|
Log-Analyse und Auswertung: Malwarebytes erkennt SpeedAnalysis.com als potenzielle BedrohungWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
15.06.2014, 20:56 | #1 |
| Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung Hi, ich hab grade ein Suchlauf mit Malwarebytes Anti Malware gemacht. Dabei wurden potenzielle Bedrohungen erkannt. Ausschließlich mit dem Pfad C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com Ich hab keine Ahnung, ob ich das in Quarantäne verschieben soll oder löschen oder ob das nix gefährliches ist... Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 15.06.2014 Suchlauf-Zeit: 21:09:09 Logdatei: mbam log.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.06.15.05 Rootkit Datenbank: v2014.06.02.01 Lizenz: Premium Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Aktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Philipp Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 325970 Verstrichene Zeit: 20 Min, 49 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 5 PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\mz, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\skin, , [ebc73d36b2c98fa78bbb9c03a260d729], Dateien: 22 PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome.manifest, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\install.rdf, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\background.html, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\bg.js, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\button.xml, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\config.js, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\content.js, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\framework.js, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\framework.xul, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon128.png, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon16.png, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon24.ico, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon24.png, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon32.ico, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon32.png, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon48.png, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\jquery-1.6.2.min.js, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\options.xul, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\settings.json, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\mz\background.js, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\mz\content.js, , [ebc73d36b2c98fa78bbb9c03a260d729], PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\skin\framework.css, , [ebc73d36b2c98fa78bbb9c03a260d729], Physische Sektoren: 0 (No malicious items detected) (end) MFG Philipp
__________________ Viele Grüße hypercraft just take the coffee smiley |
16.06.2014, 06:10 | #2 |
/// the machine /// TB-Ausbilder | Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
16.06.2014, 10:16 | #3 |
| Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung hi,
__________________hier die addition.txt und die frst.txt: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-06-2014 Ran by Philipp (administrator) on PHILIPPS-PC on 16-06-2014 11:13:08 Running from C:\Users\Philipp\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916112 2012-04-08] (Synaptics Incorporated) HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation) HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation) HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-01-31] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Philipp\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Philipp\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-23] Chrome: ======= CHR Extension: (Adblock Plus) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-26] CHR Extension: (Adblock Advisor) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplojogpbcbnjoemcalepfmbcpnkpjjo [2014-04-26] CHR Extension: (Google Wallet) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-09] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2266296 2014-05-16] (Microsoft Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-04-18] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [164184 2012-04-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [99616 2014-03-05] (Overwolf LTD) R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76888 2014-06-04] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed] R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed] R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-03-09] (Atheros) ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [32896 2012-03-19] (Advanced Micro Devices, Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation) R2 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [91352 2014-05-12] (Malwarebytes Corporation) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-16] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-16 11:13 - 2014-06-16 11:13 - 00016290 _____ () C:\Users\Philipp\Downloads\FRST.txt 2014-06-16 11:12 - 2014-06-16 11:13 - 00000000 ____D () C:\FRST 2014-06-16 11:12 - 2014-06-16 11:12 - 02081280 _____ (Farbar) C:\Users\Philipp\Downloads\FRST64.exe 2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg 2014-06-12 10:27 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-06-12 10:27 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-06-12 10:27 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-06-12 10:27 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-06-12 10:27 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-06-12 10:27 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-06-12 10:27 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-06-12 10:27 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-06-12 10:27 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-06-12 10:27 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-06-12 10:27 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-06-12 10:27 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-06-12 10:27 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-06-12 10:27 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-06-12 10:27 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-06-12 10:27 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-06-12 10:27 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-06-12 10:27 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-06-12 10:27 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-06-12 10:27 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-06-12 10:27 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-06-12 10:27 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-06-12 10:27 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-06-12 10:27 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-06-12 10:27 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-06-12 10:27 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-06-12 10:27 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-06-12 10:27 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-06-12 10:27 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-06-12 10:27 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-06-12 10:27 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-06-12 10:27 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-06-12 10:27 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-06-12 10:27 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-06-12 10:27 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-06-12 10:27 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-06-12 10:27 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-12 10:27 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-06-12 10:27 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-06-12 10:27 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-06-12 10:27 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-06-12 10:27 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-06-12 10:27 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-06-12 10:27 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-06-12 10:27 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-06-12 10:27 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-06-12 10:27 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-06-12 10:27 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-06-12 10:27 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-06-12 10:27 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-06-12 10:27 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-06-12 10:27 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-06-12 10:27 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll 2014-06-12 10:27 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll 2014-06-12 10:27 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll 2014-06-12 10:27 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll 2014-06-12 10:27 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2014-06-12 10:27 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-06-12 10:27 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll 2014-06-12 10:27 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll 2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll 2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll 2014-06-12 10:27 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll 2014-06-12 10:27 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll 2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll 2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll 2014-06-12 10:25 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-06-12 10:25 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig 2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2014-06-06 15:21 - 2014-06-06 15:22 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe 2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR 2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR 2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe 2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory 2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk 2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2014-06-06 13:53 - 2014-06-06 13:55 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe 2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt 2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822 2014-06-03 17:24 - 2014-06-03 17:25 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp 2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP 2014-06-03 15:50 - 2014-06-07 00:33 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core 2014-06-02 18:50 - 2014-06-07 00:33 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe 2014-06-02 18:50 - 2014-06-07 00:32 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0 2014-06-02 18:50 - 2014-06-04 20:29 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe 2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk 2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3 2014-06-01 20:39 - 2014-06-15 20:59 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2014-06-01 20:37 - 2014-06-03 18:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin 2014-06-01 20:37 - 2014-06-03 15:45 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin 2014-06-01 20:34 - 2014-06-15 22:05 - 00000000 ____D () C:\ProgramData\Origin 2014-06-01 20:34 - 2014-06-15 20:56 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-06-01 20:34 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk 2014-06-01 15:14 - 2014-06-01 15:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D} 2014-05-31 18:01 - 2014-06-04 20:21 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab 2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-31 16:21 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2014-05-31 16:21 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2014-05-31 16:21 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2014-05-31 16:21 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2014-05-31 16:20 - 2014-05-31 