - 00495616 _____ () D:\Programme\RocketDock\RocketDock.exe 2014-05-01 18:11 - 2009-11-12 14:25 - 00221184 _____ () C:\Windows\system\Cm106eye.exe 2014-03-20 11:24 - 2014-03-20 11:24 - 05288608 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe 2014-03-20 11:24 - 2014-03-20 11:24 - 00667808 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll 2014-05-26 12:07 - 2009-01-10 12:32 - 00011362 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll 2014-05-26 12:07 - 2009-06-22 20:42 - 00043008 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll 2014-05-26 12:07 - 2010-05-05 10:47 - 02415104 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll 2014-05-26 12:07 - 2010-02-10 16:10 - 01148416 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll 2014-05-05 10:37 - 2014-05-05 10:37 - 00138320 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll 2014-05-05 10:37 - 2014-05-05 10:37 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2014-05-26 12:07 - 2010-02-10 16:43 - 09515520 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtGui4.dll 2014-06-10 13:44 - 2012-10-08 03:41 - 00082944 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\plugins\imageformats\qgif4.dll 2014-06-10 13:44 - 2012-10-08 03:41 - 00081920 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\plugins\imageformats\qico4.dll 2014-05-01 17:56 - 2007-09-02 13:57 - 00069632 _____ () D:\Programme\RocketDock\RocketDock.dll 2014-05-01 18:40 - 2012-06-17 11:20 - 00061440 _____ () C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\hiddriver.dll 2014-03-18 23:22 - 2014-03-18 23:22 - 32733088 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll 2014-06-07 13:05 - 2014-05-05 10:37 - 00049744 _____ () C:\Users\David\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2014-05-01 18:11 - 2006-09-13 13:08 - 00491520 _____ () C:\Windows\system\CmAu106.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00087040 _____ () C:\Program Files (x86)\Raptr\_ctypes.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00043008 _____ () C:\Program Files (x86)\Raptr\_socket.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00805376 _____ () C:\Program Files (x86)\Raptr\_ssl.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 05812736 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtGui.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00067584 _____ () C:\Program Files (x86)\Raptr\sip.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 01662464 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtCore.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00494592 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtNetwork.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00096256 _____ () C:\Program Files (x86)\Raptr\win32api.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00110592 _____ () C:\Program Files (x86)\Raptr\pywintypes26.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00324608 _____ () C:\Program Files (x86)\Raptr\PIL._imaging.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00356864 _____ () C:\Program Files (x86)\Raptr\_hashlib.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00036352 _____ () C:\Program Files (x86)\Raptr\win32process.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00111104 _____ () C:\Program Files (x86)\Raptr\win32file.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00124928 _____ () C:\Program Files (x86)\Raptr\_elementtree.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00127488 _____ () C:\Program Files (x86)\Raptr\pyexpat.pyd 2012-02-06 22:28 - 2012-02-06 22:28 - 00031744 _____ () C:\Program Files (x86)\Raptr\Crypto.Cipher.AES.pyd 2012-02-06 22:28 - 2012-02-06 22:28 - 00010752 _____ () C:\Program Files (x86)\Raptr\Crypto.Random.OSRNG.winrandom.pyd 2012-02-06 22:28 - 2012-02-06 22:28 - 00011264 _____ () C:\Program Files (x86)\Raptr\Crypto.Util._counter.pyd 2011-05-10 21:01 - 2011-05-10 21:01 - 00030208 _____ () C:\Program Files (x86)\Raptr\simplejson._speedups.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00313856 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtWebKit.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00044544 _____ () C:\Program Files (x86)\Raptr\_sqlite3.pyd 2011-02-15 20:17 - 2011-02-15 20:17 - 00417501 _____ () C:\Program Files (x86)\Raptr\sqlite3.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00354304 _____ () C:\Program Files (x86)\Raptr\pythoncom26.dll 2010-11-23 00:57 - 2010-11-23 00:57 - 00016384 _____ () C:\Program Files (x86)\Raptr\win32trace.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00167936 _____ () C:\Program Files (x86)\Raptr\win32gui.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00009216 _____ () C:\Program Files (x86)\Raptr\winsound.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00010240 _____ () C:\Program Files (x86)\Raptr\select.pyd 2013-11-21 02:05 - 2013-11-21 02:05 - 00256000 _____ () C:\Program Files (x86)\Raptr\amd_ags.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00583680 _____ () C:\Program Files (x86)\Raptr\unicodedata.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00263168 _____ () C:\Program Files (x86)\Raptr\win32com.shell.shell.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00141312 _____ () C:\Program Files (x86)\Raptr\gobject._gobject.pyd 2012-10-27 09:53 - 2012-10-27 09:53 - 02717595 _____ () C:\Program Files (x86)\Raptr\heliotrope._purple.pyd 2011-02-15 20:17 - 2011-02-15 20:17 - 01213633 _____ () C:\Program Files (x86)\Raptr\libxml2-2.dll 2010-11-23 01:06 - 2010-11-23 01:06 - 00055808 _____ () C:\Program Files (x86)\Raptr\zlib1.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 00495680 _____ () C:\Program Files (x86)\Raptr\plugins\libaim.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 01183699 _____ () C:\Program Files (x86)\Raptr\liboscar.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 00483306 _____ () C:\Program Files (x86)\Raptr\plugins\libicq.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00655356 _____ () C:\Program Files (x86)\Raptr\plugins\libirc.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 01306387 _____ () C:\Program Files (x86)\Raptr\plugins\libmsn.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 00565461 _____ () C:\Program Files (x86)\Raptr\plugins\libxmpp.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 01640221 _____ () C:\Program Files (x86)\Raptr\libjabber.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 00506276 _____ () C:\Program Files (x86)\Raptr\plugins\libyahoo.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 01053730 _____ () C:\Program Files (x86)\Raptr\libymsg.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00497782 _____ () C:\Program Files (x86)\Raptr\plugins\libyahoojp.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00603326 _____ () C:\Program Files (x86)\Raptr\plugins\ssl-nss.