|
Log-Analyse und Auswertung: GS Supporter 1.80 auf dem RechnerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
24.06.2014, 22:49 | #1 |
| GS Supporter 1.80 auf dem Rechner Hallo zusammen Ich habe mir bei der Installation eines Spieles welches ich aus dem Netz gezogen habe irgend etwas eingefangen. Nachdem ich unter Installierte Programme "GS Supporter 1.80" gesehen habe und mal danach gesucht habe bin ich hier im Forum darauf gestossen. Ich vermute ich hab mir einen Trojaner und noch mehr eingefangen. Mein PC is seit her extrem langsam beim aufstarten und auch sonst ist die Leistung gehemmt. Ausserdem hat mein Antivirenscanner das gefunden: Habe bereits mal follgende Log Files erstellt. Hoffe ihr könnt mir weiter helfen. Danke Habe die Scanns als txt files angehängt. |
25.06.2014, 08:10 | #2 |
| GS Supporter 1.80 auf dem Rechner Nachdem der Virenscanner durchgelaufen is hat er noch mehr gefunden:
__________________ |
25.06.2014, 08:13 | #3 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | GS Supporter 1.80 auf dem Rechner Hi und
__________________Zitat:
Außerdem: Logs bitte nicht anhängen, notfalls splitten und über mehrere Postings verteilt posten Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
25.06.2014, 08:36 | #4 |
| GS Supporter 1.80 auf dem Rechner Also ich wollte mir Star Wars Galaxies herunterladen, um SWG Emu zu zocken. Hab einige Torrentlinks aus dem Forum benuzt welche andere Spieler angegeben haben. Aber das ging in die Hose wie ich nu weiss. Eigentlich wüsste ich es ja besser. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2014 Ran by Maeph (administrator) on MAEPH-HP on 24-06-2014 23:34:08 Running from C:\Users\Maeph\Downloads Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\ccSvcHst.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\ccSvcHst.exe (DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe () C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe () C:\Users\Maeph\AppData\Roaming\InetStat\inetstat.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe (Curse) C:\Users\Maeph\AppData\Local\Apps\2.0\XYGL4YPM.90D\BE1XBXN0.GVC\curs..tion_9e9e83ddf3ed3ead_0005.0001_36a9b6290e21932c\CurseClient.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Bose Corporation) C:\Program Files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch music server.exe () C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe (Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe (Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.4710\Battle.net.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MfeEpePcMonitor] => C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [200704 2011-07-13] () HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1179576 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.) HKLM-x32\...\Run: [HP KEYBOARDx] => C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE [710656 2010-02-11] (Hewlett-Packard) HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-05-06] (PDF Complete Inc) HKLM-x32\...\Run: [File Sanitizer] => c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [12277248 2011-05-10] (Hewlett-Packard) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1935824 2014-05-16] (APN) HKLM-x32\...\Run: [SoundTouch Music Server] => C:\Program Files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch music server.exe [1062912 2014-04-09] (Bose Corporation) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [183376 2014-05-14] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-06-17] (Avira Operations GmbH & Co. KG) HKLM\...\RunOnce: [NCPluginUpdater] - "c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\NCPluginUpdater.exe" Update [21720 2014-06-24] (Hewlett-Packard) HKLM-x32\...\Runonce: [removeSettingsManagerdatamngr] - cmd.exe /c RD /S /Q "C:\Program Files (x86)\Settings Manager" [X] HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe, Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X] HKU\S-1-5-21-1490942193-3814011691-1127731215-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [15146376 2011-04-18] (Skype Technologies S.A.) HKU\S-1-5-21-1490942193-3814011691-1127731215-1002\...\Run: [InetStat] => C:\Users\Maeph\AppData\Roaming\InetStat\inetstat.exe [659470 2014-06-21] () HKU\S-1-5-21-1490942193-3814011691-1127731215-1002\...\MountPoints2: {581af640-beb9-11e3-a68b-806e6f6e6963} - E:\Setup.exe AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe Lsa: [Notification Packages] EpePcNp64 DPPassFilter scecli Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Maeph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.v9.com/web/?type=ds&ts=1403380256&from=irs&uid=HitachiXHDS721010CLA632_JP2940J833BZ5V33BZ5VX&i=psd&t=3447ad542&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.v9.com/web/?type=ds&ts=1403380256&from=irs&uid=HitachiXHDS721010CLA632_JP2940J833BZ5V33BZ5VX&i=psd&t=3447ad542&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.v9.com/web/?type=ds&ts=1403380256&from=irs&uid=HitachiXHDS721010CLA632_JP2940J833BZ5V33BZ5VX&i=psd&t=3447ad542&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.v9.com/web/?type=ds&ts=1403380256&from=irs&uid=HitachiXHDS721010CLA632_JP2940J833BZ5V33BZ5VX&i=psd&t=3447ad542&q={searchTerms} SearchScopes: HKLM - {093564D6-DF51-499E-B193-C5E166FE482A} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMDTDF SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=146&itype=n&ver=13001&tm=385&src=ds&p={searchTerms} SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ch.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMDTDF SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5222-111091-7834-8/4?satitle={searchTerms} SearchScopes: HKLM-x32 - {093564D6-DF51-499E-B193-C5E166FE482A} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMDTDF SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=146&itype=n&ver=13001&tm=385&src=ds&p={searchTerms} SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ch.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMDTDF SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5222-111091-7834-8/4?satitle={searchTerms} SearchScopes: HKCU - {093564D6-DF51-499E-B193-C5E166FE482A} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMDTDF SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=146&itype=n&ver=13001&tm=385&src=ds&p={searchTerms} SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ch.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMDTDF SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5222-111091-7834-8/4?satitle={searchTerms} BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.192.1 FireFox: ======== FF ProfilePath: C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default FF SearchEngineOrder.1: default-search.net FF Keyword.URL: hxxp://www.default-search.net/search?sid=476&aid=146&itype=n&ver=13001&tm=385&src=ds&p= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF SearchPlugin: C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\searchplugins\ask-search.xml FF SearchPlugin: C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\searchplugins\default-search.xml FF SearchPlugin: C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ask Toolbar - C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-03-26] FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt FF Extension: DigitalPersona Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2011-11-24] FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFFPlgn FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFFPlgn [2014-04-07] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn [2014-04-07] FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] FF HKCU\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\extensions\cliqz@cliqz.com Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (CostMin) - C:\Users\Maeph\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk [2014-06-21] CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\Extensions\Chrome.crx [2011-11-24] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-05-16] (APN LLC.) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [123984 2014-05-14] (Avira Operations GmbH & Co. KG) R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [485712 2011-05-19] (DigitalPersona, Inc.) S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [464440 2011-05-10] (Hewlett-Packard Company) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] R2 HPAuto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [682040 2011-02-17] (Hewlett-Packard) R2 HPFSService; c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [320512 2011-05-10] (Hewlett-Packard) [File not signed] R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED) R2 McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [1318912 2011-07-13] () [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\ccSvcHst.exe [138760 2011-05-25] (Symantec Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation) R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-06] (PDF Complete Inc) S2 be0fb33b; "C:\Windows\system32\rundll32.exe" "c:\progra~2\suppor~1\SupporterSvc.dll",service ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-06-17] (Avira Operations GmbH & Co. KG) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20110519.002\BHDrvx64.sys [1143416 2011-05-13] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1300000.080\ccSetx64.sys [165512 2011-05-23] (Symantec Corporation) S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [64312 2011-05-10] (Hewlett-Packard Company) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20110519.031\IDSVia64.sys [488056 2011-05-13] (Symantec Corporation) R0 MfeEpeOpal; C:\Windows\System32\Drivers\MfeEpeOpal.sys [91080 2011-07-13] (McAfee, Inc.) R0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [158280 2011-07-13] (McAfee, Inc.) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20110607.003\ENG64.SYS [117880 2011-06-07] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20110607.003\EX64.SYS [2011768 2011-06-07] (Symantec Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) S3 OxPPort; C:\Windows\system32\drivers\OxPPort.sys [98304 2008-07-31] (OEM) S3 OxSer; C:\Windows\system32\drivers\OxSer.sys [98352 2009-09-16] (OEM) S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2011-11-24] () S3 SRTSP; C:\Windows\system32\drivers\NISx64\1300000.080\SRTSP64.SYS [721528 2011-05-21] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1300000.080\SRTSPX64.SYS [37496 2011-05-21] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1300000.080\SYMDS64.SYS [451192 2011-05-16] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1300000.080\SYMEFA64.SYS [1083512 2011-05-16] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2011-11-24] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1300000.080\Ironx64.SYS [189560 2011-05-16] (Symantec Corporation) R1 SymNetS; C:\Windows\system32\drivers\NISx64\1300000.080\SYMNETS.SYS [396408 2011-05-09] (Symantec Corporation) R4 F06DEFF2-5B9C-490D-910F-35D3A9119622; \??\C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc2.cfg [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-24 23:34 - 2014-06-24 23:35 - 00025158 _____ () C:\Users\Maeph\Downloads\FRST.txt 2014-06-24 23:34 - 2014-06-24 23:34 - 00000000 ____D () C:\FRST 2014-06-24 23:33 - 2014-06-24 23:33 - 02082816 _____ (Farbar) C:\Users\Maeph\Downloads\FRST64.exe 2014-06-24 23:24 - 2014-06-24 23:24 - 00003150 _____ () C:\Windows\System32\Tasks\{9906AFC3-9716-45DC-93A7-E5EA5CE49D38} 2014-06-24 23:13 - 2014-06-24 23:16 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-06-24 23:12 - 2014-06-24 23:12 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Avira 2014-06-24 23:11 - 2014-06-17 16:25 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-24 23:11 - 2014-06-17 16:25 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-06-24 23:11 - 2014-06-17 16:25 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-06-24 23:10 - 2014-06-24 23:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-06-24 23:10 - 2014-06-24 23:11 - 00000000 ____D () C:\ProgramData\Avira 2014-06-24 23:10 - 2014-06-24 23:11 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-06-24 23:10 - 2014-06-24 23:10 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Maeph\Downloads\avira_de_av___ws.exe 2014-06-24 23:10 - 2014-06-24 23:10 - 00001099 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-06-21 22:30 - 2014-06-21 22:30 - 00001507 _____ () C:\Users\Maeph\Desktop\AgeOfConan - Verknüpfung.lnk 2014-06-21 21:55 - 2014-06-21 21:55 - 00024210 _____ () C:\Users\Maeph\Downloads\D2A590AAAA1D0539E1913CBA05228D02CC11ADFD.torrent 2014-06-21 21:53 - 2014-06-24 23:21 - 00000000 ____D () C:\ProgramData\CostMin 2014-06-21 21:53 - 2014-06-24 23:21 - 00000000 ____D () C:\ProgramData\527dd4c7744378ff 2014-06-21 21:53 - 2014-06-24 23:21 - 00000000 ____D () C:\Program Files (x86)\CostMin 2014-06-21 21:53 - 2014-06-21 21:53 - 00000442 __RSH () C:\ProgramData\ntuser.pol 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Torch 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Packages 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Chromatic Browser 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Torch 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Chromatic Browser 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator 2014-06-21 21:52 - 2014-06-21 21:52 - 02044896 _____ () C:\Users\Maeph\Downloads\Star_Wars_Galaxies__Pre_CU_(including_Patches_00-13).exe 2014-06-21 21:51 - 2014-06-24 23:23 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-06-21 21:51 - 2014-06-21 21:51 - 00000000 ____D () C:\ProgramData\IePluginServices 2014-06-21 21:50 - 2014-06-24 23:15 - 00000000 ____D () C:\Program Files (x86)\Supporter 2014-06-21 21:50 - 2014-06-24 23:07 - 00003476 _____ () C:\Windows\System32\Tasks\GPUpdateCheck 2014-06-21 21:50 - 2014-06-21 21:50 - 00003218 _____ () C:\Windows\System32\Tasks\GPUpdate 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\smi 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\InetStat 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\GetPrivate 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Program Files (x86)\GetPrivate 2014-06-21 21:48 - 2014-06-21 21:48 - 02044896 _____ () C:\Users\Maeph\Downloads\SWG_Pre-CU.exe 2014-06-21 21:46 - 2014-06-21 21:46 - 00003118 _____ () C:\Windows\System32\Tasks\{FFC2A938-BEC4-4947-B5D2-A2FA289E2E4F} 2014-06-21 21:42 - 2014-06-21 21:42 - 39833841 _____ (SWGEmu) C:\Users\Maeph\Downloads\setup(1).exe 2014-06-21 21:42 - 2014-06-21 21:42 - 00002777 _____ () C:\Users\Public\Desktop\SWGEmu Launchpad.lnk 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Downloaded Installations 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SWGEmu 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\Program Files (x86)\SWGEmu 2014-06-21 21:41 - 2014-06-24 23:23 - 00000000 ____D () C:\Users\Maeph\AppData\Local\CrashDumps 2014-06-21 21:41 - 2014-06-24 23:17 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Linkey 2014-06-21 21:40 - 2014-06-24 23:09 - 00000000 ____D () C:\ProgramData\BOINC 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Windows\Downloaded Installations 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Settings Manager 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Program Files (x86)\Sony 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Program Files (x86)\Settings Manager 2014-06-21 21:35 - 2014-06-21 21:35 - 00357776 _____ (Softonic) C:\Users\Maeph\Downloads\SoftonicDownloader_fuer_star-wars-galaxies-an-empire-divided.exe 2014-06-21 20:47 - 2014-06-21 20:47 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\BEGAware 2014-06-21 15:46 - 2014-06-21 15:49 - 04389376 _____ (BEGAware) C:\Users\Maeph\Desktop\PicturePuzzle.exe 2014-06-21 13:28 - 2014-06-21 13:28 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Funcom 2014-06-21 13:27 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-06-21 13:27 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-06-21 13:27 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-06-21 13:27 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-06-21 13:27 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-06-21 13:27 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-06-21 13:27 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-06-21 13:27 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2014-06-21 13:27 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-06-21 13:27 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-06-21 13:27 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-06-21 13:27 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-06-21 13:27 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-06-21 13:27 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2014-06-21 13:27 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-06-21 13:27 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2014-06-21 13:27 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2014-06-21 13:27 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-06-21 13:27 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2014-06-21 13:27 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-06-21 13:27 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2014-06-21 13:27 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-06-21 13:27 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-06-21 13:27 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-06-21 13:27 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-06-21 13:27 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-06-21 13:27 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-06-21 