16:21 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log 2014-05-27 16:39 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll 2014-05-27 16:39 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2014-05-26 20:01 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys 2014-05-26 20:01 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-05-26 20:01 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-05-26 20:01 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll 2014-05-26 20:01 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll 2014-05-26 20:01 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll 2014-05-26 20:01 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll 2014-05-26 20:01 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll 2014-05-26 20:01 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll 2014-05-26 20:01 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll 2014-05-26 20:01 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe 2014-05-26 20:01 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe 2014-05-26 20:01 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll 2014-05-26 20:01 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe 2014-05-26 20:01 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll 2014-05-26 20:01 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe 2014-05-26 20:00 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll 2014-05-26 20:00 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll 2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-05-23 14:31 - 2014-06-07 10:48 - 00010364 _____ () C:\windows\PFRO.log ==================== One Month Modified Files and Folders ======= 2014-06-16 11:13 - 2014-06-16 11:13 - 00016290 _____ () C:\Users\Philipp\Downloads\FRST.txt 2014-06-16 11:13 - 2014-06-16 11:12 - 00000000 ____D () C:\FRST 2014-06-16 11:13 - 2013-07-14 23:17 - 01671541 _____ () C:\windows\WindowsUpdate.log 2014-06-16 11:13 - 2012-10-21 19:17 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Temp 2014-06-16 11:12 - 2014-06-16 11:12 - 02081280 _____ (Farbar) C:\Users\Philipp\Downloads\FRST64.exe 2014-06-16 11:11 - 2014-04-11 17:40 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-16 11:09 - 2014-04-27 12:29 - 00005040 _____ () C:\windows\setupact.log 2014-06-16 11:09 - 2012-05-25 07:00 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-06-16 11:09 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-06-15 22:06 - 2013-01-14 18:13 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-06-15 22:05 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Origin 2014-06-15 22:03 - 2012-05-25 22:31 - 00700134 _____ () C:\windows\system32\perfh007.dat 2014-06-15 22:03 - 2012-05-25 22:31 - 00149984 _____ () C:\windows\system32\perfc007.dat 2014-06-15 22:03 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI 2014-06-15 21:50 - 2013-04-23 19:22 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-15 21:49 - 2013-04-02 20:58 - 00001128 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000UA.job 2014-06-15 21:07 - 2013-04-02 21:01 - 00002373 _____ () C:\Users\Philipp\Desktop\Google Chrome.lnk 2014-06-15 21:00 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-15 21:00 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-15 20:59 - 2014-06-01 20:39 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2014-06-15 20:56 - 2014-06-01 20:34 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-06-15 19:20 - 2012-05-25 06:56 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg 2014-06-15 19:09 - 2012-05-25 07:00 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-06-15 18:00 - 2013-04-02 20:58 - 00001076 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000Core.job 2014-06-15 18:00 - 2012-11-11 16:51 - 00000000 ____D () C:\Users\Philipp\AppData\Local\CrashDumps 2014-06-14 10:27 - 2013-08-16 21:15 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\.minecraft 2014-06-14 10:25 - 2013-07-15 14:17 - 00000000 ____D () C:\windows\system32\MRT 2014-06-14 10:23 - 2012-10-20 21:21 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-06-14 10:20 - 2014-05-06 22:19 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-06-08 11:13 - 2014-06-12 10:25 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-06-08 11:08 - 2014-06-12 10:25 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK 2014-06-07 10:48 - 2014-05-23 14:31 - 00010364 _____ () C:\windows\PFRO.log 2014-06-07 00:33 - 2014-06-03 15:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr 2014-06-07 00:33 - 2014-06-02 18:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe 2014-06-07 00:32 - 2014-06-02 18:50 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig 2014-06-06 20:14 - 2012-10-21 19:17 - 00000000 ____D () C:\Users\Philipp 2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2014-06-06 15:22 - 2014-06-06 15:21 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe 2014-06-06 15:17 - 2013-05-27 22:46 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\vlc 2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR 2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR 2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe 2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory 2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk 2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2014-06-06 13:56 - 2013-05-18 14:55 - 00000000 ____D () C:\Program Files (x86)\FreeTime 2014-06-06 13:55 - 2014-06-06 13:53 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe 2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt 2014-06-04 20:29 - 2014-06-02 18:50 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe 2014-06-04 20:21 - 2014-05-31 18:01 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp 2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822 2014-06-03 18:37 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin 2014-06-03 17:25 - 2014-06-03 17:24 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp 2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP 2014-06-03 17:24 - 2012-11-22 15:12 - 00000000 ____D () C:\windows\Minidump 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core 2014-06-03 15:45 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin 2014-06-03 15:45 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk 2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3 2014-06-02 18:50 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-02 18:49 - 2014-04-27 15:59 - 00018934 _____ () C:\windows\DirectX.log 2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk 2014-06-01 15:14 - 2014-06-01 15:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-01 15:10 - 2012-11-25 17:18 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-06-01 00:32 - 2013-06-21 23:54 - 00007597 _____ () C:\Users\Philipp\AppData\Local\Resmon.ResmonCfg 2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D} 2014-05-31 17:55 - 2012-10-21 12:31 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\SoftGrid Client 2014-05-31 17:29 - 2014-03-27 23:55 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\TS3Client 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab 2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-31 16:21 - 2014-05-31 16:20 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log 2014-05-31 16:21 - 2013-10-16 23:29 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-31 16:21 - 2013-06-23 18:37 - 00000000 ____D () C:\Program Files (x86)\Java 2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-30 22:12 - 2013-03-02 20:49 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-30 12:21 - 2014-06-12 10:27 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-05-30 12:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-05-30 12:02 - 2014-06-12 10:27 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-05-30 11:45 - 2014-06-12 10:27 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-05-30 11:39 - 2014-06-12 10:27 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-05-30 11:39 - 2014-06-12 10:27 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-05-30 11:38 - 2014-06-12 10:27 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-05-30 11:28 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-05-30 11:27 - 2014-06-12 10:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-05-30 11:24 - 2014-06-12 10:27 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-05-30 11:21 - 2014-06-12 10:27 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-05-30 11:21 - 2014-06-12 10:27 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-05-30 11:20 - 2014-06-12 10:27 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-05-30 11:18 - 2014-06-12 10:27 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-05-30 11:11 - 2014-06-12 10:27 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-05-30 11:08 - 2014-06-12 10:27 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-05-30 11:06 - 2014-06-12 10:27 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-05-30 11:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-05-30 10:55 - 2014-06-12 10:27 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-05-30 10:49 - 2014-06-12 10:27 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-05-30 10:46 - 2014-06-12 10:27 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-05-30 10:44 - 2014-06-12 10:27 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-05-30 10:44 - 2014-06-12 10:27 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-05-30 10:43 - 2014-06-12 10:27 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-05-30 10:42 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-05-30 10:38 - 2014-06-12 10:27 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-05-30 10:35 - 2014-06-12 10:27 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-05-30 10:34 - 2014-06-12 10:27 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-05-30 10:33 - 2014-06-12 10:27 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-05-30 10:30 - 2014-06-12 10:27 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-05-30 10:29 - 2014-06-12 10:27 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-05-30 10:28 - 2014-06-12 10:27 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-05-30 10:27 - 2014-06-12 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-05-30 10:24 - 2014-06-12 10:27 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-05-30 10:23 - 2014-06-12 10:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-05-30 10:16 - 2014-06-12 10:27 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-05-30 10:10 - 2014-06-12 10:27 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-05-30 10:06 - 2014-06-12 10:27 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-05-30 10:04 - 2014-06-12 10:27 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-05-30 10:02 - 2014-06-12 10:27 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-05-30 09:56 - 2014-06-12 10:27 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-05-30 09:56 - 2014-06-12 10:27 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-05-30 09:54 - 2014-06-12 10:27 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-05-30 09:50 - 2014-06-12 10:27 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-05-30 09:49 - 2014-06-12 10:27 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-05-30 09:43 - 2014-06-12 10:27 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-05-30 09:40 - 2014-06-12 10:27 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-05-30 09:30 - 2014-06-12 10:27 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-05-30 09:21 - 2014-06-12 10:27 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-05-30 09:15 - 2014-06-12 10:27 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-05-30 09:13 - 2014-06-12 10:27 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-05-30 09:13 - 2014-06-12 10:27 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-05-29 16:46 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache 2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-05-26 16:37 - 2013-02-17 16:31 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Windows Live 2014-05-22 15:50 - 2013-03-04 22:23 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-05-17 11:52 - 2013-04-23 19:06 - 00000000 ____D () C:\windows\pss Some content of TEMP: ==================== C:\Users\Philipp\AppData\Local\Temp\drm_dialogs.