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00474199 _____ () C:\Program Files (x86)\Raptr\plugins\ssl.dll 2014-05-01 17:40 - 2013-09-03 16:52 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 00598480 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libglesv2.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 00124368 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libegl.dll 2014-05-01 17:03 - 2013-03-20 08:04 - 04050896 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll 2014-05-01 17:03 - 2013-03-20 08:04 - 00390096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 01606096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-06-10 14:17:04.137 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 14:14:21.503 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 13:43:55.156 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-08 11:32:01.977 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-07 21:10:12.832 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-07 21:04:55.394 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-07 20:48:21.839 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-07 20:41:29.104 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-07 20:36:02.374 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-07 20:01:58.365 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 29% Total physical RAM: 8111.09 MB Available physical RAM: 5756.25 MB Total Pagefile: 16220.33 MB Available Pagefile: 13300.39 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:195.31 GB) (Free:147.88 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:292.87 GB) (Free:286.42 GB) NTFS Drive e: () (Fixed) (Total:443.23 GB) (Free:386.2 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: DA688F2A) Partition 1: (Active) - (Size=195 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=443 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Geändert von xXFenrizXx (10.06.2014 um 13:29 Uhr) |
11.06.2014, 08:23 | #8 |
/// the machine /// TB-Ausbilder | TR/Drop.Softomat.AN/Windows 7 64 BitESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.06.2014, 12:14 | #9 |
| TR/Drop.Softomat.AN/Windows 7 64 Bit Eset wirklich löschen?` Weil der 11 Sachen gefunden hat Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=d24b757a712e67438b8229ebdea4d737 # engine=18681 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2014-06-12 11:12:28 # local_time=2014-06-12 01:12:28 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7600 NT # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 149006 9253884 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 3157710 154977219 0 0 # scanned=178286 # found=11 # cleaned=0 # scan_time=2531 sh=B9A96D9AE94C4B42CA5499933F6DF218B3903768 ft=1 fh=966b3592656dc188 vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Avira\AntiVir Desktop\offercast_avirav7_.exe" sh=99D2EA99C2B71797087BE9F1948D3606A1E2AA12 ft=1 fh=9ee0c8c2572ae7fd vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\ProgramData\Avira\My Avira\Temp\antivirus.exe" sh=99D2EA99C2B71797087BE9F1948D3606A1E2AA12 ft=1 fh=9ee0c8c2572ae7fd vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Users\All Users\Avira\My Avira\Temp\antivirus.exe" sh=E410DD1707D97E7AC5F13D81982D1A324D5A25E8 ft=1 fh=5d2688694540a297 vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="C:\Users\David\Downloads\FreeYouTubeDownload.exe" sh=DDA705F87269A26DC91475BD68431BDCC13ACC3E ft=1 fh=c71c00118ff5d6ae vn="Win32/InstallCore.OL evtl. unerwünschte Anwendung" ac=I fn="C:\Users\David\Downloads\FreeYouTubeToMP3Converter.exe" sh=21CF2C15E7ED2DDB292587E4B775F803CE63571C ft=1 fh=180ad7e5084b6f14 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\David\Downloads\Open Broadcaster Software - CHIP-Installer.exe" sh=DE0F453AD7E45914C2F6E2A6BC782AFB6DB94B9D ft=1 fh=1f461786edf5f19c vn="NSIS/StartPage.CC Trojaner" ac=I fn="C:\Users\David\Downloads\vlc-2.1.3-win32.exe" sh=B1C343644A90B831AB1F659BA14EDF533CAE3154 ft=0 fh=0000000000000000 vn="Win32/HackTool.WinActivator.I potenziell unsichere Anwendung" ac=I fn="G:\Downloads\Windows+7+Loader+v2.1.1+by+Daz+(x86+&+x64).zip" sh=3B6BDCA414A53DF7C8C5096B953C4DF87A1091C7 ft=1 fh=55ca6504931631dc vn="Win32/HackTool.WinActivator.I potenziell unsichere Anwendung" ac=I fn="G:\Windows Loader\Windows Loader.exe" sh=C5E0829F0443FEC9FAA1FF5DE28BDC8D2B81E5F6 ft=1 fh=f16fed22e902ec25 vn="Win32/Keygen.DK potenziell unsichere Anwendung" ac=I fn="G:\Zips & Co\Installs & Images\Call of Duty 4\Crack\rzr-cod4.exe" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Variante von Win32/Keygen.GU potenziell unsichere Anwendung" ac=I fn="G:\Zips & Co\Installs & Images\Crysis\CRYSYS_by_chio-ENJOY\CRYSYS_by_chio-ENJOY.iso" Code:
ATTFilter Results of screen317's Security Check version 0.99.83 Windows 7 x64 (UAC is enabled) Out of date service pack!! ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Adobe Reader XI Google Chrome 26.0.1410.40 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe Internet Manager OnlineUpdate ouc.exe Internet Manager OnlineUpdate LiveUpd.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-06-2014 01 Ran by David (administrator) on MONGREL on 12-06-2014 14:02:45 Running from C:\Users\David\Desktop Platform: Windows 7 Professional (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe () C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe () D:\Programme\RocketDock\RocketDock.exe (Akamai Technologies, Inc.) C:\Users\David\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\David\AppData\Local\Akamai\netsession_win.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\KoneXTDMonitor.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Raptr, Inc) C:\Program Files (x86)\Raptr\raptr.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Raptr, Inc) C:\Program Files (x86)\Raptr\raptr_im.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Raptr Inc.) C:\Program Files (x86)\Raptr\raptr_ep64.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe () E:\Games\LoL\RADS\system\rads_user_kernel.exe () E:\Games\LoL\RADS\projects\lol_launcher\releases\0.0.0.209\deploy\LoLLauncher.exe () E:\Games\LoL\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\LolClient.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Nullsoft, Inc.) D:\Programme\Winamp\winamp.exe (TeamSpeak Systems GmbH) D:\Programme\Teamspeak\ts3client_win32.exe () E:\Games\LoL\RADS\solutions\lol_game_client_sln\releases\0.0.1.43\deploy\League of Legends.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [Cm106Sound] => C:\Windows\Syswow64\cm106.dll [8151040 2009-10-20] (C-Media Corporation) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-09-03] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM-x32\...