13:27 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-06-21 13:27 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-06-21 13:27 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-06-21 13:27 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-06-21 13:27 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-06-21 13:27 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-06-21 13:27 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-06-21 13:27 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-06-21 13:27 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-06-21 13:27 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-06-21 13:27 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-06-21 13:27 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-06-21 13:27 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-06-21 13:27 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-06-21 13:27 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-06-21 13:27 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-06-21 13:27 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-06-21 13:27 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-06-21 13:27 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-06-21 13:27 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-06-21 13:27 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-06-21 13:27 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-06-21 13:27 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-06-21 13:27 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-06-21 13:27 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-06-21 13:27 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-06-21 13:27 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-06-21 13:27 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-06-21 13:27 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-06-21 13:27 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-06-21 13:27 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-06-21 13:27 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-06-21 13:27 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2014-06-21 13:27 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-06-21 13:27 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-06-21 13:27 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-06-21 13:27 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-06-21 13:27 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-06-21 13:27 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-06-21 13:27 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-06-21 13:27 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-06-21 13:27 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-06-21 13:27 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-06-21 13:27 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-06-21 13:27 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-06-21 13:27 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-06-21 13:27 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-06-21 13:26 - 2014-06-21 13:27 - 00010009 _____ () C:\Windows\DirectX.log 2014-06-21 13:26 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-06-21 13:26 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-06-21 13:26 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-06-21 13:26 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2014-06-21 13:26 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-06-21 13:26 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-06-21 13:26 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-06-21 13:26 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-06-21 13:26 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-06-21 13:26 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-06-21 13:26 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2014-06-21 13:26 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-06-21 13:26 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-06-21 13:26 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2014-06-21 13:26 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-06-21 13:26 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2014-06-21 13:26 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-06-21 13:26 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2014-06-21 13:26 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-06-21 13:26 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2014-06-21 13:26 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-06-21 13:26 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2014-06-21 13:26 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-06-21 13:26 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2014-06-21 13:26 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-06-21 13:26 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2014-06-21 13:26 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-06-21 13:26 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2014-06-21 13:26 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-06-21 13:26 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2014-06-21 13:26 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-06-21 13:26 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2014-06-21 13:26 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-06-21 13:26 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2014-06-21 13:25 - 2014-06-21 13:27 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-06-21 13:25 - 2014-06-21 13:26 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-06-21 13:25 - 2014-06-21 13:25 - 20858106 _____ (Funcom ) C:\Users\Maeph\Downloads\ageofconan-de.exe 2014-06-21 13:25 - 2014-06-21 13:25 - 00000000 ____D () C:\Program Files (x86)\Funcom 2014-06-21 11:14 - 2014-06-21 11:14 - 14994368 _____ () C:\Users\Maeph\Downloads\Setup_Railroad_Tycoon.exe 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\2K Games 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Games 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\Program Files (x86)\2K Games 2014-06-20 14:21 - 2014-06-21 11:14 - 01058200 _____ (Adobe) C:\Users\Maeph\Downloads\install_flashplayer14x32au_ltr5x64d_awc_aih.exe 2014-06-16 10:51 - 2014-06-16 11:26 - 00042302 _____ () C:\Users\Maeph\Desktop\Lebenslauf Vorlage.odt 2014-06-16 10:48 - 2014-06-16 10:48 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.0.lnk 2014-06-16 10:48 - 2014-06-16 10:48 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0 2014-06-16 10:48 - 2014-06-16 10:48 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\OpenOffice 2014-06-16 10:47 - 2014-06-16 10:47 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-06-16 10:46 - 2014-06-16 10:46 - 00000000 ____D () C:\Users\Maeph\Desktop\OpenOffice 4.1.0 (de) Installation Files 2014-06-16 10:44 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll 2014-06-16 10:44 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll 2014-06-16 10:43 - 2014-06-16 10:43 - 00961360 _____ (Chip Digital GmbH) C:\Users\Maeph\Downloads\OpenOffice - CHIP-Installer.exe 2014-06-10 22:44 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-10 22:44 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-10 22:44 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-10 22:44 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-10 22:44 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-10 22:44 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-10 22:44 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-10 22:44 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-10 22:44 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-10 22:44 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-10 22:44 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-10 22:44 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-10 22:44 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-10 22:44 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-10 22:44 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-10 22:44 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-10 22:44 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-10 22:44 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-10 22:44 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-10 22:44 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-10 22:44 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-10 22:44 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-06-10 22:44 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-10 22:44 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-10 22:44 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-06-10 22:44 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-10 22:44 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-10 22:44 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-10 22:44 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-10 22:44 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-06-10 22:44 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-10 22:44 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-06-10 22:44 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-06-10 22:44 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-10 22:44 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-10 22:44 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-10 22:44 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-10 22:44 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-10 22:44 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-10 22:44 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-10 22:44 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-10 22:44 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-10 22:44 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-10 22:44 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-06-10 22:44 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-10 22:44 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-10 22:44 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-10 22:44 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-10 22:44 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-10 22:44 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-10 22:44 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-10 22:44 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-06-10 22:44 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-10 22:44 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-10 22:44 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-10 22:44 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2014-06-10 22:44 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-10 22:44 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-10 22:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2014-06-10 22:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-06-10 22:44 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-10 22:44 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-10 22:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2014-06-10 22:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-06-10 22:42 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-10 22:42 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-04 08:33 - 2014-06-04 08:43 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\SoundTouchPersist 2014-06-04 08:33 - 2014-06-04 08:33 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\SoundTouch 2014-06-04 08:32 - 2014-06-04 08:33 - 00000000 ____D () C:\Program Files (x86)\SoundTouch 2014-06-04 08:32 - 2014-06-04 08:32 - 00001911 _____ () C:\Users\Public\Desktop\SoundTouch.lnk 2014-06-04 08:32 - 2014-06-04 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundTouch 2014-06-04 08:31 - 2014-06-04 08:32 - 50130944 _____ () C:\Users\Maeph\Downloads\SoundTouch-app-installer-5.0.21.6712.msi 2014-06-02 22:21 - 2014-06-02 22:21 - 00001333 _____ () C:\Users\Maeph\Desktop\6b94eeecf0a3a536c6e0a362a2d954cd13789e37d54a4b2f6f25561ed90d6629836d56c143dae7bde29b3e4952886629d810ed806388959351b0ac47d9bc652e.htm 2014-06-02 00:43 - 2014-06-02 00:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2014-06-02 00:43 - 2014-06-02 00:43 - 00000000 ____D () C:\Program Files\McAfee Security Scan ==================== One Month Modified Files and Folders ======= 2014-06-24 23:35 - 2014-06-24 23:34 - 00025158 _____ () C:\Users\Maeph\Downloads\FRST.txt 2014-06-24 23:34 - 2014-06-24 23:34 - 00000000 ____D () C:\FRST 2014-06-24 23:34 - 2014-04-07 17:17 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Battle.net 2014-06-24 23:33 - 2014-06-24 23:33 - 02082816 _____ (Farbar) C:\Users\Maeph\Downloads\FRST64.exe 2014-06-24 23:24 - 2014-06-24 23:24 - 00003150 _____ () C:\Windows\System32\Tasks\{9906AFC3-9716-45DC-93A7-E5EA5CE49D38} 2014-06-24 23:23 - 2014-06-21 21:51 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-06-24 23:23 - 2014-06-21 21:41 - 00000000 ____D () C:\Users\Maeph\AppData\Local\CrashDumps 2014-06-24 23:21 - 2014-06-21 21:53 - 00000000 ____D () C:\ProgramData\CostMin 2014-06-24 23:21 - 2014-06-21 21:53 - 00000000 ____D () C:\ProgramData\527dd4c7744378ff 2014-06-24 23:21 - 2014-06-21 21:53 - 00000000 ____D () C:\Program Files (x86)\CostMin 2014-06-24 23:20 - 2014-04-30 03:12 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-06-24 23:20 - 2011-11-24 06:23 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-06-24 23:19 - 2014-05-13 19:09 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-06-24 23:17 - 2014-06-21 21:41 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Linkey 2014-06-24 23:16 - 2014-06-24 23:13 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-06-24 23:15 - 2014-06-21 21:50 - 00000000 ____D () C:\Program Files (x86)\Supporter 2014-06-24 23:13 - 2009-07-14 06:45 - 00027568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-24 23:13 - 2009-07-14 06:45 - 00027568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-24 23:12 - 2014-06-24 23:12 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Avira 2014-06-24 23:12 - 2014-06-24 23:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-06-24 23:11 - 2014-06-24 23:10 - 00000000 ____D () C:\ProgramData\Avira 2014-06-24 23:11 - 2014-06-24 23:10 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-06-24 23:11 - 2014-04-07 18:07 - 01623670 _____ () C:\Windows\WindowsUpdate.log 2014-06-24 23:10 - 2014-06-24 23:10 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Maeph\Downloads\avira_de_av___ws.exe 2014-06-24 23:10 - 2014-06-24 23:10 - 00001099 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-06-24 23:10 - 2014-05-09 15:25 - 00000000 ____D () C:\ProgramData\Package Cache 2014-06-24 23:09 - 2014-06-21 21:40 - 00000000 ____D () C:\ProgramData\BOINC 2014-06-24 23:09 - 2014-05-09 15:48 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Skype 2014-06-24 23:08 - 2014-05-06 18:41 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Deployment 2014-06-24 23:08 - 2014-04-07 17:28 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\TS3Client 2014-06-24 23:07 - 2014-06-21 21:50 - 00003476 _____ () C:\Windows\System32\Tasks\GPUpdateCheck 2014-06-24 23:06 - 2011-11-24 06:33 - 00000000 ____D () C:\ProgramData\PDFC 2014-06-24 23:06 - 2011-11-24 06:18 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-06-24 23:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-24 23:06 - 2009-07-14 06:51 - 00053659 _____ () C:\Windows\setupact.log 2014-06-24 23:04 - 2014-04-07 17:12 - 00003930 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{96A4DA01-74A4-4AF6-B1B6-DB7946587841} 2014-06-23 23:39 - 2014-05-10 00:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-22 09:23 - 2014-05-06 18:35 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\NVIDIA 2014-06-22 09:22 - 2010-11-21 05:47 - 00105474 _____ () C:\Windows\PFRO.log 2014-06-22 09:22 - 2009-07-14 06:45 - 00296496 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-21 22:30 - 2014-06-21 22:30 - 00001507 _____ () C:\Users\Maeph\Desktop\AgeOfConan - Verknüpfung.lnk 2014-06-21 21:55 - 2014-06-21 21:55 - 00024210 _____ () C:\Users\Maeph\Downloads\D2A590AAAA1D0539E1913CBA05228D02CC11ADFD.torrent 2014-06-21 21:53 - 2014-06-21 21:53 - 00000442 __RSH () C:\ProgramData\ntuser.pol 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Torch 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Packages 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Chromatic Browser 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Torch 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Chromatic Browser 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator 2014-06-21 21:53 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-06-21 21:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-06-21 21:52 - 2014-06-21 21:52 - 02044896 _____ () C:\Users\Maeph\Downloads\Star_Wars_Galaxies__Pre_CU_(including_Patches_00-13).exe 2014-06-21 21:51 - 2014-06-21 21:51 - 00000000 ____D () C:\ProgramData\IePluginServices 2014-06-21 21:50 - 2014-06-21 21:50 - 00003218 _____ () C:\Windows\System32\Tasks\GPUpdate 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\smi 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\InetStat 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\GetPrivate 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Program Files (x86)\GetPrivate 2014-06-21 21:50 - 2014-04-07 17:13 - 00064464 _____ () C:\Users\Maeph\AppData\Local\GDIPFONTCACHEV1.DAT 2014-06-21 21:48 - 2014-06-21 21:48 - 02044896 _____ () C:\Users\Maeph\Downloads\SWG_Pre-CU.exe 2014-06-21 21:46 - 2014-06-21 21:46 - 00003118 _____ () C:\Windows\System32\Tasks\{FFC2A938-BEC4-4947-B5D2-A2FA289E2E4F} 2014-06-21 21:42 - 2014-06-21 21:42 - 39833841 _____ (SWGEmu) C:\Users\Maeph\Downloads\setup(1).exe 2014-06-21 21:42 - 2014-06-21 21:42 - 00002777 _____ () C:\Users\Public\Desktop\SWGEmu Launchpad.lnk 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Downloaded Installations 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SWGEmu 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\Program Files (x86)\SWGEmu 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Windows\Downloaded Installations 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Settings Manager 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Program Files (x86)\Sony 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Program Files (x86)\Settings Manager 2014-06-21 21:35 - 2014-06-21 21:35 - 00357776 _____ (Softonic) C:\Users\Maeph\Downloads\SoftonicDownloader_fuer_star-wars-galaxies-an-empire-divided.exe 2014-06-21 20:47 - 2014-06-21 20:47 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\BEGAware 2014-06-21 15:49 - 2014-06-21 15:46 - 04389376 _____ (BEGAware) C:\Users\Maeph\Desktop\PicturePuzzle.exe 2014-06-21 13:28 - 2014-06-21 13:28 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Funcom 2014-06-21 13:27 - 2014-06-21 13:26 - 00010009 _____ () C:\Windows\DirectX.log 2014-06-21 13:27 - 2014-06-21 13:25 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-06-21 13:27 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-21 13:26 - 2014-06-21 13:25 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-06-21 13:25 - 2014-06-21 13:25 - 20858106 _____ (Funcom ) C:\Users\Maeph\Downloads\ageofconan-de.exe 2014-06-21 13:25 - 2014-06-21 13:25 - 00000000 ____D () C:\Program Files (x86)\Funcom 2014-06-21 11:14 - 2014-06-21 11:14 - 14994368 _____ () C:\Users\Maeph\Downloads\Setup_Railroad_Tycoon.exe 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\2K Games 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Games 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\Program Files (x86)\2K Games 2014-06-21 11:14 - 2014-06-20 14:21 - 01058200 _____ (Adobe) C:\Users\Maeph\Downloads\install_flashplayer14x32au_ltr5x64d_awc_aih.exe 2014-06-21 04:43 - 2014-05-06 19:19 - 00003186 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForMaeph 2014-06-21 04:43 - 2014-05-06 19:19 - 00000332 _____ () C:\Windows\Tasks\HPCeeScheduleForMaeph.job 2014-06-20 14:06 - 2014-04-07 17:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-20 01:05 - 2014-05-10 12:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-17 16:46 - 2014-04-07 17:21 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft 2014-06-17 16:32 - 2011-11-24 05:57 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-06-17 16:32 - 2011-11-24 05:57 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-06-17 16:32 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-17 16:25 - 2014-06-24 23:11 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-17 16:25 - 2014-06-24 23:11 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-06-17 16:25 - 2014-06-24 23:11 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-06-16 11:26 - 2014-06-16 10:51 - 00042302 _____ () C:\Users\Maeph\Desktop\Lebenslauf Vorlage.odt 2014-06-16 11:18 - 2014-05-20 09:59 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-06-16 10:48 - 2014-06-16 10:48 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.0.lnk 2014-06-16 10:48 - 2014-06-16 10:48 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0 2014-06-16 10:48 - 2014-06-16 10:48 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\OpenOffice 2014-06-16 10:47 - 2014-06-16 10:47 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-06-16 10:46 - 2014-06-16 10:46 - 00000000 ____D () C:\Users\Maeph\Desktop\OpenOffice 4.1.0 (de) Installation Files 2014-06-16 10:43 - 2014-06-16 10:43 - 00961360 _____ (Chip Digital GmbH) C:\Users\Maeph\Downloads\OpenOffice - CHIP-Installer.exe 2014-06-11 22:00 - 2014-04-07 17:17 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-06-11 19:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-06-11 03:00 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-08 11:13 - 2014-06-10 22:42 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-08 11:08 - 2014-06-10 22:42 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-04 08:43 - 2014-06-04 08:33 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\SoundTouchPersist 2014-06-04 08:33 - 2014-06-04 08:33 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\SoundTouch 2014-06-04 08:33 - 2014-06-04 08:32 - 00000000 ____D () C:\Program Files (x86)\SoundTouch 2014-06-04 08:33 - 2011-11-24 06:24 - 00008490 _____ () C:\Windows\DPINST.LOG 2014-06-04 08:32 - 2014-06-04 08:32 - 00001911 _____ () C:\Users\Public\Desktop\SoundTouch.lnk 2014-06-04 08:32 - 2014-06-04 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundTouch 2014-06-04 08:32 - 2014-06-04 08:31 - 50130944 _____ () C:\Users\Maeph\Downloads\SoundTouch-app-installer-5.0.21.6712.msi 2014-06-02 22:21 - 2014-06-02 22:21 - 00001333 _____ () C:\Users\Maeph\Desktop\6b94eeecf0a3a536c6e0a362a2d954cd13789e37d54a4b2f6f25561ed90d6629836d56c143dae7bde29b3e4952886629d810ed806388959351b0ac47d9bc652e.htm 2014-06-02 00:43 - 2014-06-02 00:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2014-06-02 00:43 - 2014-06-02 00:43 - 00000000 ____D () C:\Program Files\McAfee Security Scan 2014-06-02 00:43 - 2014-05-10 00:43 - 00001933 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2014-06-02 00:43 - 2014-05-10 00:43 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-05-30 12:21 - 2014-06-10 22:44 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-30 12:02 - 2014-06-10 22:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-30 12:02 - 2014-06-10 22:44 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-05-30 11:45 - 2014-06-10 22:44 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-30 11:39 - 2014-06-10 22:44 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-30 11:39 - 2014-06-10 22:44 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-05-30 11:38 - 2014-06-10 22:44 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-05-30 11:28 - 2014-06-10 22:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-30 11:27 - 2014-06-10 22:44 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-05-30 11:24 - 2014-06-10 22:44 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-05-30 11:21 - 2014-06-10 22:44 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-30 11:21 - 2014-06-10 22:44 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-05-30 11:20 - 2014-06-10 22:44 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-05-30 11:18 - 2014-06-10 22:44 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-30 11:11 - 2014-06-10 22:44 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-05-30 11:08 - 2014-06-10 22:44 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-30 11:06 - 2014-06-10 22:44 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-30 11:02 - 2014-06-10 22:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-30 10:55 - 2014-06-10 22:44 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-05-30 10:49 - 2014-06-10 22:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-05-30 10:46 - 2014-06-10 22:44 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-30 10:44 - 2014-06-10 22:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-05-30 10:44 - 2014-06-10 22:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-30 10:43 - 2014-06-10 22:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-05-30 10:42 - 2014-06-10 22:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-05-30 10:38 - 2014-06-10 22:44 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-05-30 10:35 - 2014-06-10 22:44 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-05-30 10:34 - 2014-06-10 22:44 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-05-30 10:33 - 2014-06-10 22:44 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-05-30 10:30 - 2014-06-10 22:44 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-05-30 10:29 - 2014-06-10 22:44 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-30 10:28 - 2014-06-10 22:44 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-05-30 10:27 - 2014-06-10 22:44 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-05-30 10:24 - 2014-06-10 22:44 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-05-30 10:23 - 2014-06-10 22:44 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-30 10:16 - 2014-06-10 22:44 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-05-30 10:10 - 2014-06-10 22:44 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-05-30 10:06 - 2014-06-10 22:44 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-05-30 10:04 - 2014-06-10 22:44 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-30 10:02 - 2014-06-10 22:44 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-05-30 09:56 - 2014-06-10 22:44 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-05-30 09:56 - 2014-06-10 22:44 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-30 09:54 - 2014-06-10 22:44 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-05-30 09:50 - 2014-06-10 22:44 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-05-30 09:49 - 2014-06-10 22:44 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-05-30 09:43 - 2014-06-10 22:44 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-30 09:40 - 2014-06-10 22:44 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-05-30 09:30 - 2014-06-10 22:44 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-30 09:21 - 2014-06-10 22:44 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-05-30 09:15 - 2014-06-10 22:44 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-05-30 09:13 - 2014-06-10 22:44 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-05-30 09:13 - 2014-06-10 22:44 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Some content of TEMP: ==================== C:\Users\Maeph\AppData\Local\Temp\18be6784_.exe C:\Users\Maeph\AppData\Local\Temp\223c3xzq.kqc.exe C:\Users\Maeph\AppData\Local\Temp\294823_.exe C:\Users\Maeph\AppData\Local\Temp\APNSetup.exe C:\Users\Maeph\AppData\Local\Temp\avgnt.exe C:\Users\Maeph\AppData\Local\Temp\btwjo5bd.xsq.exe C:\Users\Maeph\AppData\Local\Temp\ce-desktop.exe C:\Users\Maeph\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Maeph\AppData\Local\Temp\Nv3DVStreaming.dll C:\Users\Maeph\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Maeph\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Maeph\AppData\Local\Temp\nvStInst.exe C:\Users\Maeph\AppData\Local\Temp\odxc15u1.y3r.exe C:\Users\Maeph\AppData\Local\Temp\SettingsManagerSetup.exe C:\Users\Maeph\AppData\Local\Temp\sp64126.exe C:\Users\Maeph\AppData\Local\Temp\UninstallHPSA.exe C:\Users\Maeph\AppData\Local\Temp\zuyzejyt.r1s.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-18 12:58 ==================== End Of Log ============================ |
25.06.2014, 08:38 | #5 |
| GS Supporter 1.80 auf dem RechnerCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-06-2014 Ran by Maeph at 2014-06-24 23:35:21 Running from C:\Users\Maeph\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Norton Internet Security (Disabled - Out of date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Disabled - Out of date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security (Disabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19120 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 2.6.0.19120 - Adobe Systems Incorporated) Hidden Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden Age of Conan: Unchained (HKLM-x32\...\Age of Conan_is1) (Version: - Funcom) Ask Toolbar (HKLM-x32\...\{4F524A2D-5637-4300-76A7-A758B70C0C02}) (Version: 12.12.2.83 - APN, LLC) <==== ATTENTION Avira (HKLM-x32\...\{68e29fba-92b1-4f6f-a604-1d8679da3a9f}) (Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.5.444 - Avira) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden Blasterball 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden Bounce Symphony (x32 Version: 2.2.0.97 - WildTangent) Hidden Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden Chronicles of Albian (x32 Version: 2.2.0.95 - WildTangent) Hidden Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.4.1.3 - Cliqz.com) Cradle of Rome 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Curse Client (HKCU\...\101a9f93b8f0bb6f) (Version: 5.1.1.810 - Curse) Device Access Manager for HP ProtectTools (HKLM\...\{55B52830-024A-443E-AF61-61E1E71AFA1B}) (Version: 6.0.0.12 - Hewlett-Packard Company) DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden Drive Encryption For HP ProtectTools (HKLM\...\{8A0041CD-277C-4C1F-BFE4-7AC508B20B4C}) (Version: 6.0.79.26218 - Hewlett-Packard Company) Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden File Sanitizer For HP ProtectTools (HKLM-x32\...\{6D6ADF03-B257-4EA5-BBC1-1D145AF8D514}) (Version: 6.0.0.13 - Hewlett-Packard Company) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Auto (Version: 1.0.12935.3667 - Hewlett-Packard Company) Hidden HP Client Services (Version: 1.1.12938.3539 - Hewlett-Packard) Hidden HP Connect Solutions (HKLM-x32\...\{BE1C9464-DEBB-4DA6-B19A-8EC634F22D73}) (Version: 1.0.0.4 - Hewlett-Packard) HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Desktop Keyboard (HKLM-x32\...\HP Keyboard_is1) (Version: 1.0.0.13 - Hewlett-Packard) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent) HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard) HP ProtectTools Security Manager (HKLM\...\HPProtectTools) (Version: 6.03.959 - Hewlett-Packard Company) HP ProtectTools Security Manager (Version: 6.03.959 - Hewlett-Packard Company) Hidden HP Setup (HKLM-x32\...\{03046EBB-CB7C-4B98-BEFB-690EB955DA22}) (Version: 8.5.4526.3645 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13880.3792 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard) HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.9.0.0 - Hewlett-Packard) Intel(R) Identity Protection Technology 1.1.2.0 (HKLM-x32\...\{C01A86F5-56E7-101F-9BC9-E3F1025EB779}) (Version: 1.1.2.0 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden Jewel Quest: The Sleepless Star - Collector's Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.154 - Logitech Inc.) Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Mystery of Mortlake Mansion (x32 Version: 2.2.0.97 - WildTangent) Hidden Namco All-Stars: PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden Norton Internet Security (HKLM-x32\...\NIS) (Version: 19.0.0.128 - Symantec Corporation) NVIDIA 3D Vision Controller-Treiber 335.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 335.21 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation) OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.54 - PDF Complete, Inc) Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6387 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.0.4222 - CyberLink Corp.) Hidden Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) SHIELD Streaming (Version: 1.7.321 - NVIDIA Corporation) Hidden Sid Meier's Railroad Tycoon (HKLM-x32\...\Sid Meier's Railroad Tycoon) (Version: 1.0 - 2K Games) Skype™ 5.3 (HKLM-x32\...\{5335DADB-34BA-4AE8-A519-648D78498846}) (Version: 5.3.111 - Skype Technologies S.A.) Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden SoundTouch (HKLM-x32\...\{2BE5D5D5-8279-41A7-88A4-96760E553952}) (Version: 5.0.21.6712 - BOSE) Supporter 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{be0fb33b}) (Version: - Costmin) <==== ATTENTION SWGEmu Launchpad (HKLM-x32\...\{37A10E4F-B984-462D-A33E-6C3D74CB1299}) (Version: 0.22 - SWGEmu) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Vacation Quest - The Hawaiian Islands (x32 Version: 2.2.0.97 - WildTangent) Hidden VIP Access SDK (1.0.1.4) (HKLM-x32\...\VIP Access SDK) (Version: 1.0.1.4 - Symantec Inc.) Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden WildTangent Games App (HP Games) (x32 Version: 4.0.5.2 - WildTangent) Hidden World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) Zinio Reader 4 (HKLM-x32\...\ZinioReader4) (Version: 4.2.4164 - Zinio LLC) Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Restore Points ========================= 04-06-2014 06:32:21 Installed SoundTouch 04-06-2014 06:41:41 Windows Update 10-06-2014 20:42:09 Windows Update 11-06-2014 01:00:22 Windows Update 15-06-2014 20:52:29 Windows Update 16-06-2014 08:46:16 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 16-06-2014 08:46:53 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 16-06-2014 08:47:40 OpenOffice 4.1.0 wird installiert 21-06-2014 02:53:19 Windows Update 21-06-2014 11:26:36 DirectX wurde installiert 21-06-2014 19:40:01 Installed Star Wars Galaxies 21-06-2014 19:42:35 Installed SWGEmu Launchpad. 21-06-2014 19:45:49 Installed Star Wars Galaxies 21-06-2014 19:46:39 Configured Star Wars Galaxies 21-06-2014 19:49:39 Removed Star Wars Galaxies 24-06-2014 21:02:22 Windows Update 24-06-2014 21:12:44 Removed Charity Engine. 