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-05-29 16:39 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-06-2014 Ran by Philipp at 2014-06-16 11:14:11 Running from C:\Users\Philipp\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== „Windows Live Essentials“ (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden „Windows Live Mail“ (x32 Version: 16.4.3505.0912 - „Microsoft Corporation“) Hidden „Windows Live Messenger“ (x32 Version: 16.4.3505.0912 - „Microsoft Corporation“) Hidden 4Story DE 4.0.167 (HKLM-x32\...\4Story_DE_is1) (Version: - ) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Ace of Spades (HKLM-x32\...\Steam App 224540) (Version: - Jagex Limited) Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Amazon MP3-Downloader 1.0.17 (HKLM-x32\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC) AMD Accelerated Video Transcoding (Version: 2.00.0002 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.898.1 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{F81156E9-1687-E56A-E3B4-3CF3D17520E2}) (Version: 3.0.868.0 - Advanced Micro Devices, Inc.) Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Bluetooth Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.126 - Atheros) Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros) AVG PC TuneUp 2014 (de-DE) (x32 Version: 14.0.1001.174 - AVG) Hidden Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.4.0 - EA Digital Illusions CE AB) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center (x32 Version: 2012.0418.645.10054 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.0418.645.10054 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.0418.645.10054 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Profiles Mobile (x32 Version: 2012.0418.645.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.0418.645.10054 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.02 - Piriform) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.4852 - CDBurnerXP) CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.) CyberLink Media Suite (x32 Version: 8.0.2227 - CyberLink Corp.) Hidden CyberLink Media+ Player10 (HKLM-x32\...\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 - CyberLink Corp.) CyberLink Media+ Player10 (x32 Version: 10.0.1110.00 - CyberLink Corp.) Hidden CyberLink MediaShow (HKLM-x32\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1130a - CyberLink Corp.) CyberLink MediaShow (x32 Version: 5.0.1130a - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.) CyberLink Power2Go (x32 Version: 6.1.3802 - CyberLink Corp.) Hidden CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3306 - CyberLink Corp.) CyberLink PowerDirector (x32 Version: 8.0.3306 - CyberLink Corp.) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.5016 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.1.5016 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DIE SIEDLER - Das Erbe der Könige - Gold Edition (HKLM-x32\...\{E08DE897-B6AF-4DFF-9E90-131E80C876B4}) (Version: 1.00.0000 - Blue Byte) Easy File Share (HKLM-x32\...\{12F81925-F3C1-40DB-91F7-777817974319}) (Version: 1.3.1 - Samsung Electronics CO., LTD.) Easy Migration (HKLM-x32\...\{EDE7A262-DB20-4432-A630-2ACEE186C416}) (Version: 1.0 - Samsung Electronics CO., LTD.) Easy Settings (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.1 - Samsung Electronics CO., LTD.) Easy Software Manager (HKLM-x32\...\{DE256D8B-D971-456D-BC02-CB64DA24F115}) (Version: 1.2.17.13 - Samsung Electronics CO., LTD.) Easy Support Center (HKLM\...\{0738F5F1-8E70-49A6-8692-F5722E1E5A4D}) (Version: 1.2.23 - Samsung Electronics CO., LTD.) E-POP (HKLM-x32\...\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) FormatFactory 3.3.4.0 (HKLM-x32\...\FormatFactory) (Version: 3.3.4.0 - Format Factory) Formatwandler 2D zu 3D (HKLM-x32\...\{1F9E4FE1-5C7E-4501-0001-87D989B30F53}) (Version: 2.3.10.804 - S.A.D.) Fotoattēlu galerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogaléria (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Foto-galerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalleri (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalleriet (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotoğraf Galerisi (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Free DVD Video Converter version 2.0.13.430 (HKLM-x32\...\Free DVD Video Converter_is1) (Version: 2.0.13.430 - DVDVideoSoft Ltd.) Free Video Dub version 2.0.18.430 (HKLM-x32\...\Free Video Dub_is1) (Version: 2.0.18.430 - DVDVideoSoft Ltd.) Free Video to DVD Converter version 5.0.24.430 (HKLM-x32\...\Free Video to DVD Converter_is1) (Version: 5.0.24.430 - DVDVideoSoft Ltd.) Galeria de Fotografias (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galeria de Fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galeria fotografii (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerie foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerija fotografija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Gameforge Live 1.10.1 "Legend" (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 1.10.1 - Gameforge) GIMP 2.8.8 (HKLM\...\GIMP-2_is1) (Version: 2.8.8 - The GIMP Team) Google Chrome (HKCU\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden HAWKEN (HKLM-x32\...\Steam App 271290) (Version: - Adhesive Games) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3090 - Intel Corporation) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36279 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.23.943.1 - Intel Corporation) Hidden iTunes (HKLM\...\{1CF5754A-545B-4360-BFDE-2847BC728DFC}) (Version: 11.2.0.115 - Apple Inc.) Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.600 - Oracle) Java Auto Updater (x32 Version: 2.1.60.19 - Oracle, Inc.) Hidden Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden LEGO® Der Herr der Ringe™ (HKLM-x32\...\{C6F20FA7-342A-47A9-A3C8-EB36CABE6419}) (Version: 1.0.0.0 - Warner Bros. Interactive Entertainment) LEGO® Star Wars™: Die Komplette Saga (HKLM-x32\...\InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}) (Version: 1.00.0000 - LucasArts) LEGO® Star Wars™: The Complete Saga (x32 Version: 1.00.0000 - LucasArts) Hidden Logitech Unifying-Software 2.10 (HKLM\...\Logitech Unifying) (Version: 2.10.37 - Logitech) LUMIX Map Tool (HKLM-x32\...\InstallShield_{7DCF5B1D-79C2-4F24-9746-511436EBC6B4}) (Version: 1.1.0 - Panasonic Corporation) LUMIX Map Tool (x32 Version: 1.1.0 - Panasonic Corporation) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 15.0.4615.1002 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 17.0.2006.0314 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.0.162.0 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (Version: 2.0.162.0 - Microsoft Corporation) Hidden Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 22.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Multimedia POP (HKLM-x32\...\{CE3007FF-3E77-4B5B-8F94-662C9582C8A5}) (Version: 1.2 - Samsung Electronics CO., LTD.) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4615.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4615.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4615.1002 - Microsoft Corporation) Hidden Origin (HKLM-x32\...\Origin) (Version: 9.4.7.2799 - Electronic Arts, Inc.) Overwolf (HKLM-x32\...\{FB83467F-D8EB-43E6-8B3D-860B045C1C52}) (Version: 0.51.325 - Overwolf) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.9 - Pando Networks Inc.) PDF24 Creator 5.4.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden PHOTOfunSTUDIO 9.1 PE (HKLM-x32\...\{C13FE7DE-D34D-48CC-9FA3-8DB9A3621B98}) (Version: 9.01.709 - Panasonic Corporation) Poczta usługi Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden RarmaRadio 2.69 (HKLM-x32\...\RarmaRadio_is1) (Version: - RaimerSoft) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.54.309.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6602 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.39025 - Realtek Semiconductor Corp.) S4 League_EU (HKLM-x32\...\{27E4F38F-8E97-4701-B620-E575A83D5EC9}) (Version: 1.00.0000 - ) Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.2.7 - Samsung Electronics CO., LTD.) Seterra 4.02 (HKLM-x32\...\{7C7C274C-DBC8-47FE-923F-9AAD59A4F9F4}}_is1) (Version: 4.02 - Marianne Wartoft AB) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Software Launcher (HKLM-x32\...\{B750B5C2-CC17-4967-905B-29F4EB986131}) (Version: 1.0.2 - Samsung Electronics CO., LTD.) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Stronghold Legends (HKLM-x32\...\{66A405D2-BA14-4594-BF36-B3B544F0754E}) (Version: 1.20.0000 - Firefly Studios) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.1.1.0 - Synaptics Incorporated) System Requirements Lab CYRI (HKLM-x32\...\{F3FCB08B-E752-444D-86A0-0634A4F3B23D}) (Version: 6.0.8.0 - Husdawg, LLC) Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.26297 - TeamViewer) The Lord of the Rings Online™ (HKLM-x32\...\Steam App 212500) (Version: - Turbine, Inc.) User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.2 - Samsung Electronics CO., LTD.) Valokuvavalikoima (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Family Safety (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3505.0912 - společnost Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 16.4.3505.0912 - společnost Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 16.4.3505.0912 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Pošta (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live 메일 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live 필수 패키지 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live 软件包 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Liven peruspaketti (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) Συλλογή φωτογραφιών (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 16.4.3505.0912 - Корпорация Майкрософт) Hidden Фотоальбом (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Фотогалерия (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Фотографии (общедоступная версия) (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden גלריית התמונות (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden معرض الصور (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 사진 갤러리 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 影像中心 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 照片库 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 10-06-2014 08:51:19 Windows Update 14-06-2014 08:19:31 Windows Update 15-06-2014 17:18:51 Entfernt League of Legends ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-07-29 12:22 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {061B63E3-4702-4798-9A4C-44EDF6DED531} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe Task: {0D877A6A-DAFC-4706-92DE-ACAEEC9828FC} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2012-01-28] (SEC) Task: {106A0457-C34C-467F-AD5B-7BE2FFD8FD55} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe [2012-01-31] (Samsung Electronics Co., Ltd.) Task: {1B240628-46D9-4919-BF2D-EA60809CCB7A} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe [2012-04-03] (Samsung Electronics) Task: {2D458F6E-F3FF-48B6-9648-C6B89F61843C} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {43583B6E-C95B-4249-B8B9-5C6A581569A9} - System32\Tasks\EasySupportCenter => C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe [2012-04-19] (Samsung Electronics CO., LTD.) Task: {595B2086-8717-4475-ADF3-34317656AAAE} - System32\Tasks\Easy Software Manager Agent => C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe [2012-04-12] (Samsung Electronics CO., LTD.) Task: {6074B35D-C6A5-4464-8D76-F06C6B2163E8} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-15] (Adobe Systems Incorporated) Task: {619A7A74-D5D5-4977-A82F-3FC2B87E3BBD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd) Task: {628382A1-D753-4470-862B-787A23703886} - System32\Tasks\{A59A4412-F918-422E-8312-E52EC3A6ADE4} => C:\Program