\Run: [RoccatKoneXTD] => C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\KoneXTDMonitor.EXE [552960 2013-10-25] (ROCCAT GmbH) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2691480 2014-03-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-27] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [182352 2014-05-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [RocketDock] => D:\Programme\RocketDock\RocketDock.exe [495616 2007-09-02] () HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [Akamai NetSession Interface] => C:\Users\David\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55360 2014-05-15] (Raptr, Inc) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [HP Deskjet 3050 J610 series (NET)] => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 Tcpip\..\Interfaces\{A395CEDE-D5A6-48E6-8CC2-506A45065462}: [NameServer] FireFox: ======== FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: adobe.com/AdobeExManCCDetect32 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect32.dll (Adobe Systems) FF Plugin HKCU: adobe.com/AdobeExManCCDetect64 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect64.dll (Adobe Systems) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://google.de/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-01] CHR Extension: (Adblock Plus) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-01] CHR Extension: (Type Scout) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\fedokkaolmkkoeedicihicdeppjjeamj [2014-05-01] CHR Extension: (AdBlock) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-01] CHR Extension: (TabJump - Intelligenter Tab-Navigator) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokofmgcicpnjchllaccgedmmmbbnbmf [2014-05-01] CHR Extension: (Google Mail-Checker) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-05-01] CHR Extension: (WGT Golf Game) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpedbpkelbhcbkdaglillalioeeekbpb [2014-05-01] CHR Extension: (Google Mail) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-01] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [124496 2014-05-05] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-05-09] () [File not signed] R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2011-06-17] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation) S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-27] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-27] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [495376 2013-05-30] (Intel Corporation) U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.) S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [238080 2012-04-23] (Huawei Technologies Co., Ltd.) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation) S3 USBMULCD; C:\Windows\System32\drivers\CM10664.sys [1307648 2009-10-01] (C-Media Electronics Inc) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-12 12:29 - 2014-06-12 12:29 - 00854367 _____ () C:\Users\David\Desktop\SecurityCheck.exe 2014-06-12 12:26 - 2014-06-12 12:26 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-06-12 12:24 - 2014-06-12 12:24 - 02347384 _____ (ESET) C:\Users\David\Downloads\esetsmartinstaller_deu.exe 2014-06-10 14:28 - 2014-06-12 14:00 - 00000000 ____D () C:\Users\David\Desktop\FRST-OlderVersion 2014-06-10 14:24 - 2014-06-10 14:24 - 00000695 _____ () C:\Users\David\Desktop\JRT.txt 2014-06-10 13:55 - 2014-06-10 13:55 - 01016261 _____ (Thisisu) C:\Users\David\Desktop\JRT.exe 2014-06-10 13:50 - 2014-06-10 13:51 - 01333465 _____ () C:\Users\David\Downloads\adwcleaner_3.212.exe 2014-06-07 13:13 - 2014-06-07 13:13 - 00001633 _____ () C:\Users\David\Desktop\avcenter.lnk 2014-06-07 13:07 - 2014-06-07 13:07 - 00034127 _____ () C:\ComboFix.txt 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-07 12:59 - 2014-06-07 13:07 - 00000000 ____D () C:\Qoobox 2014-06-07 12:59 - 2014-06-07 13:06 - 00000000 ____D () C:\Windows\erdnt 2014-06-07 12:59 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-07 12:59 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-07 12:59 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-07 12:59 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-07 12:59 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-07 12:59 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-07 12:59 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-07 12:59 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-07 12:56 - 2014-06-07 12:57 - 05205146 ____R (Swearware) C:\Users\David\Desktop\ComboFix.exe 2014-06-07 12:47 - 2014-06-07 12:47 - 00001268 _____ () C:\Users\David\Desktop\Revo Uninstaller.lnk 2014-06-07 12:47 - 2014-06-07 12:47 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-06-07 12:46 - 2014-06-07 12:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\David\Downloads\revosetup95.exe 2014-06-06 21:16 - 2014-06-07 15:57 - 00001019 _____ () C:\Users\David\Desktop\Werbung.txt 2014-06-06 13:54 - 2010-11-20 14:16 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2014-06-06 13:33 - 2014-06-06 13:38 - 00126464 _____ () C:\Windows\SysWOW64\audiodg.exe 2014-06-05 20:25 - 2014-06-10 14:28 - 00027382 _____ () C:\Users\David\Desktop\Addition.txt 2014-06-05 17:05 - 2014-06-05 17:05 - 00076918 _____ () C:\Users\David\Desktop\GMER.txt 2014-06-05 16:56 - 2014-06-05 16:56 - 00380416 _____ () C:\Users\David\Desktop\Gmer-19357.exe 2014-06-05 16:55 - 2014-06-12 14:02 - 00016380 _____ () C:\Users\David\Desktop\FRST.txt 2014-06-05 16:54 - 2014-06-12 14:00 - 02081792 _____ (Farbar) C:\Users\David\Desktop\FRST64.exe 2014-06-05 16:53 - 2014-06-05 16:53 - 00001510 _____ () C:\Users\David\Desktop\Malwarebytes.txt 2014-06-05 15:59 - 2014-06-06 12:53 - 00000000 ____D () C:\Users\David\AppData\Roaming\Apple Computer 2014-06-05 15:59 - 2014-06-05 15:59 - 00000000 ____D () C:\Users\David\AppData\Local\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Users\David\AppData\Local\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-06-05 15:54 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-06-05 15:47 - 2014-06-05 15:48 - 41945432 _____ (Apple Inc.) C:\Users\David\Downloads\QuickTimeInstaller.exe 2014-06-05 15:45 - 2014-06-05 15:46 - 00000000 ____D () C:\Users\David\AppData\Roaming\vlc 2014-06-05 15:40 - 2014-06-05 15:41 - 25531584 _____ () C:\Users\David\Downloads\vlc-2.1.3-win32.exe 2014-06-03 14:47 - 2014-06-03 14:51 - 44199212 _____ () C:\Users\David\Downloads\Pentakill-SmiteandIgnite.zip 2014-06-03 14:15 - 2014-06-03 14:15 - 00000000 ____D () C:\Users\David\AppData\Roaming\OBS 2014-06-03 14:14 - 2014-06-03 14:14 - 00961360 _____ (Chip Digital GmbH) C:\Users\David\Downloads\Open Broadcaster Software - CHIP-Installer.exe 2014-06-02 23:20 - 2014-06-03 14:31 - 16849882 _____ () C:\Users\David\Downloads\Season-4-Overlay-Mega-Pack-by-Temporalcortex.zip 2014-06-02 16:41 - 2014-06-02 16:58 - 00026934 _____ () C:\Users\David\Downloads\debug.log 2014-06-02 16:32 - 2014-06-02 16:32 - 00000796 _____ () C:\Users\Public\Desktop\XSplit Broadcaster.lnk 2014-06-02 16:32 - 2014-06-02 16:32 - 00000000 ____D () C:\Users\David\AppData\Local\SplitMediaLabs 2014-06-02 16:30 - 2014-06-12 14:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-02 16:30 - 2014-06-02 16:30 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-02 16:30 - 2014-06-02 16:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-02 16:30 - 2014-06-02 16:30 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\system32\Macromed 2014-06-02 16:28 - 2014-06-02 16:29 - 42360392 _____ (SplitMediaLabs) C:\Users\David\Downloads\xsplit_bc_installer.exe 2014-06-02 16:21 - 2014-06-02 16:21 - 00000000 ____D () C:\Users\David\AppData\Local\IsolatedStorage 2014-06-02 15:59 - 2014-06-02 16:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit 2014-06-02 15:59 - 2014-06-02 15:59 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-06-02 15:58 - 2014-06-02 16:31 - 00000000 ____D () C:\Users\David\AppData\Roaming\SplitmediaLabs 2014-06-02 15:55 - 2014-06-02 15:57 - 46455952 _____ (SplitmediaLabs) C:\Users\David\Downloads\xsplit_gc_installer.exe 2014-05-31 19:39 - 2014-05-31 19:39 - 00111788 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget (1).zip 2014-05-31 19:12 - 2014-05-31 19:12 - 00112213 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget.zip 2014-05-31 15:04 - 2014-06-03 15:23 - 00150528 ___SH () C:\Users\David\Thumbs.db 2014-05-30 15:01 - 2014-06-03 15:23 - 00000132 _____ () C:\Users\David\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen 2014-05-26 18:37 - 2014-05-26 18:37 - 01677440 _____ (Skype Technologies S.A.) C:\Users\David\Downloads\SkypeSetup (1).exe 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_juextctrl_01007.Wdf 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf 2014-05-26 12:07 - 2014-05-26 12:07 - 00001245 _____ () C:\Users\Public\Desktop\Internet Manager.lnk 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Manager 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Internet Manager 2014-05-26 12:07 - 2012-04-26 05:04 - 00450048 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbwwan.sys 2014-05-26 12:07 - 2012-04-23 03:58 - 00238080 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juwwanecm.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00104448 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcacm.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00090112 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00076800 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys 2014-05-26 12:07 - 2012-04-23 03:57 - 00030720 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys 2014-05-26 12:07 - 2011-12-31 03:20 - 00225920 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2014-05-26 12:07 - 2011-08-16 10:40 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2014-05-26 12:07 - 2011-08-16 10:40 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01007.dll 2014-05-26 12:07 - 2010-10-08 10:59 - 00032768 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys 2014-05-26 12:07 - 2010-09-26 12:09 - 00022016 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys 2014-05-26 12:07 - 2010-08-06 01:43 - 01001472 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys 2014-05-26 12:07 - 2010-07-27 03:52 - 00117248 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys 2014-05-26 12:07 - 2010-03-20 06:06 - 00013952 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys 2014-05-26 12:06 - 2014-05-26 12:06 - 00000000 ____D () C:\Program Files (x86)\T-Mobile 2014-05-26 12:03 - 2014-05-26 12:08 - 00000000 ____D () C:\ProgramData\DatacardService 2014-05-18 15:41 - 2014-05-18 15:42 - 00000036 _____ () C:\Users\David\Malwarebytes ID.txt ==================== One Month Modified Files and Folders ======= 2014-06-12 14:02 - 2014-06-05 16:55 - 00016380 _____ () C:\Users\David\Desktop\FRST.txt 2014-06-12 14:02 - 2014-05-08 15:54 - 00000000 ____D () C:\FRST 2014-06-12 14:02 - 2014-05-01 16:56 - 00000000 ____D () C:\Users\David\AppData\Local\Temp 2014-06-12 14:01 - 2014-06-02 16:30 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-12 14:00 - 2014-06-10 14:28 - 00000000 ____D () C:\Users\David\Desktop\FRST-OlderVersion 2014-06-12 14:00 - 2014-06-05 16:54 - 02081792 _____ (Farbar) C:\Users\David\Desktop\FRST64.exe 2014-06-12 13:55 - 2014-05-01 16:56 - 01511401 _____ () C:\Windows\WindowsUpdate.log 2014-06-12 13:08 - 2014-05-01 17:03 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-12 12:55 - 2014-05-01 17:15 - 00000000 ____D () C:\Users\David\AppData\Local\PMB Files 2014-06-12 12:31 - 2014-05-03 18:47 - 00000000 ____D () C:\Users\David\AppData\Local\Adobe 2014-06-12 12:29 - 2014-06-12 12:29 - 00854367 _____ () C:\Users\David\Desktop\SecurityCheck.exe 2014-06-12 12:29 - 2014-05-01 17:57 - 00000000 ____D () C:\Users\David\AppData\Roaming\TS3Client 2014-06-12 12:29 - 2009-07-14 06:45 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-12 12:29 - 2009-07-14 06:45 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-12 12:28 - 2009-07-14 19:58 - 00699726 _____ () C:\Windows\system32\perfh007.dat 2014-06-12 12:28 - 2009-07-14 19:58 - 00149364 _____ () C:\Windows\system32\perfc007.dat 2014-06-12 12:28 - 2009-07-14 07:13 - 01621742 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-12 12:26 - 2014-06-12 12:26 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-06-12 12:24 - 2014-06-12 12:24 - 02347384 _____ (ESET) C:\Users\David\Downloads\esetsmartinstaller_deu.exe 2014-06-12 12:24 - 2014-05-12 00:06 - 00000000 ____D () C:\Users\David\AppData\Roaming\Raptr 2014-06-12 12:24 - 2014-05-01 17:15 - 00000000 ____D () C:\ProgramData\PMB Files 2014-06-12 12:23 - 2014-05-08 15:36 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-12 12:23 - 2014-05-01 17:03 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-12 12:21 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-12 12:21 - 2009-07-14 06:51 - 00035801 _____ () C:\Windows\setupact.log 2014-06-10 14:28 - 2014-06-05 20:25 - 00027382 _____ () C:\Users\David\Desktop\Addition.txt 2014-06-10 14:24 - 2014-06-10 14:24 - 00000695 _____ () C:\Users\David\Desktop\JRT.txt 2014-06-10 14:16 - 2014-05-11 18:11 - 00000000 ____D () C:\AdwCleaner 2014-06-10 14:16 - 2014-05-01 17:43 - 00091794 _____ () C:\Windows\PFRO.log 2014-06-10 13:55 - 2014-06-10 13:55 - 01016261 _____ (Thisisu) C:\Users\David\Desktop\JRT.exe 2014-06-10 13:51 - 2014-06-10 13:50 - 01333465 _____ () C:\Users\David\Downloads\adwcleaner_3.212.exe 2014-06-07 15:57 - 2014-06-06 21:16 - 00001019 _____ () C:\Users\David\Desktop\Werbung.txt 2014-06-07 14:55 - 2014-05-01 17:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-06-07 14:52 - 2014-05-01 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2014-06-07 13:13 - 2014-06-07 13:13 - 00001633 _____ () C:\Users\David\Desktop\avcenter.lnk 2014-06-07 13:07 - 2014-06-07 13:07 - 00034127 _____ () C:\ComboFix.txt 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-07 13:07 - 2014-06-07 13:07 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-07 13:07 - 2014-06-07 12:59 - 00000000 ____D () C:\Qoobox 2014-06-07 13:07 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-06-07 13:06 - 2014-06-07 12:59 - 00000000 ____D () C:\Windows\erdnt 2014-06-07 13:04 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-06-07 12:57 - 2014-06-07 12:56 - 05205146 ____R (Swearware) C:\Users\David\Desktop\ComboFix.exe 2014-06-07 12:47 - 2014-06-07 12:47 - 00001268 _____ () C:\Users\David\Desktop\Revo Uninstaller.lnk 2014-06-07 12:47 - 2014-06-07 12:47 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-06-07 12:47 - 2014-06-07 12:46 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\David\Downloads\revosetup95.exe 2014-06-06 13:38 - 2014-06-06 13:33 - 00126464 _____ () C:\Windows\SysWOW64\audiodg.exe 2014-06-06 12:53 - 2014-06-05 15:59 - 00000000 ____D () C:\Users\David\AppData\Roaming\Apple Computer 2014-06-05 17:05 - 2014-06-05 17:05 - 00076918 _____ () C:\Users\David\Desktop\GMER.txt 2014-06-05 16:58 - 2014-05-01 17:52 - 00000000 ____D () C:\Users\David\AppData\Roaming\Skype 2014-06-05 16:56 - 2014-06-05 16:56 - 00380416 _____ () C:\Users\David\Desktop\Gmer-19357.exe 2014-06-05 16:53 - 2014-06-05 16:53 - 00001510 _____ () C:\Users\David\Desktop\Malwarebytes.txt 2014-06-05 15:59 - 2014-06-05 15:59 - 00000000 ____D () C:\Users\David\AppData\Local\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Users\David\AppData\Local\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\ProgramData\Apple 2014-06-05 15:58 - 2014-06-05 15:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-06-05 15:58 - 2014-06-05 15:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-06-05 15:48 - 2014-06-05 15:47 - 41945432 _____ (Apple Inc.) C:\Users\David\Downloads\QuickTimeInstaller.exe 2014-06-05 15:46 - 2014-06-05 15:45 - 00000000 ____D () C:\Users\David\AppData\Roaming\vlc 2014-06-05 15:41 - 2014-06-05 15:40 - 25531584 _____ () C:\Users\David\Downloads\vlc-2.1.3-win32.exe 2014-06-05 13:07 - 2014-05-01 17:52 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-06-05 13:07 - 2014-05-01 17:52 - 00000000 ____D () C:\ProgramData\Skype 2014-06-03 15:23 - 2014-05-31 15:04 - 00150528 ___SH () C:\Users\David\Thumbs.db 2014-06-03 15:23 - 2014-05-30 15:01 - 00000132 _____ () C:\Users\David\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen 2014-06-03 15:23 - 2014-05-01 16:56 - 00000000 ____D () C:\Users\David 2014-06-03 14:51 - 2014-06-03 14:47 - 44199212 _____ () C:\Users\David\Downloads\Pentakill-SmiteandIgnite.zip 2014-06-03 14:31 - 2014-06-02 23:20 - 16849882 _____ () C:\Users\David\Downloads\Season-4-Overlay-Mega-Pack-by-Temporalcortex.zip 2014-06-03 14:15 - 2014-06-03 14:15 - 00000000 ____D () C:\Users\David\AppData\Roaming\OBS 2014-06-03 14:14 - 2014-06-03 14:14 - 00961360 _____ (Chip Digital GmbH) C:\Users\David\Downloads\Open Broadcaster Software - CHIP-Installer.exe 2014-06-02 16:58 - 2014-06-02 16:41 - 00026934 _____ () C:\Users\David\Downloads\debug.log 2014-06-02 16:32 - 2014-06-02 16:32 - 00000796 _____ () C:\Users\Public\Desktop\XSplit Broadcaster.lnk 2014-06-02 16:32 - 2014-06-02 16:32 - 00000000 ____D () C:\Users\David\AppData\Local\SplitMediaLabs 2014-06-02 16:32 - 2014-06-02 15:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit 2014-06-02 16:31 - 2014-06-02 15:58 - 00000000 ____D () C:\Users\David\AppData\Roaming\SplitmediaLabs 2014-06-02 16:30 - 2014-06-02 16:30 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-02 16:30 - 2014-06-02 16:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-02 16:30 - 2014-06-02 16:30 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-06-02 16:30 - 2014-06-02 16:30 - 00000000 ____D () C:\Windows\system32\Macromed 2014-06-02 16:29 - 2014-06-02 16:28 - 42360392 _____ (SplitMediaLabs) C:\Users\David\Downloads\xsplit_bc_installer.exe 2014-06-02 16:21 - 2014-06-02 16:21 - 00000000 ____D () C:\Users\David\AppData\Local\IsolatedStorage 2014-06-02 15:59 - 2014-06-02 15:59 - 00000000 ____D () C:\ProgramData\SplitMediaLabs 2014-06-02 15:57 - 2014-06-02 15:55 - 46455952 _____ (SplitmediaLabs) C:\Users\David\Downloads\xsplit_gc_installer.exe 2014-05-31 19:39 - 2014-05-31 19:39 - 00111788 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget (1).zip 2014-05-31 19:12 - 2014-05-31 19:12 - 00112213 _____ () C:\Users\David\Downloads\teamspeak-3-viewer-plugin-for-wordpress-widget.zip 2014-05-31 13:45 - 2014-05-08 15:36 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-27 11:28 - 2014-05-07 00:03 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-27 11:28 - 2014-05-07 00:03 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-26 18:37 - 2014-05-26 18:37 - 01677440 _____ (Skype Technologies S.A.) C:\Users\David\Downloads\SkypeSetup (1).exe 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_juextctrl_01007.Wdf 2014-05-26 12:08 - 2014-05-26 12:08 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf 2014-05-26 12:08 - 2014-05-26 12:03 - 00000000 ____D () C:\ProgramData\DatacardService 2014-05-26 12:07 - 2014-05-26 12:07 - 00001245 _____ () C:\Users\Public\Desktop\Internet Manager.lnk 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Manager 2014-05-26 12:07 - 2014-05-26 12:07 - 00000000 ____D () C:\ProgramData\Internet Manager 2014-05-26 12:06 - 2014-05-26 12:06 - 00000000 ____D () C:\Program Files (x86)\T-Mobile 2014-05-22 19:04 - 2014-05-12 00:06 - 00000000 ____D () C:\Program Files (x86)\Raptr 2014-05-19 19:59 - 2014-05-12 17:17 - 00000000 ____D () C:\Users\David\AppData\Roaming\HpUpdate 2014-05-18 15:42 - 2014-05-18 15:41 - 00000036 _____ () C:\Users\David\Malwarebytes ID.txt 2014-05-16 11:33 - 2014-05-11 23:44 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-13 21:27 - 2014-05-12 00:18 - 00000000 ____D () C:\Users\David\Documents\dragoon Some content of TEMP: ==================== C:\Users\David\AppData\Local\Temp\avgnt.exe C:\Users\David\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-10 15:33 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-06-2014 01 Ran by David at 2014-06-12 14:03:06 Running from C:\Users\David\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.5.0.367 - Adobe Systems Incorporated) Adobe Dreamweaver CC (HKLM-x32\...\{00E094E1-A852-11E2-803D-ACEA632352B4}) (Version: 13 - Adobe Systems Incorporated) Adobe Extension Manager CC (HKLM-x32\...\{244FD30F-63F1-49B9-9D98-1150FF4FFCB1}) (Version: 7.1.1 - Adobe Systems Incorporated) Adobe Flash Player 11 ActiveX (HKLM-x32\...