24-06-2014 21:17:52 Konfiguriert LabelPrint 24-06-2014 21:19:24 Konfiguriert Power2Go ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {16AA6967-B2BF-4FFF-A32A-5C483F31CC3E} - System32\Tasks\HPCeeScheduleForMaeph => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard) Task: {23391B43-D72E-4A91-87B7-9A14067DA71A} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\WSCStub.exe [2011-05-28] (Symantec Corporation) Task: {42234625-4890-4613-BC69-8A10FA9D9FA0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated) Task: {4E5EA3AE-9638-492E-867C-8D49974A226D} - System32\Tasks\GPUpdate => C:\Program Files (x86)\GetPrivate\gpup.exe [2014-06-21] () Task: {5ADFF536-AF8F-4E5E-9BED-D302D2868FCD} - System32\Tasks\GPUpdateCheck => C:\Program Files (x86)\GetPrivate\gpup.exe [2014-06-21] () Task: {6E09EEAE-13A8-4702-A703-B0179907F8C0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {AA7DA277-52CB-4B50-BAA9-00C55152CDDD} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\SymErr.exe [2011-05-26] (Symantec Corporation) Task: {AE9911AA-99C6-47F3-AF98-27686D0733AC} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2011-01-25] () Task: {B2E0D5BE-32A0-4549-B412-796E56EF95F4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {C9FA59A3-C3ED-4C6F-934D-38E564F221C9} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) Task: {CB70DACB-F606-41C2-A7F6-446466DE1C07} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\SymErr.exe [2011-05-26] (Symantec Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\HPCeeScheduleForMaeph.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2014-04-07 19:51 - 2014-03-04 15:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-04-11 09:24 - 2014-04-11 09:24 - 00034304 _____ () C:\Windows\System32\sst6clm.dll 2011-07-13 02:49 - 2011-07-13 02:49 - 03371520 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpeHpFve64.dll 2011-07-13 02:42 - 2011-07-13 02:42 - 01929728 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcNp64.DLL 2011-07-13 02:11 - 2011-07-13 02:11 - 01318912 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe 2011-07-13 02:36 - 2011-07-13 02:36 - 00200704 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe 2014-02-11 20:21 - 2014-02-11 20:21 - 00860160 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 01043968 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-02-11 20:21 - 2014-02-11 20:21 - 00052736 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 00236032 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-06-21 21:50 - 2014-06-21 21:50 - 00659470 _____ () C:\Users\Maeph\AppData\Roaming\InetStat\inetstat.exe 2014-06-14 10:17 - 2014-06-14 10:17 - 00014848 ____N () C:\Users\Maeph\AppData\Local\Apps\2.0\XYGL4YPM.90D\BE1XBXN0.GVC\curs..tion_9e9e83ddf3ed3ead_0005.0001_36a9b6290e21932c\Curse.CurseClient.WowDb.dll 2014-05-06 18:43 - 2014-05-06 18:43 - 00035840 _____ () C:\Users\Maeph\AppData\Local\Apps\2.0\XYGL4YPM.90D\BE1XBXN0.GVC\curs..tion_9e9e83ddf3ed3ead_0005.0001_36a9b6290e21932c\Curse.Advertising.dll 2014-06-14 10:17 - 2014-06-14 10:17 - 00099840 ____N () C:\Users\Maeph\AppData\Local\Apps\2.0\XYGL4YPM.90D\BE1XBXN0.GVC\curs..tion_9e9e83ddf3ed3ead_0005.0001_36a9b6290e21932c\Curse.CurseClient.CMOD2.dll 2011-11-24 06:29 - 2009-07-03 00:58 - 00406016 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe 2014-02-28 11:14 - 2014-02-28 11:14 - 00173568 _____ () C:\Program Files\TeamSpeak 3 Client\quazip.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 01080832 _____ () C:\Program Files\TeamSpeak 3 Client\platforms\qwindows.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00833024 _____ () C:\Program Files\TeamSpeak 3 Client\sqldrivers\qsqlite.dll 2014-02-28 15:07 - 2014-02-28 15:07 - 00102344 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll 2014-02-28 15:07 - 2014-02-28 15:07 - 00108488 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00030208 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qgif.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00233984 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qjpeg.dll 2014-02-28 15:10 - 2014-02-28 15:10 - 00563656 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 2014-02-28 15:10 - 2014-02-28 15:10 - 00577480 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00159232 _____ () C:\Program Files\TeamSpeak 3 Client\accessible\qtaccessiblewidgets.dll 2011-07-13 02:33 - 2011-07-13 02:33 - 02834432 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcEncryptionProviderPlugin.dll 2011-07-13 02:10 - 2011-07-13 02:10 - 00126976 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHostInterface.dll 2011-07-13 02:32 - 2011-07-13 02:32 - 03100672 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpeOpalEncryptionProviderPlugin.dll 2011-07-13 02:35 - 2011-07-13 02:35 - 02854912 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpeHpDpHostPlugin.dll 2011-07-13 02:34 - 2011-07-13 02:34 - 00053248 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpeOpalATASec4SATA.dll 2011-07-13 02:13 - 2011-07-13 02:13 - 02035712 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeCoreEncryptionPlugin.dll 2011-07-13 02:14 - 2011-07-13 02:14 - 01929216 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeProductDetectionPlugin.dll 2014-05-14 14:27 - 2014-05-14 14:27 - 00137296 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll 2014-05-14 14:27 - 2014-05-14 14:27 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2014-06-24 23:12 - 2014-05-14 14:27 - 00049744 _____ () C:\Users\Maeph\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2014-05-10 12:22 - 2014-06-20 01:05 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-05-14 17:39 - 2014-05-14 17:39 - 16361136 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll 2014-06-11 22:00 - 2014-06-11 22:00 - 26065408 _____ () C:\Program Files (x86)\Battle.net\Battle.net.4710\libcef.dll 2014-06-11 22:00 - 2014-06-11 22:00 - 00739840 _____ () C:\Program Files (x86)\Battle.net\Battle.net.4710\libglesv2.dll 2014-06-11 22:00 - 2014-06-11 22:00 - 00130048 _____ () C:\Program Files (x86)\Battle.net\Battle.net.4710\libegl.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/24/2014 11:23:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 30.0.0.5269, Zeitstempel: 0x53914233 Name des fehlerhaften Moduls: mozalloc.dll, Version: 30.0.0.5269, Zeitstempel: 0x53911393 Ausnahmecode: 0x80000003 Fehleroffset: 0x0000141b ID des fehlerhaften Prozesses: 0x1968 Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (06/23/2014 05:33:42 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: ) Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (06/21/2014 09:53:07 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 30.0.0.5269, Zeitstempel: 0x53914233 Name des fehlerhaften Moduls: mozalloc.dll, Version: 30.0.0.5269, Zeitstempel: 0x53911393 Ausnahmecode: 0x80000003 Fehleroffset: 0x0000141b ID des fehlerhaften Prozesses: 0xd4c Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (06/21/2014 09:50:56 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 30.0.0.5269, Zeitstempel: 0x53914233 Name des fehlerhaften Moduls: mozalloc.dll, Version: 30.0.0.5269, Zeitstempel: 0x53911393 Ausnahmecode: 0x80000003 Fehleroffset: 0x0000141b ID des fehlerhaften Prozesses: 0x18dc Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (06/21/2014 09:44:32 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (06/21/2014 09:41:09 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 30.0.0.5269, Zeitstempel: 0x53914233 Name des fehlerhaften Moduls: mozalloc.dll, Version: 30.0.0.5269, Zeitstempel: 0x53911393 Ausnahmecode: 0x80000003 Fehleroffset: 0x0000141b ID des fehlerhaften Prozesses: 0x16a0 Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (06/21/2014 09:37:03 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (06/21/2014 09:37:02 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (06/21/2014 09:37:01 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (06/21/2014 09:35:59 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (06/24/2014 11:15:16 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Supporter" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/24/2014 11:06:07 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 24.06.2014 um 23:04:38 unerwartet heruntergefahren. Error: (06/21/2014 09:41:15 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "Systemk Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (06/16/2014 02:44:51 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst lmhosts erreicht. Error: (05/07/2014 00:53:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "HP Support Assistant Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/07/2014 00:52:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "HP Support Assistant Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (05/07/2014 09:30:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (05/07/2014 09:30:59 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (05/07/2014 09:30:59 AM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (05/04/2014 04:15:02 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Microsoft Office Sessions: ========================= Error: (06/24/2014 11:23:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe30.0.0.526953914233mozalloc.dll30.0.0.526953911393800000030000141b196801cf8ff07313453fC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllc2af74d7-fbe5-11e3-8042-2c4138960bba Error: (06/23/2014 05:33:42 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: ) Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (06/21/2014 09:53:07 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe30.0.0.526953914233mozalloc.dll30.0.0.526953911393800000030000141bd4c01cf8d8a2c967ee4C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dlla98c6f57-f97d-11e3-a7ec-2c4138960bba Error: (06/21/2014 09:50:56 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe30.0.0.526953914233mozalloc.dll30.0.0.526953911393800000030000141b18dc01cf8d88c694a94cC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll5b8a92c0-f97d-11e3-a7ec-2c4138960bba Error: (06/21/2014 09:44:32 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Maeph\Downloads\SoftonicDownloader_fuer_star-wars-galaxies-an-empire-divided.exe Error: (06/21/2014 09:41:09 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe30.0.0.526953914233mozalloc.dll30.0.0.526953911393800000030000141b16a001cf8d77c386b92eC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllfdcd8f26-f97b-11e3-a7ec-2c4138960bba Error: (06/21/2014 09:37:03 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Maeph\Downloads\SoftonicDownloader_fuer_star-wars-galaxies-an-empire-divided.exe Error: (06/21/2014 09:37:02 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Maeph\Downloads\SoftonicDownloader_fuer_star-wars-galaxies-an-empire-divided.exe Error: (06/21/2014 09:37:01 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Maeph\Downloads\SoftonicDownloader_fuer_star-wars-galaxies-an-empire-divided.exe Error: (06/21/2014 09:35:59 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Maeph\Downloads\SoftonicDownloader_fuer_star-wars-galaxies-an-empire-divided.exe ==================== Memory info =========================== Percentage of memory in use: 37% Total physical RAM: 8172.82 MB Available physical RAM: 5073.09 MB Total Pagefile: 16343.81 MB Available Pagefile: 12908.3 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:917.86 GB) (Free:813.59 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (HP_RECOVERY) (Fixed) (Total:13.55 GB) (Free:1.67 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (SAMSUNG_CLBP) (CDROM) (Total:0.22 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ==================== End Of Log ============================ Ich hoffe das passt so |
25.06.2014, 09:26 | #6 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | GS Supporter 1.80 auf dem RechnerZitat:
__________________ --> GS Supporter 1.80 auf dem Rechner |
25.06.2014, 11:07 | #7 | |
| GS Supporter 1.80 auf dem RechnerZitat:
Alles klar hab beides deinstalliert |
25.06.2014, 11:11 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | GS Supporter 1.80 auf dem Rechner Dann bitte jetzt Combofix ausführen: Scan mit Combofix
__________________ Logfiles bitte immer in CODE-Tags posten |
25.06.2014, 12:22 | #9 |
| GS Supporter 1.80 auf dem Rechner So Scan gemacht... Code:
ATTFilter ComboFix 14-06-24.01 - Maeph 25.06.2014 13:13:11.1.8 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.41.1031.18.8173.6386 [GMT 2:00] ausgeführt von:: c:\users\Maeph\Downloads\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\CostMin c:\program files (x86)\Java\jre7\bin\jp2ssv.dll c:\programdata\CostMin c:\programdata\CostMin\LRis.exe c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\background.html c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\content.js c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\lsdb.js c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\manifest.json c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\tGzrG.js c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\background.html c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\content.js c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\lsdb.js c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\manifest.json c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\tGzrG.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\background.html c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\content.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\manifest.json c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\tGzrG.js c:\users\Maeph\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk c:\users\Maeph\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\background.html c:\users\Maeph\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\content.js c:\users\Maeph\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\lsdb.js c:\users\Maeph\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\manifest.json c:\users\Maeph\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopljkainjongdagaedicbdmbcjaeajk\2.2\tGzrG.js . . ((((((((((((((((((((((( Dateien erstellt von 2014-05-25 bis 2014-06-25 )))))))))))))))))))))))))))))) . . 2014-06-25 11:16 . 2014-06-25 11:16 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-06-25 07:33 . 2014-06-25 07:33 -------- d-----w- c:\program files (x86)\7-Zip 2014-06-24 21:34 . 2014-06-24 21:36 -------- d-----w- C:\FRST 2014-06-24 21:13 . 2014-06-24 21:16 -------- d-----w- c:\windows\system32\appmgmt 2014-06-24 21:02 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0DE41829-688A-477F-B1A0-42624CD72AF7}\mpengine.dll 2014-06-21 19:53 . 2014-06-24 21:21 -------- d-----w- c:\programdata\527dd4c7744378ff 2014-06-21 19:53 . 2014-06-21 19:53 -------- d-----w- c:\users\Maeph\AppData\Local\Packages 2014-06-21 19:53 . 2014-06-21 19:53 -------- d-----w- c:\users\Maeph\AppData\Local\Torch 2014-06-21 19:53 . 2014-06-21 19:53 -------- d-----w- c:\users\Maeph\AppData\Local\Google 2014-06-21 19:53 . 2014-06-21 19:53 -------- d-----w- c:\users\Maeph\AppData\Local\Comodo 2014-06-21 19:53 . 2014-06-21 19:53 -------- d-----w- c:\users\Maeph\AppData\Local\Chromatic Browser 2014-06-21 19:53 . 2014-06-21 19:53 -------- d-----w- c:\users\HomeGroupUser$ 2014-06-21 19:53 . 2014-06-21 19:53 -------- d-----w- c:\users\Gast 2014-06-21 19:53 . 2014-06-21 19:53 -------- d-----w- c:\users\Administrator 2014-06-21 19:51 . 2014-06-24 21:23 -------- d-----w- c:\program files (x86)\SupTab 2014-06-21 19:51 . 2014-06-21 19:51 -------- d-----w- c:\programdata\IePluginServices 2014-06-21 19:50 . 2014-06-25 07:08 -------- d-----w- c:\program files (x86)\Supporter 2014-06-21 19:50 . 2014-06-21 19:50 -------- d-----w- c:\users\Maeph\AppData\Roaming\InetStat 2014-06-21 19:50 . 2014-06-21 19:50 -------- d-----w- c:\program files (x86)\GetPrivate 2014-06-21 19:50 . 2014-06-21 19:50 -------- d-----w- c:\users\Maeph\AppData\Roaming\GetPrivate 2014-06-21 19:50 . 2014-06-21 19:50 -------- d-----w- c:\users\Maeph\AppData\Roaming\smi 2014-06-21 19:42 . 2014-06-21 19:42 -------- d-----w- c:\program files (x86)\SWGEmu 2014-06-21 19:42 . 2014-06-21 19:42 -------- d-----w- c:\users\Maeph\AppData\Local\Downloaded Installations 2014-06-21 19:41 . 2014-06-24 21:23 -------- d-----w- c:\users\Maeph\AppData\Local\CrashDumps 2014-06-21 19:41 . 2014-06-24 21:17 -------- d-----w- c:\users\Maeph\AppData\Local\Linkey 2014-06-21 19:40 . 2014-06-21 19:40 -------- d-----w- c:\users\Maeph\AppData\Roaming\Settings Manager 2014-06-21 19:40 . 2014-06-24 21:09 -------- d-----w- c:\programdata\BOINC 2014-06-21 19:40 . 2014-06-21 19:40 -------- d-----w- c:\windows\Downloaded Installations 2014-06-21 19:40 . 2014-06-21 19:40 -------- d-----w- c:\program files (x86)\Sony 2014-06-21 18:47 . 2014-06-21 18:47 -------- d-----w- c:\users\Maeph\AppData\Roaming\BEGAware 2014-06-21 11:28 . 2014-06-21 11:28 -------- d-----w- c:\users\Maeph\AppData\Local\Funcom 2014-06-21 11:26 . 2007-03-05 10:42 15128 ----a-w- c:\windows\SysWow64\x3daudio1_1.dll 2014-06-21 11:25 . 2014-06-21 11:26 -------- d--h--w- c:\windows\msdownld.tmp 2014-06-21 11:25 . 2014-06-21 11:25 -------- d-----w- c:\programdata\media center programs 2014-06-21 11:25 . 2014-06-21 11:25 -------- d-----w- c:\program files (x86)\Funcom 2014-06-21 09:14 . 2014-06-21 09:14 -------- d-----w- c:\program files (x86)\2K Games 2014-06-16 08:48 . 2014-06-16 08:48 -------- d-----w- c:\users\Maeph\AppData\Roaming\OpenOffice 2014-06-16 08:47 . 2014-06-16 08:47 -------- d-----w- c:\program files (x86)\OpenOffice 4 2014-06-16 08:44 . 2014-06-16 08:44 -------- d-----w- c:\users\Maeph\AppData\Local\Programs 2014-06-16 08:44 . 2011-05-13 10:16 493056 ----a-w- c:\windows\SysWow64\dhRichClient3.dll 2014-06-16 08:44 . 2011-03-25 18:42 338432 ----a-w- c:\windows\SysWow64\sqlite36_engine.dll 2014-06-10 20:42 . 2014-06-08 09:13 506368 ----a-w- c:\windows\system32\aepdu.dll 2014-06-10 20:42 . 2014-06-08 09:08 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-06-04 06:33 . 2014-06-04 06:33 -------- d-----w- c:\users\Maeph\AppData\Roaming\SoundTouch 2014-06-04 06:32 . 2014-06-04 06:33 -------- d-----w- c:\program files (x86)\SoundTouch 2014-06-01 13:10 . 2014-06-01 13:10 -------- d-----w- c:\users\Maeph\AppData\Local\ElevatedDiagnostics . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-05-14 15:39 . 2014-05-09 22:43 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-05-14 15:39 . 2011-11-24 04:30 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-05-14 15:39 . 2014-05-14 15:39 17938608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2014-04-30 03:28 . 2014-04-30 03:28 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2014-04-30 03:28 . 2014-04-30 03:28 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2014-04-30 03:28 . 2014-04-30 03:28 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2014-04-30 03:28 . 2014-04-30 03:28 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2014-04-30 03:28 . 2014-04-30 03:28 337408 ----a-w- c:\windows\SysWow64\html.iec 2014-04-30 03:28 . 2014-04-30 03:28 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2014-04-30 03:28 . 2014-04-30 03:28 235008 ----a-w- c:\windows\system32\elshyph.dll 2014-04-30 03:28 . 2014-04-30 03:28 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2014-04-30 03:28 . 2014-04-30 03:28 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2014-04-30 03:28 . 2014-04-30 03:28 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2014-04-30 03:28 . 2014-04-30 03:28 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2014-04-30 03:28 . 2014-04-30 03:28 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2014-04-30 03:28 . 2014-04-30 03:28 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2014-04-30 03:28 . 2014-04-30 03:28 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2014-04-30 03:28 . 2014-04-30 03:28 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2014-04-30 03:28 . 2014-04-30 03:28 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2014-04-30 03:28 . 2014-04-30 03:28 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2014-04-30 03:28 . 2014-04-30 03:28 942592 ----a-w- c:\windows\system32\jsIntl.dll 2014-04-30 03:28 . 2014-04-30 03:28 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2014-04-30 03:28 . 2014-04-30 03:28 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2014-04-30 03:28 . 2014-04-30 03:28 77312 ----a-w- c:\windows\system32\tdc.ocx 2014-04-30 03:28 . 2014-04-30 03:28 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2014-04-30 03:28 . 2014-04-30 03:28 48640 ----a-w- c:\windows\system32\mshtmler.dll 2014-04-30 03:28 . 2014-04-30 03:28 413696 ----a-w- c:\windows\system32\html.iec 2014-04-30 03:28 . 2014-04-30 03:28 247808 ----a-w- c:\windows\system32\msls31.dll 2014-04-30 03:28 . 2014-04-30 03:28 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2014-04-30 03:28 . 2014-04-30 03:28 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2014-04-30 03:28 . 2014-04-30 03:28 105984 ----a-w- c:\windows\system32\iesysprep.dll 2014-04-30 03:28 . 2014-04-30 03:28 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-04-30 03:28 . 2014-04-30 03:28 81408 ----a-w- c:\windows\system32\icardie.dll 2014-04-30 03:28 . 2014-04-30 03:28 774144 ----a-w- c:\windows\system32\jscript.dll 2014-04-30 03:28 . 2014-04-30 03:28 62464 ----a-w- c:\windows\system32\pngfilt.dll 2014-04-30 03:28 . 2014-04-30 03:28 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2014-04-30 03:28 . 2014-04-30 03:28 48128 ----a-w- c:\windows\system32\imgutil.dll 2014-04-30 03:28 . 2014-04-30 03:28 30208 ----a-w- c:\windows\system32\licmgr10.dll 2014-04-30 03:28 . 2014-04-30 03:28 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2014-04-30 03:28 . 2014-04-30 03:28 243200 ----a-w- c:\windows\system32\webcheck.dll 2014-04-30 03:28 . 2014-04-30 03:28 235520 ----a-w- c:\windows\system32\url.dll 2014-04-30 03:28 . 2014-04-30 03:28 167424 ----a-w- c:\windows\system32\iexpress.exe 2014-04-30 03:28 . 2014-04-30 03:28 147968 ----a-w- c:\windows\system32\occache.dll 2014-04-30 03:28 . 2014-04-30 03:28 143872 ----a-w- c:\windows\system32\wextract.exe 2014-04-30 03:28 . 2014-04-30 03:28 13824 ----a-w- c:\windows\system32\mshta.exe 2014-04-30 03:28 . 2014-04-30 03:28 135680 ----a-w- c:\windows\system32\iepeers.dll 2014-04-30 03:28 . 2014-04-30 03:28 101376 ----a-w- c:\windows\system32\inseng.dll 2014-04-30 03:21 . 2014-04-30 03:21 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2014-04-30 03:21 . 2014-04-30 03:21 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2014-04-30 03:21 . 2014-04-30 03:21 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2014-04-30 03:21 . 2014-04-30 03:21 363008 ----a-w- c:\windows\system32\dxgi.dll 2014-04-30 03:21 . 2014-04-30 03:21 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 296960 ----a-w- c:\windows\system32\d3d10core.dll 2014-04-30 03:21 . 2014-04-30 03:21 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2014-04-30 03:21 . 2014-04-30 03:21 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2014-04-30 03:21 . 2014-04-30 03:21 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2014-04-30 03:21 . 2014-04-30 03:21 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll 2014-04-30 03:21 . 2014-04-30 03:21 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll 2014-04-30 03:21 . 2014-04-30 03:21 1682432 ----a-w- c:\windows\system32\XpsPrint.dll 2014-04-30 03:21 . 2014-04-30 03:21 1643520 ----a-w- c:\windows\system32\DWrite.dll 2014-04-30 03:21 . 2014-04-30 03:21 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll 2014-04-30 03:21 . 2014-04-30 03:21 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll 2014-04-30 03:21 . 2014-04-30 03:21 1175552 ----a-w- c:\windows\system32\FntCache.dll 2014-04-30 03:21 . 2014-04-30 03:21 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll 2014-04-30 03:21 . 2014-04-30 03:21 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll 2014-04-30 03:21 . 2014-04-30 03:21 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-04-30 03:21 . 2014-04-30 03:21 1238528 ----a-w- c:\windows\system32\d3d10.dll 2014-04-30 03:21 . 2014-04-30 03:21 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2014-04-30 03:21 . 2014-04-30 03:21 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2014-04-30 03:21 . 2014-04-30 03:21 293376 ----a-w- c:\windows\SysWow64\dxgi.dll 2014-04-30 03:21 . 2014-04-30 03:21 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2014-04-30 03:21 . 2014-04-30 03:21 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2014-04-30 03:21 . 2014-04-30 03:21 194560 ----a-w- c:\windows\system32\d3d10_1.dll 2014-04-30 03:21 . 2014-04-30 03:21 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll 2014-04-14 18:13 . 2014-05-07 07:40 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2014-04-12 02:22 . 2014-05-15 09:15 155072 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2014-04-12 02:22 . 2014-05-15 09:15 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2014-04-12 02:19 . 2014-05-15 09:15 29184 ----a-w- c:\windows\system32\sspisrv.dll 2014-04-12 02:19 . 2014-05-15 09:15 136192 ----a-w- c:\windows\system32\sspicli.dll 2014-04-12 02:19 . 2014-05-15 09:15 28160 ----a-w- c:\windows\system32\secur32.dll 2014-04-12 02:19 . 2014-05-15 09:15 1460736 ----a-w- c:\windows\system32\lsasrv.dll 2014-04-12 02:19 . 2014-05-15 09:15 31232 ----a-w- c:\windows\system32\lsass.exe 2014-04-12 02:12 . 2014-05-15 09:15 22016 ----a-w- c:\windows\SysWow64\secur32.dll 2014-04-12 02:10 . 2014-05-15 09:15 96768 ----a-w- c:\windows\SysWow64\sspicli.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-04-18 15146376] "InetStat"="c:\users\Maeph\AppData\Roaming\InetStat\inetstat.exe" [2014-06-21 659470] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HP KEYBOARDx"="c:\program files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE" [2010-02-11 710656] "PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2011-05-06 658424] "File Sanitizer"="c:\program files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2011-05-09 12277248] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2014-05-16 1935824] "SoundTouch Music Server"="c:\program files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch music server.exe" [2014-04-09 1062912] . c:\users\Maeph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ CurseClientStartup.ccip [2014-5-6 0] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP] 2011-05-09 23:43 75320 ----a-w- c:\windows\System32\DeviceNP.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ DPPassFilter scecli . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys;c:\windows\SYSNATIVE\DRIVERS\DAMDrv64.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe;c:\windows\SysWOW64\flcdlock.exe [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x] R3 OxPPort;OxPPort;c:\windows\system32\drivers\OxPPort.sys;c:\windows\SYSNATIVE\drivers\OxPPort.sys [x] R3 OxSer;OxSer;c:\windows\system32\drivers\OxSer.sys;c:\windows\SYSNATIVE\drivers\OxSer.sys [x] R3 pmxdrv;pmxdrv;c:\windows\system32\drivers\pmxdrv.sys;c:\windows\SYSNATIVE\drivers\pmxdrv.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 MfeEpeOpal;MfeEpeOpal; [x] S0 MfeEpePc;MfeEpePc; [x] S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x] S2 HPAuto;HP Auto;c:\program files\Hewlett-Packard\HP Auto\HPAuto.exe;c:\program files\Hewlett-Packard\HP Auto\HPAuto.exe [x] S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [x] S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [x] S2 IePluginServices;IePlugin Services;c:\programdata\IePluginServices\PluginService.exe;c:\programdata\IePluginServices\PluginService.exe [x] S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [x] S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [x] S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . Inhalt des "geplante Tasks" Ordners . 2014-06-25 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-09 15:39] . 2014-06-25 c:\windows\Tasks\HPCeeScheduleForMaeph.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MfeEpePcMonitor"="c:\program files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe" [2011-07-13 200704] "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-02-05 2234144] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-02-05 1179576] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-04-15 10396440] . ------- Zusätzlicher Suchlauf ------- . uStart Page = about:blank uLocal Page = c:\windows\system32\blank.htm mDefault_Search_URL = hxxp://search.v9.com/web/?type=ds&ts=1403380256&from=irs&uid=HitachiXHDS721010CLA632_JP2940J833BZ5V33BZ5VX&i=psd&t=3447ad542&q={searchTerms} mDefault_Page_URL = about:blank mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://search.v9.com/web/?type=ds&ts=1403380256&from=irs&uid=HitachiXHDS721010CLA632_JP2940J833BZ5V33BZ5VX&i=psd&t=3447ad542&q={searchTerms} TCP: DhcpNameServer = 192.168.192.1 FF - ProfilePath - c:\users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\ FF - prefs.js: keyword.URL - hxxp://www.default-search.net/search?sid=476&aid=146&itype=n&ver=13001&tm=385&src=ds&p= . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-10 - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-10 - (no file) AddRemove-{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1 - c:\users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\extensions\cliqz@cliqz.com\unins000.exe AddRemove-{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE} - c:\program files (x86)\InstallShield Installation Information\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}\setup.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher] "ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.13" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-06-25 13:21:27 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-06-25 11:21 . Vor Suchlauf: 9 Verzeichnis(se), 876'074'868'736 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 877'384'339'456 Bytes frei . - - End Of File - - 7240B37330AC613E5EF981699C6FF7F6 |
25.06.2014, 12:26 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | GS Supporter 1.80 auf dem Rechner Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
25.06.2014, 13:24 | #11 |
| GS Supporter 1.80 auf dem Rechner So alle scans gemacht: Adw Scan: Code:
ATTFilter # AdwCleaner v3.213 - Bericht erstellt am 25/06/2014 um 14:12:34 # Aktualisiert 23/06/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Maeph - MAEPH-HP # Gestartet von : C:\Users\Maeph\Downloads\adwcleaner_3.213.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : APNMCP Dienst Gelöscht : IePluginServices ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\ProgramData\AskPartnerNetwork Ordner Gelöscht : C:\ProgramData\IePluginServices Ordner Gelöscht : C:\Program Files (x86)\AskPartnerNetwork Ordner Gelöscht : C:\Program Files (x86)\GetPrivate Ordner Gelöscht : C:\Program Files (x86)\supporter Ordner Gelöscht : C:\Program Files (x86)\SupTab Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Chromatic Browser Ordner Gelöscht : C:\Users\Administrator\AppData\Local\torch Ordner Gelöscht : C:\Users\Gast\AppData\Local\Chromatic Browser Ordner Gelöscht : C:\Users\Gast\AppData\Local\torch Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\torch Ordner Gelöscht : C:\Users\Maeph\AppData\Local\Chromatic Browser Ordner Gelöscht : C:\Users\Maeph\AppData\Local\Linkey Ordner Gelöscht : C:\Users\Maeph\AppData\Local\torch Ordner Gelöscht : C:\Users\Maeph\AppData\Roaming\GetPrivate Ordner Gelöscht : C:\Users\Maeph\AppData\Roaming\InetStat Ordner Gelöscht : C:\Users\Maeph\AppData\Roaming\Settings Manager Ordner Gelöscht : C:\Users\Maeph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat Datei Gelöscht : C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\searchplugins\ask-search.xml Datei Gelöscht : C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\searchplugins\default-search.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml Datei Gelöscht : C:\Windows\System32\Tasks\GPUpdate ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [InetStat] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon] Schlüssel Gelöscht : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelöscht : HKCU\Software\AskPartnerNetwork Schlüssel Gelöscht : HKCU\Software\Linkey Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\Software\AskPartnerNetwork Schlüssel Gelöscht : HKLM\Software\SupDp Schlüssel Gelöscht : HKLM\Software\SupTab Schlüssel Gelöscht : HKLM\Software\SystemK Schlüssel Gelöscht : HKLM\Software\V9Software Schlüssel Gelöscht : HKLM\Software\Wpm Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5F003B-C71B-72E3-42B4-DE51AB079EB2} ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] -\\ Mozilla Firefox v30.0 (de) [ Datei : C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\prefs.js ] Zeile gelöscht : user_pref("browser.search.order.1", "default-search.net"); Zeile gelöscht : user_pref("extensions.lqxXI.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.n[...] Zeile gelöscht : user_pref("extensions.toolbar_ORJ-V7C@apn.ask.com.install-event-fired", true); Zeile gelöscht : user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=146&itype=n&ver=13001&tm=385&src=ds&p="); -\\ Google Chrome v ************************* AdwCleaner[R0].txt - [6239 octets] - [25/06/2014 14:10:18] AdwCleaner[S0].txt - [5222 octets] - [25/06/2014 14:12:34] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5282 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Professional x64 Ran by Maeph on 25.06.2014 at 14:15:48.80 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{093564D6-DF51-499E-B193-C5E166FE482A} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{093564D6-DF51-499E-B193-C5E166FE482A} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Maeph\AppData\Roaming\mozilla\firefox\profiles\9i0953h4.default\minidumps [14 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 25.06.2014 at 14:19:28.45 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2014 Ran by Maeph (administrator) on MAEPH-HP on 25-06-2014 14:20:50 Running from C:\Users\Maeph\Downloads Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Bose Corporation) C:\Program Files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch music server.exe () C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MfeEpePcMonitor] => C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [200704 2011-07-13] () HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1179576 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.) HKLM-x32\...\Run: [HP KEYBOARDx] => C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE [710656 2010-02-11] (Hewlett-Packard) HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-05-06] (PDF Complete Inc) HKLM-x32\...