Files (x86)\Intel\Intel Control Center\IntelControlCenter.exe [2009-11-18] (Intel Corporation) Task: {7149B2AA-8F61-45F8-9A31-828C6949AA65} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Easy Settings\SCCSpeedBoot.exe [2012-03-27] (Samsung Electronics Co., Ltd.) Task: {7294C6FC-FA3D-4C3F-B4DE-57501CAC5B83} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {762C6DB5-6A3E-4460-860A-E821269AA442} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-04-15] (Microsoft Corporation) Task: {7A0A3164-C5A9-462D-B461-97D0045EE6D9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000UA => C:\Users\Philipp\AppData\Local\Google\Update\GoogleUpdate.exe [2013-04-02] (Google Inc.) Task: {82E0BCD1-FF69-400B-84CF-2ED358EDEEE8} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe Task: {994B5893-7320-4417-BD3F-B0C83F32673F} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-02-16] (CyberLink) Task: {9C3DC8C1-6F2C-4B7E-AD51-261ABDDF334C} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-03-26] (Intel Corporation) Task: {9FB3BC54-6143-4E17-95F7-EA5FA049ADEB} - System32\Tasks\{7176894E-22A2-4903-925E-9F3E1D4F4A60} => Chrome.exe hxxp://ui.skype.com/ui/0/6.3.0.105/de/go/help.faq.installer?LastError=1618 Task: {A289079E-5A5E-466E-AA92-3E99AB1EF0D7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-05-22] (Microsoft Corporation) Task: {A52A91BB-6DFA-42E3-9CF1-F3B12982887E} - System32\Tasks\{6003407F-CA82-409D-9441-255F86102808} => C:\Users\Philipp\Desktop\4Story_DE_gflive_4.0.167.exe Task: {ABB4245A-C9A9-41FE-A112-BAA5683F90FB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000Core => C:\Users\Philipp\AppData\Local\Google\Update\GoogleUpdate.exe [2013-04-02] (Google Inc.) Task: {AF6E35AA-D638-4AFD-807B-7F47B72A27D6} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe [2012-03-27] (Samsung Electronics Co., Ltd.) Task: {B0F3B2DF-CE80-4BDB-8523-5C84D5DAB82E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-23] (Google Inc.) Task: {B6C71C8A-9C94-421E-A573-711B809B149A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-23] (Google Inc.) Task: {C4063F29-E7ED-4D12-BE19-8C27EC1BB1C6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-05-22] (Microsoft Corporation) Task: {D8689179-7317-4A6F-A06B-D4BC8C521FF0} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe [2012-01-31] (Samsung Electronics) Task: {DB90A8B3-522B-45B9-98E4-34BB14322A29} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe [2012-04-17] (Samsung Electronics Co., Ltd.) Task: {E25C0C07-448F-40C0-9775-A09A41E27956} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-03-26] (Intel Corporation) Task: {F073AAC5-C82F-49B1-A28A-C120BC045192} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe [2011-11-18] (SAMSUNG Electronics co., LTD.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000Core.job => C:\Users\Philipp\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000UA.job => C:\Users\Philipp\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============= 2014-03-20 18:47 - 2013-10-31 18:13 - 00102568 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2013-03-04 22:23 - 2014-04-15 03:39 - 00630952 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll 2014-06-02 18:50 - 2014-06-04 20:29 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe 2012-05-25 08:04 - 2009-12-01 09:21 - 00244904 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2012-07-06 03:45 - 2012-02-13 08:02 - 00031624 _____ () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe 2012-03-26 11:33 - 2012-03-26 11:33 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll 2012-05-25 07:00 - 2012-04-18 12:49 - 00127320 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2012-07-06 03:45 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll 2012-07-06 03:46 - 2011-02-16 18:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll 2014-06-15 21:06 - 2014-06-05 15:58 - 00716616 _____ () C:\Users\Philipp\AppData\Local\Google\Chrome\Application\35.0.1916.153\libglesv2.dll 2014-06-15 21:06 - 2014-06-05 15:58 - 00126280 _____ () C:\Users\Philipp\AppData\Local\Google\Chrome\Application\35.0.1916.153\libegl.dll 2014-06-15 21:06 - 2014-06-05 15:58 - 04217672 _____ () C:\Users\Philipp\AppData\Local\Google\Chrome\Application\35.0.1916.153\pdf.dll 2014-06-15 21:06 - 2014-06-05 15:58 - 00414536 _____ () C:\Users\Philipp\AppData\Local\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll 2014-06-15 21:06 - 2014-06-05 15:58 - 01732424 _____ () C:\Users\Philipp\AppData\Local\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll 2012-05-25 07:23 - 2011-09-08 12:40 - 01645056 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll 2009-11-02 07:20 - 2009-11-02 07:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-02 07:23 - 2009-11-02 07:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2012-05-25 06:59 - 2011-11-29 13:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2012-05-25 07:00 - 2012-04-18 12:50 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PHOTOfunSTUDIO 9.1 PE.lnk => C:\windows\pss\PHOTOfunSTUDIO 9.1 PE.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Philipp^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^An OneNote senden.lnk => C:\windows\pss\An OneNote senden.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: AthBtTray => "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" MSCONFIG\startupreg: AtherosBtStack => "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY MSCONFIG\startupreg: Google Update => "C:\Users\Philipp\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch MSCONFIG\startupreg: Overwolf => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent MSCONFIG\startupreg: PDFPrint => C:\Program Files (x86)\PDF24\pdf24.exe MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15397 Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15397 Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6318 Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6318 Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5257 Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5257 Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/15/2014 10:01:27 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4243 System errors: ============= Error: (06/15/2014 10:10:16 PM) (Source: bowser) (EventID: 8003) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{65CCD3D7-2C99-4B7D-B1E3-EF3835655E6B}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (06/15/2014 10:05:38 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (06/15/2014 07:19:43 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (06/15/2014 07:19:42 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (06/15/2014 07:19:42 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (06/15/2014 07:19:41 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (06/15/2014 07:19:41 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (06/14/2014 08:45:03 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1000) (User: NT-AUTORITÄT) Description: Fehler bei der CBS-Clientinitialisierung. Letzter Fehler: 0x8007045b Error: (06/14/2014 08:42:06 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {ED1D0FDF-4414-470A-A56D-CFB68623FC58} Error: (06/14/2014 10:27:40 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Microsoft Office Sessions: ========================= Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15397 Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15397 Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6318 Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6318 Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5257 Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5257 Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/15/2014 10:01:27 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4243 CodeIntegrity Errors: =================================== Date: 2013-06-15 11:39:05.946 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-06-15 11:39:05.899 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 28% Total physical RAM: 8081.44 MB Available physical RAM: 5815.67 MB Total Pagefile: 16161.06 MB Available Pagefile: 13647.34 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:674.67 GB) (Free:401.22 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 699 GB) (Disk ID: A44E69F2) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=675 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=24 GB) - (Type=27) ==================== End Of Log ============================
__________________ |
16.06.2014, 21:39 | #4 |
/// the machine /// TB-Ausbilder | Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.06.2014, 20:00 | #5 |
| Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung hi, adwcleaner: Code:
ATTFilter # AdwCleaner v3.212 - Bericht erstellt am 17/06/2014 um 20:18:41 # Aktualisiert 05/06/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Philipp - PHILIPPS-PC # Gestartet von : C:\Users\Philipp\Desktop\adwcleaner_3.212.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS Schlüssel Gelöscht : HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 -\\ Mozilla Firefox v29.0.1 (de) [ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\895ns92q.default\prefs.js ] [ Datei : C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1299 octets] - [28/09/2013 12:06:44] AdwCleaner[R1].txt - [1161 octets] - [02/11/2013 17:59:30] AdwCleaner[R2].txt - [1572 octets] - [23/01/2014 16:18:42] AdwCleaner[R3].txt - [1637 octets] - [17/06/2014 16:52:33] AdwCleaner[R4].txt - [1695 octets] - [17/06/2014 20:15:16] AdwCleaner[S0].txt - [1362 octets] - [28/09/2013 12:08:18] AdwCleaner[S1].txt - [1223 octets] - [02/11/2013 19:05:09] AdwCleaner[S2].txt - [1633 octets] - [23/01/2014 16:20:23] AdwCleaner[S3].txt - [1570 octets] - [17/06/2014 20:18:41] ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1630 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Philipp on 17.06.2014 at 20:24:01,14 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3905478184-3407929709-2893840352-1000\Software\sweetim ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Philipp\AppData\Roaming\mozilla\firefox\profiles\yjwidrr9.default\minidumps [4 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 17.06.2014 at 20:33:23,64 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-06-2014 Ran by Philipp (administrator) on PHILIPPS-PC on 17-06-2014 20:57:10 Running from C:\Users\Philipp\Desktop\Virensuche Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916112 2012-04-08] (Synaptics Incorporated) HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation) HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation) HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-01-31] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Philipp\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Philipp\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-23] Chrome: ======= CHR HomePage: CHR Extension: (Adblock Plus) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-26] CHR Extension: (Adblock Advisor) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplojogpbcbnjoemcalepfmbcpnkpjjo [2014-04-26] CHR Extension: (Google Wallet) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-09] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2279608 2014-05-21] (Microsoft Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-04-18] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [164184 2012-04-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [99616 2014-03-05] (Overwolf LTD) R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76888 2014-06-04] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed] R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed] R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-03-09] (Atheros) ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [32896 2012-03-19] (Advanced Micro Devices, Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation) R2 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [91352 2014-05-12] (Malwarebytes Corporation) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-17] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-17 