\{E94EFAB6-653F-4837-9E8A-F6377CA1EC0D}) (Version: 11.8.800.175 - Adobe Systems Incorporated) Adobe Photoshop CC (HKLM-x32\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc) AMD Accelerated Video Transcoding (Version: 13.30.100.40417 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2014.0417.2226.38446 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{6119B3A6-3603-9695-0398-CDF2AF0A13F8}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.80911.2216 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.15 - Advanced Micro Devices, Inc.) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Arma 2 (HKLM-x32\...\Steam App 33900) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead (HKLM-x32\...\Steam App 33930) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead Beta (HKLM-x32\...\Steam App 219540) (Version: - ) Avira (HKLM-x32\...\{70a79d1f-686d-4d5c-962b-07aa1294eae0}) (Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) DayZ Commander (HKLM-x32\...\{B3653588-3AC0-4A1D-950F-D96531E84374}) (Version: 0.92.91 - Dotjosh Studios) Dragon's Prophet (HKLM-x32\...\{C31556D7-F2B9-4787-B223-F7A035067E89}_is1) (Version: 2.0.1349.21 - Infernum Productions AG) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Free YouTube Download version 3.2.34.430 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.34.430 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.34.430 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.34.430 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 26.0.1410.40 - Google Inc.) Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden HP Deskjet 3050 J610 series - Grundlegende Software für das Gerät (HKLM\...\{EF3293DE-FCAC-4742-91BF-AD0174143FC3}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Network Connections 18.5.54.0 (HKLM\...\PROSetDX) (Version: 18.5.54.0 - Intel) Intel(R) Network Connections 18.5.54.0 (Version: 18.5.54.0 - Intel) Hidden Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation) Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.18.68.55 - Huawei Technologies Co.,Ltd) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Left 4 Dead (HKLM-x32\...\Steam App 500) (Version: - Valve) Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.154 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Raptr (HKLM-x32\...\Raptr) (Version: - ) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) ROCCAT Kone XTD Mouse Driver (HKLM-x32\...\{7133137D-DF48-4522-AD88-13C82B7D0A63}) (Version: - Roccat GmbH) RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software) Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) USB Multi-Channel Audio Device (HKLM\...\C-Media CM106 Like Sound Driver) (Version: - ) VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) XSplit Broadcaster (HKLM-x32\...\{3A1F3A32-7E9D-4AD2-A2E2-DFC98BAA9DC7}) (Version: 1.3.1403.1202 - SplitMediaLabs) XSplit Gamecaster (HKLM-x32\...\{C5E8E927-8182-40D0-8718-ED74E5C0690A}) (Version: 1.7.1405.2114 - SplitmediaLabs) ==================== Restore Points ========================= 26-05-2014 17:15:58 Geplanter Prüfpunkt 02-06-2014 13:58:55 Installed XSplit Gamecaster 02-06-2014 14:30:22 Installed Adobe Flash Player 11 ActiveX. 02-06-2014 14:32:26 Installed XSplit Broadcaster 05-06-2014 13:54:19 Installed QuickTime 7 05-06-2014 13:58:09 Installed QuickTime 7 07-06-2014 10:54:24 Revo Uninstaller's restore point - Speedial ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-06-07 13:02 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {312E2046-82A0-450F-8497-4FFBC6FEC623} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-01] (Google Inc.) Task: {321826E4-3D5B-4EA4-A7F2-A06FFD4092D3} - System32\Tasks\AdobeAAMUpdater-1.0-Mongrel-David => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated) Task: {743E8047-E9DE-45B1-BF85-54DD421FEC8B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {7FB71025-B02D-4B48-A07D-6BDD38B91116} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-01] (Google Inc.) Task: {EC8DE1A6-566C-4753-9372-C5513FBF4946} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-02] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-14 17:27 - 2011-03-14 17:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2014-05-26 12:07 - 2011-06-17 13:04 - 00224096 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe 2014-06-10 13:44 - 2011-06-17 13:04 - 01434464 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe 2014-03-20 11:24 - 2014-03-20 11:24 - 00667808 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll 2014-02-11 20:21 - 2014-02-11 20:21 - 00860160 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 01043968 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-02-11 20:21 - 2014-02-11 20:21 - 00052736 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 00236032 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-05-01 17:56 - 2007-09-02 13:58 - 00495616 _____ () D:\Programme\RocketDock\RocketDock.exe 2014-03-20 11:24 - 2014-03-20 11:24 - 05288608 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe 2013-06-12 18:11 - 2014-05-01 17:16 - 01294336 _____ () E:\Games\LoL\RADS\system\rads_user_kernel.exe 2014-05-01 17:43 - 2014-06-04 18:31 - 05431800 _____ () E:\Games\LoL\RADS\projects\lol_launcher\releases\0.0.0.209\deploy\LoLLauncher.exe 2014-05-01 18:15 - 2014-05-01 18:15 - 00074752 _____ () E:\Games\LoL\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\LolClient.exe 2014-05-01 19:36 - 2014-06-10 13:51 - 16608760 _____ () E:\Games\LoL\RADS\solutions\lol_game_client_sln\releases\0.0.1.43\deploy\League of Legends.exe 2014-05-26 12:07 - 2009-01-10 12:32 - 00011362 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll 2014-05-26 12:07 - 2009-06-22 20:42 - 00043008 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll 2014-05-26 12:07 - 2010-05-05 10:47 - 02415104 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll 2014-05-26 12:07 - 2010-02-10 16:10 - 01148416 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll 2014-05-05 10:37 - 2014-05-05 10:37 - 00138320 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll 2014-05-05 10:37 - 2014-05-05 10:37 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2014-05-26 12:07 - 2010-02-10 16:43 - 09515520 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtGui4.dll 2014-06-10 13:44 - 2012-10-08 03:41 - 00082944 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\plugins\imageformats\qgif4.dll 2014-06-10 13:44 - 2012-10-08 03:41 - 00081920 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\plugins\imageformats\qico4.dll 2014-05-01 17:56 - 2007-09-02 13:57 - 00069632 _____ () D:\Programme\RocketDock\RocketDock.dll 2014-05-01 18:40 - 2012-06-17 11:20 - 00061440 _____ () C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\hiddriver.dll 2014-03-18 23:22 - 2014-03-18 23:22 - 32733088 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll 2014-06-07 13:05 - 2014-05-05 10:37 - 00049744 _____ () C:\Users\David\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00087040 _____ () C:\Program Files (x86)\Raptr\_ctypes.