\Run: [File Sanitizer] => c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [12277248 2011-05-10] (Hewlett-Packard) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [SoundTouch Music Server] => C:\Program Files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch music server.exe [1062912 2014-04-09] (Bose Corporation) Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X] HKU\S-1-5-21-1490942193-3814011691-1127731215-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [15146376 2011-04-18] (Skype Technologies S.A.) Lsa: [Notification Packages] DPPassFilter scecli Startup: C:\Users\Maeph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {093564D6-DF51-499E-B193-C5E166FE482A} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5222-111091-7834-8/4?satitle={searchTerms} SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5222-111091-7834-8/4?satitle={searchTerms} SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5222-111091-7834-8/4?satitle={searchTerms} BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll No File BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.192.1 FireFox: ======== FF ProfilePath: C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF SearchPlugin: C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ask Toolbar - C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-03-26] FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt FF Extension: DigitalPersona Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2011-11-24] FF HKCU\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\extensions\cliqz@cliqz.com Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [485712 2011-05-19] (DigitalPersona, Inc.) S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [464440 2011-05-10] (Hewlett-Packard Company) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] R2 HPAuto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [682040 2011-02-17] (Hewlett-Packard) R2 HPFSService; c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [320512 2011-05-10] (Hewlett-Packard) [File not signed] R2 McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [1318912 2011-07-13] () [File not signed] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation) R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-06] (PDF Complete Inc) ==================== Drivers (Whitelisted) ==================== S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [64312 2011-05-10] (Hewlett-Packard Company) R0 MfeEpeOpal; C:\Windows\System32\Drivers\MfeEpeOpal.sys [91080 2011-07-13] (McAfee, Inc.) R0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [158280 2011-07-13] (McAfee, Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) S3 OxPPort; C:\Windows\system32\drivers\OxPPort.sys [98304 2008-07-31] (OEM) S3 OxSer; C:\Windows\system32\drivers\OxSer.sys [98352 2009-09-16] (OEM) S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2011-11-24] () S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-25 14:20 - 2014-06-25 14:20 - 00012468 _____ () C:\Users\Maeph\Downloads\FRST.txt 2014-06-25 14:19 - 2014-06-25 14:19 - 00001050 _____ () C:\Users\Maeph\Desktop\JRT.txt 2014-06-25 14:15 - 2014-06-25 14:15 - 00000000 ____D () C:\Windows\ERUNT 2014-06-25 14:14 - 2014-06-25 14:14 - 00005374 _____ () C:\Users\Maeph\Desktop\AdwCleaner[S0].txt 2014-06-25 14:10 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-25 14:09 - 2014-06-25 14:10 - 01016261 _____ (Thisisu) C:\Users\Maeph\Downloads\JRT.exe 2014-06-25 14:08 - 2014-06-25 14:12 - 00000000 ____D () C:\AdwCleaner 2014-06-25 14:08 - 2014-06-25 14:08 - 01342659 _____ () C:\Users\Maeph\Downloads\adwcleaner_3.213.exe 2014-06-25 13:21 - 2014-06-25 13:21 - 00031488 _____ () C:\ComboFix.txt 2014-06-25 13:12 - 2014-06-25 13:21 - 00000000 ____D () C:\Qoobox 2014-06-25 13:12 - 2014-06-25 13:21 - 00000000 ____D () C:\ComboFix 2014-06-25 13:12 - 2014-06-25 13:20 - 00000000 ____D () C:\Windows\erdnt 2014-06-25 13:12 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-25 13:12 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-25 13:12 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-25 13:12 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-25 13:12 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-25 13:12 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-25 13:12 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-25 13:12 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-25 13:11 - 2014-06-25 13:11 - 05211571 ____R (Swearware) C:\Users\Maeph\Downloads\ComboFix.exe 2014-06-25 09:33 - 2014-06-25 09:33 - 01110476 _____ () C:\Users\Maeph\Downloads\7z920.exe 2014-06-25 09:33 - 2014-06-25 09:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-06-25 09:33 - 2014-06-25 09:33 - 00000000 ____D () C:\Program Files (x86)\7-Zip 2014-06-24 23:34 - 2014-06-25 14:20 - 00000000 ____D () C:\FRST 2014-06-24 23:33 - 2014-06-24 23:33 - 02082816 _____ (Farbar) C:\Users\Maeph\Downloads\FRST64.exe 2014-06-24 23:24 - 2014-06-24 23:24 - 00003150 _____ () C:\Windows\System32\Tasks\{9906AFC3-9716-45DC-93A7-E5EA5CE49D38} 2014-06-24 23:13 - 2014-06-24 23:16 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-06-24 23:10 - 2014-06-24 23:10 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Maeph\Downloads\avira_de_av___ws.exe 2014-06-21 22:30 - 2014-06-21 22:30 - 00001507 _____ () C:\Users\Maeph\Desktop\AgeOfConan - Verknüpfung.lnk 2014-06-21 21:55 - 2014-06-21 21:55 - 00024210 _____ () C:\Users\Maeph\Downloads\D2A590AAAA1D0539E1913CBA05228D02CC11ADFD.torrent 2014-06-21 21:53 - 2014-06-24 23:21 - 00000000 ____D () C:\ProgramData\527dd4c7744378ff 2014-06-21 21:53 - 2014-06-21 21:53 - 00000442 __RSH () C:\ProgramData\ntuser.pol 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Packages 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator 2014-06-21 21:52 - 2014-06-21 21:52 - 02044896 _____ () C:\Users\Maeph\Downloads\Star_Wars_Galaxies__Pre_CU_(including_Patches_00-13).exe 2014-06-21 21:50 - 2014-06-25 13:18 - 00003476 _____ () C:\Windows\System32\Tasks\GPUpdateCheck 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\smi 2014-06-21 21:48 - 2014-06-21 21:48 - 02044896 _____ () C:\Users\Maeph\Downloads\SWG_Pre-CU.exe 2014-06-21 21:46 - 2014-06-21 21:46 - 00003118 _____ () C:\Windows\System32\Tasks\{FFC2A938-BEC4-4947-B5D2-A2FA289E2E4F} 2014-06-21 21:42 - 2014-06-21 21:42 - 39833841 _____ (SWGEmu) C:\Users\Maeph\Downloads\setup(1).exe 2014-06-21 21:42 - 2014-06-21 21:42 - 00002777 _____ () C:\Users\Public\Desktop\SWGEmu Launchpad.lnk 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Downloaded Installations 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SWGEmu 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\Program Files (x86)\SWGEmu 2014-06-21 21:41 - 2014-06-24 23:23 - 00000000 ____D () C:\Users\Maeph\AppData\Local\CrashDumps 2014-06-21 21:40 - 2014-06-24 23:09 - 00000000 ____D () C:\ProgramData\BOINC 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Windows\Downloaded Installations 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Program Files (x86)\Sony 2014-06-21 21:35 - 2014-06-21 21:35 - 00357776 _____ (Softonic) C:\Users\Maeph\Downloads\SoftonicDownloader_fuer_star-wars-galaxies-an-empire-divided.exe 2014-06-21 20:47 - 2014-06-21 20:47 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\BEGAware 2014-06-21 15:46 - 2014-06-21 15:49 - 04389376 _____ (BEGAware) C:\Users\Maeph\Desktop\PicturePuzzle.exe 2014-06-21 13:28 - 2014-06-21 13:28 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Funcom 2014-06-21 13:27 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-06-21 13:27 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-06-21 13:27 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-06-21 13:27 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-06-21 13:27 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-06-21 13:27 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-06-21 13:27 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-06-21 13:27 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2014-06-21 13:27 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-06-21 13:27 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-06-21 13:27 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-06-21 13:27 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-06-21 13:27 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-06-21 13:27 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-06-21 13:27 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-06-21 13:27 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-06-21 13:27 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-06-21 13:27 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-06-21 13:27 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-06-21 13:27 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-06-21 13:27 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2014-06-21 13:27 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-06-21 13:27 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2014-06-21 13:27 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2014-06-21 13:27 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-06-21 13:27 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2014-06-21 13:27 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-06-21 13:27 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2014-06-21 13:27 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-06-21 13:27 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-06-21 13:27 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-06-21 13:27 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-06-21 13:27 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-06-21 13:27 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-06-21 13:27 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-06-21 13:27 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-06-21 13:27 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-06-21 13:27 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-06-21 13:27 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-06-21 13:27 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-06-21 13:27 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-06-21 13:27 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-06-21 13:27 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-06-21 13:27 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-06-21 13:27 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-06-21 13:27 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-06-21 13:27 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-06-21 13:27 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-06-21 13:27 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-06-21 13:27 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-06-21 13:27 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-06-21 13:27 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-06-21 13:27 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-06-21 13:27 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-06-21 13:27 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-06-21 13:27 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-06-21 13:27 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-06-21 13:27 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-06-21 13:27 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-06-21 13:27 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-06-21 13:27 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-06-21 13:27 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-06-21 13:27 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-06-21 13:27 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-06-21 13:27 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-06-21 13:27 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-06-21 13:27 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-06-21 13:27 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-06-21 13:27 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-06-21 13:27 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2014-06-21 13:27 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-06-21 13:27 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-06-21 13:27 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-06-21 13:27 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-06-21 13:27 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-06-21 13:27 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-06-21 13:27 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-06-21 13:27 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-06-21 13:27 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-06-21 13:27 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-06-21 13:27 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-06-21 13:27 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-06-21 13:27 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-06-21 13:27 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-06-21 13:26 - 2014-06-21 13:27 - 00010009 _____ () C:\Windows\DirectX.log 2014-06-21 13:26 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-06-21 13:26 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-06-21 13:26 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-06-21 13:26 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2014-06-21 13:26 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-06-21 13:26 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-06-21 13:26 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-06-21 13:26 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-06-21 13:26 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-06-21 13:26 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-06-21 13:26 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2014-06-21 13:26 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-06-21 13:26 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-06-21 13:26 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2014-06-21 13:26 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-06-21 13:26 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2014-06-21 13:26 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-06-21 13:26 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2014-06-21 13:26 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-06-21 13:26 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2014-06-21 13:26 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-06-21 13:26 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2014-06-21 13:26 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-06-21 13:26 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2014-06-21 13:26 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-06-21 13:26 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2014-06-21 13:26 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-06-21 13:26 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2014-06-21 13:26 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-06-21 13:26 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2014-06-21 13:26 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-06-21 13:26 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2014-06-21 13:26 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-06-21 13:26 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2014-06-21 13:25 - 2014-06-21 13:27 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-06-21 13:25 - 2014-06-21 13:26 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-06-21 13:25 - 2014-06-21 13:25 - 20858106 _____ (Funcom ) C:\Users\Maeph\Downloads\ageofconan-de.exe 2014-06-21 13:25 - 2014-06-21 13:25 - 00000000 ____D () C:\Program Files (x86)\Funcom 2014-06-21 11:14 - 2014-06-21 11:14 - 14994368 _____ () C:\Users\Maeph\Downloads\Setup_Railroad_Tycoon.exe 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\2K Games 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Games 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\Program Files (x86)\2K Games 2014-06-20 14:21 - 2014-06-21 11:14 - 01058200 _____ (Adobe) C:\Users\Maeph\Downloads\install_flashplayer14x32au_ltr5x64d_awc_aih.exe 2014-06-16 10:51 - 2014-06-16 11:26 - 00042302 _____ () C:\Users\Maeph\Desktop\Lebenslauf Vorlage.odt 2014-06-16 10:48 - 2014-06-16 10:48 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.0.lnk 2014-06-16 10:48 - 2014-06-16 10:48 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0 2014-06-16 10:48 - 2014-06-16 10:48 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\OpenOffice 2014-06-16 10:47 - 2014-06-16 10:47 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-06-16 10:46 - 2014-06-16 10:46 - 00000000 ____D () C:\Users\Maeph\Desktop\OpenOffice 4.1.0 (de) Installation Files 2014-06-16 10:44 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll 2014-06-16 10:44 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll 2014-06-16 10:43 - 2014-06-16 10:43 - 00961360 _____ (Chip Digital GmbH) C:\Users\Maeph\Downloads\OpenOffice - CHIP-Installer.exe 2014-06-10 22:44 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-10 22:44 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-10 22:44 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-10 22:44 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-10 22:44 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-10 22:44 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-10 22:44 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-10 22:44 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-10 22:44 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-10 22:44 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-10 22:44 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-10 22:44 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-10 22:44 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-10 22:44 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-10 22:44 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-10 22:44 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-10 22:44 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-10 22:44 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-10 22:44 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-10 22:44 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-10 22:44 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-10 22:44 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-06-10 22:44 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-10 22:44 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-10 22:44 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-06-10 22:44 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-10 22:44 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-10 22:44 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-10 