20:23 - 2014-06-17 20:23 - 01016261 _____ (Thisisu) C:\Users\Philipp\Downloads\JRT.exe 2014-06-17 20:14 - 2014-06-17 20:14 - 00364286 _____ () C:\Users\Philipp\Documents\Die Entdeckung Amerikas.pptx 2014-06-17 16:53 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll 2014-06-17 16:49 - 2014-06-17 16:49 - 01333465 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.212.exe 2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 __SHD () C:\ProgramData\DSS 2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 ____D () C:\Users\Philipp\Documents\FIFA 14 DEMO 2014-06-16 11:47 - 2014-06-16 11:47 - 00000378 _____ () C:\Users\Philipp\Downloads\text-2.txt 2014-06-16 11:20 - 2014-06-17 20:57 - 00000000 ____D () C:\Users\Philipp\Desktop\Virensuche 2014-06-16 11:14 - 2014-06-16 11:14 - 00042738 _____ () C:\Users\Philipp\Downloads\Addition.txt 2014-06-16 11:13 - 2014-06-16 11:14 - 00048826 _____ () C:\Users\Philipp\Downloads\FRST.txt 2014-06-16 11:12 - 2014-06-17 20:57 - 00000000 ____D () C:\FRST 2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg 2014-06-12 10:27 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-06-12 10:27 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-06-12 10:27 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-06-12 10:27 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-06-12 10:27 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-06-12 10:27 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-06-12 10:27 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-06-12 10:27 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-06-12 10:27 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-06-12 10:27 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-06-12 10:27 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-06-12 10:27 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-06-12 10:27 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-06-12 10:27 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-06-12 10:27 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-06-12 10:27 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-06-12 10:27 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-06-12 10:27 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-06-12 10:27 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-06-12 10:27 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-06-12 10:27 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-06-12 10:27 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-06-12 10:27 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-06-12 10:27 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-06-12 10:27 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-06-12 10:27 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-06-12 10:27 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-06-12 10:27 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-06-12 10:27 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-06-12 10:27 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-06-12 10:27 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-06-12 10:27 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-06-12 10:27 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-06-12 10:27 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-06-12 10:27 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-06-12 10:27 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-06-12 10:27 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-12 10:27 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-06-12 10:27 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-06-12 10:27 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-06-12 10:27 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-06-12 10:27 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-06-12 10:27 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-06-12 10:27 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-06-12 10:27 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-06-12 10:27 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-06-12 10:27 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-06-12 10:27 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-06-12 10:27 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-06-12 10:27 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-06-12 10:27 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-06-12 10:27 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-06-12 10:27 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll 2014-06-12 10:27 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll 2014-06-12 10:27 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll 2014-06-12 10:27 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll 2014-06-12 10:27 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2014-06-12 10:27 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-06-12 10:27 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll 2014-06-12 10:27 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll 2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll 2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll 2014-06-12 10:27 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll 2014-06-12 10:27 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll 2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll 2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll 2014-06-12 10:25 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-06-12 10:25 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig 2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2014-06-06 15:21 - 2014-06-06 15:22 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe 2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR 2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR 2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe 2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory 2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk 2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2014-06-06 13:53 - 2014-06-06 13:55 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe 2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt 2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822 2014-06-03 17:24 - 2014-06-03 17:25 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp 2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP 2014-06-03 15:50 - 2014-06-16 14:20 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core 2014-06-02 18:50 - 2014-06-16 14:20 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe 2014-06-02 18:50 - 2014-06-16 14:20 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0 2014-06-02 18:50 - 2014-06-04 20:29 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe 2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk 2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3 2014-06-01 20:39 - 2014-06-15 20:59 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2014-06-01 20:37 - 2014-06-03 18:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin 2014-06-01 20:37 - 2014-06-03 15:45 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin 2014-06-01 20:34 - 2014-06-16 14:58 - 00000000 ____D () C:\ProgramData\Origin 2014-06-01 20:34 - 2014-06-16 11:22 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-06-01 20:34 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk 2014-06-01 15:14 - 2014-06-01 15:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D} 2014-05-31 18:01 - 2014-06-04 20:21 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab 2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-31 16:21 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2014-05-31 16:21 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2014-05-31 16:21 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2014-05-31 16:21 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2014-05-31 16:20 - 2014-05-31 16:21 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log 2014-05-27 16:39 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll 2014-05-27 16:39 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2014-05-26 20:01 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys 2014-05-26 20:01 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-05-26 20:01 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-05-26 20:01 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll 2014-05-26 20:01 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll 2014-05-26 20:01 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll 2014-05-26 20:01 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll 2014-05-26 20:01 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll 2014-05-26 20:01 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll 2014-05-26 20:01 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll 2014-05-26 20:01 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe 2014-05-26 20:01 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe 2014-05-26 20:01 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll 2014-05-26 20:01 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe 2014-05-26 20:01 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll 2014-05-26 20:01 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe 2014-05-26 20:00 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll 2014-05-26 20:00 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll 2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-05-23 14:31 - 2014-06-17 20:19 - 00016238 _____ () C:\windows\PFRO.log ==================== One Month Modified Files and Folders ======= 2014-06-17 20:57 - 2014-06-16 11:20 - 00000000 ____D () C:\Users\Philipp\Desktop\Virensuche 2014-06-17 20:57 - 2014-06-16 11:12 - 00000000 ____D () C:\FRST 2014-06-17 20:57 - 2012-10-21 19:17 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Temp 2014-06-17 20:56 - 2013-04-23 19:22 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-17 20:56 - 2013-04-02 20:58 - 00001128 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000UA.job 2014-06-17 20:35 - 2014-04-11 17:40 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-17 20:27 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-17 20:27 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-17 20:24 - 2013-07-14 23:17 - 01724993 _____ () C:\windows\WindowsUpdate.log 2014-06-17 20:23 - 2014-06-17 20:23 - 01016261 _____ (Thisisu) C:\Users\Philipp\Downloads\JRT.exe 2014-06-17 20:20 - 2012-05-25 07:00 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-06-17 20:19 - 2014-05-23 14:31 - 00016238 _____ () C:\windows\PFRO.log 2014-06-17 20:19 - 2014-04-27 12:29 - 00005208 _____ () C:\windows\setupact.log 2014-06-17 20:19 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-06-17 20:18 - 2013-09-28 12:06 - 00000000 ____D () C:\AdwCleaner 2014-06-17 20:14 - 2014-06-17 20:14 - 00364286 _____ () C:\Users\Philipp\Documents\Die Entdeckung Amerikas.pptx 2014-06-17 20:06 - 2013-01-14 18:13 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-06-17 19:45 - 2013-08-16 21:15 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\.minecraft 2014-06-17 19:31 - 2012-05-25 22:31 - 00700134 _____ () C:\windows\system32\perfh007.dat 2014-06-17 19:31 - 2012-05-25 22:31 - 00149984 _____ () C:\windows\system32\perfc007.dat 2014-06-17 19:31 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI 2014-06-17 19:29 - 2012-05-25 07:00 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-06-17 16:51 - 2013-04-02 20:58 - 00001076 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000Core.job 2014-06-17 16:49 - 2014-06-17 16:49 - 01333465 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.212.exe 2014-06-16 14:58 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Origin 2014-06-16 14:20 - 2014-06-03 15:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr 2014-06-16 14:20 - 2014-06-02 18:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe 2014-06-16 14:20 - 2014-06-02 18:50 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0 2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 __SHD () C:\ProgramData\DSS 