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00043008 _____ () C:\Program Files (x86)\Raptr\_socket.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00805376 _____ () C:\Program Files (x86)\Raptr\_ssl.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 05812736 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtGui.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00067584 _____ () C:\Program Files (x86)\Raptr\sip.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 01662464 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtCore.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00494592 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtNetwork.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00096256 _____ () C:\Program Files (x86)\Raptr\win32api.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00110592 _____ () C:\Program Files (x86)\Raptr\pywintypes26.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00324608 _____ () C:\Program Files (x86)\Raptr\PIL._imaging.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00356864 _____ () C:\Program Files (x86)\Raptr\_hashlib.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00036352 _____ () C:\Program Files (x86)\Raptr\win32process.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00111104 _____ () C:\Program Files (x86)\Raptr\win32file.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00124928 _____ () C:\Program Files (x86)\Raptr\_elementtree.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00127488 _____ () C:\Program Files (x86)\Raptr\pyexpat.pyd 2012-02-06 22:28 - 2012-02-06 22:28 - 00031744 _____ () C:\Program Files (x86)\Raptr\Crypto.Cipher.AES.pyd 2012-02-06 22:28 - 2012-02-06 22:28 - 00010752 _____ () C:\Program Files (x86)\Raptr\Crypto.Random.OSRNG.winrandom.pyd 2012-02-06 22:28 - 2012-02-06 22:28 - 00011264 _____ () C:\Program Files (x86)\Raptr\Crypto.Util._counter.pyd 2011-05-10 21:01 - 2011-05-10 21:01 - 00030208 _____ () C:\Program Files (x86)\Raptr\simplejson._speedups.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00313856 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtWebKit.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00044544 _____ () C:\Program Files (x86)\Raptr\_sqlite3.pyd 2011-02-15 20:17 - 2011-02-15 20:17 - 00417501 _____ () C:\Program Files (x86)\Raptr\sqlite3.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00354304 _____ () C:\Program Files (x86)\Raptr\pythoncom26.dll 2010-11-23 00:57 - 2010-11-23 00:57 - 00016384 _____ () C:\Program Files (x86)\Raptr\win32trace.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00167936 _____ () C:\Program Files (x86)\Raptr\win32gui.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00009216 _____ () C:\Program Files (x86)\Raptr\winsound.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00010240 _____ () C:\Program Files (x86)\Raptr\select.pyd 2013-11-21 02:05 - 2013-11-21 02:05 - 00256000 _____ () C:\Program Files (x86)\Raptr\amd_ags.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00583680 _____ () C:\Program Files (x86)\Raptr\unicodedata.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00263168 _____ () C:\Program Files (x86)\Raptr\win32com.shell.shell.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00141312 _____ () C:\Program Files (x86)\Raptr\gobject._gobject.pyd 2012-10-27 09:53 - 2012-10-27 09:53 - 02717595 _____ () C:\Program Files (x86)\Raptr\heliotrope._purple.pyd 2011-02-15 20:17 - 2011-02-15 20:17 - 01213633 _____ () C:\Program Files (x86)\Raptr\libxml2-2.dll 2010-11-23 01:06 - 2010-11-23 01:06 - 00055808 _____ () C:\Program Files (x86)\Raptr\zlib1.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 00495680 _____ () C:\Program Files (x86)\Raptr\plugins\libaim.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 01183699 _____ () C:\Program Files (x86)\Raptr\liboscar.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 00483306 _____ () C:\Program Files (x86)\Raptr\plugins\libicq.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00655356 _____ () C:\Program Files (x86)\Raptr\plugins\libirc.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 01306387 _____ () C:\Program Files (x86)\Raptr\plugins\libmsn.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 00565461 _____ () C:\Program Files (x86)\Raptr\plugins\libxmpp.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 01640221 _____ () C:\Program Files (x86)\Raptr\libjabber.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 00506276 _____ () C:\Program Files (x86)\Raptr\plugins\libyahoo.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 01053730 _____ () C:\Program Files (x86)\Raptr\libymsg.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00497782 _____ () C:\Program Files (x86)\Raptr\plugins\libyahoojp.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00603326 _____ () C:\Program Files (x86)\Raptr\plugins\ssl-nss.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00474199 _____ () C:\Program Files (x86)\Raptr\plugins\ssl.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 00598480 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libglesv2.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 00124368 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libegl.dll 2014-05-01 17:03 - 2013-03-20 08:04 - 04050896 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll 2014-05-01 17:03 - 2013-03-20 08:04 - 00390096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 01606096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ffmpegsumo.dll 2014-05-01 17:40 - 2013-09-03 16:52 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2014-05-01 17:45 - 2014-06-04 18:31 - 01531896 _____ () E:\Games\LoL\RADS\projects\lol_launcher\releases\0.0.0.209\deploy\RiotLauncher.dll 2014-05-01 18:15 - 2014-05-01 18:15 - 04774248 _____ () E:\Games\LoL\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\Adobe AIR\Versions\1.0\Resources\WebKit.dll 2014-06-12 12:29 - 2014-06-12 12:29 - 00014336 _____ () C:\Users\David\AppData\Local\Temp\WDE2895.tmp\ml_online.lng 2014-06-12 12:29 - 2014-06-12 12:29 - 00036352 _____ () C:\Users\David\AppData\Local\Temp\WDE2895.tmp\ombrowser.lng 2013-12-13 04:47 - 2013-12-13 04:47 - 00333824 _____ () D:\Programme\Winamp\Plugins\freeform\wacs\freetype\freetype.wac 2014-02-28 15:33 - 2014-02-28 15:33 - 00148480 _____ () D:\Programme\Teamspeak\quazip.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00864768 _____ () D:\Programme\Teamspeak\platforms\qwindows.dll 2014-02-27 15:45 - 2014-02-27 15:45 - 00677376 _____ () D:\Programme\Teamspeak\sqldrivers\qsqlite.dll 2014-02-28 15:41 - 2014-02-28 15:41 - 00092104 _____ () D:\Programme\Teamspeak\soundbackends\directsound_win32.dll 2014-02-28 15:41 - 2014-02-28 15:41 - 00105416 _____ () D:\Programme\Teamspeak\soundbackends\windowsaudiosession_win32.