22:44 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-10 22:44 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-06-10 22:44 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-10 22:44 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-06-10 22:44 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-06-10 22:44 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-10 22:44 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-10 22:44 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-10 22:44 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-10 22:44 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-10 22:44 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-10 22:44 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-10 22:44 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-10 22:44 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-10 22:44 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-10 22:44 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-06-10 22:44 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-10 22:44 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-10 22:44 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-10 22:44 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-10 22:44 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-10 22:44 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-10 22:44 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-10 22:44 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-06-10 22:44 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-10 22:44 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-10 22:44 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-10 22:44 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2014-06-10 22:44 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-10 22:44 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-10 22:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2014-06-10 22:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-06-10 22:44 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-10 22:44 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-10 22:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2014-06-10 22:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-06-10 22:42 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-10 22:42 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-04 08:33 - 2014-06-04 08:43 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\SoundTouchPersist 2014-06-04 08:33 - 2014-06-04 08:33 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\SoundTouch 2014-06-04 08:32 - 2014-06-04 08:33 - 00000000 ____D () C:\Program Files (x86)\SoundTouch 2014-06-04 08:32 - 2014-06-04 08:32 - 00001911 _____ () C:\Users\Public\Desktop\SoundTouch.lnk 2014-06-04 08:32 - 2014-06-04 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundTouch 2014-06-04 08:31 - 2014-06-04 08:32 - 50130944 _____ () C:\Users\Maeph\Downloads\SoundTouch-app-installer-5.0.21.6712.msi 2014-06-02 22:21 - 2014-06-02 22:21 - 00001333 _____ () C:\Users\Maeph\Desktop\6b94eeecf0a3a536c6e0a362a2d954cd13789e37d54a4b2f6f25561ed90d6629836d56c143dae7bde29b3e4952886629d810ed806388959351b0ac47d9bc652e.htm ==================== One Month Modified Files and Folders ======= 2014-06-25 14:21 - 2014-06-25 14:20 - 00012468 _____ () C:\Users\Maeph\Downloads\FRST.txt 2014-06-25 14:20 - 2014-06-24 23:34 - 00000000 ____D () C:\FRST 2014-06-25 14:20 - 2009-07-14 06:45 - 00027568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-25 14:20 - 2009-07-14 06:45 - 00027568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-25 14:19 - 2014-06-25 14:19 - 00001050 _____ () C:\Users\Maeph\Desktop\JRT.txt 2014-06-25 14:17 - 2014-04-07 17:28 - 00001013 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-06-25 14:16 - 2014-05-09 15:48 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Skype 2014-06-25 14:15 - 2014-06-25 14:15 - 00000000 ____D () C:\Windows\ERUNT 2014-06-25 14:14 - 2014-06-25 14:14 - 00005374 _____ () C:\Users\Maeph\Desktop\AdwCleaner[S0].txt 2014-06-25 14:13 - 2011-11-24 06:33 - 00000000 ____D () C:\ProgramData\PDFC 2014-06-25 14:13 - 2011-11-24 06:18 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-06-25 14:13 - 2010-11-21 05:47 - 00946800 _____ () C:\Windows\PFRO.log 2014-06-25 14:13 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-25 14:13 - 2009-07-14 06:51 - 00054163 _____ () C:\Windows\setupact.log 2014-06-25 14:12 - 2014-06-25 14:08 - 00000000 ____D () C:\AdwCleaner 2014-06-25 14:12 - 2014-04-07 18:07 - 01680313 _____ () C:\Windows\WindowsUpdate.log 2014-06-25 14:10 - 2014-06-25 14:09 - 01016261 _____ (Thisisu) C:\Users\Maeph\Downloads\JRT.exe 2014-06-25 14:08 - 2014-06-25 14:08 - 01342659 _____ () C:\Users\Maeph\Downloads\adwcleaner_3.213.exe 2014-06-25 13:39 - 2014-05-10 00:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-25 13:21 - 2014-06-25 13:21 - 00031488 _____ () C:\ComboFix.txt 2014-06-25 13:21 - 2014-06-25 13:12 - 00000000 ____D () C:\Qoobox 2014-06-25 13:21 - 2014-06-25 13:12 - 00000000 ____D () C:\ComboFix 2014-06-25 13:21 - 2014-05-06 18:41 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Apps\2.0 2014-06-25 13:21 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-06-25 13:20 - 2014-06-25 13:12 - 00000000 ____D () C:\Windows\erdnt 2014-06-25 13:18 - 2014-06-21 21:50 - 00003476 _____ () C:\Windows\System32\Tasks\GPUpdateCheck 2014-06-25 13:18 - 2011-11-24 06:35 - 00000000 ____D () C:\ProgramData\Norton 2014-06-25 13:18 - 2009-07-14 06:45 - 00295704 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-25 13:18 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-06-25 13:17 - 2009-07-14 04:34 - 66846720 _____ () C:\Windows\system32\config\SOFTWARE.bak 2014-06-25 13:17 - 2009-07-14 04:34 - 15204352 _____ () C:\Windows\system32\config\SYSTEM.bak 2014-06-25 13:17 - 2009-07-14 04:34 - 00786432 _____ () C:\Windows\system32\config\DEFAULT.bak 2014-06-25 13:17 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2014-06-25 13:17 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2014-06-25 13:11 - 2014-06-25 13:11 - 05211571 ____R (Swearware) C:\Users\Maeph\Downloads\ComboFix.exe 2014-06-25 13:11 - 2014-05-06 18:41 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Deployment 2014-06-25 13:11 - 2014-04-07 17:17 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Battle.net 2014-06-25 12:04 - 2014-05-09 15:25 - 00000000 ____D () C:\ProgramData\Package Cache 2014-06-25 09:33 - 2014-06-25 09:33 - 01110476 _____ () C:\Users\Maeph\Downloads\7z920.exe 2014-06-25 09:33 - 2014-06-25 09:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-06-25 09:33 - 2014-06-25 09:33 - 00000000 ____D () C:\Program Files (x86)\7-Zip 2014-06-25 09:07 - 2014-05-06 19:19 - 00003186 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForMaeph 2014-06-25 09:07 - 2014-05-06 19:19 - 00000332 _____ () C:\Windows\Tasks\HPCeeScheduleForMaeph.job 2014-06-24 23:50 - 2014-04-07 17:28 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\TS3Client 2014-06-24 23:44 - 2014-04-07 17:13 - 00064024 _____ () C:\Users\Maeph\AppData\Local\GDIPFONTCACHEV1.DAT 2014-06-24 23:33 - 2014-06-24 23:33 - 02082816 _____ (Farbar) C:\Users\Maeph\Downloads\FRST64.exe 2014-06-24 23:24 - 2014-06-24 23:24 - 00003150 _____ () C:\Windows\System32\Tasks\{9906AFC3-9716-45DC-93A7-E5EA5CE49D38} 2014-06-24 23:23 - 2014-06-21 21:41 - 00000000 ____D () C:\Users\Maeph\AppData\Local\CrashDumps 2014-06-24 23:21 - 2014-06-21 21:53 - 00000000 ____D () C:\ProgramData\527dd4c7744378ff 2014-06-24 23:20 - 2014-04-30 03:12 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-06-24 23:20 - 2011-11-24 06:23 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-06-24 23:19 - 2014-05-13 19:09 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-06-24 23:16 - 2014-06-24 23:13 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-06-24 23:10 - 2014-06-24 23:10 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Maeph\Downloads\avira_de_av___ws.exe 2014-06-24 23:09 - 2014-06-21 21:40 - 00000000 ____D () C:\ProgramData\BOINC 2014-06-24 23:04 - 2014-04-07 17:12 - 00003930 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{96A4DA01-74A4-4AF6-B1B6-DB7946587841} 2014-06-22 09:23 - 2014-05-06 18:35 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\NVIDIA 2014-06-21 22:30 - 2014-06-21 22:30 - 00001507 _____ () C:\Users\Maeph\Desktop\AgeOfConan - Verknüpfung.lnk 2014-06-21 21:55 - 2014-06-21 21:55 - 00024210 _____ () C:\Users\Maeph\Downloads\D2A590AAAA1D0539E1913CBA05228D02CC11ADFD.torrent 2014-06-21 21:53 - 2014-06-21 21:53 - 00000442 __RSH () C:\ProgramData\ntuser.pol 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Packages 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Gast 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-06-21 21:53 - 2014-06-21 21:53 - 00000000 ____D () C:\Users\Administrator 2014-06-21 21:53 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-06-21 21:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-06-21 21:52 - 2014-06-21 21:52 - 02044896 _____ () C:\Users\Maeph\Downloads\Star_Wars_Galaxies__Pre_CU_(including_Patches_00-13).exe 2014-06-21 21:50 - 2014-06-21 21:50 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\smi 2014-06-21 21:48 - 2014-06-21 21:48 - 02044896 _____ () C:\Users\Maeph\Downloads\SWG_Pre-CU.exe 2014-06-21 21:46 - 2014-06-21 21:46 - 00003118 _____ () C:\Windows\System32\Tasks\{FFC2A938-BEC4-4947-B5D2-A2FA289E2E4F} 2014-06-21 21:42 - 2014-06-21 21:42 - 39833841 _____ (SWGEmu) C:\Users\Maeph\Downloads\setup(1).exe 2014-06-21 21:42 - 2014-06-21 21:42 - 00002777 _____ () C:\Users\Public\Desktop\SWGEmu Launchpad.lnk 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Downloaded Installations 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SWGEmu 2014-06-21 21:42 - 2014-06-21 21:42 - 00000000 ____D () C:\Program Files (x86)\SWGEmu 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Windows\Downloaded Installations 2014-06-21 21:40 - 2014-06-21 21:40 - 00000000 ____D () C:\Program Files (x86)\Sony 2014-06-21 21:35 - 2014-06-21 21:35 - 00357776 _____ (Softonic) C:\Users\Maeph\Downloads\SoftonicDownloader_fuer_star-wars-galaxies-an-empire-divided.exe 2014-06-21 20:47 - 2014-06-21 20:47 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\BEGAware 2014-06-21 15:49 - 2014-06-21 15:46 - 04389376 _____ (BEGAware) C:\Users\Maeph\Desktop\PicturePuzzle.exe 2014-06-21 13:28 - 2014-06-21 13:28 - 00000000 ____D () C:\Users\Maeph\AppData\Local\Funcom 2014-06-21 13:27 - 2014-06-21 13:26 - 00010009 _____ () C:\Windows\DirectX.log 2014-06-21 13:27 - 2014-06-21 13:25 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-06-21 13:27 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-21 13:26 - 2014-06-21 13:25 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-06-21 13:25 - 2014-06-21 13:25 - 20858106 _____ (Funcom ) C:\Users\Maeph\Downloads\ageofconan-de.exe 2014-06-21 13:25 - 2014-06-21 13:25 - 00000000 ____D () C:\Program Files (x86)\Funcom 2014-06-21 11:14 - 2014-06-21 11:14 - 14994368 _____ () C:\Users\Maeph\Downloads\Setup_Railroad_Tycoon.exe 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\2K Games 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Games 2014-06-21 11:14 - 2014-06-21 11:14 - 00000000 ____D () C:\Program Files (x86)\2K Games 2014-06-21 11:14 - 2014-06-20 14:21 - 01058200 _____ (Adobe) C:\Users\Maeph\Downloads\install_flashplayer14x32au_ltr5x64d_awc_aih.exe 2014-06-20 14:06 - 2014-04-07 17:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-20 01:05 - 2014-05-10 12:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-17 16:46 - 2014-04-07 17:21 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft 2014-06-17 16:32 - 2011-11-24 05:57 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-06-17 16:32 - 2011-11-24 05:57 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-06-17 16:32 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-16 11:26 - 2014-06-16 10:51 - 00042302 _____ () C:\Users\Maeph\Desktop\Lebenslauf Vorlage.odt 2014-06-16 11:18 - 2014-05-20 09:59 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-06-16 10:48 - 2014-06-16 10:48 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.0.lnk 2014-06-16 10:48 - 2014-06-16 10:48 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0 2014-06-16 10:48 - 2014-06-16 10:48 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\OpenOffice 2014-06-16 10:47 - 2014-06-16 10:47 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-06-16 10:46 - 2014-06-16 10:46 - 00000000 ____D () C:\Users\Maeph\Desktop\OpenOffice 4.1.0 (de) Installation Files 2014-06-16 10:43 - 2014-06-16 10:43 - 00961360 _____ (Chip Digital GmbH) C:\Users\Maeph\Downloads\OpenOffice - CHIP-Installer.exe 2014-06-11 22:00 - 2014-04-07 17:17 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-06-11 19:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-06-11 03:00 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-08 11:13 - 2014-06-10 22:42 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-08 11:08 - 2014-06-10 22:42 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-04 08:43 - 2014-06-04 08:33 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\SoundTouchPersist 2014-06-04 08:33 - 2014-06-04 08:33 - 00000000 ____D () C:\Users\Maeph\AppData\Roaming\SoundTouch 2014-06-04 08:33 - 2014-06-04 08:32 - 00000000 ____D () C:\Program Files (x86)\SoundTouch 2014-06-04 08:33 - 2011-11-24 06:24 - 00008490 _____ () C:\Windows\DPINST.LOG 2014-06-04 08:32 - 2014-06-04 08:32 - 00001911 _____ () C:\Users\Public\Desktop\SoundTouch.lnk 2014-06-04 08:32 - 2014-06-04 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundTouch 2014-06-04 08:32 - 2014-06-04 08:31 - 50130944 _____ () C:\Users\Maeph\Downloads\SoundTouch-app-installer-5.0.21.6712.msi 2014-06-02 22:21 - 2014-06-02 22:21 - 00001333 _____ () C:\Users\Maeph\Desktop\6b94eeecf0a3a536c6e0a362a2d954cd13789e37d54a4b2f6f25561ed90d6629836d56c143dae7bde29b3e4952886629d810ed806388959351b0ac47d9bc652e.htm 2014-05-30 12:21 - 2014-06-10 22:44 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-30 12:02 - 2014-06-10 22:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-30 12:02 - 2014-06-10 22:44 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-05-30 11:45 - 2014-06-10 22:44 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-30 11:39 - 2014-06-10 22:44 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-30 11:39 - 2014-06-10 22:44 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-05-30 11:38 - 2014-06-10 22:44 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-05-30 11:28 - 2014-06-10 22:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-30 11:27 - 2014-06-10 22:44 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-05-30 11:24 - 2014-06-10 22:44 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-05-30 11:21 - 2014-06-10 22:44 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-30 11:21 - 2014-06-10 22:44 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-05-30 11:20 - 2014-06-10 22:44 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-05-30 11:18 - 2014-06-10 22:44 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-30 11:11 - 2014-06-10 22:44 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-05-30 11:08 - 2014-06-10 22:44 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-30 11:06 - 2014-06-10 22:44 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-30 11:02 - 2014-06-10 22:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-30 10:55 - 2014-06-10 22:44 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-05-30 10:49 - 2014-06-10 22:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-05-30 10:46 - 2014-06-10 22:44 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-30 10:44 - 2014-06-10 22:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-05-30 10:44 - 2014-06-10 22:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-30 10:43 - 2014-06-10 22:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-05-30 10:42 - 2014-06-10 22:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-05-30 10:38 - 2014-06-10 22:44 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-05-30 10:35 - 2014-06-10 22:44 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-05-30 10:34 - 2014-06-10 22:44 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-05-30 10:33 - 2014-06-10 22:44 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-05-30 10:30 - 2014-06-10 22:44 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-05-30 10:29 - 2014-06-10 22:44 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-30 10:28 - 2014-06-10 22:44 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-05-30 10:27 - 2014-06-10 22:44 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-05-30 10:24 - 2014-06-10 22:44 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-05-30 10:23 - 2014-06-10 22:44 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-30 10:16 - 2014-06-10 22:44 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-05-30 10:10 - 2014-06-10 22:44 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-05-30 10:06 - 2014-06-10 22:44 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-05-30 10:04 - 2014-06-10 22:44 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-30 10:02 - 2014-06-10 22:44 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-05-30 09:56 - 2014-06-10 22:44 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-05-30 09:56 - 2014-06-10 22:44 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-30 09:54 - 2014-06-10 22:44 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-05-30 09:50 - 2014-06-10 22:44 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-05-30 09:49 - 2014-06-10 22:44 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-05-30 09:43 - 2014-06-10 22:44 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-30 09:40 - 2014-06-10 22:44 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-05-30 09:30 - 2014-06-10 22:44 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-30 09:21 - 2014-06-10 22:44 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-05-30 09:15 - 2014-06-10 22:44 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-05-30 09:13 - 2014-06-10 22:44 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-05-30 09:13 - 2014-06-10 22:44 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Some content of TEMP: ==================== C:\Users\Maeph\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-18 12:58 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-06-2014 Ran by Maeph at 2014-06-25 14:27:28 Running from C:\Users\Maeph\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19120 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 2.6.0.19120 - Adobe Systems Incorporated) Hidden Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden Age of Conan: Unchained (HKLM-x32\...