2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 ____D () C:\Users\Philipp\Documents\FIFA 14 DEMO 2014-06-16 11:50 - 2013-03-04 22:23 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-06-16 11:49 - 2014-04-27 15:59 - 00037483 _____ () C:\windows\DirectX.log 2014-06-16 11:49 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-16 11:47 - 2014-06-16 11:47 - 00000378 _____ () C:\Users\Philipp\Downloads\text-2.txt 2014-06-16 11:22 - 2014-06-01 20:34 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-06-16 11:14 - 2014-06-16 11:14 - 00042738 _____ () C:\Users\Philipp\Downloads\Addition.txt 2014-06-16 11:14 - 2014-06-16 11:13 - 00048826 _____ () C:\Users\Philipp\Downloads\FRST.txt 2014-06-15 21:07 - 2013-04-02 21:01 - 00002373 _____ () C:\Users\Philipp\Desktop\Google Chrome.lnk 2014-06-15 20:59 - 2014-06-01 20:39 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2014-06-15 19:20 - 2012-05-25 06:56 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg 2014-06-15 18:00 - 2012-11-11 16:51 - 00000000 ____D () C:\Users\Philipp\AppData\Local\CrashDumps 2014-06-14 10:25 - 2013-07-15 14:17 - 00000000 ____D () C:\windows\system32\MRT 2014-06-14 10:23 - 2012-10-20 21:21 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-06-14 10:20 - 2014-05-06 22:19 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-06-08 11:13 - 2014-06-12 10:25 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-06-08 11:08 - 2014-06-12 10:25 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig 2014-06-06 20:14 - 2012-10-21 19:17 - 00000000 ____D () C:\Users\Philipp 2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2014-06-06 15:22 - 2014-06-06 15:21 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe 2014-06-06 15:17 - 2013-05-27 22:46 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\vlc 2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR 2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR 2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe 2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory 2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk 2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2014-06-06 13:56 - 2013-05-18 14:55 - 00000000 ____D () C:\Program Files (x86)\FreeTime 2014-06-06 13:55 - 2014-06-06 13:53 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe 2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt 2014-06-04 20:29 - 2014-06-02 18:50 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe 2014-06-04 20:21 - 2014-05-31 18:01 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp 2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822 2014-06-03 18:37 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin 2014-06-03 17:25 - 2014-06-03 17:24 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp 2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP 2014-06-03 17:24 - 2012-11-22 15:12 - 00000000 ____D () C:\windows\Minidump 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core 2014-06-03 15:45 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin 2014-06-03 15:45 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk 2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3 2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk 2014-06-01 15:14 - 2014-06-01 15:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-01 15:10 - 2012-11-25 17:18 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-06-01 00:32 - 2013-06-21 23:54 - 00007597 _____ () C:\Users\Philipp\AppData\Local\Resmon.ResmonCfg 2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D} 2014-05-31 17:55 - 2012-10-21 12:31 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\SoftGrid Client 2014-05-31 17:29 - 2014-03-27 23:55 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\TS3Client 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab 2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-31 16:21 - 2014-05-31 16:20 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log 2014-05-31 16:21 - 2013-10-16 23:29 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-31 16:21 - 2013-06-23 18:37 - 00000000 ____D () C:\Program Files (x86)\Java 2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-30 22:12 - 2013-03-02 20:49 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-30 12:21 - 2014-06-12 10:27 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-05-30 12:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-05-30 12:02 - 2014-06-12 10:27 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-05-30 11:45 - 2014-06-12 10:27 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-05-30 11:39 - 2014-06-12 10:27 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-05-30 11:39 - 2014-06-12 10:27 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-05-30 11:38 - 2014-06-12 10:27 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-05-30 11:28 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-05-30 11:27 - 2014-06-12 10:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-05-30 11:24 - 2014-06-12 10:27 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-05-30 11:21 - 2014-06-12 10:27 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-05-30 11:21 - 2014-06-12 10:27 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-05-30 11:20 - 2014-06-12 10:27 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-05-30 11:18 - 2014-06-12 10:27 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-05-30 11:11 - 2014-06-12 10:27 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-05-30 11:08 - 2014-06-12 10:27 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-05-30 11:06 - 2014-06-12 10:27 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-05-30 11:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-05-30 10:55 - 2014-06-12 10:27 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-05-30 10:49 - 2014-06-12 10:27 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-05-30 10:46 - 2014-06-12 10:27 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-05-30 10:44 - 2014-06-12 10:27 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-05-30 10:44 - 2014-06-12 10:27 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-05-30 10:43 - 2014-06-12 10:27 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-05-30 10:42 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-05-30 10:38 - 2014-06-12 10:27 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-05-30 10:35 - 2014-06-12 10:27 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-05-30 10:34 - 2014-06-12 10:27 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-05-30 10:33 - 2014-06-12 10:27 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-05-30 10:30 - 2014-06-12 10:27 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-05-30 10:29 - 2014-06-12 10:27 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-05-30 10:28 - 2014-06-12 10:27 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-05-30 10:27 - 2014-06-12 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-05-30 10:24 - 2014-06-12 10:27 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-05-30 10:23 - 2014-06-12 10:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-05-30 10:16 - 2014-06-12 10:27 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-05-30 10:10 - 2014-06-12 10:27 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-05-30 10:06 - 2014-06-12 10:27 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-05-30 10:04 - 2014-06-12 10:27 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-05-30 10:02 - 2014-06-12 10:27 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-05-30 09:56 - 2014-06-12 10:27 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-05-30 09:56 - 2014-06-12 10:27 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-05-30 09:54 - 2014-06-12 10:27 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-05-30 09:50 - 2014-06-12 10:27 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-05-30 09:49 - 2014-06-12 10:27 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-05-30 09:43 - 2014-06-12 10:27 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-05-30 09:40 - 2014-06-12 10:27 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-05-30 09:30 - 2014-06-12 10:27 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-05-30 09:21 - 2014-06-12 10:27 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-05-30 09:15 - 2014-06-12 10:27 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-05-30 09:13 - 2014-06-12 10:27 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-05-30 09:13 - 2014-06-12 10:27 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-05-29 16:46 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache 2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-05-26 16:37 - 2013-02-17 16:31 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Windows Live Some content of TEMP: ==================== C:\Users\Philipp\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-05-29 16:39 ==================== End Of Log ============================
__________________ Viele Grüße hypercraft just take the coffee smiley |
18.06.2014, 11:23 | #6 |
/// the machine /// TB-Ausbilder | Malwarebytes erkennt SpeedAnalysis.com als potenzielle BedrohungESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung |
18.06.2014, 23:29 | #7 |
| Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung was mach ich mit den Funden von ESET? Entfernen lassen? hier das Log: Code:
ATTFilter C:\AdwCleaner\Quarantine\C\Users\Philipp\AppData\Local\cre\oolkekjjhnaeaahibbnfebmogackofpf.crx.vir Variante von Win32/Toolbar.Conduit.AH evtl. unerwünschte Anwendung C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\Ask\AskPIP_FF_.exe Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst.exe Variante von Win32/Hao123.A evtl. unerwünschte Anwendung C:\Program Files (x86)\Mozilla Firefox\components\sprotector.js Win32/Conduit.SearchProtect.A evtl. unerwünschte Anwendung C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe Variante von Win32/Hao123.A evtl. unerwünschte Anwendung C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung
__________________ Viele Grüße hypercraft just take the coffee smiley |
19.06.2014, 20:38 | #8 |
/// the machine /// TB-Ausbilder | Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung Entfernen lassen, MBAM quarantäne kanste leeren, dann den Rest von oben.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.06.2014, 23:05 | #9 |
| Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung hi, FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-06-2014 Ran by Philipp (administrator) on PHILIPPS-PC on 19-06-2014 23:34:51 Running from C:\Users\Philipp\Desktop\Virensuche Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Windows\System32\igfxext.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\POWERPNT.EXE (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916112 2012-04-08] (Synaptics Incorporated) HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation) HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation) HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-01-31] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Philipp\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Philipp\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-23] Chrome: ======= CHR HomePage: CHR Extension: (Adblock Plus) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-26] CHR Extension: (Adblock Advisor) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplojogpbcbnjoemcalepfmbcpnkpjjo [2014-04-26] CHR Extension: (Google Wallet) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-09] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2279608 2014-05-21] (Microsoft Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-04-18] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [164184 2012-04-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [99616 2014-03-05] (Overwolf LTD) R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76888 2014-06-04] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed] R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed] R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-03-09] (Atheros) ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [32896 2012-03-19] (Advanced Micro Devices, Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation) R2 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [91352 2014-05-12] (Malwarebytes Corporation) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-19] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-19 23:11 - 2014-06-19 23:11 - 00003224 _____ () C:\windows\System32\Tasks\{C30FB847-060E-4DA6-B676-154FC9D4A79F} 2014-06-19 23:06 - 2014-06-19 23:11 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\GlarySoft 2014-06-19 23:06 - 2014-06-19 23:06 - 00001070 _____ () C:\Users\Philipp\Desktop\Absolute Uninstaller.lnk 2014-06-19 23:05 - 2014-06-19 23:05 - 02194784 _____ (Glarysoft.com ) C:\Users\Philipp\Downloads\au29setup.exe 2014-06-19 19:09 - 2014-06-19 19:09 - 00000165 ____H () C:\Users\Philipp\Desktop\~$Die Entdeckung Amerikas.pptx 2014-06-19 00:20 - 2014-06-19 00:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-18 18:52 - 2014-06-18 18:52 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe 2014-06-17 20:23 - 2014-06-17 20:23 - 01016261 _____ (Thisisu) C:\Users\Philipp\Downloads\JRT.exe 2014-06-17 20:14 - 2014-06-19 19:08 - 01156526 _____ () C:\Users\Philipp\Desktop\Die Entdeckung Amerikas.pptx 2014-06-17 16:53 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll 2014-06-17 16:49 - 2014-06-17 16:49 - 01333465 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.212.exe 2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 __SHD () C:\ProgramData\DSS 2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 ____D () C:\Users\Philipp\Documents\FIFA 14 DEMO 2014-06-16 11:47 - 2014-06-16 11:47 - 00000378 _____ () C:\Users\Philipp\Downloads\text-2.txt 2014-06-16 11:20 - 2014-06-19 23:34 - 00000000 ____D () C:\Users\Philipp\Desktop\Virensuche 2014-06-16 11:14 - 2014-06-16 11:14 - 00042738 _____ () C:\Users\Philipp\Downloads\Addition.txt 2014-06-16 11:13 - 2014-06-16 11:14 - 00048826 _____ () C:\Users\Philipp\Downloads\FRST.txt 2014-06-16 11:12 - 2014-06-19 23:34 - 00000000 ____D () C:\FRST 2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg 2014-06-12 10:27 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-06-12 10:27 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-06-12 10:27 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-06-12 10:27 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-06-12 10:27 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-06-12 10:27 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-06-12 10:27 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-06-12 10:27 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-06-12 10:27 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-06-12 10:27 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-06-12 10:27 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-06-12 10:27 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-06-12 10:27 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-06-12 10:27 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-06-12 10:27 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-06-12 10:27 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-06-12 10:27 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-06-12 10:27 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-06-12 10:27 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-06-12 10:27 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-06-12 10:27 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-06-12 10:27 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-06-12 10:27 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-06-12 10:27 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-06-12 10:27 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-06-12 10:27 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-06-12 10:27 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-06-12 10:27 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-06-12 10:27 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-06-12 10:27 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-06-12 10:27 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-06-12 10:27 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-06-12 10:27 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-06-12 10:27 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-06-12 10:27 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-06-12 10:27 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-06-12 10:27 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-12 10:27 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-06-12 10:27 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-06-12 10:27 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-06-12 10:27 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-06-12 10:27 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-06-12 10:27 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-06-12 10:27 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-06-12 10:27 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-06-12 10:27 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-06-12 10:27 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-06-12 10:27 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-06-12 10:27 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-06-12 10:27 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-06-12 10:27 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-06-12 10:27 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-06-12 10:27 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll 2014-06-12 10:27 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll 2014-06-12 10:27 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll 2014-06-12 10:27 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll 2014-06-12 10:27 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2014-06-12 10:27 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-06-12 10:27 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll 2014-06-12 10:27 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll 2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll 2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll 2014-06-12 10:27 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll 2014-06-12 10:27 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll 2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll 2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll 2014-06-12 10:25 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-06-12 10:25 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig 2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2014-06-06 15:21 - 2014-06-06 15:22 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe 2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR 2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR 2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe 2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory 2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk 2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2014-06-06 13:53 - 2014-06-06 13:55 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe 2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt 2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822 2014-06-03 17:24 - 2014-06-03 17:25 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp 2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP 2014-06-03 15:50 - 2014-06-19 18:25 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core 2014-06-02 18:50 - 2014-06-19 18:25 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe 2014-06-02 18:50 - 2014-06-19 18:25 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0 2014-06-02 18:50 - 2014-06-04 20:29 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe 2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk 2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3 2014-06-01 20:39 - 2014-06-15 20:59 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2014-06-01 20:37 - 2014-06-03 18:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin 2014-06-01 20:37 - 2014-06-03 15:45 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin 2014-06-01 20:34 - 2014-06-19 13:19 - 00000000 ____D () C:\ProgramData\Origin 2014-06-01 20:34 - 2014-06-19 13:19 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-06-01 20:34 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk 2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D} 2014-05-31 18:01 - 2014-06-04 20:21 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab 2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-31 16:21 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2014-05-31 16:21 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2014-05-31 16:21 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2014-05-31 16:21 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2014-05-31 16:20 - 2014-05-31 16:21 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log 2014-05-27 16:39 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll 2014-05-27 16:39 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2014-05-26 20:01 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys 2014-05-26 20:01 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-05-26 20:01 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-05-26 20:01 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll 2014-05-26 20:01 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll 2014-05-26 20:01 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll 2014-05-26 20:01 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll 2014-05-26 20:01 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll 2014-05-26 20:01 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll 2014-05-26 20:01 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll 2014-05-26 20:01 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe 2014-05-26 20:01 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe 2014-05-26 20:01 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll 2014-05-26 20:01 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe 2014-05-26 20:01 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll 2014-05-26 20:01 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe 2014-05-26 20:00 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll 2014-05-26 20:00 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll 2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-05-23 14:31 - 2014-06-17 20:19 - 00016238 _____ () C:\windows\PFRO.log ==================== One Month Modified Files and Folders ======= 2014-06-19 23:34 - 2014-06-16 11:20 - 00000000 ____D () C:\Users\Philipp\Desktop\Virensuche 2014-06-19 23:34 - 2014-06-16 11:12 - 00000000 ____D () C:\FRST 2014-06-19 23:11 - 2014-06-19 23:11 - 00003224 _____ () C:\windows\System32\Tasks\{C30FB847-060E-4DA6-B676-154FC9D4A79F} 2014-06-19 23:11 - 2014-06-19 23:06 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\GlarySoft 2014-06-19 23:06 - 2014-06-19 23:06 - 00001070 _____ () C:\Users\Philipp\Desktop\Absolute Uninstaller.lnk 2014-06-19 23:06 - 2013-01-14 18:13 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-06-19 23:05 - 2014-06-19 23:05 - 02194784 _____ (Glarysoft.com ) C:\Users\Philipp\Downloads\au29setup.exe 2014-06-19 23:01 - 2013-04-23 19:22 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-19 22:49 - 2013-04-02 20:58 - 00001128 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000UA.job 2014-06-19 22:39 - 2014-04-11 17:40 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-19 21:31 - 2012-05-25 22:31 - 00700134 _____ () C:\windows\system32\perfh007.dat 2014-06-19 21:31 - 2012-05-25 22:31 - 00149984 _____ () C:\windows\system32\perfc007.dat 2014-06-19 21:31 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI 2014-06-19 21:28 - 2013-07-14 23:17 - 01758705 _____ () C:\windows\WindowsUpdate.log 2014-06-19 19:09 - 2014-06-19 19:09 - 00000165 ____H () C:\Users\Philipp\Desktop\~$Die Entdeckung Amerikas.pptx 2014-06-19 19:09 - 2012-05-25 07:00 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-06-19 19:08 - 