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00025600 _____ () D:\Programme\Teamspeak\imageformats\qgif.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00242688 _____ () D:\Programme\Teamspeak\imageformats\qjpeg.dll 2014-02-28 15:42 - 2014-02-28 15:42 - 00477128 _____ () D:\Programme\Teamspeak\plugins\clientquery_plugin.dll 2014-02-28 15:42 - 2014-02-28 15:42 - 00483784 _____ () D:\Programme\Teamspeak\plugins\teamspeak_control_plugin.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00123904 _____ () D:\Programme\Teamspeak\accessible\qtaccessiblewidgets.dll 2014-05-01 19:36 - 2014-06-10 13:51 - 01531896 _____ () E:\Games\LoL\RADS\solutions\lol_game_client_sln\releases\0.0.1.43\deploy\RiotLauncher.dll 2014-05-01 19:36 - 2014-06-04 18:31 - 01616888 _____ () E:\Games\LoL\RADS\RiotRadsIO.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/12/2014 01:55:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (720)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/12/2014 01:55:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (720)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/12/2014 01:55:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (720)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/12/2014 01:55:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (720)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/12/2014 01:25:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (720)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/12/2014 01:25:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (720)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/12/2014 01:25:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (720)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/12/2014 01:25:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll (720)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (06/12/2014 01:15:18 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest. Error: (06/12/2014 01:13:29 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest. System errors: ============= Error: (06/12/2014 00:21:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/12/2014 00:21:33 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Microsoft Office Sessions: ========================= Error: (06/12/2014 01:55:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll720SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/12/2014 01:55:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll720SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/12/2014 01:55:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll720SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/12/2014 01:55:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll720SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/12/2014 01:25:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll720SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/12/2014 01:25:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll720SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/12/2014 01:25:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll720SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/12/2014 01:25:26 PM) (Source: ESENT) (EventID: 412) (User: ) Description: wuaueng.dll720SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (06/12/2014 01:15:18 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifestC:\Users\David\Downloads\esetsmartinstaller_deu.exe Error: (06/12/2014 01:13:29 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe CodeIntegrity Errors: =================================== Date: 2014-06-12 12:21:28.298 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 16:37:56.972 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 16:05:53.260 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 15:44:28.863 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 15:38:06.823 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 15:32:30.744 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 15:22:34.979 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 15:03:48.901 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 14:34:55.219 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 14:17:04.137 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\audiodg.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 8111.09 MB Available physical RAM: 4473.89 MB Total Pagefile: 16220.33 MB Available Pagefile: 11692.92 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:195.31 GB) (Free:145.97 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:292.87 GB) (Free:286.42 GB) NTFS Drive e: () (Fixed) (Total:443.23 GB) (Free:385.79 GB) NTFS Drive g: (TrekStor) (Fixed) (Total:931.51 GB) (Free:845.8 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: DA688F2A) Partition 1: (Active) - (Size=195 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=443 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 932 GB) (Disk ID: 12521609) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Geändert von xXFenrizXx (12.06.2014 um 13:04 Uhr) |
13.06.2014, 11:54 | #10 |
/// the machine /// TB-Ausbilder | TR/Drop.Softomat.AN/Windows 7 64 Bit Was soll der ganze Crack-Müll? Ist dein WIndows auch geklaut?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.06.2014, 12:14 | #11 |
| TR/Drop.Softomat.AN/Windows 7 64 Bit Hä welcher crack müll? Ne windows ist original Was du da im eset siehst ist meine externe festplatte die ich Ewigkeiten nicht benutzt habe. Da stand man soll solche Geräte mit anschließen. Aber die Spiele und Programme sind ja alle älter |
15.06.2014, 06:11 | #12 |
/// the machine /// TB-Ausbilder | TR/Drop.Softomat.AN/Windows 7 64 Bit Da ist auch ein WIndows Crack dabei. LÖsch den ganzen Mist, die komplette Platte, und lass die FInger von sowas, oder du bist schneller wieder hier wie du denkst. Windows updaten, da fehlt en ganzes Servicepack.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.06.2014, 17:51 | #13 |
| TR/Drop.Softomat.AN/Windows 7 64 Bit Danke dir werde ich machen Wie gesagt hab die Platte ewig nicht angerührt und brauch das Zeug da nicht. Hatte einfach mal die Platte von nem Kumpel bei der letzten LAN kopiert. Ich weiß total dumm xD naja egal bin ich da jetzt fertig wenn ich das neue Service Pack drauf mache? |
16.06.2014, 09:33 | #14 |
/// the machine /// TB-Ausbilder | TR/Drop.Softomat.AN/Windows 7 64 Bit Wenn es drauf ist bitte ein frisches FRST log.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.06.2014, 14:10 | #15 |
| TR/Drop.Softomat.AN/Windows 7 64 Bit Irgendwie kann ich das neue SP nicht finden. Entweder bin ich zu doof oder irgendwas passt da nicht ^^ Im Windows Update zeigt er es mir nicht an und auch im Netz finde ich kein SP 2 für Windows 7 |