\Age of Conan_is1) (Version: - Funcom) Ask Toolbar (HKLM-x32\...\{4F524A2D-5637-4300-76A7-A758B70C0C02}) (Version: 12.12.2.83 - APN, LLC) <==== ATTENTION Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden Blasterball 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden Bounce Symphony (x32 Version: 2.2.0.97 - WildTangent) Hidden Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden Chronicles of Albian (x32 Version: 2.2.0.95 - WildTangent) Hidden Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.4.1.3 - Cliqz.com) Cradle of Rome 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Curse Client (HKCU\...\101a9f93b8f0bb6f) (Version: 5.1.1.810 - Curse) Device Access Manager for HP ProtectTools (HKLM\...\{55B52830-024A-443E-AF61-61E1E71AFA1B}) (Version: 6.0.0.12 - Hewlett-Packard Company) DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden Drive Encryption For HP ProtectTools (HKLM\...\{8A0041CD-277C-4C1F-BFE4-7AC508B20B4C}) (Version: 6.0.79.26218 - Hewlett-Packard Company) Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden File Sanitizer For HP ProtectTools (HKLM-x32\...\{6D6ADF03-B257-4EA5-BBC1-1D145AF8D514}) (Version: 6.0.0.13 - Hewlett-Packard Company) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Auto (Version: 1.0.12935.3667 - Hewlett-Packard Company) Hidden HP Client Services (Version: 1.1.12938.3539 - Hewlett-Packard) Hidden HP Connect Solutions (HKLM-x32\...\{BE1C9464-DEBB-4DA6-B19A-8EC634F22D73}) (Version: 1.0.0.4 - Hewlett-Packard) HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Desktop Keyboard (HKLM-x32\...\HP Keyboard_is1) (Version: 1.0.0.13 - Hewlett-Packard) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent) HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard) HP ProtectTools Security Manager (HKLM\...\HPProtectTools) (Version: 6.03.959 - Hewlett-Packard Company) HP ProtectTools Security Manager (Version: 6.03.959 - Hewlett-Packard Company) Hidden HP Setup (HKLM-x32\...\{03046EBB-CB7C-4B98-BEFB-690EB955DA22}) (Version: 8.5.4526.3645 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13880.3792 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard) HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.9.0.0 - Hewlett-Packard) Intel(R) Identity Protection Technology 1.1.2.0 (HKLM-x32\...\{C01A86F5-56E7-101F-9BC9-E3F1025EB779}) (Version: 1.1.2.0 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden Jewel Quest: The Sleepless Star - Collector's Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.154 - Logitech Inc.) Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Mystery of Mortlake Mansion (x32 Version: 2.2.0.97 - WildTangent) Hidden Namco All-Stars: PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden NVIDIA 3D Vision Controller-Treiber 335.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 335.21 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation) OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.54 - PDF Complete, Inc) Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6387 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.0.4222 - CyberLink Corp.) Hidden Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) SHIELD Streaming (Version: 1.7.321 - NVIDIA Corporation) Hidden Sid Meier's Railroad Tycoon (HKLM-x32\...\Sid Meier's Railroad Tycoon) (Version: 1.0 - 2K Games) Skype™ 5.3 (HKLM-x32\...\{5335DADB-34BA-4AE8-A519-648D78498846}) (Version: 5.3.111 - Skype Technologies S.A.) Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden SoundTouch (HKLM-x32\...\{2BE5D5D5-8279-41A7-88A4-96760E553952}) (Version: 5.0.21.6712 - BOSE) SWGEmu Launchpad (HKLM-x32\...\{37A10E4F-B984-462D-A33E-6C3D74CB1299}) (Version: 0.22 - SWGEmu) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Vacation Quest - The Hawaiian Islands (x32 Version: 2.2.0.97 - WildTangent) Hidden VIP Access SDK (1.0.1.4) (HKLM-x32\...\VIP Access SDK) (Version: 1.0.1.4 - Symantec Inc.) Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden WildTangent Games App (HP Games) (x32 Version: 4.0.5.2 - WildTangent) Hidden World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) Zinio Reader 4 (HKLM-x32\...\ZinioReader4) (Version: 4.2.4164 - Zinio LLC) Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Restore Points ========================= 10-06-2014 20:42:09 Windows Update 11-06-2014 01:00:22 Windows Update 15-06-2014 20:52:29 Windows Update 16-06-2014 08:46:16 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 16-06-2014 08:46:53 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 16-06-2014 08:47:40 OpenOffice 4.1.0 wird installiert 21-06-2014 02:53:19 Windows Update 21-06-2014 11:26:36 DirectX wurde installiert 21-06-2014 19:40:01 Installed Star Wars Galaxies 21-06-2014 19:42:35 Installed SWGEmu Launchpad. 21-06-2014 19:45:49 Installed Star Wars Galaxies 21-06-2014 19:46:39 Configured Star Wars Galaxies 21-06-2014 19:49:39 Removed Star Wars Galaxies 24-06-2014 21:02:22 Windows Update 24-06-2014 21:12:44 Removed Charity Engine. 24-06-2014 21:17:52 Konfiguriert LabelPrint 24-06-2014 21:19:24 Konfiguriert Power2Go ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-06-25 13:18 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {16AA6967-B2BF-4FFF-A32A-5C483F31CC3E} - System32\Tasks\HPCeeScheduleForMaeph => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard) Task: {42234625-4890-4613-BC69-8A10FA9D9FA0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated) Task: {4E5EA3AE-9638-492E-867C-8D49974A226D} - \GPUpdate No Task File <==== ATTENTION Task: {5ADFF536-AF8F-4E5E-9BED-D302D2868FCD} - System32\Tasks\GPUpdateCheck => C:\Program Files (x86)\GetPrivate\gpup.exe Task: {6E09EEAE-13A8-4702-A703-B0179907F8C0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {AE9911AA-99C6-47F3-AF98-27686D0733AC} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2011-01-25] () Task: {B2E0D5BE-32A0-4549-B412-796E56EF95F4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {C9FA59A3-C3ED-4C6F-934D-38E564F221C9} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\HPCeeScheduleForMaeph.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2014-04-11 09:24 - 2014-04-11 09:24 - 00034304 _____ () C:\Windows\System32\sst6clm.dll 2011-07-13 02:49 - 2011-07-13 02:49 - 03371520 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpeHpFve64.dll 2011-07-13 02:42 - 2011-07-13 02:42 - 01929728 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcNp64.DLL 2014-04-07 19:51 - 2014-03-04 15:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2011-07-13 02:11 - 2011-07-13 02:11 - 01318912 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe 2011-07-13 02:36 - 2011-07-13 02:36 - 00200704 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe 2014-02-11 20:21 - 2014-02-11 20:21 - 00860160 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 01043968 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-02-11 20:21 - 2014-02-11 20:21 - 00052736 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 00236032 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2011-11-24 06:29 - 2009-07-03 00:58 - 00406016 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe 2011-07-13 02:33 - 2011-07-13 02:33 - 02834432 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcEncryptionProviderPlugin.dll 2011-07-13 02:10 - 2011-07-13 02:10 - 00126976 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHostInterface.dll 2011-07-13 02:32 - 2011-07-13 02:32 - 03100672 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpeOpalEncryptionProviderPlugin.dll 2011-07-13 02:35 - 2011-07-13 02:35 - 02854912 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpeHpDpHostPlugin.dll 2011-07-13 02:34 - 2011-07-13 02:34 - 00053248 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpeOpalATASec4SATA.dll 2011-07-13 02:13 - 2011-07-13 02:13 - 02035712 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeCoreEncryptionPlugin.dll 2011-07-13 02:14 - 2011-07-13 02:14 - 01929216 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeProductDetectionPlugin.dll 2014-05-10 12:22 - 2014-06-20 01:05 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-05-14 17:39 - 2014-05-14 17:39 - 16361136 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-06-25 13:16:28.831 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-06-25 13:16:28.800 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 22% Total physical RAM: 8172.82 MB Available physical RAM: 6338.36 MB Total Pagefile: 16343.81 MB Available Pagefile: 14376.77 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:917.86 GB) (Free:817.15 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (HP_RECOVERY) (Fixed) (Total:13.55 GB) (Free:1.67 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (SAMSUNG_CLBP) (CDROM) (Total:0.22 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ==================== End Of Log ============================ |
25.06.2014, 14:00 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | GS Supporter 1.80 auf dem Rechner Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File FF Extension: Ask Toolbar - C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-03-26] Task: {4E5EA3AE-9638-492E-867C-8D49974A226D} - \GPUpdate No Task File <==== ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
25.06.2014, 17:10 | #13 |
| GS Supporter 1.80 auf dem Rechner Ok auch das ist erledigt: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 22-06-2014 Ran by Maeph at 2014-06-25 18:04:36 Run:1 Running from C:\Users\Maeph\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File FF Extension: Ask Toolbar - C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-03-26] Task: {4E5EA3AE-9638-492E-867C-8D49974A226D} - \GPUpdate No Task File <==== ATTENTION ***************** C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value deleted successfully. 'HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}'=> Key not found. C:\Users\Maeph\AppData\Roaming\Mozilla\Firefox\Profiles\9i0953h4.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4E5EA3AE-9638-492E-867C-8D49974A226D}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E5EA3AE-9638-492E-867C-8D49974A226D}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GPUpdate' => Key deleted successfully. The system needed a reboot. ==== End of Fixlog ==== |
26.06.2014, 08:48 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | GS Supporter 1.80 auf dem Rechner Okay, dann Kontrollscans mit MBAM und ESET bitte: Downloade Dir bitte Malwarebytes Anti-Malware
ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
26.06.2014, 09:56 | #15 |
| GS Supporter 1.80 auf dem Rechner Alles klar hier die Berichte: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 26.06.2014 Suchlauf-Zeit: 10:01:06 Logdatei: mbam.txt Administrator: Nein Version: 2.00.2.1012 Malware Datenbank: v2014.06.26.02 Rootkit Datenbank: v2014.06.23.02 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Maeph Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 317894 Verstrichene Zeit: 5 Min, 8 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 1 PUP.Optional.Softonic.A, C:\Users\Maeph\Downloads\SoftonicDownloader_fuer_star-wars-galaxies-an-empire-divided.exe, In Quarantäne, [17f3e4996d0e082e917f73b2ec1542be], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=2a2c3b4b6e7f0747b21331a97ef67e4c # engine=18894 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-06-26 08:47:47 # local_time=2014-06-26 10:47:47 (+0100, Mitteleuropäische Sommerzeit) # country="Switzerland" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 128701 155402317 0 0 # scanned=127741 # found=33 # cleaned=0 # scan_time=1924 sh=C7C0F42A23562AA6DCCD60326FD8CC2AA41B5448 ft=1 fh=c053642cee9f3def vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir" sh=9DC13DB9C123270C2356ED410128E11D5ADF7C6E ft=1 fh=023ab782f0a9b07d vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir" sh=56659F7FF1F1FA7906A77228E315F65F38BCEF73 ft=1 fh=0ff759dfc352fd03 vn="Variante von Win32/ELEX.AD evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir" sh=A84C039FF1DAAAA7252955732A4E8EE4CF968B1B ft=1 fh=fed45452708664fd vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF10.dll.vir" sh=752B1961DB6AB8898FE0549213AA914C0CA6B718 ft=1 fh=e5d4be7c69805ddc vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF11.dll.vir" sh=8E74C63DB1BAC349315C961B8841EDCF82BA530A ft=1 fh=337c683ba543637d vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF12.dll.vir" sh=3E7F1EFE26E75577548C5671F96EF9DE97C27C58 ft=1 fh=d8ed7d6979bcd6ef vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF13.dll.vir" sh=AC4FE55F016ED99D97300F0EFDD79ABC36060043 ft=1 fh=01bf7131f02413ac vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF14.dll.vir" sh=38A77551D640ABFD1B7B77BBDE6DF8151EA4A7A1 ft=1 fh=27f3972bc5673f7b vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF15.dll.vir" sh=8181CE4B98D928987E2DD91FC198126FE0EFF7A1 ft=1 fh=2a775ad338f1b5dd vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF16.dll.vir" sh=9B49C9E0D598D596BD85FB0684D112A0D89962D9 ft=1 fh=e6a9dc5fafe354f4 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF17.dll.vir" sh=1C57F6653160B658BC4A89D90BB9B965EE6A73EB ft=1 fh=1af4b14ddb1938ad vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF18.dll.vir" sh=F5FF4EAEF5C87A0A52177525DC9EB51858F3CD09 ft=1 fh=a75a944064dce744 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF19.dll.vir" sh=BC3949E551957E3239F6EE8C8FD6E51D9B90F7A4 ft=1 fh=d4e1767a93b4bb5e vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF2.dll.vir" sh=547744A7A940F2A4CA6F29F149FAB2667E2E20FF ft=1 fh=3bc94f24f04e02e0 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF20.dll.vir" sh=68511D85675A119A2B0042C4B9E9E68568F9CC69 ft=1 fh=849a46b3d8334628 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF21.dll.vir" sh=2D970117EA235A150F60B0BFDA0570B572E15579 ft=1 fh=9f13dfd8ed655a92 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF22.dll.vir" sh=3CB040F2370648DCDF09F3538036D04A86C0016B ft=1 fh=84033a4e69d1c455 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF23.dll.vir" sh=82C9197CD905EF3FD391D8C3962E78A1D222E215 ft=1 fh=b83dd79fed78a9f0 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF24.dll.vir" sh=91F93AA323D593CA34486817DF5F452E73C7D265 ft=1 fh=1ce4277cdede7c3c vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF25.dll.vir" sh=D31C2E79DC3E09F9D46C77A556EA79D851314B56 ft=1 fh=1c9bfbeb879ff592 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF26.dll.vir" sh=4EC3A1EA248A2ADDE05B4E21DC1747D920ECE241 ft=1 fh=8006870a8fd0800a vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF27.dll.vir" sh=19C242DE42C333A72C4D2FD98B4A5E45E2722E2F ft=1 fh=88e7a324c335ae67 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF28.dll.vir" sh=C10DA08A224A5058B04C89D7E2545DCE1B1882E1 ft=1 fh=1cfd12f4ffe5f981 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF29.dll.vir" sh=4B8BF4B3A786BC8EFC31F124A79121633FCCEFB5 ft=1 fh=956688c87ea41354 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF30.dll.vir" sh=34DC7765D841F6A826809B070E61A3A9C265DEC2 ft=1 fh=17d7a39a89f60080 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF4.dll.vir" sh=3A2A87661BE7C287C16C8EC5D4DCB28F44DED34A ft=1 fh=29d9b991721e7a0e vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF5.dll.vir" sh=F71815E064A9AACFAD9001B174C667611C93827C ft=1 fh=719e07282195d0f2 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF6.dll.vir" sh=0B8EF6FA304399EC687F76F3B2C835F3C5F178EF ft=1 fh=135f4e0fefbaf1ca vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF7.dll.vir" sh=26BDD9A0B5F4A7CD1F0C096FB6160F83CC0EC902 ft=1 fh=bcf16556bf4bbb7c vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF8.dll.vir" sh=4E6CA7B1AA06BE7936C5B76313F0ED55C8B27F55 ft=1 fh=028c7e2bd08d993f vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maeph\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF9.dll.vir" sh=CA52336F05BE0CBDAFC0F23B93BC75B8B05F9138 ft=1 fh=c71c0011b36c8cc8 vn="Variante von Win32/AdWare.MultiPlug.Y Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\CostMin\LRis.exe.vir" sh=E08147D092058953586EEFB991E2FA8BAA0DCED0 ft=1 fh=e6ad25d740b8418d vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Maeph\Downloads\OpenOffice - CHIP-Installer.exe" |
Themen zu GS Supporter 1.80 auf dem Rechner |
bereits, files, gesuch, installation, installierte, irgend, log, programme, pup.optional.softonic.a, scan, supporter, troja, trojaner, win32/adware.multiplug.y, win32/downloadsponsor.a, win32/elex.ad, win32/thinknice.b, win32/toolbar.searchsuite.q |