2014-06-17 20:14 - 01156526 _____ () C:\Users\Philipp\Desktop\Die Entdeckung Amerikas.pptx 2014-06-19 18:25 - 2014-06-03 15:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr 2014-06-19 18:25 - 2014-06-02 18:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe 2014-06-19 18:25 - 2014-06-02 18:50 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0 2014-06-19 15:49 - 2013-04-02 20:58 - 00001076 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000Core.job 2014-06-19 13:19 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Origin 2014-06-19 13:19 - 2014-06-01 20:34 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-06-19 11:56 - 2013-04-23 19:22 - 00004108 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-19 11:56 - 2013-04-23 19:22 - 00003858 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-19 11:56 - 2013-04-23 19:22 - 00001108 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-19 00:20 - 2014-06-19 00:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-18 18:52 - 2014-06-18 18:52 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe 2014-06-18 12:06 - 2013-08-16 21:15 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\.minecraft 2014-06-18 11:28 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-18 11:28 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-18 11:19 - 2014-04-27 12:29 - 00005264 _____ () C:\windows\setupact.log 2014-06-18 11:19 - 2012-05-25 07:00 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-06-18 11:19 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-06-17 22:37 - 2012-11-03 14:49 - 00016896 ___SH () C:\Users\Philipp\Documents\Thumbs.db 2014-06-17 20:23 - 2014-06-17 20:23 - 01016261 _____ (Thisisu) C:\Users\Philipp\Downloads\JRT.exe 2014-06-17 20:19 - 2014-05-23 14:31 - 00016238 _____ () C:\windows\PFRO.log 2014-06-17 20:18 - 2013-09-28 12:06 - 00000000 ____D () C:\AdwCleaner 2014-06-17 16:49 - 2014-06-17 16:49 - 01333465 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.212.exe 2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 __SHD () C:\ProgramData\DSS 2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 ____D () C:\Users\Philipp\Documents\FIFA 14 DEMO 2014-06-16 11:50 - 2013-03-04 22:23 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-06-16 11:49 - 2014-04-27 15:59 - 00037483 _____ () C:\windows\DirectX.log 2014-06-16 11:49 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-16 11:47 - 2014-06-16 11:47 - 00000378 _____ () C:\Users\Philipp\Downloads\text-2.txt 2014-06-16 11:14 - 2014-06-16 11:14 - 00042738 _____ () C:\Users\Philipp\Downloads\Addition.txt 2014-06-16 11:14 - 2014-06-16 11:13 - 00048826 _____ () C:\Users\Philipp\Downloads\FRST.txt 2014-06-15 21:07 - 2013-04-02 21:01 - 00002373 _____ () C:\Users\Philipp\Desktop\Google Chrome.lnk 2014-06-15 20:59 - 2014-06-01 20:39 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2014-06-15 19:20 - 2012-05-25 06:56 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg 2014-06-15 18:00 - 2012-11-11 16:51 - 00000000 ____D () C:\Users\Philipp\AppData\Local\CrashDumps 2014-06-14 10:25 - 2013-07-15 14:17 - 00000000 ____D () C:\windows\system32\MRT 2014-06-14 10:23 - 2012-10-20 21:21 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-06-14 10:20 - 2014-05-06 22:19 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-06-08 11:13 - 2014-06-12 10:25 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-06-08 11:08 - 2014-06-12 10:25 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner 2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig 2014-06-06 20:14 - 2012-10-21 19:17 - 00000000 ____D () C:\Users\Philipp 2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2014-06-06 15:22 - 2014-06-06 15:21 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe 2014-06-06 15:17 - 2013-05-27 22:46 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\vlc 2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR 2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR 2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe 2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory 2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk 2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2014-06-06 13:56 - 2013-05-18 14:55 - 00000000 ____D () C:\Program Files (x86)\FreeTime 2014-06-06 13:55 - 2014-06-06 13:53 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe 2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt 2014-06-04 20:29 - 2014-06-02 18:50 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe 2014-06-04 20:21 - 2014-05-31 18:01 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp 2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822 2014-06-03 18:37 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin 2014-06-03 17:25 - 2014-06-03 17:24 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp 2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP 2014-06-03 17:24 - 2012-11-22 15:12 - 00000000 ____D () C:\windows\Minidump 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3 2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN 2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core 2014-06-03 15:45 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin 2014-06-03 15:45 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk 2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3 2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk 2014-06-01 15:10 - 2012-11-25 17:18 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-06-01 00:32 - 2013-06-21 23:54 - 00007597 _____ () C:\Users\Philipp\AppData\Local\Resmon.ResmonCfg 2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D} 2014-05-31 17:55 - 2012-10-21 12:31 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\SoftGrid Client 2014-05-31 17:29 - 2014-03-27 23:55 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\TS3Client 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab 2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab 2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-31 16:21 - 2014-05-31 16:20 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log 2014-05-31 16:21 - 2013-10-16 23:29 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-31 16:21 - 2013-06-23 18:37 - 00000000 ____D () C:\Program Files (x86)\Java 2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-30 22:12 - 2013-03-02 20:49 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-30 12:21 - 2014-06-12 10:27 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-05-30 12:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-05-30 12:02 - 2014-06-12 10:27 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-05-30 11:45 - 2014-06-12 10:27 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-05-30 11:39 - 2014-06-12 10:27 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-05-30 11:39 - 2014-06-12 10:27 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-05-30 11:38 - 2014-06-12 10:27 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-05-30 11:28 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-05-30 11:27 - 2014-06-12 10:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-05-30 11:24 - 2014-06-12 10:27 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-05-30 11:21 - 2014-06-12 10:27 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-05-30 11:21 - 2014-06-12 10:27 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-05-30 11:20 - 2014-06-12 10:27 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-05-30 11:18 - 2014-06-12 10:27 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-05-30 11:11 - 2014-06-12 10:27 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-05-30 11:08 - 2014-06-12 10:27 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-05-30 11:06 - 2014-06-12 10:27 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-05-30 11:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-05-30 10:55 - 2014-06-12 10:27 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-05-30 10:49 - 2014-06-12 10:27 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-05-30 10:46 - 2014-06-12 10:27 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-05-30 10:44 - 2014-06-12 10:27 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-05-30 10:44 - 2014-06-12 10:27 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-05-30 10:43 - 2014-06-12 10:27 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-05-30 10:42 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-05-30 10:38 - 2014-06-12 10:27 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-05-30 10:35 - 2014-06-12 10:27 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-05-30 10:34 - 2014-06-12 10:27 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-05-30 10:33 - 2014-06-12 10:27 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-05-30 10:30 - 2014-06-12 10:27 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-05-30 10:29 - 2014-06-12 10:27 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-05-30 10:28 - 2014-06-12 10:27 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-05-30 10:27 - 2014-06-12 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-05-30 10:24 - 2014-06-12 10:27 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-05-30 10:23 - 2014-06-12 10:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-05-30 10:16 - 2014-06-12 10:27 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-05-30 10:10 - 2014-06-12 10:27 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-05-30 10:06 - 2014-06-12 10:27 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-05-30 10:04 - 2014-06-12 10:27 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-05-30 10:02 - 2014-06-12 10:27 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-05-30 09:56 - 2014-06-12 10:27 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-05-30 09:56 - 2014-06-12 10:27 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-05-30 09:54 - 2014-06-12 10:27 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-05-30 09:50 - 2014-06-12 10:27 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-05-30 09:49 - 2014-06-12 10:27 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-05-30 09:43 - 2014-06-12 10:27 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-05-30 09:40 - 2014-06-12 10:27 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-05-30 09:30 - 2014-06-12 10:27 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-05-30 09:21 - 2014-06-12 10:27 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-05-30 09:15 - 2014-06-12 10:27 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-05-30 09:13 - 2014-06-12 10:27 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-05-30 09:13 - 2014-06-12 10:27 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-05-29 16:46 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache 2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod 2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-05-26 16:37 - 2013-02-17 16:31 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Windows Live Some content of TEMP: ==================== C:\Users\Philipp\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-05-29 16:39 ==================== End Of Log ============================ Code:
ATTFilter Results of screen317's Security Check version 0.99.83 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` AVG PC TuneUp 2014 (de-DE) Java 7 Update 60 Java version out of Date! Adobe Flash Player 13.0.0.214 Adobe Reader XI Mozilla Firefox (30.0) Google Chrome 35.0.1916.114 Google Chrome 35.0.1916.153 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
__________________ Viele Grüße hypercraft just take the coffee smiley |
20.06.2014, 19:59 | #10 |
/// the machine /// TB-Ausbilder | Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung Java updaten. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung |
ahnung, appdata, conduit.search, conduit.search entfernen, datenbank, datum, detected, erkennt, löschen, malwarebytes, mbam, mozilla, pup.optional.speedanalysis.a, quarantäne, roaming, webseite, webseiten, win32/bundled.toolbar.ask.d, win32/conduit.searchprotect.a, win32/downloadsponsor.a, win32/hao123.a, win32/toolbar.conduit.ah, windows 7 |